BlockRivals Privacy Policy
Effective date: 11 September 2026
This policy explains what data the BlockRivals mobile game collects, how it is used, where it is processed, who it is shared with, and what rights users have. This website itself does not use cookies — see the Cookie Notice.
1. Data we collect
BlockRivals processes only the minimum data needed to run the game, provide competitive features (matchmaking, ranking, leaderboards), and respond to support requests. Signing in with a Google account, email address, or phone number is NOT required.
Username — visible to your rivals
The username you choose the first time you enter the Arena (the online competitive area) is your account's single public identity. It is shown to other players in matches and on the leaderboard. It must be 3-16 characters, may only contain letters, numbers and underscores, and the system rejects offensive or brand-infringing names.
Device and session information
When you enter the Arena, a device identifier and a player identity are assigned to your device. The server records the device identifier together with the platform name (e.g. Android) and app version. A refresh token is issued to keep you signed in; only a hash of this token is stored on the server, while the token itself is stored on your device.
Recovery code
When you claim your username, the server shows you a one-time recovery code. This code lets you regain your account when you switch phones or reinstall the app. The plain-text code is never stored anywhere; the server keeps only a cryptographic hash of it (argon2id). If you lose it, recovery may still be possible through support with identity verification.
Gameplay data
Rating, the Crest balance (the game's single currency), level, XP, match history, and the recorded moves of competitive matches (Live Duel, Tactical — kept for replay) are processed on the server. This data is required to run fair, accurate competition. The game currently offers no shop, no in-app purchases and no premium currency.
Community content — public
If you publish a post or a comment in the Community section of the website, the text you write and the username shown next to it are published publicly — visitors who are not signed in, and search engines, can see them. When you report a post or a comment, the reason and the username of the reporting account are written to a moderation record; moderation decisions (removing content from public view, restoring it, restricting community access) are kept in a separate audit log. Neither record is public; they are processed to review rule violations, prevent abuse, and evaluate appeals. For the content rules, the reporting route and appeals, see Section 4 of the Terms of Service.
Data stored on the device
The following files are kept only on your device and are not automatically sent to the server:
- Language, sound, vibration and graphics preferences, and tutorial status.
- Progression (level/reward) cache and Solo mode's best score — kept on-device because Solo can be played fully offline.
- Session file: account type, username, and refresh token — used to keep you signed in.
- Run-state file: last open screen, app version, and timestamps — used only to detect whether the previous session shut down cleanly (a possible crash); it carries no personal content.
Technical event and crash records
A limited set of technical events is processed to measure stability and diagnose issues: app open, a previous session that did not close cleanly, tutorial steps, Solo/match start and end, matchmaking queue, rematch offers, room create/join, revive/refresh usage, settings changes, opening the store screen, connection loss/recovery, a rival leaving, sync mismatches, and error reports. Each record includes the app version, platform name, and event time; the player id is included when you are signed in — if there is no valid session (for example, a crash report sent after your token expired), the record is accepted anonymously instead. No advertising id, device hardware id, location, contacts, or other personal content is collected in these records. Records are not sent to any third-party analytics service; they are processed only on our own server infrastructure (as a system log) and are deleted automatically after 30 days.
IP address and server access logs
To prevent abuse (such as opening many accounts from one device, or excessive requests), the IP address of requests made to the server is processed temporarily in short-lived, hourly rate-limiting counters that expire on their own when the window closes. Separately, like all web servers, our server also keeps standard access logs for security and outage diagnostics: IP address, request time, request type and normalized path (query strings and access tokens are NOT logged), and browser/client information. These access logs may be retained longer than the rate-limiting counters (for the duration of our standard log-rotation policy), but the IP address is not a field permanently attached to your player profile and is not used to build a profile of you.
Support communications
If you contact us by email, we process the message content and contact information needed to resolve your request.
Advertising
BlockRivals shows advertising. Rewarded video ads are shown only at the player's own request (for example, to continue a run), and a banner ad is shown at the bottom of gameplay screens. Advertising is served by Google AdMob.
When an ad is shown, AdMob processes the device's advertising identifier and technical information about the ad impression and interaction through its own SDK, under its own privacy policy. That data does not reach our servers and is not stored by us. See Google's Privacy Policy for AdMob's data practices. AdMob may use its own cookie-like technologies inside its SDK — this is part of the game app, not this website (see the Cookie Notice).
In-app purchases
BlockRivals does not currently offer in-app purchases. This policy will be updated if they are introduced.
