1. Who is responsible
COPU is an independently developed game. Its developer operates the game and this website, and is the controller of the personal data described here.
- Contact for privacy questions, rights requests, and complaints
- commonlistapp@gmail.com
This is a monitored address and the direct route to the person responsible — not a ticket queue that ends nowhere. We have not appointed a data protection officer, because COPU does not carry out large-scale monitoring or large-scale processing of special categories of data.
2. What this policy covers
It covers the COPU mobile game on Android and iOS, and this website at
copu-app.web.app. It does not cover Google Play, the App
Store, or a Google or Apple account you use to sign in — those are run
by Google and Apple under their own privacy policies, and your
relationship with them is separate from your relationship with us.
3. What COPU does not do
Stating this plainly is more useful than a long list of what we might theoretically do:
- No advertising and no advertising SDK in the app.
- No advertising identifier is read, and no cross-app or cross-site tracking takes place. Android removes the advertising-ID permissions from the final manifest and disables their collection; iOS excludes the Analytics component that can use IDFA. Analytics data is also marked unavailable for personalised advertising.
- No recording of what you type, no contents of your moves on the board, and no screen recording.
- No advertising or individual decision profiles, and no automated decision-making that produces legal or similarly significant effects. Analytics is used only in aggregate to tune the game and diagnose flows.
- No sale of personal data, and no sharing of it for anyone else's marketing.
- No GPS or precise location, contacts, photos, microphone, or camera. If you consent to play analytics, Google derives an approximate country or region from a masked IP address, as disclosed below.
- No chat, no friend lists, no player-created content, and no leaderboard that publishes your name to other players.
4. What we process and why
The table below is the complete list of what COPU stores about you on our side, why, and the legal basis under the GDPR. "Contract" means Article 6(1)(b) — processing necessary to provide the game you asked for. "Legitimate interests" means Article 6(1)(f), balanced against your rights. "Legal obligation" means Article 6(1)(c).
| Data | Why | Legal basis |
|---|---|---|
| Account identifier | A Firebase Authentication user ID. When you first start the game this is an anonymous account created on your device — it contains no name and no email address. It exists so your cloud save has an owner. | Contract |
| Linked sign-in details | If you choose to secure your progress with Google or Apple, we receive the provider's account identifier and, depending on the provider and your choices, an email address and display name. We use them to recognise you on a new device and to restore your save. Signing in with Apple lets you hide your real address; the relay address works fine with COPU. | Contract |
| Cloud save | Your game progress: level completion, stars, quest and daily state, unlocked cosmetics, gameplay settings, COPUCOIN balance, and boost inventory. This is what makes your progress survive a lost or replaced phone. | Contract |
| Purchase and entitlement records | When you buy COPUCOIN, our purchase provider RevenueCat records the transaction against your COPU account and confirms it with the store. We store the resulting entitlement so the coins reach the right account. We never receive your card number, bank details, or billing address — the payment happens entirely inside Google Play or the App Store. | Contract; legal obligation for accounting records |
| Operation records | Short server-side records of individual actions: spending coins, activating a boost for a run, replacing a save, and account-deletion requests. They exist so an action that is retried after a dropped connection cannot be applied twice, charge you twice, or silently corrupt your save, and so we can investigate if your balance ever looks wrong. | Contract; legitimate interests in integrity and fraud prevention |
| Save backups | When a save is replaced — for example when you sign in on a new device and choose which progress to keep — we keep a copy of the replaced save so that a wrong choice does not destroy years of progress. | Legitimate interests in not losing your data |
| Technical request data | Our hosting and backend providers process the technical information any internet service needs to answer a request: IP address, timestamps, device and operating-system information, and error information. COPU also uses Firebase App Check, which asks Google's attestation services to confirm that a request comes from a genuine, unmodified copy of the app rather than a script draining someone's wallet. | Legitimate interests in security, abuse prevention, and keeping the service running |
