Duelio — Privacy Policy
Effective date: 2 August 2026 · Last updated: 22 September 2026
The short version
Duelio is a collection of games you play inside iMessage and in the standalone app. We built it to need as little of your data as possible, and here is the honest summary:
- Duelio contains no third-party analytics or advertising software. There are no ads, no cross-app tracking, no third-party crash-reporting SDK, and no advertising identifier. Duelio sends a small, allow-listed set of first-party product, game-funnel, and aggregate Apple MetricKit signals to our own server so we can improve activation, game completion, multiplayer reliability, performance, LiveOps, community features, and the shop. Those events never contain free-form text, scores, words, opponents, room codes, payment details, raw crash call stacks, or an advertising identifier, and Section 5 explains exactly what they contain.
- We never ask for contacts, location, microphone, or full photo-library access. Camera access is requested only if you choose to scan a friend's Duelio QR code. A tournament host can optionally choose one invitation image through Apple's system photo picker. Duelio re-renders and compresses only that selected image; it stays in the local draft and is uploaded only if the host publishes the tournament as invite-only. Public discovery always uses Duelio's built-in artwork.
- There is no sign-up, email, or password. Friends uses a hidden random Duelio social ID backed up through your iCloud account, plus a permanent short numeric Duelio ID shown only in Add Friends.
- Most cumulative statistics stay on your device and may sync through your personal iCloud account. For worldwide leaderboards, Social uploads only ten lifetime aggregates—overall wins; your highest Word Hunt, Bowling, Word Bomb, Anagrams, Word Shift, and Drift scores; your longest Darts Combo streak; your fastest Road Rush completion time; and your number of unlocked avatars—so it can place your chosen name and avatar on the worldwide leaderboards. Separately, the first-party analytics in Section 5 can send bounded game-funnel fields such as a game identifier, local result, play-mode/player-count/duration bucket, and random run identifier, but not a score or full history.
- Online session security and five starter hints use Apple DeviceCheck. When Duelio needs a signed online session, and when it checks the one-time starter-hint offer, the app sends an encrypted, temporary DeviceCheck token through our server to Apple. We never receive an Apple ID, serial number, or advertising identifier, and we do not store the DeviceCheck token. Session ownership is also protected by a P-256 credential: its private key stays in the shared device Keychain and syncs through iCloud Keychain when enabled, while our server stores only the public verifier and last-used time.
- Message games and Pass & Play do not send their game state or content to us. An asynchronous game sent as an iMessage stays in that conversation, and Pass & Play stays on the device in front of you. Their bounded selection/start/completion/abandonment analytics described in Section 5 can still be sent without the game state, message content, score, or opponents.
- Standalone online play does use our server — including turn-based games. Find Game, Host Online, and Join with Code relay the room and current game state through Duelio's server.
- Sharing a Pool Table Builder design is an optional server upload. Anyone with its 10-digit code can retrieve it until you ask us to delete it.
- You can voluntarily send us a bug report or suggestion. If you use the feedback form in Settings, the note is sent to our server so the developer can read it. It is not sent while you type, and it is never required to play.
- You can report another player in a live ready room or report a hosted tournament/invitation and its host. The report is stored for review and deleted automatically after 90 days.
- Friends, presence, requests, challenges, and Duelio chats use our server. Social messages are stored so recipients can read them later. You can delete all of your Duelio social data in-app.
- Player-hosted tournaments use our server. We store their authored details and settings, schedule and visibility, memberships and standings, and match/result records. Public discovery shows public tournament details and an active-player count, not the participant roster. Section 5 explains invite-only images and exactly who can see each part.
- Gifts use our server. We keep the item, sender and recipient Duelio IDs/profile snapshots, Apple's signed transaction identifiers, and delivery/refund status so a paid gift can be claimed once, restored if unsent, and removed if Apple refunds it. We never receive payment-card details or the iMessage contact/address you choose.
- Real-time live games also connect to a Duelio server. While an online room is running we can technically see what passes through it. Online matches are not end-to-end encrypted. This is the most important thing on this page.
The rest of this policy explains that in detail.
1. Who we are
Duelio is published by METK LLC ("METK", "Duelio", "we", "us"), a limited liability company whose sole owner is Tarek Khalifa.
- Contact: contact@metkapps.com
- Postal address: 3625 10th St N, Unit 708, Arlington, VA 22201, United States
If you have a question about your privacy, or want to report something a player said or drew, email us at the address above. We aim to review reports of objectionable content and abusive behaviour, and to act on them, within 24 hours.
For the purposes of the UK and EU GDPR, we are the data controller for the data described in this policy.
2. How each way to play handles your game
This distinction matters more than anything else in this policy, so it comes first.
