YEET BOX — PRIVACY POLICY
Effective Date: August 18, 2026 Last Updated: August 18, 2026
1. Who We Are
YEET BOX (the "App," the "Game," the "Service") is published by YEET BOX LLC, a Colorado limited liability company with a principal place of business at 6796 S Langdale St, Unit 308, Aurora, CO 80016 ("YEET BOX," "we," "us," "our"). We are the data controller for the personal information described in this Policy.
Contact:
- Privacy and general enquiries: support@yeetbox.app
- Postal: YEET BOX LLC, 6796 S Langdale St, Unit 308, Aurora, CO 80016
- EU/UK Representative: Not currently appointed. YEET BOX LLC is a U.S. company with no establishment in the EU or UK. If the Service becomes regularly available to EU or UK users at scale, we will appoint a representative as required by Article 27 GDPR / UK GDPR and update this section.
This Policy explains what we collect, why, how long we keep it, who we share it with, and what rights you have. It applies to the iOS application and to yeetboxgame.com (the "Site").
2. Summary — "Dark Protocol"
YEET BOX is a real-world proximity game, and we designed it so that playing it does not require us to know where you are.
- We never collect, transmit, or store GPS or any location data. Not precise, not coarse, not at any time. The App does not request location permission.
- Proximity is detected locally on your device using Bluetooth Low Energy ("BLE") radio signal strength. Your phone can tell that another player's phone is nearby, not where either of you is. That determination happens on the device and is not sent to us.
- The identifier your phone broadcasts is a random, rotating, meaningless token. It rotates every 15 minutes and expires within 30 minutes. It contains no name, no user ID, no account information, and no location.
- When your in-game box is empty, your phone broadcasts nothing at all.
- You can only be detected by, and can only detect, players you have explicitly accepted as friends. Detection is mutual and consent-based on both sides. Strangers cannot detect you.
- No third-party advertising SDKs. No advertising identifiers. No cross-app tracking. We do not sell or share your personal information.
- We keep no location history, no message history, and no behavioural profiling.
This summary is provided for clarity and does not replace the detail below.
3. Age Requirements
YEET BOX is rated 13+ and is not directed to children under 13.
- We apply an age gate on first launch. If you indicate you are under 13, sign-up is blocked and no account is created and no personal information is retained from that attempt beyond what is necessary to enforce the block.
- We do not knowingly collect personal information from anyone under 13. If we learn that we have, we will delete the account and associated data promptly. Parents and guardians who believe a child under 13 has created an account should contact support@yeetbox.app.
- Our age gate works by self-attested birth year. We do not independently verify age, and we rely in part on Apple's own age-rating (13+) and parental control tools (Screen Time, Ask to Buy) as an additional layer for younger teens whose devices are managed by a parent or guardian.
- If you are between 13 and the age of majority where you live, you may use YEET BOX only with the awareness and consent of a parent or legal guardian, who is encouraged to review this Policy and our Terms of Service. If a jurisdiction requires a specific verifiable parental consent mechanism beyond self-attested age-gating, we will implement it for users in that jurisdiction and update this Policy accordingly.
- We do not use minors' data for advertising, profiling, or any purpose other than operating the Game and keeping it safe.
