Durak Online Privacy Policy
Last updated: 2026-08-29
This policy explains how Durak Online processes personal data when you use the app and its online services. The controller is AC Beauty to Customer UG (haftungsbeschränkt), Dovestraße 11, 10587 Berlin, Germany. You can contact us at contact@beauty2customer.com.
Data We Process
- Account and sign-in data: a Supabase account identifier and authentication records. You may use an anonymous account or Sign in with Apple. For Apple sign-in, we process Apple's provider identifier and your email address if Apple provides it. We request the email scope, but not your name.
- Profile and economy data: nickname, locale, selected avatar, frame, card back and table skin, league, trophies, level, XP, virtual Gold, rewards, daily-bonus and challenge progress, and VIP status.
- Friends and table-invitation data: a stable public player identifier and searchable player tag that are separate from the private account identifier, friend requests and accepted friendships, invitation sender and recipient, invitation and response status, timestamps, expiry, and live table membership or readiness state. Your public player tag, nickname, selected avatar or frame, and public social identifier may be shown to other players so they can find you, send or respond to friend requests, invite you to a table, and identify you in a lobby, match, or result screen. Your private account or authentication identifier and mutation receipts are not shown to other players. Blocking a player also prevents friendship discovery and invitations between the affected accounts.
- Gameplay data: match participation, game mode and configuration, opponents, stakes, actions, results, reconnect and settlement state, reward grants, and fair-play or abuse-prevention signals. Private card hands and future deck order are processed to run and recover a match, but are not intentionally included in product analytics or client logs.
- Purchase data: App Store product and transaction identifiers, purchase and subscription status, trial and entitlement status, purchase time, expiry or cancellation information, restore and sync attempts, refunds, and resulting virtual-item grants. We do not receive your full payment-card details.
- Product analytics: linked events such as first app open, screen views, paywall views and dismissals, purchase starts, cancellations and failures, session and match milestones, reward claims, and bounded client error codes. These events can include app version and build, locale, device model, event time, placement, product identifier, and other strictly limited event properties. Client events are submitted under the signed-in Supabase account identifier, including events queued before sign-in.
- Apple Ads attribution and RevenueCat technical data: RevenueCat collects Apple's AdServices attribution token and, where available, Apple Ads campaign, ad group and keyword attribution so we can measure installs, trials, subscriptions and revenue from our Apple Ads campaigns. RevenueCat also processes its anonymous and account-linked customer identifiers, the identifier for vendor (IDFV), app and SDK version, operating-system and device information, locale or storefront, installation information, and network metadata needed to provide its service. The anonymous RevenueCat identity created at first launch is merged into the Supabase account identifier after sign-in.
- Push notification data: if you enable notifications, we process the APNs device token, account identifier, app environment and bundle identifier, locale, current time-zone offset, notification trigger and delivery status. Locale and time-zone offset are used to choose language, respect quiet hours, and limit notification frequency.
- Crash and diagnostics data: Sentry may receive crash reports, stack traces, app hangs, performance information, app version, device and operating-system basics, and app-authored diagnostic events. Default personal-information collection and network tracking are disabled. App-authored diagnostics remove email and nickname, redact credentials and tokens, and may replace an account identifier with a one-way hash so repeated failures can be correlated.
- Safety data: player blocks and reports, including a client report identifier, the reporting account, a separate report-only identifier for the reported player, report category, nickname as displayed at the time, moderation status, and review timestamps. Reports do not contain player-authored free text. Protected administrative audit records store the report identifier, status transition, a fixed reason code, moderator account, and timestamp.
- Technical service data: our servers and service providers may process IP address, request time, security and rate-limit information, and similar connection data needed to deliver and protect the service. We do not intentionally put raw bearer tokens, Apple identity tokens, Supabase service keys, full WebSocket URLs, Colyseus session identifiers, or future deck order into analytics or diagnostic logs.
Purposes And Legal Bases
We process data on the following GDPR legal bases where the GDPR applies:
- Contract performance (Article 6(1)(b)): to create and authenticate your account, provide multiplayer matches, friendships and table invitations, preserve reconnect and settlement integrity, maintain your profile and virtual economy, and process or restore purchases and subscriptions.
- Legitimate interests (Article 6(1)(f)): to secure the service, prevent fraud and abuse, enforce fair play, investigate reports, diagnose failures, improve reliability and gameplay, understand the install-to-purchase funnel, and measure our own Apple Ads campaigns. Our interests are operating a safe, reliable product and spending advertising funds effectively; we limit event fields and identifiers to reduce the impact on players.
- Consent (Article 6(1)(a)), where required: for optional push notifications and any processing for which applicable law requires consent. You can withdraw notification permission in iOS Settings and disable notifications in the app. Withdrawal does not affect earlier lawful processing.
- Legal obligations (Article 6(1)(c)) and legitimate interests in legal claims (Article 6(1)(f)): for accounting, tax, consumer-protection, refund, dispute, security-incident, and rights-request records where applicable.
You do not have to enable notifications or use Sign in with Apple. An account identifier and the gameplay data required for an online match are necessary to provide the service; without them, online features cannot operate.
Service Providers And Sharing
We disclose only the data needed for these roles:
- Apple provides Sign in with Apple, App Store purchases and subscriptions, APNs push delivery, and Apple Ads attribution. Apple may act as an independent controller for its own services and records.
