Nobs Privacy Policy
Pre-launch draft — pending qualified legal review. Not approved for launch.
At a glance
- You can play solo as a guest without an account. That play stays on your device and does not contact Nobs’ game server, register for push notifications, or send Nobs analytics or review events. Your device and app store may still handle installation, permissions, diagnostics, reviews, or backups under their own policies.
- Social and cloud features are for players age 13 or older. Apple or Google may tell the app whether you meet that rule. Otherwise, you confirm your age when you create your account. Nobs never collects a birth date and does not keep the age range.
- If you link an account, we use sign-in, profile, friend, game, and cloud-save data to provide the features you choose.
- Apple, Google, Firebase, Railway, Amazon Web Services, and email providers help run Nobs. Some handle data for Nobs; others also use data under their own privacy notices.
- We do not currently show ads, sell or rent personal data, use behavioral-advertising software, or send promotional push notifications. We keep limited daily counts of store-review opportunities that are not tied to an account or device.
- Authorized reviewers handle reports. Automated checks can reject a username or mark a safety report as urgent, but report count alone never decides enforcement.
- Your rights depend on where you live and why we use the data. Start a privacy request at https://www.nobscribbage.com/support or support@nobscribbage.com.
Who is responsible and what this policy covers
Kyle McGahey, an individual trading as Nobs Cribbage (“Nobs,” “we,” or “us”), is responsible for the processing described in this policy. Our address is 504 Beacon Street, Boston, Massachusetts 02115, USA. Email privacy or support questions to support@nobscribbage.com. Under data-protection law, this usually makes Kyle McGahey the controller.
This policy covers the Nobs mobile game, its social and cloud service, public legal and report pages, support, and administrative tools used to operate them. Apple, Google, app stores, device makers, networks, and email providers may separately control some processing and explain it in their own notices.
Before intentional EEA or UK social availability, qualified counsel must confirm and publish any required EEA or UK representative. The current assessment is that Nobs does not require a DPO, subject to rechecking if the scale or features materially change.
On your device
A local guest uses a random guest ID. The device stores solo game state and actions, progress, statistics, grades, achievements, preferences, caches, and local review-opportunity timestamps. The app can also keep a small record of the most recent app crash—time, source, error name, a shortened message, and up to eight stack lines.
Ordinary guest play does not send that data to the Nobs game server. Android app backup is disabled. iOS and other platform backup behavior must be verified before launch.
Age check
Apple or Google may briefly share an age range with the app. Nobs turns it into eligible, ineligible, or unknown, then discards the range. If no clear result is available, creating an account is your own confirmation that you meet the 13+ rule; no birth date is ever entered or collected.
If you qualify and continue, we keep the check source—the platform signal or your own confirmation—the time, and the 13+ rule version. If you do not qualify during initial setup, we keep only a retry date on the device. For an established linked account, Nobs attempts to suspend social access and record a dated age-ineligibility event after a failed recheck. That server update is not yet reliable for every incomplete account and remains launch work.
Sign-in, profile, and legal records
Sign in with Apple or Google uses Firebase. Depending on the provider and configuration, Firebase or Google may receive or store a provider identifier, sign-in credential, Firebase user ID, authentication times, email, display name, profile image, device or installation identifiers, and diagnostic or service data. Other players see only your Nobs username and preset avatar. Nobs never receives your provider password.
Apple sign-in asks for email permission, which may return an Apple private-relay address. Firebase may retain that provider email to authenticate the account and detect when Apple and Google credentials use the same address. Nobs does not copy the provider email into its game database or show it to other players. The app may show the signed-in provider address back to you on your own device to help you recognize and switch an empty or unintended provider account. When an Apple user deletes a Nobs account, the app obtains a fresh authorization code, uses it to revoke Nobs access, and does not store the code.
Nobs stores your username and username history, preset avatar, account status and warnings, age-check record, and the version, source, displayed language, time, and idempotency record for Terms, Privacy Policy, and Community Standards acceptance or acknowledgement.
Friends, games, and cloud data
Nobs stores searches and limited public profiles, friendships, blocks, invitations, challenges, presence and room state, complete online-game actions and results, scores, statistics, achievements, linked solo games and analysis, cloud snapshots, revisions, progress, preferences, and integrity metadata.
Friend-invite links contain a random bearer token. The intended recipient and hosting or browser logs may see the URL. A stable app-generated installation source can become part of uploaded game identifiers after an account is linked.
Other players receive only the profile, friend or challenge state, live game state, and shared results needed for the interaction.
Notifications and review counts
For notifications, Nobs stores a Firebase notification token linked to your account, platform, selected delivery language, and preferences. Firebase also uses an installation identifier. A payload can contain a username, score, challenge or game ID, turn or forfeit state, or moderation action. It may appear on a lock screen.
