Privacy Policy
Effective date: 13 August 2026 · Last updated: 13 August 2026
Klack is a scorekeeping app for the game of Mölkky, published by Suuntio (“we”, “us”), based in Finland. This policy explains what data Klack handles, why, and what control you have over it.
The short version: Klack works on your device by default. You do not need a Klack account, and there is no advertising, no analytics, and no third-party tracking. Data leaves your phone in three cases: when you choose a feature that needs it (sharing a game or joining one, backing up to the cloud, or subscribing to Klack Pro), when the app sends us a crash report, which you can turn off in Settings, and once in the background, when the app first reaches the network and creates the random player identifier described in section 3.1.
1. Who is responsible for your data
Suuntio
Business ID (y-tunnus): 3634040-2
Louhentie 13 D 32
02130 Espoo
Finland
Email: support@klack.club
Phone: +358 45 869 1204
Suuntio is the data controller for the personal data described in this policy, within the meaning of the EU General Data Protection Regulation (GDPR).
2. Data stored on your device only
By default, everything Klack records stays on your phone in a local database and is never transmitted anywhere:
- Games you have played: throws, scores, rules used, timestamps, outcomes
- Your player roster: the names you give the people you play with
- Statistics and skill ratings derived from those games
- App settings: language, theme, and your own display name
This data is not accessible to us. If you delete the app without ever using an online feature or creating a Klack account, this data is deleted with it and no copy exists anywhere else.
3. Data processed when you use online features
Klack’s online features are optional and user-initiated, and the data described in sections 3.2–3.7 is processed only when you use one. Two things happen without you choosing a feature: the app creates its pseudonymous device identity in the background the first time it can reach the network (section 3.1), and it sends crash reports unless you switch them off (section 3.8). Beyond those, no personal data is sent to our servers unless you use a feature that needs it.
3.1 Pseudonymous device identity
The first time the app can reach the network, Klack automatically creates an identifier for your device in the background: a random UUID. It carries no name, email, device fingerprint, or advertising identifier, and it is not derived from anything about you or your hardware.
This identifier exists so that a person can be recognised across games and devices: it is how your history follows you, and how the app knows that “Anna” on your friend’s phone and “Anna” on yours are the same player. Because its purpose is to recognise a person, it is pseudonymous personal data in GDPR terms, not anonymous data. We refer to it in the app as your Klack user id.
- Purpose: enabling multiplayer, player identity, and backup
- Legal basis: legitimate interest (GDPR Art. 6(1)(f)) in providing a functioning app; for the features you actively choose, performance of a contract (Art. 6(1)(b))
- Retention: signing out or reinstalling the app discards the identity from your device, and the app starts over with a fresh one. That alone does not delete the server-side record of the old identity, or its appearances in games other players have recorded; section 7 describes exactly what deletion covers. Deleting your Klack account deletes the identity and every record we hold that belongs to it.
The app is fully usable if this identity is never created, for example if the device is permanently offline.
3.2 Sharing a game
When you share a game, or join a game someone else shared, the following is sent to our backend:
- A game record (its rules, its status, and a short join code)
- The list of participants: their Klack user ids and the display names they chose
- An ordered log of the throws recorded during the game, and the final result
- Skill-rating values reported by participants, so ratings can be settled
This serves two things: while the game is running, participants can follow the score in real time, and once it ends, the finished game is delivered to every participant so it lands in each player’s own history. The data is readable only by the people who are members of that game session. It is kept only for as long as it is needed to relay the game to its participants and let them download their own copy, and is then deleted from the relay.
- Purpose: delivering the shared-game features you requested: live score following during the game, and delivery of the finished game to its participants afterwards
- Legal basis: performance of a contract (Art. 6(1)(b))
3.3 Creating a Klack account
A Klack account is optional. It makes your player identity durable: your name, statistics and skill rating stay yours across your devices and in games other people record. It is also what a Klack Pro subscription and any cloud backup attach to. Every local feature of Klack (scoring, history, statistics, ratings, the roster) works with no Klack account.
