Privacy Policy for The Queen of Hearts
This Privacy Policy explains how N.I.E.22 LIMITED, company number 17246955, registered in England and Wales, D-U-N-S Number 234870472, registered office 17 Bailey Road, Banbury, England, OX16 1HW, operating The Queen of Hearts, collects, uses, shares, protects, and retains personal data in connection with the mobile app, website, support channels, safety systems, and related services. The Queen of Hearts is an 18+ social discovery, Royal Court, tournament, messaging, Final Room, and optional real-world planning service. Contact us at info@nie22.com.
1. Who We Are and Scope
N.I.E.22 LIMITED is the controller of personal data processed through The Queen of Hearts unless a different role is stated in a signed agreement. This Policy applies to the app, account features, social discovery, courts, tournaments, final rooms, messages, optional real-world planning, payments, moderation, support, website product pages, and related safety operations. It does not replace privacy notices from Apple, payment providers, hosting providers, AI providers, or other third parties that process data under their own terms.
2. Personal Data We Collect
We may collect account identifiers, user ID, Sign in with Apple identity data, email address where provided, display name, date of birth, age, height, body type, gender, orientation, optional ethnicity, photos, profile text, occupation, interests, preferences, approximate and precise location where entered or permitted, discovery filters and interactions, court and gift activity, saved Royal Gift Gallery placement coordinates, messages and gift notes, tournament participation, gameplay content, scores and anti-cheat telemetry, final-room answers, reveal content, real-world plan details, reports, blocks, moderation records, subscription status, consumable balances, App Store transaction identifiers and purchase history, first-party product-interaction events, APNs device tokens, operational performance and diagnostic logs, notification state, privacy requests, support messages, and consent records.
3. Sensitive and Special-Category Data
The Queen of Hearts is an adult social discovery product, so some data may reveal sensitive information, including sexual orientation, gender identity, racial or ethnic origin, relationship preferences, photos, messages, location, private outcomes, and safety reports. In the UK/EU, sexual orientation and racial or ethnic origin may be special-category data. Where required, we rely on explicit consent for profile, discovery, matching, court, tournament, AI, and safety features that use this information. You may withdraw consent, but some features may stop working or your profile may no longer be eligible for discovery.
4. Sources of Data
We collect data directly from you when you create or edit a profile, upload photos, send messages, join courts, play tournament games, answer final-room questions, submit reports, block users, manage subscriptions, request export or deletion, or contact support. We also generate data from your app activity, such as role eligibility, tournament state, scores, notification state, moderation status, and security events. Apple may provide identity information through Sign in with Apple and purchase status through App Store purchase systems.
5. How We Use Data
We use personal data to create and authenticate accounts, verify adult eligibility, assign app roles, show profiles to eligible users, operate discovery, courts, tournaments, final rooms, messages, reveal cards, optional real-world planning, notifications, subscriptions, and paid features, personalize the app experience, generate AI-assisted content, prevent spam, fraud, cheating, harassment, and abuse, review reports, enforce policies, secure the service, debug and improve reliability, comply with legal obligations, respond to lawful requests, and process privacy rights requests.
6. UK/EU Lawful Bases
For UK/EU users, our lawful bases may include contract where processing is necessary to provide the app; legitimate interests for safety, fraud prevention, service improvement, security, and limited analytics; consent for optional profile data, device permissions, AI processing where not necessary for the service, and special-category profile data; legal obligation where we must preserve or disclose records; and vital interests where necessary to protect someone from serious harm.
7. Consent and Withdrawal
Where we rely on consent, you may withdraw it through in-app controls where available or by contacting info@nie22.com. Withdrawal does not make earlier processing unlawful, but it may prevent us from showing your profile, using special-category fields for discovery, generating certain AI-assisted content, using location-based features, or sending optional notifications. We may keep consent records so we can demonstrate when consent was given, withdrawn, or updated.
8. What Other Users May See
Eligible users may see profile photos, display name, age, gender or role signals, public profile text, interests, court participation, tournament status, final-room participation where relevant, messages sent to them, and real-world plan details shared with them. Gifts that a recipient explicitly pins may show their gift type and attached note on an eligible court card or gift display, but the sender's identity remains visible only to the gift recipient. In a Royal Gift Gallery, challengers may see the current arrangement after the Queen manually places a pinned gift and its position is saved. Hosts may see court and tournament activity for their court. Challengers may see information needed for their tournament card and final room. We do not show other users your raw date of birth, raw session tokens, Apple identity token, private moderation notes, privacy requests, or internal security logs.
9. Location, Photos, and Messages
Location may be used for discovery, safety, approximate distance, optional real-world planning, or service reliability. We use approximate location where possible and do not expose raw coordinates to other users. Photos are used for profiles, galleries, discovery, courts, tournaments, reports, and safety review. Messages, final-room answers, prompts, and real-world plan details are private to the intended participants, but may be processed for delivery, safety filtering, reporting, moderation, legal compliance, and abuse prevention.
