Privacy Policy
Last updated: April 10, 2026 · Effective: April 10, 2026
Summary (plain English)
Percent is a real-time social prediction game for adults aged 18 and over. To run it we need a small amount of personal information — mainly your email (or Apple/Google sign-in), a display name, your date of birth (to confirm you meet the 18+ minimum), and an optional profile photo. We record how you play (ratings, streaks, game history) so you can progress through the ranks. Your individual answers to in-game questions stay private: other players only see the room's aggregate percentage, never what you personally answered.
We do not sell your data. We do not use third-party advertising or cross-app tracking. We use Google Firebase to run the back-end and Apple / Google to let you sign in. You can view, correct, export, and permanently delete your account at any time. If you're in the EU/UK or California, you have additional legal rights listed in section 8.
1. Who we are
This Privacy Policy describes how Percent ("Percent", "we", "us", "our") processes your personal information when you use the Percent mobile application (the "App") and the website at percentgame.co (together, the "Service"). Percent is operated by Nadir Aktan as an independent developer.
For all privacy matters (including GDPR, UK GDPR, and CCPA requests), the data controller can be contacted at nadir.aktan@hotmail.com.
2. Personal information we collect
We only collect what we actually need to run the game. Below is a complete list of the categories of personal data we process, the specific fields within each category, and the source.
2.1 Account and authentication data
- Email address — for account creation, sign-in, and essential service communications. Provided by you or received from Apple / Google when you choose those sign-in methods.
- Authentication identifier — an opaque user ID issued by Firebase Authentication, plus (if applicable) the anonymized identifier returned by Sign in with Apple or Google Sign-In. We never receive your Apple ID password or Google account password.
- Password — if you sign up with email and password, the password is handled entirely by Firebase Authentication and is hashed on Google's servers. We do not have access to the plaintext.
2.2 Profile data
- Display name — the name shown to other players in your rooms.
- Username — a unique handle used to find and invite you.
- First name and last name — optional; used inside your own profile.
- Date of birth and age — Percent is an 18+ service. We ask for your date of birth at signup to confirm you meet the minimum age. We store your date of birth on your user document and your age (derived from it) for display in your profile. Accounts for people under 18 are not permitted and will be deleted if discovered.
- Country — optional; used on leaderboards and for showing regional context.
- Profession and education level — optional profile fields.
- Short bio — optional; visible to your friends.
- Profile photo — optional; uploaded from your photo library and stored in Firebase Cloud Storage.
2.3 Gameplay data
- Your answers to in-game questions — stored per round on your own private player document. Other players cannot see your individual answers, only the aggregated room percentage.
- Your predictions — your guesses about what percentage of the room said yes, plus your per-player guesses within the room. These are stored on your private player document and are not visible to other players.
- Rating (ELO-style score), tier, and rank — calculated server-side from your accuracy and used to show your progress through the five tiers (Stranger → Mind Reader).
- Game statistics — current and best streak, total score, games played, per-category accuracy, achievements unlocked, login streak, last played time, and account creation time.
- Game history — a list of recent games you participated in, with date, room ID, your result, and a summary of what happened.
- Answer history — a record of questions you have been shown, so we don't repeat the same question too soon.
- Daily question responses — if you play the daily question, your response is stored on your private document.
2.4 Social data
- Friends list — a list of accounts you have added as friends, stored on your own user document.
- Friend requests — sent and received, stored on a separate friend-request collection visible only to the sender and recipient.
- Invite sessions — private rooms you create to invite specific friends into a game.
- Referral data — your unique referral code, and (if someone used a code to sign up) the code that was used. We do not collect or store any contact lists from your phone.
2.5 Purchase data
- In-app purchase transactions — when you buy a session pack, Apple processes the payment. We receive the App Store transaction identifier and product ID, which we use to verify the purchase on our servers and grant you the sessions. We do not see or store your credit card, Apple ID password, or billing address.
- Bonus session balance — a server-managed counter of how many paid or bonus sessions you currently have available.
2.6 Device and technical data
- Push notification token (FCM token) — a device-specific token issued by Firebase Cloud Messaging, used only to deliver notifications the app sends you (friend invites, room-ready alerts, the daily question). Stored on your user document and refreshed automatically.
- App and OS version — read at runtime to help us troubleshoot compatibility issues; not stored on our servers in a form tied to your identity.
- Language / locale — read from your device or chosen in-app, used to localize the interface.
