Privacy Policy for Clackyard
Clackyard ("the game") is a dominoes game — Mexican Train and Chicken Foot — developed and published by Machinaut Studios LLC ("we", "us"). This policy explains what data the game handles. The short version: we run no server, there is no account of ours to make, and nothing about you is ever sent to us. There is no analytics or crash reporter of ours, no advertising and no in-app purchase code in the build. Your name, your avatar, your settings, your lifetime stats and your saved games are written to your own device, and your stats and a few settings are also kept in your own iCloud or Android backup — storage that belongs to your Apple or Google account, which we cannot read — so that deleting the game or changing devices does not lose them. A solo game against bots and a table played over your own Wi-Fi send nothing past your own network — except that, if you signed in to the cross-platform save, the stats a finished game adds are synced to Epic afterwards, usually a few seconds after it ends. Two things are off until you choose them: online play, and the cross-platform save, which keeps your lifetime stats with Epic Online Services if you sign in with Apple or Google. The sections below say exactly what each one sends, to whom, what Epic's SDK and Google's sign-in library declare they collect for themselves, and what is still not sent.
Information we collect
Nothing reaches us, from any part of the game. We operate no server for Clackyard and we receive nothing from it. There is no analytics SDK of ours, no crash-reporting SDK, no advertising SDK and no attribution SDK in the build. There is no account of ours to create and no sign-up: we never ask you for your name, email address, phone number, contacts or anything else. We build no profile of you, we have nothing to sell, rent or trade, and we hold no record that you exist. The name and avatar you pick are for the other players at your table to see, and for your own other devices through your own iCloud or Android backup; they are not sent to us, because there is no us to send them to.
The cross-platform save is the one place anything of yours is kept for you by a company we chose, and only once you sign in to it: then your lifetime stats, and an id Epic assigns you, are stored by Epic Online Services, which we use as a service provider to keep that save for you. Its section says exactly what is stored, what the sign-in involves, and how to delete it. Even then nothing reaches a machine of ours.
Two third-party SDKs in the game declare that they can collect data for their own makers, and neither sends anything to us:
- Epic's SDK, which only a build with Epic credentials carries, and which starts only when you choose an online table or when a cross-platform save you signed in to syncs. What it collects goes to Epic and is described under Online play.
- Google's sign-in library (Google Sign-In for iOS), which is built into every iPhone, iPad and Mac version of the game — whether or not that version offers Sign in with Google, and although the Mac never does. It does nothing until you choose Sign in with Google in a version that offers it; the button appears in Settings only where it is offered. Its own privacy manifest, the statement Apple reads into the App Store's privacy label, declares that it may collect a name, an email address, a phone number and a coarse location, for app functionality; a user id and other data types, for app functionality and analytics; and a device id and other usage data, for analytics — all linked to the person signing in, and none used for tracking. That is why Clackyard's App Store privacy label lists those types. Google's own published disclosure for the library names less: an identifier for your account, to record the permissions you grant, and your internet address, which may be used to estimate a general location to prevent fraud. What the library collects goes to Google under the Google privacy policy, never to us. The Android version carries Google's sign-in library too, and it likewise does nothing until you choose Sign in with Google.
What the game stores, and where
Everything Clackyard remembers is written to your device's own private app storage. It is kept under these keys:
- Your settings and your identity (
cy.settings) — the display name you typed (up to 16 characters, and blank until you type one), which of the twelve avatars you picked, sound, haptics, reduce motion, whether tiles show pips or numerals, whether your hand's running total is shown, the last room name you used, the house rules you last hosted with, and a random player id. That id is sixteen hexadecimal characters drawn from your device's cryptographic random source on first run. It is not a device identifier, an advertising identifier or anything derived from your hardware, your account or your name — it exists so that a host can recognise you if your phone drops off the table mid-round and comes back. Beside it is a seat key (cy.seatKey): another random secret made on first run, never shown, which your device sends to the host of a table you join and to nobody else, so that only your device can take your seat back. - Your lifetime stats (
cy.stats.ledger) — games and rounds played and won, rounds you went out in, rounds that ended blocked, your best game, total points, the largest table you have sat at, and games played and won of each of the two games. Numbers only. Each installation of the game keeps its own tally, filed under a random install code (cy.install: thirty-two hexadecimal characters drawn from your device's cryptographic random source on first run — like the player id, not a device identifier, an advertising identifier or anything derived from your hardware, your accounts or your name. It is kept in the game's cache folder, which no backup or phone transfer copies, so a restored or copied device starts a tally of its own), and the stats you see are every installation's tally added together. That is what lets two of your devices, or a reinstall, add up instead of overwriting each other. Versions before this one kept a single record undercy.stats; it becomes this installation's tally and is left where it was. There is a "Reset stats" button in Settings. - The table in progress (
