Privacy Policy
Effective · June 13, 2026
Thanks for playing Tag'it. This Privacy Policy describes what data we collect, why we collect it, who can see it, and the choices you have about it. It applies to the Tag'it mobile app, this website, and any related services (together, the "Service"). It is written to be readable. If anything here is unclear, write to us at privacy@patiostudios.com.au.
01Contact us
If you have a question about your data, a request to exercise one of your rights, or just want to talk to a human about how the Service handles your information, the fastest path is the in-app support flow in Profile → Settings → Get help. Most account-specific things we can only confirm and act on from inside the app, so the in-app path is preferable.
Alternatively, you can email privacy@patiostudios.com.au. Mail goes to a real person on our team, we aim to respond promptly.
Controller for the purposes of this policy: Patio Studios, the operator of the Service. (Patio Studios, ABN 32 504 767 825.)
02The data we collect
What we collect depends on which parts of the Service you use. We try to collect only the minimum needed for the Service to work and to keep it fair.
Data you give us directly
- A display name and an avatar. You pick both. The display name is visible to the people you play with in the same round; the avatar is a small style choice. Real names are not required and are not collected.
- A sign-in identifier. Either an anonymous device-bound account, or — once Snapchat Login Kit is enabled — a Snapchat user identifier you provide through Snap's OAuth flow. We do not see your Snapchat password.
- Your email address. When you join the launch list on this website, we collect the email address you submit so we can notify you when the beta opens. If you write to support, we also collect the contents of your message and any reply chain.
- Survey responses if you choose to fill out an in-app or emailed survey. Optional and labelled as such when asked.
Data we collect automatically when you play
- Gameplay state. Which rounds you are in, who is in those rounds, tag events you sent and received, your Tag Points balance, your power-up inventory, your daily-login streak, and your leaderboard rank.
- A hashed device identifier used to keep your account tied to your device and to detect duplicate or abusive accounts.
- Basic device info: operating system and version, app version, language, time zone, and a coarse country derived from your IP address. We do not collect precise location.
- Crash and diagnostic data: stack traces, the screen you were on when the app crashed, and a redacted device fingerprint. Used to fix bugs.
- Typed product-analytics events: a defined list of events such as "tag sent", "tag received", "round ended", "ad watched", "purchase completed". Each event carries only the minimum metadata it needs.
Data we receive from partners
A small number of platform partners pass information back to us as part of running the Service:
- Apple App Store and Google Play tell us whether a purchase succeeded and provide a validated receipt. They do not share your payment instrument with us.
- Apple Push and Google FCM route push notifications to your device using a token we generate. They do not see notification content.
- Snapchat (when Login Kit is enabled) returns a Snapchat user identifier and the display name and avatar you chose to share. They do not return your friend list — the Service does not use any Snap social graph.
- The advertising network (rewarded ads only) returns whether you watched a rewarded ad to completion. Ad requests are sent with both child-safety flags set unconditionally, which limits what targeting data is allowed in the request in the first place.
03Why we collect it
To make the Service work
To do what you asked us to — sign you in, put you in a round, deliver a tag, settle a round, credit a purchase, send a push notification — we have to process the data described above. This is the contract between you and us: if we cannot process this minimum, we cannot run the game.
To make the Service good
Game balance, bug fixes, and product improvements run on typed analytics events. We look at aggregate patterns — pass rate, dodge rate, round-end distribution — to decide what to tune. We do not need a profile of any individual player to tune the game.
To keep the Service safe and fair
We monitor for abusive patterns — automated tagging, self-tagging through fake accounts, attempts to exploit the points economy, and similar — and we take action against accounts doing those things. If you tell us another player is harassing you, we may review the relevant event log and take appropriate action at our discretion.
To deliver rewarded ads
The Service shows rewarded ads only — never banners, interstitials, or native ads. A rewarded ad is one you tap a button to start. Every ad request is sent to the network with child-safety flags set, regardless of the player's actual age, which means the network is required to treat the request as if it were for a child and not to personalise. Players under 13 never reach the rewarded-ad surface at all.
To process purchases
If you buy a power-up charge, we receive a validated receipt from Apple or Google and credit your inventory. We never see your payment card or your stored payment method. Tag Points — the in-game currency that drives your leaderboard rank — are not available for purchase. Only power-up charges (Boost, Shield, Freeze, Lock) are available for sale.
With your consent
For anything that is not strictly necessary to run the Service (for example, sending you launch emails about the public release), we ask once and you can withdraw consent at any time, either inside the app or by emailing us.
