Privacy Policy

Last updated: 17 May 2026

This Privacy Policy explains how Guess The Date ("we", "us", "our") collects and uses information when you visit guessthedate.app (the "Site"). We are the data controller for the personal data described below. This policy is written for the United Kingdom and complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

Guess The Date is a free daily history guessing game. If you have any questions about this policy or your personal data, you can contact us at hello@guessthedate.app.

2. Data we collect

We only collect data that we need to run the game and improve it. Specifically:

  • Account data (if you register): first name, last name, email address, a hashed password, and your communication preference for email updates.
  • Game data: your guesses, scores, streaks, achievements, challenges you create or accept, and the public profile slug derived from your name.
  • Push notification subscriptions (if you opt in): the browser-issued endpoint and keys needed to deliver notifications.
  • Technical data: IP address, browser type, device type, referring page, and pages viewed. This is used for rate-limiting, abuse protection, and analytics.
  • Cookies and similar technologies: see section 6 below.

We do not knowingly collect special category data, payment information, or data from children under 13.

3. How we use your data and our lawful basis

  • To provide the service — saving your progress, ranking you on the leaderboard, running challenges. Lawful basis: performance of a contract (our Terms with you).
  • To send service emails — verification, password resets, and important account notices. Lawful basis: performance of a contract and legitimate interests.
  • To send optional marketing or product update emails — only if you opt in. Lawful basis: consent, which you can withdraw at any time.
  • To deliver push notifications — only if you opt in. Lawful basis: consent.
  • To analyse and improve the Site — understanding usage, fixing bugs, planning features. Lawful basis: consent (for non-essential analytics cookies) or legitimate interests for first-party aggregated metrics.
  • To protect the Site — preventing abuse, spam, brute-force, and bot attacks. Lawful basis: legitimate interests.

4. Sharing your data

We do not sell your personal data. We share limited data with the following categories of processor strictly to run the Site:

  • Hosting and infrastructure providers that host our servers and databases.
  • Email providers used to send transactional emails such as account verification.
  • Google LLC — Google Analytics (measurement) and Google AdSense (advertising). These services may set cookies and collect device/IP-derived data. Both involve transfers outside the UK; Google relies on the UK Addendum to the EU Standard Contractual Clauses for international transfers.
  • Push notification services operated by your browser vendor (e.g. Google, Apple, Mozilla) — only used when you have opted in.

We may also disclose personal data if required by law, court order, or to protect the rights, property, or safety of Guess The Date, our users, or others.

5. International transfers

Some of our processors (notably Google) are based outside the United Kingdom. Where personal data is transferred outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or adequacy decisions made by the UK Government.

6. Cookies and similar technologies

We use a small number of cookies and similar technologies:

  • Strictly necessary cookies — for sessions, login state, CSRF protection, and rate-limiting. These do not require consent.
  • Local storage — used to save your in-progress puzzle and preferences on your device. This data stays on your device.
  • Analytics cookies — Google Analytics (gtag.js) to understand how the Site is used.
  • Advertising cookies — Google AdSense to serve and measure ads. AdSense may use cookies and similar technologies to personalise the ads you see.

You can manage or block cookies through your browser settings. You can opt out of personalised Google advertising at google.com/settings/ads and from Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

7. How long we keep your data

  • Account data: kept while your account is active. If you delete your account, we anonymise or remove personal identifiers within 30 days, except where we need to keep certain records for legal, accounting, or fraud-prevention purposes.
  • Game results: retained in aggregated or anonymised form to preserve leaderboards and statistics.
  • Server logs and abuse data: typically retained for up to 12 months.

8. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you;
  • Have inaccurate data corrected;
  • Have your data erased (the "right to be forgotten"), subject to legal exceptions;
  • Restrict or object to certain processing;
  • Receive your data in a portable format;
  • Withdraw consent at any time where we rely on consent;
  • Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

To exercise any of these rights, email hello@guessthedate.app. We respond within one month.

9. Security

We use industry-standard measures to protect your data, including HTTPS in transit, hashed passwords, rate-limiting, and access controls. No system is 100% secure, but we take reasonable steps to minimise risk.

10. Children

Guess The Date is not directed at children under 13, and we do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date above and, for material changes, give clearer notice on the Site.

12. Contact

Questions, requests, or complaints? Email hello@guessthedate.app.