Privacy Policy
“Post Mortem” app (Android and iOS).
Effective 12 September 2026.
1. Who is responsible, and who to contact
The app is published by Benoît Roussel, the data controller under the General Data Protection Regulation (GDPR).
For any question about your data, and to exercise one of the rights in section 10: contact@laboitebleue.games.
2. What the app stores on your phone
So that your game survives from one launch to the next, the app writes to the private storage the operating system reserves for it: which riddles you have solved, read the solution to or marked as favorites, when you last opened each of them, the language you picked, the course of your solo investigations, the permission you gave solo mode, a random token created with your first solo question and used to count your questions for the day, which paid packs you own, and the answer you gave to the advertising consent form in section 6. If you enable usage statistics, it also stores that choice and a separate random measurement identifier (section 12).
No name, no email address, no location: riddle and product identifiers, counters, dates, the text you typed yourself in solo mode, and the answer you gave the consent form in section 6. None of it is sent to us, with these exceptions: in solo mode, your questions and the token go to the service that answers them (section 4), and when you ask for a video, the token and the riddle's identifier go to Google, which hands them back to us (section 6). For unlimited solo play, the bundle purchase proof also reaches our service for verification (section 5). With your separate permission, usage events also leave the phone (section 12).
If your phone's automatic backups are on, that data may be included in them, which is what lets your progress come back after a reinstall. The backup belongs to you and to Google or Apple: we have no access to it, and it can be turned off in your phone's settings.
3. The update check
On each launch, the app asks Expo's servers (u.expo.dev) whether a newer version of its content exists, and downloads it if so: that is how fixes and new riddles arrive without waiting for a store release. The game itself runs offline.
The request carries what any internet request carries, your IP address included, plus the app's version, its platform, your device's operating system, and a random token that only says whether the update has already been downloaded. It carries none of your progress.
The service is operated by 650 Industries, Inc. (Expo), in the United States, as a technical processor (https://expo.dev/privacy). The lawful basis is legitimate interest (GDPR article 6(1)(f)): delivering fixes and content to the people who installed the app. The transfer outside the European Union is covered by the EU-U.S. Data Privacy Framework, under which Expo states it is self-certified, and by the European Commission's standard contractual clauses, a copy of which can be requested at the address in section 1.
4. “Investigate solo”
This is the only feature that sends text you wrote anywhere, and it is optional: until you open it, none of what follows happens. The first time, the app asks your permission and sends nothing until you have given it. “Erase my progress”, in the app's Settings, withdraws it along with the rest (section 8), and nothing leaves again until you give it back.
In solo mode you ask closed questions about a riddle, and an artificial-intelligence model answers “yes”, “no” or “irrelevant”. For that, each question leaves your phone and passes through our service.
What is sent, and nothing more:
- the question you just typed (300 characters at most);
- the identifier of the riddle you are on, and the language you are playing in;
- the last twelve questions of the current investigation and their answers;
- the discovery identifiers already unlocked, and the app version;
- the random token from section 2, used only to count your questions for the day;
- your IP address, as with any internet request.
Your saved game stays on your phone. The discoveries above help the narrator follow the current investigation. We match the quota token against no other information: it says neither who you are nor what device you use. Google sees it too when you ask for a video, beside what section 6 lists. Still, this field is the only place in the app where text of yours leaves the phone: keep anything personal out of it.
The service is hosted by Cloudflare, Inc. (United States), and OpenAI (United States) is what classifies the question. Both act as technical processors (https://www.cloudflare.com/privacypolicy/, https://openai.com/policies/privacy-policy/). The lawful basis is legitimate interest (GDPR article 6(1)(f)): answering the question you just asked. Those transfers outside the European Union are covered by the European Commission's standard contractual clauses, a copy of which can be requested at the address in section 1; Cloudflare additionally states it is self-certified under the EU-U.S. Data Privacy Framework.
We keep your question and the answer. They serve one purpose, improving the game: reading real questions is the only way to see where the narrator answers badly and where a riddle is badly calibrated. What is kept: the text of the question, the answer, the riddle's identifier, the language, how far into the investigation the question came, the model that answered and the version of the service. We also record response time, token usage, discoveries returned and app version for up to 90 days. Neither your quota token nor your IP address is written to this log. Questions have a date, without a time of day. Only if you enable usage statistics can recent questions be grouped by a random session identifier (section 12). The lawful basis for the unlinked question log remains legitimate interest (GDPR article 6(1)(f)).
