Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how Eponymical Games Ltd ("we", "us", "our") collects, uses and protects personal data when you visit our website or use our apps, including MenuSage, Learn Piano: Play Songs and Red Flag Detector.
1. Who we are
Eponymical Games Ltd is a private limited company registered in England and Wales, based at 86-90 Paul Street, London, EC2A 4NE, United Kingdom. For the purposes of UK data protection law, including the UK GDPR and the Data Protection Act 2018, we are the controller for the personal data described in this policy.
Contact: direct@eponymicalgames.com. We have not appointed a data protection officer because we are not currently required to do so.
2. Information we collect
- Information you give us - such as your name, email address, waitlist signup, support messages and any details you include in a message.
- Account information - if you create an account or sign in, we may process your email address, display name, sign-in provider identifier and authentication identifiers from providers such as Apple, Google, Facebook and Firebase.
- MenuSage health preferences - health-related flags, allergies, dietary goals and an optional note that you choose in MenuSage. The profile is stored on your device. When you request an analysis, the active profile is transmitted with the selected menu or prepared-food image solely to produce that result; it is not written to MenuSage cloud history.
- Menu and prepared-food images and analysis requests - an image of a menu or prepared food that you take or select, any OCR text derived from it, the active profile and app language are transmitted through our proxy to Google Gemini. A random installation identifier and technical request data reach our proxy for rate limits and abuse prevention but are not included in the Gemini prompt. Our proxy processes the image in memory and does not save the image to a database or object-storage bucket. Google may retain limited request data for abuse monitoring or other purposes described in its applicable terms. Small preview images stay only on your device.
- MenuSage history and feedback - the generated analysis JSON, cuisine or context, top pick, dish and verdict counts, model/prompt version, timestamps, and feedback such as ordered, skipped or liked. Without sign-in this stays on the device. If you explicitly sign in with Apple or Google, the latest 300 records sync to Firebase under your account identifier; analysis photos, previews and the health profile are excluded from that cloud history.
- Learning and app content - in-app progress such as songs played, arrangements, levels completed, scores, streaks, saved settings, imported learning material, downloaded catalog items and generated practice data.
- Audio, MIDI, score and microphone data - microphone input may be used for pitch detection and recording features. User-selected audio, MIDI, MusicXML, PDF, score and similar files may be used for import, transcription, notation, catalog, playback and practice features. By default, live pitch detection and local song analysis are designed to run on the device. If you choose a cloud or third-party analysis endpoint, the selected file or derived analysis data may be sent to that configured service.
- Photos and local face signals - Red Flag Detector may let you take or choose a photo so the app can generate an entertainment-only red or green flag result. In the current TestFlight candidate, photos are intended to be processed locally on your device, simple face signals may be read by the on-device detector when available, and the app does not upload photos or face data to us.
- Purchase and subscription data - Apple and services such as PurchaseKit or RevenueCat may provide product identifiers, transaction identifiers, subscription status, entitlement status, renewal/cancellation information and app user or installation identifiers. We do not receive your full payment card details.
- Advertising, analytics and attribution data - app events, crash logs, device identifiers, consent status, approximate region, IP address, campaign attribution signals, SKAdNetwork postback data, ad impressions/clicks and related diagnostics. The Identifier for Advertisers (IDFA) is collected only if you grant permission through Apple's App Tracking Transparency prompt.
- Technical data - device model, operating system, app version, browser information, push notification tokens, IP address, approximate region, diagnostics and performance data collected to keep our services secure and working.
3. How we use your information
- To provide the website, app, account, practice, import, recording, analysis and saved-progress features you request.
- To send launch news and early-access updates where you asked for them.
- To respond to enquiries and provide support.
- To personalise your learning experience, sync progress where enabled and track practice history.
- To analyse a menu or prepared-food image you select against the MenuSage preferences you choose and return food recommendations, cautions and, where relevant, a phrase you can use with restaurant staff.
- To keep MenuSage history locally and, only after an explicit Apple or Google sign-in, synchronize the latest 300 analysis records and feedback across your devices.
- To generate local entertainment-only Red Flag Detector results from photos you choose or take.