cy.table) — so that closing the game mid-round and coming back does not lose it. If you are the host this is the whole table: the room name, the rules, the roster (every player's display name, avatar and player id, and the seat key each player's device took its seat with), the door code if the table is private, every hand, the trains on the board and the boneyard. If you joined someone else's table it is only what your device needs to dial back in: the host's address or join code, and the door code you knocked with if the table was private. - Your saved games (
cy.savesand onecy.save.…entry per game) — up to twenty unfinished games, each a whole table as described above, plus the few facts the shelf lists: room name, which game, which network, the round, the seat names and when it was saved. The oldest falls off when a twenty-first is saved, and any of them can be deleted from the shelf. - A little bookkeeping for the sync — for each setting that follows you between devices (the ones listed under iCloud below), when you last changed it, by the clock of the device you changed it on, or zero if you never have (
cy.settings.at), so the newest change to each setting wins when your devices compare notes, and a change you make on one device is not undone by an older one from another; and, only if you signed in to the cross-platform save, whether that was with Apple or Google (cy.cloud.provider, andcy.cloud.linkedif you added the other one), when it last synced (cy.cloud.synced), and a one-way fingerprint of the account you signed in with (cy.cloud.subject.…: a salted hash of that provider's id for your account, never the id itself, an email address or a name), so the game knows whom to ask next time and can tell you if you pick a different account. The game also notes, on the device alone and in the same cache folder as the install code, when it has stopped asking Google in the background until you tap Sync now (cy.cloud.paused). The game never writes down a password or a sign-in token. (Google's own sign-in library on iPhone and iPad keeps its sign-in in your device's Keychain — see the cross-platform save.)
On every platform these live in the ordinary per-app storage the platform gives every app. None of it is uploaded to us — we have nowhere to put it. Copies beyond the device exist only in places that belong to you: your own iCloud or Android backup, described next; the cross-platform save, only if you signed in to it (and Epic's SDK may keep an encrypted working copy of that one file in the game's own storage on the device); and, as for any app, the device backups you make of an iPhone, iPad or Mac. We cannot read any of them. To erase it all, see Deleting your data.
The game also writes diagnostic lines to your platform's ordinary developer console while it runs. Those lines are not saved to a file and are not sent anywhere; they exist for a developer with the device in hand, and they disappear when the app closes.
Your own iCloud, and Android's backup
So that deleting the game, reinstalling it or moving to a new device does not cost you your record, a copy of some of it is kept in storage that belongs to your own Apple or Google account. This needs no sign-in and is on unless you switch it off. It is not collected by us — nothing of ours sits in between, and neither we nor anyone working for us can read it — and you control it in your device's own settings.
- iPhone, iPad, and the Mac App Store version — the game keeps two things in its own space in your iCloud key-value storage, the small private store Apple gives an app inside your iCloud account: your lifetime stats (each installation's tally, as above, with any reset you made) and a few settings — your display name, your avatar, sound, haptics, reduce motion, whether tiles show pips or numerals, whether your hand's running total is shown, and the house rules you last hosted with — each with the time you last changed it, as described in the bookkeeping above. They come back when you reinstall, they reach a new iPhone, iPad or Mac signed into the same Apple Account, and a setting you change on one reaches the others: each setting takes its newest change, wherever it was made, so changing your name on one device and your avatar on another keeps both. A new installation on which you have changed nothing takes your settings from iCloud and never puts its own defaults over them. Nothing else goes there: never your player id or your seat key (they identify your seat at a table, so each device keeps its own), never the last room name you used, never a table in progress or a saved game, never your install code or anything about a cross-platform save sign-in. When iCloud is on, Settings in the game says "Stats and settings sync through iCloud automatically." Apple holds the store under the Apple privacy policy. To stop it, switch iCloud off for Clackyard — on iPhone or iPad under Settings → [your name] → iCloud, among the apps using iCloud; on a Mac under System Settings → [your name] → iCloud — and the game carries on with what is on the device.
- Android — the game lets Android's own backup include its settings file, and only that file: your name, avatar and settings, when you last changed each of those settings (
cy.settings.at), your player id together with its seat key, your lifetime stats, the table in progress and your saved games (on a device that hosted them, with the other players' seat keys and a private table's door code), and, if you signed in to the cross-platform save, the sign-in bookkeeping listed above, so a restored phone wakes up signed in. When backup is on, Android copies that file into your Google account — encrypted on the phone with your screen lock, if you have one — and restores it when you reinstall the game or set up a new phone from that backup; setting up a new phone by copying from the old one carries the same file. Android decides when a backup runs, usually about once a day while the phone is idle, charging and on Wi-Fi. Nothing else the game or Epic's SDK keeps on the phone is included: not the install code, not the note that Google is paused, and not Epic's device credential, which is encrypted with a key that never leaves the phone. Google holds the backup under the Google privacy policy, and you control it in your phone's backup settings (usually Settings → Google → Backup; the path varies by phone maker). - Windows, Linux, and a Mac copy not bought from the Mac App Store, have neither: everything stays on that one computer.
