Privacy policy

Last updated: 01.09.2026

This is a translation. The German version is the authoritative one; in case of discrepancy, it prevails.

In short

Typical is a game in which people write sentences about other people. That is the appeal of the game — and the reason this policy is longer than it would be for an app that only counts scores.

Who is responsible

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Schwartz & Zuhmann GbR
Represented by the partners Gabriel Schwartz and Marcel Daniel Zuhmann
Badener Str. 122/1, 74074 Heilbronn, Germany
Email: support@typical.cloud

We have not appointed a data protection officer. The conditions of Art. 37 GDPR are not met: we are not a public authority, our core activity is not large-scale regular monitoring, and we do not process special categories of data on a large scale. Questions about data protection are answered at the address above.

What data we process, why, and on what legal basis

The legal basis throughout is Art. 6(1)(b) GDPR — processing is necessary for the performance of the user agreement. Where a different basis applies, it is stated explicitly.

Providing this data is neither a statutory nor a contractual requirement. It is, however, necessary in order to use the service: without it the game cannot take place. Anything voluntary is marked as such below.

No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place. The app does not evaluate your behaviour, builds no profiles and makes no decisions about you.

Predictions: data about other people

This is the most unusual part of this app, and we therefore state it openly.

A prediction is a sentence you write about another person — "sleeps through breakfast", "tells the same story twice". In legal terms this is personal data about a third party, not obtained from that person. We store this sentence together with who wrote it and whom it is about.

What this means for you as the writer. You decide what it says. Write only what you would say to that person's face. And write nothing that reveals specially protected data: health, sex life or sexual orientation, religion or belief, political opinion, trade union membership, ethnic origin or biometric data. There is no legal basis for such information in this game, and it does not belong here. The app warns you about coarse words, but it cannot understand a sentence — responsibility for what you write remains with you.

What this means for you as the person described. Sentences about you arise in a round you joined, and they are shown only to the players of that round. You may at any time ask to learn what is stored about you and request erasure — including where somebody else wrote the sentence. How to do this is set out under "Your rights".

What this means for us. We do not read these sentences and do not evaluate them. The server stores the game state as a whole and does not interpret it. Only when somebody reports content to us do we look at it — see the Terms of use.

The game rule "nobody sees what is written about them" — and your right of access

The core of the game is that the sentences about you stay hidden from you until they come true. That is a game rule, not a promise of confidentiality, and we must be clear at this point:

Your right of access under Art. 15 GDPR takes precedence over the game rule. If you ask us what is stored about you, you will receive it — including the still-hidden sentences and who wrote them. We may not refuse you this, and we will not try.

Expect the answer to spoil the game for you. This paragraph is here and not in the small print for that reason: you should know about this route before you take it by accident.

Profile picture

Instead of a symbol you may set a photo. It is reduced to around 4 kilobytes on your device and then travels as part of the game state to all players in your rounds and onto our server. There it sits in such a way that we could technically read it — as we could any other part of the game state.

A photo of you is personal data, and it is voluntary. The symbol is the normal case and does the job just as well. If you set a photo showing someone else, you need their agreement.

If you delete your account, the player card loses its name and its picture.

Signing in with Apple or Google

Everything works without signing in — only your rounds stay tied to that one device. Anyone who wants to use them on a second device signs in.

With "Sign in with Apple" we deliberately request only the name, not the email address. Our server is configured to accept accounts without an email address. We enter your name as your display name the first time; you can change it afterwards.

With "Sign in with Google", Google transmits your email address and name to our sign-in service as part of the procedure. The email address serves solely to recognise your account. We send no messages to it.

In both cases Apple or Google learns that you have signed in to Typical. We have no influence on their own processing; their privacy notices apply.

Notifications on your device

If you allow notifications, the app registers a device token with our server — an identifier issued by Apple or Google to which a notification can be delivered. It sits in a table that cannot be read or written from outside.

The path of the notification necessarily runs via Apple (APNs) or Google (Firebase Cloud Messaging). These services see the content of the notification.

The notification contains the name of the round and the fulfilled sentence in plain text — for example "Kim – sleeps through breakfast". That therefore appears on your lock screen and is readable by anyone standing next to you. Only what has already come true and is visible to everyone is sent; even so, you can set your device to show previews only after unlocking.

If you do not allow notifications, no device token is transmitted either. You can withdraw this at any time in your system settings.

Advertising

Advertising in this app is contextual only. This section applies wherever an advertisement is displayed.

Contextual only. We build no user profile, do not read your device's advertising identifier, do not recognise you across apps or services and do not evaluate your behaviour. Which advertisement appears depends at most on where in the app it sits.

Who delivers the advertisements: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, through its AdMob service. When an advertisement is requested, Google learns your IP address and rough technical details of your device; that arises with every request over the network. In addition, the advertising component stores information on your device — among other things to limit how often the same advertisement appears and to detect abuse.

What Google never learns: predictions, player names, round names, profile pictures and your account identifier. This data does not leave the game, and that is at the same time part of our contract with the advertising partner.

