Legal Architecture

Privacypolicy

Compliant with 2026 App Store & Google Play Data Safety Mandates.
Effective Date: June 12, 2026

01Core Philosophy

This Privacy Policy governs the mobile application ecosystem operating under the project domain ("Game"), engineered and published by sandokae ("we", "us", or "our"). Our target architecture is built for global thinkers across North America, East Asia, and worldwide. We deploy data minimization practices; we do not sell your personal data under any jurisdiction.

02Data Safety Matrix

To ensure full alignment with iOS App Privacy declarations and Android 16 (API 36) Data Safety guidelines, the grid below explicitly catalogs what we sync, process, and protect:

Data CategoryIdentity / Account
User ScopeSocial Auth Only
AttributesEmail Address, Nickname
TreatmentSecure cross-device profile syncing & leaderboard indexing via Supabase identity pipeline.
Data CategoryDevice Diagnostics
User ScopeAll Users
AttributesDevice ID, Model, Country Code
TreatmentGeographic ranking sorting and telemetry configuration validation.
Data CategoryGameplay Analytics
User ScopeAll Users
AttributesDifficulty Metrics, Counter Telemetry, Exit Signals
TreatmentAggregated difficulty load balancing and gameplay tuning. Includes tracking structural application states.
Data CategoryFinancial / Purchase
User ScopeAll Users
AttributesTransaction Receipts, Entitlements
TreatmentSecure subscription and permanent item entitlement handling via RevenueCat SDK. We do not store financial credentials.

03Infrastructure

We run a multi-layered sandboxed storage model to maximize digital sovereign security:

  • Local Sandbox (SQLite)For Guest Mode states, all puzzle states, local parameters, and historical markers are kept isolated within your localized sandbox database.
  • Server Isolation (Supabase)Remote tables operate under strict Row Level Security (RLS). Direct client database hooks are completely severed; transaction validation occurs exclusively through cryptographically pinned remote procedures.
  • Ad Ecosystem & IdentifiersWe display restricted standard banners and reward ad sequences. Third-party ad networks may read mobile tracking tokens (IDFA/GAID) solely for programmatic fraud check compliance and rate-limiting capping.

04In-App Commerce

Digital commerce interactions (such as acquiring game currency credits or purchasing permanent Ad-Free passes) are processed through native App Store / Google Play billing protocols. Tokenization and validation mechanics are streamlined strictly using the RevenueCat SDK pipeline. No raw financial data or billing credentials hit sandokae servers.

05Jurisdictional Protection

Depending on where you play, you hold absolute rights over your telemetry data under regional framework legislation (including CCPA, GDPR, and respective East Asian Personal Information Protection acts):

  • You have the right to request deletion of your synced cloud ledger.
  • You can request a copy of the specific parameter values mapped to your device.

To trigger an absolute data elimination pipeline, invoke the purge function inside the game parameters panel or contact our verification handle directly.

06Governance

For security compliance verifications, data access demands, or architecture suggestions, direct your inquiries to our encrypted support line:

[email protected]