Permissions
Clackyard is a multiplayer game, so it needs networking, and networking is the whole permission story. It asks for no camera, no microphone, no location, no contacts, no photo library, no files of yours and no notifications, and it uses no advertising identifier.
- Android — the app asks the system for exactly four permissions:
INTERNET,ACCESS_NETWORK_STATE,ACCESS_WIFI_STATEandCHANGE_WIFI_MULTICAST_STATE. All four are normal install-time permissions, so none of them shows you a prompt. They are what lets the host open a table on your network, announce it so other devices can find it, and keep Android from dropping those announcements while the screen is on battery. The libraries the game is built with add one more entry that asks for nothing of yours: a signature permission belonging to the app's own package, which an Android support library declares so that no other app can send the game its internal broadcasts. Epic's Android library, which a build with online play carries, adds nothing to that list but a second declaration ofINTERNET; it also brings package-visibility queries for a web browser and Custom Tabs, and an activity that receives the return from an Epic account sign-in, which this game never performs. Google's sign-in library would bring two fingerprint and biometric permissions with it; the game removes them, because its sign-in does not use them. Neither Android's backup nor Google sign-in adds a permission, and the release build is checked for exactly this set before it ships. Beyond that there is the package-visibilityqueriesblock for the system "process text" action that the Flutter engine includes as standard, and a link filter that lets an invite link open in the app (see Invite links). None of those is a permission, and none grants access to anything. - iOS / iPadOS — the only usage description in the app's
Info.plistis the local-network one, which is what iOS shows you, once, the first time you host or look for a table on your Wi-Fi. The two Bonjour service types the app declares (_clackyard._tcpand_clackyard._udp) belong to that same local-network permission. No other usage description is declared, so there is nothing else iOS can prompt you for. The app also declares that it uses no non-exempt encryption. It carries three capabilities that are not permissions — none shows a prompt and none reaches anything on the device: associated domains, which let an invite link on machinautstudios.com open the game; iCloud key-value storage, which gives the game its own small store in your iCloud (above) and nothing else of your iCloud; and Sign in with Apple, which lets the game show Apple's sign-in sheet when you ask for it. - macOS — the release build runs inside the App Sandbox and declares outgoing network connections and incoming ones, which are what let a sandboxed Mac join a table and host one. The Mac App Store version adds the same two capabilities as iOS, iCloud key-value storage and Sign in with Apple; a Mac copy from anywhere else (the Developer ID download) keeps only the two network ones, and has no iCloud and no sign-in. There is no camera, microphone, location, contacts or file-access entitlement. Recent versions of macOS may also ask once for Local Network access.
- Windows and Linux — the desktop builds request nothing beyond their own network sockets and their own settings and cache folders. Windows may ask whether to let Clackyard through its firewall the first time you host; that is the operating system's question, and allowing private networks is enough for a table on your own Wi-Fi.
Development builds of any Flutter app carry extra permissions so the tooling can hot-reload over a cable. Those debug and profile builds are never distributed; the release that goes to Google Play carries the four permissions described above.
Playing solo, and playing on the same Wi-Fi
Play vs bots uses no network at all. The whole game — tiles, rules, opponents — runs on the device in your hand. (The stats it adds to your record are copied to your own iCloud or Android backup like any others, as described above; that is your platform's sync, not the table's. And if you signed in to the cross-platform save, they are also synced to Epic after the game, as that section describes — usually a few seconds after it ends.)
A Same Wi-Fi table stays on your own network and does not touch the internet. One device hosts: it listens on a TCP port and announces the room by UDP broadcast about once a second, so the other devices on the same network can list it without anyone typing an address. The announcement carries the room name the host typed (up to twenty characters), the host's chosen display name, the host's random player id described above, the port, how many seats are taken, how many there are, whether the game has started, whether the table is private, which of the two games it plays, and which app and protocol version sent it. Once a player joins, what travels between the devices is the game: names, avatars, player ids, moves, the seven built-in emotes, and each seat's own view of the table. It goes to the other players' devices and to nothing else. It does not pass through us, and it does not leave your network. (What the game adds to your stats afterwards travels as a solo game's does, above.) It is not encrypted on that network, though: neither the room announcement nor the game messages are, so another device on the same Wi-Fi that listens for them could read the names and moves in them, and the view of the table each seat is sent. Host Same Wi-Fi tables on a network you trust.
