Privacy Policy
Last updated: 12 July 2026
Protecting your data matters to us. This policy explains which personal data we process, for what purposes, on what legal basis, and which rights you have under the EU General Data Protection Regulation (GDPR).
1. Controller
HANGMAN APP
Unit 4.07, The Tea Building
56 Shoreditch High Street
London E1 6JJ
United Kingdom
Email: hangman@kurve.co.uk
For privacy questions: hangman@kurve.co.uk
2. What data we process
When you visit the site: technical log data (shortened IP address, user agent, referrer, timestamp) to deliver and secure the website.
When you create an account or contact us: your name, email address, and any other information you choose to provide.
When you submit a data subject request: your name, email, the type of request and any details you provide.
3. Purposes and legal bases
Operating and securing the site: legitimate interest (Art. 6(1)(f) GDPR).
Performing a contract with you (e.g. providing the service you signed up for): Art. 6(1)(b) GDPR.
Marketing and optional analytics: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
Complying with legal obligations: Art. 6(1)(c) GDPR.
4. Cookies and local storage
By default we only use strictly necessary storage. Analytics or marketing cookies load only after you actively consent via the cookie banner.
You can withdraw consent at any time by clearing our cookies in your browser and declining on your next visit.
A full per-tool breakdown is in our Cookie Policy.
5. Recipients and processors
Website hosting: Lovable / Cloudflare.
Backend, database and authentication: Lovable Cloud (Supabase).
Email delivery: Resend (only when a data request is submitted).
All processors are bound by a data processing agreement under Art. 28 GDPR.
6. Transfers to third countries
Where personal data is transferred outside the EU/EEA, it is done only on the basis of appropriate safeguards — in particular Standard Contractual Clauses under Art. 46(2)(c) GDPR, and adequacy decisions where available (e.g. the EU-US Data Privacy Framework).
7. Retention
We keep personal data only as long as necessary for the purpose it was collected for, or as required by law.
Server logs: typically up to 30 days.
Contact enquiries and data subject requests: until your request has been fully resolved, plus statutory retention where applicable.
8. Your rights
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21).
You can withdraw consent at any time with effect for the future (Art. 7(3) GDPR).
The fastest way to exercise these rights is the request form on our Legal page.
You also have the right to lodge a complaint with a data protection supervisory authority (the UK Information Commissioner's Office (ICO)).
9. Security
We apply current technical and organisational measures: TLS encryption in transit, row-level security in the database, and tightly scoped team access.