Privacy Policy
1. Who we are
“Guess The Song” is developed and published by Maksym Myronenko, an individual sole developer based in Ukraine. There is no company behind the app — it is one person.
For the purposes of the EU/UK General Data Protection Regulation (GDPR), Maksym Myronenko is the data controller for the personal data described in this policy.
| Controller | Maksym Myronenko (a natural person, sole developer) |
| Contact email | maximusik2@gmail.com |
| App | Guess The Song, iOS 17 or later, iPhone |
| Bundle identifier | com.myronenkomaksym.guessthesong |
| Website | https://guessthesong.pro |
Email is the only contact channel. If you need a postal address — for example to send a formal legal notice or a written data subject request — email maximusik2@gmail.com and it will be provided to you on request.
No EU representative under GDPR Article 27 and no UK representative have been appointed at this time. If you are in the EU/EEA or the UK you can still exercise every right described in section 9 directly by email, and you can complain to your national supervisory authority (section 10).
There is no Data Protection Officer; one is not required for processing at this scale.
1.1 Scope of this policy
This policy covers:
- the Guess The Song iOS app;
- the backend API that supports the app;
- the marketing website at https://guessthesong.pro.
It does not cover Apple’s own processing of your Apple Account, your App Store purchase history or your payment details. Apple is an independent controller for that. See Apple’s privacy policy: https://www.apple.com/legal/privacy/
2. The short version
- There is no sign-up. No username, no password, no email address, no name.
- Your account is anonymous and device-bound. The app generates an identifier and stores a device authentication token in the iOS Keychain on your iPhone.
- We collect pseudonymous gameplay and app-usage events, your app version and device model, your coarse country / App Store storefront, and your subscription status.
- We do not collect your name, email, phone number, password, precise or coarse GPS location, contacts, calendar, photos, microphone audio, health or fitness data, financial account details, or any advertising identifier.
- There is no advertising, no IDFA, no App Tracking Transparency prompt, no tracking across other apps or websites, no data selling and no data brokers.
- Payments are handled entirely by Apple. We never see your card, bank details or billing address.
- The website sets no cookies and runs no analytics.
The rest of this policy is the detail.
3. What we collect, and what we do not
3.1 Data we do collect
A. Device and install identifiers. When you first open the app it generates a random install/device identifier and registers an anonymous account with our backend. A device authentication token is stored in the iOS Keychain on your iPhone. This identifier is not your Apple Account ID, not your device serial number, not the IDFA and not the IDFV as a stable cross-app identifier — it exists only for Guess The Song and is regenerated if you delete the app and reinstall it.
B. Technical and environment data. App version and build, iOS version, device model (for example “iPhone 15 Pro”), device language, and the coarse country or App Store storefront associated with your device. Country/storefront is derived at country level only. We do not collect GPS coordinates, and the app never asks for location permission.
C. Gameplay data. Your scores, which rounds you played, which difficulty tier you selected, whether you answered correctly, how much of a preview clip you had heard when you answered, hearts remaining, Classic or Arcade mode, how many of your three free daily games you have used, streaks and progression state.
D. Product analytics events. Pseudonymous events describing how you use the app — screens opened, buttons tapped, a game started, a game finished, the paywall shown, a subscription started or cancelled — each keyed to the generated identifier in (A). These events are sent to Amplitude.
E. Subscription status. Whether you currently hold a Premium entitlement, which product it corresponds to (yearly or monthly), and its expiry or renewal state. Entitlement is verified on the device using StoreKit 2 verified transactions. We do not receive or store your card number, the last four digits of it, your billing address, or your Apple Account email.
F. Server logs. When your app calls our API, the hosting layer records the request — timestamp, endpoint, HTTP status, and the connecting IP address. An IP address is personal data under GDPR. We use these logs only to keep the service running and to investigate abuse and outages, and we do not use them to build a profile of you.
G. Crash and diagnostic data. If the app crashes, Apple may make an aggregated, Apple-controlled crash report available to us through App Store Connect — only if you have separately agreed to share analytics with Apple in your iOS settings. We do not operate our own third-party crash SDK. Where crash data reaches us it contains stack traces and device/OS context, not the contents of your personal files.
H. Correspondence. If you email maximusik2@gmail.com, we hold your email address and whatever you write, for as long as needed to deal with your message and to keep a record of it.
