Rowdy
Privacy Policy
Last updated August 18, 2026
Rowdy is a social party game for crews of 2–8 — you hand dares to your crewmates instead of doing them yourself. This page explains what we collect, what we deliberately don’t, and what you can do about it. It’s written by the person who built the app, not a law firm, and it describes what the software does today rather than what it’s planned to do.
1. Where things stand
The Rowdy app hasn’t launched. Right now the only thing that exists publicly is this website, and the only thing this website collects is a waitlist email address if you choose to give us one. Sections 3 and onward describe the app, which you can’t download yet; they’re here so you can read them before you sign up for anything, and we’ll update this page before the app ships if any of it changes.
2. Who this covers
This policy covers the Rowdy mobile app and getrowdy.app. They’re operated by Alexander Hoogland and our mailing address for legal notices is 8401 Mayland Drive, Suite S, Richmond, VA 23294, USA.
3. This website
- Your waitlist email address, if you submit the form — plus which page you submitted it from and the time you did. That’s the whole record. We use it for exactly one thing: to email you once, when Rowdy launches.
- How long we keep it. Until we’ve sent that launch email, or until you ask us to remove you — whichever comes first. If Rowdy never ships, we’ll delete the list rather than sit on it. Ask at any time and we’ll take you off it by hand, normally within a few days and at the outside within 30.
- No analytics, no ad pixels, no cookies. This site sets no cookies of its own and loads no third-party scripts. Fonts are served from our own domain rather than a font CDN, specifically so that visiting this page doesn’t hand your IP address to anyone else.
- Server logs. Our host records ordinary request logs (IP address, time, page) as part of serving the site and defending it from abuse. We don’t build profiles from them.
4. The app, once it ships
Rowdy asks for the minimum needed to run a night, and not much more:
- Email address — to create your account, sign you back in, and (if you ask for one) send a password reset.
- Display name — what your crew sees on cards, quests, and recaps. Doesn’t have to be your legal name.
- Date of birth — used once, on your device. At sign-up we ask for your birthday to work out whether you’re 18+ (required to use Rowdy at all) and 21+ (required for bar-context nights). The calculation happens on your phone and only the two true/false answers are sent to us. The date itself never leaves the device and is never stored, so we can’t look it up or hand it to anyone.
- Quest activity — which dares get assigned, to whom, whether they’re accepted, completed, verified, or declined, plus the XP, Schmeckels, and cards that activity earns. This is the core gameplay loop and we keep a record of it the same way any game keeps a record of what you’ve played.
- Crew & night data — who’s in a crew with you, which nights you’ve joined, and the join code used to get in.
- Your boundaries — visible to your crew. When you start or join a night you pick the categories of dare you don’t want handed to you. Those selections are sent to everyone else in that night, because the app has to stop them dealing you a card that conflicts with one. Treat a boundary as something the people in the room can see, not as a private setting.
- Reports & blocks — if you report something or block someone, we keep a record of it. See section 6 for what that does and doesn’t currently do.
5. Photos
Some quests are written to be proved with a photo, and the app’s data model has a place to attach one. Photo upload isn’t built yet. The app cannot currently take, upload, or store a photo, and we hold none. When it does ship, uploading one will be optional, the photo will be visible to the crew you played that night with rather than published, and this page will say so before the feature is switched on rather than after.
6. Reporting and blocking, honestly
The rules in our Community Guidelines are real and we’ll enforce them. The tooling is not all there yet, and you should know which parts:
- In-app report and block controls aren’t built. The backend records both, but no screen in the app calls it yet. Until that lands, the way to reach us is support@getrowdy.app, which is read by a person.
- A block is recorded, not yet enforced. Today blocking stores your decision; it does not yet stop that person being placed in a crew with you. We’re not going to describe it as protection until it is.
- Reports we do receive are read and acted on by hand. We’re one person pre-launch, so we won’t promise a response time we can’t keep — anything involving someone’s safety goes to the front of the queue.
7. What we don’t do
- We don’t sell your data. Not to advertisers, not to data brokers, not to anyone.
- We don’t run third-party ad trackers, in the app or on this site.
- We don’t receive your birthday at all — see section 4.
8. Who else sees it
We use a small number of infrastructure providers, all bound to protect your data and use it only to provide the service:
- Supabase hosts our database and authentication. Your account data, quest activity, and the waitlist list itself live there.
- Vercel hosts this website and handles the requests you make to it.
- Apple and Google will handle app distribution once Rowdy is released, and if a paid subscription is ever offered they process that payment directly — Rowdy never sees or stores card details. Neither has anything to do with you today, because there is nothing to download.
We don’t share your data with anyone else unless the law requires it.
9. How long we keep it, and deleting it
Waitlist retention is in section 3. For app accounts, we keep your data for as long as your account is active.
There is no self-serve delete button in the app yet. Deletion today is a manual job: email support@getrowdy.app from the address on the account, we’ll confirm it’s you, and we’ll delete your profile and the activity attached to it within 30 days — sooner in practice, since it’s one person doing it directly. We’ll keep something longer only where we’re required to (for example, records tied to an active abuse report). Quest activity that forms part of someone else’s night may persist for them after your account is gone, with your identifying details removed.
10. Your rights
You can ask us to access, correct, or delete your personal data at any time by emailing support@getrowdy.app. We’ll verify it’s really you and respond within 30 days. If you’re in a jurisdiction with a specific legal framework for this (GDPR, CCPA, or similar), tell us and we’ll handle your request under that framework.
11. Age requirements
Rowdy is 18+. We don’t knowingly collect information from anyone under 18. Bar-context nights additionally require everyone in them to be 21+, checked the same way as the 18+ gate — once, at sign-up, without the birthday behind it ever reaching us. If you believe a minor has created an account, email us and we’ll remove it.
12. Security
We use industry-standard practices (encryption in transit, access controls, row-level security on our database) to protect your data. No system is perfectly secure, and we can’t guarantee absolute protection — but we treat a breach of your data as seriously as we’d want ours treated, and we’ll notify you if one ever affects you.
13. Changes to this policy
If we materially change what we collect or how we use it, we’ll update the date at the top of this page and, for significant changes, email you directly.
14. Contact
Questions, requests, or concerns: support@getrowdy.app.