Free-beta privacy
Personal stories belong to the people in them.
This product only works because friends type true things about someone they know. That material is theirs, not ours and not the organizer's, and the whole design follows from that.
In effect from 2 August 2026.
Account and event data
Signing in stores your email address and an authentication record. Creating an event stores its occasion, title, subject name, date, time zone, settings, invited collaborators, and the content you choose to collect. Secret contributor and play links are stored as one-way hashes rather than readable tokens.
Organizers control their events. Contributors can access only the event linked by their invitation, and players can access only a published game through its play link.
An organizer may ask us to email an invitation link on their behalf. That address is passed to Resend to deliver the one message and is never stored on the event, so we hold no list of the people who were invited.
Photographs
Photo contributions are closed for this beta. The form no longer offers an upload, and the endpoint refuses one. Photographs sent before that still exist and are still governed: they live in a private bucket no browser can read directly, organizers see them through short-lived signed links and never a storage path, and they are included in an export, a withdrawal and a deletion exactly as before.
Playing in the browser
Joining a game stores the display name a guest types and the answers they give, tied to a random identifier held in a cookie on their own phone. That cookie is what lets somebody rejoin after their screen locks. We never ask a guest for an email address or an account, and play data is deleted with the event.
Reporting something
Anyone holding a contributor link or a join card can report what they see, at /reporton their own link, without an account. Every reason except “something is broken” pauses the game immediately: nobody is shown the pack again until the organizer has looked at the report.
We do not record who reported it. The organizer sees the reason chosen and anything the reporter chose to type, and cannot delete the report.
Taking your contribution back
A contributor can withdraw what they sent from their own link. If approved material of theirs has already reached a published pack, publication is paused and the organizer is told to regenerate before the game runs again.
What the site measures
A first-party endpoint records an anonymous visitor ID, session ID, landing path, traffic-source tags, and named funnel steps such as starting personalization, adding source material, copying a contributor invitation, or completing a preview. The records are stored in a private Supabase table that browsers cannot read directly.
The browser uses localStorage for the anonymous visitor ID and sessionStorage for the current session and landing path. PostHog, the visitor-counting service described below, keeps a second anonymous identifier in localStorage as well. This test uses no tracking cookies, advertising pixels, session replay, or automatic click-and-text capture.
Separately from the funnel records above, PostHog counts visits: the page addresses, the site that linked you, your device type and country. Those requests go to playtheirstory.com and are passed on from there, and PostHog stores them in the European Union. It is not sent any of the material in the next section.
What analytics and logs never receive
The guest of honour's name, trivia questions, answers, contributor names, memories, photographs, blocked topics, and relationship details are not sent as event properties.
The same rule applies to the audit trail an organizer can read on their own event. It records that something happened and how many rows it touched — never anybody's words. Metadata is restricted to counts, flags, and values from a fixed list, and anything else is refused rather than trimmed.
Service providers
Supabase provides authentication, private product storage, and the separate analytics database. PostHog counts visits to the site. Vercel hosts the site and runs its server routes and scheduled retention job. Anthropic drafts games from organizer-approved text. Groq turns an optional voice note into text, and is configured for zero data retention, so the recording is not kept there either. Resend delivers invitation emails when an organizer asks us to send one.
How long anything is kept
An event and everything in it is deleted 90 days after the event date, whether or not anyone asks. The organizer gets 14 days'notice on the event's privacy page, with an export link, before that happens.
An organizer can delete an event at any time from that page. Every contributor and join link stops working the moment they ask. The stored data is erased after a 24-hour window in which they can change their mind, by a job that runs once a day — so deletion happens on the next daily run after that window closes, not at an exact hour. After that it is gone, including the photographs in storage and the audit trail itself.
Anonymous usage counts are deleted after 90 rolling days. They hold no stories, names, answers or email addresses.
Free beta
No payment is collected in the beta, and there is nothing to buy.
Operator and requests
Play Their Story is operated under that name from Abu Dhabi, United Arab Emirates. It is run by one person rather than a registered company, so the app name is the operator name. That is who decides what happens to the data described above.
Because there is no company behind it, email is the way to reach the operator. Write to privacy@playtheirstory.com to request deletion or ask how your data is handled. A person reads that mailbox and replies.
A contributor who wants their own stories removed does not need to write at all — the invitation link they were sent has a withdraw button, and it takes effect immediately.