Nobs Privacy Policy
At a glance
- You can play solo as a guest without an account. Gameplay does not go through Nobs’ game server. Where the law allows, the app collects limited usage and crash data by default under a random installation ID, and you can turn it off at any time in Settings → Privacy choices. Where the law requires your consent first, the app asks once and collects nothing until you say yes. Known under-13 states and local-development builds are always excluded. Your device and app store may separately handle installation, diagnostics, reviews, or backups under their own policies.
- Social and cloud features are for players age 13 or older. Apple or Google may tell the app whether you meet that rule. Otherwise, you confirm your age when you create your account. Nobs never collects a birth date and does not keep the age range.
- If you link an account, we use sign-in, profile, friend, game, and cloud-save data to provide the features you choose.
- Apple, Google, Firebase, Railway, Cloudflare Email Routing, Google’s Gmail service, and PostHog help run Nobs. The Amazon Web Services integration exists but is currently disabled in production and receives no Nobs data. Some providers handle data for Nobs; others also use data under their own privacy notices.
- Nobs Pro is billed by Apple or Google. Nobs receives proof of purchase—transaction identifiers and signed store notifications—to grant and maintain the entitlement; Nobs never sees your full payment-card or bank-account details.
- We do not show ads, sell or rent personal data, use behavioral-advertising software, or send promotional push notifications. When client telemetry is on, PostHog receives a random installation identifier and a limited event list for app opens, game starts, completions or abandonments, review opportunities, and scrubbed crashes. It never receives your Nobs account ID, username, room or game ID, cards, individual moves, free text, advertising ID, push token, or precise or coarse location from Nobs client telemetry.
- Authorized reviewers handle reports. Automated checks can reject a username or mark a safety report as urgent, but report count alone never decides enforcement.
- Your rights depend on where you live and why we use the data. Start a privacy request at https://www.nobscribbage.com/support or support@nobscribbage.com.
Who is responsible and what this policy covers
Kyle McGahey, an individual trading as Nobs Cribbage (“Nobs,” “we,” or “us”), is responsible for the processing described in this policy. Our address is 504 Beacon Street, Boston, Massachusetts 02115, USA. Email privacy or support questions to support@nobscribbage.com. Under data-protection law, this usually makes Kyle McGahey the controller.
This policy covers the Nobs mobile game, its social and cloud service, public legal and report pages, support, and administrative tools used to operate them. Apple, Google, app stores, device makers, networks, and email providers may separately control some processing and explain it in their own notices.
The current assessment is that Nobs does not require a data protection officer, subject to rechecking if the scale or features materially change.
On your device
A local guest uses a random guest ID. The device stores solo game state and actions, progress, statistics, grades, achievements, Coach usage, preferences, caches, local review-opportunity timestamps, and your usage-and-diagnostics preference. For a linked account, the device can also hold pending Coach claims and cached game reviews for offline use. The app can keep a small record of the most recent app crash—time, source, error name, a shortened message, and up to eight stack lines.
When client telemetry is on, PostHog’s local queue stores a separate random installation identifier, session identifier, and allowlisted events until batched delivery. Turning the choice off stops collection, clears queued client telemetry, and resets that identity. Gameplay never waits for delivery and remains playable offline. Android cloud backup is disabled for the app; a device-to-device transfer may still copy on-device data depending on the device. On iOS, on-device data follows your Apple device-backup settings.
Age check
Apple or Google may briefly share an age range with the app. Nobs turns it into eligible, ineligible, or unknown, then discards the range. If no clear result is available, creating an account is your own confirmation that you meet the 13+ rule; no birth date is ever entered or collected.
If you qualify and continue, we keep the check source—the platform signal or your own confirmation—the time, and the 13+ rule version. If you do not qualify during initial setup, we keep only a retry date on the device. For an established linked account, a failed recheck suspends social access on the server and records a dated age-ineligibility event.
Sign-in, profile, and legal records
Sign in with Apple or Google uses Firebase. Depending on the provider and configuration, Firebase or Google may receive or store a provider identifier, sign-in credential, Firebase user ID, authentication times, email, display name, profile image, device or installation identifiers, and diagnostic or service data. Other players see only your Nobs username and preset avatar. Nobs never receives your provider password.
Apple sign-in asks for email permission, which may return an Apple private-relay address. Firebase may retain that provider email to authenticate the account and detect when Apple and Google credentials use the same address. Nobs does not copy the provider email into its game database or show it to other players. The app may show the signed-in provider address back to you on your own device to help you recognize and switch an empty or unintended provider account. When an Apple user deletes a Nobs account, the app obtains a fresh authorization code, uses it to revoke Nobs access, and does not store the code.
