Coldfront

Coldfront — Privacy Policy

Effective date: 30 July 2026 Last updated: 25 August 2026 Who is responsible for your data (the "controller"): Gurpreet Heer, the sole developer of Coldfront. If you need a postal address — to send a formal notice, for example — email us and we will give you one. Contact: support@playcoldfront.com


1. The short version

Coldfront is a strategy game made by one person. It contains no advertising, no tracking, and no third-party analytics or SDKs of any kind — that is not a promise about intent, it is a property of the build. The one measurement it takes, it takes to a server we run ourselves: the Game counts which of its features get used, as anonymous event totals with nothing in them that identifies you — §3(g) lists everything such a count contains — and Settings › Legal has a switch that turns it off in one tap. No third party receives it. There is no account, no sign-in and no password of ours. The Game does ask iOS when it starts whether you are signed in to Game Center, and reads your Game Center player id if you are. Sign-in is never required to play — but if you are signed in, that id is now used for two things, both online-only and both described in §3: it travels to the other players in a room you play in, so that blocking someone can survive them renaming themselves; and when you play a rated Quick Match it is sent to our server with Apple's signature over it, so your rating can belong to a verified player rather than to a string anyone could type. That rating, and the win-loss record behind it, are then shown to everyone on a public leaderboard, under an opaque handle rather than your name (§3(f), §4, and §6 for how to come off it). Beyond that, the Game never reads a device advertising identifier, your location, your contacts, your photos, your microphone or your camera — it never asks iOS where you are, and holds no location permission at all. One thing about where you are is nevertheless written down, and we would rather say so here than only in §3(g): when one of those anonymous usage messages reaches our own server, the server works out from the connection which country and which region — state or province — it came from, and keeps that beside the anonymous row. Not the city, and not the address it worked that out from.

The very first launch is counted before you have seen the switch that stops it. We would rather put that here than leave it to §3(g). The Game counts a launch the moment it starts — every launch, and that includes the first one on a new install: the count goes out from the app's start-up code, before the title screen is drawn, before the first-run card offers you the boot camp, and before the conduct terms card you meet on your way into online play. The switch is on unless you turn it off, so on a device that has never run Coldfront the first thing the Game sends anywhere is that count. It carries what the other counts carry and nothing more — no name, no identifier, nothing about you (§3(g) is the full list) — but it is sent before you have had the chance to decline it, and we are not going to describe it as a choice you made. Turning it off is one tap, in Settings › Legal › SHARE ANONYMOUS USAGE, and from then on the Game sends nothing of the kind; what it cannot do is un-count the launches that came before it.

Nothing you do in single-player or the campaign ever leaves your device, and neither do your saves, your replays or the maps you draw — with one exception, which you control: if you host an online match on a map you drew, that map is sent to the players who join you, because their device has to draw the same battlefield. That is the only way anything from the editor leaves your device.

Beyond those anonymous usage counts, online play is the only part of the Game that sends anything anywhere, and it sends the minimum needed to run a match between people who already have each other's room code.

We do not sell your data and we do not share it with advertisers. We keep one record about a person and it is the rated Quick Match row in §4 — a rating, a win-loss count and standing counters against a verified Game Center id, published on the leaderboard. Nothing else about you is compiled anywhere, and you can delete that row yourself, in the app, from Settings › Multiplayer › DELETE MY LADDER RECORD. §6 says exactly what deleting it removes and what it keeps.

2. What stays on your device

The Game stores the following in its own app sandbox. None of it is uploaded to us automatically. The rows marked † also travel to the other players in your room when you play online — see §3.

