Tickle the Pig — Privacy Policy
Effective date: 2026-07-18
This is the privacy policy for Tickle the Pig (the "App"), operated by Brian Broeking ("we", "us", "our"). We try to keep this short and plain — no dark patterns, no jargon for jargon's sake. This policy describes what we collect, why, who we share it with, and the controls you have. It is not legal advice.
Who we are
Tickle the Pig is a single-developer mobile game built on Expo / React Native with a Supabase backend. The operator and data controller is Brian Broeking. You can reach us at brian@broeking.dev. The App is distributed through Apple's App Store / TestFlight and Google Play.
What we collect
You need an account to play, so some collection is unavoidable. Here's everything, by category.
Account and identity
- Sign in with Apple: when you log in with Apple, we receive a stable Apple user identifier (which becomes your account ID) and, at first sign-in, the name and email Apple shares with us. If you use Apple's Hide My Email feature, the email we see is an anonymized Apple relay address, not your real one. You can choose not to share your name.
- Email and password sign-up: if you create an account with an email address and password instead of Apple, we store your email address and a securely hashed version of your password in our authentication system. We never store your password in readable form.
- Username and display fields: the username you choose (with a short numeric tag to keep names unique), and any name or avatar passed along from Apple at sign-in. Your username is public — it appears on leaderboards, in friend lists, and in crews — so please don't put personal information in it.
Gameplay and economy
- Game progress: your tickle counts, lifetime score, your balance of in-game currency ("snouts"), happiness state, active days, and similar play stats.
- Cosmetics and progression: the hats, titles, glasses, masks, backgrounds, auras, and other cosmetic items you own and have equipped; your achievements; your Season Pass and battle-pass progress; bounty, daily, and onboarding state.
- Alignment / morality state: a behavioral score derived from how you play, which places you in an "angel / neutral / goblin" band shown on leaderboards.
- World Cup allegiance: if you choose a country/flag allegiance for in-game events, we store that choice (it locks once selected).
Social data
- Friends ("the Sounder"): who you've sent or accepted friend requests with, and the status of those connections.
- Player-to-player interactions ("rituals"): blessings and curses you send or receive — who, what kind, when, and any small in-game currency effect.
- Trades and transfers: Tickle Trade requests and outcomes between players.
- Referrals: your referral code, which account invited you, and which accounts you've invited — used to credit referral rewards.
- Other social activity: barn visits, buried/dug truffles, community item drives and donations, leaderboard pass events, and your in-app notification history.
- Mud Wars crews: crew names (user-chosen), membership, invitations, ratings, and per-user battle contributions.
Moderation data
- Blocks: the list of accounts you've blocked.
- Reports: if you report another player, we store who reported whom and your free-text reason. Reports are reviewed by us and are not shown to other players.
Purchases
- Subscription and purchase status: if you buy something through Apple In-App Purchase or Google Play Billing, we learn which product you bought and whether your entitlement (e.g., Slop Club membership or a Season Pass) is active. We do not see your card number or store password — Apple or Google handles payment. Purchase records held by our payments partner (RevenueCat) are keyed to your account ID.
Notifications
- Push token: if you allow push notifications, we store an Expo push token (a device-linked identifier) and your permission status so we can send you alerts (for example, when a friend sends you a Tickle Trade). The token, along with the notification's title, body, and a small data payload, is transmitted to Expo's push service for delivery.
Diagnostics
- Crash and error reports: in production builds, we use Sentry to capture crashes and errors. This includes diagnostic context such as device model, OS version, app version, stack traces, breadcrumbs, and a small sample of performance traces. We attach your account ID and username to these events so we can debug problems tied to a specific account.
On your device
- Local storage: your login session, a cached copy of your push token, and a handful of UI flags (e.g., whether you've seen onboarding) are stored on your device. These are cleared when you sign out or delete the App.
We do not collect: your location, contacts, photos, microphone audio, or advertising identifiers. We do not use any advertising or third-party analytics SDKs.
How we use it
- Run the game — show your stats, leaderboards, friends, crews, and social interactions.
- Operate the in-game economy and deliver the cosmetics and rewards you earn or buy.
- Validate purchases and unlock the right entitlements (through RevenueCat and the store that distributed your copy of the App).
- Send the push notifications you opt into.
- Keep the App working — diagnose and fix crashes and errors.
- Moderate the community — review reports, enforce username and conduct rules, and act on abuse.
- Run internal, operator-only analytics to understand sign-ups and overall game health.
We do not use your data for advertising or behavioral profiling, and we do not sell it.
Who we share it with
We rely on a small number of service providers to run the App. Their privacy policies apply alongside this one. We never sell your data.
