Who this policy covers.
This policy covers the Pile Raid mobile application and this public website. The publisher of Pile Raid is the data controller for account and gameplay information. The approved operator legal name, postal address, jurisdiction and privacy contact must be inserted into the public runtime configuration before public account creation is enabled.
The current public website does not set advertising or analytics cookies. Essential browser requests may still include ordinary connection information, such as an IP address, to the hosting provider. Secure account actions use Firebase Authentication. The web support form creates a temporary anonymous Firebase session, keeps its token only in session storage for safe retry, and asks Firebase to remove that temporary identity after a confirmed ticket. The web deletion flow keeps only a random private deletion request ID in browser local storage for at most 30 days; it never stores the account password or Firebase ID token.
Information Pile Raid uses.
| Category | Examples | Source |
|---|---|---|
| Account & authentication | Firebase UID, email, display name, profile photo URL, provider type, email-verification and anonymous-account state. | You, Firebase Authentication, and Google or Apple only when you choose and the provider is enabled. |
| Age band & family state | The age range selected in a neutral age screen, plus adult-action or parental-control state where required. Pile Raid should not request a full birth date merely to choose an age band. | You or a parent/guardian. |
| Profile & social | Username, avatar, country code, friends, invitations, blocks, public profile fields and safety reports. | You, other players interacting with you, and server-authoritative game services. |
| Gameplay & competition | Match membership, format, moves, public table state, private hand, results, rating, leaderboard projections, achievements, forfeits and anti-cheat provenance. | Your play and the Pile Raid game server. |
| Progress & virtual economy | Coins, Diamonds when provider purchases are enabled, XP, level, inventory, equipped cosmetics, rewards, transaction commands and exact-once ledger records. | Verified gameplay and, only when enabled, Apple or Google purchase verification. |
| Security & operations | Session timestamps, Firebase App Check signals, rate-limit counters, abuse events, request IDs, server errors and deletion receipts without passwords or secret card state. | Your device and Pile Raid/Firebase services. |
| Support & rights requests | Ticket category, subject, message, reply email, language, source, request ID, reference code, status and rate-limit identity hash. Never include passwords, login codes, payment credentials or private room codes. | You, the mobile app or this website, and the Pile Raid support service. |
| On-device data | Game settings, language, region preference and up to 50 local history entries. The server cannot automatically read this local store. | Your device. |
Never included in a player data export: password hashes, access or refresh tokens, provider secrets, another player’s private hand, the hidden deck, private room codes, or another player’s private email.
Why the data is used.
- create, authenticate, secure and recover an account;
- run local and online matches, reconnect players and determine verified results;
- show public profiles, friends, invitations, ratings and achievements;
- deliver earned or purchased virtual items without duplicate rewards;
- prevent cheating, account abuse, fraud, harassment and unsafe behaviour;
- answer support, privacy, deletion and safety requests; and
- meet legal, tax, refund, dispute or platform obligations when they apply.
The final jurisdiction-by-jurisdiction legal-basis register remains subject to owner and legal approval. Pile Raid must not activate optional analytics, personalised advertising, marketing or new providers until this policy and the relevant consent controls are updated and verified.
Mixed-audience, protected by default.
Pile Raid is designed for age groups 9–12, 13–15, 16–17 and 18+. Players under 9 are not eligible to create or use a Pile Raid account. A neutral age screen should choose the correct experience without using age information for advertising.
The current app source contains no advertising SDK, analytics SDK or crash-reporting SDK. If ads are introduced later, child and unknown-age users must remain on a non-personalised, families-compatible treatment and this policy must be updated before the first ad request.
Parents and guardians can review the Family Guide and use the active privacy support channel. We do not claim COPPA, GDPR-K or any other child-privacy approval merely because these controls are documented.
Who receives information.
Pile Raid does not sell player personal information. Data is shared only as needed to operate the service, respond to a request, protect players, or meet law and store obligations.
- Google Firebase / Google Cloud: authentication, database, callable functions and app-integrity services.
- Google Sign-In and Apple Sign-In: only when selected and enabled; each provider also applies its own policy.
- Apple App Store or Google Play: purchase and entitlement records only if paid products are enabled.
- Other players: only public profile, table-visible gameplay, competition and social information—not email, private hands or hidden deck state.
- Authorities or professional advisers: only where reasonably required by law, safety, fraud, disputes or legal rights.
The game backend is configured to a European Firebase region for its primary real-time and function workloads. Authentication and other provider processing may occur in additional locations under the provider’s terms and safeguards.
How long information stays.
Profile and account data is kept while the account is active and then removed through the approved deletion workflow. Some records may need a different treatment:
- financial-integrity commands and ledgers may be retained in pseudonymised form for reconciliation, refunds, fraud prevention or legal obligations;
- security and abuse records may be retained for a limited period to protect the service and other players;
temporary_sealed_deletion_security_tombstoneis a minimal pseudonymous mutation barrier retained for no more than 24 hours after account deletion finalises; scheduled cleanup removes it only after an independent Firebase Admin Authentication check proves the old account remains absent, and a failed proof safely retains the blocker for retry;temporary_deletion_response_recovery_capabilityis a non-PII record addressed by the SHA-256 digest of the random deletion request ID and retained for no more than 30 days; it contains receipt/status/rate-window/expiry data but no UID, email or raw request ID, allowing this browser to recover a lost completion response;- support ticket content expires after 180 days under the current server policy; an account deletion removes open tickets and strips contact/free-text content from any terminal workflow record retained for case integrity;
- de-identified match-integrity records may remain so another player’s result, rating or exact-once reward is not corrupted;
- device-local settings and history require a separate local erase because the server cannot reach them.
Access, correction, deletion and objection.
Depending on where you live, you may have rights to access, correct, export, delete, restrict or object to processing, withdraw consent, or complain to a regulator. These rights can have legal limits.
- Edit supported public-profile information in the app.
- Review privacy controls at Settings → Privacy & Safety.
- Start deletion at Settings → Privacy & Safety → Delete account, or use the public deletion page.
- Contact privacy support through the active secure ticket channel.
We may need to verify identity before acting on a sensitive request. We do not ask for an account password by email or support message.
How the game protects information.
Pile Raid separates public match state, each player’s private hand and server-only deck/code state. Client writes to profiles, wallets, ratings and inventories are denied; authoritative changes are made by server functions. Authentication, short-lived tokens, rate controls and exact-once receipts reduce abuse. App Check signals are staged for monitoring, but backend enforcement is not yet enabled and remains a release gate.
No system is perfectly secure. Do not share passwords, verification links or private room codes with untrusted people. Report suspected account compromise through Support.
Questions or policy changes.
The public operator identity, address and privacy channel are mandatory deployment values and are not invented in source control. Until that channel is configured, use the in-app Privacy & Safety route.
Material changes should produce a new version, effective date and in-app notice. Continued use is not treated as consent where affirmative consent is legally required.