Privacy Policy
Effective date: 3 August 2026 · Last updated: 3 August 2026
This Privacy Policy describes how GameRot (“GameRot”, “we”, “us”, or “our”) collects, uses, discloses, and safeguards information in connection with the GameRot mobile application (the “App”) and the website at gamerot-d05b7.web.app (together, the “Service”).
For the purposes of the EU and UK General Data Protection Regulation, GameRot is the data controller in respect of personal data processed through the Service. Please read this Policy carefully. By accessing or using the Service, you acknowledge that you have read and understood it.
1. Information We Collect
1.1 Information you provide through third-party sign-in
Creating a profile is optional. If you elect to sign in, authentication is performed entirely by Google or Apple. We do not receive, process, or store your password at any time. Upon successful authentication we receive:
| Category | Source | Necessity |
|---|---|---|
| Full name | Google / Apple | Optional, collected only on sign-in |
| Email address | Google / Apple | Optional, collected only on sign-in |
| Profile image URL | Optional, collected only on sign-in | |
| Unique user identifier | Firebase Authentication | Generated on account creation |
| Authentication provider identity | Firebase Authentication | Generated on account creation |
Where you use Sign in with Apple and elect Apple's “Hide My Email” feature, Apple supplies a private relay address in place of your personal email address. The Service functions identically in that configuration. Apple discloses your name only upon your first authorisation.
1.2 Information you provide through the website waitlist
If you submit your email address to the launch waitlist on our website, we store that address, the time you submitted it, and the fact that it came from the website. We use it for one purpose: to email you when GameRot is released. We do not use it for marketing unrelated to that release, and we do not share or sell it.
| Category | Source | Necessity |
|---|---|---|
| Email address | You, via the website form | Optional, only if you join the waitlist |
| Submission timestamp | Your browser | Recorded with the address |
The lawful basis is your consent, given by submitting the form. You may withdraw it at any time by emailing askgamerot@gmail.com and we will delete your address. We keep waitlist addresses until the release email has been sent, or until you ask us to remove yours, whichever comes first.
1.3 Information collected automatically
We use Google Analytics for Firebase, which collects the following on an automatic basis irrespective of whether you hold an account:
- a pseudonymous application instance identifier generated by Firebase, which is reset upon reinstallation of the App;
- device model, operating system and version, device language, and coarse geographic region derived from IP address;
- application opens, session duration, and screens viewed;
- discrete events recorded by us, namely
sign_up,login,logoutandaccount_deleted, each recording only the authentication provider used.
Where you are signed in, your Firebase user identifier is associated with these events so that activity may be measured consistently across sessions. That association is terminated upon logout or account deletion.
1.4 Information stored solely on your device
Per-game high scores are written to the App's private storage area on your device. This information is not transmitted to us, to any server, or to any third party, is not accessible to us, and is not backed up by us. It is erased when the App is uninstalled.
1.5 Information we do not collect
- We do not collect any advertising identifier (IDFA or Android Advertising ID). The App does not link Apple's AdSupport framework.
- We do not track your activity across applications or websites owned by other companies, and accordingly do not present an App Tracking Transparency prompt.
- We do not collect precise geolocation data.
- We do not request or access contacts, photographs, microphone, camera, health data, or files.
- We do not collect payment information. The App contains no in-app purchases.
- We do not knowingly collect biometric or special category data.
2. Purposes of Processing
We process personal data for the following purposes only:
- to create, authenticate, and maintain your optional user profile;
- to display your username and profile image within the App;
- to measure aggregate usage of the Service and diagnose defects;
- to respond to your support enquiries and deletion requests;
- to comply with applicable law and to establish, exercise, or defend legal claims.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We do not use your personal data to train machine learning or artificial intelligence models.
3. Legal Bases for Processing (EEA, UK and Switzerland)
Where the GDPR or UK GDPR applies, we rely on the following lawful bases under Article 6(1):
| Processing | Lawful basis |
|---|---|
| Creating and maintaining your profile | Performance of a contract (Art. 6(1)(b)) |
| Analytics and service improvement | Legitimate interests (Art. 6(1)(f)) |
| Responding to support and rights requests | Legal obligation (Art. 6(1)(c)) and legitimate interests |
| Any processing you have separately agreed to | Consent (Art. 6(1)(a)), withdrawable at any time |
Where we rely on legitimate interests, we have assessed that our interest in understanding aggregate usage does not override your rights and freedoms, having regard to the pseudonymous nature of the data and the absence of advertising or cross-context tracking.
