Stop Slop

Privacy Policy

Effective date: TODO: owner to set publication date.

Who we are and how to contact us

Stop Slop is operated by Hichem Benzair. Our privacy contact is Hichem Benzair, Person responsible for the protection of personal information, reachable at [email protected]. This policy covers the Stop Slop app, these pages, and requests you send to us.

Information on your device

Stop Slop stores XP, streaks, scores, saved games, recent-question histories, Free play allowances, introductory access records, game preferences, and cached Premium status on your device. These records support gameplay, resuming games, content rotation, and access limits. Session identifiers are generated locally. Historical Figure records from earlier introductory access may remain saved; a current Premium entitlement is required to resume that standalone game.

There is no Stop Slop login or account-based gameplay backup or synchronization service. The app does not upload your answers, scores, or progress to a developer-operated gameplay server. Device backups may contain app data according to your device settings.

Party Tilt requests motion access when needed and processes device-motion readings locally to interpret game actions. Its on-screen Pass and Correct buttons are also available. Screen transitions can create temporary images of the app interface locally; these are not photos from your library and are not uploaded by the app.

Subscriptions, RevenueCat, and Apple

We use RevenueCat to validate purchases, retrieve subscription status, restore eligible purchases, and determine Premium access. It also provides subscription analytics. The subscription SDK initializes when the app starts, including for Free users; network requests are not limited to people who buy Premium.

The RevenueCat SDK generates an anonymous App User ID and associates it with subscription and transaction information. Stop Slop does not supply a custom account ID, name, or email to that SDK. An anonymous ID is still an identifier; it does not mean no personal information is processed.

Subscription requests include app and device context, such as app/build and SDK versions, operating system, device model, preferred locales, and storefront when available. The installed iOS SDK also sends Apple's identifier for vendor (IDFV) in a request header when available. Requests reach RevenueCat's servers, which receive network information needed to communicate with your device.

RevenueCat has confirmed, for Stop Slop's exact configuration, that this processing is Purchase History collected for app functionality and subscription analytics, is not linked to your identity, and is not used for tracking. RevenueCat generates the anonymous App User ID as a random identifier; it is cached on your device, and reinstalling the app creates a new one. Restoring purchases can associate more than one anonymous identifier with the same underlying RevenueCat record. RevenueCat has also confirmed that it does not store Apple's identifier for vendor (IDFV) as part of your subscriber record unless we explicitly instruct the SDK to collect it — we do not; the request header mentioned above is separate, transient request information, not something stored on your RevenueCat profile.

TODO: confirm RevenueCat's exact request/log retention period, and its subprocessors and processing countries, from RevenueCat's published Terms, Privacy Policy, Data Processing Addendum and Security & Compliance documentation, before publication.

Apple handles payment through the App Store. Stop Slop does not directly receive or store payment-card numbers or CVV. The app receives purchase/subscription status and product information through RevenueCat and Apple's purchase services. Apple's billing records follow Apple's applicable practices.

See Apple's Privacy Policy and RevenueCat's Privacy Policy. RevenueCat's app-user processing is also governed by its agreements with the app operator; its website privacy policy alone does not describe every aspect of that processing.

Minimization, analytics, and permissions

You do not need to provide a name, email, or telephone number to play. Stop Slop does not use an advertising SDK or a dedicated remote gameplay analytics or crash-reporting SDK. It does not implement advertising tracking or IDFA collection. No additional RevenueCat integrations are active in the release configuration.

The app does not request access to your contacts, camera, microphone, photo library, location, or notifications. Development builds log gameplay and motion events locally. Some local haptic error warnings may also occur outside development builds. There is no app-operated remote destination for those console logs.

Support and this website

If you contact support at [email protected], we receive your sender address and the information you choose to send, and use it to respond to your request. That mailbox is provided by Gmail; Google's handling of the message is subject to Google's own practices. Send only what is needed to explain the issue. Do not send passwords, card numbers, CVV, or unrelated personal information. Support correspondence is retained only as long as reasonably necessary to respond to your request, maintain appropriate support/compliance records, and satisfy applicable legal obligations; we do not keep it for a fixed, predetermined period.

