Privacy Policy
TooTall Gaming
Effective date: July 22, 2026
Last updated: August 2, 2026
Version: 1.1
1. The short version
- This policy covers the whole TooTall Gaming platform and every game on it. One account, one privacy policy.
- We collect what we need to run free social sports games: your email, your name, your nickname, your picks, and whatever you post.
- We do not sell your personal information. We have never sold it. We do not share it for advertising.
- There are no ads on TooTall Gaming. We use Google Analytics on our public web pages (not inside the signed-in app) to understand site traffic, and our own internal usage counts to run the service — details in Section 14.
- Profile photos are screened by an automated tool before anyone else can see them. That tool classifies image content. It is not facial recognition, and it does not create, collect, or store a faceprint or any other biometric identifier.
- You can delete your account from inside the app. Section 9 explains exactly what gets deleted and what does not.
The details are below. This policy is written to be read, not to be skimmed past.
2. Who we are
Mic Drop Ventures, LLC, a Florida limited liability company, operates the TooTall Gaming platform. We are the controller of the personal information described in this policy.
Mic Drop Ventures, LLC 5753 Hwy 85 N, PMB 4233 Crestview, FL 32536 support@tootallgaming.com (448) 777-6754
This policy is platform-wide. It covers the TooTall Gaming website at tootallgaming.com and its subdomains, all of our web and mobile applications, and every game or product we offer under the TooTall Gaming brand, now and in the future (each, a "Product"; together with the platform, the "Service").
You have one TooTall Gaming account across all Products. Your account information, profile photo, nickname, and blocks are account-level and apply everywhere, not per Product. If a future Product involves materially different privacy practices, we will describe them here or in-Product.
This policy does not cover third-party services you reach from the Service.
3. Information we collect
3.1 Information you give us
| What | Details | Why |
|---|---|---|
| Email address | Required to create an account and sign in | Authentication, account recovery, transactional email |
| First and last name | Provided at registration or by your sign-in provider | Identity within pools; commissioner administration; shown to pool-mates only if you turn on the profile setting |
| Nickname | Chosen by you; displayed to other members | Display name in pools, standings, and Smack Talk |
| Password | Only if you register with email and password. Stored as a salted cryptographic hash — we never store your password itself and cannot see it | Authentication |
| Profile photo | Optional. An image file you upload | Displayed as your avatar to members of your pools |
| Bio and location | Optional short free-text fields you can add to your profile | Displayed on your profile to members of your pools |
| Support messages | Anything you send to support@tootallgaming.com | Answering you; troubleshooting |
| Reports you submit | The content you report and any description you add | Reviewing and acting on reports |
3.2 Information created by using the Service
| What | Details |
|---|---|
| Picks and game history | Your picks and entries, results, scoring, standings, XP, and pool membership, across every Product you play |
| Smack Talk posts | Text you post, emoji reactions, and GIFs you select |
| Pool data | Pools you create or join, pool names and settings, invitations you send, and which Products you use |
| Blocks and mutes | Who you have blocked; who has been muted in a pool |
| Moderation records | Reports involving your content, filter events, actions we take, and the reasons |
| Terms acceptance | Which version of the Terms and photo policy you accepted, and when |
3.3 Information collected automatically
| What | Details |
|---|---|
| Session and authentication data | Session identifiers and tokens used to keep you signed in |
| Server logs | IP address, timestamp, requested URL, HTTP status, user agent, and referring page, recorded by our hosting and network providers |
| Security and rate-limiting data | Request counts, failed login attempts, and abuse signals used to protect the Service |
| Push notification token | If you enable notifications, a device-specific token used only to deliver them. See Section 15 |
We use the cookies and local storage necessary to sign you in and keep you signed in, and to remember basic preferences. On our public web pages, Google Analytics sets its own cookies to measure site traffic (Section 14). We do not use advertising cookies or cross-site tracking.
3.4 Information from third parties
- Apple Sign in / Google Sign-In. If you sign in this way, we receive your name and email address (or, if you use Apple's Hide My Email, a relay address that forwards to you) and a unique identifier for your account with that provider. We do not receive your password or access anything else in your Apple or Google account.
- Beta invitations. During our closed beta, we hold email addresses on an access list for people who have been invited but have not yet created an account. Those addresses are used only to permit account creation and are deleted when the closed beta ends or on request.
3.5 What we do not collect
We do not collect: government identification numbers; financial account or payment card information (the Service has no payment functionality); precise geolocation; contacts, photo libraries, camera roll, or microphone access beyond the single image you choose to upload; health information; biometric identifiers; or information from advertising networks or data brokers. We do not currently collect a date of birth.