4. Disclosure of Information
We do not sell personal data. We disclose personal data only to the following categories of recipients, each of which processes data on our behalf under contractual terms requiring appropriate confidentiality and security:
| Recipient | Function | Data |
|---|---|---|
| Google LLC (Firebase Authentication, Analytics, Hosting) | Processor | Account identifiers, name, email, usage events |
| Apple Inc. (Sign in with Apple) | Independent controller for its own authentication | Authentication assertions, where you use Apple sign-in |
Google's handling of data processed through Firebase is described at firebase.google.com/support/privacy.
We may additionally disclose personal data where required to do so by law, court order, or a lawful request by a public authority, or where necessary to protect our rights, safety, or property or those of our users.
In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity, subject to this Policy or a successor policy providing equivalent protection.
5. Data Retention
| Data | Retention period |
|---|---|
| Account data (name, email, identifiers) | For so long as your account remains active. Deleted immediately upon account deletion. |
| Analytics data | Retained by Google for the period configured for our Firebase project, being no longer than 14 months, after which it is deleted or retained only in aggregated form. |
| Support correspondence | Up to 24 months from resolution. |
| On-device high scores | Retained on your device until you delete the App or your account. Not retained by us. |
6. Your Rights
Subject to applicable law, you have the right to request access to, rectification of, or erasure of your personal data; to obtain a portable copy; to restrict or object to processing; and to withdraw any consent previously given. Where the GDPR applies you also have the right to lodge a complaint with your local supervisory authority.
California residents. Under the CCPA as amended by the CPRA you have the right to know, delete, and correct personal information, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined, and we do not process sensitive personal information for the purpose of inferring characteristics. We will not discriminate against you for exercising any right.
India. Where the Digital Personal Data Protection Act, 2023 applies, you may exercise your rights of access, correction, erasure, and grievance redressal by contacting us at the address in Section 13.
We will respond to verified requests within the period required by applicable law, and in any event within 30 days.
7. Deletion of Your Account
You may delete your account at any time, without contacting us, from within the App: open the App, tap the profile icon in the upper-right corner, select Delete account, and confirm. Deletion takes effect immediately. Where your session is not recent, you may be required to re-authenticate first; this is a security measure and deletion proceeds immediately thereafter. Where you signed in with Apple, we additionally revoke the Apple authentication token.
If you no longer have the App installed, you may request deletion by email in accordance with the Delete Account page. Analytics events already recorded are pseudonymous and are retained in accordance with Section 5.
8. International Transfers
Personal data processed through the Service may be transferred to, stored in, and processed in the United States and other jurisdictions in which our processors operate, which may not provide the same level of data protection as your jurisdiction. Where personal data is transferred out of the EEA, the UK, or Switzerland, such transfers are made pursuant to the Standard Contractual Clauses approved by the European Commission, or another lawful transfer mechanism relied upon by the relevant processor.
9. Children's Privacy
The Service is not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal data from such children. If we become aware that we have collected personal data from a child under that age without appropriate consent, we will delete it promptly. A parent or guardian who believes their child has provided us with personal data should contact us at the address in Section 13.
10. Security
We implement technical and organisational measures appropriate to the risk, including transmission of all data over encrypted connections (HTTPS/TLS), delegation of authentication to Google and Apple such that we never handle credentials, and restriction of administrative access to the Firebase project. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
11. Third-Party Links
The Service may contain links to third-party websites or services. We do not control and are not responsible for the privacy practices or content of such third parties. We encourage you to review their privacy policies before providing them with personal data.
12. Changes to This Policy
We may amend this Policy from time to time. Where changes are material, we will update the “Last updated” date above and, where required by law, provide notice within the App or by other appropriate means prior to the change taking effect. Your continued use of the Service following the effective date constitutes acceptance of the amended Policy.
13. Contact
For any question, request, or complaint concerning this Policy or our processing of your personal data, contact:
14. Governing Law
This Policy and any dispute arising out of or in connection with it are governed by the laws of India, without prejudice to any mandatory data protection rights available to you under the laws of your country of residence.
By accessing or using GameRot, you acknowledge that you have read and understood this Privacy Policy.
GameRot · Privacy Policy · Effective 3 August 2026