Privacy notice: How Picky Am I?

Last updated: 25 September 2026

In short: there are no accounts, no cookies, no ads and no tracking. Like every website, my server receives some technical data with each request, such as your IP address. Apart from that, the only thing it receives is the text of any rule you type. It sends that text to an AI service in the United States so the game can understand it, without your IP address. Your swipes, your results, the name you put on your card and the pool you pick (women, men or everyone) stay on your device. If you share a challenge link or a share image, it goes wherever you send it.

1. Who is responsible

I am Artur P., a private individual living in Poland. I run How Picky Am I? at picky.withartur.io as a free, non-commercial project. Under the EU General Data Protection Regulation (GDPR), I am the "controller" of your personal data.

Contact: privacy@withartur.io

2. What I process, why, and for how long

Rules you type

What happens. You can add a rule in two ways:

Why, and my legal basis. I need your rule to run the game you asked to play, under the terms of use (Art. 6(1)(b) GDPR).

Please don't type names, contact details, anything about real people, or anything about your own health, religion, ethnicity, sexual orientation or sex life. The game doesn't need any of it.

How long I keep it.

Your IP address

What happens. Every website receives the IP address of whoever visits it. My app uses yours for one thing only: to limit how many rules can be sent from one address in a short time. This protects the game against abuse and runaway AI costs.

Legal basis. My legitimate interest in keeping a free service secure and affordable (Art. 6(1)(f) GDPR).

How long I keep it.

What stays on your device

I never receive:

Your browser also keeps a few things on your device so the game works well:

None of this is sent to me. You can delete it at any time by clearing this site's data in your browser settings.

Challenge links and share images

When you tap "Challenge a friend", the link contains:

It doesn't contain your rules or your pool choice. This information sits in the part of the link after "#". Browsers don't send that part to my server, so I don't receive it. It is encoded, not encrypted: anyone who has the link can read it.

When you tap "Share my result", your device draws a picture showing your rules, your score, your verdict and how many times you broke your rules while swiping. It doesn't show your name. It is made on your device and I don't receive it.

You decide whether to share either of them, and with whom.

3. Who else receives data

OpenRouter, Inc. (USA) receives the text of typed rules that the cache can't answer. My server sends it, so OpenRouter never sees your IP address. OpenRouter passes the text to the AI model and returns the answer. It acts as my processor under its data processing agreement, which is part of its terms of service. I have prompt logging switched off. OpenRouter then keeps the text of requests only as far as it needs to prevent abuse and meet legal obligations.

TypeSafe (USA) makes Jev, the AI model that reads your rule. OpenRouter uses TypeSafe as its model provider for these requests, so TypeSafe is OpenRouter's sub-processor. I have no contract with TypeSafe myself. TypeSafe says it does not train its models on the requests it receives. It may keep requests for as long as it needs them to run and secure its service.

Contabo GmbH (Germany) hosts my server in a data centre in Germany. As the hosting provider, it could technically access what is on the server. It acts as my processor under a data processing agreement I have concluded with it.

I don't sell data, I don't show ads, and I don't share data with anyone else.

4. Transfers outside the EU/EEA

The rule text sent to the AI is processed in the United States. The transfer to OpenRouter is covered by the European Commission's Standard Contractual Clauses (Module 2, controller to processor; Art. 46(2)(c) GDPR). They are part of OpenRouter's data processing agreement: https://openrouter.ai/data-processing-agreement. Under those clauses, OpenRouter is responsible for giving the same protection to the data it passes on to TypeSafe. You can also ask me for a copy.

5. AI, and the people in the game

Everyone in the game is fictional. Their photos were generated with AI (Google Gemini) and their bios were written with AI. All of this happened when I built the game. None of your data goes to Google.

An AI model decides whether each fictional person matches your rule. It reads their written profile, not their photo. The profile gives their age, height, habits and bio, plus a short written description of their looks. The AI makes no decisions about you, and the results are only for fun.

6. Age

The game is for adults (18+). It is not meant for children, and I don't knowingly process children's data.

7. Cookies and tracking

The game uses:

The only things stored on your device are the ones described in section 2 under "What stays on your device". The game needs them to work the way you asked. If any of this changes, I will update this notice first, and I will ask for your consent where the law requires it.

8. Your rights

Under the GDPR, you can ask me to:

You can also object to processing that I base on my legitimate interest (Art. 21). To do any of this, email privacy@withartur.io.

There are no accounts, and I don't link rule text to IP addresses or to anything else about you. So I usually can't tell which data is yours. If you tell me the exact rule text, I can remove it from the cache straight away.

You also have the right to complain to a data protection authority, either the one in Poland or the one where you live or work. In Poland that is UODO, the Personal Data Protection Office (uodo.gov.pl).

9. Changes

If the game changes how it uses data, I will update this page and change the date at the top.

Back to the game