← Yapathon

Privacy Policy

Loy-Ren AB  ·  Last updated: September 3, 2026

This Privacy Policy explains how Loy-Ren AB ("we", "us", or "our") handles information when you use version 2.0.0 or later of the Yapathon mobile application (the "App"). It also explains the choices available to you and the rights you may have under applicable privacy law.

1. Who We Are

Loy-Ren AB is the developer and publisher of Yapathon.
Org. nr: 559547-2399
Contact: info@loy-ren.com

For users in the European Economic Area (EEA) or United Kingdom, Loy-Ren AB acts as the data controller for personal data processed in connection with the App.

2. Information We Collect

2.1 Yapathon Account and Profile

Yapathon uses Supabase to create a pseudonymous account identifier. An anonymous account lets essential features such as profiles, progress synchronization, leaderboards, support, and account deletion work without requiring your name or email address.

We may store:

  • Your Supabase user identifier and authentication or session information
  • Your profile name selected from Yapathon's predefined word choices and the generated leaderboard identifier based on it
  • Your avatar, title, frame, XP, level, progression revision, and related profile history
  • Ownership of the Yapathon Supporter title granted to eligible players upgrading from version 1.10.0; this is not a RevenueCat purchase or subscription entitlement
  • App version, device platform, and the time the account was last seen
  • Technical identifiers used to make synchronization, score submission, recovery, and account operations reliable and idempotent

You select a profile name by combining words from Yapathon's predefined choices. That selected combination is sent to Supabase as the base of your generated leaderboard identifier, which adds a four-digit suffix. Your generated identifier, avatar, title, frame, rank, and eligible scores may be visible to other players on Yapathon leaderboards, so do not treat them as private information.

2.2 Sign in with Apple

Sign in with Apple is optional and lets you recover the same Yapathon account on another installation or device. Yapathon does not request your Apple name or email address. During authentication, Apple and Supabase process the stable Apple provider identifier, an Apple identity token, and a cryptographic nonce. A fresh Apple authorization code and nonce are also used when Apple access must be revoked during account deletion.

Yapathon's application code does not persist Apple identity tokens, authorization codes, or nonces. Supabase session tokens are stored in the device's secure credential storage, such as iOS Keychain. If an existing Apple-linked Yapathon account is found, the App asks before replacing the disposable anonymous profile on that device; the two accounts are not silently merged.

Apple processes information under Apple's Privacy Policy when you use Sign in with Apple.

2.3 Cloud Progress and Gameplay Records

To synchronize and restore progress, Yapathon may store:

  • Completed Classic, Daily, and Yapathon session summaries, including mode, timestamps, score, duration, word-count totals, mistakes, streak statistics, input type, and app or content versions
  • Lifetime gameplay totals and high scores
  • XP, level, progression revision, completed stages, stars, and reward state
  • Achievements, achievement progress, and limited evidence needed to reconcile achievement state
  • Daily and Yapathon completion or reward state
  • Play-streak activity, current and best streaks, and Streak Saver history

Account synchronization does not upload suspended or in-progress games, typed guesses, answer timelines, or the words in a played chain.

Device preferences are not synchronized as account settings. Privacy choices and notification preferences remain device-local. When analytics is enabled, however, analytics events may include selected setting values such as input preference, reminder configuration, notification permission, or purchase-entitlement status. Achievement synchronization may also reveal limited derived facts, such as whether a notification-related achievement was earned or whether a theme or input mode was tried.

2.4 Yapathon Leaderboards

When you submit an eligible score, we store your account identifier, leaderboard and challenge identifiers, score and related totals, completion time, leaderboard period, app version, platform, a client run identifier, and validation or rejection information. Leaderboard results may display your generated leaderboard identifier, profile cosmetics, rank, score, or points to other players.

2.5 Support Requests

If you contact support through the in-app form, the submission is stored in Supabase for later review. It does not leave Supabase for a separate support-desk provider. We store your account identifier, selected topic, message, optional reply email, app version, platform, request identifiers, and timestamps. If you explicitly choose to include purchase details, we also store your RevenueCat support identifier. Gameplay history is not automatically attached.

The App also offers an email fallback. If you choose it, your email provider and ours process the email under their respective terms.

2.6 Purchases and Subscriptions

Apple processes payments made through the App Store. RevenueCat helps manage purchase and subscription status. RevenueCat may receive a pseudonymous purchase identifier, product and entitlement information, purchase status, and related transaction metadata. We do not receive your full payment-card details. RevenueCat's privacy practices are described in its Privacy Policy.

