← Back to duelioapp.com

Duelio — Privacy Policy

Effective date: 2 August 2026  ·  Last updated: 22 September 2026

The short version

Duelio is a collection of games you play inside iMessage and in the standalone app. We built it to need as little of your data as possible, and here is the honest summary:

The rest of this policy explains that in detail.


1. Who we are

Duelio is published by METK LLC ("METK", "Duelio", "we", "us"), a limited liability company whose sole owner is Tarek Khalifa.

If you have a question about your privacy, or want to report something a player said or drew, email us at the address above. We aim to review reports of objectionable content and abusive behaviour, and to act on them, within 24 hours.

For the purposes of the UK and EU GDPR, we are the data controller for the data described in this policy.


2. How each way to play handles your game

This distinction matters more than anything else in this policy, so it comes first.

There are four different paths, and the difference matters:

Separately, Duelio Friends uses our server for the social information described in Section 5 so friends can see requests, presence, chats, challenges, and game cards across launches.

Section 4 describes both kinds of server-backed online play. Choosing the standalone app does not by itself mean gameplay is local; only Pass & Play is local there. Separately, asking for a Pool Table Builder share code uploads that design as described in Section 5.

Separately, Duelio uses a temporary DeviceCheck validation when it needs to issue or renew a signed online session and when it tries to grant the five starter hints described in Section 5. Those requests are not game activity and do not reveal what you play.


3. What we do not do

All of the following are true of Duelio, and we intend to keep them true:

Because Duelio contains no third-party analytics or advertising SDK, there are no advertising networks, analytics vendors, or data brokers involved in this measurement. The allow-listed events go directly to Duelio's own Cloudflare-hosted server.


4. Online multiplayer games

Both standalone online turn relay and real-time live games use a Duelio server. Your device opens a connection while the online room is on screen. The connection closes when you leave, but the current room state may remain temporarily so a player can reconnect, as explained in Section 8.

Standalone online turn relay

Games that normally exchange turns inside iMessage can also be played online from the standalone app. Find Game, Host Online, and Join with Code send the current turn or checkpoint through our server so the other player can receive it immediately and a reconnecting player can catch up. Those turns are not part of an iMessage conversation and do not receive iMessage's end-to-end encryption.

Real-time live games

Eleven of Duelio's games use a shared live room for their ready room and real-time gameplay. These rooms can be reached from an iMessage invite or from the standalone app. The server relays the roster, settings, live actions, chat, and current state to the players in the room.

What is sent to our server

We use this only to run the match and relay it to the other players. There is no other purpose. We do not profile you, personalise anything, or make automated decisions about you.

If you are in the UK or EU, our legal basis is Article 6(1)(b) — performance of a contract: this data is what makes the game you chose to start work. Nothing here is optional, and there is nothing to consent to or opt out of, other than not playing online multiplayer.

Online matches are not end-to-end encrypted

Your connection to our server is encrypted in transit using TLS, which prevents anyone in between from reading it. But the encryption ends at our server, which processes your match data in readable form in order to relay it.

We are saying this plainly because Duelio launches from inside an iMessage bubble, and iMessage itself is end-to-end encrypted. That protection does not extend to an online Duelio room, even when the room was opened from an iMessage invite. Please don't treat an online Duelio room as a private channel the way you would treat an iMessage conversation.

Who can join or see each kind of match

We do not verify anyone's real-world identity. People in an online room can see the names, avatars, chat, drawings, answers, and other game content that the room shows them. Depending on the game, a person who joins after play begins may also be able to watch and receive the saved current state.


5. Things worth calling out specifically

We would rather over-explain these than have you discover them later.

Friends, presence, challenges, and Duelio chat

The standalone app's Friends area sends a hidden random social ID, your display name and chosen avatar/cosmetics to our server. The server stores your permanent numeric Duelio ID, accepted friendships, pending requests, blocks, recent Duelio opponents, whether you were recently online, and the game/room you are currently in when you choose to show online status. Friends can use that information to see that you are online, challenge you, or join a game that is advertised as joinable. You can turn online visibility off.

