Daily Mahj/Privacy Policy
Privacy Policy
Last updated: August 24, 2026
1. Scope and operator
Daily Mahj is operated by Sam Ships, an independent app studio based in Colorado, United States (“Daily Mahj,” “Sam Ships,” “we,” “us,” or “our”). This policy explains how information is handled when you use the Daily Mahj mobile app, optional account, Friends and leaderboard features, subscriptions, support, and related services (collectively, the “Service”).
You can play without creating an account. Core game progress is stored locally. Limited technical information is still processed by services used for app distribution, updates, and subscription entitlement checks, as described below.
2. Privacy at a glance
- Core gameplay does not require a name, email, or account.
- Game progress, puzzle history, settings, cosmetics, and virtual currency are primarily stored locally on your device.
- We do not use advertising SDKs or Apple's advertising identifier, sell personal information, or track you across other companies' apps or websites for advertising.
- Apple and RevenueCat process limited purchase and subscription data. RevenueCat uses a random anonymous App User ID that we do not link to the optional Daily Mahj account.
- If you choose Sign in with Apple, Supabase stores the account, profile, friendship, leaderboard, and streak data needed for those features.
- Production builds contact Expo to check for app updates.
3. Information stored on your device
Daily Mahj stores information locally, including:
- Puzzle progress, completed boards, results, scores, turn counts, and gameplay history.
- Streaks, streak savers, claimed rewards, referral rewards, and related dates.
- Virtual coins or chips, owned and selected tile themes, avatars, cosmetics, and collection progress.
- Tutorial completion, difficulty, display choices, and settings.
- A local display name, avatar, and an Apple-provided email or private relay address after optional account sign-in.
- Cached subscription status, a random RevenueCat identifier, and Supabase session credentials when applicable.
Information remains local unless a feature described here transmits part of it. Qualifying gameplay history can be uploaded when you first sign in, and streak information can synchronize while signed in. Deleting the app generally removes ordinary local app data, subject to Apple backups, purchase history, Keychain behavior, and system policy.
4. Subscriptions and purchases
Daily Mahj Pro uses Apple in-app purchase. Apple handles your payment method and Apple Account; we do not receive your complete card number. RevenueCat processes the purchased product, transaction and receipt data, purchase and renewal dates, expiration or cancellation status, storefront, currency, entitlement, a random anonymous App User ID, and limited technical information needed for validation, fraud prevention, restoration, subscription analytics, and troubleshooting.
Daily Mahj does not call RevenueCat's login or identify APIs. We do not intentionally link its anonymous identifier to your optional Daily Mahj account, display name, or email. RevenueCat's policy is at revenuecat.com/privacy.
5. Optional account, profile, Friends, and leaderboards
An account is optional. When you choose Sign in with Apple, Apple and Supabase may process an opaque account ID, the name Apple provides on first authorization, an email or private relay address, authentication tokens, session information, and account-creation metadata.
Our Supabase database stores:
- Your account ID, display name, avatar, and generated invite code.
- Accepted friendships and their creation dates.
- Qualifying results such as course date, score relative to par, completed boards, and streak information.
- Current and longest streaks, last completion date, streak savers, claimed milestones, and record timestamps.
Your display name, avatar, invite code, and relevant leaderboard results are visible to accepted Friends. A signed-in player who enters your exact invite code may receive the profile information needed to connect. Treat invite codes as shareable information, not passwords. Supabase's policy is at supabase.com/privacy.
6. Updates and technical service information
Production versions use Expo Application Services to check for and download compatible updates. Requests can include project, channel, runtime, app and update versions, platform information, request headers, and the IP address visible to the service. Expo uses this information to select and deliver updates, secure the service, and maintain operational records. Expo's policy is at expo.dev/privacy.
Apple, RevenueCat, Supabase, Expo, and ordinary internet infrastructure may automatically process connection data such as IP address, request time, response status, app or SDK version, platform, locale, and security events. Daily Mahj has no general behavioral analytics or third-party crash-reporting SDK. RevenueCat provides purchase and subscription analytics as described above.
7. Information you choose to share or send
- System sharing: Scorecard text or images are created locally and sent only to the recipient or app you choose in the system share sheet. The destination handles the material under its own privacy practices.
- Support: If you email us, we receive your address, message, attachments, and details you choose to include. Gmail support mail is processed by Google. Do not send passwords, authentication tokens, or unnecessary private data.
