Privacy Policy
Last updated: August 21, 2026
Smart Fella or Fart Smella is part brain workout and part arcade, with a very stupid name. This policy explains, in plain language, what the app collects (not much), why, and the choices you have.
About this policy
Effective date: July 25, 2026
Last updated: August 21, 2026
This Privacy Policy is provided by Kim Khoi Lam, the operator of the Smart Fella or Fart Smella mobile app (the “app”). It explains, in plain language, what information the app handles when you play, why we handle it, and the choices you have.
We wrote this policy to be easy to read. If anything here is unclear, please reach out through our support page.
Who we are
Kim Khoi Lam makes and operates Smart Fella or Fart Smella. You can reach us through the contact details in the Contact us section below.
Smart Fella or Fart Smella is a brain-training and casual-games app: part brain workout, part arcade. Quick logic, memory, focus, and word games with a very stupid name.
The short version
Here is the whole policy in a nutshell.
- Signing in is optional. The games work without an account.
- We collect very little: what the app needs to run, plus usage analytics so we can improve it.
- We never sell or share your personal data, and there are no third-party ads.
- The app is made for teens and adults, and it is not directed to children under 13. The free test on this website is different: children do take it, and we never ask a child for their own contact details. See the test on this website.
- We may send the odd note about our own app, but only to addresses given on or after August 12, 2026, and you can stop it whenever you like. Older addresses keep the promise they were given. See Email we send you.
- You can ask us to delete your data at any time through our support page.
Who the app is for
Smart Fella or Fart Smella is made for teens and adults who like silly humour and quick brain games. It is rated 4+ because there is nothing objectionable in it, but it is not designed for or directed to children under 13, and it is not enrolled in Apple’s Kids Category.
We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, contact us and we will delete it.
The free test on this website is a separate thing. It is offered from Grade 3 upward, so children plainly do take it, and we have designed it so that we never ask a child for their own contact details. What that means in practice is set out in The test on this website below.
Information we collect and why
We keep data collection small and honest. Here is what the app may handle and why.
| Data | Purpose | Source |
|---|---|---|
| Account email | Create and secure your optional account. | You, at sign-in, handled through Supabase using email and password, Google, or Apple. |
| Google profile basics (name, email, avatar) | Identify your account if you choose Google sign-in. | Google (only if you use Google sign-in). |
| Apple account basics (name, email) | Identify your account if you choose Sign in with Apple. | Apple. With Apple’s Hide My Email, the email may be a private relay address that forwards to us. |
| Game scores and progress | Save your progress, personal bests, and achievements. | Your gameplay in the app. |
| Pro entitlement status | Know whether your unlock or subscription is active. | RevenueCat, based on your Apple or Google purchase. |
| App usage events (screens viewed, buttons tapped, purchases started or completed) | Understand which parts of the app work and which do not, so we can improve it. Not used for advertising. | Your use of the app, sent to PostHog. |
| Limited technical data | Deliver over-the-air updates and keep the app working. | Expo and EAS. |
The app does not collect or store payment card data. Apple and Google process all payments. We use a privacy-friendly analytics tool (PostHog) to understand how the app is used in aggregate, and we do not add advertising trackers.
Analytics, and what we deliberately do not do. We use PostHog to see how the app is used in aggregate. We have turned off the things that would matter most for privacy: we do not record your screen, we do not automatically capture what you tap, we do not collect your IP address or location, we do not use advertising identifiers, and we do not build an advertising profile.
How analytics connect to your account. PostHog gives your install its own identifier. If you sign in and buy, our payments provider (RevenueCat) reports that purchase against the same identifier, and your purchases are tied to your account, so your analytics events can be connected back to that account. We use this to answer questions like whether people who reach the paywall go on to buy. If you never sign in, there is no account for any of it to connect to.
How we use information
We use the limited information above to:
- provide and run the games;
- save your progress and achievements;
- enable and restore purchases and subscriptions;
- secure accounts and prevent abuse;
- understand how the app is used, in aggregate, so we can improve it;
- respond to your support requests;
- tell you about our own app, but only if you gave us your address on or after August 12, 2026. What that covers and how to stop it is set out in Email we send you; and
- meet our legal obligations.
We do not use information for behavioral advertising, and we do not build advertising profiles.