2.7 Apple Game Center

If you choose to enable Apple Game Center, Apple may process your Game Center identity, scores, achievements, and related gameplay information under its own terms and privacy policy. Game Center is separate from Yapathon's Supabase profile and leaderboard system.

2.8 Product Analytics — PostHog

When analytics is enabled in the App's privacy settings, we use PostHog to understand feature use, improve the App, operate feature flags or experiments, and present optional surveys. PostHog may receive:

  • A persistent pseudonymous device or distinct identifier
  • App lifecycle and screen-navigation events
  • Feature interactions and aggregate gameplay or progression events
  • App version, operating system, device type, locale, and similar technical context
  • Selected properties such as purchase-entitlement status, reminder configuration, notification permission, and input preference
  • Feature-flag and survey interaction data
  • Any free-text response you voluntarily enter in a survey
  • Technical request information, which may include an IP address depending on the active PostHog project configuration

These properties can form a pseudonymous PostHog person profile. Yapathon does not send your Supabase account identifier, Apple identifier, profile name, leaderboard identifier, or email address to PostHog. We do not enable PostHog session replay, touch capture, or PostHog error tracking. PostHog data is sent to its EU Cloud endpoint.

Analytics is enabled by default on a fresh installation. You can disable or re-enable it at any time in the App's privacy settings. Disabling analytics stops future PostHog collection from the App but does not erase information already retained by PostHog.

2.9 Crash Reporting and Diagnostics — Sentry

We use Sentry in production to diagnose crashes, errors, and reliability problems. Sentry may receive crash reports, exception types, stack traces, error messages, warning- or error-level application logs, navigation and diagnostic breadcrumbs, app release information, operating-system and device context, and pseudonymous SDK identifiers.

Sentry is configured not to collect default personally identifiable information. We additionally filter RevenueCat anonymous identifiers and profile-identifier fields from application-provided diagnostic payloads. This does not guarantee that every unexpected error message is automatically stripped of all personal information, so we design diagnostic events not to include profile names, leaderboard identifiers, email addresses, Apple credentials, support-message contents, typed guesses, or word-chain contents.

Yapathon does not enable Sentry screenshots, view-hierarchy capture, or session replay. Fatal and unhandled crash reports may be sent even when the App's analytics setting is disabled because they are needed to maintain security and reliability. Other Sentry telemetry is sent only after startup is complete and analytics is enabled. Disabling analytics clears active Sentry scopes but does not erase reports already retained by Sentry.

2.10 Meta SDK

When analytics is enabled, Yapathon initializes the Meta SDK and permits limited automatic app-event logging, such as app installations and activations. Separately, iOS may provide privacy-preserving attribution postbacks to registered advertising networks through Apple’s SKAdNetwork. Advertiser-ID collection is disabled, native automatic initialization is disabled, and Yapathon does not request App Tracking Transparency permission.

3. How We Use Information

We use the information described above to:

  • Provide accounts, profiles, authentication, recovery, synchronization, leaderboards, achievements, purchases, and support
  • Maintain the security, integrity, and availability of Yapathon
  • Prevent abuse, validate scores, diagnose failures, and recover safely from interrupted account operations
  • Understand App usage and improve features when analytics is enabled
  • Operate feature flags, experiments, attribution, and optional surveys
  • Comply with legal obligations and enforce our terms

4. Legal Basis for Processing (EEA / UK Users)

If you are located in the EEA or UK, we rely on the following legal bases as applicable:

  • Contract performance — to provide requested account, authentication, synchronization, leaderboard, purchase, and support functionality
  • Legitimate interests — to protect the service, prevent abuse, maintain reliability, diagnose fatal crashes, understand product use, and improve Yapathon, balanced against your rights
  • Consent — where required by law or where we specifically ask for it; you may withdraw consent at any time
  • Legal obligation — where processing is required by applicable law

5. Service Providers and Disclosures

We do not sell your personal information. We disclose information only as needed to operate Yapathon, comply with law, protect rights and safety, or complete a business transaction subject to appropriate safeguards.