Nobs stores your username and username history, preset avatar, account status and warnings, age-check record, and the version, source, displayed language, time, and idempotency record for Terms, Privacy Policy, and Community Standards acceptance or acknowledgement.
Friends, games, and cloud data
Nobs stores searches and limited public profiles, friendships, blocks, invitations, challenges, presence and room state, complete online-game actions and results, scores, statistics, achievements, linked solo games and analysis, cloud snapshots, revisions, progress, preferences, Coach allowance claims, and integrity metadata.
Friend-invite links contain a random bearer token. The intended recipient and hosting or browser logs may see the URL. A stable app-generated installation source can become part of uploaded game identifiers after an account is linked.
Other players receive only the profile, friend or challenge state, live game state, and shared results needed for the interaction.
Purchases and Nobs Pro
Apple or Google handles Nobs Pro billing, payment methods, and receipts under its own terms and privacy notice; Nobs never receives your payment card or bank details. To grant and maintain the entitlement, Nobs receives and stores proof of purchase: the store product and plan, a signed store transaction record or purchase token, the original transaction identifier, the store environment and signing time, the entitlement’s status and any expiry or revocation, signed store server notifications about the entitlement’s lifecycle, and a change history for the entitlement.
Nobs uses these records to deliver what you bought, restore purchases, prevent fraud and abuse, handle refunds and disputes, and keep required accounting records. Purchase records are kept for the life of the entitlement; raw store notifications are pruned twenty-four months after they are processed. Deleting a Nobs account deletes its entitlement record and replaces the account ID in the retained change history with a random history ID; it does not cancel an active store subscription or remove a one-time purchase or other store record, and restoring purchases from the same store account can grant the entitlement again.
Notifications and client telemetry
For notifications, Nobs stores a Firebase notification token linked to your account, platform, selected delivery language, and preferences. Firebase also uses an installation identifier. A payload can contain a username, score, challenge or game ID, turn or forfeit state, or moderation action. It may appear on a lock screen.
Nobs currently sends service notifications, not promotional notifications. Your in-app category choices are enforced before delivery, and device settings can stop all delivery.
When client telemetry is on, the app sends allowlisted lifecycle, gameplay, review-opportunity, review-request-call, and scrubbed crash events directly to PostHog in batches. Event properties are limited to app/build/platform and beta status, game mode and bot, outcome and scores, duration, hands played, abandonment stage/reason, and a session identifier. Screen, touch, text, console, replay, performance, profiling, advertising, feature-flag, push-token, and location capture are disabled.
Whether telemetry starts on by default or only after you choose to share depends on the region and language set on your device. It starts on by default, with an off switch in Settings → Privacy choices, in the United States, the United Kingdom, Canada (except on devices set to French), and other regions without a prior-consent rule. It stays off until you choose to share in the European Economic Area, Switzerland, Brazil, Türkiye, on devices set to French in Canada, and whenever the device region cannot be determined; there the app asks once and never sends anything before you say yes. Nobs reads only the device’s own region and language settings for this and never looks up your location.
The random client-telemetry installation identifier is not joined to your Nobs account. A native review-request call means only that the app called the platform API; Apple and Google do not tell Nobs whether a prompt appeared or a rating or review resulted, and TestFlight suppresses StoreKit review prompts.
Reports, moderation, and support
An in-app report can contain reporter and subject account IDs, the reported username version, a reason, an optional note, case state, actions, appeal, and audit events. A public report also requires a contact email and can contain a target username or link and optional note.
Authorized reviewers and operators can see report and case data. We normally keep a reporter’s identity from the reported player, but may disclose limited information when law, safety, an investigation, or fair redress requires it. Report text can reveal sensitive information or allegations. Include only necessary facts, not passwords, identity documents, financial information, or unnecessary health, child, criminal, or third-party details.
Tapping Support opens your mail app. If you send a message, Nobs and the email providers involved receive the address, message, attachments, and delivery information you choose to send.
Website, security, logs, and administration
Public pages and APIs may process IP address, browser or device information, route, selected language, request time and status, rate-limit counters, authentication and security events, and application errors. Operational logs may contain account, room, game, invite, or case identifiers. PostHog server exception reporting is currently disabled. If Nobs activates it after a new review, privacy-scrubbed exceptions may contain error type and stack, service source, environment, and build—not request bodies, headers, account IDs, or free text.
Authorized operators can access account, age, legal, social, game, push-device, moderation, support, and operational records where needed. Nobs public pages use no Nobs advertising or behavioral-analytics cookies or SDKs.
Why we use data and our legal bases
Nobs records a purpose and legal basis for each processing activity below.
- Requested account, sign-in, cloud save, social and online play, service messages, deletion, and support: performance of the requested service or contract (GDPR Article 6(1)(b)), with legitimate interests where a request is not contractual.
