Privacy Policy
Last updated: 9 October 2026
This policy explains what personal data Nothing To Lose collects at nothingtolose.live, why we collect it, who processes it for us, and what you can ask us to do with it. It covers hosts who sign up, participants who join an event from their phone, and visitors who only read the website. If anything here is unclear, please ask us.
1. Who is responsible for your data
GO ALL INC., trading as Nothing To Lose, is the controller of the personal data described here. This means we decide why and how it is used. Our registration details and address are in section 6 of our Support page.
Our Data Protection Officer, GO ALL INC. is responsible for this policy and answers your requests. To reach them, email nothingtolose.internal@gmail.com and put “Privacy” in the subject line.
2. Who this policy covers
- Hosts — people who create an account, build activities and launch events. Hosts must be 18 or older.
- Participants — people who join a host’s event on their own phone with a room code. Participants have no account. We never ask them for an email address.
- Visitors — anyone who reads the website without signing in.
3. What we collect and why
“Legal basis” is the GDPR term for the reason the law allows us to hold something. The Philippine Data Privacy Act and other laws have similar reasons. The “Why we have it” column is the same under all of them.
| Data | Why we have it | Legal basis |
|---|---|---|
| Email address and password (the password is hashed and stored by our sign-in provider). If you use Sign in with Google: your Google account ID, name and profile picture | To create your account, sign you in, reset your password and contact you about your account | Performance of our contract with you |
| Display name and chosen avatar | To show who you are in the builder and on your own screens | Performance of our contract |
| Your plan and the billing records Paddle sends us (listed in section 6) | To give you the features you paid for, apply plan limits, and handle refunds, plan changes, chargebacks and billing problems | Performance of our contract |
| The activities you build: event descriptions, categories, answers, prompts, timings | To save your work and run it at your event | Performance of our contract |
| Records of events you launched: when, which activity, how many joined, how long it ran | To show you your history, to help you when something goes wrong, and to plan our capacity | Performance of our contract; our legitimate interest in running a reliable service |
| Feedback you send us through the form in the product | To answer you and fix what you reported | Our legitimate interest in supporting and improving the product |
| Technical connection data: IP address at the time of a request, browser type, timestamps | To keep the service secure, apply rate limits and find faults | Our legitimate interest in security; legal obligation where records must be kept |
| Product analytics while you are signed in: pages viewed and features used, linked to your account number, plan and account type (never your email or name) | To learn which features hosts use | Our legitimate interest in improving the product |
| If you signed up after a campaign link: the campaign name, source and medium, saved on your account | To know which campaigns bring hosts | Our legitimate interest in understanding where our hosts come from |
| Error reports when something breaks, with email address and IP address removed. They may include your account number. | To find and fix the fault, including problems with your plan | Our legitimate interest in a working service |
“Gameplay data” means what a participant types or does while playing: their display name, answers, drawings, the squares they tag in Human Bingo, and their score. We collect it only when someone joins and plays.
| Data | Why we have it | Legal basis |
|---|---|---|
| Gameplay data | To run the activity: score each round, fill in Human Bingo cards, and show results on the shared screen | Our legitimate interest, and the host's, in running the activity you chose to join |
| A device identifier and a rejoin code stored on your phone | So you get back into the same seat if your phone loses the connection during the game | Our legitimate interest in the activity working |
| Connection timestamps and the session's progress log | To keep everyone on the same slide and to find faults afterwards | Our legitimate interest in the service working |
| Data | Why we have it | Legal basis |
|---|---|---|
| Anonymous product analytics: pages viewed and features used, with no personal profile | To learn which parts of the site work and which confuse people | Our legitimate interest in improving the product |
| One first-party attribution cookie, n2l_utm | To remember which campaign link brought you, so we know which campaigns work | Our legitimate interest in understanding where our visitors come from |
| Page performance timings | To find slow pages and fix them | Our legitimate interest in a usable site |
| Error reports when something breaks, with email address and IP address removed | To find and fix the fault | Our legitimate interest in a working service |
4. What we do not collect
- From participants we collect only gameplay data and technical connection data. We never ask participants for an email address, a phone number or an account.
