Legal

Privacy Policy

Last Updated: October 5, 2026

This Privacy Policy describes how Taban Ion, operating as Adydino Studio (“we”, “our”, or “us”), collects, uses, stores, and shares information in connection with the mobile application Swords & Brains (the “App”), bundle id com.ion.taban.swords-and-brains (iOS) / com.ion.taban.swordsandbrains (Android).

Swords & Brains is primarily a device-local fantasy roguelike trivia game. There is no traditional account system (no email/password signup and no social login in the App). Data leaves your device only when you use optional online features or when third-party SDKs run for ads, purchases, multiplayer, or custom-topic generation.

1. Summary of practices

ChannelPurposeAccount required?
On-device storageSettings, saves, encyclopedia, scores, custom topicsNo
SupabaseMultiplayer rooms + custom-topic generation jobsNo (anonymous device / client ids)
OpenAI (server-side only)Generate custom trivia questionsNo (via Supabase Edge Function)
RevenueCatSubscriptions / Pro entitlementsStore account (Apple/Google)
Google Mobile Ads (AdMob)Rewarded + interstitial adsNo

There is no first-party analytics, crash reporter, or marketing attribution SDK in the App at this time (for example: no Sentry, Firebase Analytics, Amplitude, or AppsFlyer).

2. What we do not collect

Unless listed elsewhere in this Policy, the App does not knowingly collect or require:

  • Email address, phone number, or real name for an App account
  • Postal address or government ID
  • Precise GPS / continuous location
  • Contacts, photos, camera, or microphone content for gameplay
  • Social media profile linking
  • Payment card numbers (billing is handled by Apple or Google)
  • Children’s school or parental contact data beyond store age ratings

The display name used in multiplayer is a player-chosen nickname and is not a verified identity.

3. On-device data (stored locally)

Technology: AsyncStorage (unencrypted key-value storage on the device). This data is cleared if you uninstall the App or clear app data. It is not synced to a developer-controlled cloud save except where the features below explicitly send data.

3.1 Settings

  • Sound / music preferences
  • Notifications toggle (UI preference only — no push notification system is implemented in the current App)
  • Locale (en or ro; also influenced by device locale at first launch)
  • Trivia difficulty preference
  • Enabled / preferred topics for runs and multiplayer

3.2 Active single-player run

Full mid-run game state so you can continue: map progress, HP, inventory, artifacts, screen, topics, character, and related state. Tutorial runs are not persisted. Result screens clear the active save.

3.3 Meta progress & scores

  • Whether the Forest boss was defeated (unlocks harder difficulties)
  • Encyclopedia unlocks (revealed artifacts and enemies)
  • Highest recorded run score on this device

3.4 Custom topics library

Local copy of player-created topic packs: title, description, status, and generated questions/answers after download. Packs are designed to stay on the device after generation completes.

3.5 Anonymous identifiers (local)

  • A stable anonymous device id used for custom-topic rate limiting and job ownership
  • A stable anonymous multiplayer client id used for room membership
  • Last used multiplayer nickname (maximum 20 characters)

These identifiers are randomly generated on device and are not tied to your Apple or Google account email inside the App.

4. Online / server data

4.1 Supabase (backend)

We use Supabase for (1) multiplayer (database + realtime) and (2) custom topic generation jobs (Edge Function + jobs table). The App uses a public anon key configuration and does not use password login (session persistence is disabled).

Multiplayer data may include room codes, host/client ids, status, topics, difficulty, seeds, winner, display names, HP/loadout, ready/connected flags, round/question metadata, answer indices or guesses, response times, and continue acknowledgements.

Custom topic jobs may store an anonymous device id, title, description, locale, status/error metadata, and temporary generated questions until the client downloads and acknowledges. After acknowledgement, server-side payload cleanup is attempted. Job tables are not intended for direct anon client read/write; the Edge Function (service role) orchestrates them.

4.2 OpenAI (via Supabase Edge Function)

Custom topic generation calls a server-side function that uses OpenAI. Conceptually, generation may receive: topic title, description, locale, target question count, and device id for rate limits. It does not receive your Apple/Google account email, payment information, or full single-player run saves.

Prompts and content may be processed by OpenAI under OpenAI’s policies. Do not submit personal data or confidential information in topic titles or descriptions.

4.3 RevenueCat

We use RevenueCat to manage the Pro entitlement (swords_brains_pro), offerings, paywall, restore purchases, and Customer Center. Typical data includes anonymous or store-linked purchase identity, product identifiers, entitlement status, expiration/renewal, and purchase/restore events. The App does not log you into RevenueCat with a custom account id in the current build.

