BlockRivals Privacy Policy

Effective date: 11 September 2026

This policy explains what data the BlockRivals mobile game collects, how it is used, where it is processed, who it is shared with, and what rights users have. This website itself does not use cookies — see the Cookie Notice.

1. Data we collect

BlockRivals processes only the minimum data needed to run the game, provide competitive features (matchmaking, ranking, leaderboards), and respond to support requests. Signing in with a Google account, email address, or phone number is NOT required.

Username — visible to your rivals

The username you choose the first time you enter the Arena (the online competitive area) is your account's single public identity. It is shown to other players in matches and on the leaderboard. It must be 3-16 characters, may only contain letters, numbers and underscores, and the system rejects offensive or brand-infringing names.

Device and session information

When you enter the Arena, a device identifier and a player identity are assigned to your device. The server records the device identifier together with the platform name (e.g. Android) and app version. A refresh token is issued to keep you signed in; only a hash of this token is stored on the server, while the token itself is stored on your device.

Recovery code

When you claim your username, the server shows you a one-time recovery code. This code lets you regain your account when you switch phones or reinstall the app. The plain-text code is never stored anywhere; the server keeps only a cryptographic hash of it (argon2id). If you lose it, recovery may still be possible through support with identity verification.

Gameplay data

Rating, the Crest balance (the game's single currency), level, XP, match history, and the recorded moves of competitive matches (Live Duel, Tactical — kept for replay) are processed on the server. This data is required to run fair, accurate competition. The game currently offers no shop, no in-app purchases and no premium currency.

Community content — public

If you publish a post or a comment in the Community section of the website, the text you write and the username shown next to it are published publicly — visitors who are not signed in, and search engines, can see them. When you report a post or a comment, the reason and the username of the reporting account are written to a moderation record; moderation decisions (removing content from public view, restoring it, restricting community access) are kept in a separate audit log. Neither record is public; they are processed to review rule violations, prevent abuse, and evaluate appeals. For the content rules, the reporting route and appeals, see Section 4 of the Terms of Service.

Data stored on the device

The following files are kept only on your device and are not automatically sent to the server:

Technical event and crash records

A limited set of technical events is processed to measure stability and diagnose issues: app open, a previous session that did not close cleanly, tutorial steps, Solo/match start and end, matchmaking queue, rematch offers, room create/join, revive/refresh usage, settings changes, opening the store screen, connection loss/recovery, a rival leaving, sync mismatches, and error reports. Each record includes the app version, platform name, and event time; the player id is included when you are signed in — if there is no valid session (for example, a crash report sent after your token expired), the record is accepted anonymously instead. No advertising id, device hardware id, location, contacts, or other personal content is collected in these records. Records are not sent to any third-party analytics service; they are processed only on our own server infrastructure (as a system log) and are deleted automatically after 30 days.

IP address and server access logs

To prevent abuse (such as opening many accounts from one device, or excessive requests), the IP address of requests made to the server is processed temporarily in short-lived, hourly rate-limiting counters that expire on their own when the window closes. Separately, like all web servers, our server also keeps standard access logs for security and outage diagnostics: IP address, request time, request type and normalized path (query strings and access tokens are NOT logged), and browser/client information. These access logs may be retained longer than the rate-limiting counters (for the duration of our standard log-rotation policy), but the IP address is not a field permanently attached to your player profile and is not used to build a profile of you.

Support communications

If you contact us by email, we process the message content and contact information needed to resolve your request.

Advertising

BlockRivals shows advertising. Rewarded video ads are shown only at the player's own request (for example, to continue a run), and a banner ad is shown at the bottom of gameplay screens. Advertising is served by Google AdMob.

When an ad is shown, AdMob processes the device's advertising identifier and technical information about the ad impression and interaction through its own SDK, under its own privacy policy. That data does not reach our servers and is not stored by us. See Google's Privacy Policy for AdMob's data practices. AdMob may use its own cookie-like technologies inside its SDK — this is part of the game app, not this website (see the Cookie Notice).

In-app purchases

BlockRivals does not currently offer in-app purchases. This policy will be updated if they are introduced.