- To process purchases, subscriptions, entitlements, restores, refunds and billing support.
- To request notification permission and send app notifications where you enable them.
- To measure advertising performance, prevent duplicate purchase reporting, improve acquisition campaigns and comply with app-store privacy rules.
- To keep our services secure, debug problems and prevent abuse.
- To comply with legal obligations.
4. Legal bases for processing
We rely on the following legal bases under UK GDPR: contract (to provide the app, account features, purchases and support you request); consent (for marketing emails, optional app permissions, tracking permission, non-essential cookies and personalised advertising where required); legitimate interests (to run, secure, debug and improve our services, measure non-personalised performance and prevent abuse); and legal obligation (where the law requires us to process or retain data).
5. Sharing your information
We do not sell your personal data. We share it only with service providers who help us operate the Services, and only as needed to perform those services on our behalf, with your consent where required, or as required by law.
- Apple for App Store distribution, TestFlight, in-app purchases, subscriptions, Sign in with Apple, push notification infrastructure, Apple Music/MusicKit permissions where enabled and App Tracking Transparency controls.
- Google/Firebase for Google authentication, Firebase Authentication and Firestore cloud sync, and in other apps for analytics, Crashlytics diagnostics, Firebase Cloud Messaging and advertising/consent SDKs such as Google Mobile Ads and User Messaging Platform.
- Google Gemini API to process MenuSage menu or prepared-food images, OCR text where available and the active on-device profile for the analysis you request. We use a paid API project; Google states that paid-service prompts and responses are not used to improve its products, although limited safety and abuse-monitoring retention may still apply.
- Google Ads and Google tag for website advertising measurement only after website cookie consent where required.
- PurchaseKit and RevenueCat for purchase validation, subscription entitlement management and app-store purchase analytics. MenuSage uses PurchaseKit; other Eponymical Games apps may use RevenueCat.
- UniversalMMP, our attribution service, for MenuSage's random installation identifier, platform, country derived from device locale, install/session records and product events. It does not receive your health-profile selections, analysis photo or cloud-history record UUID, does not use IDFA and is not used for cross-app tracking.
- Meta/Facebook for optional login, app events, advertising attribution, SKAdNetwork-related campaign measurement and ad mediation where enabled.
- GitHub Pages for website hosting, FormSubmit for contact/waitlist form delivery, and Google Fonts for website font delivery.
- AI or analysis providers only if you choose to enable a configurable cloud analysis endpoint or similar feature in the app.
6. App privacy and tracking
The App Store privacy label must reflect the data practices of each app and any third-party SDKs included in it. MenuSage processes health-related preferences and menu or prepared-food images for app functionality, account identifiers and optional cloud history for app functionality, and a random installation identifier and product interaction events for first-party analytics. Because that random installation identifier accompanies an analysis request to our proxy, the analysis image is treated as linked to a device identifier for Apple's privacy-label purposes even though it is not linked to a Firebase account and is not used for tracking. MenuSage does not access IDFA and does not use data for cross-app tracking. Learn Piano: Play Songs may include data types such as user content, audio data, purchases, identifiers, usage data and diagnostics depending on which features are enabled. Red Flag Detector's current TestFlight candidate is designed not to collect data from you: selected photos and simple face signals are processed locally for the joke result, are not stored by us, are not uploaded to us and are not used to identify you. Tracking for advertising or attribution in apps where it is enabled is subject to Apple's App Tracking Transparency prompt and your device settings.
7. Audio files, MIDI, scores, catalog items and generated materials
Audio files, MIDI files, MusicXML files, PDFs, score files, recordings and catalog downloads are processed to provide learning, transcription, notation, playback and practice features. Local processing means the analysis happens on your device where technically supported. If cloud analysis is enabled and you choose to use it, your selected audio or derived analysis data may be transferred to the configured analysis provider. Generated notes, arrangements and practice results may be stored locally or synced to your account if sync is enabled.
Catalog downloads may be cached on your device and may use technical data such as app version, file identifiers, file size, checksum, download status and diagnostics to deliver, verify or troubleshoot the catalog. Rights complaints, DMCA notices and related support messages are handled through direct@eponymicalgames.com.
