Privacy, in plain language.
Balooza can be played locally without an account. Cloud, community, sharing, and AI features use only the information needed to work.
Who is responsible
Balooza is made and operated by Kevin Araujo in Alberta, Canada. Questions and privacy requests can be sent to hello@balooza.app.
Information Balooza handles
Local play
You can browse included decks and play local rounds without creating an account. Local players, game preferences, generated deck copies, and recent activity may be stored on your device. Removing the app can remove this local information unless it has already synced to an account.
Accounts and cloud features
If you use Sign in with Apple, Balooza receives a unique Apple account identifier. Apple may also provide your name and an email address, including a private relay address, when you choose to share them. Balooza stores an internal user ID, profile preferences, cloud decks, saves, reports, blocks, sharing records, and your access entitlement in Supabase.
Community content
Decks you publish are visible to other Balooza users. A published deck can include its title, description, language, cards, creator identifier, and moderation state. Reports and blocks are visible only to the people and systems needed to operate safety controls.
Support
If you email Kevin, the message, your email address, and any information you include are used to answer you and resolve the issue.
AI generation and recent information
When you ask Balooza to make a deck, the request and the resulting deck content pass through the Balooza service and OpenRouter to a selected model provider. Requests that need current information can also send an informational search query to Exa. Do not include names, contact details, secrets, or other sensitive personal information in a deck request.
OpenRouter and model providers can process request content and technical metadata under their own settings and policies. Depending on the selected provider, inputs or outputs may be retained or used to improve services. Exa states that query data can be used to improve its products and technology. You can review the current OpenRouter Privacy Policy, OpenRouter data collection guide, and Exa Privacy Policy.
Technical information
Cloudflare, Fly.io, Supabase, Apple, and the Balooza service can process technical information needed to deliver and secure the service. This can include IP address, device or browser type, request time, route, response status, service errors, and coarse network location. Balooza does not use this information for targeted advertising.
Analytics and crash reports
The friends-and-family build does not send Balooza product analytics to a third-party analytics project. Apple can provide TestFlight crash reports and diagnostic information according to your Apple settings and Apple’s policies. Balooza can also keep short operational logs for security, reliability, abuse response, and AI cost control. If product analytics are enabled in a future public release, this policy and the App Store privacy answers will be updated first.
Why information is used
- Provide local play, accounts, cloud sync, deck generation, publishing, sharing, reports, and blocks.
- Keep the service secure, reliable, family-safe, and within its operating budget.
- Answer support requests and act on community reports.
- Comply with legal obligations and protect people, Balooza, and its services.
Service providers and transfers
Balooza uses Apple for sign-in and TestFlight, Supabase for authentication and cloud data, Fly.io for the Balooza service, OpenRouter and its model providers for AI generation, Exa for optional web research, and Cloudflare for the website and network services. These companies can process information in Canada, the United States, and other countries where they or their providers operate.
Retention
Account data is kept while your account is active. Public decks and shares are kept until they are removed, the account is deleted, or they are no longer needed to provide the feature. Reports, moderation records, and limited security records can be retained after deletion when needed to prevent abuse, resolve disputes, meet legal duties, or preserve the safety of other users. Service providers keep technical records under their own retention rules.
Delete your account and data
In Balooza, open Settings, choose your account, then choose Delete Account. Confirm the request to remove the account and associated cloud data. You can also read the account deletion guide or email hello@balooza.app if the in-app control is unavailable.
You can ask to access, correct, or delete your information. Depending on where you live, you can also have rights to object, restrict processing, withdraw consent, or complain to a privacy regulator. Kevin may need to verify that the request belongs to you.
Children
Balooza is made for general audiences. Children under 13 must not create an account, publish decks, or send personal information to Balooza. A parent or guardian who believes a child provided personal information should contact Kevin so it can be removed.
Security and changes
Balooza uses access controls, encrypted network connections, limited service credentials, and provider security controls. No online system can guarantee perfect security. Material changes to this policy will be posted here with a new effective date before the changed practice begins when notice is required.