CipherWalk

Privacy Policy

Last updated: 1 August 2026

This Privacy Policy explains how Eskil Jarlskog (“we”, “us”) collects and uses your personal data when you use the CipherWalk mobile app or visit cipherwalk.com (the “Service”). We are based in Switzerland and act as the data controller for the personal data described below.

1. Data we collect

Mobile app

When you use the CipherWalk app, we collect:

  • An account identifier, a UUID generated on first launch. When you open the app for the first time we create an anonymous account for you automatically, with a random display name and no email. This identifier is also attached to any crash reports we receive so we can correlate a crash with the affected account.
  • Your email address, only if you choose to sign in. Signing in is optional and upgrades your anonymous account so you can restore your progress on another device. We support magic-link sign-in (you enter your email and we send a one-time link), Sign in with Apple, and Sign in with Google. Your email is stored on your account so we can recognise you when you sign in again and contact you about your account if needed. If you use Sign in with Apple and choose to share your name, we store that as your display name. If you never sign in, we never collect an email.
  • A display name, only if you choose to set one. This is visible to other players in lobbies and on leaderboards.
  • Your location, only while you have a quest open. Location is used to determine when you arrive at a quest stop. We do not track your location in the background and we do not store a continuous trail of your movements.
  • Gameplay content, including puzzle state, answers you submit, hints you use, stops and quests you have completed, cities you have played in, and your team's progress in multiplayer sessions. This is needed to run the game and to show leaderboards.
  • Purchase records, including which quests you have unlocked, how each unlock was granted (in-app purchase, promo code, or gift), the store transaction identifier, and the time of the purchase. This is stored on your account so we can give you access to the quests you have paid for.
  • Support messages, if you email us for help. Messages sent to our support address are retained in our support inbox so we can respond and follow up.
  • Basic technical data sent automatically by your device to our backend (such as IP address) for security and abuse prevention.
  • Crash and diagnostic data. When the app hits an unexpected error we send a crash report that includes the stack trace, device model, operating system version, app version, device locale, recent console logs, and a breadcrumb trail of the screens you visited and the API calls the app made in the moments leading up to the error. We use this only to identify and fix bugs.

Marketing website (cipherwalk.com)

If you sign up for the new-quests email list, we store your email address until you unsubscribe. We use it only to send the monthly update.

If you purchase a quest on the website, payment is processed by Stripe. We do not see or store your card details. Stripe shares your email address and the amount paid with us so we can confirm your purchase and provide support. The purchase is linked to the CipherWalk account you sign in with at checkout.

We measure how the website is used. On every visit we collect the pages you view, the site or search engine that referred you, and your device and browser type. Until you accept analytics storage, and if you decline it, nothing is stored on your device, but we still count the visit. To do that we use a temporary identifier calculated from your IP address and your browser characteristics. It changes every day, so the pages you view within one day can be linked to each other, but they cannot be linked to a later day. We do not work out where you are from your IP address unless you accept analytics storage.

If you accept analytics storage, we also store a random visitor identifier on your device, which links your repeat visits, and we derive an approximate location (city level) from your IP address. We record your session too: the pages you view, mouse movement, clicks, scrolling, and the content of the pages as they appeared on your screen. Text you type into form fields is masked and is not recorded, and we mask your own email address where it appears on screen. Section 4 explains how to change or withdraw this choice.

If you are signed in, we send our analytics provider your account identifier, not your email address, so your activity on the website is linked to your CipherWalk account. This happens whether or not you accept analytics storage.

2. How we use your data

  • Provide and operate the Service (gameplay, multiplayer, leaderboards, purchase confirmation).
  • Respond to support and refund requests.
  • Understand how the website is used (which pages people visit, where they arrive from, where they get stuck) so we can improve it.
  • Detect and prevent abuse (e.g., cheating, fraudulent payments).
  • Comply with legal obligations.

We do not sell your personal data, and we do not use it for advertising.

