Averune Privacy Policy

Last updated: August 20, 2026

This policy applies to the production Google Play version of Averune, a single-player fantasy action game. The free download includes the Sunken Mire chapter. One optional permanent Google Play purchase unlocks the rest of the campaign.

Summary

Optional gameplay analytics and diagnostics

On first use of a Firebase-enabled build, Averune asks whether you want to share anonymous gameplay analytics and technical diagnostics. Collection is disabled unless you accept. If you decline, no gameplay analytics event or Crashlytics report is sent. You can reset this choice by clearing the app's storage.

If accepted, Firebase Crashlytics receives crash and application-not-responding (ANR) reports. These reports may contain stack traces, relevant application state, app and operating-system versions, device model and manufacturer, session metadata, and a per-installation Crashlytics identifier. Averune does not attach an account, player name, save content, advertising ID, custom user ID, or free text to these reports.

If accepted, Google Analytics for Firebase receives automatic app events such as first open, app open, and session start, plus a limited set of Averune events: Adventure start and session number, two/ten/thirty-minute play milestones, first combat, enemy defeat, down, reward, home return and permanent upgrade, tutorial and quest completion, reclaimed-site and territory identifiers, rescued-companion identifiers, and returns after one and seven days. Progress parameters contain authored quest IDs and aggregate milestone counts, not the save file. These identifiers name authored game content; they are not player names or account IDs.

Firebase Analytics uses a resettable app-instance identifier and may process app version, operating system, device model, session information, and approximate region derived from the network connection. Averune removes the Android advertising-ID permission and denies advertising storage, advertising user data, and advertising personalization consent. It does not send save contents, a gameplay route, precise location, free text, email address, or an Averune account to Analytics.

Google Play purchases

Google Play processes the payment for full_campaign_unlock. Averune and its developer do not receive your payment-card number or full payment details. Google handles that information under Google's own terms and privacy policy.

When you buy, restore, or revalidate the campaign unlock, Averune sends the app package name, product ID, and Google Play purchase token over HTTPS to the Averune verification service. The service checks the purchase with the Google Play Developer API, acknowledges completed purchases, and grants or revokes campaign access after purchases, refunds, cancellations, or chargebacks.

Information retained by Averune

The raw Google Play purchase token is used to perform verification and is not stored in the Averune database. The database retains a one-way SHA-256 hash of the token, the product ID, purchase and acknowledgement state, entitlement state, test-purchase flag, and verification timestamps. The Google Play order ID is not stored.

The purchase flow also sends a random identifier created for the current app run, the product ID, and limited commerce events such as paywall shown, purchase started, cancelled, pending, verified, restored, failed, or revoked. An event may contain the in-game purchase trigger and a short Play Billing or verification error code.

These commerce events do not contain the purchase token, Google Play order ID, advertising ID, persistent device ID, Averune account, save data, gameplay route, precise location, contacts, photos, recordings, or text entered by you.

Why this information is used

Purchase and commerce information is used to deliver and restore the permanent campaign unlock, keep offline access working for confirmed owners, process refund or revocation updates, prevent fraud, diagnose purchase failures, and meet legal or dispute-handling obligations. Optional gameplay analytics is used to understand onboarding, engagement, progression, and retention. Optional Crashlytics diagnostics are used to identify and fix crashes and ANRs. None of these data flows is used for advertising personalization or sale of data.

Retention

Commerce diagnostic events expire after 90 days. Hashed entitlement records are kept while reasonably necessary to honour the permanent purchase, restore access, process refunds or disputes, prevent fraud, and meet applicable legal obligations. A signed entitlement proof is stored locally on your device after successful verification.

User-level Google Analytics event data may be retained for up to 14 months; aggregated reports may remain longer. Firebase Crashlytics retains crash stack traces and associated installation identifiers for 90 days before deletion begins. Clearing app storage stops collection until a new privacy choice is made and resets Averune's local analytics preference and milestone flags.

Data stored on your device

Game saves, graphics settings, controls, and other preferences are stored locally and are not sent to the developer. If the optional privacy choice is accepted, only the limited milestones listed above and technical crash/ANR diagnostics are sent, not the save file. Android cloud backup is disabled. Local data is normally removed when you clear the app's storage or uninstall it. After reinstalling, an Internet connection and Google Play restore are required before previously purchased offline access can be established again.

Service providers and security

Google Play provides billing and purchase-status services. Google Analytics for Firebase processes optional gameplay analytics, and Firebase Crashlytics processes optional crash and ANR diagnostics. Vercel hosts the Averune verification endpoints. Supabase stores the restricted entitlement ledger and expiring commerce events. These companies process information as service providers for payment, hosting, database delivery, reliability, and security; they may also process ordinary network and security logs, such as IP address and request metadata, under their own terms and retention settings. Averune does not send this information to advertising networks or data brokers.

Data sent by the app is encrypted in transit using HTTPS. Access to the entitlement database is restricted to the verification service. No method of storage or transmission is completely risk-free, but access is limited to what is needed to operate these features.

Permissions and information not collected

The production app uses Internet, network-state, Google Play Billing, and vibration permissions. It does not request camera, microphone, contacts, precise device location, photos, broad storage, or advertising-ID permissions. Optional Analytics may derive an approximate region from the network connection without requesting Android location. It does not include chat, user-generated content, or cloud saves.

Children's privacy

Averune is not directed to children under 13. We do not knowingly collect personal information from children. Purchase verification is processed in the same limited way for every player who chooses to use Google Play Billing.

Your choices and requests

There is no Averune account to delete. You can remove local game data by clearing the app's storage or uninstalling the app. You may contact us to request access, correction, or deletion of information controlled by the developer. You may decline optional gameplay analytics and crash/ANR diagnostics in the in-app privacy choice. Because Averune does not store your account, raw purchase token, or order ID, we may need information from your Google Play receipt to locate the correct entitlement record safely. Deleting an Averune record does not delete Google's independent transaction record and may require the purchase to be verified again before access can be restored.

Changes to this policy

This policy will be updated before the production app introduces materially different data use, such as accounts, advertising, cloud saves, multiplayer, or broader diagnostics. The date at the top identifies the current revision.

Contact

tvelievdev@gmail.com