8. Information Daily Mahj does not collect
Daily Mahj does not request your contacts, location, camera, photo library, microphone, health data, or advertising identifier. It has no open chat and does not collect an address book or full payment-card details.
9. How we use information
- Provide gameplay, preserve local progress, and remember settings.
- Authenticate optional accounts and maintain sessions.
- Provide profiles, invite codes, friendships, leaderboards, streaks, and rewards.
- Validate, restore, and analyze Daily Mahj Pro subscriptions.
- Deliver compatible updates and maintain reliability.
- Prevent fraud, abuse, cheating, unauthorized access, and disruption; provide support; enforce our Terms; and comply with law.
10. When we disclose information
We disclose information only as reasonably needed to:
- Apple for distribution, Sign in with Apple, purchases, refunds, subscription management, and platform services.
- RevenueCat for validation, entitlements, restoration, fraud prevention, and subscription analytics.
- Supabase for optional authentication, profiles, Friends, leaderboards, streaks, and database services.
- Expo for over-the-air updates and operational security.
- Google for support email hosting.
- Advisers, authorities, or transaction participants when necessary to comply with law, protect safety and rights, investigate misuse, or complete a financing, reorganization, sale, or transfer.
We require providers processing personal information for us to protect it consistently with their agreements, this policy, and applicable law. We do not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or disclose it to data brokers.
11. Retention
- Local information remains until removed through available controls, app storage is cleared, or the app is deleted, subject to Apple backup and system behavior.
- Optional account information remains while the account exists. The in-app deletion flow deletes the Supabase auth user and cascades to its profile, friendships, shared results, server streaks, and milestone claims.
- Apple and RevenueCat retain purchase data as needed for entitlement, fraud prevention, disputes, tax, accounting, and law. Account deletion does not cancel a subscription or erase their independent purchase records.
- Providers retain update and operational records under their configuration, agreements, and legal obligations. Support messages remain until resolved and for a reasonable recordkeeping period.
Backups and records already scheduled for deletion may persist for a limited period before being overwritten or isolated from ordinary use.
12. Your choices and rights
You can:
- Play without an account and use Apple's Hide My Email option.
- Edit your display name and avatar or remove Friends.
- Sign out or permanently delete an account in Settings.
- Manage or cancel Daily Mahj Pro through Apple.
- Delete local data by deleting the app, subject to backups.
- Request access, correction, deletion, or a portable copy of information we control by emailing support@samships.app.
Depending on your location, you may also have rights to restrict or object to processing, withdraw consent prospectively, appeal a privacy decision, use an authorized agent, or complain to an authority. We may reasonably verify requests. We will not discriminate for exercising a privacy right. We do not sell data or use it for targeted advertising, so no sale or targeted-advertising opt-out is required.
13. Account deletion
Use Settings → Account → Delete Account. This permanently deletes the Supabase account and associated cloud profile, Friends, leaderboard, streak, and milestone records. Local history remains unless you separately delete the app or clear storage.
Account deletion does not cancel Daily Mahj Pro. Cancel through Apple if you do not want renewal. If you cannot access the in-app control, email support@samships.app. We may need to verify the account.
14. International legal bases and transfers
Where a legal basis is required, we process information to perform our contract and provide requested features; with consent where required; for legitimate interests in operating, securing, supporting, and improving the Service; and to comply with law. Consent can be withdrawn prospectively. Daily Mahj and its providers operate in the United States and other countries. Where required, we use contractual or other recognized transfer safeguards.
15. Children
Daily Mahj is a general-audience puzzle game and is not directed to children under 13. We do not knowingly collect personal information directly from a child under 13. Optional account and Friends features are not intended for a child under 13 to use independently. Contact us if you believe a child submitted information without authorization.
16. Security
We use safeguards appropriate to the information, including HTTPS, Apple authentication, authenticated sessions, row-level database rules, restricted backend functions, and deletion cascades. No system is completely secure. Protect your device, Apple Account, and invite code, and contact us if you suspect unauthorized access.
17. Changes to this policy
We may update this policy as Daily Mahj, providers, or law changes. We will post the revision here and update the date. If required, we will provide additional notice or request consent before a material change applies.
18. Contact
Questions, privacy requests, or complaints may be sent to support@samships.app.
Sam Ships
Colorado, United States
Account deletion details are also available on the Daily Mahj support page.