Back to Balooza

Privacy, in plain language.

Balooza works without a visible account. Local play stays on your phone. Online features use only the information needed to work safely.

Effective September 23, 2026Kevin Araujohello@balooza.app

Who is responsible

Balooza is made and operated by Kevin Araujo in Alberta, Canada. Send privacy questions or requests to hello@balooza.app.

Information Balooza handles

Local play

Built-in and saved Decks, local players, game preferences, and recent activity can be stored on your device. Balooza does not upload your local Deck library for account backup or cloud sync. Removing the app can remove this local information.

Invisible service identity

Balooza can create an anonymous Supabase service identity when you use AI generation or private feedback. There is no profile or visible login. The identity helps secure requests, apply daily allowances, prevent abuse, and delete linked server data. It is not used for advertising or joined to tip payments.

Direct Deck sharing

A new Deck you share with a friend is carried in a self-contained link or file. Balooza does not publish the Deck, add it to a public feed, or retain it on a Deck-sharing server. The receiving app validates the Deck and asks before saving an independent local copy.

Older opaque share links made during testing can remain temporarily readable for compatibility. The current app does not create new hosted shares.

Support and feedback

If you send in-app feedback, Balooza privately stores the category and message in Supabase with the app version and build, selected Balooza language, device locale, platform, screen context, time, and triage status. The anonymous service identity helps secure, rate-limit, and deduplicate submissions.

You can type an email address if you want a reply. If you use email support, your address and the information you include are used to answer you. Feedback text and contact details are not sent to product analytics.

AI generation and recent information

When you ask Balooza to make a Deck, the request and generated content pass through the Balooza service and OpenRouter to Meta’s Muse Spark 1.3 Contributor model. Meta may use prompts and generated content to improve its products. One daily Deck can also send a search query to Exa for recent information. Do not include names, contact details, secrets, or other sensitive information in a Deck request.

These providers can process request content and technical metadata under their own policies. Review the Muse Contributor model details, OpenRouter Privacy Policy, OpenRouter data collection guide, and Exa Privacy Policy.

Optional tips

The separate Support Balooza webpage can open a Stripe-hosted payment page. Stripe processes the payment and can collect an email for the payment and receipt. Kevin may use that email for a personal thank-you. Balooza does not copy the email or payment into Supabase, connect it to your service identity, or unlock anything in the app.

Technical information

Cloudflare, Fly.io, Supabase, Apple, Google, and the Balooza service can process technical information needed to deliver and secure the service. This can include IP address, device or browser type, request time, route, response status, service errors, and coarse network location. Balooza has no targeted advertising.

Analytics and crash reports

Apple and Google can provide crash reports and diagnostics under your device settings and their policies. Balooza can keep bounded operational logs for security, reliability, abuse response, and AI cost control. Product analytics, if enabled, do not receive Deck text, feedback text, contact details, or payment data.

Why information is used

  • Provide AI Deck generation and private feedback.
  • Keep the service secure, reliable, family-safe, and within its operating budget.
  • Answer support requests and comply with legal duties.

Providers, transfers, and retention

Balooza uses Apple and Google for app distribution, Supabase for anonymous authentication and private feedback, Fly.io for the service, OpenRouter and model providers for AI generation, Exa for optional web research, Cloudflare for the website and network, and Stripe for optional website tips. These companies can process information in Canada, the United States, and other countries where they or their providers operate.

Server data is kept only while needed to provide the feature, enforce bounded abuse controls, answer support, meet legal duties, or maintain reliable backups. Providers keep technical and payment records under their own retention rules.

Delete your server data

If this installation has an anonymous service identity, Balooza Settings shows Delete Balooza Data. Choose it and confirm to remove that identity and linked Balooza server data. It keeps your local Decks and preferences by default. The data deletion guide explains the steps.

You can ask to access, correct, or delete information connected to you. Rights vary by location. Kevin may need enough information to verify a request without exposing another person’s data.

Children

Balooza is made for general audiences. Children under 13 should not send personal information through Deck prompts, feedback, support email, or shared Decks. A parent or guardian who believes a child provided personal information should contact Kevin.

Security and changes

Balooza uses access controls, encrypted network connections, limited service credentials, and provider security controls. No online system can guarantee perfect security. Material changes will be posted here with a new effective date when notice is required.

Balooza

Balooza
Made with care by Kevin Araujo.

PrivacyTermsSupportSupport Balooza
ENPTES