Privacy Policy
Last Updated: August 13, 2026
This Privacy Policy applies to all mobile games provided by DodoSoft ("we," "us," or "our"), including Neon Drop Arcade, Snackcade, StarGuardians, and any future titles (collectively, the "Services"). Some features described below (such as global leaderboards and analytics) apply only to certain titles; this is noted where relevant.
We take your privacy seriously. This Privacy Policy explains what information we collect, how we use it, and how we protect it. By using our Services, you agree to the terms described below.
1. Information We Collect
To provide and improve our Services, we collect the following types of information:
- Advertising, App, and Device Identifiers: Google Advertising ID (AAID), Apple Identifier for Advertisers (IDFA, when tracking is permitted), Firebase app-instance identifiers, Unity installation and session identifiers (StarGuardians only), and similar identifiers
- Device Information: Device model, operating system version, system language, country code, screen resolution, and app version
- App Usage and Game Activity: App launches and sessions, screen and feature interactions, play time, level progress, game over, item usage, purchase-related events, and other events automatically collected by an SDK or sent by the app
- Crash Logs and Diagnostics: Crash and error information, SDK and network diagnostics, performance, and other app-stability data
- Approximate Location: Country- or region-level location inferred from an IP address or country code; we do not collect precise location
- Account Identifier and Account Information (Snackcade, StarGuardians): A Firebase Authentication user ID (uid) is generated automatically on first launch. If you optionally link a Google or Apple account in StarGuardians, the provider identifier and any name, email address, or display name supplied by that provider may be processed for authentication. The app displays email addresses in masked form.
- Auto-Generated Display Name (Snackcade only): A randomly generated nickname (e.g., "Player1234") derived from the anonymous uid, used only for global leaderboard display. No user input is collected.
- Game Score Data (Snackcade only): Highest score per game, timestamp of submission, and the auto-generated display name, stored on Firebase Realtime Database for global leaderboard purposes.
- TikTok Game Measurement Data (Snackcade Android, only after separate explicit opt-in): If you directly enable this choice in Settings, the app may send TikTok Business app install and launch events, game identifier, game start and completion, score, play duration in seconds, and pseudonymous event IDs scoped to the installation, session, and game run. The TikTok App Events SDK may automatically attach a TikTok pseudonymous identifier; IP address, network type and user agent; language and locale; operating-system and device model; screen size and density; app name, version, package and installer source; Google Play install referrer; and SDK diagnostic context. Android advertising-ID collection is disabled. This integration does not send your name, email, Firebase uid, purchase or payment information, screen text, buttons, resource names, or ad-revenue events.
- Profile and Social Information (StarGuardians only): We process a nickname, public player ID and friend code, selected profile card, avatar, frame and cosmetics, friend requests, friend and block relationships, clan name, emblem, notice, role, contribution and join requests, and card-trade offers, status and audit records. Items you choose or expect to make visible for a feature, such as your nickname, public ID, profile cosmetics and clan information, are shown to other users of that feature. Your email and sign-in-provider ID are not shown on social screens.
- Search Information (StarGuardians only): A nickname, friend code, or clan-name query you enter to find a friend or clan is transmitted temporarily to the server. The current game server does not persist or log the raw query.
- Roster, Save, Ranking, and Game Activity Data (StarGuardians only): Owned cards, decks and deck names, currency balances, stage, mission, attendance and tutorial progress, gacha, rewards and mail, PvP and clan-war results, and season scores are stored on Firebase Cloud Firestore under your uid.
- In-App Purchase Records (StarGuardians only): Product IDs, purchase history, receipts, purchase tokens, order or transaction IDs, and purchase status are processed for purchase, restoration, refunds, and duplicate-grant prevention. Payments are handled by Google Play or the App Store; we do not collect or store payment card details.
- Coupon, Ad Reward, and Security Data (StarGuardians only): Coupon campaign, reward and redemption time, ad transaction IDs, request timestamps, App Check and Play Integrity status, and rate-limit, idempotency and security-audit records are processed to prevent duplicate rewards and automated abuse. The raw coupon code you enter is not stored or logged; a normalized hash is used for lookup. For rewarded-ad server-side verification (SSV), your pseudonymous Firebase uid is sent to Google AdMob as
user_id and is included in the verification callback.