WhatWhy
Your display name † and the relay address you connect toSo you don't retype your name. The address is the one the Game ships with, unless an older version of the Game saved a different one you had typed
Music and sound-effect levels, the "seen the intro", "seen the editor hint" and "seen the low-power hint" flags, and a note that you agreed to the Terms before playing onlineYour preferences, and so you are not asked again
Whether the Share anonymous usage switch is on, and which one-time usage milestones have already been countedSo your choice is remembered, and so a first-time event (§3(g)) is only ever counted once
Which campaign missions you have completedSo the campaign remembers where you got to
Which paid items you own — today only the Frost faction — as one line per App Store product id, and nothing about the payment itself: no card, no price, no receipt, no dateSo the Game knows what you paid for without asking the App Store every launch, and so a faction you bought still works with no network. This is a copy of an answer that belongs to your Apple Account, not the purchase: the Game asks Apple again quietly at every launch, and Settings › Purchases › Restore Purchases asks on demand — so losing this device, or deleting the app, loses the copy and not the purchase
Custom maps you draw †The map editor itself
Saved games and replaysThe features themselves
A Quick Match device key † — sixteen random bytes the Game makes up the first time you use Quick Match, meaning nothing about you or your deviceSo unrated Quick Match play can be attributed to a device consistently without any sign-in; see §3(f)
Your own place on the Quick Match ladder as it was last shown to you — your rank and rating, or a short word or count — which is a copy of the §4 row, not a second record about youSo the menu can show where you stand immediately, instead of a blank space while the leaderboard is asked
A Quick Match result the relay has not acknowledged yet — the match id and its report token, your device key †, who won, how long the match ran, a checksum of the match's final state, and how many times that match had to resync. It is deleted as soon as the relay records the result, or refuses it for goodSo a finished match still counts if your connection drops as it ends; the Game resends it the next time it connects
Your blocked-player list — for each block, that player's display name, the room code you met them in, the date, and, when that player was signed in to Game Center, their Game Center player idSo blocks survive a restart — and, with the id, survive the blocked player renaming themselves
A copy of every report you submit — its reference id, the category you chose, the reported player's display name and their slot, the room code, your own display name and your own slot, the app and build number, the date, and for a map report that map's name, its id, its layout (size, biome, number of starting positions and control points), the size in bytes and the sha256 checksum of the exact map data that was on the wire, and every row of its painted terrainSo you keep your own record of what you sent

Nothing about a purchase leaves your device, and nothing about it reaches us. Buying the Frost faction is a transaction between you and Apple; we are never told who bought it, and no payment detail is ever handed to the Game. What the Game keeps is one line saying that this Apple Account owns that item, so it does not have to interrupt you with a store round-trip every time it starts. The purchase itself is not kept here — it is held against your Apple Account — which is why it follows you to a new phone, and why Restore Purchases can always fetch it back.

Replays and saves can contain someone else's map. The Game records a replay of every match automatically, online matches included. You can also save a match in progress, but only in single-player — an online match is live-only and the Game refuses to save it. When a match is played on a custom map rather than a built-in one, a copy of that map is written into the replay file, and into the saved game where there is one, so that it can still be opened later. If you join a room and the host has chosen a map they drew, your device therefore keeps a copy of their map inside your replay of that match, until you delete that replay.

Submitting a report also uses your clipboard. When you tap SEND REPORT, the Game puts the full report text on your device's clipboard as well as saving it, so you can paste it in if your mail app drops it. The clipboard is shared across the whole device: whatever app you paste into next receives it, and if you have Handoff switched on, iOS copies it to your other Apple devices. That text contains another player's display name and, for a map report, the map they drew — so copy something else afterwards if you would rather not leave it sitting there. The Game itself reads your clipboard only when you tap PASTE on the join screen, and takes nothing from it but a room code.

Deleting things. Every saved game and every replay has a DELETE control in its own browser, every custom map has one in the editor, and Settings › Blocked Players lets you review and undo any block. Deleting a replay or a saved game also deletes the copy of any custom map that match was played on. In this version there is no in-Game control for deleting a saved report copy: removing those means deleting the app, which removes everything at once.

Like every iOS app, Coldfront's data is included in your iCloud or computer backups. So a backup made before you deleted the app can still hold a copy — of your block list, or of a report you filed. That backup is held by you and by Apple, not by us; we never see it, and it goes when the backup is replaced or removed.

We cannot read anything on your device. The only way any of it reaches us is if you choose to send us a report, which is §3(e).

Coldfront also remembers how you like the screen set up — for example the size you chose for the radar — in a small settings file on your device. It is a display preference, nothing about you, and it is never sent anywhere.

