Privacy Policy
Privacy in one minute: the single-player campaign works offline and without signing in. Cloud progress is optional. Gameplay and product analytics are on by default and can be turned off under Settings → Privacy. Borrowed Gravity has no ads, does not use the advertising identifier, and does not track you across other companies’ apps or websites.
Who this policy covers
This policy covers the Borrowed Gravity iPhone and iPad app, this website, and support email. “We” means the developer and operator of Borrowed Gravity.
Data handled by the app
| When | Data | Purpose |
|---|---|---|
| Guest play | Progress, best runs, settings, and privacy choices stored in the app container on your device. | Run the game and preserve guest progress. Guest and signed-in account progress use separate local namespaces; account progress synchronizes only while signed in. |
| Optional Sign in with Apple | Apple’s app-specific user identifier, an internal Supabase user identifier, and authentication timestamps. | Create and secure the optional account and recognize it on another device. |
| Optional cloud progress | Stable mission identifier and revision, completion state, earned result, best fuel, burn count, duration, update time, and synchronization generation. | Back up progress, merge valid results between devices, and prevent deleted or stale records from silently returning. |
| Product analytics by default | A random analytics identifier that is not linked to your optional account, event time, app version and build, screen or feature used, and compact mission-attempt outcomes such as completion, fuel, burns, and duration; and purchase, restore, and campaign-unlock events. Payment details, receipts, and transaction identifiers are not sent to analytics. | Find interrupted player journeys, confusing missions, progression drop-off, balance problems, and features that are not enjoyable. |
| Security and synchronization | Authentication, request, error, and abuse-prevention metadata generated by the service providers. | Protect accounts, diagnose failed synchronization, enforce access controls, and respond to incidents. |
What gameplay analytics excludes
Analytics does not include raw flight trajectories, touch-by-touch input, route images, free-form text, contacts, photos, precise location, advertising identifiers, or session replay. It is not used for advertising, data brokerage, or cross-app tracking. Turning analytics off stops future product events and does not change gameplay or synchronization.
Website and support email data
Cloudflare processes ordinary request information such as IP address, browser headers, requested URL, timing, and security signals to deliver and protect this website. We do not add advertising pixels or cross-site tracking to these pages.
If you email support, the developer and the sender’s and developer’s email providers process the sender address, message, timestamps, and any attachment you choose to send so the developer can answer and investigate the request. In the first message, do not include an Apple relay address, account or analytics identifier, access token, exported data, or another person’s information.
Service providers and subprocessors
- Apple — app distribution, Sign in with Apple, system share sheets, and platform services. See Apple’s privacy policy.
- Supabase — optional authentication, account records, cloud progress, row-level access controls, and secure server functions. See Supabase’s privacy policy.
- PostHog — gameplay and product analytics, enabled by default unless you turn it off under Settings → Privacy. Autocapture and session replay are disabled for the app. See PostHog’s privacy policy.
- Cloudflare — website hosting, content delivery, transport security, and abuse prevention. See Cloudflare’s privacy policy.
- Google — Gmail delivery and storage for messages you voluntarily send to support. See Google’s privacy policy.
These providers may process data in countries different from yours and apply their contractual and legal transfer safeguards.
Retention
- Local game data: guest progress is kept until you reset it or remove the app. Account-scoped local progress is hidden on sign-out and removed after successful account deletion.
- Account and cloud progress: kept while the optional account exists. Confirmed account deletion removes the live account, cloud progress, and that account’s local progress namespace; any residual provider copies are subject to the provider’s backup and deletion processes.
- Product analytics: PostHog provides a 12-month analytics history on our current plan. This access window does not guarantee that all underlying copies are deleted at the same time. Provider retention and deletion processes apply. You can stop future events in Settings and contact us to request deletion of an existing analytics history.
- Diagnostics and security records: Supabase project logs are available to us for one day on our current plan. Providers retain other operational and security records under their own policies and legal obligations.
- Support email: kept only as long as reasonably necessary to answer the request, investigate related problems, prevent abuse, meet legal obligations, or establish and defend legal claims.
Your choices and controls
- Play as a guest without creating an account.
- Signing out hides that account’s local progress until the same account signs in again. The app starts a fresh guest with separate progress.
- Product analytics is enabled by default. Turn future product events on or off under Settings → Privacy → Share Product Analytics.
- Export cloud data, delete the account, or erase local progress using the steps on the account and data controls page.
- The app attempts to revoke Sign in with Apple authorization during account deletion. If revocation fails, it explains how to remove the authorization in Apple’s settings.
Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data. Start with the in-app controls. If you cannot access them, email borrowedgravity@susnoodle.com without including account or analytics identifiers in the first message; the developer will provide a safe next step.
Account deletion is different from app deletion
Successful account deletion removes the cloud account and that account’s local progress namespace, then starts a fresh guest. Removing Borrowed Gravity from a device deletes its local container but cannot authenticate a request to remove an existing cloud account. Use Settings → Account → Delete Account first.
Children
Borrowed Gravity is a general-audience puzzle game and does not ask for age, real name, contacts, or precise location. If you believe a child has provided personal information through account, analytics, website, or support features, email support with only the minimum detail needed to request a safe follow-up.
Legal requirements and safety
We may preserve or disclose limited information when reasonably necessary to comply with law, protect users and the service, investigate fraud or abuse, or establish and defend legal claims.
Changes
We will update the effective date and this page before materially changing data practices. App Store privacy disclosures will be updated to match the released archive.