Privacy Policy
Last updated 23 September 2026
The short version
You do not make an account, and the app does not ask for your name, email, or phone number. (The website has one voluntary form — see The website below.) We give your device an anonymous ID so it can rejoin a game after you close the app. We store the games you play and the guesses you make, because that is the game. We do not sell anything about you. From version 1.0.2 the free version shows an ad between some rounds, served by Google AdMob, and the only thing that decides whether those ads use your device's advertising identifier is the tracking prompt iOS shows you — tap Ask App Not to Track and you get generic ads instead. From the same version you can buy a Premium subscription or a category pack; Apple takes the payment and we never see your card. From version 1.0.7, if you ask for them, we can send you a Daily Challenge reminder and a nudge when your group has finished — nothing else, never an ad, and you can switch them off in the app. From the same version you can add a photo to a Daily group or to your profile: only people in your groups see it, and every photo is checked automatically before anyone does. And from the same version you can find your Facebook friends on the Daily leaderboard. We keep only the ID Facebook gives you for this app and the IDs of your friends who connected too. We never keep your Facebook name, photo or access key, and Disconnect deletes them.
Who we are
This app is made by Joe Spisak. Contact: hello@rank100.app.
What we collect, and why
An anonymous account
When you first open the app we create an anonymous account with our backend provider, Supabase. It is a random identifier (a UUID). It is not linked to your name, email, phone number, Apple ID, or advertising identifier, and we cannot use it to work out who you are.
It persists on your device so that closing the app mid-game does not lose your score. If you delete and reinstall the app, you get a new one and the old history is no longer associated with you.
Things you type
- Your display name. You choose it, and other players in your game see it. Please do not use your full name or anything you would not want the other people in the room to see.
- Your guesses. Stored with the round they belong to, because scoring and the reveal both need them. Other players see your guesses only after the round is revealed.
Gameplay data
Which games you joined, when, your score, and which content packs you have access to. This is what makes the game work.
Reports
If you report another player we store who reported whom, in which game, the reason, and anything you typed — so we can act on it. The person you report is not told. Reports are readable only by us.
Feedback you send us (version 1.0.2 and later)
There are two places in the app where you can tell us what you think: Settings → Send feedback, and a card we show once, after a game has finished. Both send the same thing to the same place.
When you send feedback we store what you wrote, the version of the app you were running, and — only if the message came from the card after a game — which game you were in, so a bug report about a round can be traced to that round. If you typed an email address in the optional box, we store that too, and we use it for one thing: replying to you. The box can be left empty and the message sends just the same.
We keep feedback until we have acted on it. It is not deleted when your account is — if it were, the anonymous accounts this app runs on would take most messages with them before anyone had read them, which would make the feature pointless. What survives is the message itself; the account it came from is unlinked. If you want a message or the email you left with it removed, write to hello@rank100.app and we will delete it.
Feedback goes to nobody but us. It is not shown to other players, and it is not sent to any third party — it sits in our own database, which only we can read.
Analytics and crash reporting
Version 1.0 of the app contains none. No analytics, no crash reporting, no PostHog, no Sentry, and no other measurement or diagnostics service, so nothing about how you use it is sent anywhere except the game data described above.
Version 1.0.1 and later contain two, and only two. This section was updated before that version was submitted, which is what the earlier version of this policy promised would happen.
- PostHog, for product analytics, receives your anonymous ID and a short list of named events: the app was opened, an invite link was followed, a game was created, joined, started or finished, a guess was submitted, a result was shared. Each one carries counts and timings only — how many players were in the room, which round it was, how many seconds were left on the clock.
- Sentry, for crash reporting, receives crashes and errors: your device model, OS version, app version, and the technical stack trace. It is not told your anonymous ID, so a crash is not tied to a player.
Neither one is ever sent your guesses, your display name, the contents of any list, the rank or score of any particular answer, or any redemption code. That is enforced by the app and not merely intended: every event is checked against a list of forbidden fields before it leaves the device, and an event carrying one is discarded whole rather than trimmed.
Neither is an advertising, attribution, or ad-network service. The App Tracking Transparency prompt the app can show belongs to the advertising section below, not to these two.
Advertising (version 1.0.2 and later)
The free version shows an ad between some rounds. An ad only ever starts between rounds, never while the clock is running; there are never more than two in a game, and none in your first session after installing. The ads are served by Google AdMob, an ad network run by Google, and are requested with Google's strictest content setting, so they are meant to be suitable for a general audience.
