Privacy Policy

Related legal docs in this directory:


1. Who we are (Controller)

We are the publisher of the AlcheMagic mobile game ("AlcheMagic", "the Service", "we", "us").

For EU users, this entity is the data controller under GDPR Art. 4(7) for all data described in this policy. Apple Inc. is a separate controller for App Store transactions and Game Center authentication.

2. Scope

This policy covers data processed by the AlcheMagic iOS app, its backend service, and its supporting websites. It does not cover data processed by Apple Inc. or other third parties acting as independent controllers — see their own policies.

3. Data we process

We process the following pseudonymous data. We do not receive your real name, email address, Apple ID, phone number, postal address, IDFA, IDFV, or any contact list.

CategoryExamplesSourceIdentifier link
Game Center identity (pseudonymous)HMAC-SHA256 hash of Game Center player idApple Game Center sign-inHashed server-side.
Session id (pseudonymous)HMAC-SHA256 hash of session tokenCreated on Game Center proof verifyHashed server-side.
Cloud save dataLevel progress, owned upgrades, settings, display nameIn-app gameplayLinked to hashed player id only.
Purchase recordsApple originalTransactionId, product id, entitlement state, refund flagsApple App Store Server Notifications (ASSN v2)Linked to hashed player id only.
Gameplay telemetry (opt-in)Waves played, levels completed, towers built, funnel eventsIn-app instrumentationSent to GameAnalytics only with consent (default OFF).
Crash & ANR reports (opt-in)Stack traces, device model, OS versionFirebase CrashlyticsSent only with consent (default OFF).
Server access logHTTP method, path, status, timing, hashed player idBackend Pino loggerRetained 30 days; rotated daily.
Audit logAccount deletion events, purchase mutationsBackend audit writerRetained indefinitely (compliance — see §7).

We do not collect: IDFA, IDFV (telemetry layer blocks IDFA at code level), location, contacts, camera, microphone, photo library, calendar, or health data.

4. Why we process (legal bases — GDPR Art. 6)

PurposeData usedLegal basis (GDPR Art. 6)
Verify Game Center sign-in (anti-abuse, account binding)Hashed Game Center id, session idContract (Art. 6(1)(b)) — necessary to provide the Service.
Sync cloud save across devicesCloud save data, hashed player idContract (Art. 6(1)(b)).
Deliver and verify In-App PurchasesPurchase recordsContract (Art. 6(1)(b)).
Comply with tax, accounting, and fraud-prevention obligationsPurchase recordsLegal obligation (Art. 6(1)(c)).
Measure gameplay quality (analytics)Telemetry eventsConsent (Art. 6(1)(a)) — opt-in only, default OFF, withdrawable any time.
Investigate abuse / security incidentsAccess log, audit logLegitimate interest (Art. 6(1)(f)) — to keep the Service secure for all players.

We do not process for: advertising, profiling, automated decision-making with legal effect, or sale of personal data.

5. Where data is stored

6. Third-party processors and international transfers

We use the following processors. All process data on our behalf under signed Data Processing Agreements (DPAs) / Standard Contractual Clauses (SCCs) where the processor is outside the EEA.

ProcessorRoleData receivedLocationTransfer mechanism
Microsoft AzureHostingAll backend dataSweden CentralEU SCCs (if region outside EEA)
Apple Inc.Game Center auth, App Store paymentsGame Center proof, purchase eventsUS / globalApple's published terms (Apple is independent controller, not processor)
GameAnalytics ApS (Denmark)Gameplay analytics (opt-in)Pseudonymous gameplay eventsEU + US sub-processorsDPA + SCCs (signed 2026-07-09)
Google LLC — Firebase CrashlyticsCrash reporting (opt-in)Crash stack traces, device infoUSDPA + EU SCCs (signed 2026-07-09)
Google LLC — Firebase Remote ConfigApp config deliveryAnonymous device/install idUSDPA + EU SCCs (signed 2026-07-09)
Sentry (Functional Software, Inc.)Backend error reportingBackend stack traces, hashed player idUSDPA + EU SCCs (signed 2026-07-09)

We do not transfer your data to advertisers, brokers, social networks, or any party not listed above.

