Privacy Policy
Last updated 21 September 2026 · Applies to the SamNeon apps for iPhone, iPad, Mac and Android, and to samneon.com
SamNeon is made by Akomolafe Samuel ("we", "us"). This policy says exactly what we store, why, who else sees it, and how to get rid of it. There are no advertising networks, no analytics SDKs and no trackers in SamNeon, and we do not sell personal information to anyone.
1. What we store, and why
The short version: as little as the contest can be run on honestly.
If you just play
- A game account. Created silently on first launch so your progress survives a reinstall. It holds a random identifier, a secret token for your device, your platform, and your progress: XP, rank, levels cleared and the date each was cleared, missions, best score, Endless wave.
- A device identifier, hashed. We take the identifier your platform already gives apps (the vendor identifier on Apple devices, the settings identifier on Android, the hardware UUID on Mac) and store only a keyed hash of it. It lets one device hold one account, and lets your account come back after a reinstall. We cannot turn the hash back into the identifier.
- Your IP address, hashed. Stored only as a keyed hash, for rate limiting and abuse detection. We do not keep the address itself and do not use it to locate you.
- The player name you choose. Public by design: it appears on the leaderboard and on any proof card you share. Choose one you are happy for strangers to see.
- Your runs. Each counted run is stored as the record of your inputs plus the result our servers computed from replaying them. This is what makes the contest cheat-resistant. It is gameplay data, not anything about you personally.
- On Apple devices, a DeviceCheck result. Apple tells us one bit: whether this device has held a SamNeon account before. We use it as a signal against mass account creation. Apple does not tell us anything else about the device.
If you sign in
Signing in is optional and only needed to be paid a prize.
- Email and password — the password is stored only as a scrypt hash, never in a form we or anyone else can read back.
- Sign in with Apple or Google — we store the stable identifier the provider gives us, and the email if the provider shares it. If you use Apple's private relay address, that relay address is all we ever have.
If you subscribe
- A subscription identifier from Apple or Google, so one subscription belongs to one account. We never see or store your card, bank or payment details — those stay with Apple or Google and never reach us.
If you win and ask to be paid
- Your name, email, chosen network and wallet address, to send the payment and to enforce one prize set per person.
- A payout PIN, stored only as a scrypt hash.
- An identity check. A government ID and a live selfie are handled by an independent verification provider, not by us. We never receive or store your ID document or your selfie. The provider returns only a pass or fail and a stable code that stands for "this person", which lets us enforce one verified person per account. We keep that code, the result, the date and any note the provider sends.
2. What we never collect
- No advertising identifiers, no cross-app or cross-site tracking, no ad networks.
- No third-party analytics or crash SDK inside the app.
- No contacts, photos, microphone, camera or precise location. The camera is used only by the identity provider's own flow, if you choose to be paid.
- No payment card details, ever.
3. Who else is involved
These are the only parties that touch any of it, and only for the job named:
- Supabase — the database holding the accounts and runs (hosted in the United States).
- Vercel — runs our servers and this website.
- Apple and Google — sign-in, subscriptions and, on Apple, DeviceCheck.
- An independent identity verification provider — only if you ask to be paid a prize, and only for that check. The provider's own privacy policy governs the documents you give it. We will name the provider here and in the app before any check is ever run.
- A public blockchain — when we pay a prize, the transaction is public and permanent by nature. It shows the wallet address you gave us and the amount. It does not carry your name.
We do not sell personal information, and we do not share it for advertising.
4. The blockchain is permanent
A payment on a public blockchain cannot be deleted by us or by anyone else. If you would rather a wallet address not be linked to a prize payment for ever, use a wallet address you are comfortable being public, and remember that deleting your SamNeon account does not remove a transaction that already happened.
5. How long we keep it
- Account and progress: while the account exists.
- Run recordings: while they matter to the contest, and at most two years.
- Payout records and identity-check results: seven years after a payment, because tax and anti-fraud rules require a payer to be able to show who was paid.
- Hashed IPs and abuse signals: 12 months.
6. Your choices
- Delete your account from inside the app at any time, or without the app from samneon.com/delete-account. It removes your player name, email, sign-in links and contact details, and unlinks your runs. Where a prize has already been paid we keep the minimum payment record the law requires, and nothing more.
- Ask us for a copy of what we hold about you, or ask us to correct it, by emailing support@samneon.com. We answer within 30 days.
- Play without signing in. Ranks, the ladder and the prize board all work without an account. Signing in is needed only to be paid.
- If you are in the UK, EU, or a similar jurisdiction, you also have the right to object, to restrict processing, to data portability and to complain to your data protection authority. Our lawful bases are performance of a contract (running the game and the contest), legitimate interests (keeping the contest fair) and legal obligation (payment records).
7. Children
SamNeon is not directed at children and the Ultimate Challenge is open only to people aged 18 or over. We do not knowingly collect personal information from children. If you believe a child has given us personal information, email us and we will delete it.
8. Security
Everything travels over HTTPS. Passwords and payout PINs are stored only as scrypt hashes. Device identifiers and IP addresses are stored only as keyed hashes. Our database is not reachable from the public internet; only our own servers can read it. The keys that authorise a payout exist only on the developer's own machine, encrypted with a passphrase, and our servers cannot move money on their own.
9. This website
samneon.com sets no cookies, runs no analytics and loads no third-party scripts or fonts. The live prize figures on the home page come from our own servers on this same domain.
10. Changes
If this policy changes we update the date at the top and, for anything material, say so in the app. Continuing to use SamNeon after a change means the updated policy applies.
11. Contact
Akomolafe Samuel · support@samneon.com
We answer privacy requests within 30 days.