Privacy policy
Last updated: 01.09.2026
This is a translation. The German version is the authoritative one; in case of discrepancy, it prevails.
In short
Typical is a game in which people write sentences about other people. That is the appeal of the game — and the reason this policy is longer than it would be for an app that only counts scores.
- The sentences about you stay hidden from you during the game. That is a game rule, not a promise of confidentiality: if you ask us, you get them. Why that is so and what it costs you is set out below under "The game rule".
- No tracking, no profiles. Advertising in this app is contextual only — no advertising identifier, no profile, no evaluation of your behaviour. Personalised advertising is ruled out.
- We measure no usage behaviour, report no crashes to third parties and embed no analytics tool.
- Everything stored sits on servers in Frankfurt am Main, Germany.
- You can delete your account in the app at any time. That is not a request to us; it is a button that acts.
- What you play by yourself never leaves your device.
Who is responsible
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Schwartz & Zuhmann GbR
Represented by the partners Gabriel Schwartz and Marcel Daniel Zuhmann
Badener Str. 122/1, 74074 Heilbronn, Germany
Email: support@typical.cloud
We have not appointed a data protection officer. The conditions of Art. 37 GDPR are not met: we are not a public authority, our core activity is not large-scale regular monitoring, and we do not process special categories of data on a large scale. Questions about data protection are answered at the address above.
What data we process, why, and on what legal basis
The legal basis throughout is Art. 6(1)(b) GDPR — processing is necessary for the performance of the user agreement. Where a different basis applies, it is stated explicitly.
Providing this data is neither a statutory nor a contractual requirement. It is, however, necessary in order to use the service: without it the game cannot take place. Anything voluntary is marked as such below.
- Account identifier — a random string created on first launch. No name, no email address. Purpose: to recognise you across devices and rounds. Stored for as long as the account exists.
- Display name, symbol and colour — whatever you enter in the app. Whether that is your legal name, a nickname or a word is your decision. Purpose: to make you recognisable to your fellow players. Stored for as long as the round exists.
- Profile picture — voluntary, see the separate section below.
- The round — its name, the players, the teams, the agreed prize, which square was reported as fulfilled, when and by whom, and who contested it. Purpose: to run the game and hold everyone at the same state.
- Prediction texts together with author and target — the core of the game, see the separate section below.
- Join codes — a six-digit code points at a round for a short time. Purpose: joining without searching for an account. Expires after two hours at the latest and is deleted when the round starts.
- Device token for notifications — voluntary, only if you allow notifications. See the separate section below.
- Access data — technical server logs which include IP addresses. Purpose: operation, fault finding and the prevention of abuse. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a functioning and secure service. They are kept only briefly by our service provider.
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place. The app does not evaluate your behaviour, builds no profiles and makes no decisions about you.
Predictions: data about other people
This is the most unusual part of this app, and we therefore state it openly.
A prediction is a sentence you write about another person — "sleeps through breakfast", "tells the same story twice". In legal terms this is personal data about a third party, not obtained from that person. We store this sentence together with who wrote it and whom it is about.
What this means for you as the writer. You decide what it says. Write only what you would say to that person's face. And write nothing that reveals specially protected data: health, sex life or sexual orientation, religion or belief, political opinion, trade union membership, ethnic origin or biometric data. There is no legal basis for such information in this game, and it does not belong here. The app warns you about coarse words, but it cannot understand a sentence — responsibility for what you write remains with you.
What this means for you as the person described. Sentences about you arise in a round you joined, and they are shown only to the players of that round. You may at any time ask to learn what is stored about you and request erasure — including where somebody else wrote the sentence. How to do this is set out under "Your rights".
What this means for us. We do not read these sentences and do not evaluate them. The server stores the game state as a whole and does not interpret it. Only when somebody reports content to us do we look at it — see the Terms of use.
The game rule "nobody sees what is written about them" — and your right of access
The core of the game is that the sentences about you stay hidden from you until they come true. That is a game rule, not a promise of confidentiality, and we must be clear at this point:
Your right of access under Art. 15 GDPR takes precedence over the game rule. If you ask us what is stored about you, you will receive it — including the still-hidden sentences and who wrote them. We may not refuse you this, and we will not try.
