Effective 4 August 2026 · Applies to the Headbands - Top Party Charades iOS app
Headbands is a party game you play with the people in the room. Almost everything it creates stays on your phone and is never sent to us: your custom categories, your recorded videos, your scores. This page explains the parts that do leave your device, and why.
The controller of any personal data described here is:
David KadlĨek, 07347103
Czech Republic
Email: da.developer605@gmail.com
Headbands is an independent app made by one person. Writing to that address reaches me directly, and I answer.
None of the following is sent to us, and none of it is visible to us in any form.
Your custom categories and the words you write into them are saved to your private iCloud, so they survive reinstalling the app and appear on your other devices signed in to the same Apple Account.
They go into your iCloud, not ours. We have no access to it and cannot read your categories. Apple's handling of it is covered by Apple's Privacy Policy.
Because that copy lives in iCloud, deleting the app does not delete it. To remove it, manage the app's iCloud data in the iOS Settings app under your Apple Account.
Sharing a category by QR code sends nothing to any server. It goes straight to the person who scans it. We never see it and could not retrieve it if asked.
Separately, if you have iCloud Backup switched on, your device's own backup may include the app's files, exactly as it does for every app you have installed. That backup belongs to you and is tied to your Apple Account. We have no access to it.
Deleting the app removes everything held on the phone. The iCloud copy of your custom categories is the one exception, as described above.
| What | Why | Legal basis | Who receives it | How long |
|---|---|---|---|---|
| Usage statistics: screens opened, buttons tapped, which built-in categories were played, app and device model, OS version, language, your IP address and the approximate location it points to, such as country or city, and a per-install identifier. Categories you created yourself are counted but never named | To understand which parts of the game are used and where people get stuck | Legitimate interest (Art. 6(1)(f) GDPR) | Google (Firebase Analytics) | Event data 2 months, user-level data 14 months. Aggregate reports are kept longer |
| Crash reports: the error, the state of the app at the time, device model, OS version, IP address | To find and fix crashes | Legitimate interest (Art. 6(1)(f) GDPR) | Google (Firebase Crashlytics) | 90 days |
| The topic you type into the AI category generator, plus your adult-content setting | To generate the list of words you asked for | Performance of a contract (Art. 6(1)(b) GDPR) | Google (Gemini via Firebase) | Not stored by us; see section 6 |
| Purchase and subscription events, and an anonymous customer identifier | To unlock what you bought and keep it working across reinstalls | Performance of a contract (Art. 6(1)(b) GDPR) | RevenueCat, Apple | While your purchase is active, plus statutory accounting periods |
| Subscription events: your anonymous customer identifier and any earlier identifiers for the same installation, what was bought, price, currency, country, store, and the purchase and expiry dates. This can also include the attributes RevenueCat holds for you, such as your push token | To see how the app is doing as a business: revenue, renewals and cancellations | Legitimate interest (Art. 6(1)(f) GDPR) | Our own reporting server, hosted at Railway in the United States | Kept for as long as the figures are useful for business reporting |
| Push notification token | To send the notifications you allowed | Consent (Art. 6(1)(a) GDPR) | Google (Firebase Cloud Messaging) and RevenueCat | Until you turn notifications off or delete the app |
| Your email address and message, if you contact us. The app opens your own Mail app with a message pre-addressed to us and pre-filled with your anonymous customer identifier, so we can match it to a purchase | To read and reply to what you wrote | Legitimate interest (Art. 6(1)(f) GDPR) | Sent by your mail app straight to us. No server of ours is involved | Until the matter is resolved, then a reasonable period |
| App Store install attribution token | To measure which of our App Store campaigns brought you to the app, and whether it led to a purchase | Legitimate interest (Art. 6(1)(f) GDPR) | Apple and RevenueCat | Held against your anonymous customer record for as long as that record exists |
| Consumption information, if you request a refund | To help Apple decide the refund fairly | Consent (Art. 6(1)(a) GDPR) | Apple | Sent once per request; see section 9 |
The app uses Google Analytics for Firebase. It is worth being exact about what that does and does not mean, because "analytics" is a word that covers very different practices.
What it does not do:
We see the results only as charts and totals.
The analytics identifier is shared with RevenueCat and stored alongside your purchase record and your push token, so those sit together under one anonymous customer identifier.
We want to be straightforward about this rather than hide behind the word "anonymous". The per-install identifier listed in section 4 is a pseudonymous identifier, and under EU law it counts as personal data even though it does not tell us who you are. We rely on legitimate interest to collect it, and you have an unconditional right to object, as set out in section 13. Write to da.developer605@gmail.com and we will stop processing your data.
Headbands can generate a category of words from a topic you type, suggest categories you might like, and top up words during a long game. These features send text to Google's Gemini model.
What goes to Google: the topic you type and your adult-content setting. Google returns the words and applies its own safety filtering. We do not store your prompts, and we do not use them to train anything. The names of your own categories, and the words inside them, are never sent.
The app asks you to agree before it first sends anything you have typed to Google. Topping up words during play can be turned off in Settings.
