Astrafort Privacy Policy

Last updated: 5 September 2026

This policy explains how Astrafort for Android and iOS (the “App”) handles personal data. It also covers requests made to the Astrafort website and services that host this policy, supply the App with configuration, cloud saves, and the current server time, and receive feedback you send.

1. Who is responsible

Wirecube Software OÜ is the controller of the processing described in this policy and publishes Astrafort.

Address: Kooli tn 14-33, 76901 Tabasalu, Estonia
Privacy contact: wirecube.software+privacy@gmail.com

2. Data we handle and why

Data How it is used Legal basis
App interactions and analytics, including screens viewed, gameplay actions, settings, App version, product identifiers, purchase outcomes, and rewarded-ad outcomes. Google may also collect device information, an app-instance identifier, and approximate location inferred from the IP address. Firebase Analytics helps us understand use of the App, balance gameplay, and improve features. We do not set an Analytics user ID or send your name or email address. Your consent where required by law.
Crash and diagnostic data, including stack traces, exception details, App and operating system versions, device model and state, and diagnostic logs. Logs include breadcrumbs derived from gameplay, settings, purchase, and advertising events and their parameters. Firebase Crashlytics helps us identify, investigate, and fix faults. You can turn this off using Settings → Privacy → Send Error Reports. Turning it off also deletes reports waiting to be sent from the device. Our legitimate interest in maintaining a stable and secure App. You may object at any time by turning off Send Error Reports.
Performance data, including Firebase installation and session identifiers, trace timings, App and device information, network type, country inferred from the IP address, and network request URLs and response metrics. Network query parameters and response bodies are not collected by Firebase Performance Monitoring. Firebase Performance Monitoring helps us diagnose slow or unreliable operation. Our legitimate interest in operating, securing, and improving the App.
Advertising data, which may include IP address, approximate location inferred from it, advertising or app identifiers where available, ad interactions, diagnostics, and device information. Google AdMob and the advertising partners listed in the consent form provide rewarded ads, measure them, limit fraud, and, if you consent, personalize advertising. If the required consent is unavailable, ads may be non-personalized, limited, or not shown. Your consent where required by law. Security and fraud-prevention processing may also rely on legitimate interests or legal obligations.
Purchase information, including the store product identifier and whether a purchase was pending, completed, cancelled, failed, consumed, or restored. We do not receive your payment-card details. Apple or Google processes the payment. The App uses the result to provide or restore the item and records the product identifier and outcome in Analytics when Analytics is enabled. Performance of your purchase contract and our legitimate interest in preventing fraud. Analytics processing is based on consent where required.
App platform, version, build number, and language, IP address, and normal HTTP request metadata when the App requests configuration and the current server time, sends feedback, or when you view this policy through Firebase Hosting. Cloudflare delivers the App services, protects them from abuse, including limiting how often feedback can be sent from one address, and returns configuration and the current time. Firebase Hosting delivers this policy. Our legitimate interest in operating and securing the App and this website.
Feedback you choose to send, including the message you write, the App version and build number, the platform, your device language, the country inferred from the IP address, and the time you sent it. The message is free text, so it contains whatever you choose to write. We do not store your IP address, account identifier, or device identifier with it. Cloudflare stores the message so that we can read it, understand the problem or suggestion, and improve the App. The version, build number, platform, language, and country tell us which build and market a message refers to. Our legitimate interest in understanding and improving the App.
A Firebase account identifier, sign-in information supplied by Google or Apple, authentication token data needed to verify the account, saved game content, save revision, and last-updated time when you enable cloud saves. Sign-in information may include your name or email address. Cloudflare's cloud-save storage does not store the authentication token, name, or email address. Firebase Authentication verifies your sign-in. Cloudflare stores your saved game under the account identifier so that you can back up progress, detect conflicting changes, and load the save on another device. Performance of the cloud-save service you request.

3. Saved game data

Game progress, settings, and locally recorded purchased upgrades are saved in the App's private storage. Local data remains until the App or its data is removed, subject to device-level backups controlled by Apple, Google, or you.

Cloud saves are optional. If you sign in and use cloud saves, the App uploads saved game data to Cloudflare. You can delete the cloud save and its Firebase account using Settings → Cloud Save → Delete Account. This does not delete local game progress.

4. Consent and privacy controls

Where required, the App uses Google's User Messaging Platform to request choices for advertising, device storage or access, and Analytics. You can reopen those choices using Settings → Privacy → Manage Privacy Choices when that option is required in your region. Withdrawing consent does not affect processing that occurred before withdrawal.

Error reporting is controlled separately. You can object to future Crashlytics reporting using Settings → Privacy → Send Error Reports.

5. Who receives data

We use the following recipients where needed for the purposes above:

We do not sell personal data ourselves. Advertising providers may process data for their own purposes as described in the consent form and their privacy information.

6. Retention

We may retain information longer where required to establish, exercise, or defend legal claims, comply with law, or prevent abuse.

7. International transfers

Google, Apple, Cloudflare, and advertising partners operate internationally. Data may therefore be processed outside your country. Where required, transfers are protected by an adequacy decision, the EU-US Data Privacy Framework, standard contractual clauses, or another lawful safeguard. See each provider's privacy information for its current safeguards.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or obtain a copy of personal data, to object to processing based on legitimate interests, and to withdraw consent. You may also complain to the data-protection authority where you live, work, or believe an infringement occurred.

Cloud saves use a Firebase account. Cloudflare's cloud-save storage uses the Firebase account identifier from your authentication token but does not store the token, your name, or your email address. Firebase Authentication and your sign-in provider may hold the account information they need to authenticate you. To make a request, contact us at wirecube.software+privacy@gmail.com. We may ask for relevant App or device identifiers so that we can locate the data without collecting unnecessary identity data.

Feedback is not stored with an account, device, or advertising identifier, so we normally cannot tell which message is yours and cannot act on a request about it on our own. If you want a message you sent removed, tell us roughly when you sent it and what it said, and we will delete the entries that match.

9. Security

Local App data is kept in the operating system's private App storage, access to cloud saves requires a valid account token, conflicting writes are rejected, and network connections use HTTPS. We and our providers use organizational and technical safeguards appropriate to the nature of the data. No storage or transmission method is completely secure.

10. Children

Apart from optional sign-in handled by Google, Apple, and Firebase, the App does not ask users for their name, date of birth, or contact details, so we do not know a user's age. Device and usage data described above may nevertheless be processed when a child uses the App. A parent or guardian can contact us if they believe a child's data has been processed contrary to applicable law or this policy.

11. Changes to this policy

We may update this policy when the App, its providers, or legal requirements change. We will update the date above and provide additional notice where required. Material new features, such as public profiles or tournaments, will be described here before they are introduced.

12. Provider information