Privacy policy
RUNEFALL Privacy Policy
Last updated: September 18, 2026
This policy applies to the RUNEFALL app and its online account, matchmaking, gameplay, social, and support services. It does not replace the policies for other TurboInc apps.
Your choices
You can play supported offline modes without creating a RUNEFALL account. An account is required for online account, social, matchmaking, rating, and cross-device service features. Providing a reply email in the public support form is optional.
Information RUNEFALL processes
- Account and contact information: email address, handle, display name, verification state, and account timestamps. RUNEFALL stores an Argon2id password hash, not the account password in readable form.
- Authentication and security records: one-way token digests, session identifiers, expiry and revocation records, and verification or recovery status. The raw verification or recovery link is sent through the transactional email provider and expires after 30 minutes.
- Social and gameplay information: friend requests, friendships, blocks, invitations, matchmaking choices and state, game positions and moves, clocks, presence and reconnect state, results, and ratings.
- Support information: category, subject, message, ticket state, and—when submitted while signed in—the account identifier. A public signed-out form separately stores the app, category, subject, message, and an optional reply email only when the sender consents.
- Service and security logs: network address, request time, HTTP method and route without query text, status, response size, request duration, and generic error information. Request bodies, passwords, session tokens, support text, and account email are not written to these request logs.
Offline game state, local preferences, and the app's protected on-device session credential remain on the device unless they are sent to an online feature or included by the user's operating-system backup or transfer settings.
How the information is used
RUNEFALL uses this information to create and secure accounts, verify email addresses, recover access, provide social and online game features, match players, maintain ratings and game continuity, investigate service failures or abuse, respond to support requests, and maintain and restore the service.
RUNEFALL does not use third-party advertising or analytics SDKs, does not sell personal information, and does not track users across other companies' apps or websites for advertising.
Service providers and disclosure
Cloudflare carries public web traffic and may process connection and security metadata such as network addresses, including provider-injected browser network-error reports. Resend delivers verification and account-recovery email and processes the destination email address and message needed for that delivery. Authorized operators can access private service data only for service operation, security, support, backup, recovery, or deletion work. A private owner notification for a committed support ticket contains only its ticket number and category; the support message and email remain in the private support system.
Apple distributes the app and processes App Store and device information under Apple's own terms. RUNEFALL may also disclose information when required by law or to protect users, the service, or others.
Retention
- Account, social, invitation, authentication-history, and rating records remain while the account is active unless the service removes them earlier.
- Finished game records and abandoned active game records are scheduled for removal after 90 days. Terminal matchmaking tickets are scheduled for removal after 7 days.
- Application audit records and local HTTP/service logs are retained for up to 14 days.
- Encrypted service backups are retained for up to 30 days. A protected restore quarantine, when used, is retained for up to 24 hours and is never promoted automatically.
- Support tickets do not currently have an automatic expiry. They remain for private review until an authorized operator removes them. Account deletion removes the account link and reply consent from an authenticated support ticket but retains the deidentified issue text and ticket number.
Account deletion
An authenticated user can delete the RUNEFALL account in the app's account settings by confirming the current password. Deletion removes the account profile, email, password hash, sessions, verification and recovery records, social relationships, invitations, and current rating record. Game history, rating-ledger entries, audit references, and support text that must remain operationally useful are changed to pseudonymous or unlinked records rather than retaining the deleted account identity.
To prevent an encrypted backup from recreating a deleted account, RUNEFALL keeps keyed, non-readable deletion proofs for 31 days—longer than the backup window—and replays them during any quarantined restore. Existing encrypted backups age out within 30 days.
Support and privacy requests
If you can sign in, use the in-app account settings for account deletion. If you cannot sign in, or want to ask about privacy or request review or deletion of a public support submission, use the RUNEFALL public support form. Include the support ticket number if you have one. Do not send passwords, access codes, private keys, payment information, or other secrets.
A privacy or deletion request may require enough information to identify the relevant account or ticket and protect it from unauthorized requests. The public form is the verified contact route; this policy does not publish or promise an unverified support email address.
Security and changes
RUNEFALL uses access controls, password hashing, encrypted backups, minimized notifications, and protected device storage, but no service can guarantee absolute security. Material changes to this policy will be posted here with a new last-updated date.