Privacy policy
Effective August 13, 2026
The short version
Verdict is a puzzle game, not a data business. It is operated by Endpaper Labs LLC ("we," "our," or "us"). We collect the minimum needed to run the game: an email if you create an account, your account-linked puzzle activity, and usage analytics that we don't tie to your name or account (described under "Analytics" below). Optional product-research prompts are described below. We don't sell data, we don't run ads, and we don't use third-party advertising or tracking SDKs.
What we collect
Without an account: you can play the daily case with no signup. On the web, your progress and streak are stored only in your browser (localStorage) and never leave your device unless you create an account. Two things are still reported anonymously so we can see which modes people enjoy and how hard the cases land: finishing one of the quick teasers (the Contradiction, Interrogation, Redaction, Cross-Examination or Frame-Up) records that it was played and whether it was solved, and finishing a daily case records its date, difficulty, how long it took and how many hints were used. Neither record carries an account, a device identifier, or anything that could be traced back to you.
With an account: your email address, an optional display name, a securely hashed password (or your verified account details if you sign in with Google or Apple), and your puzzle results (solve times, hints used, streaks). If you arrived through a tagged campaign or a recognized referral category, we also keep that bounded first-touch source and campaign on the account. We do not retain a full referring URL, its path/query, search terms, or an advertising click identifier.
Purchases: web payments are processed by Stripe, and in-app purchases by Apple or Google via RevenueCat. We never see or store your card number. We do store the product or plan, entitlement status and dates, and the provider application, store, environment, customer, subscription chain, transaction, or payment identifiers and provider event dates needed to grant access and handle renewals, restores, refunds, disputes, transfers, and support. For a Case Pack bought outright, that includes the pack, purchase source, grant or revocation dates, and its Stripe payment identifier. Access to packs included with Pro is calculated from your membership and does not create a separate purchase. In the durable RevenueCat transfer-history ledger, account aliases are stored only as SHA-256 digests (not as raw aliases) together with the app, store, environment, event date, and whether a local destination is linked, was never linked, or was erased. We also keep authoritative state for each store transaction. Its durable key is a namespaced SHA-256 digest; the raw provider transaction identifier and local owner link are cleared when that account is deleted. Pending webhook aliases may remain temporarily in a bounded retry payload, while its lookup index stores only SHA-256 digests (including anonymous RevenueCat aliases). Digests are not included in account exports.
Second Chair: if you sponsor or accept a household seat, we store the relationship, an outstanding invite code and its expiry, join and removal dates, and the sponsor's swap-window status. Each person can see the other's display name (or email local-part when no name is set), initials, rank, current streak, and total cases solved. We do not show either person the other's full email address, billing details, puzzle grids, or individual solve history.
Bug reports: if you send one, we receive the description you write plus basic device context (app version, platform, OS version, device model) so we can reproduce the problem.
Cancellation feedback: after opening your store or billing management, you may optionally tell us whether you plan to cancel now or turn off auto-renew, choose a reason, and add a comment. We store that intent, reason, comment, and a server-recorded snapshot of the billing source, plan, and whether the account was in a trial. Skipping the question stores nothing, and a response does not itself cancel or change a subscription.
Optional product research: if you answer or dismiss one of our short prompts, we store the prompt moment and whether it was answered or dismissed. An answer also stores your selected choice, any detail you choose to write, and limited game context such as platform, app version, mode, difficulty, or the closed-set screen that opened a paywall. Positioning tests also store which exact statements you saw, their order, and which you preferred. We never copy an email, IP address, referring URL, advertising identifier, or payment-provider identifier into a research response. When you are signed in, the response is linked to your account and receives server-derived snapshots of account age, tier, bounded acquisition category, and test/internal status. When you are not signed in, it has no account or network identifier and is retained for no more than 12 months. Interview consent is a separate, unchecked choice available only while signed in; checking it records the time you volunteered and lets authorized Verdict staff use the email already on your account for one optional research invitation. The prompt does not itself send an email or share information with an outside service. You can withdraw that consent at any time in Settings or through DELETE /api/v1/product-research/consent.
Notifications: if you opt into reminders, we store a push token so we can send them. Turning reminders off deletes the token.
Promotional email: this is off when an account is created unless you explicitly tick the optional signup choice. You can change it later without changing daily case reminders, and every promotional message has its own unsubscribe link.
