Privacy Policy for the Rille app
Last updated: 2 September 2026
This policy covers the Android app Rille. For the website extra-level-quizzes.com, see the website privacy policy.
The short version. Rille needs no account, asks for no registration and builds no usage profiles. Your playlists stay on your device. An account exists only once you buy something — and then a pseudonymous one, with no name and no email address.
Controller
Nicolas GoossExtra Level Quizzes
Lange Str. 15
70806 Kornwestheim
Germany
info@extra-level-quizzes.com
What stays on your device
Most of it. Rille is built as a local app, not as a service with an account behind it. Stored on the device:
- Your playlists — title, artist, year and the references to Apple Music.
- The game in progress, so an interrupted round can continue.
- Four settings: language, last playlist played, sort order and list order.
- Cached view counts for the Klicks mode, for at most thirty days.
None of this reaches us: it is not transmitted to us and not analysed. Delete the app and it is gone from the device.
One limitation belongs with that: Android can include app data in the backup of your Google account. Rille allows this, so that your playlists survive a change of device. Such a backup belongs to your Google account and follows its rules — we have no access to it and do not see what is in it.
When the app sends something out
Six cases, and none of them happens in the background without a reason.
Creating or importing a playlist
The title and artist being looked up are queried at Apple. Apple sees your IP address. Back come the artwork, the year and a preview clip.
Pasting a Deezer playlist link
Only the identifier of the playlist you pasted is queried at Deezer. This happens solely when you paste such a link yourself.
Pasting a YouTube playlist link
Only the identifier of the playlist you pasted goes to our own server, which looks it up on YouTube. Our server makes the request; we do not pass your device's address on to Google. What comes back are the video titles, from which the app reads an artist and a title; the songs are then looked up at Apple as above. Nothing from YouTube is stored for this.
Matching the videos for the Klicks mode
If you built a playlist yourself, the app does not yet know which YouTube video belongs to which song. When you pick the Klicks mode, the artist and title go to our server, which queries MusicBrainz and YouTube about them. What is transmitted there are artist and track names, never your device's address. What comes back is cached for at most thirty days and then deleted.
Playing the Klicks mode
The YouTube video identifiers in your playlist go to our own server, to fetch view counts. Our server makes the request; we do not pass your device's address on to Google. The counts are cached for at most thirty days and then deleted.
Buying a pack or a pass
The purchase receipt goes to Google Play and to our server, so the entitlement can be verified and stored. This is where an account first exists at all.
The legal basis in each case is Art. 6(1)(b) GDPR as far as your data is concerned: the processing is necessary for the feature to do what you asked of it. Without the Apple lookup there is no playlist; without receipt validation there is no entitlement. For the information about artists and playlist owners processed along the way we rely on Art. 6(1)(f) GDPR — see "Data about artists and playlist owners" below. You are under no statutory or contractual obligation to provide your data; without it, though, the respective features cannot be offered.
The brake against abuse of the YouTube features
The YouTube routes above go through our server, and every player shares that server's allowance at Google. So that a single caller cannot drain it and switch the Klicks mode off for everybody, there is a brake against abuse.
For that our server stores no IP address, but an identifier derived from it in its place. That identifier changes daily and cannot be worked back to the address. The address itself never reaches the database, and rows from different days cannot be chained into a history of anybody's use. They are deleted after two calendar days at the latest; a daily clean-up run in the database sees to that, whether or not anybody is playing.
The legal basis here is Art. 6(1)(f) GDPR: our legitimate interest in keeping an openly reachable endpoint reachable for everyone. The intrusion is as small as it can be — an identifier that changes daily, and a number.
Playing along over Wi-Fi
Further devices can join a game in progress as long as they are on the same Wi-Fi. That runs straight from phone to phone: what is transferred is the state of the game with the player names and — only if you expressly share them — your own playlists. There is no server in between. None of it leaves the local network, and none of it reaches us.
There is a limitation to it that we would rather name ourselves: this connection on your home network is unencrypted. Anyone listening in on the same network can therefore read which songs are on the table and who is playing. On a home network you trust the risk is low — ruled out it is not; on an open or unfamiliar network it is a reason to leave the joining alone.
Our server, our processor and the logs
Everything we store at all — the caches for the Klicks mode, the counters for the abuse brake and, once you buy something, the account and the entitlements — sits with Supabase. Storage is in Frankfurt am Main, Germany — inside the European Union, so the storage location itself involves no third-country transfer under the GDPR.
Our contractual partner and data importer for this is Supabase Pte. Ltd., based in Singapore. The data processing agreement — the Data Processing Addendum, which the terms of service make part of the contract — contains the European Commission's standard contractual clauses. Under that agreement, storage and primary processing are committed to the chosen region; processing outside that region is possible under it.
Every call to our server functions also produces operational logs there, including the caller's IP address, the user agent and the country of origin. They serve the operation, debugging and security of the platform. These logs are deleted automatically after 24 hours at the latest. The legal basis is Art. 6(1)(f) GDPR.
This expressly applies to anyone who never buys a thing: the YouTube routes and the Klicks mode run through the same functions, and using them leaves such a log behind. What remains true alongside it: there is no tracking, no analytics, no ad networks and no profiling. An operational log is not the same thing as observation — but it is not nothing either, which is why it is written here.
Apple, Deezer, YouTube and MusicBrainz
For what these four do with a request afterwards, they are responsible themselves; for the transfer to them, we are. For YouTube and MusicBrainz it is our server that asks and not your device — so what they see is our address, not yours. Their own notices apply: Apple, Deezer, Google/YouTube and MusicBrainz.