Nobs currently sends service notifications, not promotional notifications. The existing in-app category choices are not relied upon as effective controls until server enforcement is completed under the launch backlog. Device settings can stop delivery.
We count a limited set of store-review opportunities by day. The count is not tied to an account, app installation, game, or browser. Our server may still briefly use an IP address to rate-limit or secure the request, and hosting logs may receive request data, so we call the result unlinked rather than anonymous.
Reports, moderation, and support
An in-app report can contain reporter and subject account IDs, the reported username version, a reason, an optional note, case state, actions, appeal, and audit events. A public report also requires a contact email and can contain a target username or link and optional note.
Authorized reviewers and operators can see report and case data. We normally keep a reporter’s identity from the reported player, but may disclose limited information when law, safety, an investigation, or fair redress requires it. Report text can reveal sensitive information or allegations. Include only necessary facts, not passwords, identity documents, financial information, or unnecessary health, child, criminal, or third-party details.
Tapping Support opens your mail app. If you send a message, Nobs and the email providers involved receive the address, message, attachments, and delivery information you choose to send.
Website, security, logs, and administration
Public pages and APIs may process IP address, browser or device information, route, selected language, request time and status, rate-limit counters, authentication and security events, and application errors. Logs can contain account, room, game, invite, or case identifiers.
Authorized operators can access account, age, legal, social, game, push-device, moderation, support, and operational records where needed. Nobs public pages use no Nobs advertising or behavioral-analytics cookies or SDKs.
Why we use data and candidate legal bases
This is a draft basis schedule. Qualified counsel must approve it, complete necessary legitimate-interest assessments with child-specific balancing, and resolve special-category and criminal-allegation data before launch.
- Requested account, sign-in, cloud save, social and online play, service messages, deletion, and support: performance of the requested service or contract (GDPR Article 6(1)(b)), with legitimate interests where a request is not contractual.
- Age assurance and enforcing the social minimum age: legitimate interests in age-appropriate operation (Article 6(1)(f)); legal obligation (Article 6(1)(c)) only where a specific law requires it.
- Security, fraud and abuse prevention, rate limits, reliability, and operational logs: legitimate interests (Article 6(1)(f)).
- Username screening, reports, human moderation, safety evidence, and legal claims: legitimate interests (Article 6(1)(f)), legal obligation where applicable (Article 6(1)(c)), and the establishment, exercise, or defense of claims.
- Shared results retained for opponents, integrity, disputes, and unlinked review counts: legitimate interests (Article 6(1)(f)), subject to a documented purpose and finite retention rule.
- Valid legal requests and applicable privacy rights: legal obligation (Article 6(1)(c)) and legal claims where applicable.
Who receives data
Other players receive the limited profile, social, game, and result data needed for their interactions. Authorized Nobs operators and professional advisers receive what they need for support, moderation, security, legal compliance, and operations.
Google and Firebase provide sign-in and notification delivery. Google also handles Google Account, Google Sign-In, Play Age Signals, Play Store, platform, security, and service data under its own notices. Firebase Authentication uses US infrastructure and Firebase Cloud Messaging uses global infrastructure.
Apple provides Sign in with Apple, Declared Age Range, notification delivery, and App Store services and separately controls Apple Account and platform processing.
Railway hosts the server, database, edge, and logs. Amazon Web Services SES sends moderation and case-status email. The support mailbox provider also receives support email. The actual contracts, mailbox provider, service regions, subprocessors, and role classification must be verified before launch.
Courts, regulators, law enforcement, professional advisers, or a transaction successor may receive limited data where lawfully required or reasonably necessary with appropriate safeguards.
International processing
Nobs is based in the United States. Current providers may process data in the United States and other countries. Firebase Authentication is US-based; notification and Apple or Google platform services can use global infrastructure; Railway uses a selected service region plus a global edge; email processing depends on the configured SES and mailbox regions.
Before worldwide social launch, Nobs must verify the actual regions and contracts and document the applicable adequacy decision, Data Privacy Framework participation, Standard Contractual Clauses, UK Addendum, or other lawful transfer mechanism.
How long we keep data
We keep data only as long as reasonably necessary for its purpose, then delete or de-identify it unless a documented legal hold or legal duty requires longer. Several launch periods below still require verification and implementation.
- Guest identity and owner-scoped game/account data: until successful guest reset, app-data clearing or uninstall, or applicable device backup expiry. The device-wide review-opportunity ledger holds at most two timestamps. Entries older than 365 days are ignored for prompt decisions and removed on the next successful ledger write; without a later write, they can remain until app-data clearing or uninstall. Guest reset does not clear the ledger. The latest crash record remains until the next recorded crash, app-data clearing or uninstall; guest reset does not clear it.