Expect the answer to spoil the game for you. This paragraph is here and not in the small print for that reason: you should know about this route before you take it by accident.
Profile picture
Instead of a symbol you may set a photo. It is reduced to around 4 kilobytes on your device and then travels as part of the game state to all players in your rounds and onto our server. There it sits in such a way that we could technically read it — as we could any other part of the game state.
A photo of you is personal data, and it is voluntary. The symbol is the normal case and does the job just as well. If you set a photo showing someone else, you need their agreement.
If you delete your account, the player card loses its name and its picture.
Signing in with Apple or Google
Everything works without signing in — only your rounds stay tied to that one device. Anyone who wants to use them on a second device signs in.
With "Sign in with Apple" we deliberately request only the name, not the email address. Our server is configured to accept accounts without an email address. We enter your name as your display name the first time; you can change it afterwards.
With "Sign in with Google", Google transmits your email address and name to our sign-in service as part of the procedure. The email address serves solely to recognise your account. We send no messages to it.
In both cases Apple or Google learns that you have signed in to Typical. We have no influence on their own processing; their privacy notices apply.
Notifications on your device
If you allow notifications, the app registers a device token with our server — an identifier issued by Apple or Google to which a notification can be delivered. It sits in a table that cannot be read or written from outside.
The path of the notification necessarily runs via Apple (APNs) or Google (Firebase Cloud Messaging). These services see the content of the notification.
The notification contains the name of the round and the fulfilled sentence in plain text — for example "Kim – sleeps through breakfast". That therefore appears on your lock screen and is readable by anyone standing next to you. Only what has already come true and is visible to everyone is sent; even so, you can set your device to show previews only after unlocking.
If you do not allow notifications, no device token is transmitted either. You can withdraw this at any time in your system settings.
Advertising
Advertising in this app is contextual only. This section applies wherever an advertisement is displayed.
Contextual only. We build no user profile, do not read your device's advertising identifier, do not recognise you across apps or services and do not evaluate your behaviour. Which advertisement appears depends at most on where in the app it sits.
Who delivers the advertisements: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, through its AdMob service. When an advertisement is requested, Google learns your IP address and rough technical details of your device; that arises with every request over the network. In addition, the advertising component stores information on your device — among other things to limit how often the same advertisement appears and to detect abuse.
What Google never learns: predictions, player names, round names, profile pictures and your account identifier. This data does not leave the game, and that is at the same time part of our contract with the advertising partner.
That is why we ask you beforehand. Because information is stored on and read from your device, § 25(1) TDDDG applies: before the first advertisement is loaded, a consent screen appears. If you do not give consent, no advertisement is loaded. The legal basis for the processing is then your consent under Art. 6(1)(a) GDPR.
You can withdraw at any time — in the settings under "Legal", at "Advertising consent". The withdrawal takes effect immediately; the lawfulness of processing up to that point remains unaffected.
Purchases in the app
If you buy a paid extra, the purchase runs through the App Store or Google Play, and the contracting party is the respective store operator. Payment data arises there, and their privacy notices apply.
All we learn of it is that a purchase applies to your account — a confirmation from the store with a transaction identifier. No card number, no billing address, no name.
Who else gets to see the data
We sell no data and pass none on for advertising purposes. Only those service providers are involved without whom operation would not be possible:
Supabase operates the database and the sign-in service. The data sits in Frankfurt am Main, Germany. Supabase is our processor under Art. 28 GDPR. The company is domiciled in the United States; access from a third country in the course of maintenance and fault clearance can therefore not be ruled out. For that case the European Commission's Standard Contractual Clauses are agreed (Art. 46(2)(c) GDPR).
Apple and Google deliver the notifications, see above, and handle sign-in where you use it.
Apple and Google also distribute the app. What arises in their stores through a purchase or an installation they process on their own responsibility; we receive only aggregated figures without any personal reference.
An advertising partner, wherever an advertisement is displayed — see the separate section above. It receives no game content.
Beyond this we pass on data only where we are legally obliged to.
