WhiteSpy Privacy Policy

WhiteSpy respects your privacy. This policy explains what data the app stores, what data is sent to WhiteSpy servers for online play, and how that data is used.

App Privacy Summary

WhiteSpy has no advertising or tracking across other companies’ apps. In version 2.13 and later, usage analytics is on by default and can be turned off in Settings. Earlier versions start it off. Crash reporting is off by default.

Local mode: names, game words and saved decks stay on your device. When usage analytics is enabled, limited events about use of the app are sent to Google Firebase.

Online mode: certain lobby, session, and gameplay data is sent to WhiteSpy servers so online hosting, joining, reconnect, voting, and match synchronization can work.

Data Used for Online Gameplay

Your display name is visible to other players in the same online lobby. WhiteSpy online mode is lobby-code based and does not require account creation.

AI Custom Decks

When you choose to build a deck with AI, your theme, difficulty, language, and requested card count are sent through WhiteSpy servers to OpenAI for generation and content checks. Please avoid including private personal information in your theme. AI is optional; you can still create packs manually.

WhiteSpy verifies Apple-signed app download details for your one free custom-deck creation every 24 hours, or your signed Premium purchase for Premium access. Hashed identifiers link allowances across devices without a separate WhiteSpy account. Signed proofs are not stored in application logs or sent to OpenAI. Free creation cooldowns and daily Premium allowance and attempt counters are retained for up to 48 hours. Claimed deck identifiers are retained without automatic expiry so saved decks remain available and retrying a save does not consume another creation; deleting decks or reinstalling does not reset the free creation cooldown. Completed AI responses are retained for 24 hours so retries can recover them. The initial free manual-deck save requires an internet connection to check the allowance; saved decks remain playable offline.

OpenAI requests use store:false. OpenAI may retain content for abuse monitoring under its own data controls. See OpenAI API data controls. Saved deck libraries remain on your device.

When you host an online game with custom packs, the selected deck names and cards are uploaded to WhiteSpy. Names and card counts are visible in that lobby; each player receives only their assigned word during play. Uploaded cards expire with the lobby after inactivity. Guests do not receive a copy of your deck library.

We record operational measures such as request duration, outcomes, token usage and allowance consumption to run the service. We do not include themes, card contents or purchase proofs in those logs.

Usage Analytics and Optional Crash Reports

Usage analytics is enabled by default in version 2.13 and later unless you previously turned it off. Umi Studios uses Google Analytics for Firebase to understand which screens, game options and features are used, whether games and deck creation finish, and which operations fail. We use coarse player-count and duration ranges. App users in these reports represent app installations, not each person sharing a device. We do not send player names, emails, typed feedback, custom deck names, AI themes, card contents, guesses, lobby codes, session tokens or purchase proofs as analytics parameters.

Firebase Analytics creates an app-instance identifier and collects app/device information, app activity, sessions, approximate geographic information derived from network information, and in-app purchase information. The identifier is used to measure return visits on that installation. We disable advertising identifier collection, advertising consent and advertising personalization. We do not set an account user ID or request location access for analytics. Google processes this data under its privacy policy.

Crash reporting is off by default. If you turn it on, Firebase Crashlytics collects crash traces, device/OS and app-version information, installation identifiers, session diagnostics, finite screen/action breadcrumbs and selected technical error categories. If usage analytics is also enabled, recent usage events may appear as crash breadcrumbs. We do not attach user-entered text to diagnostics.

You may turn usage analytics off or enable crash reporting independently using the switches in Settings → About & Privacy. Turning usage analytics off stops future collection and resets its local analytics identifier. Turning crash reporting off stops uploads and deletes unsent reports. Turning an option off does not itself erase information previously sent. Contact us about privacy requests; we do not link these identifiers to names or accounts.

Google Analytics user and event data retention is configured for 14 months without resetting on new activity. Aggregated standard reports can remain available longer. Crashlytics generally retains crash reports and associated identifiers for 90 days. Daily raw-data exports use Google’s US-region BigQuery sandbox, with automatic 60-day expiry and a 10 GiB lifetime storage limit; it is not permanent archival storage. Network metadata is also processed to deliver and secure these services.

On-Device Data

This local data is stored on your device using system-provided storage such as UserDefaults and the app's Documents directory.

Retention

We may temporarily process network information such as IP address for security, rate limiting, abuse prevention, and server operations.

What We Do Not Collect for Advertising or Tracking

Data Control

You can remove local app data by deleting the app. Online lobbies expire automatically after inactivity.

Contact

If you have questions about this policy, contact us at WhiteSpyApp@gmail.com.