3. What the Game sends, and to whom

Parts (a) through (f) are about online play: online matches run through a small relay server we operate (see §4), and when you host or join a room, this is what is processed. Part (g) is the one thing sent outside online play — the anonymous usage counts — and it is the only part of this section you can switch off in the Game itself.

a. Your display name. Sent to the relay and shown to the other players in your room. The relay keeps it in memory for as long as that room exists, sends it to everyone in the room whenever the roster changes, and holds it briefly after you disconnect so you can rejoin the same slot. When the room empties or the server restarts, it is gone.

Two copies can outlive the room, and they sit on other people's devices rather than ours. If another player blocks you, your display name, the room code and the date are saved to a block list on their device until they unblock you. If another player reports you, your display name is written into a copy of the report kept on their device, and is sent to us inside that report. Neither is something we control or can undo for you.

It is a self-chosen handle. If you put your real name in it, that is what other people see and store — please don't.

b. Custom maps, if you host and choose one. The whole map file is relayed to everyone who joins your room: its name, the terrain you painted (that is, arbitrary imagery you drew), its size and biome, its starting positions and control points, and the id it was saved under. It is sent more than once. The lobby broadcasts a preview copy so joiners can see the map before the match, and re-sends it every time the roster changes — so a room that fills up, or that people join and leave, relays it again each time — and the binding copy is sent once more when the match starts.

On a joiner's device the map is loaded into memory for the match and dropped when they return to the main menu; it is never added to their saved map library. But the replay their device records of that match keeps a copy of it — see §2. That file is on their device, not ours, and we cannot delete it. If you would rather not hand a map you drew to the people in your room, do not host a match with it.

c. Gameplay commands. The moves and orders every player makes, relayed so that everyone's copy of the match stays in step, along with a short numeric fingerprint of the game state used to detect when two copies have drifted apart. They are about the game — where you sent a tank, what you chose to build — not about you or your device. They do travel through the same room as your display name and are tagged with your slot, so treat them as part of what the other players in that room can see. We do not store them: they pass through the relay and are gone.

d. Connection metadata. Like any internet service, the relay has to see the network address a connection arrives from — that is how a connection works. It is not written down.

The relay writes one line to its host's log stream for each connection event: connect, room created, joined, rejoined, slot freed, dropped, reconnect grace expired, room removed, idle socket reaped, disconnect. Those lines carry, depending on the event, the room code, the slot number and a short connection label — a connect or disconnect line, for instance, has no room to name yet. They never carry a display name, and they never carry anything that was relayed — no map, no command, no message contents.

That connection label is not your address. It is a scrambled six-character stand-in, computed with a secret the relay generates fresh in its own memory each time it starts, keeps nowhere, and never writes down. It exists so we can tell that three lines came from one connection while we are fixing a fault. It cannot be turned back into an address — not by us, not by our hosting provider, not by anyone who obtained the logs — and after the relay restarts, the same person's connections get an entirely different label.

Those lines go to our hosting provider's log stream and nowhere else. We keep no copy of them, and there is no database. The provider deletes them on its own automatic cycle, currently about seven days. We use them to diagnose faults in the relay. We do not use them for advertising, and because no line contains a display name or an address, we cannot connect a line to a person.

e. If you send us a report or an email. The Game does not email us for you. Tapping SEND REPORT writes a copy of the report to your own device, puts the same text on your clipboard, and opens your own email app with the message ready — nothing leaves your device until you tap Send there. If your email app does not open, the report is still on your clipboard and saved on your device, and you can send it to us any way you like.

When you do send it, we receive what your mail app sends: your email address, the text of the report, the display name of the player you are reporting, the room code, your own display name, and for a report about a map, that map's name and its painted terrain. Your email provider carries it, and a copy stays in your Sent folder. We use it only to look into the report and to enforce our Terms, and we reply from the same address.

There is no account system. No password, no sign-in of ours, no contact list, no location permission, no device advertising identifier, no photos, no microphone or camera access. The Game never asks for those permissions and never reads them. (§3(g) covers the one thing recorded about where you are. It is worked out at our end, from the connection, and is never read from your phone.)

f. Game Center, if you are signed in. When the Game starts it asks iOS whether you are signed in to Game Center. If you are, it reads your Game Center player ids — the game-scoped id and the team-scoped id Apple issues for this developer's games; both identify your Game Center account only within this developer's games and are not your Apple ID, your name or your email — and the flags iOS attaches to that account: whether it is an underage account, and whether Screen Time restricts multiplayer or messaging.