4. How we use information
We use personal information to:
- create and maintain your account and authenticate you;
- operate the game — record picks, calculate scoring, standings, tiebreakers, and XP, and display results;
- display your nickname and profile photo to members of pools you belong to;
- deliver Smack Talk messages, reactions, and GIF selections within your pools;
- send transactional email — verification, password reset, invitations, and important notices about your account or the Service;
- screen uploaded photos and filter Smack Talk content as described in Sections 5 and 6;
- receive, review, and act on reports of abusive content or conduct;
- enforce our Terms of Service, investigate violations, and take account actions;
- protect the security and integrity of the Service, prevent fraud and abuse, and apply rate limits;
- diagnose and fix errors and improve the Service;
- respond to your support requests; and
- comply with law, including our reporting and preservation obligations regarding child sexual abuse material, and to respond to lawful requests, establish or defend legal claims, and enforce our agreements.
We do not use your personal information for advertising, ad targeting, profiling, or automated decision-making that produces legal or similarly significant effects about you. We do not send marketing email.
5. Automated photo screening — what it is and what it is not
This section matters. Read it if you upload a photo.
5.1 We screen photos before publishing them. When you upload a profile photo, it is stored privately in a pending state and submitted to an automated screening service. Our systems are designed not to display it to other users until it passes. Screening is automated and may occasionally be delayed, bypassed, or fail — we do not guarantee that any particular photo was screened, and publication is not our review or approval of it.
5.2 What the screening service does. We use Google Cloud Vision SafeSearch Detection. It analyzes an image and returns likelihood ratings across five content categories — adult/sexually explicit, violence, racy, medical, and spoofed. We act only on the clearly-explicit signals: adult content and graphic violence. Images flagged at those thresholds are rejected and not published; the remaining categories do not by themselves cause rejection. We receive a category rating. We do not receive, and the service does not produce for us, any identification of who is in the image.
5.3 What the screening service does not do — and this is deliberate.
The screening we perform is content classification. It is not facial recognition, face matching, face detection for identification, or any form of biometric processing.
Specifically:
- We do not use facial recognition or face-matching technology.
- We do not scan, extract, measure, derive, generate, or store face geometry, facial landmarks, faceprints, face templates, face embeddings, or any other biometric identifier or biometric information.
- We do not attempt to identify who appears in a photo, match a photo against any database of faces, match a photo against another photo, or link a photo to any person's identity.
- We do not use the SafeSearch API's separate face-detection capability, and we do not use any other face-detection, face-analysis, or identity-verification feature of any provider.
- We do not use uploaded photos to estimate age, sex, ethnicity, emotion, or any other personal characteristic.
- We do not use your photos to train, tune, or improve any machine learning model, and our agreements with our providers do not permit them to do so with our content.
The only question the screening asks is: does this image contain explicit content? Nothing about who is depicted.
5.4 Hash-based CSAM screening on delivery. Images that are published and served through our media domain are additionally screened by Cloudflare's CSAM Scanning Tool, which compares a mathematical fingerprint (a hash) of an image against hash lists of known child sexual abuse material maintained by child-protection organizations. This check runs at delivery only — a photo rejected at upload is deleted without being hash-scanned, because it is never delivered. This is a fingerprint comparison against known illegal material. It is not facial recognition and does not identify individuals. If a match is reported to us, we follow the process in Section 8.4.
5.5 Automated screening is not human approval. Automated screening is imperfect. A photo passing screening does not mean we have reviewed, approved, or endorsed it. Photos can also be reported by users and removed by us at any time.
5.6 If your photo is rejected. You are told the upload was not accepted and you can upload a different photo. A rejected photo is not published and is deleted, along with its stored file — except where we reasonably need to retain a copy to enforce our Terms, defend a claim, or comply with law, including the preservation obligation described in Section 8.4. If you believe a rejection was a mistake, contact support@tootallgaming.com.
6. Smack Talk content filtering
Smack Talk posts pass through an automated server-side filter that blocks certain categories of harmful content, including slurs, explicit sexual content, and certain threatening or self-harm content. This filter analyzes the text of your message at the time you send it. It does not build a profile of you, and its results are not used for any purpose other than blocking prohibited content and enforcing our Terms. Filter events may be logged for abuse prevention and enforcement.
7. Who we share information with
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not disclose personal information to data brokers, advertisers, or ad networks.
7.1 Other users
- Members of your pools see your nickname, your profile photo, your picks (after applicable lock times), your standings, your XP, your Smack Talk posts, and your full name, if you've chosen to share it.
