Privacy Policy


Aethus Ltd, trading as thoozie

Last updated 1 October 2026. Aethus Ltd is the data controller for thoozie under UK GDPR and the Data Protection Act 2018. This page says what we hold, why, who touches it, how long we keep it, and what you can do about it.

1. Who we are

Aethus Limited, trading as thoozie, registered in England and Wales, company number 17067424, registered office Independence House, 14a Nelson Street, Southend-on-Sea, SS1 1EF. Contact us about your data at hi@thoozie.com. We're a small company and don't have a statutory Data Protection Officer; that address reaches the people responsible.

2. What we hold

  • Account data: email address, passkey or sign-in credentials, a user ID, your date of birth for the age gate, and your @handle, which is public.
  • Session and security data: for each sign-in, the IP address and the browser or device type. We use these to spot stolen sessions and duplicate accounts, and for nothing else.
  • Gameplay records: collection, duel history, swap and trade history, coin and pack ledger entries, quest and streak progress, events entered.
  • Submitted content: any photo, board title, profile photograph or profile text (home park, favourite coaster) you choose to submit, with EXIF location data removed before the photo is stored. In the app it is removed on your device before upload; if a photo's location cannot be removed, the app refuses to send it. On the website it is removed on our server as the photo arrives, before anything is written to storage. Profile photographs and profile text are public once published.
  • Social publishing data: an Instagram handle is private own-account data in thoozie. Adults only can give separate, explicit permission to tag or mention that account when they appear in standings, welcome posts, Reels and other thoozie posts, including Instagram collaborator invites they can accept or decline on Instagram, and permission to feature their thoozie card or profile in social spotlights.
  • Notification data: a push-notification token for each iOS device, and a browser push subscription on the web, if you turn notifications on. They identify the device, not you, and are removed when you turn notifications off.
  • Purchase records: which coin packs or FastPass subscriptions you bought, when, and the transaction identifier from Apple (in the app) or Stripe (on the website), plus your own spending limit and cooling-off settings. Kept so we can verify a purchase and grant what it paid for, and to handle refunds. Payment is handled entirely by Apple or Stripe; we never see your card details.
  • Referral and campaign data: if you sign up through a friend's link, we record which member referred you (they see that a friend joined, by handle). If you arrive through a tagged campaign link, we store the campaign label with your account (see §8).
  • Messages you send us: anything you send through the contact, feedback, fact-report or makers forms, with the name and email you give.
  • Diagnostic data: crash and error reports, so we can fix what breaks. Reports are never linked to your account, and we do not attach your identity, cookies or IP address to them.

What's public: your @handle, mascot and member card, your position in standings and events, and your duel and swap history with the other player involved. Photo credits name you by handle.

Players you ride with, or have duelled, see a rough sense of whether you've been around (about today, or this week), never an exact time and never whether you're online now. Your riders also see your spare duplicates and the cards you still need, and your notable pulls and duel results from the last day.

We don't track you: no advertising identifiers, no ad SDKs, no App Tracking Transparency prompt. Usage analytics are anonymous and never tied to your account. We don't collect your location; the only location data we could ever see is what a camera embeds in a photo, and that is removed before the photo is stored, never kept.

To run your account and the game itself (performance of our contract with you). To meet the age-verification, consumer-protection and tax obligations we're under (legal obligation). To keep the game secure and fair, prevent fraud and abuse, and understand how the game is used (our legitimate interests, balanced against your rights). Push notifications, social publishing and profile photos run on your consent, which you can withdraw at any time in Settings.

Email reminders, win-back messages and set news go to members who've kept email reminders switched on. We send them under the rules for existing customers of our own service; every one has a one-click unsubscribe, and the switch is in Settings.

We use an Instagram handle for automatic tags, mentions, collaborator invites or profile features only with the relevant explicit permission, and we check that permission again each time a post goes out. A collaborator invite is yours to accept or decline on Instagram. Revoking one permission stops future automatic uses covered by that permission. The other permission remains independent. Historic Stories and posts, screenshots, and other copies may remain and cannot be withdrawn automatically.

We don't make automated decisions about you with legal or similarly significant effects. Anti-cheat checks flag an account for a person to look at; they don't act on their own.