8. Red Flag Detector photos
Red Flag Detector is an entertainment app. It is not a personality, relationship, health, identity, safety or biometric identification service. The current TestFlight candidate does not require an account, does not connect to a backend, does not include a live ad network and does not collect analytics. If you share a generated result through your operating system's share sheet, the destination app you choose handles that shared image under its own privacy terms.
8A. MenuSage image analysis and cloud history
MenuSage is a food recommendation aid, not a medical device or clinical service. A request to our Cloud Run proxy contains the menu or prepared-food image and any OCR text you selected, the active health-related profile stored on your device, app language, prompt version and a random installation identifier used for rate limits and abuse prevention. The proxy sends the image, OCR/profile context and prompt to Google Gemini, but not the installation identifier. The proxy does not persist the analysis image or health profile. We do not opt MenuSage requests into model-improvement datasets.
Without an account, analysis history stays on your device. If you explicitly sign in with Apple or Google, Firebase stores the latest 300 analysis snapshots and feedback records under your Firebase user ID so they can sync across devices. That cloud record does not include the analysis photo, its local preview, your health profile, email address or display name. You can delete synced history or delete the account from MenuSage settings. Account deletion removes the Firebase user and MenuSage cloud history. To stop an already-authorized request from recreating deleted data, we temporarily retain a one-way hash of the deleted Firebase user ID as a security tombstone; Firestore automatically expires it after 24 hours. Apple, Google, app-store and legally required transaction records may be governed by their own retention obligations.
9. Data retention
We keep personal data only for as long as needed for the purposes described above, or as required by law. Waitlist and support messages are kept while we need them to communicate with you and handle support. Account, purchase and entitlement records may be retained for security, dispute handling, tax, accounting and app-store compliance. MenuSage's proxy does not persist menu or prepared-food images or health profiles; its account cloud history is limited to the latest 300 analysis and feedback records until you delete the history or account. After account deletion, the one-way hashed security tombstone described above expires automatically after 24 hours. Local app data remains on your device unless you delete it, uninstall the app or enable a sync/cloud feature. You can ask us to delete your data, although some transaction or compliance records may need to be retained by Apple, Google, PurchaseKit, RevenueCat or us where legally required.
10. Your rights
Under UK data protection law you may have rights to access, correct, delete or restrict the processing of your personal data, object to processing, withdraw consent and receive certain data in a portable format. To exercise these rights, email direct@eponymicalgames.com. You also have the right to complain to the UK Information Commissioner's Office (ICO).
11. Children's privacy
Our Services are designed for a general audience and music learners, but are not directed at children under the age where parental consent is required by applicable law. MenuSage is intended only for users aged 18 or older because its AI provider's current developer terms impose that age boundary. Where another Service permits use by a child, a parent or guardian should manage their use, permissions and any sign-up. We do not knowingly collect more personal data from children than is necessary for the requested feature and will delete such data on request where required.
12. Cookies and similar technologies
Our website uses essential local storage or similar technologies to remember choices such as cookie consent. We load Google Ads measurement tags only after you accept non-essential measurement cookies. You can change cookie settings through your browser by clearing site data. The app may use SDK identifiers and similar technologies for authentication, analytics, crash reporting, purchases, advertising measurement and consent management. You can control app tracking through iOS settings and app permissions such as microphone or notifications through your device settings.
13. International transfers
Some providers may process data outside the UK. Where that happens, we take steps designed to protect your data through appropriate safeguards required by law, such as adequacy regulations, contractual protections or other lawful transfer mechanisms.
14. Security
We use appropriate technical and organisational measures to protect personal data. No method of transmission or storage is completely secure, but we work to safeguard the information we process.
15. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "last updated" date above and, where appropriate, let you know or ask for renewed consent.
16. Contact us
Questions about this policy, your data, rights complaints, DMCA notices, subscriptions, refunds, support or any other matter should be sent by email:
Eponymical Games Ltd
86-90 Paul Street, London, EC2A 4NE, United Kingdom
direct@eponymicalgames.com