Back to home

Privacy policy

This Privacy Policy explains how the Taboo application ("App", "we", "us") collects, uses, stores, and protects personal information about our users ("you"). By using the App, you agree to the practices described here.

1. Information We Collect

1.1. Automatically Collected Information

The App may automatically collect the following information needed to operate:

  • Technical data: device type, OS version, browser type and version
  • Usage data: game sessions, duration, statistics (scores, correct/forbidden-word counts)
  • IP address: stored in a hashed form for security and service delivery
  • Session data: session identifiers used to track game sessions securely

1.2. Information You Provide

You may provide the following while using the App:

  • Word suggestions: words and optional notes you submit
  • Word reports: reported words and reasons (optional)
  • Instagram username: optional, only when reporting a word
  • Game settings: preferences such as timer, pass rules, team names

2. How We Use Information

We use collected data to:

  • Run the App and improve quality
  • Personalise gameplay (saved settings)
  • Track and analyse game statistics
  • Review suggestions and reports
  • Maintain security and prevent abuse
  • Meet legal obligations

3. Storage and Security

3.1. Where Data Is Stored

Information may be stored as follows:

  • Local storage: game settings and preferences in browser cookies
  • Server: sessions, statistics, and suggestions on our servers
  • IP hashes: IP data is stored in a one-way hashed form where applicable

3.2. Security Measures

We apply measures including:

  • HTTPS encryption for transmission
  • Secure session handling
  • Hashing of IP addresses where used
  • Regular security updates
  • Access controls and authorisation

4. Children’s Privacy

Under-13 users: The App is not directed at children under 13. If children use it anyway:

  • We do not knowingly collect personal information from children
  • We do not sell or share children’s information with third parties for their marketing
  • Parents may request access or deletion of their child’s data
  • We take care to keep play safe and age-appropriate where possible

If you believe we have collected data from a child under 13, please contact us.

5. Third-Party Services

5.1. Google AdSense

We may use Google AdSense, which can use cookies to personalise ads. See Google’s policy: Google Privacy Policy

5.2. Google Analytics

We may use Google Analytics for usage statistics. See: Google Privacy Policy

6. Cookies

We use cookies for:

  • Essential cookies required for the App to work
  • Preference cookies to remember your settings
  • Analytics cookies for aggregated usage data
  • Advertising cookies where AdSense is enabled

You can control cookies in your browser; some features may not work if you disable them.

7. Your Rights

Depending on your region (including KVKK and GDPR), you may have rights to:

  • Information: know whether we process your personal data
  • Access: obtain a copy of your data
  • Rectification: correct inaccurate or incomplete data
  • Erasure: request deletion where applicable
  • Objection: object to certain processing
  • Portability: receive your data in a structured format where applicable

Contact us to exercise these rights.

8. Retention

We retain data roughly as follows:

  • Game sessions: active sessions for a limited period (e.g. 30 minutes), then removed
  • Statistics: may be kept in anonymised form
  • Suggestions: kept during review; may be removed after approval or rejection
  • Settings: for the lifetime of the relevant cookie (e.g. up to about one year by default)

9. Sharing

We do not sell your personal data. We may share information only when:

  • Required by law
  • Necessary to protect security or prevent abuse
  • With service providers (e.g. hosting, analytics) who need limited data to operate our service
  • With your clear consent

10. International Transfers

Data may be stored on servers in Türkiye. Services such as Google Analytics or AdSense may involve transfers (including to the United States). We aim to handle such transfers in line with applicable law, including GDPR and KVKK where relevant.

11. Changes

We may update this policy from time to time. For material changes we will provide notice in the App or on the website. Updates take effect from the date they are published.

12. Contact

For privacy questions or to exercise your rights, contact us:

13. Legal Bases

We rely on appropriate legal bases under applicable law, which may include:

  • Consent where required (including under KVKK)
  • Performance of our service to you
  • Compliance with legal obligations
  • Legitimate interests (security, service quality), balanced against your rights

This privacy policy has been prepared in line with the laws of the Republic of Türkiye and the EU General Data Protection Regulation (GDPR), where applicable.