-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathprivacy.html
More file actions
229 lines (195 loc) · 12.7 KB
/
Copy pathprivacy.html
File metadata and controls
229 lines (195 loc) · 12.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Privacy Policy — Tiny Takeoff</title>
<style>
body {
font-family: Arial, sans-serif;
background-color: #353069;
color: white;
padding: 20px;
line-height: 1.6;
}
.main {
max-width: 760px;
margin: auto;
}
h1 {
margin-bottom: 0;
}
h2 {
margin-top: 2em;
border-bottom: 1px solid rgba(255, 255, 255, 0.2);
padding-bottom: 0.3em;
}
.updated {
color: rgba(255, 255, 255, 0.6);
margin-top: 0.3em;
}
.summary {
background: rgba(255, 255, 255, 0.08);
border-left: 3px solid rgba(255, 255, 255, 0.4);
padding: 1px 20px;
margin: 25px 0;
}
a {
color: #9fd0ff;
}
code {
background: rgba(0, 0, 0, 0.25);
padding: 1px 5px;
border-radius: 3px;
}
footer {
margin-top: 40px;
color: rgba(255, 255, 255, 0.4);
}
footer a {
color: rgba(255, 255, 255, 0.4);
}
</style>
</head>
<body>
<div class="main">
<h1>Privacy Policy</h1>
<p class="updated">Tiny Takeoff — last updated: 11 August 2026</p>
<p>This policy explains what Tiny Takeoff ("the game") collects, why, and who else sees it. It covers
the iOS, tvOS, desktop and web versions of the game, and this website.</p>
<div class="summary">
<p><strong>In short:</strong> there is no sign-up. We never ask for your name, email address or phone
number, and we do not know who you are. The game creates an anonymous account for itself so it can put
your run on the daily leaderboard. There are no ads, no advertising identifiers, no third-party
tracking SDKs and no in-app purchases.</p>
</div>
<h2>Who we are</h2>
<p>The game is made and operated by <strong>Rustunit</strong>, Blaak 520, 3011TA Rotterdam, Netherlands.
Rustunit B.V. is the data controller for the processing described here. You can reach us at
<a href="mailto:privacy@rustunit.com">privacy@rustunit.com</a>.</p>
<h2>What the game collects</h2>
<h3>Your anonymous account</h3>
<p>The first time you launch the game it creates an account for you automatically — there is no sign-in screen
and nothing to fill in. That account consists of:</p>
<ul>
<li>a randomly generated account ID and a secret token, which together let your device prove the account is
yours;</li>
<li>a randomly generated display name, such as <code>CrazyDancerMD396</code>;</li>
<li>the platform family you play on (for example <code>ios</code> or <code>wasm</code>) — not your device
model or a device identifier;</li>
<li>a two-letter country code;</li>
<li>the date your account was created and the date you last played.</li>
</ul>
<p>The country code is worked out from your IP address when your account is created, by a geolocation service
we run ourselves. Only the two-letter result is stored — <strong>your IP address is not saved in our
database</strong>. Like any web service, our servers and hosting providers do process your IP address
in order to answer the request at all, and it may appear in short-lived server logs and in error
diagnostics (see below).</p>
<h3>Your runs</h3>
<p>When you finish a run on the daily level, the game uploads a recording of it. That recording is purely
gameplay: the tick numbers at which you pressed and released the one control, the length of the run, stars
collected, your plane's colour, and which daily level it was. Our server replays those inputs through the
same simulation the game runs, to confirm the score is real, and stores the result together with your
score and distance. Runs that fail verification are kept and flagged rather than deleted.</p>
<p>A recording contains no location data, no device information, no text you wrote and no camera, microphone or
photo data. The game asks for no such permissions.</p>
<h3>Game Center (iOS and tvOS, optional)</h3>
<p>If you are signed in to Game Center, the game links your account to it so your progress survives
reinstalling the game or moving to a new device. To do that we receive from Apple, and store, your Game
Center <em>team player ID</em> — an identifier that is specific to our games and cannot be used to identify
you elsewhere — and your Game Center <strong>alias, which then becomes your public display name on the
leaderboard</strong>. Verifying the sign-in involves a request from our server to Apple.</p>
<p>This is optional. If you are not signed in to Game Center, or decline, the game works normally with the
anonymous account described above.</p>
<h2>What is public</h2>
<p>Tiny Takeoff is a competitive game with a global daily leaderboard. Your <strong>display name, country flag,
score and rank are shown publicly</strong> to other players, and your recorded run can be replayed by
others as a ghost. If you share a run, the link you create is public and shows the run and the display name
attached to it. Please keep that in mind when choosing a Game Center alias, since it is used as your
leaderboard name.</p>
<h2>What is stored on your device</h2>
<p>The game saves your account ID and token, your best runs and ghost replays, your audio settings and your
notification preference on your own device — in browser <code>localStorage</code> on the web, and in the
app's private storage on iOS, tvOS and desktop. <strong>The game itself sets no cookies.</strong> Clearing
your browser storage, or deleting the app, removes this local data; on the web it also means the game can
no longer reach the account it created, so it will make a new one.</p>
<h2>Notifications</h2>
