Privacy Policy
Taverna Royale processes the data required to run classic backgammon, story mode, bot practice, same-device two-player, online/async matches, leaderboards, friends, chat safety, support, account deletion, notifications and purchase verification.
Short summary
In local game modes, data stays on your device as much as possible. When you use online account, match, chat, leaderboard, purchase, push or support features, related data may be processed by providers such as Firebase, Photon, Apple App Store or Google Play. Ads are not live yet; if ads are enabled, the Google AdMob SDK, UMP consent choices and store data disclosures will be added to this policy. We do not sell personal data and do not use it for third-party ad tracking.
Minimum principle
Only data the feature needs
Local gameplay is not designed to transmit data off-device. Cloud account, online match or chat activate the related service data.
Security
Server authority
The client is never treated as the sole source of truth for online matches, dice/move validation, purchases or moderation; Cloud Functions and Firestore rules are used.
Control
Deletion and support
Players who use an account-based live service can start a deletion request in-app; if access is lost, the web/email support path is used. Support/feedback requests are tracked in a separate queue.
| Local profile and settings | Nickname, system language, theme, accessibility, audio, haptics, story progress and similar settings may be kept on device. If cloud sync is off, this information is not sent off-device. |
|---|---|
| Account and authentication | On guest/anonymous or email sign-in, Firebase Auth user ID, session data and account status records may be used. Email is only processed if that sign-in method is active. |
| Online game data | Match ID, player ID, dice/move records, turn, duration, resign/abandon/timeout status, ELO, score changes, leaderboard, tournament, replay, reconnect and anti-abuse records may be processed to protect online game integrity. |
| Chat and user content | Online chat messages, message hashes, reports, blocks, moderation status and abuse signals may be retained for player safety and policy violation review. Raw message text is redacted by default when a message is removed by moderation; the hash, decision trail, appeal and notice metadata are kept for the required period. |
| Profile photo/avatar | Any optional profile photo you upload is stored in Firebase Storage and goes through content moderation (a moderation status record is kept). If you do not upload an avatar, a default image is used. |
| Friends system and profile visibility | So other players can find and add you, your display name, unique player code, avatar and public statistics (e.g. ELO, rank) are visible by default to other authenticated players. When an account is deleted, this profile is hidden/anonymized. |
| Voice chat metadata | When voice chat/calls are enabled, audio is only transmitted in real time and is not recorded; only short-lived call metadata (participants, match ID, status, timestamp) is processed to operate and secure the feature. |
| Purchases and economy | Apple App Store or Google Play purchase/receipt information, product ID, entitlement, restore and pending/deferred status may be processed for payment verification and fraud prevention. |
| Notifications and device status | If push notifications are enabled, FCM token, opt-in status and notification delivery/tap evidence may be used. Analytics/crash features are only enabled once the relevant opt-in and release gate are completed. |
| Ads and AdMob readiness | Live ad serving is currently off. If ads are enabled in the future, Google AdMob may show banner or natural-break interstitial ads; the ad SDK may process signals such as IP address, approximate location inference, ad interactions, diagnostics, performance data and device/advertising ID for Google's advertising, analytics and fraud-prevention purposes. The first phase is planned with non-personalized ads and UMP consent choices; IDFA-based tracking will not be enabled without App Tracking Transparency permission. |
| Security and anti-cheat | App Check/Auth signals, rate limits, device/session signals, server dice/move validation records, error codes and violation history may be used to prevent cheating, bots, fraud and service abuse. |
| Support requests | Player ID, platform, app version, issue description, match/report/purchase/call reference, screenshots, purchase order ID and correspondence content may be used for support response and record integrity. In the in-app support/feedback form, a plain-text email is not stored raw; it is tracked with a hashed reference if needed. |
| Service providers | Firebase Authentication, Firestore, Realtime Database, Cloud Functions, Firebase Hosting, Firebase Cloud Messaging, the Photon/Fusion live networking layer, Apple App Store, Google Play Billing, and support/email providers when required. Third-party SDK data is additionally disclosed in store forms. |
| Retention and deletion | Account, profile and live service data are deleted or anonymized upon an account deletion request. Default retention: chat messages, chat reports, blocks and moderation events 90 days; moderation appeals and decision notices 180 days; support/feedback requests 180 days; voice call metadata 30 days; friend requests 30 days; friend invite codes 7 days; match invitations 10 minutes; rate-limit records 48 hours; security/suspicious activity records 180 days; data/legal requests, IAP disputes, match arbitration and admin audit records 365 days. For chat messages removed by moderation, raw text is redacted and the message hash/decision trail is kept for the retention period. Purchase and accounting records are kept as long as legally required. In case of a serious security or legal review, a legal hold may apply; while an active legal hold is in place, the TTL deletion field for the related evidence is removed, redaction is deferred until the hold ends, and normal retention resumes once the hold is lifted. |
Chat and user safety
- Chat messages are not written directly to Firestore; they pass through a backend filter and rate limit.
