Privacy Policy
Effective date: September 27, 2026
Who we are
Arclight: Gatefall is operated by Tae Hyun Kim, doing business as Dalbit Games, a sole proprietor in California, USA. We are responsible for the personal information we process as described here.
Contact: dalbitgames.dev@gmail.com
Website: arclightgatefall.com
This policy covers the Arclight: Gatefall apps for Android and iOS and our website, arclightgatefall.com. The website gives information and support; the game is not offered in a browser, and there is no website checkout at launch.
The first Android closed test runs with purchases and purchase accounts switched off. The purchase parts of this policy apply once purchases are switched on; purchases then go through Google Play Billing or Apple In-App Purchase, and RevenueCat helps us process the purchase records.
We will update this policy before adding website purchases or new uses of your information.
Players of different ages
Arclight: Gatefall is a general-audience game. It is not directed to children under 13. Age ratings are set by each store and can differ by country, so check the rating your store shows. Gameplay and local saves remain available to everyone.
A neutral age screen appears before analytics consent, purchase email features or purchases. It opens those features at 13, or at 16 when the device uses a European time zone. Below that age, analytics stays off, and email features, purchases and purchase restoration are unavailable. Passing the age screen does not mean you are an adult or allowed to buy: purchases stay subject to applicable law, any required parent or guardian authorization, and Apple’s and Google’s family controls. Opening a Focus chest with purchased gems also requires confirming that you are 18 or over.
Parents or guardians may contact us about a child’s information. We will investigate and delete information collected contrary to applicable requirements, subject to lawful retention exceptions. Store controls do not replace children’s privacy protections. eCFR
Information we use
Game progress and settings. Gameplay saves and preferences are stored on your device. Optional save transfers do not create a general game account. Purchased-item records are handled separately.
Age checks. The age question keeps only its result on your device: whether you are at or above the age that opens these features (13, or 16 on a European time zone), the age limit used, whether you are 18 or over, and the date of the answer. The birth year itself is not stored or sent. The first time you open a Focus chest with purchased gems, our purchase service records that you confirmed you are 18 or over, and when, on your purchase record. The answer on your device stays until you clear the game's data.
Optional gameplay analytics. After you opt in, we use a random, pseudonymous installation identifier, session identifiers, timestamps, coarse device categories and gameplay events. Examples include tutorial milestones, stage outcomes, choices, shop interactions, performance measurements and canonical error codes with a short fingerprint and in-game file/line location. Error messages, URLs and arbitrary user text are not collected. Pseudonymous information can distinguish an installation; it is not automatically anonymous. Gameplay analytics does not contain your complete save, your purchase email, payment-card details or your name.
Purchases. This applies once purchases are switched on; the first closed test makes none of these calls. Each app installation gets a random purchase ID. The app sends it to RevenueCat and our purchase service when it loads store prices or your purchased items, when you buy and when you restore purchases, so this can happen before you buy anything. When you buy or restore, we process product and transaction identifiers, purchase and refund status, and records of purchased items and currency; Apple or Google and RevenueCat process store receipts or purchase tokens and the information needed to process the purchase. Linking an email address is optional. If you ask for a six-digit code to link purchases, we store the address encrypted, with a keyed lookup value, even if you do not finish linking, and use it to send one-time codes and to restore your purchases on another device. When Focus chests are offered or opened with gems, our purchase service reads your country from your connection, through Cloudflare, to apply regional restrictions; the country is not stored with your purchase records, and the app remembers the last result on your device.
Support and security. We receive messages and information you send us. Cloudflare, our hosting provider, and Apple, Google and RevenueCat receive connection information, including IP addresses, to deliver and protect their services. Our analytics database does not store raw IP addresses, and our server logs record only errors and counts, without IP addresses, email addresses, tokens, request contents or installation or purchase IDs.
Your analytics choice
Analytics is off until you opt in. Events temporarily buffered in memory before your choice are discarded when you opt in; nothing from before that consent is sent. A valid choice saved from an earlier visit continues to apply until changed.
Declining analytics does not prevent gameplay or otherwise eligible purchases. Purchase processing is separate from optional analytics.
Turn off Share play stats in Camp Settings to stop analytics and request deletion of server records linked to your installation. When offline, collection stops immediately and the deletion request is kept on your device for retry when connected.
Deletion removes identifiable analytics from active storage, with the limited tombstone and backup exceptions below. Statistics that are genuinely anonymous may remain until their normal expiry. Withdrawal does not undo processing that was lawful before withdrawal.
How long information remains
| Information | Retention |
|---|---|
| Raw analytics events | 14 days after receipt. |
| Analytics aggregates | 400 days. |
| Installation registry and milestones | Until 200 days without a request, or earlier deletion. |
| Deletion tombstones | 30 days after deletion, retaining only the limited identifier and verification information needed to block delayed traffic. |
| Provider recovery copies of raw events | Up to 44 days from collection, including the recovery window after active-data deletion. |
| Your purchase email (encrypted) and its lookup value | While your purchase account exists. If you never finish linking and have no purchases, 30 days after your last code request. |
| Sign-in codes | The copy in the email queue is removed within 2 days of sending; the hashed code record 30 days after it expires, or once the sign-in session that used it is deleted. |
| Purchase sign-in sessions | 30 days after they end or are revoked. |
| Order, payment, refund and spending records | Seven years after the transaction, for tax, accounting and dispute purposes; without your email after you delete your purchase account. |
| Payment-provider notification details | Reduced to the outcome and a fingerprint 180 days after receipt, unless a case about that order is still open. |
| Request-limit counters (keyed by a hashed email address or purchase account) | Up to 3 days. |
| Server error logs, without IP addresses, email addresses or IDs | Up to 7 days. |
| Recovery copies of our purchase database | Up to 30 days after a change or deletion. |
| Support emails | Up to two years after the conversation ends, or longer while a dispute or legal claim needs them. A child’s email received only to answer a one-time request is deleted once we have replied. |
Recovery copies are restricted to recovery purposes. Restoring a backup must also restore applicable deletion instructions.
