Privacy Policy

Wasted Penguinz — wastedpenguinz.com and the Wasted Penguinz mobile app.
Last updated: 23 August 2026

Wasted Penguinz AB ("we", "us") operates the Wasted Penguinz community — the website at wastedpenguinz.com, its chat and calling features, the shop, and the mobile app. This policy explains what personal data we handle, why, and what your rights are. We are the data controller under the EU General Data Protection Regulation (GDPR).

What we collect

Account data. Username, email address, password (stored only as a salted hash), optional phone number (for SMS sign-in), optional profile details you choose to add (bio, country, links, banner, avatar).

Messages and content. Messages you post in public rooms are visible to the community. Private messages and uploaded files are encrypted at rest on our servers. Voice and video calls are transmitted in real time and are not recorded.

Purchases. Orders, donations and subscriptions are processed by our payment providers (Stripe, PayPal). We never see or store your card details — we keep the order records (what was bought, amount, date) that Swedish bookkeeping law requires.

Activity and engagement. XP, badges, quests and similar community features are tied to your account.

Technical data. IP addresses and technical logs, kept for security, moderation and abuse prevention. If you enable notifications in the mobile app, the device push token needed to deliver them.

Translations. If chat translation is enabled, message text is translated on our own server — it is never sent to a third-party translation service.

Why we use it

To run the service you signed up for (contract), to keep the community safe and moderated and to prevent abuse (legitimate interest), to meet legal obligations such as bookkeeping, and — for things like optional notifications — because you asked for them (consent, which you can withdraw at any time in your device settings).

Who we share it with

We do not sell personal data. We use a small number of processors to run the service: Stripe and PayPal (payments), Twilio (SMS sign-in codes), Hetzner (hosting, EU data centres), Cloudflare (network security), and our email provider for transactional email. Each processes data only on our instructions. Payment providers process your payment data under their own policies.

How long we keep it

Account data is kept while your account exists. Purchase records are kept for seven years as required by the Swedish Bookkeeping Act (bokföringslagen). Security logs are kept for a limited period. When you delete your account, your profile, email, phone number, friends and private messages are removed; your posts in public rooms remain, shown as "Deleted user".

Your rights

You can access, correct or delete your data, object to or restrict processing, and take your data with you. You can delete your account yourself at any time: Profile → Settings → Delete account, in the app or on the website. For anything else, email us and we will respond within a month. You also have the right to complain to the Swedish Authority for Privacy Protection (IMY).

Cookies

We use a session cookie to keep you signed in and functional storage for your preferences (such as theme). We do not use advertising or cross-site tracking cookies.

Children

The service is not directed at children under 16. If you believe a child has created an account, contact us and we will remove it.

Changes

If we change this policy in a way that matters, we will announce it in the app and on the site before it takes effect.