Privacy Policy
Effective date: 2026-07-29 · Version 2026-07-29
MOLVERINE CORP, a Wyoming, USA corporation with its registered office at 30 N Gould St, Sheridan, WY 82801, USA (“we”, “us”), operates the Molverine web service (the “Service”). This Privacy Policy explains what personal data we process, why, and what rights you have under the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and other applicable privacy laws.
1. Data Controller
- Legal name: MOLVERINE CORP
- Registered office: 30 N Gould St, Sheridan, WY 82801, USA
- Contact for privacy requests: molverinecorp@gmail.com
We do not currently maintain an establishment in the European Union; however we are subject to the GDPR to the extent we offer the Service to data subjects in the EU/EEA (Art. 3(2) GDPR). EU/EEA users may also contact us at the address above for any data-protection matter.
2. What We Collect
- Account data — email, display name, hashed password (bcrypt) or OAuth provider identifier (Google), avatar URL, role, account-status flags.
- Consent records — timestamps and version strings of the Terms / Privacy / marketing consents you gave at signup.
- Game state — cases you activated, evidence-board nodes, theories, chat history with in-game NPCs (AI-generated), lab analyses you submitted.
- Technical data — IP address, user-agent, request timestamps. Used for rate-limiting, abuse detection, and basic operational logs.
- Push notification tokens (mobile apps only) — if you allow notifications in our mobile app, we store the device token issued by the platform (Apple Push Notification service on iOS, Firebase Cloud Messaging on Android) linked to your account so we can deliver game notifications. See Section 9.
- Purchase data (mobile apps only) — App Store / Google Play product identifiers and purchase state for in-app purchases you make, linked to your account so we can unlock the purchased cases. We never receive your payment-card details — payment is processed entirely by Apple or Google. See Section 9.
- Subscription state (mobile apps only) — whether a Lurkie Pro subscription is active and when the current period ends, so we know which cases to unlock. See Section 9.
- Guest accounts. The mobile apps let you play without registering. On first launch we create an anonymous account identified by a random identifier and a synthetic address of the form
guest_<random>@guest.molverine.app. It is not a real mailbox, we cannot contact you through it, and it exists only so your progress and purchases have somewhere to live. It is still personal data under the GDPR, because it is tied to your device and your purchases, and every right in Section 6 applies to it. - Product telemetry — in-app events describing how the game is used (screens opened, a case started, a clue flagged, a paywall shown, a purchase completed), a randomly generated session identifier, the platform (iOS / Android / web), the app language, and any UTM campaign parameters present the first time you arrive. Events describe actions, not the content of your interrogations. See Section 8.
- Cookies — see Section 8.
We do not intentionally collect special-category data (health, biometric, political opinions, etc.) and we do not knowingly collect data from children under 16.
3. Why We Process It (Lawful Basis under GDPR)
- Contract (Art. 6(1)(b)) — to deliver the game you signed up for: store progress, run interrogations, accept payment for paid cases.
- Legitimate interest (Art. 6(1)(f)) — security, fraud prevention, rate-limiting, aggregate product analytics.
- Consent (Art. 6(1)(a)) — non-essential cookies, marketing emails. You can withdraw at any time.
- Legal obligation (Art. 6(1)(c)) — responding to lawful requests from authorities.
4. Subprocessors
We share personal data with the following processors strictly to operate the Service:
- Amazon Web Services, Inc. — application hosting (AWS Amplify) and the PostgreSQL database (Amazon RDS), including request logs.
- OpenAI, L.L.C. — generates NPC dialogue from your interrogation messages. Per OpenAI’s API terms, your prompts are not used to train their models.
- Resend, Inc. (if email features are enabled) — transactional + contact-form emails.
- Google LLC — if you sign in with Google OAuth; in the Android app, Google additionally processes in-app-purchase payments (Google Play Billing) and delivers push notifications (Firebase Cloud Messaging).
- Apple Inc. (iOS app only) — processes in-app-purchase payments and delivers push notifications (APNs).
- RevenueCat, Inc. (mobile apps only) — validates App Store / Google Play purchases and manages purchase entitlements on our behalf. Your account identifier is passed to RevenueCat as the subscriber id, which is what makes Restore Purchases work across reinstalls.
