Privacy policy
Effective October 3, 2026.
The short version
What you log is kept on your phone. Without an account, nothing you log is uploaded. If you make an account, what you log is also saved to it on a server, where only your account can read it, and the ratings you give houses count in each house's average, which never shows whose they are. Reviews, posts and comments you write in Community are public, with your name, and a review shows your rating. The account itself is kept there too: its ID, an email address, your username and the name the app shows for you. The feedback board is public and holds what you post on it. A tip is an App Store purchase, and the app keeps nothing about it. You can delete your account from inside the app.
What stays on your phone
Everything you log is stored on your phone, in the app's own storage: nights, runs, scare zones and shows, ratings, rankings, tags and notes, passport stamps, what you paid for a season, and the profile picture, banner and colour you choose. Without an account, none of it is sent to us or to anyone else. With an account, a copy is also saved to your account and your ratings count in the averages, as the next two sections say.
If you back up your phone, the app's data is part of that backup like any other app's. That backup is yours and Apple's. We never see it.
Accounts
You can use the app without an account, and log everything without one. An account is what opens the Profile page, it gives what you have logged an owner and a name, and it saves your log beyond your phone (see Your account's saved log). Your ratings also count in each house's average (see Ratings), and you can write in Community (see Reviews, posts and comments).
You make an account by signing in with Apple or with Google. The app asks Apple for your name and your email address. With Apple you can choose Hide My Email, and then the address we receive is Apple's relay address and not your own.
Accounts are kept for the app by Supabase, which stores this on the app's behalf:
- An account ID, made by the server.
- An email address: the one Apple or Google shares when you sign in, or Apple's relay address.
- What Apple or Google tells the server about you when you sign in. From both, a stable identifier for you. From Google, also the name and the address of the picture on your Google account. The app does not show or use the Google name or picture.
- Which of Apple and Google you sign in with, and when you made the account and last signed in.
- Your username, if you have picked one. It shows with your name on what you write in Community and on your profile there. Nobody can search for you by it.
- The name the app shows for you. With Apple this is the name Apple gave the app the first time you signed in.
The app itself never reads or shows your email address. To keep you signed in, it keeps the sign-in session Supabase issues in the phone's Keychain, and that session carries the account details listed above, the email address among them. The app also keeps the name and identifier it needs to know whose log is whose.
We use the email address for nothing except knowing that two ways of signing in belong to the same person. We do not send marketing email, and we do not share or sell the address.
If you sign in with Google using an email address that already has an account made with Apple, or the other way round, the server joins them into one account. The app stops and tells you when this happens, and lets you undo it. Two separate accounts on one email address is not possible.
Your account's saved log
If you have an account, what you log is saved to it, so that it is not lost with your phone: your nights and runs, scare zones and shows, ratings and scare scores, tags and notes, rankings, the seasons and houses you added from memory, passport stamps, what you paid for a season, the highlights and favourites you pick for your profile, and your profile picture and banner photo. The two photos are stored as files that only your account can open, and a photo you remove or replace is deleted from the server.
The saved log is kept for the app by Supabase, in a table that only your account can read. Nobody else using the app can see it, and nothing in it is public. The app sends it in the background when there is a connection and never makes you wait for it. Without an account, nothing you log is uploaded.
Before the first time your log is saved to an account, the app writes a complete copy of it to its own storage on your phone, as a safety backup. It never leaves the phone.
When you delete something you logged, the server is told, so that another phone signed in to your account does not bring it back. What the server keeps of a deleted record is only which kind of record it was and its key, never what it said.
Deleting your account deletes its saved log from the server. Delete all data erases your log on your phone and the saved copy on the server. Signing out deletes nothing, on your phone or on the server.
Ratings
If you have an account, the rating you give a house is sent to the server so the app can show each house's average. With it go your account ID, the house and its season, and, if you scored the scare of your runs through that house, the average of those scores. Nothing else about your runs is sent: not the date or time, the line, the wait, tags or notes.
