Privacy Policy — Astro Cat (TowerRush)

Version 2.0 · Effective date: 16 July 2026 · Applies to: Android

§1. Data Controller

The data controller is Marcin Wawrzyniak, contact: marcin.wawrzyniak@devpartner.pl, website: devpartner.pl. The full policy is hosted at devpartner.pl/privacy-policy-game.html (Polish version: devpartner.pl/polityka-prywatnosci-gry.html).

§2. What Data We Collect

CategoryDataSourceRequired?
Player nicknameText entered by the userUserNo
Game resultsRecords, stats, achievements, starsAppYes (needed for the game to function)
Duel codesString containing the round's seed and scoreUser / appNo
Notification settingsChannel togglesUserNo
Push tokenDevice identifier used to deliver notifications (Expo Push Token)OSIf notifications are enabled
Advertising IDAnonymous Google Play Services identifierOS (via the Google AdMob SDK)Yes — required to display ads
IP addressProcessed briefly for abuse prevention (rate-limiting) on the duel/leaderboard serverAutomaticYes (service security)
Diagnostic dataAnonymous crash/error reports (Expo SDK)AutomaticYes
Purchase data (IAP)Purchase confirmation and product ID — no card dataGoogle Play BillingOnly on purchase

We do not collect: email addresses, phone numbers, location data, biometric data, lists of installed apps, or microphone/camera data.

§3. Purpose and Legal Basis (GDPR Article 6)

§4. Data Sharing

User data is not sold to third parties for marketing purposes. Data is shared only to the extent necessary for the functions below:

Data may only be disclosed where required by law or to protect rights and safety.

§5. Expo SDK — Diagnostics and Updates

The app is built on Expo SDK 54 and sends anonymized crash reports to Expo's servers. These include device type, OS version, app version, and error stack traces — with no ability to identify the user. The app also fetches over-the-air (OTA) updates from Expo's servers, which involves sending basic device and app-version information needed to select the correct update.

Data transfers to the USA rely on Standard Contractual Clauses under GDPR Chapter V.

§6. Locally Stored Data

Game progress, achievements, stats, player nickname, and notification settings are stored exclusively locally on the device (app storage / AsyncStorage). This data is never synchronized externally, is inaccessible to the controller, and is permanently deleted when the app is uninstalled.

Exception — data related to duels and the global leaderboard (nickname, score, push token, duel codes) does leave the device and is processed on the controller's server, as described in §7.

§7. Duels and Global Leaderboard — Controller's Server

The "Challenges" (friend duels) and "Ranking" (global leaderboard) features require a server, since they connect different players. The server (towerrush.devpartner.pl), operated by the controller, stores:

Unclaimed duels are automatically deleted after a set period (a recurring cleanup job). Communication with the server uses HTTPS with API-key authentication.

§8. Push Notifications

The app sends two kinds of notifications:

Users can disable notifications at any time in the app or system settings — the token then stops being used for delivery.

§9. Advertising (Google AdMob)

The app displays ads (banner, rewarded video, and rewarded interstitial ads) via Google AdMob (Google Mobile Ads SDK). This relies on the device's advertising identifier (Advertising ID) and, once consent is given, ad-personalization data.

For users in the European Economic Area (including Poland), the app shows an IAB-standard consent form (UMP — User Messaging Platform) before the first ad is shown, allowing a choice between personalized and non-personalized ads and the ability to withdraw consent at any time.

Ads may be served by Google and by partners within Google AdMob's mediation network. Users can also restrict ad personalization in Android system settings (Settings → Google → Ads → "Opt out of Ads Personalization"), independently of the in-app consent choice.

§10. In-App Purchases

The app offers an optional, one-time "Premium" purchase that removes full-screen and banner ads and unlocks additional platform color themes. Rewarded ads (optional, watched voluntarily in exchange for in-game bonuses) remain available even after purchasing Premium.

All transactions are processed by Google LLC via Google Play Billing. The controller has no access to payment card or other financial data — only a purchase confirmation and product ID are received, used to unlock the corresponding feature in the app. Google's policy: policies.google.com/privacy

§11. User Rights (GDPR)

Users in the EEA have the right to:

To exercise these rights, contact the controller at the address given in §1.

§12. Children

Astro Cat is intended for users aged 16 and older. The controller does not knowingly collect data from users under 16. Parents or guardians who suspect a minor has submitted data are asked to contact the controller for prompt deletion.

§13. Data Retention and Deletion

Data typeRetention periodDeletion method
Game data (local)Until uninstall or manual clearingUninstall / Settings → Apps → Clear data
Nickname and score on the leaderboard serverUntil deletion is requestedContact the controller (§1)
Unclaimed duels on the serverDeleted automatically after a set periodAutomatic (recurring job)
Push tokenUntil uninstall or notifications are disabledDisable notifications in settings
IP address (rate-limiting)Up to 60 secondsAutomatic expiry
Diagnostic dataPer Expo's policyContact Expo Platform, Inc.

§14. Data Security

The controller applies technical and organizational safeguards:

No system can guarantee absolute security; in the event of a data breach, the controller will take the legally required action.

§15. Policy Updates

The controller may update this policy alongside app updates (noted in the release notes) or by changing the effective date above. Continued use of the app constitutes acceptance of the revised terms.

§16. Contact

Controller: Marcin Wawrzyniak
Email: marcin.wawrzyniak@devpartner.pl
Website: devpartner.pl
Response time: up to 30 days (GDPR Article 12(3))