Privacy policy
Last updated: 18 August 2026
1. Who we are
INTAYO is published by CWC Solutions LLC, a limited liability company under the law of the State of Wyoming, 1309 Coffeen Avenue, Suite 1200, Sheridan, WY 82801, USA. We are an American company and we operate under the law of the United States; that is where we answer and where we can be held to account. The service is open to users everywhere. If you live elsewhere, we grant you the rights your law gives you — set out in sections 15 to 17. Full provider details are in our legal notice.
2. Information we collect
- Account data: email address, display name, optionally username, phone number, profile picture and short bio.
- Content: claims, counter-claims, uploaded evidence, comments and ratings.
- Usage data: wins, losses, streaks, ranks and outstanding honor debts.
- Technical data: sign-in sessions and, if you enable push, a device token from your browser.
- Operational log: to notice malfunctions, our server records error messages — time, affected part of the program and reason for the error. This log deliberately contains no names, email addresses or IP addresses; any reference to you appears only as a non-reversible short code. It stays on our own server, is not shared with anyone and is deleted after 30 days.
- Evidence uploads: images and videos you upload for a challenge or to settle an honor debt, together with the time and the link to that challenge. They are stored in the file storage on our own server.
- Audience measurement: pages viewed, time, device type, browser, language, the referring page, and an approximate origin derived from a truncated IP address. How this works in detail and how to switch it off is set out in section 8.
- Session recording: in the web interface we record how a visit unfolds — pages opened, clicks, scrolling, how the page changes and error messages from your browser. What you type into form fields is expressly excluded. What is captured, what is left out and how to switch the recording off is set out in section 8.
- Payment data: only for a paid subscription — card brand and last four digits. We never see full card details. Sales and billing are handled by Paddle as merchant of record; Stripe remains a fallback for existing subscriptions. No payment data arises for challenges or honor debts; no money flows through them.
3. How we use it
We use the data to run the service: maintain accounts, associate challenges, notify you about events, track outcomes and honor debts, measure reach, and prevent abuse. We do not sell data, we do not share it for anyone else’s advertising and we do not serve personalized advertising. How this relates to the rules in Europe and Switzerland is set out in section 15.
4. Decisions made by AI
If the two of you cannot agree on the outcome of a challenge, you can have an AI decide. That is your choice — it never happens automatically in the background. Before it starts you see a notice in the app, and you can instead keep working towards an agreement or later have a human decide.
The following is transmitted: the display names of both sides, the claim and the counter-claim, the evidence texts you submitted, and the addresses of uploaded evidence files. We do not upload the images and videos themselves into the AI, and the address alone is not enough to retrieve a file — the file storage is not public (section 5).
The request runs through an AI gateway we operate and from there to the respective language model. The provider processes the data under our instructions and solely to produce a proposed outcome; it may not use it for its own purposes. Processing also takes place outside your state of residence, including in the United States. Which model is used depends on your plan and may change. We do not keep the request and the result on file with the provider — what stays in the app is the reasoning that both of you get to see.
The AI only decides the outcome of a game. It has no legal consequences for you — the outcome is not an enforceable title. If you do not accept the result, a human referee can decide afterwards; that route is always available.
Public challenges additionally pass an automated check for prohibited content, during which detected personal details are redacted. For that reason, do not submit anything you would not want processed — and nothing about third parties without their consent.
5. Evidence files
Uploaded images and videos are stored in the file storage of our own server. That storage is not public: the address of a file alone is not enough to retrieve it. Anyone allowed to view a file receives an individually issued link when opening it, which expires after a few minutes. That applies to the two participants of the challenge or honor debt — and, where needed for a support request, to us.
Even so, treat evidence files as something you give away: do not upload anything concerning third parties or anything you would not want passed on. We delete your own evidence files together with your account (section 9); your counterpart’s files remain, because they are not your data.
6. Sharing with service providers
We share data only as required to operate the service:
- Paddle — sale and billing of paid services as merchant of record. Paddle is the seller, issues the invoice and remits the tax; we only receive the details needed for activation.
- Stripe — fallback for existing subscriptions. Not used for challenges or honor debts.
