PRIVACY POLICY & DATA RIGHTS
Effective Date: September 23, 2026. Compliant with Apple App Store Guideline 5.1.1, GDPR (EU/UK), and California Consumer Privacy Act (CCPA).
Looking to Delete Your Account?
In accordance with Apple Guideline 5.1.1(v) and GDPR Art. 17, you can execute irreversible account erasure online.
1. Introduction & Data Controller
Plot Armor (“Plot Armor”, “we”, “us”, or “our”) operates the Plot Armor mobile game client (iOS and Android), web game party client (localhost:3000), and related online services.
We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, disclose, and safeguard your information when you use our cross-platform multiplayer games and websites.
Data Protection Officer (DPO) Contact: via the Support page • Plot Armor
2. Information We Collect
We collect information in three primary categories:
A. Information You Provide Directly:
- Account Credentials: Your username and, if you provide it, your year of birth (used only to apply age-appropriate settings). Plot Armor does not use passwords.
- OAuth Identifiers: Apple Sign-In Subject ID, Google Account ID, or Discord User ID when linking authentication providers.
- Communications: Inquiries, customer support tickets, and bug reports submitted through our portals.
B. Information Collected Automatically:
- Gameplay Telemetry: Match placements, round dilemma responses, remaining hearts, answer timestamps, streak counters, Elo MMR ratings, and clan battle participation.
- Virtual Inventory & Ledger: Balances of Jade gems, Spirit Stones, Cliché Shards, unlocked cosmetic attire, auras, pedestals, and title plates.
- Anti-Cheat & Device Kinematics: Hardware model, OS version, touch tap coordinate velocity, and socket clock drift metrics used strictly to detect automated macro scripts and memory injection.
- Network Identifiers: IP addresses (anonymously hashed at ingestion), session IDs, and WebSocket connection states.
C. Transaction Information:
- Purchase receipts from Apple StoreKit and Google Play Billing (processed through RevenueCat). We never store your raw credit card numbers or financial account details on our servers; all payments are processed securely by certified third-party payment gateways.
3. Legal Bases for Processing (GDPR Article 6)
Under European data protection laws, we process your personal data under the following legal bases:
- Contractual Necessity (Art. 6(1)(b)): To operate real-time multiplayer matchmaking, maintain your persistent wallet, and deliver requested digital items.
- Legitimate Interests (Art. 6(1)(f)): To detect fraud, enforce anti-cheat competitive integrity, optimize 60fps network routing, and secure our cloud infrastructure.
- Legal Obligations (Art. 6(1)(c)): To comply with tax, corporate accounting, and law enforcement subpoena requirements.
- Consent (Art. 6(1)(a)): For optional push notifications and personalized marketing broadcasts, which you can withdraw at any time.
4. Third-Party Sub-Processors & Service Providers
We share minimal necessary data with vetted third-party service providers under strict data protection agreements:
- Apple Inc. & Google LLC: Authentication, push notifications (APNs / FCM), and app distribution.
- RevenueCat: Cross-platform receipt validation and subscription status tracking.
- Google AdMob: Ad serving for server-verified rewarded and interstitial ads. AdMob may use your device's advertising identifier to show and measure ads. Where the law requires it we ask for your consent first, on iOS the system tracking prompt decides whether the identifier is shared, and players under the age of consent are only shown non-personalised ads.
- PostHog: Product analytics. We record in-app events such as screens opened, matches played, and purchases started or completed, to understand how the game is used and to fix problems.
- Expo: Delivery of push notifications to your device through Apple and Google's notification services, and delivery of app updates.
- Cloudflare & AWS: Distributed DDoS protection, edge caching, and Redis WebSocket socket clustering.
5. Your Rights Under GDPR (EU/UK) & CCPA (California)
Regardless of your geographic location, we provide all players with full control over their personal data:
Request an export of all telemetry, match logs, and wallet history associated with your account.
Permanently erase all personal data across PostgreSQL, Redis, and mobile SecureStore via our self-service portal.
Correct inaccurate account information or update your linked authentication credentials.
Opt out of marketing telemetry and restrict automated processing of your player profile.
To exercise any of these rights, use the in-app settings menu, visit our Delete Account Portal, or contact us through the Support page.
6. Children's Privacy (COPPA & Age Restrictions)
Plot Armor is intended for audiences aged 12 and older. We ask for a year of birth so we can apply age-appropriate settings: players under 13 are limited to preset quick messages in guild chat, are shown only non-personalised ads, and are not asked for personalised-advertising consent. We do not knowingly collect more personal data from children under 13 (or under 16 in the European Union) than is needed to provide the game. A parent or guardian can ask us to delete a child's account at any time through the Delete Account Portal or the Support page.
7. Data Retention & Security Measures
We implement strict AES-256 encryption at rest, TLS 1.3 encryption in transit, and role-based access control (RBAC) across all databases. Match telemetry is anonymized after 90 days. Inactive guest accounts with zero purchase history are purged automatically after 180 days.
8. Changes to this Privacy Policy
We may update this policy periodically to reflect operational, legal, or regulatory changes. We will notify active players of material updates through in-game system mail notices or prominent banners on our website prior to changes taking effect.