Privacy Policy

How Midknight Entertainment Ltd handles information in its mobile applications.

Effective date: 11 August 2026 · Last updated: 8 September 2026

Material change: 8 September 2026. Flotsam has gained an optional feature that posts a listing to your own eBay account, and this policy has been corrected to describe it. Three things follow, and the new section 19 sets out all of them: connecting signs you in to eBay, so the claim that none of our apps has a login is no longer true of Flotsam; we keep the eBay token that connection produces, which is the first time we have stored anything that belongs to an account of yours; and posting a listing sends your photographs to eBay to be published in public. The feature is off unless you turn it on, nothing about it applies to any other app, and nothing else in this policy has weakened.

Material change: 4 September 2026. A fourth app, Duskroot, now shows advertisements, and this policy has been corrected to say so. Its advertisements are only ones you choose to watch in exchange for something in the game; it shows none you did not ask for, and it includes no analytics software, so section 17 now describes two different arrangements rather than one. This page also now names RevenueCat, the provider that tells our apps whether a subscription is active, where it previously described it without naming it. No other app has changed, and nothing else in this policy has weakened.

Material change: 19 August 2026. Three corrections. First, this policy previously described a single third-party AI provider; it now names both of the providers that actually generate a response. Which one serves which app and tier is set out in section 4 and section 11. Second, this policy did not previously mention Foretold's duel feature at all; section 18 now covers what a duel sends us, how long we keep it, and what has no expiry. Third, section 4 previously said we do not remove the location and other hidden information a photograph can carry; that was accurate when written and is not anymore. Every photograph is now stripped of that hidden information before it leaves your device, and this page has been corrected to say so. No other app has changed, and nothing else in this policy has weakened.

This policy applies to the mobile applications published by Midknight Entertainment Ltd that link to it from inside the app (“we”, “us”, “our”). It describes what our apps collect, what they deliberately do not collect, why, and what you can ask us to do about it.

It is written to be true of every app it covers. Where a particular app does something only some of those apps do, for example sending a photograph to an AI feature, the relevant section says so.

1. Who we are, and the law that applies

Midknight Entertainment Ltd is a company incorporated in the Province of Nova Scotia, Canada.

The law that governs how we handle personal information is Canada's federal Personal Information Protection and Electronic Documents Act (PIPEDA), which applies to personal information that a private-sector organization collects, uses or discloses in the course of commercial activities. Nova Scotia has no private-sector privacy statute of general application, so PIPEDA is the law that applies to us.

PIPEDA works through ten fair information principles, and the first of them is accountability: we are responsible for the personal information under our control, including information we hand to someone else to process for us, and one person in the company is designated as accountable for our compliance: our Privacy Officer. You can reach them by emailing support@midknightltd.com, or by post at the address in section 20.

For anything to do with this policy, your information, or your rights, use the same address.

2. The short version

This summary is not the whole policy. The sections below are.

3. What we collect, and why

WhatWhyWhere it goes
An anonymous device identifier. A random identifier created on your device the first time you open the app and stored there. So we can apply free-usage limits and prevent abuse without asking you to create an account. Sent to our server with each request to an AI feature. Our server stores only a one-way, salted hash of it: never the identifier itself.
Content you submit to an AI feature. Text you type, and in some apps a photograph you choose to take or select, plus limited context such as which feature you were using. To generate the response you asked for. Our server, then a third-party AI provider. Not stored by us. See section 4.
Server log entries. Date and time, which app, which feature, which AI model was used, the salted hash of the anonymous identifier, the number of tokens sent and received, how long the request took, whether it succeeded or failed, and whether an active subscription was found. To keep the service running, find faults, detect abuse and manage cost. Our hosting provider's logging service. Logs deliberately exclude the content of requests and responses.
Content you report. The reason you selected, the text you are reporting, limited technical context, and the salted hash of the anonymous device identifier. So we can review the report, act on it, and spot repeated problems. The app stores require apps that show AI-generated content to offer reporting. Stored on our server. This is the one thing our server keeps deliberately. See section 6.
Purchase and subscription state. Whether a subscription is active, linked to an anonymous identifier created by our subscription-management provider. To unlock paid features and let you restore a purchase on your devices. Apple or Google (who take the payment) and our subscription-management provider. We never see or hold card or payment details. See section 7.
Your eBay connection, in Flotsam only, and only if you connect it. The token eBay gives us to post on your behalf, the date that token stops working, eBay's own identifier for your account, and the date you connected. So Flotsam can post a listing to your eBay account without asking you to sign in again every time, and so we can delete your record if you ever close your eBay account. Our server, stored against the salted hash of the anonymous device identifier. We do not store your eBay password, your eBay email address, your listings or your prices. See section 19.
A listing you choose to post, in Flotsam only. The title, description, price, condition, category and item details, together with the photographs. To create the listing on eBay that you asked for. Straight to eBay through our server, which does not keep a copy. eBay publishes it. Photographs have their hidden location data removed before they leave your phone. See section 19.
Information kept on your device. History, saved items, settings, and the anonymous identifier. So the app works and remembers what you did. Stays on your device. See section 8.