2.7 What we do NOT collect
We want to be explicit. Percent does not collect: your precise or approximate location, your phone's contacts, your microphone, your camera roll (we only see the one photo you explicitly pick for your profile), your health data, your financial data, your browsing history outside the app, or any advertising identifier (IDFA). We do not use Crashlytics, Google Analytics, Firebase Analytics, or any third-party advertising or attribution SDK. Firebase Analytics is explicitly disabled in our configuration.
3. How we use your personal information
We use the information listed above only for the purposes below. For EU and UK users, the legal basis (under Article 6 GDPR) is shown next to each purpose.
- To create and operate your account — email, authentication identifier, display name, username, age. Legal basis: performance of a contract (Art. 6(1)(b)).
- To run the game — matching you into rooms, delivering questions, collecting your answers and predictions, revealing results, calculating ratings, streaks, and rank. Legal basis: performance of a contract.
- To manage your friends and invites — delivering friend requests, showing your friends list, letting you start private games. Legal basis: performance of a contract.
- To verify and fulfill in-app purchases — confirming the Apple receipt and granting the sessions you bought. Legal basis: performance of a contract.
- To send push notifications you opted into (friend requests, invites, room ready, daily question). Legal basis: performance of a contract; or consent (Art. 6(1)(a)) where local law requires opt-in.
- To keep the Service safe and fair — protecting against cheating, harassment, abuse, and misuse; enforcing our Terms. Legal basis: legitimate interests (Art. 6(1)(f)) in running a safe community game.
- To fix bugs and improve the app — diagnosing technical issues reported by you or detected in logs. Legal basis: legitimate interests in maintaining a working product.
- To comply with legal obligations — responding to valid legal process and meeting our own legal duties. Legal basis: legal obligation (Art. 6(1)(c)).
4. How we share your personal information
We do not sell your personal information. We do not share it with advertising networks or data brokers. We share it only with the processors and in the situations listed below.
4.1 Service providers (sub-processors)
- Google LLC — Firebase (Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, Cloud Messaging). Firebase hosts the entire back-end of Percent. Data flows to Firebase whenever you sign in, create or update your profile, play a game, or receive a notification. Firebase's privacy information is available at firebase.google.com/support/privacy.
- Apple Inc. — for Sign in with Apple (authentication), the App Store (processing your purchases and issuing receipts), and the Apple Push Notification service (delivering notifications to your device). Apple's privacy information is at apple.com/legal/privacy/.
- Google Sign-In — if you choose to sign in with a Google account, Google returns a verified identifier and your email to us. Google's privacy policy is at policies.google.com/privacy.
These providers process your data on our behalf under their own privacy terms and applicable data protection agreements. We do not use any other third-party data processors.
4.2 Other players you interact with
When you play a game, the other players in your room (up to four others) can see the limited profile information described in section 5. They cannot see your individual answers.
4.3 Bot-controlled players
To keep wait times short, some rooms may include bot-controlled players if there aren't enough humans immediately available. Bots do not see, store, or share your personal data — they only interact with the room's aggregate gameplay. You will not always know whether a room contains bots.
4.4 Legal requests and safety
We may disclose your information if we genuinely believe disclosure is required to (a) comply with a valid legal process or lawful government request, (b) enforce our Terms, (c) protect the rights, property, or safety of Percent, our users, or the public, or (d) investigate suspected fraud or abuse.
4.5 Business transfers
If Percent is acquired by, merges with, or transfers its assets to another entity, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.
5. What other players can see
Inside a game room, other players can see: your display name, username, profile photo, country (if set), current rating, tier, and rank. Once a round is over, everyone in the room sees the room's aggregated percentage result — never individual answers. On your friends list, your friends can see your profile, your current rating, and your streak. Leaderboards (if displayed) show display name, rating, and rank.
Your email address, date of birth, password, in-app purchase history, friends list, and individual answers are never visible to other players.
6. How long we keep your information (retention)
- Active accounts: we keep your account data for as long as your account is active.
- Gameplay records: your game history, answer history, and game statistics are retained to support progression and rating calculation. You can erase this history by deleting your account.
- Aggregated room results: once a room has finished, the anonymized group percentage becomes part of historical question statistics. This data does not identify you and may be retained indefinitely.
- Deleted accounts: when you delete your account, we permanently remove your profile, friends, game history, answer history, daily question responses, friend requests, pending invites, lobby records, profile photo, and authentication record. Deletion is typically immediate; in rare cases it may take up to 30 days for all backups to rotate out.
