This Privacy Policy explains how Got Stampd? ("we", "us") collects, uses, and shares information when you use the Got Stampd? mobile app and website at gotstampd.com (the "Service"). By using the Service, you agree to this Policy.
We do not sell your personal information, and we do not show third-party ads that track you across other apps.
Where GDPR/UK-GDPR applies, we rely on: contract (to provide the Service you request), legitimate interests (to secure, improve, and moderate the Service), consent (e.g. push notifications, contacts import, precise location), and legal obligation (e.g. mandatory child-safety reporting).
We share information with service providers ("processors") that help us run the Service, under contracts that limit their use of it:
| Provider | What they help us do |
|---|---|
| Supabase | Database, authentication & account storage |
| Cloudflare (incl. R2 storage, Images & Stream) | Media storage, delivery, image/video processing & security (WAF) |
| Apple App Store & Google Play, via RevenueCat | Subscription billing & entitlements |
| Stripe | Printed-book & merchandise payments |
| Cloudflare CSAM Scanning + a content-moderation provider | Automated content safety & CSAM detection (see §5) |
| Anthropic (Claude API) | Challenge generation & moderation assistance |
| Print-on-demand partner | Printing & shipping the physical book / merchandise |
| PostHog & Sentry | Product analytics & crash / error reporting |
| Apple APNs & Google FCM (via Expo) | Push notifications |
We keep this list current as our providers change. Confirm your final content-moderation and print-on-demand vendors before publishing.
We may also share information to comply with law, respond to lawful requests, protect rights and safety, or in connection with a merger or sale of the business. Content you post publicly (public entries, profile) is visible to others per your visibility settings.
To keep the Service safe and comply with law, uploaded images are scanned before they can be shown publicly, including automated scanning for known child sexual abuse material (CSAM). If we detect apparent CSAM, we are legally required to report it to the U.S. National Center for Missing & Exploited Children (NCMEC) and to preserve related records. We also use automated and human review to detect other prohibited content described in our Community Guidelines.
We keep information for as long as your account is active and as needed to provide the Service. When you delete content or your account, we remove it from public view promptly and delete or de-identify it within a commercially reasonable period, except where we must retain it to comply with law, resolve disputes, prevent abuse, or complete an order already placed. Backups age out on a rolling schedule.
The Service is not directed to children under 13 (or 16 where required, such as parts of the EU), and we do not knowingly collect their personal information. Some challenges (e.g. alcohol-related) are restricted to users 18+. If you believe a child has provided us information, contact privacy@gotstampd.com and we will delete it. We comply with COPPA and the Age-Appropriate Design Codes as applicable.
We may process information in the United States and other countries. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for transfers out of the EEA/UK.
Depending on your state, you may have the right to know, access, correct, delete, and opt out of "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined by the CPRA. To exercise your rights, email privacy@gotstampd.com. We will not discriminate against you for exercising them.
Our website uses essential cookies and, with your consent where required, basic analytics to understand traffic. You can control cookies through your browser and our consent banner. The mobile app does not use advertising cookies.
We use encryption in transit, access controls, and other safeguards to protect your information. No method is 100% secure, but we work to protect your data and will notify you and regulators of breaches where required.
We may update this Policy; we'll post the new date above and, for material changes, notify you in-app. Questions or requests: privacy@gotstampd.com or support@gotstampd.com.