Privacy Policy

Version 1.1.5. Last updated October 7, 2026.

Commander Crush is operated by Cargo Shorts Studios LLC, a Minnesota limited liability company ("we," "us"). This policy explains what we collect, why, and what you can do about it.

What this covers. This policy applies to the Commander Crush mobile app. It does not cover third-party sites the app links out to, such as card databases or online stores. Each of those has its own privacy policy. See "Links to other sites, and affiliate links" below.

The short version

  • There are no accounts, and browsing and swiping never ask who you are.
  • The only place the app itself asks for contact information is the feedback form, and only if you choose to use it. If you email us, we receive your email address and whatever you include.
  • We collect how you use the app: your crushes, passes, searches, and stats, to improve it and build better recommendations. Some of that stays on your device; some may be stored on our servers. Usage data we receive is deleted within about 90 days of the last activity we receive from your device, except in aggregate or de-identified form that can't be linked back to you.
  • If the app crashes, that report includes the last few things you did.
  • We show ads, but they are not personalized and we do not build an advertising profile about you.
  • You can erase your data at any time from Settings → Delete my data.

Where the app is available

We currently offer Commander Crush in the United States only.

What we collect

We collect information two ways: automatically, as you use the app, and directly from you, which happens only if you choose to send us feedback or contact us. We do not buy information about you, and we do not receive it from data brokers or from any other third party.

How you use the app

We record how the app is used: screens you open, features you use, searches you run, and the decisions you make.

That activity is stored on your device, so the app works without a connection. It may also be stored on our servers, so we can build features that need it, such as better recommendations. Cached card images stay on your device only.

If you import a card collection, it stays on your device, and in your own device backups if you use them, with the rest of your activity. See "Erasing your data" below. We receive only counts, such as how many cards an import found, never the cards themselves.

Our analytics and advertising providers also derive an approximate location, at the level of a city or region, from your IP address. We never collect precise location, and we never ask your device for it.

We also record that an ad was shown and what it earned, alongside your other app activity, so we can tell which features support the app. That record is never used to choose which ads you see.

Crash and performance data

When the app crashes or misbehaves, we receive a report containing technical details about the failure, your device type, and the app version. This helps us fix bugs.

A crash report also includes a short trail of recent app activity leading up to the failure. That trail exists only inside that one report, only for a session that actually crashed, and it expires when the report does. See "Identifiers" below for how crash reports relate to the rest of your app activity.

Feedback you send us

If you send us feedback through the in-app feedback option or the shake-to-report gesture, the form offers an optional field for contact information so we can follow up with you. That field is free-form, so whatever you enter there, such as an email address or a phone number, is what we receive. If you email us instead, at any address we publish, we receive your email address and whatever your message contains.

The app itself never asks who you are anywhere else. None of this happens unless you choose to contact us.

We use it to understand your report, to respond to you, and to track the fix.

Because the message is free-form, please don't include personal details beyond what's needed to describe the problem. We never need financial or payment information to fix a bug.

Identifiers

We don't use accounts, and the app never asks for your name or email address. Instead it relies on several separate device-level identifiers:

  • one that groups your app activity,
  • a different one that groups your crash reports,
  • a device advertising identifier used to serve ads (on iOS this is a limited identifier, not the IDFA; see "Advertising"), and
  • a short-lived token that proves a request came from a genuine, unmodified copy of the app.

We keep these separate on purpose. A crash report includes the recent actions leading up to that one crash, visible only inside that single report, for a session that crashed, and nowhere else. Beyond that one report, we never join your app activity to your crash reports as a dataset. The two never meet anywhere we can query across users, and we do not combine them.

If you send us feedback or email us, the contact information you provide is likewise not connected to any of these identifiers.

What we don't collect

Apart from the contact information you choose to give us, described above, we do not collect your name, email address, or phone number. We never collect your contacts, photos, precise location, or payment information, and we never ask for them.