2. Data inventory table
| Data type | Where collected | Where stored | How long | Why |
|---|---|---|---|---|
| Username (public, visible to rivals) | Arena sign-in screen | Server database | While the account is active | Identity, matchmaking, leaderboard |
| Recovery code | Generated by server at registration, shown to you once | Only a cryptographic hash (argon2id) on the server; plain text is never stored anywhere | While the account is active / until regenerated | Recovering the account after a device change |
| Device record (device id, platform, app version) | First launch / Arena sign-in | Server | While the device stays linked | Session management, multi-account/abuse prevention |
| Push notification token (FCM) | Sent by the app when you allow notifications | Server | Until the token becomes invalid, notifications are turned off, or the account is deleted | Match invites, season/league and comeback notifications |
| Refresh token | After sign-in | Only a hash on the server; the token itself on the device | Until expiry or revocation | Keeping you signed in |
| Rating, Crest balance, level, XP | In-game progress | Server | While the account is active | Competition, progression, economy |
| Match history and move records (replay) | Rush Duel / Tactical Turn matches | Server | As needed for competitive integrity and replay; see Section 6 | Dispute resolution, cheat detection, replay |
| Community post and comment text | When you publish a post or comment in the Community section | Server database — published publicly | Until you send a removal request or moderation takes it down | Providing the Community section |
| Community username (public) | Shown next to your post or comment | Server database — published publicly | While the content stays published | Attributing content to its author, abuse prevention |
| Content report (reason + reporting user's username) | When the Report button is used on a post or comment | Server moderation record — NOT public | As long as needed for the review and abuse audit | Reviewing rule violations, preventing duplicate or malicious reports |
| Moderation decisions (removal/restore, community access restriction) | When a moderation action is taken | Server audit log — NOT public | As long as needed for security and appeal review | Traceability of decisions, evaluating appeals |
| Device settings (language, sound, vibration, graphics, tutorial) | Created on device, never sent over the network | Device only | Until the app is uninstalled / data cleared | Remembering preferences |
| Progression and Solo best-score cache | Created on device | Device only | Until the app is uninstalled | Offline Solo mode |
| Technical event / crash record (first-party) | Automatically during app use | Our own server infrastructure (system log) | 30 days, deleted automatically | Stability, debugging, connection diagnostics |
| IP address — rate-limit counter | Requests made to the server | Temporary counter (hourly window) | Short (expires when the limit window closes) | Abuse and fake-account prevention |
| IP address — server access log | Every request made to the server (nginx) | Our own server infrastructure, standard access log | Standard log-rotation period (may exceed the rate-limit window) | Security and outage diagnostics |
| Support correspondence | When a user emails us | Support inbox | Duration of resolution + a reasonable period | Responding to support requests |
| Advertising identifier & ad impression/interaction data | When a rewarded video or banner ad is shown, via the Google AdMob SDK | Processed and stored by Google AdMob under its own systems; not stored on our servers | Governed by AdMob's own retention policy | Serving and measuring rewarded video and banner ads |
| In-app purchase data | None at this time — this feature is not offered | |||
3. How we use data
- Create accounts, sign users in, and maintain sessions.
- Recover an account with the recovery code after a device change.
- Provide matchmaking, leaderboard, rating, and replay features.
- Support game reliability, debugging, and abuse/cheat prevention.
- Remember user preferences on the device.
- Respond to support requests.
4. Processing infrastructure
BlockRivals' server infrastructure is currently in transition: the current version runs on cloud-provider infrastructure (including authentication, database, and logging services); a move to the game's own server is planned and partly completed for some services. Hosting country/region: Türkiye (Istanbul). This section will be updated once the migration is complete.
5. Sharing of data
We do not sell personal data. Data is shared only with service providers needed to provide the game, when required by law, or at the user's request. Our own servers do not share data with advertising networks; however, Google AdMob processes the device's advertising identifier and the ad-impression/interaction data described in Section 1 through its own SDK, under its own privacy policy, when an ad is shown. We do not share data with third-party analytics providers.
6. Retention and account deletion
Account and gameplay data is retained while the account is active. When you request account deletion:
- Your username, identity, device records, and session tokens are deleted.
- Match history and score records may be retained a while longer with your username removed (de-identified), to preserve the integrity of other players' match results and the leaderboard.
- A limited set of records that must be retained for legal, security, or abuse-prevention reasons may be kept longer.
We cannot promise that "everything is destroyed instantly and irreversibly" — a competitive game needs to preserve the integrity of past matches. See the Delete Account page for details and the request process.
7. User rights
Users may request access, correction, or deletion of their account data. Identity verification may be required for a deletion request (e.g. confirming your username). See Delete Account and, for users in Turkey, the Data Protection Notice (KVKK).
8. Children's privacy
BlockRivals does not knowingly target the collection of personal data from children. The age groups the app may be offered to, and any parental consent requirements, are evaluated separately based on the rules of each publication country and store age ratings. If you believe a child's data has been processed improperly, contact us.
9. Security
We apply authentication, access control, and infrastructure security measures to protect data (recovery codes and session tokens are stored as cryptographic hashes, never as plain text). No system is completely risk-free, however.
10. Changes
This policy may be updated from time to time; it MUST be updated if advertising or purchase features are added. Significant changes may be communicated through an in-app notice, release notes, or the app store listing.
11. Contact
For privacy and data requests: 43softwareltd@gmail.com.