- Photos taken during Human Bingo never leave the participant’s phone. They are saved in the browser’s own storage (IndexedDB) on the phone that took them. They are never uploaded to us, to our analytics, or to anyone else.
- We never see or store card numbers. Payment details go straight to Paddle (see section 6). If you choose to save your card, Paddle keeps it, not us.
- We do not sell personal data, and we do not share it for advertising. There is no advertising on the service.
- We do not profile you for advertising or make automated decisions about you. There is no targeted advertising, and no automated decision that has a legal or similarly serious effect on anyone.
- We do not ask for sensitive personal information, such as health, religion, ethnicity, political opinions, sexual orientation or government ID numbers. We ask hosts not to collect it through the service.
5. Content suggestions and OpenAI
When a host asks the builder for suggestions, we send OpenAI the host’s own event description and the category and answer text the host has typed. OpenAI sends back suggested content. The host then reviews, edits or deletes it.
Participant data never goes to OpenAI. We never send it gameplay data or Human Bingo photos.
If a host types personal information into an event description, that text is sent. So please keep descriptions about the event, not about named people.
6. Payments via Paddle
Paddle processes our payments. When you buy a plan, you give your payment and billing details to Paddle, not to us. Paddle is an independent controller of the data you give it at checkout. It handles that data under its own privacy policy: paddle.com/legal/privacy.
To set up your billing, we give Paddle your account email address and your account number with us. Paddle sends us back: your Paddle customer number and billing email; your plan, its status, and when it renews, changes or ends; and the reference numbers and amounts of your payments, credits and refunds, so we can find your purchase when you ask about it.
7. Who processes data for us
These companies run parts of the service for us. Each one has a contract with us that allows it to use data only on our instructions. Each one has its own privacy policy.
| Provider | What they do for us | Where they process |
|---|---|---|
| Supabase | Database, host sign-in, and the emails that confirm a sign-in or reset a password | United States and/or European Union |
| Vercel | Hosting for the website, and page performance metrics | United States and/or European Union |
| Cloudflare | Delivers video and media files on our website | United States and/or European Union |
| Upstash | Short-lived cache and rate limiting | United States and/or European Union |
| Ably | Realtime messaging between participants' phones, the host and the screen | United States and/or European Union |
| OpenAI | Turns the host's own event description into suggested game content | United States and/or European Union |
| PostHog | Product analytics | United States and/or European Union |
| Sentry | Error reports, scrubbed of email address and IP address | United States and/or European Union |
| Resend | Sends us an email when a host submits feedback | United States and/or European Union |
Google. If you choose Sign in with Google, Google confirms who you are and shares your name, email address and profile picture with us. Google acts under its own privacy policy.
Paddle. Paddle is our Merchant of Record and acts as an independent controller (see section 6).
8. International transfers
We are based in the Philippines. Most of our processors are in the United States and the European Union. So if you live outside the Philippines, your data crosses a border when you use the service.
These transfers are protected by the data protection terms in our contract with each provider. For every provider, the safeguard includes the European Commission’s Standard Contractual Clauses. The table shows the details for each one, including the terms for UK data. PostHog and Sentry are also certified under the EU–US Data Privacy Framework. We checked each provider’s agreement, and the Data Privacy Framework list, in September 2026.
