Trust & security

Fun for the room.Serious about the data.

Tikroo is built to collect as little as possible and protect everything it does collect. Here's exactly how — in plain English, with nothing we can't back up.

How we protect Tikroo

The practices behind every board, PIN, and answer.

Encrypted in transit

All traffic to Tikroo runs over HTTPS (TLS 1.2+), enforced with HSTS. Plain HTTP never happens.

Edge-protected delivery

The app is delivered through Cloudflare's global network, which shields it with built-in DDoS mitigation.

Safe authentication

Passwords are stored hashed — never in plain text. Sessions use secure, HTTP-only cookies with CSRF protection.

Restricted access

Production systems are accessible to a minimal set of people, each protected by multi-factor authentication.

Secure development

Changes go through review and automated tests before release. Dependencies are monitored for known vulnerabilities, and strict security headers (CSP) guard the app.

Payments we never see

Payments are handled by PCI DSS–compliant processors (Stripe, Square). Card numbers never touch our servers.

Backups

Data is backed up automatically on a regular schedule so a bad day stays a bad hour.

Consent-first analytics

Nothing non-essential loads until you say yes. Decline the banner and no analytics run — the game works exactly the same.

Data minimisation

Participants never need an account. The less we collect, the less there is to protect — that principle shapes every feature.

The data we handle

Participants join with a PIN and a nickname — no account, no app, no email. Organisers give us only what an account needs.

Account data
Organiser name, email, hashed password
To run your account and boards
Until you delete your account
Game content
Boards, questions, and answers you create
It's your content — you own it
Until you delete it
Participation data
Nickname, answers, and scores in games you join
To run the live game and leaderboard
Life of the game
Technical data
IP address, browser type, request logs
Security, debugging, abuse prevention
Short-lived logs
Payment data
Subscription status only — card details stay with Stripe/Square
To know what plan you’re on
Life of the subscription
No third-party advertising No selling personal data No tracking without consent No card numbers on our servers

Privacy & compliance

What's true today, and what we're working toward. We'll publish reports here when they exist — not before.

In place today
  • GDPR data rights

    Access, correction, erasure, portability, and objection — honoured for every user worldwide, answered within one month.

  • Australian Privacy Act & APPs

    We're an Australian company and align our handling of personal information with the Australian Privacy Principles.

  • Explicit consent for analytics

    Analytics only run after an explicit opt-in, and withdrawing consent is one click on our privacy page (GDPR art. 7(3)).

  • CCPA

    California users can request disclosure or deletion of their data. We don’t sell personal data, so there’s nothing to opt out of.

On the roadmap
  • ISO 27001 certification

    Formalising our security practices into a certified information-security management system.

  • SOC 2 report

    Independent attestation of our controls, on the heels of ISO 27001.

  • Independent penetration testing

    Annual third-party testing, with reports available to customers under NDA.

  • Data Processing Agreement (DPA)

    A signable DPA with our subprocessor list, for organisations that need one.

Evaluating Tikroo for your organisation? Email security@tikroo.com and we'll answer your security questionnaire directly.

Security FAQ

Do participants need an account to join a game?

No. Participants join with a PIN and a nickname — no email, no sign-up, no app. That’s a privacy feature as much as a convenience one: we can’t lose data we never collected.

Do you sell my data or show ads?

Never. Tikroo shows no third-party advertising, uses no advertising cookies or tracking pixels, and does not sell personal information. Our revenue comes from paid plans, not your data.

Can I have my data deleted?

Yes. Delete your account from your profile, or email us and we’ll erase your personal data. Under GDPR we respond within one month; we honour the same rights for everyone, everywhere.

Are you SOC 2 or ISO 27001 certified?

Not yet — and we won’t pretend otherwise. Tikroo is young, and formal certification (ISO 27001 first, then SOC 2) is on our roadmap. In the meantime we’re happy to answer any security questionnaire directly at security@tikroo.com.

What happens to game data after a live game ends?

Organisers keep their boards and results for as long as they want them. Participant-side data lives in the participant’s own browser and much of it expires automatically after the game.

How do I report a security issue?

Email security@tikroo.com, or check /.well-known/security.txt for machine-readable details. We respond promptly, fix responsibly, and will credit you for the find if you’d like.

Found a vulnerability?

We appreciate security researchers. We don't run a paid bounty program yet, but we respond quickly, fix responsibly, and credit you if you'd like. Machine-readable details live at /.well-known/security.txt .

Please don't access other people's data or disrupt live games while testing.