Privacy Policy

Last updated

Summary

Capone’s Bones is operated by Sorce Code Labs, LLC, a Utah limited liability company (“we”, “us”). We are the controller of the personal information described here.

We use your account details, your game data, analytics and limited device information to run the game, keep accounts and leaderboards working, prevent fraud, fix bugs, and show ads. We do not sell personal information.

  • Deleting your account: do it in the app (menu, Preferences, Delete Account). Your account data is erased from our live database immediately. Backups roll off within the window described under Data retention. See Delete your account for exactly what is erased and kept.
  • Ads: the game requests non-personalized ads from Google AdMob. Where the law requires consent, Google’s consent form is shown before ads load. On iOS the game may also ask Apple’s tracking permission; either answer is fine.
  • Analytics: we use PostHog to understand how the game is played and to find errors. There is no in-app switch to turn it off; email us to object or to have your analytics data deleted.
  • Children: you must be at least 13 to create an account.
  • Questions or requests: [email protected].

This policy also covers our website, https://caponesbones.app/, which is described under Our website.

Information we collect

Information you give us

  • Account details: your email address, display name and, if you choose one, a profile photo. If you sign in with Apple or Google, we receive the account identifier and email address that provider shares with us.
  • Profile photo: stored in our storage service at a web address that anyone who has the address can open. Other players see it next to your name.
  • Bug reports: if you use Report an Issue, we receive your description together with your email address, account ID, display name, a snapshot of your profile, your device model, operating system, app version and the analytics IDs of your session, so we can find and fix the problem.
  • Support email: whatever you send us.

Information created as you play

  • Game data: scores, progress, campaign diamonds, awards, streaks, dough and items, leaderboard entries and game history. Your display name and street name appear on leaderboards.
  • Purchases: a record of what you bought and when, and the store receipt details we use to confirm the purchase with Apple or Google. We never see your payment card details.
  • Crew: who is in your crew, crew requests, and invites. Your crew can see when you are online and when you were last seen. Other players can find you by your exact email address or username, but we never show them your email.

Information collected automatically

  • Device and usage information: device type, operating system, app version, and events such as screens viewed, buttons tapped, games played, errors and performance, collected through PostHog. We link these events to your account, including your email address and display name, so we can look into problems you report and understand how the game is used.
  • Session replay: some builds record a small sample of sessions as a replay of the screens and taps, to help us fix bugs. Text you type, images and embedded web views are masked, so they are not recorded.
  • Advertising data: Google AdMob receives information it needs to show and measure ads and prevent ad fraud, such as device and app information, your IP address and, if your device settings allow it, your device’s advertising identifier.
  • Push notification token: if you allow notifications, the app registers a token with Expo’s push service so we can send them.
  • Hashed device identifier (referral fraud prevention): when you sign in, the app sends your device’s app-vendor identifier (iOS) or Android ID to our servers over an encrypted connection. The server immediately turns it into a one-way, keyed hash and stores only that hash, linked to your account; the identifier itself is never stored. We use it only to prevent referral fraud (for example, one person creating several accounts on one phone to collect invite rewards). It is not used for advertising and is not shared with advertisers or analytics providers.
  • Referral records: if you join with a friend’s invite link or code, we record whose code it was, how it reached you (link, Google Play install referrer, or typed in), and when your first heist qualified it. To spot clusters of fake sign-ups we also keep the network block the invite was claimed from (the first three parts of an IPv4 address, or the first 48 bits of an IPv6 address), never the full IP address. Your friend sees your display name, when you joined with their invite and how, and the invite’s status, never your device identifier or network block.
  • Bluetooth: Private Heist uses Bluetooth to find and connect to nearby phones. Nothing sent over those connections is sent to our servers. On Android, scanning for nearby devices can require location permission; we do not collect or use your location.

How we use information

  • To run the game: your account, progress, multiplayer, Crew, leaderboards and purchases.
  • To confirm purchases with Apple or Google and credit what you bought.
  • To send notifications you have allowed.
  • To show ads, pace them, and confirm rewards for ads you choose to watch.
  • To understand how the game is played and to find and fix errors.
  • To answer support requests and bug reports.
  • To keep the game secure and prevent fraud, including referral fraud.
  • To pay invite rewards to you and the friend who invited you when your first heist qualifies.
  • To comply with legal obligations.

Where the GDPR or a similar law applies, we rely on:

  • Performance of a contract: to provide the features you ask for, such as your account, multiplayer, progress and purchases.
  • Legitimate interests: to keep the game reliable, measure how it performs, prevent fraud and keep it secure.
  • Consent: for features that depend on your permission, such as push notifications, and for ad consent where the law requires it.
  • Legal obligations: where we must keep or disclose information by law.

Permissions

Depending on your device and what you use, the app may ask for:

  • Notifications: to send reminders and alerts you have turned on. You choose which kinds in Preferences.
  • Bluetooth: for Private Heist. On Android this can include nearby-device or location permission, which the system requires for Bluetooth scanning.
  • Camera and photos: only when you choose to take or pick a profile photo.
  • Tracking (iOS): after you have played for a while, iOS may ask whether the game may use your activity to choose ads. Either answer is fine, and you can change it later in Settings, Privacy & Security, Tracking.

If you decline a permission, only the feature that needs it is affected.

Who processes information for us

We use these service providers. Each processes information on our behalf, or under its own terms where noted.

