Privacy Policy
Effective date: August 13, 2026 · Original: April 15, 2026
Arcforge Digital Labs LLC ("we," "us," or "our") operates the arcforgelabs.dev website (the "Site"), web tools served from it such as Key (the "Tools"), and the Reversi mobile application for iOS (the "App"). This Privacy Policy explains what data each collects, how we use it, and your rights regarding that data.
The short version: the Site and the Tools collect nothing. Only the App — which offers accounts, multiplayer, and purchases — processes personal data, and Sections 4–10 cover it in detail.
1. The Website
The Site is a set of static pages. It sets no cookies, runs no analytics, embeds no third-party scripts, fonts, or trackers, and shows no ads. There are no accounts and no forms; nothing you do on the Site is recorded by us.
The Site is served by our hosting provider, Vercel Inc., which processes requests in order to deliver pages and retains ordinary, short-lived operational server logs (such as IP address and browser user agent) as any web host does. See Vercel's Privacy Policy. We do not use those logs to identify or profile visitors.
Because we hold no personal data about Site visitors, there is nothing for us to access, correct, export, or delete on request.
2. Key, the password generator
Key generates passwords and passphrases entirely on your device, using your browser's built-in cryptographic random number generator. Everything it makes exists only on your screen and, if you use the Copy button, your clipboard — which is managed by your device, not by us.
- We never receive, transmit, log, or store anything Key generates.
- The page is served with a Content-Security-Policy that forbids it from making network requests of any kind, so it is technically incapable of sending data anywhere — not a promise, a property you can verify in your browser's developer tools.
- Key sets no cookies and writes nothing to your browser's storage. It works offline.
- Key's source code is publicly available for inspection.
3. Scope of the remaining sections
Everything below this point applies only to the Reversi iOS App. If you have never installed the App, none of it involves you.
4. Information We Collect (Reversi App)
4.1 Account Information
When you sign in with Apple, we receive your Apple-provided user identifier and, if you choose to share it, your email address. If you continue as a guest, we create an anonymous identifier.
4.2 Game Activity
We record matches played, game moves, match outcomes, and your Elo-style rating to provide matchmaking, leaderboards, and rating integrity.
4.3 Device Identifiers
We collect a hashed version of your Identifier for Vendor (IDFV) for anti-cheat purposes. We do not collect the Identifier for Advertisers (IDFA) without your explicit permission via the App Tracking Transparency prompt.
4.4 Push Notification Tokens
If you enable push notifications, Apple provides a device token that we store to deliver game invitations and match updates.
4.5 Purchase History
We store your subscription status and entitlement records to unlock premium features. We do not have access to your payment method or full transaction details — Apple processes all payments.
4.6 Analytics Data
We collect gameplay events (e.g., tutorial progress, feature usage) via Firebase Analytics to improve the App. For users in the European Economic Area (EEA), United Kingdom, or Switzerland, analytics data is collected only with your explicit consent.
5. Third-Party Services (Reversi App)
| Service | Provider | Purpose |
|---|---|---|
| Firebase Authentication | Google LLC | User sign-in and identity management |
| Cloud Firestore & Realtime Database | Google LLC | Game data storage and real-time multiplayer |
| Cloud Functions for Firebase | Google LLC | Server-side game logic and account management |
| Firebase Analytics | Google LLC | Anonymous usage analytics |
| Google AdMob | Google LLC | Advertising (free tier users) |
| Sign in with Apple | Apple Inc. | Authentication |
| StoreKit (In-App Purchases) | Apple Inc. | Subscription and purchase management |
These services are used by the App only — none of them is present on the Site or in the Tools. Each has its own privacy policy. We encourage you to review Google's Privacy Policy and Apple's Privacy Policy.
6. How We Use Your Information (Reversi App)
- Provide, maintain, and improve the App.
- Matchmaking, leaderboards, and Elo rating calculations.
- Detect and prevent cheating and abuse.
- Send push notifications you have opted in to.
- Display advertisements (free tier) — personalized only with your consent and App Tracking Transparency authorization.
- Analyze usage patterns to improve gameplay (with consent where required by law).
7. Advertising and Tracking (Reversi App)
The App displays ads via Google AdMob for users on the free tier. We request your permission through Apple's App Tracking Transparency (ATT) framework before enabling personalized advertising. If you decline, you will see non-personalized ads only. You may change your tracking preference at any time in iOS Settings → Privacy & Security → Tracking.
8. Data Retention (Reversi App)
- Game records: Retained indefinitely to preserve rating integrity for all players.
- User profile: Retained until you delete your account.
- Analytics data: Retained per Google's standard retention policies (typically 14 months).
- Anti-cheat data: Anonymized records retained for 90 days after account deletion, then permanently purged.
9. Account Deletion (Reversi App)
You may delete your account at any time from Settings → Account → Delete Account within the App. Upon deletion:
- Your user profile, entitlements, sanctions, and personal data are permanently deleted.
- Your match history is anonymized (your identity is replaced with "Deleted User") to preserve opponents' rating records.
- Your Firebase Authentication account is removed.
- Active games are forfeited.
10. Your Rights (Reversi App)
Depending on your jurisdiction, you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate data.
- Deletion — request deletion of your data (see Section 9).
- Portability — request your data in a structured, machine-readable format.
- Opt-out — opt out of analytics and personalized advertising at any time via the App's Settings → Privacy section.
For EEA, UK, and Swiss users: we process your data under GDPR. Analytics and personalized advertising require your explicit opt-in consent, which you may withdraw at any time.
11. Children's Privacy
The App and the Site are not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal data, please contact us so we can delete it.
12. Data Security
The Site and the Tools are served exclusively over HTTPS with strict security headers, and — as described above — hold no user data that could be exposed. For the App, we use industry-standard security measures, including Firebase's built-in encryption at rest and in transit, Firestore Security Rules, and authenticated Cloud Functions. However, no method of electronic storage or transmission is 100% secure.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised effective date. Your continued use of the Site, the Tools, or the App after changes are posted constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
Arcforge Digital Labs LLC
7901 4th St N, STE 300
St. Petersburg, FL 33702
Email: privacy@arcforgelabs.dev