Device sensors

If "Shake to report" is enabled in Settings, the app reads your device's motion sensor so it can detect a shake and offer to open the feedback form. This happens entirely on your device. No motion or sensor data is ever transmitted or stored. You can turn the feature off in Settings.

Services your device contacts directly

Some of what the app shows you loads straight from services we don't operate. We don't send them information about you. Your device makes a request directly, and they see what any website sees when you visit it: your IP address and basic technical details about your device. What they do with that is governed by their own privacy policies, not this one.

  • Card images load from the card database's image servers as you browse, so we don't have to bundle thousands of images into the app. This means that provider can see which cards your device requests.
  • Card data updates are fetched from our own hosting provider about once a day.
  • App integrity checks use services provided by your device's operating system, to confirm requests come from a genuine copy of the app rather than an automated script.
  • Configuration is fetched so we can turn features on and off without shipping an update.
  • Ads are requested from our ad network.
  • Feedback is submitted through our form provider.

Advertising

The app displays ads through a third-party ad network (see "Service providers" below). Every ad request we make is non-personalized, for every user, in every region. We do not ask for ads targeted to your interests or behavior, and we do not build, sell, or share an advertising profile about you. The recommendation profile described in "How we use information" is separate: it shapes which commanders the app shows you, not which ads you see.

To deliver an ad, the network receives a device advertising identifier, your IP address, and basic technical details about your device. It may use these to limit how often you see the same ad, to prevent fraud, and to produce aggregate reports. Its handling of that data is governed by its own privacy policy.

Because we do not request personalized ads, the app does not show Apple's App Tracking Transparency prompt, and the ad network does not receive your device's IDFA. It uses a more limited identifier instead.

Links to other sites, and affiliate links

The app links out to card databases and online stores. When you follow one of those links, you leave the app and that site's own privacy policy applies.

Store links carry a referral identifier. It credits either us or the card database we source the link from, and whoever it credits may earn a commission if you buy something after following the link, at no extra cost to you. The store and its affiliate network can associate your visit with that referral. We don't receive your order details, payment information, or identity from them.

How we use information

We use what we collect to:

  • operate and improve the app, including the recommendations it shows you;
  • build a profile of your card preferences from your activity, and use it to personalize what the app recommends to you;
  • build features and improvements based on ideas and reports you send us;
  • diagnose bugs and crashes, and measure performance and reliability;
  • understand which features are used, so we can decide what to build;
  • measure which ads were shown and what they earned alongside app activity, so we can tell which features support the app;
  • respond to feedback and support requests you send us;
  • protect the app against fraud, abuse, and automated misuse; and
  • display ads, as described above.

These are the only purposes we use it for. If that changes, we will update this policy and tell you in the app first. See "Changes to this policy."

Aggregated and de-identified data

We may combine data across many users into aggregate statistics. For example, which commanders are most popular, or how many users like two given commanders at the same time.

We may use aggregate statistics to improve our recommendations, show them in the app, or publish or share them with third parties. We will not attempt to re-identify individuals from them, and anyone who receives them from us, including users of the app under our Terms of Service, agrees not to either.

We may also keep de-identified records of app activity. A de-identified record describes choices made on one device, such as a set of commanders crushed together, but it carries no identifier, no precise time, no location, and no device details, and it is not linked to any identifier the app uses. We also remove or generalize details that could single someone out, such as a commander very few people have chosen. We use de-identified records to understand how commanders relate to one another and to improve our recommendations.

We keep de-identified records in a form that cannot reasonably be linked to you or your device, and we will not attempt to re-identify them. We do not publish them. If we share them with anyone, we will require them by contract not to re-identify them either.

What we don't do

  • We do not sell your personal information. We do not share it for cross-context behavioral advertising, which is what US state privacy laws call sale and sharing. If that changes, we will update this policy and offer the opt-out those laws require before it takes effect.
  • We never sell or license your individual swipe history or crushes. Not to data brokers, not to anyone. The only way that information could change hands is as part of a business transfer, described below, and this policy goes with it.
  • Your activity is private by default. If we add sharing features, sharing will always be something you choose.