Duelio direct and group chat messages, including game-invite cards, are stored on our server so participants can receive them later. A two-player play-when-ready card also stores its current turn session and revision so each player can move at a different time. Chats and those turns are encrypted in transit but are not end-to-end encrypted. Do not use Duelio chat for sensitive information. Blocking removes the friendship and prevents new requests, social messages, and challenges between the two hidden IDs. Reporting from the Friends area stores the same limited moderation record described below.

If an iMessage opponent runs a compatible version of Duelio, a game bubble can contain that opponent's hidden Duelio social ID and chosen Duelio profile. Duelio may then list them under Recent Players as an “iMessage” connection. We do not receive their phone number, email address, Apple ID, contact-card data, or iMessage address, and Duelio never reads your Messages conversation or Contacts database.

The QR scanner reads only a QR value on-device. The share link and QR contain your permanent public Duelio ID, not the hidden account ID. You can permanently delete your social profile, public Duelio ID, friendships, requests, blocks, challenges, recent-player records, messages you sent, hosted tournament ownership and participation data described below, leaderboard row, and existing pseudonymous analytics rows from Settings → Legal → Social Privacy → Delete Social Data and Analytics. This does not delete device/iCloud game statistics or App Store/gift records. The opaque random account key on your device/iCloud is retained because App Store transactions and gift purchase records are bound to it; the server retains that key only in purchase/gift records after social deletion, subject to the retention explanation in Section 8. Re-entering Social can use the same opaque key with a newly created public profile/code.

Player-hosted tournaments

Creating or joining a player-hosted tournament uses the hidden social ID authenticated by your device. For a tournament you create, the server stores that host ID and the public Duelio name/profile associated with it; the title and description you author; the size tier and player cap; selected game and game configuration; duration and schedule; public/invite-only choice; lifecycle timestamps and revision; and its hosting-credit source, App Store product, transaction identifier, environment, verification, consumption, and status record. Tournament titles and descriptions pass through the server's safety filter and cannot contain links. For participants, the server stores the hidden member IDs, join/leave times, matchmaking queue position, wins/losses/draws/forfeits, match and room identifiers, the paired player IDs, reported or forfeited result/winner, and relevant timestamps.

A public discovery card can show the host's public Duelio name/profile, authored title and description, game configuration, size/cap, schedule, status, and aggregate active-player count to authenticated Duelio users. It does not show the participant roster. Full standings—including each participant's current Duelio name/profile, rank, results, and join time—are returned only to the host and current participants. An invite-only tournament is omitted from public discovery, although an authenticated person who has its high-entropy tournament identifier or invitation can retrieve its ordinary tournament metadata and choose whether to join.

An invitation image is optional. The host selects it through Apple's system photo picker, and the app re-renders it as a bounded compressed image before upload. Player-uploaded art is prohibited on a publicly discoverable tournament; public cards use artwork compiled into Duelio. For an invite-only tournament, the image can be read only by its host, a current participant, or a person presenting the separate unguessable 128-bit capability contained in the private invite link. The tournament UUID by itself is not enough to read the image. The capability is kept in the link fragment, sent only to the same Duelio origin after you open that invitation, rotated when the image is replaced, and cleared when the image is removed or the tournament is made public. Anyone you forward the private invite link to can use its capability, so treat that link as private. If the host uses the system share sheet, the person or app the host selects receives the invitation text and private link and may also receive an attached copy of the invitation image under that destination's own privacy terms.

Hosted tournament metadata and records are stored in Cloudflare D1, and an optional invitation image is stored privately in Cloudflare R2. A server-backed tournament or invitation includes controls to report the tournament/host and block the host, except that a host cannot report or block themselves. The separate moderation-report record and its 90-day retention are described below. Hosted tournament record and image retention, and what the in-app social deletion control removes, are in Sections 8 and 9.

