Privacy Policy
Clash Social Challenge Platform & Mobile Application
Clash Inc. operates the Clash mobile application and related services (collectively, the "Service"). This Privacy Policy transparently details how we collect, store, use, disclose, and protect your personal information when you access our app. By using Clash, you agree to the practices described in this policy.
1. Information We Collect
We collect information you provide directly to us, information generated automatically during your use of the app, and limited verification parameters necessary to operate social challenges.
A. Account and Profile Information
- Sign In with Apple Identifier: When you register using Sign In with Apple, we receive an encrypted user identifier provided by Apple, along with the name and email address you authorize Apple to share (which may include Apple’s private relay email address).
- Profile Details: Custom profile elements you configure, including your public username, display name, avatar/profile image, and biographical snippet.
B. Social & Challenge Data
- Friendships & Connections: Requests sent, received, accepted, or blocked, as well as active social connections on the platform.
- Challenge Parameters & History: Challenge configurations (duration, target screen time metric, forfeit conditions), challenge participation state, mutual result confirmation logs, outcome history, win/loss stats, and exact server timestamps.
C. Penalty Selfies (User Content)
- Images voluntarily taken and submitted within the app as a stake or forfeit penalty for specific challenges ("Penalty Selfies").
D. Technical, Device, and Security Data
- App performance logs, crash reports, device model, operating system version, unique device identifiers, IP address, request headers, session tokens, and security telemetry used for fraud prevention.
2. How We Use Your Data
We process your personal information strictly for legitimate operating purposes, including:
- Authentication & Account Provisioning: Authenticating your identity via Apple Sign In and maintaining your active session.
- Service Delivery & Gameplay: Operating social challenges, syncing state between participants, storing encrypted Penalty Selfies, and executing challenge logic (revealing forfeits upon verified defeat).
- Fraud & Abuse Prevention: Detecting unauthorized automated bots, cheating mechanisms, multiple account creation abuse, and community standard violations.
- Customer Support & Communication: Responding to support inquiries, resolving technical glitches, and sending transactional notifications regarding challenge progress.
- Service Enhancement: Analyzing anonymized technical diagnostics and aggregated telemetry to improve app performance and stability.
3. Service Providers & Third-Party Vendors
We disclose data only to vetted third-party infrastructure providers necessary for technical delivery. These entities are bound by strict data processing agreements prohibiting them from using your data for any unauthorized purpose.
| Vendor Name | Service Category | Data Disclosed & Purpose |
|---|---|---|
| Apple Inc. | Authentication & Platform API | User ID token, Sign In authorization parameters, native Screen Time rendering interface. |
| Supabase Inc. | Database & Storage Infrastructure | Encrypted user records, profile data, challenge logs, and secure encrypted cloud bucket storage for Penalty Selfies. |
| Sentry / Firebase Crashlytics | Crash Diagnostics & Monitoring | Anonymous stack traces, device model, OS version, and performance metrics at time of app crash. |
| Postmark / SendGrid | Transactional Email Delivery | User email address (or Apple Relay address) for transactional support communications. |
4. Device Permissions & Control
Clash requests explicit permission prior to accessing specific hardware features or iOS frameworks. You retain full control over these access points:
- Camera Access: Required solely to capture live Penalty Selfies or upload profile avatars within the app interface. Access is completely optional until you attempt to initiate a selfie-staked challenge. You can revoke access at any time in iOS Settings > Privacy & Security > Camera > Clash.
- Screen Time Framework Access: Requested so that your device can locally compute whether a challenge threshold has been reached. You may revoke access via iOS Settings > Screen Time > Content & Privacy Restrictions or app permission settings. Revoking access will prevent you from participating in Screen Time-based challenges.
5. Penalty Selfie Handling & Reveal Mechanics
Screenshot Advisory: While Clash strictly restricts access prior to defeat, once a Penalty Selfie is revealed to your opponent on their screen, Clash cannot control or prevent the opponent from taking a hardware screenshot, screen recording, or using a third-party camera to record the image. Submit photos with this explicit understanding.
6. Data Retention & Deletion Timeline
We adhere to strict retention schedules to ensure data is not held longer than legally or operationally required:
| Data Category | Retention Period / Deletion Trigger |
|---|---|
| Active Account Profile | Retained for the lifetime of the account. Permanently deleted within 30 days of account deletion request. |
| Penalty Selfies | Stored encrypted until challenge completion. Automatically deleted from cloud storage within 14 days post-challenge completion or forfeit reveal. Unrevealed selfies from canceled challenges are purged immediately. |
| Challenge Logs & Metadata | Anonymized and retained for 90 days following challenge completion for reporting and leaderboards, then hard-deleted. |
| System Logs & IP Telemetry | Retained on a rolling 30-day security log rotation, after which logs are permanently overwritten. |
| Backups | Encrypted database backups rotate out completely within 30 days of standard deletion. |
7. User Rights and Controls
Depending on your location, you hold specific legal rights regarding your personal data:
- Access & Export: You may request a machine-readable copy of your personal data stored on our servers.
- Correction: You can update or amend your display name, username, and profile picture directly inside the app settings.
- Deletion (Right to be Forgotten): You may request account deletion in-app under Settings > Account > Delete Account or by emailing our privacy desk. Upon confirmation, all associated data, active challenges, and selfies are purged.
- Consent Withdrawal: You may revoke consent for optional data processing by modifying iOS device permissions.
8. Security Safeguards
We implement robust technical and organizational measures to protect your information, including end-to-end transport encryption (TLS 1.3), AES-256 encryption for stored asset buckets, strict role-based access control, and periodic infrastructure audits. However, no electronic transmission over the internet or cloud storage backend is 100% secure; we cannot guarantee absolute security.
9. Children’s Privacy
Clash is strictly intended for individuals aged 13 years and older (or 16+ where required by applicable local EU law). We do not knowingly collect personal data from children under 13. If we discover that a child under 13 has submitted personal information, we will immediately terminate the account and purge all associated records. Parents or guardians who suspect a minor has created an account may contact us directly.
10. International Data Transfers & Regional Specifics
Your information may be transferred to and processed on servers located within the United States or other jurisdictions where our cloud service providers operate. We utilize standard contractual clauses and regulatory safeguards to ensure your data receives adequate protection globally under GDPR, CCPA/CPRA, and other applicable data privacy laws.
11. Policy Updates & Contact Information
We may amend this Privacy Policy periodically. Material updates will be notified in-app or via the email address associated with your account prior to taking effect. Continuous use of Clash after updates constitutes acceptance.
Email: junjason1126@gmail.com
Response Window: We strive to acknowledge and fulfill all verified requests within 30 days.