<p>The game can remind you that a new daily board is up. This is off by default and only ever asked for when
you turn the switch on. These reminders are scheduled locally by your device — <strong>we do not operate
push notifications and no device push token is collected or sent to us</strong>. You can turn them off
again in the game or in your system settings.</p>
<h2>What we do not do</h2>
<ul>
<li>No advertising, ad networks or ad identifiers. We do not access the IDFA and the game shows no ads.</li>
<li>No tracking across other apps or websites, and no App Tracking Transparency prompt, because we do no
tracking.</li>
<li>No analytics or crash-reporting SDK inside the game itself.</li>
<li>No in-app purchases or payments — we collect no payment data of any kind.</li>
<li>No selling or renting of personal data, ever.</li>
<li>No marketing emails, because we have no email address for you.</li>
</ul>
<h2>Who else processes this data</h2>
<p>We use a small number of service providers to run the game. They act on our instructions:</p>
<ul>
<li><strong>Neon</strong> — hosts the database holding accounts, scores and recordings.</li>
<li><strong>Vercel</strong> — hosts the web version of the game; its request logs include IP addresses.</li>
<li><strong>Sentry</strong> (EU region) — collects server error reports so we can fix faults. An error
report can include the IP address of the request that triggered it.</li>
<li><strong>PostHog</strong> (EU region) — product analytics on the server. When a run is scored we send it
the account ID, the public display name, the score and the rank, so we can see how the game is being
played. No IP address, and nothing from your device, is sent.</li>
<li><strong>Apple</strong> — distributes the app and provides Game Center. Apple's own handling of your
data is governed by <a href="https://www.apple.com/legal/privacy/">Apple's privacy policy</a>.</li>
</ul>
<p>Some of these providers are based in the United States. Where data reaches them, the transfer is covered by
the European Commission's Standard Contractual Clauses or an equivalent safeguard.</p>
<h2>Why we are allowed to do this</h2>
<p>Under the GDPR we rely on <em>performance of a contract</em> — running the account, leaderboard and score
verification you asked for by playing — and on our <em>legitimate interest</em> in keeping the game
working, keeping the leaderboard honest, and understanding in aggregate how it is played. Notifications
rely on your <em>consent</em>, which you give by turning the switch on and can withdraw at any time.</p>
<h2>How long we keep it</h2>
<p>Your account and your runs are kept for as long as the account exists, so that your records and your place in
the game's history survive from one day's board to the next. We are working towards automatically clearing
out old recordings that no longer back a live leaderboard. Everything tied to your account is deleted when
you ask us to delete it.</p>
<h2>Your rights and deleting your data</h2>
<p>You can ask us for a copy of the data attached to your account, ask us to correct it, or ask us to delete it
outright. Write to <a href="mailto:privacy@rustunit.com">privacy@rustunit.com</a>.</p>
<p>Because the game never asks who you are, we cannot look your account up from a name or an email address. The
way to point us at it is to use the game's share button on one of your runs and send us the link it
produces — it identifies the run, and through it the account. Telling us your in-game display name and
roughly when you played helps us confirm the match. There is currently no self-service delete button inside
the game; we handle these requests by email, normally within 30 days.</p>
<p>Deleting your account removes your display name, country, Game Center link and runs, and takes your entries
off the leaderboard. If you are in the EU or UK and think we have handled your data badly, you may also
complain to your national data protection authority — in the Netherlands, the
<a href="https://autoriteitpersoonsgegevens.nl/">Autoriteit Persoonsgegevens</a>.</p>
<h2>Children</h2>
<p>Tiny Takeoff is a general-audience game and is not directed at children under 13. We do not knowingly
collect personal data from children under 13, and the game asks for no personal information from anyone. If
you believe a child has provided us with personal data — most plausibly by using a real name as a Game
Center alias — contact us and we will remove it.</p>
<h2>Security</h2>
<p>Traffic between the game and our servers is encrypted with HTTPS, as is the connection between our servers
and the database. No system is perfectly secure, but the best protection here is structural: we hold very
little about you, and nothing that could identify you offline.</p>
<h2>This website</h2>
<p>tinytakeoff.com uses <a href="https://usefathom.com/">Fathom Analytics</a> to count visits. Fathom is
cookieless, does not track visitors across sites and does not build personal profiles. The web version of
the game, at web.tinytakeoff.com, carries no analytics at all.</p>
<h2>Changes to this policy</h2>
<p>If we change what we collect, we will update this page and the date at the top. Significant changes will
also be announced in the game or on this site.</p>
<h2>Contact</h2>
<p>Questions about this policy, or about your data:</p>
<ul>
<li>Email: <a href="mailto:privacy@rustunit.com">privacy@rustunit.com</a></li>
<li>Post: Rustunit, Blaak 520, 3011TA Rotterdam, Netherlands</li>
</ul>
<footer>
<a href="/">Back to Tiny Takeoff</a>
</footer>
</div>
</body>
</html>