Skip to content

Legal file 01

Privacy Policy — beta draft

This page explains how the current Bureau of Odd Cases beta stores and processes information. It deliberately distinguishes device-only records from pseudonymous server activity.

Last updated: 14 August 2026

1. Website

This first website version has no accounts, contact forms, advertising trackers, analytics, or non-essential cookies. It is designed as an informational site only.

The website is hosted through OpenAI Sites and its underlying infrastructure. Those providers may create technical access and security logs under their own policies. The Bureau does not currently receive a separate website analytics dashboard or set non-essential cookies.

2. Information kept on your device

The app keeps language preferences, detailed round outcomes, favorites, recent-case history, solve statistics, downloaded case content, purchase-access cache, and session information on your device so the game can work reliably and offline where supported.

3. Pseudonymous app activity

If the Supabase service is configured, the app creates a persistent random device identifier and sends it with the selected language, platform, first and last activity time, case and deck identifiers, and limited round events such as played or liked.

This activity record does not include a name or email by default, but a persistent identifier can still be personal data under some privacy laws.

4. Purchases and protected content

The app creates an anonymous Supabase user identifier when it needs to verify purchases or retrieve protected case content. The same identifier is used with RevenueCat to manage entitlements and restore access.

Apple processes payment credentials and billing. Bureau of Odd Cases receives product, purchase, and entitlement status, but not your full payment-card details.

5. Stories, alternative explanations, and support

If you submit a story or an alternative explanation, we receive the text, its language, and any author name or contact detail you choose to provide. Submissions are hidden by default and reviewed before publication.

A future support channel may retain the messages and technical details you send voluntarily. Do not send passwords, full receipts, payment-card details, or confidential information.

6. Why this information is used

Information is used only to operate and improve the game, including to:

  • deliver the included and purchased case archives;
  • verify, restore, and revoke purchase access when required;
  • remember game state and support offline play;
  • understand aggregate case activity and reliability;
  • moderate voluntary submissions;
  • respond to support, privacy, and content reports.

7. Service providers and sharing

The beta relies on Apple for TestFlight and in-app purchases, RevenueCat for entitlement management, and Supabase for anonymous authentication, protected content, submissions, and pseudonymous activity records. Those providers process information under their own terms and security practices.

We do not use third-party advertising, sell personal information, or perform cross-app tracking. Information may be disclosed when required by law or necessary to protect users, rights, and service security.

8. Retention, transfers, and security

Device records stay on the device until removed by the app, an app-data reset, or uninstall, subject to platform backup behavior. Service records are kept only while needed for the purposes above, legal obligations, dispute handling, and service security.

A precise production retention schedule, backup period, Supabase processing region, and international-transfer safeguards will be published before commercial release. Reasonable safeguards are used, but no online system can promise absolute security.

9. Your choices and rights

Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection, and to complain to a data-protection authority. The production contact and a practical way to identify the relevant anonymous account will be added before release.

The audience age policy and final store rating are not yet set. Until they are, children should not submit names or contact details without a parent or guardian.

10. Changes and contact

Material changes will be dated on this page. A verified privacy and support address, together with the operator’s full identity, will replace this release-readiness notice before general App Store release.