- Web analytics vendors (website only, and only where the corresponding integration is switched on and you have accepted the analytics or marketing cookie category): Google LLC (Google Analytics), YANDEX, LLC (Yandex Metrica), Microsoft Corporation (Clarity), Meta Platforms, Inc. (Meta Pixel) and Plausible Insights OÜ. None of these are present in the mobile apps.
We do not sell or rent your personal data to third parties for their own marketing.
5. Data Retention
- Account data — for as long as your account exists, plus up to 30 days after deletion (backup rotation).
- Game state — same as account; can be exported on request.
- Contact-form messages — up to 24 months, then purged unless tied to an open support thread.
- Operational logs (IP, request metadata) — up to 90 days.
- Push notification tokens — until you disable notifications, delete your account, or the platform (Apple / Google) reports the device token invalid; dormant tokens are pruned after 12 months.
- Purchase records — for as long as your account exists (they prove your entitlement to purchased cases), plus statutory bookkeeping periods.
- Consent timestamps — kept as long as the underlying account, as proof of valid consent (GDPR Art. 7).
- Product telemetry in our own pipeline — up to 24 months, after which events are aggregated and the account link is dropped.
- Telemetry and crash reports held by the mobile analytics SDK — retained by that processor under its own schedule; we do not control it and cannot shorten it. See Section 4.
6. Your Rights
Under the GDPR / UK GDPR you have the right to:
- Access — get a copy of your data (download via your account settings, or request by email).
- Rectification — correct inaccurate data.
- Erasure (“right to be forgotten”) — delete your account and associated data.
- Restriction and objection to certain processing.
- Portability — receive your data in a structured, machine-readable format (JSON).
- Withdraw consent at any time, without affecting prior lawful processing.
- Lodge a complaint with your local supervisory authority.
Under the CCPA / CPRA, California residents additionally have the right to know what personal information we collect, to delete it, to correct it, and to opt out of any “sale” or “sharing” for cross-context behavioral advertising. We do not currently sell or share your personal information; see Do Not Sell or Share.
To exercise any right, email molverinecorp@gmail.com from the address on file, or use the in-app controls under Account → Privacy. We respond within 30 days (45 days for CCPA requests, with one extension permitted).
7. International Transfers
Our own infrastructure stores and processes data in the United States. Where personal data is transferred outside the EEA / UK, we rely on Standard Contractual Clauses (SCCs) and, where the recipient is certified, the EU–US Data Privacy Framework.
8. Cookies, SDKs and Product Telemetry
On the website we classify cookies and similar technologies into three categories:
- Strictly necessary — session, authentication, CSRF protection, your language choice, your cookie preferences. Always on; you cannot opt out without breaking the Service.
- Analytics — third-party measurement (Section 4). Only set if you accept the analytics category in our cookie banner.
- Marketing — advertising measurement (Section 4). Only set if you accept the marketing category.
You can change your choice any time via the “Cookie settings” link in the footer.
In the mobile apps there is no cookie banner, because there is nothing cookie-based to consent to and no third-party analytics SDK of any kind. The apps contain exactly one measurement mechanism: our own telemetry — the events listed in Section 2, sent to our own servers. We process these under legitimate interest (GDPR Art. 6(1)(f)) to understand which parts of a case players get stuck on and whether a build is working. They are not used to build advertising profiles and they are not shared for that purpose.
It does not read the text of your interrogations, your notes or your theories.
9. The Mobile Apps: Apple and Google
Our mobile apps for iOS and Android (distributed as Lurkie on the App Store and Google Play) present the same Service, and this Policy applies to them in full. What follows is what is specific to them.
9.1 Purchases and subscriptions
Everything sold inside the apps is sold through the platform’s own billing system — Apple In-App Purchase on iOS, Google Play Billing on Android. There is no other way to pay us from inside an app, and the apps contain no links to any outside store.
- We never see your payment details. Card numbers, billing addresses and bank details are collected and processed by Apple or Google as the merchant of record. We receive the product identifier, whether the purchase is active, and — for subscriptions — when the current period ends.
- What we do with it. That state is stored against your account so the right cases unlock and stay unlocked, and so Restore Purchases can find them again after a reinstall or on a second device.
