Skip to content

Privacy policy

Straight talk: what we collect on the site, in the game and in the app, who we share it with, and how you stay in control.

Last updated: 25 August 2026

Who the data controller is

The controller of your data is Ravenlab sp. z o.o., Dębowa 11, 66-120 Kargowa, Poland, KRS 0001247798, NIP PL9731122188, REGON 545003226 - the owner and operator of the Buzzin platform.

For any data matter, email eryk@ravenlab.tech. We have not appointed a Data Protection Officer, so you reach us directly.

What this policy covers

This policy covers every Buzzin surface:

  • the playbuzzin.com website (information, account, purchases),
  • the TV game screen (tv.playbuzzin.com),
  • the phone controller in the browser (m.playbuzzin.com),
  • the Buzzin mobile apps for iOS and Android.

It does not cover third-party services we link to (Discord, the App Store, Google Play, our social profiles). Those run on their own terms.

What data we process

Playing without an account (the default). You need no account and no email to play. In that case we process:

  • a device identifier: a random string generated on your device and stored there, so the game recognizes the same phone after a refresh,
  • your nickname, chosen character and in-game activity (answers, points, drawings) plus the room code - without these the game cannot run,
  • technical data: IP address (which implies an approximate location, usually country and city), device type, operating system, app version, language.

Nicknames, drawings and answers live in the room's memory and disappear with it. What stays in the database is a pseudonymous trace of events (that someone played, how many points, in which game) tied to a device identifier, not to your name.

An account (optional, needed for purchases).

  • your email address and name; when you sign in with Google, Apple or Discord also your avatar and the account identifier at that provider,
  • session data: IP address and browser information, to keep you signed in and to spot abuse.

We store no password: sign-in works with a one-time email code or through your Google, Apple or Discord account.

Payments.

  • subscription status and period, transaction and customer identifiers at the payment provider, amount and currency.
  • We never see your card number. Payments run through Stripe and card details go straight to them.

The mobile app.

  • a push notification token if you enable notifications, along with the device language, platform and time zone (so a notification lands at a sensible hour),
  • crash reports and diagnostics (Firebase Crashlytics),
  • app usage events (Firebase Analytics, our own PostHog) and Meta SDK events used to measure installs from ads,
  • on Android, install source information from Google Play; on iOS, your answer to the system tracking prompt (ATT).

Forms and contact.

  • an email address you voluntarily submit through a form on the site,
  • the content of feedback sent from the in-app form, together with an optional contact detail, app version, platform, language and the last room code,
  • the content of your correspondence if you write to us.

Analytics and advertising.

  • analytics events (landing on the site, clicking "play", starting a game, purchasing) carrying a pseudonymous device and session identifier,
  • session recordings on the website and click maps in our own self-hosted PostHog (described below),
  • cookies and click identifiers from advertising links.

Purposes and legal bases

  • Providing the service (gameplay, rooms, account, access to decks): performance of a contract, Art. 6(1)(b) GDPR.
  • Payments and billing: performance of a contract (b) and our legal obligations in accounting and tax (c).
  • Our own analytics and website session recordings: our legitimate interest (f) in understanding how the product works and where players come from. The data goes to our own infrastructure.
  • Third-party ad pixels, campaign measurement and remarketing: your consent (a), given in the banner. Without it those scripts never load.
  • Push notifications: your consent (a), given in the system prompt; revoke it in your phone settings.
  • Email list sign-up: your consent (a), withdrawable at any time.
  • Crash reports, stability, security and abuse prevention: legitimate interest (f).
  • Handling feedback and requests: legitimate interest (f), or performance of a contract (b) when it concerns a purchase.
  • Establishing, exercising and defending legal claims: legitimate interest (f).

Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

Advertising, pixels and campaign measurement

We promote Buzzin with paid campaigns on Facebook and Instagram (Meta), Google and YouTube, TikTok and Reddit. To know which ads are worth running, we measure their effect:

  • The site carries those platforms' pixels. They load only after you accept the banner; before that none of those scripts runs. We use Google Consent Mode v2, so consent signals are set before any tag sends anything.
  • After consent we send the platforms conversion events: landing on the site, clicking "play", clicking through to an app store, starting a payment, purchasing (with amount and currency) and joining Discord. Each event carries its own identifier so it is not counted twice.
  • If you sign up to our email list, an irreversible hash (SHA-256) of your email address may be sent to TikTok - purely to match a conversion; the platform never receives the address in readable form.
  • In the mobile app, installs and events are measured by Firebase Analytics and the Meta SDK. On iOS measurement relies on Apple's SKAdNetwork and we ask for tracking permission in the ATT prompt; without your permission we do not use the advertising identifier.
  • On that basis the ad platforms may profile you for advertising and build audiences (for example, show ads to people similar to our players). They do so as separate controllers, under their own rules.

What we do not do: we do not sell data, we show no third-party ads inside the game, and we do not target ads at people under 16.