An average never shows whose ratings are in it, whether your profile is public or private. Other people see a house's average and how many people rated it, and the average appears only once at least three people have rated that house. Below three, the app shows how many ratings there are, or nothing. The one place anyone else sees a rating of yours is your review, if you write one (see Reviews, posts and comments). Ratings of scare zones and shows are not used for averages. A review of one shows your rating of it, which the app sends with the review and again whenever you change that rating.
Ratings made without an account stay on your phone and are not sent. If you make an account later, the ratings already on your phone are sent then. If you change a rating, the server's copy is replaced. If you remove it, reset the house or use Delete all data, it is removed from the server. Deleting your account removes all your ratings, and every average is worked out again without them.
Anyone using the app can read the averages, with or without an account. Reading them sends nothing about you.
Reviews, posts and comments
With an account, you can review a house, a scare zone or a show, post about a house or a season, and comment on what other people write. All of it is public. Everyone using the app can read it, with or without an account.
This is what is stored for each one, by Supabase:
- What you wrote: the words, whether you marked them as containing spoilers, and a GIF if you added one (see GIFs).
- What it is about: the house, scare zone or show, or the season for a post in its General thread.
- Your account, and when you posted it and last edited it.
- On a review, your rating of that house. The review shows the rating you have saved for the house and follows it if you change it. If you remove the rating, the review keeps the number it showed. A review of a house you have not rated shows no rating.
- On a review of a scare zone or show, your rating of it, which the app sends with the review and again when you change it. A review of one you have not rated shows no rating.
The note you can add when you log a scare zone or show is private. It is saved with your log (see Your account's saved log) and is never posted or added to a review.
Everyone sees what you write with your name and your @username, if you have one. Tapping your name opens your profile in Community, which lists your reviews and posts. A private account's reviews, posts and comments are public too. They appear on houses and in Community like anyone else's, and only the list on the profile is hidden from others.
Before your first review, post or comment, the app asks you to agree to the community rules, and the server stores which version you agreed to and when.
A review after a run. With an account, the sheet that opens after you log a run has a place for your review of that house until you have written one, with Post to Community switched on. Save and Post sends only the words you wrote there and whether you marked them as containing spoilers, as a review written on the house's page does. The run's own note stays in your log and is never posted. With no connection, the review waits on your phone and is sent once the app can reach the server. The phone gives each of these reviews a random code, and the server keeps the code with the review so that a review sent twice is posted once. If you turn Post to Community off, it stays off on that phone until you turn it on again.
Hearts. A heart stores your account and what you hearted. Everyone sees how many hearts something has, and only its author sees who gave them, in their Activity. Taking a heart back removes it.
Comments are stored like posts. The author of the review or post you comment on sees your comment in their Activity.
Following. When you follow someone, the server stores that you follow them, and they see it in their Activity. Nobody else can see who follows whom. Unfollowing removes it.
Checks. Links can be posted once an account is a day old. Until the account is a week old, anything it writes with a link waits for the app's developer to look at it, and so does anything that uses a word on the developer's list of words to check. Only you can see it while it waits. The server also limits how often one account can post, comment, heart and report. These checks use your account's age and what it has posted recently, and nothing else.
Reports. You can report any review, post or comment. A report stores your account, what you reported and who wrote it, the reason you chose, a note if you add one, and when. Your account is used to hide what you reported from you straight away, to count each person's report once (three reports from three people hide something until the developer looks), and to limit how many reports one account can send. The person you report is never told who reported them. The app never shows who made a report to anyone, and the developer's list of reports shows the reasons and notes without the names of the people who sent them.
Blocks. Blocking someone stores who blocked whom and when. From then on neither of you sees the other's reviews, posts, comments or profile lists, and any following between you ends. Neither of you is told, and only you can see your list of blocked accounts. Unblocking removes it.
