Privacy Policy

Effective September 7, 2026 · Qirai Technologies (3-101-960370 Sociedad Anónima) · Río Segundo, Alajuela, Costa Rica.

Tiny Dungeon is a single-player puzzle game made by Qirai Technologies. It has no accounts, no sign-in, no advertising, and no social features. This policy describes everything it collects and why.

The short version. We create an anonymous ID so your progress can be saved. We keep your progress, your balances, what you have bought, and your settings against that ID. We use Google Firebase to do it. We do not ask for your name or email, we do not see your payment details, and we do not sell anything to anyone.

Contents

  1. Who we are
  2. What we collect
  3. Why we collect it
  4. Who processes it
  5. How long we keep it
  6. Your rights
  7. Children
  8. Changes
  9. Contact

1. Who we are

The controller of the data described here is Qirai Technologies (3-101-960370 Sociedad Anónima), Río Segundo, Alajuela, Costa Rica.. You can reach us at privacy@qirai.tech.

Tiny Dungeon is sold worldwide, so more than one data protection law applies to it, and we hold ourselves to all of them:

Where these differ we apply whichever gives you more protection, to every player, wherever they live. We do not offer a weaker standard outside Europe.

2. What we collect

An anonymous player ID

On first launch the app creates an anonymous account through Firebase Authentication. This produces a random identifier. It is not linked to your name, email, phone number, or any account you hold elsewhere, and we cannot use it to identify you as a person. It exists so your progress can be saved and so purchases can be credited to the right save.

Game data

Stored on your device and, when online, against your anonymous ID:

DataExample
ProgressWhich rooms you have completed, how far you have reached
BalancesYour gold and gems
InventoryWhich heroes you own and which is equipped
Reward recordsWhich rooms have already paid their one-time gold
SettingsLanguage, sound preferences, hints, vibration
ProfileWhen the save was created, when it was last used, which platform created it

Purchase records

When you buy gems, we record the store the purchase came from, the product identifier, the store's transaction identifier, whether it was a sandbox or production purchase, how many gems it granted, and when. This is what lets us give you what you paid for exactly once, and support a refund or a dispute later.

We never see your payment details. Card numbers, billing addresses and the payment itself are handled entirely by Apple or Google.

Analytics

We use Firebase Analytics to understand how the game is played — which rooms people reach, where they stop, whether a purchase flow failed. The events we send are: starting and completing a room, selecting or buying a hero, opening the shop, buying a gold bundle, starting, completing or failing a gem purchase, and changing language. They carry a room number, a hero name, a product identifier or a language code, and nothing else.

Firebase Analytics also collects some information automatically, including an app instance ID, device model, operating system version, and approximate country. We do not send it purchase tokens, receipts, or anything that identifies you as a person.

Crash reports

If the app crashes, Firebase Crashlytics sends us a report: the error, where in the code it happened, and the device state at the time. We do not attach purchase data or personal information to those reports.

Abuse protection

Firebase App Check verifies that requests come from a genuine copy of the app, using Play Integrity on Android and App Attest on iOS. This helps stop people forging requests to our servers to award themselves currency.

What we do not collect

3. Why we collect it

PurposeLegal basis (UK/EU GDPR)
Saving your progress and balances, delivering purchases Performance of a contract — it is the service you asked for
Preventing duplicate or fraudulent purchases; App Check Legitimate interests — protecting the service and paying customers
Keeping purchase records for refunds, disputes and accounting Legal obligation and legitimate interests
Analytics and crash reporting Legitimate interests — making the game work and improving it

4. Who processes it

We use Google Firebase (Google Ireland Limited / Google LLC) for authentication, storage, analytics, crash reporting and abuse protection. Google acts as our processor and its own terms apply to that processing.

Apple and Google Play process purchases as independent controllers under their own privacy policies. We receive only confirmation of a purchase and its identifiers.

Data may be processed outside your country, including in the United States, under the transfer safeguards Google offers, such as Standard Contractual Clauses.

We do not sell personal information, and we do not share it for advertising.

5. How long we keep it

6. Your rights

We extend these to every player, whether or not the law where you live requires it:

We answer within 30 days. We do not charge for this, and we will not treat you differently for asking.

Because your save is anonymous, we usually cannot connect it to you as a person from an email alone. To act on a request we may need the identifier the app can show you — see Delete my data.

7. Children

Tiny Dungeon is a mixed audience app: adults play it, and it plainly appeals to children too. We treat it that way rather than claiming otherwise.

We ask, once

The first time you open the game it asks what year you were born. The question is deliberately neutral — it does not tell you what answer gets you anything, and no year is filled in for you. Your answer is stored on your device and in your own save. Nothing about the game changes because of it; only what we collect does.

If you do not answer, we treat you as a child. That is the cautious direction: it means less is collected, not more.

What changes for a player under 16

Under 1616 and over
No analytics at all. Collection is switched off. The gameplay events listed in section 2
Links out of the game are behind a question a small child is unlikely to answer Links open directly
No advertising, no advertising identifier and no ad personalisation, for anybody, at any age — the game carries no advertising at all

We use 16 rather than 13. Data-protection law sets the age of consent anywhere between 13 and 16 depending on the country; taking the strictest common threshold means one rule protects everyone, wherever they live.

Purchases

Parents can disable in-app purchases entirely through Screen Time on iOS or parental controls in the Google Play Store. If you believe a child has made a purchase you did not authorise, Apple and Google both offer refunds — see Support.

If you believe a child has given us information you would rather we did not hold, email privacy@qirai.tech and we will remove it. See also Delete my data.

8. Changes

If we change this policy we will update the effective date at the top. If a change materially affects how we handle your data, we will say so in the app.

9. Contact

Qirai Technologies (3-101-960370 Sociedad Anónima), Río Segundo, Alajuela, Costa Rica.
privacy@qirai.tech