How to limit it: do not accept the banner, or clear cookies in your browser; you can also change ad settings directly with Meta, Google, TikTok and Reddit, and on your phone through the ATT prompt (iOS) or advertising-identifier settings (Android).

Cookies, click IDs and consent

On the site and in the game we use:

  • Essential storage: bz_consent holding your banner choice (180 days), the signed-in session cookie, and browser sessionStorage that keeps one event from being counted twice. No consent required.
  • First-party analytics: events, traffic statistics, click maps and session recordings go only to our own infrastructure (self-hosted PostHog in the EU, our own database, and Umami traffic statistics on a server in Germany). A recording shows movement around the page and clicks, and form fields are masked. This analytics runs from the moment you land, which the banner tells you; you can object by writing to us and we will delete the data.
  • Third-party ad pixels (Meta, Google, TikTok, Reddit): only after you accept the banner.
  • Click identifiers appended to links in ads (fbclid, gclid, ttclid, rdt_cid) - they let us attribute a visit to a specific campaign.

You can also clear or block cookies in your browser settings. Regardless of the banner, you keep every right listed under "Your rights", including the right to object and the right to erasure.

Who we share data with

We use providers that process data on our behalf:

  • Hostinger - application servers and database, located in Frankfurt (Germany, EU); Hetzner (Germany) for the staging environment and traffic statistics.
  • Stripe - payments and subscriptions.
  • Postmark - sign-in codes and transactional email.
  • Loops - email to people on our list.
  • Google (Firebase) - push notifications, crash reports and mobile app analytics.
  • PostHog - product analytics and session recordings; we host it ourselves, on infrastructure in the EU.

Separate controllers, deciding on their own: the ad platforms (Meta, Google, TikTok, Reddit), which receive data only after you consent to pixels, plus Apple and Google for the app stores and Discord if you join our server.

We may disclose data where the law requires it or where it is necessary to establish or defend legal claims. We do not sell your data.

Transfers outside the EEA

Our core infrastructure (servers, database, product analytics) sits in the European Union.

Some providers and ad platforms (Stripe, Postmark, Loops, Google, Meta, TikTok, Reddit, Discord, Apple) also process data outside the EEA, including in the United States. That happens under the mechanisms GDPR provides: standard contractual clauses or an adequacy decision (the EU-US Data Privacy Framework). Write to us and we will tell you which mechanism applies to a given provider.

How long we keep data

  • Account: for as long as it exists. After deletion we erase the data within 30 days, except what we must keep (accounting records, for instance).
  • Billing records and invoices: 5 years from the end of the tax year in which the tax obligation arose.
  • Analytics events: up to 24 months, then deleted or aggregated.
  • Website session recordings: up to 3 months.
  • Technical and security logs: up to 90 days.
  • In-app feedback: up to 24 months from submission.
  • Email address on the list: until you withdraw consent or unsubscribe.
  • Push token: until you turn notifications off or uninstall the app.
  • Consent records: 3 years, so we can demonstrate that consent was given and in what scope.
  • Gameplay content (nickname, drawings, answers): gone when the room closes.

Your rights

You have the right to:

  • access your data and get a copy,
  • rectify inaccurate data,
  • erase data (the "right to be forgotten"),
  • restrict processing,
  • data portability,
  • object to processing based on legitimate interest, including analytics and session recordings,
  • withdraw consent at any time, without affecting lawful processing carried out earlier.

To exercise any of these, email eryk@ravenlab.tech. We answer without undue delay and within one month at the latest. We will delete your account on request sent from the address it is registered to.

You also have the right to lodge a complaint with a supervisory authority. Ours is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl; if you live elsewhere in the EEA you may complain to your local authority.

Age of players

Buzzin is meant for people aged 16 and over. Younger players need a parent's or guardian's permission.

We do not target ads at people under 16 and we do not build remarketing audiences with them in mind. If we learn that we hold a child's data without a proper basis, we delete it. If you are a parent or guardian and want to report such a case, email eryk@ravenlab.tech.

Data security

We apply reasonable technical and organizational measures: encrypted connections (HTTPS), restricted access to systems, separated production and staging environments, and passwordless sign-in (a one-time code or a Google, Apple or Discord account), which means we never store your password.

No method of transmitting data over the internet is 100% secure, so we cannot promise absolute security. We do everything we reasonably can to keep the risk low. If you spot a vulnerability, email eryk@ravenlab.tech.

Changes to this policy

We update this policy as Buzzin grows, for example when a new game, a new provider or a new way of measuring arrives. We will announce material changes on the site, and the last-updated date sits at the top of this document.

Contact

Questions about privacy and data? Email eryk@ravenlab.tech and we will reply as soon as we can.

Data controller: Ravenlab sp. z o.o., Dębowa 11, 66-120 Kargowa, Poland. We have not appointed a Data Protection Officer, so for all data matters contact us directly at the address above.