Skip to content
NPWNumberplate Words
HomeSupport

Numberplate Words

Privacy policy

How account, gameplay, reliability and moderation information is handled.

Version 1.2.0 · Effective 2 August 2026

Who is responsible

Numberplate Words is operated by Rogue Terrapin, a self-employed business (autónomo) in Spain. Rogue Terrapin is the controller for personal data processed through the game and this website.

Privacy requests can be sent to privacy@numberplatewords.app. General support requests can be sent to support@numberplatewords.app. Operator details are published at https://rogueterrapin.io/legal/.

Guest and device-local play

Practice and the current Daily Challenge can be played without an account. Appearance, haptics, reduced-motion preference, optional diagnostics choice and guest-capable Daily history may be stored locally on the device. Clearing app storage or uninstalling the app removes this local information.

Player accounts and sessions

When you create a recoverable player account, Numberplate Words processes your display name, the Apple or Google sign-in provider used, provider-supplied email where available, provider and player identifiers, aliases, linked-account state and session records. Security records can include creation and expiry times, IP address and user-agent information. Provider identity tokens are verified during sign-in and are not stored as reusable credentials.

Gameplay and social features

Competitive matches store rules, timing, participants, banked guesses, adjudications, scores, results and lifecycle state so matches survive restarts, reconnect safely and resolve consistently. Friends, invitations, blocks, notification preferences, device push tokens and in-app notifications are processed when those features are used.

Safety, moderation and support

A player report contains a selected category and server-verified profile, invitation or closed-match context. There is no free-text report field. Reports do not attach guesses, provider identities or private account details.

Moderation records can retain a reported display-name snapshot, limited match metadata, decisions and audit events needed for review. When an account is deleted, references to that account and retained display-name snapshots are removed or anonymised while a non-identifying record may remain for safety, fraud prevention and legal obligations. Support emails contain the information you choose to send.

Reliability, crash diagnostics and security

Optional mobile reliability telemetry records typed events such as app version, environment, operation, timing, outcome, lifecycle stage and privacy-safe error fingerprints. It excludes raw guesses, request bodies, access tokens, email addresses, display names and raw account or match identifiers. These typed mobile events are sent only to the Numberplate Words API, which validates and minimises them before they enter the private operational logging and monitoring platform.

When **Share crash and reliability diagnostics** is enabled, the signed mobile application may also send scrubbed JavaScript or native crash events directly to Rogue Terrapin's self-hosted GlitchTip error-tracking service. A crash event can include a generic exception type, bounded stack-frame coordinates, native thread/debug identifiers needed to symbolicate the fault, app/build version, immutable release identifier, platform and a small set of lifecycle or component labels. Private source maps and native debug symbols are uploaded separately during the signed build so the operator can identify the affected code.

Mobile and server error events are rebuilt through an allowlist before they leave the application. They exclude account identity, email, display name, provider identity, authentication or push tokens, raw words or guesses, match/share codes, request or response bodies, cookies, authorization headers, query strings, arbitrary application context, screenshots, session replay and breadcrumb history. GlitchTip is not used for advertising, behavioural tracking or gameplay authority.

Minimised server request, security and failure records are still created where needed to operate and protect online features. The API may send a scrubbed server exception to GlitchTip containing the exception type, bounded application stack coordinates, exact release, component, route template, status and validated request correlation ID. It does not send request bodies or player identity.

How information is used

  • Provide guest play, player accounts, multiplayer, friends, invitations, notifications and recovery.
  • Apply game rules, preserve competitive integrity and resolve matches consistently.
  • Investigate reports, enforce blocks, prevent abuse and protect the service.
  • Respond to support, privacy, export and deletion requests.
  • Diagnose crashes, reliability failures and security incidents.
  • Correlate a fault with the exact application release and privately held source-map or native-symbol material.
  • Meet legal, dispute-handling and app-store obligations.

Depending on the activity, the legal basis is performance of the service requested, legitimate interests in operating and protecting the game, consent for optional device diagnostics, or compliance with legal obligations. Numberplate Words does not sell personal information, use gameplay for targeted advertising, upload your address book or provide direct messaging.

Service providers and disclosures

Information is shared only where needed to operate the service, comply with law or protect players. Relevant recipients can include Apple and Google for authentication; Apple Push Notification service, Firebase Cloud Messaging and Expo notification infrastructure for delivery; infrastructure, database, email and observability providers acting on the operator’s instructions; and authorities or professional advisers where legally required.

Rogue Terrapin operates its own GlitchTip error-tracking service on protected infrastructure. The application uses a Sentry-compatible software development kit to send the scrubbed exception contract described above to that service. Build tooling may use Expo/EAS to produce signed applications and to run the protected upload step for source maps and native debug symbols. Upload credentials are build secrets and are not embedded in the application.

Providers receive only the information required for their role and are subject to contractual, platform or legal safeguards. International transfers, where applicable, use the mechanisms required by data-protection law.

Retention

  • Completed competitive matches: 180 days.
  • Abandoned or cancelled matches: 30 days.
  • Raw structured reliability telemetry: no more than 30 days.
  • Raw scrubbed error events: no more than 30 days.
  • Aggregated reliability metrics: no more than 90 days.
  • Private source maps and native debug symbols: retained only while supported releases and related incident evidence require them.
  • Player reports: normally 180 days.
  • Moderation audit events: normally 365 days.
  • Account and active social data: while the account remains active, then removed or anonymised through deletion.

A longer period may apply where necessary for an active investigation, security incident, dispute, fraud prevention, legal claim or legal obligation. Closed records are removed through documented retention cleanup. The configured observability and error-tracking systems must use matching or shorter retention and restricted operator access before production activation.

Your choices and rights

You can disable **Share crash and reliability diagnostics** in Settings. The choice remains on that device, queued typed mobile events are cleared immediately, the mobile error-tracking SDK is closed, and new optional mobile lifecycle or crash events are not delivered while diagnostics are disabled. This preference does not disable minimised server request, security and failure records needed to operate and protect online features.

Signed-in players can export a portable account record and permanently delete their account from Account Data. The public account-deletion page at https://numberplatewords.app/account-deletion/ provides a route for people who cannot access the app. Deletion revokes sessions, removes provider links and personal account details, anonymises safety references and resolves active matches under the published lifecycle rules.

Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier processing. Contact privacy@numberplatewords.app. You may also complain to the Spanish Data Protection Agency or another competent supervisory authority.

Children, security and changes

Numberplate Words is intended for a general audience but is not directed at young children. A parent or guardian who believes a child supplied personal information without appropriate permission should contact the privacy address.

We use proportionate safeguards including encrypted connections, access controls, minimised telemetry, event scrubbing and server-authoritative competitive state. No online service can guarantee absolute security.

This policy may change when features, providers or legal requirements change. Material changes will update the document version and effective date and, where appropriate, be accompanied by an in-app notice.

NPWNumberplate Words

© 2026 Numberplate Words

PrivacySupportAccount deletionTermsSafety