The Fine Print · in effect from 18 August 2026
Privacy Policy
HushDare is a collection of social party games published by Self Capsule Pty Ltd (ABN 34 696 418 970), a company registered in New South Wales, Australia. This policy explains what we collect when you play, why we collect it, how long we keep it, and what you can ask us to do with it. It covers everything: the HushDare app on iOS and Android, the web version of the game, and the hushdare.com website. One document, so you never have to work out which policy applies to you.
The short version: you can play without an account, and a player who has not bought anything is never asked for an email address or for any name beyond the one they type into the game. There is no advertising and no third-party tracking software in the app. We measure how the games are used with our own system and keep those records for 90 days. Everything that happens inside a game room is deleted automatically about a day after you finish playing, with one exception we state plainly: if a player reports something written in a room, we keep a copy of the reported text with that report for 90 days so we can act on it. The one time we hold an email address is when somebody who has already bought an unlock chooses to attach one so the purchase follows them to their other devices, and that is offered after the purchase rather than asked for before it. The rest of this document is the detail behind those statements.
1. Who we are
Self Capsule Pty Ltd is the data controller for the information described in this policy. HushDare is our consumer brand, and Hush is the game on the bill. This policy covers any further games we add under it.
You can reach us about privacy at privacy@hushdare.com, and about anything else, including reports of objectionable content, at support@hushdare.com.
2. You do not need an account
Anonymous play is the default. There is no sign-up, no password, and no option to connect a social network. We never ask you for your real name.
The first time you open the app, it creates an anonymous session with our database provider. That session is a random identifier with no personal information attached to it. It belongs to that installation of the app on that device. If you delete and reinstall the app, the old identifier is gone and a new one is created.
The one exception, and it is opt-in
If you buy an unlock, we offer afterwards to attach an email address to that same anonymous session, so the unlock reaches your other devices and survives a reinstall. That is the only account we operate, it is offered only after a purchase, and declining it costs you nothing you have already paid for. Signing in on another device with that address confirms what you own and nothing else.
Attaching an address does not create a profile. There is still no password, no display picture, no friends list, and nothing about you beyond the address itself. You can delete the account from inside the app at any time, as described in section 10.
3. What we collect
We collect the smallest amount of information that lets a room full of people play a game together. Specifically:
- The display name you type
- This is a free-text field. Whatever you type is stored with the room and shown to everyone else in it. You do not have to use your real name, and we recommend you do not. Please do not put an email address, a phone number, or anything else identifying into it.
- What you write during a game
- Some games ask you to write something: an answer to a prompt (up to 280 characters) or a question for other players to answer (up to 140 characters). We store it so the game can show it to the other players in your room at the right moment, and we delete it with the room. Same advice as above: it is a free-text field, and other players will see it.
- Gameplay state
- The four-letter room code, which game is being played, which topic pack is selected, the round in progress, scores, who is host, and timestamps for when the room was created and last active.
- Your anonymous session identifier
- The random per-installation identifier described above. It is how the service knows that two requests came from the same player, and how a purchase stays attached to the device that made it.
- Purchase records
- If you buy an unlock in the app, Apple or Google gives us a cryptographically signed receipt. We verify it on our server and store the product identifier, the platform, the store transaction identifier, and the time it was granted, attached to your anonymous identifier. If you buy on hushdare.com, Polar tells our server that the order settled and hands back the anonymous identifier we stamped on the checkout, and we store the same four things with the Polar order identifier in place of the store one. Either way that is the entire record, and it never contains a payment detail.
- Your email address, only if you attach one
- Offered after a purchase and never before it. If you accept, we store the address against the same anonymous identifier and send you a sign-in link when you ask for one. We use it for that and for writing back to you about the purchase, and for nothing else: no newsletter, no product announcements, no marketing, and it is never given to anyone else. A player who has not bought anything is never asked for it, and you can delete the account, and the address with it, as described in section 10.
- How the games are used
- We record a short, fixed list of moments so we can see where the game works and where people get stuck: the app opening, a room being created or joined, a round or a game finishing, a locked pack or an upgrade screen being shown, whether a purchase completed, failed, or was cancelled, whether you were offered the app when arriving from a link, whether you rejoined a room you had left, and whether we asked you to rate the app. There are eighteen of these events and no others, and the list is fixed in the app rather than configurable after the fact. Each record carries the event name, the time, the platform, the app version, your anonymous session identifier, and, where it applies, the room code and which game was being played. It never carries your display name, anything you wrote during a game, your date of birth, or any advertising identifier. We collect this ourselves, into our own database. There is no third-party analytics service involved and no analytics software from another company in the app.