One device holds the only true state of the game and sends every other seat a copy with every other player's hand and the whole boneyard removed before it is sent. A tile you are not holding is not "hidden by the interface" — its value is simply not in the message. Nobody at the table, the host included, is sent a tile they are not entitled to see.
Nothing in the online section below applies to a solo game or a Same Wi-Fi table — including the data Epic's SDK collects for Epic. Neither of them starts Epic's SDK while you play, and a build without Epic credentials does not contain it at all. The one exception comes after the game, not during it: if you signed in to the cross-platform save, the game starts Epic's SDK a few seconds after the game ends to sync your stats, and that section lists everything it sends then. The tiles, the hands and the moves never leave your network.
Online play, and exactly what reaches Epic
Playing across the internet is the one part of the table that involves a company other than the store you bought the game from, and it is opt-in twice over.
- The build has to carry Epic Online Services credentials, which are supplied at build time and are not in the source. A build without them cannot offer online play at all; the Online option is greyed out and says so.
- You have to choose it: switch the table from Same Wi-Fi to Online on the Host or Join screen, open an invite link (which opens the Join screen already set to Online, with the code filled in), or resume a saved game that was played online. Wi-Fi is what is selected every time you open the Host or Join screen yourself.
If you never do any of those — and never sign in to the cross-platform save — the game never contacts Epic. It does not check in, does not log in in the background, and does not start Epic's SDK at all — that happens the first time an online table is opened or searched for, or the first time a save you signed in to syncs, and not before.
When you do choose Online, this is what the game itself does and sends, and to whom — with what Epic's SDK collects on its own account in the paragraph after it:
- An anonymous, per-device sign-in. The game asks Epic for a Device ID credential and logs in with it. There is no Epic account, no email, no password, no web page and no prompt — nothing for you to sign up for and nothing for you to remember. Two values go with that request: a coarse device model, which is literally the name of your operating system ("ios", "android", "macos", "windows" or "linux") and nothing more specific; and a display name, which is hard-coded to the word "Player" rather than anything you typed. Epic returns an anonymous per-device id, and Epic's SDK keeps the credential in local storage it manages on your device. Like any online service, Epic also sees your internet address and the ordinary technical details its SDK sends with each request, such as the SDK's own version and your platform.
- Hosting publishes a room record to Epic. While your table is open, Epic holds a lobby record for it so other players can find it. It carries the six-character join code, which app and protocol version it is, which of the two games it plays, a listed flag, the room name you typed, the display name you typed in Settings, the random player id described above, how many seats are taken, the maximum, and whether the game has started. A listed table can be seen by anyone searching from a compatible build. A table you mark private is left out of that room list and is found only by its code, but its record carries the same fields. If you would rather not publish a name, change it in Settings before you host — the field is yours and the game does not require it. The record is deleted when the table closes.
- Joining searches Epic's lobbies for that code, or lists the listed tables of the same protocol version, and joining a table adds your anonymous Epic id to that table's lobby while you are at it.
- The game's packets travel over an Epic peer-to-peer connection between the players' devices. They are the same messages the Wi-Fi game sends — names, avatars, player ids, moves, emotes, and each seat's masked view of the table. Epic's job is to get the devices talking: it first tries to connect them directly, in which case each device learns the other's internet address, as with any peer-to-peer connection; where a direct connection cannot be made, Epic relays the bytes between them. Epic is a US company and operates that service on its own infrastructure and under its own policies; see the Epic Games privacy policy.
Epic's SDK also collects data of its own, for Epic. A build with online play carries Epic's SDK, and whenever that SDK is running — at an online table you chose, or during a sync of a cross-platform save you signed in to — it may also collect data for Epic's own purposes. According to Epic's own privacy manifest for the SDK, that is product interaction data (how the app and its online features are used), which is linked to the anonymous per-device Epic id and used for Epic's analytics and to run the service, and performance data (diagnostics), which is not linked to that id and is used for Epic's analytics. The same manifest lists a name, a user id and gameplay content, used to make the service work; those are the names, ids, room record and packets already described above, and, for the cross-platform save, the save file and the id it is kept under. It also lists an email address, which applies only to signing in with an Epic account, and Clackyard never does that. Epic's manifest declares that none of this is used for tracking. We do not receive any of it and have no access to it: it is collected by Epic and governed by the Epic Games privacy policy.