- Pool commissioners can see the same information for members of their pool and can use commissioner tools within it.
- Your full name is only shown to other members if you choose to share it — a profile setting that is off unless you turn it on. Your email address is never displayed to other members — except that a pool's commissioners and co-commissioners can see the email addresses used for that pool's invitations, including after those invitations are accepted.
- Members of one pool do not see your activity in pools or Products they do not share with you.
Blocking applies across the whole platform and is not symmetrical — you stop seeing the blocked member, but they continue to see you and are not notified. Section 10.4 of our Terms of Service describes exactly what blocking does and does not do.
7.2 Service providers
We use the following processors. Each is bound by contract to process personal information only on our instructions and to protect it.
| Provider | What it does | What it handles | Location |
|---|---|---|---|
| Render.com | Application hosting, database, background jobs | All account data, content, picks, logs | United States (Oregon) |
| Cloudflare, Inc. | DNS, CDN, network security, R2 image storage, CSAM hash scanning | Traffic metadata, IP addresses, stored images | United States / global network |
| Google Cloud (Vision API) | Automated image content classification | Uploaded profile photos, at the moment of screening | United States |
| Giphy | GIF search and delivery | Search terms you type in the GIF picker; request metadata | United States |
| Resend | Transactional email delivery | Your email address and message contents | United States |
| Apple Inc. | Apple Sign in; app distribution | Authentication identifiers | United States |
| Google LLC | Google Sign-In; app distribution; push delivery | Authentication identifiers, push tokens | United States |
| Expo | Push notification delivery | Device push tokens, notification contents | United States |
| Google Analytics (Google LLC) | Website traffic measurement on public pages | Pages visited, browser/device type, approximate location from IP, analytics cookie identifiers | United States |
Note: when you search for a GIF, your search term is sent to Giphy. Giphy is a third party with its own privacy practices, and its handling of that request is governed by its own policy.
7.3 Legal and safety disclosures
We may preserve and disclose personal information and content when we believe in good faith that it is necessary to:
- comply with a law, subpoena, court order, warrant, or other lawful request;
- report apparent child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC) and to law enforcement, as required by 18 U.S.C. § 2258A, and to preserve related material as required by that statute;
- enforce our Terms of Service or investigate a violation;
- detect, prevent, or address fraud, abuse, security, or technical problems; or
- protect the rights, property, or safety of Mic Drop Ventures, our users, or the public.
7.4 Business transfers
If we are involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, personal information may be transferred as part of that transaction.
8. How long we keep information
8.1 Active accounts. We keep your account information for as long as your account exists.
8.2 After you delete your account. See Section 9 for exactly what is deleted and what is retained.
8.3 Backups. Deleted data may persist in encrypted database backups for currently approximately 3 days after deletion, after which those backups expire on a rolling schedule and the data is unrecoverable. Backups are not used to restore individual deleted accounts.
8.4 Child sexual abuse material — mandatory preservation. If we identify apparent child sexual abuse material and report it to NCMEC's CyberTipline, federal law requires us to preserve the reported content and related information for one year following submission of the report (18 U.S.C. § 2258A(h)). We preserve that material in a restricted, access-controlled store, separate from the ordinary operation of the Service. This preservation happens even if the associated account is deleted, and it overrides deletion requests, because it is a legal obligation. We do not view, copy, or distribute such material beyond what the law requires, and access is limited to what is necessary to comply. We may retain it longer where the statute permits, or where required by legal process.
8.5 Other retention.
| Category | How long |
|---|---|
| Server and security logs | Typically 30–90 days, per our providers' configurations |
| Moderation and enforcement records | While the account exists, and afterward as needed to enforce bans, defend claims, and detect repeat abuse |
| DMCA notices and counter-notices | Retained as needed to administer our repeat-infringer policy |
| Support correspondence | Up to 2 years |
| Terms acceptance records | For the life of the account and for the applicable limitations period afterward |
| Beta access-list emails | Until the closed beta ends or on request |
9. Deleting your account — what actually happens
You can delete your account from within the Service. Deleting your account deletes it across the entire platform, in every Product — not from one game at a time. Deletion is permanent and cannot be undone. Here is precisely what happens.