ProviderPurposeTypical information
SupabaseAuthentication, database, backend functions, profiles, synchronization, leaderboards, support storage, and deletion workflowsAccount identifiers, Apple provider link, profile, completed-game summaries, progression, leaderboard, support, and recovery data
AppleApp distribution, Sign in with Apple, payments, and Game CenterApple authentication data, transaction information, Game Center information, and Apple-controlled device or account context
RevenueCatPurchase and subscription managementPseudonymous purchase identifier, product, entitlement, and transaction status
PostHogOptional analytics, feature flags, experiments, and surveysPseudonymous analytics identifiers, events, properties, technical context, and voluntary survey responses
SentryCrash reporting and reliability diagnosticsCrash or error information, logs, breadcrumbs, release and device context, and pseudonymous SDK identifiers
MetaAnalytics and install attribution when analytics is enabledAutomatically logged app events and basic app, device, and technical request context

In-app support submissions are stored in Supabase and are not forwarded to a separate support-desk provider.

6. Data Retention

We retain information only for as long as needed for the purposes described above, including to provide the service, protect its integrity, resolve disputes, and meet legal obligations.

  • Supabase account, profile, synchronized progress, gameplay summaries, achievements, streaks, leaderboards, and account-linked support submissions: retained while the account exists and removed from the active service when the account is deleted, subject to temporary protected backups, security records, and legal requirements
  • PostHog analytics and survey data: retained for up to 30 days; disabling analytics stops future collection but does not automatically erase previously collected records
  • Sentry crash and diagnostic data: retained for up to 30 days
  • Purchase and transaction records: retained independently by Apple and RevenueCat under their policies and as required for accounting, fraud prevention, and legal compliance
  • Device-local data: retained until it is cleared by the App, an account transition, or removal of the App, depending on the data type

When an existing Apple-linked account replaces a disposable anonymous account, Yapathon stores a protected cleanup record containing the old and destination Supabase identifiers, a migration token, status, timestamps, and bounded error metadata. Confirmed cleanup is delayed for 24 hours to protect recovery. Cleanup records may be retained afterward for security, operational, and audit purposes and are removed when no longer needed. An unconfirmed recovery ticket may remain longer when needed to complete or safely cancel an interrupted account restore.

We may retain aggregated or de-identified information that no longer identifies you.

7. Account Deletion and Your Rights

You can request immediate account deletion from the App. For an Apple-linked account, a fresh Sign in with Apple authorization is required so Yapathon can revoke the Apple connection before deleting the account. No Apple authorization is required for an anonymous account.

Account deletion removes the Supabase Auth user and account-linked profile, progression, completed-game summaries, achievements, streaks, leaderboard records, and stored support submissions from the active service. It also clears account-owned profile and gameplay data on that device, including suspended games. Some device preferences and non-personal onboarding or migration markers may remain so the App can continue operating correctly.

Account deletion does not automatically delete:

  • App Store, RevenueCat, or Game Center records controlled independently by Apple or RevenueCat
  • PostHog, Sentry, or Meta records that are not linked to your Supabase account identifier
  • Information temporarily retained in protected backups, security records, or as required by law

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy of information; withdraw consent; and complain to your local data-protection authority.

To exercise a privacy right, contact info@loy-ren.com. Because analytics and diagnostic systems use pseudonymous SDK identifiers rather than your Supabase account identifier, we may need information from your device to locate a record and may not always be able to identify a specific record without collecting additional information. We will request no more information than reasonably necessary.

8. Children's Privacy

Yapathon is intended for a general audience and is not directed specifically to children. We do not knowingly collect personal information from children in violation of applicable law. If you believe a child has provided us with personal information, please contact us so we can investigate and take appropriate action.

9. Security

We use reasonable technical and organizational measures intended to protect the information we handle, including authenticated backend access, row-level access controls, secure device credential storage, bounded validation, and account-linked deletion. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

10. International Transfers

Some providers may process information outside your country. The App sends PostHog data to its EU Cloud endpoint and Sentry data to its German ingestion endpoint. Supabase hosts backend data in the project's configured hosting region. Apple, RevenueCat, Meta, and other providers may process information in additional countries.

Where required, we rely on appropriate safeguards such as adequacy decisions, European Commission standard contractual clauses, or another lawful transfer mechanism.

11. Changes to This Policy

We may update this Privacy Policy when Yapathon or its data practices change. We will publish the revised version and update its date. Previous versions remain available through the version selector above.

12. Contact Us

If you have questions or concerns about this Privacy Policy or your information, contact:
Loy-Ren AB
Org. nr: 559547-2399
info@loy-ren.com