Tallywater

Privacy Policy

Last updated: 2026-09-08

This Privacy Policy explains how Tallywater collects, uses, and retains information when you use the Tallywater mobile application ("App"). By using the App you agree to this policy.

1. What we collect

1.1 Data stored locally on your device

DataStorageNotes
Game settings and preferencesUserDefaults, on-device onlyNever transmitted to our servers
Device secret (48-hex credential)iOS Keychain, on-device onlyThe plaintext secret is never transmitted; only a bcrypt hash is stored server-side
Motion sensor readings (CoreMotion)Processed in memory onlyCast mechanics are computed locally; raw accelerometer and gyroscope data is never recorded or transmitted

1.2 Data stored on our server

DataPurpose
Profile UUID, randomly generated on first launchUnique identifier for leaderboards and catch history
Display handle, chosen by youShown on leaderboards and the catch feed
bcrypt hash of your device secretAuthenticates write requests; we never know your plaintext secret
Catch records (species, weight, water, timestamp)Powers leaderboards, the catch feed, and your own history
Group membership and group metadataPrivate crews
Vault payload (progression data)Restoring your record on a new device

1.3 Data we do not collect

2. How we use your data

Leaderboards. Display handles and catch records are used to rank players on global and group leaderboards.

Catch history and feed. Catch records power the feed visible to other players.

Authentication. The bcrypt hash is used solely to verify that write requests originate from your device.

Progression sync. The vault payload lets you restore your record on a new device.

We do not sell your data. We do not use your data for advertising, profiling, or any purpose beyond operating the game described above.

3. Data retention

Your data is retained until you delete your account. Account deletion is available in-app via Settings, then Delete account and data. On deletion, all of your catch records, group memberships, vault data, and profile information are permanently and irreversibly removed from our servers.

4. Your rights

Access. You may request a description of the data we hold about your profile UUID.

Deletion. You may delete your account and all associated data at any time from within the App.

Portability. We do not currently offer a structured data export. Contact us if you need one.

5. Data security

All data in transit uses TLS. Server-side data is held in a PostgreSQL database hosted by Supabase. Direct table access is revoked for all API roles; the only access surface is a set of server-side functions that enforce authentication on every write.

6. Children

Tallywater is rated 12+ on the App Store. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, contact us and we will delete it.

7. Third-party services

Tallywater uses Supabase (Supabase, Inc.) to host the game database. No other third-party analytics, advertising, or tracking SDKs are included in the App.

8. Changes to this policy

We may update this policy to reflect changes to our practices. Material changes will be noted in the App Store release notes. Continued use of the App after an update constitutes acceptance of the revised policy.

9. Contact

Questions about this policy: povkonop@gmail.com

Support · Terms

Back to Tallywater