The terms by which we guard your information, set down in good faith.
1. Introduction
This Privacy Policy explains how Johnathon Nicolaou (“we”, “us” or “our”) collects, uses, discloses, stores and protects personal information in connection with the mobile application The Lost Artefacts (the “App”) and any related services we provide.
We are committed to protecting your privacy and handling your personal information in accordance with:
- ◆the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs);
- ◆the EU General Data Protection Regulation (GDPR) and the UK GDPR, where applicable;
- ◆the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), where applicable; and
- ◆Apple’s App Store Review Guidelines, App Privacy requirements and App Tracking Transparency framework.
By downloading, accessing or using the App you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Policy, please do not use the App.
2. Who we are
The App is published and operated by:
- ◆Name: Johnathon Nicolaou (operating as a sole trader)
- ◆Jurisdiction: New South Wales, Australia
- ◆Contact email for privacy matters: thelostartefacts@gmail.com
For the purposes of the GDPR, we are the “data controller” of personal information we collect through the App.
3. Scope of this Policy
This Policy applies to personal information we collect:
- ◆when you download and install the App from the Apple App Store;
- ◆when you create an account, sign in, or use any account-related feature within the App;
- ◆when you play the App as a guest (without signing in);
- ◆when you take part in online play, ranked competition or friend battles;
- ◆when you create or redeem a referral code;
- ◆when you make an in-app purchase;
- ◆when you contact us for support, enquiries or to exercise your privacy rights; and
- ◆when you visit any website operated by us that links to this Policy.
This Policy does not apply to the collection, use or disclosure of information by Apple Inc. in connection with the App Store, by Google LLC in connection with the Firebase platform we use, by Meta Platforms, Inc. in connection with the advertising measurement described in section 4.6, or by any third-party website or service that the App may link to. Those parties are governed by their own privacy policies.
4. Information we collect
The type of information we collect depends on how you use the App. We collect only what we reasonably need for the purposes described in this Policy.
4.1 Information you provide directly
- ◆Account registration information: when you choose to create an account, we collect your email address, a password, and a username of your choice (between 3 and 16 characters). Your password is encrypted and hashed by our authentication provider (Firebase Authentication by Google); we never see or store your password in plain text.
- ◆Account updates: if you change your username or request a password reset, we process the information necessary to action those requests. Usernames are reserved on a first-come basis, so a record of the usernames claimed and released by your account is kept for as long as the reservation exists.
- ◆Referral codes: if you enter someone’s referral code, we collect that code. See section 4.4.
- ◆Support correspondence: if you email us or otherwise contact us, we collect the contents of your message, your email address, and any other information you choose to provide.
4.2 Information generated by your use of the App
Gameplay progress is stored locally on your device at all times. If you are signed in to an account, we also synchronise that progress to the cloud so you can use it across your devices and restore it if you reinstall. The synchronised information includes:
- ◆your in-game character collection, equipment, move collection and deck configurations;
- ◆your in-game virtual currency balances (including “Titum” and “Dark Matter”) and the timestamp of the last update to those balances;
- ◆your story mode, mission, challenge, trial, “Energy Mining” and war progress and the teams you assigned to each;
- ◆your career and lifetime statistics, achievements, daily reward streaks and season or monthly pass entitlements;
- ◆a record of the in-app purchases delivered to your account (see section 4.8);
- ◆tutorial and onboarding completion flags;
- ◆sort and display preferences you set within the App; and
- ◆a monotonically increasing version counter used to prevent outdated data from overwriting newer data.
4.3 Information visible to other players
The App includes online features — friend battles, ranked competition, war defence and similar modes. When you take part in these, certain information leaves your private cloud save and becomes visible to other players or is stored in shared areas of our database:
- ◆Your username, which is shown to opponents and on leaderboards and rankings.
- ◆Your account identifier, used to match you to your entry and to prevent duplicate or fraudulent entries.
- ◆The teams you submit for attack or defence, including the characters, equipment and moves on them, so that your opponent’s device can play the battle out.
- ◆Your competitive record for the relevant period — points, wins, losses and the time of your last update.
- ◆Battle codes you create or enter to play against a specific person.
Please choose a username that you are comfortable having seen by other players, and do not include your real name, email address or other personal details in it. Records created by online play — such as a completed ranked week or a finished friend battle — are competitive records rather than part of your personal cloud save, and may be retained after your account is deleted in an anonymised or account-identifier-only form so that historical results remain coherent.
