Privacy Policy

Play without worry.
Your data stays yours.

Bandicoot is a word game made by Magic Factory LLC, based in Boston, MA. You can play without an account. We collect only what's needed to make the game work.

What We Don't Collect

Data We Collect

Anonymous player ID
Created automatically via Supabase anonymous auth to save your game progress.
Email address
Only if you optionally link your account for cross-device sync. Used solely for authentication via magic link.
Display name
Shown on leaderboards. You choose what to display.
Game scores & stats
Submitted to the server for leaderboards, streaks, and personal statistics.
Game history
Words found, scores, mode played, and timestamps.

How We Use It

Mailing List

If you subscribe to our mailing list on our website, we collect your email address via Buttondown. This is entirely opt-in — we never add you without your consent.

Third-Party Services

Supabase
Backend database and authentication. Privacy Policy
Sentry
Crash and error reporting. Captures device info, OS version, and error context — no directly identifying information such as names or emails. Privacy Policy
PostHog
Product analytics to understand how the game is used. No directly identifying information is shared. PostHog may receive device type, OS version, and anonymized usage events. Analytics traffic is proxied through Cloudflare. Privacy Policy
Cloudflare
Used as a reverse proxy for analytics traffic. Cloudflare may process request metadata (IP address, headers) in transit. Privacy Policy
Stripe
Payment processing for premium upgrades. Stripe handles all payment data directly — we never see or store your card details. Privacy Policy
Apple Game Center
Leaderboards and achievements on iOS. Governed by Apple's Privacy Policy.
Google Play Games
Leaderboards and achievements on Android. Governed by Google's Privacy Policy.
Buttondown
Email newsletter service. If you subscribe to our mailing list, Buttondown stores your email address to deliver updates. You can unsubscribe at any time via a link in every email. Privacy Policy
TikTok Pixel
Advertising measurement on our website. Collects anonymized browsing data to measure ad performance. No in-app data is shared with TikTok. Privacy Policy

Data Retention

We keep your data for as long as your account exists. If you request account deletion, we will delete your data within 30 days.

Security

Your data is stored securely via Supabase (US-hosted). All communication uses HTTPS encryption. If you are located outside the United States, your data is transferred to and processed in the US. Our service providers maintain appropriate safeguards for international data transfers.

Your Rights

You can update or delete your profile info at any time. To delete your account and all associated data, go to Settings → Delete Account inside the app. You can also request deletion by emailing support@magicfactory.dev.

If you are in the EU/EEA, you have the right to access, correct, delete, port, or restrict your data, and to object to processing. Our legal basis for processing is legitimate interest (providing and improving the game) and, where applicable, your consent. Contact us to exercise these rights.

If you are in California, you have the right to know what data we collect, request its deletion, and opt out of the sale or sharing of personal information. We do not sell or share your personal information.

Children

Bandicoot does not knowingly collect personal information from children under 13. The game can be played without providing any personal info.

Changes

We may update this policy. If we make material changes, we'll notify you through the app or by other means before they take effect.

Questions? support@magicfactory.dev

See also our Terms of Use

Updated April 11, 2026