The short version
Deadly Prompt does not use advertising trackers and does not access your camera, microphone, photos, contacts, GPS, or iPhone Location Services. Private Story mode keeps the conversation on your iPhone. Live AI mode sends the conversation to our server and then to Anthropic only after you consent.
Opening case-file personalization
When the recovered case-file opening begins, our server may use the IP address already needed to service that real-time request to infer a U.S. state. It returns only the state name to the app. The lookup code does not persist either value, disclose it to an AI provider, or write it to application or web access logs; connection metadata may still be held transiently by normal network security controls. If no state can be resolved, the opening works without one.
The app may cache the returned state name on your iPhone so later openings do not repeat the lookup. It never requests GPS or iPhone Location Services. The local lookup database contains GeoLite2 data created by MaxMind.
What Live AI processes
When you choose Live AI, the app sends a random session identifier, the current story beat, the conversation messages needed for continuity, and an optional language locale. Our server uses the session identifier for request validation and does not send it to Anthropic. Anthropic receives the conversation, the locale if supplied, and our fictional character instructions to generate a reply.
Like any internet service, the server receives network information such as an IP address. It is used transiently for the opening region lookup, rate limiting, and abuse prevention. Our configured application and web access logs do not record raw IP addresses, inferred regions, or conversation text.
What stays on your iPhone
Story progress, settings, Live AI consent, the inferred case state, and the locally displayed conversation are stored on the device. You can erase the saved conversation or withdraw Live AI consent in Settings. Withdrawing consent switches the experience to the private handcrafted story; it does not retroactively remove API traffic already processed under the retention rules below.
Anthropic processing and retention
Live replies are generated with Anthropic’s commercial API. Anthropic states that API inputs and outputs are normally deleted from its backend within 30 days and are not used to train its models by default. Exceptions can include longer retention required by law or to enforce its Usage Policy; content flagged for a Usage Policy violation can be retained for up to two years.
Read Anthropic’s current explanations of commercial data retention and model training. Anthropic controls and may update those policies.
User-triggered response reports
If you explicitly choose “Report response” in the app, we store only the selected AI response excerpt, its response identifier, your chosen category (safety, privacy, or other), the app version, a generated report identifier, and the submission time. We do not attach the full conversation, session identifier, or raw IP address. Reports are retained for 90 days and then removed on a daily schedule. Reports are never submitted automatically.
Our server records
The backend keeps a daily numeric request count to enforce a hard usage budget; it contains no conversation, session identifier, or IP address. Operational logs contain request identifiers, route, status, timing, and short process-specific hashes used to diagnose abuse. The hashes change when the service restarts and are not used to track you across products.
The website
This website is static. It has no account system, advertising pixel, analytics script, contact form, or marketing cookie. Standard network providers may still process connection metadata needed to deliver the pages securely.
Sharing, sale, and legal needs
We do not sell personal information. We disclose Live AI content to Anthropic to provide the feature and may use infrastructure providers to operate the service. We may preserve or disclose limited information when legally required or reasonably necessary to secure the service, investigate abuse, or protect people.
Children and sensitive information
Deadly Prompt is a mature horror experience and is not directed to children under 13. Do not enter passwords, payment details, an address, medical information, or other sensitive personal data into the conversation.
Questions and requests
Email support@onesmallprompt.com. This is the current monitored support address for Deadly Prompt while dedicated domain mail is being configured. Include only what is necessary for the request.
Changes
If this policy changes materially, we will update the effective date and provide an in-app notice when appropriate.