Privacy Policy
Last updated: 27 September 2026
Chonky is a walking game for iPhone and Apple Watch made by Russell Ong. This policy explains what the app reads, what it stores, and what leaves your device. The short version: the game runs on your steps; detailed Health data stays on your device; the local adventure needs no account; optional online features, purchases, and ads for adults use the limited data described below; other players see only what is listed under What other players can see; and we do not sell your personal data.
Playing without an account
The full local adventure works without any account. In that mode your progress, rewards, and home decorations are stored only on your device and in your personal iCloud device backup. We cannot see them.
Apple Health
- On iPhone, Chonky requests read-only access to step count. The iPhone app does not write to Health.
- On Apple Watch, Chonky requests permission to read steps and walking/running distance and to save workouts. Trail Walks you start on the Watch can be saved in Apple Health as Outdoor Walk workouts. The Watch uses workout steps, distance, and elapsed time to show your walk's progress.
- Chonky does not request access to heart rate, weight, your existing workout history, or location. Choosing an Outdoor Walk does not enable route or location tracking.
- Step data is processed on your devices to charge attacks and track daily progress. You can change Health permissions in Apple's Health settings or use Manual Walk for the local adventure.
- When you are signed in, in a Pack, and using Apple Health on iPhone, the app sends your step counts as plain numbers, with the day and time window they cover, signed by App Attest so Packs and leaderboards stay fair. Manual Walk steps are never sent. No HealthKit sample or other Health information leaves your device.
Signing in with Apple
Online features (Packs, Friends, Leaderboards, friend invites, home sync) require Sign in with Apple. When you sign in:
- We create a pseudonymous player record. The server verifies the Apple identity token for sign-in and keeps a one-way keyed hash of the Apple subject in the account record; it does not retain the raw Apple subject or identity token in that record. We do not request your Apple relay email address.
- On your device, Chonky stores the Apple user identifier, Chonky access and refresh tokens, and a random app installation identifier in the current-device iOS Keychain. This secure record lets the app restore and refresh your sign-in and is separate from the ordinary local game database.
- When Apple supplies a refresh token for your sign-in, our server stores it encrypted so it can revoke Apple's authorization when you delete your account.
- We store your player profile (player name, look, title, and your Public Profile and Leaderboards choices), game state you share online (Pack membership, step contributions, Team Battle and Daily Dash results, inventory, home room layouts, friends and friend requests), and the security records needed to keep sessions safe, including a one-way hash of the app installation identifier for each sign-in.
- Apple's App Attest helps verify that requests come from a genuine copy of the app on a real device. Our server stores the public verification key, Apple's attestation receipt, app build, request counters, and related timestamps. The private signing key stays on your device.
Purchases
Optional purchases are processed by Apple through the App Store. RevenueCat provides purchase validation, entitlement status, and signed delivery events. Apple and RevenueCat may process the product, purchase time, status, storefront, and a pseudonymous app user identifier needed to provide and restore purchases. You can buy Chonky Club and No Banner Ads without an account; RevenueCat then uses a random identifier created on this install, and if you sign in later, the purchase moves to your account. Chonky never receives your card or other payment details. Our server stores only the product, delivery status, pseudonymous account, and one-way-hashed transaction identifiers needed to prevent duplicate delivery.
Optional ads
- For adults, on by default: the app asks your age group. If you say you are under 18, or have not chosen an age group, you get no ads and no tracking prompt, and the ad service never starts. If you say you are 18 or older, ads are on, and Apple's App Tracking Transparency prompt appears as you continue, with nothing from Chonky in front of it. Where the law requires Google's consent form, it follows once you have answered Apple's prompt. Ads are shown only once a signed-in adult's account is connected to Chonky Live.
- What adults see: a signed-in adult may see one small banner above the main tabs. After the normal Daily Walk reward is complete, they may also choose to watch at most one rewarded ad per day for one additional Gem. Ads are limited to content suitable for a parental-guidance audience. Chonky has no forced, app-open, post-loss, or purchase-shortfall ads. Walking rewards and progression never require an ad.
- Apple's prompt decides personalization: if you allow tracking, Google may use your device's advertising identifier (IDFA) to personalize and measure ads. If you ask the app not to track, if tracking is restricted on your device, or if you have not answered, ads are not personalized and IDFA is unavailable. You can change your answer any time in the iOS Settings app; Chonky's Settings links straight there. Chonky also runs Google's User Messaging Platform flow and requests ads only when it permits them. Publisher first-party identifiers remain disabled.
- Ad serving and measurement: Google AdMob serves the ad. Google and participating demand sources may process data needed to request, deliver, secure, personalize when authorized, and measure an ad, such as IP address, device and app information, permitted device identifiers, approximate location inferred from IP, ad unit and network, interaction and completion events, timestamps, impression revenue, crash data, performance data, and other diagnostic data. RevenueCat receives ad lifecycle and impression-revenue events tied to Chonky's pseudonymous app user identifier so we can measure the feature alongside purchases.
- Server-verified reward: the app's completion callback cannot add Gems. AdMob sends a server-side verification event to RevenueCat. RevenueCat verifies it and sends Chonky Live an authenticated virtual-currency event containing pseudonymous customer, RevenueCat and AdMob transaction identifiers, source, and the currency adjustment. Chonky Live accepts only the configured ad-reward source and exactly one GEMS adjustment, then stores the minimum event, day, placement, pseudonymous account, and reward record needed to prevent duplicate or over-limit grants.
- No Health data for ads: Google AdMob, its demand sources, and RevenueCat do not receive HealthKit samples, step totals, workouts, weight, or other Health data from the ad flow.
- Your control: you can turn ads off at any time in Chonky Settings, under Age & Ads, which stops new ad requests. A permanent No Banner Ads purchase removes passive banners while leaving the optional rewarded choice available; an active Chonky Club membership also suppresses banners. Where Google requires it, Settings provides Privacy Options for reviewing your regional choices.
Online wallet
If you sign in, Chonky Live stores a server-owned Gem wallet and reward ledger for your account so each Gem purchase and each verified reward is delivered exactly once. Gems bought before you sign in are held by the anonymous purchase ID the store uses on your iPhone. When you sign in, the app sends that ID and the purchases' transaction IDs to Chonky Live, which keeps a one-way code of the ID with your account so those Gems are credited once and never to a second account. The Gem balance is sent to the app through inventory sync and is shown only to the signed-in account that owns it. Coins you earn by playing stay on your device. When the server issues Coins, for a Gem exchange or a friend invite reward, it keeps a signed Coin receipt and a running total for your account, and the app adds those Coins to your balance once. Coins are in-game currency with no cash value.
Friend invitations
- We store the public referral code, pseudonymous inviter and invitee account identifiers, reservation and claim status, integrity result, reward history, and expiry timestamps needed to complete and protect an invitation.
- The App Clip and full app may use App Attest to verify genuine app requests. Key identifiers are one-way hashed; proofs are verified and not logged.
- If you choose Reserve with Apple on the invite page, we keep a one-way hash of your Apple Account with the saved invite, so it can find you after you sign in on another device.
- The Paste button in Invite Friends reads your clipboard only when you tap it, and uses only a Chonky invite code or link. What it reads is not logged, and unrelated clipboard content is never stored.
- An invite qualifies when the invited player joins or starts a Pack and takes a walk in it within 30 days, and it pays once their account is at least a day old. The referral service checks only Pack membership and whether and when a verified walk was recorded. It never receives step counts, HealthKit samples, distances, or other Health data.
- To stop self-invites, the referral service checks whether the two accounts share an iPhone by comparing the one-way-hashed App Attest keys and app installation identifiers described above. It also keeps a one-way hash of the invited player's Apple Account so each Apple Account gets one welcome reward.
- Using an invite sends the invited player a friend request from the inviter, which they can accept or decline.
What other players can see
- Your player name, look and title are shown to your friends, to anyone on the other side of a friend request, and to your Pack. Chonky's Form shows too, but only when Public Profile is on.
- Your Pack also sees your daily steps and your Team Battle damage, in the Team Battle, the Daily Dash and Pack Pulse.
- When Public Profile is on, friends see your latest walk this week (the day and its step count) and can visit your Home.
- Your name, look, step totals and Adventure Points appear on leaderboards only when Public Profile and Leaderboards are both on. Both start off. Leaderboards never show your friend code.
- Anyone with your invite link or code can see your player name and look, and your Pack's name and size, for example in the App Clip.
- There is no chat. Other players never see your Health data, your Apple Account, or where you walk.
Reports and blocks
- We keep your blocks until you undo them.
- When you report a player or a Pack name, we keep the report, the reason you picked, the name and friend code you reported, and what we did about it. The player you report is never told who reported them.
- We review every report within 24 hours. Resolved reports are deleted after 180 days.
- A record of any action we take on an account, with the name and friend code it had then, is kept for 2 years to keep players safe, even if that account is deleted.
- If we suspend an account, we keep a one-way hash of its Apple Account, so the suspension still applies if the same Apple Account makes a new Chonky account.
What we do not do
- No forced, app-open, post-loss, or progression-gating ads.
- No selling or renting of personal data by Chonky.
- No sharing of Health data with advertisers, ad networks, or RevenueCat. Step totals reach other players only as described in What other players can see.
- No reading of contacts, photos, or location, and no automatic clipboard scanning.
- No chat or direct messages between players.
Your data, your controls
- Export: signed-in players can download a portable copy of their online game data from inside the app.
- Sharing: turn Public Profile and Leaderboards on or off at any time in Settings, under Online Sharing. You can undo a block in Settings, under Blocked Players.
- Deletion: you can delete your account from inside the app. This removes your account and personal game state from our server. A hashed deletion receipt expires after 90 days so an interrupted deletion can be confirmed safely. If Apple's authorization cannot be revoked immediately, an encrypted token is retained while the server retries; it is removed after successful revocation or scheduled for removal after 90 days. Operational records without your account identity may also remain. Some records stay after deletion: reports about your account and any action we took on it, kept as described in Reports and blocks; a one-way hash of your Apple Account if the account was suspended; and, if you used an invite, a one-way hash of your Apple Account so one Apple Account gets one welcome reward.
- Deleting the app removes its ordinary local game database, but it does not guarantee that Keychain items are removed; current-device Keychain records can survive an uninstall. Uninstalling is therefore not the same as signing out or deleting an account.
- Signing out deletes the saved Apple identifier and account session tokens from the Keychain on that device. Deleting your account also removes its account-bound security state as device cleanup completes. A later installation validates any surviving Keychain session with Apple and Chonky Live before it can restore the account.
Data security
Traffic to Chonky Live is encrypted with TLS. Where the server needs to correlate the identifiers described in this policy, it uses domain-separated keyed hashes rather than raw values.
Children
Chonky does not knowingly collect personal information from children. Playing offline requires no personal information at all. Online play needs Sign in with Apple, and other players see the player name and look you choose, so pick a name that is not your real name. Player names and Pack names are the only things players type that others can see, and they pass a word filter. There is no chat, Public Profile and Leaderboards start off, and every player can block or report anyone. Google AdMob is never initialized or used unless the player explicitly confirms they are at least 18; optional ads must remain off for children. If you believe a child has created an online account without permission, contact us and we will delete it.
Changes
If this policy changes, the new version will be posted here with an updated date. Material changes will be called out in the app.
Contact
Questions about privacy or your data: russellongdev@gmail.com