Privacy Policy
InGame is a mobile app for building and sharing a personal game collection. It is operated by Aiden Molyneaux, an individual developer in Ontario, Canada ("we", "us"). This policy explains what InGame collects, why, who else handles it, how long we keep it, and how you delete it. It covers the InGame app on iOS and Android and the website at ingamehq.com.
We wrote this in plain language on purpose. If anything is unclear, email [contact email]@ingamehq.com.
- Age
- What we collect
- Why we use it
- Who can see what
- Service providers
- Where your data is stored
- How long we keep it
- Deleting your account
- Your choices and rights
- Security
- Data on your device
- Changes to this policy
- Contact
1. Age
You must be 13 or older to use InGame. We do not ask for your date of birth. By creating an account you confirm that you are at least 13. If we learn that an account belongs to someone younger, we delete it. If you believe a child under 13 has an account, email us at the address above.
2. What we collect
Account
When you register we store your email address, your username, and your password as an argon2 hash. We never see or store the password itself. If you use Sign in with Apple, we store the identifier Apple assigns to you and the email address Apple shares, which may be an Apple private relay address. We record when the account was created and, if you verify your email, when that happened.
Profile
Whatever you put on your profile: an avatar (designed in the app, never uploaded), a short bio, favourite genres, a pinned favourite game, gamertags for the platforms you choose, and your privacy setting (friends-only or limited public).
Collection and activity
The games you add, with status, hours played, percent complete, platforms, owned-since date, rating, and private notes. Your What to Play queue and your Top 10. Achievements you unlock and your progress toward them. All of this is what you type in. InGame does not connect to any platform account and does not read play data from your device or other apps.
Community content
Catalog entries you add or edit (game name, studio, publisher, release date, genres) and the history of each edit. Card designs you make, including the cosmetic components on them. Which cards you publish, and who adopts them. The Terms of Service describe how this content is shared and credited.
Social
Friend requests, friendships, users you block, invite links you generate, game recommendations you send or receive, and an activity feed of events such as "published a card". Reports you file about content or users, with the reason and any details you write.
Purchases and Pixels
Your Pixel balance and a ledger of every change to it: daily claims, pack purchases, adoption spends, refund reversals, and any adjustment we make. For in-app purchases we receive validated receipts and transaction identifiers from Apple, Google, and RevenueCat. We never receive your card number or other payment details. The app stores handle payment.
Support and feedback
Feedback, suggestions, and bug reports you send through Settings, with the app version and platform. On a bug report you can choose to attach the app's diagnostic logs. This is off by default and needs an explicit toggle each time. Logs can contain personal information, for example your username or the screens you visited. Attached logs are stored privately for support use and are never shown to other users.
Technical
Our server keeps request logs (a request ID, the endpoint called, timing, and error details) and a coarse "last seen" timestamp per account, updated at most every 15 minutes, so we can count roughly how many accounts were active in a day. The app records product events such as "card published" or "friend request accepted". These drive achievements and give us aggregate usage numbers. If the app or server hits an error, a report may go to Sentry with authorization headers, cookies, and request bodies removed first. If you turn on push notifications, we store the push token your device gives us.
We do not collect your location, contacts, photos, advertising identifiers, or a device fingerprint. InGame shows no ads and does not sell personal information.
3. Why we use it
Most of it exists so the app works: signing you in, showing your collection, connecting you with friends, rendering the card gallery, and running the store.
We use your email address for verification at sign-up, for password reset codes, and for notices about your account, such as a suspension or a material change to our terms. We send no marketing email.
Public text (usernames, bios, card titles, catalog fields) is screened for banned words, and reports are read by staff so we can enforce the Terms of Service.
Purchase records let us validate receipts, grant Pixels, and reverse them when a store issues a refund.
Error reports and usage events help us fix bugs and see which parts of the app get used. We look at counts and funnels rather than at individuals, unless you ask for help or a report or abuse investigation needs it.
We also keep what we need to meet legal obligations and resolve disputes.
4. Who can see what
Your privacy setting, under Settings > Privacy & Safety, controls what people who are not your friends can see. The default is friends-only.
- Friends can see your profile, your device, your Top 10, your collection (hours, status, owned-since date, and the card you display for each game, but not your notes, rating, or platforms), your achievements, and can compare hours with you.
- People who are not your friends see a limited profile if you set it to public, and only headline counts otherwise.
- Some things are always public and credited to your username: catalog entries and edits you contribute, cards you publish and their designer credit, and any card image you choose to share outside the app.
- Anonymous aggregates never identify you: how many collections contain a game, or the total games and hours shown on the welcome screen.
