# Privacy Policy — BattleArena: Gods of Myth

**Owner:** HashCoreAI
**Contact:** contact@hashcoreai.com
**Last updated:** 2026-09-18
**Applies to:** BattleArena: Gods of Myth for Android and iOS, version 1.0.x

> This file and `Assets/BattleArena/Data/PrivacyPolicy.txt` say the same thing; the `.txt` is the
> copy shipped inside the app (Settings → *Privacy policy*, and the *Privacy policy* link on the
> consent screen). Change both, or neither. When the policy is published at a URL, put it in
> `UiTheme.PrivacyPolicyUrl` and the in-game buttons open the page instead — Google Play also
> requires the URL in the store listing.

## Short version

BattleArena keeps your progress in a single save file on your own device. It does not ask for your
name, e-mail address or phone number, and it never sells data to anyone.

Some features do talk to other companies, and every one of them is optional and asked for first:
anonymous gameplay analytics (a log kept on this device, plus a handful of milestone events sent to
Google), rewarded ads you choose to watch, in-app purchases handled by Apple or Google, and — when a
build is configured for it — an anonymous account with cloud save and asynchronous arena. That anonymous account can be given an e-mail
address, a Google account or an Apple account, if you want your progress to survive a lost phone;
you can delete it, with everything in it, from inside the game.

The **Your privacy** screen, shown the first time you play and reachable any time from Settings, is
where you accept or decline the optional parts. Declining costs you nothing but the feature itself.

## What the game stores on your device

The game writes one save file in the private storage of the application
(`Application.persistentDataPath` — a folder only this app can read):

- your heroes, their levels, stars, gear and the formation you last used;
- campaign progress (unlocked stages, stars, chests claimed);
- gold, gems, stamina and the timestamp of the last stamina tick;
- what you bought with real money, so it is not granted twice, and how many rewarded ads you
  watched today;
- your privacy answers (analytics yes/no, personalized ads yes/no);
- settings: language, music and sound volume, battle speed, auto battle;
- the moment the profile was created, as a UTC timestamp;
- if you added an account, the e-mail address on it, the list of sign-in methods and the session
  refresh token described below — so the Account screen can show them without a network call, and
  so the next start signs you back in. Never the password.

The save contains **no** name, e-mail address, phone number, contact list, location or advertising
identifier.

Uninstalling the game deletes the save. The **Settings → Reset progress** button deletes it too,
from inside the game.

## Analytics (optional)

Saying yes to analytics does two different things, and they deserve to be told apart.

**A log that stays on this device.** The game appends short gameplay events to a log file kept in the
same private folder — for example *a battle started*, *a stage was cleared*, *a summon was made*.
Each line is a timestamp, an event name and a number (`{"t":…,"e":"battle_end","result":1}`); there
is no identifier of you or of your device in it. The log is capped in size and the oldest part is
dropped. It is **never uploaded**: it exists so the game can be balanced from real play, and it is
read only on the device it was written on.

**A few milestones that do leave the phone.** The game also uses **Google Analytics for Firebase**,
so we can tell whether the game is worth carrying on and which advert brought a player in. What is
sent is only that: the tutorial was finished, the first campaign battle was won, a purchase was
verified (with the product bought and its list price) — plus the two events Google's own library
writes by itself, the first time the app is ever opened and once at the start of each session.
Nothing about an individual battle is sent, and no line of the log above is uploaded.

With those events Google receives an app-instance identifier that its library generates — not the
advertising identifier, and never your name, e-mail address or phone number — together with the
usual technical detail: device model, operating system, app version, language, and the country the
request came from.

Declining — or turning analytics off later in Settings — deletes the log already on the device and
switches Google's collection **off**, which stops its own automatic events as well as ours. The same
switch is ours to throw remotely if the game ever needs to stop collecting.

- Google's privacy policy: <https://policies.google.com/privacy>
- Firebase privacy and security: <https://firebase.google.com/support/privacy>

## Ads (optional)

There are two kinds of ad in the game, and no banners.

**Rewarded video** is never shown without a button you pressed, and it always pays: extra stamina,
an extra summon, doubled battle rewards.

**One interstitial**, the only ad you do not ask for, can appear on the "Continue" screen *after* a
battle — never during one. It is deliberately rare: at most one per three battles, never less than
two minutes after the previous one, and it is skipped for a battle whose reward you have just
doubled by watching a rewarded ad. **If you have ever bought anything in the game, you never see it
at all** — that does not expire, and a refund does not take it back.

When a build is configured with an ad network (**Google AdMob**, from Google), that network
— not the game — receives what it needs to deliver a video, to know it was watched and to keep the
same video from repeating: your device's **advertising identifier** (IDFA on iOS, the Google
Advertising ID on Android, or the equivalent), your **IP address**, and basic **device and app
information** (model, operating system, language, app version). None of it is copied into the save
file or sent anywhere by the game itself.