First-party product analytics

Duelio sends a small, fixed set of product-usage events from the standalone app and Messages extension to our server. We use these events to understand activation, retention, game and multiplayer funnels, performance, whether LiveOps is working, which games and community features are used, and where players encounter problems in the shop. The events can contain:

The app emits only fixed, compiled event call sites, and the server enforces a per-event field allow-list; this system does not send display names, messages, search text, feedback, or other free-form content. The upload is authenticated with your hidden Duelio social ID. Before storing an event, our server replaces that ID, the random session identifier, and any random game-run identifier with separate one-way HMAC hashes that use different domain prefixes. The analytics table does not store the raw player ID, raw session/run ID, IP address, display name, room code, or arbitrary JSON. Cloudflare necessarily processes the connecting IP address while delivering the request, just as it does for other Duelio server requests, but we do not put that address in the analytics record.

The developer console shows aggregate counts and rates, such as active players, activation/retention cohorts, selection-to-start and start-to-completion rates, abandonment/rematch/multiplayer outcomes, build-level performance, community participation, and shop-funnel totals. It does not expose event-level player rows or identifiers. These analytics are not used for advertising, cross-app tracking, eligibility decisions, or automated profiling, and they are not a verified creator-payout or revenue ledger. If you are in the UK or EU, our legal basis is our legitimate interest under Article 6(1)(f) in operating, securing, and improving Duelio. We limit that interest through fixed fields, pseudonymous hashes, aggregate reporting, short retention, and the deletion control described in Section 9. You may also object as described there.

Gifts and App Store verification

When you buy or receive a gift, Duelio sends the selected item and the sender's hidden social ID, display name, and profile snapshot to our server. A direct Friends gift also includes the recipient's hidden social ID and current display name. For an iMessage gift, the server issues a random one-time claim secret that is placed in the Duelio message; the server does not receive the contact, phone number, email address, Apple ID, or iMessage address you choose in Messages.

Apple handles payment. Duelio sends Apple's signed StoreKit transaction to our server, which verifies the app, product, transaction identifier, environment, refund status, and random gift intent before granting anything. We store the transaction identifier, product, sender and eventual recipient IDs, profile/name snapshots, one-way claim-secret hash, and created/purchased/sent/claimed/applied/refunded timestamps. The plain one-time secret remains available to the purchaser while the gift is unclaimed so an unsent gift can be opened again from Gifting. A received durable item is stored as a recipient-specific gift entitlement; a hint gift records only whether its idempotent wallet credit was applied. This data is used only to deliver, recover, track, prevent duplicate claims of, and process refunds for gifts. It is not used for advertising, analytics, or profiling.

Worldwide leaderboards

When you use Social, Duelio reads the same statistics record shared by the standalone app and the iMessage extension and uploads ten lifetime aggregates: overall wins; highest Word Hunt score; highest Bowling score; highest Word Bomb round score; longest Darts Combo streak; highest Anagrams score; highest Word Shift score; fastest Road Rush completion time; highest Drift score; and number of avatars unlocked. This means qualifying results earned through either place can contribute after the standalone app next refreshes Social. Duelio does not upload the words you found, opponents, individual match results, full statistics history, or which route you used to earn a result for this feature.

The server stores those ten values with your hidden social ID, chosen display name, and chosen avatar/cosmetics. The leaderboards show the name, avatar, rank, and aggregate value to other Duelio Social users worldwide. Submitted score, win, and streak values are kept at their highest received value; the avatar count is kept for the current unlock era; Road Rush time is kept at the lowest positive value. This prevents an older device from accidentally replacing a better record. Blocked players are omitted from one another's boards. These records are used only to provide the leaderboards, not for advertising, analytics, tracking, or marketing profiles. Deleting all Duelio social data also deletes your leaderboard record; the complete statistics stored on your device and in iCloud are not deleted.

Bug reports and suggestions

The Settings panel includes an optional Bug Report / Suggestions form. Nothing is sent while you type. If you tap Transmit Feedback, we send the note (up to 8,000 characters), whether it is a bug report or suggestion, an anonymous per-install identifier, your current display name, and the app and operating-system versions. Our hosting provider also necessarily sees the connecting IP address. The note is stored so the developer can review it; it is not used for advertising, analytics, profiling, or tracking.

