QuizNeko respects your privacy. This page describes what data we collect and how we use it.
1. Data We Collect
- Account info: email, name, nickname, country, preferred language, date of birth (optional).
- Authentication: your Metagrid ID and the identifier of your sign-in session; for accounts created before unified sign-in, a hashed password, Google ID or Apple ID.
- Anti-abuse signals: signup IP and user-agent, device fingerprint.
- Usage data: quizzes attempted, answers, points and XP, comments.
- iOS app notifications: if you allow notifications, the app registers an Apple Push Notification service (APNs) device token with QuizNeko, linked to your account, and we send the notification title, body and a link within the site through Apple's APNs. The token is deleted when it becomes invalid or when your account is deleted, and you can turn notifications off in iOS Settings.
2. How We Use It
We use this data to operate the service: authenticating you, ranking quizzes, computing XP rewards, detecting fraud (multi-account / referral abuse), and supporting moderation (reports / appeals). We may also derive an approximate country from your IP address using an offline geolocation database, to show an origin for anonymous quiz attempts and for aggregate statistics; this lookup runs on our own servers, and your IP is not passed to any third party for it. The analytics tool listed in section 4 (Google Analytics) operates separately, and Google may collect connection information through it.
3. Sharing
We do not sell your personal data. Aggregated, anonymized statistics may be displayed on quiz results pages (e.g. country/language breakdowns).
Unified sign-in. You sign in with a Metagrid ID issued by our unified account service at auth.metagrid1.com. That service passes us your account identifier, email address, display name, country and language settings, and the identifier of your sign-in session; we use the session identifier to confirm the session is still valid and to end it when you sign out there. Country and language are used only to pre-fill the sign-up form, and you can change them before signing up. The role it reports is recorded only — it does not grant administrator or payment rights on QuizNeko. Registration and password changes happen on that service, not on QuizNeko. In the iOS app, sign-in opens the system authentication sheet (Apple's ASWebAuthenticationSession) to auth.metagrid1.com, and the session is then handed to the app with a one-time code that expires in 2 minutes; no additional personal data is collected in this step.
4. Cookies and browser storage
- Essential cookies – HTTP-only cookies are used for session authentication (
access_token). Without them you cannot stay logged in. - Anti-cheat tokens – short-lived signed tokens are used to authorize quiz image requests and prevent scraping.
- Analytics cookies – Google Analytics (gtag.js) may set cookies on your device for usage measurement.
- Browser storage – Besides cookies, we keep small values in your browser's local and session storage: an anti-abuse device identifier, your in-progress quiz answers and background-colour preference, an invite token, and a flag marking that this visit has already been counted. These stay on your device, and the visit flag contains no identifier.
- Consent cookie – We store a
qn_consentcookie for one year to remember your choice about cookies. The analytics cookies above are not loaded at all until you agree. You can change your choice at any time via "Cookie settings" at the foot of the page.
5. Automated Anti-Abuse Measures & Data Retention
To protect the points and XP economy and prevent multi-account abuse, QuizNeko automatically evaluates signup and gameplay signals — including IP address, device fingerprint and account-linkage patterns. Attempts from accounts flagged as high risk may not settle at all, new rewards may be restricted, or, in clear cases, the account may be blocked. These measures are applied conservatively and are designed to be reversible.
You may contest an automated decision through the in-app support channel. A human reviewer can release held rewards or whitelist a mistakenly flagged account. To prevent circumvention, we do not disclose the exact detection thresholds.
Data retention. Account and point-transaction records are retained while your account is active and for any period required for audit or legal obligations. Anti-abuse signals (IP address, user-agent, device fingerprint) are kept only as long as necessary for fraud analysis, then deleted or anonymized.
6. Your Rights
You can edit your profile or request account deletion. Some data (audit trail of point transactions, reports) may be retained to comply with operational policy.
7. Contact
For privacy questions, contact the site operator through the in-app support channel.
8. Payment Processing (Paddle, Google Play, Apple)
When you make a purchase on the website, payments are processed by our reseller and Merchant of Record, Paddle.com. Paddle collects the billing data needed to complete your payment (such as name, billing address, and payment-method details) under its own privacy policy. QuizNeko does not receive or store your full card number — we only receive a transaction record (order ID, product, amount, status) needed to grant your purchase and handle refunds. See Paddle's privacy policy.
In-app purchases in the Android app are processed through Google Play billing, and Google collects the billing data needed to complete the purchase under its own privacy policy. QuizNeko does not receive your card number; we receive only the transaction record needed to grant and refund points (order number, product, purchase token, purchase status). Our server queries Google's Play Developer API with the purchase token to verify purchases and detect refunds, and we do not send your IP address to Google for this.
In-app purchases in the iOS app are processed through Apple In-App Purchase, and Apple collects the billing data needed to complete the purchase under its own privacy policy. QuizNeko does not receive your card number; we receive only the transaction record needed to grant and refund points (transaction ID, product, purchase date, production or test environment, refund status). Each purchase is tied to your QuizNeko account by an anonymous account identifier (a random-looking UUID derived from your account), so it cannot be credited to a different account; this identifier does not reveal your identity to Apple. Our server queries Apple's App Store Server API with the transaction ID to verify purchases and receives App Store refund notifications, and we do not send your IP address to Apple for this.
9. Deleting your account
You can request deletion of your account from your profile page at any time. Deletion is not immediate: it takes effect 30 days after you request it, and you can cancel at any point during those 30 days by returning to your profile page. Simply logging back in does not cancel the request.
When the 30 days elapse, we erase or anonymise:
- your email address, name, nickname, date of birth, country and profile details (avatar, status message);
- your password and any linked Google, Apple or Metagrid sign-in;
- the IP address, browser user-agent and device fingerprint recorded at sign-up.
The following is kept, in a form no longer linked to you personally:
- Point ledger and payment records, as required for accounting, tax and audit obligations. Any remaining points are voided at deletion and cannot be restored or refunded.
- Quizzes and comments you posted, shown as authored by a deleted user. Removing them would corrupt the quiz history and scores of other users.
- A salted hash of your sign-up IP, used solely to prevent a deleted account from being re-registered to farm referral bonuses. It is not a raw identifier and is not used for any other purpose.
- A record that a deletion took place (dates only), so we can evidence that the erasure was carried out.
Last updated: 2026-09-15