Skip to content
TrinfunityBack to trinfunity.com

Trinfunity Privacy Notice

Effective date: 28 August 2026

Contact:privacy@trinfunity.com

1. The short version

Trinfunity is made so people can play and study without handing over a real name, email address, or phone number. Playing alone does not require an account. If you play online, we create a random guest ID and let you choose a table name (a nickname). Please do not use your real name as your table name.

You can also choose to connect mutually with trusted players, see whether they are available to invite, send game invitations, and use a small set of predefined reactions. Trinfunity does not search your phone contacts or provide a public player directory.

We use the smallest amount of information needed to make online games, trusted player connections, optional notifications, purchases, and ads work. We do not use your Bible reading, Scripture references, gameplay, or table name to choose ads.

2. Who this notice is for

Trinfunity is a Bible-based gaming app published by Matthew Chad Schenk. This notice explains how the Trinfunity mobile app handles information. In this notice, “we”, “us”, and “Trinfunity” mean the people who operate the app. Third-party services have their own privacy notices and may process information under their own terms.

3. Information we use to make the app work

Playing alone

You can play offline without creating an account or giving us contact details. Your local game progress stays on your device unless you choose an online feature that needs a guest account.

Online play

Online games need a few pieces of information so the right people can join the right table:

  • a random guest ID;
  • your chosen table name/nickname;
  • room membership, moves, scores, and game state; and
  • player-written content that a game needs to work, such as a Hidden Word clue.

We use this information to run the game, reconnect a player to a room, and protect the service. It is not a profile of your faith or Bible study.

Please use a nickname rather than a real name, and do not put private or sensitive information into a table name, clue, chat-style message, or other player-created content.

Trusted players, invitations, presence, and reactions

You can choose to connect with another player by accepting a mutual request. Trinfunity stores the two random guest IDs that form that connection. Trusted players can see a coarse availability state, such as whether you are available to invite; Trinfunity does not publish a precise last-seen history. It keeps one current availability marker for you, replaces it each time you refresh it, treats it as expired after 2 minutes, and deletes it in the daily cleanup. There is no stored trail of when you were online. Trusted players can send game invitations and use only Trinfunity's predefined reactions in a game.

There is no public player search, phone-address-book upload, free-form direct message, text chat, voice chat, photo sharing, or user-authored link sharing. For an optional QR invitation, Trinfunity only displays a short-lived HTTPS invitation link. Scanning is performed by the recipient's system Camera, Code Scanner, or equivalent—not by Trinfunity—so Trinfunity does not request camera or photo-library access or receive camera frames. Share Link, Copy Link, and a manual code provide the same invitation path without scanning. You can remove or block a player. Blocking removes the trusted-player connection, prevents new requests and invitations between those accounts, and is not disclosed to the blocked player.

Invitation codes and invitation links

To connect with somebody you are with, you can show a short invitation code, or share a link that carries the same code. The code lasts 15 minutes, can be used once, and you can replace or cancel it at any time. Trinfunity does not keep the code itself. It stores only a one way scrambled form of it, so the code cannot be read back out of the database, and the daily cleanup deletes that record once the code has expired.

In a link, the code sits in the part of a web address that a device keeps to itself and does not send to a web server. Opening an invitation link, or typing a code, never connects anybody automatically. It asks the person whose code it is, and they still have to accept.

Trinfunity keeps a short private record of failed code entries, and of how many requests and invitations an account has recently sent. It exists only to limit how many attempts an account can make, holds no code, no name, and no message, and is deleted within 24 hours.

Optional correspondence notifications

If you opt in, Trinfunity can send a notification for a trusted-player request, game invitation, or turn that needs your attention. Lock-screen text is kept generic and does not include private game content. This uses Firebase Cloud Messaging, provided by Google. Firebase processes a device/installation identifier and a notification token so the notification reaches your chosen device. Notifications are optional and can be switched off by type in the app or entirely in your device settings.

Purchases and Trinfunity+

Subscriptions and purchases are made through Apple’s App Store or Google Play. Those stores handle payment details; Trinfunity and RevenueCat do not receive your card or bank-account number. We receive purchase and entitlement status (for example, whether Trinfunity+ or a complimentary no-ads entitlement is active) so we can unlock the right features.

We use RevenueCat to help manage that entitlement. It receives the app’s random guest ID when billing is enabled, so it can associate the entitlement with that guest account.

4. Advertising

Free users may see a post-game ad from Google Mobile Ads (AdMob). We ask AdMob for contextual, non-personalized ads. That means Trinfunity does not give Google your Scripture references, game history, table name, player-written content, or religious activity to target an ad.

Contextual does not mean that no data is processed. Google Mobile Ads may use device and app identifiers, IP-derived broad region (such as city or region), ad impressions and interactions, and diagnostic/performance information to serve, limit, measure, and improve ads and its SDK. Google explains its own practices in its Mobile Ads privacy documentation.

We do not request Apple’s permission to track you across other companies’ apps or websites, do not enable ad-network mediation or attribution in this release, and do not enable Google’s publisher first-party identifier. These limits are reviewed for each release; if they change, this notice and the App Store privacy label will change first.

