English Primary version
This policy explains how Realmfall.io ("Realmfall", "we", "us") handles information when you use the Realmfall web game, Android application, game servers, community tools, and support channels.
1. Information we handle
Account and sign-in data
A local Realmfall account uses an account name and a salted, one-way password verification hash. When you choose Google sign-in, we receive and store Google's stable provider user ID, your Google display name, email address, and whether Google reports that email as verified. Realmfall never receives your Google password.
Game identity and progress
We process your run nickname, permanent tagged account handle or player identifier, selected cosmetics, inventory, currencies, progression, upgrades, quests, match and run statistics, clan information, and multiplayer state. Your nickname, tagged handle, clan, and relevant live-game state may be visible to other players.
Chat, reports, and moderation
Local and clan chat is delivered to the relevant players and kept in bounded live-room history. When a message or player is reported, the report can include the reason, reporter and target identifiers, room or channel context, IP evidence, and both the filtered and original reported message so moderators can review what happened.
Connection and device information
We process IP addresses, connection and last-seen times, session identifiers, ban and moderation records, and limited technical or performance diagnostics to operate the multiplayer service, secure accounts, prevent abuse, and investigate faults. Language, controls, audio, chat-display, muted-player, and similar preferences may remain on your device or in browser storage.
2. How we use information
We use the information above to:
- create and authenticate accounts and preserve progress across sessions;
- provide matchmaking, multiplayer worlds, clans, chat, invites, and leaderboards;
- operate purchases made with in-game currency, cosmetics, rewards, and progression;
- filter abusive chat, investigate player reports, enforce bans, and prevent fraud;
- diagnose outages, security incidents, crashes, hangs, and performance problems; and
- show advertising at the placements described below only when enabled and permitted by the applicable privacy flow; and
- deliver verified game-content updates and check rewarded-ad transactions to prevent duplicate or fraudulent rewards.
3. Advertising and privacy choices
Administrators can disable all advertising or individual Android formats. When enabled, the web lobby may use Google AdSense and Android may use Google AdMob. Android banners appear only in the lobby and are hidden while menus or dialogs cover it. Interstitial ads may appear when returning to the lobby after a completed game. App-open ads are limited to the startup loading screen, skip the first two launches, and are skipped if they are not ready before that loading window ends. Realmfall does not request or show ads during active combat. The web client also suppresses AdSense for signed-in accounts and during authentication transitions.
Rewarded ads and rewarded interstitial ads are optional. Before either format begins, a screen explains the reward and lets you choose to watch or skip. Completing an eligible live ad offers 50 in-game gold, subject to server verification, a 120-second interval and a maximum of 10 rewards per day. Test ads do not award real gold. For verification, the application sends a pseudonymous Realmfall profile identifier and a signed, one-time challenge through AdMob. Our server checks Google's signed callback, including the ad-unit, timestamp, transaction identifier and challenge, before adding the reward. Reward receipts and daily-limit records are stored with the game profile to prevent repeat claims; your Realmfall password or sign-in token is not included in this ad-verification data.
According to Google's Mobile Ads SDK disclosure, the SDK can automatically collect and share IP address (which can be used to estimate approximate location), user or product interactions such as app launches and taps, diagnostic information such as performance and hang data, and device or account identifiers such as the Android advertising ID and app-set ID. Google describes the purposes as advertising, analytics, and fraud prevention. These transmissions occur under Google's terms and privacy practices when its ad services are in use; Realmfall does not receive your Google advertising-account password.
On Android, Google User Messaging Platform (UMP) checks whether a privacy message or a privacy-options entry point is required and whether an ad request is permitted. When the live privacy check cannot authorize an ad request, Realmfall does not request a live Android ad. If Google reports that a privacy-options entry point is required, it appears in the game's Options menu. A Google privacy message may also be used for web ads when configured in the publisher account. The Android integration requests a Teen maximum ad-content rating; this is an ad-content setting, not an age check.
Provider details: Google Mobile Ads SDK data disclosure, Google UMP privacy guidance, Google Privacy Policy, and How Google uses data from partner sites and apps.
Signed game-content updates
When automatic content updates are enabled by an administrator, the Android application checks for a compatible release during startup and may download game web-content files over HTTPS. It verifies the release signature, archive size and integrity before use. If verification or activation fails, the application can continue with its bundled or previously working content. This mechanism does not download APKs or replace native application code, Android permissions or advertising SDKs; those changes require an application update through the store. Downloaded content and update-version information are kept in the application's local storage.
4. Sharing and public visibility
Realmfall does not sell your account credentials or game profile. We disclose information only as needed to operate the service: public game identity and live state to other players; report evidence to authorized moderators and administrators; infrastructure data to hosting and technical service providers; and advertising data to Google when those services are enabled. We may also preserve or disclose limited information when reasonably necessary to comply with law, protect users, investigate fraud, or defend the service.
5. Storage and retention
Account, progression, inventory, reward receipts, and moderation status remain while the account is active or until they are deleted through the support process. Unreported chat history is bounded and exists only in the active game-room session. A submitted moderation report, including its evidence and audit trail, is configured to be retained for no more than 180 days. Security records needed for an active ban, fraud investigation, dispute, or legal obligation may be retained only for as long as that purpose requires. Operational backups may retain a residual copy for a limited rotation period before overwrite.
6. Account deletion and other requests
Use the in-game Delete account link or visit the account deletion request page. The current process is a manual support request; opening the page or email link does not instantly or automatically delete an account. Support must safely verify ownership without asking you to email a password or session token. After verification, the target is to complete deletion within 30 days. Limited security or legal records may remain where retention is necessary, and support can explain the applicable scope. Deleting Realmfall data does not delete your Google Account.
You may also ask to access or correct account information by emailing emre155tk@gmail.com with your permanent tagged game handle. Never send your Realmfall password, Google password, authorization code, or session token by email.
7. Children
Realmfall is not directed to children under 13. We do not ask for age or date of birth and do not use an age gate. If you are a parent or guardian and believe a child has submitted personal information, contact support so the report can be reviewed and appropriate deletion steps can be taken.
8. Security, changes, and contact
We use HTTPS in production, signed short-lived authentication state, restricted moderation access, and salted password verification hashes. No online service can promise absolute security. We may update this policy when the game's features, service providers, or legal obligations change; the date at the top will be updated.
Privacy, support, and deletion contact: emre155tk@gmail.com. Community conduct is covered by the Community Guidelines.