- Mailgun — delivery of system and notification emails.
- AI provider — for the decision and content check described in section 4 and, on the Plus plan, for stylising the profile photo: the uploaded photo is transmitted to the provider for processing and is not stored there; we keep only the generated image (at most the current and the previous one), never the original.
- Cloudflare Turnstile — protects guest access against automated requests. Cloudflare processes technical signals: IP address, TLS fingerprint, user agent, and the site key with its origin. The check serves solely to tell humans from bots, not to identify individuals; Cloudflare acts on our instructions. Details are in the Turnstile Privacy Addendum.
- Google Analytics 4 — audience measurement for the website and the app’s web interface. Google processes the usage data listed above and sets an identifier in your browser; advertising features and sharing for advertising purposes are switched off (section 8).
- Matomo — the same measurement on our own infrastructure, cookie-free and with a truncated IP address. That data never leaves our servers.
We operate our database, our file storage and the session recording described in section 8 on our own infrastructure; for those three there is no recipient other than ourselves. Product suggestions for stakes contain affiliate links to Amazon and eBay; if you follow them, the respective provider’s privacy terms apply.
7. Calendar subscription
You can subscribe to your challenge deadlines as a calendar. To do so we generate a personal, random address. Anyone who opens that address receives your open deadlines including the claim, the opponent’s name and the stake — no password is requested, the address itself is the key.
If you enter the address into a calendar service, that provider — for example Apple, Google or Microsoft — retrieves it regularly and stores the events. Treat it like a password and do not share it.
Access is read-only; no actions can be taken through it. In your settings you can switch the subscription off at any time or generate a new address — the old one becomes invalid immediately.
8. Cookies, audience measurement and session recording
For sign-in we use strictly necessary cookies; without them the service does not work. On the guest flow an equally necessary cookie from Cloudflare Turnstile is added for the bot check (section 6). Your chosen language and the state of the install prompt are kept locally by your browser — that information never leaves your device. We set no advertising cookies.
To see how the service is used, we measure reach with two tools. Matomo runs on our own infrastructure, expressly without cookies and with a truncated IP address; it does not recognise you between visits. Google Analytics 4, by contrast, sets an identifier in your browser and transmits the usage data to Google, including to the United States (section 13). Advertising features and sharing for advertising purposes are switched off there, and we do not link the measurement to your account.
Under the law where we are based this measurement needs no prior consent, and we will not put a consent window in your way. Instead we tell you here what happens and you decide — at any time, with one click: the switch at the end of this section stops Google Analytics and the session recording and deletes the identifiers your browser holds up to that point. Your decision stays in your browser and never reaches our servers. The cookie-free count with Matomo runs either way — it does not touch your device.
Independently of the switch you can also block Google Analytics through your browser settings or through the opt-out add-on Google provides; inside the installed app this measurement does not take place at all, and Matomo does not recognise you as it sets no cookie.
One moment …
Alongside audience measurement we record how visits to the web interface unfold, in order to find faults and improve the way things work. The tool is called OpenReplay and runs on our own server in Germany; the recordings never leave our infrastructure and no third party sees them. What is kept: pages opened, clicks, scrolling, how the page changes and error messages from your browser. So that the parts of a running recording belong together, the tool stores random identifiers in your browser; one of them survives closing the browser and ties a later visit to the same identifier. It is not linked to your account, and if you switch measurement off we delete it straight away.
What does not go in: we do not record what you type into form fields, and the tool masks email addresses and numbers in visible text. On pages whose address carries an access key — sign-in link, invitation, password reset, deletion page — the recording does not start at all, and it stops the moment you open such a page. We do not write an identifier of your account into the recording; what is visible on your screen, however, is visible in it. Inside the installed app nothing is recorded.
If your browser sends the “Do Not Track” signal we do not record at all — that is the switch that turns it off. While you have the web interface open our support team can also watch a session live to help with a malfunction; taking control of your browser asks your explicit permission every time. The recordings serve only fault-finding and improving the way things work, and they are deleted automatically no later than 30 days after your visit. We will delete them sooner on request through our support page.