3.2 Data we do not collect
To be explicit, Guess The Song does not collect, request or store:
- your name, nickname or username;
- your email address (unless you choose to email us);
- any password — there are none;
- your precise or coarse GPS location;
- your contacts, calendar, reminders, photos, camera or files;
- microphone recordings or any audio from your device;
- health, fitness or medical data;
- payment card numbers, bank details or billing addresses;
- the IDFA or any other advertising identifier;
- any biometric data;
- any data about children knowingly and specifically (see section 11);
- your Apple Music library, playlists, listening history or Apple Music subscription status (see section 6.3).
There is no advertising SDK in the app, no ad network, no attribution SDK, no social login SDK, and no App Tracking Transparency prompt — because there is nothing to track.
4. Why we process it, and our lawful basis
Under GDPR Article 6 every processing activity needs a lawful basis. Ours are set out below.
| # | Data category | Purpose | Lawful basis (GDPR Art. 6) |
|---|---|---|---|
| 1 | Device/install identifier, Keychain device token | Create and recognise your anonymous account so your progress, streaks and daily game count persist between sessions | Art. 6(1)(b) — performance of the contract with you (our Terms of Service) |
| 2 | Gameplay data (scores, tiers, answers, hearts, daily game count) | Run the game: score rounds, apply the three-hearts rule, enforce the free tier’s 3 games per day and the tier 1–6 free / 7–10 premium split | Art. 6(1)(b) — performance of the contract |
| 3 | Subscription status and entitlement | Unlock unlimited daily games and difficulty tiers 7–10 for Premium subscribers; restore your entitlement on a new device | Art. 6(1)(b) — performance of the contract |
| 4 | App version, iOS version, device model, device language | Make the app work correctly on your device, diagnose device-specific bugs, decide which iOS versions to support | Art. 6(1)(b) where needed to deliver the app; otherwise Art. 6(1)(f) — legitimate interests in a functioning product |
| 5 | Coarse country / App Store storefront | Show the right currency and price, and comply with regional requirements | Art. 6(1)(b) — performance of the contract |
| 6 | Product analytics events (Amplitude) | Understand which features are used, where players get stuck, whether difficulty tiers are balanced, and how to improve the app | Art. 6(1)(f) — legitimate interests in understanding and improving our own product. See section 5 for how we have weighed this and what you can do about it |
| 7 | Server logs, including IP address | Keep the API available, detect and stop abuse, cheating and denial-of-service, investigate incidents | Art. 6(1)(f) — legitimate interests in the security and availability of the service |
| 8 | Crash and diagnostic data | Find and fix crashes | Art. 6(1)(f) — legitimate interests in app stability |
| 9 | Correspondence with us | Answer your question, handle a data subject request, handle a complaint or dispute | Art. 6(1)(b) where it concerns the contract; Art. 6(1)(c) — legal obligation for data subject requests; Art. 6(1)(f) for general support |
| 10 | Records relating to a purchase | Keep accounting and tax records, and respond to consumer-law or regulatory obligations | Art. 6(1)(c) — compliance with a legal obligation |
| 11 | Any of the above, where necessary | Establish, exercise or defend legal claims | Art. 6(1)(f) — legitimate interests in defending our legal position |
We do not rely on consent for anything in the app today, and we do not process any GDPR Article 9 special-category data. We do not carry out automated decision-making or profiling that has a legal or similarly significant effect on you (section 9.7).
Where we rely on legitimate interests you have the right to object. See section 9.6.
5. Analytics — the honest position
We want to be straight with you rather than describe a consent flow that does not exist.
How it works today. The Amplitude analytics SDK initialises when the app launches and begins sending pseudonymous events keyed to the generated install identifier described in section 3.1(A). The app does not currently show a consent prompt or an analytics opt-out toggle before this happens. We rely on legitimate interests (Art. 6(1)(f)) for this processing, on the basis that the events are pseudonymous, are limited to how the app itself is used, are not combined with any directly identifying data, are not used for advertising, are not sold, and are not used to track you across other apps or websites.
What that means for you. If you are not comfortable with analytics, your options today are:
- email maximusik2@gmail.com and object to the processing under Art. 21 GDPR — we will stop analytics processing for your identifier and delete the associated events (see section 9.6); or
- delete the app, which stops all further event collection from that install.
