TBCSTUD.IO TERMS →
PRIVACY.TXT

Privacy Policy.

LAST UPDATED: 10 AUGUST 2026

TBC Studio is a one-person independent software studio. This policy covers the website at tbcstud.io and the apps listed on it — Gliding, Daylight, Fog, Lockin and Caliskill.

The short version: the apps are built to work without accounts and without a server, so for the most part there is nothing about you for us to hold. The long version is below.

WHO WE ARE

TBC Studio ("we", "us") is an independent software studio, and is the data controller for any personal data described in this policy. You can reach us at the address in Contact below.

Trading name and email only, by choice, while nothing is launched. UK GDPR is satisfied by this — Art. 13 asks for the controller's identity and contact details, and a working email is contact details. Selling directly through Stripe is what changes the position: the Consumer Contracts Regulations 2013 require a trader's geographic address to be given before a distance sale, and the Companies Act 2006 Part 41 and the E-Commerce Regulations expect a name and address once you trade under a name that isn't your surname. So this holds until the first live Stripe key, not until the first download. It still need not be a home address.

WHAT WE COLLECT

Data you give us directly. If you email us, we hold your email address and whatever you put in the message, for as long as we need it to answer you and to keep a record of the conversation.

Data stored on your own device. Most of what our apps know about you never leaves your device. Tasks, progress, settings, saved boards and similar app data are held in your browser's local storage or in the app's own on-device storage. We cannot read it, and clearing your browser data or deleting the app deletes it.

Data collected automatically. Our web hosting provider processes your IP address and basic request information in order to serve the site and to keep it secure. This is ordinary server logging, not analytics about you.

Confirm there is no analytics or crash reporting (Vercel Analytics, Sentry, Google Analytics, TelemetryDeck) in any app. The leaderboards and Stripe checkout below are described from the actual code; analytics is the one category not yet verified. If any app has it, name the provider here.

LEADERBOARDS — LOCKIN AND FOG

Lockin and Fog each have an optional daily leaderboard. This is the only part of either app that sends anything about you to a server, so it is worth being precise about.

What gets sent. Two things, and nothing else: a display name of up to 24 characters, and your score for that day. If you do not choose a name, your entry is submitted as "Anonymous". No email address, no account, no device identifier and no location is attached to the entry.

The name is yours to choose, and it is public. Today's top fifty entries are visible to everyone playing. Please pick something you are happy to have shown publicly — you do not need to use your real name, and we would rather you did not.

How long it lasts. Each day's board is stored under its own key which is set to expire automatically after 48 hours. Entries are not archived, not aggregated, and not linked across days. After two days the data is gone whether you ask for it or not.

Where it is stored. In a Redis store operated by Upstash and provisioned through Vercel. Scores are submitted by your device and are not independently verified.

Removing an entry. Changing your name in the app removes the previous entry and replaces it, so a score appears once. If you want an entry taken down sooner than its automatic expiry, email us — though in practice it will expire within 48 hours regardless.

Both leaderboards are optional. If the leaderboard is not configured or is unreachable, the app falls back to a purely local board on your own device, and nothing is transmitted at all.

WHAT WE DO NOT DO

PAYMENTS

Paid unlocks reach us by one of two routes, and they work differently.

Through an app store. Where you buy inside an app distributed by Apple or Google, that store takes the payment and holds the payment details. We receive only the fact that a purchase was made.

On the web, through Stripe. Fog and Lockin sell their one-time unlock on the web using Stripe Checkout. You enter your card details on Stripe's own pages, never on ours — we never see or store your card number. Stripe processes the payment as our payment processor and passes back a confirmation, together with the limited billing information it collects, such as your email address and country. We use that only to grant your unlock, to answer support questions and to keep the accounting records we are legally required to keep.

Stripe handles your payment data under its own privacy policy, at stripe.com/privacy.

Confirm what Stripe Checkout is configured to collect for these unlocks — email alone, or also a billing address and name. Whatever it actually collects has to match this paragraph. Also confirm how long you keep the Stripe records; UK tax rules generally expect business records to be kept for six years, which is longer than the retention stated below, so accounting data is an exception to it.

COOKIES AND LOCAL STORAGE

This website does not use tracking or advertising cookies. Our apps use your browser's local storage to remember your own data and preferences between visits — for example, whether you muted the sound on this site. That is a technical necessity for the app to work, not tracking, and none of it is sent to us.

SHARING

We share personal data only with the service providers who help us run the studio, and only to the extent each one needs it:

We may also disclose data where we are legally required to. We do not share it with anyone else.

Add your email provider once the mailbox exists. If you later add analytics or crash reporting, it goes in this list too.

WHERE YOUR DATA GOES

Some of our providers operate outside the UK and the European Economic Area. Where personal data is transferred internationally, we rely on the safeguards those providers have in place, such as UK International Data Transfer Agreements or Standard Contractual Clauses.

HOW LONG WE KEEP IT

PLEASE DON'T SEND US SENSITIVE INFORMATION

We have no need for special category data — health, biometrics, political or religious views, and so on — and we ask you not to send it. Please do not put it in a leaderboard name, and do not include it in a support email beyond what is needed to describe your problem.

YOUR RIGHTS

If you are in the UK or the EEA you have the right to access a copy of your personal data, to have it corrected or deleted, to restrict or object to how we use it, and to receive it in a portable format. To exercise any of these, email us and we will respond within one month.

If you think we have handled your data badly you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first so we can fix it.

CHILDREN

Our apps are not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, email us and we will delete it.

DATA LICENCES

Fog uses publicly available country data — names, capitals, flags and borders. Where that data or artwork carries a licence requiring attribution, the attribution is given in the app.

Name Fog's actual data sources and their licences here (for example Natural Earth, REST Countries, a flag icon set). Fog's footer links to this section specifically, so it should not stay generic.

CHANGES

If this policy changes we will update the date at the top of this page. Material changes will be noted on the site.

CONTACT

Email hello@tbcstud.io for anything in this policy, including data requests.

hello@tbcstud.io is not receiving mail yet. A privacy policy has to give a contact route that actually works — set up the mailbox before this page goes live, or substitute an address that does work.
© 2026 TBC STUDIO TBCSTUD.IO · TERMS OF USE