These pages use no analytics scripts, advertising, forms, or application cookies. This website is hosted on Cloudflare Pages. Opening a page sends a request that Cloudflare, our hosting provider, processes to deliver, secure, and operate the site — this can include standard web request metadata such as your IP address, browser/request information, and security-related request metadata. This is a normal function of how any website is served over the internet, not an analytics or tracking feature added by Stop Slop. External links open the named provider's website and are subject to its own practices.

TODO: confirm Cloudflare's exact request-log retention period and processing locations from Cloudflare's own documentation, and resolve the RevenueCat vendor questions above, before publication.

Retention and deletion

Local records remain until they are changed, replaced, or cleared by the app's storage lifecycle, or app data is removed. Different records have different lifecycles; a daily allowance reset does not necessarily erase older stored bytes at midnight. Recent-question histories are bounded. There is no user-facing global erase/export control in this release.

Deleting the app and its data may remove local progress. Offloading the app is different from deleting its data, and backups or restored devices may retain records. Contact support before reinstalling as a troubleshooting step. Restoring purchases restores eligible subscription access, not local gameplay progress.

Removing app data does not cancel an Apple subscription or delete Apple or RevenueCat records. Use Apple's subscription settings to cancel. Contact our privacy contact to request help with provider-held information. We cannot retrieve local-only gameplay records remotely.

RevenueCat has confirmed it can delete your RevenueCat record, including purchase history, on request, and that doing so is sufficient to satisfy a data-erasure request for the information RevenueCat holds. Because Stop Slop does not use accounts, we do not automatically know which RevenueCat record is yours. To help us find and delete the correct one, Stop Slop provides a Privacy Request ID: an anonymous subscription/customer reference you can find on any Premium screen, near the Privacy Policy, Terms of Use and Support links. Tap Show ID to reveal it, then Copy ID to copy the full value. The app does not transmit this ID anywhere automatically — you choose whether and when to share it, for example by including it in a privacy or deletion request you send to [email protected]. Do not post this ID publicly, such as in a review, forum, or social media post; treat it like any other account reference.

TODO: confirm RevenueCat's exact default vendor-side retention period before an explicit deletion request, and finalize identity-verification proportionality and response-time commitments for privacy/deletion requests that include a Privacy Request ID. Support correspondence retention is described above.

Processing outside Québec and Canada

A Canada-only launch does not mean all information is processed in Canada. Subscription, support, and hosting providers may process information outside Québec or Canada, where different laws may apply.

TODO: confirm actual provider locations and transfer safeguards, complete the applicable Québec privacy impact assessment, and replace this marker with the verified transfer disclosure.

Security

Gameplay records use the app's local device storage. Subscription functionality relies on Apple and RevenueCat services. Protect your device and avoid sending sensitive information in support requests. No storage or transmission method is completely secure.

Children

Stop Slop is a general-audience app and is not offered in Apple's Kids Category. It does not ask for a player's age or require an account. A parent or guardian with a concern about information provided by a child can contact our privacy contact. Applicable protections for children still apply.

Your privacy rights and complaints

Depending on the applicable law, you may request access to or correction of personal information and information about how it is used or disclosed. Québec and Canadian law may provide rights to withdraw consent, subject to applicable limits; Québec law also provides portability rights in specified circumstances. Contact us to make a request or complaint. We may need proportionate information to verify and locate the relevant records.

Where the GDPR applies, rights may include access, rectification, erasure, restriction, portability, objection, withdrawal of consent where processing relies on consent, and a complaint to a supervisory authority. These rights are subject to legal conditions. A Canada-only release does not, by itself, determine GDPR applicability.

You can also contact the Commission d'accès à l'information du Québec, the Office of the Privacy Commissioner of Canada, or another competent privacy authority.

TODO: owner to establish the privacy-request and complaint process and verify applicable response periods, legal bases, consent requirements, and any additional jurisdiction-specific disclosures before publication.

Updates

We may revise this policy as our practices change. We will publish the revised policy with its effective date and provide any additional notice required by applicable law.