When an ad is about to show, the app sends AdMob an ad request. That request carries your IP address (which AdMob may use to estimate your general location), your device model and OS version, the app's identifier, and — only if you allowed tracking — your device's advertising identifier (IDFA). AdMob also records which ads you were shown and whether you tapped one, and collects diagnostics about how its own code performed. AdMob does not receive your anonymous ID, your display name, or anything you type in the game.
Tracking is your call, and the app works the same either way. The first time an ad is about to show, iOS asks whether Rank 100 may track you. Allow it and AdMob may use your advertising identifier to pick ads for you and to measure them across apps. Tap Ask App Not to Track and the app asks AdMob for non-personalized ads instead — you still see ads, they are simply not chosen for you. You can change your answer at any time in the iOS Settings app, under Privacy & Security, then Tracking.
If you are in the EEA or UK, you will also see Google's consent choices before the first ad. Ads are only requested once you have made your choice, and your choice decides whether they may be personalized. You can reopen those choices at any time: in the app, under Settings, tap Ad privacy choices. That row appears only where Google's consent rules give you a choice to change, so if you do not see it, there is nothing there to change.
Ads are how the free version pays for itself. Rank 100 Premium removes them — see Purchases, next.
Purchases (version 1.0.2 and later)
Earlier versions of the app are free and sell nothing. From version 1.0.2 there are two optional things to buy: Rank 100 Premium, an auto-renewing subscription (monthly or annual) that removes the ads between rounds and unlocks every category pack, current and future; and individual category packs, bought once and kept. Everything else in the game stays free.
Apple takes the payment. Purchases go through the App Store, under your Apple Account, and we never see your card, your billing address, or your Apple ID. Refunds are handled by Apple, not by us.
RevenueCat records what you unlocked. RevenueCat is the service we use to check purchases with Apple and to tell our server what your anonymous ID has paid for. It receives your anonymous ID and the purchase record Apple issues for the transaction, and it sends our server the result: which packs your anonymous ID has unlocked, and the date your Premium subscription runs to. We store that with your gameplay data, because the game needs it to open the pack. If Apple refunds a purchase, the unlock is removed the same way.
Your purchases follow your Apple Account, not your anonymous ID. If you reinstall the app or get a new phone, you get a new anonymous ID; tap Restore purchases on the Premium screen and Apple's record moves what you bought onto the new one.
Notifications (version 1.0.7 and later)
Earlier versions only ever scheduled reminders on your own phone. Nothing left the device and no server could reach you. From version 1.0.7 we can send two kinds of notification from our own server, and only two: a Daily Challenge reminder you asked for, and a "the board is in" nudge for a Daily group you joined, once everyone in it has played that day. Neither is advertising, and neither carries an offer or a price.
You have to ask for them. The reminder is offered at the end of a puzzle you finished, never when you open the app. If you never tap it and never join a group, we never have anything to send to.
What we store to do it. When you turn reminders on, your phone asks Apple or Google for a push token — a random identifier for that one installation of this app, not for you and not for your phone across other apps — and we store it with your anonymous ID. We store it alongside your time zone: the offset from UTC and the zone's name, so a reminder arrives in your evening rather than in the middle of your night. We also store which app version asked, so we can tell whether a token that stopped working belongs to a version still in use.
What rides in a notification. The text is written by us, in advance, and your phone receives it already composed. The one thing you or another player can type that may appear is the name of a Daily group you are in — and only after it passes the same word filter as display names. If it does not pass, or if the group has been reported, the notification just says "your group" instead. Nothing else you type ever appears: not your display name, not your guesses, not your score, not a report, not feedback.
Turning them off. Switch them off in your phone's own Settings, or in the app's Settings, which also tells our server to stop sending to that installation. Turning them back on is the same switch. The rest of the game is identical either way — no streak is protected, no points are given, and nothing is unlocked for allowing them.
Who sends them. We hand the notification to Expo, whose push service passes it to Apple and Google for delivery. See the table below.
Photos (version 1.0.7 and later)
Only if you add one. A Daily group's owner can give the group a photo, and you can give yourself a profile photo in Settings. Nobody has to, and nothing in the game changes if you don't.
We see only the photo you pick. The app opens your phone's photo picker; it never reads your photo library and never uses the camera. The photo you pick is cropped to a square and shrunk to 512 by 512 pixels on your phone before it is sent.
Who sees it. A group's photo is seen by the people in that group. Your profile photo is seen by you and by people who share a Daily group with you — never on the Friends or Everyone boards, never on the website, and never on a card you share.
Every photo is checked before anyone sees it. When you upload a photo, our server sends it to Google Cloud Vision to check it for adult, violent or racy content, and refuses it if Google rates any of those likely. A photo that is refused is not stored. Google's terms for this service say the image is "processed in memory and not persisted to disk", that Google does "not use any of your content (such as images and labels) for any purpose except to provide you with the Vision API service", and that it does not use it to train its models. We keep a record that each photo was checked and what the check said — never the photo itself.
