Privacy Policy
The short version
- We collect what the game needs: your email to sign you in, your name and match record, and what you say during a match as text.
- Your voice is never stored. Each spoken phrase is sent to our AI provider to be turned into text, and the audio is discarded.
- We use no advertising, no analytics trackers, and only the cookies the service needs to work.
- Your public profile is off until you turn it on.
- You can export or delete your data at any time in Settings.
- Who we are
- What we collect
- Why, and on what basis
- Who processes it
- Transfers
- How long
- Cookies
- What others see
- Your rights
- Age
- Contact
1. Who we are
Contradicto is a browser game in which players argue a motion out loud while an AI jury votes. It is run by Contradicto (“we”, “us”). We are the controller of the personal data described in this policy. Our legal notice has our contact details.
For any privacy question or request, write to [email protected].
2. What we collect
Your account
- Your email address, and your name if Google or Apple shares it with us when you sign in.
- The sign-in method you used, an internal account ID, and the user ID from our sign-in provider.
- If you were invited, the referral code you arrived with, so we can credit the friend who invited you.
- A one-way hash of the IP address you signed up from. We cannot read the address back from it; we compare it with other accounts’ hashes to stop people from rewarding themselves through referrals.
Your player profile
- Your display name, handle, short bio, and whether your profile is public.
- Your rating, wins, losses, match history (the motion, your side, the votes, the result, and your opponent), streak, badges, and Daily Debate results.
- Your friends, the friend requests you sent or received, the players you blocked, and any reports you made about other players or that others made about you (who reported, about whom or which match, the reason, and any note).
What happens in a match
- Your voice. While it is your turn, your browser detects each spoken phrase and sends that short audio clip to our server. The server trims the silence, sends the clip to our AI provider for transcription (see section 4), adds the text to the match, and discards the audio. We never store recordings of your voice.
- The text of the match. The transcript of what each debater said or typed, the motion, the jury’s votes and reactions, Vera’s replies, and the verdict.
- Friend matches. In an online match with a friend, your voices travel directly between your browsers over an encrypted WebRTC connection. To set up that connection, your browser asks a public STUN server (by default Google’s) for its public IP address. When a direct connection is not possible, the encrypted audio passes through a relay run by Cloudflare. We do not record it.
- Your browser’s speech recognition. If server transcription is off, the game falls back to your browser’s own speech recognition. Some browsers, such as Chrome, send that audio to their maker (for example Google) under the browser’s own privacy terms.
- Notes. Notes you write in the lobby stay in your browser. They are never sent to us.
Automatic screening of what you write
Before text you write is shown to others, our AI provider checks it for illegal or abusive content. This covers motions you write, display names, handles, bios, and tournament room names. The provider receives only that text, and we refuse text that fails the check. We keep each verdict for up to 90 days, so the same text is not checked again. Separately, a profanity and slur filter masks words in names, captions, motions, and AI output.
Tokens and purchases
- Your token balance by bucket (daily, monthly, and your own), when your monthly games end, and a ledger of every change to it (daily grants, games hosted, refunds, purchases, monthly refills and expiries, streak and referral rewards).
- For each purchase, including each paid invoice of a subscription: the plan, the number of games, the amount, the currency, the time, the withdrawal statement you agreed to, and Stripe’s identifiers for the checkout or invoice, the payment, the subscription, and you as a customer. We never see or store your card details. Stripe handles them.
- For a subscription, its tier, its status, and its renewal date; for a pass bought before subscriptions replaced passes, the same.
Technical data
- Your IP address, used to apply rate limits, to cap how many accounts can receive free daily tokens from one network, and to stop abuse.
- Server logs of requests and errors.
- For each match, a record of how much the AI models cost to run it, which we use to keep the service affordable.
