Skip to content
← Back to HowClose

Legal

Last updated: 8 April 2026

HowClose (“we”, “us”, “the Service”) is a Fermi estimation game operated by Rise Schilling ApS (CVR 44819929), based in Copenhagen, Denmark. This policy explains what data we collect, why, and how we protect it.

1. What we collect

Account data

When you sign in via Google OAuth or email magic link, we store your email address and a display name (nickname) you choose. We do not store passwords — authentication is handled by Supabase Auth.

Game data

We store your game results: scores, individual answers (your estimate vs. the actual value), time taken per question, and completion timestamps. This data powers your profile stats, the leaderboard, and our scoring system (Glicko ratings).

Device & usage data

We collect basic analytics: screen dimensions, app version, country (derived from IP via Vercel headers — we do not store your IP address), and anonymised session identifiers. We use this to fix bugs, understand usage patterns, and improve the game.

Anonymous play

If you play without signing in, we store an anonymous game record with your score and device metadata. This data is not linked to any identity. If you later sign in, your most recent anonymous game can be migrated to your account.

2. How we use your data

Your data is used to: display your scores and stats, maintain the leaderboard, calculate your Glicko rating, send challenge completion notifications (email), and improve the game experience. We do not sell or share your personal data with third parties for advertising.

3. Data storage & security

Data is stored in Supabase (EU region, AWS eu-central-1). The application is hosted on Vercel. All data is transmitted over HTTPS. Database access uses Row Level Security (RLS) policies — you can only read your own profile and game data through the client. Server-side operations use a privileged service role restricted to our API routes.

4. Cookies & local storage

We use browser localStorage to remember your preferences (theme, mute state, onboarding progress) and authentication session cookies managed by Supabase. We do not use third-party tracking cookies.

5. Email communications

We send transactional emails only: magic link sign-in and challenge completion notifications (when a friend plays your challenge). Emails are sent via Resend from noreply@howclose.app. We do not send marketing emails.

6. Your rights (GDPR)

Under the EU General Data Protection Regulation, you have the right to: access your personal data, request correction of inaccurate data, request deletion of your data, and data portability. To exercise these rights, email hello@howclose.app. We will respond within 30 days.

Account deletion

You can request full account deletion by emailing hello@howclose.app. This will permanently remove your profile, game history, ratings, and all associated data. Anonymous game records (which contain no personal identifiers) are retained for aggregate statistics.

7. Children

HowClose is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

8. Changes to this policy

We may update this policy from time to time. Material changes will be noted by updating the “Last updated” date above. Continued use of the Service after changes constitutes acceptance of the updated policy.

9. Contact

For privacy inquiries: hello@howclose.app

HowClose is operated by Rise Schilling ApS (CVR 44819929) · Copenhagen, Denmark · Contact: hello@howclose.app