Privacy Policy — Tiny Fates
Last updated: July 17, 2026 Effective date: Upon app launch
This policy describes how Tiny Fates ("the App," "we," "us") collects, uses, and protects information when you use the iOS or Android app or visit the marketing website.
1. Information We Collect
Data we DO collect:
Anonymous usage analytics (PostHog in the app; Google Analytics on the marketing website after consent):
- App open / session start timestamps
- Gameplay events: life started, age advanced, event shown, life ended, share clicked
- Device type (iOS or Android version and model)
- App version
- Anonymous random UUID (not linked to any identity)
Crash diagnostics (via Sentry):
- Scrubbed error messages, stack traces, app version, and limited breadcrumbs
- Default SDK PII collection disabled; known contact fields, URLs, and auth material scrubbed before send
- Enabled only after optional analytics/diagnostics consent and disabled when that setting is withdrawn
Purchase information (App Store or Google Play purchase status validated through RevenueCat):
- Purchase receipts (subscription status, one-time purchases)
- Entitlement status (Fates Pass, Founder Pack)
- Store transaction identifiers needed to validate purchases (never full card numbers)
Advertising delivery (free users only):
- Ad placement shown in the app through Google AdMob
- Optional marketing-site advertising through Google AdSense after consent
- Basic device context needed by the relevant ad provider
- No ads shown to active Fates Pass users
Game state (stored locally by default):
- Character progress, achievements unlocked, lives played
- Language preference
- Optional cloud save data if you sign in
- Email address if you create account or request email sign-in link
- Public FateWire milestone rows only if you opt in from Settings
Data we DO NOT collect:
- NO phone number or physical address
- NO precise location
- NO access to contacts, photos, camera, microphone
- NO sell data to third parties
- NO personal profile inside Tiny Fates
- NO cross-app/website tracking with our own analytics
2. How We Use Your Information
- Anonymous analytics: improve game balance, identify crashes, measure retention
- Purchases: deliver content you paid for; process refund requests if needed
- Advertising: support free gameplay without charging every player
- Locally stored data: save game progress on your device so you can continue later
- Cloud sync: restore save slots when you sign in
We do not sell data. Free-user app ads may involve standard Google AdMob processing to deliver, cap, and measure ads. The marketing website may use Google AdSense after consent. Avoid in-app ads by enabling Fates Pass.
3. Data Processing Location
PostHog (app analytics): EU ingestion region (eu.i.posthog.com) for consented app analytics.
Google Analytics 4: optional marketing-website analytics after consent, used for traffic and download-funnel measurement.
Sentry (crash diagnostics): receives scrubbed error diagnostics for reliability and debugging. Personal data is disabled by default; project retention and processing location follow the configured Sentry project.
RevenueCat (purchase validation): validates App Store and Google Play receipts and provides entitlement state.
Apple App Store and Google Play (payments): process in-app purchases and subscriptions under their store terms.
Supabase (optional auth/cloud saves): stores account profile and save slots only if you sign in.
Your device: Character data is stored locally by default.
4. Your Rights (GDPR + CCPA)
You have right to:
- Access: request what anonymous data tied to device's anonymous ID
- Deletion: delete all data by uninstalling app (local data) and contacting us to reset anonymous analytics record
- Objection: opt out of analytics and crash diagnostics (see below)
- Portability: request copy of data in JSON format
Exercise these rights, email: support@tinyfates.com
Respond within 30 days.
How to opt out of analytics
In Settings screen, open Privacy section, toggle "Analytics" to OFF. Prevents further analytics events and crash diagnostics from being recorded. Queued analytics events are discarded locally.
Delete existing analytics data: email support@tinyfates.com from account address used for Tiny Fates.
5. Children's Privacy
Tiny Fates rated 17+ due to:
- References to alcohol, substance use, therapy
- Simulated gambling (crypto trading mechanics)
- Crime-themed content (tax evasion, white-collar crime)
- Mature humor
No knowingly collect data from children under 13 (U.S. COPPA) or under 16 (EU). If child used app, contact us and we delete any associated anonymous analytics record.
6. Data Retention
- Anonymous analytics: 90 days (PostHog default retention policy, configured for EU compliance)
- Crash diagnostics: according to the configured Sentry project retention policy
- Purchase records: retained as required for tax/audit
- Local game data: retained until you clear app data, uninstall, or reset the game
7. Third-Party Services
| Service | Purpose | Privacy Policy |
|---|---|---|
| PostHog (EU) | Optional app analytics | https://posthog.com/privacy |
| Google Analytics | Optional marketing-site analytics | https://policies.google.com/privacy |
| Sentry | Scrubbed crash diagnostics | https://sentry.io/privacy/ |
| RevenueCat | Purchase validation | https://www.revenuecat.com/privacy |
| Apple App Store | iOS purchase processing | https://www.apple.com/legal/privacy/ |
| Google Play | Android purchase processing | https://policies.google.com/privacy |
| Google AdMob / AdSense | App ads and consented marketing-site ads | https://policies.google.com/privacy |
| Self-hosted game backend (our VPS) | Optional account auth and cloud save slots | This policy (host: api.tinyfates.com) |
No send these services your account password. If opt in to FateWire milestones, our backend stores public username and character name needed to display that public feed row.
8. Security
- Data in transit: TLS 1.3 for all API calls
- Sensitive auth tokens at rest: stored through platform secure storage. Game saves and local preferences use app storage on the device.
- Optional accounts handled by our self-hosted auth service
- PostHog / RevenueCat are SOC 2 Type II certified
9. Changes to This Policy
May update policy occasionally. Material changes announced in app (What's New screen) and on website at least 30 days before taking effect. "Last updated" date at top reflect current version.
10. Contact
Data Controller: FainTech Solutions SRL Romania, EU
Email: support@tinyfates.com Response time: within 30 days for GDPR requests
11. Compliance Summary
- ✅ GDPR (EU): Optional analytics, diagnostics, and marketing-site advertising are consent-gated; purchase processing is necessary to perform the purchase contract
- ✅ CCPA (California): No sale of personal information, opt-out available
- ✅ COPPA (U.S. children): Not directed at children under 13
- ✅ App Store Privacy Nutrition Label: include product interaction, purchase history, diagnostics, advertising identifiers if personalized ads enabled
- ✅ Google Play Data Safety: disclose app activity, app info/performance, purchase history, advertising ID use where applicable
Apple Privacy Nutrition Label
Fill in App Store Connect:
Data Types Collected:
- Product Interaction (anonymous) — Analytics
- Purchase History — App Functionality (IAP)
- Performance Data (crashes) — Analytics
- Device ID / Advertising ID — Third-party advertising for free users
Linked to User? No Used for Tracking? Yes if personalized ads / ATT tracking enabled
Google Play Data Safety Form
Data collected:
- App activity → In-app actions (for analytics)
- App info and performance → Crash logs (for fixing bugs)
- Device or other IDs → Advertising ID for ad delivery and measurement
Data shared: In-app ad requests are processed by Google AdMob for free users. Marketing-site ad requests may be processed by Google AdSense after consent.
Data encrypted in transit: Yes Can request deletion: Yes (email support@tinyfates.com)