Viewers
Watching a match through a viewer link needs no account. If viewers vote for The Chat seat, each browser casts one ballot under a random ID stored in that browser. To limit how many ballots one network can cast, the server also keeps a one-way hash of the voter’s IP address, in memory only and only while the match runs. If a streamer connects a Twitch channel, the streamer’s browser reads the channel’s public chat anonymously, directly from Twitch, to count !for and !against votes. Twitch sees that connection under its own privacy terms. We do not store chat messages or usernames.
Reports and notices
Reports you file in the game, notices of illegal content and complaints you send us by email (see the Terms), and what we decided about them.
When you contact us
Your email and whatever you write to us.
3. Why we use it, and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Signing you in and running your account | Account data | Performance of our contract with you, Art. 6(1)(b) |
| Running matches: transcription, the AI jury, Vera’s arguments and voice, results, rating, streaks | Voice phrases (transient), match text, profile | Contract, Art. 6(1)(b) |
| Tokens, subscriptions, top-ups, legacy passes, purchases, and rewards | Wallet, ledger, purchase records, referrals | Contract, Art. 6(1)(b) |
| Keeping purchase records for tax and accounting | Purchase records | Legal obligation, Art. 6(1)(c) |
| Friends, leaderboards, and your public profile | Profile, results, friends | Contract, Art. 6(1)(b). The public profile is on only if you switch it on. |
| Screening text you write before others see it | Motions, names, handles, bios, room names, and the verdicts | Our legitimate interest in keeping illegal and abusive content off the game, Art. 6(1)(f) |
| Handling reports, notices of illegal content, and complaints about our decisions | Reports, notices, complaints, the content concerned, our decisions | Legal obligation under the EU Digital Services Act, Art. 6(1)(c), and legitimate interest, Art. 6(1)(f) |
| Preventing abuse, fraud, and reward farming; rate limits and security | IP address, sign-up IP hash, Chat ballot IP hash, logs, account and wallet data, reports, blocks, and post-deletion hashes | Our legitimate interest in a safe, fair game, Art. 6(1)(f) |
| Backups, so that accounts and purchases survive a failure | Everything in our database | Legitimate interest, Art. 6(1)(f), and our duty to keep data secure, Art. 32 |
| Watching costs and keeping the service running | Per-match cost records, logs | Legitimate interest, Art. 6(1)(f) |
| Answering your messages | What you send us | Contract or legitimate interest, Art. 6(1)(b) or (f) |
We do not sell your data, show ads, or build advertising profiles. We do not use your matches to train AI models, and our agreements with our AI providers do not let them train their models on the data we send through their APIs.
The AI jury decides who wins a match. That decision affects only the game (your rating, streak, and the leaderboards), so it has no legal or similarly significant effect on you. The automatic screening only decides whether a text you wrote may be shown. If you think it refused something by mistake, write to us and a person will look at it.
4. Who processes your data for us
These companies process personal data on our behalf, under data processing agreements, and only for the purposes above:
| Company | What it does | Where |
|---|---|---|
| WorkOS, Inc. | Sign-in: Google and Apple sign-in and the six-digit email codes. Holds your email and sign-in identifiers. | United States |
| OpenAI, L.L.C. / OpenAI Ireland Ltd | Runs the AI: transcribes your spoken phrases, voices Vera, writes Vera’s arguments, runs the AI jury, and screens text you write. Receives audio phrases and text, either directly from us or through OpenRouter (below). Audio is not stored by Contradicto. | United States |
| OpenRouter, Inc. | When we route AI requests through it: an intermediary that receives the text and audio phrases and forwards them to the model provider we configured, by default OpenAI’s models. Transcription through OpenRouter may use Google’s Gemini models, in which case Google LLC receives the audio phrases as a further processor. | United States |
| Cloudflare, Inc. | Relays encrypted voice between friends when a direct connection fails (TURN). | Global network |
| Our hosting provider | Hosts our servers and database. | In the EEA, or elsewhere under the safeguards in section 5 |
| Our backup storage provider | Stores copies of our database off our servers. They travel there over an encrypted connection. | In the EEA, or elsewhere under the safeguards in section 5 |
Stripe. Purchases go through Stripe’s hosted checkout with Stripe as merchant of record (Stripe Managed Payments). Stripe sells the purchase to you and processes your payment details as an independent controller under Stripe’s privacy policy. Stripe tells us what you bought and whether the payment succeeded or was refunded.
