Publisher and contact
Second Signal is developed and published by Julien Simiand, responsible for the processing described here. For privacy questions: contact@secondsignal-game.com.
The game does not ask for a name, age or password account. If you email us, we use your email address and message to respond and handle your request.
Data used by the validation service
The server automatically receives data needed to authenticate the installation and authorize repairs. Pseudonymous identifiers remain linked to an installation or purchase; they are not anonymous.
Device identifiers: installation ID, App Attest key ID and public key, request counter and device-verification hash. User identifiers: pseudonymous purchase token, Apple’s identifier for your App Store account within this app and links to authorized installations. Purchase history: Apple transaction IDs, product, environment, dates and refund or revocation status.
Gameplay content and product interactions: requested mission and scenario, installation, authorization issue and expiry times. Other data: Apple attestation receipt and a salted network-source hash used to limit abuse.
Supabase infrastructure logs include coarse location inferred from the network (country, region, city, postal code), performance data (call duration) and other diagnostics (IP address, user agent, path, HTTP status, errors). The game does not access GPS.
Purposes and service providers
These data provide the game, validate and restore purchases, authorize repairs, apply refunds, prevent fraud and diagnose failures. Game access and purchases rely on performance of the contract; security, abuse prevention and support rely on our legitimate interest. None of these data are used for advertising targeting.
Supabase hosts the validation server on our behalf. Apple verifies purchases and installation integrity. Communications use HTTPS and server tables are not directly accessible to clients. Apple handles payment details; they are not sent to our server.
OVHcloud hosts support email and processes addresses, messages and metadata needed to deliver and protect them. Support messages are forwarded to Gmail (Google), which processes their content and metadata. A copy is kept in the OVHcloud mailbox.
Supabase and OVHcloud agreements limit processing to the service and require personnel confidentiality and security measures. Cloudflare’s agreement also provides confidentiality and security obligations. Apple, OpenAI and Google publish technical and organizational safeguards. We rely on these commitments to maintain the same privacy and security principles described here, according to each provider’s role.
Official commitments : Apple https://www.apple.com/legal/privacy/en-ww/ ; Supabase https://supabase.com/legal/customer-resources/data-processing-addendum ; OpenAI https://openai.com/policies/eu-privacy-policy/ ; Cloudflare https://www.cloudflare.com/cloudflare-customer-dpa/ ; OVHcloud https://contract.eu.ovhapis.com/1.0/pdf/OVH_Data_Protection_Agreement-fr.pdf ; Google (Gmail) https://policies.google.com/privacy
Saves and Apple services
Progress is saved on your device. When iCloud is available, CloudKit may sync saves in your private iCloud database. The validation server receives neither these saves nor detailed fault states or dialogues.
If you use Game Center, Apple processes achievements and your Game Center identity. iCloud, Game Center and purchases are also subject to Apple’s settings and privacy policy.
Retention periods
Installation identifiers, attestations, purchase links and purchase or revocation status are kept while needed to operate the service and support restoration. Signed Apple transactions are verified; their complete signed payloads are not retained.
Security challenges are valid for 120 seconds and mission authorizations for 15 minutes. Daily cleanup deletes those expired more than 24 hours earlier, so they may remain for about 48 hours after expiry. Processed notification IDs are deleted after 30 days, or up to about 31 days on this schedule. Failures delaying cleanup may extend these periods.
The current Supabase plan’s stated API and database log retention is one day. Support correspondence is kept as long as needed to handle the request.
Your choices and requests
You can request access, correction or deletion of your data at contact@secondsignal-game.com. Depending on applicable law, you may also request portability, restrict or object to processing, or contact your data protection authority. We may request information needed to locate and verify the relevant records. In France, you can lodge a complaint with the CNIL: https://www.cnil.fr/fr/adresser-une-plainte.
Deleting service data revokes the affected installations and authorizations; it does not cancel the purchase held with Apple. Later restoration of a valid Apple purchase may create new links and records. Local or iCloud saves and Game Center data are managed separately on your device or with Apple.
Website, children and updates
The website is hosted through OpenAI Sites on Cloudflare infrastructure. We add no advertising cookies or audience analytics. To block abusive automated traffic, Cloudflare performs technical browser checks and uses security cookies, including __cf_bm, which expires after 30 minutes of inactivity. These providers may process IP addresses, requests and technical browser information to deliver and secure the website. Cookie information: https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/.
The game does not request players’ ages and does not market to children through targeted advertising. Parents can contact us about their child’s data. We will update this policy if processing changes.