There are four different paths, and the difference matters:
- Asynchronous games sent through iMessage do not use a Duelio server to deliver or store the match. The configuration, moves, drawings, scores, and other game data are packed into the messages you send and stay in your iMessage conversation, protected by Apple's security. We do not receive or store those message-game turns. When a message game finishes, the fixed analytics system described in Section 5 can send bounded selection, setup, start, completion, abandonment, and message-send outcomes without sending that game or conversation content.
- Pass & Play is local. Both or all players use the same device. Gameplay stays on that device and does not use a Duelio server.
- Standalone online turn relay uses a Duelio server. If you choose Find Game, Host Online, or Join with Code in the standalone app, the room and its current game state go through our server. This includes games that would stay entirely in iMessage if you chose the message-based way to play them.
- Real-time live games use a Duelio server. These rooms use the server for their ready room, roster, chat, live actions, and current game state, whether entered from an iMessage invite or from the standalone app.
Separately, Duelio Friends uses our server for the social information described in Section 5 so friends can see requests, presence, chats, challenges, and game cards across launches.
Section 4 describes both kinds of server-backed online play. Choosing the standalone app does not by itself mean gameplay is local; only Pass & Play is local there. Separately, asking for a Pool Table Builder share code uploads that design as described in Section 5.
Separately, Duelio uses a temporary DeviceCheck validation when it needs to issue or renew a signed online session and when it tries to grant the five starter hints described in Section 5. Those requests are not game activity and do not reveal what you play.
3. What we do not do
All of the following are true of Duelio, and we intend to keep them true:
- No advertising. Duelio contains no ads and no advertising software.
- No advertising or cross-app tracking. We do not collect an advertising identifier, track you across other apps or websites, or combine your activity with data from anyone else. We do not sell or share your personal information. The limited first-party product analytics described in Section 5 measure activity only inside Duelio and are not used for advertising or profiling.
- No location. Duelio never requests or receives your location. The app requests no location permission and could not access your location if it tried.
- No contacts, location, microphone, full photo-library, or health access. If you tap Scan Friend QR Code, iOS asks for camera access; the camera image is processed on-device and is not uploaded. A tournament host can separately choose one invitation image through Apple's system photo picker as described in Section 5; Duelio receives only the image the host selects, after the app re-renders and compresses it for an invite-only tournament.
- No conventional account. There is no sign-up, login, password, email address, phone-number lookup, or contact upload. A hidden random social ID lets the friends and chat system work and is restored through your personal iCloud key-value store.
- No third-party crash reporting or raw diagnostic uploads. The standalone app uses Apple's MetricKit delivery to send only aggregate crash/hang/CPU/disk exception counts and bounded launch, responsiveness, memory, CPU, foreground-time, and disk measurements. Duelio does not upload MetricKit's raw payload JSON, call stacks, device identifiers, or diagnostic bodies.
- Your complete statistics record is not uploaded. Wins, best scores, streaks and unlocks may sync through Apple's iCloud key-value storage. For worldwide leaderboards, Social uploads only the ten aggregate values explained below. Separately, the first-party analytics in Section 5 can send bounded game-funnel fields, but not scores, words, moves, opponents, or full history.
Because Duelio contains no third-party analytics or advertising SDK, there are no advertising networks, analytics vendors, or data brokers involved in this measurement. The allow-listed events go directly to Duelio's own Cloudflare-hosted server.
4. Online multiplayer games
Both standalone online turn relay and real-time live games use a Duelio server. Your device opens a connection while the online room is on screen. The connection closes when you leave, but the current room state may remain temporarily so a player can reconnect, as explained in Section 8.
Standalone online turn relay
Games that normally exchange turns inside iMessage can also be played online from the standalone app. Find Game, Host Online, and Join with Code send the current turn or checkpoint through our server so the other player can receive it immediately and a reconnecting player can catch up. Those turns are not part of an iMessage conversation and do not receive iMessage's end-to-end encryption.
Real-time live games
Eleven of Duelio's games use a shared live room for their ready room and real-time gameplay. These rooms can be reached from an iMessage invite or from the standalone app. The server relays the roster, settings, live actions, chat, and current state to the players in the room.
What is sent to our server
- Your display name, as you typed it in Duelio.
- An anonymous player identifier. In a room opened from iMessage, Apple Messages supplies a random identifier scoped to this app and conversation. In standalone online play, Duelio creates a random per-install identifier stored on your device. Neither is your name, phone number, Apple ID, or advertising identifier. The standalone identifier survives relaunches but resets if you reinstall or use a new device.
- Your chosen avatar, badge, and cosmetic settings.
- Room and matchmaking information, such as the room and game identifiers, public or private status, host display name, player count, and game settings.
- What you do in the match — your moves, scores, guesses, and game state.
- Anything you type or draw during the match. Depending on the game, this includes chat messages, drawings, prompts, custom words, and your answers.
- Your IP address. Our hosting provider necessarily sees this because your device connects to it. We do not use it to work out where you are.
Why, and on what legal basis
We use this only to run the match and relay it to the other players. There is no other purpose. We do not profile you, personalise anything, or make automated decisions about you.