- Blocking a user makes the two of you invisible to each other. The other person is not told.
- Staff with an admin role can see reports and feedback and, while investigating a report, a user's report history and content. Every staff action is written to an append-only audit log with the actor and the reason.
5. Service providers
These companies process data on our behalf and only on our instructions.
| Provider | What it does | What it receives |
|---|---|---|
| Railway | Hosts the API server and the PostgreSQL database (US West). Card renders live on a Railway storage volume today. | Everything in section 2. |
| Cloudflare | DNS for ingamehq.com, hosting for this website, and R2 object storage for database backups. Card renders may move to R2 later. | Backup files; card images when moved. |
| Resend | Sends our email from mail.ingamehq.com. | Your email address and the message. |
| RevenueCat | Validates in-app purchase receipts and tells us about refunds. | An app user ID tied to your account, and purchase records. |
| Apple App Store, Google Play | Payment, refunds, and Sign in with Apple. Their own privacy policies apply. | Handled by them; we receive receipts and, for Apple sign-in, an identifier and email. |
| Expo (EAS) | Builds the app and, when push notifications are enabled, delivers them. | Your push token and notification content. |
| Sentry | Collects error reports, if we enable it. | Error details with credentials and request bodies removed. |
We do not share personal information with anyone else, except where the law requires it or to protect users, for example when responding to a valid legal request or an immediate safety issue.
6. Where your data is stored
Our servers run in the United States (Railway, US West). Backups sit in Cloudflare R2. Email goes through Resend's US region. Your information is therefore stored and processed outside Canada and may be subject to the laws of those places, including lawful access by authorities there. We choose providers with standard security practices and contractual commitments to protect data.
7. How long we keep it
- Account, profile, collection, and social data: as long as your account exists.
- Community content (catalog entries, edits, published cards): indefinitely, because other users rely on it. When you delete your account it is anonymized rather than removed (section 8).
- Pixel ledger and purchase records: with your account, and afterwards for as long as needed for refund disputes and financial record-keeping.
- Support submissions and attached diagnostic logs: until the report is resolved, then 90 days.
- Server request logs and error reports: 90 days.
- Product events (the activity that powers achievements): for as long as your account exists, then anonymized when the account is deleted.
- Moderation records (reports, suspensions, the staff audit log): for as long as needed for safety and for the integrity of the audit trail.
- Database backups: a rolling 14 days. Deleted data can persist in a backup for up to 14 days after deletion.
8. Deleting your account
You can delete your account from Settings.
We delete your profile, collection, What to Play queue, wallet and Pixel balance, gamertags, recommendations, push tokens, friendships and pending requests, and your activity feed events. Unspent Pixels are forfeited and are not refunded.
Community content stays, anonymized. Catalog entries and edits you contributed keep their content, with the contributor credit replaced by an anonymous one. Cards you published are unpublished, so no one new can adopt them. People who already adopted a card keep their copy of the image and any cosmetic components they acquired, with the designer credit anonymized.
We also keep the purchase and ledger records we need for financial and refund obligations, and moderation records, in anonymized form where possible.
Deletion takes effect immediately in the live database. Backups age out over the following 14 days.
9. Your choices and rights
- Change your username (once per cooldown period), your bio, avatar, gamertags, and favourites from your profile.
- Switch between friends-only and limited public from Settings.
- Unfriend or block anyone. Blocked users are listed in Settings so you can unblock them.
- Turn each type of push notification on or off.
- Decide, on every bug report, whether to attach diagnostic logs.
- Ask us for a copy of the personal information we hold about you, or to correct it. Email us and we will respond within 30 days.
Canada's federal privacy law (PIPEDA) applies to InGame. If you are not satisfied with how we handle a request, you can complain to the Office of the Privacy Commissioner of Canada.
10. Security
Passwords are hashed with argon2. Sign-in tokens are kept in your device's secure store, not in ordinary app storage. All traffic between the app and our server uses HTTPS. Sign in with Apple tokens are verified against Apple's published keys. Sensitive endpoints are rate-limited, and admin functions are restricted to staff accounts. No system is perfectly secure. If a breach affects your information we will tell you and, where the law requires it, notify the Privacy Commissioner.
11. Data on your device
The app caches your own profile and collection so it opens offline. Card drafts save locally while you work. Nothing about other users is cached at rest. Signing out clears the cache.
12. Changes to this policy
When we change this policy we post the new version here with a new date and a changelog entry below. For a material change, the app asks you to accept it before you continue.
13. Contact
Aiden Molyneaux
Ontario, Canada
[contact email]@ingamehq.com
You can also reach us from Settings > Help in the app.