Lie2Me — Privacy Policy
Last updated: 15 September 2026
This Privacy Policy explains what personal data the Lie2Me mobile game collects, why we collect it, who we share it with, and what you can do about it.
It applies to the Lie2Me app on iOS (bundle identifier com.twoliesandatruth.app) and on Android (application id com.lietome.app), and to the backend services that run the game.
Lie2Me is a party bluffing game. You write short statements about yourself — some false, at least one usually true — and the other players in your room try to work out which is which. That means the text you write is, by design, shown to other people. Please read section 3 before you start typing.
1. Who we are
Lie2Me is developed and operated by nstudio, established in Hungary ("nstudio", "we", "us"). For users in the European Economic Area and the United Kingdom, nstudio is the data controller for the personal data described in this policy.
You can reach us about anything in this policy, including any request to exercise your rights, at [email protected].
2. What data we collect and why
We collect only what the game needs in order to work, to stay secure, and to be paid for. The categories below describe everything the app transmits.
- Guest play: If you play without signing up, we create an anonymous Firebase account so your progress can be saved. We do not ask for your name or email address. All the gameplay and technical data below is still collected.
- Account and sign-in: If you sign in with email and password or with Google Sign-In, we receive and store your email address and a display name. We use them to identify your account, restore your progress on a new device, and let friends find you. We also store an internal Firebase user ID and a human-readable Game ID that other players can use to add you.
- Profile and progress: Level, experience points, Gems, Stars, achievements, owned items and entitlements, inventory, avatar, frame and profile style choices, gameplay statistics and rewarded-ad counters.
- Statements you write: The free-text statements you write about yourself are stored on our servers so that rounds can be played and so that you can reuse saved drafts. They are personal content written by you and are shown to the other players in your room.
- Relationship features: If you use Romance Mode and link a partner, we store that partner's user ID, display name, avatar and the relationship label you choose.
- Game sessions: Room membership, rounds, votes, scores, reactions, matchmaking tickets, daily challenge progress, match history and activity feed entries.
- Friends: Your friends list and the friend requests you send or receive.
- Purchases: If you buy something, the transaction is handled by Apple or Google and processed through RevenueCat, our purchase infrastructure provider. We store a record of what you own. We never receive or store your card details.
- Push notification identifiers: If you allow notifications, we store a Firebase Cloud Messaging registration token together with a platform label and timestamps, so we can tell you when it is your turn.
- Usage analytics: Firebase Analytics records an app instance identifier, event names such as which screens are opened and which game modes are played, and a coarse region derived from your IP address. We do not deliberately attach your user ID or email address to analytics records.
- Crash and performance diagnostics: Firebase Crashlytics collects crash reports, stack traces and performance diagnostics so we can fix faults. Before reports are sent, the app automatically redacts common sensitive patterns including email addresses, IP addresses, access tokens and account identifiers.
- Advertising data: Google AdMob receives a device advertising identifier and ad interaction data in order to deliver ads, cap how often you see them, and detect invalid traffic. See section 7.
- Stored only on your device: Ad frequency counters, language choice, onboarding and tutorial flags, audio and haptics preferences, and solo or couples session state are kept in local storage on your device and are never transmitted to us.
3. What other players can see
Lie2Me is a multiplayer game, so some of your data is visible to the people you play with. In a room, other players can see your display name, your avatar and frame, your level, the statements you submit in a round, and your votes and reactions once the round resolves. Players who know your Game ID can send you a friend request, and your friends can see your public profile.
Treat anything you type into Lie2Me the way you would treat a message sent to a group chat. Do not write anything — about yourself or about anyone else — that you would not want the other players in the room to read, screenshot or repeat.
4. Reporting, blocking and moderation
You can report a statement or a player from inside a match, and you can block another player so that you are no longer matched with them or contacted by them. When you submit a report, we receive the reported content, the identifiers of the reporting and reported accounts, and the room and round it came from.
