Privacy

Live Gizmo is a multiplayer games site. This page says what it stores about you, why it stores it, and how to get rid of it. It covers livegizmo.com and the Live Gizmo Android app, which are the same site.

What is stored

Your account. A username, and the email address you signed in with. If you signed in with Google, we also keep Google’s account identifier so we recognise you next time, and a copy of your Google profile picture β€” copied onto our own storage rather than linked, so that loading a page never tells Google you were here.

Playing as a guest. A guest has no account and no email. You get a random id and a random name, held in your browser, and the games you join are recorded against it exactly as they would be for a signed-in player.

Games. The rooms you are in, the moves you make, your scores, and the messages you send in a room. This is the substance of a multiplayer game: it is visible to the other people in the room, which is the point of them being there.

Notifications. If β€” and only if β€” you turn notifications on, your browser gives us an address it can be woken at, the two keys needed to encrypt a message to it, and a note of which browser it was, so that β€œit did not ring” is diagnosable. Turning notifications off deletes it.

Friends. Who you have added, and requests you have sent or received.

Chat. What you send in a room's chat: the message, who sent it, which room, and when. Messages are kept for 30 days and then deleted automatically, or sooner if the room is deleted. A message carries the name you had when you sent it, so renaming yourself doesn't rewrite what you already said.

Whether you're online. If you let people see when you're online, we keep one timestamp: roughly when your browser last told us it was open. Nothing about what you were doing, and no history β€” each update overwrites the last.

What is not stored

There is no advertising, no ad network and no fingerprinting anywhere in this app, and nothing about you is sold or shared for advertising, because there is no mechanism here that could.

Counting visits

We use Umami to count how many people open the site and which screens they reach, so we can tell whether anything here is working. It is deliberately set up in the weakest form it offers:

  • It sets no cookies and stores nothing on your device. The identifier it uses is invented fresh every time a page loads and is thrown away when you leave, so the next visit is not connected to this one and you cannot be recognised as a returning player.
  • Room links are not sent. Umami is told that you opened a room, never which one β€” the code is taken out of the address first, because that code is the invite. Profile links are shortened the same way, and the part of an address after a question mark is never sent at all.
  • Nothing you do inside a game is measured: no scores, no guesses, no chat, no names. Only which screen was opened.

Umami receives the page address, your approximate location from your IP address, and what kind of browser and device you are using. If you would rather not be counted at all, any tracker blocker stops it, and nothing on the site behaves differently if you block it.

Cookies and browser storage

Two cookies, lg_access and lg_refresh, keep you signed in. They are not used for tracking and there is nothing else in them. Those two are the only cookies this site sets β€” the analytics described above sets none. Your browser also keeps a few preferences that never leave the device β€” your light/dark choice, whether you dismissed the install prompt, and whether you turned notifications off.

Who else sees it

Amazon Web Services. Hosts everything β€” the site, the database, the file storage. AWS is the only place your data is stored.

Google. Only if you choose to sign in with Google, to complete that sign-in. Nothing else on the site is sent to Google.

Umami. Umami counts visits on every page β€” the address of the screen you opened, with room and profile codes taken out, plus your IP address and browser. It sets no cookies and stores nothing on your device.

Your browser’s push service. To deliver a notification the message goes through whichever service your browser uses β€” Google for Chrome, Mozilla for Firefox, Apple for Safari. Every message is encrypted with the keys your browser supplied, so the service carrying it cannot read it.

A model, inside our own AWS account. What a game is built from is what somebody typed: the category a player picks in Trivia, the topic a host sets for a Crossword. That text goes to a model running inside our own AWS account, which writes the questions or the clues back. In Trivia it also marks typed answers, so a right answer spelled differently still counts. A model in the same account also checks text headed somewhere strangers read it β€” a username, a room name, a category or topic, a chat message β€” against the rules in the terms. What it sees is that text and nothing else about you. It is not a third-party service, and nothing sent to it trains anything.

The people in your room. Everyone in that room, including people watching without playing and anyone who joins later and scrolls back. Chat is not private and is not encrypted between players.

Anyone who can see your name. Anyone signed in who can see your name β€” in a room, on your profile, or on their friends list. You can turn this off in settings, and then everyone sees you as offline.

Beyond that, data is disclosed only where the law requires it.

How long it is kept

Your account. Until you delete it, which you can do yourself at any time and which takes effect immediately.

Notification permissions. 180 days after the last notification we successfully sent to that device, so a browser you stopped using drops off on its own.

Rooms and games. Abandoned rooms are swept away automatically; a finished game is kept so the result survives, and an untouched room is gone within a year at the outside.

Guests. A guest identity lives as long as the rooms it is in.

Chat. 30 days, or until the room is deleted. A message you reported, or that somebody reported, is copied onto that report and kept with it β€” that copy outlives the 30 days, because a report nobody can read is a report that cannot be acted on.

Whether you're online. One timestamp, overwritten every minute your browser is open and expiring within minutes of your last tab closing. Deleting your account removes it.

What you can do

  • Turn notifications off at any time, from the bell β€” that deletes the stored permission, it does not just mute it.
  • Change your username from your profile.
  • Stop other people seeing when you are online, from settings. They then see you as offline; you still see them.
  • Block somebody from their profile or your friends list, which hides their messages from you. Blocking is private β€” they are never told.
  • Leave a room to stop appearing in it.
  • Delete your account and everything attached to it from your profile, or by emailing privacy@livegizmo.com if you can no longer sign in. It happens immediately and cannot be undone β€” your profile, friends and notifications go, and you are removed from every room you are in. A game you already played keeps its score so the other players' history stays intact, but your name on it is replaced with "Deleted player".
  • Ask for a copy of what is stored about you, at the same address.

Children

Live Gizmo is not directed at children under 13, and accounts are not knowingly created for them. If you believe a child has made one, email privacy@livegizmo.com and it will be removed.

Changes

If this policy changes in a way that affects what is collected or who sees it, the change will be announced in the app before it takes effect.

Contact

privacy@livegizmo.com β€” for anything on this page, including deletion requests.