Removal. The app's developer reads reports every day. He can keep what was reported, mark it as containing spoilers, or remove it. When something of yours is removed, your Activity says so and gives the reason, and never names who reported it. An account that keeps breaking the rules can be banned from posting, and the server then stores the account, the reason and when. A banned account can still read, report, block, delete what it wrote and delete itself.
How long it is kept.
- What you delete disappears for everyone straight away. The server keeps it for 90 days in case a report about it needs another look, then deletes it for good, with its hearts and comments.
- What the developer removes is kept for the same 90 days, then deleted.
- A report is kept for 90 days after the developer deals with it, or, when what it was about is gone, 90 days after it was made. A report that has not been dealt with, and anything waiting for the developer to look, is kept until he does.
- An Activity line is kept for 30 days.
Deleting your account deletes your reviews, posts, comments, hearts, follows, blocks, Activity, your agreement to the rules and any ban straight away. Reports you made stay, without your account, until the developer deals with them, and then for the 90 days above.
Activity
With an account, Community has an Activity list. It tells you when someone hearts something you wrote, comments on your review or post, or follows you, and when the developer removes something of yours and why. Each line stores whose list it is on, who did it, what it was about and when. Only you can read your Activity.
The list shows the last 30 days, and the server deletes each line after 30 days. The switches in Settings → Community choose what the list shows on your phone. The server still writes every line, and a removal always shows. Taking a heart back or unfollowing removes the line it made, and lines from someone you have blocked are not shown.
The feedback board
Settings has a Feedback screen: a shared board where anyone using Frightfolio can suggest something, report a problem, reply to someone else's post and upvote. Nothing you log goes on the board.
When you post, reply or upvote, this is what is sent and stored:
- What you typed: a post's title and its words, or a reply's words. Everyone using the app can read them, so please do not put anything private in a post.
- Your name, only if you are signed in. A post or reply made while you are signed in carries your account's ID and the name the app shows for you. Made without an account, it carries neither, and shows as Anonymous.
- A code for your copy of the app. The app creates a random identifier on your phone the first time it reaches the server, and sends it with every request it makes there. The server stores only a one-way scrambled version of it, and only with what you post, reply or upvote, never the identifier itself. It exists to do three things: keep one upvote to one phone, let the phone that wrote a post correct it for fifteen minutes, and stop the board being flooded. It is a device identifier, listed as Device ID in the app's App Store privacy details, and it is never used to track you: it is never shown to anyone, it is not an advertising identifier, and it cannot be turned back into anything. Deleting the app removes it from your phone.
- When each of those happened.
Nothing else. Not your location, not your phone's model, and nothing you have logged.
The board is hosted by Supabase too. Posts and replies are moderated by the app's developer, who can change a post's status or remove a post or a reply. Removing hides something from everyone. It is kept and not erased, so a mistake can be undone. To have something you wrote taken off the board, or to ask what the board holds about you, write to the address at the end of this page and say which post it was.
If the board is switched off, or cannot be reached, the Feedback screen says so and nothing is sent.
The settings the app reads when it opens
When the app opens it reads one small row of settings from the server. It says whether accounts, saving to accounts and the feedback board are switched on, and whether this version of the app is too old to use them. The row is the same for everyone. Reading it sends nothing about you. If it cannot be read, the app carries on. It never stops you opening the app, logging a house or reading what you have logged.
Wait times
While a Halloween Horror Nights season is running, the app fetches the current queue times for Universal Studios Florida from Queue-Times.com so that each house can show its wait. That request carries nothing about you or what you have logged. You can turn it off in Settings, and then the app asks Queue-Times.com for nothing.
Tips
Settings has a tip jar. A tip is an optional in-app purchase. Apple takes the payment and tells the app only that it went through, so no card or account details ever reach the app. Nothing about a tip is stored on the phone or sent anywhere by the app. A tip unlocks nothing.
