Privacy
Privacy Policy
Last updated: September 8, 2026
Oraks ("the App") recognizes the importance of user privacy. This Privacy Policy explains what information the App collects, how it is used, and how users can contact the developer.
1. Information We Collect
The App does not require users to create an account, log in, or provide personal contact details. However, the App may process the following information to provide its features:
- Global leaderboard: When the user opens the global leaderboard, the App uses Firebase Anonymous Authentication to create or retrieve a pseudonymous user ID and reads the leading score entries from Cloud Firestore. Firebase may also process technical information needed to secure and operate those services, such as IP address, app and device information, and diagnostic data. The App does not upload the user's local score, nickname, or selected profile image until the user separately agrees to submit a score. After that consent, each score entry stores only the pseudonymous user ID, nickname, game identifier, best score, and update time. Profile images are never copied into score entries.
- Optional device transfer: When the user asks the App to create a transfer code, the App stores a temporary recovery snapshot in Cloud Firestore. It can contain the user's nickname, selected profile image, best game scores, coin balance, individually unlocked games, nickname-change ticket balance, pseudonymous Firebase user ID, and timestamps. The readable transfer code remains on the device and is not uploaded; Firebase stores only a SHA-256 identifier derived from the code. Anyone who obtains the code may claim the snapshot, so users should protect it like a password.
- Firebase configuration and installation metadata: To retrieve app configuration such as version and update notices, feature settings, and advertising safety controls, Firebase Remote Config and Firebase Installations process a Firebase Installation ID (FID), country and language codes, time zone, platform and operating-system versions, Firebase App ID, package or bundle identifier, SDK version, and related app/device metadata. An FID identifies an app installation and does not uniquely identify a user or physical device.
- Profile photo: If the user chooses a profile image after leaderboard consent, the image is first stored in a private, owner-accessible review record in Cloud Firestore. For a first image, other players see a default avatar until the developer approves it after a safety review. When an approved image is replaced, the previously approved image can remain visible while the new image is reviewed. An approved image is stored once in the user's public leaderboard profile. A rejected image may remain in the private review record to prevent the same image from being automatically resubmitted, until it is replaced, deleted, or removed during maintenance. The App only accesses photos when the user selects a photo.
- Leaderboard safety reports: If a user reports another leaderboard player, the App stores the reporting user's pseudonymous Firebase Anonymous Authentication user ID, the reported user's pseudonymous user ID, the selected report reason, the related game ID (
gameId), and the report timestamp in Cloud Firestore. Reports are used for manual safety review; submitting a report does not automatically penalize the reported player or change a score or rank. - Blocked-player list: If a user blocks another leaderboard player, the App stores only the blocked player's pseudonymous user ID and the block time on that user's device. This personal blocked-player list is not uploaded to Firebase. Blocking hides the blocked player's nickname and profile image for the blocking user, but does not remove or change the blocked player's score or rank.
- Optional rewarded advertising: If an eligible user expressly enables rewarded advertising, the App uses Unity LevelPlay for mediation and Unity Ads as its only currently enabled advertising network. Unity may process information such as user or account identifiers assigned by Unity or its partners, device and advertising identifiers where permitted, IP address and general location derived from it, purchase history or purchase tendencies, app and device information, ad impressions and interactions, and diagnostic or performance information. The App does not invoke LevelPlay advertising initialization or request or load an advertisement until all required choices have been recorded.
- In-app purchases: Apple App Store and Google Play process purchase information required to complete transactions. The developer does not receive full payment card details.
2. How We Use Information
- Leaderboard data is used only to display and maintain global rankings.
- Device-transfer data is used only to move the listed records to another installation selected by the user and to prevent reuse of a transfer code.
- Firebase configuration and installation metadata is used to retrieve and apply app configuration, including update notices, feature settings, and advertising safety controls.
- Profile images are used only for safety review and, after approval, to show the user's chosen image in the App and leaderboard.
- Leaderboard safety reports are used for manual review of potentially inappropriate nicknames or profile images and potentially suspicious scores. After review, the developer may hide or replace an inappropriate nickname or profile image from public display and may investigate, correct, reset, or remove a suspicious score or related ranking record.
- The blocked-player list is used only on the user's device to hide a blocked player's nickname and profile image from that user. Scores and ranks remain visible and unchanged.
- When rewarded advertising is enabled, Unity may use advertising-related information to mediate, request, deliver, limit the frequency of, measure, and report advertisements; prevent fraud and abuse; maintain service performance; and comply with legal obligations, subject to the user's choices, device permissions, applicable law, and Unity's privacy policy.
- Purchase information is used only to fulfill in-app purchases and deliver virtual goods such as coins.