3. Sub-processors

We use the following service providers to operate the Service. They process personal data on our behalf:

  • Supabase — authentication, database, and realtime multiplayer. Data stored in the European Union.
  • Stripe — payment processing for quest purchases on the website. Stripe is GDPR-compliant and processes data in the EU and the US under appropriate transfer safeguards.
  • Sentry — crash and error reporting for the mobile app. When an error occurs, Sentry receives your account identifier, the stack trace, device model, operating system version, app version, device locale, recent console logs, and a breadcrumb trail of recent screens and API calls. Data may be processed in the EU or the US under appropriate transfer safeguards.
  • Vercel — hosting and performance monitoring for cipherwalk.com. Used solely to operate the website.
  • PostHog — product analytics and session recording for cipherwalk.com (page views, button clicks, form submissions, and JavaScript errors). Analytics requests are sent through cipherwalk.com, and the data is stored in the European Union. Until you accept analytics storage, and if you decline it, PostHog stores nothing on your device and counts your visit using a temporary identifier that it calculates from your IP address and your browser characteristics. That identifier changes every day, so the pages you view within one day can be linked to each other, but they cannot be linked to a later day. If you accept, PostHog stores a random visitor identifier on your device so your repeat visits are linked, and it records your session: pages viewed, mouse movement, clicks, scrolling, and the content of the pages as they appeared on your screen. Text you type into form fields is masked and is not recorded, and we mask your own email address where it appears on screen. If you are signed in, we send PostHog your account identifier, not your email address, so your analytics activity is linked to your CipherWalk account. Our servers also send PostHog events, for example when a purchase completes or you sign in; those involve no storage on your device.

4. Cookies and similar technologies

The website stores the following on your device. Nothing else is written to cookies, local storage, or session storage. The mobile app does not use cookies.

  • Sign-in session (essential, no consent needed). Set by Supabase when you sign in and used to keep you signed in. Without it you cannot sign in or buy a quest.
  • Your analytics choice (essential, no consent needed). A first-party local storage entry set by PostHog, named __ph_opt_in_out_ followed by our project identifier. It records whether you accepted or declined analytics storage, so we do not ask you again on every visit. It is written only at the moment you accept or decline. If you ignore the banner, we store nothing on your device.
  • Analytics identifier (optional, set only after you accept). A cookie and local storage entry set by PostHog, under keys starting with ph_ followed by our project identifier and _posthog. It holds a random identifier that links your visits to each other, so we can count visitors and see how people move through the site. Accepting also turns on session recording, described in section 3.

When you accept, PostHog starts a new identifier rather than carrying the temporary one over, so what you did before you accepted is not linked to what you do afterwards.

We ask for your consent before storing the analytics identifier or recording your session, and those two things are the only ones we rely on consent for. You can change or withdraw your choice at any time using the Cookie settings control, which is in the footer of our homepage and here:

Withdrawing consent stops session recording and stops PostHog storing the identifier on your device. It does not affect what we collected while your consent was in place.

We are based in Switzerland, so the Swiss Federal Act on Data Protection (FADP) applies. If you are in the EU or the EEA, the EU GDPR applies as well, and your consent is the legal basis for the analytics identifier and session recording.

5. How long we keep your data

  • Game account data (account identifier, email, display name, gameplay content) is kept until you delete your account. You can delete your account at any time inside the app, in the Profile screen.
  • Quest creator form submissions are kept for as long as we are following up with you, then deleted within a reasonable time.
  • Payment records are kept for 10 years as required by Swiss commercial law.
  • Website analytics events are kept for 12 months, then deleted.
  • Session recordings are deleted after 30 days.

6. Your rights

Under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate data corrected.
  • Have your data deleted. You can do this directly inside the app via Profile → Delete account.
  • Object to or restrict certain processing.
  • Withdraw consent you have given. For website analytics and session recording, use the Cookie settings control, in the footer of our homepage and in section 4 above, to change or withdraw your choice at any time.
  • Lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local supervisory authority.

To exercise any of these rights, email privacy@cipherwalk.com.

7. Children

The Service is intended only for adults and is not directed to anyone under 18. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has used the Service, contact us and we will delete the data.

8. Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent change. Material changes will be communicated through the app or the website before they take effect.

9. Contact

Eskil Jarlskog
privacy@cipherwalk.com