If you are in the UK or EU, our legal basis is Article 6(1)(b) — performance of a contract: this data is what makes the game you chose to start work. Nothing here is optional, and there is nothing to consent to or opt out of, other than not playing online multiplayer.
Online matches are not end-to-end encrypted
Your connection to our server is encrypted in transit using TLS, which prevents anyone in between from reading it. But the encryption ends at our server, which processes your match data in readable form in order to relay it.
We are saying this plainly because Duelio launches from inside an iMessage bubble, and iMessage itself is end-to-end encrypted. That protection does not extend to an online Duelio room, even when the room was opened from an iMessage invite. Please don't treat an online Duelio room as a private channel the way you would treat an iMessage conversation.
Who can join or see each kind of match
- An asynchronous iMessage game is visible to the people in that Messages conversation and to anyone to whom its messages are forwarded. Apple, not Duelio, controls conversation membership.
- Pass & Play is visible to anyone using or looking at the shared device.
- An online room opened from an iMessage invite can be joined by people who can use that invite, including people in a group conversation or anyone to whom the invite is forwarded.
- A public standalone room is advertised in Duelio's room browser or matchmaking pool. People you do not know can find and join it. Find Game is specifically designed to match you with other players, who may be strangers.
- A private standalone room is not advertised, but anyone who knows or guesses its six-character code can try to join it. Treat a room code as an invitation, not as a password.
We do not verify anyone's real-world identity. People in an online room can see the names, avatars, chat, drawings, answers, and other game content that the room shows them. Depending on the game, a person who joins after play begins may also be able to watch and receive the saved current state.
5. Things worth calling out specifically
We would rather over-explain these than have you discover them later.
Friends, presence, challenges, and Duelio chat
The standalone app's Friends area sends a hidden random social ID, your display name and chosen avatar/cosmetics to our server. The server stores your permanent numeric Duelio ID, accepted friendships, pending requests, blocks, recent Duelio opponents, whether you were recently online, and the game/room you are currently in when you choose to show online status. Friends can use that information to see that you are online, challenge you, or join a game that is advertised as joinable. You can turn online visibility off.
Duelio direct and group chat messages, including game-invite cards, are stored on our server so participants can receive them later. A two-player play-when-ready card also stores its current turn session and revision so each player can move at a different time. Chats and those turns are encrypted in transit but are not end-to-end encrypted. Do not use Duelio chat for sensitive information. Blocking removes the friendship and prevents new requests, social messages, and challenges between the two hidden IDs. Reporting from the Friends area stores the same limited moderation record described below.
If an iMessage opponent runs a compatible version of Duelio, a game bubble can contain that opponent's hidden Duelio social ID and chosen Duelio profile. Duelio may then list them under Recent Players as an “iMessage” connection. We do not receive their phone number, email address, Apple ID, contact-card data, or iMessage address, and Duelio never reads your Messages conversation or Contacts database.
The QR scanner reads only a QR value on-device. The share link and QR contain your permanent public Duelio ID, not the hidden account ID. You can permanently delete your social profile, public Duelio ID, friendships, requests, blocks, challenges, recent-player records, messages you sent, hosted tournament ownership and participation data described below, leaderboard row, and existing pseudonymous analytics rows from Settings → Legal → Social Privacy → Delete Social Data and Analytics. This does not delete device/iCloud game statistics or App Store/gift records. The opaque random account key on your device/iCloud is retained because App Store transactions and gift purchase records are bound to it; the server retains that key only in purchase/gift records after social deletion, subject to the retention explanation in Section 8. Re-entering Social can use the same opaque key with a newly created public profile/code.
Player-hosted tournaments
Creating or joining a player-hosted tournament uses the hidden social ID authenticated by your device. For a tournament you create, the server stores that host ID and the public Duelio name/profile associated with it; the title and description you author; the size tier and player cap; selected game and game configuration; duration and schedule; public/invite-only choice; lifecycle timestamps and revision; and its hosting-credit source, App Store product, transaction identifier, environment, verification, consumption, and status record. Tournament titles and descriptions pass through the server's safety filter and cannot contain links. For participants, the server stores the hidden member IDs, join/leave times, matchmaking queue position, wins/losses/draws/forfeits, match and room identifiers, the paired player IDs, reported or forfeited result/winner, and relevant timestamps.
A public discovery card can show the host's public Duelio name/profile, authored title and description, game configuration, size/cap, schedule, status, and aggregate active-player count to authenticated Duelio users. It does not show the participant roster. Full standings—including each participant's current Duelio name/profile, rank, results, and join time—are returned only to the host and current participants. An invite-only tournament is omitted from public discovery, although an authenticated person who has its high-entropy tournament identifier or invitation can retrieve its ordinary tournament metadata and choose whether to join.