Email delivery: to detect permanent bounces, stop repeatedly sending to unreachable addresses, and monitor sender health, we keep the message category, delivery event type, provider event time, provider message/event identifiers, and a keyed one-way digest of the recipient address. We do not keep the address, subject, body, raw webhook payload, bounce message, or SMTP diagnostic in this local delivery history. A random delivery identifier links each user-addressed message to your account, including verification sent to a pending new address and the security notice sent to a former address. Your export includes only categories, statuses, and timestamps, never recipient digests or provider identifiers. Account deletion removes the owned facts and suppression provenance transactionally. We retain only an account- and address-free late-webhook fence (random delivery id plus expiry) for 31 days so a delayed signed provider event cannot recreate erased delivery data.
Analytics: we use self-hosted, cookie-free analytics (Umami) with no advertising identifiers and no cross-site tracking. Analytics events are not tied to your name or account by us, but they are not fully anonymous: an event can carry coarse attributes such as platform, device class, subscription tier, app version, and a closed-set acquisition source and campaign category. Our analytics server derives an approximate region and city from the request IP and does not store the IP address itself. Separately, to stop abuse of sign-in, signup and password reset, we hold the requesting IP address (and, where the request names one, the email address) in a short-lived rate-limiting record. Those records exist only to count recent attempts and are not used to build a profile. If you create an account, that first-touch category is linked to the account so we can compare signups and purchases by channel; it is included in your data export and removed from the account and its conversion records when you delete it. If you are signed in, finishing a teaser is also recorded against your account, in the same way your daily puzzle results are, so the totals stay accurate. Crash reports (Sentry) include stack traces and device context, not your puzzle data.
What we never do
No selling or renting data. No ads or ad networks. No data brokers. No social-media tracking pixels. We don't access your contacts or photos, request precise location, or use device location services. The only location-related information we use is the approximate region and city derived for analytics as described above. We don't collect anything else the game doesn't need.
Where your data lives
On servers we operate in the United States (Hetzner, Hillsboro, Oregon). If you use Verdict from outside the US, your data is processed and stored in the US. Email (account, security and reminder mail) is delivered via Resend. Web payments via Stripe; in-app purchases are brokered by RevenueCat (with Apple or Google as the store of record). Crash and diagnostic reports go to Sentry. Push notifications are delivered via Expo's push service. Encrypted nightly database backups are stored with Backblaze B2. If you sign in with Google or Apple, that provider verifies your identity to us. That's the full list of processors.
Deleting & exporting your data
Settings → Delete account immediately removes your account, results, streaks, push tokens, sessions, pending tokens, optional cancellation feedback, account-linked product-research responses, keyed email-delivery history and bounce suppression, Case Pack entitlements, and purchase links from our live account data, and asks our payment processors to delete your customer records. It also ends your Second Chair relationship: deleting a sponsor ends the sponsored access, while deleting a seat holder empties that chair and removes their account link. The sponsor's empty-chair and swap-window dates remain with the sponsor's account, without the former holder's identifier. Deleting Verdict does not cancel an App Store or Google Play subscription; you must also cancel it in your store account.
A few things persist briefly or by legal necessity: anonymized bug reports; provider transaction records kept for tax, accounting, refunds, and disputes; a de-identified native currency payment ledger whose account, cohort, acquisition, store, SKU, plan, and exact-time links are removed, but whose pseudonymous SHA-256 digests remain solely to deduplicate provider retries and reconcile partial refunds, reversals, and disputes for the applicable financial retention period (the digests are not anonymous and contain no raw provider id); encrypted provider-deletion tasks or detached payment/session identifiers while an already-required deletion, cancellation, expiry, or refund is still retrying; error logs that expire within 90 days; and encrypted backups that expire within 30 days. Completed provider tasks retain only a minimal completion record, and aggregate analytics are detached from your account. Full detail: verdictpuzzle.com/account-deletion. You can export everything we hold about you as JSON first (GET /api/v1/me/export), or email us (below) for deletion or a copy of your data. We respond within 30 days.
Children
Verdict is not directed at children under 13, and we don't knowingly collect personal information from them.
Changes & contact
If this policy changes materially, we'll note it in the app. Questions or requests: hello@endpaperlabs.com.