4. Information We Collect
4.1 Information you give us
| Data | Why we have it | Notes |
|---|---|---|
| Phone number | Account creation and sign-in (SMS one-time passcode) | Handled by Firebase Authentication. Within our own game database we store only a cryptographic hash of the number, not the number itself. |
| Birth year | 13+ age gate and legal compliance | We collect the year only — not a full date of birth. |
| Display name ("alias") | Your public identity in the Game | Visible to your friends and, where you appear, on leaderboards. Choose a name that does not identify you personally. |
| Avatar selection | Profile display | Chosen from 12 preset images. We do not accept uploaded photos. |
| Email address | Optional and only if you ask us to email you your Recovery Code. | Not collected at sign-up. Collected only at the moment you use the "email it to me" function, and stored so you don't have to re-enter it. |
| Reports you submit | Safety and moderation | Includes the category you select and any optional free-text detail you write. |
| Support correspondence | Answering you | Whatever you choose to include in an email to support. |
4.2 Information generated by playing
| Data | Why we have it |
|---|---|
| Game state — points balance, lifetime points earned, tier classification, current in-game item, active and shelved consumables, timers | To run the Game. All game state is authoritative on our servers. |
| Extraction history — a capped, rolling log of your most recent 100 extractions, recording the other player's account ID, the item tier, outcome, and timestamp | Gameplay history, support, and anti-cheat. It records no location and no display name. |
| Statistics — total extractions, times extracted from, invites accepted | Profile display and leaderboards. |
| Friends list and invite relationships (including your invite code and, if you joined via someone's code, a permanent one-time record of who invited you) | Friend-gated detection and the referral programme. |
| Blocked-user list | To enforce mutual invisibility between blocked players. |
| Moderation state — reports filed against you in the trailing 90 days, suspension status, suspension count, ban status | Community safety and enforcement of the Terms. |
| Presence heartbeat — a "last seen" timestamp and a session-start timestamp | To award time-based in-game points only while the app is in the foreground, and to prevent point inflation. Continuously overwritten; no history is kept. |
| Ephemeral BLE tokens and the short-lived server mapping from a token to an account ID | To let friends' devices confirm that a detected signal belongs to a friend. Rotates every 15 minutes; expires within 30 minutes. |
| Bluetooth signal strength (RSSI) | Read on your device to determine how long an extraction takes. We record only a coarse bucket (weak / medium / strong) in anonymous analytics — never a raw distance, and never a location. |
| Purchase records — App Store transaction identifiers, product identifiers, a receipt hash, timestamps, refund status | Delivering what you paid for, preventing duplicate or fraudulent delivery, refund handling, and tax/audit obligations. |
4.3 Information collected automatically
| Data | Source | Notes |
|---|---|---|
| Push notification tokens (up to 10 devices) | Apple Push Notification service via Firebase Cloud Messaging | Only if you allow notifications. Used solely to deliver game notifications. |
| Hashed device identifier | The iOS "identifier for vendor," hashed with SHA-256 before storage | Used only to limit sign-ups to three per device per 30 days as an anti-abuse measure. This is a per-vendor value that resets when you delete all of our apps; it is not an advertising identifier and cannot be used to track you across other companies' apps. |
| App integrity attestation | Apple App Attest via Firebase App Check | Confirms requests come from a genuine copy of the App rather than a bot or script. No personal information. |
| Crash and performance data | Firebase Crashlytics | Device model, OS version, stack traces, and breadcrumb events leading to a crash. Not linked to your identity. |
| Anonymous usage analytics | Firebase Analytics | A fixed list of game events (for example: app opened, extraction attempted, extraction succeeded, item purchased, tier promoted). No advertising identifiers, no third-party analytics, no cross-app or cross-site tracking, and no IDFA. |
| Standard technical logs | Google Cloud / Firebase | IP address, timestamps, and request metadata retained transiently for security, abuse prevention, and debugging. |
4.4 Information we deliberately do not collect
Precise or coarse location · GPS · Wi-Fi or cell-tower positioning · your contacts or address book · photos, camera, or microphone · health or fitness data · browsing or search history · advertising identifiers (IDFA) · payment card numbers, bank details, or billing addresses (Apple processes all payments; we never see your payment instrument) · biometrics · any content of your messages with other people.
We do not run advertising in YEET BOX and we do not integrate any advertising SDK.
5. How We Use Information
We use personal information to:
- 1. Create and authenticate your account and keep it secure.
- 2. Operate the Game — detection, extractions, points, tiers, items, timers, leaderboards, and notifications.
- 3. Deliver and verify in-app purchases and handle refunds and purchase disputes.
- 4. Enforce the age gate and our Terms of Service and Community Guidelines.
