Spiky Sweeper — Privacy Policy

FieldValue
Version1.0.0
Effective date2026-06-14
Last updated2026-07-16
OperatorPraserGames LLC (the "Operator", "we", "us")
ProductSpiky Sweeper (the "App"), a grid-logic puzzle racing game distributed via the Google Play Store

1. Summary

Spiky Sweeper is a competitive grid-logic puzzle game in which you race a pre-recorded run of another player on the same puzzle. This policy explains what data the App collects, why, who we share it with, how long we keep it, and your rights.

The App is anonymous-first. You can install and play without an account and without giving us a name, email address, or any other personally identifying information. Your default identity is an opaque, device-bound anonymous account. You may optionally upgrade to Google sign-in to preserve your progress. Sign-in is handled by Firebase Authentication, which holds the link between your Google account and your account here so it can keep you signed in; we do not copy your email address or Google profile data into our game database, and we do not use them for anything beyond signing you in (see Section 4).

We do not sell your data, show ads, build advertising profiles, or offer in-app purchases.


2. Data We Collect

2.1 Stored only on your device

The following stays on your device so the App works offline and across restarts, and is not sent to us:

2.2 Stored on our servers (Google Firebase / Cloud Firestore)

We do not collect your real name, email address, phone number, precise location, contacts, photos, advertising identifiers, or persistent device or advertising IDs, and we do not use device data to track or profile you.

2.3 Community-visible content (replays and display name)

Some content you create is, by design, visible to other players:

Non-canonical replays are kept for your own re-watch history and future integrity validation but are not served to other players.


3. How We Use Data

We use the data above only to:


4. Third-Party Processors

We use the following service providers ("processors"), each processing data on our behalf under its own data-processing terms:

ProcessorPurposeData processedTerms
Google Firebase (Cloud Firestore, Firebase Authentication, Firebase App Check) — Google LLC / Google Ireland Ltd.Anonymous identity, backend storage (replays, ratings, match records), and device-integrity attestation.Opaque account identifier, display name, replays, ratings, match records, attestation tokens.firebase.google.com/terms/data-processing-terms
Google Firebase Crashlytics — Google LLC / Google Ireland Ltd.Client-side crash reporting.Technical crash metadata and opaque identifiers only; personal fields are scrubbed on your device before sending (Section 4.1).firebase.google.com/terms/data-processing-terms
Google Play Integrity API — Google LLC.Device-integrity attestation.Attestation verdict / token; no game content.cloud.google.com/terms/data-processing-addendum
Sentry — Functional Software, Inc. (dba Sentry).Server-side error reporting.Technical error metadata and opaque identifiers only (Section 4.1).sentry.io/legal/dpa

4.1 Crash and error reporting (required; no opt-out)

Crash and error reports are required app-functionality data — we rely on them to keep the App stable — so they cannot be turned off. This is declared as required app-functionality data in the Google Play Console Data Safety form. Reports auto-delete from our diagnostics processors within approximately 90 days.

Before any report leaves your device it is scrubbed so it retains only opaque identifiers and technical metadata (such as your opaque account identifier, the opaque puzzle identifier, difficulty, match phase, match identifier, the result code, the rating snapshot, and diagnostic stack fields). Authentication tokens, attestation tokens, display names, and any email-shaped values are stripped on your device and never reach either processor. IP addresses are not included in report payloads, and we configure our diagnostics processors not to store them.


5. Data Retention and Deletion

We keep server-side data for as long as your account exists, except crash and error reports, which our processors auto-delete within approximately 90 days (Section 4.1).

Data is encrypted in transit (HTTPS/TLS). Our infrastructure providers process your device's IP address transiently to route requests and guard against abuse; we do not store it or use it to identify you.

5.1 Account deletion

You can delete your account from in-app settings. The purge begins immediately when you request it and completes promptly, removing your player record, all canonical and non-canonical replays, your rating history, match records, queued submissions, abuse-prevention counters, consent record, and display-name claim. You can also request deletion without opening the App, at https://spikysweeper.prasergames.com/delete-account. Any deletion request made by other means is completed within 30 days. Our deletion process acts only on the authenticated account — it accepts no other-account input and cannot delete anyone else's data. Once your display-name claim is released, the name returns to the pool.

Anonymized aggregate data that identifies no one may be retained. Deleting your account does not un-serve replays already downloaded and cached on another player's device during an earlier match; those local copies expire under that device's caching.


