Nurçin Ehlimanoğlu

Glow Catch · Privacy Policy · Updated 23 September 2026

What the game knows about you.

Glow Catch is a game. It has no accounts, no sign-in, no messaging and no profile. We never ask you for your name, your email address or your location, and there is nothing in the app that lets you type any of them in.

What follows is everything the app stores or sends, described plainly.

Who is responsible

The data controller is RockPaperScissors, the trading name of Nurçin Ehlimanoğlu, a sole proprietorship registered in Türkiye, reachable at nehlimanoglu@gmail.com. There is no data protection officer: the business is one person, and that person reads the address above.

What stays on your device

Your progress is saved on the phone itself, using Apple's standard storage (UserDefaults). It never leaves the device, and we cannot read it. It holds:

  • which levels you have unlocked and how many stars each one has
  • gold, energy, boosters, and anything you have bought
  • daily-reward streak, weekly stars, event progress
  • whether sound is muted

Deleting the app deletes all of it. There is also a reset inside Settings that clears your progress. Neither can undo a purchase — purchases live with your Apple ID, not with us, and can be restored.

What the app sends

Analytics — Google Firebase

We record how the game is played so we can tell which levels are unfair and which parts people stop at. These are the events, in full:

EventWhat it carries
session_startfurthest level, gold, stars
level_startlevel, kind, chapter, attempt number
level_completelevel, stars, seconds, reward
level_faillevel, reason, progress, seconds
gate_blockedwhere you were stopped
gold_earned, gold_spentin-game currency in and out

Alongside them we set two properties: how far you have got and how many stars you hold.

None of that identifies you. Firebase itself also collects standard technical information we do not choose the contents of — an app-instance identifier, your device model and operating system version, and a coarse country or region worked out from your IP address. Firebase's own terms cover that; see Firebase privacy.

Crash reports — Firebase Crashlytics

When the game crashes, a report is sent so the fault can be found. It carries the technical state of the crash — the stack trace, your device model and iOS version, how much memory was free — and the little we add on purpose: which level you were on, which attempt, and what the game was doing at the time, such as showing a screen or returning from one.

There is no name, no address and no account in a crash report, because the game holds none. Crashlytics' own terms cover what Google does with it; see Firebase privacy.

Advertising

Glow Catch shows advertisements from version 1.2. They appear in two places and nowhere else: a full-screen ad between levels, and an ad you choose to watch in exchange for something — another attempt, a revive, a skip. There is no banner, because this game is played by tapping and a strip of advertising along the bottom would cost you lives.

The ads are filled by AppLovin MAX, which runs an auction between several ad networks for each slot and shows whichever bids highest. The networks that take part are AppLovin, the AppLovin Exchange, Unity Ads and Google AdMob. Each of them receives the request and, with it, your device's advertising identifier where you have allowed one, along with your approximate location by country, your device model and its operating system version. They use it to choose an ad and to count whether it was seen.

We also send the auction two facts about you, and no more: whether you have ever bought anything in this game, and which of five bands your progress falls into. Neither is tied to your name, because we do not have it.

Measurement. Two further SDKs tell us which advertisement brought someone to the game, so we know which campaigns to stop paying for: AppsFlyer, which also receives what an ad impression earned, and Meta's SDK, for advertising we run on Facebook and Instagram. They receive the same device-level identifiers, not your profile on those services.

You are asked first. On iOS the system asks whether Glow Catch may track you across other companies' apps and websites; if you decline, the advertising identifier is withheld and the ads you see are chosen without it. In the EEA and the UK you are additionally shown a consent form, run by Google's User Messaging Platform, before any personalised advertising happens. You can reopen that form at any time from Settings → Ad consent, and change your answer.

Why we are allowed to do this

Under the GDPR the basis is legitimate interest (Article 6(1)(f)): knowing which levels are unfair and which crashes are real is what makes the game fixable, and it is done with data that identifies nobody. We balanced that against your privacy by collecting no contact details, no location beyond a country, and nothing you type — because the game gives you nothing to type.

Advertising is different, and is not done on that basis. Personalised advertising, and the advertising identifier it runs on, happen only where you have agreed to them — through the iOS tracking prompt, and in the EEA and the UK through the consent form described above. That agreement is the whole of the permission: withhold it and the ads still appear, chosen without anything that follows you between apps. Withdrawing it later is a setting, not a request to us: Settings → Ad consent, or Apple's own Settings → Privacy & Security → Tracking.

You can end the rest of the processing at any time by deleting the app. There is no account to close, because there was never one to open.

How long it is kept

Individual analytics events are held for 2 months, and the anonymous identifier a device is counted under for 14 months after its last event; Google deletes both when the period runs out. What survives is the aggregate — how many people cleared level nine, not which device did. Crash reports are kept by Crashlytics for around 90 days and then removed. Nothing is archived elsewhere, and we never sell or rent any of it. What the ad networks receive is described under Advertising above; each keeps it under its own retention terms, which we do not set and cannot shorten.

Where it goes

Both services are run by Google, so the data leaves Türkiye and the EEA and is processed in the United States and other countries where Google operates. Google covers those transfers with the European Commission's standard contractual clauses and its own certification under the EU–US Data Privacy Framework; their terms are at Firebase privacy.

The advertising and measurement companies named above — AppLovin, Unity, Google, AppsFlyer and Meta — are established in the United States and process the data there and wherever else they operate. Each relies on the standard contractual clauses, and on the EU–US Data Privacy Framework where it is certified under it. Their own policies are the authority on what they do with what they receive: AppLovin, Unity, Google, AppsFlyer, Meta.

Children

Glow Catch is not directed at children under 13, and we do not knowingly collect anything from them. If you believe a child has been tracked through this app, write to us at nehlimanoglu@gmail.com and we will remove what we can.

Your rights

Because we hold nothing that identifies you, there is usually nothing for us to look up, correct or delete on request. If you are in the UK, the EU, or a state with comparable law, you may still write to nehlimanoglu@gmail.com and we will help as far as the data allows.

  • Stop personalised advertising: Settings → Ad consent inside the game reopens the consent form, and Apple's Settings → Privacy & Security → Tracking withdraws the tracking permission. Ads continue either way; they stop being chosen from what you did elsewhere.
  • Remove advertising entirely: the Remove Ads purchase.
  • Stop analytics: delete the app. There is no in-game switch, because there is nothing switchable left once the app is gone.
  • Delete everything: delete the app.

In Türkiye the same applies under KVKK (Law no. 6698): we do not hold personal data that identifies you, so there is no record to hand over or erase, and the routes above are the ones that work.

If you think we have handled this badly, you can complain to a regulator without going through us first: your national data protection authority in the EEA, the Information Commissioner's Office in the UK, or the Kişisel Verileri Koruma Kurumu in Türkiye.

Changes

If the app starts collecting something new, this page changes before the version that does it ships, and the date at the top changes with it.

Contact

RockPaperScissors (Nurçin Ehlimanoğlu)
nehlimanoglu@gmail.com
A sole proprietorship registered in Türkiye. Governed by the law of Türkiye.