Privacy Policy
Last updated: August 30, 2026
Operated by Social Chain, Ukraine · This document is provided in English.
Social Chain is an invite-only app. There is no public feed, no advertising, and no cross-app or advertising tracking. This policy describes exactly what the app holds, why it holds it, and what leaves your device.
No conventional account credentials
You enter with a single access key. We do not ask for your real name, email address, phone number, password, or social login, so none of those are ever collected.
We never store your raw key — only a one-way hash of it and a short non-secret prefix used for support lookup. On your device the key and your session token are held in the iOS secure store. One device is signed in at a time.
The support code shown in Settings → Support is derived from your public id. It identifies your account to support without exposing your key.
Your identity in the app
When your key is first used, the app assigns you an identity: a name, a mark, and short phrases. You do not choose them and they are not your real name.
Your public identity is exactly this: your public id, your assigned name, your mark, your phrases, and the sealed seasons you took part in. Nothing else about you is shown to other players.
What the app holds
- Identity — an internal id, your public id, your assigned name, mark and phrases, and the hash of your access key and session.
- Your content — rare-proof photos you capture, your private journal, your private season archive, and the cards you craft.
- Play record — the signals you answer, rare selections and proofs, the traces you help clear, duels, inventory, ledger history, crafting and ritual contributions.
- Whisper — private messages between two identities in the app, and any report you send about one.
- Device and diagnostics — platform, app version, a device id for notices, your push token if you allow notices, your language, and operational logs (sign-in attempts, rate-limit hits, errors) with secrets removed.
What the app never collects
No real name, email address, phone number, postal address or date of birth. No contacts. No location — the app has no location permission and none of its features use one. No photo library access. No advertising identifier.
The app bundles no analytics, advertising, attribution or tracking SDK, and does not track you across other companies' apps or websites. Nothing is sold, and nothing is used for advertising. If that ever changes, this policy changes first.
Camera and rare-proof photos
The camera is used only to capture proof during a rare window. There is no gallery upload, and the camera is never opened outside that moment.
Proof photos are private. They are shown to you and to the players a proof is offered to during trace clearing, and access requires a signed-in session. There is no public proof feed and no public proof page. The app stores a private storage reference, never a public link.
A proof photo must never contain another person's face, private information, or a minor.
Whisper messages
Whisper carries private messages between two identities. Messages are not public and are not used to build a profile of you. They are stored so a thread can be delivered and read, and so a report can be acted on.
You can mute, block, or report the other side of a thread at any time from the thread's safety menu. A report — and the messages it concerns — is kept for the time needed to review and act on it.
Notices
If you allow notifications, the app registers a push token for this device so the field can call you. Decline, and no token is stored. You can turn notices off in Settings → Notices, or in iOS Settings, at any time.
Push messages are delivered through Expo's push service and Apple's Push Notification service.
What other players can see
Your public identity, as listed above, and the seasons you passed through — season name and number only, never your own numbers.
A sealed season's shared record is collective and anonymous: counts, rhythm, outcomes. It never names a person and never attributes behaviour to one. Named lines about who was present appear only inside a live season's closing ritual, are plain observable facts, and are not kept once the season seals.
Why we are allowed to process it
We process the data needed to run Social Chain and your participation in it because it is necessary to provide the service you asked for.
We process limited security, abuse-prevention and operational information for our legitimate interest in keeping the field safe and enforcing these rules.
Where processing depends on your permission — notifications, the camera — you can refuse it, and withdraw it later in the app or in iOS Settings.
Who else processes it
These providers process data on our instruction, to run the app. There are no advertising or analytics recipients.
We require every provider that handles data for us to protect it consistently with this policy and applicable law, and to use it only to provide their service to us.
- Cloud hosting, database and object storage for the app's backend and your private proof photos, in the EU.
- Expo and Apple, for delivering push notifications to this device.
- Apple, for distributing the app and for the secure store that holds your session on your device.
How long it is kept
Your identity and your persistent play record are kept while your account exists.
Proof photos are kept only as long as their verification, archive or safety purpose requires, and are deleted when you delete your account unless the law requires us to keep them.
Short-lived field state — the current field, a rare window, an open duel — expires by itself. Security and abuse-prevention logs are kept for a limited operational period, then dropped.
Deleting your account
Settings → Access & Safety → Delete account. Your key stops working immediately, your private data is removed or anonymised, and your proof photos are deleted.
Anonymous safety records may be kept where required for the integrity of the system, and a confirmed rare trace may already have become part of an anonymous sealed Season Memory — that archive form carries no name, key, profile or private account data.
Your rights
Depending on where you live, you may ask for access to your data, a copy of it, correction, deletion, or restriction of how it is used; you may object to processing based on our legitimate interests; and you may withdraw a permission you gave. You may also complain to your local data-protection authority. Write to info@socialchain.world with your support code and we will answer.
Because we hold no email or phone number, that support code is the only way to tie a request to an account. Never send your access key.
Children
Social Chain is for people aged 16 and over. It is not directed to children and we do not knowingly collect their data; if we learn we have, we delete it. Proof photos must never include a minor.
Security
Keys and session tokens are hashed, one session is active at a time, sign-in is rate-limited, private reads are scoped to their owner, and secrets are redacted from logs. No system is perfectly secure, and a lost key cannot be recovered for you.
Changes and contact
Material changes appear here and on the web copy, with a new date. Questions or requests: info@socialchain.world.
See also: Account & Data Deletion · Terms of Use