Service providers

Providers that process data for us

We use a small number of outside companies to run the app. Most handle data on our behalf, only for the purposes described in this policy, under agreements that govern what they may do with it, and are not permitted to use it for their own purposes. Our advertising provider is the exception: it serves ads under its own terms and privacy policy, as described in "Advertising," rather than solely on our instructions.

The categories are:

  • Analytics and product measurement providers, which receive the app activity described above.
  • Crash and performance reporting providers, which receive crash reports.
  • Advertising providers, which serve the non-personalized ads described above under their own privacy policy.
  • Hosting, storage, and content delivery providers, which host the card data the app downloads.
  • Feedback, support, and issue-tracking providers, which receive what you send through the feedback form.
  • App integrity and security providers, which confirm requests come from a genuine copy of the app.

We may add or change providers within these categories without updating this policy, as long as what is collected and why does not change. If we ever needed a provider outside these categories, or needed to share more than this policy describes, we would update the policy first.

You can ask us who they are. Some states give you the right to a list of the specific companies we've shared personal information with, and we'll give you that list on request whether or not your state requires it. Email us at legal@cargoshortsstudios.com.

Other situations where information may be disclosed

Beyond the providers above, there are two situations worth stating plainly.

Legal requests and safety. We may disclose information where we are required to by law, for example in response to a subpoena, court order, or other valid legal process, or where we believe in good faith that disclosure is necessary to comply with a legal obligation, to investigate fraud or abuse, or to protect the rights, property, or safety of our users, the public, or us. Where we are permitted to tell you about such a request, we will.

Business transfers. Information covered by this policy may be disclosed in connection with an actual or prospective business transaction, an investment in us, financing, a merger, or the sale or transfer of all or part of our business or assets, including to prospective counterparties and their advisers while it is being negotiated, and to an acquirer or successor, or in an insolvency or bankruptcy. If that happens, we will require the recipient to honor this policy for information collected before the transfer, or give you notice and a choice before your information is used in any new way.

Retention and deletion

We retain information for as long as necessary to provide the app and for the purposes described in this policy, or as required by law.

Information stored on your device stays there until you delete it or the app. See "Erasing your data" below for how that works. Deleting the app only clears what's stored on your device.

Usage data and crash reports we receive are deleted automatically within about 90 days of the last activity we receive from your device. Aggregate statistics and de-identified records, described above, may be kept longer.

We retain feedback you send us, including any contact information in it, for as long as we need it to address the report and improve the app. You can ask us to delete or de-identify it at any time. See "Your choices and rights" below.

Erasing your data

You can erase your data at any time from Settings → Delete my data. This deletes the crushes, passes, stats, imported card collection, and other activity the app stores on your device, discards crash reports that haven't been sent yet, and resets the identifier your usage data is recorded against, so nothing further is attributed to it. It keeps your settings, and the record of which versions of this policy and our Terms of Service you agreed to and when, so the app doesn't ask you to agree to them again. That record contains none of your activity and never leaves your device. It can't reach a report or event that was already sent to us before you erased your data. Those are deleted automatically under the retention period above. It also can't reach aggregate statistics or de-identified records, because they are no longer linked to you or your device.

If your phone backs up app data to your Apple or Google account, such as iCloud Backup or Android backup, or copies it to a new phone, that copy can include your crushes, passes, stats, imported card collection, and settings. Apple or Google holds those backups under your account's settings, and we can't access them. Delete my data can't reach a backup made before you erased your data, so restoring from one can bring that activity back. Card images and the identifier your usage data is recorded against are left out of those backups, so a restored phone starts with a new identifier.

Email legal@cargoshortsstudios.com to have feedback or email you sent us deleted or de-identified.