Email we send you
Until now the only email this site has ever sent anybody is the one carrying their test results, which they asked for by typing an address in. From August 12, 2026 we may also send the occasional note about our own app. This section says what that means, and it says just as plainly who it does not apply to.
- What we send. News that the app has launched or changed in a way worth knowing about, and now and then a note about what we are building next. That is the whole list.
- How often. Rarely. We are thinking a few times a year, and we would rather send nothing than send filler. If that ever stops being true, this line changes before the sending habit does.
- Who it goes to. Only addresses given to us on or after August 12, 2026.
- How to stop it. Ask us and we stop, for good. Today that means one line to smartfellaorfartsmella123@gmail.com or a message through our support page. You never have to give a reason.
If you gave us your address before August 12, 2026, none of the above applies to you. When those addresses were given, this policy said the address would not be used to send you anything you did not ask for, and it listed what a results address would be used for and said nothing else. Those sentences are still further down this page, in the same words, and they still govern every address collected while they were the live wording. A policy can only speak for what happens after it is written. Changing one does not reach backwards, and we are not going to pretend otherwise by quietly counting old addresses as new ones. If we ever want to send those people something, we will ask them first and they can say no.
We are not sending any of this until there is a one-click way out of it. Saying you can stop at any time is only honest if stopping is easy, and writing to a human and waiting is not easy enough for mail you did not go looking for. So no product email leaves here until every one of them carries its own unsubscribe link and our postal address at the bottom. This paragraph comes down when that is built, and not before.
What has not changed. We still do not sell your address, we still do not share it with anyone outside the people who run this site, and we still do not use it for advertising or to build an advertising profile. Telling you about our own app is not the same thing as either of those, and we would rather keep that distinction than trade it for a wider permission we do not need. Everything else this policy says about your address, including how to have it deleted, is unchanged.
Legal bases (GDPR)
For players in the European Economic Area and the United Kingdom, we rely on these legal bases:
- Contract. To provide the app and the features you ask for, including the unlock and any subscription.
- Consent. For optional sign-in. You can withdraw consent at any time.
- Legitimate interests. To keep the service secure and working, and to understand how the app is used in aggregate so we can improve it.
Children under 13
The app.It is not designed for or directed to children under 13, and it is not enrolled in Apple’s Kids Category.
The test on this website.This one is offered from Grade 3 upward and children do take it. We do not ask a child to sign in, we do not ask a child for their name, their age or their email address, and we do not ask for anything that identifies them. To see the results, the test asks for a parent or guardian’s email address, and it says so on the screen in words a child can read. The full detail is in The test on this website below.
- We do not knowingly collect personal information from children under 13.
- We keep collection small for everyone: an optional account email, your game progress, and whether the unlock is active.
- We do not show behavioral ads or use third-party ad tracking.
- We do not sell or share personal data.
- If you believe a child under 13 has provided us personal information, tell us through our support page or email smartfellaorfartsmella123@gmail.com and we will delete it.
No sale or sharing of personal data
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, in the sense those terms are used under California law (CCPA and CPRA). This applies to everyone.
Third-party service providers
We use a small set of trusted providers (sometimes called subprocessors) to run the app. They process data on our behalf, under their own terms and safeguards.
- Supabase. Authentication and database hosting (stores your account and game data). Privacy policy.
- RevenueCat. Manages purchase and entitlement status so we know whether your unlock is active. Privacy policy.
- Apple. Sign-in and payment processing on iOS. Privacy policy.
- Google. Sign-in and payment processing on Android. Privacy policy.
- Expo and EAS. App builds and over-the-air updates. Privacy policy.
- PostHog. Privacy-friendly product analytics, used to understand how the app is used in aggregate. Analytics data is not used for advertising and is not sold. PostHog also holds the email addresses collected on our website, and the results of tests taken on it, kept in its data warehouse as separate lists rather than joined to the analytics above; see About this website and Test results in our analytics warehouse below. Privacy policy.
Data retention
We keep information while your account is active and for a reasonable period afterward for legal, security, and operational reasons. When you ask us to delete your data, we delete it. We may keep anonymized or aggregate information that does not identify you.
Analytics events. Analytics events are kept for seven years. That is the retention period our analytics provider applies to our plan, and it is not a setting we can shorten.