And this is what does not happen, even then:
- The game is still yours. The host's device holds the only true state, runs every rule, and masks every other seat exactly as it does on Wi-Fi. Epic carries bytes and lists rooms. It does not hold the boneyard, decide a turn, or see anyone's hand.
- Online play still needs no account — nothing to create, nothing to sign into, nothing to delete, and no way to link one table to another except by the anonymous per-device identity Epic issued. The cross-platform save's sign-in, below, is separate and is never used for online play.
- We still receive nothing. There is no Clackyard server, no database and no telemetry of ours anywhere in the picture. Nothing about your game reaches Machinaut Studios, online or otherwise.
- There is no chat. The only things a player can put in front of another player are seven fixed emotes, a display name of at most sixteen characters, and — if they are the host — a room name of at most twenty. There is no message box, no voice, no images and no friends list; those two names are the only text anyone types, and the room name of an online table is published to Epic's room record along with the host's display name.
The cross-platform save, and exactly what reaches Epic
Your iCloud stays among Apple devices and Android's backup among Android phones. To carry your lifetime stats between an iPhone and an Android phone you can sign in to the cross-platform save. It is off until you do. It exists only in a version of the game whose Settings screen shows a Cross-platform save section: if yours shows none, nothing in this section applies to it, and that version never contacts Epic for a save. Like online play it is opt-in twice over:
- The build has to carry Epic Online Services credentials, the save's storage key and, for Google, Google's sign-in settings, all supplied at build time and not in the source. A build without them does not show the section at all.
- You have to sign in, in Settings: with Apple on iPhone, iPad and the Mac App Store version, and with Google on iPhone, iPad and Android in a version that offers it. Android does not offer Apple, so an Apple sign-in alone reaches only your Apple devices; on an iPhone or iPad you can add Google to the same save so an Android phone can open it too. Windows, Linux, and a Mac copy not bought from the Mac App Store do not offer the save.
If you never sign in, nothing in this section happens. When you do, the game syncs when you sign in, at launch, a few seconds after every game ends — solo and Wi-Fi games included — after you reset your stats (or a reset reaches this device through iCloud), and when you tap Sync now. (A device signed in with Apple alone syncs in the background only within a few minutes of your last sign-in there, because Apple cannot sign you in without asking; otherwise it waits for Sync now.) Each sync is this complete list of what happens:
- The same anonymous per-device sign-in online play uses (described above: a Device ID credential that Epic's SDK keeps on the device, your operating system's name and the display name "Player", and an anonymous per-device id at Epic) is made first, even if you never play online, because Epic's SDK needs it running. It lasts as long as the sync, and the game then shuts the SDK down again unless you are at an online table. While it runs, Epic's SDK may collect for Epic the usage and performance data described under online play.
- Apple or Google signs you in and hands the game a short-lived sign-in token that says who you are to them. The game asks Apple for no name and no email, so Apple's token carries neither. Google's sign-in always puts your Google account's name, email address and profile picture into its token, whatever the app asks for — that is why Google's sheet says it will share them with Clackyard. The game never shows, stores or uses them, and they leave your device only inside that token, which goes to Epic for Epic to verify. The game keeps the token in memory while it is valid, so you are not asked after every game, and never writes it down. On iPhone and iPad, Google's own sign-in library keeps its sign-in — a renewal token and the last sign-in token, with the name, email and picture in it — in your device's Keychain, which is what lets the game sync after a game without asking you again; it stays until you choose Sign out or Delete cloud save, and iOS may keep it after the app is deleted, until Google's library next starts. It never leaves the device. Android keeps no sign-in token for the game, and Sign in with Apple keeps no session on the device at all. On Android, when the game syncs after a game, Google's quiet sign-in can show its account chooser if it cannot pick the account by itself — as when more than one Google account on the phone has used Clackyard. Choosing the save's account lets that sync go ahead, and the chooser can appear again after a later game; dismissing it, or choosing a different account, stops the game asking in the background until you tap Sync now.
- Epic checks the token. The game passes it to Epic Online Services, which verifies it with Apple or Google and gives you a product user id: a random id, scoped to Clackyard, that Epic links to the account you signed in with. What Epic documents keeping about that link is which provider it was and that provider's environment, your account's id with that provider (an opaque code, not your email address), a display name — which the game always sets to the word "Player" — and when you last signed in. Your email address is not on that list. On an iPhone or iPad, where both are offered, you can add the other provider to the same save; Epic then links both accounts to the one id, so either opens it. If the account you add already has a save of its own, the game asks first: Combine adds the two saves' stats up in this one and marks the other deleted, the way Delete cloud save does below; Keep apart changes nothing.
- The game reads your save, adds this device's stats, and writes it back. The save is one file,
clackyard-stats.json, and it holds your lifetime stats and nothing else: the numbers listed above, one tally per installation under that installation's random install code, with any reset you made. No name, no avatar, no settings, no house rules, no tables or games. It is encrypted on your device, with a key built into the game, before it is uploaded, and Epic stores it in its Player Data Storage. - The sign-in lasts only as long as that read and write; the game then signs the account out of Epic again. It is a separate sign-in from the anonymous one online play uses and sits beside it rather than replacing it, so it never changes a join code and never ties an online table to your Apple or Google account. Once your first sign-in has read the save, the game remembers on this device which provider you chose, when it last synced, and the one-way account fingerprint described under What the game stores, so it can sync again later. Those notes never go to iCloud or Epic, but they ride your Android backup and your device backups with the rest of the game's settings file, so a restored device wakes up signed in.
And this is what does not happen:
- We still receive nothing. The save goes to Epic, not to us. We run no server, and we do not download or read players' saves.
- Nothing else about you goes to Epic. Not the display name you typed, your avatar, your settings, your house rules, your tables or your games. What online play sends, if you use it, is described above and does not change when you sign in.
- No advertising and no tracking. The save exists to keep your stats. It is not used to advertise to you, to track you across other apps or websites, or for anything else we do.
Epic is a US company and holds the save on its own infrastructure, as our service provider, under the Epic Games privacy policy. Apple and Google see that you signed in to Clackyard, as with any sign-in, under their own policies. The save stays until you delete it.
Signing out of the cross-platform save, and deleting it
This is how to delete Clackyard's cross-platform save, in the game or without it. It applies only if you signed in to the save in a version of the game that offers it (Settings shows a Cross-platform save section). If you never signed in, there is no save at Epic to delete: your stats are only on your devices and in your own iCloud or Android backup, and the last item below says how to clear those.
- Sign out (Settings → Cross-platform save → Sign out) stops this device syncing. The save stays with Epic for the next time you sign in, on any device, and your stats stay on this device.
- Delete cloud save (Settings → Cross-platform save → Delete cloud save, then Delete to confirm; there is no undo) replaces the save file at Epic with a marker that says it was deleted and holds no stats, so your stats are gone from Epic at once, and unlinks the Apple or Google account (or both) that device signed in with. If that device holds both and one of them cannot be reached once the save is marked — you back out of Apple's sheet, say, or the network drops — the device keeps that sign-in and asks you to tap Delete cloud save again to unlink it.
- Your other devices. Epic only lets a device unlink the account it signed in with, so any other device of yours signed in to that save sees the marker the next time it syncs, unlinks its own account and signs out, telling you the save was deleted on another device — it never fills the save back up. If that unlink fails — the network drops, say — the device stays signed in and tries again the next time it syncs, still without writing anything. A device signed in with both Apple and Google lets go of them one at a time: when one of them reaches the deleted save — reading the marker and unlinking, or finding its link already removed — the device drops only that one and reaches the marker through the other before it signs out: quietly for Google, and for Apple, which cannot sign in without asking, the next time you tap Sync now there.
- What Epic keeps afterwards. The product user id with that empty marker, and — until each device holding a link has synced through it and unlinked (a device signed in with Apple alone at its next Sync now; one whose unlink failed at the sync after), or, on the deleting device, until you tap Delete cloud save again — the account links those devices hold. Nothing with a stat, a name or an email address in it. Once the last link is gone, no sign-in can reach that id, and signing in again by choice starts a new save, holding the stats of the device you sign in on. What Epic keeps is governed by the Epic Games privacy policy. Nothing of ours ever held a copy, so there is nothing of ours left to delete or keep.
- What it does not touch. Delete cloud save does not touch the stats on your devices, or in your iCloud or Android backup (the last item below). On iPhone and iPad it also ends Google's own sign-in in the Keychain, as Sign out does.
- Removing Clackyard from your Apple or Google account — in your Apple Account settings under Sign in with Apple, or in your Google Account under Security → Your connections to third-party apps & services — means the game can no longer sign in as you without asking you again. The game never exchanges Apple's sign-in for a longer-lived Apple token, so it holds none to revoke, and we have no server that could; removing Clackyard there is how you end the link on Apple's side. It does not delete a save already on Epic, so use Delete cloud save first.
- Without the game. We keep no list of who has a save, and a save can only be found by signing in to it, so the quickest way is any device you can install Clackyard on — reinstalling it from the store account you bought it with costs nothing — then sign in with the same Apple or Google account and choose Delete cloud save. If that is not possible, email info@machinautstudios.com with the subject "Delete my Clackyard cloud save". We will answer, and do what Epic's tools allow; but we hold no record connecting your Apple or Google account to a save, so what we can do by email is limited, and we will tell you plainly if we cannot find it.
- Your iCloud and Android copies are not part of the cross-platform save and are not with us; they are in your own Apple or Google account (described above). iCloud: Reset stats in Settings empties this installation's tally and marks every other tally this device knows about, so that none of them counts any more, there or on your other devices as they sync; each of your devices still in use then empties its own tally, including the games it played before the reset reached it, while games from a device this one has not synced with yet still count. The tally of an installation that no longer exists, such as one a reinstall left behind, stays in the store with its mark and no longer counts, because only the installation that wrote it could empty it. Switching iCloud off for Clackyard stops the game using the store; the store itself is part of your iCloud account, and Apple keeps and erases it with that account under the Apple privacy policy. Android: you can turn backup off, or delete a phone's backup, in your phone's backup settings (usually Settings → Google → Backup) or the Google One app; deleting a phone's backup removes it for every app on that phone.
Invite links
The host of an online table can send an invite link of the form
machinautstudios.com/.
Building that link is plain text work inside the app; it is handed to
your device's own share sheet, and you pick the recipient in your own
messaging app. The game never sees your contacts. The link carries the
join code and nothing else.
On a device that has Clackyard, the operating system opens the link in the app instead of a browser — it confirms the app may do that by checking a file on our website, and involves no data of yours. On a device that does not, the link opens an ordinary web page on this site, which shows the code and where to get the game. That page runs no analytics and sets no cookies. Like any web page it is fetched from our host (GitHub Pages) and loads fonts from Google Fonts, and those services see the request, including the code in the address, the way they see any visit to any site.
Purchases
Clackyard is a premium game: one flat price, no ads, no in-app purchases, no subscription and no currency of any kind. There is nothing to buy inside the game, which is why the build contains no billing or in-app-purchase library at all and why "restore purchases" does not exist. Your purchase of the game itself is processed entirely by the store you bought it from. We do not receive or store your payment details, card information or billing address; what reaches us is an aggregate sales figure, never anything about an individual buyer. The stores handle your purchase under their own policies: Apple and Google.
Data sharing
We do not sell, rent or trade your data, and we have none to share. No third party receives anything from a solo game or a same-Wi-Fi table, because those send nothing off your network — except, if you signed in to the cross-platform save, the stats a finished game adds, which reach Epic at the sync that follows it. The companies in the picture are the store that distributes Clackyard and processes its purchase; Apple or Google, which hold your iCloud or Android backup for you, in your own account; Apple or Google again, only if you sign in to the cross-platform save with them, and Google's sign-in library for whatever it collects for Google once you choose Sign in with Google; and Epic Online Services, only if you choose an online table or sign in to the cross-platform save — as our service provider, for the room discovery, packet carriage and save storage described above, and for the usage and performance data Epic's own SDK collects for Epic while it runs.
Children's privacy
Clackyard is a dominoes game with no gambling, no advertising, no account of ours and no chat: the only things one player can put in front of another are seven fixed emotes, a display name capped at sixteen characters and, from the host, a room name capped at twenty. We do not knowingly collect personal information from anyone, children included; nothing about anybody reaches us, and there is no advertising identifier in use. The cross-platform save is the one feature that keeps anything with a third party, and it needs an Apple or Google sign-in that the player — or, for a child's account, the parent who manages it — has to choose; it stores numbers and an id, not a name. A display name is typed by the person playing, so if a child is playing on a shared device it is worth picking a display name that is not their real one — particularly before hosting an online table, where that name and the room name go into Epic's room record for other players to read. Solo and same-Wi-Fi play publish nothing anywhere.
Your choices
- Play solo or on your own Wi-Fi and the table never leaves the building: the game sends nothing past your own network. Only your record goes further — to your own iCloud or Android backup, which you can switch off, and, if you signed in to the cross-platform save, to Epic, usually a few seconds after each game ends, until you sign out. Solo and Wi-Fi are the default, on every screen, every time.
- Leave the name field blank or type any name you like; the game shows "Player" if you leave it empty, and it is editable in Settings whenever you want. The room name you host under is the other thing anyone reads, so name an online table with that in mind.
- Never choose Online and never sign in to the cross-platform save, and the game never starts Epic's SDK or contacts Epic.
- Never choose Sign in with Google, and Google's sign-in library never does anything.
- Leave iCloud on for Clackyard and your record survives a reinstall and follows you between your Apple devices; switch it off and it stays on each device alone. On Android, your phone's backup setting decides the same thing.
- Sign in to the cross-platform save only if you want your stats on both Apple and Android; sign out to stop a device syncing, or delete the save outright — see above.
