LevelSelect

Privacy Policy

Last updated 18 September 2026

LevelSelect has no accounts, no ads, no analytics, and no tracking. Your library is stored on your device and synced to your own private iCloud database. The developer cannot read it.

What stays on your device

Your games, play sessions, tracker progress, playthroughs, runs, collections, ratings, notes, and linked videos are stored locally and synced through your private iCloud database using CloudKit. That data is under your Apple account's control. Deleting the app and its iCloud data removes it. You can export your library's content to a readable JSON file at any time from Settings.

So that Spotlight and Siri can find your games, LevelSelect adds each game's name, platform, status, hours played and rating to your device's own Spotlight index. The index is kept by your device, is not sent to us, and is rebuilt whenever your library changes.

What leaves your device

These features talk to LevelSelect’s backend. In each case, only what's listed is sent:

FeatureWhat is sentWhere it goes
Game searchThe search text or game id you look upOur proxy → IGDB, for titles, cover art, and release dates
AI tracker generationThe game's name, its public IGDB metadata, and any guide text or URL you provideOur generator → Anthropic's Claude, which may search the web for a guide
RetroAchievements lookupA game name and system, or a RetroAchievements game idOur proxy → RetroAchievements, to find a game and fetch its published achievement list. Sent with our API key, not yours — these say nothing about who you are
Artwork lookupThe game's name, then a SteamGridDB game idOur proxy → SteamGridDB, to fetch covers, backdrops and logos. Sent with our API key, not yours — these say nothing about who you are
Steam achievement listsA game name you search for, or a Steam app idOur proxy → Steam, to find a game and fetch its published achievement list. Sent with our API key, not yours — these say nothing about who you are
Steam game matchingThe Steam app ids of games you import from Steam or look up achievements for — numbers that identify games in Steam's storeOur proxy → IGDB, to find which game each one is. Sent with no Steam key and no SteamID, the same way a CSV import sends the titles in your file
Import matchingThe names of games you import from Xbox, PlayStation, itch.io or a CSV file, and any title you search for while reviewing themOur proxy → IGDB, to match each one to its game, cover and release date. Sent without your sign-in for any of those services and without saying where the names came from
Suggestions & releasesThe IGDB ids of games in your library, their series and studio names, and any studios or publishers you follow; for upcoming releases, only the range of datesOur proxy → IGDB, to find games like yours, more from a series or studio, and what is coming out. Nothing about who you are
Game creditsThe IGDB id of a game whose page you openOur proxy → Wikidata, to find the people credited on it and what else they made
Barcode lookupThe number on a game box you scan. If ScanDex didn't know it and you then choose the game yourself, that barcode with the game and console you choseOur proxy → ScanDex, to find which game the box is — and, in the second case, to add the match so the next scan works. The camera image never leaves your device; only the number does
Map search (planned)The game's name and an optional wiki page URLOur finder → Anthropic's Claude with web search

Separately, and entirely from your device: your public Deku Deals wishlist is fetched if you configure one, cover art loads from IGDB's and SteamGridDB's image servers, and YouTube titles and thumbnails load for links you add.

News

The News tab fetches each site's feed directly from that site, and for a story whose feed sends no picture, the story's own page, to read the picture it names. These are ordinary requests with nothing of ours attached — no install identifier, no LevelSelect key — so a site learns only that its feed was read. Opening a story is an ordinary visit in Safari's in-app view (or Reader). The feeds you follow and the stories you save sync through your own iCloud; the stories themselves are cached on your device and never stored with us.

Your RetroAchievements account, and why its key skips our servers

Connecting a RetroAchievements account is optional. If you do, your username and Web API key are stored in your device's Keychain and sent straight from your device to retroachievements.org to read what you've earned. They never pass through our backend, and they deliberately don't sync between your devices — you enter them on each one, or not at all. Removing them in Settings deletes them.

The reason is logging, and it's worth being precise rather than reassuring. Our hosting platform's function logs capture request and response data — bodies and headers alike — for a short window used for errors and abuse detection. A RetroAchievements Web API key is password-equivalent, so routing one through our backend would write it into those logs on every sync, readable by anyone with dashboard access. Putting it in a header wouldn't have helped, because headers are logged too.

So the app doesn't send it to us at all. What does go through our backend is the catalog side — searching for a game, fetching its published achievement list — using our own key, which says nothing about who you are.

Your Steam account

Connecting Steam is optional. If you do, the Web API key you registered on Steam is stored in your device's Keychain, and your SteamID and Steam display name stay in the app's settings on that device. They're sent straight from your device to api.steampowered.com to read the games you own and the achievements you've earned — never through our backend, for the same logging reason as the RetroAchievements key, and never synced between your devices. Steam only answers when your profile's game details are public on Steam. Disconnecting in Settings deletes the key.

Your itch.io account

Connecting itch.io is optional. It opens itch.io's own sign-in page, where you approve LevelSelect reading your itch.io profile and the games you've bought or claimed. itch.io hands the access token back inside the web address, and a page on this site that runs only in your browser forwards it to the app — so the token is never sent to our servers. It's stored in your device's Keychain, never synced between your devices, and sent straight from your device to api.itch.io when you import. Imported games keep their itch.io cover image, which loads from itch.io's servers. Disconnecting in Settings deletes the token.

Your PlayStation account

Connecting PlayStation is optional. PlayStation has no public way for apps to read trophies, so LevelSelect uses the same sign-in as Sony's PlayStation App. You paste your NPSSO — a sign-in code from playstation.com that works like your password — and the app sends it straight to Sony once to get a sign-in token, then doesn't keep it. The token is stored in your device's Keychain, never synced, and sent straight from your device to Sony to read your trophy lists, the trophies you've earned, and the PS4 and PS5 games you've played with their playtime — never through our backend. Disconnecting in Settings deletes it. Because Sony doesn't publish this route for other apps, it could stop working at any time.

Your Xbox account

Connecting Xbox is optional. You sign in on Microsoft's own page; LevelSelect never sees your password. The sign-in token Microsoft returns is stored in your device's Keychain, never synced, and used straight from your device with Microsoft and Xbox Live to read the games you've played and the achievements you've earned. Your gamertag and Xbox user id stay in the app's settings on that device to show who's connected. None of it passes through our backend. Disconnecting in Settings deletes the token.

The install identifier

Requests to our backend carry a random identifier the app generates on first launch, used only to enforce fair-use rate limits. It isn't derived from your device's hardware, isn't linked to you or your iCloud account, and resets if you delete and reinstall the app.

If you ask for an invite

The invite form is the one place on this site that collects anything, and only because a beta invite has to be sent somewhere. It stores what you type into it — your email address, which Apple devices you have, what you play on, how you track things today and what you use to do it, and any note you leave — with Netlify, who host this site. It is used to send you a TestFlight invite and to understand who is asking. It is not sold, shared, or added to any mailing list; the build-update emails are a checkbox you have to tick yourself, and it is off by default.

Ask at privacy@levelselect.app and your submission is deleted. None of it is connected to the app, to your library, or to the install identifier above.

What LevelSelect never does

Crash reports and TestFlight

During the beta, Apple's TestFlight may share crash logs and any feedback you choose to submit, governed by Apple's privacy policy.

Children

LevelSelect is not directed at children under 13 and collects no personal information from anyone.

Changes

If this policy changes, the updated version is posted here with a new date, and material changes are noted in the release notes.

Contact

Questions or concerns: privacy@levelselect.app, or use TestFlight's built-in feedback during the beta.