An invitation image is optional. The host selects it through Apple's system photo picker, and the app re-renders it as a bounded compressed image before upload. Player-uploaded art is prohibited on a publicly discoverable tournament; public cards use artwork compiled into Duelio. For an invite-only tournament, the image can be read only by its host, a current participant, or a person presenting the separate unguessable 128-bit capability contained in the private invite link. The tournament UUID by itself is not enough to read the image. The capability is kept in the link fragment, sent only to the same Duelio origin after you open that invitation, rotated when the image is replaced, and cleared when the image is removed or the tournament is made public. Anyone you forward the private invite link to can use its capability, so treat that link as private. If the host uses the system share sheet, the person or app the host selects receives the invitation text and private link and may also receive an attached copy of the invitation image under that destination's own privacy terms.
Hosted tournament metadata and records are stored in Cloudflare D1, and an optional invitation image is stored privately in Cloudflare R2. A server-backed tournament or invitation includes controls to report the tournament/host and block the host, except that a host cannot report or block themselves. The separate moderation-report record and its 90-day retention are described below. Hosted tournament record and image retention, and what the in-app social deletion control removes, are in Sections 8 and 9.
First-party product analytics
Duelio sends a small, fixed set of product-usage events from the standalone app and Messages extension to our server. We use these events to understand activation, retention, game and multiplayer funnels, performance, whether LiveOps is working, which games and community features are used, and where players encounter problems in the shop. The events can contain:
- a random event identifier and timestamp, the app or Messages surface, the app build, and a random session identifier. Foreground entries more than 30 minutes apart receive a new session identifier;
- one-time first-session, first-game-selection, first-game-start, and first-game-completion milestones, plus How-to-Play page and mode identifiers;
- game selection, setup, start, completion, abandonment, and rematch signals. These may include a game identifier, local result, fixed play-mode/player-count/duration/reason bucket, and a random per-run identifier, but not scores, words, moves, opponents, room identifiers/codes, room contents, or full statistics;
- fixed multiplayer stages and outcomes for hosting, finding, joining by code, reconnecting, message invitations/sends, and match starts, without the conversation, recipient, room, or opponent identifier;
- from the standalone app, aggregate values delivered by Apple MetricKit: counts of crash, hang, CPU-exception, disk-write-exception, and memory-exit reports, plus bounded p95 launch/hang time and memory, CPU, foreground-time, and disk-write measurements. Raw MetricKit payloads, diagnostic bodies, call stacks, and device identifiers are not uploaded;
- LiveOps catalog refresh results and revision numbers;
- views, follows, RSVPs, registrations, and check-ins for specific creator, event, or tournament identifiers; and
- shop section/item views and purchase start/completion results, including the catalog product, section, and attributed creator identifiers when applicable. These events do not contain a price, payment-card information, an Apple transaction identifier, or verified revenue.
The app emits only fixed, compiled event call sites, and the server enforces a per-event field allow-list; this system does not send display names, messages, search text, feedback, or other free-form content. The upload is authenticated with your hidden Duelio social ID. Before storing an event, our server replaces that ID, the random session identifier, and any random game-run identifier with separate one-way HMAC hashes that use different domain prefixes. The analytics table does not store the raw player ID, raw session/run ID, IP address, display name, room code, or arbitrary JSON. Cloudflare necessarily processes the connecting IP address while delivering the request, just as it does for other Duelio server requests, but we do not put that address in the analytics record.
The developer console shows aggregate counts and rates, such as active players, activation/retention cohorts, selection-to-start and start-to-completion rates, abandonment/rematch/multiplayer outcomes, build-level performance, community participation, and shop-funnel totals. It does not expose event-level player rows or identifiers. These analytics are not used for advertising, cross-app tracking, eligibility decisions, or automated profiling, and they are not a verified creator-payout or revenue ledger. If you are in the UK or EU, our legal basis is our legitimate interest under Article 6(1)(f) in operating, securing, and improving Duelio. We limit that interest through fixed fields, pseudonymous hashes, aggregate reporting, short retention, and the deletion control described in Section 9. You may also object as described there.
Gifts and App Store verification
When you buy or receive a gift, Duelio sends the selected item and the sender's hidden social ID, display name, and profile snapshot to our server. A direct Friends gift also includes the recipient's hidden social ID and current display name. For an iMessage gift, the server issues a random one-time claim secret that is placed in the Duelio message; the server does not receive the contact, phone number, email address, Apple ID, or iMessage address you choose in Messages.
Apple handles payment. Duelio sends Apple's signed StoreKit transaction to our server, which verifies the app, product, transaction identifier, environment, refund status, and random gift intent before granting anything. We store the transaction identifier, product, sender and eventual recipient IDs, profile/name snapshots, one-way claim-secret hash, and created/purchased/sent/claimed/applied/refunded timestamps. The plain one-time secret remains available to the purchaser while the gift is unclaimed so an unsent gift can be opened again from Gifting. A received durable item is stored as a recipient-specific gift entitlement; a hint gift records only whether its idempotent wallet credit was applied. This data is used only to deliver, recover, track, prevent duplicate claims of, and process refunds for gifts. It is not used for advertising, analytics, or profiling.
