PlayOrder Privacy Policy

01

Introduction

Hiro App Works (hereinafter “we”) provides the iOS app “PlayOrder” (hereinafter “the App”). This policy explains how user information is handled in the App based on its current implementation.

The App helps organize games, plan what to play, and manage play history. Users may enter text such as game names and notes. Steam and Xbox integrations are optional and require authentication with the respective service when used.

We will provide business operator information required to be disclosed by applicable law without delay upon a request to our contact address.

02

Information handled in the app

Game records entered, created, or retrieved in the App are stored primarily in the on-device database (SQLite) and the App’s storage. The main information and purposes are as follows.

  • Game information: Game names, platforms, Status, notes, and image URLs, used to organize and display games.
  • Plans and release information: PLAN and ordering, release targets, retrieved release information, and manual settings, used for play planning and display.
  • Playtime and REPORT: Retrieved or recorded play information, titles, observation times, and aggregates, used to display history and reports.
  • AUTO and settings: Suggestion and selection history, day and week management information, trial usage, and notification settings, used for suggestions and feature eligibility.

03

Information sent to external services

The App uses our intermediary services on Cloudflare for searches and integrations. Saving records on the device and requesting information from services are separate processes.

IGDB and Cloudflare

Game searches send search terms, display language, and related information; release checks send game IDs and related information to the intermediary service to obtain information from sources including IGDB. Steam game IDs are also used to match Steam games to catalog entries. Requests occur during search, the initial release check when adding a catalog game, and explicit updates from game details. These requests do not send note text or the entire on-device database.

The intermediary uses request processing and necessary caches. Cloudflare may handle communications information, such as IP addresses, and logs to provide its services, maintain security and investigate faults. These have different storage locations and responsible parties from game records on your device, and Cloudflare’s applicable service terms and privacy policy are relevant to their handling. Request processing does not mean that no logs are stored. Please also see the Cloudflare Privacy Policy and Twitch Privacy Notice.

Steam and Xbox / OpenXBL

When an integration is used, authentication uses the external service’s sign-in interface and our intermediary. For Steam, we handle the Steam ID and owned-game and play information available under the account’s privacy settings. For Xbox, we handle account identifiers, profile information such as display names, game history, and available play information through Microsoft/Xbox and OpenXBL. This supports imports, updates, REPORT, and suggestions.

The App does not collect login passwords through its own input fields, but authentication codes and credentials used to maintain connections are processed during authentication and requests. Connection credentials use the device’s secure storage mechanism.

After connection, synchronization may occur through manual actions and at launch, on return to the foreground, or when opening from a notification or Widget, subject to connection, entitlement, and waiting conditions. This does not mean continuous background synchronization. Available information depends on each service’s privacy settings and terms.

On-device Steam records also include game IDs, titles, last-played information, connection/synchronization records, and observations and aggregates used by REPORT. Communications information and logs processed by the intermediary are handled separately from these on-device records.

Before you first connect Steam or Xbox, the App explains how information is handled by external services and starts authentication only when you agree and start the connection.

Handling and Storage Location of Steam Data

PlayOrder uses the Steam Web API to retrieve Steam Data such as your Steam ID, game library and playtime information. Steam Data retrieved by the app is generally stored locally on your device (iPhone).

Communications with Steam may pass through a relay service operated by Hiro App Works for the purpose of connecting to Steam and retrieving data. However, Hiro App Works does not maintain a persistent server-side database of your Steam library or playtime information.

Accordingly, Steam Data stored locally by the app is stored in the country where your device is physically located.

If you enable Apple-provided backup services such as iCloud Backup, app data may also be included in those backups. Storage and processing in that case are governed by Apple's services and privacy policies.

OpenXBL states that it handles Xbox Live profile information and retains API request logs for usage tracking, billing and debugging. This differs from our collecting screen-view or interaction events for app usage analytics. OpenXBL also states that users may request deletion of their accounts and associated data; disconnecting PlayOrder does not perform that deletion. Please also see the OpenXBL Terms of Service & Privacy Policy.

Please also see the Steam Privacy Policy and Microsoft Privacy Statement.

Apple and RevenueCat

The App uses Apple and RevenueCat to check entitlements, products, prices, renewal, expiration, and related status. These services handle SDK-generated user identifiers, purchase and transaction information, and technical information about the app and device. Checks occur not only when a purchase button is pressed but also at startup and when entering or returning to purchase or settings screens.

The App does not specify a RevenueCat App User ID and uses the ID generated by the SDK. This does not mean that all information is completely anonymous. Please also see the RevenueCat Privacy Policy and Apple Privacy Policy.

04

In-app purchases

PRO is offered through monthly and annual App Store subscriptions. Apple processes payments, and RevenueCat assists with checking purchase status and PRO entitlements. The App has no screen for entering or storing card numbers or similar payment details entered on Apple’s payment screen.

Entitlement checks and local storage of games and notes are separate. Saved games and notes are not deleted solely because of purchase status. Cancellation does not mean immediate deletion of past transaction information.

