Privacy Policy

Expedition Detail Sketchbook

Effective date: 2026-10-06

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Expedition Detail Sketchbook stores campaign progress, collected creatures, unfinished rounds, selected details, attempt accuracy, play duration, daily challenge dates and results, cached challenges, language and accessibility preferences on your iPhone. Campaign and practice records are not uploaded. When a server daily challenge is completed, the app sends its UTC date, accuracy and elapsed seconds. The backend assigns a random installation identifier and secret automatically; the secret stays in the device Keychain and only a bcrypt hash is stored in PostgreSQL. The backend stores the installation identifier, credential hash, creation time and daily result update times. Requests to the API, home page and privacy page also expose network information such as IP address, request path and ordinary HTTP metadata to Railway infrastructure. No name, email address, account, password, location, contacts, photos or advertising identifier is requested. Local fallback challenge results remain on the device.

How we use information

Local records let you resume an expedition, build your atlas, practice and review real progress. The backend delivers a date-specific daily challenge and compatible challenge metadata, receives installation-scoped daily results and supports deletion of those results. Result records allow anonymous operational summaries of daily challenge accuracy and duration; the app does not display a public leaderboard or other players’ records. Random credentials authorize only the requesting installation. Transient IP-based rate-limit entries protect the API against abuse. Error codes and request identifiers support service operation without logging credentials or request bodies.

Service providers and sharing

The app has no advertising, social sign-in, third-party analytics or outbound email SDK. Railway hosts the HTTP service and PostgreSQL database and processes requests, network metadata and infrastructure logs as the hosting provider. The service operator can access stored operational data to run the service. Results are not publicly accessible, and no result-sharing feature is provided. Apple supplies iOS networking, device storage and Keychain services; device backups are controlled by your Apple settings. Information may be disclosed when legally required. We do not sell installation records.

Data retention

Local game records and settings remain until you delete them in Journal Settings or remove app storage. Keychain credentials can survive uninstalling the app, so use the in-app deletion action before removal if you want to revoke server access. The backend keeps installation records and associated daily results until deletion; it currently has no scheduled expiry policy. Cached challenges are eligible for reuse only for their current UTC date and for less than 24 hours. Pending daily submissions are discarded after their UTC date expires. Rate-limit entries are transient in-memory data with minute or hour windows. Railway infrastructure log and backup retention depends on the hosting service configuration; no fixed retention duration is promised here.

Deleting your information

Journal provides Delete installation data. If a server credential exists, this first requests deletion of the installation and all its daily results from the active database, then clears local progress, cached content, pending results and the Keychain secret. If the server deletion cannot be confirmed, the app keeps the data and secret so you can retry online. Deletion cannot undo processing already performed, erase infrastructure logs immediately or selectively remove records from any existing infrastructure or device backup. Backup copies, if present, follow the provider’s lifecycle. Without the installation secret we cannot identify or restore your installation’s private records. The privacy contact can answer deletion questions but is not an account recovery system.

Permissions and your choices

The app does not request location, camera, microphone, photo-library, contacts or notification permission. It uses ordinary internet access for daily challenges and server deletion. Campaign and practice remain available offline. You can stop network requests by disconnecting the device, but server deletion requires a connection. Sound feedback, touch feedback and reduced motion are controlled in Journal and iOS accessibility settings. You can change app preferences or delete local data at any time; there is no account authorization or social permission to withdraw.

Your privacy rights

You can review local progress and challenge results in Journal and control your records through the deletion action. Depending on applicable law, you may have rights to request access, correction, deletion, restriction or information about processing, and to contact your relevant privacy authority. Contact alastair.abernethy@icloud.com with privacy questions. Do not send your installation secret by email. This address is a public privacy contact only; the app does not require email or provide an email delivery or support-ticket feature.

Security

The deployed API uses HTTPS. Installation secrets are generated using cryptographically secure randomness, held in device Keychain with device-only protection, and checked against bcrypt hashes on the server. Private result routes require installation-specific authorization; an installation cannot read another installation’s results. PostgreSQL stores server records, input constraints validate results, and request-size, timeout and rate limits reduce abuse. The app embeds no shared server credential. No transmission or storage system can guarantee absolute security.

Children’s privacy

The game is intended for players aged 12 and older and is not designed specifically for children under 12. It does not ask for age, names or contact details and has no accounts, chat, advertising or purchases. If you believe information concerning a child was submitted improperly, contact alastair.abernethy@icloud.com. Installation-scoped deletion is available in the app without creating an account.

Changes to this policy

This policy describes the current app and backend practices and is effective on 2026-10-06. Changes will be published on this page with an updated effective date and made accessible through the Privacy Policy link in Journal. Material changes to processing will be reflected in the app and policy before they are introduced.