2. Data inventory table

What data, where it originates, where it is stored, for how long, and why.
Data typeWhere collectedWhere storedHow longWhy
Username (public, visible to rivals)Arena sign-in screenServer databaseWhile the account is activeIdentity, matchmaking, leaderboard
Recovery codeGenerated by server at registration, shown to you onceOnly a cryptographic hash (argon2id) on the server; plain text is never stored anywhereWhile the account is active / until regeneratedRecovering the account after a device change
Device record (device id, platform, app version)First launch / Arena sign-inServerWhile the device stays linkedSession management, multi-account/abuse prevention
Push notification token (FCM)Sent by the app when you allow notificationsServerUntil the token becomes invalid, notifications are turned off, or the account is deletedMatch invites, season/league and comeback notifications
Refresh tokenAfter sign-inOnly a hash on the server; the token itself on the deviceUntil expiry or revocationKeeping you signed in
Rating, Crest balance, level, XPIn-game progressServerWhile the account is activeCompetition, progression, economy
Match history and move records (replay)Rush Duel / Tactical Turn matchesServerAs needed for competitive integrity and replay; see Section 6Dispute resolution, cheat detection, replay
Community post and comment textWhen you publish a post or comment in the Community sectionServer database — published publiclyUntil you send a removal request or moderation takes it downProviding the Community section
Community username (public)Shown next to your post or commentServer database — published publiclyWhile the content stays publishedAttributing content to its author, abuse prevention
Content report (reason + reporting user's username)When the Report button is used on a post or commentServer moderation record — NOT publicAs long as needed for the review and abuse auditReviewing rule violations, preventing duplicate or malicious reports
Moderation decisions (removal/restore, community access restriction)When a moderation action is takenServer audit log — NOT publicAs long as needed for security and appeal reviewTraceability of decisions, evaluating appeals
Device settings (language, sound, vibration, graphics, tutorial)Created on device, never sent over the networkDevice onlyUntil the app is uninstalled / data clearedRemembering preferences
Progression and Solo best-score cacheCreated on deviceDevice onlyUntil the app is uninstalledOffline Solo mode
Technical event / crash record (first-party)Automatically during app useOur own server infrastructure (system log)30 days, deleted automaticallyStability, debugging, connection diagnostics
IP address — rate-limit counterRequests made to the serverTemporary counter (hourly window)Short (expires when the limit window closes)Abuse and fake-account prevention
IP address — server access logEvery request made to the server (nginx)Our own server infrastructure, standard access logStandard log-rotation period (may exceed the rate-limit window)Security and outage diagnostics
Support correspondenceWhen a user emails usSupport inboxDuration of resolution + a reasonable periodResponding to support requests
Advertising identifier & ad impression/interaction dataWhen a rewarded video or banner ad is shown, via the Google AdMob SDKProcessed and stored by Google AdMob under its own systems; not stored on our serversGoverned by AdMob's own retention policyServing and measuring rewarded video and banner ads
In-app purchase dataNone at this time — this feature is not offered

3. How we use data

4. Processing infrastructure

BlockRivals' server infrastructure is currently in transition: the current version runs on cloud-provider infrastructure (including authentication, database, and logging services); a move to the game's own server is planned and partly completed for some services. Hosting country/region: Türkiye (Istanbul). This section will be updated once the migration is complete.

5. Sharing of data

We do not sell personal data. Data is shared only with service providers needed to provide the game, when required by law, or at the user's request. Our own servers do not share data with advertising networks; however, Google AdMob processes the device's advertising identifier and the ad-impression/interaction data described in Section 1 through its own SDK, under its own privacy policy, when an ad is shown. We do not share data with third-party analytics providers.

6. Retention and account deletion

Account and gameplay data is retained while the account is active. When you request account deletion:

We cannot promise that "everything is destroyed instantly and irreversibly" — a competitive game needs to preserve the integrity of past matches. See the Delete Account page for details and the request process.

7. User rights

Users may request access, correction, or deletion of their account data. Identity verification may be required for a deletion request (e.g. confirming your username). See Delete Account and, for users in Turkey, the Data Protection Notice (KVKK).

8. Children's privacy

BlockRivals does not knowingly target the collection of personal data from children. The age groups the app may be offered to, and any parental consent requirements, are evaluated separately based on the rules of each publication country and store age ratings. If you believe a child's data has been processed improperly, contact us.

9. Security

We apply authentication, access control, and infrastructure security measures to protect data (recovery codes and session tokens are stored as cryptographic hashes, never as plain text). No system is completely risk-free, however.

10. Changes

This policy may be updated from time to time; it MUST be updated if advertising or purchase features are added. Significant changes may be communicated through an in-app notice, release notes, or the app store listing.

11. Contact

For privacy and data requests: 43softwareltd@gmail.com.