We review reports in order to enforce the game's rules and to keep the service usable, and we may warn, suspend or permanently ban accounts as a result. This processing is based on our legitimate interest in preventing abuse.
5. Legal bases for processing
Under Article 6(1) of the GDPR we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): Creating and running your account, saving your progress, running matches and rooms, the friends system, and delivering purchases and entitlements you have paid for.
- Consent (Art. 6(1)(a)): Push notifications, and personalised advertising where you have agreed to it in the consent prompt described in section 7. You can withdraw consent at any time without affecting processing carried out before the withdrawal.
- Legitimate interests (Art. 6(1)(f)): Keeping the service secure and available, preventing cheating, abuse and fraud, moderating reported content, diagnosing crashes, and understanding in aggregate how the game is used so we can improve it.
- Legal obligation (Art. 6(1)(c)): Retaining accounting records relating to purchases and responding to lawful requests from competent authorities.
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you.
6. Service providers and SDKs we use
We do not sell your personal data and we do not share it with data brokers. We share data only with the following processors and partners, and only so that they can perform the function described:
- Google Firebase Authentication: Anonymous, email and password, and Google Sign-In accounts. Receives your email address and authentication identifiers. Firebase project: lies-and-truth.
- Google Cloud Firestore and Cloud Functions: The game database and server-side game logic. Store your profile, statements, rooms, rounds, friends and match history.
- Google Firebase Analytics: Usage events, app instance identifier and IP-derived coarse region, used to understand how the app is used.
- Google Firebase Crashlytics: Crash and error reports, used to diagnose faults.
- Google Firebase Cloud Messaging: Delivery of the push notifications you have enabled.
- Google Firebase Remote Config and App Check: Feature configuration, and attestation that requests to our backend come from a genuine, unmodified copy of the app.
- Google AdMob: Advertising identifier and ad interaction data, used to serve the interstitial and rewarded ads described in section 7.
- RevenueCat: Receives your Firebase user ID as a purchase account identifier, together with purchase and entitlement records, and manages in-app purchases across platforms.
- Apple App Store and Google Play: Process the payment itself and issue receipts. Their own privacy terms apply to the transaction.
- DiceBear: Avatar artwork is generated by an external image service, which receives your IP address as a consequence of your device loading the image.
We may also disclose data where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims.
7. Advertising
Lie2Me shows two kinds of ads through Google AdMob: occasional full-screen interstitial ads between solo levels, and rewarded video ads that you choose to watch in exchange for Gems. Rewarded ads are always opt-in. You can remove the interstitial ads permanently with the Remove Ads purchase; rewarded ads remain available because you choose when to watch them.
Lie2Me uses a Google-certified consent management platform. The first time you open the app in the European Economic Area, the United Kingdom or Switzerland, a consent prompt asks whether we and our advertising partners may use your data for personalised advertising. If you consent, the ads you are shown may be selected using a profile built from your activity in the app. If you decline, or until you have made a choice, ads are served on a non-personalised basis: they still use a device advertising identifier and limited context for frequency capping, measurement and fraud prevention, but they are not selected from a behavioural profile.
You can change your decision at any time from the privacy options entry in the app's settings. Withdrawing consent is as easy as giving it, and it applies to the ads you are served from that point onwards.
On iOS we do not request App Tracking Transparency permission and therefore cannot access the IDFA, and we do not track you across other companies' apps and websites.
8. Push notifications
With your permission we send notifications about your turn in an asynchronous game, daily challenge reminders, and friend activity. Notifications are optional. You can turn them off at any time in your device settings, or in the app's settings, and we will stop sending them.
9. Children and age rating
Lie2Me is rated 12+ and is not directed at children. Because the game is built around free-text statements written by players and shown to other players, it is not suitable for young children.
We do not knowingly collect personal data from children under 13. If you are below the age at which you can validly consent to the processing of your personal data in your country — 16 in Hungary and in a number of other EU member states — you may use Lie2Me only with the consent of a parent or legal guardian. If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it without undue delay.