What never leaves your device
Some things stay local deliberately and are never transmitted:
- Cards you create just for yourself ("Just for me"). They sit in their own file on the device and know no server.
- Your language choice and the settings for appearance, background and motion.
- The marks recording when you last looked at a round — all that arises from them is the small number on the round's row.
The web version in the browser
Anyone playing without the app uses the web version. There the following applies in addition:
In your browser's local storage (`localStorage`) we place what operation strictly requires: the identifier of your sign-in session and your language choice. Under § 25(2) no. 2 TDDDG this is strictly necessary for the service you have expressly requested to function — we therefore do not ask your permission and do not put a banner in front of you. We set no advertising or analytics storage.
A browser loses its sign-in as soon as site data is cleared. So that you can get back into your round afterwards, we store the hash of a secret on our server which is contained in your personal return link. The secret cannot be computed back from the hash. Whoever holds the link steps into your role — treat it like a password.
How long we store
The retention period for each item is given above. For the round itself there is no fixed period: it stays stored for as long as it sits in the app of at least one player. The reason lies in the purpose — a shared look back at a week's holiday still makes sense years later, and an expiry date would take it from everyone involved at once.
It is deleted when the last player with an account deletes their account. You can delete finished rounds yourself at any time.
If you delete your account
In the settings under "Delete account". This runs immediately and without any enquiry to us. The following happens, in this order:
- If you are host of a round, the office passes to another player. Otherwise the whole group would lose its round because one person leaves.
- If nobody else in the round has an account, the round is deleted.
- In every round in which you appear as a player, name, symbol and picture lose their content and the link to your account falls away. The player card is then called "—".
- Your memberships and your account are deleted.
What remains are the prediction texts. They belong to the round, not to your person: a sentence you wrote about somebody is part of the others' shared game state. After deletion its authorship points at a nameless card. If you want the texts deleted as well, contact the address above — we will then weigh that in the individual case against the interests of the remaining players.
Your rights
You are entitled to:
- Access (Art. 15 GDPR) — see the separate section above; it applies to the hidden sentences too.
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR) to processing based on a legitimate interest
Contact support@typical.cloud for this. We answer within one month.
How we make sure it is you. We must not hand your data to somebody passing themselves off as you. We therefore need something to go on – and the app brings it along by itself: write to us from Settings → Support & feedback. The email that opens already carries your account ID in its text. We need nothing more.
If that is not possible – because you no longer have the app, or you prefer another route – it depends on how you play:
- Signed in with Google: write to us from the email address you are signed in with. That is sufficient.
- Signed in with Apple, or not signed in at all: we then have no email address for you. Your account ID is in the app under More, at the bottom of your account area; tapping shows it in full and copies it if you want. Without it, only the name of a round and your display name in it remain – we check what matches and ask if in doubt.
Where we cannot identify you. For rounds played entirely without an account, the player card is linked to no person — we then do not know who is behind it and cannot find out. In such cases Art. 11 GDPR means we are not obliged to obtain additional data solely in order to identify you, and the rights under Arts. 15 to 20 have nothing to attach to. You may however send us additional details at any time that make attribution possible; we will then deal with your request.
You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the country of your habitual residence or at the controller's seat. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI Baden-Württemberg).
Children and young people
Typical is intended for people aged 13 and over. We do not process data on the basis of consent but for the performance of the user agreement; the age threshold of Art. 8 GDPR therefore does not apply directly here. For minors, however, their parents or guardians must agree to the user agreement.
To parents and guardians: the game consists of children writing sentences about other children which those children do not get to see. Look at the app before you agree.
Security
All connections are encrypted (TLS). On the server, row-level access rules ensure that an account can see only the rounds in which it is a player — the rule "nobody sees what is written about them" is built not only into the app but enforced on the server. Device tokens and return-link hashes can neither be read nor written from outside. These rules are automatically tested against attempts to break them on every change.
Nobody can promise absolute protection. If a personal data breach becomes known to us, we report it to the supervisory authority within 72 hours under Art. 33 GDPR and, where the risk is high, notify you as well.
Changes to this policy
If what the app does changes, this policy changes with it. The version in force is in the app under Settings and online at the address given above. The date at the top tells you which version you are reading.