ANISOMORPHIC PRIVACY POLICY

Your game data, in plain language.

Last updated: 24 July 2026

Scope

This policy covers the Anisomorphic iOS, Android, and web game. Guest play does not require you to provide a name or email. Features you choose may require the data described below.

Data we process

  • Account data: Firebase user ID, display name, public player handle, authentication provider, and—if supplied—email address.
  • Social data: friend requests, accepted friendships, direct challenges, and their status.
  • Game data: match code, seat, commands, board state, result, rating changes, leaderboard position, and timestamps.
  • Notification data: an Expo push token and device platform, only after permission is granted.
  • Operational data: request metadata, rate-limit counters, service errors, and security logs.
  • Optional analytics: a small allowlisted set of usage or crash events after explicit consent.

Recent match codes are stored locally in Keychain/Keystore-backed storage on native devices and in browser storage on the web. We do not sell personal data or use it for targeted advertising.

How and why we use it

We use data to authenticate players, connect friends, deliver challenges, validate game commands, synchronize live and correspondence matches, calculate ratings and signed-in leaderboards, preserve requested history, send turn notifications, prevent abuse, diagnose faults, and operate and secure the service. Optional analytics are off by default. Accepted telemetry uses a shortened one-way hash rather than a raw Firebase ID and excludes email addresses.

Service providers

Firebase provides identity services; Cloudflare hosts APIs, realtime rooms, storage, and operational logs; Expo routes push notifications and builds releases; Apple and Google provide optional sign-in and app distribution. Each provider processes data under its own terms and privacy commitments. Data may be processed where those providers operate.

Retention, security, and deletion

Realtime match rooms expire after 30 days without an accepted command. Correspondence games, friendships, challenges, account profiles, and opted-in push tokens remain until completion, expiry, removal, or account deletion as applicable. Operational log retention follows the configured hosting account settings. We use encrypted transport, short-lived one-time WebSocket tickets, server-side rule validation, rate limits, and platform-protected local storage.

In the app, open Account & settings and choose Delete my account and data. This deletes the profile, push tokens, local match list, and Firebase identity, and redacts the player identity in active rooms. You can also use the web deletion page.

Your choices and contact

You can decline notifications, leave analytics off, disable it later, use guest play, or delete your account. Privacy questions and requests can be sent to privacy@anisomorphic.com.

Return to Anisomorphic