Privacy Policy

This Privacy Policy explains how we collect, secure, and process your information when you interact with our gaming platform.

Privacy Policy

This Privacy Policy explains how we collect, secure, and process your information when you interact with our gaming platform.

Privacy Policy

This Privacy Policy explains how we collect, secure, and process your information when you interact with our gaming platform.

Effective date:09/01/2026 

  1. Scope and Operator 

ScareScore is operated by CYNQ LABS LLC, a Wyoming limited liability company ("ScareScore," "we," "us," or "our"). This Privacy Policy explains how we process information through the ScareScore mobile and wearable applications and related account, scoring, and support services (the "Service"). We are the controller of personal information processed for these purposes. 

The Service provides physiological response feedback, entertainment scores, comparisons, and ratings for theatrical films, streaming content, theme parks, and other participating entertainment experiences. We treat identifiable physiological readings and health-related inferences as sensitive information, including when used solely for entertainment. 

  1. Information and Sources 

Account information includes the account identifier, login information, contact details, display name, preferences, and support communications you provide or authorize your sign-in provider to provide. 

Physiological information consists only of the measurements you expressly authorize from supported devices and health integrations: Heart Rate, Pulse, accelerometer and six months of historical health kit Data. We also process the resulting response measurements, scores, and session history. We do not request access to unrelated medical records or your entire health history. 

Session and technical information includes the selected film or experience, synchronization identifiers and timing, permission records, device and application information, IP address, and limited diagnostic and security logs needed to operate the Service. We obtain this information from your interactions, authorized devices, and the Service itself. We do not obtain information from data brokers or build profiles of your activity outside ScareScore. We do not use physiological readings to create identity-recognition templates. 

  1. Microphone and Session Synchronization 

When you affirmatively start a ScareScore measurement session that uses audio synchronization and grant microphone permission, ScareScore activates microphone access solely for the duration of that active measurement session. Audio captured through the microphone is processed in real time on your device only to identify participating entertainment audio or a designated synchronization signal and to align your authorized biometric response data to the corresponding moment in the content or experience. ScareScore does not use microphone access when you are not actively measuring and does not use microphone access to monitor background activity. 

Movie and streaming synchronization. ScareScore maintains reference audio fingerprints on its servers. A reference audio fingerprint is a limited digital signature derived from participating source content and is used solely to recognize and synchronize supported entertainment. During an active measurement session, the device listens for playback of the participating soundtrack and performs the microphone-audio analysis on the device using reference fingerprint information made available by ScareScore. Raw microphone audio, speech, conversations, or environmental recordings are not transmitted to ScareScore servers, stored by ScareScore, or retained by ScareScore. Reference fingerprints stored on our servers are derived from participating source content, not from a user's microphone recording, and may be retained while the applicable content remains supported for synchronization. 

Theme Park synchronization. In participating theme park or location-based entertainment environments, ScareScore may, during an active measurement session, listen for a designated high-frequency audio synchronization tone or watermark embedded in or transmitted as part of the experience. That signal is used solely to identify the relevant point in the participating experience and synchronize biometric response measurements for scoring. It is not used to identify a person's voice, listen to conversations, track a user outside the participating experience, or infer unrelated activities. 

No recording, speech analysis, or voice identification. Microphone audio is ephemeral. We do not record or retain raw microphone audio, transcribe speech, analyze the content of conversations, identify speakers, create voiceprints, or use audio to infer sensitive characteristics. Raw microphone audio is discarded as part of the on-device real-time processing and is not retained by CYNQ LABS. We may retain non-audio synchronization identifiers and timing events associated with a scoring session only to the extent necessary to calculate, verify, display, or preserve the ScareScore result, subject to the retention limits in Section 9. 

Location and health care facility protections. We do not use session information, synchronization information, or location information for advertising, marketing, cross-context behavioral advertising, audience targeting, or data brokerage. We do not use such information to identify, track, or infer a user's visit to a health care facility or attempt to obtain health care services. We do not establish or use geofences around entities that provide in-person health care services for the purpose of identifying or tracking consumers, collecting consumer health data, or sending notifications, messages, or advertisements relating to consumer health data or health care services. Any location information that may be processed for a specifically requested ScareScore feature is limited to that disclosed feature and is not repurposed for advertising or health-related tracking. 

  1. Limited Purposes; No Sale or Marketing 

We use information only to provide your requested scoring, synchronization, feedback, saved results, authorized in-app comparisons and ratings; administer your account; respond to support requests; maintain the accuracy, security, and operation of the Service; and meet applicable legal obligations. 

We do not sell, rent, trade, or commercially license user information or user-derived datasets. We do not use or disclose user information for advertising, marketing, promotional messages, audience targeting, advertising measurement, or data brokerage. These restrictions also apply to aggregated and deidentified datasets. We do not use health or response information for insurance, credit, employment, or unrelated profiling, research, or general-purpose artificial intelligence training. 

Communications are limited to requested functionality, account administration, support, security, and legally required notices. We do not send promotional push notifications based on user information. 

  1. Consent and Control 

We obtain your explicit, affirmative consent before collecting or processing sensitive response information for scoring. Public score publication and contribution to collective ratings are separate, optional choices. Before each choice, we identify the relevant data, purpose, recipients, and withdrawal method. Accepting our Terms of Service does not constitute these consents. 

You may withdraw consent through our privacy contact and revoke device permissions through your operating system. Withdrawal stops the applicable future processing and does not invalidate earlier lawful processing. A feature may become unavailable when its necessary data is withheld; unrelated features remain available. 

Withdrawing permission alone does not delete previously stored records. You may separately request deletion. 