9. Retention and deletion
You can delete your account at any time — at the bottom of Settings, or, even without the app installed, through our deletion page.
This removes credentials, name, email address, username, phone number, profile picture, short bio, notifications, badges, push registrations and the payment link. The evidence files you uploaded yourself are deleted as well — for challenges and for honor debts alike. Past challenges and outstanding honor debts remain as records, because they are equally part of your opponents’ history; there you will appear only as a “deleted user” with no reference to your identity. Your counterpart’s evidence files also remain, because they are their data and not yours. If one of them concerns you, contact us through the support page.
Beyond that we clean up regularly, without you having to do anything:
- Account data: until you delete your account.
- Notifications: read ones after 24 hours, unread ones after 30 days.
- Operational log: 30 days, deleted automatically thereafter.
- Backups: 30 days (section 10).
- Challenges, outcomes and honor debts: permanently, with no reference to you after an account deletion.
10. Backups
So that nothing is lost after an outage, we back up the database and the file storage once a day. These backups stay on our own server, go to no one else and are deleted after 30 days. If you delete your account or a piece of content, that takes effect immediately in live operation; the copies disappear from backups only once the affected snapshots expire, after 30 days at the latest. We touch a backup only to restore after damage.
11. Children
The service is not intended for children. The minimum age is 13. Where the law of your home requires more — up to 16 in the European Economic Area depending on the country, and capacity of judgement in Switzerland —, that age applies. Anyone younger must not create an account; we do not knowingly collect data from such children. If we learn of such an account, we delete it together with its content. Parents and guardians can reach us through the support page.
12. Security
All traffic is encrypted in transit, passwords are stored only as hashes, and data access is restricted per user at the database level. That said, no service can promise absolute security.
13. Where we process and when data leaves the country
Database, file storage, operational log, the cookie-free measurement with Matomo and the session recording run on our own servers in data centres in the European Union. We ourselves are based in the United States; our administration accesses the service from there.
A service used all over the world cannot avoid cross-border transfers. The providers named in section 6 — in particular Paddle, Stripe, Mailgun, Cloudflare, Google and the AI providers — also process data outside your country, including in the United States. There, authorities may demand access under the law of the recipient country, and we cannot prevent that.
For data reaching us from Europe or Switzerland: where an adequacy decision covers the recipient we rely on it — for certified US companies on the EU-US and Swiss-U.S. Data Privacy Framework respectively — and otherwise on the usual standard contractual clauses together with the addenda for the United Kingdom and Switzerland. On top of that we assess the situation in the recipient country and keep the transfer encrypted throughout. You can obtain a copy of the safeguards on request.
You can obtain a copy of the safeguards on request through the support page.
14. Your rights
Wherever you live, you may ask us to:
- tell you which data we process about you, and give you a copy.
- correct inaccurate data and complete incomplete data — much of which you can do yourself in Settings.
- delete your data, and restrict processing while a dispute about its accuracy is running.
- hand over the data you provided in a common, machine-readable format and, where technically feasible, transmit it to another provider.
- object to processing we base on a legitimate interest, and withdraw consent with effect for the future.
To do so, contact us through the support page or, if it is only about deletion, through the deletion page. We answer within one month; if it turns out to be complex, we tell you beforehand and extend by at most two further months. Handling is free of charge and costs you nothing inside the service. So that nobody can obtain someone else’s data, we verify your identity first — usually through the email address on the account. An authorised agent may act for you on proof of authorisation.
There is one limit: completed challenges and outstanding honor debts are equally part of your counterpart’s history. They therefore remain, but you appear there only as a deleted user (section 9).
15. Europe, United Kingdom and Switzerland
We are an American company with no establishment in Europe. If you live there, we nonetheless grant you the rights provided by the General Data Protection Regulation, the UK GDPR and the Swiss Data Protection Act — not because a foreign authority holds us to them, but because they match what we do anyway. We have not appointed a representative in the Union: anyone who wants something from us goes to the same place as every other user, our support page or the Wyoming address given above.
What we process for which purpose, in the language of those rules:
- To perform our contract with you: running your account, tracking challenges and honor debts, notifying you, providing paid plans, giving support.
- On the basis of legitimate interests: preventing abuse and fraud, protecting guest access against bots, detecting malfunctions, taking daily backups, measuring reach, and bringing and defending legal claims. Our interest is secure and reliable operation; we have weighed opposing interests and you may object at any time.
- With your consent: push notifications, the calendar subscription and the decision by an AI. You may withdraw it at any time; what happened until then remains lawful.
- To comply with legal obligations: retaining commercial records and answering legitimate requests from authorities.
We take no automated decision producing legal effects. The AI ruling starts only if you expressly ask for it, concerns only the outcome of a game and is not an enforceable title; if you do not want to accept the result, a human decides on request (section 4). In any case you only have to provide what the account needs — essentially a valid email address.
If you want to complain, talk to us first — that is quicker than any official route. If you insist, the competent body is the supervisory authority where you live in the European Economic Area, the Information Commissioner’s Office in the United Kingdom, and the Federal Data Protection and Information Commissioner in Switzerland.
16. United States: California and other states
If you live in California, the California Consumer Privacy Act as amended by the CPRA applies; comparable rights are granted by Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky and Rhode Island, among others. We apply this section to all users in the United States.
In the past twelve months we collected the following categories: identifiers (name, email address, phone number, account identifier, IP address), customer records (card brand and last four digits), commercial information (plan and purchases), internet activity (usage and measurement data per section 2), audio, visual and video recordings (your evidence files), approximate location from the IP address, and inferences (ranks, points, streaks). They come from you, from your counterpart, from your device and from our providers; what we use them for is in section 3, who receives them in section 6, and how long we keep them in sections 9 and 10.
We do not sell personal information and we do not share it for cross-context behavioral advertising — neither for adults nor for anyone under 16. We do not ask for sensitive information; whatever you upload as evidence yourself, we use solely to run the challenge and never to infer characteristics about you. A right to limit the use of sensitive information therefore has nothing to bite on here. For the same reason a “Global Privacy Control” signal from your browser changes nothing: there is no sale and no sharing for it to object to.
You may ask what we collected and where it came from, obtain a copy, and have it corrected or deleted. How to do that is set out in section 14. We do not discriminate against you for exercising these rights: prices, features and points stay the same. If we deny a request you may appeal to us; we will review the matter again and give you the outcome with reasons, together with the route to complain to the competent body in your state — in California the California Privacy Protection Agency or the Attorney General.
On California’s “Shine the Light” law: we do not disclose personal information to third parties for their own direct marketing.
17. Other countries
Outside Europe and the United States too, we abide by what the law of where you live requires of us. We grant the rights in section 14 to all users, wherever they live and whether or not their law expressly provides them.
- Brazil: in addition to the rights in section 14, the LGPD lets you request confirmation of processing, anonymisation and information about shared data; the complaints body is the ANPD.
- Canada: PIPEDA applies, supplemented in Québec by Law 25; complaints go to the Office of the Privacy Commissioner of Canada and the Commission d’accès à l’information.
- Australia and New Zealand: the Australian Privacy Principles and the Privacy Act apply; complaints go to the OAIC and the New Zealand Privacy Commissioner.
- Japan, South Korea, India and South Africa: the APPI, PIPA, the Digital Personal Data Protection Act and POPIA apply, with the rights of access, correction and deletion they provide.
If the law of your country gives you more than is set out here, you get it — contact us through the support page.
18. If something goes wrong
If we detect a breach of data security, we investigate it at once, close the gap and record what happened. Where there is a high risk to you, we tell you without delay. We notify the competent bodies within the deadlines that apply in each place — in the United States under the law of the state, in Europe within 72 hours, in Switzerland as soon as possible.
19. Changes
We may update this policy as the service changes. The date above reflects the current version; we will announce material changes in the app.
20. Contact
Questions about privacy, requests under section 14 and complaints are handled through the support page. In writing you can reach us at [email protected] or at CWC Solutions LLC, 1309 Coffeen Avenue, Suite 1200, Sheridan, WY 82801, USA. Please quote the email address of your account so that we can identify you.
See also: Terms of service · Legal notice