Fun for the room.
Serious about the data.
Tikroo is built to collect as little as possible and protect everything it does collect. Here's exactly how — in plain English, with nothing we can't back up.
How we protect Tikroo
The practices behind every board, PIN, and answer.
All traffic to Tikroo runs over HTTPS (TLS 1.2+), enforced with HSTS. Plain HTTP never happens.
The app is delivered through Cloudflare's global network, which shields it with built-in DDoS mitigation.
Passwords are stored hashed — never in plain text. Sessions use secure, HTTP-only cookies with CSRF protection.
Production systems are accessible to a minimal set of people, each protected by multi-factor authentication.
Changes go through review and automated tests before release. Dependencies are monitored for known vulnerabilities, and strict security headers (CSP) guard the app.
Payments are handled by PCI DSS–compliant processors (Stripe, Square). Card numbers never touch our servers.
Data is backed up automatically on a regular schedule so a bad day stays a bad hour.
Nothing non-essential loads until you say yes. Decline the banner and no analytics run — the game works exactly the same.
Participants never need an account. The less we collect, the less there is to protect — that principle shapes every feature.
The data we handle
Participants join with a PIN and a nickname — no account, no app, no email. Organisers give us only what an account needs.
Privacy & compliance
What's true today, and what we're working toward. We'll publish reports here when they exist — not before.
- GDPR data rights
Access, correction, erasure, portability, and objection — honoured for every user worldwide, answered within one month.
- Australian Privacy Act & APPs
We're an Australian company and align our handling of personal information with the Australian Privacy Principles.
- Explicit consent for analytics
Analytics only run after an explicit opt-in, and withdrawing consent is one click on our privacy page (GDPR art. 7(3)).
- CCPA
California users can request disclosure or deletion of their data. We don’t sell personal data, so there’s nothing to opt out of.
- ISO 27001 certification
Formalising our security practices into a certified information-security management system.
- SOC 2 report
Independent attestation of our controls, on the heels of ISO 27001.
- Independent penetration testing
Annual third-party testing, with reports available to customers under NDA.
- Data Processing Agreement (DPA)
A signable DPA with our subprocessor list, for organisations that need one.
Evaluating Tikroo for your organisation? Email security@tikroo.com and we'll answer your security questionnaire directly.
Security questions: security@tikroo.com · Privacy questions: privacy@tikroo.com
Security FAQ
Do participants need an account to join a game?
No. Participants join with a PIN and a nickname — no email, no sign-up, no app. That’s a privacy feature as much as a convenience one: we can’t lose data we never collected.
Do you sell my data or show ads?
Never. Tikroo shows no third-party advertising, uses no advertising cookies or tracking pixels, and does not sell personal information. Our revenue comes from paid plans, not your data.
Can I have my data deleted?
Yes. Delete your account from your profile, or email us and we’ll erase your personal data. Under GDPR we respond within one month; we honour the same rights for everyone, everywhere.
Are you SOC 2 or ISO 27001 certified?
Not yet — and we won’t pretend otherwise. Tikroo is young, and formal certification (ISO 27001 first, then SOC 2) is on our roadmap. In the meantime we’re happy to answer any security questionnaire directly at security@tikroo.com.
What happens to game data after a live game ends?
Organisers keep their boards and results for as long as they want them. Participant-side data lives in the participant’s own browser and much of it expires automatically after the game.
How do I report a security issue?
Email security@tikroo.com, or check /.well-known/security.txt for machine-readable details. We respond promptly, fix responsibly, and will credit you for the find if you’d like.
Found a vulnerability?
We appreciate security researchers. We don't run a paid bounty program yet, but we respond quickly, fix responsibly, and credit you if you'd like. Machine-readable details live at /.well-known/security.txt .
Please don't access other people's data or disrupt live games while testing.