Last updated:
TriviAI is an AI-powered trivia game. This policy explains what we collect, why, how long we keep it, and what you can ask us to do about it. We have tried to write it in plain language rather than in the defensive register these documents usually use.
Who we are
TriviAI is operated by Ludoitte Oy (business ID 3242565-2), a company registered in Finland at Köydenpunojankatu 4 B 25, 00180 Helsinki. Ludoitte Oy is the data controller for the processing described here. You can reach us about anything on this page at developer@ludoitte.com.
You do not have an account with us
There is no sign-up, no email, no password and no social login. When you first open the game your device generates a random player identifier. That identifier is how your progress, score and purchases are remembered.
This matters for two reasons, one in your favour and one not:
- We do not know who you are. We hold no name, no email address and nothing that identifies you as a person outside the game.
- Because we cannot connect that identifier to you as a person, we also cannot verify that a particular record is yours if you ask us about it. See Your rights below, where we say what this means in practice rather than pretending it away.
What we collect
Your game data
Your player identifier, display name if you set one, your progress, level, score, in-game currency balances, and when you first played and last played. This is what makes the game work at all.
An approximate location, worked out from your IP address
When you connect, we look your IP address up in an offline geolocation database to find the country, region and city. We store that, along with the coordinates of the centre of that city — not your position. Everyone in the same city gets the same coordinates.
We do not use your device's GPS. The game never asks for location permission and would not receive a location if it did. We use this for country and city leaderboards and to understand roughly where our players are.
Purchases
If you buy something, Apple or Google handles the payment. We never see your card details. We receive a receipt from the store, which we check with Apple or Google to confirm it is genuine, and we record what you bought so we can give you the item.
Security logs
Our servers keep an access log of requests they receive. It records the IP address the request came from, the address requested, the time, the result, and what kind of client made it. This is the ordinary access log that essentially every internet service keeps.
We use it only to keep the service secure: to investigate abuse, to diagnose incidents, and to establish what happened if something goes wrong. We do not use it for advertising, tracking, profiling or personalisation, we do not share it with anyone, and it is not connected to your player identifier — the log has no idea which requests were yours.
Our lawful basis for this one is legitimate interests: keeping a service secure is a recognised legitimate interest, and an access log is the minimum needed to do it. We have written down our reasoning, including the balancing test, rather than assuming it. You can object to this processing at the address above.
How long we keep it
| What | How long |
|---|---|
| Security and access logs, including IP addresses | 90 days, then automatically deleted |
| Your game data and approximate location | For as long as the game is operating |
We keep the security logs for 90 days because a shorter window has already proved too short: when we investigated an incident in 2026 we could not answer basic questions about who had accessed what, because we were not keeping this at the time.
Who we share it with
We do not sell your data and we do not share it for advertising.
We use service providers to run the game — cloud hosting on Microsoft Azure, and Apple and Google for payments. They process data on our instructions in order to provide the service, and they are required to protect it to the same standard this policy describes.
Children
TriviAI is not directed at children. We do not knowingly collect data from anyone under 13, and the game is rated for teens and above.
Your rights
If you are in the UK or EEA you have rights to access, correct, delete, restrict, object to and port your personal data, and to complain to a data protection authority.
Because Ludoitte Oy is established in Finland, the authority that supervises us is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), Lintulahdenkuja 4, 00530 Helsinki, Finland — https://tietosuoja.fi. You do not have to use it: you may also complain to the authority where you live or where you work. We would rather you wrote to us first, but you are not obliged to.
Here is the honest position on how we can act on them.
Your game data
If you send us your player identifier we can find your record, and we can give you a copy of it or delete it. You can find that identifier in the game's settings screen.
The security logs
These do not contain your player identifier or anything else you could quote to us, so if you ask us to delete “your” entries we genuinely cannot find them. We are not going to start recording a link between your identity and those logs so that we could — that would mean collecting more about you, not less, and it would undermine the separation that makes the logging proportionate in the first place.
If you give us an IP address and a rough time, we can find and delete those rows, and we will. In most cases the 90-day expiry will have removed them before it becomes necessary.
We would rather explain that than write a sentence implying we can do something we cannot.
Changes to this policy
We will update this page when what we collect changes, and we will change the date at the top. When we add advertising or analytics to the game — which we intend to — we will ask for your consent first and update this page before we do.