Privacy Policy

Last updated 8 September 2026

This policy covers all mobile apps published by Weasel Development ("we", "us", "our") and this website, weaseldev.com, including the Field Reports section at weaseldev.com/experiences. We act as the data controller for the limited personal data described below. For questions or requests, email support@weaseldev.com.

The document is short because our apps do very little with personal data themselves. They have no user accounts, no cloud sync, and no Weasel-operated server that stores your photos, recordings, chats, or location. The only things our server ever receives are a diagnostics report you choose to send with a feedback email, and any comment or reaction you choose to post on the Field Reports section of this website. Most of what's described below covers the third-party ad, analytics, and purchase SDKs we embed.

This policy applies to all of our apps. Tap to see the list.

What we collect

On your device: we don't directly collect anything that identifies you. The third-party SDKs we embed for ads and analytics may receive a resettable advertising ID, your IP address, your device type and OS version, and app-usage or crash events. Under EU/UK law some of these identifiers may count as personal data. See Third-party services below for the full list of providers.

When you contact support from inside an app: the in-app "Send Feedback" button first asks whether you want to attach a diagnostics report. If you agree, the app uploads that report to our server and opens your email client with a draft addressed to support@weaseldev.com, containing a short report ID so we can match the email to the report. In older app versions the same information is pasted into the email draft instead.

The diagnostics report contains technical information only: device model, OS version, screen size, memory, language and country, network type, app version, install date, your app settings and feature counters (for example how many spirits you have caught), whether a purchase is active, and the app's most recent log lines. It also contains a random ID the app generates once per install so that several reports from the same device can be grouped. That ID is not linked to your name, email, or advertising ID. The report never contains your chats, photos, recordings, notes, or location coordinates.

Because the message itself is a normal email from your own email client, we receive whatever sender name and email address your client is set up with. We only see those because you chose to send the email; the app does not transmit them in the background. You can edit or delete the draft before tapping Send, and you can decline the diagnostics upload and still email us.

Camera, microphone, photo, gallery, chat, and location content stays on your device. Our apps don't upload photos, audio, video, chat history, or session data to any server.

Ghost Chat keeps everything you build up in the app on your device: your spirit contacts, chat history, voice messages, portrait photos, and (if you opted in) the location where each spirit was caught. If you have Android backup switched on for your Google account, Ghost Chat's contacts, chat history, and settings are included in that backup so they survive a phone change. Voice messages and photos are not backed up. The backup is handled by Android and stored in your own Google account under Google's privacy policy; we never see it. Settings has a "Delete all data" action that wipes everything the app stores.

Accounts and servers

We don't run user accounts. There's no login, no profile, and no cloud sync. Anything you create in an app (photos, recordings, chats, session history, settings) lives on your device, and uninstalling the app removes it (for Ghost Chat, any Android backup copy in your Google account is managed by Android, not by us).

The only data our own server holds is the diagnostics reports described above, which exist only because you chose to send one with a feedback email, and the comments and reactions described in the next section, which exist only because you chose to post them. We keep diagnostics reports for product-quality and bug-history purposes and delete them on request.

Field Reports comments and reactions

The Field Reports section of this website (weaseldev.com/experiences) republishes selected public app-store reviews as short stories. Under each story you can tap a reaction emoji or leave a comment. Neither needs an account, and the section loads no third-party scripts, fonts, or trackers.

Comments: when you post a comment we receive the comment text, the display name you typed (it's optional; a blank name is shown as "Anonymous"), the story you posted on, the time you posted, and a salted one-way hash of your IP address. Every comment goes into a queue that we read ourselves. Nothing appears on the site until we approve it. Once approved, your display name, comment text, and the date are shown publicly to everyone who opens that story. Please don't include contact details or other people's personal information in a comment; treat it as text that will be published on a public web page.

Why we hash your IP address: the hash lets us limit how many comments and reactions one connection can post per hour and, if someone keeps posting spam or abuse, block further comments from that connection. The hash is made with a random secret that lives only on our server, so it can't be turned back into your address, and the address itself is never stored.

Reactions: reactions are counted per story only. We keep a total per emoji, not a record of who tapped it. To avoid counting the same reaction twice, our server keeps your IP hash, the story, and the emoji for the current day and deletes that record within two days, and your browser remembers which reactions you've tapped in its local storage (see Cookies).

The stories themselves: each one is a review that was already public on Google Play or the App Store, with the reviewer's name changed. If a story is based on your review and you'd rather it wasn't there, or if you want a comment of yours removed, email support@weaseldev.com with the story link and we'll take it down. See Data retention for how long comments are kept.

Third-party services

Our apps embed the following third-party SDKs. Each acts as an independent controller or processor under its own privacy policy:

These services use the data they receive to show and measure ads, run ad auctions, process purchases, draw maps, diagnose crashes, and produce aggregate usage statistics. We don't sell that data, and we have no other data on you to combine it with.