That is why we ask you beforehand. Because information is stored on and read from your device, § 25(1) TDDDG applies: before the first advertisement is loaded, a consent screen appears. If you do not give consent, no advertisement is loaded. The legal basis for the processing is then your consent under Art. 6(1)(a) GDPR.

You can withdraw at any time — in the settings under "Legal", at "Advertising consent". The withdrawal takes effect immediately; the lawfulness of processing up to that point remains unaffected.

Purchases in the app

If you buy a paid extra, the purchase runs through the App Store or Google Play, and the contracting party is the respective store operator. Payment data arises there, and their privacy notices apply.

All we learn of it is that a purchase applies to your account — a confirmation from the store with a transaction identifier. No card number, no billing address, no name.

Who else gets to see the data

We sell no data and pass none on for advertising purposes. Only those service providers are involved without whom operation would not be possible:

Supabase operates the database and the sign-in service. The data sits in Frankfurt am Main, Germany. Supabase is our processor under Art. 28 GDPR. The company is domiciled in the United States; access from a third country in the course of maintenance and fault clearance can therefore not be ruled out. For that case the European Commission's Standard Contractual Clauses are agreed (Art. 46(2)(c) GDPR).

Apple and Google deliver the notifications, see above, and handle sign-in where you use it.

Apple and Google also distribute the app. What arises in their stores through a purchase or an installation they process on their own responsibility; we receive only aggregated figures without any personal reference.

An advertising partner, wherever an advertisement is displayed — see the separate section above. It receives no game content.

Beyond this we pass on data only where we are legally obliged to.

What never leaves your device

Some things stay local deliberately and are never transmitted:

The web version in the browser

Anyone playing without the app uses the web version. There the following applies in addition:

In your browser's local storage (`localStorage`) we place what operation strictly requires: the identifier of your sign-in session and your language choice. Under § 25(2) no. 2 TDDDG this is strictly necessary for the service you have expressly requested to function — we therefore do not ask your permission and do not put a banner in front of you. We set no advertising or analytics storage.

A browser loses its sign-in as soon as site data is cleared. So that you can get back into your round afterwards, we store the hash of a secret on our server which is contained in your personal return link. The secret cannot be computed back from the hash. Whoever holds the link steps into your role — treat it like a password.

How long we store

The retention period for each item is given above. For the round itself there is no fixed period: it stays stored for as long as it sits in the app of at least one player. The reason lies in the purpose — a shared look back at a week's holiday still makes sense years later, and an expiry date would take it from everyone involved at once.

It is deleted when the last player with an account deletes their account. You can delete finished rounds yourself at any time.

If you delete your account

In the settings under "Delete account". This runs immediately and without any enquiry to us. The following happens, in this order:

  1. If you are host of a round, the office passes to another player. Otherwise the whole group would lose its round because one person leaves.
  2. If nobody else in the round has an account, the round is deleted.
  3. In every round in which you appear as a player, name, symbol and picture lose their content and the link to your account falls away. The player card is then called "—".
  4. Your memberships and your account are deleted.

What remains are the prediction texts. They belong to the round, not to your person: a sentence you wrote about somebody is part of the others' shared game state. After deletion its authorship points at a nameless card. If you want the texts deleted as well, contact the address above — we will then weigh that in the individual case against the interests of the remaining players.

Your rights

You are entitled to:

Contact support@typical.cloud for this. We answer within one month.

How we make sure it is you. We must not hand your data to somebody passing themselves off as you. We therefore need something to go on – and the app brings it along by itself: write to us from Settings → Support & feedback. The email that opens already carries your account ID in its text. We need nothing more.

If that is not possible – because you no longer have the app, or you prefer another route – it depends on how you play:

Where we cannot identify you. For rounds played entirely without an account, the player card is linked to no person — we then do not know who is behind it and cannot find out. In such cases Art. 11 GDPR means we are not obliged to obtain additional data solely in order to identify you, and the rights under Arts. 15 to 20 have nothing to attach to. You may however send us additional details at any time that make attribution possible; we will then deal with your request.

You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the country of your habitual residence or at the controller's seat. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI Baden-Württemberg).

Children and young people

Typical is intended for people aged 13 and over. We do not process data on the basis of consent but for the performance of the user agreement; the age threshold of Art. 8 GDPR therefore does not apply directly here. For minors, however, their parents or guardians must agree to the user agreement.

To parents and guardians: the game consists of children writing sentences about other children which those children do not get to see. Look at the app before you agree.

Security

All connections are encrypted (TLS). On the server, row-level access rules ensure that an account can see only the rounds in which it is a player — the rule "nobody sees what is written about them" is built not only into the app but enforced on the server. Device tokens and return-link hashes can neither be read nor written from outside. These rules are automatically tested against attempts to break them on every change.

Nobody can promise absolute protection. If a personal data breach becomes known to us, we report it to the supervisory authority within 72 hours under Art. 33 GDPR and, where the risk is high, notify you as well.

Changes to this policy

If what the app does changes, this policy changes with it. The version in force is in the app under Settings and online at the address given above. The date at the top tells you which version you are reading.