| Category | Data | Why we need it | Retention |
|---|---|---|---|
| Account | Google sub / email, display name, avatar | Login, identifying you across devices, showing you on the leaderboard (if opted-in) | Life of account + 30 days after deletion request |
| Gameplay | Owned tiles, gold, TC, quests, achievements, streaks, mining rate | Running the game, syncing progress across devices | Life of account + 30 days |
| Coarse location | ISO country + first-level administrative region (state / prefecture / county) | Regional leaderboards, RMG eligibility check | Life of account |
| Precise location | GPS coordinates (only while the "Claim Nearby Tile" flow is open) | Verifying you're within tile range for a claim | Not persisted — used in-memory only |
| Device | OS, model, app version, install ID, IP address (short-lived) | Bug reports, fraud prevention, ad delivery | IP retained 90 days; other fields life of account |
| Purchases | Store receipts, RevenueCat entitlement, product SKU (never card numbers) | Restoring purchases, refund handling, tax reporting | 7 years (tax law) |
| Cashouts | PayPal email, USD amount, timestamp, tax-reporting name/DOB/ID (only above the $600/£1,000 threshold) | Sending payouts, tax reporting, sanctions screening | 7 years (financial recordkeeping) |
| Analytics | Anonymised event counters (sessions, key features used) | Improving the game | Aggregated forever; raw events 90 days |
| Ads | AdMob device advertising ID (opt-out honored), coarse ad-topic profile | Serving rewarded / banner ads | Per Google AdMob retention policy |
We do not sell your personal data. We do not share your data with data brokers.
Our servers are hosted primarily in the United States. When we transfer data out of the EU/UK/EEA, we rely on the EU–US Data Privacy Framework (where the recipient is certified) and the UK Extension. Standard Contractual Clauses (2021/914) are executed with all sub-processors that are not DPF-certified. A copy of the SCCs applicable to your data is available on request.
You have the right to access and correct your data at any time from Profile → Account, and to delete your account. Non-account data (server logs, analytics) is anonymised or purged per §1 retention.
Email support.terrangold.app@gmail.com with subject "Data Subject Request" and include:
We respond within 30 days (GDPR/UK-GDPR), 45 days (CCPA, extendable once by another 45 days if we tell you why).
The App is not directed at children under 18. If we learn we have collected data from a user under 18 (or under 21 where local law applies to cashouts), we will delete the account and refund any pending cashout.
ADMIN_KEY.No system is perfectly secure. In the event of a breach affecting your personal data we will notify you and the applicable supervisory authority within 72 hours of becoming aware, per GDPR Art. 33/34 (or the local equivalent).
The App itself does not use browser cookies. It does embed the following native SDKs:
Sicarii Business LLC — Data Protection Officer
support.terrangold.app@gmail.com
EU-representative (Art. 27 GDPR): appointed on request; email us for details.
We may update this Policy. Material changes trigger an in-app prompt.
Continued use after the effective date constitutes acceptance. Prior
versions are available at
sicariibusiness.github.io/terran-gold-legal/privacy-history/.