Privacy Policy
Last updated: 13 June 2026
1. Introduction
Kingfisher Labs ("we", "us") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights in relation to it. By using Falcon you agree to this policy. If you do not agree, please do not use the service. Questions: privacy@kingfisherlabs.co.uk.
2. Information we collect
- Account information — name and email address (provided directly or via Google OAuth); profile picture when using Google sign-in.
- Game data — questions you ask during Who Am I? puzzles, puzzle sessions, scores, streaks, and completion history.
- Payment data — handled entirely by Stripe. We store only your Stripe customer ID and subscription status. We never see your card details.
- Technical data — session cookies to keep you logged in; IP address and user agent stored with your GDPR consent record only.
3. How we use your information
We use your data to:
- Authenticate your account and maintain your session
- Provide the daily puzzle games and track your progress
- Calculate your streaks and statistics
- Generate custom puzzles based on topics you submit (Plus users)
- Process subscription payments
- Respond to support enquiries
- Comply with legal obligations
4. Automated puzzle responses
When you ask questions in the Who Am I? game, your messages are sent to a third-party inference provider (Anthropic) to generate answers. Anthropic processes this data under their own privacy policy and we have a Data Processing Agreement in place. We do not use your questions to train any AI models.
5. Third-party services
- Google— OAuth sign-in. Basic profile data is shared per Google's Privacy Policy.
- Anthropic — inference for Who Am I? puzzle responses. DPA in place.
- Stripe — payment processing. PCI DSS Level 1 certified.
- Vercel — application hosting (EU region available). DPA in place.
- Neon — database hosting (EU region). DPA in place.
- Resend — transactional email (magic links, password resets).
6. Cookies
We use only essential session cookies required to keep you logged in. We do not use advertising or tracking cookies. You can withdraw consent at any time by clearing your browser storage or deleting your account.
7. Data storage and security
Your data is stored in encrypted databases with industry-standard security controls. Access is restricted to authorised personnel using secure authentication. No method of internet transmission is 100% secure, and we cannot guarantee absolute security.
8. Data retention
We retain your data for as long as your account is active. Deleting your account permanently removes your profile, game history, and statistics. Aggregated, anonymised data may be retained for service improvement.
9. Your rights (UK GDPR / GDPR)
If you are in the UK or EU, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate data
- Erasure — request deletion of your data
- Portability — export your game data in machine-readable form
- Objection — object to processing in certain circumstances
- Restriction — request that we restrict processing
To exercise any of these rights, contact privacy@kingfisherlabs.co.uk. You also have the right to lodge a complaint with the ICO (Information Commissioner's Office) at ico.org.uk.
10. Age requirement
You must be at least 13 years old to use Falcon. We do not knowingly collect personal data from children under 13. If we become aware that a child under 13 has provided us with personal data, we will delete it.
11. International data transfers
Some of our third-party service providers may transfer data outside the UK/EEA. Where this occurs, we ensure appropriate safeguards are in place (such as standard contractual clauses or adequacy decisions).
12. Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with a revised date. We recommend checking periodically.
13. Contact
Falcon is operated by Kingfisher Labs. privacy@kingfisherlabs.co.uk
© 2026 Kingfisher Labs. All rights reserved.