  1. Public Scores and Collective Ratings 

Individual results are private by default. Only after your separate, explicit election do we display your selected score, chosen display name, rank, and associated film or experience on the global in-app scoreboard. The publication screen identifies every field and the audience before publication. We do not publicly display raw sensor readings, health records, contact details, or precise session timestamps. 

A display name does not make a score anonymous. Publication may reveal your response to, or participation in, an experience to app users worldwide. You may remove your published result through our privacy contact. We remove it from displays we control and perform legally required downstream deletion steps, but cannot guarantee recovery of screenshots independently retained by other users. 

With your separate permission, results may contribute to collective in-app content ratings. We publish such ratings only in a form that does not reasonably identify an individual or reveal an individual response, and 

suppress insufficiently populated groups. We do not reidentify deidentified information. Withdrawal prevents future contributions; a contribution already irreversibly anonymized cannot be individually retrieved. 

  1. Restricted Disclosures 

We permit contracted hosting, authentication, synchronization, security, and support providers to process only the information necessary to operate the Service on our instructions. They must protect confidentiality, restrict access, assist with deletion, and refrain from independent use, advertising, sale, or model training. Sensitive information is disclosed only within your authorization and applicable law and platform rules. 

Except for the public results you elect to publish, we do not provide private user records or individual response analytics to film studios, exhibitors, streaming platforms, theme parks, sponsors, advertisers, or data brokers for their own purposes. 

We may disclose the minimum information legally required by binding legal process, or otherwise lawfully necessary to address a serious security incident or protect legal rights. We evaluate such requests and apply the additional restrictions governing sensitive information. No disclosure is authorized merely because a recipient requests it. 

  1. Health Platforms 

Access to Apple HealthKit, Apple motion or fitness interfaces, Google Health Connect, and other protected sources is limited to purposes and disclosures permitted by the applicable platform. Consent does not authorize a prohibited use. We restrict or disable a source-dependent feature, including public or aggregate scoring, when the source rules do not permit it. 

We do not place personal health information in our iCloud storage or write entertainment scores into health records as clinical measurements. Apple, Google, and device providers separately govern information they process for their own services. 

  1. Security, Storage, and Retention 

We maintain safeguards proportionate to the sensitivity of the information, including encryption in transit and at rest, restricted access, and security controls for our providers. No system is entirely secure. We investigate suspected incidents and provide notifications required by applicable law. 

We retain information only for its disclosed purpose. Maximum retention periods are: raw physiological readings; identifiable scores and account history; synchronization data, as stated in Section 3; diagnostic and security logs, and backups. Earlier deletion applies when required by law or a valid request. Any mandatory retention is limited to the necessary records, purpose, and legally required period, with other use restricted. 

  1. Deletion and Privacy Rights 

You may request access, a copy, correction, or deletion of your information, withdraw consent, and remove published scores. Depending on applicable law, you may also request portability or processing restrictions, object to processing, obtain information about recipients, and limit use of sensitive information. We do not penalize you for exercising privacy rights. 

Request account and associated data deletion IN APP Deletion requests. Requests are ordinarily free; any lawfully permitted charge will be explained in advance. We reasonably verify identity without requiring a new account and recognize authorized agents where applicable. We delete covered records and direct our processors and other required recipients to do the same, subject only to lawful exceptions. Any permitted backup delay is limited to the published backup period and applicable law; Washington consumer health data is deleted from backups no later than six months after authentication of the deletion request. 

We respond without undue delay and within the applicable deadline, ordinarily 45 days after receipt, or one month for GDPR requests. We explain any legally permitted extension or refusal. To appeal, contact support@scarescore.com with "Privacy Appeal." We respond within 45 days or any shorter required period and provide the applicable regulator complaint route when denying an appeal. You may complain directly to a competent regulator or seek other available remedies without first contacting us. 

  1. United States Privacy Rights 

Where applicable, California and other state laws provide rights to know the categories and specific information collected, sources, purposes, and recipients; to correct or delete information; and to opt out of sale, targeted advertising, or certain profiling. We do not sell personal information or share it for cross-context behavioral advertising, and do not use sensitive information for those purposes. We honor applicable opt-out preference signals, including Global Privacy Control. We do not track activity across other companies' websites or apps; browser Do Not Track signals therefore do not change our practices. 

Additional consumer health disclosures and request procedures appear in our Consumer Health Data Privacy Policy at www.Scarescore.com . More protective applicable requirements control. Nothing in this Policy waives statutory privacy rights. 

  1. European and United Kingdom Processing 

Where the EU or UK GDPR applies, our bases are consent for optional processing; performance of our agreement for necessary account and service administration; legitimate interests in protecting the Service for proportionate, nonsensitive security processing; and compliance with applicable legal obligations. Sensitive scoring, optional publication, and collective-rating contributions require explicit consent under Article 9(2)(a), together with Article 6(1)(a). We do not rely on contract or legitimate interests alone to authorize health-data processing. 

Scores are automated estimates derived from authorized readings during an entertainment session. They may affect in-app comparisons or ranking but are not used by us for decisions producing legal or similarly significant effects. 

International transfers are made only through a legally valid mechanism and required safeguards. Transfer destinations and applicable mechanisms: 

  1. Age and Policy Changes 

The Service is intended for adults aged 18 and older and is not directed to children. We do not knowingly collect information from anyone under 18. Please notify us of suspected underage use so we can investigate, restrict access, and delete improperly collected information. 

We identify revisions by the effective date and provide advance notice of material changes. Additional consent is obtained before new consent-dependent processing begins. An update does not authorize sale or marketing use of information collected under this Policy or override an existing privacy choice. 

  1. Contact 

CYNQ LABS LLC

support@scarescore.com