- Players can report a message or user, block an opponent, and request support review.
- Reported content is placed in a moderation queue; severe violations may lead to account restrictions.
- For a wrong decision, harm, payment, account deletion or live match issue, the in-app support/feedback form or the support email can be used.
Voice chat note
When voice chat/calls are enabled, explicit microphone permission is required (you may decline and still play), you can mute yourself at any time, and you can block another player. Audio is only transmitted in real time; it is not recorded or stored by us. Call metadata such as participants, match ID, status and timestamp is kept for 30 days by default. Accounts restricted from voice communication by a moderation decision cannot start or accept new calls. The feature is rolled out gradually and only once the required permission, moderation, age/region compliance, retention policy and store privacy disclosures are complete.
User rights
- Access
- You may request information about the profile, support and live service records linked to your account.
- Correction
- You may request correction of your nickname, support contact information, or inaccurate account data.
- Deletion
- You may start a deletion request for your account and related data through the account deletion flow.
- Objection and restriction
- You may object to legitimate-interest-based processing, marketing-type notices, or certain analytics/crash processing choices.
- Portability
- Where technically feasible and legally required, you may request an export of core data linked to your account.
Contact
For privacy and data rights, use privacy@tavernaroyale.com; for DPO requests, dpo@tavernaroyale.com; for account deletion, deletion@tavernaroyale.com; for payments, billing@tavernaroyale.com; for security, security@tavernaroyale.com. For general routing, see the Support Center page.
You also have the right to lodge a complaint with your local data protection authority: BfDI/the competent state authority in Germany, AEPD in Spain, HDPA (Αρχή Προστασίας Δεδομένων) in Greece, and the Personal Data Protection Authority (KVKK) in Türkiye.
Legal basis and international transfers
Processing relies on contract performance, legitimate interest, security/fraud prevention, legal obligation, purchase records and, where required, explicit consent. Depending on your region, GDPR, UK GDPR, KVKK, CCPA/CPRA or similar local rights may apply.
Our service providers (e.g. Firebase/Google Cloud, Photon) may process your data outside the EU/EEA, for example in the United States. In that case we rely on European Commission adequacy decisions or EU Standard Contractual Clauses (SCCs); a copy of the transfer mechanism used can be requested via privacy@tavernaroyale.com.
Data controller
The data controller is Yes Tech (sole proprietor: Hasan Bicici), Venloer Str. 1307, 50829 Köln, Germany. Full provider information is available on the Impressum page. An EU representative under Art. 27 GDPR is not required, as the controller is already established in the EU (Germany).
Policy sources
- Apple App Review Guidelines
- Apple Account Deletion
- Google Play Data Safety
- Google Play Account Deletion Requirements
- Google Play UGC Policy
- EU Digital Services Act
- KVKK
- Google Mobile Ads Android Data Disclosure
- Google Mobile Ads iOS App Store Data Disclosure
- Google UMP Unity Privacy
- Taverna Royale Community Guidelines
Short summary
Taverna Royale only processes the data needed for active features: account sign-in, online matches, leaderboards, chat moderation, support, account deletion, purchase verification, push notifications, live service integrity and, if enabled in the future, non-personalized ad delivery. We do not sell personal data and do not use it for third-party ad tracking.
