Privacy Policy
Last updated: September 2026
This policy describes how SparkleQuiz collects, uses and protects your personal data, in compliance with the General Data Protection Regulation (GDPR) and the requirements of Google Play and Apple's App Store.
1. Service publisher
SparkleQuiz is operated by Quentin Bastos. Contact: [email protected]. The service is available at https://sparklequiz.fr and through the mobile apps distributed on Google Play (Android) and the App Store (iOS).
2. Data we collect
- Account data: email address, hashed password, username, avatar, preferred language.
- Gameplay data: scores, MMR/rank, daily streaks, quizzes you create, games played, friends and clubs.
- Technical data: IP address, mobile device identifier, OS version, push notification token (FCM), error logs. In the Android app only, the device advertising ID is read by Google AdMob to serve ads (see section 4). On iOS we do not request access to the advertising identifier (IDFA) and do not track you across other apps.
- Payment data: we do not store any card data. Transactions are handled exclusively by Stripe (web) or, in the mobile apps, by Google Play Billing (Android) and Apple's App Store (iOS), through RevenueCat.
- Support data: messages you send us and their content.
3. Purposes of processing
Account creation and management; providing solo, multiplayer and ranked game modes; computing leaderboards and rewards; sending push notifications (with your consent); detection and prevention of fraud, cheating and abusive behaviour; aggregated statistics to improve the service; advertising in the mobile apps only (no ads on the website), except for Premium subscribers and people who bought the "No ads" option.
4. Service providers and partners
We share data with the following providers, strictly within the scope of their service:
- Google (OAuth authentication when you sign in with Google);
- Apple (authentication when you sign in with Apple);
- Stripe (web payments: PCI-DSS certified);
- RevenueCat, Google Play Billing and Apple's App Store (in-app purchases in the mobile apps);
- Firebase Cloud Messaging by Google (push notification delivery);
- Sentry (anonymised technical error collection for diagnostics);
- Mistral AI (text generation in the quiz editor, hosted in the European Union): only the topic and the questions you submit to the assistant are sent to it, never your email address or your username;
- OVHcloud (sending the service's emails, hosted in the European Union): your email address and the content of the message sent;
- Google AdMob (advertising in the Android and iOS apps only: videos you choose to watch for a reward, a banner on the results screen and, where enabled, an occasional full-screen ad when leaving the results screen of a solo game, never during a question and never in multiplayer). Your consent is collected on first launch through Google's consent form (UMP); if you decline, ads stay non-personalised. You can change your choice at any time from Settings. The Premium subscription and the one-time "No ads" purchase remove the banner and the full-screen ad; only the videos you choose to watch are still offered.
No personal data is sold to third parties.
5. Retention period
- Account data: kept for as long as your account is active, then deleted immediately when you delete your account, which happens during your request.
- Technical and Sentry logs: 90 days maximum. An email address only ever appears there as a hash.
- Admin action log: the action row is kept for 12 months; the IP address and browser are wiped from it after 90 days.
- Product analytics and subscription funnel: 180 days maximum, and the events tied to your identifier are deleted along with your account.
- Transaction data: the local records (heart purchases, subscriptions) are deleted along with your account. Accounting and tax records are kept by our payment providers, Stripe, Google Play Billing and Apple, for as long as the law requires of them; we hold no copy tied to your account.
- Public quizzes and posts: kept while published; you can delete them at any time from your account. After you delete your account they stay published without your author name or their image: delete them or set them to private beforehand if you want them gone.
- Private and room messages: the text of your messages is retained on your correspondents' side and in the game transcript, without your name, including after you delete your account. A one to one conversation belongs to the other person too.
- Club messages: kept while your account exists, deleted along with it.
- Support messages sent without an account: the reply address and the message content are kept for 90 days, then deleted automatically.
6. Your rights
Under the GDPR, you have the right to access, rectify, erase, port, restrict and object to the processing of your data. You can exercise these rights at any time by emailing [email protected]. You also have the right to lodge a complaint with your national supervisory authority (in France: the CNIL: www.cnil.fr).
7. Account deletion
You can delete your account at any time from Settings > Danger zone > Delete Account. This action is irreversible and immediate: there is no queue and no cooling-off period. Two exceptions, detailed in section 5 and repeated on the confirmation screen: your published quizzes and themes stay online without your author name (their images are deleted), and the text of your private and room messages stays with your correspondents. Minimal security logs we are required to retain are kept as well.
8. Children
SparkleQuiz is not intended for children under the age of 13 and we do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected] and we will delete it.
9. Transfers outside the European Union
Some of our processors (notably Google, including AdMob, Apple, Stripe, RevenueCat and Sentry) are based in the United States. These transfers are governed by the European Commission's Standard Contractual Clauses and the Data Privacy Framework, ensuring an adequate level of protection.
10. Security
Your data is stored in secure databases hosted in Europe. Passwords are hashed with bcrypt. Communications are encrypted over HTTPS (TLS 1.2+). We offer optional two-factor authentication and apply brute-force protection on authentication endpoints.
11. Updates
This policy may evolve to reflect changes in the law, our services or our practices. The last-updated date is shown at the top of this page. We will notify you in-app of any substantial changes.
12. Contact
For any question relating to this policy or to exercise your rights, email us at: [email protected].
See also: our cookie policy and the account deletion procedure.