Please do not type personal information, real names or anything confidential into the generator.
Google's handling of this data is governed by the Firebase privacy documentation and the Google Privacy Policy.
The app asks for four permissions. Each is optional, the game is fully playable without any of them, and each is used only for the purpose below.
Used to record video of your game and to build highlight reels. The recording is written to your device and stays there. It is never uploaded to us or to anyone else. If you delete the app or the video, it is gone.
Two separate uses: saving a video you chose to keep, and reading a QR code from a picture you select. We only ever receive the specific image you pick, and only for long enough to read the code out of it. The app does not browse, index or upload your library.
If you play with voice control, the app listens for words like "correct" and "pass" so you do not have to touch the phone. This uses Apple's speech recognition, and depending on your device and language, the audio may be sent to Apple's servers to be transcribed. That processing is governed by Apple's Privacy Policy. We do not receive or store the audio or the transcript.
You can withdraw any of these permissions at any time in the iOS Settings app.
If you allow notifications, iOS issues a push token for your installation. We share it with Google and RevenueCat so the messages you allowed can reach you. Those messages include our own marketing, such as an offer on a subscription, and which offer you are sent depends on what you have already bought.
Reminders about the game itself are scheduled by your phone, on your phone. Nothing leaves the device for those.
The token is tied to a random identifier, not to your name or email. Turning notifications off in iOS Settings, or deleting the app, ends it.
All payments run through Apple. We never see your card number, billing address or Apple ID. We are told only that a purchase happened, what was bought, and whether it is still active.
We use RevenueCat to keep track of subscription status so your purchases keep working when you reinstall or switch devices. RevenueCat identifies you by a random identifier it generates, not by anything personal.
We also keep a record of subscription events on our own reporting server, hosted at Railway in the United States, so we can see how the app is doing as a business. It holds no name, no email and no payment details.
By using the app and making in-app purchases, you consent to us sharing data about your usage and consumption of purchased content with Apple, as part of resolving refund requests. This information may include details about how you have accessed and interacted with the purchased content. The purpose of sharing this data is to help Apple make an informed decision regarding a refund request. We ensure that such data sharing is done in compliance with Apple's policies and only as necessary to process your request.
In practice this is only sent when a refund request is actually made, and it goes to Apple alone.
These are the only third parties that receive any of your data, whether from the app itself or passed on by one of the others. Each has its own privacy policy:
Every third party listed here is required, under its data processing agreement with us, to provide the same or equal protection of your data as set out in this policy, and to use it only to provide the service we engaged them for. We do not sell your data, and we do not share it with anyone outside this list.
If you play over SharePlay, game state travels through Apple's FaceTime session between the players' devices. It does not pass through us.
Headbands is rated 13+ and is not directed at children under 13. We do not knowingly collect personal data from children under 13. Some categories contain adult humour. These can be hidden with the "Hide Adult Content" setting, which is offered when the app is first set up and can be changed at any time in Settings.
In some EU countries the age of consent for online services is higher than 13, in some cases 16. Where that applies, a parent or guardian should agree to this policy on the child's behalf.
If you believe a child has provided personal data to us, write to da.developer605@gmail.com and it will be deleted.
Our service providers, Google, Apple and RevenueCat, are based in the United States and may process data there or in other countries. Our own reporting server is hosted at Railway, also in the United States. These transfers are covered by the European Commission's EU-US Data Privacy Framework where the provider is certified under it, and otherwise by Standard Contractual Clauses.
If you are in the EU or the UK, the GDPR gives you the right to:
To exercise any of these, email da.developer605@gmail.com. We will respond within one month.
One honest limitation. Because the app has no accounts, we usually have no way to link a request to a specific record. There is no name or email in our data to search for. In most cases that means there is nothing to hand over or delete beyond what deleting the app already removes. If you have written to us before, or if you tell us the identifier shown in the app, we can act on the specific records that exist.
Where we rely on your consent, you can take it back at any time in the iOS Settings app, without asking us. Turn off notifications to stop the push token being used. Withdraw the camera, microphone, photo library or speech recognition permissions the same way, and the features that use them simply stop. To withdraw consent for anything else, or to ask us to delete what we hold, email the address above.
We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the past twelve months. You have the right to know what we collect, to request deletion, and not to be discriminated against for asking. The same email address applies.
Retention is listed per item in the table in section 4. As a rule: data that lives on your phone lasts until you delete it or the app; data held by our providers follows the periods stated there; and anything you email us is kept only as long as it takes to deal with your message.
Everything the app sends leaves your device over an encrypted connection. Data stored on your device is protected by iOS itself, and your subscription state is kept in the iOS Keychain.
Our reporting server holds subscription figures only, and contains no name, no email, no password and no payment details.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. What we can say is that the categories of data we hold are deliberately small: no accounts, no passwords, no payment details, no content you created.
If this policy changes, the new version will be posted on this page with a new effective date. Material changes will also be announced in the app. Continuing to use Headbands after a change means you accept the updated policy.
Questions, requests or complaints about this policy, or about anything in it you think is wrong, go to da.developer605@gmail.com.