Privacy Policy
Belao Forest Golfer
This policy explains how this application handles information and how to contact us about privacy.
Information we process
Belao Forest Golfer stores your saved round, ball state, completed holes, best scores, assisted-hint status, daily results and sound, music, haptic and reminder preferences locally on your iPhone. Daily hole configurations are cached locally. For online content, the backend automatically creates a random installation UUID and a random secret. The UUID and secret are kept in the device Keychain; the server stores the UUID, a SHA-256 secret hash, creation time and rolling request counters in PostgreSQL. No name, email, password, player score or game history is sent to the backend. Railway hosting receives network requests, including IP addresses and ordinary technical request information. The application has no analytics, advertising or third-party tracking SDKs.
How we use information
Local data let you resume a round, keep personal bests, unlock courses and remember preferences. The installation credential authorizes this installation, supports deletion of its own server record and limits requests. The backend stores authored hole configurations and supplies the daily challenge and individual hole content. Optional notifications remind you about the daily challenge locally; they do not send your progress to a messaging service. Technical hosting information supports delivery, security and diagnosis of service failures.
Service providers and sharing
The backend and PostgreSQL database run on Railway, which processes hosted data and technical network information as the infrastructure provider. Our server logs startup and limited error codes and generated request identifiers; it does not deliberately log installation secrets, player scores or request bodies. Railway may keep infrastructure and network logs under its own service practices. We do not sell player information or share it with advertising, analytics, social sign-in or email-delivery services. Requests from this app go to its configured Railway HTTPS service; the public policy page can also be visited directly.
Data retention
Local progress remains until you reset it, remove the app or remove it through device storage controls. Daily content is reused only for the current UTC day and for up to 24 hours after it was fetched; subsequent fetches replace the cache. Server installation records and counters remain until deletion is requested. Rolling rate-limit counters are overwritten as their request windows advance; no separate request-history table is maintained. Authored game content remains as part of the service. We have not established a fixed retention period for Railway infrastructure logs or provider backups and do not claim that deleting a live record immediately removes copies from every provider backup.
Deleting your information
Settings offers Reset Local Progress, with confirmation, to clear lantern progress, best scores, the saved round and daily results. Preferences are retained. Delete Server Installation Data authorizes deletion using this device credential and removes this installation row, including its secret hash and request counters, from the live database; after a successful response the app removes the local credential and daily cache. A new installation may be created when online content is requested again. Other installations are unaffected. Uninstalling alone does not contact the server and Keychain items may remain under iOS behavior. Device or infrastructure backups may retain earlier copies according to the applicable provider settings. If you lose the credential, we cannot authenticate a request as that installation or restore its data.
Permissions and your choices
The game does not request location, camera, microphone, contacts or photo-library access. Local notification permission is optional and requested only when you enable the Daily Hole Reminder in Settings. Turning that reminder off cancels its pending notification. You can also withdraw notification permission in iPhone Settings; the game remains playable. Sound and haptic controls are local preferences. Ordinary network access is used for daily content and installation deletion, with an offline built-in challenge when the service cannot be reached.
Your privacy rights
You can inspect your progress in the app and use its local-reset and server-deletion controls. Depending on your location, you may have rights to access, correct, delete or restrict processing of personal information. Contact cuthbert.brampton@icloud.com for privacy questions or to exercise applicable rights. This is a public privacy contact only; the app has no account or email-delivery feature. Please do not send installation secrets. We may need enough non-secret information to understand a request; without the device credential we cannot identify you as the owner of a random installation record.
Security
Online requests use HTTPS. Each installation uses a separate random secret stored in the iOS Keychain with device-only accessibility; the server keeps only its hash and checks both the UUID and secret before content requests or deletion. Database credentials stay on the server, which uses its Railway database connection. Rate limits and bounded request and database timeouts reduce abuse. There is no shared installation credential embedded in the app. Local progress is stored in the app sandbox with atomic writes. No system can guarantee absolute security, and the game does not promise recovery after the installation secret is lost.
Children’s privacy
The game is designed for a general casual audience, including older teens and adults, rather than specifically for children under 13. It has no accounts, chat, advertising or purchases. We do not ask players for an age, identity or contact details. If you believe a child has provided personal information to us outside the ordinary anonymous service operation, contact cuthbert.brampton@icloud.com so we can assess the request.
Changes to this policy
We may update this policy when the game or its processing practices change. The current policy is available through Settings and at the public /privacy page, with its effective date displayed. A changed policy will describe the actual practices in the released app and deployed backend. Review this page periodically; material changes will be reflected in the effective date and app information as appropriate.