Privacy Policy

Reel Blink Archive

Effective date: 2026-10-05

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Reel Blink Archive is a free visual-memory game without user accounts. On your device, it stores completed campaign episodes, recovered frames and completion dates, the current round and object arrangement, language, sound and motion preferences, daily-scene metadata, and daily results waiting to upload. The game does not request your name, email, contacts, location, photos, microphone or camera. When you submit a completed server daily challenge, the backend receives its UTC date, score and error count. An automatically issued random installation secret is kept in device-only Keychain storage. The server stores a SHA-256 hash of that secret, installation creation time, and result creation/update times, rather than the raw secret. Fetching daily scenes or visiting this website also sends ordinary network information to Railway hosting, which can include IP address, request URL, time, response status and client headers. The service temporarily uses network addresses in an in-memory rate limiter. Its application logs contain startup events and storage-error request identifiers, not result bodies or credentials. The backend also keeps a non-personal daily-scene record containing its date and game metadata so the same challenge survives service restarts.

How we use information

Local game state lets you resume a round, keep campaign progress, view your recovered-frame archive and apply your preferences. Daily metadata selects the same server challenge for a UTC date and is cached locally; a built-in local challenge is available when the service cannot be reached. Installation credentials authorize access only to that installation's results and deletion request. Server results retain your best submitted score for each date. Pending results retry when the application next connects. Operational request information and rate limiting support delivery, reliability and abuse prevention. There is no advertising, behavioral analytics, public leaderboard, marketing email or cross-application tracking.

Service providers and sharing

Railway hosts the same backend service and public privacy website and provides its network and persistent-volume infrastructure. Railway therefore processes service requests and may retain infrastructure logs according to its own operational policies. The game uses Apple's system networking, Keychain and local storage frameworks; it contains no third-party advertising or analytics SDK. Local files may be included in device backups if your operating-system backup settings allow them. Individual installation results are not publicly exposed or shared with other installations. We do not sell game data. Information may be disclosed when a valid legal obligation requires it.

Data retention

Local progress, archive entries, preferences and queued results remain on your device until reset, deletion or removal by you or the operating system. Daily metadata is replaced when a new daily scene is fetched, or cleared by deleting all game data. Server installation hashes and best daily results remain until that installation requests deletion; there is no automatic expiry in the current implementation. The service does not create app-managed scheduled backups. Any infrastructure copies or logs retained by Railway follow the provider's practices, for which this policy does not promise a fixed retention period. Device backup copies are controlled through your device backup settings. Public daily-scene records have no automatic expiry and contain no player or installation data.

Deleting your information

In Settings, Reset local progress removes the campaign episode record, current round and frame archive on this device, but leaves server results and preferences. Delete all game data uses the installation secret to delete its server results and revoke that installation, then removes the local secret, queued results, cached daily scene, local progress and archive. Language, sound and motion preferences remain. A network failure shows a retry message and preserves local game state rather than pretending deletion succeeded. If this installation has never submitted results, deletion can clear its game state without registering an installation. SQLite is configured to overwrite deleted table cells and checkpoint its journal; this does not promise removal from infrastructure logs or any previously retained provider or device backup. Uninstalling alone does not notify the server, and Keychain credentials can outlast an uninstall under system behavior. Use the in-app deletion control before uninstalling when possible. There is no account recovery: lost installation credentials cannot be restored or used to retrieve old results.

Permissions and your choices

The application does not request camera, microphone, photo-library, location, contacts or notification permissions. Network access is used to load daily scenes and submit or delete installation-scoped results. You can play campaign and practice offline; a local daily fallback is offered automatically. Sound and reduced-motion preferences can be changed at any time in Settings, and the system Reduce Motion setting is respected. Opening the public Privacy Policy link uses your system web browser and does not require login or cookies.

Your privacy rights

You can view locally stored progress and frames, reset local gameplay and request deletion of your installation's server data using the controls described above. For privacy questions or applicable access, correction, deletion or other data-rights requests, contact talfryn.larkspur@icloud.com. The email is a public privacy contact, not an application account or an email-delivery feature. We may need enough information to establish authority over a request, but you should never send your installation secret by email. Applicable rights depend on your location. Because results are associated with a random installation rather than your identity, we cannot find or recover another installation's records solely from a name or email address.

Security

The production API uses HTTPS. Each installation receives its own cryptographically random secret, stored in device-only Keychain storage with no shared credential embedded in the app. The backend stores only its hash and checks registration and ownership on every private result or deletion operation. Public scene and policy endpoints contain no private player results. The service validates request sizes and types, limits connections and requests, and uses transactional SQLite storage on a Railway persistent volume. Local gameplay snapshots are written atomically with system file protection. Secrets and result payloads are not intentionally written to application logs. No system can guarantee absolute security, and these measures are not a claim of certification.

Children’s privacy

Reel Blink Archive is designed for people aged 14 and older who enjoy quiet observation puzzles. It is not directed to children under 14, does not ask for age or identity, and offers no chat, advertising, purchases or account registration. If you believe a child has supplied information that should be removed, contact talfryn.larkspur@icloud.com and use the installation's deletion control when available. We will handle the request according to applicable requirements and the information we can reasonably identify.

Changes to this policy

This policy may be updated when the game's data handling, hosting or features change. The effective date on this page identifies the current version. Material changes will be described in the updated policy and, where appropriate, communicated through an application update or a visible in-app notice. The application Settings link opens the current public policy.