Gargoyle Drip Privacy Policy
This policy covers the Gargoyle Drip Android application and the game hosted at gargoyle-drip.web.app. Gargoyle Drip is developed and published by Bojan Ilievski.
Data collection and sharing
Gargoyle Drip has no user accounts or advertising. The developer does not sell user data.
The owned web game sends limited gameplay telemetry when Share Play Counts is enabled in Options. It is enabled by default and can be turned off at any time. The events cover visits, tutorial starts, completions and skips, round starts, finishes and abandoned rounds, game mode, coarse round-length and stage ranges, and whether a boss was reached or defeated. The game does not send scores, save data, input history, daily seeds, page addresses, names, email addresses, Google account identifiers, cookies, or a player or device identifier. Without an identifier, the counters show visits and rounds rather than unique people.
The Android app, Steam build, itch.io build, and web portal builds do not send this gameplay telemetry.
Data stored on your device
Scores, settings, streaks, relics, and other complete game progress are stored locally in app- or browser-provided storage. This information is used only to preserve your preferences and progress on that device. The owned web telemetry sends only the limited aggregate facts listed above, not this saved progress. Your Share Play Counts choice is stored with the local settings.
On Android, this local progress participates in Android's own device backup and device-to-device transfer when you have those Google services enabled, so your progress can survive a reinstall or move to a new phone. Backups are managed by Android under the Google Privacy Policy; the developer cannot read them.
Purchase verification
Google Play processes the purchase under the Google Privacy Policy. Gargoyle Drip sends the purchase token over HTTPS to confirm the product, payment state, acknowledgement state, and later refund or revocation notices with Google Play. The server does not store the raw purchase token. It stores a one-way SHA-256 fingerprint, the product identifier, ownership and acknowledgement states, whether Play marked it as a test purchase, the verification source, and timestamps. Real-time Google Play notification event identifiers, types, processing states, and timestamps are also stored so notifications are handled once.
Website and hosting
When you visit the hosted game or this policy, your browser connects to Firebase Hosting over HTTPS. If Share Play Counts is enabled, fixed gameplay events go to a same-site Firebase function. The function validates each event, increments counters in one daily Firestore document, and does not write the request IP address or browser details into that analytics document. There is no third-party analytics script or advertising tracker.
Google may still process ordinary request information such as an IP address, browser details, requested URLs, and security logs to deliver and protect Firebase Hosting, Cloud Functions, and Firestore. Google handles its service data under the Google Privacy Policy.
Security
The Android application keeps game data inside platform-provided local storage. A successful verified ownership result is cached on the device using Android Keystore-backed encryption so a known owner can play offline. Purchase verification and hosted pages use HTTPS. The purchase-verification database is not accessible directly from the game client.
Retention and deletion
Local game data remains on the device until you clear the app or browser storage, reset the game data, or uninstall the application. Purchase-verification records are retained while purchased-content ownership and refunds need to be supported; the raw purchase token is never retained. Firebase and Google Play service logs and request data follow Google's applicable retention policies. You may contact the developer with a deletion or privacy request, although there is no Gargoyle Drip account or stored raw token that can directly identify a player.
Daily gameplay counters are kept as aggregate product history. They contain no player identifier or raw event record, so the developer cannot connect a counter to one person or delete one person's past contribution. Turning off Share Play Counts stops future telemetry from that browser.
The exact deletion steps are on the Data Deletion Requests page.
Children
Gargoyle Drip is not directed to children under 13 and does not knowingly collect personal information from children.
Changes to this policy
If the game's data practices change, this policy and the Google Play Data safety declaration will be updated before the affected version is released. The effective date above will also be revised.
Privacy contact
For privacy questions about Gargoyle Drip, contact Bojan Ilievski at drakuwa@gmail.com.