Privacy Policy
Terms of Mischief · Updated 2026-09-24
Who operates the game
Sean Cantrell operates Terms of Mischief. Contact sean.a.cantrell@gmail.com for privacy questions, requests or concerns. This policy covers the current beta and its game service. It distinguishes information stored on your device, information relayed to other players and information handled by distribution or infrastructure providers.
Information on your device
The app stores your profile, settings, decks, collection, friends and blocks, Wishes and lists, matches and replays, chat history, unread-message records, fulfillment records and unsent deliveries. A chosen profile photo is cropped for use as a banner; the app does not upload your photo library. Private planning notes stay on your device. Identity and connection keys use protected device storage where implemented. Local message and Wish history is readable app data, not a separately encrypted vault. Device security and backup settings affect its protection.
Information shared with players
Your username is searchable through the public directory. The directory stores your display name, player and device identifiers and public identity keys for discovery and authentication. Your chosen recipients receive the messages, Wishes, match information and profile presentation that you share through the game. They can retain screenshots or their own copies. Wish contents are withheld until the relevant in-game decision. Local erasure does not recall content already delivered to another person.
What the game service processes
The service registers devices and public profiles, routes friend requests and encrypted deliveries, and supports turns, Wish decisions and notifications. While a delivery is pending, it necessarily processes temporary routing identifiers, room membership, delivery timing, ciphertext hashes, notification types and match identifiers. Connections expose network information such as IP addresses to the infrastructure carrying them. Message text, Wish text and Wish reveals are end-to-end encrypted between the paired phones; our relay does not receive their plaintext or hold a chat or Wish archive. Encryption does not hide all temporary delivery metadata. The service also records which app version your phone uses and the day it last connected, blocks you place (so the blocked player's friend requests stop and your profile is hidden from them) and, for seven days, friend requests you declined. If you report a player, the operator receives the reason, your note and any of that player's recent messages you chose to include; reports are deleted 30 days after review and never kept longer than 180 days. This is not a claim of Signal-equivalent security or anonymity.
Optional error reports
Error reports are off unless you turn on Send error reports in Settings. When on, your phone reports when it cannot apply a friend's move, when your move is undone because your friend's phone could not apply it, when a match's shared history disagrees, or when the app hits an unexpected error. A report contains only the app checkpoint, whether the phone is an iPhone or an Android phone, a fixed error code and the game's own error text, or for an app error its type and code location, with identifiers and file paths removed. It never contains your name, username, friends, moves, messages or Wishes. Your phone authenticates the request like other game-service requests, but the service stores the report without your device or player identifier and deletes it after 30 days. Turning the setting off stops further reports.
Retention
Pending encrypted deliveries are retained until the intended receiving phone confirms a durable local save; going offline does not start a deletion countdown. Ordinary delivery ciphertext is deleted on that confirmation. A content-free delivery receipt (message identifier, routing, ciphertext hash and delivery time) is retained for 24 hours after confirmation to recognize retries, then removed by the periodic cleanup. A cancelled sealed Wish offer is deleted immediately. After a Wish is accepted or refused, its encrypted reveal, signed choice and associated routing record remain pending until both phones confirm their local saves, then are deleted together. Explicit actions end retention sooner: removing or blocking a friend deletes every conversation and match room your two phones share, including deliveries and Wish records still waiting in either direction; leaving, declining or archiving a match discards whatever was still waiting for your phone in that match; and deleting your account erases every room you share. Otherwise, if a phone never confirms, the pending delivery may remain stored indefinitely. Notification jobs are deleted when the push provider accepts them or the app confirms delivery; stale alert jobs can expire without deleting the underlying pending game or chat delivery. Notification tokens not refreshed for 90 days are cleared. Encrypted backups contain only the device credential hashes and public directory profiles needed to restore access; they exclude rooms, relationships, matches, messages, turns, Wishes, decisions and notification data, retain at most three copies and expire within seven days. Local history remains on each phone until its owner erases it or removes app data. Deletion cannot guarantee removal from a recipient's phone, provider systems or filesystem snapshots outside the game service.
Notifications, updates and providers
If you allow alerts, our service stores your notification token and alert preferences and sends notifications directly through Apple Push Notification service or Android Firebase Cloud Messaging. You can disable all alerts, choose active or quiet presentation, and independently choose invitations, turns and chat. Notification payloads contain generic event information and routing identifiers, not private message or Wish text. A short foreground-presence lease suppresses chat alerts while the app is active. Expo provides app-update distribution; Apple, Dropbox or our HTTPS installer may distribute installers. Our game service, website and iPhone installer page run on a server we operate, hosted by Hetzner Online in Nuremberg, Germany; Cloudflare provides DNS for termsofmischief.com. These providers receive information necessary to deliver their services and operate under their own privacy policies. Firebase use here is for messaging delivery, not a Firebase chat database or advertising analytics.
TestFlight diagnostics and feedback
For TestFlight installations, Apple collects beta usage and crash information and makes beta-testing information available to the developer under its TestFlight terms. TestFlight feedback may include screenshots, comments, device information and contact information. This collection is separate from the game's lack of added advertising or behavioral-analytics SDKs. Do not include private messages or Wishes in feedback screenshots. Information you deliberately email us is available to us and our email provider so we can respond.
Purposes, sharing and your choices
We use the minimum information needed to provide gameplay and communication, authenticate devices, deliver updates and alerts, prevent abuse, troubleshoot faults and respond to requests. We do not collect gameplay analytics; error reports are optional and off by default. We do not sell personal data, use private messages or Wishes for advertising, or train AI models on them. If legally compelled, we can disclose only the limited records actually present at that time; the relay has no plaintext message or Wish archive and does not preserve who accepted which Wish after delivery cleanup. You can disable notifications, change your profile and username, remove or block friends, and use Settings > Privacy & account to erase supported local records.
Deletion and privacy requests
Local erasure is not account deletion and does not erase your partner's phone or provider records. Small content-free erased-match records remain locally to prevent delayed deliveries from restoring erased history. Server delivery records disappear through the acknowledgement and deletion rules above. Public directory profiles and device credential hashes remain until you delete your account in Settings → Privacy & account, or ask us to; deletion erases your directory profile, friend requests, alert registration and every room you share, and permanently revokes the device credential so it cannot be used again. Contact sean.a.cantrell@gmail.com to request access, correction or deletion; we may need proportionate proof that the identity belongs to you. Do not email private keys, passwords, Wishes or sensitive chat contents. Rights and response requirements depend on your location; you may also have a right to complain to your local privacy regulator.
Age, security and changes
Follow applicable minimum-age and parental-permission requirements. Do not submit information about children or other people without the authority required by law. Contact us if you believe information was provided without required permission. No storage or transmission method is perfectly secure. Services and providers may process information outside your country. We will update this dated policy when practices change and provide appropriate notice of material changes. We will not describe new data collection as already covered without updating the disclosure.