1. The local-play boundary
A local match does not require an aiOrion community account. Game rules, legal-move validation, local opponents and supported on-device AI features run on the Apple device. Local settings, templates, progress and saved games may be stored on the device and, when the player enables the relevant Apple service, in the player's private iCloud container.
aiOrion does not use local conversations or local game content for advertising. The apps do not contain third-party advertising SDKs.
2. When GCServer is used
Server-backed features need server records. Depending on the feature the service may process:
- account identifiers, chosen username and authentication state;
- Game Coin balance, holds, purchases, rewards and transaction audit records;
- Arena and tournament entries, validated results and per-game ratings;
- device and push-notification tokens when notifications are enabled;
- diagnostic, security and abuse-prevention information such as IP address, user agent, request identifier and security events;
- consent-gated product analytics needed to understand reliability and feature use.
This information is used to deliver the requested service, protect balances and competition integrity, prevent abuse, investigate faults and meet applicable accounting or legal obligations. The client cannot mint or alter server-confirmed Game Coins by itself.
3. The public community page
The website requests a read-only public feed from GCServer. It exposes aggregate counts and open public tournament facts. It does not expose player names, internal user IDs, balances, IP addresses, invitation lists or private events. Only these aggregate figures and open events are shown.
4. This website
The company site does not set advertising cookies, embed ad networks or install a third-party analytics tag. Normal web and API infrastructure can process standard connection data, including IP address and browser user agent, for delivery, rate limiting and security logs. Clicking an App Store link moves the visitor to Apple, whose own privacy terms apply.
5. Apple services
The apps can use Apple services such as the App Store and StoreKit, Game Center, iCloud, Sign in with Apple, push notifications and platform speech or on-device model capabilities. Apple processes information under its own terms. aiOrion receives only the identifiers, receipts, match context or service responses needed for the chosen feature.
6. Retention and deletion
Operational data is retained for as long as the account or service requires it. Some transaction, security and audit records may need a longer retention period to protect ledger integrity, investigate abuse or meet legal obligations. A deletion request removes or anonymizes eligible account data while preserving records that must remain for those purposes.
7. Choices and rights
Players can avoid community processing by using local play only, disable optional analytics and notifications in the available controls, and use Apple's own controls for iCloud and Game Center. Depending on applicable law, a person may request access, correction, deletion, restriction, objection or portability by contacting privacy@aiorion.it. Identity may need to be verified before acting on an account request.
8. Security and changes
GCServer uses authenticated requests for private operations, encrypted transport in production, server-side transaction validation, rate limiting and audit logging. No system is risk-free; suspected security issues should be reported to security@aiorion.it.
This notice will be updated when a material feature or data flow changes. The effective date at the top identifies the current version.