Wanderlings is a step-tracking pet game. I try to collect as little as possible. This document explains what is collected, why, and who, if anyone, sees it. The in-app Settings → App → Data Privacy screen summarizes the same information in plainer language.
Everything you do in camp (your Wanderling, your bag, the village you build, your settings, any notes) is stored locally on your device. Nothing about your gameplay is sent to a server I operate unless you opt into a social feature (see "Optional social features" below).
If you delete the app, this local data is deleted with it (except where a backup you've enabled has mirrored it; see "Backup" below). Data you previously chose to sync through a social feature remains on the server until you request deletion.
If you turn on iCloud Backup on iPhone, a copy of your save is mirrored to your private iCloud via Apple's iCloud Key-Value Store. Only you can read it, since the store is scoped to your Apple ID. I do not have access to this data. Apple's privacy terms apply.
On Android, your save is included in the system's Auto Backup by default, which Google ships to your private Google Drive. Only you can read it. Google's privacy terms apply.
You can also export a manual backup file from Settings → Backup. Where that file goes is up to you.
Wanderlings offers two independent, optional social features. Enabling either one creates an anonymous social profile on my server, hosted by Supabase. You can use either feature without enabling the other.
The Hall is an opt-in leaderboard for Wanderling age and moonpetals collected. If you join, the following data is sent to my server:
Nickname, species, adoption date, moonpetal score, selected appearance, and Town Hall completion may be shown publicly in Hall rankings. The last-seen timestamp is used to determine whether a Wanderling is still active and is not displayed publicly.
Friend Visits let you share a randomly generated eight-character friend code. If you enable Friend Visits, the following data about your current Wanderling is sent to my server:
Another player must know and enter your friend code before your Wanderling can appear in their Camp. The server stores that Camp connection between your anonymous social profiles. Friend codes and Camp connections belong to the persistent social profile, so they can continue when either player adopts a new Wanderling.
Turning Friend Visits off makes your Wanderling unavailable in other Camps and hides your own visitors until you turn the feature on again. The underlying Camp connections are retained so they can return when the feature is re-enabled. You can remove an individual visitor from your Camp at any time.
I do not send your name, email, location, step count, HealthKit / Health Connect data, or contacts to either social feature. There is no email, password, or named player profile.
Each install gets an anonymous account managed by Supabase. It is a random identifier that lets the server tell one player from another; it is not linked to you personally. The account lives for the lifetime of this install. Uninstalling the app loses the account.
To support reinstalling and restoring across devices, your save file also includes a private recovery key for your Wanderling. The server stores only a one-way hash of this key. When your save restores (via iCloud, Auto Backup, or a manual backup file), the app uses the key to reclaim your social profile, friend code, Camp connections, and Hall record under the new anonymous account.
A Wanderling is removed from the Hall in any of these cases:
Once removed from active competition, that specific Wanderling cannot rejoin, but a new one you adopt can. Historical all-time leaderboard results may remain visible after a Wanderling leaves active competition. Leaving the Hall does not disable Friend Visits.
You can request deletion of any data tied to your Wanderling at any time by contacting me (see "Contact" below).
Your step count is read from Apple Health on iPhone or Health Connect on Android, with your permission, and stays on your device. It is used to feed your pet and advance gameplay. I do not transmit step or other health data to my server or any third party.
You can revoke health permission at any time:
I use TelemetryDeck to understand how the app is used in aggregate (e.g. how many people complete onboarding, how often pets are fed). TelemetryDeck is designed to be privacy-respecting: events are hashed and aggregated server-side. I do not send your name, email, contacts, location, health data, or device advertising identifiers.
A typical event records: the event name, the app version, the OS version, and an anonymous installation identifier described below.
TelemetryDeck's own privacy information: https://telemetrydeck.com/privacy/.
The app uses random identifiers instead of a named account:
These identifiers are not linked to your name, email, Apple ID, Google account, phone number, advertising identifier, or any hardware identifier. I do not engage in tracking as defined by Apple's App Tracking Transparency framework, so you will not see an ATT prompt.
The app is not directed at children under 13 (or the equivalent age in your jurisdiction) and I do not knowingly collect data from children. If you believe a child has provided data through the app, contact me and I will delete it.
To request deletion of data tied to your Wanderling on my server (Hall entries, friend code, Camp connections, or anonymous account records), contact me at the address below with your friend code, if you know it. Otherwise include the date you adopted your current Wanderling and its nickname. I do not have a way to identify you by name or email, so this is the information I need to find the right rows.
I may update this policy as the app evolves. Material changes will be noted in the app or in release notes.
Questions about this policy or data deletion requests: [email protected]