← Back to Aita: The Dark Domain
Privacy Policy
Aita: The Dark Domain — Last updated: 24 August 2026
This privacy policy describes how we collect, use, and protect information when you use Aita: The Dark Domain ("the Game") on any platform (web, Android, iOS, or Steam).
1. Information We Collect
1.1 Account Information
- Email address (for account creation and login)
- Password (stored as a cryptographic hash by Firebase Authentication; we never access plaintext passwords)
- Google account identifier (if you choose to sign in with Google)
- Apple Account identifier (if you choose to Sign in with Apple). If you use Apple's Hide My Email, we only ever receive the private relay address Apple generates for you, never your real email address.
- Display name (chosen by you, visible to other players in multiplayer)
- Friend code (automatically derived from your user ID)
1.2 Gameplay Data
- Run telemetry: run outcomes (victory/defeat), act reached, bosses encountered, blessings chosen, campfire decisions, obols earned, turns taken, enemies defeated, game version, platform, and related gameplay statistics. This is collected whether or not you sign in.
- Achievement progress and unlock timestamps
- Cloud save data (game state snapshots for resuming runs across devices)
- Friends list (friend codes and display names of accepted friends)
1.3 Device Information
- Device platform (Android, iOS, web)
- Device model and operating system version
- User agent string
- Device identifier (a locally generated random UUID used for telemetry correlation; the telemetry server stores a one-way hash rather than the original UUID)
1.4 Bug Reports (User-Initiated)
When you choose to submit a bug report through the in-game menu, we collect:
- Your description of the issue
- Contact email (optional, only if you provide it)
- A snapshot of the game state at the time of the report
- Recent combat log entries
- Device information (platform, model, OS version)
1.5 Multiplayer & Presence
- Online/offline status (automatically cleared when you disconnect)
- Lobby invitations (sender, room code, timestamp)
- Lobby chat is filtered for abusive language and relayed to the players in your lobby. It is not stored on our servers beyond a short in-memory buffer of the most recent messages, kept only so reports can include context.
- Player reports: when you report a player or a chat message we store the report — your account identifier and display name (as the reporter), the reported player's account identifier and display name, the lobby code, your selected reason, your optional note, and the recent chat messages from that lobby. See our Community Standards for how reports are handled.
2. How We Use Your Information
- Account management: to create and maintain your account, authenticate you, and sync progress across devices
- Game functionality: to enable multiplayer features (friends, lobbies, co-op play), save and restore game state, and track achievements
- Game balance: to analyse aggregate gameplay telemetry for difficulty tuning and game balance
- Bug fixing: to investigate and resolve issues reported by players
- Analytics: to understand how the game is used and improve the experience (via Firebase Analytics)
- Stability and performance: to detect crashes and performance problems in the mobile apps (via Firebase Crashlytics and Firebase Performance Monitoring)
- Community safety: to review player reports and enforce our Community Standards
We do not use your information for advertising, profiling, or marketing purposes.
3. Data Sharing
We do not sell, rent, or share your personal data with third parties, advertisers, or data brokers.
Your data is processed by the following service providers solely to operate the Game:
- Firebase (Google LLC): authentication (including Sign in with Apple and Google sign-in), database, analytics (Firebase Analytics), crash reporting (Firebase Crashlytics, mobile apps only), and performance monitoring (Firebase Performance Monitoring) — governed by Google's Privacy Policy. We do not use this data for advertising, and we do not enable configurations that combine it with third-party data for advertising.
- Apple: if you Sign in with Apple, Apple processes the sign-in itself under Apple's Privacy Policy; we receive only the resulting account identifier and (relay) email.
- Stripe (web platform only): payment processing for web purchases — governed by Stripe's Privacy Policy. Stripe is not used for Google Play or App Store purchases.
4. Data Summary
| Data Type |
Collected |
Shared |
Purpose |
| Email & password | Yes | No | Authentication |
| Display name | Yes | No | Multiplayer / friends |
| Device identifiers | Yes | No | Telemetry / analytics |
| Gameplay telemetry | Yes | No | Game balance |
| Friends list | Yes | No | Social / multiplayer |
| Bug reports | Optional | No | Quality improvement |
| Player reports & chat context | When you report or are reported | No | Community safety |
| Crash & performance data | Yes (mobile apps) | No | Stability |
| Payment info | Via Stripe (web only) | No | Purchase processing |
5. Data Retention
- Account data, saves, achievements, and friends list: retained until you delete your account.
- Gameplay telemetry: retained for aggregate game balance analysis. Signed-out telemetry uses a pseudonymous hashed installation identifier. When you delete your account, your telemetry is irreversibly anonymized: every record is re-keyed to a random identifier with no link to your former account (see Section 6).
- Bug reports: retained for quality improvement. Bug reports contain no user identifier beyond an optional contact email you may provide.
- Player reports: retained while moderation enforcement may still need them, and deleted no later than 12 months after they are actioned.
- Crash and performance data: retained by Firebase for its standard rolling window (90 days) and used only for stability work.
6. Account Deletion
You may delete your account at any time from within the Game's settings. Deletion removes:
- Your user profile and public profile (display name, friend code)
- Your achievements and cloud save backups
- Your friends list, friend requests, and block list
- Your presence and lobby invite data
- Your local storage data
- Your Firebase Authentication account
Deletion also irreversibly anonymizes your gameplay telemetry: each record is re-keyed to a random identifier, so neither the data nor its storage keys can be traced back to your account. If you signed in with Apple, your Sign in with Apple authorization is revoked with Apple as part of deletion. If the anonymization step cannot be completed (for example, our server is briefly unreachable), deletion safely stops before removing anything so you can try again — your account is never deleted with linked telemetry left behind.
Bug reports are retained as described in Section 5; they carry no account identifier. Player reports in which you were involved are retained as described in Section 5 for moderation integrity.
7. Children's Privacy
Aita: The Dark Domain is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly.
8. Security
We use industry-standard security measures provided by Firebase and Google Cloud Platform to protect your data, including encrypted connections (HTTPS/TLS), hashed passwords, and access-controlled database rules.
9. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, or delete your personal data. You can exercise your deletion right directly through the in-app account deletion feature. For other requests, contact us at the address below.
10. Changes to This Policy
We may update this policy from time to time. Changes will be posted at this URL with an updated "Last updated" date.
11. Contact
For questions about this privacy policy, contact us at:
support@aitatdd.com