| Provider | Safeguard for data leaving the EU/UK |
|---|---|
| Supabase | Standard Contractual Clauses and UK Addendum in its DPA |
| Vercel | Standard Contractual Clauses and UK IDTA in its DPA |
| Cloudflare | Standard Contractual Clauses in its DPA |
| Upstash | Standard Contractual Clauses (EU and UK) in its DPA |
| Ably | UK company; Standard Contractual Clauses and UK Addendum in its DPA |
| OpenAI | Standard Contractual Clauses and UK Addendum in its DPA |
| Paddle | UK company; Standard Contractual Clauses in its DPA |
| PostHog | EU–US Data Privacy Framework (active, with UK extension) plus Standard Contractual Clauses |
| Sentry | EU–US Data Privacy Framework (active, with UK extension) plus Standard Contractual Clauses |
| Resend | Standard Contractual Clauses (EU and UK) in its DPA |
9. How long we keep data
| What | How long |
|---|---|
| Event data — gameplay data, device ids and session logs | Deleted 12 months after the event ends. After that we keep only anonymous totals: how many people joined, how long the event ran, which activity was played, and round and category totals. None of these can identify a person |
| Host account data — email address, display name, plan, saved settings | Kept while the account exists; deleted within 30 days of a closure request |
| Saved activities a host has built | Kept until the host deletes them or closes the account |
| Billing records from Paddle (see section 6) | Kept while the account exists. When you delete your account, we keep only amounts and dates, with nothing that links them to you. |
| Payment records held by Paddle (invoices, tax records) | Kept by Paddle for as long as tax and accounting law requires. See Paddle's privacy policy. |
Backups are overwritten on their own schedule. So a deleted record can stay in a backup for a short time before it is overwritten.
11. Your rights
Wherever you live, you can ask us to: give you a copy of the personal data we hold about you; correct it; delete it; limit what we do with it; send it to you in a portable format; stop processing we base on legitimate interest; and withdraw any consent you have given.
How to ask: email nothingtolose.internal@gmail.com with “Privacy” in the subject line. If you have an account, write from its email address. We answer within 30 days. A person on our team handles every request.
If you are in the EU or the UK: these are your rights under the GDPR and the UK GDPR. You may also complain to your national data protection authority. In the UK, that is the Information Commissioner’s Office.
Representative in the EU and the UK. GO ALL INC. is established in the Philippines. When our activities there require it, we will appoint a representative under Article 27 of the GDPR and the UK GDPR and list their details here. Until then, please contact us directly at nothingtolose.internal@gmail.com.
If you are in California: you may ask what categories of personal information we collected about you, why, and who we shared it with. You may ask us to delete or correct it. We will not treat you worse for asking. We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of.
If you are in India: under the Digital Personal Data Protection Act, you may access and correct your data and ask us to erase it. You may name someone to use your rights if you cannot. You may also raise a grievance with us before going to the Data Protection Board. Send grievances to the same address. We handle them first.
Complaints: you can complain to the National Privacy Commission of the Philippines at privacy.gov.ph, or to the data protection authority where you live. You do not have to contact us first.
12. Children and young people
Participants of any age may join an event. The host running the event decides whether that is appropriate, not us.
Hosts are responsible for having the permission the law requires from parents, guardians, or the school or organization, for any participant below the age of digital consent where they live. That age is 18 in the Philippines, and in India for sensitive data; between 13 and 16 across the EU and the UK; and 13 in the United States.
From participants of any age, we collect only gameplay data and technical connection data. Human Bingo photos never leave the phone. There is no advertising, no profiling and no sale of data, at any age.
Host accounts must be held by someone 18 or older. If you believe a child has given us data through a host account, email nothingtolose.internal@gmail.com and we will delete it.
13. Security and breach notification
- All traffic uses HTTPS. HSTS stops browsers from falling back to an unencrypted connection.
- Row-level security is on for every database table, so one host’s data cannot be reached from another host’s session.
- Public routes have rate limits to slow down automated abuse.
- A Content Security Policy limits what the browser may load and run on our pages.
- Email addresses and IP addresses are removed from error reports before they reach us. We do not record session replays.
No system is perfectly secure. If a breach is likely to put people at risk, we notify the people affected and the National Privacy Commission within 72 hours, where the law requires it. We tell you what happened, what we know, and what we are doing about it.
14. Changes to this policy
We update this policy when what we do changes. Before an important change takes effect, we email hosts and show a notice on the site. The “Last updated” date at the top of this page always shows which version you are reading.
Questions? Email nothingtolose.internal@gmail.com or visit our Support page.