Worldwide leaderboards
When you use Social, Duelio reads the same statistics record shared by the standalone app and the iMessage extension and uploads ten lifetime aggregates: overall wins; highest Word Hunt score; highest Bowling score; highest Word Bomb round score; longest Darts Combo streak; highest Anagrams score; highest Word Shift score; fastest Road Rush completion time; highest Drift score; and number of avatars unlocked. This means qualifying results earned through either place can contribute after the standalone app next refreshes Social. Duelio does not upload the words you found, opponents, individual match results, full statistics history, or which route you used to earn a result for this feature.
The server stores those ten values with your hidden social ID, chosen display name, and chosen avatar/cosmetics. The leaderboards show the name, avatar, rank, and aggregate value to other Duelio Social users worldwide. Submitted score, win, and streak values are kept at their highest received value; the avatar count is kept for the current unlock era; Road Rush time is kept at the lowest positive value. This prevents an older device from accidentally replacing a better record. Blocked players are omitted from one another's boards. These records are used only to provide the leaderboards, not for advertising, analytics, tracking, or marketing profiles. Deleting all Duelio social data also deletes your leaderboard record; the complete statistics stored on your device and in iCloud are not deleted.
Bug reports and suggestions
The Settings panel includes an optional Bug Report / Suggestions form. Nothing is sent while you type. If you tap Transmit Feedback, we send the note (up to 8,000 characters), whether it is a bug report or suggestion, an anonymous per-install identifier, your current display name, and the app and operating-system versions. Our hosting provider also necessarily sees the connecting IP address. The note is stored so the developer can review it; it is not used for advertising, analytics, profiling, or tracking.
Player and hosted-tournament reports and blocks
In a supported live ready room, tapping another player's seat lets you report that player. A server-backed player-hosted tournament detail or private invitation also lets a non-host viewer report the tournament and its host. If you choose a reason and send the report, Duelio sends the relevant anonymous identifier described in Section 4, the reported player's identifier and current display name, the room or tournament identifier, a fixed source/game label, and the reason you selected. There is no free-text report field, and the report does not automatically include a transcript, drawing, invitation image, tournament description, or other copy of the reported content. Our hosting provider necessarily sees the connecting IP address. We store the report in a protected review inbox so we can investigate objectionable content and abusive behaviour. Reports are used only for moderation and are deleted automatically 90 days after their most recent submission.
Blocking a hosted-tournament host stores the same two hidden social IDs as an ordinary Social block. It removes the invitation/tournament from your local view and prevents the two accounts from seeing one another in tournament discovery or starting new Social interactions; it does not send the blocked person a notification. If a report control is not available, including in an asynchronous iMessage game, you can report the incident by emailing the address in Section 1.
Pool Table Builder share codes
If you tap Copy to share a Pool Table Builder design, Duelio uploads the normalized scene JSON to our server. That design can include the table, ball positions and appearance, rules, goals, and powers you selected. The server stores the design, its creation time, and a random 10-digit table code. Duelio's application database does not store an uploader or player identifier, IP address, device token, or download history with the design, although Cloudflare necessarily processes the connecting IP address and standard platform metadata while serving the upload or download.
There is no user account, ownership check, or password on a shared table. Anyone who has or guesses its 10-digit code can retrieve it. Treat the code like a public link and share it only with people you want to receive the design. Shared designs do not expire automatically; they remain retrievable until manually deleted. To request deletion, email the address in Section 1 and include the table code so we can identify it.
Session authentication, starter hints, and DeviceCheck
Before our server issues or renews a signed session for a Duelio player identifier, the app asks Apple for an encrypted, temporary DeviceCheck token. Our server forwards that token to Apple's DeviceCheck service, then returns a two-minute, one-time challenge. Duelio signs the exact challenge with a P-256 account credential. The private key is generated on-device and stored in the Keychain, shared between the app and Messages extension using their App Group. It syncs through iCloud Keychain when enabled so the same hidden identity can survive reinstall or work on another device using the same iCloud account. Legacy private keys are migrated out of preferences and iCloud KVS only after the Keychain copy is verified. The private key is never sent to us. Our server stores the matching public-key verifier, its creation time, and its last-used time so another install cannot claim an identifier merely by knowing it.
Session challenges are consumed once and removed after a session is issued; an abandoned challenge expires after two minutes and is removed during cleanup. The temporary DeviceCheck token is not stored. A public-key verifier is retained while the corresponding opaque player/account, purchase, or gift identity remains protected. There is no public credential-rebind endpoint because allowing an unverified rebind would let someone take over a known player identifier.
