English · 한국어
Privacy Policy
This policy explains what data Smithmare (the “Game”, package com.smithmare.app) collects, why, and what you can do about it. It applies to the mobile app and to the servers that run it.
1. Who is responsible
| Developer | Bonghyun Jung (TeamHealers) |
|---|---|
| Contact | support@smithmare.com |
| Location | Republic of Korea |
We are an independent developer. We do not sell personal data, and we have never done so.
2. What we collect
2.1 Account data — collected when you sign in
Smithmare has no password of its own. You sign in with Google or Apple, and that provider hands us a minimal identity record:
- Provider user ID — an opaque identifier issued by Google or Apple. This is what actually identifies your save.
- Email address — used to recognise your account and to contact you about the service. Apple users who choose “Hide My Email” give us a relay address instead, which works the same way for us.
- Display name — if the provider supplies one.
We never receive your password, and we do not request access to your contacts, photos, files, calendar, microphone, camera, or precise location.
2.2 Device data — collected so the app can run
- Device identifier — a random ID generated by the app on first launch, used to keep separate logins on separate devices.
- Push token (Firebase Cloud Messaging) — only if you allow notifications.
- Platform, app version, language, time zone — to serve the right content and to avoid sending notifications in the middle of your night.
- Advertising ID — read by Google AdMob when you watch a rewarded ad. See §4.
- IP address — present in server logs, as it is for any internet service.
2.3 Gameplay data
Your progress: floor reached, equipment owned, currencies, enhancement state, battle results, missions, and purchase history. This is the save file. It is stored on our servers because combat is resolved server-side.
2.4 Purchase data
When you buy something, the store (Google Play or the App Store) processes the payment and sends us a receipt and order ID, which we verify and store. We never see your card number, bank details, or billing address. Those stay with the store.
2.5 Diagnostics
Crash reports and basic usage analytics via Firebase Crashlytics and Google Analytics for Firebase — what screen was open, what the app was doing when it fell over.
3. Why we collect it
| Purpose | Data used |
|---|---|
| Run the game and keep your save | Account, device, gameplay |
| Verify purchases and honour refunds | Purchase |
| Verify rewarded ads actually completed | Advertising ID, device |
| Send notifications you asked for | Push token, time zone |
| Fix crashes and balance the game | Diagnostics, gameplay |
| Prevent cheating, fraud, and abuse | Account, device, purchase |
Legal basis (for players in the EEA and UK)
- Contract — account, device, gameplay, and purchase data. Without these there is no game to provide.
- Legitimate interests — diagnostics, fraud prevention, service security.
- Consent — push notifications, marketing messages, and personalised advertising. You can withdraw any of these at any time without losing access to the game.
4. Advertising
Smithmare shows rewarded video ads only. You choose to watch one in exchange for something in-game. There are no banners, no interstitials, and nothing that interrupts you.
Ads are served by Google AdMob, which may read your device’s advertising ID to select and measure ads. This is the one category of data that leaves us for a third party that is not merely acting on our instructions.
You can limit this at any time in Android Settings → Privacy → Ads, where you may reset or delete your advertising ID. Doing so does not affect your ability to earn ad rewards.
AdMob’s own policy: policies.google.com/technologies/ads
5. Who else touches your data
The following providers process data on our behalf, under contract, and may not use it for their own purposes:
| Provider | Role |
|---|---|
| Amazon Web Services | Server and database hosting |
| Google (Firebase) | Push notifications, crash reporting, analytics |
| Google Play / Apple | Sign-in and payment processing |
| Cloudflare | DNS and network security |
Beyond these, we disclose personal data only where the law requires it.
6. Where your data goes
Our servers are in the Republic of Korea. Our providers may process data in other countries, including the United States. Where that involves transferring data out of the EEA or UK, our providers rely on the European Commission’s Standard Contractual Clauses.
7. How long we keep it
| Data | Retention |
|---|---|
| Account and gameplay | Until you delete your account |
| Deleted accounts | Erased 7 days after you request deletion |
| Purchase records | 5 years, as required by Korean tax and e-commerce law |
| Server and access logs | 30 days |
| Crash reports | Per Firebase defaults, up to 90 days |
8. Deleting your account
You can delete your account from inside the app: Settings → Delete account.
- Deletion is scheduled, not instant. You have a 7-day grace period in which signing in again cancels it — this exists so a mistap does not cost you your save.
- After 7 days your account, progress, equipment, currencies, and identity records are permanently erased. This cannot be undone and there is no backup we can restore from.
- Purchase records are retained for the statutory period above, stripped of any link to you.
- Unspent paid currency is forfeited. Spend it before you delete.
If you cannot reach the in-app screen, email support@smithmare.com from the address on your account and we will process it manually.
9. Your rights
You may ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to our use of it. Where you gave consent, you may withdraw it. Write to support@smithmare.com and we will respond within 30 days.
If you are in the EEA or UK you may complain to your local data protection authority. If you are in Korea you may contact the Personal Information Protection Commission (privacy.go.kr, 국번없이 182).
10. Children
Smithmare is not directed to children. You must be at least 13 years old to play, or older where your country requires it — 14 in Korea, and 16 in parts of the EEA. We do not knowingly collect data from children below that age. If you believe a child has given us data, write to us and we will delete it.
11. Security
All traffic between the app and our servers is encrypted with TLS. Authentication tokens are stored in the operating system’s secure keystore. Refresh tokens are stored hashed, never in the clear. Access to production data is restricted to the developer.
No system is perfectly secure. If a breach affects you, we will notify you and the relevant authority as the law requires.
12. Changes
We will post any change here with a new effective date. If a change materially affects your rights, we will tell you in the app before it takes effect.