Last updated: 28 April 2026
Hi! Quick version: we keep just enough data to run the quiz, we don't sell anything, we don't track you around the web, your password is hashed so even we can't see it. The longer version below covers everything in plain English — if you live somewhere with privacy laws (UK, EU, most US states), the rights you'd expect are all here.
It's just The Bodach Show, run from the UK. We're the ones responsible for your data — technically the "data controller" if anyone asks.
If you've got a privacy question, want a copy of your data, or want it deleted, drop us a line at [email protected]. We read every one.
Whatever you give us when you sign up, plus the boring technical stuff needed to keep you signed in and stop bots.
That's it. No ad cookies, no tracking, no analytics, no third-party anything. Just enough to keep the site working.
Running the quiz, keeping you signed in, stopping bots and abuse, and emailing you about your account when something needs your attention.
| What we do | What we use | Why we're allowed (UK/EU) |
|---|---|---|
| Manage your account | Email, display name, password hash | Contract |
| Verify your email / reset your password | Email, code or token | Contract |
| Keep you signed in | Session token, browser fingerprint hash | Contract |
| Run the quiz, score it | Answers, votes, display name | Contract |
| Show leaderboards / Hall of Fame | Display name, scores | Legitimate interest |
| Stop bots and brute-force | IP hash, honeypot fields | Legitimate interest |
| Spot stolen sessions | Browser fingerprint hash | Legitimate interest |
What we don't do: marketing, advertising, profiling, automated decisions about you, or selling anything to anyone.
Nobody, in the "selling or trading" sense. Your data stays with us.
There are a few background helpers who have to touch it briefly to do their job:
They're all bound by data processing agreements and they can't use it for anything else.
The only exception is if a court legally orders us to hand something over — we'll comply but you'd be hard-pressed to find a reason that'd happen for a quiz site.
When you delete your account, all the personal stuff is gone for good.
We can't promise something is unhackable (nobody honestly can), but we follow the boring sensible defaults that mostly stop the bad guys.
Our servers live in the UK. If you log in from somewhere else, your data still rests on UK infrastructure — the protections don't change based on where you are.
If we ever have to move data outside the UK or EEA, we'd use the standard legal safeguards (Standard Contractual Clauses, or destinations the regulators have already cleared).
If you're in the UK or EU, the law gives you a bunch of rights and we're not going to argue with any of them:
Email [email protected] for any of these. We'll get back to you within a month.
If you're not happy with how we handle it, you can complain to:
If you live in a US state with a privacy law, you've got pretty much the same rights as the UK/EU folks above. Loads of states have passed these now — California started it and most of them copy the same playbook:
In CCPA terms, here's what falls into each bucket:
| Category | What that means here | We collect? |
|---|---|---|
| Identifiers | Email, display name, IP (hashed) | Yes |
| Internet activity | Browser type (hashed), login times | Yes |
| Login credentials | Email/username + password hash | Yes |
| Geolocation | — | No |
| Audio / visual | — | No |
| Job info | — | No |
| Biometric | — | No |
| Sensitive personal info | — | No |
Depending on your state, some or all of these apply:
To use any of these, email [email protected]. We'll verify it's actually you (don't want to delete the wrong person's account) and reply within whatever your state's deadline is — usually 45 days.
We don't. We never have. We won't.
Since we don't track anyone in the first place, GPC signals don't change what we do — we already aren't tracking you.
You can have someone act on your behalf. We'll need proof you actually authorised them and we may need to confirm your identity directly too.
None. We don't reward you for sharing data and we don't penalise you for not.
This isn't aimed at kids under 13 (16 in some places). We don't knowingly collect anything from them. If you're a parent or guardian and reckon your kid signed up anyway, email us and we'll wipe the account.
Nope. Nothing automated decides anything about you that matters. Rate-limiting bots and adding up your quiz score is the closest we get and neither of those legally counts as "profiling".
If we make a real change (not just a typo fix) we'll post a notice in the app and update the date at the top of this page. If it materially affects you we'll email you too.
Carrying on using the site after a change means you're OK with it. Don't agree? You can delete your account any time and we'll wipe everything.
Anything privacy-related — questions, complaints, requests — email [email protected]. We won't dodge the question.
If you're not happy with our reply, you've got an escalation path through your local supervisory authority (see sections 8 and 9).