Privacy notice: How Picky Am I?
Last updated: 25 September 2026
In short: there are no accounts, no cookies, no ads and no tracking. Like every website, my server receives some technical data with each request, such as your IP address. Apart from that, the only thing it receives is the text of any rule you type. It sends that text to an AI service in the United States so the game can understand it, without your IP address. Your swipes, your results, the name you put on your card and the pool you pick (women, men or everyone) stay on your device. If you share a challenge link or a share image, it goes wherever you send it.
1. Who is responsible
I am Artur P., a private individual living in Poland. I run How Picky Am I? at picky.withartur.io as a free, non-commercial project. Under the EU General Data Protection Regulation (GDPR), I am the "controller" of your personal data.
Contact: privacy@withartur.io
2. What I process, why, and for how long
Rules you type
What happens. You can add a rule in two ways:
- By tapping a suggested rule. It is applied on your device and never leaves it.
- By typing a rule. Your browser sends the text to my server. My server first replaces email addresses, social media handles and phone numbers with placeholders. Then:
- Number rules such as "under 32" are worked out on my server, without any AI.
- If someone has typed the same rule before, the answer comes from my cache and nothing is sent to the AI.
- Otherwise my server asks an AI model what the rule means. If the rule doesn't match one of the game's standard rules, or you choose to keep it exactly as you typed it, my server also asks the AI which of the fictional people in the game meet it.
Why, and my legal basis. I need your rule to run the game you asked to play, under the terms of use (Art. 6(1)(b) GDPR).
Please don't type names, contact details, anything about real people, or anything about your own health, religion, ethnicity, sexual orientation or sex life. The game doesn't need any of it.
How long I keep it.
- In a cache on my server. The cache stores the cleaned rule text and the answer, with no IP address and nothing else that identifies you. It means the same rule doesn't have to go to the AI twice, which keeps the game fast and cheap to run. That is my legitimate interest (Art. 6(1)(f) GDPR). I empty the cache on the 1st of every month, so nothing in it is older than about a month.
- Not in my logs. The app's technical log records that a rule was handled, how long it was and what it cost, but not its text.
Your IP address
What happens. Every website receives the IP address of whoever visits it. My app uses yours for one thing only: to limit how many rules can be sent from one address in a short time. This protects the game against abuse and runaway AI costs.
Legal basis. My legitimate interest in keeping a free service secure and affordable (Art. 6(1)(f) GDPR).
How long I keep it.
- The app keeps it in memory only. It never writes it to disk and never sends it to the AI service. It forgets it about 10 minutes after your last request, or sooner if the app restarts.
- My web server keeps no access log for this game.
- If a request fails with an error, my web server's error log may record the IP address and browser details of that request. That log is deleted within 31 days.
What stays on your device
I never receive:
- your pool choice (women, men or everyone)
- your swipes
- your results
- the name you put on your card
Your browser also keeps a few things on your device so the game works well:
- A copy of the game's files and of the pictures you've seen. This makes the game load quickly and lets it open on a poor connection. These files contain nothing about you, and each new version of the game replaces them.
- Two small notes in your browser's local storage. They record whether you added the game to your home screen or closed the "add to home screen" suggestion, so the suggestion doesn't keep coming back.
None of this is sent to me. You can delete it at any time by clearing this site's data in your browser settings.
Challenge links and share images
When you tap "Challenge a friend", the link contains:
- the name you chose (or "A friend" if you left it empty)
- your score
- your pickiness verdict
It doesn't contain your rules or your pool choice. This information sits in the part of the link after "#". Browsers don't send that part to my server, so I don't receive it. It is encoded, not encrypted: anyone who has the link can read it.
When you tap "Share my result", your device draws a picture showing your rules, your score, your verdict and how many times you broke your rules while swiping. It doesn't show your name. It is made on your device and I don't receive it.
You decide whether to share either of them, and with whom.
3. Who else receives data
OpenRouter, Inc. (USA) receives the text of typed rules that the cache can't answer. My server sends it, so OpenRouter never sees your IP address. OpenRouter passes the text to the AI model and returns the answer. It acts as my processor under its data processing agreement, which is part of its terms of service. I have prompt logging switched off. OpenRouter then keeps the text of requests only as far as it needs to prevent abuse and meet legal obligations.
TypeSafe (USA) makes Jev, the AI model that reads your rule. OpenRouter uses TypeSafe as its model provider for these requests, so TypeSafe is OpenRouter's sub-processor. I have no contract with TypeSafe myself. TypeSafe says it does not train its models on the requests it receives. It may keep requests for as long as it needs them to run and secure its service.
Contabo GmbH (Germany) hosts my server in a data centre in Germany. As the hosting provider, it could technically access what is on the server. It acts as my processor under a data processing agreement I have concluded with it.
I don't sell data, I don't show ads, and I don't share data with anyone else.
4. Transfers outside the EU/EEA
The rule text sent to the AI is processed in the United States. The transfer to OpenRouter is covered by the European Commission's Standard Contractual Clauses (Module 2, controller to processor; Art. 46(2)(c) GDPR). They are part of OpenRouter's data processing agreement: https://openrouter.ai/data-processing-agreement. Under those clauses, OpenRouter is responsible for giving the same protection to the data it passes on to TypeSafe. You can also ask me for a copy.
5. AI, and the people in the game
Everyone in the game is fictional. Their photos were generated with AI (Google Gemini) and their bios were written with AI. All of this happened when I built the game. None of your data goes to Google.
An AI model decides whether each fictional person matches your rule. It reads their written profile, not their photo. The profile gives their age, height, habits and bio, plus a short written description of their looks. The AI makes no decisions about you, and the results are only for fun.
6. Age
The game is for adults (18+). It is not meant for children, and I don't knowingly process children's data.
7. Cookies and tracking
The game uses:
- no cookies
- no analytics
- no advertising
- no third-party scripts, fonts or embeds
The only things stored on your device are the ones described in section 2 under "What stays on your device". The game needs them to work the way you asked. If any of this changes, I will update this notice first, and I will ask for your consent where the law requires it.
8. Your rights
Under the GDPR, you can ask me to:
- give you access to your personal data (Art. 15)
- correct it (Art. 16)
- delete it (Art. 17)
- restrict how I use it (Art. 18)
- give you the data you provided in a machine-readable format, or pass it to someone else (data portability, Art. 20)
You can also object to processing that I base on my legitimate interest (Art. 21). To do any of this, email privacy@withartur.io.
There are no accounts, and I don't link rule text to IP addresses or to anything else about you. So I usually can't tell which data is yours. If you tell me the exact rule text, I can remove it from the cache straight away.
You also have the right to complain to a data protection authority, either the one in Poland or the one where you live or work. In Poland that is UODO, the Personal Data Protection Office (uodo.gov.pl).
9. Changes
If the game changes how it uses data, I will update this page and change the date at the top.