PRIVACY FILE / CURRENT PRACTICES

Cappy West Privacy Policy

This Policy explains the limited information involved when a family uses Cappy West and how the application keeps optional progress on the visitor's device.

Effective 2026-09-05

PUBLISHED POLICY

Dates and details

Effective / Last reviewed

What the application asks for

The Cappy West application does not ask a visitor to provide a name, email address, account credential, payment detail, message, photograph, audio, video, precise location, or upload. The site has no account, signup, contact form, chat, comment, public profile, leaderboard, on-site checkout, advertising, or social-media widget.

Technical information is still processed by Cloudflare and the origin systems that deliver and protect the site. Email providers also process correspondence that a grown-up chooses to send.

Progress on this device

Optional progress uses the browser-local key cappywest.progress.v1. Its value records only the version, country slugs for earned stamps, and game slugs for completed games. It does not contain a name, contact detail, free text, score, answer history, location, retailer activity, or advertising identifier.

Progress stays in that browser and is not transmitted by the Cappy West application. The application assigns no expiration date. The Explorer Club reset removes this key, and a visitor can also clear it through the browser's site-data controls.

Cloudflare delivery and security

Cappy West uses Cloudflare for DNS, edge encryption, caching, delivery, and security, and uses an outbound Cloudflare Tunnel to reach the self-hosted origin. Cloudflare can process an IP address and request, system, network, routing, traffic, and security details while providing those services.

Ordinary route testing observed no browser cookie or Set-Cookie response. Cloudflare may set a strictly necessary security cookie when its security features respond to particular traffic. Cloudflare's own privacy policy governs its provider-controlled processing.

Technical records

Origin access logging is disabled. The origin container keeps warning and error output in at most three rotated files of up to 10 MiB each; that size limit is not a fixed number of days. The host journal is limited to 30 days and 250 MiB and may discard entries sooner when the size limit is reached. Monitoring retains only the latest fixed status, aggregate connection or request counters, and a timestamp.

The reviewed Cloudflare Free plan does not give the operator Logpull access, and no Logpush job or purchased Log Explorer product was present. Cappy West does not promise a single retention period for Cloudflare-controlled records; Cloudflare controls those records under its own service and privacy terms. Customer-configurable Network Error Logging is disabled.

Purposes and recipients

Technical data is used to deliver pages, maintain availability, detect abuse, secure the service, diagnose faults, and verify releases. It may be handled by Kerry Kier and by service providers that operate hosting, network, security, email, backup, or recovery systems. Cappy West does not sell visitor data or use it for behavioral advertising or profiling.

Retention and deletion

Correspondence is kept while the matter is handled and deleted from the active mailbox within 30 days after final resolution. It may be kept longer when reasonably necessary for a legal obligation, a legal claim or defense, an abuse or security investigation, or a documented legal hold. Provider recovery copies may remain after active-mailbox deletion under the provider's retention cycle.

Hypervisor snapshots are created only for maintenance, deleted after the associated change is confirmed valid, and never kept longer than 72 hours. An encrypted full virtual-machine backup is made onsite nightly and kept for seven days, then deleted or overwritten. A record removed from the live host can remain in an already-created encrypted backup until that backup expires.

Release evidence and sanitized audit records may be retained to establish the integrity, safety, and provenance of a published release. Protected operational credentials, private infrastructure details, and unsanitized logs are not public evidence.

Analytics and measurements

Cloudflare Web Analytics and Real User Measurements are disabled for the reviewed configuration, and public testing found no analytics beacon, custom event, or third-party tracking script. Network Error Logging is also disabled. Aggregate Cloudflare traffic information may still be available as part of delivery and security operations.

Children and families

Cappy West is designed for children and growing readers, with grown-ups as a secondary audience. The application is designed so a child can read and play without providing a name, contact detail, free text, account, or submission. A grown-up must handle email, retailer visits, and purchases.

This technical design is not a blanket statement that every child-privacy law is inapplicable or satisfied. A grown-up may use the contact below for a privacy question or deletion request concerning correspondence.

Operator and contact

Kerry Kier, an individual, operates Cappy West. Email privacy, accessibility, Terms, copyright, security, or other site questions to hello@cappywest.com. Kerry Kier ordinarily reads and responds to that mailbox.

Mail may be addressed to Kerry Kier, 3631 Truxel Rd. #1115, Sacramento, CA 95834, United States.

Effective date and changes

This Privacy Policy is effective on 2026-09-05 and was last reviewed on 2026-09-05. A revision becomes effective when posted. Material changes receive a visible site notice and an updated review date.