- Consent and Preferences (StarGuardians only): We may process the accepted version and timestamp of the required Terms and Privacy Policy, optional marketing consent, advertising-privacy choices, language, and game settings. Required-consent version and time and marketing consent may be stored in the cloud with the account save.
- Support and Deletion Request Information: When you voluntarily email a support or account-deletion request, we may use the sender email address, message and attachments, platform, app version, nickname or friend code, sign-in provider, approximate last-login time, and the minimum relevant purchase identifier to respond and verify the request. Never send a password, login token, original identity document, or full payment credentials.
- Retired Auction Records (StarGuardians only): The auction feature is retired and accepts no new listings or bids. Historical listing, bid, settlement, refund, asset-recovery, and anti-abuse audit records may be processed only for deletion, pseudonymization, or applicable retention.
StarGuardians Android analytics notice: The Android app includes Firebase Analytics SDK. Without a separate in-game analytics action, it may automatically process app-instance identifiers, first-open, app-launch, session, lifecycle, screen and purchase-related automatic events, app and device information, IP-derived approximate location, and an advertising identifier when available. Unity IAP Insights may also send purchase and transaction events, Unity installation, session and device identifiers, device and country information, and crash, diagnostic and performance information to Unity to operate the purchase feature.
We do not collect or store your sign-in password, payment card number, or government identification number. If you link Google or Apple, we may process the provider identifier and the email or display name described above.
2. How We Use Information
- To provide advertising services and display relevant ads
- To improve our Services and user experience
- To fix bugs and maintain app stability
- To analyze usage statistics
- When you separately opt in, to measure and attribute TikTok advertising performance and optimize campaigns for Snackcade Android
- To operate global leaderboards and display rankings (Snackcade only)
- To authenticate accounts and operate cloud save, profiles, friends, clans, card trades, PvP, and clan wars (StarGuardians only)
- To verify purchases, grant rewards, prevent duplicate payment or abuse, and resolve disputes (StarGuardians only)
- To validate coupons, enforce per-account redemption limits, and grant server-authoritative rewards (StarGuardians only)
- To record required consent, apply optional marketing and advertising-privacy choices, and meet compliance duties (StarGuardians only)
- To respond to support, bug, purchase and account inquiries, verify deletion requests, and report the result
- To recover residual assets and handle refunds, disputes, and anti-abuse audits for the retired auction feature (StarGuardians only)
3. Third-Party Services
We use the following third-party services, which may receive some of your information:
| Third Party |
Purpose |
Data Processed |
| Google AdMob |
Advertising, rewarded-ad SSV, advertising analytics, and fraud prevention |
Advertising and device identifiers, IP-derived approximate location, device and app information, ad and app interactions, and diagnostics. For a StarGuardians rewarded ad, the ad transaction ID and Firebase uid are also processed as SSV user_id. |
| Google UMP (User Messaging Platform) |
Consent management |
Consent status |
| TikTok for Business App Events SDK (Snackcade Android, only after separate explicit opt-in) |
Advertising measurement, attribution, and campaign optimization for app install, launch, game start, and game completion |
InstallApp, LaunchAPP, game_start, and game_complete events; game identifier; score; play duration in seconds; pseudonymous installation, session and run event IDs; TikTok pseudonymous identifier; IP address, network type and user agent; language and locale; OS, device model and screen information; app, installer source, Google Play install referrer and SDK diagnostic information. Android advertising-ID collection, automatic purchase, ad-revenue, two-day-retention, and enhanced screen, text, and resource collection are disabled. |
| Google Play Services / Play Integrity (StarGuardians Android) |
App distribution and updates, app and device integrity, and fraud prevention |
Device and app metadata, license status, request hash or nonce, and Play Integrity token and verdict. We do not receive an installed-app list. |
| Firebase Analytics (Snackcade, StarGuardians; Android 23.2.0) |
Automatic usage analytics and app stability and feature improvement |
App-launch, first-open, session, lifecycle, screen and purchase-related automatic events; app and device information; app-instance and advertising identifiers; and IP-derived approximate location. Automatic collection is enabled in StarGuardians Build 63. |