Hiding, reporting and removing. Anyone in a group can hide a photo on their own phone, or report it. A photo that two different people report is hidden from everyone automatically. A group's owner can remove the group's photo, you can remove your own, and we can remove any photo.
Facebook friends (version 1.0.7 and later)
Only if you tap Find Facebook friends. The button is on the Daily Challenge's Friends leaderboard, and nowhere else in the app. It is not a login: you keep the same anonymous account, nothing in the game needs Facebook, and connecting earns nothing.
Facebook asks first. Your phone opens Facebook's own screen, which asks whether Rank 100 may see your name and profile picture and your friends list. If you agree, Facebook gives your phone two things: a temporary access key, and a note signed by Facebook that says which Facebook account agreed. Your phone uses the access key to ask Facebook which of your friends also connected Rank 100. Facebook only ever answers with friends who did that themselves, never your whole friends list. The app does not ask for your total number of friends, and if Facebook includes it anyway the app ignores it: it is never sent to us and never kept. The access key stays on your phone. It is never sent to our server and never saved, and it is gone when the connect finishes.
What we store. Your phone sends our server the signed note and the list of those friends. We check Facebook's signature, and then we keep two things:
- your app-scoped Facebook ID — a number Facebook issues for you and Rank 100 only. It is not your Facebook profile ID and means nothing to any other app;
- the app-scoped IDs of your Facebook friends who also connected Rank 100.
That is all. The signed note also carries your Facebook name and a link to your profile picture, because Facebook puts them in every one. Our server throws them away as soon as the signature is checked. It never stores or logs them. We never store your Facebook name, photo or email address, or any Facebook access key. While Facebook's screen is open we also hold a one-time code tied to your anonymous ID, so the answer that comes back can only be attached to your account. It expires after ten minutes. Each time you connect, the friends list you send replaces the one we held before. It is never added to.
Who sees what. Your Facebook friends who have also connected see your Rank 100 display name and your Daily scores on their Friends leaderboard, and you see theirs. Nobody sees your Facebook name or photo. Nobody is added this way unless they tapped Find Facebook friends themselves. A friend who connects after you appears on your board without you doing anything.
We never post to Facebook. We do not ask for a permission that could. We do not read your posts, photos, messages or anything else on Facebook.
What PostHog, our analytics service, is told. That you tapped the button; whether the connect worked, was cancelled or failed, with a short code for why it failed; roughly how many friends it found (0, 1–2, 3–9 or 10 or more); and, when you disconnect, whether Facebook confirmed removing Rank 100's access. It is never told a Facebook ID, a friend's ID, or your exact number of friends.
Disconnecting. Disconnect Facebook is on the same leaderboard. Facebook asks you to confirm. Your phone then asks Facebook to remove Rank 100's access, and we delete your app-scoped Facebook ID and every friend record that names you: the ones you sent, and the ones your friends' phones sent about you. Your account, scores and streak are not touched. If Facebook does not confirm the removal, we still delete everything on our side, and the app tells you to remove Rank 100 in your Facebook settings too.
What we never do
- We do not track you across other apps or websites unless you allow it. The one ad network in the app, Google AdMob, may use your advertising identifier (IDFA) only after you tap Allow on the App Tracking Transparency prompt. Say no and you get non-personalized ads. There are no attribution SDKs.
- We do not sell your personal information. Personalized advertising can count as "sharing" under the California Consumer Privacy Act; the way to opt out is the same tracking switch, in the iOS Settings app under Privacy & Security, then Tracking.
- We do not see or store your payment details. Apple does, under Apple's own privacy policy.
- We do not ask for your phone's contacts, location, microphone, or camera, and we never read your photo library — from version 1.0.7 we receive only a photo you pick for a group or your profile (see Photos above). The one friends list the app ever reads is Facebook's, only if you tap Find Facebook friends, and only the friends who connected Rank 100 too (see Facebook friends above).
Who else sees it
| Who | What | Why |
|---|---|---|
| Other players in your game | Display name, score, and your guesses after the reveal | It is a multiplayer game |
| Supabase | Everything in this policy, including list suggestions and in-app feedback | Our database and authentication provider |
| PostHog (1.0.1 and later, and the website) | From the app: your anonymous ID, and named events with counts and timings. From the website: the page you are on and a few named events, with no cookie and nothing stored on your device | Product analytics, so we can see where the game loses people |
| Sentry (1.0.1 and later) | Crashes: device model, OS version, app version, stack trace | Crash reporting, so a bug that kills the app can be found |
| Google AdMob (1.0.2 and later, free version only) | Ad requests: IP address, device model and OS version, the advertising identifier only if you allowed tracking, and which ads were shown or tapped | Serving the ads between rounds |
| Apple (1.0.2 and later, only if you buy something) | The purchase itself, under your Apple Account | The App Store is the payment processor |
| RevenueCat (1.0.2 and later, only if you buy something) | Your anonymous ID and Apple's purchase record; it sends our server what that ID has unlocked | Checking purchases with Apple and recording what you own |
| People in your Daily groups (1.0.7 and later) | The group's photo, and your profile photo if you added one | So the people in a group can see who is in it |
| Your Facebook friends who also connected (1.0.7 and later, only if you connect Facebook) | Your display name and your Daily scores, on their Friends leaderboard. Never your Facebook name or photo | So friends can see each other's Daily scores |
| Meta (1.0.7 and later, only if you connect Facebook) | That you connected Rank 100 to your Facebook account, and your phone's requests for the friends who also connected. Meta sees these under its own privacy policy. We send Meta nothing about your games, your display name or anything you type | Facebook shows its consent screen and answers the friends request |
| Google Cloud Vision (1.0.7 and later, only if you add a photo) | The photo you picked, once, as it is uploaded | Checking every photo for adult, violent or racy content before anyone sees it |
| Expo (1.0.7 and later, only if you turn on notifications) | Your push token and the notification's text, which it passes to Apple or Google for delivery. Not your anonymous ID, not your score, and nothing you typed except a group name that passed our filter | Our push notification provider — it is how a reminder reaches your phone |
| Vercel | Website requests, including a list suggestion as it passes through | Our website host |
| Ahrefs Analytics | Aggregate, cookieless visit and click counts from the website — never an email | Website analytics |
That is the whole list. No data brokers and no attribution network. Google AdMob is the one ad network, and it is contacted only when an ad is about to be shown. Apple is the one payment processor, and RevenueCat is the one service that sees a purchase record, and both are involved only if you buy something.
If that ever changes, this table is where it will show up, and we will say so in the app before it does.
How long we keep it
- Anonymous accounts that have not been used for 30 days are deleted, along with the profile and game history attached to them. An account that holds a live Premium subscription or a purchased pack is not deleted for being idle.
- Finished games are kept while they are still useful to the people who played them, then removed with the accounts they belong to.
- Reports are kept longer than the accounts involved, deliberately: a report about someone who deletes their account should not disappear with it.
- Purchase records — which packs an anonymous ID unlocked and when Premium runs to — are kept as long as that anonymous account exists and are deleted with it. Apple keeps its own record of the purchase under your Apple Account, which is what Restore purchases uses.
- Push tokens (1.0.7 and later) are kept while that installation is still registered, and are deleted with the anonymous account they belong to — including by the 30-day idle deletion above, so a phone we stopped being allowed to know about stops being buzzed. A token that Apple or Google tells us is dead is marked as dead and kept as the record that this installation stopped answering; turning reminders off from the app stops sending to it immediately.
- Photos (1.0.7 and later) are kept while they are a group's photo or your profile photo. When a photo is replaced or removed, or the account or group it belongs to is deleted, the photo is deleted too — straight away where we can, and within a week at most — except that a photo someone reported may be kept for up to 30 days so we can act on the report. The record that a photo was checked (never the photo) is kept like a report.
- Facebook friends (1.0.7 and later): your app-scoped Facebook ID and your friends' IDs are kept until you disconnect, delete your account (the 30-day idle deletion above included), or remove Rank 100 in your Facebook settings. Facebook tells us about that last one, and we delete the same data as Disconnect does. If you ask Facebook to have us delete your data, Facebook gives you a confirmation code and a link to a page on our server showing when it was done. The record behind that page holds the code, the dates and how many records were removed. Nothing in it says whose they were. Disconnect before you delete your account. Disconnect also deletes the entries your friends' phones sent about you. Deleting the account does not delete them, because once the account is gone we can no longer tell which entries were yours. Those entries keep your app-scoped Facebook ID. They match nobody while you are not connected, but they can stay indefinitely. An entry goes when that friend connects again after Facebook has stopped listing you, for example because you removed Rank 100 in your Facebook settings. If the same Facebook account connects Rank 100 again later, the entries that remain come back into use.
- The launch list (the pre-release "tell me when it's out" form) was deleted in full on 2 September 2026, after the app was released; the form no longer exists.
- List suggestions are kept while we are still working through them. If you left an email with one, ask us and we will delete it from that suggestion — the suggestion itself is about a list, not about you.
