The short version
We do not run targeted advertising, create advertising profiles, or track you across other companies' apps and websites.
Information stored on your device
The app stores settings and game information locally so it can work: preferences, the card you opened, possible-hand marks, game history, and local purchase or trial status. Most of this information stays on your device.
You can clear the app's local data from Settings. Removing the app also removes its local data, although Apple keeps its own App Store purchase records.
Anonymous beta and entitlement account
When beta access or server-backed purchase verification is enabled, Mahj IRL creates an anonymous technical account through Supabase. It has a random user identifier and secure session token, but no name, email address, phone number, or password.
The account can be associated with beta-code redemptions, failed redemption attempts, card entitlements, start and expiration times, and revocation status. It exists to keep protected-card access secure, prevent a beta code from being reused, and restore the access the service can verify.
Optional game research
When beta game research is enabled in a released app version, Mahj IRL may collect how possible hands were added or removed during a completed game, the final target hand if one was selected, the card and version, and the closed game outcome. This helps us understand how cards play and design better future cards.
This research record uses separate random game and delivery identifiers. It does not include a name, email address, account or authentication identifier, device or installation identifier, contact information, hand text, free-form text, or PostHog identifier. Raw game-research records are kept separate from raw product analytics and expire within 90 days.
Purchases and protected cards
Apple processes purchases and restores through the App Store. Mahj IRL does not receive your payment-card number. To confirm access to a protected card, the app may send an Apple-signed transaction proof, product identifier, requested card identifier and version, and the validation result to Mahj IRL's protected-content service.
That information is used only to verify a purchase or trial, deliver the requested card, prevent repeat-trial abuse, support restores, and respond to refunds or revocations. Routine service and security logs may also contain an IP address, user-agent, timestamp, requested route, and error information.
Shared links
A Mahj IRL card link contains the card identifier and version, plus an expiration time only when one was deliberately added. It does not contain the sender's identity, recipient identity, marked hands, game history, or purchase status. Opening a link never transfers ownership.
Website and support
We do not use advertising cookies or analytics trackers on this website. Our hosting provider may process routine request and security information—such as IP address, browser type, timestamp, and requested page—to deliver the site and protect it from abuse.
If you contact support, we receive the information you choose to provide, such as your email address, message, and any troubleshooting details or attachments.
Product analytics and crash reporting
Mahj IRL uses PostHog's United States cloud for limited product analytics. The app sends only allowlisted events such as app and session starts, onboarding completion, card opens, trials, purchases and restores, coarse completed-game outcomes, sharing results, and review-prompt activity. Those events may include stable card, product, and app-version identifiers, enumerated results, and aggregate counts.
PostHog uses a random, persistent installation identifier so events can be understood across app sessions and delivered after a device was temporarily offline. Mahj IRL does not link that identifier to an account or person profile. Session replay, automatic screen or touch capture, person profiles, surveys, automatic error capture, precise location enrichment, and storage of the client IP address with analytics events are disabled. We do not send marked or winning hand identifiers, player names, share recipients, search text, contact information, or free-form messages to PostHog.
Mahj IRL uses Sentry to diagnose JavaScript crashes and specific app failures. Reports are restricted to a fixed failure category, app-release and environment information, and sanitized code locations needed to find the problem. Default personal information, user and request payloads, breadcrumbs, logs, screenshots, view hierarchy, session replay, performance tracing, and free-form error details are disabled.
Retention and deletion
Local app information stays on your device until you clear it or remove the app. We keep support messages only as long as needed to respond, maintain a reasonable support record, or meet legal obligations. Transaction-validation records may be kept while needed to support access, restores, refunds, revocations, fraud prevention, and legal obligations. Product-analytics and crash records are kept only for the limited operational and product-analysis period configured with those providers and are periodically reviewed for deletion. Optional anonymous game-research records expire within 90 days. Routine security logs are retained for a limited operational window and are not used for advertising.
You can ask us to delete support information or other information directly associated with you. We may need enough detail to locate the record, and Apple-controlled purchase records must be handled through Apple. Because optional game-research records deliberately contain no person, account, or device identifier, we generally cannot locate an individual's research record; those records expire automatically.
Service providers
Apple provides App Store purchases and related transaction services. Supabase provides anonymous authentication and protected-card entitlement infrastructure and optional anonymous game research. PostHog provides product analytics through its United States cloud. Sentry provides crash reporting. Hosting providers deliver the website and related services. These providers process information only to provide and secure their services and meet their own legal obligations. We do not authorize them to use Mahj IRL information for targeted advertising.
Children
Mahj IRL is a general-audience game companion and is not directed to children under 13. We do not knowingly collect personal information from children.
Your choices
You can use the app without creating an account, decline to contact support, clear local app data, and choose whether to start a purchase or trial. If an anonymous beta account exists, Settings includes an option to permanently delete that account, its server entitlements, and related beta records. Learn more on the account deletion page. For privacy requests, email support@mahj-irl.com. You can also review our support page.
Changes to this policy
We may update this policy as the app changes. The effective date at the top will change when we do. If a change materially affects how personal information is handled, we will provide an appropriate notice in the app or on this website.
Contact
Questions or privacy requests can be sent to support@mahj-irl.com.