Privacy Policy
Paper Town Firebreak
This policy explains how this application handles information and how to contact us about privacy.
Information we process
Paper Town Firebreak stores campaign completion, rescued houses, the current board and selected actions, settings, the last downloaded daily puzzle, daily results and pending result uploads locally in iOS UserDefaults. A random secret identifying this installation is stored in the device Keychain, with device-only accessibility. There are no user accounts, names, email registration, advertising identifiers, location collection or analytics SDKs. When you use the daily challenge, our server stores a hash of the installation secret, its creation time, and your challenge date, win or loss outcome, turn count and update time. Daily puzzle schedules are public game content. HTTP requests necessarily reach Railway infrastructure with connection information such as IP address, requested route and request timing. The application service logs request method, response status and duration, and operational errors; it does not intentionally log authorization headers or result bodies. An IP-based rate limiter keeps short-lived counters in server memory. The public website does not require login or cookies.
How we use information
Local storage lets you continue paused games, keep your campaign and collection, use language and sound preferences, and play the last downloaded challenge without a connection. The backend publishes a consistent puzzle for each date and records your own daily outcomes. Installation authorization isolates private results without creating an account. Network and service information is used to deliver requests, protect against excessive requests and diagnose failures. Optional reminders are scheduled locally by iOS, rather than sent by an external push or email provider.
Service providers and sharing
Railway hosts the same backend service, its persistent storage and public privacy page, and processes network and infrastructure information needed to operate that hosting. Apple iOS provides device storage, Keychain and optional local notifications on your device. We do not integrate advertising, analytics, social login, email delivery or other third-party SDKs, and there is no public leaderboard or public access to installation results. We do not sell your game results. Hosting infrastructure logs may be retained under Railway's own operational practices; no specific infrastructure log retention period has been verified for this service. The privacy contact email is a contact address only, not an in-app email sending service.
Data retention
Local progress, preferences, cache and results remain until you reset them, remove the app, or iOS removes the associated data. iOS backup and device-management behavior may affect local copies. Device-only Keychain entries are not synchronized to other devices and may remain on the same device after the app is removed. Server installation records and results remain until their installation is deleted; there is no automatic expiry period configured. Public daily configurations remain as game content. Rate-limit entries expire and are pruned in memory or disappear when the process restarts. Persistent SQLite data is kept on a Railway volume. No application-level backup job or fixed backup retention schedule is configured. Any infrastructure backups or logs are subject to the hosting provider's practices and may not be immediately removed by deleting live database rows.
Deleting your information
Settings offers separate actions to reset local progress and to delete server data. Local reset removes the campaign, collection, saved round, daily cache, local results and pending uploads; it does not delete results already stored on the server. Server deletion authenticates with this installation's secret, deletes its installation record and all related results, revokes the secret, and removes the local Keychain secret and pending uploads after a successful response. Existing local campaign and daily history remain unless you also reset local progress. A future daily result can create a new installation secret. There is no account-based recovery or cross-device restore. If the installation secret is lost, the app cannot authorize access to its old server records. Deleted live rows may remain in underlying storage or provider backups until those are reclaimed under infrastructure practices; no immediate backup purge is promised.
Permissions and your choices
The app requests notification permission only when you explicitly enable the optional daily reminder in Settings. You can turn that reminder off in the app and revoke notification permission in iOS Settings. Turning reminders off removes the app's pending daily reminder; it does not remove game progress. The app does not request location, contacts, camera, microphone or photo-library access. Network access is used for daily puzzles, result uploads, deletion requests and opening the public privacy policy; offline campaign play does not need those requests.
Your privacy rights
You can inspect your local game history and preferences in the app, reset local progress, and delete the server data associated with this installation. Depending on where you live, you may have rights to access, correction, deletion, restriction or objection concerning personal information. For privacy questions or rights requests, contact Minerva1Bexworth@icloud.com. Do not send your installation secret by email. We may need enough information to identify the relevant request, and cannot promise to recover records when their authorization secret is unavailable. You may also contact your local data-protection authority where applicable.
Security
The deployed API uses HTTPS. Each installation receives a cryptographically random secret, stored in the iOS Keychain with device-only accessibility; only its SHA-256 hash is stored on the server. Private result reads, writes and deletion require that secret and are scoped to the matching installation. The service validates input, limits request sizes and rate-limits API traffic. SQLite foreign keys and transactions maintain result ownership and deletion consistency. No shared client credential or server administration key is embedded in the app. These measures reduce risk but do not guarantee absolute security; anyone who obtains an installation's secret could use its authorization.
Children’s privacy
This tactical puzzle is designed for players aged 12 and older. It does not request a child's name, age, contact details or account, and has no chat, advertising or purchases. Daily challenge networking still processes the installation-scoped game results and hosting information described above. If you believe a child's personal information has been provided contrary to this policy, contact Minerva1Bexworth@icloud.com so the situation can be reviewed.
Changes to this policy
This page may be updated when the app's features, storage or hosting practices change. The effective date identifies the current version. Material changes will be reflected in the policy available through the app's Settings privacy link. Please review that page after an app update. Questions about a change can be sent to Minerva1Bexworth@icloud.com.