Legal
Privacy Policy
Full transparency on every byte. Thinko is built with privacy-first architecture — here's exactly what we collect, why, and your complete rights under global law.
01
Who we are
Thinko is made by AroraLabs, based in Australia. We are the data controller for the information described here, and this policy covers the Thinko app and thinko.aroralabs.org.
Contact us any time at contact@aroralabs.org.
02
What we collect, and why
You can play as a guest. Guests get an anonymous identifier so scores and progress work; no name or email is involved.
If you create an account we collect:
- Your email address, name and chosen public username — to create the account and let you sign back in. Your username is visible to other players.
- A profile photo, if you use email sign-in — derived from a one-way hash of your email address by an avatar service. We never send them your address itself.
- Your scores, progress and game history — so they follow you between devices.
- Your password is never visible to us. Sign-in is handled by our authentication provider, which stores only a secure hash. We cannot see or recover it.
Whether or not you have an account, we also collect:
- Anonymous usage data — which screens and features get used, and how long sessions last. Used to work out which parts of the app are worth keeping.
- Crash reports — device model, operating system and the technical trace of the failure.
- Purchase records, if you subscribe — which plan and until when.
- Your country — taken from your device settings, and also looked up from your IP address by an outside geolocation service. Your IP goes to that service, which returns a country; we store only the country, not the IP. Used to show the right content and prices.
- A device identifier — used to keep your account secure and to spot abuse.
Legal bases (UK/EU): your account and gameplay data are processed to perform our contract with you; analytics, crash reporting and security are our legitimate interests; advertising identifiers rely on your consent where it is required.
We do not sell your data, and we do not make automated decisions that have a legal effect on you.
03
Advertising
The free version shows adverts supplied by Google AdMob. To serve them, Google may use your device's advertising identifier.
On iOS you are asked through Apple's App Tracking Transparency prompt first, and on Android you can reset or limit the identifier in your device settings. Declining does not stop you using Thinko — you simply see less relevant adverts.
A paid subscription removes advertising entirely.
04
How quiz questions are made
Quiz questions are generated by an AI provider, reached through our own server rather than from your device. Only the topic, language and difficulty are sent.
Where AI generation is unavailable we fall back to a public trivia database and to Wikipedia, using anonymous requests that contain only a topic and difficulty.
05
Who we share it with
We never sell your data. We use a small number of providers who process it only on our instructions:
- Google — our database, sign-in, notifications, anonymous analytics and crash reporting, and the AdMob adverts on the free tier.
- Apple and Google Play — the stores. They take every payment; we never see your card details.
- An AI provider — quiz questions only, with no personal data, as described above.
- An avatar service — receives only a one-way hash of your email, never the address.
- A website host and content-delivery network — to serve this site.
We may also disclose data where the law requires it, or to protect our rights or someone's safety.
06
Where it is stored
We are in Australia and our providers are largely in the United States and the European Union, so data may be transferred outside your own country. Where it leaves the UK or the EEA we rely on the UK and EU Standard Contractual Clauses, or on an adequacy decision where one applies.
07
How long we keep it
- Your account and gameplay data — for as long as the account is active.
- After you delete your account — removed within 30 days, with a recoverable copy held for up to 90 days in case you change your mind, then erased.
- Anonymous analytics — up to 26 months.
- Crash reports — a short rolling window set by our provider.
- Purchase records — up to 7 years, as Australian tax law requires.
- Support emails — up to 3 years after the matter is closed.
After your account is deleted we may still keep a limited amount of information for a while — the records above that we are required to hold, and anything we genuinely need to deal with a dispute, a chargeback, a suspected fraud or abuse, or a legal claim. Copies also persist in routine backups and server logs for a short period before they cycle out. We keep no more than we need, and none of it is used to market to you.
You can delete your account from inside the app, or at our delete account page.
08
Your rights
Wherever you live, you can ask us for a copy of your data, ask us to correct or delete it, or ask us to stop using it. Email contact@aroralabs.org and we will respond within 30 days. We will never treat you worse for asking.
UK and EEA. You also have the right to restrict or object to processing, the right to data portability, the right to withdraw consent at any time, and the right to complain to your data-protection authority — the Information Commissioner's Office in the UK, or your national authority in the EEA.
California. You may request the categories and specific pieces of personal information we hold and ask us to delete them. We do not sell or share personal information as the CCPA defines those terms.
Australia. You may access and correct your personal information, and complain to the Office of the Australian Information Commissioner if you are not satisfied with how we handled it.
09
Security
Everything travels over HTTPS. Your data is protected by server-side rules that only ever let your own account read or write it, and access to our systems is limited and protected by multi-factor authentication. We also check that requests come from a genuine, unmodified installation of the app.
No system is perfectly secure, but if a breach affects you we will tell you and the relevant regulator as the law requires.
10
Children
Thinko is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has given us any, email us and we will delete it. Where a child under 13 has used the app, a parent or guardian may contact us to review or delete that information.
11
Changes & contact
If we change this policy we will update the date at the top of this page, and tell you in the app before any change that materially reduces your privacy takes effect.
Questions, requests or complaints: contact@aroralabs.org.