Privacy policy
Last updated: 03/10/2026
Welcome to Would you rather. We are committed to protecting your privacy and your personal data. This privacy policy explains how we collect, use, share and protect your personal information, in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.
1. Data controller
The controller of the personal data collected on this site is:
Would you rather
For any question about your personal data, you can reach us through our contact form.
2. Personal data we collect
We collect the following data:
2.1. Registration data
- Email address: to create and manage your account
- Username or display name: to identify you on the site
- Password: stored in encrypted form
- Registration date
2.2. Google sign-in (OAuth2)
- Google ID (googleId)
- Google avatar (googleAvatar)
- Google email address: to link your Google account to your user account
2.3. Usage data
- Questions created: the "Would you rather" questions you publish
- Answers: what you choose on each question
- Votes and ratings
- Game statistics: number of answers, favourite categories
- Moderation history: if you moderate content
2.4. Payment data
- Payment information via Stripe: for premium subscriptions
- Transaction history
- Premium subscription status
2.5. Advertising data
- Advertising metrics: number of views, ads viewed or skipped per category
- Advertising preferences: managed through our CMP (consent management platform)
- House banners and direct advertisers: number of impressions and clicks per day, without cookies or personal data
3. Why we process your data
We use your data for:
- Account management: creation, authentication and profile management
- Running the service: suggesting questions, saving your answers and calculating statistics
- Personalisation: showing content suited to your preferences
- Payments: processing your premium subscriptions through Stripe
- Targeted advertising: showing relevant ads (with your consent)
- Statistical analysis: improving the service with Google Analytics
- Communication: telling you about what's new (question of the day newsletter if you subscribed)
- Legal compliance: meeting our legal obligations
4. Legal basis for processing
We process your data on the following legal bases:
- Consent: for targeted advertising, non-essential cookies and the newsletter
- Performance of a contract: to provide the service and manage your account
- Legitimate interest: for site security, anonymised statistics and improving the service
- Legal obligation: to keep billing records
5. What is a cookie?
A cookie is a small text file stored on your device. It lets the site keep some data to make browsing easier and to enable certain features.
5.1. What does this site use cookies for?
Cookies let the site keep some data in order to:
- Offer you personalised content (showing question results and remembering your answers).
- Show you advertising suited to your preferences.
5.2. Types of cookies used
- Essential cookies: required for the site to work (session, authentication)
- Performance cookies: Google Analytics, to analyse how the site is used
- Advertising cookies: through The Moneytizer, to show relevant ads
- Preference cookies: to remember your choices (language, consent)
5.3. Managing cookies
You can manage your cookie preferences at any time from our consent banner (CMP InMobi Choice) or in your browser settings. Refusing some cookies may limit certain features of the site.
6. Sharing data with third parties
We only share your data with the following providers:
- Stripe: secure payment processing (premium subscriptions)
- Google: OAuth2 sign-in and analytics (anonymised)
- The Moneytizer / InMobi: targeted advertising (with your consent)
- Web host: storage of the data on a secure server
These providers must comply with the GDPR and may only use your data for the defined purposes. We never sell any data to third parties.
7. How long we keep your data
- Active account: for as long as you use your account
- Inactive account: 3 years after your last login, then deleted
- Billing data: 10 years (legal obligation)
- Cookies: 13 months maximum
- Connection logs: 12 months
8. Your GDPR rights
Under the GDPR, you have the following rights:
- Right of access: get a copy of your personal data
- Right to rectification: correct inaccurate or incomplete data
- Right to erasure: delete your data ("right to be forgotten")
- Right to restriction: restrict the processing of your data
- Right to data portability: receive your data in a structured format
- Right to object: object to the processing of your data
- Right to withdraw consent: at any time, for processing based on consent
- Right to lodge a complaint: with a supervisory authority, in particular the CNIL (France) or the data protection authority of your country
To exercise these rights, contact us through our contact form or manage your settings directly from your profile.
9. Data security
We apply appropriate security measures:
- Encryption: hashed passwords and HTTPS connection
- Secure authentication: OAuth2 for Google and CSRF protection
- Secure payments: through Stripe (PCI-DSS certified)
- Restricted access: only authorised administrators can access the data
- Regular backups: to prevent data loss
- Security updates: the Symfony framework is updated regularly
10. International data transfers
Some providers (Google, Stripe) may transfer your data outside the European Union. These transfers are covered by appropriate safeguards in line with the GDPR (standard contractual clauses, EU-US Data Privacy Framework, etc.).
11. Changes to this policy
We may change this privacy policy at any time. Changes take effect as soon as they are published on this page, and the date of the last update is shown at the top. We encourage you to check this page regularly.
12. Contact us
For any question about this privacy policy or your personal data, you can reach us through our contact form.