Privacy Policy
ARBEEF is an augmented-reality fighting game for iPhone made by Egor Sharapov ("we", "us"). This policy explains what data the app and this website handle, why, and what you can do about it. The short version: we keep as little as we can, your photos are not stored on our servers, and what happens in a fight is not recorded.
1. Who is responsible
Egor Sharapov, an individual developer, is the data controller for ARBEEF. Questions and requests go to hello@arbeef.app.
2. What we collect and why
Account
You sign in with your Apple ID. Apple gives us a stable anonymous identifier for your account and, if you choose to share it, your email address (Apple's "Hide My Email" relay addresses work too). We use the identifier to keep your credit balance attached to you and the email, when present, only to contact you about your account. We never see your Apple password.
Photos and generated fighters
To create a fighter you send us a photo. Our server forwards it to Tripo (Tripo3D, operated by VAST) to generate a cartoon concept and a 3D model, and does not keep a copy. Tripo processes the photo under its own privacy policy. The finished fighter is downloaded to your phone and lives there; we keep a short-lived job record (status, error, temporary download links) so the app can pick up the result if it was interrupted.
Only upload photos you have the right to use. If you photograph another person, make sure they are fine with it.
Purchases and credits
Credits are bought through Apple's In-App Purchase. Apple handles payment; we never see your card. We receive the transaction identifier and product from Apple, verify it, and record it in a credit ledger (purchases, spends, automatic refunds for failed generations). Apple also notifies us about refunds and revocations so we can adjust your balance.
Fights
Multiplayer runs between two phones. In the same room they talk directly over the local network (Wi-Fi or peer-to-peer). When you fight someone far away through a fight link, the phones first connect through our server, which forwards fight messages and both fighters' 3D models between them and keeps neither. Where the networks allow it, the phones then switch to a direct connection set up with the help of Cloudflare's STUN/TURN service: to make it, each phone shares its network addresses (IP addresses and ports) with the other player's phone. If a direct path is not possible, the traffic goes through Cloudflare's TURN relay, which forwards it without reading or storing it. A fight room lives only until its first fight and no longer than 7 days; it holds a code, a secret, the host's player name, the host's fighter name and picture for the link preview, and timestamps. What happens in a fight — positions, inputs, camera frames — is not stored by us; we only learn, through the analytics below, that a fight started and ended, who won, how long it lasted, the connection type (local, relay or direct) and its latency — never your IP address. The camera image is processed on the device by ARKit to find the floor and the arena anchor and is never uploaded.
Diagnostics and usage
- PostHog collects product analytics and crash reports.
- Usage: how far you get in the app — whether the arena was placed, whether a fight finished, who won and how long it took, whether a fighter generation succeeded and how long it took, whether a credit purchase went through (the pack and its price, never your payment details).
- Crashes and errors: device model, OS and app version, a stack trace, and the last few app states before the problem.
- Cloudflare hosts our API and this website and keeps standard request logs (IP address, request path, timing) for a short period for security and debugging.
- Apple may share crash logs and analytics with us if you opted in on your device; that is governed by Apple's privacy settings.
This website
This site is static: no cookies, no analytics. Fonts are loaded from Google Fonts, which sees your IP address.
3. How long we keep it
- Account and credit ledger — until you delete your account.
- Sign-in tokens — up to 90 days, then they expire on their own.
- Apple purchase notifications — 90 days.
- Generation job records — a short period after the job finishes.
- After deletion — we keep only a marker that your Apple identifier has already received its free starter credits, so they cannot be claimed again. Nothing else.
- Crash and analytics data — up to one year in PostHog, then deleted.
4. Your choices and rights
- Delete your account in the app under Settings → Delete account. It removes your account, credit balance and tokens immediately.
- Delete a fighter in the app; it is removed from your phone and from our job records.
- Access or correct your data, or ask us to delete it, by emailing hello@arbeef.app. We answer within 30 days.
- Refunds for purchases go through Apple, per their policy.
Depending on where you live you may have additional rights (for example under the GDPR or the CCPA), including the right to complain to your data protection authority. We honour those rights on request.
5. Where data goes
Our API runs on Cloudflare's global network; Tripo runs in the United States and/or the EU; PostHog stores our analytics in the United States. By using ARBEEF you accept that your data may be processed in those locations, protected by the providers' standard contractual terms.
6. Children
ARBEEF is not intended for children under 13 (or the age required in your country to consent to data processing). We do not knowingly collect data from them; if you think a child has created an account, email us and we will delete it.
7. Changes
We may update this policy as the app changes. The effective date at the top tells you when it was last revised; material changes will also be announced in the app.
See also the Terms of Service.