What we are working on. We recognise that regulators in some EU/EEA member states take the position that analytics of this kind requires prior consent, particularly where the SDK writes or reads an identifier on your device. We intend to add an in-app analytics choice. Until that ships, the description above is what actually happens, and the objection route in section 9.6 is available to you at any time.
Amplitude processes this data only on our instructions, as our processor. It is not used to serve you advertising and it is not shared onward for anyone else’s marketing.
6. Who else processes your data
We use a small number of service providers. These are all of them. We do not sell personal data, we do not share it with data brokers, and we do not disclose it for anyone’s advertising.
| Provider | What they do for us | What they receive | Their privacy policy |
|---|---|---|---|
| Apple | App distribution through the App Store; in-app subscriptions and billing through StoreKit; App Store Server Notifications about subscription lifecycle events | Your App Store transaction with Apple (as an independent controller); server notifications identify a transaction and its status, not your identity | https://www.apple.com/legal/privacy/ |
| Amplitude | Product analytics | Pseudonymous event data keyed to the generated device/install identifier, plus app version, device model, device language and coarse country | https://amplitude.com/privacy |
| Railway | Cloud hosting for the backend API and the PostgreSQL database, region EU West (Amsterdam) | Everything stored server-side: the anonymous account record, gameplay data, subscription status, server logs | https://railway.com/legal/privacy |
Apple acts partly as our processor (StoreKit billing on our behalf) and partly as an independent controller (your Apple Account, your payment method, your App Store purchase history, its own fraud prevention). Amplitude and Railway act as our processors under GDPR Article 28 data processing terms.
We may also disclose data where we are legally required to — for example in response to a valid, binding legal request from a competent authority — or where necessary to establish, exercise or defend legal claims. If Guess The Song were ever transferred to another owner, your data could transfer with it; we would update this policy and note the change before that took effect.
6.1 The marketing website
The website at https://guessthesong.pro is a static marketing and legal site. It sets no cookies, uses no local storage for tracking, runs no analytics, has no advertising, embeds no social widgets or pixels, and makes no third-party requests. Your web server logs are handled by the hosting provider for basic delivery and security only.
6.2 No advertising
There is no advertising in Guess The Song, no ad SDK, no IDFA or other advertising identifier, no ATT prompt, and no tracking as Apple defines it — we do not link your data to third-party data for advertising or measurement, and we do not share it with data brokers.
6.3 Apple Music previews
Rounds play 30-second audio previews sourced through Apple Music / MusicKit. You do not need an Apple Music subscription to play. The app does not read your Apple Music library, your playlists, your listening history or your Apple Music subscription status, and it does not write anything to them.
6.4 Song metadata
Song titles, artist names, artwork and difficulty tiers are catalogue metadata about recordings, not data about you. Songs are ranked by global play count, the bottom half of the catalogue is dropped, and the remainder is split into ten difficulty tiers with multipliers from x1.0 to x3.5. That ranking is computed from catalogue-level data, not from your individual listening behaviour.
6.5 Leaderboards and multiplayer
Because your account is anonymous and carries no username, there is nothing to publish about you. Leaderboards is currently a placeholder screen. Duel 1v1, Friends Room and Hotseat are designed but not shipped and are shown in the app as “coming soon”. No personal data is published, shared with other players or made public today. If any of those features ship and would involve sharing anything about you, we will update this policy first.
7. International transfers
Our backend API and database are hosted by Railway in the EU West region (Amsterdam), so your gameplay and account data is stored inside the EEA by default.
Apple and Amplitude are US-linked providers and processing may involve transfers to, or access from, the United States and other countries outside the EEA and the UK.
Where personal data is transferred outside the EEA or the UK, we rely on:
- the European Commission’s adequacy decision for the EU–US Data Privacy Framework (and the UK Extension to it) where the recipient is certified under that framework; and otherwise
- the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved, plus any supplementary measures appropriate to the transfer.
You can ask us for information about the transfer mechanism relied on for a specific provider by emailing maximusik2@gmail.com.
Note that we ourselves are based in Ukraine. Ukraine is not currently covered by an EU adequacy decision, so where we access EEA or UK personal data from Ukraine that access is itself an international transfer, covered by the safeguards described above.