Where required, Google’s User Messaging Platform presents consent and privacy choices before an ad request. Trinfunity checks whether an ad request is allowed before loading one. When Google requires an ongoing privacy-options entry point, the app makes it available so you can review or change your choice. Refusing or withdrawing consent does not prevent you from playing; an ad may instead be limited or not served.

Paid and complimentary no-ads users do not load an ad or start the ad-consent flow while their entitlement is active.

5. Who processes information

We use these service providers to operate the app:

ServiceWhat it helps with
SupabaseAnonymous guest accounts, trusted-player connections, invitations, coarse presence, predefined reactions, and online game rooms/state
Google Firebase Cloud MessagingOptional correspondence notifications
Apple App Store / Google PlayStore purchases and payment processing
RevenueCatSubscription and entitlement status
Google Mobile Ads (AdMob)Contextual ads for free users, plus ad-related diagnostics and measurement
ShorebirdDelivering narrowly scoped app updates; its service may use an anonymous per-app client identifier

We do not sell gameplay, Bible-study, or contact information ourselves. We do not knowingly send those details to AdMob for advertising. A provider may still process the technical information described above to provide its own service.

6. What we do not ask for

Trinfunity does not ask you for your real name, email address, phone number, home address, device address book, camera, photo library, photos, microphone recordings, payment-card number, precise GPS location, or health information in order to play. It does store the private in-app trusted-player connections you choose to make.

If you voluntarily place personal or sensitive information into player-created content, that content can be visible to the people in that game. Please do not do that.

7. Security and international processing

We use reasonable technical and organisational measures to protect the service. No online service can promise perfect security. Information may be processed in countries where Trinfunity or its service providers operate, which can be outside your country.

8. Retention

The following periods are enforced by Trinfunity's daily server cleanup job:

InformationEnforced period
An online lobby with no activityClosed after 24 hours. Its room, table names, actions, and player-created content are deleted 7 days after closing.
An online game that is still being playedKept while it is active. A generic correspondence game with no activity for 14 days is closed, then its room data is deleted 7 days later. Hidden Word is a live table and is closed after 24 hours without activity, then deleted 7 days later.
Finished or otherwise closed room data, including table names, moves, scores, and player-created cluesDeleted 7 days after the room finishes or closes.
Pending trusted-player request or unaccepted game invitationExpires and is deleted after 7 days. Blocking either account deletes pending requests and prevents new ones.
Invitation codeExpires 15 minutes after it is created and can be used once. It can be replaced or cancelled at any time, which deletes it. Only a one way scrambled form of the code is stored, and the daily cleanup deletes the record once it has expired.
Record of failed code entries and recent request/invitation attemptsDeleted within 24 hours. Used only to limit how many attempts an account can make. It holds no code, name, or message.
Accepted trusted-player connectionKept until either player removes or blocks the other, or either guest account is deleted.
Coarse availability/presence stateUsed only to show current availability. Stored as one current marker that each refresh replaces, treated as expired after 2 minutes, deleted by the daily cleanup, and never kept as a last-seen history.
Predefined reactionTreated as part of its game room and deleted with that room under the periods above.
Firebase notification registration/tokenDeleted 30 days after its last registration or update, or immediately when its guest account is deleted. Invalid Firebase tokens are also deleted when Firebase reports them.
Current billing entitlement projectionKept only while current. An inactive or expired projection is deleted 30 days after its last update, or immediately when its guest account is deleted.
RevenueCat webhook idempotency recordKept 30 days after receipt. It contains the event ID/type/environment, not the webhook body.
Anonymous Supabase guest identity with no active roomDeleted after 30 days without sign-in.
Cleanup totalsKept 30 days as counts only. They do not contain guest IDs, table names, clues, Scripture, or notification tokens.

Trinfunity does not create or operate its own database backups or application logs containing gameplay content. Provider-operated infrastructure backups and logs are controlled by the provider, not by Trinfunity; we do not use them as a second player-history store.

9. Deleting a guest account

Open Settings → Privacy and account → Delete guest account. The app first explains what will happen and then asks a second time before deletion. After you confirm, Trinfunity deletes your anonymous Supabase guest identity and removes or irreversibly disconnects your Trinfunity-linked table names, trusted player connections, pending requests and invitations, unused invitation codes, attempt records, presence state, online history, player-created clues, notification registrations, and entitlement projection. It also signs the device out so old Trinfunity sessions cannot keep using that account.

We never delete data from under people in an active online game. If you are in one, finish or leave it and try again. A deletion request that reaches the server safely blocks new online activity while a transient server failure is retried.

Deleting a Trinfunity guest account does not cancel an Apple App Store or Google Play subscription. Cancel subscriptions in your Apple ID or Google Play account settings. Store billing and purchase restoration are separate from the Trinfunity guest account.

10. Children

Trinfunity is designed to be family-friendly, but this release is a general-audience app primarily presented to people aged 16 and older. It is not submitted as a children’s app or an Apple Kids Category app. We do not knowingly ask children for a real name, email address, phone number, or other contact details. If you are legally too young to consent to data processing where you live, ask a parent or guardian before using online play, notifications, purchases, or advertising-supported features.

11. Changes to this notice

If the app’s data practices change, we will update this notice and the relevant store privacy disclosures before the changed release is made available. The effective date at the top tells you when this notice was last changed.

12. Contact

Questions or privacy requests can be sent to privacy@trinfunity.com.