Privacy Policy
Last updated: 3 August 2026
Tambello is a quiz you play together — in a classroom, at a party, or on the sofa. It collects as little as it can. There are no cookies, no advertising and no third-party trackers, and nothing is measured about you personally. This page explains, in plain terms, exactly what is stored and where.
1. Who is responsible
The controller for the processing described here is Tambello, reachable at contact@tambello.com.
2. No cookies
Tambello does not set a single cookie. It does use your browser's local storage, which is a different thing: the data stays on your own device, is never sent anywhere automatically, and is used only to make the app work. Nothing in it identifies you to us or to anyone else.
There are nine entries, and every one of them is there because the app would not function without it: the language and the light or dark setting you chose, the current radio track, which questions have already been asked on this device, the game you are in so that you can rejoin it after losing connection, and — only if you created an account — your sign-in and the list of quizzes you wrote. Nothing is stored for analysis, for advertising, or for recognising you later.
You can delete all of it at any time by clearing site data for this domain in your browser settings. Tambello will then behave like a first visit. Nothing is lost that is not also on the server under your account.
3. Players
Anyone can join a game by scanning the QR code or typing the room code. That is true for a class of thirty and for three friends in a kitchen, and the rule is the same for both:
A player does not create an account and is not asked for a name, an email address or any other personal detail. They type a nickname of their own choosing. That nickname and the points scored live only in the memory of the running game room and are gone when the room closes. Nothing about a player is written to our long-term storage, and nothing is used to recognise the same person in a later game.
If someone types their real name as a nickname, that name is visible to everyone in the room while the game runs, exactly as if they had said it out loud. Whoever is hosting can remove a player from a room at any time.
4. Accounts
An account is optional. It exists only so that you can write your own quizzes and find them again on another device. Playing the built-in quizzes needs no account at all.
If you create one, we process:
- Your email address. It is the account name. We use it to send you a six-digit sign-in code, and for nothing else. There is no newsletter and no other mail.
- A six-digit sign-in code. Stored for 15 minutes, then deleted automatically, whether used or not.
- A counter of code requests. Kept for one hour per email address, so that nobody can have your inbox flooded. It holds a number, nothing more.
- A session token. A random string that stands in for your email address once you are signed in. Valid for 180 days, then it expires on its own. Signing out deletes it immediately.
- The quizzes you write. Question texts, answers and the title, stored under your account until you delete them.
The legal basis is Article 6(1)(b) GDPR — the processing is necessary to provide the service you asked for.
5. Language, country and where visitors come from
Our hosting provider tells us which country a request comes from, and for Switzerland also the canton. We use that once, at the moment the page is built, to pick a sensible starting language — so that Geneva does not get German. The value is written into the page and then forgotten. It is not stored, not logged by us and not combined with anything else. You can change the language at any time, and your choice overrides it.
When we hand out a link — in a post, in a message, or in an
advertisement — it sometimes carries a short tag, like
?v=fb. The server adds one to a counter for that tag and
forgets everything else. What is stored is a single number per tag per
day, nothing more: not your address, not the time, not which pages you
looked at, not whether you have been here before. There is no way back
from that number to a person. The tag is removed from the address bar as
soon as the page has loaded, so it does not travel on into your history
or into a link you pass to somebody else.
6. Who else sees data
Two companies work for us: Cloudflare hosts Tambello and stores the account data, and Resend delivers the sign-in emails from within the European Union. Both are bound by data processing agreements, and both may process data outside your country, including in the United States, under the European Commission's standard contractual clauses. There is nobody else — Tambello loads nothing at all from other people's servers.
7. How long we keep things
- Sign-in codes: 15 minutes
- Request counters: 1 hour
- Session tokens: 180 days, or until you sign out
- Your own quizzes: until you delete them or ask us to delete the account
- Game rooms including nicknames and scores: only while the game runs
8. Your rights
You have the right to ask what we hold about you, to have it corrected, to have it deleted, to have its processing restricted, to object to it, and to receive it in a portable form. Write to contact@tambello.com and we will answer within one month.
To delete your account and everything under it, use Delete account on the start page while signed in. It removes the account, every quiz you wrote and every sign-in on every device, at once and without having to ask us. If you prefer, you can instead send us a message from the address you signed up with.
You may also lodge a complaint with a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner, in the EU the authority of your country of residence.
9. Children
Children play quizzes, and Tambello is built with that in mind: joining a game needs no account and no personal detail, which is why we ask for no consent from a player and hold nothing about them. Accounts, which do need an email address, are meant for adults. If you believe a child has nevertheless given us personal data through an account, write to us and we will remove it.
10. Security
All traffic runs over an encrypted connection. Sign-in codes expire after 15 minutes and are invalidated after eight wrong attempts. We never store a password, because there is none.
11. Changes
If this policy changes, the date at the top changes with it. Material changes will be announced on the start page.
See also the Terms of Use, the Legal Notice and the Contact page.