More about the anonymous identifier

It is a randomly generated value, created on your device when you first open the app and stored in the app's own storage. It contains no hardware identifier, no advertising identifier, no serial number, and nothing derived from you, your device or your accounts. We cannot use it to work out who you are, and it is not shared with anyone for advertising.

If you delete the app, the identifier goes with it. Reinstalling creates a brand new one, and anything recorded against the old one can no longer be connected to you or to your new install.

4. AI features in detail

Some of our apps generate a response using a large language model. Here is exactly what happens.

  1. The app sends what you entered (text, and in some apps a photograph you chose) to our own server, over an encrypted connection, together with the anonymous device identifier and, in apps with purchases, the anonymous subscription identifier (section 7).
  2. Our server checks the usage limit, then passes your content to an AI provider, which generates the response. Two providers are behind these features: Cloudflare Workers AI serves The Hard Part's free tier; Anthropic serves everything else: The Hard Part's Pro tier, and the Pro features in Groat and Flotsam.
  3. The response is passed back to your app.

We do not store your content, with one exception: a response you choose to report, which we keep for 90 days (section 6). It is held in memory only for as long as it takes to produce your response, and is not written to any database or file by us. Our logs record that a request happened, not what was in it.

Each AI provider is a separate organization and handles your content under its own terms. Providers of this kind commonly retain content for a short period so they can monitor for misuse and meet their legal obligations. We cannot promise you that either provider keeps nothing, because that depends on the contract in force and on the provider's own practices, which can change. What we can tell you is this: we do not use your content to train any model, and we do not sell it or pass it to anyone else. What a provider may do with it is governed by the terms we hold with them. Please treat anything you type into an AI feature as leaving your device.

Because that content leaves your device and goes to another organization, we treat your decision to submit it as the point at which you give us your consent to do so. If you do not want something to leave your device, do not put it into an AI feature.

Please do not enter other people's information

Do not type in, or photograph, information that identifies someone else: names, contact details, health or employment details, or anything confidential. Do not enter sensitive information about yourself that you would not want to leave your device. A photograph carries whatever is in it: faces, documents on a desk, and screens. It can also carry hidden information in the image file itself, such as where and when it was taken. We remove that hidden information, including location, from every photograph before it leaves your device. We cannot remove what is visible within the photograph itself, so point your camera at what you mean to submit and nothing else.

5. Voice input

Where an app offers speech input, speech recognition is performed by your device, using the recognition built into its operating system. Audio is not sent to us, and we do not record or store audio. Only the text produced by the recognition is used, and it is then treated exactly like text you typed.

Your device's own speech recognition is provided by Apple or Google. Depending on your device, your settings and the language you use, that recognition may happen entirely on the device or may involve their servers, under their privacy policies, not ours.

The microphone permission is requested only when you choose to use a voice feature, and you can withdraw it at any time in your device settings.

6. Content you report to us

Apps that show AI-generated content include a way to report a response you think is offensive, harmful or wrong. If you use it, we store the reason you selected, the text you are reporting, limited technical context, and the salted hash of the anonymous identifier. None of that identifies you by name.

We store this deliberately, because we cannot review or act on a report we have not kept. The purposes are the ones identified in section 10: reviewing and acting on the report, spotting repeated problems, improving the safeguards around our AI features, meeting the app stores' requirements for apps that show AI-generated content, and restricting use by someone who is deliberately misusing our AI features. You give us your consent to those purposes by choosing to send the report; if you do not send one, nothing is stored. Reports are used for those purposes and nothing else.

Reports are deleted automatically 90 days after they are stored. See section 12.

Please do not include personal information in a report.

7. Purchases and subscriptions

All purchases and subscriptions are sold and processed by Apple (App Store) or Google (Google Play), depending on where you downloaded the app. They are the merchant.

