Privacy Policy

Last updated: 12 July 2026

Protecting your data matters to us. This policy explains which personal data we process, for what purposes, on what legal basis, and which rights you have under the EU General Data Protection Regulation (GDPR).

1. Controller

HANGMAN APP

Unit 4.07, The Tea Building

56 Shoreditch High Street

London E1 6JJ

United Kingdom

Email: hangman@kurve.co.uk

For privacy questions: hangman@kurve.co.uk

2. What data we process

When you visit the site: technical log data (shortened IP address, user agent, referrer, timestamp) to deliver and secure the website.

When you create an account or contact us: your name, email address, and any other information you choose to provide.

When you submit a data subject request: your name, email, the type of request and any details you provide.

3. Purposes and legal bases

Operating and securing the site: legitimate interest (Art. 6(1)(f) GDPR).

Performing a contract with you (e.g. providing the service you signed up for): Art. 6(1)(b) GDPR.

Marketing and optional analytics: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.

Complying with legal obligations: Art. 6(1)(c) GDPR.

4. Cookies and local storage

By default we only use strictly necessary storage. Analytics or marketing cookies load only after you actively consent via the cookie banner.

You can withdraw consent at any time by clearing our cookies in your browser and declining on your next visit.

A full per-tool breakdown is in our Cookie Policy.

5. Recipients and processors

Website hosting: Lovable / Cloudflare.

Backend, database and authentication: Lovable Cloud (Supabase).

Email delivery: Resend (only when a data request is submitted).

All processors are bound by a data processing agreement under Art. 28 GDPR.

6. Transfers to third countries

Where personal data is transferred outside the EU/EEA, it is done only on the basis of appropriate safeguards — in particular Standard Contractual Clauses under Art. 46(2)(c) GDPR, and adequacy decisions where available (e.g. the EU-US Data Privacy Framework).

7. Retention

We keep personal data only as long as necessary for the purpose it was collected for, or as required by law.

Server logs: typically up to 30 days.

Contact enquiries and data subject requests: until your request has been fully resolved, plus statutory retention where applicable.

8. Your rights

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21).

You can withdraw consent at any time with effect for the future (Art. 7(3) GDPR).

The fastest way to exercise these rights is the request form on our Legal page.

You also have the right to lodge a complaint with a data protection supervisory authority (the UK Information Commissioner's Office (ICO)).

9. Security

We apply current technical and organisational measures: TLS encryption in transit, row-level security in the database, and tightly scoped team access.