Website session recordings. Recordings of browsing sessions on this website are kept for 30 days and then deleted. This applies to the website only. The app does not have a session-recording module installed, so there are no app recordings to keep.
Email addresses. This one works differently. The copy of the list in PostHog is a mirror of our own database, refreshed hourly, and it keeps no history: each refresh replaces the whole list rather than adding to it. So unlike the analytics data above, deleting your email from our database does remove it from PostHog, at the next refresh.
Test results. A saved result from the test on this website, and any email address stored with it, is deleted twelve months after the test was taken. It holds a score and the answers given, is reachable only through the link we email, and carries the address the results were sent to, if any were. The copy of these results in PostHog works the same way as the email list above: it is replaced whole every hour and keeps no history, so a result deleted from our database is gone from PostHog within the hour. See The test on this website and Test results in our analytics warehouse.
How to delete your account and data
You can ask us to delete your account and data at any time.
- Visit our support page, or email us at smartfellaorfartsmella123@gmail.com.
- Tell us that it is a deletion request, and let us know which account it is for.
- Help us confirm you own the account, so we can protect it from someone else.
We aim to complete verified requests within 30 days. You can find more help on our support page.
International data transfers
We operate from the United States, and our providers may process data in the United States and other countries. When information crosses borders, we rely on appropriate safeguards for the transfer.
How we protect information
We use reasonable technical and organizational measures to protect the small amount of data we hold. These include access controls and row level security in Supabase, encryption in transit, and limiting who can access data. No online service can be perfectly secure, but we work to keep your information safe.
Your rights
Depending on where you live, you may have rights under laws such as the GDPR and California’s CCPA and CPRA, including the right to:
- access the personal information we hold about you;
- correct information that is wrong;
- delete your information;
- receive a copy of your information (portability);
- object to or restrict certain processing;
- withdraw consent where we rely on it; and
- opt out of the sale or sharing of personal information (we do not sell or share it).
We will not discriminate against you for using these rights. To exercise any of them, visit our support page or email smartfellaorfartsmella123@gmail.com.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will change the effective date at the top of this page. For material changes, we will surface a notice in the app or on this site.
Contact us
Questions, requests, or privacy concerns? Please reach out:
- Kim Khoi Lam
- Mailing address: 309 E 21st St, Austin, TX 78705
- Email: smartfellaorfartsmella123@gmail.com
For help or to make a privacy request, visit our support page. You can also read our Terms of Service.
The test on this website
This website offers a free timed reasoning test. There is a version for adults and a shorter version for children, offered from Grade 3 upward. Children take it, usually because a parent handed them the phone, so this section says plainly what happens to their information. It is separate from the app described above.
Nothing identifies the child.There is no sign-in and no account. We do not ask for a name, an age, a birthday, a school, or a child’s own email address, and there is no free-text box for one to be typed into. The one address involved is an adult’s, typed by them or with their say-so, and it is stored against the result. That is set out in full below.
What we handle when someone takes the test
- The grade that was picked, so we know which set of questions to show.
- The answers given and the score. These are saved so the results page can be reopened from the link we email. They are held in the link itself, and they carry no name.
- A parent or guardian’s email address, given at the end so the results can be sent. On the children’s version the screen asks for a parent’s address in so many words. This address joins the same list as any other signup on this site, tagged so we can tell which part of the site it came from, and it is also saved alongside that result. See below.
- Anonymous usage events, which record that a test was started and finished, the score, the grade band and how long it took. They never carry an email address, and we deliberately do not record which option was chosen on each individual question.
How long results are kept. A saved result is deleted twelve months after the test was taken, and after that the emailed link stops working and says so.
The link carries the result inside it. What it holds is which test was taken, the grade it was set for, the answers given, how long it took, whether the clock ran out, and when it was finished. That is encoded rather than encrypted, so anyone holding the link can read it. It carries no name and no email address. Treat it as private for the same reason you would treat a shared document link as private: whoever has the link can see the result.
What it cannot do is be forged or altered. The link is signed with a key only we hold, so changing any character of it makes the page refuse the whole thing rather than show an edited result, and nobody can invent a working link or work one out from another. The twelve-month expiry is inside that signature too, which is why it cannot be stretched.
When you ask us to email a result, that address is stored with that result. Until you type an address in, a result is just a score and a set of answers with nothing identifying attached to it. Sending it is what joins the two, and we keep them joined.
