Privacy Policy
Last updated: 17 September 2026
Chonky is a walking game for iPhone and Apple Watch made by Russell Ong. This policy explains what the app reads, what it stores, and what leaves your device. The short version: the game runs on your steps; detailed Health data stays on your device; the local adventure needs no account; optional online features, purchases, and adult opt-in rewarded ads use the limited data described below; and we do not sell your personal data.
Playing without an account
The full local adventure works without any account. In that mode your progress, rewards, and home decorations are stored only on your device and in your personal iCloud device backup. We cannot see them.
Apple Health
- On iPhone, Chonky requests read-only access to step count. The iPhone app does not write to Health.
- On Apple Watch, Chonky requests permission to read steps and walking/running distance and to save workouts. Trail Walks you start on the Watch can be saved in Apple Health as Outdoor Walk workouts. The Watch uses workout steps, distance, and elapsed time to show your walk's progress.
- Chonky does not request access to heart rate, weight, your existing workout history, or location. Choosing an Outdoor Walk does not enable route or location tracking.
- Step data is processed on your devices to charge attacks and track daily progress. You can change Health permissions in Apple's Health settings or use Manual Walk for the local adventure.
- If a signed, server-verified competitive feature is enabled in a future release, the app may submit step totals as plain numbers so results can be verified and shared fairly. Those features are currently unavailable. No HealthKit sample or other Health information leaves your device.
Signing in with Apple
Online features (Packs, leaderboards, friends, home sync) require Sign in with Apple. When you sign in:
- We create a pseudonymous player record. The server verifies the Apple identity token for sign-in and keeps a one-way keyed hash of the Apple subject in the account record; it does not retain the raw Apple subject or identity token in that record. We do not request your Apple relay email address.
- On your device, Chonky stores the Apple user identifier and Chonky access and refresh tokens in the current-device iOS Keychain. This secure record lets the app restore and refresh your sign-in and is separate from the ordinary local game database.
- When Apple supplies a refresh token for your sign-in, our server stores it encrypted so it can revoke Apple's authorization when you delete your account.
- We store your player profile (display name, avatar choice), game state you share online (Pack membership, contributions, inventory, home room layouts, friends, gifts), and the security records needed to keep sessions safe.
- Apple's App Attest helps verify that requests come from a genuine copy of the app on a real device. Our server stores the public verification key, Apple's attestation receipt, app build, request counters, and related timestamps. The private signing key stays on your device.
Purchases
Optional purchases are processed by Apple through the App Store. RevenueCat provides purchase validation, entitlement status, and signed delivery events. Apple and RevenueCat may process the product, purchase time, status, storefront, and a pseudonymous app user identifier needed to provide and restore purchases. Chonky never receives your card or other payment details. Our server stores only the product, delivery status, pseudonymous account, and one-way-hashed transaction identifiers needed to prevent duplicate delivery.
Optional ads
- Release-gated, off by default, and adults only: this feature is unavailable unless Chonky activates its verified server delivery contract for the installed release. Even then, the ad service is not initialized or used unless a signed-in player explicitly confirms they are 18 or older and enables optional ads. Children and anyone who does not confirm adult use must keep ads off.
- Adult opt-in placements: after enabling optional ads, an eligible adult may see one small banner above the main tabs. After the normal Daily Walk reward is complete, they may also choose to watch at most one rewarded ad per day for one additional Gem. Chonky has no forced, app-open, post-loss, or purchase-shortfall ads. Walking rewards and progression never require an ad.
- Your ad privacy choice: adults can choose relevant ads, non-personalized ads, or keep ads off. The relevant-ad choice explains the use first and then opens Apple's App Tracking Transparency prompt. If Apple does not authorize tracking, Chonky falls back to non-personalized ads and IDFA is unavailable. If authorization already exists and you choose non-personalized ads, Google disables personalization but may still use permitted mobile ad identifiers for frequency capping and aggregate reporting. Chonky also runs Google's User Messaging Platform flow and requests ads only when it permits them. Publisher first-party identifiers remain disabled.