- Feedback you send from the app (1.0.2 and later: Settings → Send feedback, or the one-time card after a game) is kept until we have acted on it. It records what you wrote, the app version, and — only if you typed one — an email so we can reply. It is not removed with your account: the message stays, unlinked from the account that sent it. Ask us at hello@rank100.app and we will delete a message, or just the email you left with it.
Your choices and rights
Because accounts are anonymous, we usually cannot tell which data is yours unless you tell us. If you write to hello@rank100.app we can help if you can identify the game — for example a join code and roughly when you played. The exception is the website's suggestion form, which is keyed to the email address you typed if you left one: write from that address and we can find and delete what it is attached to.
- Change your name: type a different one on the screen where you create or join a game. It is remembered on your device between games, and changing it there changes it everywhere afterwards. A name you have already joined a game with stays that name for the rest of that game.
- Delete your data: in the app, under Settings → Delete account. This is immediate and cannot be undone. You can also email us, or delete the app — an unused anonymous account is removed on our normal schedule. Deleting your account also removes its unlocks from our server; the purchase itself stays on your Apple Account, and Restore purchases brings it back on a new install. Deleting your account does not touch anything you sent from the website — for a list suggestion, email us.
- Manage or cancel a subscription: in the iOS Settings app, under your Apple Account, then Subscriptions. Deleting the app does not cancel a subscription.
- If you are in the EEA or UK (GDPR): you may request access, correction, erasure, or a copy of your data, and may complain to your local data protection authority. Our basis for processing is the legitimate interest of running a game you chose to play, the contract when you buy something, and for anything optional, your consent.
- Notifications (1.0.7 and later): the app's Settings screen has a Daily reminder switch, which also tells our server to stop sending to that installation. Your phone's own Settings can refuse them outright at any time, and refusing changes nothing else about the game. If you never turn them on we never hold a push token for you at all.
- Facebook friends (1.0.7 and later): Disconnect Facebook on the Daily Challenge's Friends leaderboard deletes what we hold and asks Facebook to remove Rank 100's access. Removing Rank 100 in your Facebook settings, under Apps and websites, deletes the same data from our side. Nothing else about the game changes either way.
- Ads and tracking: the iOS Settings app, under Privacy & Security, then Tracking, is where you allow or refuse tracking for Rank 100 at any time; refusing switches you to non-personalized ads. In the EEA or UK, the app's Settings screen has an Ad privacy choices row that reopens Google's consent options. Google's own controls for the ads it shows you are at adssettings.google.com.
- If you are in California (CCPA/CPRA): you may request to know, delete, or correct your personal information, and you will not be treated differently for asking. We do not sell it. To opt out of the "sharing" that personalized ads can amount to, refuse tracking as described above.
Children
This app is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided information to us, email hello@rank100.app and we will delete it. Ads are requested with Google's strictest content setting, and the app is not treated as child-directed.
Note that players type their own display names and guesses, which are shown to everyone else in the game.
Security
Data is stored with Supabase and protected by row-level security, so a player can only read the games they are actually in. Connections use HTTPS. No system is perfect and we will not pretend otherwise.
The website
Most of this policy is about the app, because that is where your data lives. The website (rank100.app) uses two analytics services to count visits and clicks in aggregate — which pages get read, which buttons get tapped: Ahrefs Analytics, and PostHog, the same service the app uses, so that a tap on "Get Rank 100" and a game played afterwards can be counted as one journey. PostHog receives the page you are on and a short list of named events — the App Store link was tapped, an invite was opened in the app, the support link was followed — and the invite code in an invite link's address is removed before the event is sent.
Neither one sets a cookie, and neither stores anything on your device, so there is nothing here to consent to and no banner to dismiss. Neither is given your name, your email, or anything you typed, and because nothing is stored, neither can recognise you when you come back. Like every request a browser makes, both arrive carrying your IP address, which they may use to estimate your general location; neither is told who you are. If your browser sends "Do Not Track", PostHog is not loaded at all.
Suggesting a list
The website has one voluntary form, at rank100.app/suggest, for telling us about a ranking you think would make a good round. It asks for the list you have in mind and a link to where its numbers are published. Both are about a list, not about you.
- The email field on that form is optional, and nothing depends on it. It exists only so we can ask you a follow-up question about your suggestion. It gets no other mail.
- It is stored with Supabase, alongside the game data, and is not linked to any game account or anonymous ID.
- Suggestions are never shown to other players.
- Sending the same suggestion twice does nothing: it is stored once.
Changes
If we change this policy we will update the date at the top. If a change is significant — for example turning on analytics — we will say so in the app.