Each physical Apple device can contribute five starter hints once. To stop deleting and reinstalling Duelio from granting them again, the app asks Apple for an encrypted, temporary DeviceCheck token and sends that token, a random request identifier, and whether the build is a development or production build to our server. Our server immediately forwards the token to Apple's DeviceCheck service to read and set one yes/no claimed bit.
We do not receive your Apple ID, device serial number, phone number, advertising identifier, or a DeviceCheck identifier we can use across other apps. For the starter-hint flow, our server stores only the random request identifier and whether that request was granted for up to 30 days as a bounded grant receipt. Our hosting provider necessarily sees the connecting IP address. DeviceCheck and the session credential are used only to authenticate Duelio, secure online services, deliver the one-time starter hints, and prevent abuse; they are not used for advertising, analytics, profiling, or tracking.
To enforce service limits, we separately keep daily request counters keyed by a one-way, secret-keyed hash of the authenticated player ID or connecting IP address. These counters contain no raw identifiers, addresses, device tokens, or request content. They expire within two days of the start of their UTC counting day and are removed by scheduled cleanup.
Chat and anything you type
Chat messages in an online room are relayed between the players in that room. They are not stored on our server. Text sent as an ordinary iMessage is handled by Apple, not our server.
Drawings
Nothing leaves your device while you are drawing. When you submit a drawing, we send the finished image and the ordered record of the strokes that made it, so that other players' devices can replay it as an animation. Stroke data is sent when you submit, never while you draw.
When Tic-Tac-Toe or Dots & Boxes is played through iMessage, a custom symbol you draw by hand is included in the message you send and appears in that message's image. In standalone online play, the corresponding game payload travels through the Duelio server as described in Section 4.
Custom word lists in Draw
If you enter your own list of words in Draw's settings, that list is included in every Draw invite you send, and everyone in the conversation who has Duelio can read it — including in the game modes that do not use custom words, and including when the custom-words option is switched off. Switching the option off stops the words being used; it does not stop them being sent. Please don't put anything in that list you wouldn't want the whole conversation to see.
Two Truths and a Lie
This game asks you to write true facts about your own life. Those statements are sent to our server, saved as part of the match, and shown to everyone in the room — including anyone who joins later. Please don't write anything you wouldn't be comfortable being seen by everyone who can reach that conversation.
Games that show your typing as you type
In Word Bomb and Insider, other players can see your word forming as you type it. To do that, your device sends what is in the text field before you submit it, several times a second. This means text you type and then delete has already left your device.
Word games played by message
When you finish a word game that was sent to you as a message, your score and the words you found are included in the reply that goes back into the conversation. Everyone in that conversation who has Duelio can see them.
Landmark and Apple Maps
The Landmark game shows maps and street-level imagery from Apple Maps. To load them, your device asks Apple for imagery of the puzzle's location — a landmark from a list built into the app — and for the map tiles you pan around while guessing. Your own location is never requested, received, or sent. Apple receives these requests from your device, including your IP address, and handles them under Apple's privacy policy.
6. What stays on your device and in your iCloud
The following is stored on your device and may be mirrored through Apple's iCloud key-value storage so it returns on another device or after a reinstall. Except for the particular fields needed for online play, analytics, feedback, or reporting as described in Sections 4 and 5, we do not receive it:
- Your complete gameplay statistics — wins, best scores, streaks, fastest times — except for the ten leaderboard aggregates described in Section 5 when you use Social.
- Which characters, badges and items you have unlocked.
- What you have bought — whether you own Pro, and how many hints you have left. Apple handles the purchase and ordinary personal entitlements remain on your device/iCloud. If you use Gifting, the limited server gift record and signed-transaction fields described in Section 5 are also kept.
- Your display name, avatar, badge, and cosmetic choices, except that your current profile choices are sent during online play, and your display name is sent with feedback or a player report, as described in Sections 4 and 5.
- Your sound and game settings.
- Your locally saved Pool Table Builder designs, except when you explicitly upload a design to get a share code as described in Section 5.
- A record of the players you have played against, kept as the anonymous player identifiers described in Section 4, so the app can show your history with them. Online play necessarily sends the relevant identifier while you are in the room.
- Saved progress in a local or iMessage turn you haven't finished yet. An online room's current checkpoint is instead handled as described in Sections 4 and 8.
- Player-hosted tournament drafts and recently fetched tournament records, including a selected and compressed invitation image while it is part of a local draft/cache. This Application Support cache is on the device; Duelio does not put it in the app's iCloud key-value statistics record.
- A bounded analytics upload queue containing the fixed fields described in Section 5. It is stored locally only until upload succeeds and automatically drops records outside the server's seven-day ingestion window.
Deleting Duelio deletes the local copy of the data above, but an iCloud copy of iCloud-backed data may remain and be restored if you reinstall. Apple handles that storage under its privacy policy, not us. Deleting the app does not itself delete server-hosted tournament/social data, feedback, or reports. Use the authenticated social-deletion control described in Section 9 for social and hosted- tournament data. Feedback remains in the developer inbox until it is manually deleted, and reports remain until their 90-day deletion date. Contact us at contact@metkapps.com if you want to request deletion of a specific submission and can give us enough information to identify it.
7. Who else is involved
We keep this list as short as we can. It is:
- Cloudflare — hosts the Duelio server and its D1/R2 storage. Online games, Friends and chat, hosted tournament records/private invitation images, Gifting, the worldwide leaderboard, first-party analytics, feedback, reports, session authentication and its brief DeviceCheck validations, the starter-hint DeviceCheck request, LiveOps media, and Pool Table Builder sharing use this infrastructure, so Cloudflare necessarily receives the connecting IP address and ordinary request metadata. Feedback and reports are stored in protected developer inboxes; the other records are stored as described in this policy; and the DeviceCheck token is forwarded to Apple rather than stored. Shop, creator, event, and official-tournament media loads only from Duelio's same-origin Cloudflare/R2 route, not from a creator's external site. Cloudflare acts as our processor under a data processing agreement.
- Apple — delivers every Duelio message as part of iMessage, provides the maps and imagery in the Landmark game, syncs the device record and private session credential through iCloud, handles any purchase you make, validates temporary DeviceCheck tokens used for session authentication, and stores the DeviceCheck claimed bit used for the five starter hints. Purchases go through the App Store, so we never see your payment details.
- Creator, event, and tournament links, only if you choose to open one — creator profiles can contain optional HTTPS community or social links, and official event/tournament cards can contain an HTTPS rules link. Duelio never contacts those destinations automatically. If you tap one, Safari or your default browser connects to that creator or site, which receives your IP address and ordinary browser/device metadata under its own privacy terms.
- A system share destination, only if you choose it — when you share a hosted-tournament invitation, iOS gives the invitation text/link and any attached invitation image to the person or app you select. That destination handles the copy under its own privacy terms.
- The other players — everyone in your match receives what you send them.
That is the complete list. Duelio does not automatically send data to anyone else.
Where your data goes
METK LLC is based in the United States, and the Duelio server runs on Cloudflare's global network, so the server-backed data described in Sections 4 and 5 may be processed outside the UK and EU. Where that happens, the transfer is covered by our data processing agreement with Cloudflare, which incorporates the European Commission's Standard Contractual Clauses and the UK Addendum to them.
8. How long we keep it
We keep as little as we can, for as short a time as we can. Specifically:
- Live ready-room chat is not stored after the room expires. It is relayed with the live room. Duelio Friends direct and group chats are stored so participants can read them later. They remain until the sender deletes all Duelio social data or we remove them for safety or operations.
- Asynchronous iMessage games and Pass & Play have no Duelio-server game state to retain. Apple controls retention of the messages in your conversation, and local Pass & Play remains on the device.
- A match that never started is deleted immediately. When the last player leaves a room that hadn't begun, everything in it goes at once.
- Starting a rematch deletes the match before it. The saved game state is deleted the moment the room resets.
- An online match that has started is saved while it runs, so that a player who disconnects can rejoin and catch up. This applies to standalone turn-relay rooms as well as real-time live rooms. What we save is the players' display names, the game's settings, and the game state itself — which, depending on the game, can include a turn-based board or checkpoint, drawings, prompts, and Two Truths statements.
- A match abandoned partway through is deleted automatically, normally within about four hours of the last player leaving. We sweep for abandoned matches every hour and delete any that have been untouched for more than three.
- Feedback is kept in the protected developer inbox until it is manually deleted.
- A shared Pool Table Builder design does not expire automatically. It remains retrievable by its 10-digit code until we manually delete it. You can request deletion by emailing us the code.
- Player reports are deleted automatically after 90 days. They are retained only long enough for moderation review and follow-up.
- Starter-hint retry receipts are deleted automatically after 30 days. The temporary DeviceCheck token itself is never stored by us. Apple retains the claimed bit under its privacy policy so reinstalling cannot reset the offer.
- Session challenges expire after two minutes and are one-time use. They are removed after session issuance or later cleanup. We retain a player's P-256 public-key verifier and last-used time while the corresponding opaque player/account, purchase, or gift identity remains protected, so a deleted social profile cannot be taken over to reach preserved purchases or gifts. The private key remains in the shared device Keychain and, when enabled, iCloud Keychain. Preferences and iCloud KVS retain only public credential metadata after migration.
- Leaderboard records remain until you delete all Duelio social data or we remove them for safety or operations. The rest of your statistics stay on your device and in your iCloud — see Section 6.
- Gift records are retained as purchase and delivery records. Uncharged intents may remain so a delayed Ask to Buy approval can still be delivered. Paid records remain to recover unsent gifts, prove one-time delivery, reconcile entitlements, and process later App Store refund/revocation notifications. Contact us with your displayed Duelio ID if you want to exercise a data right; financial/anti-fraud records may still need to be retained where law permits or requires it.
