Privacy policy

Last updated April 30, 2026

Xamsa (“we”, “us”) provides a social, real-time quiz platform. This policy describes what we process when you use the service. It is general information, not legal advice. If you need help, contact us through the support channel shown in the product.

Account and authentication

We use Better Auth for sign-up, sign-in, email verification, password reset, and OAuth. If you choose Google, Google receives standard OAuth metadata as part of that flow.

Data we store

Application data — including your profile, packs, topics, questions, gameplay history, and moderated public content — is stored in our PostgreSQL databases. We retain it as needed to run the service and meet legal obligations.

Realtime

Live gameplay features may use Ably for realtime messaging between clients and servers.

Email and notifications

Transactional email (verification, password reset, and certain notices) may be sent through Resend. You can stop marketing-style messages where we offer opt-out; operational messages related to security or your account may still be sent.

Media

Profile images may be processed and delivered using Cloudinary.

Analytics

Where enabled by configuration, we may use PostHog for product analytics. You may control trackers through your browser settings where applicable.

Optional AI-assisted features

If enabled, helpers that suggest quiz topics may call Google’s Gemini API. Request content is limited to what you submit for that feature; avoid pasting secrets or unnecessary personal information.

Public content and moderation

Published packs and other content you submit may be visible to other users. We may moderate material that violates rules or poses safety risks.

Your choices

You can access and update profile information while signed in. You may ask about deletion or data portability through support; verification may be required.

See also: Terms of Service