Our service also keeps counters, attached to your token, the riddle and your IP address, which enforce the limits of the game (twelve questions per riddle per day without the bundle) and discourage abuse. They hold no text and expire on their own after 48 hours. OpenAI, for its part, keeps the requests it receives according to its own policy, for a limited period and for abuse monitoring.
5. Purchases
Some riddle packs are paid. Buying one goes through Google Play on Android or the App Store on iPhone, entirely between you and that store. No payment detail passes through the app or through us: no card number, no billing address, no name.
What comes back from the store is the list of product identifiers you own. The app keeps that list on your phone (section 2) so a pack you paid for still opens with no network, and asks the store again at every launch: that is also how a refund closes a pack.
When you use the bundle for unlimited solo play, the app sends its purchase proof to our service, which checks it with Google or Apple. The proof is not sent to OpenAI or stored in our question logs. We cache only a cryptographic fingerprint and the verification expiry for up to five minutes, then check the store again. This also lets us detect refunded purchases.
For the transaction itself, Google and Apple act as data controllers in their own right, under their own policies. They provide sales reports and confirm the status of a purchase when our service verifies it. The lawful basis is the performance of a contract (GDPR article 6(1)(b)): giving you the pack you just bought.
6. Rewarded videos
The app shows one kind of advertising, and only one: a video you choose to watch in exchange for something in the game. Nothing appears between two screens, nothing sits at the edge of a page, nothing plays when you open the app. Every riddle, every solution and every pack behaves the same whether you watch a hundred or none.
Bundle owners are not offered these videos. For other players, one place offers one. When a riddle's twelve questions are spent, a video puts six of them back, as many times as you care to watch. It is a button you press, and pressing nothing costs nothing.
The videos come from Google Ireland Limited, through Google AdMob, under its own policy (https://policies.google.com/technologies/partner-sites). Loading one sends Google what it needs to choose and count an advert: your IP address, your device, its operating system and its language, the app and its version, the country you are in, an identifier of this install of the app, and, if you have agreed to it, your phone's advertising identifier, a number the phone hands to apps for this purpose and that you can reset or switch off in its settings. Two things from the game go along: the random token from section 2 and the identifier of the riddle you are on, so that Google can name them back to us once the video is over (below). No progress and nothing you typed is ever sent with it.
For advertising Google is a data controller in its own right and not our processor: what it does with that data answers to its policy rather than to this page. What comes back to us is aggregate, how many videos were watched and what they earned.
In the European Economic Area and the United Kingdom nothing loads before you have answered Google's consent form, which the app raises the first time you open it. That answer is the lawful basis (GDPR article 6(1)(a)), and you can change or withdraw it whenever you like: Settings, “About”, “Ad preferences”, a row that appears where the form applies, once the app has been able to fetch it, so it can be missing after a launch with no network until the next one. Refusing is a complete answer, not a lesser one. You then see non-personalized adverts, chosen from nothing but the app you are in; refuse everything the form offers, its “legitimate interest” purposes included, and no video loads at all, so the button in the spent band does nothing. The rest of the game is unchanged either way. On iPhone, if you accepted Google's form, Apple then asks a second and separate question about the advertising identifier; declining that is a complete answer too.
When a video pays for questions, Google tells our service so directly, naming the token from section 2 and the riddle you are on, so the questions land on the right budget. That message also carries a transaction number, the time, and which advert unit paid, and nothing else about you. We keep the transaction number for 48 hours, to refuse the same video being counted twice, and the rest is not stored.
7. What the app does not do
No account and no sign-up. Usage statistics are optional (section 12). No advertising beyond the videos of section 6: nothing is ever shown that you did not ask for. No data is sold, rented or transferred to third parties by us; what Google receives for a video, it collects itself, as section 6 says. No profiling by us, and no automated decision-making producing legal or similarly significant effects: solo mode classifies your question to answer it inside the game, and nothing we run builds a profile of you.
Expo (section 3), Cloudflare and OpenAI (section 4) are our processors: their terms and data processing agreements require them to act only on our instructions and to protect this data at least as well as this page promises. Google AdMob (section 6) is not one of them: it is a controller in its own right, which is why that section stands apart. Beyond that, the only third parties involved are Google Play and Apple's App Store, which distribute the app under their own terms and show us aggregate figures only (installs, sales, ratings, public reviews, technical crash reports). None of it identifies you.