4.4 Referral programme and device identifier
The App offers a referral programme that rewards both a new player and the player who referred them. To operate it we collect and store:
- ◆the referral code issued to your account and the number of times it has been redeemed;
- ◆a record linking the referring account to the referred account, the code used, whether the qualifying in-game milestone has been reached, and whether each reward has been paid; and
- ◆a device identifier — a random value generated on your device the first time it is needed, stored in the iOS Keychain and recorded by us in hashed form.
We use the device identifier for one purpose only: to enforce a limit of one referral reward per physical device, which is what prevents a single person from creating accounts repeatedly to mint rewards. It is not used for advertising, is not shared with Meta or any other third party, is not synchronised to your cloud save, and is not used to build a profile of you.
4.5 Technical information
When you use the App, certain technical information is generated automatically by the operating system and by our service providers. This may include:
- ◆the unique identifier (UID) assigned to your account by our authentication provider;
- ◆the creation date and last sign-in date of your account;
- ◆the device identifier described in section 4.4;
- ◆the App version installed on your device;
- ◆your device’s App Tracking Transparency permission status and, only where you have granted that permission, the Apple advertising identifier (IDFA) — see section 4.6;
- ◆device and connection information transmitted by the App or its service providers for the purpose of delivering the service (for example, connection metadata required to communicate with Firebase, and the device model, operating system version and locale that the Meta SDK includes with the events described in section 4.6); and
- ◆the approximate date and time of events such as logins, data syncs and pending-write flushes.
4.6 Advertising measurement and App Tracking Transparency
We advertise the App on Meta’s platforms (Facebook and Instagram). To understand which advertisements bring players to the game and whether that spending is worthwhile, the App includes the Meta (Facebook) SDK, supplied by Meta Platforms, Inc.
The SDK sends a small number of event records to Meta when you reach certain milestones. Those events are:
- ◆completing the battle tutorial;
- ◆completing account registration;
- ◆starting your first battle and your first online battle;
- ◆beginning an in-app purchase (including the product identifier, price and currency); and
- ◆completing an in-app purchase (including the amount, currency and Apple transaction identifier).
These events are accompanied by device and app information generated by the SDK, and — only if you grant tracking permission — by the Apple advertising identifier. We do not send Meta your email address, your password, your username, your gameplay save or your support correspondence.
We also participate in Apple’s SKAdNetwork, a privacy-preserving attribution system in which Apple, not we, sends advertising networks an aggregated, delayed report that an install or purchase occurred. SKAdNetwork does not identify you.
4.7 Information we do not collect
For the avoidance of doubt, the App does not:
- ◆collect or process location data;
- ◆access your camera, photo library, microphone, contacts or calendars;
- ◆display third-party advertisements inside the game;
- ◆use Google Analytics for Firebase or any other general-purpose behavioural analytics product — the Analytics library is not included in the App, and the only third-party measurement we perform is the advertising measurement described in section 4.6; or
- ◆collect biometric information.
4.8 In-app purchases
In-app purchases — including virtual currency (“Titum” and “Dark Matter”), season and monthly passes, and character or equipment packs — are processed entirely by Apple through the App Store using Apple’s StoreKit 2 framework. When you make a purchase:
- ◆We receive a verified product identifier and transaction receipt from Apple to confirm the purchase is legitimate and to deliver what you bought.
- ◆We keep a record of that delivery against your account — the product purchased, the price and currency, the Apple transaction identifier and the date. We use it to make sure you are not charged twice, to restore entitlements, to answer support and refund enquiries, and to understand which packs players buy.
- ◆We do not receive your credit card number, billing address, Apple ID password or any other payment credentials. These are handled by Apple.
- ◆Apple’s handling of your payment information is governed by the Apple Privacy Policy.
4.9 Push notifications
With your permission, the App may schedule local push notifications to let you know when an in-game mission has finished (for example, “Your Champion has completed their mission”). These notifications are generated and stored on your device; they are not delivered via a server we control and do not transmit personal information back to us. You can disable notifications at any time in your device’s Settings app.
5. How we collect your information
We collect personal information in the following ways:
- ◆Directly from you when you register, sign in, update your profile, enter a referral code, make a purchase or contact us.