International transfers: these providers are based in the United States and may process your data in the US and other countries. When required by EU/UK law, they use Standard Contractual Clauses or equivalent safeguards. Details are in each provider's privacy policy linked above.

Permissions used by some apps

Some apps request operating-system permissions to function. We only request what we need, and the content captured under these permissions stays on your device:

You can revoke any of these permissions from your device's settings at any time. The app will continue to run, though features that depend on the permission will be unavailable.

Cookies

Our apps don't use cookies. Third-party SDKs (see above) may use cookie-like identifiers within their own services. This website (weaseldev.com) doesn't set any cookies for visitors and doesn't load third-party analytics or tracking scripts. The Field Reports section uses your browser's local storage (not a cookie) to remember which reactions you've already tapped so they aren't counted twice. That value stays in your browser, is never sent to us, and disappears when you clear the site's data. The private moderation page we use to approve comments sets a login cookie, but only for us when we sign in.

Children's privacy

Our apps are not intended for use by nor marketed towards children under 13. We don't knowingly collect personal information from children. If you believe a child has provided us with information through a feedback email or a Field Reports comment, contact us at support@weaseldev.com and we will delete it.

Your rights — EU / EEA / UK (GDPR)

If you're in the EU, EEA, or UK, you have rights over personal data we hold about you, including the right to:

To exercise any of these rights, email support@weaseldev.com. Before we act on a request, we may ask for information that confirms your identity (for example, the email you used to contact us, or a description of the device and roughly when the app was used). This is so we don't accidentally disclose or delete someone else's data.

Because we store almost no identifying data on our own servers, an erasure request is usually satisfied by uninstalling the app and resetting your device advertising ID in the OS settings. Ghost Chat also has a "Delete all data" action in Settings. If you've previously emailed support, you can also ask us to delete that thread and any diagnostics report that came with it; quote the Report ID from your email if you still have it. If you've posted a comment on Field Reports, tell us the story link and the name or wording of the comment and we'll delete it.

Your rights — California (CCPA / CPRA)

If you're a California resident, you have the right to:

Categories of personal information we collect (in the last 12 months, using CCPA categories): identifiers such as a resettable advertising ID, a random purchase ID, IP address, and (for Field Reports) a hashed IP address and any display name you type; internet activity information such as app interaction events, crash reports, and diagnostics reports you choose to send; content you choose to post, namely Field Reports comments; commercial information such as purchase records; and inferences when ad networks use that data for ad targeting. Ghost Chat can process precise geolocation on your device when you opt in, but it is never transmitted to us or to our providers. We don't collect sensitive personal information, biometrics, or any of the other CCPA categories.

"Sale" and "sharing": we don't sell personal information for money. Some activity by our third-party ad SDKs may still meet the CPRA's broad definitions of "sale" or "sharing for cross-context behavioural advertising." To opt out, withhold or revoke ad-personalisation consent in the in-app consent banner, email support@weaseldev.com, or enable Global Privacy Control in a browser that supports it. GPC is a web-browser signal and most mobile ad SDKs do not currently honour it.

To submit a verifiable consumer request, email support@weaseldev.com. We may need to verify your identity first; see the GDPR section above for what we typically ask. You can authorise an agent to act on your behalf; in that case we'll ask for written authorisation and may still verify your identity directly.

Data retention

Apart from what you choose to send or post to us, we don't retain identifying personal data on our own servers because we don't collect any. Support email threads are kept for up to 24 months for product-quality and bug-history purposes, then deleted. Diagnostics reports contain no identifying data and are kept for bug-history purposes; we delete any report on request (quote the Report ID from your email if you have it). Field Reports comments are kept, together with their hashed IP address, for as long as the story is online: approved comments so they can be shown, and comments we didn't approve so we can recognise repeat spam. We delete any comment on request. Hourly rate-limit counters are deleted within a few hours and the per-day reaction record within two days; reaction totals per story are kept as plain counts with nothing tying them to you. Third-party SDK data is retained according to those providers' own retention policies, which are linked above.

Security and breach notification

Email is transmitted over your provider's network and is typically TLS-encrypted in transit between modern mail providers. Diagnostics reports, comments, and reactions are sent to us over HTTPS. The database that holds comments and reactions is stored outside the web-accessible part of our server, and it contains a salted hash of your IP address rather than the address itself. We use reasonable technical and organisational measures to protect any data we receive, but no method of transmission or storage is fully secure.

If a personal data breach occurs that is likely to put your rights or freedoms at risk, we'll notify the relevant supervisory authority. Where the law requires it, we'll also notify the affected individuals. We do both without undue delay and within the timeframes the law requires.

Changes to this policy

We post updates to this page and bump the "Last updated" date at the top. For material changes that affect how we handle your personal data, we'll give a more prominent notice where practical, such as an in-app message on next launch. The previous version of this policy is available on request.

Contact

For privacy questions, rights requests, or anything else, email support@weaseldev.com.

If any part of this policy is found to be unenforceable, the remaining parts continue in effect.