What the transfers rest on. Deezer SA is based in Paris, so that is not a transfer to a third country. For Apple, the controller in the European Economic Area is Apple Distribution International Ltd., based in Ireland; onward transfers from there to the United States rest, by Apple's own account, on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR). Google LLC is based in the United States and is certified under the EU-US Data Privacy Framework; that transfer rests on the European Commission's adequacy decision for it (Art. 45 GDPR). MusicBrainz is run by the MetaBrainz Foundation in California; we do not assume such a certification there. No data about you goes there, though: what is transmitted are artist and track names and the address of our server. Wherever a transfer rests on standard contractual clauses, you can obtain a copy of them on request at info@extra-level-quizzes.com.
Data about artists and playlist owners
A music game inevitably processes information about people who never use it: artist names and song titles, the identifiers of their YouTube channels and videos, and those videos' view counts. We do not collect this from the people concerned but from the catalogues named above (Apple, Deezer, YouTube, MusicBrainz); we have no way of reaching these people directly, which is why we inform publicly here (Art. 14 GDPR).
What is processed is only what is public anyway and relates to the artistic profession — which song is by whom, which year it is from, which video belongs to it and how often that video has been viewed. No profile and no assessment is created; the caches on our server delete themselves after thirty days at the latest. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in offering a music game about published music. Anyone concerned can contact info@extra-level-quizzes.com at any time.
Purchases and the pseudonymous account
Until you buy something, Rille has no account for you — by design. If you do, a pseudonymous account is created: a random identifier, no name, no email address, no password. We still do not call it anonymous, because it is linked to your purchases. Stored with it:
- which packs or passes are unlocked, and since when;
- the store's purchase identifier, so the same receipt cannot grant twice.
Google Play handles the payment. We never see your payment details — they do not reach us at all. Google's privacy policy applies in addition. Where the account and the entitlements sit, and who our processor for them is, is set out above under Our server, our processor and the logs.
For how long. The account, the purchase records and the entitlements stay stored for as long as the account exists; you can delete it in the app at any time (see Delete your account). A deletion takes effect in the database immediately. Nothing sits around indefinitely without your involvement either: a pseudonymous account that has not been used for 24 months is deleted automatically, together with its purchase records and entitlements. You do not lose your permanent purchases — the receipts live with Google Play, and the app restores them at any time. Expired three-day passes are deleted no later than twelve months after they run out. The store's full response from the purchase check is removed no later than 24 months after the receipt was last checked; the store's purchase identifier is not affected. We make an encrypted backup copy of the database daily; the key for decrypting it is not in the archive — we keep it separately. Every copy is deleted automatically after 30 days at the latest — so deleted data leaves the backups within 30 days as well. Only the encrypted archive is stored, with GitHub, Inc. (USA; part of the Microsoft group), which holds its own certification under the EU-US Data Privacy Framework. The legal basis for the backup is Art. 6(1)(f) GDPR: our legitimate interest in being able to restore paid entitlements after a data loss.
App permissions
- Internet — looking songs up at Apple, verifying purchases.
- Foreground service — finishing a large playlist while the app is in the background. Every song is looked up at Apple one by one, which is why it takes a while.
- Notifications — the progress bar for that. No advertising.
- Keep screen awake — so the display does not sleep during a round.
Rille asks for no access to location, contacts, photos or microphone.
No tracking
No analytics, no ad networks, no third-party crash reporting, no cookies. We build no usage profiles and run no analytics.
When you write to us
The Report button in the app sends nothing by itself. It opens your mail program with a message already filled in, which you read first and can equally well discard. If you do send it, it then sits with our email provider like any other post to us — exactly as a message you write by hand to info@extra-level-quizzes.com does.
We process the sender's address and the content solely in order to reply and to fix the fault reported. The legal basis is Art. 6(1)(f) GDPR, and Art. 6(1)(b) GDPR for questions about a purchase. We delete the messages no later than twelve months after the matter is settled; correspondence subject to statutory retention periods (for instance about payments) is kept separately for as long as those periods require.
Your rights
Access, rectification, erasure, restriction, portability and objection under Art. 15–21 GDPR. In practice:
- Without a purchase there is no account with us and nothing in your name. What remains are the operational logs above, if your app has called one of our server functions; they delete themselves after 24 hours at the latest. Added to that is the abuse brake's identifier if you have used the YouTube features; it is deleted after two calendar days at the latest. To disclose anything from them we would need you to tell us the time and the IP address yourself, because otherwise they cannot be tied to anyone. Erasure otherwise means uninstalling the app — bearing in mind that a backup of your Google account may hold app data, which is described above and is not ours.
- With a purchase you can delete your pseudonymous account in the app. Entitlements and purchase identifiers are removed. The purchases themselves remain in your Google account and can be restored later. The step-by-step route is on Delete your account.
Requests to info@extra-level-quizzes.com. You may also complain to a supervisory authority under Art. 77 GDPR.
Objection
You have the right to object at any time, on grounds relating to your particular situation, to processing we base on Art. 6(1)(f) GDPR (Art. 21(1) GDPR). For Rille that concerns four processing operations: the abuse brake on the YouTube features, the operational logs, email correspondence and the daily backup. An objection can be sent informally to info@extra-level-quizzes.com.
To be honest about it: for the abuse brake and the backup we cannot, in practice, act on an objection case by case — the brake recognises nobody (its identifier changes daily and cannot be tied to a person), and a backup from which individual people were carved out would not be one. We regard both as compelling legitimate grounds within the meaning of Art. 21(1); both data sets delete themselves after two days and 30 days at the latest, respectively.
Children
Rille is a party game for the whole family. It builds no profiles about children and asks for neither names nor contact details. If the online features are used, technical connection data can arise — see Our server, our processor and the logs. Purchases go through Google Play and its family settings.
Changes
When the app changes what it does, this policy changes with it. The date above says when that last happened.