Skip to content
Byte Size Factory

Last updated August 14, 2026

Privacy Policy

Byte Size Factory is run by Jackson Van Dyke, one person, in the United States. This page covers this website and every product shipped under Byte Size Factory. Data practices differ between products, so each one has its own section below.

The short version

I collect the least I can get away with while still running the thing. I do not sell your data, I do not share it with advertisers, and I do not build profiles on you. The only third parties who touch it are the services I need to run the products — hosting, payment processing, and the like — and they only ever act on my instructions.

If you want your data deleted, email support@bytesizefactory.dev and I will do it.

What applies to everything

This website

The site you are reading is a set of static pages. It does not set cookies, does not run analytics, and does not track you. Visiting it leaves nothing behind beyond the ordinary server logs my host keeps for security and reliability.

Who your data is shared with

Only with processors — companies that handle data on my behalf so a product can function, such as hosting providers and payment processors. They are contractually limited to that purpose. Each product’s section below names the processors that apply to it.

I do not sell personal information, and I do not share it for cross-context behavioural advertising. I may disclose data if I am legally required to — a valid court order, for example — or where it is genuinely necessary to protect someone’s safety.

How long it is kept

Retention differs per product and is stated in each section. As a general rule, account data lives as long as the account does, and records I am required to keep for tax or accounting reasons live longer than that.

Your rights, and how to delete your data

Wherever you are, you can ask me for a copy of the data a product holds about you, ask me to correct it, or ask me to delete it. If you are in the EU, the UK, California, or somewhere with comparable law, you may have additional rights — including objecting to certain processing. Exercising any of them costs you nothing and will not get you treated differently.

Email is the route for any of it: support@bytesizefactory.dev. Tell me which product and give me the account email or username, so I can find the right records. I will confirm when it is done. Deleting a game account deletes its progress too, and that is not recoverable.

Deletion has a second route as well: some products can delete their own account from the inside, without asking me first. The steps for each one, and exactly which records go with it, are on the account deletion page.

Children

None of these products are directed at children under 13, and I do not knowingly collect data from them. If you believe a child has given me personal information, email me and I will remove it.

Security

I take reasonable measures to protect what I hold, but no service can promise perfect security, and I am not going to pretend otherwise. If a breach ever affects your data, I will tell you.

Changes to this policy

When practices change, this page changes, and the date at the top changes with it. If a change is significant — new data, a new processor, a new purpose — I will make a reasonable effort to tell affected users directly rather than quietly editing this page.

By product

Each product has a permanent anchor on this page. These URLs are used in app store listings and inside the products themselves.

Starclaim

Live
#starclaim

Starclaim has accounts and sells in-game purchases, so it collects more than the rest of the site.

What it collects, and why

  • Email addressTo identify your account, let you sign in and recover access, and contact you about your account or a purchase.
  • UsernameTo identify you to other players in-game.
  • Gameplay data — your progress, holdings, and in-game activityTo run the game. This is the save file; without it there is no game to return to.
  • Purchase records — what was bought and whenTo grant what you paid for, and to answer support questions about a purchase.

Who it is shared with

  • A third-party payment processor Takes payment and handles card details directly. Starclaim never receives or stores your card number — it only records that a purchase succeeded.

How long it is kept

Account and gameplay data is kept for as long as the account exists. Purchase records are kept longer, because tax and accounting rules require it.

Deleting your data

Email support@bytesizefactory.dev from the address on the account, or tell me the username, and I will delete it. The full explanation of what deletion removes is on the account deletion page.

Starclaim support

Bodkin

Live
#bodkin

Bodkin is a multiplayer game, so it handles the data needed to put you in a match with other people.

What it collects, and why

  • Username or display nameTo identify you to other players in a match.
  • Match and gameplay dataTo run matches and keep results consistent between players.

Who it is shared with

No third parties beyond the hosting needed to run it. Your data is not sold or shared with advertisers.

How long it is kept

Match data is kept only as long as it is useful for running and debugging the game.

Deleting your data

Email support@bytesizefactory.dev from the address on the account, or tell me the username, and I will delete it. The full explanation of what deletion removes is on the account deletion page.

Bodkin support

NeedToKnow

In development
#needtoknow

NeedToKnow has accounts and a backend that reads news feeds on your behalf, so it holds a little about you — your email, the filters you write, and the settings that decide when it runs — but it ships with no analytics, no advertising identifier, and no access to your location, contacts, or photos.