3. User Consent for the Global Leaderboard
Scores are stored locally on the device by default. Opening the global leaderboard creates or retrieves a pseudonymous Firebase user ID and reads leaderboard entries, but does not upload the user's local score, nickname, or profile image. Before uploading those items, the App asks for the user's explicit consent. If the user does not agree, the score remains on the device and is not uploaded to the leaderboard server.
4. Data Sharing with Third Parties
The App shares information only as needed to provide the features described in this policy:
- Google Firebase: Used for pseudonymous authentication, reading global leaderboard entries, retrieving app configuration through Remote Config and Firebase Installations, storing and maintaining the user's submitted entry only after leaderboard consent, storing leaderboard safety reports and moderation status, and storing a recovery snapshot only when the user creates a device-transfer code.
- Unity Technologies: When an eligible user enables rewarded advertising, Unity LevelPlay mediates the request and Unity Ads supplies the advertisement. No Google AdMob or AppLovin advertising SDK or network is currently enabled in the App.
- Apple App Store and Google Play: Used to process in-app purchases.
Unity's handling of information relating to game players and app users is described in the Unity Game Player and App User Privacy Policy.
Google's handling of information processed through Firebase is described in the Google Privacy Policy.
5. Data Retention and Deletion
Leaderboard entries may remain stored while the leaderboard feature is operated. Users may contact the developer to request deletion of leaderboard data associated with their nickname or Firebase anonymous user ID. Pending or rejected profile-image review records may remain until the image is approved, replaced, deleted by the user, removed during service maintenance, or deleted following an applicable request. Safety reports and related moderation records may remain as needed to review and resolve a report, protect the leaderboard, address abuse, comply with applicable obligations, or maintain the service, and may also be removed during routine service maintenance or following an applicable user request. The on-device blocked-player list remains on that installation until the user unblocks a player or the App's local data is cleared; operating-system backup or restore behavior may vary. A recovery snapshot is deleted after a successful transfer; a minimal transfer-status record may be retained to prevent reuse. An unclaimed snapshot may remain until it is transferred, replaced, removed during service maintenance, or deleted following a user request. Information processed by Firebase, Unity, Apple, Google Play, or an enabled advertising partner is otherwise retained in accordance with the applicable provider's policies. The developer does not determine every third-party retention period.
6. User Controls
- Users can choose not to submit scores to the global leaderboard.
- Users can report a leaderboard player for an inappropriate nickname, inappropriate profile image, suspicious score, or another listed safety reason. Reports are reviewed manually.
- Users can block or unblock a leaderboard player. Blocking is a personal display control: it hides that player's nickname and profile image only for the blocking user and does not change the player's score or rank.
- Creating or entering a device-transfer code is optional. The App does not create a recovery snapshot unless the user chooses that feature.
- Users can change or remove their selected profile image in the App.
- Rewarded advertising is available only after the user confirms that they are at least 16 years old. Users can open Settings > Advertising Privacy in the App to enable or disable rewarded advertising, choose personalized or contextual advertising, opt out of the sale or sharing of personal information, or withdraw a previous advertising choice. A missing, outdated, incomplete, under-16, or declined choice prevents the App from invoking LevelPlay advertising initialization and from requesting, loading, or showing advertisements.
- Contextual advertising does not use activity across other companies' apps and websites for tracking. It may still involve limited processing needed to deliver and measure an ad, prevent fraud, comply with law, and maintain the service.
- On iOS, personalized advertising and cross-app tracking are also subject to Apple's App Tracking Transparency permission. If permission is denied, restricted, or later withdrawn, the App does not make tracking a condition of receiving the rewarded-ad feature and instead requests contextual advertising where the other required choices remain valid. Users can manage Apple's permission in the device's Settings.
- Users may contact the developer regarding privacy choices or applicable privacy rights. Requests concerning information controlled by Unity may also be submitted through the options described in Unity's privacy policy.
7. Children's Privacy
The App is not directed to children under 13. As an additional safeguard applied worldwide, the optional rewarded-advertising feature is limited to users who confirm that they are at least 16 years old. The App does not invoke LevelPlay advertising initialization or request, load, or show advertisements for a user who indicates that they are under 16 or whose required age choice is missing or outdated. The developer does not knowingly use Unity advertising services through this feature for users under 16.
If a parent or guardian believes that a child has submitted leaderboard or profile information through the App, please contact the developer to request review or deletion.
8. Contact Information
Developer: Jiung Yang
Email: stacksjiung@gmail.com
9. Changes to This Policy
This Privacy Policy may be updated from time to time. Significant changes will be announced within the App or on this page.