epilog Privacy Policy
epilog is a social game diary operated by Ayman Wehbi, who is responsible for the personal information described in this policy. This policy covers the app and its related web pages: the information processed, why it is used, who receives it and your choices. For privacy questions or requests, contact epilogg.app@gmail.com.
Information you provide
- Account and profile: email address, username, display name, biography, avatar, profile banner, platform preferences and privacy settings. For password accounts we store a password hash, not the plaintext password. We also process sign-in identifiers, verification records, sessions and any multi-factor authentication information you set up.
- Diary and social content: game-library entries, playthrough status and dates, playtime, ratings, reviews, lists, posts, comments, uploaded images and custom covers, follows, blocks, reactions and notification preferences.
- Messages: direct and group conversation content, participants, attachments and reactions. Message content is stored by epilog to provide messaging; it is not end-to-end encrypted.
- Support and safety: feedback, abuse reports and correspondence. Feedback can include the current app screen, app version/build, platform and locale. Reports may include a snapshot of the reported content and identifying information needed to investigate it.
Information from sign-in and library providers
If you choose Google or Apple sign-in, we receive the account identifier and the identity information supplied by that provider, such as your email address and name. Apple may provide a private relay email address. We do not receive your Google or Apple password.
If you choose a library import, we process the account identifier, public profile information or file you supply and the library, playtime, achievement, rating or review data available for that import. Imported content is saved with the visibility settings shown in the app. We do not ask for your Steam, PlayStation or Xbox password.
Usage and technical information
We record searches performed in epilog, including normalized search text, and recommendation/search interactions such as displayed games, impressions, taps, dismissals and additions to your library. These records can include timestamps, game identifiers, positions and recommendation context, and are linked to your epilog account; normalization does not make searches anonymous.
We also record app-open counts, the latest app-open time and the most recently reported platform, app version and build number associated with your account. This helps us understand use and identify compatibility or outdated-version issues.
Push delivery uses device registration tokens and the installation information processed by the notification SDKs. When your device connects to our services or content providers, those services receive connection information, including your IP address. Request and error logs may contain technical information used to operate, secure and diagnose the service.
Why we use information
We use account and security information to authenticate you, manage sessions and protect accounts; diary and social information to provide the features you request; library preferences and activity to personalize discovery and calculate statistics; search and interaction records to evaluate and improve search and recommendations; and device information to deliver notifications and diagnose compatibility problems. Reports, feedback and operational records help us provide support, investigate abuse and meet applicable legal obligations.
Visibility, recipients and service providers
Your profile and content use the visibility controls available in the app. Public content may be viewed or shared outside epilog. Messages are available to their conversation participants. Content you report, including relevant message content, may be reviewed by authorized moderators. Other users may retain screenshots or copies they have already received; deleting your account cannot remove those independent copies.
- Railway hosts epilog's backend and database, processing account information, content and technical requests needed to run the service.
- Amazon Web Services (AWS S3) stores uploaded media such as profile images and custom covers. Media-delivery services process image requests and the connection information needed to deliver those files.
- OpenAI processes normalized images you upload for use as an avatar, profile banner or custom cover to help screen for violations of our community rules before publication. When this moderation provider is enabled, it also checks user-written content, including message text, under our existing text safety checks. The moderation request contains the relevant image or text, rather than your account identifier. Content itself can contain personal information. This processing is used for service safety; provider-held records are subject to the provider's terms and data controls.
- Cloudflare provides domain and web infrastructure. Where a request is routed through its proxy or security services, it processes connection and request information to deliver and protect that traffic.
- Google and Apple process information needed for the sign-in methods you choose. Google Firebase Cloud Messaging and, on Apple devices, Apple Push Notification service process delivery identifiers and notification payloads, which may include notification text.
- Transactional email providers process your email address and message content to deliver verification, account-security and recovery messages.
- IGDB (a Twitch service) supplies game metadata and artwork. Game searches and identifiers are sent as needed to retrieve that information. Library-import providers receive the account identifiers or other request information needed for the imports you choose. Loading externally hosted artwork or opening provider links also connects your device to those providers, whose own privacy policies apply.
Authorized administrators can access information needed for support, service operation and moderation. Information may also be disclosed when required by applicable law or a valid legal process.
Images requiring a decision from a moderator are held in private storage and are not shown publicly while awaiting review. Your existing published image remains visible during replacement review. The uploader and authorized administrators can access an authenticated preview. Automated image screening does not send private-message attachments or the external game-artwork catalog to the provider. Private message text checks do not automatically expose conversations to administrators; relevant reported messages remain available for report investigation.
How information is protected
The production app uses HTTPS to communicate with the epilog API. Account passwords are hashed with bcrypt. Authenticated requests, ownership and visibility checks, and administrator permissions restrict access to protected functions and records. These measures reduce risk, but no network transmission or storage system can be guaranteed completely secure.
Retention and account deletion
Account, diary, social and account-linked usage records are generally stored while your account remains active, unless you remove content using an available control. To permanently delete your account, use Settings → Account → Delete account, or follow the web deletion instructions. We verify ownership before processing deletion.
Account deletion removes your account and associated live diary/social records, device registrations and sessions, and initiates removal of your epilog-hosted avatar, banner, custom covers and private pending images. Rejected, cancelled and superseded private uploads are scheduled for removal; failed storage deletions are retried. Review decision records and pending uploads follow the retention settings configured for the service. Contact us for the applicable periods; this policy does not promise immediate erasure of storage versions, provider records or backups. It does not delete accounts or original library data held by external providers.
Some records are separate from your live account. Moderation reports submitted by other users can retain content snapshots and identifying details after an account is deleted. Product feedback can retain its text and technical context after its account link is removed. Previous usernames remain reserved to prevent reuse of old profile addresses. These records are not automatically erased by account deletion. Contact us to request review or removal of personal information in retained records; applicable legal or safety requirements may affect what can be removed.
Operational logs, provider-held records and backup copies may remain separately from the live database. Their retention depends on the relevant operational purpose, provider settings and applicable legal requirements. Deletion from the live service does not mean all copies are immediately erased. Contact us for information about retention relevant to your request.
Your controls and privacy requests
You can edit your profile and content, use available visibility and blocking controls, change notification preferences, and manage notification/photo permissions in your device settings. Signing out ends use of that app session; it does not delete your account or previously collected information. Changing a notification preference does not disable search or usage recording.
Depending on where you live, you may have rights to access, correct, export or delete personal information, or to object to or restrict certain processing. Send requests to epilogg.app@gmail.com. We may need to verify your identity. You may also contact your applicable data-protection authority.
Children
Our terms require users to be at least 13 years old. If you believe a child below that age has provided personal information, contact us so we can investigate and address the account. This minimum age does not replace local requirements that may apply.
Policy updates
Changes to this policy will be posted on this page with an updated date. Check this page for the current description of our practices.
Contact
Privacy questions and requests: epilogg.app@gmail.com.