Privacy Policy
Last updated: June 23, 2026
This Privacy Policy explains how who'd poopy collects, uses, and protects your personal data.
1. Who we are
The data controller is the operator of who'd poopy (an individual). Contact: miguel.cassimiro99@gmail.com.
who'd poopy is an entertainment service.
2. Data we collect
We collect the following data:
- Account: name (optional), email, and password (stored encrypted). When using Google sign-in, we receive your name, email, and profile picture.
- Session and security: IP address and browser/device information (user agent) of your sessions.
- Game usage: chosen nickname, emoji, and color, and your logs (date, time, and score).
- Location (optional): if you enable it, we collect the latitude/longitude at the time of the log to display it on the map. This is visible only to you and your room partner — it is never public nor shared with third parties. It can be disabled at any time.
- Cookies and analytics: see the dedicated section below.
3. Purpose and legal basis
We process your data to:
- operate and provide the Service — performance of a contract (LGPD art. 7, V; GDPR art. 6(1)(b));
- analytics and location — your consent (LGPD art. 7, I; GDPR art. 6(1)(a));
- comply with legal obligations (LGPD art. 7, II; GDPR art. 6(1)(c));
- security and fraud prevention — legitimate interest (GDPR art. 6(1)(f)).
4. Cookies and Analytics
We use Google Analytics 4 to understand how the site is used. The script only loads after you accept it in the cookie banner.
We also use: a session cookie (to keep you signed in), a language cookie (i18n_redirected), and a local record of your cookie choice (cookie_consent).
You can withdraw consent at any time by clearing your browser data.
5. Sharing and processors
We share data only with your room partner and with services essential to running the Service:
- Room partner: your logs (and location, if enabled) are visible to the partner you share your room with. They are not exposed publicly.
- Stripe — payment processing. We do not have access to your card data.
- Google — sign-in (OAuth) and Google Analytics.
- Resend — sending transactional emails (verification and password recovery).
- Cloudflare — hosting and infrastructure.
6. We do not sell your data
We do not sell or trade your personal data. We share only what is necessary to operate the Service.
7. International transfers
Some processors are located outside Brazil and the European Union (for example, in the United States). Where applicable, such transfers rely on appropriate safeguards, such as standard contractual clauses.
8. Data retention
We keep your data while your account exists. Upon a deletion request, we remove your personal data within 30 days; backup copies are purged within 90 days. Analytics data follows Google's retention policy.
9. Your rights
You can access, correct, export (portability), and delete your data, withdraw consent, and object to certain processing.
To exercise your rights, email miguel.cassimiro99@gmail.com. Users in Brazil have the rights under the LGPD; in the EU/EEA, the rights under the GDPR.
10. Children's data
The Service is intended for users aged 18 and over. We do not knowingly collect data from minors. If we identify such data, it will be deleted.
11. Security
We adopt reasonable technical and organizational measures (HTTPS, encrypted passwords, and access control). No system is 100% secure.
12. Changes to this policy
We may update this Policy from time to time. Significant changes will be communicated, and the update date is shown at the top of this page.
13. Contact
For questions or to exercise your rights: miguel.cassimiro99@gmail.com.
