The data controller is Marcin Wawrzyniak, contact: marcin.wawrzyniak@devpartner.pl, website: devpartner.pl. The full policy is hosted at devpartner.pl/privacy-policy-game.html (Polish version: devpartner.pl/polityka-prywatnosci-gry.html).
| Category | Data | Source | Required? |
|---|---|---|---|
| Player nickname | Text entered by the user | User | No |
| Game results | Records, stats, achievements, stars | App | Yes (needed for the game to function) |
| Duel codes | String containing the round's seed and score | User / app | No |
| Notification settings | Channel toggles | User | No |
| Push token | Device identifier used to deliver notifications (Expo Push Token) | OS | If notifications are enabled |
| Advertising ID | Anonymous Google Play Services identifier | OS (via the Google AdMob SDK) | Yes — required to display ads |
| IP address | Processed briefly for abuse prevention (rate-limiting) on the duel/leaderboard server | Automatic | Yes (service security) |
| Diagnostic data | Anonymous crash/error reports (Expo SDK) | Automatic | Yes |
| Purchase data (IAP) | Purchase confirmation and product ID — no card data | Google Play Billing | Only on purchase |
We do not collect: email addresses, phone numbers, location data, biometric data, lists of installed apps, or microphone/camera data.
User data is not sold to third parties for marketing purposes. Data is shared only to the extent necessary for the functions below:
Data may only be disclosed where required by law or to protect rights and safety.
The app is built on Expo SDK 54 and sends anonymized crash reports to Expo's servers. These include device type, OS version, app version, and error stack traces — with no ability to identify the user. The app also fetches over-the-air (OTA) updates from Expo's servers, which involves sending basic device and app-version information needed to select the correct update.
Data transfers to the USA rely on Standard Contractual Clauses under GDPR Chapter V.
Game progress, achievements, stats, player nickname, and notification settings are stored exclusively locally on the device (app storage / AsyncStorage). This data is never synchronized externally, is inaccessible to the controller, and is permanently deleted when the app is uninstalled.
Exception — data related to duels and the global leaderboard (nickname, score, push token, duel codes) does leave the device and is processed on the controller's server, as described in §7.
The "Challenges" (friend duels) and "Ranking" (global leaderboard) features require a server, since they connect different players. The server (towerrush.devpartner.pl), operated by the controller, stores:
Unclaimed duels are automatically deleted after a set period (a recurring cleanup job). Communication with the server uses HTTPS with API-key authentication.
The app sends two kinds of notifications:
Users can disable notifications at any time in the app or system settings — the token then stops being used for delivery.
The app displays ads (banner, rewarded video, and rewarded interstitial ads) via Google AdMob (Google Mobile Ads SDK). This relies on the device's advertising identifier (Advertising ID) and, once consent is given, ad-personalization data.
For users in the European Economic Area (including Poland), the app shows an IAB-standard consent form (UMP — User Messaging Platform) before the first ad is shown, allowing a choice between personalized and non-personalized ads and the ability to withdraw consent at any time.
Ads may be served by Google and by partners within Google AdMob's mediation network. Users can also restrict ad personalization in Android system settings (Settings → Google → Ads → "Opt out of Ads Personalization"), independently of the in-app consent choice.
The app offers an optional, one-time "Premium" purchase that removes full-screen and banner ads and unlocks additional platform color themes. Rewarded ads (optional, watched voluntarily in exchange for in-game bonuses) remain available even after purchasing Premium.
All transactions are processed by Google LLC via Google Play Billing. The controller has no access to payment card or other financial data — only a purchase confirmation and product ID are received, used to unlock the corresponding feature in the app. Google's policy: policies.google.com/privacy
Users in the EEA have the right to:
To exercise these rights, contact the controller at the address given in §1.
Astro Cat is intended for users aged 16 and older. The controller does not knowingly collect data from users under 16. Parents or guardians who suspect a minor has submitted data are asked to contact the controller for prompt deletion.
| Data type | Retention period | Deletion method |
|---|---|---|
| Game data (local) | Until uninstall or manual clearing | Uninstall / Settings → Apps → Clear data |
| Nickname and score on the leaderboard server | Until deletion is requested | Contact the controller (§1) |
| Unclaimed duels on the server | Deleted automatically after a set period | Automatic (recurring job) |
| Push token | Until uninstall or notifications are disabled | Disable notifications in settings |
| IP address (rate-limiting) | Up to 60 seconds | Automatic expiry |
| Diagnostic data | Per Expo's policy | Contact Expo Platform, Inc. |
The controller applies technical and organizational safeguards:
No system can guarantee absolute security; in the event of a data breach, the controller will take the legally required action.
The controller may update this policy alongside app updates (noted in the release notes) or by changing the effective date above. Continued use of the app constitutes acceptance of the revised terms.
Controller: Marcin Wawrzyniak
Email: marcin.wawrzyniak@devpartner.pl
Website: devpartner.pl
Response time: up to 30 days (GDPR Article 12(3))