Tankapult Privacy Policy

Effective date / Date d’effet: August 13, 2026 / 13 août 2026 · Last updated / Dernière mise à jour: August 15, 2026 / 15 août 2026

This Privacy Policy explains how Tankapult handles information in the Android beta and web versions of the game. In supported Android production versions, a player must connect a Google account and complete a protected cloud-save baseline before persistent gameplay is enabled. Firebase services provide the account, cross-device cloud save, ranking, purchase verification, existing ad-free entitlement restoration, and official Tankapult inbox. Google Play processes optional purchases. The web version may expose a smaller local-only feature set.

English / Français

1. Information we collect

Tankapult does not provide its own password, email-entry, phone-number, precise-location, contacts, message, or payment-card form. A private technical Firebase identity is created automatically. On supported Android production versions, Google sign-in is required before gameplay. The Google ID credential sent to Firebase Authentication can contain the player's Google display, given, and family names, email address, unique Google account identifier, and profile-picture URL. Firebase also generates a project-specific user identifier. Tankapult does not display the Google name, email, account identifier, or profile picture in its public leaderboard.

Firebase Authentication and App Check may additionally process IP address, user-agent, app, device, license, and integrity-attestation information to authenticate the account and protect the backend from abuse.

The game stores gameplay progress and a bounded inbox cache locally on the player's device, including:

2. Local storage

Tankapult uses local device storage, such as browser localStorage inside the game WebView, to keep progress and settings on the device. In Android production, after the required Google connection, the complete supported versioned gameplay save is sent over an encrypted connection to Tankapult's protected Firebase backend before persistent gameplay is enabled. This cloud save includes progression, currencies, upgrades, statistics, missions, settings, profile progression, unlocks, and monotonic inbox receipts. Official message titles, bodies, and reward definitions remain in separate protected mailbox records and in the bounded local inbox cache; they are not duplicated inside the cloud-save document.

Players can reset local progression from the in-game settings. Android backup is disabled for Tankapult, so uninstalling the app removes its locally stored game data. The required Google-linked cloud copy can be restored after reinstalling or changing compatible devices.

3. Audio, haptics, and device features

Tankapult uses local audio files included with the app for music and sound effects. The haptics setting may use the device vibration feature when supported. These features do not collect personal information.

4. Rewarded ads and Google AdMob

The Android bundle includes the Google Mobile Ads SDK, its startup provider, and the Android advertising-ID permission. Android v105 keeps rewarded placements unavailable. Android v106 can offer an optional rewarded ad only after the player chooses a specific reward and the consent state allows an ad request. A native ad callback never grants resources by itself: Google's signed server-side-verification callback must match a short-lived Tankapult intent before the protected backend commits the reward. Tankapult does not use banner, forced interstitial, app-open, or gameplay-interrupting ads.

Google Mobile Ads may automatically collect and share:

Tankapult stores bounded rewarded-ad security records such as an opaque intent, receipt and transaction ID, reward type, status, timestamps, daily quota or cooldown, and, for a run reward, an opaque run/effect identifier. These records prevent duplicate rewards, support interrupted delivery, and detect fraud. They do not contain the content of the advertisement.

Google states that this data is collected and shared automatically for advertising, analytics, and fraud prevention, and that it is encrypted in transit. See the Google Privacy Policy and Google Mobile Ads data disclosure.

5. Consent and privacy choices

Tankapult includes Google's User Messaging Platform on Android. If rewarded ads are enabled, consent information is requested and, where required, a consent form is presented before an ad request. A Privacy choices button is available in the game settings when Google requires that option. If the resulting consent state does not allow an ad request, the rewarded ad remains unavailable and no reward is granted. The Mobile Ads SDK is part of the Android bundle, so the automatic SDK processing described in section 4 is included in Tankapult's Google Play Data Safety declaration whether or not a particular request can be shown.

6. Optional Google Play purchases

The Android version may offer optional one-time resource products, such as shell packs and a starter offer. New lifetime no-ads sales are suspended in v105 and can be offered again in v106 after the protected reward flow is available. Existing lifetime no-ads entitlements remain restorable, and an existing time-limited entitlement can be restored if it was delivered through an eligible Google Play Points promotion. Product availability can vary by account, country, catalog state, and release.

Google Play processes the payment or Play Points redemption. Tankapult does not receive or store payment-card details or a Play Points balance. To verify and restore an entitlement, Tankapult sends the Google Play purchase token and product identifier to a protected Firebase Cloud Function. The backend may store the Firebase user identifier, an obfuscated billing account identifier, product identifier, protected purchase token and its cryptographic digest, order and purchase metadata returned by Google, acknowledgement or consumption state, delivery records, entitlement dates, refund or revocation state, and verification status. This information is used to deliver purchased resources or existing entitlements, prevent duplicate or fraudulent delivery, restore eligible purchases, and meet legal or platform obligations. It is not displayed publicly.