- Nobs Pro entitlement delivery, restore, and refund or dispute handling: performance of the purchase contract (Article 6(1)(b)); required accounting and tax records: legal obligation (Article 6(1)(c)); fraud and abuse prevention: legitimate interests (Article 6(1)(f)).
- Age assurance and enforcing the social minimum age: legitimate interests in age-appropriate operation (Article 6(1)(f)); legal obligation (Article 6(1)(c)) only where a specific law requires it.
- Security, fraud and abuse prevention, rate limits, reliability, and operational logs: legitimate interests (Article 6(1)(f)).
- Client product analytics and crash diagnostics: legitimate interests in improving and stabilizing the game (Article 6(1)(f)) where collection starts by default, with an objection available at any time in Settings → Privacy choices; your consent (Article 6(1)(a)) where the app asks first. You can object or withdraw at any time without affecting earlier processing.
- Username screening, reports, human moderation, safety evidence, and legal claims: legitimate interests (Article 6(1)(f)), legal obligation where applicable (Article 6(1)(c)), and the establishment, exercise, or defense of claims.
- Shared results retained for opponents and integrity or disputes: legitimate interests (Article 6(1)(f)), under the documented necessity limits and with no fixed automatic deletion date in the current retention schedule.
- Valid legal requests and applicable privacy rights: legal obligation (Article 6(1)(c)) and legal claims where applicable.
Who receives data
Other players receive the limited profile, social, game, and result data needed for their interactions. Authorized Nobs operators and professional advisers receive what they need for support, moderation, security, legal compliance, and operations.
Google and Firebase provide sign-in and notification delivery. Google also handles Google Account, Google Sign-In, Play Age Signals, Play Store, Play billing, platform, security, and service data under its own notices. Firebase Authentication uses US infrastructure and Firebase Cloud Messaging uses global infrastructure.
Apple provides Sign in with Apple, Declared Age Range, notification delivery, and App Store and billing services and separately controls Apple Account and platform processing.
Railway hosts the server, database, edge, and logs. Cloudflare Email Routing forwards support mail to the owner’s consumer Gmail mailbox, so Cloudflare and Google receive the message and delivery data. PostHog receives client telemetry as described in this policy, with person profiles, geolocation, autocapture, replay, profiling, and remote feature flags disabled. PostHog server exception reporting and the Amazon SES moderation-email integration are currently disabled in production and receive no Nobs data.
When a provider processes personal data for Nobs, we require the provider by contract or other binding terms to give it the same or equivalent protection described in this policy. Providers that independently control their own services also apply their own privacy notices.
Courts, regulators, law enforcement, professional advisers, or a transaction successor may receive limited data where lawfully required or reasonably necessary with appropriate safeguards.
International processing
Nobs is based in the United States. Current providers may process data in the United States and other countries. Firebase Authentication is US-based; notification and Apple or Google platform services can use global infrastructure; Railway uses a selected US service region plus a global edge; Cloudflare Email Routing uses global infrastructure and forwards support mail to Google’s Gmail service.
Nobs records the applicable transfer mechanism for each provider—an adequacy decision, Data Privacy Framework participation, Standard Contractual Clauses, the UK Addendum, or another lawful mechanism—in its internal vendor register.
How long we keep data
We keep data only as long as reasonably necessary for its purpose, then delete or de-identify it unless a documented legal hold or legal duty requires longer.
- Guest identity and owner-scoped game/account data: until successful guest reset, app-data clearing or uninstall, or applicable device backup expiry. The device-wide review-opportunity ledger holds at most two timestamps. Entries older than 365 days are ignored for prompt decisions and removed on the next successful ledger write; without a later write, they can remain until app-data clearing or uninstall. Guest reset does not clear the ledger. The latest crash record remains until the next recorded crash, app-data clearing or uninstall; guest reset does not clear it.
- Account, profile, social, private cloud-solo, Coach allowance, progress, snapshot, and preference data: while the account is active, then through the deletion workflow. A justified inactivity rule has not yet been adopted.
- Age-check proof, username history, shared games, and retained opponent results: for the account’s lifetime. After deletion, the retained shared records survive only in pseudonymous form and currently have no fixed automatic deletion date because they preserve opponent history, game integrity, safety enforcement, and disputes.
- Notification tokens: until invalidated, unregistered, or account deletion. Undelivered messages may remain with Firebase or Apple under their delivery settings, potentially up to about four weeks or 30 days unless a shorter expiry is configured.
- PostHog client product and mobile error events: turning the choice off clears the device queue and resets the client-telemetry identity; already received events follow PostHog’s retention or an applicable deletion procedure. PostHog’s current free plan provides at least 12 months of retention and no configurable deletion ceiling.
