Privacy Policy

Last updated: February 2026

WHODUNIT PARTY is a murder mystery party platform. We built it to be fun and simple — and we want our privacy practices to be the same. This page explains what data we collect, why we collect it, and who sees it.

What We Collect

When you create an account, we collect your email address. This is handled by Supabase Auth — a managed authentication service. When you create a party, we store your party configuration: theme, guest count, tone, and other settings you choose. When your guests complete questionnaires, we store their answers to personalize the mystery. Payment information is processed entirely by Stripe. We never see or store your card number — only a Stripe customer ID and payment status.

How We Use Your Data

We use your email to manage your account and send transactional emails (invite links, character kits) via Resend. We use your party configuration and guest questionnaire answers to generate your murder mystery story through OpenAI's API. We use PostHog for product analytics — understanding which features get used and where people drop off — in a cookie-less, memory-only mode so we do not need a consent banner.

AI-Generated Content

We use AI (OpenAI) to generate murder mystery stories, character roles, and clue cards based on your party configuration and guest questionnaire answers. Your data is sent to OpenAI's API for processing. We do not use your data to train AI models. OpenAI processes this data according to their privacy policy.

Who Sees Your Data

We use a small number of trusted services to run the platform:

  • Supabase — database and authentication
  • Stripe — payment processing
  • OpenAI — AI story generation
  • Resend — transactional email delivery
  • PostHog — product analytics (cookie-less)
  • Vercel — hosting and edge infrastructure

We do not sell your data. We do not share it with advertisers.

Data Retention

Party data is retained while your account is active. If you delete your account, all associated data is removed from our systems. Guest questionnaire answers are tied to the party and removed when the party host deletes their account.

Your Rights

You can request a copy of your data or ask us to delete it at any time. Email us at support@whodunit.party and we will respond within 5 business days.

Cookies

We do not use cookies for analytics. PostHog runs in memory-only mode. Supabase Auth uses essential session cookies to keep you logged in — these are necessary for the service to function and do not track you across other sites.

Changes to This Policy

We will update this page when our practices change. If the changes are material, we will send you an email. The date at the top of this page reflects the most recent update.

Contact

Questions about your privacy? Email us at support@whodunit.party.