← back to the trail

Privacy Policy

last updated 25 August 2026

Short version: no ads, no data sales, no tracking pixels. We store the answers your party gives so we can build your report, and very little else.

1. Who we are

shouldwebecofounders is the controller of the personal data described here. Reach us at hello@shouldwebecofounders.com.

2. What we collect

  • Party data: the party code, the display name and critter you choose, your answers, mini-game choices, and the generated report.
  • Device identifier: a random player ID stored in your browser so your device can resume its seat in a party. It is not linked to your identity.
  • Account data (admins only): email address and authentication metadata if you sign in to the admin area.
  • Technical data: standard server logs (IP address, user agent, timestamps) kept briefly for security and abuse prevention.

We ask you not to type sensitive personal information (health details, identifiers, other people's private facts) into free-text fields. Display names are visible to everyone in your party.

3. Why we process it (legal bases)

  • Contract: to run the party you joined and produce your report.
  • Legitimate interests: to keep the Service secure, prevent abuse, and understand aggregate usage so we can improve the game.
  • Consent: for anything optional you explicitly opt into, withdrawable at any time.

4. Sharing and processors

We don't sell personal data and we don't share it for advertising. We use service providers who process data on our behalf under contract: our hosting/CDN provider, and our managed database and authentication provider. Some processors operate outside your country; transfers rely on standard contractual clauses or an equivalent safeguard.

5. Retention

Party data (answers and reports) is kept for up to 12 months so you can revisit your notes, then deleted or irreversibly aggregated. Server logs are kept for up to 30 days. Admin accounts persist until deleted on request.

6. Your rights

Depending on where you live, you can request access, correction, deletion, portability, restriction, or object to processing based on legitimate interests. Under the CCPA/CPRA you may also ask what we collected and request deletion; we do not sell or share personal information as those terms are defined. Email us with your party code and we'll action requests within 30 days. EU/UK residents may also complain to their local supervisory authority.

7. Security

Data is transmitted over TLS, stored in a managed database with row-level access controls, and writes are mediated by server-side functions. No system is perfectly secure; please don't put anything in the Service you would be harmed by disclosing.

8. Children

The Service isn't directed at children under 16. If you believe a child gave us data, email us and we'll delete it.

9. Changes

We'll update the “last updated” date when this policy changes, and describe material changes on the home page or in-app.