- 5. Investigate reports, prevent harassment and abuse, and suspend or ban accounts where warranted.
- 6. Detect, prevent, and investigate cheating, fraud, multi-accounting, and technical abuse of our systems.
- 7. Provide customer support, including account recovery.
- 8. Diagnose crashes, fix bugs, and understand aggregate usage so we can improve the Game.
- 9. Comply with law, respond to lawful requests, and establish or defend legal claims.
We do not use your information for advertising, ad targeting, ad measurement, credit or insurance decisions, or automated decision-making that produces legal or similarly significant effects. Automated moderation is limited to a report-count threshold that can result in a temporary or permanent account suspension; you may contest any suspension by contacting support@yeetbox.app and a human will review it.
6. Legal Bases for Processing (EEA / UK)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following bases under the GDPR / UK GDPR:
| Purpose | Legal basis |
|---|---|
| Creating your account; running the Game; delivering purchases; providing support | Contract — Art. 6(1)(b): necessary to perform the Terms of Service you enter into with us. |
| Anti-abuse, anti-cheat, moderation, security, fraud prevention, service improvement, aggregate analytics | Legitimate interests — Art. 6(1)(f): our interest in a safe, functioning, non-fraudulent game, balanced against your rights. You may object (Section 12). |
| Age gating; retaining transaction records; responding to lawful requests | Legal obligation — Art. 6(1)(c). |
| Push notifications; emailing you your Recovery Code | Consent — Art. 6(1)(a). Withdrawable at any time (device settings; or simply do not use the email function). |
| Safety-critical processing to protect a person from harm | Vital interests — Art. 6(1)(d), where applicable. |
Where we rely on consent, withdrawing it does not affect processing carried out before withdrawal.
7. How Information Is Shared
We do not sell your personal information. We do not share it for cross-context behavioural advertising. We do not disclose it to data brokers.
7.1 With other players
Other players can see: your display name, your avatar, your tier, your extraction statistics, and — where you rank — your position and points on leaderboards. Players on your friends list can see when you are detectable nearby (a proximity state only — never a location, an address, a direction, or a history). Your phone number, email address, birth year, purchase history, and blocked list are never shown to other players.
7.2 With service providers (processors)
| Provider | Role | Data involved |
|---|---|---|
| Google LLC (Firebase / Google Cloud Platform) | Authentication, database, serverless backend, push messaging, analytics, crash reporting, app-integrity checks, hosting | Substantially all account and game data. Servers located in the United States (us-central1). |
| Apple Inc. | App distribution, in-app purchase processing, push notification delivery, device attestation | Purchase transactions, receipts, push tokens. Apple's handling is governed by Apple's own privacy policy. |
| RevenueCat, Inc. | In-app purchase validation and receipt management | Anonymous app user ID, product IDs, transaction IDs, receipt metadata. |
| SendGrid (Twilio Inc.), via the Firebase Trigger Email extension | Sending the Recovery Code email you request | Your email address and the message content. The Recovery Code passes through this pipeline transiently in order to be delivered. |
| Expo (650 Industries, Inc.) | App builds and over-the-air updates | Technical update metadata. |
Each processor's use of data is governed by its own standard data processing terms (for example, Google's Data Processing Amendment for Firebase/Google Cloud, and RevenueCat's Data Processing Addendum), which we have accepted as part of using their services, and each may use the data only to provide services to us.
7.3 For legal and safety reasons
We may disclose information where we believe in good faith it is reasonably necessary to: comply with applicable law, regulation, subpoena, court order, or other valid legal process; enforce our Terms; investigate suspected fraud, cheating, or abuse; or protect the rights, property, or safety of our users, the public, or us — including responding to a credible threat of harm and cooperating with law enforcement.
7.4 Business transfers
If we are involved in a merger, acquisition, financing, reorganisation, bankruptcy, or sale of assets, information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a materially different privacy policy.
