App WikiRacing · last updated: September 14, 2026
WikiRacing is a free game where you navigate between two Wikipedia articles using only internal links. This page explains what data is collected, why, and who it's shared with.
| Data | When | Why |
|---|---|---|
| Email address | Sign-up (email/password or Google) | Authentication, password reset |
| Password | Email/password sign-up | Authentication (hashed, never stored in plain text) |
| Username | Chosen at sign-up | Public display (leaderboards, recent activity, public profile) |
| Game history | Every win | Stats, leaderboards, badges |
| ELO rating, campaign level | Ranked duels / campaign mode | Competitive ranking, progression |
| Friends list | Adding a friend | Social feature (online status) |
| Bug reports | Voluntary in-game submission | Bug fixing |
| Advertising identifier (IDFA on iOS, Advertising ID on Android) | iOS/Android apps only, when an ad is shown | Ad display; ad personalization only if you grant permission (see "Advertising in the mobile apps" below) |
You can play without creating an account: in that case, games are recorded with no personal data attached (empty user field).
Google sign-in only requests the openid and email scopes. No profile information (name, photo) is requested or stored.
The iOS and Android apps show ads via Google AdMob after a race finishes. The website itself does not show ads.
The first time the iOS app could use your device's advertising identifier (IDFA) for ad personalization, Apple's App Tracking Transparency system prompt asks for your permission. If you decline, or take no action, the app cannot access the IDFA and AdMob serves only non-personalized ads instead. You can review or change your answer later in Settings → Privacy & Security → Tracking on your device. That same screen also has a device-wide "Allow Apps to Request to Track" switch which, if off, prevents any app from ever showing this prompt or accessing your IDFA.
The Android app uses Google Play Services' advertising ID under Google's standard Play Store policies for ad personalization. You can reset or limit it at any time in your device's Google Settings → Ads.
The site uses browser localStorage for your login session and chosen language. A cookie-consent banner is shown on your first visit; Google AdSense and Google Analytics / Google Tag Manager only load if you accept it. You can change your choice at any time by clearing your browser's local storage for this site (this resets the banner).
Account data is kept as long as the account exists. Games played without an account aren't linked to any identity and are kept indefinitely in anonymous form (leaderboards, recent activity).
You can delete your account and all associated data at any time, directly from the app (profile → "Delete my account"), or see the dedicated page: wiki-racing.com/delete-account.
For any other request about your data (access, correction, export), email chabnco@gmail.com.
Connections to the site are encrypted (HTTPS/HSTS). Passwords are hashed by Supabase Auth and never accessible in plain text. Row Level Security rules restrict access to each user's own data.
WikiRacing is not directed at children under 13 and does not knowingly collect data from them.
This policy may change over time; the "last updated" date at the top reflects the latest version.