8. Retention and deletion
On your phone, your progress stays as long as you keep it. You can delete it in two ways, both immediate and final. “Erase my progress”, in the app's Settings, erases your progress, your favorites, the course of your investigations, the random token from section 2 and the permission you gave solo mode. It also switches off usage statistics and removes their local identifier; only your language, the fact that you have seen the rules, the packs you bought, since the store would hand those back at the next launch anyway, and your answer to the advertising consent form survive it. That answer is Google's form's to keep, and changes through “Ad preferences” (section 6). Uninstalling takes everything in section 2 with it; the packs come back from the store after a reinstall.
We keep the solo questions and their answers, with no token or IP address (section 4); counters and video receipts, erased after 48 hours (sections 4 and 6); and purchase-verification fingerprints and their expiry, erased within five minutes (section 5). The technical data Expo receives (section 3) and the questions OpenAI receives (section 4) are kept according to each of their own policies.
You can also write to the address in section 1 to request deletion, or to object to a processing (section 10). We answer requests concerning the processing described here. Your local progress is deleted using the controls above. The purchase-verification cache expires within five minutes (section 5). The questions we keep carry no name or account identifier. Optional session links expire after 90 days (section 12); outside those links we cannot recognise a question as yours.
9. How this data is protected
Your saved game stays on your phone. Optional usage reports include activity such as opening or solving a riddle (section 12). Purchase proofs are not written to the question log. The solo service keeps question-and-answer rows, separate from its 48-hour abuse counters (section 4) and five-minute purchase-verification cache (section 5).
On your phone, the data in section 2 sits in the private storage reserved for the app: no other installed app can read it, and it is covered by the encryption the operating system applies to the device. The update check (section 3), solo questions (section 4), purchase verification (section 5) and videos (section 6) all run over encrypted connections (HTTPS).
10. Your rights
The GDPR gives you rights of access, rectification, erasure, restriction, objection and portability over your personal data.
You may object at any time to the two processings based on legitimate interest (GDPR article 21): the update check (section 3) and solo mode (section 4), answering your question and improving the game alike. Solo mode is avoided by not opening it; for the update check, write to the address in section 1, as the app carries no setting to turn it off.
The advertising of section 6 rests on your consent, not on legitimate interest, so it is withdrawn rather than objected to, in the app and at any time: Settings, “About”, “Ad preferences”. Withdrawing changes nothing about the game.
We do not keep an account profile. The data in section 2 is under your direct control, and section 8 says how to delete it. Section 5 describes the temporary purchase-verification cache. The question log contains no name or account identifier. Section 12 explains the optional session links and how to withdraw permission for them.
You can write to the address in section 1 and, if you consider your rights are not being respected, lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr).
11. Changes to this policy
This page will be updated if the app starts handling data it does not handle today. Significant changes will be announced in the app before they take effect. The date at the top of this page is the version in force.
12. Optional usage statistics
Usage statistics are off until you enable them in Settings, “About”, “Usage statistics”. They help us understand which riddles work, where players stop, and which app versions encounter errors. The lawful basis is your consent (GDPR article 6(1)(a)). You can switch them off in the same place; doing so stops future collection and clears reports waiting on your phone. It does not affect play or advertising preferences.
When enabled, the app sends activity names (such as app opened, riddle started or solved, solution read, purchase attempted, or video completed), riddle or pack identifiers, dates, language, platform, app version, durations, and fixed error categories. It adds a random installation identifier, renewed after 90 days, and a random identifier for each foreground session. The session identifier also accompanies solo questions, letting us read recent questions from the same session together. These identifiers are separate from the quota token, advertising identifiers and store purchase proofs. The reports contain no names, email addresses or additional text you typed.
These events and question-session links are stored with Cloudflare in our European Union database for 90 days, then removed by daily cleanup. Access is restricted to the studio administrator. Cloudflare is our technical processor, under the transfer arrangements described in section 4. Switching off does not immediately delete previously received events; they expire on that schedule. You can contact us at the address in section 1 about them.
13. The studio website
The public website counts page views and clicks to games and app stores. It also records page performance and fixed error categories. These reports contain the page path, date and language, with no query strings, referring URLs, visitor identifier, cookies or browser storage used for measurement. Browsers sending Do Not Track or Global Privacy Control are excluded. Reports are stored with Cloudflare for 90 days and used to improve the site. This limited measurement rests on legitimate interest (GDPR article 6(1)(f)); you may object by contacting the address in section 1. Network requests still carry an IP address to Cloudflare, which our measurement database does not store. The private studio area does not collect these website events.