Legal
Privacy Policy
Last Updated: October 5, 2026
This Privacy Policy describes how Taban Ion, operating as Adydino Studio (“we”, “our”, or “us”), collects, uses, stores, and shares information in connection with the mobile application Swords & Brains (the “App”), bundle id com.ion.taban.swords-and-brains (iOS) / com.ion.taban.swordsandbrains (Android).
Swords & Brains is primarily a device-local fantasy roguelike trivia game. There is no traditional account system (no email/password signup and no social login in the App). Data leaves your device only when you use optional online features or when third-party SDKs run for ads, purchases, multiplayer, or custom-topic generation.
1. Summary of practices
| Channel | Purpose | Account required? |
|---|---|---|
| On-device storage | Settings, saves, encyclopedia, scores, custom topics | No |
| Supabase | Multiplayer rooms + custom-topic generation jobs | No (anonymous device / client ids) |
| OpenAI (server-side only) | Generate custom trivia questions | No (via Supabase Edge Function) |
| RevenueCat | Subscriptions / Pro entitlements | Store account (Apple/Google) |
| Google Mobile Ads (AdMob) | Rewarded + interstitial ads | No |
There is no first-party analytics, crash reporter, or marketing attribution SDK in the App at this time (for example: no Sentry, Firebase Analytics, Amplitude, or AppsFlyer).
2. What we do not collect
Unless listed elsewhere in this Policy, the App does not knowingly collect or require:
- Email address, phone number, or real name for an App account
- Postal address or government ID
- Precise GPS / continuous location
- Contacts, photos, camera, or microphone content for gameplay
- Social media profile linking
- Payment card numbers (billing is handled by Apple or Google)
- Children’s school or parental contact data beyond store age ratings
The display name used in multiplayer is a player-chosen nickname and is not a verified identity.
3. On-device data (stored locally)
Technology: AsyncStorage (unencrypted key-value storage on the device). This data is cleared if you uninstall the App or clear app data. It is not synced to a developer-controlled cloud save except where the features below explicitly send data.
3.1 Settings
- Sound / music preferences
- Notifications toggle (UI preference only — no push notification system is implemented in the current App)
- Locale (en or ro; also influenced by device locale at first launch)
- Trivia difficulty preference
- Enabled / preferred topics for runs and multiplayer
3.2 Active single-player run
Full mid-run game state so you can continue: map progress, HP, inventory, artifacts, screen, topics, character, and related state. Tutorial runs are not persisted. Result screens clear the active save.
3.3 Meta progress & scores
- Whether the Forest boss was defeated (unlocks harder difficulties)
- Encyclopedia unlocks (revealed artifacts and enemies)
- Highest recorded run score on this device
3.4 Custom topics library
Local copy of player-created topic packs: title, description, status, and generated questions/answers after download. Packs are designed to stay on the device after generation completes.
3.5 Anonymous identifiers (local)
- A stable anonymous device id used for custom-topic rate limiting and job ownership
- A stable anonymous multiplayer client id used for room membership
- Last used multiplayer nickname (maximum 20 characters)
These identifiers are randomly generated on device and are not tied to your Apple or Google account email inside the App.
4. Online / server data
4.1 Supabase (backend)
We use Supabase for (1) multiplayer (database + realtime) and (2) custom topic generation jobs (Edge Function + jobs table). The App uses a public anon key configuration and does not use password login (session persistence is disabled).
Multiplayer data may include room codes, host/client ids, status, topics, difficulty, seeds, winner, display names, HP/loadout, ready/connected flags, round/question metadata, answer indices or guesses, response times, and continue acknowledgements.
Custom topic jobs may store an anonymous device id, title, description, locale, status/error metadata, and temporary generated questions until the client downloads and acknowledges. After acknowledgement, server-side payload cleanup is attempted. Job tables are not intended for direct anon client read/write; the Edge Function (service role) orchestrates them.
4.2 OpenAI (via Supabase Edge Function)
Custom topic generation calls a server-side function that uses OpenAI. Conceptually, generation may receive: topic title, description, locale, target question count, and device id for rate limits. It does not receive your Apple/Google account email, payment information, or full single-player run saves.
Prompts and content may be processed by OpenAI under OpenAI’s policies. Do not submit personal data or confidential information in topic titles or descriptions.
4.3 RevenueCat
We use RevenueCat to manage the Pro entitlement (swords_brains_pro), offerings, paywall, restore purchases, and Customer Center. Typical data includes anonymous or store-linked purchase identity, product identifiers, entitlement status, expiration/renewal, and purchase/restore events. The App does not log you into RevenueCat with a custom account id in the current build.