- Ad serving and measurement: Google AdMob serves the ad. Google and participating demand sources may process data needed to request, deliver, secure, personalize when authorized, and measure an ad, such as IP address, device and app information, permitted device identifiers, approximate location inferred from IP, ad unit and network, interaction and completion events, timestamps, impression revenue, crash data, performance data, and other diagnostic data. RevenueCat receives ad lifecycle and impression-revenue events tied to Chonky's pseudonymous app user identifier so we can measure the feature alongside purchases.
- Server-verified reward: the app's completion callback cannot add Gems. AdMob sends a server-side verification event to RevenueCat. RevenueCat verifies it and sends Chonky Live an authenticated virtual-currency event containing pseudonymous customer, RevenueCat and AdMob transaction identifiers, source, and the currency adjustment. Chonky Live accepts only the configured ad-reward source and exactly one GEMS adjustment, then stores the minimum event, day, placement, pseudonymous account, and reward record needed to prevent duplicate or over-limit grants.
- No Health data for ads: Google AdMob, its demand sources, and RevenueCat do not receive HealthKit samples, step totals, workouts, weight, or other Health data from the ad flow.
- Your control: you can keep ads off or stop new ad requests at any time in Chonky Settings. A permanent No Banner Ads purchase removes passive banners while leaving the optional rewarded choice available; an active Chonky Club membership also suppresses banners. Where Google requires it, Settings provides Privacy Options for reviewing your regional choices.
Online wallet
If you sign in, Chonky Live stores a server-owned Gem wallet and reward ledger for your account so each Gem purchase and each verified reward is delivered exactly once. The wallet balance is sent to the app through inventory sync and is shown only to the signed-in account that owns it. Coins remain earned through local play and are not uploaded as wallet currency.
Friend invitations
- We store the public referral code, pseudonymous inviter and invitee account identifiers, reservation and claim status, integrity result, reward history, and expiry timestamps needed to complete and protect an invitation.
- The App Clip and full app may use App Attest to verify genuine app requests. Key identifiers are one-way hashed; proofs are verified and not logged.
- If you choose Reserve with Apple, your Apple-backed pseudonymous Chonky identifier is used to find the invitation after you sign in on another device.
- The optional Paste Invite button reads only after you tap it and accepts only a Chonky one-time link. The link is not logged, and unrelated clipboard content is never requested or stored.
- Referral qualification receives only a server-validated “Meet Your Pack completed” event. Raw HealthKit samples, step counts, distances, and timestamps never enter the referral service.
What we do not do
- No forced, app-open, post-loss, or progression-gating ads.
- No selling or renting of personal data by Chonky.
- No sharing of Health data with advertisers, ad networks, RevenueCat, or other players.
- No reading of contacts, photos, or location, and no automatic clipboard scanning.
Your data, your controls
- Export: signed-in players can download a portable copy of their online game data from inside the app.
- Deletion: you can delete your account from inside the app. This removes your account and personal game state from our server. A hashed deletion receipt expires after 90 days so an interrupted deletion can be confirmed safely. If Apple's authorization cannot be revoked immediately, an encrypted token is retained while the server retries; it is removed after successful revocation or scheduled for removal after 90 days. Operational records without your account identity may also remain.
- Deleting the app removes its ordinary local game database, but it does not guarantee that Keychain items are removed; current-device Keychain records can survive an uninstall. Uninstalling is therefore not the same as signing out or deleting an account.
- Signing out deletes the saved Apple identifier and account session tokens from the Keychain on that device. Deleting your account also removes its account-bound security state as device cleanup completes. A later installation validates any surviving Keychain session with Apple and Chonky Live before it can restore the account.
Data security
Traffic to Chonky Live is encrypted with TLS. Where the server needs to correlate the identifiers described in this policy, it uses domain-separated keyed hashes rather than raw values.
Children
Chonky does not knowingly collect personal information from children. Playing offline requires no personal information at all. Google AdMob is never initialized or used unless the player explicitly confirms they are at least 18; optional ads must remain off for children. If you believe a child has created an online account without permission, contact us and we will delete it.
Changes
If this policy changes, the new version will be posted here with an updated date. Material changes will be called out in the app.
Contact
Questions about privacy or your data: russellongdev@gmail.com