4. Who processes it

We keep the list of processors short and named:

  • Our own server: the application and database run on a dedicated server we control at a European hosting provider (OVHcloud, EU). Crash reporting is self-hosted (Bugsink at errors.thoozie.com, run by us), and analytics are self-hosted (Umami, run by us). No third party sees crash or analytics data.
  • Backblaze (EU, Amsterdam): stores our backups. Backups are encrypted on our server before they leave it, with a key only we hold, so Backblaze cannot read them.
  • Mailgun (EU region): transactional and account email.
  • Apple: in-app purchases, subscription billing and push-notification delivery for the iOS app. Apple processes payment details directly; we receive only a transaction identifier and what was bought.
  • Stripe: payment processing for purchases on the website. Stripe handles your card details directly; we receive a customer reference, a transaction identifier and what was bought.
  • Browser push services (Apple, Google, Mozilla): deliver web push notifications. Payloads are encrypted to your browser; the service sees only the delivery endpoint.

Each processor is bound by data-processing terms consistent with UK GDPR.

For an opted-in social publication, Meta/Instagram is the recipient and publishing platform. We send only the Instagram handle needed for a tag, a mention or a collaborator invite, and the opted-in post, Reel or Story content. Meta is not used for thoozie's core account or gameplay data processing.

5. International transfers

Your data lives in the UK and EU. Stripe, Apple, Meta and the browser push services may process data in the United States. Those transfers rely on the UK's adequacy arrangements for the US where the provider is certified under them, and otherwise on the ICO's International Data Transfer Addendum to the standard contractual clauses.

6. How long we keep it

  • Account and gameplay data: for as long as your account is open. When you delete your account (Settings), we immediately anonymise it: email, date of birth, credentials, photos, profile text and social permissions are removed. The coin and card ledger stays in anonymised form, because the game's economy has to add up, and your handle is reserved for 12 months so nobody can impersonate you.
  • Sessions: deleted when you sign out or they expire.
  • Purchase records: six years from the end of the tax year, as UK tax law requires.
  • Messages you send us: for as long as it takes to deal with them, and up to two years after.
  • Server logs: 14 days.
  • Backups: on a rolling schedule; a deleted account drops out of every backup within 365 days.

7. Your rights

Under UK GDPR you can ask us to access, correct, delete or export your data, restrict or object to certain processing, and withdraw any consent you've given. Email hi@thoozie.com; we respond within one month. You can delete your account yourself in Settings. If you think we've got it wrong, you can complain to the Information Commissioner's Office at ico.org.uk, though we'd like the chance to fix it first.

8. Cookies and analytics

We use strictly necessary session cookies to keep you signed in, and privacy-respecting, self-hosted analytics that set no cookies and do not track you across other sites. Product analytics from the app are anonymous: events are sent without any account identifier, so they cannot be linked back to you. There's no cookie banner because there's nothing to consent to.

If you arrive through one of our tagged campaign links (an ad or a newsletter, say), a first-party cookie remembers which campaign it was for 30 days. If you then sign up, we store that campaign label with your account so we can tell which campaigns bring players who stay. Nothing about you is sent to the ad platform, and the label is deleted with your account.

When you sign in, a first-party cookie gives that browser a random label. It holds nothing about you; we use it only to spot one person making several accounts to claim invite rewards. The record of which accounts used which label is deleted with your account.

9. Children's data

No thoozie account is available to anyone under 13. Between 13 and 17 you can play, and we hold only what the game needs: no purchases, no profile photo, no social tagging (and no Instagram line when a welcome post names you), and no marketing beyond the game's own reminders, which you can turn off. We design with the ICO's Age Appropriate Design Code in mind. If you believe a child under 13 has an account, email hi@thoozie.com and we'll remove it.

10. Security

Sign-in is by passkey or emailed link, so there's no password for anyone to steal. Everything travels over TLS. Backups are encrypted before they leave our server. Access to personal data is limited to the people who need it to run the game. If a breach ever puts your rights at risk, we'll tell the ICO within 72 hours and tell you without undue delay.

11. The iOS app

The app holds your session on the device in the iOS Keychain, scoped to that device — it is not included in encrypted backups and does not transfer to a new phone, so a restored or reinstalled device starts signed out. Card artwork and stats are cached on the device so the app works offline. Deleting the app removes both.

12. Changes to this policy

We'll update this page as thoozie changes, with the date at the top. If a change materially affects how we use your data, we'll tell you by email or in-game before it takes effect.

Back to thoozie