Player and hosted-tournament reports and blocks

In a supported live ready room, tapping another player's seat lets you report that player. A server-backed player-hosted tournament detail or private invitation also lets a non-host viewer report the tournament and its host. If you choose a reason and send the report, Duelio sends the relevant anonymous identifier described in Section 4, the reported player's identifier and current display name, the room or tournament identifier, a fixed source/game label, and the reason you selected. There is no free-text report field, and the report does not automatically include a transcript, drawing, invitation image, tournament description, or other copy of the reported content. Our hosting provider necessarily sees the connecting IP address. We store the report in a protected review inbox so we can investigate objectionable content and abusive behaviour. Reports are used only for moderation and are deleted automatically 90 days after their most recent submission.

Blocking a hosted-tournament host stores the same two hidden social IDs as an ordinary Social block. It removes the invitation/tournament from your local view and prevents the two accounts from seeing one another in tournament discovery or starting new Social interactions; it does not send the blocked person a notification. If a report control is not available, including in an asynchronous iMessage game, you can report the incident by emailing the address in Section 1.

Pool Table Builder share codes

If you tap Copy to share a Pool Table Builder design, Duelio uploads the normalized scene JSON to our server. That design can include the table, ball positions and appearance, rules, goals, and powers you selected. The server stores the design, its creation time, and a random 10-digit table code. Duelio's application database does not store an uploader or player identifier, IP address, device token, or download history with the design, although Cloudflare necessarily processes the connecting IP address and standard platform metadata while serving the upload or download.

There is no user account, ownership check, or password on a shared table. Anyone who has or guesses its 10-digit code can retrieve it. Treat the code like a public link and share it only with people you want to receive the design. Shared designs do not expire automatically; they remain retrievable until manually deleted. To request deletion, email the address in Section 1 and include the table code so we can identify it.

Session authentication, starter hints, and DeviceCheck

Before our server issues or renews a signed session for a Duelio player identifier, the app asks Apple for an encrypted, temporary DeviceCheck token. Our server forwards that token to Apple's DeviceCheck service, then returns a two-minute, one-time challenge. Duelio signs the exact challenge with a P-256 account credential. The private key is generated on-device and stored in the Keychain, shared between the app and Messages extension using their App Group. It syncs through iCloud Keychain when enabled so the same hidden identity can survive reinstall or work on another device using the same iCloud account. Legacy private keys are migrated out of preferences and iCloud KVS only after the Keychain copy is verified. The private key is never sent to us. Our server stores the matching public-key verifier, its creation time, and its last-used time so another install cannot claim an identifier merely by knowing it.

Session challenges are consumed once and removed after a session is issued; an abandoned challenge expires after two minutes and is removed during cleanup. The temporary DeviceCheck token is not stored. A public-key verifier is retained while the corresponding opaque player/account, purchase, or gift identity remains protected. There is no public credential-rebind endpoint because allowing an unverified rebind would let someone take over a known player identifier.

Each physical Apple device can contribute five starter hints once. To stop deleting and reinstalling Duelio from granting them again, the app asks Apple for an encrypted, temporary DeviceCheck token and sends that token, a random request identifier, and whether the build is a development or production build to our server. Our server immediately forwards the token to Apple's DeviceCheck service to read and set one yes/no claimed bit.

We do not receive your Apple ID, device serial number, phone number, advertising identifier, or a DeviceCheck identifier we can use across other apps. For the starter-hint flow, our server stores only the random request identifier and whether that request was granted for up to 30 days as a bounded grant receipt. Our hosting provider necessarily sees the connecting IP address. DeviceCheck and the session credential are used only to authenticate Duelio, secure online services, deliver the one-time starter hints, and prevent abuse; they are not used for advertising, analytics, profiling, or tracking.

To enforce service limits, we separately keep daily request counters keyed by a one-way, secret-keyed hash of the authenticated player ID or connecting IP address. These counters contain no raw identifiers, addresses, device tokens, or request content. They expire within two days of the start of their UTC counting day and are removed by scheduled cleanup.

Chat and anything you type

Chat messages in an online room are relayed between the players in that room. They are not stored on our server. Text sent as an ordinary iMessage is handled by Apple, not our server.

Drawings

Nothing leaves your device while you are drawing. When you submit a drawing, we send the finished image and the ordered record of the strokes that made it, so that other players' devices can replay it as an animation. Stroke data is sent when you submit, never while you draw.