04Who can see your data
Other people in your round
The whole point of the game is to play with people you know, so the people in your round see your display name, your avatar, your Tag Points balance, your rank in the round, and the tags you have sent and received within that round. They see only what's needed to play the game together.
Service providers
A short list of vendors processes data on our instructions, only to do their job:
- Backend infrastructure and database provider — managed database, authentication, realtime, and edge functions.
- Push notification delivery provider.
- Crash and error reporting provider.
- Product analytics provider.
- Google AdMob — rewarded ad serving.
- Apple App Store / Google Play — purchases and receipt validation.
- Transactional email provider — account, support, and launch-ping emails.
- Mailchimp — launch waitlist email collection and delivery.
- Website hosting and DNS provider.
Each vendor receives only the data needed for its function and is contractually bound to use it only as we direct.
Public authorities
We will share data with law enforcement or other public authorities when we are legally compelled to. We will narrow what we hand over to the legal minimum.
What we don't do
We do not sell, rent, or trade your personal data. We do not share it with advertisers for the purposes of building a cross-app profile. We do not use it for credit scoring, insurance underwriting, or any decision-making that materially affects you outside the Service.
05International transfers
The Service is global, and the vendors above operate from several countries. Data may be processed outside the country you live in. Where required by law (for example, transfers out of the EEA, UK, or Switzerland), we take reasonable steps to ensure appropriate safeguards are in place with each vendor.
06Your rights and options
Access
You can request a copy of your data in a structured electronic format. Email privacy@patiostudios.com.au from the email address tied to your account, or use the in-app request. We aim to respond within thirty days.
Correction
Most things you can correct yourself in Profile → Settings (display name, avatar, notification preferences). For anything else, ask us.
Deletion
Open Profile → Settings → Delete account. Your account and personal data are removed within thirty days. A few things we are required to retain a bit longer — purchase records for tax purposes, abuse logs where we have a live investigation. Aggregated, anonymized analytics that no longer identify you cannot be reversed once aggregated.
Object and restrict
You can object to processing we do on the basis of legitimate interests, and you can ask us to restrict processing while a request is being worked out. We will honor lawful requests; some may end your ability to play certain parts of the Service.
Withdraw consent
Anything you opted into (launch emails, optional surveys), you can opt out of at the same place you opted in, or by emailing us.
Notifications and ad tracking
You can revoke push-notification permission at any time in your OS settings. You can also limit ad tracking system-wide in your device settings (iOS "Allow Apps to Request to Track" off; Android "Opt out of Ads Personalisation"). Because the Service shows only rewarded ads with child-safety flags always set, system-level tracking limits are already largely a no-op for us, but they still apply.
Complain
If you live in the EEA, UK, or Switzerland and you believe we have mishandled your data, you have the right to lodge a complaint with your local data protection authority. We would much rather you tell us first and give us a chance to fix it.
07Cookies and similar technologies
The mobile app does not use browser cookies. It uses on-device storage to remember you between sessions (your auth token, your cached game state, your preference flags). All of that is wiped when you delete the app or delete your account.
This website does not set any cookies.
08How we protect your data
We implement industry-standard technical and organisational measures to protect your data, including encryption in transit and at rest and access controls on production systems. Only the minimum number of people necessary to operate the Service have access to production data.
We retain account data while your account is active. We periodically review and remove accounts that have been inactive for an extended period.
09Children
The Service is intended for players aged 13 and over. On first launch, an age gate asks for your year of birth in a band; if the band you select indicates you are under 13, you are not allowed to create an account and you do not reach any data-collection or ad surface. We do not knowingly collect personal data from anyone under 13.
If you believe a child under 13 has somehow created an account, email privacy@patiostudios.com.au and we will delete it.
For players aged 13 through the local age of digital consent (16 in much of the EEA, 13 in the US, 14–16 in some other jurisdictions), we apply the same data-minimization defaults to everyone. Both AdMob child-safety flags are set on every ad request regardless of age. In-app purchases are subject to the parental-consent controls built into Apple's Family Sharing and Google's Family Link.
10Changes to this policy
We may update this Privacy Policy as the product and the law evolve. When we make a change that is material — meaning a change in what we collect, why, or who sees it — we will tell you in-app and by email (if you have given us an email) before it takes effect, and we will post the new version on this page with a new effective date. Continued use after that date means the new version applies.
If you skipped to the end: we collect the minimum needed to run the game, we do not sell your data, we do not use the Snap social graph, Tag Points cannot be bought, and you can delete your account from inside the app at any time. The rest is the long version.