| Firebase Authentication (Snackcade, StarGuardians) |
Anonymous sign-in and optional Google/Apple account linking |
uid, provider identifier, and provider-supplied email or display name |
| Firebase Realtime Database (Snackcade only) |
Global leaderboards |
Auto-generated display name, score, timestamp, uid |
| Firebase Crashlytics (Snackcade only) |
Crash reporting |
Crash logs, device info, app version |
| Firebase Cloud Firestore / Cloud Functions / App Check (StarGuardians only) |
Cloud save, economy ledger, profile, friends, clans, trades, PvP, clan wars, coupon, purchase and ad-reward verification, and security |
uid; nickname, public ID, friend code and profile cosmetics; friend and block social graph; clan, notice, contribution and join requests; card trades; consent status; progress, inventory, balances, PvP, coupon, purchase and ad-reward records; network and request-verification data; and historical audits for the retired auction feature |
| Google Play Billing / Apple App Store (StarGuardians only) |
In-app payment and receipt verification |
Product ID, transaction ID, purchase token or receipt, and purchase status |
| Unity IAP 5.4 or later (StarGuardians only) |
Product retrieval, purchase, restoration, IAP Insights, and payment-function diagnostics |
Purchase history and product and transaction events; personal, Unity installation, session and device identifiers; device and app information; country-level approximate location; email and advertising identifiers that may be processed under Unity's SDK disclosure; and crash, diagnostic, and other app-performance information |
| Google Cloud Logging (StarGuardians only) |
Server operations, incident diagnosis, security, and abuse investigation |
Request time, function and result, errors, network and request metadata, and limited account or transaction identifiers needed for security investigation |
In StarGuardians friend, clan, and card-trade features, a nickname, public player ID or friend code, profile cosmetics, clan name, emblem, notice, role and contribution, and trade status that you choose or expect to make visible may be shown to the counterparty or clan members. These features do not expose your sign-in email, authentication-provider ID, or payment information to other users.
Privacy policies of these third parties are available at:
4. Data Retention and Deletion
We retain collected information only as long as necessary to provide the Services. Specifically:
- Local game records (settings, preferences, etc.) are stored locally on your device (PlayerPrefs) and are deleted when you uninstall the app
- Global leaderboard data (Snackcade only): Score data is retained on Firebase Realtime Database to maintain global rankings. Upon deletion request, all records associated with your anonymous uid will be permanently removed.
- StarGuardians account and ordinary game data: Retained while the service is used. Following in-app account deletion or a verified external request, we delete the Firebase Authentication account and Google/Apple linkage; nickname, public ID, friend code and profile cosmetics; cloud save, inventory, balances, progress, consent status, mail, rewards and coupon redemptions; friend, request and block relationships; clan membership, role, contribution and join requests; card trades; and direct account linkage in PvP and clan-war data, or remove the account from those relationships. For an Apple-linked account, in-app deletion first performs Apple verification and token revocation.
- Retired auction data: Auctions no longer accept new user activity. We delete or cancel residual listings created by the deleted account and remove direct uid links from historical listings, while returning escrowed assets belonging to surviving users. Only the minimum historical audit ledger needed for asset recovery, disputes and abuse prevention may remain pseudonymized under the rules below.
- StarGuardians minimum transaction and security ledgers: We may retain the minimum fields required for refunds and accounting, prevention of duplicate purchase or ad-reward grants, retired-auction asset recovery, and abuse prevention. These records include purchase and rejected-receipt ledgers, AdMob SSV transactions, and historical auction audit and bid records. At account deletion, the plaintext uid is removed and replaced with a domain-separated, one-way SHA-256 marker; access is restricted and the ledgers are kept separate from ordinary game data.
- StarGuardians deletion-blocking marker: To prevent a still-valid authentication token or delayed ad callback from recreating wallet or reward data, we retain only the one-way uid hash described above, deletion status, and processing timestamps, without the plaintext uid. Transaction and security ledgers and this marker are used only while their purpose or a legal retention basis continues. Because the applicable purpose and obligation may differ by case, no single fixed period applies. You may contact us to ask about current retention status or request a further deletion review.
