Privacy policy

Effective 2026-10-05. Responsible operator: Hamza Hassan, an individual operator based in Vancouver, British Columbia, Canada. Contact: support@maidenless.io.

What we process

Clerk handles sign-in email, credentials, verification and sessions. The only account identity details we ask you for are your username and email. We do not ask for a first name, last name or country, and bios are disabled. Maidenless links an authentication identifier to your fictional username and stores queen customization, game activity, results, currency and inventory, text submissions, reports, blocks and policy acceptance. We do not request your GPS location. If you enable alerts, we store a push token and device timezone offset. Cloudflare and our providers process technical connection and service logs, which can include IP addresses. Login email is not displayed to other players. Private email is still personal information.

Why

We use account data to authenticate you; game data to run matches, rankings and queen ownership; submitted words to show content you choose to publish; tokens to deliver requested alerts; and safety records to prevent abuse, investigate reports and handle appeals. We use proportionate technical safeguards and limit operator access. We do not sell personal information or use it for advertising profiles.

Who receives it

Your handle, public profile and Wall text may be visible to players. Battle and recovery messages reach their participants. Service providers include Clerk for authentication, Cloudflare for hosting/storage/security, OpenRouter and OpenAI for automated text/report review, and Expo with Apple or Google for opted-in push delivery. We send necessary text and context through OpenRouter to OpenAI after your explicit permission; we do not attach your login email, credentials or full account history. A malicious message may itself contain private information: do not put personal details in game text. API content is not used to train OpenAI models by default. Providers may process data outside Canada, including in the United States, under their applicable terms and safeguards.

Retention and deletion

Game/account data stays while your account is active. Raw automated text-review records expire after 30 days. Closed report evidence is retained for 90 days after resolution for appeals and abuse prevention; unresolved reports stay until investigated. Batch inputs and results are deleted from OpenRouter after processing; its automatic retention limit is 30 days. Upstream provider records follow their retention controls. After a verified deletion request, access closes and a retryable cleanup removes account details and submitted words from active stores, caches and archives, normally within 30 days. Authentication is deleted through Clerk. Anonymous game/ownership facts remain to preserve other players’ records. A one-way identity fingerprint prevents late sessions from recreating a closed account. Limited safety evidence and required legal records may outlast account closure. Provider security logs/backups follow their retention controls; deleted data must not be restored to live service.

Your choices

You may block/report players, turn off notifications, or delete the account. Contact support@maidenless.io to request access, correction, export, restriction or an appeal, or to withdraw permission for automated text review. Withdrawal stops further optional text processing; it does not undo processing already completed. We may verify control of the account before disclosing or deleting data. Depending on where you live, you may also complain to your privacy regulator. The app is intended for adults; contact us if a person under 18 is using it.