8. How long we keep it
The periods below are the retention commitments we operate to. They are stated as commitments, and where a period depends on a legal obligation we have described the trigger rather than inventing a number.
| Data | Retention |
|---|---|
| Anonymous account record, gameplay data and progression | While the account is in use, then deleted after 24 months of continuous inactivity |
| Product analytics events in Amplitude | 24 months from the date of the event, then deleted or irreversibly aggregated |
| Subscription status and entitlement records | For the life of the subscription, then for as long as needed for accounting, tax and consumer-law purposes under applicable Ukrainian and EU law |
| Server logs, including IP addresses | 30 days for ordinary operational logs; longer only where a specific security incident or legal claim is under investigation |
| Crash and diagnostic reports | 12 months |
| Email correspondence with us | 24 months after the matter is closed, or longer where it relates to a live or foreseeable legal claim |
| Records of data subject requests | 24 months, as evidence that we handled the request — GDPR accountability |
Deleting the app from your iPhone removes the local Keychain token and local state on that device, which means that install can no longer be matched to its server-side record. Server-side records tied to that identifier then expire on the schedule above. If you want them deleted sooner, ask us — see section 9.
9. Your rights
If you are in the EU/EEA or the UK, GDPR Articles 15 to 22 give you the rights below. We extend the same rights to everyone using the app, wherever you are, as a matter of policy. Ukrainian data protection law gives you comparable rights.
To exercise any of them, email maximusik2@gmail.com. We will respond within one month of receiving your request, and will tell you if we need to extend that by up to two further months because the request is complex (GDPR Art. 12(3)). Exercising these rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive repeat requests.
9.1 The identification problem — please read this first
Your account is anonymous and device-bound. We hold no name, email or password that we could match you to. That is deliberately privacy-protective, but it has a practical consequence: if you cannot give us the identifier for your install, we may be unable to find your records, and GDPR Art. 11(2) allows us to say so and decline to act. We will never guess, and we will never hand over one person’s data to another person who merely claims it.
To let us locate the right records, include as much of the following as you can:
- the in-app identifier, if the app exposes it to you (check the app’s settings or about screen);
- the exact date and approximate time you first opened the app;
- your device model and iOS version;
- your App Store country/storefront;
- for subscription questions, the Apple transaction identifier or the receipt email Apple sent you for the purchase — that lets us match the entitlement record;
- your approximate score history or when you last played, which can help disambiguate.
We may ask follow-up questions. If we still cannot establish, to a reasonable standard, that the records are yours, we will explain why and stop there.
9.2 Access (Art. 15)
You can ask what personal data we hold about you, why, who we share it with, how long we keep it, and where it came from, and receive a copy.
9.3 Rectification (Art. 16)
You can ask us to correct inaccurate data and complete incomplete data. In practice, most gameplay data is a factual record of what happened in the app, so this most often applies to entitlement or account state.
9.4 Erasure (Art. 17)
You can ask us to delete your data. We will, unless we must keep specific records to meet a legal obligation — for example accounting and tax records relating to a purchase — in which case we will delete everything else and tell you what we kept and why.
9.5 Restriction (Art. 18)
You can ask us to stop processing your data while a dispute about its accuracy or our lawful basis is resolved.
9.6 Objection (Art. 21)
Where we rely on legitimate interests — analytics, security logging, crash diagnostics — you can object. For analytics we will always honour the objection: we will stop sending events for your identifier and delete the events already collected for it. For security logging we may need to continue where there are compelling legitimate grounds, such as an active abuse investigation; we will explain if that applies. We do not do direct marketing, so there is nothing to object to there.
9.7 Automated decision-making and profiling (Art. 22)
We do not make decisions about you by solely automated means that produce legal effects or similarly significantly affect you. Scoring and difficulty tiering are game mechanics, not decisions about you as a person: your score is round(400 × curve factor × the song's difficulty multiplier), and the curve factor depends only on how much of a recording you have already heard.
| Point in the 30-second preview | Value of naming the song |
|---|---|
| 0:00 | 100% of the payout |
| 0:15 | 75% |
| 0:30 onward | 50% (floor) |
Pausing freezes the price. Replaying ground you have already heard is free.
9.8 Portability (Art. 20)
Where we process data on the basis of the contract with you and by automated means, you can ask for it in a structured, commonly used, machine-readable format, and ask us to transmit it to another controller where technically feasible. We provide exports as JSON.
9.9 Withdrawing consent
We do not currently rely on consent for any processing, so there is nothing to withdraw. If that changes, this policy will say so and withdrawal will be as easy as giving consent.