- ◆Automatically through the App and its supporting infrastructure (Firebase Authentication and Cloud Firestore) as you play and as your device synchronises gameplay data.
- ◆Through the Meta SDK embedded in the App, as described in section 4.6.
- ◆From other players, where they enter a battle code you generated or are matched against you in a competitive mode.
- ◆From Apple and Meta in the form of anonymised, aggregated reporting (for example, download statistics, ratings summaries and advertising performance) that does not identify you individually.
6. Why we collect and use your information
We collect, use and disclose personal information for the following primary purposes:
- ◆Providing the App: creating and authenticating your account, synchronising your gameplay progress across your devices, restoring your progress if you reinstall the App, and delivering the game experience.
- ◆Operating online features: matching you with opponents, running ranked seasons and leaderboards, and displaying results.
- ◆Processing purchases: delivering what you bought, verifying transactions with Apple and handling refund or support enquiries.
- ◆Running the referral programme and preventing its abuse, as described in section 4.4.
- ◆Advertising measurement: understanding which advertisements lead to installs and purchases, so that we can spend our advertising budget sensibly and keep the game free to download (section 4.6).
- ◆Customer support: responding to your enquiries, troubleshooting issues and communicating with you about your account.
- ◆Security and integrity: protecting the App, our users and our systems from fraud, abuse, unauthorised access and other misuse; maintaining the integrity of competitive gameplay; and enforcing our Terms of Service.
- ◆Legal and regulatory compliance: meeting our obligations under applicable laws, responding to lawful requests from public authorities and protecting our legal rights.
- ◆Service improvement: diagnosing technical issues and improving the reliability, balance and performance of the App.
6.1 Legal bases for processing (GDPR / UK GDPR users)
If the GDPR or the UK GDPR applies to you, we rely on the following legal bases:
- ◆Performance of a contract — processing necessary to provide the App to you under our Terms of Service (for example, authenticating your sign-in, syncing your progress, running an online battle you chose to enter and delivering a purchase).
- ◆Legitimate interests — preventing fraud (including referral abuse and the device identifier described in section 4.4), securing the App, maintaining competitive integrity and responding to support requests. We have balanced these interests against your rights and freedoms.
- ◆Legal obligation — where we are required to retain or disclose information by law.
- ◆Consent — for the advertising measurement described in section 4.6 (given through the App Tracking Transparency prompt), and for device-level push notifications. You may withdraw your consent at any time in your device settings, without affecting the lawfulness of processing already carried out.
7. Disclosure of your personal information
We disclose personal information only in the limited circumstances set out below.
7.1 Service providers and advertising partners
We share personal information with carefully selected providers who help us operate and promote the App. They include:
- ◆Google LLC / Google Ireland Limited (Firebase) — provides authentication (Firebase Authentication) and cloud database (Cloud Firestore) services that underpin sign-in, cross-device progress synchronisation and online play. Firebase is governed by the Firebase Privacy and Security documentation and Google’s Privacy Policy.
- ◆Apple Inc. — distributes the App through the App Store, processes in-app purchases through StoreKit and operates SKAdNetwork attribution. Apple’s handling of your information is governed by its own privacy policy.
- ◆Meta Platforms, Inc. and Meta Platforms Ireland Limited — receive the advertising measurement events described in section 4.6. Meta acts as an independent controller of that information and handles it under the Meta Privacy Policy.
- ◆Professional advisers — such as legal, accounting or compliance advisers, strictly on a need-to-know basis and under duties of confidentiality.
7.2 Other players
If you use the App’s online features, the information listed in section 4.3 is made available to the players you compete against and, where relevant, on leaderboards visible to other players. We do not disclose your email address, your account’s device identifier or your purchase history to other players.
7.3 Legal, safety and enforcement
We may disclose personal information where we reasonably believe disclosure is necessary to:
- ◆comply with applicable law, a court order, subpoena, regulatory demand or other lawful request;
- ◆enforce our Terms of Service or other agreements;
- ◆detect, investigate, prevent or respond to fraud, abuse, security incidents or technical issues; or
- ◆protect the rights, property or safety of us, our users or the public.
7.4 Business transfers
If we are involved in a corporate transaction such as a merger, acquisition, reorganisation, sale of assets or insolvency, personal information may be transferred as part of that transaction. We will take reasonable steps to ensure the recipient continues to protect your information in a manner consistent with this Policy, and we will notify you in accordance with applicable law.
