Privacy Policy
exstraboat: Crazy Boat Crew
This policy explains how this application handles information and how to contact us about privacy.
Information we process
exstraboat: Crazy Boat Crew stores course progress, best times, accuracy, the last three attempts per course, earned pennants, rowing totals, language, sound settings, motion preferences and notification preference locally on your iPhone. The daily course configuration is cached locally. An unsent winning daily result can be held locally for retry. The app automatically obtains a random installation secret when first submitting a daily result and stores that secret in the iOS Keychain. The server stores only a hash of the secret, an internal installation identifier and creation timestamp, plus each installation’s best daily result: course date and pattern identifier, finish time, accuracy, hit count, total notes and result timestamp. This app sends an empty display name, so rankings identify crews by anonymous rank. The API supports an optional display name but this version does not ask for one. No account, email address, password, precise location, contacts, photos or advertising identifier is requested. Railway receives network requests, which can include IP address, request time, route and technical network metadata, even when you only read the daily course or this policy.
How we use information
Local data lets you continue courses, view records and pennants, adjust optional audio and receive an optional daily reminder. Cached courses let you play offline. Server data authorizes each installation to submit or delete its own results and produces the shared daily leaderboard. Timing and accuracy validation checks result consistency; it is not a guarantee against cheating. Short-lived in-memory rate-limit counters help protect the service. Technical diagnostics support service operation. No analytics, advertising, purchase or outbound email service is integrated.
Service providers and sharing
The public leaderboard exposes up to twenty results for a requested day, including rank, optional display name, finish time and accuracy; installation secrets and internal identifiers are not published. The backend and persistent database volume are hosted by Railway, which processes request and infrastructure metadata to operate the service. The app uses Apple iOS services for Keychain and local notifications; reminders are scheduled on the device and no push-token or remote notification service is used. There are no third-party advertising, analytics, map or social-login SDKs. The backend logs service start and internal-error request identifiers and error types, not authorization headers or result payloads. Infrastructure logging by Railway is separate from these application logs.
Data retention
Local progress and preferences remain until reset or removed with the app, subject to iOS device storage and backup behavior. The Keychain secret may remain after uninstalling, according to iOS behavior. Cached daily courses are replaced as new courses are fetched. Pending results are retried only for their UTC day; an older pending result is removed when the daily screen loads. Server installation hashes and best daily results have no automatic expiry and remain until the installation deletion action succeeds. In-memory rate-limit counters use ten-minute windows, a bounded cache and disappear on server restart. No application backup schedule or fixed Railway log-retention period is asserted. Provider logs, managed snapshots if present and device backups follow their providers’ retention and deletion behavior; deleting live application rows does not guarantee immediate removal from such copies.
Deleting your information
In Settings, Reset local progress erases local records, pennants and rowing totals after confirmation. It does not erase server results. Delete my server results uses the installation secret to delete the server installation and all its results, then removes the local Keychain secret and pending submission. Local records remain unless you reset them separately. A network failure is shown and you can retry deletion. Daily cached configuration contains public course content. Removing the app removes its app-container data subject to iOS behavior, but does not itself invoke server deletion and may not erase Keychain data. The service cannot recover access to results after the installation secret is lost; there is no account recovery or cross-device login. Deletion acts on live server data; residual storage pages, infrastructure logs or backups are governed by hosting and device lifecycle rather than a promised erasure deadline.
Permissions and your choices
Notifications are optional and requested only when you enable the daily reminder. You can turn the reminder off in the app, which cancels its pending request, or withdraw permission in iPhone Settings. No location, camera, microphone, photo-library or contact permission is requested. Audio output is optional; visual timing remains usable with sound off. System Reduce Motion is honored, and the app also offers a decorative-effects switch.
Your privacy rights
You can inspect your local records, reset local progress and delete your installation’s server data through Settings. Depending on your location, privacy rights may include access, correction, deletion, restriction or objection and the right to complain to a relevant authority. Privacy inquiries can be addressed to PhilomenaHawkridge@icloud.com. This address is a public privacy contact only; the app has no contact form or email-delivery system. Do not send your installation secret. Because no identifying account is created, a request may require enough non-secret information to understand the issue and we may be unable to associate records with a person after loss of the secret.
Security
The app connects to the deployed API over HTTPS. Each installation receives its own cryptographically random secret, stored using a device-only Keychain accessibility class. The server authorizes mutations using that secret and stores its SHA-256 hash rather than the secret. Database foreign keys cascade result deletion, result validation and payload limits constrain writes, and public ranking responses omit installation identifiers. No shared client credential grants access to private installation data. Local preferences and records are in the app container and are not separately encrypted by the app. Hosting administrators can access the server infrastructure. No storage system or network can be promised completely secure.
Children’s privacy
The game is designed for a casual audience that includes younger players, with a suggested audience starting at age ten. It does not ask for age, a real name, email, contacts, location or a user account. Daily play can send installation-linked gameplay results and exposes anonymous scores publicly; offline courses and training are available without submitting results. Parents or guardians can keep play offline, disable notifications and use the deletion controls. We do not knowingly request identifying information from children. A parent or guardian concerned about processing can contact PhilomenaHawkridge@icloud.com without sharing a secret.
Changes to this policy
This policy describes the current application and backend. The effective date is shown above. If data practices change, the policy at this public URL will be updated and the application will be updated when a change requires new controls or permission. Please review the policy when using a new version.