Averune Privacy Policy
Last updated: August 16, 2026
This policy applies to the production Google Play version of Averune, a single-player fantasy action game. The free download includes the Sunken Mire chapter. One optional permanent Google Play purchase unlocks the rest of the campaign.
Summary
- No Averune account is required.
- Averune does not include advertising, an advertising ID, subscriptions, or advertising personalization.
- The full game save and settings remain on your device and Android cloud backup is disabled.
- Limited purchase and commerce records are processed only when the purchase features are used.
- Optional anonymous gameplay analytics is sent to Google Analytics for Firebase only after you accept the in-app privacy choice.
- We do not sell personal data.
Optional gameplay analytics
On first use of a Firebase-enabled build, Averune asks whether you want to share anonymous gameplay analytics. Collection is disabled unless you accept. If you decline, no gameplay analytics event is sent. You can reset this choice by clearing the app's storage.
If accepted, Google Analytics for Firebase receives automatic app events such as first open, app open, and session start, plus a limited set of Averune events: Adventure start, reclaimed-site and territory identifiers, rescued-companion identifiers, reaching ten minutes of active play, and the first return after one day. These identifiers name authored game content; they are not player names or account IDs.
Firebase Analytics uses a resettable app-instance identifier and may process app version, operating system, device model, session information, and approximate region derived from the network connection. Averune removes the Android advertising-ID permission and denies advertising storage, advertising user data, and advertising personalization consent. It does not send save contents, a gameplay route, precise location, free text, email address, or an Averune account to Analytics.
Google Play purchases
Google Play processes the payment for full_campaign_unlock. Averune and
its developer do not receive your payment-card number or full payment details.
Google handles that information under Google's own terms and privacy policy.
When you buy, restore, or revalidate the campaign unlock, Averune sends the app package name, product ID, and Google Play purchase token over HTTPS to the Averune verification service. The service checks the purchase with the Google Play Developer API, acknowledges completed purchases, and grants or revokes campaign access after purchases, refunds, cancellations, or chargebacks.
Information retained by Averune
The raw Google Play purchase token is used to perform verification and is not stored in the Averune database. The database retains a one-way SHA-256 hash of the token, the product ID, purchase and acknowledgement state, entitlement state, test-purchase flag, and verification timestamps. The Google Play order ID is not stored.
The purchase flow also sends a random identifier created for the current app run, the product ID, and limited commerce events such as paywall shown, purchase started, cancelled, pending, verified, restored, failed, or revoked. An event may contain the in-game purchase trigger and a short Play Billing or verification error code.
These commerce events do not contain the purchase token, Google Play order ID, advertising ID, persistent device ID, Averune account, save data, gameplay route, precise location, contacts, photos, recordings, or text entered by you.
Why this information is used
Purchase and commerce information is used to deliver and restore the permanent campaign unlock, keep offline access working for confirmed owners, process refund or revocation updates, prevent fraud, diagnose purchase failures, and meet legal or dispute-handling obligations. Optional gameplay analytics is used to understand onboarding, engagement, progression, and retention and to improve the game. Neither data flow is used for advertising personalization or sale of data.
Retention
Commerce diagnostic events expire after 90 days. Hashed entitlement records are kept while reasonably necessary to honour the permanent purchase, restore access, process refunds or disputes, prevent fraud, and meet applicable legal obligations. A signed entitlement proof is stored locally on your device after successful verification.
User-level Google Analytics event data may be retained for up to 14 months; aggregated reports may remain longer. Clearing app storage stops collection until a new privacy choice is made and resets Averune's local analytics preference and milestone flags.
Data stored on your device
Game saves, graphics settings, controls, and other preferences are stored locally and are not sent to the developer. If Analytics is accepted, only the limited milestones listed above and their authored content IDs are sent, not the save file. Android cloud backup is disabled. Local data is normally removed when you clear the app's storage or uninstall it. After reinstalling, an Internet connection and Google Play restore are required before previously purchased offline access can be established again.
Service providers and security
Google Play provides billing and purchase-status services. Google Analytics for Firebase processes optional gameplay analytics. Vercel hosts the Averune verification endpoints. Supabase stores the restricted entitlement ledger and expiring commerce events. These companies process information as service providers for payment, hosting, database delivery, reliability, and security; they may also process ordinary network and security logs, such as IP address and request metadata, under their own terms and retention settings. Averune does not send this information to advertising networks or data brokers.
Data sent by the app is encrypted in transit using HTTPS. Access to the entitlement database is restricted to the verification service. No method of storage or transmission is completely risk-free, but access is limited to what is needed to operate these features.
Permissions and information not collected
The production app uses Internet, network-state, Google Play Billing, and vibration permissions. It does not request camera, microphone, contacts, precise device location, photos, broad storage, or advertising-ID permissions. Optional Analytics may derive an approximate region from the network connection without requesting Android location. It does not include chat, user-generated content, cloud saves, or a third-party crash-reporting SDK.
Children's privacy
Averune is not directed to children under 13. We do not knowingly collect personal information from children. Purchase verification is processed in the same limited way for every player who chooses to use Google Play Billing.
Your choices and requests
There is no Averune account to delete. You can remove local game data by clearing the app's storage or uninstalling the app. You may contact us to request access, correction, or deletion of information controlled by the developer. You may decline optional gameplay analytics in the in-app privacy choice. Because Averune does not store your account, raw purchase token, or order ID, we may need information from your Google Play receipt to locate the correct entitlement record safely. Deleting an Averune record does not delete Google's independent transaction record and may require the purchase to be verified again before access can be restored.
Changes to this policy
This policy will be updated before the production app introduces materially different data use, such as accounts, advertising, cloud saves, multiplayer, or broader diagnostics. The date at the top identifies the current revision.