Back to home

Privacy Policy

Last updated: June 23, 2026

This Privacy Policy explains how who'd poopy collects, uses, and protects your personal data.

1. Who we are

The data controller is the operator of who'd poopy (an individual). Contact: miguel.cassimiro99@gmail.com.

who'd poopy is an entertainment service.

2. Data we collect

We collect the following data:

  • Account: name (optional), email, and password (stored encrypted). When using Google sign-in, we receive your name, email, and profile picture.
  • Session and security: IP address and browser/device information (user agent) of your sessions.
  • Game usage: chosen nickname, emoji, and color, and your logs (date, time, and score).
  • Location (optional): if you enable it, we collect the latitude/longitude at the time of the log to display it on the map. This is visible only to you and your room partner — it is never public nor shared with third parties. It can be disabled at any time.
  • Cookies and analytics: see the dedicated section below.

3. Purpose and legal basis

We process your data to:

  • operate and provide the Service — performance of a contract (LGPD art. 7, V; GDPR art. 6(1)(b));
  • analytics and location — your consent (LGPD art. 7, I; GDPR art. 6(1)(a));
  • comply with legal obligations (LGPD art. 7, II; GDPR art. 6(1)(c));
  • security and fraud prevention — legitimate interest (GDPR art. 6(1)(f)).

4. Cookies and Analytics

We use Google Analytics 4 to understand how the site is used. The script only loads after you accept it in the cookie banner.

We also use: a session cookie (to keep you signed in), a language cookie (i18n_redirected), and a local record of your cookie choice (cookie_consent).

You can withdraw consent at any time by clearing your browser data.

5. Sharing and processors

We share data only with your room partner and with services essential to running the Service:

  • Room partner: your logs (and location, if enabled) are visible to the partner you share your room with. They are not exposed publicly.
  • Stripe — payment processing. We do not have access to your card data.
  • Google — sign-in (OAuth) and Google Analytics.
  • Resend — sending transactional emails (verification and password recovery).
  • Cloudflare — hosting and infrastructure.

6. We do not sell your data

We do not sell or trade your personal data. We share only what is necessary to operate the Service.

7. International transfers

Some processors are located outside Brazil and the European Union (for example, in the United States). Where applicable, such transfers rely on appropriate safeguards, such as standard contractual clauses.

8. Data retention

We keep your data while your account exists. Upon a deletion request, we remove your personal data within 30 days; backup copies are purged within 90 days. Analytics data follows Google's retention policy.

9. Your rights

You can access, correct, export (portability), and delete your data, withdraw consent, and object to certain processing.

To exercise your rights, email miguel.cassimiro99@gmail.com. Users in Brazil have the rights under the LGPD; in the EU/EEA, the rights under the GDPR.

10. Children's data

The Service is intended for users aged 18 and over. We do not knowingly collect data from minors. If we identify such data, it will be deleted.

11. Security

We adopt reasonable technical and organizational measures (HTTPS, encrypted passwords, and access control). No system is 100% secure.

12. Changes to this policy

We may update this Policy from time to time. Significant changes will be communicated, and the update date is shown at the top of this page.

13. Contact

For questions or to exercise your rights: miguel.cassimiro99@gmail.com.