Shinro ("we", "us") publishes the apps listed at shin.ro, including Codex Books, Codex IPO, and Codex GameHawk. You can reach us any time at contact@shin.ro.
Codex Books and Codex IPO have no accounts and no Shinro backend. Your data (libraries, watchlists, settings) stays on your device, and any API keys you configure are stored in the platform's secure store and sent only to the provider they belong to. Each app's own policy has the detail: Codex Books, Codex IPO.
Codex GameHawk uses a Shinro server to track prices and send alerts. Its full policy is at Codex GameHawk; the summary follows. When you sign in with Apple or Google, we create an account identified by a random ID and store the identifier your provider gives us, along with your email address when the provider shares it. To run the service, we additionally store:
What never reaches us: storefront credentials. Connecting a storefront happens on your device, in the storefront's own sign-in pages, and the resulting tokens are stored in the iOS Keychain or Android's encrypted, Keystore-backed storage. The service also has no passwords of its own and processes no payments.
Stored data is used only to provide the service it belongs to, such as checking storefront prices for the games you track and notifying your devices about deals. We do not sell data, share it with advertisers, or use it for profiling.
Apps with accounts include a device attestation on each sign-in (Apple App Attest on iOS, Google Play Integrity on Android) that proves to our server that the request comes from a genuine copy of the app on genuine hardware. We verify these tokens and, on iOS, store the public key of the device's attestation identity. This protects the service from abuse; it does not identify you personally.
Our servers keep standard operational logs, which include IP addresses, and apply rate limits keyed to accounts and IP addresses to keep the services available. Logs are used for security and operations only, and are never linked to any marketing or profiling use.
Some apps use crash reporting (Firebase Crashlytics on Android) so faults can be found and fixed. Crash reports carry the stack trace and device details, and never your credentials, libraries, or searches. Where an app offers a switch to disable crash reports, it is honored fully.
Our apps talk to third parties only as their function requires: storefront price interfaces are queried with game identifiers only, push notifications are delivered by Apple (APNs) and Google (FCM), game identities are matched across storefronts via IGDB, and artwork is loaded from each provider's own servers. Apps without a backend send requests from your device directly to the providers you configured.
For apps without accounts, deleting the app deletes the data. For Codex GameHawk, data is kept while your account exists; Settings → Account → Delete account removes your account and everything attached to it, immediately and permanently: wishlist, owned list, alert settings, devices, and platform connections. Sign-in sessions expire on their own after long inactivity, and push tokens for devices not seen in 180 days are removed automatically.
You may access, correct, or erase your data at any time: most of it directly in the app, and all of it via account deletion or by writing to us. If you are in the EU/EEA, these are your GDPR rights of access, rectification, erasure, and portability, and you may also lodge a complaint with your supervisory authority.
If this policy changes, the new version is published at this address with an updated effective date. Material changes are called out in the affected apps.