- Where your install came from
- Once, on first launch, we record how you arrived. On iPhone and iPad that is Apple’s own attribution token, which tells us at the campaign level whether you came from an Apple Search Ads campaign; it involves no advertising identifier and no tracking prompt. On the web it is the campaign parameters in the link you followed, taken from a fixed list of the standard ones rather than the whole address. We store one such record per installation, attached to your anonymous session identifier and nothing else.
- Technical and log data
- Our hosting and database providers process ordinary network information, including your IP address, device and browser type, and request timestamps, in order to deliver the service and to protect it against abuse. We do not use this information to build a profile of you, and we do not combine it with anything else in this list.
4. What we do not collect
This section is as important as the one above, and it is specific rather than reassuring:
- No third-party analytics. There is no analytics, attribution, advertising, or crash-reporting software from another company in the app. The measurement described in section 3 is entirely our own: the events are a fixed list written into the app, they go to our own database, and no other company receives them. We do not follow you across other apps or websites, and we cannot see anything you do outside HushDare.
- No screen-by-screen or session recording. We record the eighteen named moments listed in section 3 and nothing else. We do not capture your screen, your taps, how long you looked at something, or the text you type.
- No advertising, and no advertising identifiers. We do not serve ads, we do not read the iOS advertising identifier, and we do not show the App Tracking Transparency prompt, because nothing we collect is shared with another company or used to follow you anywhere else.
- We never sell personal information, and we never share it for cross-context behavioural advertising, as those terms are used in California law.
- No contacts, no location, no photo library, no microphone, no health data, no calendar.
- No payment details. Apple, Google, and Polar handle the entire transaction, each on its own pages. We never see your card number, your billing address, or the name on the account.
Three things that stay on your device
Some features look like they would need to send information to us. They do not, and this is a deliberate design constraint rather than a happy accident:
- The camera
- The app can use your camera to read a room code from a QR code. The image is processed on the device to find the code and is never stored, never uploaded, and never seen by us. You can always type the code by hand instead, and the app works fully without ever granting camera access.
- Your age
- One topic pack is for adults only. To reach it, the app either asks your device operating system whether the account holder is an adult, or asks you to confirm your year of birth. Your date of birth is stored on your device and nowhere else. It is never sent to us, never written to our database, and never attached to any identifier. If the check does not pass, the adult pack simply is not shown.
- On-device topic generation
- On supported phones the app can generate new topic cards using the AI model built into the device itself, Apple Foundation Models on iOS or Gemini Nano on Android. That feature makes no network requests at all. Your requests and the topics it produces never leave the phone.
What the app stores on your device
The following are saved in the app’s own storage on your device, not on our servers: the name you last used, your age confirmation, which how-to-play guides you have seen, a count of games you have finished, when you last dismissed an upgrade prompt, and any topic packs generated on the device. Deleting the app deletes all of it.
5. How we use information
We use the information in section 3 for five purposes, and nothing else:
- To run the game: to create a room, to keep every player in it in sync, to show the right thing to the right player at the right moment, and to keep score.
- To deliver what you paid for: to verify a purchase receipt or a settled web order, to unlock the content it entitles you to, to restore it if you reinstall, and, if you attached an email address, to send you a sign-in link so the unlock reaches your other devices.
- To understand how the games are used and improve them: to count how many people reach each step, to see which games and topic packs get played, to find where people get stuck or drop out, and to know whether an upgrade was bought or abandoned. This is counting and comparing, in aggregate.
- To keep the service working and safe: to fix faults, to prevent abuse and fraudulent purchases, and to protect the service and its players.
- To meet legal obligations: principally to keep the transaction records that Australian tax and consumer law require us to keep.
We do not use your information to profile you, to advertise to you, or to train any AI model.
Legal bases, if you are in the EEA or the UK
We rely on performance of a contract with you for running the game and delivering purchases; on our legitimate interests in securing the service, preventing abuse, and measuring how our own games are used so we can improve them; and on compliance with a legal obligation for keeping transaction records. The measurement interest is a narrow one: it is first-party, it is not shared, it is not used to profile or advertise to you, and the raw records expire on the schedule in section 9. Where we rely on consent we say so and you can withdraw it at any time: permission to use the camera, in your device settings; website analytics for visitors in the European Economic Area and the United Kingdom, through the "Cookie choices" link in the footer of every page, which is as easy to use as the banner that asked. Website analytics outside those regions rests on the same legitimate interest in improving what we make, and the same link turns it off.