Google Play's purchase and refund processing is governed by the Google Play Terms of Service and the Google Privacy Policy.

7. Tankapult player profiles and worldwide ranking

Tankapult automatically creates a private technical identifier through Firebase Anonymous Authentication. Players choose a public in-game nickname and avatar. The game sends that nickname, avatar, best eligible distance, update timestamps, and a separate opaque public player identifier to the Tankapult worldwide leaderboard. Other players do not receive the Firebase Authentication identifier. Google linking is required for Android gameplay but does not expose the player's Google profile in the public leaderboard.

The leaderboard uses Firebase Authentication, Cloud Firestore, callable Cloud Functions, and Firebase App Check. The app cannot directly write an authoritative score: eligible runs are checked by server-side functions before a ranking is updated. Firebase may process the anonymous identifier, IP address, app interactions, and diagnostics needed to provide and protect the service. For Android production, Firebase stores the versioned gameplay save (progression, currencies, upgrades, missions, settings, profile level and unlocks) for cross-device restoration. Purchase verification and existing ad-free entitlements are handled as described in section 6.

Players can hide another player from their own leaderboard and report an inappropriate nickname, impersonation, or suspected cheating. A private report may retain the reporting and reported anonymous identifiers, the reported public profile details, the selected reason, and timestamps for abuse prevention and moderation. Reports are not displayed in the public leaderboard.

A profile-only surface may expose a narrower Delete online profile action that removes only the public leaderboard profile, legacy leaderboard-run record, and personal block list; that action is not account deletion. In the Android production app, Settings > Account > Delete my account and data and the Android profile deletion control both start the complete account-deletion process described in section 12. See the Firebase privacy information and Google Privacy Policy.

8. Player inbox, official messages, and rewards

Tankapult's inbox receives official service, update, season, compensation, and reward messages. Players do not compose or send inbox messages to other players. The protected Firebase backend may store an opaque mailbox identifier, the intended audience, message type, sender, title and body in the supported languages, availability and expiry dates, reward amounts in in-game gold, shells, or energy, publication status, and limited audit metadata. A Firebase Authentication identifier is not exposed as the public mailbox identifier.

Opening a message creates or updates a read acknowledgement. Before a reward is added to the player's saved economy, the backend creates an idempotent reserved acknowledgement. After the saved reward is confirmed, it records a claimed acknowledgement. A receipt may contain the message and opaque mailbox identifiers, read/reserved/claimed timestamps, an opaque delivery identifier, and a cryptographic reward-payload hash. These receipts prevent duplicate rewards and allow interrupted claims to resume; they are not advertising analytics.

Monotonic receipt state may be included in the Google-linked cloud save, while full message content remains in the separate mailbox service and the bounded device cache. Expired or revoked messages are removed from the active inbox. Revocation does not remove a reward already claimed, and a reward reserved before expiry or revocation may still be completed safely. Authorized Tankapult operators may view message history and bounded receipt counts for delivery, support, abuse prevention, and audit purposes.

9. Play Integrity and in-app updates

Firebase App Check uses Google Play Integrity in the Android release. When an integrity check is requested, Google Play may process the request hash or nonce, app package/version/signing metadata, the signed-in account's Play license status, and device-attestation information. Google states that this data is encrypted, is not transferred to third parties, is retained for a fixed period, and is used to verify app, license, and device integrity.

Tankapult also uses the Google Play In-App Updates library. When an update check is made, Google Play may process device metadata, the installed application version, and the list of installed modules or asset packs to determine update availability and expected size. Google states that this data is encrypted, is not transferred to third parties, and is deleted after a fixed retention period.

10. Children's privacy

Tankapult is a family-friendly arcade game, but it is not directed to children under the applicable minimum age. The current account, cloud, purchase, security, and SDK processing described in this policy applies whenever those features are used; it is not deferred to a future version. YskillStudio does not knowingly seek additional personal information from children. A parent or guardian may use the privacy contact below for questions or a verified account-deletion request.

11. Data sharing

YskillStudio does not sell or rent player information. Google may collect and share the advertising-related data described above when its Mobile Ads SDK is used, and Google Play processes optional purchases and redemptions. Firebase processes the online profile, ranking, security, purchase-verification, mailbox, and receipt data described above as a service provider. For Android production, Tankapult sends the complete supported versioned gameplay save described in section 2 to its protected Firebase backend for synchronization and restoration.

If a player deliberately uses the invitation/share feature, Tankapult transfers app-generated invitation text, the Google Play link, and the current or best distance shown in that text to the external app or channel selected by the player, such as the Android share sheet, WhatsApp, SMS, or email. This happens only after a specific user-initiated action; the selected service handles the transferred text under its own terms and privacy policy.

12. Account and data deletion

Tankapult provides an in-app path to permanently delete the app account and its associated data. In the Play-installed Android version, open Settings > Account > Delete my account and data, use the currently linked Google account, and complete both confirmation screens. Keep the app open and connected while it securely retries bounded deletion steps. The action is complete only after the server confirms completed; Tankapult then signs out and erases the local save and identity data.