Local saves remain until you remove them. Purchase records are retained to provide remaining purchased benefits, support restoration, resolve disputes and satisfy applicable recordkeeping duties.
To delete your purchase account earlier, see Delete Your Purchase Account.
Providers and disclosures
Cloudflare provides hosting, backend infrastructure and security. RevenueCat processes store purchase records for us. Apple and Google process purchases and related information under their own notices; RevenueCat’s processing on our behalf is separate from theirs, and RevenueCat is not a separate checkout. RevenueCat
Cloudflare Email Service (Cloudflare, Inc.) delivers purchase sign-in messages. Google processes support correspondence through our Gmail address. Purchase email is used for purchase access, restoration and related service messages, not marketing. There is no website checkout at launch, so no website payment provider receives your information.
We may disclose information when legally required or necessary to establish or defend legal claims.
Storage, tracking and advertising
The apps keep these items on your device. Purchase items apply only once purchases are switched on. They stay until you clear the app's data or uninstall the app, unless a shorter time is listed.
| What | Why | How long |
|---|---|---|
| Your saves and journeys, with a backup copy | Your progress | Until you delete them |
| Settings (sound, the performance display) | Your choices | Until you change or clear them |
| Your age answer: an age group, the age limit used, whether you are 18 or over, and the date, not your birth year | Which features are open to you | Until you clear it |
| Your analytics choice | Remember yes or no | Until you clear it |
| An analytics install ID and deletion keys, only after you say yes | Group your events without your name; let you delete them | Until you withdraw consent, which erases them |
| An analytics session ID, only after you say yes | Group one play session | Until the app closes |
| A purchase in progress (order or transaction number and item) | Confirm a purchase the store is still processing | Until it is confirmed or canceled; at most 72 hours |
| A purchase you started before linking your email | Continue it after you enter the email code | 30 minutes |
| Your purchase email, shown masked (for example d•••@gmail.com) | Show where your purchases are kept | Until you uninstall the app, clear its data or delete your purchase account |
| A purchase sign-in token and its expiry time, after you enter an email code | Let this installation reach your purchase account | Until it expires, you delete your purchase account or the app's data is cleared |
| A random purchase ID for this installation | Load store prices, deliver and restore store purchases; sent to RevenueCat and our purchase service | Until you uninstall the app or clear its data; server purchase records follow the purchase retention rules |
| The last country our purchase service saw (a two-letter code) | Keep gem openings closed where they are not offered, until the next check | Until you clear it; replaced by each newer check |
| The last time our server confirmed (a date and time, no ID) | Stop daily rewards being claimed early by changing the device clock | Until you clear it; replaced by each newer confirmation |
| The date of your last progress backup (no progress data) | Remind you to back up after a stage clear | Until you clear it; replaced by each newer backup |
| Offline game files | Play offline and load faster | Replaced by each update |
Cookies. There is no website sign-in or checkout at launch, and neither the game nor this website sets advertising or cross-site tracking cookies. We will describe any website sign-in storage before website purchases start. In the apps, an installation that entered an email code stays linked to that purchase email until the app is uninstalled, its data is cleared or you delete your purchase account. The game sets no advertising or cross-site tracking cookies.
A browser’s Do Not Track setting does not override your in-game analytics choice. We do not sell personal information or share it for cross-context behavioral advertising. The game contains no advertising code and no third-party gameplay-analytics code, and no third party collects information across websites or apps through it. Cloudflare and RevenueCat process information for us under data processing agreements; Apple and Google also process information under their own notices.
No ads are shown; we will update this policy before any ads start.
EU/UK players: purposes and rights
For EU/UK processing, our grounds are consent for optional gameplay analytics; contractual necessity for delivering and restoring purchases; legitimate interests in proportionate security, fraud prevention, support, accounting and handling legal claims; and legal obligation where EU or UK law requires the processing. Refusing information necessary for a purchase or restoration prevents that feature, not ordinary gameplay. ICO
Depending on applicable law, you may request access, correction, deletion, restriction or portability. You may object to processing based on legitimate interests. You may withdraw consent and complain to your local data-protection authority or the UK Information Commissioner’s Office. ICO
Email us to exercise these rights. We may need proportionate verification. Installation credentials help identify analytics records; do not email secret credentials. Clearing device storage does not delete server records and may remove the information needed to locate them. We respond within applicable legal deadlines.
We and our providers process information in the United States. Cloudflare may handle your connection in a data center outside your country, and our providers may process information in other countries where they operate. For processing under our agreements with Cloudflare and RevenueCat, those agreements include the European Commission’s Standard Contractual Clauses and the UK Addendum, and Cloudflare also takes part in the EU-U.S. Data Privacy Framework. Contact us for details or copies. We have not appointed a representative in the EU or the UK; contact us directly. ICO
California players
CalOPPA requires a conspicuously posted, accurate privacy policy, including relevant collection, disclosure, tracking and change-notification information. This policy provides those disclosures. LegiInfo
Based on our current business size and practices, CCPA, as amended by CPRA, does not currently apply to us. We are below the adjusted annual gross-revenue threshold of $26,625,000; do not annually buy, sell or share personal information of 100,000 or more California consumers or households; and do not derive 50% or more of annual revenue from selling or sharing personal information. These are separate coverage tests, not a general exemption for indie developers. California Privacy Protection Agency+1
Changes
We update the effective date when this policy changes and provide appropriate notice of material changes. New uses requiring consent will require a new choice before that processing starts.