10. AI and Generated Content
Custom Court generation uses OpenAI or Microsoft's Azure OpenAI service. Before a host's Court prompt is sent, the app names these providers, explains that the prompt will be used to generate Court text and images, including later Gallery image updates, and asks for affirmative consent. Choosing Cancel sends nothing. Choosing Continue records the consent and sends the submitted prompt. The stored prompt may be reused for later Gallery image updates while that consent remains current; missing, withdrawn, or stale consent blocks provider-backed generation. For Gallery imagery, OpenAI or Azure OpenAI receives the consented Court design prompt and generic composition instructions to generate an empty 360 Gallery background with display furniture. The Gallery imagery request does not include profile fields, identity, location, pinned-gift types or notes, messages, tournament data, or relationship context, and gifts are not embedded in the generated background. The completed Gallery background is not sent to an AI provider for vision anchor detection or coordinate analysis. The recipient manually arranges pinned gifts, and saved placements remain first-party service state. Neither Gallery generation nor saved placement is used for advertising or tracking. Do not include names, contact information, financial information, medical information, or other sensitive data in a Court prompt. Quick Quiz generation sends the three selected category names and generic quiz instructions; it does not send user identity, profile, device, location, Court, tournament, or round identifiers, or free-form user text. AI outputs may be inaccurate, inappropriate, or incomplete and may be moderated, regenerated, removed, or restricted.
11. Safety, Reports, and Moderation
We process reports, blocks, content identifiers, reported text, reporter notes, moderation decisions, enforcement history, and safety signals to protect users and operate the service. Reports may be reviewed by automated tools and trained personnel. We may restrict visibility, suspend accounts, preserve evidence, notify affected users where appropriate, or escalate urgent matters involving minors, threats, exploitation, non-consensual intimate content, stalking, fraud, trafficking, or other illegal activity.
12. Service Providers and Disclosure
We may share data with vendors that provide hosting, database infrastructure, authentication, payment processing, App Store purchase validation, messaging, notifications, operational logging and diagnostics, moderation, AI generation, image storage, customer support, legal services, compliance support, and security operations. Production data is hosted on Microsoft Azure using encrypted Azure Database for PostgreSQL, private Blob Storage, Key Vault, TLS-required connections, private access for data services, managed backups, and documented recovery procedures. We may also disclose data to regulators, law enforcement, courts, advisers, buyers or successors in a business transaction, or others where necessary to comply with law, protect users, enforce terms, prevent abuse, or defend legal claims.
13. No Advertising or Cross-App Tracking
The Queen of Hearts does not use Apple's Advertising Identifier (IDFA), AdSupport, advertising SDKs, or third-party tracking SDKs. We do not sell personal data, share personal data with data brokers, or combine app data with third-party data for advertising, advertising measurement, or tracking across apps or websites owned by other companies. First-party product-interaction and diagnostic data is used only to operate, secure, troubleshoot, and improve The Queen of Hearts. The app's App Store tracking disclosure is No.
14. International Transfers
The Queen of Hearts may be operated from, hosted in, or supported from countries outside the UK, EEA, or your home state. Where UK/EU personal data is transferred internationally, we use appropriate safeguards such as adequacy decisions, standard contractual clauses, UK international data transfer terms, vendor due diligence, and supplementary measures where required.
15. Retention
We keep personal data only for as long as reasonably needed for the purposes in this Policy. Account and profile data is retained while the account is active. Session security, performance, and diagnostic logs are retained for security, reliability, and troubleshooting periods. Messages, gift activity, saved Gallery placements, gameplay and tournament records, final-room content, generated assets, reports, moderation actions, purchase and transaction records, privacy requests, and consent records may be retained for longer where needed for safety, dispute handling, chargebacks, legal obligations, abuse prevention, or compliance evidence. Deletion may anonymize or restrict records rather than erase every reference where lawful retention is required.
16. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, object to, or withdraw consent for your personal data. UK/EU users may also have rights relating to portability, restriction, objection, and complaints to a supervisory authority. US state privacy laws may provide similar rights, including access, deletion, correction, portability, opt-out rights, and non-discrimination for exercising rights. Use the in-app export and delete tools where available or contact info@nie22.com. We may verify your identity before acting on a request.
17. Account Deletion and Export
You may request a machine-readable data export and account deletion from the app. Deletion is intended to revoke active sessions, remove authentication links where possible, anonymize or delete profile details, remove photos from active display, remove court visibility, redact messages where feasible, and restrict retained safety/legal records. We may retain limited records where necessary for safety, fraud prevention, disputes, legal claims, tax, accounting, App Store transactions, or compliance obligations.
18. Children and 18+ Restriction
The Queen of Hearts is not for children and is not directed to anyone under 18. Users must not create an account, appear in content, participate in social discovery, or use courts, tournaments, messages, or final rooms if they are under 18. If we learn or reasonably suspect that a user is under 18, we may restrict, suspend, delete, or preserve the account and remove profile visibility while reviewing. Reports involving minors may be escalated to appropriate authorities where legally required or permitted.
19. Security, Complaints, and Contact
We use administrative, technical, and organizational safeguards such as authenticated sessions, token rotation, rate limits, Keychain storage on iOS, access controls, moderation queues, restricted safety records, encrypted Azure database storage, private media storage, managed backups, and security logging. No system can be guaranteed secure. For privacy, support, safety, or illegal-content concerns, contact info@nie22.com. UK users may also complain to the Information Commissioner's Office.