None of it is required. You do not need Game Center to play, online or otherwise; nothing in the Game is locked behind it except a rating (below), and if Game Center is switched off in your iOS Settings the Game simply gets no answer and carries on exactly as before. Because iOS handles the question itself, you may see Apple's own Game Center panel appear; that panel is Apple's, not ours, and what you tell it goes to Apple under Apple's privacy policy.

What becomes of what it reads, when you are signed in:

g. Anonymous usage counts — the one thing sent outside online play. So that one developer can tell which features earn their keep, the Game counts moments like "a match finished", "the store was opened", "the map editor was opened", or which of the two buttons was pressed on the invitation card shown at the very first launch. The list of countable events is fixed and built into the app — twelve of them, nothing free-form — and each is sent as a small message to an analytics server we run ourselves (an open-source program, self-hosted on the same provider as the relay — see §4). No analytics company is involved and no third party receives anything.

What one of those messages contains, in full — and this list is no longer maintained by hand: a test compares it against the columns the server actually stores, and fails if the two ever differ, so an upgrade to the analytics software cannot quietly make this paragraph untrue. The list is: the event's name; the moment the event happened; for a finished skirmish, which built-in map it was (a map you drew is reported only as the word "custom" — its name never leaves your device this way), the match shape (1v1, teams or free-for-all), whether you won, and the match length rounded into five coarse buckets; for a campaign win, which built-in mission it was; for the invitation card at first launch, which of its two buttons you pressed — one of exactly two fixed words, "boot_camp" or "skip", and the app can send no third one; plus the app's version and build number, the operating system's name and version, your language code (just the language — "en", not where you live), a tag naming the version of the counting code inside the app, whether the build came from the App Store or is one of our own test builds — test builds are counted separately and never mixed in with players — a session token, and a deletion date, which is how long the server keeps the record: five years for a released build, six months for one of our test builds. That is the whole list.

About that session token: the Game makes one up fresh at every launch, never writes it to your device and never reuses it. It exists so a handful of events from one sitting can be counted as one sitting. It is not purely random, and we would rather say so than round the description off: the second the app started is embedded in it, because the server checks that a session did not claim to begin in the future. So it records when a launch happened, and nothing whatever about who launched it.

There is no name in any of this, no display name, no Game Center id, no device identifier, no advertising identifier, no coordinates, and no free text of yours — and the app refuses at the door to send any event or field that is not on its built-in list, so a future mistake cannot widen this quietly. Nothing the Game sends says where you are. The one thing recorded about that is worked out at the other end, from the connection itself, and the next paragraph is about exactly that.

The server works out the country and the region a message arrived from, and nothing finer. As each message reaches the analytics server, the server looks up the network address it came from in a geographic database and keeps two things about it: a two-letter country code, and the name of the region — the state or province — inside that country. That is the whole of it: no city is worked out and none is stored. The field that would hold a city is written empty on every row by the analytics program itself, so that is a property of the software rather than a habit of ours, and a test counts that field on the live server and fails if a single row is ever found carrying one.

The network address itself is not kept. It is used for that one lookup, in memory, as the message arrives, and then it is gone — the stored rows have no address column at all. What is left is a row saying that a message came from, say, California in the United States: never who sent it, and never where in California they were.

Why we keep even that much, when the rest of this section is about keeping as little as possible. One developer with one server, in the United States, cannot otherwise tell whether the game is slow for people far from it, or which places it is played in enough to be worth translating for. A country and a region answer those questions. A city would not answer them any better, so the coarser answer costs us nothing to prefer.

The anonymous token the server uses to group one day's events together is scrambled with a secret it throws away daily, so yesterday's events cannot be connected to today's, let alone to you.

When the first of these is sent: the moment the app starts, including the very first time. One of the twelve events is simply that the app was launched, and it is sent from the app's start-up code — before the title screen is drawn, before the first-run card offers you the boot camp, and before the conduct terms card you are shown on your way into your first online match. On a device that has never run Coldfront before, that message is the first thing the Game sends anywhere. It contains exactly what the list above describes and nothing else: no name, no identifier, nothing about you. But the switch that stops it is on unless you turn it off, and on a first launch you have not been able to reach it yet — so that first count is not something you agreed to, and we would rather say so than let "on by default" carry the whole weight of it.