Deleting customer data from RevenueCat and canceling an Apple subscription are separate actions. Deleting RevenueCat data does not cancel the Apple subscription, and continued use or a later purchase restoration may recreate or re-sync information. Deleting the App does not delete purchase records held by each provider.

For purchase-related requests, we may ask for the Support ID displayed in the App’s Settings to identify the relevant data. The Support ID is not a password. However, it identifies purchase-related information, so please avoid posting it where anyone can see it. Providing the ID alone does not complete identity verification or guarantee deletion.

For requests concerning access, correction, restriction of use, deletion or similar matters, we will check the relevant information and applicable conditions, carry out only the minimum identity verification where needed, and explain whether we can act on the request and its outcome.

05

Usage analytics

This app does not collect or transmit screen-view or interaction events for the purpose of usage analytics.

REPORT aggregates and displays game records stored on your device. It is separate from usage analytics conducted by the app operator.

06

Game images

To display covers and similar images, the device accesses the destination specified by the saved image URL. Images originate from providers such as IGDB and Steam, and image URLs are stored locally. The current cover display uses an in-memory cache.

Image loading is separate from API requests. Image destinations handle IP addresses and other information associated with requests. The App’s memory-cache setting does not determine retention or log deletion by the OS or image provider.

07

Notifications and Widgets

When enabled by the user and permitted by the OS, notifications are scheduled locally on the device. Widget information, including suggested game titles, reasons, and update labels, is shared locally. Game titles and similar information may appear on the lock screen or home screen.

Notifications can be disabled through the app or OS settings, and Widgets can be removed using OS controls. Removing them does not delete saved games or REPORT records. Integrations after opening from a notification or Widget follow the synchronization conditions described above.

08

Device storage and backups

The App has no dedicated feature to back up or restore the entire set of local data through the cloud or export that data to a file.

Local app data, OS backups, iOS Keychain connection credentials, and external providers’ records have different storage locations. Deleting or reinstalling the App does not necessarily erase all of them immediately or permanently.

Depending on OS settings, app data may be included in device backups such as iCloud backups. Backup selection and deletion of saved backups are managed through settings provided by Apple. This is not a dedicated backup feature of the App, and we cannot remotely delete those backups.

Steam and Xbox connection credentials are stored in iOS Keychain with a setting that prevents migration to another device. However, Keychain information may remain on the same device after the App is deleted and reinstalled. Deleting credentials through disconnection is separate from deleting OS backups or records held by external providers.

09

Handling by external providers

External providers handle information for the purposes described above during searches, integrations, entitlement checks, and image display. Opening external pages also involves network-information handling by the destination. Merely viewing the terms page does not cause the App to make a purchase or save an acceptance state.

Use of Apple, RevenueCat, Cloudflare, Steam, Microsoft/Xbox, OpenXBL, IGDB, and other services may involve processing or storage outside Japan. RevenueCat states that customer data sent to its service is stored in AWS data centers in the United States. Not all information is stored exclusively in Japan. The respective service terms and privacy policies also apply. We do not guarantee a uniform retention period or complete deletion of information controlled by third parties.

Information processed by Cloudflare on our behalf is covered by safeguards in the Data Processing Addendum incorporated into our service agreement. This agreement does not restrict all processing or storage to Japan.

10

Data management

Deleting an individual game removes that registration from Collection. Title and aggregate information used to maintain REPORT are retained. Individual deletion is not deletion of all history, including REPORT.

Disconnecting Steam or Xbox deletes local connection information and saved connection credentials. Imported games and REPORT remain. This does not simultaneously delete an external account, revoke provider-side authorization, or erase provider-side history.

There is no dedicated feature for deleting the entire set of local data or for us to remotely delete records on your device. Connection credentials use the OS’s secure storage mechanism, and API connections use HTTPS. This does not mean that all stored information is encrypted in the same way.

Steam and Microsoft/Xbox accounts and provider-side records are handled through each provider’s privacy controls and support channels. Contacting us, disconnecting PlayOrder, and deleting an external account are not the same action.

While responding to a request, we retain only the information needed to respond, to the extent necessary. When the response is complete, we remove attachments, identifiers and other information that are no longer needed.

Where information needs to be retained for legal obligations, disputes, security or similar reasons, we retain it only to the extent needed for that purpose and remove or delete it when the reason for retention no longer applies. This does not guarantee immediate or complete deletion from every storage location, including email services and third-party backups.

11

Changes to this Privacy Policy

We will review this policy in response to changes in the App’s features, external services, applicable laws, or operations.

When we change this policy, we will update this page and the last-updated date. For material changes, we will clearly explain what is changing and when it takes effect. Where appropriate, we will also use existing channels such as App Store release notes.

If a change requires additional consent or other action under applicable law, we will carry out the necessary procedures.

12

Contact

Hiro App WorksEmail: contact@hiroappworks.com

Please use the email address above for questions about this policy or information handling. When you contact us, we handle your reply address, message, and app or device information you provide to respond and investigate. Merely using the App does not collect a support message or contact details.

Please do not include passwords, authentication tokens, card numbers, or more personal information or game records than necessary in your email.

13

Adoption, effective date, and last update