Your choices and rights

  • Erase your data at any time from Settings → Delete my data.
  • Turn off usage analytics in Settings, which stops the app sending us how you use it, apart from the crushes and passes covered by the next choice. Crash reports are separate and are still sent.
  • Turn off "Improve recommendations" in Settings, which stops the app sending us your crushes and passes, the activity we use to learn which commanders pair well. This is separate from usage analytics. If you leave it on and turn usage analytics off, the app still sends your crushes and passes, along with basic details our analytics provider records whenever the app sends anything, such as when the app was opened, your device type and operating system, and your approximate location. Turn both off to stop the app sending us how you use it.
  • Turn off shake-to-report in Settings, which stops the app reading your motion sensor.
  • Reset your advertising identifier at any time in your device's system settings.
  • Have feedback or email you sent us deleted or de-identified by emailing legal@cargoshortsstudios.com. Include the contact information you gave us so we can find the submission.

Categories of personal information

US state privacy laws describe personal information in a standard set of categories. Here is where we land on each, covering the twelve months before the date at the top of this policy.

CategoryDo we collect it?
Identifiers: name, postal address, phone number, account nameNo, unless you include one in the feedback form's optional contact field or in an email to us
Identifiers: email addressOnly if you give it to us, in the feedback form's optional contact field or by emailing us
Identifiers: IP address, device and advertising identifiersYes
Personal information under the California Customer Records statuteOnly if you include it, in the feedback form's optional contact field or in an email to us
Protected classification characteristics: age, gender, race, and similarNo
Commercial information: purchase history, payment informationNo
Biometric informationNo
Internet or network activity: how you use the app, which commanders you crush or passYes
Geolocation dataApproximate only. Our analytics and advertising providers derive a city- or region-level location from your IP address. We never collect precise location
Audio, electronic, or sensory informationNo. Shake-to-report reads your device's motion sensor on the device only; nothing is transmitted or stored
Professional, employment, or education informationNo
Inferences used to build a profile of your preferencesYes. We may build a profile of your card preferences to personalize recommendations
Sensitive personal informationNo

We have not sold or shared personal information, as those terms are defined under US state privacy laws.

State privacy rights

Depending on your state of residence, you may have the right to confirm whether we process your personal information, to access it, to correct inaccuracies, to delete it, to obtain a copy of it, and not to be discriminated against for exercising any of those rights. Some states add more, for example the right to obtain a list of the categories or the specific third parties we have disclosed personal information to, or to ask how automated profiling has been applied to you.

To make a request, contact us at legal@cargoshortsstudios.com. We will respond within the time your state's law allows. If we decline, you may appeal by replying to our response, and we will explain the decision in writing. If your appeal is denied, you may complain to your state attorney general.

Because the app has no accounts, we generally cannot locate app activity tied to a specific person. Feedback submissions and emails are different: those we can find, and delete or de-identify.

Children

Commander Crush is a general-audience app. It is not directed at children under 13, we do not knowingly collect personal information from them, and we do not knowingly sell or share any child's personal information.

We do not ask anyone's age, and there are no accounts.

If you are a parent or guardian and believe your child sent us information, most of what's stored can be cleared from Settings → Delete my data. For anything else, contact legal@cargoshortsstudios.com and we will ensure it's deleted.

Security

We use industry-standard measures to protect the information we hold, including encrypted connections for the data the app sends to us. No system is perfectly secure, but the strongest protection here is structural: there are no accounts, we never collect payment details, and apart from feedback you choose to send us, what we hold is not tied to your identity.

International users

We operate in the United States, and the providers listed above process data there and in other countries where they operate. The app is currently offered in the United States only.

Changes to this policy

We may update this policy. Minor changes are reflected in the version and date above. For material changes, including any new use of your data, we will notify you in the app before the change takes effect and ask for your consent where required.

Contact

Cargo Shorts Studios LLC

legal@cargoshortsstudios.com