Legal
Privacy Policy
Last updated: 20 June 2026
This Privacy Policy explains how Boffo Battle ("Boffo Battle", "we", "us") collects, uses, and protects information when you use boffobattle.com and related services (the "Service"). Boffo Battle is operated by Roger Tinch as an individual. By using the Service you agree to the practices described here.
Information we collect
We collect only what we need to run the game:
- Account information. When you sign up with email and password, we collect your email address. If you sign in with Google, we receive your email address, name, and profile picture from Google. We never see or store your Google password.
- Gameplay data. Your username, card collection, decks, match history, ratings, and in-game balances (Credits and Stardust). This is what makes your account yours.
- Product analytics. We use PostHog to understand how players move through the game. Analytics events are tied only to your account's anonymous user ID — never your email or name — and are limited to a small set of milestone events (for example, signing up or completing a battle). We do not run session recording, and we do not capture your keystrokes or page content.
- Error diagnostics. We use Sentry to capture technical error reports so we can fix bugs. These reports may include your anonymous user ID, browser type, and a technical stack trace. They are not used to profile you.
- Cookies and local storage. We use a session cookie to keep you signed in and your browser's local storage to hold game state. We do not use third-party advertising or tracking cookies.
How we use your information
- To create and maintain your account and save your progress.
- To operate gameplay features such as collections, decks, battles, and rankings.
- To understand and improve how the Service is used.
- To diagnose, fix, and prevent technical problems.
- To protect the Service against abuse and to comply with the law.
Service providers
We share information with a small number of trusted providers strictly to operate the Service:
- Supabase — authentication, database, and realtime hosting.
- Fly.io — application hosting.
- Google — sign-in, only if you choose Google sign-in.
- PostHog — anonymous product analytics.
- Sentry — error diagnostics.
To display cards, we fetch movie and person data from The Movie Database (TMDB) and use Anthropic's Claude to rewrite some descriptive text. We do not send your personal information to TMDB or Anthropic. We do not sell your personal information.
Data retention
We keep your account data for as long as your account is active. If you ask us to delete your account, we will remove your personal data within a reasonable period, except where we must retain limited records to comply with the law or resolve disputes.
Your rights
You can request access to, correction of, or deletion of your personal data at any time by contacting us at the address below. Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA; we honour these requests regardless of location.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.
Security
We rely on industry-standard providers and reasonable safeguards to protect your data. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above. Continued use of the Service after changes take effect means you accept the updated policy.
Contact
Questions or requests about this policy? Email ret@tinch.co.