If you create one, we process:
- Your email address, if you sign up with email and password
- The identifier supplied by Apple or Google if you use their sign-in. With Sign in with Apple you may choose Apple’s private relay address, in which case we never see your real email address.
- An encrypted password hash, if you use email and password
We use your email address only to authenticate your Klack account and to send essential service messages (confirming your address, resetting your password). We do not send marketing email.
- Legal basis: performance of a contract (Art. 6(1)(b))
- Retention: until you delete your Klack account
3.4 Cloud backup of your games (Klack Pro)
If you are a Klack Pro subscriber and you switch on backup, your completed games are uploaded to your private cloud library: the game’s rules, its players’ names and Klack user ids, the throws, the final scores and the resulting ratings. Only you can read your library: it is protected at the database level by row-level security keyed to your Klack account.
Restoring your own games from the cloud is always free and remains available even if your subscription lapses.
- Legal basis: performance of a contract (Art. 6(1)(b))
- Retention: for as long as your Klack account exists. If your subscription lapses, your cloud games are retained for a further 6 months and then deleted; we warn you in the app before this happens. Deleting your Klack account deletes them immediately.
3.5 Push notifications
If you accept notifications, your device’s push token is stored against your Klack account so we can notify you when someone invites you to a game. Klack never asks for notification permission at launch: it asks only after you first confirm an invitation or join a hosted game, and only after explaining why.
Notification tokens are used solely for game invitations and game events. We send no promotional notifications. Declining permission breaks nothing: invitations still reach you inside the app.
- Legal basis: consent (Art. 6(1)(a)); you may withdraw it at any time in your device settings
- Retention: until you revoke permission, delete your Klack account, or the token becomes invalid
3.6 Subscriptions
If you purchase Klack Pro, the purchase itself is handled by Apple or Google. We never see or receive your payment card, billing address, or any financial details.
To know whether your subscription is active, we process, via RevenueCat, a purchase record: your subscription status, product, purchase and expiry dates, platform, and an app-user identifier linked to your Klack account. RevenueCat’s SDK also collects a device identifier by default (on iOS, Apple’s identifier for vendor, IDFV) to tell devices apart. The record carries no name, email, or payment details, but because it is linked to your account it is pseudonymous personal data, not anonymised data.
- Legal basis: performance of a contract (Art. 6(1)(b)) and compliance with legal obligations (Art. 6(1)(c))
- Retention: for the life of the subscription and thereafter as required for accounting and tax purposes
3.7 Camera
Klack can scan a QR code to join a game or claim your history. The camera feed is processed live on your device and is used only to decode the code. No image, video, or frame is ever stored, transmitted, or retained. Camera access is optional; every code can also be typed in by hand.
3.8 Crash and error reports
When Klack crashes or hits an unexpected error, it sends a diagnostic report so we can find and fix the problem. This is on by default and can be switched off at any time under Settings → Privacy → Send crash reports. Switching it off stops reporting entirely: the app does not collect the reports and hold them back, it does not start the reporter at all.
A report contains the error and where in the code it happened, your app version, the over-the-air update your app was running, your device model and operating system version, and your pseudonymous Klack identifier (section 3.1).
A report never contains player names, scores, game records, your statistics, your email address, or anything you have typed. Reports are processed by Sentry, on servers in the European Union (Germany).
- Legal basis: legitimate interests (Art. 6(1)(f)): keeping the app working for the people who use and pay for it. You can object at any time by switching the setting off.
- Retention: 30 days, after which reports are deleted automatically
4. What Klack does not do
To be explicit, Klack contains:
- No advertising and no ad networks
- No analytics, telemetry, or attribution SDKs. Klack does send crash reports (see section 3), which are not analytics: they record that something broke and what the device was, never what you did, who you played with, or how you scored. Nothing measures your usage or behaviour, and you can switch crash reports off in Settings.
- No third-party trackers, pixels, or fingerprinting
- No cross-app or cross-site tracking, and no use of the advertising identifier (IDFA). We do not request App Tracking Transparency permission because we do not track.