4.4 Google Mobile Ads (AdMob)
Ads may include rewarded flows (for example bonus coins or revive), and interstitial ads (including after biome bosses for non-Pro players). AdMob / Google may process advertising identifiers and device/ad interaction data under Google’s policies. On iOS, personalized ads may require App Tracking Transparency consent where applicable. The App’s tracking usage description states that the identifier may be used to deliver personalized ads.
Pro subscribers skip the forced boss interstitial; optional rewarded ads may still be available as player-initiated bonuses.
4.5 Device permissions & system APIs
Android may declare audio / media-related permissions used for playback (for example RECORD_AUDIO, MODIFY_AUDIO_SETTINGS, and foreground service media playback permissions aligned with expo-audio / background music — not voice chat). The App may read device language via localization APIs to default UI language (en/ro). A notifications preference exists in settings, but push notifications (FCM/APNs) are not implemented in the current App.
5. How we use information
- Operate single-player gameplay and remember progress on your device
- Enable optional multiplayer matches and fair play within a room
- Generate and deliver custom trivia packs you request
- Validate subscriptions and unlock Pro features (Mage, Custom Topics, skip boss interstitial)
- Show ads in the free experience and optional rewarded placements
- Prevent abuse (for example rate limiting custom-topic generation by anonymous device id)
- Respond to support requests you send by email or the website contact form
6. Third-party processors
| Processor | Role | Category |
|---|---|---|
| Apple / Google | App distribution and in-app purchase billing | Commerce |
| RevenueCat | Subscription entitlement sync | Commerce |
| Google AdMob | Advertising | Advertising |
| Supabase | Database, realtime, and edge functions | Infrastructure |
| OpenAI | LLM generation for custom topics | AI processing |
We do not sell personal information for cash. Advertising SDKs may constitute “sharing” under some US state privacy laws — AdMob is disclosed accordingly.
- Google Privacy Policy
- Google AdMob / advertising help
- RevenueCat Privacy Policy
- Supabase Privacy Policy
- OpenAI Privacy Policy
7. Advertising & tracking
If you allow tracking on iOS (where prompted), advertising partners may use the advertising identifier to deliver personalized ads. You can change tracking permissions in iOS Settings. Android advertising preferences are controlled through your Google account / device settings. Limit Ad Tracking / opt-out tools provided by the platform may reduce personalized advertising.
8. Purchases
Payments are processed by Apple App Store or Google Play. We do not receive or store full payment card numbers. Purchase validation and entitlements may be handled by RevenueCat as described above. Refunds are governed by Apple or Google policies.
9. Children’s privacy
The App is a general-audience trivia/fantasy roguelike and is not directed at children under 13 (or under 16 where that is the relevant digital consent age). We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us and we will take appropriate steps to delete it. Final age rating is set in App Store Connect / Google Play Console.
10. Retention & deletion
| Data | Retention / deletion |
|---|---|
| Local saves / settings | Until uninstall or clear app data |
| Multiplayer room rows | Remain on Supabase until deleted by ops / future cleanup (no in-app “delete my multiplayer history” today) |
| Custom topic jobs | Temporary generation records keyed by device id; payload intended to clear after client acknowledgement |
| Purchases | Subject to Apple/Google + RevenueCat retention |
| Ads | Subject to Google Ads retention |
Controls available today include: deleting individual custom topic packs locally; managing subscriptions via RevenueCat Customer Center / store settings; leaving multiplayer rooms (match data may remain server-side); and uninstalling the App to remove local storage. There is currently no in-app “Delete all my cloud data” button — email us to request assistance.
11. Your rights (GDPR / EEA users)
If you are located in the European Economic Area, you may have the right to access, correct, delete, restrict, or object to certain processing, and to request data portability, subject to legal limits. To exercise these rights, contact us using the details below.
Legal bases we rely on may include: legitimate interests (operating the App, security, abuse prevention); contract (providing purchases/subscriptions you request); and consent (where required, including certain advertising/tracking choices).
12. International transfers
Supabase, OpenAI, Google, RevenueCat, and Apple/Google may process data in the United States or other countries. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses or the providers’ applicable transfer mechanisms and terms.
13. Security
- Local game data is stored in AsyncStorage (not a secure enclave)
- Multiplayer is an MVP: room codes should be treated as secrets; we do not promise bank-grade isolation between rooms
- Custom topic prompts are rate-limited by anonymous device id (abuse prevention, not strong identity)
- HTTPS is used for Supabase / store / ads SDKs as provided by those platforms
No method of electronic transmission or storage is 100% secure.
14. Changes to this Policy
We may update this Privacy Policy from time to time. Changes will be indicated by updating the “Last Updated” date above. Continued use of the App after changes means you acknowledge the updated Policy.
15. Contact
If you have questions about this Privacy Policy or wish to make a privacy request, contact: