1. Operator and audience
Fineform Studios LLC operates WEAVE, a mobile arcade game in development / pre-release. It is intended for teenagers and adults aged 13 and older and is not intentionally directed toward children under 13. This does not verify every player’s age or exclude applicable children’s privacy requirements.
Contact contact@fineformstudios.com for support or privacy requests.
2. Local data and anonymous sessions
WEAVE keeps local scores, progression, coins, cosmetics, settings, statistics, achievements, daily missions, rewards, username, queued submissions and grant/reward journals. These support offline play and online retries. Privacy choices and recent sanitized diagnostics are stored separately.
Configured Supabase online features use an anonymous authenticated account without requiring email or password. A unique player ID and access/refresh tokens are persisted locally and may be refreshed. “Anonymous” is a sign-in method, not a guarantee that related data is unidentifiable. Replacing an old local identity key does not delete its server records.
Cross-device recovery is not promised. Clearing storage or uninstalling may remove local copies subject to platform backups, but does not delete backend records. Online account deletion preserves local gameplay progress.
3. Competition and public sharing
When configured and reachable, Supabase processes profiles, usernames, game statistics and run-validation records. Leaderboards display chosen usernames, scores and ranks. Avoid sensitive information or real names in public usernames.
Competitive submissions include score, duration, dodge counts, multiplier, Perfect streak, coins, lost combos, continues, death type, game version/mode, run ID/seed, Daily date and a compact lane-switch input log. These support validation and rankings; the backend also records rate limits and rejected submissions.
Existing shared challenges and public posters may display username, score, Perfect count, multiplier, mode, equipped skin, continuation status, date and verification/rank information. Historical implementations could create public records even when sharing was cancelled, and exposed linked player IDs. The prepared backend update restricts public challenge access to display fields; deployment and historical exposure require verification.
The updated ordinary sharing flow generates local score media and shares the game link without creating a public upload first. A cancelled share therefore does not create a new public challenge. Recipients, downloaded files, clipboards and caches may hold copies you choose to share. Eligible owned public assets and challenge rows are included in the prepared account-deletion workflow.
Beta enrollment submits an enrollment code and records the authenticated tester; test cosmetic/coin grants are not paid purchases.
4. Optional analytics and error reporting
The updated implementation defaults optional remote analytics and error reporting off. Settings provides separate switches. Choices are saved locally; if saving fails, optional collection stays off. Older beta builds enabled remote reporting by configuration, so historical data practices still need review.
When enabled and online, event reporting sends event name and mode to daily Supabase aggregate counts. Error reporting sends fixed diagnostic class/location, build version and fatal status; arbitrary error text, stack traces, URLs, authentication tokens and personal context are excluded by the updated reporting path. Old raw local error buffers are cleared on startup; historical server reports are not automatically scrubbed.
Reporting requests use an authenticated session even when report tables have no player-ID column. Provider logs can therefore be linkable. Turning a choice off prevents new optional reporting and drops unsent queues on flush; it does not delete already processed reports. No active Firebase Analytics or Crashlytics integration was identified for WEAVE. Offline play, authentication and competition do not depend on optional telemetry.
5. Advertising and consent
Production AdMob is unavailable in the reviewed implementation. Native test integration and developer mock rewarded ads exist; ordinary browser play does not use the native ad provider. The updated native adapter refuses production initialization.
Test initialization requires UMP eligibility before the ad SDK initializes, requests non-personalized ads, uses a conservative under-age-of-consent signal for unknown age, and does not request tracking authorization. These measures do not verify age or replace regional consent and under-18 safeguards. A verified control to reopen advertising choices is not yet available.
Before any production advertising is enabled, this policy must identify active partners, data, consent/withdrawal and age/region settings. Advertising may process IP addresses, device/advertising identifiers, interactions and fraud-prevention information, even for non-personalized ads. Native test behavior remains unverified. See Google’s Privacy Policy.
6. Purchases and rewards
Local coins, cosmetics and rewards are implemented. Production billing has no verified active provider or receipt-verification service. Beta grants do not charge players.
If activated later, stores and backend may process product/transaction IDs, signed receipt or purchase-token proofs, fulfillment/grant status and ledger records. Validation, entitlement/restoration and retention must be confirmed before activation. Non-beta transaction records or active/pending billing require support review before automatic deletion, rather than silently losing entitlements. This studio website does not process payments.
7. Providers and purposes
Supabase supports online sessions, validation, profiles/rankings, optional diagnostics and existing public poster storage. Requests expose connection metadata such as IP addresses. See Supabase’s Privacy Policy.
The browser game references Google Fonts and Vercel hosting/share infrastructure; requests can expose connection data to these providers. See Google’s Privacy Policy and Vercel’s Privacy Policy. The studio website uses local assets and adds no game analytics.
Support receives information you send, including email and message. Website contact uses Cloudflare Turnstile, Cloudflare Pages/D1 rate limiting and Resend delivery. Additional logs/processors need verification. No blanket non-sale/non-sharing or compliance guarantee is made by this draft.
8. Retention and account deletion
No verified retention periods or criteria have been supplied for accounts, runs, rankings, challenges/posters, tester/grant records, diagnostics, support, logs or backups. Buffer sizes and administrative resets are not a retention policy.
The updated Settings option, “Delete Account & Associated Data,” asks for explicit confirmation and authenticates the existing session. Its privileged backend must be reviewed and manually deployed before it is available. Follow the deletion instructions or request assistance if your build cannot complete it.
Once deployed, the workflow freezes account writes, removes eligible owned public posters and associated records, then deletes the online identity. Partial cleanup can occur before a failure; the original session and pending state are kept for retry, and completion is not reported until every step confirms. Local progress is preserved, online identity/queued submissions removed on confirmation, and online connection paused. Purchase records require review.
Old diagnostics without a player ID, unknown-owner assets, provider logs, backups, public caches and recipients’ copies require separate assessment. Lost anonymous sessions may not be recoverable or reliably identifiable. Never email sensitive tokens, passwords or unsolicited identity documents. Live access controls and operational safeguards still need verification; no absolute security or complete-erasure guarantee is made.
9. International processing and your rights
Providers may process data outside your country. Actual regions, transfer arrangements and safeguards remain unverified. Depending on location and applicable law, you may have rights to access, correct, delete or obtain a copy of data, restrict/object to processing, withdraw consent, opt out of qualifying advertising disclosures, and complain to a regulator.
Contact the studio for assistance. Applicable legal bases, verification, deadlines and appeals require review; no unsupported response deadline or legal certification is promised.
10. Children’s privacy
WEAVE is intended for ages 13+ and is not intentionally directed toward under-13s. Age ratings, assurance needs, child safeguards and parental-consent procedures still need assessment. An SDK consent hook is not a verified parental-consent process.
A parent or guardian concerned about a child’s data may contact the studio. Handling the request requires appropriate verification and procedures.
11. Contact and changes
Contact Fineform Studios LLC at contact@fineformstudios.com or through Contact. Include “WEAVE” and a brief description without sensitive credentials.
This policy remains Draft pending owner approval and release verification. A final effective date and material-change notice process are still required.
