Afterdark
Privacy policy
The short version
Afterdark is built so that we cannot identify you. There is no sign-up form, because there is no account to fill in: no email, no name, no phone number, no password. Your phone is handed a random identifier the first time you open the app, and that identifier is all we ever know you by.
The part of the app that matters most — your comfort level, who you're open to being paired with, whether you want drink prompts, what cards you were dealt — is never written down anywhere. It lives in the memory of the game server while your room is open, and it is gone the moment the room closes.
No ads. No trackers. No analytics. No profiles. Nothing sold, nothing shared, nothing to scroll.
What we store
Exactly three things, all attached to that random identifier:
- The anonymous identifier itself. A random string created by our authentication provider when you first open the app. It is not derived from your device, your phone number, or anything about you.
- Your 18+ confirmation. A yes/no flag saying that you confirmed you're an adult, and the date you confirmed it. This is what lets the age gate survive a restart and lets our server refuse adult-only content to anyone who hasn't confirmed.
- Your Premium status. If you subscribe: whether the subscription is active, which product it is, and when the current period ends.
That's the complete list. There is no other record of you on our side.
What stays in the room
When you join a game, your device sends the game server the display name you typed and your private settings — your heat ceiling, your pairing choices, your drink opt-in. The server needs those to deal cards that everyone involved actually agreed to.
None of it is ever written to a database, and none of it is written to our logs. It is held in the server's working memory for the length of that room and destroyed when the room closes. Your consent settings are never shown to the other players — the game only ever reveals the card it dealt, never the settings behind it. Other players see your display name and whether you're still connected, and nothing else.
The same is true of everything the night produces: the cards dealt, the passes taken, the round history, the end-of-night summary. When the room ends, so does all of it.
What we never collect
- No contact details. No email address, no name, no phone number, no password.
- No advertising or tracking. No ad networks, no advertising identifier, no cross-app or cross-site tracking. We never show the App Tracking Transparency prompt, because there is nothing to ask you for.
- No analytics. No usage analytics, no crash-reporting SDK, no behavioural profiling, no A/B tooling, no third-party SDK watching what you tap.
- No device or location harvesting. No contacts, no photos, no microphone, no camera roll, no GPS or coarse location, no advertising ID.
- No selling or sharing. We do not sell personal data, share it with data brokers, or hand it to anyone for their own purposes. There is nothing to sell — and no market for a random string.
- No strangers. There are no public profiles, no matchmaking, no discovery, no feeds. Afterdark only connects people who already have the same room code, in the same room.
Payments
Afterdark Premium is sold through the App Store. Apple handles the entire payment: the card, the billing address, the tax, the receipt. Your payment details never reach us and we could not see them if we wanted to.
To keep your subscription status accurate across devices we use RevenueCat, a subscription-management service. RevenueCat receives your anonymous app identifier and the Apple receipt data for your purchase — nothing else, and nothing that identifies you as a person. It then tells our server whether that anonymous identifier has an active subscription.
If you want the detail: RevenueCat's privacy policy and Apple's privacy policy.
Why we're allowed to hold this
Under the GDPR and under Türkiye's Personal Data Protection Law (KVKK), we need a lawful reason for every piece of data. Ours:
- Performing our agreement with you. The anonymous identifier and the Premium record exist so that the app works and so that a subscription you paid for still works tomorrow, and on your next phone.
- Our legitimate interests. Keeping the 18+ confirmation server-side so adult-only content cannot be unlocked by a modified app, and keeping the entitlement record server-side so Premium cannot be self-granted. Both are narrow, both protect users as much as us, and neither involves knowing who you are.
We don't rely on consent as a legal basis for any of this, because none of it is optional to the service — and we ask for no data that would need separate consent.
Who else touches it
Four companies, each acting only on our instructions and only for the purpose listed. Nobody else receives anything.
| Who | What for | What they receive |
|---|---|---|
| Supabase | Anonymous sign-in and the database holding the three records above | The anonymous identifier, the 18+ flag, the Premium record |
| RevenueCat | Subscription management | The anonymous identifier and Apple receipt data |
| Apple | App distribution and payment processing | Everything about the purchase; handled entirely by Apple under Apple's own privacy policy |
| Railway | Hosting for the live game server | Nothing stored. Room data passes through the server's memory while you play and is gone when the room closes |
The game server — the one that holds a room in memory while you play — is software we wrote, running on rented hosting. It writes nothing down: no database rows, no session logs, no copies kept after a room closes.
Where it lives
The database sits in the European Union, in Supabase's eu-central-1 region (Frankfurt, Germany). We are based in Türkiye, so the people who administer the service are outside the EEA.
Supabase, RevenueCat, Railway and Apple are international companies, so data may be processed outside the EEA or outside Türkiye. Where that happens we rely on the data processing agreements those providers offer, which incorporate the European Commission's standard contractual clauses or an equivalent safeguard. The only data that ever crosses a border here is an anonymous identifier and a subscription status — never a name, an address, or a payment detail, because we don't have any.
How long we keep it
- Room data: for the length of the room. Minutes or hours, then gone.
- The anonymous identifier and your 18+ flag: until you delete your account. If you delete the app without deleting your account, the record stays — but it still contains nothing that identifies you.
- The Premium record: for as long as your account exists — that's what lets a lapsed subscription be restored if you resubscribe. It goes the moment you delete your account.
Deleting everything
Open Account & data in the app and choose to delete. We ask you to confirm twice, because it's permanent — and then your anonymous account is erased immediately, along with the 18+ flag and the Premium record attached to it. There is no grace period, no soft delete, and no backup copy we hold onto for our own use.
You can also ask us to delete it by writing to support@playafterdark.app. Because we hold nothing that identifies you, we can only act on that request if you give us the anonymous identifier from your device — otherwise there is no way for us to tell which record is yours. The in-app option is faster and needs nothing from you.
Deleting your account does not cancel your subscription — Apple owns billing, so cancel it in your App Store account settings.
Your rights
If you're in the EU or the EEA, the GDPR gives you the right to access the data we hold about you, to have it corrected, to have it erased, to restrict or object to how we use it, and to receive a copy in a portable form. If you're in Türkiye, KVKK Article 11 gives you an equivalent set: to learn whether your data is processed, to request information about it, to have it corrected or erased, and to object to results produced by automated analysis.
To exercise any of them, write to support@playafterdark.app. We answer within 30 days.
One honest limitation, which is the flip side of the whole design: we cannot identify you. We hold no email, no name, no device fingerprint — nothing that lets us match a person to a record. Both the GDPR (Article 11) and KVKK recognise this: where a controller genuinely cannot identify a data subject, it isn't required to obtain extra information just to be able to. In practice this means we can only act on a request if you send us the anonymous identifier from your device, and the in-app delete option is the surest route to the same result.
If you think we've handled your data badly, please tell us first — but you're also entitled to complain to your local data protection authority in the EEA, or to the Personal Data Protection Board (KVKK) in Türkiye.
Adults only
Afterdark is for adults. You must be 18 or older to use it, and the app asks you to confirm that. We do not knowingly collect data from anyone under 18, and we don't build the app for anyone under 18 in the first place. If you believe a minor has used the app, write to us and we'll erase the record.
Changes to this policy
If what we do with data changes, this page changes with it and the effective date at the top moves. For anything material — a new processor, a new category of data — we'll say so in the app rather than hoping you check the website. We won't quietly start collecting something this page says we don't.
Contact
Ozgur Cinkilic, individual developer, Türkiye.
support@playafterdark.app
Questions about the game itself are welcome at the same address. See also the terms of use.