That happens whether or not you allow personalized ads; the **Personalized ads** switch controls
whether the network may use that data to profile you and choose which video to show, and it is
**off** unless you turn it on. Your choice is attached to every ad request, so turning it off asks
the network for non-personalized ads. Where the law requires a choice — the European Economic Area,
the United Kingdom and Switzerland — Google's own consent form is shown on top of that, before any
ad is requested, and no ad is requested at all until you answer it.

On iOS there is no **Personalized ads** switch in the game. Instead, the first time you play, the
game asks for the system **Allow tracking** permission (App Tracking Transparency) — before any ad
is requested, and only once. That answer *is* the choice: if you allow it, ad requests may use your
advertising identifier so the network can personalize the videos it shows you; if you decline, every
ad request asks the network for non-personalized ads and your advertising identifier is not used to
track you across other companies' apps or websites. Nothing else in the game changes with your
answer, and you can change it at any time in the iOS Settings app, under *Privacy & Security →
Tracking*.

Google advertising privacy: <https://policies.google.com/technologies/ads>

Builds that ship without ad network credentials show a placeholder ad: the game itself never starts
the ad SDK and contacts no ad network. (The ad library is still linked into the Android build, so
the app declares the advertising-ID permission whether or not ads are switched on.)

## In-app purchases

Gem packs, the starter pack and the monthly card are bought through Apple's App Store or Google
Play. **They** process the payment: your payment details go to the store, never to the game, which
never sees a card number and never stores one. All the game gets back is the store's receipt for
that purchase and the transaction identifier inside it — no name, no e-mail address, no billing
address. What the game then keeps on the device is which product was granted, plus the identifiers
of the last fifty transactions, so a restored or re-delivered purchase is not granted twice.

When a build is configured with a backend, the receipt makes one more trip before anything is
granted: the game sends it to our server, which asks Apple or Google whether the purchase is real.
Nothing is added to your account until the store answers yes. What that check leaves behind, on the
server, is a record of the purchase — the store's order identifier, a one-way fingerprint of the
receipt (a SHA-256 hash; the receipt itself is never kept), which product was bought, the price the
store charged, when it happened, and whether it was later refunded. No name, no e-mail address, no
billing address, no card detail.

The stores also notify that server when a purchase is refunded, cancelled or charged back, so the
items bought with it can be taken back — including when they have already been spent, in which case
the gem balance can go negative until the debt is paid off. Repeated refunds can mark an account for
review and, in clear cases, suspend it. A suspension is reversible, and you can ask about one at the
contact address below.

When you ask Apple for a refund on a consumable purchase, Apple asks our server whether the content
was used before it decides. The server answers with the categories Apple defines, not the raw
numbers: whether the gems from that purchase are still in your wallet (unused, partly used or
used up), that the purchase was delivered, how long the account has existed (in bands such as
"10–30 days"), the bands your lifetime spending and lifetime refunds fall into, and whether the
account is active or suspended. It never sends your name, e-mail address, save data or play time.
Apple makes the decision; the game only reports honestly what happened to what you bought.

**Restore purchases**, in Settings, asks the store which non-consumable products your account owns.

- Apple's privacy policy: <https://www.apple.com/legal/privacy/>
- Google's privacy policy: <https://policies.google.com/privacy>

## Account, cloud save and arena (optional, only in configured builds)

When a build is configured with a backend (**Google Firebase**), the game can create an **anonymous**
account — a random identifier, with no e-mail address, no password and no personal detail — and use
it to back the save up and to run the asynchronous arena (you fight recorded teams, never a live
opponent). The data sent is the same game data listed above, plus a display name you choose
yourself. Do not put your real name in it if you do not want it seen by other players on the
leaderboard.

What that account holds: your save (as one text blob), the five heroes of your arena defence team
with their levels and gear, that team's total power, your arena rating, the display name, and the
moment the defence team was last published. The format of that record carries one further field,
for the campaign chapter reached, which this version always sends empty.

**Giving that account a name.** In *Settings → Account* you can attach an e-mail address and a
password, a **Google** account or an **Apple** account. The identifier does not change and nothing
is copied or moved — the account you already had simply gains a way to sign in again, on this phone
or on the next one. Staying anonymous is a complete answer; it only means a lost phone is a lost
save.