9.1 Permanently deleted
- Login credentials — your password hash, and any Apple or Google sign-in connections
- Active sessions and tokens — you are signed out everywhere
- Your push notification token — deleted, so no further notifications can be delivered to your device
- Your profile photo — removed from our database and deleted from image storage, subject only to the legal preservation exception in Section 8.4
9.2 Overwritten with anonymized values
- Your email address — replaced with a synthetic, non-deliverable placeholder
- Your first and last name — replaced with placeholder values
- Your nickname — replaced; your account displays as "Deleted user" with a generic avatar
Because names are rendered by a live reference to your user record, every past post and standing entry immediately displays as "Deleted user" the moment deletion completes.
9.3 Retained
- Your Smack Talk posts. The text of your posts is not deleted. Posts stay in the pools where you made them, attributed to "Deleted user."
- Your game history in every Product — picks and entries, results, standings, and XP — retained under the anonymized identity.
9.4 Why we retain that
Two reasons, and we want you to be able to evaluate them:
- Contest integrity. Pools are shared records. Erasing one member's picks and results would corrupt the historical standings, week-by-week results, and season records of every other member of that pool — people who did not ask for their records to change. Retaining anonymized contest history preserves the accuracy of other users' data.
- Conversation integrity. Smack Talk is a group conversation. Removing one participant's messages leaves other members' replies without context.
9.5 What this means for you — please read
Anything you typed about yourself in Smack Talk survives your account deletion, unattributed to your name but still readable. If you posted your phone number, your employer, your street, a health detail, or anything else personal, deleting your account does not remove that text.
If you want specific posts gone, remove them before you delete your account — delete them yourself, ask your pool commissioner to remove them, or email support@tootallgaming.com with details and we will remove them. We will honor reasonable requests to remove specific posts containing your own personal information, before or after account deletion.
9.6 Exceptions
Deletion does not extend to: encrypted backups until they expire (Section 8.3); material we are legally required to preserve (Section 8.4); records needed to enforce a ban or to establish, exercise, or defend legal claims; and information already disclosed to law enforcement under Section 7.3.
10. Your choices and rights
10.1 Available to everyone, regardless of where you live:
| Right | How |
|---|---|
| Access your information | Email support@tootallgaming.com; most of it is visible in the app |
| Correct your name or nickname | In your account settings, or email us |
| Change your email address | In your account settings |
| Remove or replace your photo | In your account settings |
| Delete your account | In the app, subject to Section 9 |
| Get a copy of your data | Email support@tootallgaming.com and we will send you a copy |
| Ask us to remove specific posts | Email support@tootallgaming.com |
| Block another user | In the app |
| Report content | In the app |
| Opt out of non-essential email | Unsubscribe links; note that we cannot exclude you from essential account and security messages while you have an account |
10.2 How to make a request. Email support@tootallgaming.com from the address on your account, or use the in-app tools. We may need to verify your identity — usually by confirming control of the account email — to protect against fraudulent requests. We aim to respond promptly, and we will tell you if a request will take longer.
10.3 No retaliation. We will not deny you service, charge you differently, or provide a lesser experience because you exercised a privacy right.
10.4 If we decline. If we decline a request, we will tell you why. You are welcome to write back with more information and we will take another look.
11. Children's privacy
11.1 Under 13. The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. Our Terms of Service require users to be at least 13.
11.2 If we learn of an under-13 account. We will terminate the account and delete the personal information associated with it, including any uploaded photo, promptly and without requiring a request.
11.3 If you are a parent or guardian. If you believe a child under 13 has created an account or that we hold information about a child under 13, email support@tootallgaming.com with the nickname, the pool, or any other identifying detail. We will investigate and delete the account and its information. You may also ask us to remove a photo of your child that another user uploaded — see Section 11.4.
11.4 Photos of children uploaded by others. If someone has uploaded a profile photo that depicts your child, tell us at support@tootallgaming.com and we will remove it. You do not need to prove anything beyond a reasonable explanation of the relationship. You can also report the photo from within the app.
11.5 Users aged 13 to 17. Users in this range may use the Service with the consent and involvement of a parent or legal guardian, as required by Section 3.3 of our Terms. We apply the same data practices to them, and we do not target them with advertising because we do not run advertising at all.
12. State privacy laws
12.1 Where we stand today. Most U.S. state comprehensive privacy laws apply only to businesses meeting defined size or activity thresholds, and we are a very small business that does not sell or share personal information. As of the effective date of this policy, we do not believe the California Consumer Privacy Act applies to us. Other states set applicability differently — some by revenue or volume, some by other measures — and we assess our obligations as our size and practices change.
12.2 We make these controls available to everyone. Rather than gate rights behind thresholds and state lines, we generally make the controls in Section 10 available to every user — access, correction, deletion, a copy of your data, and non-retaliation — regardless of where you live.