- Purchase records: Apple retains App Store transaction records under its own policies. We do not store billing data.
- Legal holds: if we are subject to a legal obligation to retain data (for example, in response to a lawful request), we will retain only what is required and only for as long as required.
7. Security
We protect your data with industry-standard safeguards: TLS 1.2+ for all data in transit, Firebase security rules that enforce per-user read/write access on every single document, short-lived authentication tokens, server-side validation of all game state changes in Cloud Functions, and least-privilege Admin SDK usage. No system is perfectly secure, but we work to follow the principle of least access throughout the stack.
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by GDPR, and notify affected users without undue delay.
8. Your rights
You have the following rights regarding your personal information:
- Access — ask us what personal data we hold about you.
- Correction — update your profile (display name, age, photo, country, profession, education, bio) at any time directly in the app, or contact us for fields you can't edit.
- Deletion — delete your account from Settings → Delete Account inside the app, or via our delete account page. This is permanent.
- Data portability — request a copy of your personal data in a machine-readable format.
- Restriction and objection — ask us to pause or stop certain kinds of processing.
- Withdrawal of consent — where we rely on consent (for example, push notifications), withdraw it at any time.
- Lodging a complaint — if you are in the EU, UK, or EEA, you have the right to complain to your local data protection authority. You can find yours at edpb.europa.eu (EU) or ico.org.uk (UK).
8.1 California residents (CCPA / CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- The right to know what categories of personal information we collect, the sources, the business purpose, and the categories of third parties with whom we share it (all described in sections 2 and 4 above).
- The right to delete personal information we have collected about you.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information for cross-context behavioral advertising. We do not sell or share your personal information for any such purpose.
- The right to limit use of sensitive personal information. The only sensitive data we collect is your date of birth, which we use solely to verify that you meet our 18+ minimum and to display your age in your profile.
- The right not to be discriminated against for exercising these rights.
To exercise any California right, email nadir.aktan@hotmail.com from the address associated with your account.
8.2 How to exercise your rights
For access, portability, correction, or deletion requests that you can't complete in the app, email nadir.aktan@hotmail.com. We will respond within 30 days (or longer where the law permits). We may ask you to verify your identity by signing in to the email linked to the account.
9. Automated decision-making
Percent calculates your rating, tier, and rank automatically based on the accuracy of your predictions relative to the other players in your room. This is a form of automated processing, but it does not produce any legal or similarly significant effect on you — it only changes your in-game rating. You can contact us if you believe a rating change was the result of a bug or unfair matchmaking.
10. International data transfers
Percent is built on Google Firebase, which is operated by Google LLC in the United States with data centers in various regions. When you use Percent, your personal data may be processed in the United States and other countries where Google operates. These countries may have data protection laws that are different from the laws in your country.
Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on Google's Standard Contractual Clauses and supplementary measures as outlined in the Firebase Data Processing and Security Terms.
11. Age restriction — Percent is strictly 18+
Percent is an adult service. You must be at least 18 years old to create an account or use the Service, regardless of where you live. This single rule applies worldwide, even in jurisdictions where the age of digital consent or the age of majority is lower. We do not knowingly collect personal information from anyone under 18. If we become aware that an account belongs to a person under 18, we will delete the account and associated personal information as soon as reasonably possible. If you are a parent or legal guardian and believe a person under 18 has created a Percent account, please email nadir.aktan@hotmail.com and we will promptly remove the account.
12. Third-party links
The Service may link to third-party websites or services (for example, the App Store, Firebase's privacy information page, or a social platform). We are not responsible for the privacy practices of those third parties — please read their privacy policies separately.
13. Cookies and similar technologies
The Percent mobile app does not use advertising cookies, web beacons, or cross-app tracking. The percentgame.co website is a static site and does not set any tracking cookies of its own. We do not use Google Analytics, Meta Pixel, or any similar tracking pixel on the site.
14. Changes to this policy
We may update this Privacy Policy as the Service evolves or as the law changes. The "last updated" date at the top will reflect any changes. If we make material changes, we will notify you via the app or by a prominent notice on the website before the change takes effect, and, where required, ask for your renewed consent.
15. Contact
If you have any questions, concerns, or requests about this Privacy Policy or our handling of your personal data, contact us at nadir.aktan@hotmail.com.