10. How long we keep data
We keep your account data for as long as your account exists, and delete or anonymise it after deletion as described in section 11. Beyond that:
- Gameplay content: Statements, rounds and room data are deleted when the account is deleted. Room and matchmaking records are cleared on a rolling basis once the match has finished.
- Analytics data: Retained according to our analytics provider's standard retention period, which is up to 14 months for event-level data.
- Crash reports: Retained for approximately 90 days, in line with our diagnostics provider's standard period.
- Purchase and accounting records: Retained for as long as Hungarian accounting and tax law requires, which is currently eight years, even after the account itself is deleted.
- Moderation records: Reports and enforcement decisions are kept for up to 12 months so that repeat abuse can be recognised.
- Backups: Deleted data may persist in encrypted backups for a short period before those backups are overwritten on their normal rotation.
11. Deleting your account and data
You can ask us to delete your Lie2Me account and everything attached to it — your profile, your saved statements, your match history, your friends list, your relationship links and your notification tokens — at any time, and you do not need to have the app installed to do it.
Use the account deletion page: Delete your Lie2Me account.
Deletion is permanent and cannot be undone: your progress, purchased cosmetics and in-game currency are lost with the account. Deleting your Lie2Me account does not cancel or refund purchases made through Apple or Google; those are handled by the store you bought them from. Some records are retained for the limited periods set out in section 10 where the law requires it.
12. Your rights under the GDPR
If you are in the European Economic Area or the United Kingdom, you have the following rights in relation to your personal data:
- Access: To obtain confirmation of whether we process your data and to receive a copy of it.
- Rectification: To have inaccurate data corrected and incomplete data completed.
- Erasure: To have your data deleted, as described in section 11.
- Restriction: To have processing restricted in the cases set out in Article 18 GDPR.
- Objection: To object to processing based on our legitimate interests.
- Portability: To receive the data you provided to us in a structured, commonly used, machine-readable format.
- Withdrawal of consent: To withdraw consent at any time, without affecting processing carried out before the withdrawal.
To exercise any of these rights, write to [email protected]. We will respond within one month, and will tell you if we need longer because the request is complex. We may ask you to confirm your identity — for example by writing from the email address on the account — before we act on a request.
You also have the right to lodge a complaint with a supervisory authority. In Hungary this is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9-11., [email protected], www.naih.hu. If you live in another EEA country you may complain to your local authority; in the United Kingdom, to the Information Commissioner's Office.
13. International data transfers
Our service providers, including Google and RevenueCat, are established in or process data in the United States and other countries outside the European Economic Area. Where personal data is transferred outside the EEA or the UK, the transfer is covered by appropriate safeguards under Chapter V of the GDPR — the European Commission's Standard Contractual Clauses, the EU-US Data Privacy Framework where the recipient is certified under it, and additional technical measures such as encryption in transit and at rest.
You can request a copy of the safeguards applied to a given transfer by writing to us at the address in section 16.
14. Security
All traffic between the app and our backend is encrypted in transit with TLS, and unencrypted connections are blocked at the platform level on both iOS and Android. Access to the game database is governed by server-side security rules, requests to our backend are attested with Firebase App Check so that they must come from a genuine copy of the app, and sensitive credentials are not stored in plain text on your device. Crash reports are passed through an automatic redaction step before they leave the device. We never handle your card details.
No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data, and we will notify you and the competent supervisory authority of a personal data breach where the GDPR requires it.
15. Changes to this policy
We will update this policy when the app or the way we handle data changes. The new version is published on this page and the Last updated date above is revised. If a change is significant, we will tell you in the app before it takes effect. Continuing to use Lie2Me after a change takes effect means you accept the updated policy.
16. Contact
For any privacy question, or to exercise your rights, contact us at: [email protected]
Controller: nstudio, Hungary — operator of the Lie2Me mobile game (iOS com.twoliesandatruth.app, Android com.lietome.app).