Legal
Privacy policy
Last updated: 2 October 2026
The short version
- You can play without an account. The app gives every install a random ID instead of asking who you are.
- Your voice stays on your device. Takes you record while playing are reversed on your device and never uploaded. The one exception is a garble you choose to send: that one reversed recording is uploaded so your friend can play it.
- Reaction videos (iPhone only) are saved to your Photos, not sent to us.
- We use analytics, session replay and crash reports to understand how the game is played and to fix bugs. We don’t sell your data, and Garble has no ads.
- You can delete your account, the garbles you’ve sent and your synced progress from inside the app.
Who we are
Garble is a game about phrases played backwards. It’s available as an iPhone app and in your browser at garbl.app. In this policy, “Garble”, “we” and “us” mean the operator of Garble: Garble Studio, Example Street 1, 1010 Example City. We decide how the personal data described here is used, which makes us its “controller”.
Questions about privacy go to support@garbl.app.
What we collect and why
Your anonymous ID
The first time you open Garble, the app signs you in anonymously with our backend provider, Supabase. That creates a random account ID with no name or email attached. We use it to save your progress, to remember which garbles you sent, and to connect analytics and crash reports that come from the same install.
Your account (optional)
Signing in is optional. If you do, we store:
- your email address, if you sign in with an emailed code or link;
- the identifier Apple gives us and the email address Apple shares (which can be a private relay address), if you use Sign in with Apple on iPhone;
- the identifier and email address Google gives us, if you use Google sign-in where it’s offered.
We use these to sign you in and to keep your progress and Garble Plus with you across devices.
Your display name
This is the name your garbles are sent under. If you don’t choose one, Garble uses “User” followed by the first characters of your account ID. It’s shown to the people you send garbles to and saved with your progress.
Your progress
Garble keeps track of your streak (including freezes and any repair window), your daily results and how you played them (for example how many times you listened, recorded and guessed), your progress in each pack, your inbox, your display name, and whether you’ve finished the tutorial. Your inbox is the list of garbles you’ve sent and received: their links, the senders’ names, the phrases, and whether they’ve been decoded. The audio itself isn’t stored in the inbox; it’s fetched from the link when you play it.
This progress is stored on your device and backed up to Supabase under your account ID, including before you sign in. That’s what lets it merge into your account when you sign in and stay in step across your devices.
Garbles you send
When you create a link for a garble, we upload and store:
- the reversed recording of your take (a short audio file of up to 10 seconds);
- the phrase, if you typed one;
- your display name;
- your account ID and the time the garble was created.
Your original, forwards recording is never uploaded, only the reversed one.
Each garble gets a random link (garbl.app/d/…). Anyone who has the link can play the garble and see your display name and the phrase you typed (the game keeps the phrase hidden until the reveal). The garble also carries the random ID of the account that sent it. Treat a garble like an unlisted link and share it only with people you want to hear it. When someone reveals your garble, we record the time, so your Inbox can show that it was decoded.
Usage analytics and session replay (PostHog)
We use PostHog, on its EU cloud, to understand how people play: which screens they use and where they get stuck. The app sends events such as “daily solved”, “pack opened” or “garble sent”, with details like the pack, the number of attempts, and whether you’re on iPhone or the web. Events are tied to your account ID. They don’t include your name, your email address or any audio, and garble link IDs are scrambled with a one-way hash before they’re sent. PostHog also receives standard device and browser information (such as device model, operating system, browser and screen size) and your IP address, which it may use to estimate your approximate location.
PostHog also records session replays that show how people move through the app:
- In the iPhone app, all text, images and the camera view are masked out, so replays don’t show phrases, what you type or your face.
- On the web, replays show the app screen as you see it, which can include phrases, the guesses you type and your display name. The account screen, where you enter your email address and sign-in code, is not recorded.
Analytics runs only in the released iPhone app and on garbl.app. There’s no in-app switch to turn it off. If you block PostHog with a browser content blocker, web analytics stops and the game keeps working.
Crash reports and performance (Sentry)
When something goes wrong, the app sends an error report to Sentry, hosted in the EU. It includes what failed, technical details such as the stack trace, your device or browser type, the operating system and app version, and your account ID. The app also sends performance data, such as how long screens and network requests take. Garble link IDs are removed from page addresses before a report leaves your browser, and the app’s debug logs are not attached.
Purchases (RevenueCat, Apple, Stripe)
Garble Plus subscriptions are managed by RevenueCat. In the iPhone app you pay Apple through the App Store: Apple handles your payment details and tells RevenueCat whether your subscription is active. Where Garble Plus is sold on garbl.app, payment goes through RevenueCat’s web checkout, with Stripe processing the payment; they collect the details needed to take it. We never receive your full card number.
To connect a purchase to you, we give RevenueCat a separate random purchase ID linked to your account. We don’t give RevenueCat your account ID or your email address.
Sign-in emails (Resend)
Sign-in codes and links are sent through Resend, which receives your email address and the message.
Website hosting (Cloudflare)
garbl.app is served by Cloudflare. Like any web host, it processes your IP address and request details (such as the page you asked for and your browser) to deliver pages and protect the site. Pages for shared garbles are cached for a few minutes so they load quickly.
What stays on your device
- Your takes. Recording, reversing and playback all happen on your device. Takes from the daily, packs, party mode and the Studio are never uploaded. Temporary audio files are cleaned up automatically. Only a take you choose to send as a garble leaves your device.
- Reaction videos (iPhone only). They’re filmed with your front camera, with sound from your microphone, and stay on your phone unless you save them to Photos or share them. We never receive them.
- Party mode. Player names and everyone’s takes stay on the phone you play on.
- Device settings, such as whether reaction videos are on.
Device permissions
- Microphone
- To record your take. Garble asks the first time you record.
- Camera (iPhone)
- To film reaction videos. You can say no, or switch filming off with the Camera chip during a round, and the game works the same.
- Photos (iPhone, add only)
- To save the reaction videos you keep. This permission lets Garble add to your library, not read it.
Cookies and browser storage
On garbl.app, the game keeps your progress, settings and sign-in session in your browser’s local storage. PostHog stores a random identifier in a cookie and in local storage so it can recognise the same browser between visits. We don’t use advertising cookies. This page itself runs no analytics.
Who we share data with
We don’t sell your personal data, and we don’t share it for advertising. We share it with the people you choose to send garbles to, with the service providers below who run parts of Garble for us, and where the law requires it.
- Supabase
- Accounts and sign-in, and the database and file storage for your progress and the garbles you send.
- PostHog
- Usage analytics and session replay (EU cloud).
- Sentry
- Crash and performance reports (EU, Germany).
- RevenueCat
- Garble Plus subscription management.
- Apple
- App Store purchases and Sign in with Apple.
- Stripe
- Card payments for Garble Plus on the web, where it’s sold there.
- Google sign-in, where it’s offered and only if you use it.
- Resend
- Delivery of sign-in emails.
- Cloudflare
- Hosting for garbl.app.
Some of these providers process data outside your country, including outside the EEA and UK (for example in the United States). Where personal data is transferred out of the EEA or UK, it’s covered by the safeguards the law requires, such as the European Commission’s standard contractual clauses in these providers’ data processing terms.
How long we keep data
- Your account and synced progress: until you delete your account. Progress under an anonymous ID that was never signed in is kept until it’s deleted (see below).
- Garbles you send: until you delete your account. Garbles don’t currently expire on their own. If we start removing old garbles automatically, we’ll update this policy first.
- Analytics, session replays and crash reports: for the retention periods set in PostHog and Sentry. Deleting your account doesn’t remove them; email us if you’d like them deleted.
- Purchase records: kept by Apple, RevenueCat and Stripe as needed for billing, tax and accounting.
Deleting your account and data
If you’re signed in: tap the account button at the top of the screen, then Delete account, then Delete everything. This permanently deletes your account, the garbles you’ve sent (including their audio, so their links stop working) and your synced progress, on every device. Garble stays playable; you start over with a new anonymous ID. A shared garble’s page can keep showing for a few minutes while caches expire, and copies people already saved or recorded are outside our control.
Deleting your account doesn’t cancel a Garble Plus subscription. On iPhone, cancel it in your App Store settings first.
If you never signed in: your progress and any garbles you sent belong to an anonymous ID. You can sign in with an email address that isn’t already used for Garble, which upgrades that same anonymous account, and then delete it as above. Or email us and we’ll help.
Uninstalling the app or clearing your browser’s data removes the copy on that device only.
Your rights
Depending on where you live, including in the EEA and UK, you can ask us to give you a copy of your personal data, correct it, delete it, or send it to you in a portable format, and you can ask us to restrict or stop using it. You can also complain to your local data protection authority.
You can see what’s synced and delete everything in the app. For anything else, email support@garbl.app. We may need to confirm the request comes from you, for example by asking you to write from the email address on your account.
Legal bases (EEA and UK)
- To provide the game you asked for (our contract with you): your anonymous ID, your account, progress sync, sending and receiving garbles, and Garble Plus.
- Our legitimate interests in understanding and improving Garble and keeping it working and secure: analytics, session replay, crash and performance reports, and hosting logs. You can object to this by emailing us.
- Legal obligations, such as keeping purchase records for tax and accounting.
Children
Garble isn’t directed at children under 13, or under the minimum age for this kind of service where they live (up to 16 in some EU countries), and we don’t knowingly collect personal data from them. If you believe a child has given us personal data, email us so we can remove it.
Security
Garble uses encrypted connections (HTTPS) between the app and our services, and our database only lets each account read and change its own data. Garble links are random, and there’s no way to browse or list other people’s garbles, but anyone who has a link can play that garble.
Changes to this policy
When this policy changes, we’ll update the date at the top. If a change significantly affects how we use your data, we’ll let you know before it takes effect.
Contact
Email support@garbl.app with any question about this policy or your data. See also our terms of use and help.