Privacy Policy

Kinetic Tempo Orchestra

Effective date: 2026-10-06

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Kinetic Tempo Orchestra stores campaign stars, unlocked ensembles, saved round phases, sound and haptic settings, language, reminder preference, cached challenge scores and pending daily results on your iPhone. A random installation identifier and a cryptographically random installation secret are kept in the device Keychain. When you complete an online daily challenge, the backend receives the installation identifier, challenge identifier, three completed cycles and star result. It stores the identifier, a hash of the secret, results and creation or update timestamps in its database. The plaintext secret travels over HTTPS for registration and authorization but is not stored by the backend. Requests to the game API and public website also expose network information such as IP address, request time, URL and ordinary HTTP metadata to the hosting infrastructure. There are no accounts, names, email entry, location collection, advertising identifiers, analytics SDKs or tracking cookies in the application or website.

How we use information

Local data keeps your campaign progress, saved phases, preferences and offline challenges available between sessions. The server supplies a UTC daily score and an offline challenge pack, authorizes installation-specific submissions and deletion, and keeps one best completion per installation and daily challenge so retries do not duplicate results. These records can be counted as daily completion totals; no public individual result listing or competitive leaderboard is provided. Network metadata and limited error logs support hosting, request limits, reliability and security. Optional local reminders notify you at 18:00 using iOS without a remote push service.

Service providers and sharing

The backend and public privacy page run on Railway. Railway processes requests, infrastructure metadata and the persistent database volume as the hosting provider. The application uses Apple's native Keychain, audio and local notification frameworks and no third-party mobile SDKs. Local notifications are scheduled on the device rather than sent to a messaging provider. We do not sell data or share it with advertisers. Disclosure may occur where required by applicable law. Infrastructure logging and any provider-managed backup processing are subject to Railway's practices; this product has not established a separate guaranteed retention period for those provider records.

Data retention

Local progress and caches remain until you reset them, remove application data or uninstall the application. The saved progress file is excluded from device backup by the application. The installation secret uses a device-only Keychain accessibility class and is not designed to migrate to another device; Keychain items may remain after uninstalling. Server installation and daily result rows have no automatic expiry and remain until authorized deletion. Successful submission removes the matching pending result from the local queue. No fixed infrastructure-log or backup retention duration is promised, and the application does not configure scheduled database backups. If Railway retains infrastructure records or copies under its own service practices, those may persist separately from live database deletion.

Deleting your information

In Settings, Delete server data uses this installation's secret to delete its installation row and all related daily result rows from the live database. Only after the server confirms deletion does the app clear queued results. Internet access is required; a failed request reports that deletion was not confirmed and can be retried. Local campaign progress is separate and can be removed with the confirmed Reset local progress action. Uninstalling removes ordinary application storage but does not itself issue server deletion, and iOS may retain Keychain credentials. Later daily completions can register the installation again and create new records. Loss of the installation secret cannot be repaired through a login, and cross-device recovery is not offered. Live deletion does not guarantee immediate erasure from Railway infrastructure logs or any provider-retained copies.

Permissions and your choices

Notification permission is requested only when you explicitly enable the daily reminder. You can disable the reminder in the application or withdraw notification permission in iOS Settings; the game continues to work. The application does not request access to geographic location, camera, microphone, contacts or photo library. Sound playback and optional haptic feedback are controlled in the application. Internet requests retrieve challenges and synchronize real daily results, with an offline local challenge available when requests fail.

Your privacy rights

Depending on your jurisdiction, you may have rights to access, correct, delete, restrict or object to processing of your personal data and to complain to a relevant data protection authority. Use the in-app server deletion control for data tied to your installation. For privacy questions or requests, contact Anselm35Duncombe@icloud.com. This address is a public privacy contact, not an in-app account or email delivery feature. We may need information sufficient to identify the relevant installation and verify a request, but you should not send your installation secret or other passwords by email. We cannot promise recovery or identification of installation records after the credential is lost.

Security

The deployed API uses HTTPS. Each installation has its own random secret; the server stores a SHA-256 hash of that high-entropy secret and enforces authorization and ownership on result submissions and deletion. A credential for one installation cannot authorize another installation's data. Registration cannot replace an existing installation's secret. Request size and time limits, input validation, database constraints and idempotent result writes reduce misuse and accidental duplication. Server code does not log authorization headers or request bodies. Device data relies on iOS protections, and server data uses Railway infrastructure and a persistent volume. No system is perfectly secure, and no compliance certification or absolute security guarantee is claimed.

Children’s privacy

The game is intended for an audience aged 16 and older and is not directed at children. It does not ask for age, identity or account information. If you believe a child's information has been processed inappropriately, contact Anselm35Duncombe@icloud.com so the relevant issue can be investigated, subject to our ability to identify installation-scoped records.

Changes to this policy

This policy may be updated when the application's processing or hosting changes. The current policy is published at the public privacy URL linked in Settings, and its effective date identifies the latest version. Material changes will be reflected in the policy and, where appropriate, communicated through an application update. Review this page periodically for current information.