On the children’s version that means an adult’s address stored against a child’s test performance.We would rather say that plainly than leave you to work it out. The child’s name is never asked for and there is nowhere to type one, so what is stored is an adult’s email address, a grade, a score and the answers. Not a named child.
That pairing is also readable in our analytics warehouse, which is set out in Test results in our analytics warehouse. If you read one more section of this policy, read that one.
What it is for. Three things, and nothing else: so we can answer you if you write to us about your result, so we can delete everything properly when you ask, and so we can see whether people who ask for their results score differently from people who do not. We do not sell it, we do not share it with anyone outside the people who run this site, and we do not use it to advertise to you.
That paragraph is the promise these addresses were given under, and it still holds for every one of them. On August 12, 2026 we began allowing ourselves to send the occasional note about our own app, and only to addresses given on or after that day. The paragraph above is left standing word for word rather than rewritten, because it is what people were actually told at the moment they typed an address in, and a promise you can no longer find is one nobody can hold us to. See Email we send you.
How long, and deleting it. A result and any address stored with it are deleted twelve months after the test was taken. Before that, you can ask us to delete them at any time through our support page: tell us the address and we will remove it from the mailing list and delete the results stored against it. If you only have the link from the email, send us that instead and it will find the same record.
One limit worth being honest about: anonymous usage events, which carry a score and a grade band but never an address, cannot be traced back to you and so cannot be picked out and deleted individually. There is nothing in them that identifies you, which is the same reason we cannot find yours.
About this website (separate from the app)
This section and the one before it are about this website (smartfellaorfartsmella.com), which is separate from the app described above. Both the website and the app use PostHog for analytics, configured differently: the website’s setup is described here, and the app’s more restricted setup is described in the sections above.
- Website analytics. This site uses PostHog for privacy-friendly, anonymous analytics (for example, page views and general usage). It does not collect personal information that identifies you, we do not use it for advertising, and we do not sell the data.
- Website session recordings. This site also records browsing sessions, so we can see where the page confuses people. Every input is masked, so anything you type (including your email) is never captured, and the recordings leave out request and response bodies, headers, and console logs. The app does not do this at all: it has no session-recording module installed.
- Email addresses. If you give us your email address, whether at the end of the test or through a signup form, we store it in our own database and also mirror it into PostHog’s data warehouse as a separate list, so we can query signups internally. Each address is tagged with the part of the site it came from, which is how we tell those routes apart. That list stands on its own: it is not linked to the anonymous analytics above, it is not joined to any profile or to anyone’s browsing behavior, it is not used for advertising, and it is not sold. That remains true of the list. What is no longer true of everything in the warehouse is set out next: an address given so that a test result could be emailed is now also held beside that result, which is a link the sentence above does not cover. See Test results in our analytics warehouse. What the list may be used to send you, and the date that changed, is in Email we send you.
- SFFS Creator Studio (our own posting tool). We operate an internal tool that publishes our own videos to a TikTok account that authorized it, using TikTok Login Kit and the Content Posting API. It only posts to the authorized account, uses only the scopes granted, stores access tokens securely, and access can be revoked at any time from TikTok settings. This use also follows the TikTok Developer Terms of Service.
Test results in our analytics warehouse
We mirror completed tests from our own database into PostHog’s data warehouse, in the same way and for the same reason as the email list described above: so we can count and read them internally without going to the live site for every question. This section says plainly what that means for anyone who asked to have a result emailed to them.
No new addresses, but a new link. This did not send a single new email address to PostHog. Every address involved was already there as part of the email list. What is new is the link: an address now sits beside the result it belongs to, where before the two were held apart.
What is now attached to an address. For a completed test that carries one: which test was taken, the score and the score it was out of, how many questions were answered, how long it took in seconds, whether the time ran out, the verdict the test gave, the moment it was finished recorded to the second, and the platform and referring domain the visit arrived from. A test finished without an address being given carries no address here either, and those results are still counted.
This includes children’s tests, held against an adult’s address. The children’s test asks for a parent or guardian’s address, so where one was given, what can now be read together is an adult’s email address, the grade band the test was set for, and the score the child got. A grade band says roughly how old the child is, which makes this the most sensitive thing described on this page. That is why it has a paragraph of its own rather than a line in a list. The child’s name is still never asked for, and there is still nowhere for one to be typed in.