Two smaller things belong in the same breath rather than under the word "twelve". Agreeing to the conduct terms is itself one of the twelve events: when you accept that card, the app counts that it was accepted — not who accepted it, and nothing you typed. And the two buttons on the first-run card are counted the same way; that is the "boot_camp" or "skip" described above. The screens that ask you things are counted like every other screen, and we would rather name that than leave you to work it out from the list.

You can turn this off in one tap: Settings › Legal › SHARE ANONYMOUS USAGE. It is on by default; switched off, the Game sends nothing of the kind, immediately and for as long as you leave it off. The switch is stored only on your device (§2). The one thing switching it off cannot do is un-count the launches that happened before you got to it — on a new install, at least the one that opened the app you are turning it off in.

4. Where the relay runs, and who else touches the data

The relay we operate is hosted on Fly.io, in the United States (region sjc, US West). Fly.io acts as our hosting provider and processes this data only on our instructions; it is contractually required to protect it to the same standard this policy sets out.

Room state — who is in the room, their display names, the host's chosen map — lives in the memory of the relay process and nowhere else. When a room empties, or the server restarts, that state is gone. Nothing about your friend-code matches is archived by us.

Quick Match is the one exception, and it is a small, deliberate one. A ranked ladder cannot exist without a record, so the relay keeps a matchmaking ledger in a database on its disk: for each Quick Match, which two identities played (the verified Game Center team id for signed-in players, or the one-way scrambled form of the anonymous device key — the raw key is never stored), the map, when it was played, the reported outcome, each player's rating before and after where the match was rated, and per-player standing counters (games played, matches abandoned) that keep the queue fair. That is the whole list: no display of your id to other players, no chat, no addresses, nothing from inside the match itself. The ledger lives on the same encrypted volume as the relay, is covered by its provider snapshot cycle, and is what the public leaderboard is computed from — the leaderboard shows an opaque handle, never a display name and never a Game Center id.

The anonymous usage counter in §3(g) runs the same way: an open-source analytics program we host ourselves on Fly.io, in the United States, beside the relay but on its own server. It is our instance on our infrastructure — the software's maker never receives anything, and neither does anyone else.

We use no other sub-processors: no analytics vendor, no crash reporter, no advertising network, no content delivery network for user data. The Game is distributed by Apple through the App Store, and anything Apple collects in the course of that is covered by Apple's own privacy policy, not by this one. We do not sell or share personal information as those terms are defined under California law, and we have not done so in the preceding twelve months.

If you are in the UK or the EEA. The relay runs in the United States, so when you play online your display name, any map you host and your gameplay commands leave your country. We rely on the standard contractual clauses in Fly.io's data processing agreement to protect that transfer.

5. Why we process it (legal bases)

Where the GDPR or similar law applies, we rely on:

Do you have to give us a display name? No law requires it and no contract compels it. It is simply needed for online play, because the other people in your room have to see something. Everything else in the Game works without one.

Automated filtering. The Game checks display names and custom-map titles against a list of objectionable words and refuses ones that match. That check runs entirely on your own device, on the text you type, and again on your device on every name that arrives from another player before it is drawn — nothing is sent anywhere to perform it, and we never see a name that was refused. It can refuse a name or a map title, and it tells you that it was refused, but not which word matched: naming the word would repeat it back at you and would show anyone testing the list what to change, so the message is deliberately the same every time. You are free to try another name. It makes no other decision about you, and it is not automated decision-making that produces legal or similarly significant effects.

6. How long we keep things

If the app cannot reach our server, nothing is deleted and the app says so rather than pretending it worked; try again when you have a connection. You are welcome to email support@playcoldfront.com if it never goes through, but be aware of the limit that made the in-app control necessary: your record is keyed to an identifier we never show you, we hold no display name and no email address against it, and so we usually cannot find your row from an email at all.

7. What we declare to the App Store

Apple asks every developer to declare what their app collects. Our declaration for Coldfront is:

8. Children

Coldfront is not directed at children. Our Terms set a minimum age of 13, or 16 where local law requires — but the Game has no account system and never asks your age, so that minimum is self-declared and we cannot check it. We do not knowingly collect personal information from children under those ages.

