1. Publisher and data controller

The data controller is PIXICODE, a French single-member limited liability company (EURL) with a share capital of EUR 1,000, registered office at 2 Place Jean V, 44000 Nantes, France, registered with the Nantes Trade and Companies Register under number 980 083 786, represented by its manager, Emric Pichonnier.

Contact: contact@pixicode.dev Data protection officer: dpo@pixicode.dev

The legal notice completes this information.

2. Scope

This policy applies to the Pixi Quiz mobile app (iOS and Android) and to the pixiquiz.io website. It is drawn up in accordance with Regulation (EU) 2016/679 (GDPR) and French Act No. 78-17 of 6 January 1978 as amended.

It complements the PixiCode privacy policy, which covers all of our services and prevails on any point not addressed here.

3. Data we process

Account data. Email address, username, chosen avatar and internal account identifier. If you create your account with a password, it is never stored in clear text: only a cryptographic digest (argon2) is kept. If you use “Sign in with Google” or “Sign in with Apple”, we receive only the identification details provided by those services (email address and account identifier) and then issue our own session tokens.

Game data. Scores, experience points, level, title, achievements, missions, day streak, Pixis, unlocked themes, remaining lives, game history and leaderboard positions.

Content you post. Messages sent in friend chat and in multiplayer lobbies, along with your username and avatar, visible to the other players involved.

Technical data. Device model, operating system version, app version, language, time zone, IP address and error or crash logs.

Advertising data. The device advertising identifier and ad delivery data, only within the limits of the consent you have given (see section 6).

Purchase data. The transaction identifier sent by the App Store or Google Play, used to credit your purchase. No payment details are ever disclosed to us: payment is handled entirely by Apple or Google.

Notification data. A push notification token, if you have agreed to receive notifications.

Purpose Legal basis (GDPR art. 6) Retention period
Creating and managing your account so you can play Performance of a contract, art. 6(1)(b) For the lifetime of the account
Saving your progression, scores and leaderboards Performance of a contract, art. 6(1)(b) For the lifetime of the account
Operating multiplayer, friends and chat Performance of a contract, art. 6(1)(b) Lobbies deleted automatically within 2 hours; messages deleted with the account
Keeping your session open Performance of a contract, art. 6(1)(b) Access token 15 minutes, refresh token 30 days
Processing in-app purchases and crediting content Performance of a contract, art. 6(1)(b) Statutory retention period for accounting records
Fixing defects and securing the service Legitimate interest, art. 6(1)(f) Error logs kept for a maximum of 90 days
Preventing cheating, fraud and abuse Legitimate interest, art. 6(1)(f) As long as needed to handle the incident
Showing personalised advertising Consent, art. 6(1)(a) Until consent is withdrawn
Sending push notifications Consent, art. 6(1)(a) Until consent is withdrawn

Data strictly necessary to run the game is mandatory: without it, the service cannot be provided. Processing based on consent is optional, and refusing it does not prevent you from playing.

5. Source of the data

Data comes from you (account creation, games played, messages), from your device (technical data) and, where you use Google or Apple sign-in, from the identity provider concerned.

We do not buy any data and carry out no enrichment from third parties.

The app shows advertising served by Google AdMob. On first launch, a consent screen compliant with the European framework asks whether you accept personalised advertising. On iOS, the system additionally requests tracking permission (App Tracking Transparency).

You can change this choice at any time from the app settings, and from your device settings for the advertising identifier. If you refuse, non-personalised advertising is still displayed: it is not based on your behaviour.

7. Recipients and processors

Your data is never sold, rented or transferred to third parties for commercial purposes. It is accessible only to:

  • authorised PIXICODE staff, within the limits of their duties;
  • Google Ireland Limited, for ad delivery (Google AdMob) and for routing push notifications (Firebase Cloud Messaging);
  • Apple Distribution International and Google Ireland Limited, for processing in-app purchases made on their respective platforms;
  • our hosting provider, for database storage and running the game servers.

Authentication, the game database and the collection of error reports run on our own infrastructure and involve no third-party provider.

8. Transfers outside the European Union

Data is hosted in the European Union. Some of our processors belong to groups that may process data outside the Union. Such transfers are governed by the standard contractual clauses adopted by the European Commission or by an adequacy decision, in accordance with Articles 44 et seq. of the GDPR.

9. Security

Traffic between the app and our servers is encrypted in transit (TLS). Passwords are stored as argon2 digests. Session tokens are kept on your device in the system’s secure storage (iOS Keychain, EncryptedSharedPreferences on Android). Access to production data is restricted to the people who need it.

10. Your rights

In accordance with Articles 15 to 22 of the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to issue directives on what happens to your data after your death. Where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.

To exercise these rights, write to dpo@pixicode.dev from the email address linked to your account. We reply within one month of receiving the request, which may be extended by two months for complex requests. Proof of identity may be requested where there is reasonable doubt as to the identity of the person making the request.

If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the French data protection authority (CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr) or with the supervisory authority of your country of residence.

11. Account deletion

You may request the deletion of your account at any time by writing to contact@pixicode.dev from your account’s email address. The procedure is described on the Support page.

Deletion removes the account, the progression, the messages and the associated data. Only data we are legally required to keep is retained, in particular accounting records relating to purchases, along with anonymised data, which no longer identifies you.

12. Minors

Pixi Quiz is not intended for children under 13. Between 13 and 15, creating an account requires the authorisation of a parent or guardian. If we learn that an account was created in breach of these rules, it is deleted.

13. Tracking on this website

The pixiquiz.io website measures its traffic with Matomo, hosted on our own servers and configured without tracking cookies and without transmission to third parties. No prior consent is required for such strictly necessary audience measurement, in line with CNIL guidance.

14. Changes

This policy may change, in particular to reflect new features or regulatory developments. The date of the last update appears at the top of the page. In the event of a substantial change, you are informed in the app.

15. Contact

Any question about this policy may be sent to dpo@pixicode.dev or to contact@pixicode.dev.

Back to home