  • Supabase: our database, authentication and file storage. Data location: United States (or as configured). Privacy policy.
  • PostHog: product analytics, error tracking and session replay, hosted in the United States. Privacy policy.
  • Google AdMob: ads, ad measurement and the ad consent form (Google User Messaging Platform). Google privacy policy.
  • Apple and Google: Sign in with Apple and Google Sign-In, in-app payments, and the receipt checks that confirm a purchase. Their own terms and privacy policies apply to your store accounts.
  • Expo: delivers push notifications. It receives your push token and the text of each notification. Privacy policy.
  • Linear: where we keep and work on bug reports sent from the game. Privacy policy.
  • Cloudflare: hosts our website and counts clicks on invite links. Privacy policy.

Ads and your choices

Every ad request the game makes is for non-personalized ads. In the EEA, the UK, Switzerland and other places where the law requires it, the game shows Google’s consent form before ads load; you can change your answer later from the same form where it is offered. You can also limit ad tracking in your device settings and your Google account.

Analytics and your choices

There is no in-app setting to turn analytics off. Depending on where you live, you can object to analytics or ask us to delete your analytics data by emailing [email protected]. Deleting your account does not remove analytics data automatically, so email us if you want it removed too.

Our website

When you visit https://caponesbones.app/, Cloudflare, which hosts the site, processes standard request information such as your IP address and browser to deliver pages and protect the site, and may produce aggregate visitor statistics. If we turn on page analytics with PostHog, it counts page views without cookies or browser storage, without recording your session, and not at all when your browser sends Do Not Track.

Invite links (sorcecodelabs.com/cb) count clicks per invite code, per platform (iPhone, Android, other, or link preview) and per day. We do not store IP addresses, browser details or the time of day for these counts.

Data retention

The periods below apply unless a longer period is required by law, a legal hold, or an active security or fraud investigation. We do not keep personal data indefinitely just in case.

  • Account and game data (Supabase live database): for as long as your account exists. When you delete your account in the app it is erased immediately; after a verified deletion request by email, within 30 days.
  • Database backups (Supabase): deleted data can remain in encrypted automatic backups for a limited rolling window after it leaves the live database (commonly up to 7 days on Pro plans, up to 14 days on Team, and up to 30 days on some Enterprise setups; see Supabase database backups).
  • Profile photos: deleted with your account.
  • Support email and bug reports: up to 24 months after the last message or update, unless we need them longer for legal claims or compliance.
  • PostHog events, people and errors: about one year on PostHog’s free plan, after which PostHog may move data to cold storage or delete it under its terms; paid plans can keep analytics longer (see PostHog pricing). We delete yours sooner on request.
  • PostHog session replays: up to 30 days on the free plan, or less if we set a shorter period (see PostHog session replay retention).
  • Hashed device identifiers and referral records: for the life of your account, and deleted with it. One exception: when a device has already produced a paid invite, we keep only the keyed hash of its identifier, with no link to any account, so the same phone cannot earn the new-player invite reward twice. That hash cannot be traced back to you or your device without a secret key held only on our server.
  • Ad records: records of ads shown are kept for our accounts. When you delete your account, the link to your account is removed from them.
  • Website logs: days to a few weeks, under Cloudflare’s settings, and not used to build a profile of visitors.
  • Legal holds: we may keep specific information longer when the law requires it or to establish, exercise or defend legal claims.

If we add a new analytics or logging provider, we will list its retention here.

Your rights

Depending on where you live, you may have the right to:

  • Access a copy of your personal data.
  • Correct inaccurate data.
  • Delete your data.
  • Receive your data in a portable format.
  • Object to or restrict certain processing, including analytics.
  • Withdraw consent where processing relies on it.
  • Complain to your local data protection authority.

Email [email protected] to use any of these. We may ask for information to confirm the account is yours before we act, and we answer verified requests within 30 days or sooner if the law requires.

California (CCPA)

California residents can ask what personal information we collect, ask us to delete it, and use these rights without being treated differently. We do not sell personal information. Residents of Virginia, Connecticut, Colorado, Utah and other states with privacy laws may have similar rights; email us for details.

Europe and the UK (GDPR and UK GDPR)

If you are in the European Economic Area or the United Kingdom, you have the rights listed above: access, rectification, erasure, restriction, portability, objection and withdrawal of consent.

Children

Capone’s Bones is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13. You must be at least 13 to create an account; our Terms of Service require it, and by creating an account you confirm that you meet it.

The app does not ask for your date of birth, and Sign in with Apple and Google Sign-In do not share it with us. There is no children’s account or under-13 sign-up. The store age rating is set by Apple and Google from their own questionnaires and is separate from this rule. Parents and guardians can use Apple’s Screen Time or Google Family Link to control installs and purchases.

If you believe a child under 13 has given us personal information, email [email protected] and we will delete it.

Beta builds

We test new versions through Apple TestFlight and Google Play testing. This policy applies to those builds too. Beta builds may show Google test ads instead of real ones and may connect to test servers; that changes how ads behave, not how we handle your data.

International transfers

Your information may be processed in countries other than where you live, including the United States, where our providers host data.

Where the GDPR or UK GDPR applies and data goes to a country without an adequacy decision, we rely on the EU Standard Contractual Clauses of 4 June 2021 (Commission Implementing Decision (EU) 2021/914), as included in our providers’ data processing agreements, and on the UK International Data Transfer Addendum or other UK-approved tools where needed. Providers whose transfer terms we rely on include Supabase, PostHog, Google (AdMob and Google Sign-In), Apple (Sign in with Apple), Expo, Linear and Cloudflare.

Email us for a summary of the transfer mechanism for any provider.

Changes to this policy

We may update this policy. When we do, we change the date at the top of this page and, for significant changes, tell you in the app where appropriate.

Contact