Last updated: 2026-08-18
Apple TV Privacy Policy
This policy covers the Quizzy app for Apple TV specifically. The TV is a second screen — it shows the quiz to the room while everyone plays on their own device — and it is built to hold as little as possible.
The short version
- The TV app has no accounts and no sign-in. It never asks anyone in the room for a name, an email, or a password.
- It does not use the microphone, the camera, your Apple ID, your contacts, or your location.
- Everything about a game — player names, questions, answers, scores — arrives from the host's device only while the TV is paired, is held in memory, and is gone when the game ends or the app closes.
- The app sends anonymous product analytics and crash reports to Quizzy's own analytics server. The host can switch the game-related half of this off.
- No advertising, no ad identifier, no App Tracking Transparency prompt, no session recording, no data sales.
How the app works
When you open Quizzy on your Apple TV it shows a six-letter pairing code. A host enters that code on their phone or computer at quizzy.earth/host, and from that moment the TV subscribes to that one game and mirrors it: the lobby, each question, the reveal, and the final scores.
The TV is a display, not a participant. Players never interact with it — they answer on their own phones or laptops, and those answers travel to the host's game, not to the television. The TV has no keyboard entry, no payment surface, and no way to create or sign into an account.
What the app receives, and what it keeps
Game data
While paired, the TV receives the information it needs to draw the screen: the game code, the join link, players' chosen display names and avatar emoji, the questions and answer options, who has answered, and the scoreboard. This is the host's game data, shown on their screen at their request.
The TV holds it in memory only. It is not written to disk, and it is discarded when the host unpairs, when the app is closed, or when the Apple TV is powered off. The app does not keep a history of past games.
Question images
If a question has a picture, the TV loads it directly from wherever it is hosted — commonly Unsplash, or a URL the host supplied. That request reaches the image host in the ordinary way any web request does, which means it sees your network's IP address. Quizzy does not send those hosts anything about the game.
Storage on the television
The only thing the app writes to the device's own storage is the analytics library's queue of not-yet-sent events, so a power cut doesn't lose them. There is no cached game data, no saved credentials, and no persistent profile.
Analytics and diagnostics
We use PostHog to understand how the TV app performs in real living rooms, sent to our own analytics endpoint at t.quizzy.earth rather than to a third-party ad network. Events are attached to a random identifier generated by the app on first launch. That identifier is not your Apple ID, not the device's serial number, and not an advertising identifier, and it is never matched to a named person.
What is measured
- App and device facts — that this is a TV, whether it is tvOS or Android TV, the OS version, the app version and build, whether the screen is 1080p or 4K, the device make and model, and the language the TV is set to. Device make and model tell us whether our animations are affordable on the hardware people actually own.
- Reliability — whether pairing succeeded and how long it took, whether the connection dropped and recovered, and whether the TV's view of the game fell out of step with the host's.
- Legibility — how a question had to be sized to fit, and whether anyone had to scroll it with the remote. This is how we find questions that are unreadable from a sofa.
- Crashes — when the app fails, we send the error name and stack trace so we can fix it. This is capped at ten reports per session so a wedged TV cannot spam us.
Session replay is disabled in code. We do not record the screen, and we do not capture the text of questions or answers — only their measurements, such as how many characters long a question was.
Turning it off
Analytics is split in two. Events about the host's game carry the game code and follow the host's preference: if the host has opted out of analytics on their own device, they publish that when they pair, and the TV stops sending game-related events for the whole session.
Because a television in a living room is shared, this preference is deliberately never saved to the TV. It is held in memory for that one pairing and cleared when the host unpairs or the app restarts, so one guest's choice is never silently applied to the next person who uses the TV.
A small set of events describe the television rather than the game — that a pairing screen appeared, that pairing succeeded, that the app crashed. These are facts about our own software and are always sent. They carry no game code and are never linked to a game.
What the app does not do
- It does not request microphone or camera access. Sound is playback of bundled effects only.
- It does not read your Apple ID, iCloud account, contacts, photos, calendar, or location.
- It does not use the advertising identifier and shows no App Tracking Transparency prompt, because it does not track you across other companies' apps or websites.
- It does not show ads or contain in-app purchases.
- It does not record the screen or the room.
- It does not use your data to train AI models, and it does not sell data to anyone.
Who the data reaches
- Fly.io — hosts the realtime service the TV connects to over a secure websocket to receive game updates.
- Vercel — hosts quizzy.earth, including the join link the TV shows as a QR code.
- PostHog — product analytics and crash reporting, received through our own endpoint.
- Image hosts — Unsplash or whichever host a question's picture lives on, when the TV loads that picture.
- Apple — distributes the app through the App Store and provides its own aggregate crash and usage reporting, governed by Apple's privacy policy rather than ours.
Data retention
- Game data on the TV — memory only, discarded on unpair, app close, or power off.
- Live game data on our servers — deleted shortly after the game ends, as described in our main privacy policy.
- Analytics events — retained per PostHog's default retention policy, though we do not query data older than 12 months.
Children's privacy
Quizzy is used in classrooms and at family gatherings, including with children under 13. The Apple TV app collects nothing personally identifying from anyone in the room: there are no accounts, no email addresses, and no way for a player to type anything into the television. Player display names arrive from the host's game purely to be shown on screen, and teachers and parents should ask players to use first names or nicknames.
If you believe a child's personal information has reached us in a way that requires removal, email us using the address below and we will delete it promptly.
International users
Quizzy is operated from Australia. Using the app means your game data is processed on servers operated by the providers listed above, which may be located outside your country. Those providers maintain industry-standard safeguards including encryption in transit and at rest.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data we hold. Email hello@quizzy.earth and we will respond within 30 days.
How this relates to our main policy
This page describes the Apple TV app. Hosting a quiz, claiming a quiz, Quizzy Pro, emails, and everything else on the website are covered by our main privacy policy, which also applies to the account a host may be signed into while casting to a TV.
Changes to this policy
We may update this policy as the app evolves. The "Last updated" date at the top reflects the most recent revision.
Contact
Questions, concerns, or requests: hello@quizzy.earth.