When Tic-Tac-Toe or Dots & Boxes is played through iMessage, a custom symbol you draw by hand is included in the message you send and appears in that message's image. In standalone online play, the corresponding game payload travels through the Duelio server as described in Section 4.

Custom word lists in Draw

If you enter your own list of words in Draw's settings, that list is included in every Draw invite you send, and everyone in the conversation who has Duelio can read it — including in the game modes that do not use custom words, and including when the custom-words option is switched off. Switching the option off stops the words being used; it does not stop them being sent. Please don't put anything in that list you wouldn't want the whole conversation to see.

Two Truths and a Lie

This game asks you to write true facts about your own life. Those statements are sent to our server, saved as part of the match, and shown to everyone in the room — including anyone who joins later. Please don't write anything you wouldn't be comfortable being seen by everyone who can reach that conversation.

Games that show your typing as you type

In Word Bomb and Insider, other players can see your word forming as you type it. To do that, your device sends what is in the text field before you submit it, several times a second. This means text you type and then delete has already left your device.

Word games played by message

When you finish a word game that was sent to you as a message, your score and the words you found are included in the reply that goes back into the conversation. Everyone in that conversation who has Duelio can see them.

Landmark and Apple Maps

The Landmark game shows maps and street-level imagery from Apple Maps. To load them, your device asks Apple for imagery of the puzzle's location — a landmark from a list built into the app — and for the map tiles you pan around while guessing. Your own location is never requested, received, or sent. Apple receives these requests from your device, including your IP address, and handles them under Apple's privacy policy.


6. What stays on your device and in your iCloud

The following is stored on your device and may be mirrored through Apple's iCloud key-value storage so it returns on another device or after a reinstall. Except for the particular fields needed for online play, analytics, feedback, or reporting as described in Sections 4 and 5, we do not receive it:

Deleting Duelio deletes the local copy of the data above, but an iCloud copy of iCloud-backed data may remain and be restored if you reinstall. Apple handles that storage under its privacy policy, not us. Deleting the app does not itself delete server-hosted tournament/social data, feedback, or reports. Use the authenticated social-deletion control described in Section 9 for social and hosted- tournament data. Feedback remains in the developer inbox until it is manually deleted, and reports remain until their 90-day deletion date. Contact us at contact@metkapps.com if you want to request deletion of a specific submission and can give us enough information to identify it.


7. Who else is involved

We keep this list as short as we can. It is:

That is the complete list. Duelio does not automatically send data to anyone else.

Where your data goes

METK LLC is based in the United States, and the Duelio server runs on Cloudflare's global network, so the server-backed data described in Sections 4 and 5 may be processed outside the UK and EU. Where that happens, the transfer is covered by our data processing agreement with Cloudflare, which incorporates the European Commission's Standard Contractual Clauses and the UK Addendum to them.


8. How long we keep it

We keep as little as we can, for as short a time as we can. Specifically:


9. Your rights

If you are in the UK or EU, you have rights over your personal data: to access it, correct it, have it deleted, restrict or object to how it is used, and to receive a copy. You also have the right to complain to your data protection authority — in the UK, the Information Commissioner's Office (ico.org.uk).

An honest limitation, which we want to be upfront about. Duelio does not connect its random identifiers to your real-world email, phone number, Apple ID, or legal identity. We therefore cannot usually locate data from your real-world name alone. The in-app social deletion control is the most reliable way to identify and delete the social record authenticated by your device. For feedback, reports, shared tables, or matches, we may still need the specific submission, code, or room details.

What you can do today, without asking us:


10. If you are in California

We do not sell or share your personal information, and we never have. We do not have the kind of relationships with third parties that would make that possible — see Section 7.


11. Children

Duelio is intended for people aged 13 and over. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has used Duelio and sent us information, please contact us at the address in Section 1 and we will do what we can with the information available — noting the limitation described in Section 9.


12. Changes to this policy

If we change this policy, we will update the "Last updated" date at the top, and post the new version at the same address. If a change materially affects what we collect or who we share it with, we will say so in the app before it takes effect.


13. Contact

METK LLC contact@metkapps.com 3625 10th St N, Unit 708, Arlington, VA 22201, United States