| Crash reports | When the game crashes or hits an error it could not handle, Firebase Crashlytics records what the app was doing: the line of code that failed, the version of COPU, your device model and operating-system version, the mode and level number you were in, and a Crashlytics installation identifier used to count how many players a given crash affects. It does not record your name, your email, your moves, or your screen. This is on by default and you can turn it off in the game's Settings, under Crash reports. If you separately agreed to Play data, Crashlytics may attach recent Analytics event names and parameters as breadcrumbs leading up to a crash; declining or withdrawing Play data prevents new Analytics breadcrumbs. | Legitimate interests in a game that works and can be repaired |
| Play analytics | Only if you agree. The first time you launch the game we ask, and until you answer yes, nothing in this row is collected. If you agree, Google Analytics for Firebase receives events describing level outcomes and duration, attempts, boosts, coin-store and purchase outcomes, and whether cloud synchronisation succeeded. Analytics also automatically records app sessions and lifecycle events, app version, basic device and operating-system details, an approximate country or region derived from a masked IP address, and store purchase fields such as product identifier, name, and price. It creates an app-instance identifier so records can be grouped across sessions on this installation. Automatic native screen-view reporting is disabled. We use these records to find unfair levels and unreliable or confusing flows. There is no advertising identifier, no cross-app tracking, and nothing that names you. You can withdraw your agreement at any time in Settings, under Play data. | Consent |
| Support correspondence | If you email us, we process your address and whatever you put in the message, for as long as it takes to answer you and to keep a record of what was agreed. | Legitimate interests in answering you; contract where the request concerns the game |
Where we rely on legitimate interests, you can object at any time — see Your rights. Providing this data is not a statutory requirement, but an account identifier and a cloud save are necessary to offer cloud save at all; without them the game still runs locally on your device.
5. Data that stays on your device
COPU is playable without an account. Campaign progress, stars, settings, and unlocked cosmetics are stored in the app's own storage on your device. That local data is not personal data in our hands — we cannot read it — and it is removed when you uninstall the app.
On Android, COPU deliberately turns off Android Auto Backup. This means your local save is not copied into your Google Drive backup, and a profile you deleted cannot reappear after a reinstall.
6. Who else processes the data
We keep the list of companies involved as short as the game allows.
| Recipient | What they do | Role |
|---|---|---|
| Google (Firebase, Google Cloud) | Authentication, the cloud-save database, the server functions that write it, App Check, crash reports (Crashlytics), the play analytics you agreed to (Google Analytics for Firebase), and the hosting for this website. | Processor on our behalf |
| RevenueCat | Validates purchases with the stores and tells our servers which account is entitled to what. | Processor on our behalf |
| Google Play / Apple | Distribute the app and take the payment. They decide independently what to do with the data of their own account holders. | Independent controllers |
| Our email provider | Delivers and stores support correspondence. | Processor on our behalf |
Beyond this, we disclose personal data only where the law requires it, or where it is necessary to establish, exercise, or defend legal claims. If COPU is ever transferred to another owner, the data described here may transfer with it; you would be told before that takes effect.
7. International transfers
Our providers are global services and may process data outside your country, including in the United States. Where data leaves the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses agreed with the provider, or by an adequacy decision where one applies to that provider. You can ask us for information about the safeguards that apply to a specific transfer.
8. How long we keep data
- Account, cloud save, and boost inventory — kept while your account exists, so your progress is there when you come back. Deleted when you delete the account.
- Operation and save-backup records — kept while your account exists and removed together with it. A record of a completed deletion is kept for 24 hours after the deletion finishes, purely so a repeated request cannot restart the process, and then expires automatically.
- Purchase and accounting records — kept for the period required by the applicable tax and accounting law, which is typically several years. These records survive deletion of your game account, because we are legally required to keep them.
- Technical and security logs — kept for a short period by our providers under their standard retention, and used only for security, abuse prevention, and diagnosing faults.
- Crash reports — Firebase keeps crash stack traces and associated identifiers for 90 days before beginning removal from its live and backup systems.