- Account, profile, social, private cloud-solo, progress, snapshot, and preference data: while the account is active, then through the deletion workflow. A justified inactivity rule has not yet been adopted.
- Age-check proof, username history, shared games, and retained opponent results: until the finite launch schedule required by CB-352 is adopted and enforced.
- Notification tokens: until invalidated, unregistered, or account deletion. Undelivered messages may remain with Firebase or Apple under their delivery settings, potentially up to about four weeks or 30 days unless a shorter expiry is configured.
- Unlinked daily review counts: 24 months.
- Open or appealed moderation cases: until closure. Closed case, report, contact, and audit records are currently pruned up to 24 months after closure or last update; a shorter public-contact period remains a launch requirement.
- Support email, application and provider logs, Railway backups or point-in-time recovery, database backups, and deletion-job records: the verified finite periods required by CB-348 and CB-352 must be completed before launch.
- Firebase states that user deletion from live and backup systems may take up to 180 days and that some authentication IP records may remain for a few weeks, subject to the current accepted terms.
Account deletion and shared records
Use Settings > Delete account or https://www.nobscribbage.com/delete-account. Provider sign-in is required again. The current self-service route works for ready profiles; incomplete and restricted identity states remain a launch blocker and can request help at support@nobscribbage.com.
Deletion disables the profile, can forfeit an active game, cancels pending social state, deletes or tombstones private app data, and queues Firebase user deletion. A fresh Apple authorization code is used for revocation and is not stored.
The Firebase Installation ID used by messaging follows a separate Firebase and device lifecycle; the current account-deletion workflow does not call the Firebase Installations deletion API. CB-350 must resolve that lifecycle before this draft is approved.
Finished shared games and limited moderation records may remain for the final retention period because deleting one player must not corrupt an opponent’s history, game integrity, safety work, or disputes. Nobs replaces the direct account ID in retained app records with a random history ID, but those records remain pseudonymous and may still be linked indirectly. Legal acceptance rows currently delete with the original account rather than being rewritten.
Backups may temporarily contain original identifiers until their verified expiry. A restore must reapply deletion suppression. Deleting a linked account does not remove separate local guest data or data Apple or Google controls for its own services.
Your rights and complaints
Your rights depend on where you live and why we use the data. Depending on those circumstances, you may ask for access or a copy, correction, deletion, restriction, portability of data you provided, or object to legitimate-interest processing. You may withdraw consent where consent is actually used, without affecting earlier lawful processing.
Send a request to support@nobscribbage.com or use https://www.nobscribbage.com/support. We may reasonably verify identity, protect other players and reporters, redact third-party data, and apply legal exceptions. Where GDPR applies, we will respond without undue delay and within one month, subject to any permitted extension with notice.
Nobs cannot retrieve ordinary device-only guest data; use the guest reset or device controls. If dissatisfied, contact us or the data-protection authority where you live or work or where you believe an infringement occurred. UK users may contact the ICO.
Children and age review
Solo play does not require an account and can stay on the device. Nobs does not allow anyone under 13 to create or use a social or cloud account. Nobs has no parental-consent account flow.
If a check says you do not meet the rule, social access is blocked and a retry date is stored locally. For an established linked account, Nobs also attempts a server suspension and audit; that update is not yet reliable for every incomplete account. Ask for human review at support@nobscribbage.com. A parent or guardian may contact the same address.
Qualified counsel must approve the worldwide 13+ threshold, national contract and digital-consent rules, age-assurance proportionality, and applicable child-design obligations before launch.
Automated checks and human review
The age result decides whether social setup can continue. An automated check can reject a username. A report reason can give a safety case an earlier review deadline. Game rules compute game results.
People—not report count alone—decide warnings, renames, suspensions, and bans. You can ask for age or moderation review through support. Qualified counsel must confirm the final analysis of any legally significant automated decision and safeguards.
Security
We use measures designed for this service, including HTTPS for app and API traffic, Firebase sign-in, server authorization and access controls, limited operator access, data minimization, preset avatars instead of uploads, rate limits, logs, and deletion workflows.
Before launch, Nobs must verify and document database and backup encryption, MFA, least privilege, restore behavior, secret rotation, logging, breach response, and provider controls. No system is perfectly secure. Report a suspected issue to support@nobscribbage.com.
Changes, language, and contact
We may update this policy as the service or law changes. We will identify the version and date and give proportionate notice of material changes. If a new use requires consent, it will receive a separate choice rather than being bundled into Terms acceptance.
This first pass is available in English only. Qualified, legally reviewed French Canadian and Latin American Spanish versions are required before launch; users must be able to rely on the reviewed language shown to them.
Contact Kyle McGahey, trading as Nobs Cribbage, at 504 Beacon Street, Boston, Massachusetts 02115, USA, or support@nobscribbage.com.