10. Complaining to a supervisory authority
If you think we have handled your personal data unlawfully, please tell us first — email maximusik2@gmail.com and we will try to put it right.
You also have the right to complain directly to a data protection authority, and you do not need our permission to do so:
- EU/EEA: the supervisory authority in the country where you live, where you work, or where the alleged infringement took place. The list is published by the European Data Protection Board at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en
- UK: the Information Commissioner’s Office, https://ico.org.uk/make-a-complaint/
- Ukraine: the Verkhovna Rada Commissioner for Human Rights (Ombudsman), https://www.ombudsman.gov.ua/
You also have the right to an effective judicial remedy under GDPR Art. 79.
11. Children
Guess The Song is a general-audience music quiz. It is not directed at children under 13, and it is not directed at children under 16 in EU/EEA member states that set the digital-consent age at 16.
We ask that you do not use the app if you are under 13. Between 13 and the age of majority in your country, you need your parent’s or guardian’s permission, as set out in the Terms of Service.
We do not knowingly collect personal data from children below the applicable age. Because accounts are anonymous, we have no age field and no reliable way to detect a child’s age — we do not attempt age inference, and we do not build profiles of anyone.
If you are a parent or guardian and you believe your child has used the app and that data about them is held by us, email maximusik2@gmail.com. Include what you can from the identification list in section 9.1. We will delete the associated records without charge, and confirm to you when it is done. You can also remove the app from the device and, where relevant, use Apple’s Screen Time and Family Sharing purchase controls to prevent further in-app purchases.
12. Security
We take these measures:
- All traffic between the app and our API uses HTTPS/TLS.
- The device authentication token is stored in the iOS Keychain, which is hardware-backed on modern iPhones, rather than in plain app storage.
- There are no passwords to steal, because there are none.
- We never receive card numbers or bank details — Apple handles payment end to end.
- Backend access is limited to the sole developer and protected by strong, unique credentials and multi-factor authentication where the provider supports it.
- Data is hosted with Railway in the EU West (Amsterdam) region, relying on the physical and platform security of that provider.
- Dependencies are updated to pick up security fixes.
No system is perfectly secure. If we become aware of a personal data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where GDPR Art. 33 requires it, and notify affected users without undue delay where Art. 34 requires it. Because we usually hold no way to contact you directly, such a notice may have to be given publicly — on https://guessthesong.pro and in the app — rather than by email.
If you find a security issue, please report it to maximusik2@gmail.com rather than disclosing it publicly, and we will work with you in good faith.
13. App Store “App Privacy” mapping
Apple requires a privacy label (“nutrition label”) on the App Store product page. This section states how that label maps to this policy, so the two agree.
Data Used to Track You: none. We do not track you as Apple defines tracking.
Data Linked to You: none. We hold no name, email, account ID or other identity that our data could be linked to.
Data Not Linked to You:
| App Privacy category | Data type declared | Purpose | Where it is described here |
|---|---|---|---|
| Identifiers | Device ID (our own generated install identifier) | App Functionality, Analytics | 3.1(A) |
| Usage Data | Product Interaction | App Functionality, Analytics, Product Personalization of difficulty and progression | 3.1(C), 3.1(D) |
| Purchases | Purchase History (subscription status only — no payment details) | App Functionality | 3.1(E) |
| Diagnostics | Crash Data, Performance Data | App Functionality, Analytics | 3.1(G) |
Not declared, because not collected: Contact Info, Health & Fitness, Financial Info, Location, Sensitive Info, Contacts, User Content, Browsing History, Search History, and any Advertising Data.
If the label on the App Store product page and this policy ever disagree, treat it as an error on our side and email maximusik2@gmail.com — so we can correct whichever one is wrong.
14. Changes to this policy
We may update this policy — for example when a feature ships, a processor changes, or the law changes.
- The current version always lives at https://guessthesong.pro/privacy/ with its effective date at the top.
- For material changes — a new category of data, a new purpose, a new processor, a new lawful basis, or a new international transfer — we will change the effective date and give notice in the app before or at the time the change takes effect.
- We will never apply a materially expanded use of data you have already given us retroactively without telling you first and, where the law requires consent, obtaining it.
15. How to reach us
Email maximusik2@gmail.com for anything in this policy — a data subject request, a privacy question, a security report, or a request for our postal address for formal service of notice.
Please put “Privacy” in the subject line, and for a data subject request include the details listed in section 9.1 so we can find the right records.