Last updated: May 25, 2026 · Effective date: May 25, 2026
WhoWins ("the app," "we," "us") is a single-player, on-device app for running character brackets, versus games, and tournaments. It is designed to keep your data on your device. The app has no user accounts, no login, and no server we operate that stores your content.
The only data that leaves your device does so for two reasons:
This policy explains what is processed, by whom, why, and what choices you have.
If you have any questions about this policy or want to exercise a privacy right (see Section 9), please use the contact channels above.
WhoWins stores the following entirely on your device using the operating system's local storage and file system. None of it is uploaded to a server we operate:
You can erase all of this at any time from Settings → Data → Clear Local Data.
WhoWins displays a banner ad at the bottom of the screen using the Google Mobile Ads SDK (AdMob). Showing an ad necessarily involves Google receiving:
Google uses this data to serve and measure ads, prevent fraud, and — if you have consented to tracking — to personalize ads.
Cookies and similar technologies. On a mobile app, the "cookies and similar technologies" that Google and its ad partners would normally use in a browser take the form of advertising identifiers (IDFA on iOS, Google Advertising ID on Android), SKAdNetwork postbacks, and SDK-level local storage. They serve the same function — identifying a device or session for ad delivery, measurement, and fraud prevention — but no browser cookies are set by WhoWins.
For more on Google's handling of this data, see Google's privacy policy and the AdMob/Google Mobile Ads disclosures.
The SKAdNetwork identifiers we register on iOS (used by AdMob's mediation partners for privacy-preserving attribution) are listed in the app's Info.plist file and reproduced in the App Store privacy questionnaire.
EEA / UK / Switzerland users: WhoWins does not yet present a Google-certified Consent Management Platform (CMP). Google requires a CMP for users in those regions before the Google Mobile Ads SDK can be initialized. We intend to integrate Google's User Messaging Platform (UMP) as our CMP as soon as possible. Until UMP is integrated, WhoWins is not distributed in the EEA, the UK, or Switzerland. When UMP ships, the first time you open the app in those regions you will see a Google-provided consent form asking whether ad partners may use your data for personalized ads, measurement, etc.; if you decline, AdMob will serve non-personalized (contextual) ads instead. This policy will be updated at that time.
When you search for characters, anime, or manga inside WhoWins, the app sends your search text and pagination parameters to AniList's public GraphQL API at https://graphql.anilist.co.
AniList sees, at minimum:
We do not send any account, email, or device identifier to AniList. AniList's privacy policy applies to their handling of these requests.
WhoWins is not affiliated with, endorsed by, or sponsored by AniList. Character and series data displayed in the app is provided by AniList and its contributors.
Character and cover images returned by AniList are loaded directly from AniList's image CDN. The CDN host therefore also sees your IP address and the URLs of the images being loaded. We do not control AniList's CDN.
WhoWins does not integrate Firebase, Google Analytics, Sentry, Mixpanel, Amplitude, Segment, PostHog, Crashlytics, or any similar SDK. We do not collect usage analytics or crash reports.
WhoWins asks for the following device permissions. Each is requested by the operating system at the moment you first try to use the related feature, and you can revoke any of them at any time in your OS settings.
NSPhotoLibraryUsageDescription): used only when you tap "Pick Image" (or "Change Image") to add a character image. The selected image is copied into the app's private storage; the app does not browse, index, or upload your photo library.NSPhotoLibraryAddUsageDescription): used only when you explicitly save a generated winner poster. The poster is saved into a "WhoWins" album in your Photos library on your device.NSUserTrackingUsageDescription): used only to request permission for AdMob to use the IDFA for personalized ads (see Section 3.2.1).WhoWins does not request location, contacts, microphone, calendar, reminders, health, motion, Bluetooth, or notification permissions. The current build does not include a "Take Photo" feature, so the camera is not used at runtime; if a future version adds in-app photo capture, this policy and the iOS permission strings will be updated accordingly.
WhoWins includes two explicit, user-initiated sharing actions on the Winner screen:
We do not silently share anything you create.
WhoWins is not directed at children under 13 (or under 16 in the EEA/UK). Because the app includes third-party advertising via Google AdMob, we do not knowingly collect or share personal information from children under those ages. If you believe a child has used the app and you have a concern, please contact us at the address in Section 2 and we will take appropriate steps.
The app is not configured for Google Play's "Designed for Families" program or Apple's "Kids" category, and AdMob is not initialized with child-directed treatment flags.
Where the EU or UK General Data Protection Regulation applies, our legal bases for processing are:
You have the right to withdraw consent at any time (see Section 9). For non-personalized ad processing, you may object to processing based on legitimate interests on grounds relating to your particular situation; please contact us using the details in Section 2.
You have the rights, under applicable law, to:
Because WhoWins itself does not maintain user accounts or server-side records tied to you, most of these rights apply to data held by Google AdMob and AniList. You can also exercise your access/deletion rights for AdMob-related data via Google's privacy controls (myadcenter.google.com and adssettings.google.com).
California residents have the right to:
We do not "sell" personal information for money. We have not knowingly shared or sold the personal information of California residents under 16.
To submit a verifiable consumer request, contact us using the channels in Section 2.
If you reside in a US state with a comparable privacy law (e.g., Colorado, Connecticut, Virginia, Utah, Texas, Oregon), you have substantially similar rights to those described in Section 8.2, exercised through the same channels.
No system is perfectly secure, and we cannot guarantee absolute security of data processed by third parties (AdMob, AniList).
Google AdMob and AniList are operated outside of some users' home countries (notably outside the EEA/UK and outside California). When you use WhoWins, any data described in Section 3.2 may be transferred to and processed in those jurisdictions, subject to the safeguards the respective providers have in place (e.g., Standard Contractual Clauses for Google's services).
We may update this policy from time to time — for example, when adding or removing third-party SDKs. When we make material changes, we will update the "Last updated" date at the top, and, where appropriate, surface a notice in the app or update the App Store / Play Store listing.
This policy includes links to third-party privacy policies (Google, AniList). We are not responsible for the content or practices of those third parties. Please review their policies directly.
This summary mirrors the disclosures made when filling out the App Store and Play Store privacy questionnaires. It is provided here for transparency; the authoritative labels are the ones visible on the store listings.
| Data type | Collected | Linked to user | Used for tracking | Collected by |
|---|---|---|---|---|
| Coarse location (IP-derived) | Yes | No | Yes, if ATT granted | Google AdMob |
| Device ID (IDFA / Advertising ID) | Yes, if ATT granted | No (by WhoWins) | Yes | Google AdMob |
| Device info (model, OS, language) | Yes | No | No | Google AdMob |
| Advertising data (impressions, clicks) | Yes | No | Yes | Google AdMob |
| Search queries (to AniList) | Yes | No | No | AniList |
| User-generated content (brackets, photos) | No (stays on device) | — | — | — |
| Crash data / diagnostics | No | — | — | — |
| Usage / product analytics | No | — | — | — |