6. On this website
Everything above describes the games. The hushdare.com website is a different surface with different behaviour, and this section covers it. We keep both in one document rather than two so you never have to work out which policy applies to you.
- Essential cookies
- Used to remember your cookie choice and to route you around the site. These cannot be switched off, because without them the site cannot remember that you declined anything.
- Analytics, and how you control them
- We use Google Analytics on this website to count page views, scroll depth, and which buttons get clicked, so we can tell which pages are worth keeping. Whether it starts on or off depends on where you are, because the law differs: in the European Economic Area and the United Kingdom nothing loads until you accept, and no Google script is even requested before then; everywhere else it starts on and the banner offers to turn it off. If your browser sends a Global Privacy Control signal we treat that as a decision and keep analytics off wherever you are. Either way you can change your answer at any time through the "Cookie choices" link in the footer of every page. Google Analytics runs on this website only. The games use no Google Analytics and no measurement service from any other company; what they record is our own and is described in section 3.
- If you write to us
- The contact form sends us your message and your email address so we can reply. We keep it as long as the conversation is useful and no longer.
- If you subscribe
- We store your email address until you unsubscribe, which you can do from any message we send.
- If you go to the checkout
- The checkout is hosted by Polar on its own pages, not on this one. We do not embed it here, so no Polar cookie is set on this website and Polar sees nothing about you until you arrive on its own page. When the payment is done you are sent back to a page on hushdare.com that carries no personal information in it.
The website uses Vercel for hosting, Google Analytics for the measurement described above, Resend to deliver email, and Google Fonts for typography. There is no advertising profile and no retargeting. The cookie names themselves, and how to change your choice, are listed at hushdare.com/legal/cookies.
8. What other players can see
A game room is a shared space. The name you choose, the fact that you are present, your score, and anything you write during a game are shown to the other players in your room. That is what makes the game work, and it is not something we can undo for you after the fact. Some games deliberately hide who wrote what until a reveal moment, but the content itself is always shown to the room.
A room code is the only key to a room. Treat it as you would a door: share it with the people you want at the table, and not more widely.
9. How long we keep information
- Rooms, names, and everything written in a game
- We keep a room for 24 hours after its last activity, and a job runs every hour to delete anything past that point. So a room and everything written in it is normally gone within about a day; because the sweep is hourly rather than continuous, the outside edge is a little over 24 hours rather than days or weeks. Deletion is automatic, not something you have to ask for, and it cascades to every answer and every prompt written in that room.
- Content reported to us
- If a player reports something written in a room, we keep a copy of the reported text, together with the room code and the anonymous identifiers of the player who reported it and the player it concerns, for 90 days from the moment the report is filed. A job runs every day to delete anything past that point, so a report is normally gone within about three months; because the sweep is daily rather than continuous, the outside edge is a little over 90 days. This is the one case where something written in a room outlives the room: the copy is deliberately not deleted with it, because a report we can no longer read is a report we cannot act on. We use it only to review the report and to act on it, as our Terms of Use describe.
- Usage records
- We keep an individual usage event for 90 days from the moment our server receives it, and a job runs every day to delete anything past that point. So a usage record is normally gone within about three months; because the sweep is daily rather than continuous, the outside edge is a little over 90 days rather than longer. Deletion is automatic, not something you have to ask for. What outlives it is a set of daily counts and totals, such as how many people reached a step on a given day, which carry no identifier of any kind and cannot be traced back to you or to your device. We keep those aggregates indefinitely, and we say so plainly rather than implying the whole record expires.
- Where your install came from
- One record per installation, kept while that installation exists so we do not have to ask again. It is deleted when your anonymous session is deleted.
- Purchase records
- Kept for as long as you might reasonably want to restore the purchase, and for as long as Australian tax and record-keeping law requires, currently five years from the end of the relevant financial year. The company that took the payment, whether Apple, Google, or Polar, keeps its own record of the transaction under its own policy, and deleting ours does not delete theirs.
- An attached email address
- Kept until you delete the account, which you can do from inside the app at any time. There is no other expiry, because the whole point of the address is to still work when you pick up a new phone in two years.
- Data on your device
- Kept until you delete the app or clear its data. We have no way to reach it and no copy of it.
- Provider logs
- Ordinary server and network logs are held by our providers for their standard operational periods, typically measured in days to a small number of weeks, and are not retained by us separately.