8. Information kept on your device

Most of what our apps hold never leaves your device: your history, your saved items, your settings and preferences, and the anonymous identifier. It is stored in the app's own private storage.

You can clear it from within the app where the app offers that, and deleting the app removes all of it. Note that we cannot delete it for you remotely, because we have no way to reach it.

Where an app offers reminders, most of those reminders are scheduled by your device, and for those we collect nothing.

Two apps are different: Cadge and Quarterday. They send push notifications through OneSignal, which means OneSignal holds a push token for your device, along with your device type and operating system version. Both apps also send OneSignal a small set of labels so a message can be aimed at the right group of people. Cadge sends your pet's bond level, its dominant trait, whether you subscribe, and the platform. Quarterday sends your home type, your heating type, your winter profile, whether you subscribe, and the platform. Every one of those is a fixed category worked out from what the app already knows. None of it is text you typed, and your pet's name is deliberately excluded. You can turn notifications off in your device settings at any time, and no app of ours sends marketing messages by email or text.

9. What we do not collect or do

Stated plainly, because it is easier to check a specific claim than a vague one. One qualification applies to this whole list: in The Hard Part and Flotsam advertising and analytics work as section 17 describes, and in Cadge and Duskroot advertising does. Where that section says otherwise, it governs. In every other app, every statement below holds without exception:

About IP addresses. Our own application code does not read or record your IP address. However, an IP address is a necessary part of any internet connection, so our hosting provider processes it in order to route your request and to protect the service from attack. It does this as a service provider acting for us, under its own security arrangements, and we do not use it to identify or track you.

PIPEDA does not offer a menu of legal bases to choose between. It requires two things together: that we identify the purposes we are collecting personal information for, at or before the time we collect it, and that we have your meaningful consent for those purposes, meaning consent given by someone who can reasonably be expected to understand what is being collected, why, and what follows from it.

Consent can be express or implied. PIPEDA expects express consent where information is sensitive, where the handling would fall outside what you would reasonably expect, or where it creates a meaningful risk of significant harm. Here is every purpose we have, and how consent works for each.

PurposeHow it is identified, and how you consent
Running the app itself, and unlocking paid features you have bought. Implied consent. Identified in this policy and inherent in choosing to install and use the app. Nothing here leaves your device except the check on whether a subscription is active.
Sending what you enter to our server and on to a third-party AI provider, so a response can be generated. Express consent. Your content leaves your device and goes to another organization, which is exactly the kind of handling PIPEDA expects to be consented to explicitly. You give that consent by choosing to submit content to an AI feature, having been told here and in the app what happens to it. Not using the feature withholds it.
Applying free-usage limits, rate limiting, keeping the service secure, and detecting and investigating abuse. Implied consent, identified here. This is part of operating the service you are choosing to use. We limit ourselves to an anonymous identifier and a salted hash of it, which is the least that will achieve the purpose.
Reviewing and acting on content you report, spotting repeated problems, improving the safeguards around our AI features, meeting the app stores' requirements for apps that show AI-generated content, and restricting use by someone deliberately misusing our AI features. Express consent. You give it by choosing to send a report. See section 6.
Using your camera, microphone or photo library, and scheduling reminders on your device. Express consent, given through your device's own permission prompt and withdrawable at any time in your device settings.
Meeting a legal requirement, or responding to a lawful demand from a court, regulator or law enforcement agency. PIPEDA permits use or disclosure without consent in a small number of defined situations, including where the law requires it. We rely on that only where we have to, and only to the extent we have to.

Withdrawing consent

You can withdraw your consent at any time, subject to legal and contractual restrictions and on reasonable notice. In practice, because we hold no account for you, withdrawal is immediate and in your hands: turn off a device permission in your settings, stop using a feature, or delete the app. The consequence of withdrawing is simply that the feature concerned stops working. There is no other effect, and nothing done before you withdrew is undone by it.

Where the ten principles are addressed

PIPEDA's fair information principles are set out in Schedule 1 of the Act. For anyone checking this policy against them:

Much of what we handle is unlikely to identify you at all. We still treat the anonymous identifier carefully, as though it were personal information, because that is the safer assumption.

11. Who else is involved

We use a small number of other organizations to run our apps. We share only what each one needs:

Handing personal information to one of these organizations to process for us is a transfer for processing, not a disclosure to a new owner of it. Under PIPEDA's accountability principle the information stays our responsibility while they hold it, and we are answerable for what happens to it.

We do not sell personal information, and we do not share it for advertising or marketing by anyone.

We will tell you which providers we currently use if you ask by email.

12. How long we keep things

WhatHow long
Content you submit to an AI featureNot stored by us. It exists in memory only for the seconds it takes to produce your response.
Server log entries (no content)At most 7 days, retained on our infrastructure provider's logging platform, then deleted automatically.
Content you report90 days from the day you send it, then deleted automatically, long enough to review it, act on it, and identify repeated problems.
Free-usage counters against the hashed identifier13 months after the end of the month they relate to, then deleted automatically.
Subscription state held by our subscription-management providerFor as long as the entitlement needs to be restorable, then in line with that provider's own retention policy.
Cached subscription status on our server (a yes/no flag against a salted hash of the subscription identifier)Up to 24 hours, then expires automatically.
Your eBay connection (Flotsam only)It carries the same expiry as the eBay token itself, about 18 months, and deletes itself when that passes, so a connection you abandon does not linger. It goes sooner in two cases: Disconnect in the app removes it immediately, and if you close your eBay account, eBay notifies us and we delete it.
Information on your deviceUntil you clear it in the app, or delete the app.

Deleting a report or a usage counter is not something we do by hand when we remember to. It happens on a schedule, without anyone deciding to run it.

13. Sending information outside Canada

Some of the organizations we rely on, in particular the AI provider and our hosting provider, operate internationally. Processing takes place in the United States and in other countries where our service providers operate. eBay is a United States company, so a listing you post through Flotsam goes there, and the paragraph below about the laws of another country applies to it.

PIPEDA does not forbid sending information to other countries. Unlike some other privacy laws, it has no list of approved countries and no standard transfer contract. Its rule is the accountability principle: we stay responsible for your information after we hand it to a provider, wherever that provider processes it, and we must use contracts or other measures to give it a level of protection comparable to the protection it has with us. Sending it somewhere else does not hand off the responsibility for it.

Two practical consequences follow, and you should know both:

You can ask us which providers process information outside Canada, and what we have in place with them, by emailing [email protected].

14. Security, and what we do if there is a breach

No system is completely secure. If a breach of our security safeguards occurs and it is reasonable in the circumstances to believe that it creates a real risk of significant harm to someone, PIPEDA requires us to report it to the Office of the Privacy Commissioner of Canada and to notify the people affected, as soon as feasible. Because we hold no contact details for you, notifying you would normally be indirect, a prominent notice in the affected app and at the top of this page, which PIPEDA's breach regulations permit where an organization does not have contact information for the people affected. PIPEDA also requires us to notify any other organization or government institution that can reduce the risk of harm resulting from the breach, for example law enforcement. Significant harm includes humiliation, damage to reputation or relationships, financial loss, identity theft and loss of employment or business opportunities, among other things.

We keep a record of every breach of our security safeguards involving personal information under our control, whether or not it met that threshold, for 24 months, and the Commissioner can require us to produce those records.

15. Your rights, and how to challenge us

PIPEDA gives you a specific set of rights. They are narrower than the rights some other countries' privacy laws give, and we would rather say so plainly than imply you have more than you do.

Which regulator, and why it is the federal one

Nova Scotia has no private-sector privacy law of general application. The province's Personal Information International Disclosure Protection Act applies to public bodies and municipalities; its Freedom of Information and Protection of Privacy Act applies to public bodies; and its Personal Health Information Act applies to health information custodians. None of them covers a private company's ordinary commercial activities. So the Office of the Information and Privacy Commissioner for Nova Scotia has no jurisdiction over a complaint about us, and the right place to take one is the federal Privacy Commissioner named above.

About deletion, portability and objection

PIPEDA does not give you a general right to have your information erased, a right to receive it in a portable machine-readable format, a right to restrict how it is handled, or a right to object to handling you have consented to. Some other countries' laws create those rights. Canada's does not, and we are not going to describe rights you do not have.

What we will do, as a matter of our own policy and not because the law compels it: if you ask us to delete something we hold that relates to you, and we can find it, we will delete it, unless we are required to keep it or it is needed for a live investigation into abuse. That includes deleting a particular report you sent us, if you can tell us enough for us to identify it. Treat that as a promise we are making here rather than a statutory entitlement, and note that it cannot extend to anything we are unable to locate.

One technical exception: individual server log entries cannot be selectively deleted, but they delete themselves automatically within 7 days.

How to exercise them

Email [email protected]. Tell us which app you are asking about. If you are asking about a specific record, tell us anything that would help us find it.