GIFs
A post or a comment can carry one GIF, picked with the app's GIF search. The GIFs come from KLIPY, a GIF library, and this is what happens when you use them:
- The words you search for go to KLIPY through Frightfolio's server. The app sends your search words, or a request for what's trending, to Frightfolio's own server, which asks KLIPY and sends the results back. KLIPY receives the words and the server's address. It does not receive your account, your name, the code for your copy of the app, your phone's network address or anything you have logged. The server does not write the words down or keep a record of anyone's searches. It holds recent results in memory for up to five minutes, so the same search twice is quick, and then forgets them.
- The GIFs themselves load from KLIPY. Each GIF you see, in the search or on a post or comment, is fetched by your phone straight from KLIPY's file server. Like any request on the internet, that carries your phone's network address to KLIPY. Nothing else goes with it.
- The GIF you pick is stored with your post or comment, as KLIPY's address for it, and everyone who can read the post or comment sees it. It is deleted with the post or comment (see How long it is kept, under Reviews, posts and comments), and with your account.
What KLIPY does with what it receives is covered by its own privacy policy, which says it may use it to run and improve its service, including measuring advertising. The app shows no KLIPY ads and contains no KLIPY software. A GIF on a post or comment that is hidden as a spoiler is not loaded while it is hidden.
Every request the app makes
Your account and its saved log, your ratings, the house averages, what you write and do in Community, the feedback board and the settings row go to Supabase. GIF searches go to Frightfolio's server on Supabase too, which asks KLIPY, and the GIFs themselves load from KLIPY. Signing in goes through Apple or Google. Wait times go to Queue-Times.com. A tip goes to the App Store, and so does a rating you give the app when it asks for one. Nothing else leaves the app. Like any request on the internet, each one carries your phone's network address to the server it goes to.
Analytics and crashes
The app includes no analytics or advertising software. Apple may collect app analytics and crash reports on the app's behalf only if you have opted in to sharing analytics with developers in your iPhone's settings, under Privacy & Security → Analytics & Improvements. That data reaches us through Apple, in aggregate, with nothing that identifies you.
What the app does not do
It does not track you across other apps or websites. It does not sell data, and it does not share data for advertising. It does not use your location. It does not read your contacts, photos or calendar. If you choose a profile picture or banner, only the picture you pick is stored, on your phone and, if you have an account, with your saved log.
Deleting your account and your data
To delete your account, open Settings → Account → Delete account in the app. This removes your account from the server, with its email address, your username, your profile, your saved log and your photos, and with your reviews, posts and comments (see Reviews, posts and comments for what else goes with them). It cannot be undone. Your username is held for 30 days before anyone else can take it, so nobody can pass as you the day after you leave.
Posts and replies you made on the feedback board stay on the board without your name or your account ID, because other people are reading them. Write to the address below to have a post taken down.
Deleting your account does not delete what you have logged on your phone. That stays there. To erase it, use Settings → Your data → Delete all data, which also erases the copy saved to your account. If you want both gone, erase your data first and then delete the account.
Deleting the app deletes everything the app stored on your phone, except the sign-in session in the Keychain, which iOS can keep after an app is deleted. Sign out first if you want that gone too. Deleting the app does not delete your account from the server, so delete the account first if you want it gone. If you have already deleted the app, write to the address below and we will delete the account for you.
Signing out deletes nothing. What you logged stays on the phone and opens again when you sign back in.
If you signed in with Apple, Frightfolio stays listed under Sign in with Apple in your Apple Account until you remove it. To remove it, open the Settings app on your iPhone, tap your name, then Sign in with Apple, then Frightfolio, then Stop Using.
Halloween Horror Nights
Frightfolio is an independent fan project for tracking your own nights at Halloween Horror Nights. It is not affiliated with, endorsed by or connected to Universal Destinations & Experiences or NBCUniversal. House names and seasons appear as facts about the event. All artwork in the app is the app's own, and house descriptions are the app's own words with sources listed inside the app.
Contact
Questions about this policy, or a request to delete an account or a post, can be sent to matthew.tucker.d+frightfolio@gmail.com.