Privacy Policy
This policy explains how Mahj Call handles information when you use the app with or without an account, learn, practise or play American Mahjong, play the Daily Mahj Puzzles, use social or referral features, send us feedback, or ask for support.
Information we collect
- Account information: email address (or the private relay address Apple provides when you use Sign in with Apple), your name if you choose to share it through Sign in with Apple, Supabase account identifier, authentication and session records.
- Profile information: username, display name, referral code, and profile choices you provide.
- Learning and game progress: completed lessons, achievements, the days you have played, practice-hand counts, confirmed wins and score totals, charms, and owned or equipped tile sets. Daily Mahj Puzzle results and statistics are kept on your device rather than in your synced progress; only the fact that you played on a given day is saved to your account. Puzzle scores are also part of the app usage information described below.
- App usage information: an identifier for your installation of the app (Apple's identifier for vendor where available, otherwise a random one), the app version, and records of what you do in the app: screens and onboarding steps viewed, your answers to onboarding questions, lessons started and finished, games started, finished or left and how they ended, Daily Mahj Puzzle scores, and membership-screen views and purchase steps. These records are made whether or not you have an account, and are linked to your account once you sign in. They never include anything you type.
- Feedback you send: your ratings, the options you choose, and any note you write when the app asks how a game went, how your first game felt, or what held you back from joining, or when you use Send Feedback. Feedback is stored with the app version, your installation identifier, your account if you are signed in, and the context of the question, such as how many games you have played, whether you are a member, and how the game ended. So that we can answer you in the app's Messages without an account, each note also carries a one-way fingerprint (a hash) of a random key kept on your device; only that device, or your account if you are signed in, can read the replies addressed to it. If you choose to give an email address with a note, it is stored with that note and used only to reply to it. Our replies, your answers to them, and whether a message has been opened on your device are stored with your feedback.
- Notification token: if you have allowed Mahj Call to send notifications, a push token for your device, stored with the same fingerprint, so we can let you know when we have replied to you in Messages. It is used only for those replies, never for marketing.
- Online table and gameplay information: table settings and membership, seat assignments, readiness, game commands and public table events, reconnect records, hand outcomes, and records used to deliver an interrupted game or an earned result exactly once.
- Referral activity: which referral code was redeemed, referral relationships, qualification status, and reward records.
- Subscription information: App Store product, purchase, renewal, trial, expiration, and entitlement status associated with your Mahj Call account.
- Advertising measurement information: app launches, onboarding progress, completing sign-up and how you signed up, finishing the guided first game, membership-screen views, plan selections, purchase attempts and outcomes, confirmed trial or purchase product identifiers and amounts, limited device identifiers, and account email and name used to measure which Meta ads introduced a player. The advertising identifier and Advanced Matching data are enabled only when the player authorizes App Tracking Transparency; the Meta SDK hashes email and name for matching.
- Safety information: blocks, reports, the reported account or table, a selected reason, optional details you provide, and records used to investigate abuse and prevent unwanted matching.
- Service and security data: timestamps, request and error logs, and limited technical information needed to operate and protect the service.
- Support communications: information you choose to include when contacting support.
How we use information
We use this information to authenticate accounts, preserve and synchronize progress, understand how the app is used and where players get stuck, read feedback and reply to it in the app's Messages, at an email address you give us with a note, or, when you are signed in, at your account email, show messages we write to all players or to players on a particular app version (for example, to say an update is ready), operate private tables and Quick Match, restore interrupted games, deliver results, store referral activity, respond to support requests, prevent and investigate abuse, diagnose failures, measure which of our Meta advertisements lead to app use, trials, or purchases, and comply with applicable obligations. Referral rewards are not currently paid; if a server-verified reward program is enabled later, this policy will cover the records used to administer it.
What other players can see
People at the same online table can see the display name and handle associated with your profile, the table name and settings, your seat and readiness, and public gameplay information such as discards, exposed sets, passes, calls, and hand outcomes. Concealed racks are shown only to their owning player.
Service providers and disclosure
Mahj Call uses Supabase to provide authentication, database, and server-function infrastructure (including storage of the app usage information and feedback described above), RevenueCat to validate App Store purchases and maintain subscription entitlements, and the Meta App Events SDK to measure the performance of Mahj Call advertisements. Reply notifications are delivered through Apple's Push Notification service, and the app asks Apple's public App Store listing whether a newer version is ready; that check sends nothing about you. These providers process information on our behalf to operate those services. We require service providers that process personal information on our behalf to use it only for the contracted services and to maintain the same or equivalent protection described in this policy. We may disclose information when required by law, to protect users or the service, or as part of a service transition with appropriate safeguards.
After you authorize App Tracking Transparency, Mahj Call may provide your normalized account email and name to the Meta SDK for Advanced Matching; the SDK hashes those values for matching. Mahj Call does not provide Meta with your user ID, username, referral or invitation details, messages, concealed rack, or gameplay activity, other than the fact that you finished the guided first game. We do not sell personal information or display third-party ads in the app. The Meta SDK is used only to measure and improve advertisements for Mahj Call. Access to the advertising identifier, Advanced Matching, and cross-app tracking is enabled only if you authorize App Tracking Transparency.
Retention and security
Account and progress information is kept while your account is active. Online table delivery records, reconnect records, invites, matchmaking tickets, and completed-game operational records are kept only for bounded service and recovery periods. When an account is deleted, open online play is ended safely and associated information is removed or de-identified, except where limited retention is reasonably necessary for security, abuse investigations, fraud prevention, dispute resolution, or legal compliance. App usage records and feedback, including our replies, are kept while they help us improve Mahj Call, and a notification token is deleted once Apple reports it is no longer valid; when an account is deleted, the link between those records and the account is removed. Operational logs and backups may remain for limited service-security periods. We use access controls, encrypted network transport, row-level database security, restricted server credentials, and seat-specific gameplay projections, but no system can guarantee absolute security.
Your choices
- You may edit supported profile information in the app.
- You may reset data stored locally on your device from Settings.
- You may decline App Tracking Transparency without losing app functionality, and you may change that permission later in iOS Settings.
- You may block another player and submit a safety report from supported online-table player details. Blocking prevents future Quick Match pairing with that account.
- You may initiate permanent account deletion from Profile → Settings → Delete Account. Deleting the account ends open online play and removes the authentication account and associated profile, progress, table membership, referral, and reward records, subject to the limited retention above.
- If deletion cannot be completed in the app, contact mahjcallapp@gmail.com.
Changes to this policy
We may update this policy as Mahj Call changes. The effective date above identifies the current version. Material changes will be communicated through an appropriate in-app or service notice.