12.3 Sale and sharing. We have not sold personal information, and we have not shared it for cross-context behavioral advertising, in the preceding 12 months, and we do not do so now. We do not use or disclose sensitive personal information for purposes that would require an opt-out. Because we do not sell or share personal information, browser opt-out signals such as Global Privacy Control have nothing to act on here.
12.4 What would change this. These conclusions depend on our current size and practices. They would need to be reassessed if we cross a revenue or volume threshold, introduce advertising, add payment functionality, or begin any activity that would constitute a sale or sharing of personal information.
12.5 California "Shine the Light." We do not disclose personal information to third parties for their direct marketing purposes.
13. Security
We protect personal information with measures including: encryption in transit (TLS) and at rest; salted cryptographic password hashing; access controls limiting administrative access to authorized operators; rate limiting and abuse detection; private-by-default storage for pending photo uploads; and restricted, access-controlled storage for legally preserved material.
No system is perfectly secure. We cannot guarantee absolute security, and you provide information at your own risk. If we become aware of a breach affecting your personal information, we will notify you and any required authorities as the law requires.
14. Advertising, analytics, and tracking
14.1 Analytics we use. TooTall Gaming contains no advertising and no advertising SDKs. We use two kinds of analytics:
- Google Analytics on our public web pages (the landing and policy pages — not inside the signed-in app). It helps us understand how visitors find and use the site. It collects usage information such as pages visited, browser and device type, approximate location derived from your IP address, and sets analytics cookies. We have disabled Google's advertising features, so this data is used for measurement only. Google's own privacy policy applies to its processing.
- Our own internal usage counts across the service — for example, when an account was last active and how many people have signed up — computed on our own servers, visible only to the platform operator, and never shared. These are operating records, not third-party tracking.
We do not track you across other sites or apps. The mobile app contains no analytics or tracking SDKs, and we do not engage in "tracking" as that term is defined by Apple's App Tracking Transparency framework, nor use the Advertising Identifier. We also use search-engine webmaster tools (such as Bing Webmaster Tools) to see how search engines index the site; these show us search and crawl statistics, not anything about your account.
14.2 Do Not Track. We do not track users across sites, and we do not respond to browser Do Not Track signals. If you prefer not to be counted by Google Analytics, common browser tools such as Google's Analytics opt-out add-on or content blockers will work normally — we do nothing to defeat them.
14.3 If this changes. If we add further analytics or ever introduce advertising, we will update this policy to identify the provider, describe what is collected, and provide any choices the law requires.
15. Push notifications
We offer push notifications for game results, pick deadlines and lock reminders, chat mentions and replies, and commissioner notices.
If you enable them, your device provides a push token, which we store and use only to deliver notifications you have turned on. Delivery involves Expo together with Apple's and Google's push infrastructure, which means the notification content passes through those services.
You control notifications two ways: per-pool notification preferences inside the Service, and the OS-level permission in your device settings. Turning notifications off at the device level stops all of them. Your push token is deleted when you disable notifications or delete your account.
16. Where we operate
We are based in the United States, our providers store and process information in the United States, and the Service is intended for U.S. users. The Service is intended for users in the United States and is not directed to the European Economic Area, the United Kingdom, or Switzerland. This policy does not address the GDPR or UK GDPR. If you access the Service from outside the United States, understand that your information will be processed in the United States under U.S. law.
17. Changes to this policy
We may update this policy. When we do, we will post the updated version with a new effective date and version number.
For material changes, we will make reasonable efforts to notify you — by email to the address on your account, by an in-app notice, or both. Changes are effective when posted, or on the effective date stated in the updated policy. Where the law requires your consent to a change, we will obtain it.
18. California residents — notice under Civil Code § 1789.3
California Civil Code § 1789.3 requires us to provide the following notice to California users of an electronic commercial service.
Provider of the Service: Mic Drop Ventures, LLC 5753 Hwy 85 N, PMB 4233 Crestview, FL 32536 support@tootallgaming.com
Cost of the Service: The Service is provided free of charge. There are no fees or charges of any kind.
To file a complaint or seek information about the Service, contact us at support@tootallgaming.com, or contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs in writing at 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or by telephone at (800) 952-5210.
19. Contact us
Questions, requests, or complaints about privacy:
Email: support@tootallgaming.com
Mic Drop Ventures, LLC Attn: Privacy 5753 Hwy 85 N, PMB 4233 Crestview, FL 32536 (448) 777-6754
We read every message.
© Mic Drop Ventures, LLC. TooTall Gaming is a platform operated by Mic Drop Ventures, LLC.