- Contract, cancellation, payment, and digital-goods supply records: retained separately for 5 years where required by Korean e-commerce law
- Consumer complaint or dispute records: retained separately for 3 years where required by law
- Display and advertising records: retained separately for 6 months where required by law
- Support and deletion-request data: We keep the sender email address, request and attachments, and minimum verification information until we complete and report the request, then delete them without undue delay. If the communication is a consumer complaint or dispute record, it may be retained separately for up to three years where required by law.
- Advertising and analytics data is retained according to the applicable Google AdMob and Firebase Analytics settings and provider policies. Automatically generated app-instance and advertising identifiers may not always be directly linked to a Firebase uid, so the identifiable and deletable scope depends on the identifiers supplied by the requester and provider functionality.
- TikTok game measurement data (Snackcade Android): The consent choice is stored on the device and is removed when the app is uninstalled. Events sent after opt-in are handled under TikTok for Business settings, retention, and deletion policies. We do not separately store these events on our server linked to a Firebase uid. You can immediately stop future transmission at any time through Settings → Privacy & Consent → Allow TikTok game measurement.
- Third-party diagnostic and service logs: Firebase Crashlytics (Snackcade) and Unity IAP service logs follow each provider's retention and deletion process. Unity states a general 90-day retention period for IAP service logs; retention of other purchase and Insights data may vary by purpose and Unity's role and policy. StarGuardians Google Cloud operational logs may remain for the project's configured retention period or while a continuing legal or security basis applies.
Uninstalling the app removes local device data but may not automatically delete server account data. You can request server deletion in StarGuardians through Settings → Account Management → Delete Account or through our StarGuardians Account and Data Deletion page. The live Firebase Authentication user is deleted, although clearing the provider's backup systems may require additional time under Firebase's documented process. Unless you narrow the scope, a verified external deletion request covers account and game data under our control, a review of identifiable Firebase Analytics and Google Cloud log data, and routing of a Unity IAP processor-data deletion request. For Unity IAP processor data, we instruct Unity at unity-iap-contact@unity3d.com using only the minimum transaction identifier and track the result. We also explain the provider privacy process for data Unity controls independently and for Google advertising-platform data. Transaction records required by law are separated from ordinary game data with restricted access and are deleted or de-identified after the applicable retention period.
5. Your Rights
You have the following rights regarding your personal information:
- Access your personal information
- Correct inaccurate information
- Request deletion of your information (including leaderboard records)
- Object to or restrict processing
- Withdraw consent for personalized advertising (via in-app settings or device settings)
- Withdraw consent to TikTok game measurement for Snackcade Android at any time through in-app settings
To exercise any of these rights, please email us at the address provided below.
For the StarGuardians deletion process and the exact deletion and retention scope, see our Account and Data Deletion page.
How to Reset Your Advertising ID
- Android: Settings → Google → Ads → Reset advertising ID
- iOS: Settings → Privacy & Security → Tracking → Disable "Allow Apps to Request to Track"
6. Children's Privacy (COPPA)
Our Services are not directed to children under the age of 13, and StarGuardians is offered to users aged 18 and over according to its store rating and target-audience settings. We do not knowingly collect personal information from children under 13. If you believe your child has provided us with personal information, please contact us immediately, and we will promptly delete it.
7. European (EEA/UK) and California Users
GDPR (General Data Protection Regulation)
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights:
- Right of access, rectification, and erasure ("right to be forgotten")
- Right to restrict processing, data portability, and object to processing
- Right not to be subject to automated decision-making
We use Google UMP to manage your consent for personalized advertising. You may withdraw or modify consent at any time through the in-app settings.
CCPA (California Consumer Privacy Act)
California residents have the following rights:
- Right to know what personal information is collected
- Right to request deletion of personal information
- Right to opt out of the sale of personal information (we do not sell your personal information)
- Right to non-discrimination for exercising your rights
8. Data Security
We implement industry-standard measures to protect your information:
- All data transmission uses HTTPS encryption
- Third-party services adhere to industry-standard security protocols
- Access to personal information is minimized and restricted
- Firebase Security Rules, authentication, and staged App Check verification restrict or detect unauthorized requests
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our Services or applicable laws. Material changes will be announced at least 7 days in advance via in-app notice or through this page.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: