Skip to content
DepositMonstersDepositMonstersGet the app

DepositMonstersLegalDOC 02

Privacy policy

What the app collects, where it goes and how long we keep it. Written from the game code, not from a template.

Draft pending legal reviewLast updated:

DepositMonsters is a game built on the Polish deposit return scheme: you return a container to a reverse vending machine, scan the receipt and collect Charge, which you grow a Sparkling from. For that to work, the app has to know who you are, where you are standing at the moment you press a button, and what was printed on the receipt. This document says what of that stays with us, what goes further, and what is gone at once.

Controller and contact

The data controller is [NAZWA FIRMY - do uzupelnienia], [ADRES POCZTOWY - do uzupelnienia].

Data protection officer: [to be completed by the lawyer - depends on the scale of processing and the controller’s legal form].

What data, and what for

The table below is the complete list of data the app collects or produces. There is no „and other technical data" entry in it: if something is not here, we do not collect it.

DataSourceDestinationHow long
Identity at the sign-in provider (the pair „provider and its internal identifier"), e-mail address, display nameGoogle or Apple sign-inour databaseuntil the account is deleted
Password hash for password sign-upregistrationour database, never the password itselfuntil the account is deleted
Session refresh token, stored as SHA-256app sessionour database30 days, with rotation and revocation of the whole token family
Receipt photographcamera in the appserver process memory, not disk; as a fallback Google’s vision model (Gemini) when enablednot stored
Hash of the receipt barcode (SHA-256)receiptour database, a separate collection with no owner7 days, deleted automatically by the database
GPS locationa single reading after you press „I am at the machine"server cache, as an open presence at a Zoneabout 26 hours; the permanent visit record holds no coordinates
Pin of a reported Zone: machine coordinates, address, discoverer’s accountplayerour database, and once confirmed by presence - the shared mapone day without presence confirmation, then permanently as a Zone
Settled reactivations, the Charge ledger, Sparkling state, crate, gang, challenges and matchesgameplayour databaseuntil the account is deleted; the Charge ledger is append-only by design
Device: install identifier, platform, app version, time zone, notification tokenthe app, system notification permissionour database; the token also goes to Firebase Cloud Messaging (Google)until notifications are muted or the account is deleted
Device advertising identifier, advertising consentsAdMob and the consent formGoogle AdMob; we hold none of itper Google’s policy
Purchase receipt hash (SHA-256), product identifier, store, licence statusGoogle Play or App Storeour database; verified against Google Play Developer API and App Store Server APIthe record stays even after the account is deleted - see section 11
Server errors with a request identifierserverSentryper the retention setting in Sentry
Roblox player identifier after pairingDepositMonsters Tycoonour databaseuntil the account is deleted
Email address from the wishlist, platform, page languageform on the websiteCloudflare R2, EU jurisdictionuntil the launch notification is sent or consent is withdrawn
Entries into the game on Roblox and time spent in it (paired accounts only)DepositMonsters Tycoonour database90 days
IP address and request logsserver and hosting providerRender, our infrastructurebriefly, for technical reasons [to be completed: exact log retention period]

Lawful bases

  • Performance of a contract (Art. 6(1)(b) GDPR): the account, gameplay, settling receipts, Charge, duels, licence sales.
  • Consent (Art. 6(1)(a) GDPR): personalised advertising, push notifications, location readings. Each can be withdrawn, and withdrawing it does not take away access to the game.
  • Legitimate interest (Art. 6(1)(f) GDPR): detecting fraud and abuse, account security, error diagnostics, defence against claims.
  • Legal obligation (Art. 6(1)(c) GDPR): settling purchases and complaints [to be completed by the lawyer: which obligations exactly and for how long].

Accepting the terms and confirming your age are conditions for creating an account - without them no account is created at all.

The receipt and its photograph

A receipt travels like this:

  1. The app takes a photograph and sends it to our server. The server holds it in process memory for the duration of the read.
  2. We decode the barcode ourselves, locally. The receipt text is first read by Tesseract, a program running on our own server, without sending anything outside.
  3. If that read fails and the fallback vision model is enabled, the same photograph - scaled down to 1024 pixels on the longer edge - goes to Google (the Gemini interface) purely to transcribe the numbers from it. The model does not read the barcode and receives no account data. This path is switched off on our side with a single setting, and then nothing goes anywhere.
  4. What stays with us from a receipt is only the SHA-256 hash of the barcode digits, in a separate collection, with no owner, amount, time or shop. The database deletes it by itself after 7 days. It serves one purpose: making sure the same receipt cannot be settled twice.
  5. The permanent settlement record says only this: this account received this much Charge at this Zone, with this status and this number of items. Nothing from the receipt content is in it.