4.4 Google Mobile Ads (AdMob)

Ads may include rewarded flows (for example bonus coins or revive), and interstitial ads (including after biome bosses for non-Pro players). AdMob / Google may process advertising identifiers and device/ad interaction data under Google’s policies. On iOS, personalized ads may require App Tracking Transparency consent where applicable. The App’s tracking usage description states that the identifier may be used to deliver personalized ads.

Pro subscribers skip the forced boss interstitial; optional rewarded ads may still be available as player-initiated bonuses.

4.5 Device permissions & system APIs

Android may declare audio / media-related permissions used for playback (for example RECORD_AUDIO, MODIFY_AUDIO_SETTINGS, and foreground service media playback permissions aligned with expo-audio / background music — not voice chat). The App may read device language via localization APIs to default UI language (en/ro). A notifications preference exists in settings, but push notifications (FCM/APNs) are not implemented in the current App.

5. How we use information

  • Operate single-player gameplay and remember progress on your device
  • Enable optional multiplayer matches and fair play within a room
  • Generate and deliver custom trivia packs you request
  • Validate subscriptions and unlock Pro features (Mage, Custom Topics, skip boss interstitial)
  • Show ads in the free experience and optional rewarded placements
  • Prevent abuse (for example rate limiting custom-topic generation by anonymous device id)
  • Respond to support requests you send by email or the website contact form

6. Third-party processors

ProcessorRoleCategory
Apple / GoogleApp distribution and in-app purchase billingCommerce
RevenueCatSubscription entitlement syncCommerce
Google AdMobAdvertisingAdvertising
SupabaseDatabase, realtime, and edge functionsInfrastructure
OpenAILLM generation for custom topicsAI processing

We do not sell personal information for cash. Advertising SDKs may constitute “sharing” under some US state privacy laws — AdMob is disclosed accordingly.

7. Advertising & tracking

If you allow tracking on iOS (where prompted), advertising partners may use the advertising identifier to deliver personalized ads. You can change tracking permissions in iOS Settings. Android advertising preferences are controlled through your Google account / device settings. Limit Ad Tracking / opt-out tools provided by the platform may reduce personalized advertising.

8. Purchases

Payments are processed by Apple App Store or Google Play. We do not receive or store full payment card numbers. Purchase validation and entitlements may be handled by RevenueCat as described above. Refunds are governed by Apple or Google policies.

9. Children’s privacy

The App is a general-audience trivia/fantasy roguelike and is not directed at children under 13 (or under 16 where that is the relevant digital consent age). We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us and we will take appropriate steps to delete it. Final age rating is set in App Store Connect / Google Play Console.

10. Retention & deletion

DataRetention / deletion
Local saves / settingsUntil uninstall or clear app data
Multiplayer room rowsRemain on Supabase until deleted by ops / future cleanup (no in-app “delete my multiplayer history” today)
Custom topic jobsTemporary generation records keyed by device id; payload intended to clear after client acknowledgement
PurchasesSubject to Apple/Google + RevenueCat retention
AdsSubject to Google Ads retention

Controls available today include: deleting individual custom topic packs locally; managing subscriptions via RevenueCat Customer Center / store settings; leaving multiplayer rooms (match data may remain server-side); and uninstalling the App to remove local storage. There is currently no in-app “Delete all my cloud data” button — email us to request assistance.

11. Your rights (GDPR / EEA users)

If you are located in the European Economic Area, you may have the right to access, correct, delete, restrict, or object to certain processing, and to request data portability, subject to legal limits. To exercise these rights, contact us using the details below.

Legal bases we rely on may include: legitimate interests (operating the App, security, abuse prevention); contract (providing purchases/subscriptions you request); and consent (where required, including certain advertising/tracking choices).

12. International transfers

Supabase, OpenAI, Google, RevenueCat, and Apple/Google may process data in the United States or other countries. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses or the providers’ applicable transfer mechanisms and terms.

13. Security

  • Local game data is stored in AsyncStorage (not a secure enclave)
  • Multiplayer is an MVP: room codes should be treated as secrets; we do not promise bank-grade isolation between rooms
  • Custom topic prompts are rate-limited by anonymous device id (abuse prevention, not strong identity)
  • HTTPS is used for Supabase / store / ads SDKs as provided by those platforms

No method of electronic transmission or storage is 100% secure.

14. Changes to this Policy

We may update this Privacy Policy from time to time. Changes will be indicated by updating the “Last Updated” date above. Continued use of the App after changes means you acknowledge the updated Policy.

15. Contact

If you have questions about this Privacy Policy or wish to make a privacy request, contact:

Name: Taban Ion

Email: [email protected]

Country: Republic of Moldova