Google and Apple. If you sign in with Google or Apple, they know you used their account to sign in to Contradicto, under their own privacy policies.
We may also disclose data where the law requires it, for example to an authority that orders us to, or to protect players or the service from fraud or abuse.
5. International transfers
Some of the companies above are based in the United States. When your data leaves the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses and, where the recipient is certified, by the EU–US Data Privacy Framework. You can ask us for a copy of the safeguards.
6. How long we keep it
| Data | Kept for |
|---|---|
| Voice audio | Not stored. Held in memory only while a phrase is transcribed. |
| Live match (transcript, votes, reactions) and tournament room | About 1 day after its last activity, so its viewer link keeps working. Opening or reconnecting to the viewer link counts as activity, so a match people keep watching is kept longer. A game nobody plays is deleted after 30 minutes without activity, or about 3 hours after its last activity if a server restart interrupted it; one whose token refund is still being retried is kept until the refund goes through. |
| Hashed IP addresses of Chat seat ballots | In memory only, while the match runs. |
| Match results and history, rating, streak | Until you delete your account. Deleting it removes your name, handle, bio, and public page, and your streak and friends. Your match results are kept in anonymized form, under the name “Deleted player”, so that your opponents’ histories and ratings stay intact. |
| Account, profile, friends, wallet, and ledger | Until you delete your account. |
| After deletion: one-way hashes of your sign-in ID and email, with your token balance at deletion (a negative balance, or a positive balance you forfeited), any forfeited tokens carried over from an earlier deletion as an offset, your suspension, and the day you last got free tokens, and, under the same hash, invite rewards that a refund could still reverse | Kept, so that deleting and re-creating an account cannot be used to reset a suspension, a debt from a refunded purchase, free daily tokens, or an invite reward paid for a purchase that was refunded. A forfeited balance and its offset are kept to settle a later refund of an earlier purchase: the refund takes the forfeited tokens first, so it creates debt only for tokens you spent. The hashes cannot be turned back into your email. |
| Screening verdicts for text you wrote | Up to 90 days. |
| Per-match cost records | 90 days. |
| Purchase records | As long as tax and accounting law requires, even after you delete your account. After deletion they are kept under a one-way hash of your sign-in ID instead of your account. If you sign in again with the same sign-in identity or email, they are linked to the new account again, so that a refund or chargeback of an earlier purchase can be processed. |
| Open checkouts, and refunds or cancellations we owe you | An open checkout until it is paid or expires (at most a day). A refund or subscription cancellation we start ourselves, such as for a payment that arrives after you deleted your account, until Stripe confirms it. |
| Reports you filed, or that others filed about you | An open report until we resolve it, and at most 90 days. A resolved report for 30 days after it was resolved. Deleting your account does not delete them sooner (they stay under your anonymized profile), so that we can review abuse. |
| Sign-in session | Until you sign out, or 60 days after its last use; expired sessions are deleted. |
| IP-based rate-limit counters | Up to 3 days: the counters of the current UTC day and of the two days before it. Short-term rate limits are kept only in the server’s memory and end when it restarts. |
| Server logs | On a rolling basis: the server keeps a fixed amount of log data and overwrites the oldest entries first. We do not archive logs. |
| Backups of our database | Up to 30 days. Data you deleted, or that we deleted, leaves the backups within that time. |
7. Cookies and local storage
We set only cookies that the service needs to work. All of them are our own, sent only to Contradicto, and marked HttpOnly, so scripts on the page cannot read them:
| Cookie | What it does | Lasts |
|---|---|---|
contradicto_session | Keeps you signed in. | Until you sign out, or 60 days after your last visit. |
contradicto_oauth | Protects a Google or Apple sign-in from forgery. | 10 minutes; deleted when the sign-in finishes. |
contradicto_preview | Only while the public preview runs, before real sign-in and payments start: a random secret that ties your preview account to this browser, so nobody else can sign in as you. | 400 days. Clearing it loses the way back to a preview account. |
Because these cookies are strictly necessary for the service you ask for, the law does not require a consent banner, and we do not show one. We use no analytics, advertising, or tracking cookies.
