This policy covers The Scariest App (com.rlyehtech.scariestthings), the
official native Android companion app for The Scariest Things
(scariesthings.com), a
horror-genre reviews website and podcast. The app is developed by R'lyeh Technologies in
collaboration with The Scariest Things. Note: the app is in closed testing and not yet publicly
available; this policy is published in advance and will be kept current through release.
The Scariest App is designed around a simple rule: collect nothing, hold nothing off-device. In normal use the app handles only the following, and all of it stays on your device:
The app does not request or store payment-card numbers, precise location, contacts, photos, messages, your date of birth, or your home address, and it has no user accounts of its own.
Comments on The Scariest Things require a logged-in account, so reading and posting comments in the app is gated behind sign-in. That sign-in is handled entirely by WordPress.com's own OAuth2 flow:
Authentication happens on WordPress.com's own page, opened in a secure browser tab. Your password and any two-factor codes are entered there — never in the app's own UI.
The app receives only a revocable access token, stored in Android's hardware-backed Keystore — encrypted, and never leaving secure storage.
The token reads and posts your comments through the site's official API. It is never sent to R'lyeh, and you can revoke it at any time (see below).
Signing in is entirely optional — every other part of the app works without it.
Article and podcast content comes from publicly available sources: The Scariest Things' WordPress REST API and its public podcast feed. Fetching public content does not identify you to us — there is no R'lyeh server in the middle, and the app makes these requests directly from your device over encrypted HTTPS connections.
All of your information is stored locally on your device. App data is held in encrypted on-device storage (a SQLCipher-encrypted database), and the WordPress.com token is held in Android's encrypted Keystore, protected by a hardware-backed key. Your data is excluded from Android cloud backup and device-to-device transfer, so it stays on the one device where it was created.
The Scariest App has no backend server. The developer never receives, stores, or has access to your reading history, ratings, downloads, settings, or sign-in token.
The app communicates directly and only with: The Scariest Things
(scariesthings.com) and its podcast media host for public content; and
WordPress.com (public-api.wordpress.com) — and only if you sign in — to
read and post your comments. All traffic uses encrypted HTTPS. The app contains no third-party
advertising, analytics, or crash-reporting services, and does not sell or share your information with
anyone.
Because The Scariest App stores everything locally and keeps no server-side copy, you are always in full control and can remove all of it at any time:
Since the developer holds no copy of your information, there is nothing further to request — deleting it on your device deletes it completely.
The Scariest App presents horror content intended for adult audiences. It is not directed to children and does not knowingly handle data from children.
The app is in active development, and this policy may be updated as features are finalized. The current version will always be posted at this page with a revised "Last updated" date.
Questions about this policy or your data can be sent to: scariesthings@rlyehtech.com.