Effective and last updated: 29 July 2026
Who is responsible
DrawJury is operated by GF Lab International Limited. Privacy and safety enquiries: isaac.c@gofa.co.
Age and family notice
DrawJury is intended for people aged 13 and older. If local law requires parent or guardian consent for a teenager to use an online service, the account holder must obtain that consent. We do not knowingly allow children under 13 to create accounts. A parent or guardian may contact us to request review or deletion.
Data we collect
- Account data: Google or Apple account name, verified or private-relay email address, provider identifier and optional profile image; your DrawJury nickname, language and notification choices.
- Game and content data: submitted drawings, challenge and match records, AI assessments, saved artwork, share status, friends, private invitations and safety reports. Most unsubmitted strokes remain on your device. In an accepted anytime duel, the latest draft is stored temporarily so you can leave and return; it is deleted when submitted, when the match ends without a verdict, or when the account is deleted.
- Public-matchmaking data: when you explicitly switch on Open to public challenges, DrawJury stores your consent generation, selected language, recent account activity and assignment timing. It uses only your moderated nickname when selecting a compatible opponent. Anytime availability may remain active while the app is closed; Live availability always requires a recent foreground, challenge-ready heartbeat.
- Push-registration data: if you enable native notifications, DrawJury links an opaque installation ID to your account and stores the platform, an encrypted provider registration token, notification permission and enabled state, language, time zone, app version and first/last-seen timestamps. Notification payloads do not contain drawings, prompts, scores, email addresses or stable account identifiers.
- Purchase data: product, order or transaction identifiers, account-binding token, status, price/currency metadata and AI-pass balance. Stripe, Google Play and Apple process payment credentials; DrawJury does not receive full card details or Apple payment credentials.
- Technical and safety data: browser/app and device information, timestamps, security and diagnostic events, and a shortened one-way hash derived from network address for rate limiting. Sensitive request fields and drawings are redacted from application logs.
Why we use data
- Provide sign-in, rooms, drawing, AI judging, galleries, sharing, friends, invitations and support.
- When you opt in, select a compatible public challenge, keep the in-app invitation authoritative, and send a transactional invitation or game-update nudge to your registered devices. Optional email backup is a separate choice.
- Verify purchases, grant passes, prevent duplicate grants, reconcile refunds and protect the service from fraud or abuse.
- Moderate reported user or AI-generated content, enforce the safety rules and investigate service failures.
- We do not run behavioural advertising or sell personal data.
Services that process data
We use Google for web and Android sign-in and Android purchases, and Apple for iOS sign-in and In-App Purchase; Firebase Cloud Messaging and Apple Push Notification service to deliver opted-in native notifications; Vercel for hosting, runtime and AI Gateway; database/cache and object-storage providers for account, room and artwork records; OpenAI-compatible AI providers for challenge generation and judging; Resend for separately opted-in transactional and safety email; and Stripe for web payments. Each receives only the data needed for its function. Data may be processed outside Hong Kong under the provider's contractual safeguards.
What other people can see
Your email, provider identifier, account identifier and private gallery are not shown in public matchmaking. A Beacon candidate sees only your moderated nickname; your selected language limits who may be matched with you. A Live-room host receives a short-lived room-bound invitation token, not your account identifier. Players who join the same room or accept an Anytime duel see each other's nickname; Anytime drawings and feedback remain sealed until both official submissions receive the shared verdict. An artwork becomes publicly accessible only after you choose Share; deleting it disables its share link. We may disclose data when required by law or to protect users and the service.
Retention
Live availability expires after about five minutes without a foreground heartbeat. An unanswered Anytime invitation normally expires after 24 hours and an unfinished accepted duel after 72 hours. A native push registration that has not been refreshed for 30 days is no longer targeted and is deleted by scheduled cleanup; provider backups may expire later under their documented lifecycle. Ephemeral live rooms normally expire after two hours. Private artwork is normally retained for up to 365 days and explicitly public artwork for up to 730 days. Account, purchase, safety and audit records are kept while needed to provide the service, meet payment/security obligations, resolve reports or comply with law.
Your controls and deletion
You can turn off Open to public challenges immediately, disable push or email nudges independently, ignore an invitation or decline a letter, change your nickname, delete individual artwork, make or remove a public share, block a user, and delete your account from Account. Signing out unregisters that installation when the app supplies its installation ID. Account deletion removes account-linked push registrations, availability, notification preferences, private artwork, match history, friends, invitations and unsent notifications; shared official verdicts may remain without private account identity. You may also email isaac.c@gofa.co for access, correction, deletion or privacy questions.
Security
We use encrypted transport, HttpOnly signed sessions, server-side purchase verification, access controls, validation, rate limits and privacy-redacted logs. No online service can guarantee absolute security; please report suspected misuse promptly.
Changes and contact
We will update the date and policy when data practices materially change. Contact isaac.c@gofa.co for privacy, child-safety or data requests.