The game also saves these items in your browser’s storage. You can clear them in your browser’s settings.
| Key | What it holds | Leaves your device |
|---|---|---|
contradicto.lang | The language you picked. | No. |
contradicto.sfx, contradicto.sfxVolume, contradicto.voiceVolume | Whether sound effects are on, and the volume of sound effects and voices. | No. |
contradicto.streamer | Whether streamer mode is on. | No. |
contradicto.twitch | The Twitch channel you entered. | Your browser uses it to join that channel’s chat at Twitch. |
contradicto.name, contradicto.name2, contradicto.room-name | The names you last typed: yours, a second player’s on the same screen, and a tournament room’s. | Sent when you start or join a match or room. |
contradicto.notes | Your lobby notes for the current match. | No. |
contradicto.ref | The referral code from an invite link. | Sent once when you sign up, then deleted. |
contradicto.profile | When sign-in is off: your device profile and its private key. | The key is sent with your matches to keep your record. Your first sign-in moves the profile into your account and deletes it here. |
contradicto.viewer | A random ID for your Chat seat ballot. | Sent with each ballot. |
contradicto.match.…, contradicto.room.… (session storage) | Your seat in a match or tournament room you are in. Deleted when you close the tab. | Sent with your moves in that match or room. |
contradicto.grantBlocked.… (session storage) | That we already told you today that your network got no daily tokens. Deleted when you close the tab. | No. |
8. What other people can see
- In a match: your opponent, the audience on the same screen, and anyone with the match’s viewer link see your display name, your avatar, and live captions of what you say. Streamers may broadcast their matches and share 15-second clips, which show names and quotes from the match.
- Leaderboards: show your display name and rating, and your handle only if your profile is public. You can leave the leaderboards with the “Show me on leaderboards” setting.
- Friends: see your rating and streak, whether or not your profile is public.
- Public profile: off by default. If you switch it on, anyone can see your name, handle, bio, rating, record, streak, badges, activity, and recent matches at your profile address. Opponents in your recent matches are named only if their own profile is public.
9. Your rights
Under the GDPR you have the right to:
- access your data and get a copy of it,
- rectify it if it is wrong (you can edit your name, handle, and bio in Settings),
- erase it,
- restrict how we use it,
- port it to another service,
- object to processing based on our legitimate interests,
- withdraw any consent you gave, without affecting what happened before.
Export and deletion are built in. In Settings, “Download my data” downloads your account, profile, history, ledger, purchases, friends, and referrals as a file, and “Delete account” erases your account at once (if you have a subscription, cancel it in Manage billing first, so you are not charged again; see section 6 for what is kept). For anything else, email [email protected]. We answer within one month.
You may also complain to a data protection authority. In Lithuania that is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), vdai.lrv.lt. You may also complain in the EU country where you live or work.
10. Age
Contradicto is for people aged 14 and over. We do not knowingly collect data from children under 14. If you believe a child under 14 has an account, tell us and we will delete it.
11. Security
All traffic to Contradicto is encrypted with HTTPS. Sign-in codes expire after 10 minutes, sessions are random tokens we can revoke, backups travel over encrypted connections, and access to production data is limited to the people who run the service.
12. Changes to this policy
If we change this policy in a way that matters, we will say so in the game and, for significant changes, by email before the change takes effect. The date at the top shows the latest version.
13. Contact
Email: [email protected].