What it collects, and why

  • Email addressTo identify your account, sign you in, let you recover access, and reach you about the account. Sign-in is handled by Supabase Auth; if you use a password, only a salted hash of it is stored, never the password itself.
  • An account identifier — a random id created when you sign upEverything else the service stores is keyed to that id rather than to your email, so your filters and your results can be told apart from someone else's.
  • The filters you write — the name and the criteria text of each oneTo decide what to surface. This is the whole product; without it there is nothing to match against. It is also the one thing that leaves my servers for the scoring model, so read the Anthropic entry below before you write anything private into a filter.
  • A notification token for your device, if you allow notificationsTo send you a push when a story clears your bar. It is optional — decline the permission and the app works fine, you just check the Signal tab yourself. Turning notifications off in the app, or signing out, deletes that device's token.
  • Your chosen scan frequencyTo know when your next scan is due. You pick it in the app; your plan only sets the fastest cadence you are allowed to choose.
  • The stories surfaced to you, and your scan countsTo fill the Signal tab and to show you the service actually ran — for each story, the headline, link, publisher, date, and the one-line reason the scorer gave. A short-lived record of which feed items you have already been screened against goes with it, so the same story is never scored against you twice.

Who it is shared with

  • Supabase Runs the database and the sign-in system. It holds your email, your account id, your filters, your settings, your device token, and the stories surfaced to you.
  • Fly.io Hosts the background worker that reads the feeds and runs your scans, in their US East region in Virginia. Everything above passes through it in memory; its logs record your account id and scan counts, never your email and never your filter text.
  • Anthropic Scores stories against your filters. Each scan sends the name and criteria of your enabled filters exactly as you typed them, together with a batch of public news items — headline, publisher, and up to roughly 400 characters of the published summary. It does not send your email, your account id, or your device token, and the request comes from my server rather than your phone, so it does not carry your IP address either. The practical version: a filter is a description of a topic, not a diary, so do not write anything into one you would not want a third-party model to read.
  • Google Firebase Cloud Messaging Delivers the push notifications. It receives your device token and the notification itself — when a single story clears your bar, that is the publisher name, the headline, and the link to the publisher's page; when several clear at once, it is only a count of how many.

How long it is kept

Your email, account id, filters, settings, and device tokens are kept for as long as the account exists. Surfaced stories are kept with the account as well — the app shows a rolling seven-day window, and older rows stay in the database until the account goes. The records of what has already been screened for you are deleted automatically seven days after they are written, and a device token is deleted as soon as you turn notifications off, sign out, or Firebase reports it dead. Deleting the account removes all of it. Two things trail behind it: copies inside encrypted database backups until those roll over, and the worker's log lines, which carry your account id and a couple of counts but never your email and never your filter text. Neither is kept more than 30 days.

Deleting your data

In the app: Account tab, then Delete my account, then type DELETE to unlock the button. It happens immediately and cannot be undone, and it takes everything with it — your login, your filters, every story surfaced to you, your scan stats, your settings, the record of what has already been screened against you, and any device tokens. What outlives it is described above and nothing else: the backup copies, which roll over on their own and are never used to bring one account back; the worker log lines, which carry a random id and nothing that reaches you; and the filter text already sent to the scoring model on earlier scans, which left my servers before you deleted and cannot be pulled back. If you would rather I did it, email me from the address on the account and I will. The full explanation of what deletion removes is on the account deletion page.

NeedToKnow support

The Guide Forge

Retired
#guide-forge

The Guide Forge is retired. This section stays published because it had user accounts, and people with accounts keep their rights over that data after a product shuts down.

What it collects, and why

  • Email address and username, from accounts created while it was runningIt was used to sign in and to attribute published guides. Nothing new is being collected — the service is off.

Who it is shared with

No third parties beyond the hosting needed to run it. Your data is not sold or shared with advertisers.

How long it is kept

No new data is collected. Any remaining account data from when the service ran is kept only until it is deleted on request or removed in the course of shutting the service down.

Deleting your data

Email me and say you had a Guide Forge account. Include the email address or username you used, so I can find it. The full explanation of what deletion removes is on the account deletion page.

The Guide Forge support

Contact

Questions about any of this, or about data I hold, go to support@bytesizefactory.dev. The person who reads it is Jackson Van Dyke.