8. Retention
We keep personal information only as long as necessary for the purposes above.
| Data | Retention |
|---|---|
| Account record (alias, avatar, hashed phone, birth year, game state, stats) | For the life of your account; deleted on account deletion. |
| BLE ephemeral tokens | Rotate every 15 minutes; expire and are deleted within 30 minutes. |
| Extraction locks | 30 seconds. |
| Presence heartbeats | Continuously overwritten; no history retained. |
| Extraction log | Rolling most recent 100 entries per account; older entries dropped automatically. |
| Weekly leaderboard snapshots | 90 days. |
| Display name after account deletion or name change | The name string alone is held in quarantine for 90 days to prevent impersonation, then released. No account data is attached to it. |
| Phone-number re-registration cooldown (only where an account was deleted while suspended, or with 3+ reports in the prior 90 days) | 90 days, or indefinitely for permanently banned accounts. Stored as a number-derived key for anti-evasion only. |
| Reports | Counted against an account for 90 days; report records retained for one (1) year from filing for pattern detection and appeals, then deleted. |
| Purchase / transaction idempotency records | 180 days, then automatically deleted. Underlying purchase-log entries are retained as long as required for tax, accounting, refund, and audit obligations — generally no longer than seven (7) years. |
| Administrative moderation audit entries | Retained as an immutable record. Contains account IDs and moderation reasons; never raw phone numbers. |
| Crash and anonymous analytics data | Per Firebase defaults (typically 90 days to 14 months, depending on data type). |
We may retain information longer where necessary to comply with a legal obligation, resolve a dispute, or enforce our agreements.
9. Account Deletion and What Survives It
You can delete your account at any time: Profile → Settings → Delete My Account. Deletion is a deliberate two-step confirmation and cannot be undone.
On deletion we remove your user record and the personal information attached to it, including your alias, avatar, hashed phone number, birth year, email address (if any), Recovery Code hash, push tokens, friends and blocked lists, game state, points, and statistics.
What remains, and why:
- Your display name is quarantined for 90 days (anti-impersonation), then released for anyone to claim.
- Other players' extraction logs may still contain a bare account identifier referring to a past interaction with you. Because display names are resolved live from the account record, that identifier resolves to nothing once your record is deleted — it is not linkable to you.
- Transaction records are retained where required for tax, accounting, refund, and platform-audit purposes.
- Moderation audit entries for accounts suspended or banned are retained; these contain account identifiers and reasons, not raw phone numbers.
- Anonymous, aggregated analytics that cannot be linked back to you are not deleted.
- Backups. Deletions propagate to routine backups within 30 days, after which the data is overwritten in the ordinary backup rotation.
Deleting your account permanently forfeits all points, items, and consumables, including purchased ones. These are not refundable. See the Terms of Service.
10. Security
- All traffic between the App and our servers is encrypted in transit (TLS). Data at rest is encrypted by Google Cloud.
- All game-state changes are made exclusively by our server-side functions. The App cannot write to the database directly.
- Your raw phone number is stored only within Firebase Authentication; our game database holds only a hash.
- Your Recovery Code is never stored in plaintext — only a bcrypt hash. We cannot look it up or recover it for you. If you ask us to email it, the App generates a fresh code and sends that.
- Requests are attested with Apple App Attest so that scripts and bots cannot impersonate the App.
- Administrative access is restricted, requires a privileged credential, and every administrative action is written to an immutable audit log.
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your device, your phone number, and your Recovery Code secure.
Breach notification. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected users, within the timeframes set by applicable law.
11. International Transfers
We are based in the United States, and our infrastructure is hosted in the United States. If you use YEET BOX from outside the United States, your information will be transferred to, stored in, and processed in the United States and other countries where our service providers operate, which may have different data-protection laws than your own.
Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum / UK IDTA where applicable) together with supplementary measures as needed. You may request a copy of the relevant safeguards by contacting support@yeetbox.app.