One honest limitation

Because our apps have no accounts, we hold almost nothing that can be connected to a named person. To find any record relating to your device, we would need the anonymous identifier that your app holds (you can see and copy it in the app's Settings), and if you have already deleted the app, that identifier no longer exists and the remaining records cannot be linked to you by us or by anyone else.

Where we genuinely cannot tell which records are yours, we may not be able to act on an access, correction or deletion request. If that happens we will tell you clearly, explain why, and help where we can, for example by deleting a specific report if you can tell us enough to identify it.

16. Children

Our apps are not directed at children. They are rated for teenagers and above, and are intended for people aged 13 or over. We do not knowingly collect personal information from children under 13.

The Office of the Privacy Commissioner of Canada takes the position that, other than in exceptional cases, a child under 13 cannot give meaningful consent, and that consent has to come from a parent or guardian instead. Our apps are not built to obtain parental consent, which is another reason they are not for younger children.

If you believe a child has provided personal information through one of our apps, email [email protected] and we will take steps to delete it.

17. Advertising and analytics in three of our apps

Four of our apps show advertisements. The Hard Part, Flotsam and Cadge show them in their free tier and also count how the app is used. Duskroot shows only advertisements you choose to watch, and counts nothing. No other app of ours does either. This section says exactly how it works, in the same spirit as the rest of this policy.

18. Foretold's duel feature

Foretold has no AI feature, so this policy's AI sections do not reach it. Its predictions feature also does not. A prediction you keep to yourself is never sent anywhere; there is no network call in that part of the app at all. What follows is about the part that is different: duels, where you make a claim against another player.

19. Flotsam's eBay connection

Flotsam writes a marketplace listing from a photograph of something you want to sell. For most of its life it stopped there: it gave you the text and you pasted it into eBay yourself, and nothing left your phone except the photograph the AI feature needed. Posting straight to eBay is new, it is optional, and it is off until you switch it on. If you never connect it, nothing in this section happens to you and the rest of this policy describes the app completely.

Connecting

Connect opens eBay's own sign-in page, not a page of ours. You sign in to your own eBay account there and eBay asks whether you want to let Flotsam list on your behalf. We never see your eBay password, and we never receive your eBay email address. If you say yes, eBay hands us a token, which is a key that lets us post for you and does nothing else.

What we hold, and what we do not

We store four things, against the same salted hash of the anonymous device identifier described in section 3: the token, the date the token stops working, eBay's own identifier for your account, and the date you connected. That is the complete list.

We do not store your listings, your prices, what sold, what did not, your feedback, your buyers, or anything else eBay's systems know about you. The token is kept for one reason: so that connecting is something you do once rather than every time you post.

Posting a listing

When you tap Post, the listing goes to eBay through our server, which passes it on and keeps no copy. That means the title, the description, the price, the condition, the category and the item details, together with the photographs.

The photographs are stripped of their hidden location data before they leave your phone. A camera photograph of something in your front room usually carries the coordinates of your house inside it, and a public listing carrying those would hand your address to everyone who looked. Flotsam removes that information, and resizes the image, before it is uploaded. This is the same protection described in section 3, applied here deliberately rather than by accident.

Everything you post becomes public, because that is what a listing is. Once it is on eBay it is on eBay's terms and under eBay's privacy policy, it is visible to anyone, and we cannot take it down for you. Use eBay to end a listing, the same way you would end one you wrote yourself.

Disconnecting, and deletion

There are three ways the connection ends, and all three delete what we hold:

Disconnecting stops future posts. It does not remove listings you have already published, which belong to your eBay account and are yours to manage there.

One thing this feature does not change

None of this touches any other app. No other app of ours connects to a marketplace, holds a token for an account of yours, or uploads anything to be published in public. Where this section and an earlier one appear to disagree, this section governs, and only for Flotsam.

20. Changes to this policy

If we change this policy we will update the “last updated” date at the top of this page and publish the new version here.

If a change materially affects what we collect or what we do with it, we will highlight it at the top of this page for a reasonable period, update the privacy declarations we give to the App Store and Google Play, and, where we reasonably can, note it in the release notes of the next app update. Where a change would extend what we do to a new purpose, we will seek your consent for that purpose rather than assume it. Please check this page from time to time.

21. Contact

Midknight Entertainment Ltd
Attn: Privacy Officer
114 Woodlawn Rd Suite 1005
Dartmouth, Nova Scotia
B2W 2S7
Canada

Email: support@midknightltd.com

If you contact us about your information, please tell us which app you are asking about, so we can find the right records.