← Back

Privacy

Last updated: September 11, 2026

Survive the Minute is built data-minimal by design. We collect the least we can to run a daily game and a waitlist, and we hold ourselves to the ceiling described here. This policy covers the website and the app.

What we collect

  • Waitlist email — only if you enter it, used to send your number. Occasional updates are separate and begin only if you tick the optional box and confirm the email we send.
  • A player ID — a random identifier for your game account. It is not your name, but it connects your results and activity to the same account.
  • Device push token — only if you turn on notifications, so we can remind you the Minute is about to begin.
  • Gameplay input traces — the timing of your taps during a Minute. These make the game deterministic and verifiable and are associated with your game account.
  • Coarse region — a country or region derived from your connection headers. Never GPS, never precise location.
  • Crash and analytics events — product and stability data so we can fix problems. In the app, these may include a coded identifier derived from your player ID and can be linked to the same game account. Website analytics use a separate identifier stored for the browser-tab session.

What we never collect

  • No contacts, no address book.
  • No location services, no GPS.
  • No tracking across other apps or websites. There is no Ask App Not to Track prompt because we do not track you.

How we use it

We use this data to run the daily Minute, keep scores honest, send the emails and reminders you asked for, and keep the game stable. We do not sell your data. We do not build advertising profiles about you.

Cookies and analytics

The website uses cookieless analytics with an identifier stored for the browser-tab session. We do not use advertising cookies. Crash reporting is configured to scrub IP addresses from new events.

Who processes data for us

We use a small set of service providers strictly to operate the game: web hosting, operational logs, and monitoring (Google Cloud); database, coordination, and rate limits (Supabase); product analytics (PostHog); crash reporting (Sentry); email delivery (Resend); and bot protection (Cloudflare Turnstile). Each only receives what it needs to do its job.

Your rights

You can ask us to show you the data tied to your account, correct it, or delete it — including removing your email from the waitlist. Depending on where you live, you may have rights under the GDPR or the CCPA; we honor those requests regardless of where you are.

Children

Survive the Minute is not directed to children under 13. We do not knowingly collect personal data from children. Ads, when present, are configured family-safe.

Changes

If this policy changes in a meaningful way, we will update the date above and, where appropriate, tell you in the app.

Contact

Questions or requests: privacy@survivetheminute.com.