Halloway

Privacy

Halloway is local-first. You can play all three hunts with no account: your progress lives only on this device. An account is optional — you only create one if you want your progress + purchases synced across devices.

Playing without an account

Your progress is saved only in this device's local storage, and answers are checked on-device against built-in hashes. On the web and the installable PWA there are no tracking cookies, no advertising identifiers, no third-party analytics or crash SDKs, and no data sold — ever. The App Store and Google Play apps carry one narrow exception, ad-install measurement, described in the next section.

The one thing we collect anonymously is a small set of aggregate funnel counts — e.g. how many people finished the Foyer, opened a door, or saw the unlock screen — to tune the puzzles. These beacons carry no account, no device identifier, and no stored IP address (your IP is used only transiently for rate-limiting, never recorded with the event), so they can't be tied to you. Turn them off entirely in Settings → Privacy.

The App Store and Google Play apps

We run ads on Meta (Facebook and Instagram) to tell people Halloway exists. To measure whether those ads lead to an install or purchase, the iOS app from version 1.0.3 and the Android app from version 1.0.8 include Meta's SDK. The SDK can report that the app was installed or opened and that an in-app purchase happened, together with an app/device identifier, IP address, and basic device details such as model, OS version, and language. Meta may link those details with information from other companies for ad measurement and targeting. Your Halloway account, email, progress, and answers are never sent to Meta, and we do not sell personal data.

On iPhone and iPad, Halloway asks for permission through Apple's App Tracking Transparency prompt before the Meta SDK starts. If you deny or restrict permission, Halloway does not initialize the Meta SDK or send it app events. If you allow permission, Meta App Events and Apple's advertising identifier (IDFA) are enabled for the measurement described above. You can change that choice later in iOS Settings. On Android, Meta App Events are enabled, but Halloway removes access to the Android advertising ID and Privacy Sandbox advertising APIs; Meta still receives its app-scoped identifier and the event and device details listed above.

Meta handles this information under its own privacy policy. Because this measurement rides Meta's ad system rather than a Halloway account, our in-app stats switch does not control it. On iOS, Apple's tracking permission controls it. You can also limit how Meta uses data like this in your Meta ad preferences, or play the web version at halloway.noevilstar.studio, which contains no Meta SDK at all.

If you create an account

Signing in is the only thing that sends data off your device, and only what's needed to run the account:

Email is delivered through a standard email provider solely for transactional messages, unless you separately opt into the mailing list. Your account data is never sold and never used for ads — the only third party the native apps ever report to is Meta's install-and-purchase measurement above, and it never receives your email, account, or progress.

Mailing list

If you enter your email for launch updates, we store that address only for Halloway email. It does not create an account, and duplicate signups are ignored.

Your control

Erase any hunt's progress on this device from Settings at any time. If you have an account, you can delete it from Settings — that permanently removes your account, synced progress, entitlements, signed-in metrics, and any matching mailing-list signup from our servers. Deleting the app removes everything stored on the device. You can also email a request to delete a specific category of server-side account data where retention is not needed for security, purchase restoration, or legal records.

Children

Halloway is a riddle game for a general audience and is not directed at children under 13. We don't knowingly collect personal information from children; an account requires an email address and acceptance of the terms.

Changes

Material changes show up here with a new date. Last updated July 19, 2026 — added the native apps' Meta measurement and iOS tracking-permission disclosure.

Contact

Questions or a deletion request by email: halloway@noevilstar.studio.

Local-first · no account required · anonymous aggregate stats are optional. Terms