GRIDLOCK
Privacy Policy
Effective date: 2026-07-26 · Version 2026-07-22
1. Operator and contact
Gridlock is operated by Ishaan Bery, individual developer, located at 4126 Rockingham Drive (“Gridlock,” “we,” “us”). Privacy questions may be sent to Gridlockapp@outlook.com.
2. Scope and age
This policy applies to the Gridlock mobile game, websites, support channels, and online services. Gridlock accounts are intended for people age 13 or older. We do not knowingly create an online account for a child under 13. Local offline play may be offered without an online account.
3. Information processed
- Account information: Supabase user ID, Apple or Google sign-in identifier, email address when supplied by the provider, display name, friend code, authentication provider, and account status.
- Game and competition information: scores, move logs used for anti-cheat replay, match history, rank, rating, streaks, Daily attempts, achievements, missions, settings, inventory, equipped cosmetics, virtual-currency balances, and cloud-save data.
- Social and safety information: friend relationships and requests, blocks, reports, report details, moderation decisions, and account restrictions.
- Purchase information: Apple product and transaction identifiers, subscription or entitlement status, refund or revocation status, and virtual items credited. Apple processes payment-card information; Gridlock does not receive complete card details.
- Technical and security information: app and ruleset version, device and operating-system details, session identifiers, request times, IP-derived security signals, crash or error diagnostics, rate-limit events, and security audit logs.
- Support information: messages and attachments you choose to send to support.
4. Information not requested in version 1.0
Gridlock does not request access to contacts, photos, precise location, microphone recordings, health data, or the advertising identifier. Version 1.0 includes no advertising SDK, no third-party ads, and no cross-app tracking. This section must be updated before adding an advertising or tracking SDK.
5. How information is used
- create and secure accounts, restore sessions, and provide cloud saves;
- operate Classic, Daily, Ranked, Friend Duels, leaderboards, missions, achievements, the Shop, and Vault rewards;
- verify scores, enforce attempt limits, prevent fraud and cheating, rate-limit abuse, and resolve disputes;
- process and restore purchases, subscriptions, refunds, and entitlements;
- provide reporting, blocking, moderation, account deletion, and customer support;
- diagnose reliability problems and improve the user experience using limited first-party telemetry.
6. Public information
Your display name, rank, rating, and verified leaderboard scores may be visible to other players. Friend codes are shared only when you choose to share them. Do not use a display name that contains private contact information.
7. Service providers
The planned production providers are Supabase for authentication, database, storage, and server functions; Apple for Sign in with Apple, App Store distribution, StoreKit purchases, and TestFlight; and Google for optional Google Sign-In. Add every production analytics, crash-reporting, email, hosting, or support provider before publication.
8. Legal bases and disclosures
Depending on your location, processing may be necessary to perform the service contract, comply with law, protect legitimate security interests, or follow your consent. We do not sell personal information. We do not share personal information for cross-context behavioral advertising in version 1.0. Information may be disclosed to service providers, authorities when legally required, or a successor in a lawful business transaction.
9. Retention
Proposed operational defaults are: account data while the account is active; detailed anti-cheat move logs only as long as reasonably needed for validation and disputes; security and moderation records for 24 months; and transaction, tax, refund, and legal-consent records for the period required by applicable law. Deleted data may remain in encrypted backups for up to 90 days before routine overwrite.
10. Your choices and rights
You may edit your display name subject to safety limits, manage friends and blocks, turn off optional sound and haptics, sign out, restore purchases, and request deletion inside the app. Depending on your location, you may request access, correction, deletion, portability, restriction, or an appeal of certain decisions by contacting the privacy address.
11. Account deletion
Use Gridlock → Profile → Settings → Account → Delete Account. The production flow requires reauthentication, removes or anonymizes account and social data, revokes the session, and retains only records lawfully needed for security, transactions, disputes, or compliance. Details appear on the account deletion page.
12. International processing
Service providers may process information in countries other than your own. Where required, appropriate safeguards are used for international transfers and service-provider processing.
13. Security
Gridlock uses encrypted transport, Keychain session storage on iOS, Row Level Security, server-authoritative wallets and competitive results, replay validation, request limits, security logging, and restricted service credentials. No system can guarantee complete security.
14. Changes
Material changes will be posted here with a new version and, when appropriate, presented for acceptance in the app.