10. Your choices and your rights
Depending on where you live, you may have the right to ask for access to the personal information we hold about you, to have it corrected, to have it deleted, to object to or restrict how we use it, to receive a copy in a portable form, and to withdraw consent where we relied on it.
How to delete your information
- Anything from a game deletes itself about a day after the room’s last activity, as described in section 9. You do not need to ask, and there is nothing to wait for beyond that. The one exception is text a player has reported to us, a copy of which is kept with the report for 90 days and deletes itself on the same schedule.
- Usage records delete themselves 90 days after we receive them, as described in section 9. If you want them gone sooner, write to us with the detail described below and we will delete what we can identify as yours.
- Deleting the app removes everything stored on your device, including your name, your age confirmation, and your anonymous session.
- If you attached an email address, you can delete that account from inside the app. Doing so removes the address and the record that carries your unlock between devices. A purchase made through Apple or Google can still be restored afterwards from the store that took the payment; a purchase made on hushdare.com cannot be carried to a new device once the account is gone, so the app says so and asks you to confirm first.
- To have a purchase record deleted on its own, email privacy@hushdare.com. Deleting it means we can no longer restore that purchase for you, so we will confirm before we do it.
An honest limitation
Unless you attached an email address, we deliberately hold nothing that identifies you as a person, so we usually cannot connect a request to specific records without your help. If you write to us, please include the room code and roughly when you played, or the transaction identifier from your receipt. If you did attach an address, write from it and we can find your records directly. If we genuinely cannot identify any information as yours, we will tell you so plainly rather than guess, because guessing would mean handing your information to whoever asked.
How to complain
Write to us first at privacy@hushdare.com. We answer as quickly as we can, and always within the period your law allows: one month in the United Kingdom and the EEA, thirty days in Australia, forty-five days in California. If a request is complex enough that we need longer, and your law permits an extension, we will tell you why before the first deadline passes rather than after. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or, if you are in the EEA or the UK, to your local data protection authority.
11. Where your information is processed
We are based in Australia, and our database and server functions run in the United States. Some of our providers operate globally, so information may also be processed in other countries.
Where we transfer personal information out of the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum. Where Australian Privacy Principle 8 applies, we take reasonable steps to ensure any overseas recipient handles your information consistently with the Australian Privacy Principles.
12. How we protect information
- All traffic between the app and our servers is encrypted in transit.
- Every table in our database enforces row-level security, so a player can only read the rows they are entitled to read. Purchases can only be written by our server after it verifies the store’s signature, never by an app claiming to have bought something.
- Administrative credentials exist only on the server and are never included in the app.
- We hold as little as possible, and we delete it as fast as the game allows. The strongest protection for information is not to be holding it.
No service can promise perfect security, and we do not. If a breach ever affects your information in a way that is likely to cause you serious harm, we will notify you and the relevant regulator as the law requires.
13. Children
HushDare is rated 16+ on the App Store and Teen on Google Play, and it is not directed to children. We do not knowingly collect personal information from anyone under 16, or under 13 in the United States. Content rated for adults sits behind an age check, as described in section 4.
If you believe a child has provided us with personal information, write to privacy@hushdare.com and we will delete it.
14. Additional regional information
Australia
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may contact us anonymously or under a pseudonym; in practice, that is how the game works by default.
California
In the twelve months before the date of this policy we collected the categories of information described in section 3, being identifiers and internet or network activity information, for the business purposes described in section 5. We did not sell personal information, we did not share it for cross-context behavioural advertising, and we did not knowingly collect or sell the personal information of anyone under 16. We do not discriminate against anyone who exercises their privacy rights, and we offer no financial incentives in exchange for personal information.
EEA and UK
Self Capsule Pty Ltd is the controller. Our legal bases are set out in section 5, our transfer safeguards in section 11, and your rights in section 10. You have the right to lodge a complaint with your local supervisory authority.
Everywhere else
HushDare is available worldwide, and we have named the three regimes above only because they are the ones that ask for specific wording. They are not the limit of what we honour. Wherever you live, the rights in section 10 are available to you, on request, by the same route and to the same standard, whether or not your country compels us to offer them. If your local law gives you something further, tell us when you write and we will apply it.
15. Changes to this policy
If we change what we collect or what we do with it, we will update this page and change the effective date at the top. Where a change materially affects your rights, we will tell you inside the app before it takes effect. Continuing to play after a change means you accept the updated policy.
16. Contact us
Self Capsule Pty Ltd (ABN 34 696 418 970), New South Wales, Australia
Privacy and data requests: privacy@hushdare.com
Everything else: support@hushdare.com