Deck games collection

Privacy Policy

Deck has no accounts and asks for nothing about you. It sends no data at all until you say yes, and everything it may send is listed on this page by name. You can say no and keep playing: nothing in the app is locked behind that answer.

Who is responsible

TODO: имя владельца как в документах — оно попадёт в App Store ЕС по DSA, TODO: страна резидентства владельца (TODO: почтовый адрес для DSA и для обращений; домашний адрес будет опубликован Apple в ЕС) is the controller of the data described here. Questions about this policy: privacy@deckgames.app.

Representative in the European Union under Article 27 GDPR: TODO: представитель в ЕС по ст. 27 GDPR — имя, адрес, почта; нужен, пока контроллер вне ЕС.

What never leaves your phone

Deck is built to work offline. The following is stored on your device and is not sent to us:

There is one exception, and it is your own doing: the report sheet described below.

What is sent, and only after you agree

At the end of onboarding, Deck asks two separate questions: may it send usage events, and may it send crash reports. Until you answer, no analytics or crash SDK is switched on and nothing is sent. If you decline, the queue held on the device is erased. You can change both answers at any time in Settings, Data.

Usage events

Each event carries the app version, the build environment (dev or prod) and the interface language, and nothing else about you. The complete list of events Deck can send, with the question each one answers:

EventWhat it tells us
app_launchedhow often the app is opened, and from where
screen_shownwhich screens are used and in what order
onboarding_completedwhether people finish the introduction or skip it
consent_answeredhow many people allow analytics and crash reports
game_openedwhich games are opened
round_startedwhich games are actually played, at which level
round_endedhow rounds end: won, lost, abandoned
round_resumedwhether people come back to an unfinished round
round_milestone_reachedhow far into a round people get before leaving
rules_shownwhether the rules are read, and whether they were asked for
animation_completedwhether animations are watched to the end
animation_skippedwhich animations are skipped, and how early
daily_openedwhether the daily task is used
setting_changedwhich settings people change
report_senthow often the report sheet is used
experiment_exposedwhich variant of a trial a device was given
error_recordedthat an error occurred, on which screen, with a reproduction string
paywall_shownwhich gate led to the subscription screen
subscription_purchasedwhich subscription was bought
purchase_failedwhy a purchase did not go through
subscription_restoredthat a subscription was restored on a device
limit_reachedwhich free limit people hit

Raw taps, card movements and the contents of your games are not part of any event.

Device properties

Alongside the events, the following properties are attached to the device record:

Identifiers

Deck creates no identifier of its own and has no accounts. The analytics tools generate their own device identifiers (an Amplitude device ID, a Firebase app instance ID). They identify a device, not a person, and they are reset when you withdraw consent.

Crash reports

If you allow them, a crash sends the technical circumstances of the failure: device model, operating system version, app version, and the stack of the code that failed. Crash reports are handled by Firebase Crashlytics.

Purchases

When you buy or restore a subscription, the app records that it happened and which product it was. Payment itself is handled entirely by Apple or Google: we never see your card, your name or your billing address.

Reports you send yourself

Taking a screenshot inside Deck opens a report sheet. If you choose to send it, your own mail app opens with the screenshot and, if you leave the switch on, the session log attached. Nothing is sent until you press send in your mail app, and your message reaches us as ordinary email at support@deckgames.app.

Why we are allowed to do this

Our legal basis is your consent (Article 6(1)(a) GDPR). You may withdraw it at any moment in Settings, Data. Withdrawal stops the collection, resets the identifiers on the device, and does not affect the lawfulness of what happened before it.

Who else sees this data

RecipientWhat forWhere
Amplitude, Inc.product analyticsUnited States
Google (Firebase Analytics, Crashlytics, Remote Config)crash reports, trials, analyticsUnited States and other Google regions
Apple, Google Playthe sale of subscriptions, on their own termstheir own regions

Both analytics providers act as our processors under a data processing agreement, and transfers outside the European Economic Area rely on the European Commission's standard contractual clauses. We do not sell data, we do not share it for advertising, there are no advertising SDKs in Deck, and no data is used to build profiles for third parties.

How long it is kept

Event and crash data is kept for 14 months and then deleted by the analytics providers on a rolling basis. Email you send us is kept as long as the conversation is useful, and no longer than three years.

Your rights

If the GDPR or the UK GDPR applies to you, you have the right of access, rectification, erasure, restriction, portability, and the right to object, as well as the right to complain to your national supervisory authority. Because Deck has no accounts, we usually cannot connect any record to a named person; to act on a request about analytics data we need the device identifier, which is why Delete my data below explains what to send us.

Children

Deck is not directed at children. You must be at least 13 to use it, and at least 16 in countries where consent to data processing requires that age, unless a parent or guardian agrees on your behalf. We do not knowingly collect data from children below those ages; if you believe we have, write to privacy@deckgames.app and we will delete it.

California

We do not sell or share personal information as those terms are used in the CCPA, and we have not done so in the preceding twelve months. California residents may exercise the rights described above through the same address.

Russia

TODO: если владелец резидент РФ — реквизиты оператора персональных данных и номер уведомления РКН

Changes

When this policy changes we update the date at the bottom of the page and, if the change affects what we collect or why, we ask for your consent again inside the app. The previous versions of this page live in the project's version history.

Contact

privacy@deckgames.app · TODO: имя владельца как в документах — оно попадёт в App Store ЕС по DSA, TODO: почтовый адрес для DSA и для обращений; домашний адрес будет опубликован Apple в ЕС


Delete my data

Deck has no accounts. Your games, your history and your progress live on your phone and were never sent to us — deleting the app deletes them, and nobody, including us, can recover them.

The only data we ever hold is what you allowed us to collect: usage events and crash reports, listed one by one above.

Stop the collection

Open Settings, then Data. Turn off "Usage events", or "Crash reports", or both.

Turning them off stops the sending immediately and resets the identifiers the analytics tools created on the device. From that moment nothing new is added to the record, and what was already collected expires by itself after 14 months.

Delete what was already collected

Write to privacy@deckgames.app from any address and say that you want your analytics data deleted.

Because there are no accounts, we cannot look up a person: the record belongs to a device identifier, not to a name. In our reply we will tell you exactly what we need in order to find your device's record, and we will delete it and confirm when it is gone. We answer within 24 hours and complete deletion requests within thirty days.

Delete everything on the device

Delete the app. On iOS you can also remove its data through Settings, General, iPhone Storage, Deck. Nothing of it stays behind on our side, because nothing of it was ever there.

Email you have sent us

If you wrote to support, that correspondence sits in an ordinary mailbox. Ask us to delete it and we will, unless we are required to keep it — for example, while a payment dispute is open.