How separate this really is. The separation is structural rather than enforced, and the difference is worth stating. We do not identify anyone to PostHog, we do not create or update any PostHog profile from this data, and nothing joins these rows to the anonymous analytics automatically. But the table can be queried by anyone with access to our PostHog project, and a query could join an address to event data. So the honest sentence is that we do not link them, rather than that they can never be linked. Access to the project is limited to the people who run this site.
What it is not used for. It is not used for advertising, it is not sold, it is not shared with anyone outside the people who run this site, and it is not used to send you anything you did not ask for.
The last of those four still stands for every address given before August 12, 2026, which is all of them at the time of writing. From that date, an address given to us may also be used to send the occasional note about our own app, and only if it was given on or after that date. The first three do not change for anybody: still no advertising, still not sold, still not shared outside the people who run this site. See Email we send you.
Deleting it, and why that works here. The mirror keeps no history: each hourly refresh replaces the whole table rather than adding to it. Deleting a result from our database therefore removes it from PostHog at the next refresh, within the hour. That is a real deletion rather than a request to a third party, and it is worth contrasting with the anonymous analytics events described under Data retention, which our provider keeps for seven years on a schedule we cannot shorten. To ask for a deletion, use our support page: tell us the address, and we will remove it from the email list and delete the results stored against it.
What this website keeps in your browser
This website leaves four things in your browser’s own storage. Here they all are, with how long each one lasts and how to get rid of it. Three of them are ours. The fourth belongs to PostHog, our analytics provider, which is listed under Third-party service providers above. This section is about the website; the app is a separate thing and is described further up.
| What it is, and whose | How long it lasts | How to remove it |
|---|---|---|
| A link back to your last result Ours, in this browser’s local storage. | Until you clear it. We stop offering it once it is twelve months old, which is when the link itself expires. | Clear this site’s data in your browser settings. Having another result emailed to you replaces it. |
| A flag marking this browser as one of ours Ours, in this browser’s local storage. | Until you clear it. | Clear this site’s data, or use the control on the page that sets it to switch it back off. |
| PostHog’s analytics entries PostHog’s, in one cookie plus several browser storage entries. | The cookie lasts twelve months. Most of the storage entries last until you clear them, and a few last only as long as the tab is open. | Clear this site’s cookies and data in your browser settings. |
| How far you have got through the test Ours, in this tab’s session storage. | Until the tab closes, when the browser discards it. | Close the tab. |
The saved link is the one we emailed you. We write it only after a results email has actually been sent, never before, and what we keep is that link and the date we kept it. Nothing is stored beside it: no email address, and nothing that would let a returning visit display a score or a verdict before the link is opened. It is there so that someone who finished the test and closed the tab is offered their result above the opening question, rather than being dropped at that question with no way back to what they earned. It is a copy of the same link, kept locally, and not a second route to the result. What that link itself carries, and why it is worth treating as private, is set out under The test on this website above.
The internal-user flag is a team tool, and an ordinary visit never sets it. Someone working on this site opens /internal in their own browser so that their visits stop skewing our numbers. It does not stop those visits being recorded. It labels them, and the label is what keeps them out of the reports we read.
The ph_entries are PostHog’s rather than ours. They are what its software uses to tell one visit from the next, and they are the mechanics behind the anonymous website analytics described in About this website. What is in them is a randomly generated visitor and session id, the kind of device and the page you arrived from, and the analytics settings themselves. No email address and no test result is kept in any of them.
Your progress through the test is deliberately the shortest-lived thing here. It holds the answers given so far and the time left on the clock, and it sits in session storage, which belongs to one tab and is thrown away when that tab closes. That is enough for an accidental refresh part-way through a timed test not to lose the answers already given. Storage that outlived the tab would have kept a half-finished attempt for days, and we chose against it on purpose: this is often a phone a parent hands to a child, and nobody should open the site and land in somebody else’s abandoned test.
There is no cookie banner here, and this section is not asking you to agree to anything. Where a browser sends a Global Privacy Control or Do Not Track signal, we turn analytics capture off in response rather than putting the question to you. Worth knowing either way: the ph_ entries are still created when capture is off, so finding them in your browser does not on its own mean anything is being recorded.