- **We never see and never store your password.** It goes straight from the screen to Firebase
  Authentication over an encrypted connection, and the game keeps none of it. *Forgot password*
  asks that service to send you a reset e-mail; the game never learns what you choose.
- **One session token stays with you.** So that you are not asked to sign in every time the game
  starts, a refresh token for your session is kept on your device — in the operating system's own
  small settings store and, as part of your save file, in your cloud save, which only your own
  account can read. It is used for nothing but signing you back in with Firebase Authentication.
  It is removed from your device when you sign out and when you uninstall the game; the copy
  inside your cloud save is deleted together with your account.
- **Google and Apple are sign-in providers, not data sources.** Google's part happens in your own
  browser, Apple's in the system sheet; what comes back is a signed token proving who you are, plus
  the e-mail address on that account. The game asks them for nothing else — no contacts, no
  profile, no calendar, no photos. Apple's *Hide My Email* works as intended: if you use it, the
  relay address is all anyone here ever sees.
- **What the server keeps about the account:** in Firebase Authentication, the e-mail address, the
  sign-in methods linked to it and the account identifier. Separately, in a support index the game
  itself writes: the same e-mail address and display name, when the account was created, when it
  was last seen, the platform and app version of the phone, and a snapshot of a few in-game numbers
  (rating, gems, gold, how many heroes, how many rewarded ads were watched). That index exists for
  two reasons only — to answer a support message, and to notice an account that is obviously
  broken or cheating. It is never shown to other players, never used for advertising and never
  sold.

The same connection is also used to read a small settings file the game itself uses (prices,
timers), which sends nothing about you beyond the request.

Firebase privacy: <https://firebase.google.com/support/privacy>

The build in this repository ships with those credentials **empty**, which means no account is
created and nothing leaves the device.

## What the game never does

- It never sells or rents your data to anyone.
- It has no chat, no friends list, no voice, no messaging between players. In a build with a
  backend, the only thing other players ever see of you is the display name you chose, next to your
  rating on the leaderboard.
- It asks for no runtime permissions beyond two optional ones: notifications (reminders you can
  refuse) and, on iOS, *Allow tracking* (described under Ads). No camera, microphone, contacts,
  location or storage outside its own private folder.
- It does not use your data to build a profile about you outside the ad network switch and the
  analytics switch described above.

## Children

The game is not directed at children under 13. It contains optional purchases and optional rewarded
ads; personalized ads are off by default and, where the law requires it, they stay off. If you
believe a child has provided data through this game, write to the contact address above and it will
be removed.

## Your rights

The fastest way to exercise deletion is inside the game itself:

- **Settings → Account → Delete account** deletes an account you have signed in to. You type the
  word DELETE and sign in once more to prove it is you — that proof has to be fresh, less than five
  minutes old, and the server checks it, not the phone. It is the same button whether you signed in
  with an e-mail address, with Google or with Apple. Then the server erases, in one operation: the
  support index row with your e-mail address and display name, the search words built from them,
  your cloud save, your arena defence team, your arena rating, any pending support operation — and,
  last of all, the sign-in account itself. It cannot be undone, and afterwards the game starts again
  on a fresh, empty profile.
- **Settings → Account → Delete account & data** is the same right for a game you never signed in
  to. Playing without an account still creates one — an anonymous account, held only by this phone
  — so the button is there as well, under the sign-in options. You type the word DELETE, and that is
  all that is asked: there is no password to re-enter and no sign-in page to visit, so the server
  does not ask for a fresh proof either. The unlocked phone in your hand is the proof, because that
  anonymous account exists nowhere else. The server then erases your cloud save, your arena defence
  team, your arena rating, the support index row, any pending support operation and the anonymous
  account itself; the game erases the progress stored on this device. It cannot be undone, and the
  game starts again on a fresh, empty profile with a new anonymous account.
- **Settings → Reset progress** deletes the save file without touching the account. In a build with
  a backend it also replaces the cloud copy with the fresh, empty profile, so the old progress is
  not sitting there waiting to come back.
- Turning **analytics** off in Settings deletes the log that was already written and switches
  Google's collection off.
- Uninstalling deletes everything the game kept on the device.

Three things deliberately survive either deletion — whether or not you had signed in — and it is
fair that you know which:

- **the record of purchases and refunds** — an accounting obligation, and the only evidence in a
  payment dispute, which a store can open months after the fact. It holds the order identifier, the
  receipt fingerprint, the product, the price and the dates — never a name, an e-mail address or a
  card detail;
- **a suspension**, if the account was suspended, so that deleting an account cannot be used to
  undo one;
- **one line in the server log** saying a deletion happened, keyed by the account identifier only —
  no name, no e-mail address in it. It is kept about 30 days, so that "I asked for deletion, did it
  happen?" has an answer.

The audit trail kept on the server records only what an **administrator** does to someone's
account. A player acting on their own account never appears in it.

If you cannot reach the button — you lost the phone, or the game will not open — write to the
contact address above and ask; tell us the e-mail address on the account, or your in-game display
name, so the row can be found.

## Changes

If a future version changes what is collected, this policy is updated **before** that version ships,
and the in-game screen shows the new text. The change will also be visible in the store listing's
"what's new" section.

## Contact

Questions about this policy: contact@hashcoreai.com.