Privacy Policy

Blade the FireShow

Effective date: 2026-10-06

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Blade the FireShow stores compositions, show titles, effect positions and colors, cover-beat choices, backgrounds, campaign and daily progress, and accessibility and language preferences locally on your device. These are not uploaded. When you open the online daily show, the server creates a random installation secret; the app stores it in the device Keychain with device-only accessibility. The server stores a SHA-256 hash of that secret and the installation creation time. Daily completion records contain the daily-show identifier, completion time, attempt count and server recording time linked to that hash. Daily requests include the requested date and game version. Railway infrastructure receives connection information such as IP addresses and HTTP request metadata, including requests to this public website. The application server logs a request identifier, method, generalized route, response status and duration, and does not log installation secrets or request bodies. We do not request your name, email address, contacts, precise location or an account.

How we use information

Local data allows offline composition editing, playback, campaign progression, the show album and your preferences to work after reopening the app. The installation secret authorizes access to your installation-specific daily completion records. Server data delivers version-compatible daily puzzles and records completion facts and attempts. Request metadata and operational logs support service availability, security and diagnosis. Optional notifications are scheduled locally to remind you about the daily show; no email delivery or remote push service is used.

Service providers and sharing

The backend and public policy are hosted by Railway, which processes the network requests and infrastructure data needed to operate the service. There are no advertising, analytics, social-login or other third-party SDKs in the app, and no sale of your data. Apple provides the device operating system, Keychain and local notification facilities. Device backup handling depends on your Apple and device settings. We may disclose information if required by applicable law. The public privacy contact is saf.claremont@icloud.com; contacting it is optional and is not an in-app messaging feature.

Data retention

Local compositions and progress remain until you reset local progress in Settings or remove the app. The device-only Keychain installation secret may remain after app removal, depending on operating-system behavior. Server installation and completion records remain until you use the online-data deletion control. No automatic expiry duration is currently configured. Operational and infrastructure log retention is governed by the hosting configuration and provider practices; we do not state an unverified fixed duration. No application-managed backup schedule is configured. Provider-managed copies, if any, follow provider retention and deletion processes rather than immediate deletion from every backup.

Deleting your information

Settings offers separate controls to reset local progress, drafts and the album, and to delete online installation data. Online deletion requires a working connection and your installation secret, deletes the installation and its completion records from the active database, and then removes the secret from the app Keychain. If the request fails, the app keeps the secret so you can retry. Later online use creates a new installation. Resetting local data does not itself delete online records. Losing the installation secret prevents the service from proving ownership of those records; there is no account-based recovery. Deleted database content can remain in storage journals or provider backups until those copies are retired under their normal processes.

Permissions and your choices

The app requests notification permission only when you explicitly enable the optional daily reminder. You can turn it off in the app or withdraw notification permission in iOS Settings at any time. Campaigns, free shows and the album work without notification permission or a network connection. No camera, microphone, photo-library, contacts or location permission is requested. Cover previews are derived from your composition inside the app and do not access your photos.

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete or restrict processing of your data and to complain to your local data-protection authority. You can manage local shows directly and delete installation data through Settings. For privacy questions or rights requests contact saf.claremont@icloud.com. We may need enough information to verify a request, but do not send your installation secret in an email. We cannot reliably associate an anonymous installation with a person who no longer has its secret.

Security

The app communicates with the production service over HTTPS. Each installation receives its own cryptographically random secret; the client keeps it in Keychain and the server stores only its hash. Protected endpoints check that secret and restrict records to the authorized installation. The service validates inputs, limits request sizes and uses persistent SQLite storage with restricted database-file permissions. These measures reduce risk but cannot guarantee absolute security. There is no shared secret embedded in the client and no public endpoint for private completion records.

Children’s privacy

The game is intended for players aged 12 and above and contains virtual light-show puzzles, not instructions for real pyrotechnics. It does not ask for a birth date or create user accounts. If you believe a child has provided personal information through a privacy enquiry, contact saf.claremont@icloud.com so we can address it. Parents can disable notifications and network access using device controls.

Changes to this policy

We will update this policy when the app or backend processing changes. The current policy and its effective date are published at /privacy and linked from the app Settings. Material changes will be described in the updated policy or accompanying app release information. Please review the policy periodically.