If the app is unavailable, use the bilingual external deletion page at https://yskillstudio.github.io/Tankapult/delete-account.html or email contact@yskillstudio.com. Email requests are normally completed within 30 days after account ownership is verified. Support email content and verification evidence are used only to handle and document the request and are then deleted or minimized, except for narrow proof needed for security, fraud prevention, legal compliance, or completion audit.

Deletion removes the Firebase Authentication account; cloud saves and recovery guards; public profile, scores, runs, tickets, streams, receipts, progression and account-mutation records; mailbox account and receipts; billing entitlements, grants, deliveries and purchase intents; rewarded-ad intents, receipts, run claims, quotas and cooldowns; block lists, report limits, identity-link backups, and other records owned by that account. Cross-account moderation and ownership references are anonymized when deleting them would harm another player's security or purchase evidence.

Tankapult retains only: a minimal technical deletion tombstone keyed to the former Firebase user identifier for the lifetime of the service to prevent deleted data from being restored; an anonymized Google Play purchase anti-replay/legal proof when a purchase belonged to the deleted account; and anonymized moderation or completed identity-link proof when necessary to protect another player or purchase owner. Retained purchase proofs contain hashes and limited product/state timestamps, not the raw purchase token, raw order ID, former account binding, region, or Google profile. These narrow records are not used to recreate the account, advertising, or gameplay. Deleting Tankapult does not delete the player's Google account or Google's own Play transaction records.

13. Changes to this policy

This policy may be updated when Tankapult changes its features, SDK configuration, analytics, online services, cloud save, purchases, accounts, or other data-related systems.

14. Contact

For privacy questions or an alternative account-deletion request, email contact@yskillstudio.com. Never send a password, Google/Firebase token, purchase token, or payment-card information by email.

Résumé en français

Tankapult crée une identité technique Firebase. Dans les versions Android prises en charge, la connexion à un compte Google et la validation d'une base cloud sont obligatoires avant de jouer. Le justificatif Google transmis à Firebase peut contenir le nom affiché, le prénom, le nom de famille, l'adresse e-mail, l'identifiant Google unique et l'URL de la photo de profil. Ces informations Google ne sont pas affichées dans le classement public.

La progression, les pièces, les améliorations, les missions et les réglages sont sauvegardés localement et la sauvegarde de jeu versionnée complète prise en charge est envoyée au backend Firebase protégé de Tankapult pour la synchronisation et la restauration sur Android. Les sons sont des fichiers locaux inclus dans l'application. Les vibrations sont optionnelles. Google Mobile Ads peut traiter l'adresse IP, les interactions, les diagnostics et des identifiants d'appareil pour la publicité, l'analyse et la prévention de la fraude. Elles restent indisponibles dans v105. Dans v106, une publicité récompensée est facultative et la récompense n'est validée qu'après la vérification côté serveur de la signature Google. Tankapult conserve des identifiants opaques de demande, de reçu et de partie, le type de récompense, le statut, les horodatages, les quotas et les délais nécessaires pour empêcher les doublons et reprendre une livraison interrompue. Un formulaire de consentement et un accès aux choix de confidentialité sont affichés lorsque la réglementation l'exige. Google Play traite les paiements ou échanges Play Points. Tankapult ne reçoit pas les coordonnées bancaires ni le solde Play Points, mais son backend vérifie le jeton d'achat des packs de ressources optionnels et conserve les informations minimales nécessaires à la livraison, à la restauration et à la lutte contre la fraude. Les nouvelles ventes sans publicité sont suspendues dans v105 et peuvent être proposées à nouveau dans v106 ; les droits existants restent restaurables.

La boîte aux lettres reçoit uniquement des messages officiels de Tankapult ; les joueurs ne peuvent pas s'envoyer de messages. Le backend conserve séparément le contenu du courrier et les récompenses éventuelles. Des accusés lu, réservé et réclamé, avec leurs horodatages et des identifiants techniques opaques, permettent d'éviter un double cadeau et de reprendre une récupération interrompue. L'état monotone de ces accusés peut faire partie de la sauvegarde cloud, mais le contenu complet des messages reste dans le service de courrier séparé et dans un cache local borné.

L'action Supprimer le profil en ligne reste limitée au classement. Pour supprimer définitivement le compte et les données associées, utilisez Réglages > Compte > Supprimer mon compte et mes données avec le compte Google actuellement lié, puis validez les deux confirmations. En l'absence d'accès à l'application, utilisez la page externe de suppression ou écrivez à contact@yskillstudio.com. Une demande par e-mail est normalement traitée dans les 30 jours suivant la vérification du compte. Les sauvegardes, le profil, les parties, la boîte aux lettres, les droits et livraisons sont supprimés ; seuls un marqueur technique anti-restauration et des preuves minimales anonymisées d'achat, de sécurité ou de modération peuvent être conservés comme décrit en section 12.