- No collection of location, contacts, photos, health data, microphone audio, or your browsing activity
- No sale or sharing of personal data with data brokers, ever, under any circumstances
We do not use your data to train machine-learning models.
5. Who else processes your data
Processors. We use a small number of processors. They handle data only on our instructions, and each is bound by a data-processing agreement:
| Provider | Role | Data | Location | Transfer safeguard |
|---|---|---|---|---|
| Supabase | Backend: authentication, database, live relay | Klack account identifiers, game data, push tokens | European Union | Data stays in the EEA |
| RevenueCat | Subscription entitlement management | Purchase status, app-user identifier, device identifier (IDFV) | United States | EU Standard Contractual Clauses incorporated in its data-processing agreement |
| Expo (EAS) | Over-the-air app updates | Update requests; no account or game data | United States | Certified under the EU–U.S. Data Privacy Framework |
| Sentry | Crash and error diagnostics | Error detail, app version, device and OS, pseudonymous identifier | European Union (Germany) | Data stays in the EEA |
You can obtain a copy of the safeguards covering these transfers (for example the Standard Contractual Clauses incorporated in RevenueCat’s data-processing agreement) by emailing support@klack.club.
Independent controllers. Apple and Google distribute the app, operate their sign-in services, and process payments. In those roles they are independent data controllers under their own privacy policies, not our processors, and their processing is governed by the terms you have with them.
Request logs. Like almost every internet service, the infrastructure of the providers above records the IP address of incoming requests in short-lived technical server logs. These logs exist to route and secure traffic and to prevent abuse; we do not use them to identify you.
6. How long we keep things
| Data | Retention |
|---|---|
| Local data on your device | Until you delete it, or uninstall the app |
| Pseudonymous device identity | Discarded from your device when you sign out or reinstall; the server-side record is kept until you delete your Klack account (section 7) |
| Shared-game relay data | Until the game is over and its participants have their copies |
| Klack account and cloud library | Until you delete your Klack account |
| Cloud library after a lapsed subscription | 6 months, then deleted (with prior in-app warning) |
| Push tokens | Until revoked, invalidated, or the Klack account is deleted |
| Purchase records | As required by accounting and tax law |
| Crash and error reports | 30 days, then deleted automatically |
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, object to, and port your personal data, and to withdraw consent where processing is based on it.
You can exercise the most important of these yourself, in the app:
- Rectification: rename yourself and any player from the Players tab.
- Erasure: open your Klack account from the “You” tab → account icon → Delete Klack account. This deletes your Klack account credentials and every record we hold that belongs to you, including your entire cloud library, and returns the device to a fresh, unused identity. It is immediate and irreversible.
- Local erasure: deleting the app removes all local data.
For anything else, or to make a request in writing, email support@klack.club. We respond within one month.
What deletion does not do. Deleting your Klack account does not reach into other people’s data. Games your friends recorded on their devices remain theirs, including the pseudonymous player identifier that links your appearances in them. That record of games you played together is theirs, and removing it would destroy their history. The identifier carries no name, email, or contact detail of yours.
If you believe we have handled your data unlawfully, you may lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi) or your local supervisory authority.
8. Security
Data in transit is encrypted with TLS. Cloud data is protected by database-level row-level security policies that make each row readable only by its owner or by the members of the game session it belongs to, so knowing someone’s identifier grants no access to their data. Authentication sessions are held in the device’s secure storage (iOS Keychain / Android Keystore).
9. Children
Klack is not directed at children under 13 (or under the applicable age of digital consent in your country, which is 13 in Finland). We do not knowingly collect personal data from children. Klack is safe for family use offline, where it collects nothing at all. If you believe a child has created a Klack account, contact support@klack.club and we will delete it.
10. Changes to this policy
If we change this policy materially, we will update the date above, publish the revised policy at this address, and, where the change affects data we already hold, notify you in the app before it takes effect.
11. Contact
Questions, requests, or complaints:
Suuntio
Business ID (y-tunnus): 3634040-2
Louhentie 13 D 32, 02130 Espoo, Finland
Email: support@klack.club
Phone: +358 45 869 1204
Effective · Published by Suuntio · support@klack.club