- Mark an online table private and it stays out of the room list; only people you give the code can find it.
- Reset your lifetime stats from Settings, with a confirmation, at any time. It forgets every game and round the device you reset on knows about, there and on your other devices as they sync through iCloud or the cross-platform save — and every game those devices play before the reset reaches them. Games from a device it has not synced with yet still count. Delete any saved game from the shelf, at any time.
- Erase everything the game saved, with no request to file with us and nobody of ours to ask — see below.
- Delete the app, which removes everything it stored on that device; the copies in your own iCloud or Android backup, and a cross-platform save, stay until you clear them.
Deleting your data
Clackyard data lives on your device and in places that belong to you, so you delete it yourself. There is no account of ours to close, no copy on a server of ours, no backup of ours, and no request to file with us — we could not delete your data if you asked, because we never had it. The copies beyond the device are your iCloud or Android backup and, only if you signed in, the cross-platform save on Epic. To erase it:
- 1. Android — open Settings → Apps → Clackyard → Storage and tap Clear storage. Your name, avatar, settings, lifetime stats, the table in progress and every saved game are erased from the phone; the app stays installed and starts as if new. A copy in your Android backup is kept by Google so a reinstall can restore it — see item 8.
- 2. Android — or touch and hold the Clackyard icon and choose Uninstall. The app and all of its data on the phone go together, with the same exception for your Android backup.
- 3. iOS / iPadOS — touch and hold the Clackyard icon, tap Remove App, then Delete App. This removes the app along with everything it stored on the device. (Choosing Offload App instead deliberately keeps the data for when you reinstall.) The copy in your iCloud is deliberately kept too, so a reinstall brings your record back — see item 7. If you signed in with Google on that device, choose Sign out or Delete cloud save first: Google's sign-in library keeps its sign-in in the Keychain, and iOS may keep it after the app is deleted.
- 4. macOS — quit the game, then drag Clackyard from your Applications folder to the Trash and delete the folder ~/Library/
Containers/ com.machinautstudios. clackyard (in Finder, use Go → Go to Folder… and paste that path). The app is sandboxed, so everything it saved on the Mac is inside that one container. The Mac App Store version's iCloud copy is covered by item 7. - 5. Windows — quit the game, then delete the Machinaut Studios LLC\
Clackyard folder inside %APPDATA%, and the folder of the same name inside %LOCALAPPDATA%, which holds the install code (paste %APPDATA% or %LOCALAPPDATA% into the File Explorer address bar to get there). Uninstalling the game does not remove those folders; deleting them does. - 6. Linux — quit the game and delete the folder ~/.local/
share/ com.machinautstudios. clackyard (or the same name under $XDG_DATA_HOME, if you have set it), and the cache folder ~/.cache/ com.machinautstudios. clackyard (or the same name under $XDG_CACHE_HOME), which holds the install code. - 7. Your iCloud copy — it is in your own Apple Account, not with us. Reset stats in Settings forgets every game the device you reset on knows about, there and on your other devices as they sync, and every game those devices play before the reset reaches them (games from a device it has not synced with yet still count), and switching iCloud off for Clackyard (see above) stops the game using it. The store itself is part of your iCloud account and is kept and erased with it, under the Apple privacy policy. The cloud save section says exactly what a reset leaves in the store.
- 8. Your Android backup — it is in your own Google account. You can turn backup off, or delete a phone's backup, in your phone's backup settings or the Google One app; deleting a phone's backup removes it for every app on that phone.
- 9. The cross-platform save — Delete cloud save in Settings removes your stats from Epic; the section above has what it does on your other devices, what Epic keeps until they sync, and the way to ask without the game.
- 10. If you played online — removing the app removes the game's own data, including anything it kept about an online table. The anonymous device credential belongs to Epic's SDK rather than to us, and any record Epic keeps of it is governed by the Epic Games privacy policy; Epic is who to ask about it, and there is no name, email or account attached to it in the first place. A room record disappears from Epic's lobby list when the table closes.
- 11. Any platform — that is the entire procedure. Nothing about you exists on any machine of ours, so there is nothing left to request from us, revoke, export or wait on.
Your purchase is the one thing this does not erase, and it is not ours to erase: the record of what you bought is held by the store. Deleting the game does not refund or cancel it, and reinstalling from the same store account gives you the game back — with your stats and settings if your iCloud or Android backup still holds them (on Android, your saved games too), or with your stats once you sign in to a cross-platform save you kept; and without them otherwise.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above. If Clackyard ever gained a feature that sent something new anywhere, this page would say so before that version shipped.
Contact
Clackyard is published by Machinaut Studios LLC. Questions about this policy, or about the game, can be sent to info@machinautstudios.com.