8. International data transfers
Because we use Firebase, which is operated by Google, your personal information may be stored and processed on servers located outside Australia, including in the United States, the European Union and other jurisdictions where Google operates data centres. We endeavour to host user data in the australia-southeast1 Google Cloud region where practicable; however, Google may replicate or process data across other regions in accordance with its standard practices.
The advertising measurement events described in section 4.6 are transmitted to Meta Platforms and processed on its infrastructure, principally in the United States and Ireland.
Where personal information is transferred outside Australia, we take reasonable steps to ensure the recipient handles the information in a manner consistent with the APPs. Where personal information is transferred outside the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission or the UK International Data Transfer Agreement.
9. Storage, security and retention
9.1 Security measures
We take reasonable technical and organisational measures to protect your personal information against loss, misuse, unauthorised access, modification and disclosure. These measures include:
- ◆encryption of data in transit between the App and our cloud infrastructure (TLS);
- ◆encryption of data at rest on Google Cloud infrastructure;
- ◆password hashing performed by Firebase Authentication (we do not store plain-text passwords);
- ◆storage of the referral device identifier in the iOS Keychain on your device, and in hashed form on our side;
- ◆Firestore security rules that restrict your private save data to your authenticated account, and that limit shared competitive records to the fields required for play;
- ◆restricted administrative access to systems containing personal information on a need-to-know basis; and
- ◆logging and monitoring of administrative activity.
Despite our efforts, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, and you use the App at your own risk.
9.2 Retention
We retain personal information for as long as it is reasonably necessary to fulfil the purposes described in this Policy, including:
- ◆while your account is active;
- ◆for a reasonable period after account closure to allow for account recovery, to resolve disputes, to enforce our agreements and to comply with our legal obligations;
- ◆indefinitely, in the case of referral records and the hashed device identifier, because those records exist to stop the same person claiming the same reward repeatedly and deleting them would defeat that control. These records consist of account identifiers, a code and a hashed device value; they contain no email address, name or gameplay data;
- ◆for the life of the relevant competitive season or historical leaderboard, in the case of the online play records described in section 4.3;
- ◆for as long as required for tax, accounting and refund purposes, in the case of purchase records; and
- ◆for any longer period required by applicable law.
Information held by Meta as a result of the events described in section 4.6 is retained by Meta under its own retention practices, which we do not control.
When we no longer need personal information, we will take reasonable steps to destroy or de-identify it in accordance with APP 11.2.
10. Your rights and choices
Subject to applicable law, you have the following rights in relation to your personal information. To exercise any of these rights, please contact us at thelostartefacts@gmail.com. We may need to verify your identity before actioning your request.
10.1 Rights available to all users
- ◆Access: request a copy of the personal information we hold about you.
- ◆Correction: ask us to correct information that is inaccurate, incomplete or out of date. You can update your username directly within the App via the Settings screen.
- ◆Deletion: delete your account and the personal information associated with it. You can do this yourself inside the App, in Settings > Account Details, or by emailing us. Deleting your account removes your authentication record, your email address and your cloud save. Once deleted, your progress cannot be recovered.
- ◆Complaints: make a complaint about how we have handled your personal information (see section 15 below).
Two categories survive account deletion, and we think it is fairer to say so plainly than to bury it. Referral records and the hashed device identifier are kept for the anti-fraud reason given in sections 4.4 and 9.2. Completed competitive records may be kept against your former account identifier so that historical results remain intact. Neither contains your email address or your gameplay save. Apple also keeps its own record of your purchases, which we cannot delete.
10.2 Additional rights for EEA, UK and Swiss residents
Where the GDPR or the UK GDPR applies, you also have the right to:
- ◆restrict our processing of your personal information;
- ◆object to our processing where we rely on legitimate interests;
- ◆receive your personal information in a structured, commonly used and machine-readable format (data portability); and
- ◆withdraw any consent you have given — including tracking consent, which you can withdraw at any time in Settings > Privacy & Security > Tracking on your device — without affecting the lawfulness of processing already carried out.
10.3 Additional rights for California residents
If you are a California resident, the CCPA and CPRA give you the right to:
- ◆know the categories and specific pieces of personal information we have collected about you;
- ◆request deletion of your personal information, subject to certain exceptions;
- ◆correct inaccurate personal information;
- ◆opt out of the sharing of your personal information for cross-context behavioural advertising; and
- ◆not be discriminated against for exercising your rights.