12. Your Rights
Subject to applicable law, you have the right to:
- Access — obtain a copy of the personal information we hold about you. The App provides a data-export function that produces a machine-readable JSON file of your account data and emails it to you.
- Rectification — correct inaccurate information. You can change your display name and avatar in Settings (subject to in-game cooldowns).
- Erasure — delete your account and data (Section 9), subject to the limited exceptions listed there.
- Portability — receive your data in a structured, commonly used, machine-readable format (the export above).
- Restriction — ask us to limit processing in certain circumstances.
- Objection — object to processing based on our legitimate interests, including profiling. Note that we do not profile users for advertising.
- Withdraw consent — at any time, without affecting prior processing.
- Complain — lodge a complaint with your local supervisory authority (EEA), the UK Information Commissioner's Office, or another competent regulator. We would appreciate the chance to address it first.
How to exercise these rights: use the in-app functions where available, or email support@yeetbox.app from the email address on file or with your display name and enough information for us to verify you. We will respond within 30 days (extendable where permitted by law). We will not discriminate against you for exercising your rights, and we do not charge a fee unless a request is manifestly unfounded or excessive.
Verification. Because we authenticate by phone number and store only a hash, we may need you to verify from the phone number on the account, or to supply your Recovery Code or an Apple purchase receipt, before we act on a request. This protects you against someone else making requests in your name.
Authorised agents may submit requests on your behalf with written proof of authorisation and verification of your identity.
13. United States State Privacy Rights
California (CCPA/CPRA). In the 12 months before the effective date of this Policy we collect the categories described in Section 4, which map to the statutory categories: identifiers (phone number in hashed form, account ID, device identifier in hashed form, email if provided); commercial information (purchase records); internet or other electronic network activity (in-app usage events); and inferences limited to in-game tier classification. We collect these from you, from your device, and from our service providers, for the business purposes in Section 5, and we disclose them to the service providers in Section 7.2.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising — including that of any consumer we know to be under 16.
- We do not use or disclose sensitive personal information for purposes beyond those permitted under CPRA § 7027(m).
- California residents have the rights to know, delete, correct, opt out of sale/sharing (not applicable — we do neither), limit use of sensitive personal information (not applicable), and to be free from retaliation. Exercise them as described in Section 12.
Other states (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others as their laws take effect) provide comparable rights to access, correct, delete, port, and opt out of targeted advertising, sale, and certain profiling. We do not conduct targeted advertising, sale, or profiling with legal effects. To appeal a decision we make on a rights request, reply to our response with "Appeal" and a human will re-review; if we deny the appeal you may contact your state Attorney General.
Nevada. We do not sell covered information as defined by Nevada law.
14. Bluetooth, Notifications, and Your Device Controls
- Bluetooth is required. Without it, the Game cannot detect nearby players and will not function. You can revoke Bluetooth permission at any time in iOS Settings; the Game will stop working until you restore it.
- Push notifications are optional. Manage them in iOS Settings or in the App's notification preferences.
- Our use of Bluetooth is exclusively for local proximity detection between consenting friends. We do not use Bluetooth for location inference, beacon-based tracking, retail analytics, or any advertising purpose, and we do not share Bluetooth-derived data with anyone.
- We do not respond to browser "Do Not Track" signals, as the App is not a web browser. Where required, we honour the Global Privacy Control signal on our website.
15. Cookies and the Website
yeetboxgame.com uses only strictly necessary cookies required for the site to function (for example, session and security cookies). We do not use advertising or non-essential analytics cookies on the site, so no cookie-consent banner is required. The App itself does not use cookies.
16. Changes to This Policy
We may update this Policy. If we make material changes we will notify you in the App and/or by push notification before the changes take effect, and we will update the "Last Updated" date. Where required by law, we will obtain your consent. Continuing to use YEET BOX after changes take effect means you accept the updated Policy.
17. Contact
Questions, requests, or complaints:
YEET BOX LLC support@yeetbox.app 6796 S Langdale St, Unit 308, Aurora, CO 80016