- Supabase — our database, authentication, and backend hosting. Nearly all of your account and gameplay data lives here. https://supabase.com/privacy
- Apple — Sign in with Apple, App Store / TestFlight distribution, and payment processing for purchases made on iOS. https://www.apple.com/legal/privacy/
- Google — Google Play distribution and, when Android purchases are enabled, payment processing. https://policies.google.com/privacy
- RevenueCat — in-app purchase and subscription validation. When purchases are enabled, RevenueCat receives your account ID, the store transaction it validates with Apple or Google, product identifiers, and entitlement status. https://www.revenuecat.com/privacy
- Sentry — crash and error reporting, including the diagnostic data and the account ID + username described above. https://sentry.io/privacy/
- Expo / EAS — app build infrastructure and push-notification delivery. When you receive a push, Expo's service handles your device push token and the notification content (which may include another player's username and an in-game amount) and forwards it to Apple or Google for delivery. https://expo.dev/privacy
Your account ID is a single identifier that links your records across Supabase, RevenueCat, and Sentry. We may also disclose information if required by law, to protect our rights or users' safety, or as part of a business transfer — but we will never sell your personal data.
Data retention
We keep your account data for as long as your account exists. When you delete your account, your data is removed from our systems as described below. Note that some records held by our service providers may persist according to their own retention policies — in particular, purchase history at RevenueCat (tied to your account ID) and crash/error events at Sentry are not erased by our in-app deletion and remain subject to those vendors' policies. On-device data is cleared when you sign out or delete the App.
Your rights
- Access and export: ask us and we'll send you a copy of the data we hold about you, in a portable format.
- Delete your account: you can delete your account yourself from within the App, or request deletion by emailing brian@broeking.dev. Include the email address or username associated with your account so we can verify the request. Deletion hard-deletes your authentication record and cascades to remove the related rows we hold — your profile, friendships, blessings and curses, trades, blocks, crew memberships, owned cosmetics, achievements, Season Pass progress, and the rest of your gameplay data. Some transaction, diagnostic, security, or fraud-prevention records held by Apple, Google, RevenueCat, or Sentry may be retained under those providers' policies or where legally required. (Note: "cleansing" a curse inside the game is a gameplay action, not a data-deletion request.)
- Correct your data: you can change your username and other profile fields in the App, or contact us for help.
- Opt out of leaderboards: you can hide yourself from public in-app leaderboards. (This does not remove your data from our internal, operator-only analytics.)
- Manage notifications: turn push notifications on or off in your device settings; signing out also clears your stored push token.
- Cancel a subscription: use your Apple ID subscription settings on iOS or Google Play subscription settings on Android. We don't gate this.
Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA, including the right to object to or restrict certain processing and the right to lodge a complaint with your local data-protection authority. To exercise any right, email us at brian@broeking.dev.
Children
Tickle the Pig is rated 4+ for content (it's a cartoon pig), but it is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has created an account or provided us personal information, contact us at brian@broeking.dev and we'll delete it. In line with COPPA, if we learn we've collected such data, we will remove it promptly. A parent or guardian should consent to and supervise any minor's use of the App, including any purchases.
Subscriptions and auto-renewal
Tickle the Pig may offer purchases through Apple In-App Purchase on iOS and Google Play Billing on Android:
- Slop Club — an auto-renewable subscription (monthly or yearly). It renews automatically at the price and interval shown at the time of purchase unless you cancel before renewal. You can manage or cancel it from the subscription settings for the store where you purchased it.
- Season Pass — a separate purchase for each season that unlocks that season's premium reward track. It's a consumable, bought again each new season, and does not auto-renew.
Apple or Google processes all payments; we never see your payment-card details or store password. Our virtual currency ("snouts") and virtual items have no real-world or cash value and are not redeemable for money. Refund requests are handled under the policies of the store where the purchase was made.
Security
We protect your data with industry-standard measures: encrypted connections (HTTPS/TLS), hashed passwords, and database-level access controls (row-level security) that limit what each account can read or write. Payment data is handled entirely by Apple or Google and never touches our servers. No system is perfectly secure, but we take reasonable steps to safeguard your information and we limit the data we collect in the first place.
International users and app stores
The App is distributed and billed through Apple or Google under the applicable store's standard terms, and our service providers (Supabase, RevenueCat, Sentry, Expo) may process and store data on servers located in the United States and other countries. If you use the App from outside the United States, you understand that your information may be transferred to, stored, and processed in the U.S. and other jurisdictions whose data-protection laws may differ from your own. By using the App you consent to that transfer and processing.
Changes to this policy
We'll update this page if anything material changes, and we'll revise the effective date at the top. For significant changes we may also notify you in the App. Continuing to use the App after an update means you accept the revised policy.
Contact
Questions, requests, or concerns about your privacy: brian@broeking.dev.