Privacy Policy
Last updated: 21 September 2026
1. Who is responsible
Hallingcast AS, Torpomoen 27, 3579 Torpo, Norway, is the data controller for personal data processed in the CelebClash app and on celebclash.com. Contact: support@celebclash.com.
2. What we collect
- Account data. A randomly generated account ID, your display name, avatar, and language. Guest accounts require nothing else. If you register an account we also store your email address and, where you sign in with Apple or Google, the identifier that provider returns to us. We never receive your password from those providers.
- Gameplay data. Matches, questions, answers, guesses, hints, coin balance and transactions, and invite links you create, so the game can work between you and your rivals.
- Push tokens. A device token so we can tell you when it is your turn (Firebase Cloud Messaging).
- Usage and crash data. App events, device model, operating system version, app version, coarse country, and crash reports, so we can fix bugs and improve the game (Firebase Analytics, Firebase Crashlytics).
- Purchase data. Purchase receipts and subscription status, processed by RevenueCat together with the App Store or Google Play, so we can credit what you bought and handle restores. We never see your card details.
- Invite codes. If you open an invite link, the invite code is read from the link or from the install referrer so we can seat you at the right table. On iOS, on first launch after installation, the app checks the clipboard once for a CelebClash invite link. The link is placed there by celebclash.com when you tap the App Store button on an invite page. iOS asks for your permission before the app reads it; nothing else is read or stored.
3. Why we process it, and our legal basis
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Account and gameplay data | Running the game, matching you with rivals, keeping your progress | Performance of our contract with you — Art. 6(1)(b) |
| Push tokens | Telling you when it is your turn | Consent, given through the system notification prompt — Art. 6(1)(a) |
| Usage and crash data | Fixing bugs, measuring whether features work, improving the game | Our legitimate interest in a working product — Art. 6(1)(f) |
| Purchase data | Delivering what you bought, restoring purchases, accounting | Contract — Art. 6(1)(b), and legal obligation for accounting records — Art. 6(1)(c) |
| Moderation records | Enforcing fair play and handling abuse reports | Legitimate interest in a safe service — Art. 6(1)(f) |
Where we rely on consent, you can withdraw it at any time — turn off notifications in your device settings, or change analytics choices in the app under Settings. Withdrawing consent does not affect processing that already happened.
4. What we do not do
We do not sell your personal data. We do not use it to build advertising profiles about you, and we do not track you across other companies' apps and websites.
There is no advertising in the app during beta. If rewarded video ads are introduced at launch, we will update this policy first and explain what the ad provider receives.
5. Who processes data for us
| Provider | What they do for us | Where data is processed |
|---|---|---|
| Supabase | Database, authentication, file storage | European Union |
| Google Firebase | Push notifications, analytics, crash reporting, remote configuration | United States and EU |
| RevenueCat | In-app purchase validation and receipt handling | United States |
| Cloudflare | Hosting and delivery of celebclash.com | Global edge network |
| Apple / Google | App distribution and payment processing | United States and globally |
Each of these processes data on our behalf under a data processing agreement. We do not give them permission to use your data for their own purposes.
6. Transfers outside the EEA
Some of our providers are based in the United States, which means your personal data may be transferred outside the European Economic Area.
Where that happens, the transfer is covered by one of the following safeguards: the provider is certified under the EU–US Data Privacy Framework, or we have entered into the European Commission's Standard Contractual Clauses with them, together with additional technical measures such as encryption in transit and at rest. You can ask us for details of the safeguard used for a particular provider.
7. How long we keep data
| Data | Retention |
|---|---|
| Account and gameplay data | For as long as your account exists. Deleted within 30 days of you deleting your account. |
| Guest accounts | Deleted after 24 months without activity. |
| Push tokens | Deleted when the token stops working or you turn notifications off. |
| Crash reports | Up to 90 days (Firebase Crashlytics default). |
| Analytics events | Up to 14 months, then aggregated. |
| Purchase and accounting records | Five years after the transaction, as required by the Norwegian Bookkeeping Act. |
| Moderation records | Up to 12 months after the case is closed. |
Backups are overwritten on a rolling cycle and may briefly contain deleted data before they are replaced.
8. Your rights
You can export your data and delete your account directly in the app under Settings → Account.
Under the GDPR you also have the right to access your data, have it corrected, have it erased, restrict or object to how we process it, and receive it in a portable format. For anything you cannot do in the app, email us and we will respond within 30 days.
So that we can act on a request sent by email, we need to identify your account. If you have a registered account, write from the email address on the account. If you play with a guest account, include your Player ID, shown in the app under Settings → Account. A guest account holds no name, email address or other contact details, so without a Player ID we cannot identify it — it is then deleted automatically after 24 months without activity, as described in section 7.
If you think we have handled your data wrongly, you can complain to your national data protection authority. In Norway that is Datatilsynet (datatilsynet.no).
9. Children
CelebClash is not directed at children under 13, and we do not knowingly collect personal data from them. Where the country you live in sets a higher minimum age for consenting to online services on your own, that age applies instead.
If you believe a child below that age is using the Service, contact us and we will remove the account and the data associated with it.
10. Security
Data is encrypted in transit. Access to the production database is restricted to named administrators and protected by two-factor authentication. Game state is written through server-side functions rather than directly by the app, which limits what a compromised device can change.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and Datatilsynet as required by law.
11. Changes to this policy
We may update this policy as the game develops — for example when purchases or ads launch. Material changes will be announced in the app or on this page before they take effect. The date at the top shows when it was last revised.
12. Contact
Hallingcast AS · Torpomoen 27, 3579 Torpo, Norway