- Supabase provides authentication and the hosted database used for account, profile, friendship, invitation, gameplay, economy, purchase, notification, analytics, and safety records.
- Hetzner provides infrastructure for the Durak API, multiplayer server, operational logs, Redis state, and restricted backups.
- RevenueCat processes purchase, subscription, entitlement, restore, customer, and Apple Ads attribution data on our behalf and exchanges the necessary transaction and attribution information with Apple.
- Sentry processes crash, performance, app-hang, and sanitized diagnostic data on our behalf.
We may also disclose data where required by law, to protect players or the service, or in connection with a corporate transaction subject to appropriate confidentiality and legal safeguards. We do not sell personal data.
Where a provider processes personal data on our behalf, the applicable service terms and any data-processing agreement in force govern that processing and the provider's use of subprocessors. The relevant data-processing terms include obligations concerning documented instructions, confidentiality, security, and subprocessor safeguards.
Apple Ads And Tracking
Durak Online does not contain a third-party advertising network SDK, does not access the IDFA, and does not use app data to track you across apps or websites owned by other companies. The Apple AdServices token is used through RevenueCat only to attribute downloads and in-app purchase outcomes to our Apple Ads campaigns. We do not use it to serve behavioural advertising or combine Durak data with third-party data for cross-app targeting. This processing is therefore not tracking as Apple defines that term.
International Transfers
Our providers and their subprocessors may process data in the European Economic Area and in other countries, including the United States. The applicable transfer mechanism depends on the provider, recipient, and service configuration and may include an applicable adequacy decision, including the EU-U.S. Data Privacy Framework for a participating U.S. recipient, or the European Commission's Standard Contractual Clauses, together with supplementary measures where required. You may request more information about relevant safeguards at contact@beauty2customer.com.
Retention And Deletion
- Raw product analytics events are retained for 90 days. If you delete your account during that period, their direct account link is cleared, while the event and its limited properties remain until the 90-day cleanup.
- Account, profile, wallet, progression, cosmetics, active entitlement, notification token, and most account-linked gameplay and purchase rows are kept while the account exists and are removed when the Supabase auth account is deleted, subject to the exceptions below.
- Device tokens are deregistered when notifications are disabled or you sign out where the request succeeds, and are deleted with the account. Notification delivery records may remain while the account exists for frequency limits, troubleshooting, and delivery integrity.
- Historical match, settlement, security, provider-event, and audit records may remain after account deletion where needed to preserve game and transaction integrity, detect fraud, handle refunds or disputes, or meet legal obligations. Direct account references are deleted or set to null where supported. Some historical records may retain a pseudonymous former account identifier that no longer resolves to an active account.
- Pending player reports are deleted after 180 days. Reviewed or dismissed reports are deleted 90 days after review, and actioned reports 365 days after review. When an account is deleted, reporter links are cleared; reports about that player lose their account/profile link and the nickname snapshot becomes
Deleted Player. A report-only retry identifier may remain until the report expires. Player-identifier-free moderation audit entries may be kept for the lifetime of the service for security and accountability. - Player blocks remain until you remove them or either account is deleted.
- Friendship records remain until the relationship is removed or either account is deleted. Pending table invitations expire automatically. Invitation history and related retry receipts are kept while the relevant accounts exist, unless an operational cleanup removes expired records. Deleting an account removes its account-linked invitation records.
- Sentry data is kept according to the configured Sentry retention period and only as long as needed for reliability and security purposes. RevenueCat, Apple, Supabase, and infrastructure providers may retain limited records or backups according to applicable service settings, retention schedules, and legal obligations. We will forward a verified deletion request to processors where required and technically applicable.
- Restricted backups and operational logs can retain deleted data temporarily until normal rotation or overwrite. Backups are used for disaster recovery rather than ordinary product analytics; restoring a backup can temporarily reintroduce a record until the corresponding deletion is reapplied.
Deleting the Durak account does not cancel an App Store subscription and does not erase transaction records that Apple controls. Subscriptions must be managed separately in your Apple account settings.
Your Rights
The app includes account deletion. After signing in, open Profile and use Delete Account in the account section. The app first prevents deletion while a match or its rewards or refund are still being finalized, then deletes the Supabase account and signs the app out.
Depending on applicable law, you may request access, correction, deletion, restriction, or portability of your personal data, or object to processing based on legitimate interests. You may withdraw consent at any time where processing relies on consent. These rights can be subject to legal exceptions, including obligations to retain transaction, fraud-prevention, or legal-claims records.
Send requests to contact@beauty2customer.com. We may need to verify that the request relates to your account. You also have the right to lodge a complaint with a data-protection supervisory authority, in particular the Berliner Beauftragte für Datenschutz und Informationsfreiheit, or the authority where you live or work.
Children
Durak Online is not directed at children. Because matches use wagered in-game virtual Gold, the app carries a 17+ age rating on the App Store.
Changes And Contact
We may update this policy when the app, providers, or legal requirements change. The date above identifies the current version.
- AC Beauty to Customer UG (haftungsbeschränkt)
- Dovestraße 11, 10587 Berlin, Germany
- Privacy requests:
contact@beauty2customer.com