Location

The reading goes into the server cache as an open presence at the chosen Zone and disappears from it by itself after about 26 hours, that is after the time in which a receipt can no longer be settled anyway. The record that stays permanently says only which Zone the settlement happened at - with no coordinates.

Separately: when you report a new Zone, the coordinates of the machine and its address become - once confirmed by your presence - a point on the shared map, visible to all players. The Zone also permanently records that your account discovered it. That is the location of the machine, not yours, but it is worth knowing it is public.

Sign-in and identity

You sign in with a Google or Apple account; you can also create one with a password. We store the identity as the pair „provider and its internal identifier" - never as the e-mail address alone. The e-mail address, if the provider supplies one, serves two purposes: contact and linking accounts.

  • Linking accounts works only on a verified address. An account created with a password is unverified, so Google or Apple sign-in cannot be attached to it. That is a safeguard, not an inconvenience: without it someone could create an account on somebody else’s address and wait for the owner to sign in with Google straight into an account whose password the attacker knows.
  • We keep passwords only as hashes. We do not know the password itself and it cannot be reconstructed from the database.
  • From Apple we store one additional token, solely so that we can revoke the link on Apple’s side when an account is deleted. We use it for nothing else and send it nowhere but Apple.
  • Each account gets a public six-character code, by which other players find you to issue a challenge. Your Sparkling name is the same code written in syllables, not a separate field in the database. The rival search matches only a full code or a full name, never a fragment of an account name: that list is deliberately not an address book.
  • We also record the date of age confirmation and terms acceptance - that is a requirement, not a statistic.

Advertising and consent

The app is free and shows full-screen adverts served by Google AdMob. Neither adverts nor money ever give Charge or any advantage in the game.

Full-screen adverts appear in three places and only there:

  • on the mini-game round summary, after the result has been shown;
  • on the Launcher match summary;
  • when leaving the games screen.

The list of places without adverts is closed:

  • the entire path at the machine: choosing a Zone, presence, camera, receipt result;
  • hatching the Capsule and a new player’s first day;
  • care routines for the Sparkling;
  • the map while looking for a machine;
  • first launch, language choice, sign-in and consent screens.

To serve an advert AdMob uses the device advertising identifier and data about events in the app. That data goes to Google, not to us: we hold neither the advertising identifier nor an advertising profile of a player.

In the European Economic Area and the United Kingdom we show a consent form (Google User Messaging Platform) before the first advert. Until it is answered, no advert is served. Consent can be withdrawn or changed at any time in the app settings, in the documents section. Refusing personalisation does not switch adverts off - it switches personalisation off. On iOS the system asks separately for tracking permission (App Tracking Transparency), and its absence means non-personalised adverts.

We do not store the consent state ourselves - it is owned by the provider’s software and by the operating system.

A single licence purchase removes full-screen adverts forever, on every device of that account. Voluntary adverts, the ones a player starts themselves, keep working after the purchase and likewise give no Charge.

Purchases and the licence

The ad-free licence is bought in Google Play or the App Store. The store handles the payment: we neither see nor store card details or any other payment data.

After a purchase the store issues a receipt. What stays with us is:

  • the SHA-256 hash of the receipt - so that one purchase cannot unlock two accounts;
  • the product identifier, store name, purchase date and licence status.

We verify the receipt directly with the issuer (Google Play Developer API, App Store Server API); the app’s own claim is not enough for us. We also listen to store refund notifications: a refund extinguishes the licence, and its record stays with the status „refunded", so that the question of why the adverts came back can be answered.

The licence belongs to the account in our database, not to a phone and not to a store account.

Notifications

Notifications are optional. We ask for the system permission only at the first arranged duel, not at app start.

We send two kinds of notification and only those two:

  • your turn in an arranged duel;
  • Charge running out, at most once a day.

Sending one requires a device token from Firebase Cloud Messaging (Google). We store it together with the install identifier, platform, app version and the device time zone. The time zone is needed so that nobody is woken at night: a notification falling between 22:00 and 08:00 in the player’s own time waits until morning instead of being discarded.

Muting in the app settings deletes the token from our database, so we have nowhere to send a notification. We do not copy the system permission on our side - its only owner is the operating system, and that is also where it can be withdrawn.

The game on Roblox

DepositMonsters Tycoon is a separate place on the Roblox platform where your Sparkling from this app works in the plant you are rebuilding. It has not been released yet.

  • Accounts are linked with a pairing code generated in our app: one code per account, valid for a few minutes, single use. The code is typed into the game on Roblox. We do not use the public account code for this, because other players know that one.
  • Plant progress is saved by Roblox on its own servers and we do not keep it. For paired accounts we do record entries into the game and time spent in it (these events are deleted after 90 days), so that support can see what happened. None of it affects gameplay in the app.
  • After pairing we store the Roblox player identifier on our side and tie it to the game account. Roblox passes us that identifier alone - we receive no player name, no e-mail address and no other data from the Roblox account.
  • The link is one-time and cannot be undone from the app. One Roblox account corresponds to one game account and the other way round. A mistake is corrected by support, because that is the only place with a human on the other side. The link disappears together with the account.
  • Everything that happens on the Roblox platform is subject to the terms and privacy policy of Roblox Corporation. We have no influence over what data Roblox collects there. DepositMonsters is not affiliated with Roblox Corporation.

Recipients of the data

We do not sell data and do not share it for anyone else’s marketing. We do however use providers without which the app would not work.

RecipientWhat forWhat it receives
Googlesign-in, notifications (Firebase), advertising (AdMob), the Google Play store, fallback receipt reading (Gemini)sign-in identity, notification token, advertising identifier and consents, purchase receipt, and in a fallback read also the receipt photograph
Applesign-in, the App Storesign-in identity, purchase receipt
MongoDB Atlasthe game database, Frankfurt region (European Union)all account and gameplay data listed in section 2
Renderserver hosting and cache, Frankfurt region (European Union)network traffic, request logs, data in processing
Sentryserver error reportsthe error content and the request identifier
Cloudflarestoring the launch wishlist (R2, EU jurisdiction)email address, platform and page language from the wishlist form
Roblox CorporationDepositMonsters Tycoon, once accounts are pairedthe Roblox player identifier and the Sparkling card data computed from gameplay

How long we keep data

  • Receipt photograph - not stored at all.
  • Barcode hash - 7 days, deleted automatically by the database.
  • Location reading - about 26 hours in the cache, then gone by itself.
  • A pin without presence confirmation - one day, then it deletes itself.
  • Session refresh token - 30 days, rotated on every use.
  • Notification token - until notifications are muted or the account is deleted.
  • Account, identity and gameplay data - until the account is deleted. What exactly happens on deletion is described on the account deletion page.
  • The licence record - stays even after the account is deleted, because it is proof of purchase and the basis for settlement [to be completed by the lawyer: the exact period, following from accounting and limitation-of-claims rules].
  • Zones on the shared map - they stay, because they describe a machine, not a player; after the account is deleted the discoverer note no longer points to an existing account.

Your rights

You have the right to:

  • access your data and obtain a copy of it;
  • rectify inaccurate data;
  • erase data;
  • restrict processing;
  • port data processed on the basis of a contract or consent;
  • object to processing based on legitimate interest;
  • withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
  • lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).

We accept requests at support@depositmonsters.com. The fastest route to erasing your data is, however, the app itself - the account deletion page describes it.

We do not take decisions about players based solely on automated processing that would produce legal effects for them. An automated check does flag suspicious receipt settlements and suspicious mini-game runs; such a case is then looked at by a human in the support panel.

Security

  • All communication between the app and the server goes over HTTPS.
  • The access token lives 15 minutes, the refresh token 30 days and sits in the database only as SHA-256. It is rotated on every use, and an attempt to use a spent token revokes the whole session family.
  • Passwords are kept as hashes; purchase receipts and receipt barcodes likewise only as hashes.
  • The database and the server are in the Frankfurt region, with backups and point-in-time recovery.
  • Only accounts with an assigned role can reach the support panel; a role cannot be granted to oneself from the app.
  • We collect as little as we can - hence no receipt photo store, no background tracking and no copy of advertising consents of our own.

Children and age

The game is intended for people aged 16 and over. Confirming your age is a condition for creating an account. We do not direct the app at children and we do not knowingly collect data of people below that threshold. If we learn that an account was created by someone younger, we will delete it together with the data.

Launch wishlist

On the website you can leave an email address to get one notification on the day the app launches. Signing up does not require an account and is not linked to a game account.

  • We store the email address, the platform if you chose one, the language of the page you signed up from (the notification goes out in it), the sign-up date and the version of the consent text. Nothing else - no IP address, no browser data.
  • The legal basis is consent (Art. 6(1)(a) GDPR). You withdraw it by writing to support@depositmonsters.com - we then remove the address from the list.
  • The list is kept in Cloudflare R2, under European Union jurisdiction, and cannot be read through the website - only with an administrator key.
  • To send the notification we will pass the addresses to an email provider [to be completed: Brevo or another], for the duration of the send only.
  • Once the launch notification is sent, we delete the whole list. We do not use the address for anything else and we do not sell it to anyone.

Changes to this policy

We will give notice of material changes in the app before they take effect. The date of the last change is at the top of this page. A change that requires consent will not take effect without asking for it.