We do not sell personal information, and we do not receive money or other valuable consideration in exchange for it. We do disclose identifiers and commercial information (the events in section 4.6) to Meta for advertising measurement, which may constitute “sharing” for cross-context behavioural advertising under the CPRA.
To opt out of that sharing, decline the App Tracking Transparency prompt, or turn tracking off at any time in Settings > Privacy & Security > Tracking on your device. You may also email us at thelostartefacts@gmail.com and we will action your request. We honour Global Privacy Control signals on any website we operate that links to this Policy. We do not knowingly share the personal information of consumers under 16 years of age.
10.4 In-app and on-device controls
You can also manage your information yourself:
- ◆update your username in the Settings > Account Details screen;
- ◆reset your password via the Forgot Password flow;
- ◆delete your account in the Settings > Account Details screen;
- ◆sign out of your account at any time;
- ◆turn tracking off in Settings > Privacy & Security > Tracking on your device; and
- ◆play as a guest, in which case your gameplay progress stays on your device and is not synchronised to our servers (see the note in section 4.2).
11. Children’s privacy
The App is not directed to, and we do not knowingly collect personal information from, children under the age of 13 (or the equivalent minimum age in the jurisdiction in which the user resides, for example 16 in parts of the European Economic Area). The App’s content includes fantasy violence and may not be suitable for young children; our App Store age rating reflects Apple’s classification for that content.
We do not knowingly track children or share their information for advertising. Apple does not present the App Tracking Transparency prompt to accounts managed as child accounts, and where tracking permission is not granted no advertising identifier is available to us or to Meta. If we become aware that we have collected personal information from a child in circumstances requiring parental consent, we will delete it.
If you are a parent or guardian and believe that your child has provided personal information to us without your consent, please contact us at thelostartefacts@gmail.com and we will take prompt steps to delete the information.
12. Apple App Store “Privacy Labels”
Apple requires all iOS app developers to disclose their data practices on the App Store listing. Consistent with this Policy and with the privacy manifest shipped inside the App, our disclosures cover:
- ◆Data used to track you: device identifiers (the advertising identifier, where you have granted permission).
- ◆Data linked to you: email address, user ID, purchase history and the identifiers described above.
- ◆Purposes: app functionality and third-party advertising.
Where there is any apparent inconsistency between the App Store listing and this Policy, this Policy governs.
13. Cookies, identifiers and similar technologies
The App is a native iOS application and does not use browser cookies. It does use local identifiers, tokens and cached data on your device: our service providers use them to authenticate you and deliver the service, the referral system uses the Keychain identifier described in section 4.4, and the Meta SDK uses device and advertising identifiers for the measurement described in section 4.6. Except for that measurement, we do not use identifiers or similar technologies for advertising, profiling or cross-site tracking, and no advertising identifier is used at all unless you grant tracking permission.
If we operate a website that links to this Policy, that website may use cookies. Details will be provided in a separate cookie notice on the website where applicable.
14. Links to third-party sites
The App or our communications may contain links to third-party websites or services — for example, links to Apple, Google, support resources, or to the author’s books on Amazon. Opening such a link takes you to a service we do not control, and that service will receive your request and apply its own privacy practices. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies before providing any personal information to them.
15. Complaints
If you have a concern about how we have handled your personal information, please contact us first at thelostartefacts@gmail.com. We will investigate and respond to you within a reasonable timeframe (and in any event within 30 days of receipt where required by the APPs).
If you are not satisfied with our response, you may lodge a complaint with the relevant privacy regulator:
- ◆Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
- ◆European Economic Area: your local data protection supervisory authority
- ◆United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk
- ◆California: California Privacy Protection Agency — cppa.ca.gov
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, our service providers or the law. When we make material changes, we will update the “Last updated” date at the top of this Policy and, where appropriate, provide additional notice through the App or by email. Your continued use of the App after the updated Policy takes effect constitutes your acceptance of the revised terms.
The changes made in this version are summarised in the notice at the top of this document.
17. Contact us
If you have any questions, requests or concerns regarding this Privacy Policy or our handling of your personal information, please contact us at:
- ◆Johnathon Nicolaou — Privacy Officer
- ◆Email: thelostartefacts@gmail.com