- Play analytics — individual event records are kept by Google Analytics for Firebase for up to 14 months, then removed automatically. Aggregate figures that no longer relate to any device, such as "how many attempts level 128 takes on average", are not personal data and we keep them for as long as we tune the game.
- Support correspondence — kept for as long as needed to resolve your request and to show what was agreed, then deleted.
9. Your rights
If the GDPR applies to you, you have the right to: obtain confirmation of whether we process your data and get a copy of it; have inaccurate data corrected; have data erased; have processing restricted; object to processing based on legitimate interests; and receive data you provided in a portable, machine-readable form. Where we rely on consent — which in COPU means play analytics, and nothing else — you can withdraw it at any time without affecting processing already carried out.
Two of those rights have a switch instead of an email. Open Settings in the game: Play data withdraws your consent to play analytics, and Crash reports is how you object to crash reporting, which we base on legitimate interests. The Play data switch stops Analytics collection immediately. COPU also stops adding new Dart error records as soon as Crash reports is turned off; on iOS, Firebase applies its native crash collection override after you next close and reopen the game. Both choices survive restarting the game. You do not have to write to us first, and you do not have to tell us why.
Write to commonlistapp@gmail.com to exercise any of these. We answer without undue delay and within one month of your request, and we tell you if we need the extension the GDPR allows for complex cases. We may need to ask you for enough information to be sure the account is yours — that check protects you, because an account we hand to the wrong person is an account we have leaked.
You can also complain to a data-protection supervisory authority. In the EU or EEA that is the authority of the country where you live, where you work, or where you believe the problem happened — you do not have to come to ours, and you do not need our permission.
10. Deleting your account
You can delete your account and progress yourself, from inside the game: open Account & wallet, expand Danger zone, and choose Delete account & progress. If you signed in with Google or Apple you will be asked to sign in again first, because a device left unlocked on a table should not be enough to erase someone's progress.
This permanently removes your cloud save, boost inventory and history, operation records, save backups, and the Firebase account itself. Your COPUCOIN balance and boosts stop being available, and none of it can be restored afterwards. Deleting your COPU account does not cancel a purchase or a subscription in Google Play or the App Store, and does not delete the accounting records described above.
If you cannot reach the in-game route — for example you no longer have the device — use the Account Deletion page.
11. Children
COPU is a single-player puzzle game with no chat and no user-generated content, but it is not directed at children, and we do not knowingly collect personal data from a child below the age at which they can consent on their own in their country. If you believe a child has given us personal data, write to us and we will delete it. Optional purchases are real payments; if a child uses your device, use the parental controls in Google Play or the App Store to require authentication for every purchase.
12. Security
Security choices worth naming, because they change what can go wrong:
- No app on any device can write to your cloud save directly. The database rules reject every client write; progress, coins, and boost state change only through our server functions, which check who you are first.
- You may read your own save and nobody else's. There is no configuration in which one player's save is readable by another.
- COPU sends Firebase App Check attestation tokens so tampered or automated traffic can be measured. During the initial observation rollout, server functions do not yet reject a request solely because that token is missing; enforcement follows only after genuine Play and App Store traffic has been verified.
- Data is encrypted in transit, and encrypted at rest by our infrastructure providers.
- We never receive card numbers. There is nothing of that kind in COPU to steal.
No system is perfectly secure. If a breach ever puts your rights at risk, we notify the supervisory authority and, where required, you.
13. This website
This site is static and hosted on Firebase Hosting. It sets no analytics, advertising, or marketing cookies, has no contact form, and embeds nothing from third parties — every image, style, and font is served from this domain. Our host processes the technical request information needed to deliver a page, as described above.
14. Changes to this policy
If we change how COPU handles data, we update this page and the date at the top. For a change that materially affects you — a new category of data, a new purpose, or a new kind of recipient — we tell you in the app before it takes effect, and where the law requires consent we ask for it rather than assume it.
15. Contact
Privacy questions, rights requests, and complaints: commonlistapp@gmail.com. Say what you want and which account it concerns, and we will come back to you within the time set out in section 9.