A quiz doesn't need your life. We store what makes your record work, and nothing that makes it sellable.
Your username, your email, an encrypted password. The answers you give, the time you took, your streak, your ranks and the faces you've earned. Reports and comments you write, under your username. That's the record.
Your address book, your location, your photo library, your phone number. No advertising identifier, no cross-app tracking, no fingerprinting. If a feature ever needs one of those, it will ask first and work without it.
One cookie to keep you logged in, one to remember your fandom and your accent colour. Aggregated, IP-truncated analytics so we know which questions are broken — never resold, never joined to your identity. No consent banner, because there is nothing to consent to.
Our hosting and database providers, strictly to run the service, under contract, inside the EU — Hostinger (Frankfurt, Germany) and Supabase (Paris, France). Nobody else. Public by design: your username, your rank, your position on a leaderboard and the comments you post.
As long as your record is open. Delete it and everything personal goes within 30 days — anonymised answer statistics stay, because they belong to the questions, not to you. Inactive records are deleted after three years, after two warnings.
Access, correction, export, deletion, objection — in the app under Account, or by writing to privacy@canonquiz.com TO CONFIRM. We answer within 30 days. You can also complain to your national data protection authority.
Under 15? Ask a parent before opening a record. Controller and legal entity details are in the legal notice.