- Subscriptions. Lurkie Pro renews automatically until cancelled. We are told the renewal happened; we are not told how it was paid. See section 6a of our Terms of Service for the renewal and cancellation terms.
- Refunds and cancellation are handled entirely by Apple or Google under their own terms — we cannot issue a refund for a store purchase or cancel a store subscription on your behalf, because we never hold the billing relationship.
- Access codes (press, creator and review keys) involve no payment and no store. Redeeming one records that the code was used and which cases it unlocked.
9.2 Push notifications
If you grant the notification permission, the platform issues a device token which we store against your account and use to send game-related notifications. On iOS the token comes from Apple Push Notification service. Notifications are currently sent on iOS only; when Android delivery is enabled it will use Google’s Firebase Cloud Messaging and this Policy will be updated before it ships.
We ask for the permission only after you have actually started playing, never on the launch screen, and the game is fully playable if you decline. You can revoke it at any time in your device’s notification settings; revoking it, or deleting your account, retires the token.
9.3 What the stores themselves collect
Apple and Google collect their own data about your download and your purchases under their own privacy policies, as controllers in their own right — we do not control that and it is not covered by this Policy. They also give us aggregate, non-identifying sales and crash statistics through App Store Connect and Google Play Console.
9.4 What we do not do in the apps
- We do not use the advertising identifier (IDFA / GAID) and we do not ask for App Tracking Transparency permission, because we do not track you across other companies’ apps or websites.
- We do not run third-party advertising or analytics SDKs in the apps. Measurement is our own, on our own servers.
- We do not sell or share personal information for cross-context behavioural advertising.
- We do not request location, contacts, camera, microphone, photo-library or health permissions. The apps use haptic feedback and, with your permission, notifications.
9a. Store Privacy Disclosures
Both stores require us to declare what the app collects. This is that declaration in plain text, so that our App Store “App Privacy” labels and our Google Play “Data safety” form can be checked against it. If you ever find the two disagree, this Policy is what we consider binding, and we would like to hear about it.
- Contact info — email address. Registered accounts only; linked to you; used for app functionality and account management. Guest accounts have a synthetic address (Section 2).
- Purchases — purchase history and subscription state. Linked to you; used for app functionality. Not used for tracking.
- Identifiers — our own account identifier and a randomly generated session identifier. Linked to you; used for app functionality and analytics. No advertising identifier, and no tracking across other companies’ apps or sites.
- User content — the messages you write to characters, your notes and your theories. Linked to you; used for app functionality. Interrogation messages are sent to our AI provider for inference (Section 10).
- App activity — the product telemetry in Sections 2 and 8, on our own servers. Linked to you; used for analytics.
- Not collected — precise or coarse location, contacts, photos, health and fitness, financial information, browsing history, advertising identifiers, sensitive categories.
Data is encrypted in transit, you can request a copy of it, and you can delete your account and its data from inside the app (Section 6).
10. AI-Generated Content
In-game NPC interrogations are produced by large language models (currently OpenAI GPT models). The content is fictional and may be inaccurate, offensive, or contradictory. We do not represent NPC dialogue as factual. Your interrogation messages are sent to OpenAI for inference; per OpenAI’s API terms, those messages are not used to train their models. See also Section 10 of our Terms of Service.
11. Security
We use TLS in transit, bcrypt password hashing, role-based access control, IP rate-limiting, and least-privilege database credentials. No system is perfectly secure. If you discover a vulnerability, please email molverinecorp@gmail.com.
12. Children
The Service carries a 16+ content rating and is intended for users aged 16 and older — case content includes depictions of crime and other adult themes typical of the detective genre. We do not knowingly collect personal data from children under 13 (COPPA in the United States) or below the digital-consent age in your jurisdiction (16 in most of the EU). If you believe a minor has created an account, contact us and we will delete it.
13. Changes
We may update this Policy from time to time. Material changes will be announced in-app and the version number at the top of this page will be incremented. Continued use after the new effective date constitutes acceptance of the updated Policy.
14. Contact
Privacy questions and DSARs: molverinecorp@gmail.com.
Postal address: MOLVERINE CORP, 30 N Gould St, Sheridan, WY 82801, USA.