- Daily imported Apple analytics and review/TestFlight aggregate metadata: 24 months. Apple’s threshold-suppressed usage values are stored as unavailable, never zero.
- Open or appealed moderation cases: until closure. Closed case, report, public-contact, and moderation-event records are pruned after the applicable 24-month boundary.
- Nobs Pro entitlement records: for the life of the entitlement and any required accounting period. Raw signed store notifications are pruned twenty-four months after they are processed. Apple and Google keep their own purchase records under their own policies.
- Support email: no fixed automatic retention period is currently configured. The owner deletes it manually when it is no longer needed or on request, subject to security, legal, and rights-request exceptions.
- Railway server logs: seven days. The current Railway plan has no volume backups or point-in-time recovery. Deletion-job records remain while needed to complete or document deletion; no separate automatic expiry is currently configured.
- Firebase states that user deletion from live and backup systems may take up to 180 days and that some authentication IP records may remain for a few weeks, subject to the current accepted terms.
Account deletion and shared records
Use Settings > Delete account or https://www.nobscribbage.com/delete-account. Provider sign-in is required again. The self-service route works for ready and suspended linked accounts. If incomplete legal or profile setup prevents you from reaching it, ask for help at support@nobscribbage.com and we will complete the deletion.
Deletion disables the profile, can forfeit an active game, cancels pending social state, deletes or tombstones private app data, and queues Firebase user deletion. A fresh Apple authorization code is used for revocation and is not stored.
The Firebase Installation ID used by messaging follows a separate Firebase and device lifecycle; the current account-deletion workflow does not call the Firebase Installations deletion API, and that identifier expires under Firebase’s own lifecycle.
Finished shared games and limited moderation records may remain without a fixed automatic deletion date because deleting one player must not corrupt an opponent’s history, game integrity, safety work, or disputes. Nobs replaces the direct account ID in retained app records with a random history ID. Those records are unlinked rather than anonymous: they remain pseudonymous and may still be linked indirectly. Legal acceptance rows currently delete with the original account rather than being rewritten.
Firebase may temporarily retain original sign-in identifiers in its provider backup systems during its deletion window. The current Railway plan has no database backups or point-in-time recovery. Deleting a linked account does not remove separate local guest data or data Apple or Google controls for its own services.
Your rights and complaints
Your rights depend on where you live and why we use the data. Depending on those circumstances, you may ask for access or a copy, correction, deletion, restriction, portability of data you provided, or object to legitimate-interest processing. Client telemetry can be turned off at any time in Settings → Privacy choices, whether it started by default or after you chose to share; turning it off does not affect earlier processing.
Send a request to support@nobscribbage.com or use https://www.nobscribbage.com/support. We may reasonably verify identity, protect other players and reporters, redact third-party data, and apply legal exceptions. Where GDPR applies, we will respond without undue delay and within one month, subject to any permitted extension with notice.
Nobs cannot retrieve ordinary device-only guest data; use the guest reset or device controls. If dissatisfied, contact us or the data-protection authority where you live or work or where you believe an infringement occurred. UK users may contact the ICO.
Children and age review
Solo play does not require an account and can stay on the device. Any known under-13 state forces client telemetry off. Nobs does not allow anyone under 13 to create or use a social or cloud account. Nobs has no parental-consent account flow.
If a check says you do not meet the rule, social access is blocked and a retry date is stored locally. For an established linked account, a failed recheck also suspends the account on the server and records an audit entry. Ask for human review at support@nobscribbage.com. A parent or guardian may contact the same address, including to ask that a child’s account or data be deleted.
Automated checks and human review
The age result decides whether social setup can continue. An automated check can reject a username. A report reason can give a safety case an earlier review deadline. Game rules compute game results.
People—not report count alone—decide warnings, renames, suspensions, and bans. You can ask for age or moderation review through support. No Nobs automated check makes a legal or similarly significant decision about you on its own.
Security
We use measures designed for this service, including HTTPS for app and API traffic, Firebase sign-in, server authorization and access controls, limited operator access, data minimization, preset avatars instead of uploads, rate limits, logs, and deletion workflows.
Nobs maintains internal records of provider security controls and a breach-response runbook. No system is perfectly secure. Report a suspected issue to support@nobscribbage.com.
Changes, language, and contact
We may update this policy as the service or law changes. We will identify the version and date and give proportionate, conspicuous notice of material changes in the app before they take effect. This policy is a notice rather than a contract; if a new use of personal data requires consent, it will receive a separate choice rather than being bundled into Terms acceptance.
Nobs legal documents are provided in English, and the English version is the operative text. Courtesy translations, if ever offered, do not change the English version’s meaning.
Contact Kyle McGahey, trading as Nobs Cribbage, at 504 Beacon Street, Boston, Massachusetts 02115, USA, or support@nobscribbage.com.