7. Retention

We delete or anonymize data as soon as the purpose for which it was collected is satisfied. See the Account Deletion Policy for the full schedule.

DataRetentionReason
Session id30 days from last useAuth UX; reduce re-sign-in friction.
Cloud saveUntil account deletionService functionality.
Purchase records (originalTransactionId, product id, refund state)7 yearsTax, accounting, and fraud-prevention legal obligations.
Telemetry events90 days (GameAnalytics retention)Aggregate measurement only.
Crash reports90 days (Firebase Crashlytics default)Bug triage.
Server access log30 daysSecurity investigation.
Audit log of account access / deletionIndefinite (anonymized after account deletion)Security forensics + DSAR audit trail.

8. Your rights (GDPR Chapter III)

You have the following rights at no cost. We answer within 30 days of receiving a valid request (extendable to 90 days for complex cases per Art. 12(3)).

RightHow to exercise
Access (Art. 15)Settings → Account → Download my data. Returns td-account-export-<date>.json. Full procedure in the DSAR Procedure.
Rectification (Art. 16)Settings → Account → edit display name, language, consent. For other corrections, contact privacy@arcaneduck.com.
Erasure (Art. 17)Settings → Account → Delete my account. Cascade cleans players, sessions, cloud save, and entitlements. Retention exceptions in the Account Deletion Policy.
Restriction (Art. 18)Email privacy@arcaneduck.com. We freeze processing within 7 days.
Portability (Art. 20)Same as Access — exported JSON is portable.
Object (Art. 21)Settings → Privacy → Share analytics toggle (revokes consent — Art. 7(3)). Email for legitimate-interest objections (logs / fraud detection).
Lodge a complaint (Art. 77)Contact your national Data Protection Authority. List at edpb.europa.eu/about-edpb/board/members_en.

9. Consent (analytics + crash reporting)

On first launch in the EU, the analytics consent toggle defaults to OFF. We only send data to GameAnalytics or Firebase Crashlytics after you set the toggle to ON in Settings → Privacy → Share analytics.

You can withdraw consent at any time. Withdrawal does not affect data we already processed lawfully before withdrawal (GDPR Art. 7(3)).

EU detection method: Accept-Language header on first launch.

10. Children

The Service is rated 4+ on the App Store. We do not knowingly collect data from children under 13 (US — COPPA) or under 16 in the EU (GDPR Art. 8 — "GDPR-K"). Full age policy and parental contact procedure in the Age Rating, COPPA & GDPR-K Policy.

If you believe we have collected data from a child without verifiable parental consent, contact privacy@arcaneduck.com and we will delete it within 30 days.

11. Security

We disclose security breaches affecting EU residents to the lead supervisory authority within 72 hours (GDPR Art. 33).

12. Apple ATT (App Tracking Transparency)

We do not track you across apps or websites owned by other companies. The App Privacy manifest declares NSPrivacyTracking=false. The ATT prompt is therefore not required and not shown.

If we ever add a tracking SDK, we will show the ATT prompt and update this policy before that SDK ships.

13. Refunds

See the Refund Policy. Apple is the merchant of record for all In-App Purchases; refund requests go through Apple. We honor Apple's refund decisions and revoke entitlements automatically via App Store Server Notifications.

14. EU Digital Services Act (DSA)

Our DSA single point of contact for authorities and users is published in the EU Digital Services Act Contact Point. It satisfies DSA Art. 11 (authorities) and Art. 12 (users).

15. Changes to this policy

We notify users of material changes by:

  1. Updating the Last updated date at the top of this file.
  2. Publishing the new policy at the hosted Privacy URL: https://arcaneduck.com/legal/privacy.
  3. Showing an in-app notice on next launch if the change is material (e.g., new processor, new data category).

Minor edits (typo fixes, link updates) do not trigger an in-app notice.

16. Contact

For any privacy question or to exercise any right above, contact:

For DSA-specific requests, see the EU Digital Services Act Contact Point. For DSAR-specific procedure, see the DSAR Procedure.