- Player-hosted tournament records use a bounded lifecycle. Ended/cancelled records and drafts that have been inactive for more than 30 days become eligible for hourly batched deletion. That deletion removes the tournament, membership/standings, queue, match and result records, hosting credit, notification rows, and optional R2 invitation image. Transient storage failures or a cleanup backlog can delay the final deletion; failed image deletions remain in a durable cleanup queue and are retried rather than becoming untracked. A host deletion purges a non-active tournament immediately; deleting an active one cancels and de-lists it immediately, removes its invitation image/queue/pending matches, and retains the terminal record only for the same cleanup window.
- First-party analytics records are deleted automatically after 90 days by default. The app will not upload queued records more than seven days old. Deleting all Duelio social data also deletes server analytics rows tied to the keyed hash of that hidden social ID and clears the pending analytics queue on the device that performs the deletion. This deletes existing records; continued use of Duelio can create new first-party analytics events.
9. Your rights
If you are in the UK or EU, you have rights over your personal data: to access it, correct it, have it deleted, restrict or object to how it is used, and to receive a copy. You also have the right to complain to your data protection authority — in the UK, the Information Commissioner's Office (ico.org.uk).
An honest limitation, which we want to be upfront about. Duelio does not connect its random identifiers to your real-world email, phone number, Apple ID, or legal identity. We therefore cannot usually locate data from your real-world name alone. The in-app social deletion control is the most reliable way to identify and delete the social record authenticated by your device. For feedback, reports, shared tables, or matches, we may still need the specific submission, code, or room details.
What you can do today, without asking us:
- Delete the app. The on-device data described in Section 6 goes with it; already-submitted feedback does not, but you can request its deletion at the contact address.
- Change your display name at any time in Duelio's settings.
- Delete your Duelio social profile and interaction data from Settings → Legal → Social Privacy → Delete Social Data and Analytics without contacting us. A successful request immediately removes tournaments you host and their invitation art/credits; removes your membership, queue, match and result-submission rows from other hosted tournaments; clears the local tournament cache/private invite capabilities; and deletes your leaderboard row, creator follows, official event/tournament registrations, and existing pseudonymous analytics rows. A moderation report already submitted is retained under its separate 90-day safety rule. Device/iCloud game statistics and App Store/gift records are not deleted and are handled under Section 8. The public session-key verifier remains attached to the preserved opaque account key so another person cannot reclaim that identifier and reach purchases or gifts.
- Not use online multiplayer. Asynchronous games sent through iMessage and local Pass & Play do not send match state or content to our server; their bounded lifecycle analytics described in Section 5 can still be sent, and voluntary feedback is a separate Settings action.
- Wait. Online match data is not kept indefinitely — see Section 8.
10. If you are in California
We do not sell or share your personal information, and we never have. We do not have the kind of relationships with third parties that would make that possible — see Section 7.
- Categories of personal information we collect: identifiers (an identifier issued by Apple for a Messages room or a random per-install identifier created for standalone online play, an IP address, the hidden random social ID, the temporary DeviceCheck token and random request identifier, and the session public-key verifier and last-used time described in Section 5), your display name and avatar choices, your ten leaderboard values described under “Worldwide leaderboards,” friend relationships, presence, requests, challenges, recent players, Duelio social chat content, room and matchmaking information, content you create in an online match (Section 4), a Pool Table Builder design you voluntarily share, gift item/transaction/delivery records and sender/recipient profile snapshots, player-hosted tournament authorship/details/configuration/schedule/visibility, membership, standings, match/result records and optional invitation image, player/hosted-tournament-report details, the pseudonymous first-party product-interaction, gameplay, and bounded operational- diagnostic events described in Section 5, and any feedback note you voluntarily submit (Section 5).
- Categories of third parties we share it with: our hosting provider, Apple, and the other players in your match. A creator or website receives a normal browser connection only if you choose to tap a creator, event, or tournament link; a person or app you choose in the system share sheet receives only the invitation content you direct there. Duelio does not automatically send data to anyone else.
- Do Not Track: Duelio does not track you across other apps or websites, so there is no cross-service tracking for a Do Not Track signal to turn off.
- Third parties collecting information about you over time across services through Duelio: none. A creator-, event-, or tournament-linked site you choose to open operates under its own terms and may have its own data practices outside Duelio.
- Reviewing or changing your information: see Section 9.
11. Children
Duelio is intended for people aged 13 and over. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has used Duelio and sent us information, please contact us at the address in Section 1 and we will do what we can with the information available — noting the limitation described in Section 9.
12. Changes to this policy
If we change this policy, we will update the "Last updated" date at the top, and post the new version at the same address. If a change materially affects what we collect or who we share it with, we will say so in the app before it takes effect.
13. Contact
METK LLC contact@metkapps.com 3625 10th St N, Unit 708, Arlington, VA 22201, United States