6. Breach Notification

If we become aware of a personal-data breach likely to create a risk to your rights, we will notify the relevant supervisory authority within the timeframes required by law (for example, within 72 hours where the GDPR applies) and notify affected players without undue delay where the law requires it, using in-app or public notice because the App's anonymous-first design means we hold no direct contact details for you.


7. Changes to This Policy

We may update this policy. Each version carries a version number, an effective date, and a last-updated date (see the header), and substantive changes are recorded in the Changelog and announced in-app or on our site. The current version is always available from in-app settings and the Play Store listing.

Before you can play, the App requires you to explicitly accept the current Privacy Policy and Terms of Service; access is blocked until you do. When a substantive change raises the required policy version, you must explicitly accept the updated policy to keep playing. Acceptance is an affirmative action you take — it is never implied by your continued use of the App.


8. Children's Privacy

Spiky Sweeper is intended for adults and is not directed to anyone under 18. The App is anonymous-first and requires no personal information to play, and we do not knowingly permit its use by, or collect personal information from, anyone under 18. If you believe someone under 18 has provided us personal information, contact us (Section 11) and we will delete it.


9. Your Rights

Depending on where you live, you may have some or all of the rights below. Because anonymous accounts are not tied to any contact information, we may need enough information to locate the specific account (for example, your in-app account identifier) to act on a request, and we may be unable to verify a request we cannot tie to an account.

9.1 EU/UK GDPR (Articles 15–22)

You may also lodge a complaint with your local data-protection authority.

9.2 CCPA/CPRA (California residents)

To exercise any right, use in-app account deletion where applicable (Section 5.1) or contact us (Section 11).


10. Governing Law

This policy and any dispute relating to it are governed by the laws of the State of New Jersey, United States, without regard to its conflict-of-laws provisions, except where mandatory consumer-protection or data-protection law in your place of residence applies. Nothing here deprives you of the protection of mandatory provisions of the law of your country of residence.


11. Contact

For privacy questions, requests, or to exercise your rights, contact the Operator:


Changelog

VersionDateSummary
1.0.02026-07-16Aligned Section 8 to an adults-only (18+) audience, matching the Google Play 18+ target-audience selection and the Terms Section 2 minimum age. This keeps the App outside child and teen data-protection regimes (COPPA, the UK Age-Appropriate Design Code, and comparable teen-privacy laws). No change to the data we collect, how we use it, retention, deletion, or your rights — only the stated minimum age. Version held at 1.0.0 (pre-public alignment; no consent-version bump — ADR-0028).
1.0.02026-07-14Moved the web account-deletion URL to the brand domain https://spikysweeper.prasergames.com/delete-account, matching the in-app links and hosted site now that the brand domain is live (it is a CNAME to the same hosting; the prior web.app URL still resolves). URL canonicalization only — no change to the data we collect, how we use it, retention, deletion, or your rights. Version unchanged (1.0.0).
1.0.02026-07-13Accuracy and plain-language pass so the policy describes the shipped v1 product exactly. Removed descriptions of features cut from v1 before launch and never shipped — the daily challenge and its leaderboard, and push notifications and the associated Firebase Cloud Messaging push token — because the App collects none of that data; described the active per-difficulty ratings; disclosed the PII-free consent record and the opaque Google sign-in link. Precision corrections so no statement over-claims: the email/Google-profile statement now says that data is not copied into our game database (Firebase Authentication holds the sign-in link); IP addresses are "not stored" rather than "never reach" the diagnostics processors; the "device fingerprints" line now targets persistent device/advertising IDs and tracking; crash-report retention reads "approximately 90 days"; breach notice separates the authority deadline from player notice; and the automated-decisions section acknowledges automated anti-cheat with a human-review route. Added the web account-deletion route and an encryption-in-transit statement. These edits only narrow, clarify, or add user-favorable detail; they do not expand the data we collect and do not change how we use it, retention, or your rights. Version unchanged (1.0.0).
1.0.02026-06-22Aligned the acceptance framing in Section 7 with the App's explicit-acceptance consent gate: acceptance is an affirmative action you take before you can play, never implied by continued use. Framing/wording alignment only; no change to the data we collect, how we use it, retention, deletion, or your rights.
1.0.02026-06-14Initial published policy. Establishes anonymous-first data model, local vs server-side data split, community-visible replay surface, required client-scrubbed crash/error reporting with 90-day retention, immediate in-app account deletion (30-day outer bound for other requests), GDPR/CCPA rights, New Jersey governing law, and versioning convention.