If you believe a child is using the Game and has sent us something, email support@playcoldfront.com. In practice there is very little that could exist: a display name held in a server's memory for the length of one match, any report email, and — if that person signed in to Game Center and played rated Quick Match — the ladder row described in §4, which is published on the leaderboard. We will delete whatever we hold and stop processing it; for the ladder row, §6 says what we need in order to find it.

9. Your rights, and what you can do without asking us

Depending on where you live you may have the right to access, correct, delete, restrict or port your personal data, and to object to processing. You can also complain to the data protection authority of the country where you live or work — in the United Kingdom that is the Information Commissioner's Office, ico.org.uk.

Most of it you can do yourself, immediately, without writing to anyone. To stop what online play sends (§3(a)–(f)), stop playing online; to stop the anonymous usage counts, switch off Settings › Legal › SHARE ANONYMOUS USAGE (§3(g)). With those two done, nothing in the Game sends anything anywhere. It is worth knowing before you go looking for that switch that some counting has already happened by the time you reach it: the Game counts each launch as it starts, including the first one on a new install, which is before that screen — or any other — has been drawn. §3(g) sets out what those counts contain and why we will not call the first one consented to. Inside the Game, every saved game, replay and custom map has a DELETE control, and Settings › Blocked Players lets you review and undo any block. Deleting the app removes everything held on your device at once.

To ask us to delete something we hold — in practice, a report you or someone else sent us — email support@playcoldfront.com. We will respond without undue delay and in any event within one month of receiving your request; if the request is complicated we may take up to two further months, and we will tell you inside the first month if that happens.

There is one more thing we hold, and it is the one this section exists for. If you have played a rated Quick Match while signed in to Game Center, the relay keeps a row for you — your rating, your win-loss record and your standing counters, against your verified Game Center id (§4) — and while it qualifies that row is published on the public leaderboard. You can delete it yourself, in the app: Settings › Multiplayer › DELETE MY LADDER RECORD. §6 says exactly what that deletes and what it keeps, and deleting it is the way off the board. Read §6 before you use it, because what it erases cannot be brought back, the match rows are kept, and you can only delete once every 30 days. You do not need to write to us and you do not need to find an identifier — the control uses the identity your device already holds, and it is the only way an anonymous record can be deleted at all. Nothing else about you is kept alongside that row: no account, no password, no email address of yours unless you have written to us, and nothing you do offline.

Your display name and any map you share exist only for the life of a room. Connection logs are held by our hosting provider on its own cycle and age out by themselves; we cannot delete an individual line from them, and since no line contains a display name we could not identify which line was yours in any case.

10. Security

Traffic between your device and the relay we operate is encrypted in transit (TLS, wss://). There are no passwords or credentials to protect, because the Game has none.

The larger risk in online play is social rather than technical, and it is worth knowing exactly how a room works. A room is protected by its five-character code and by nothing else. Anyone holding that code joins straight away — there is no approval step and no invite list — and codes are short enough that one could be guessed. The moment someone joins, they are shown the display names of everyone already in the room, and if you have chosen a custom map they receive that map, its name and the terrain you drew, before the match even starts. Once someone is in, the host cannot remove them: to get rid of an unwanted joiner you leave and host again, which gives you a fresh code.

So treat anything you put in your display name, or draw into a map you host, as visible to whoever ends up in that room — and share codes privately. You can block a player from the report sheet in a lobby, while you are still in the room with them: their name and their map disappear from your screen immediately, nothing they send reaches your game after that, and the match will not start. There is no block control once you have left the room, so block before you go; Settings › Blocked Players lets you review and undo blocks, not add one. And a block only applies from that moment on — a replay your device recorded earlier still holds that player's map and still draws its terrain on playback, so delete the replay to remove it.

11. Changes

We will post changes on this page with a new "Last updated" date. This page is linked from the Game's Settings › Legal screen and opens in your browser, so you can check it whenever you like — and it is worth a look before you play online after an update.

12. Severability, and how this fits with our Terms

If any part of this policy is found to be unenforceable, the rest of it still applies. Where this policy and our Terms of Use say different things about how we handle your data, this policy governs.

13. Contact

support@playcoldfront.com Support page: https://playcoldfront.com/support