Coldfront — Privacy Policy
Effective date: 30 July 2026 Last updated: 25 August 2026 Who is responsible for your data (the "controller"): Gurpreet Heer, the sole developer of Coldfront. If you need a postal address — to send a formal notice, for example — email us and we will give you one. Contact: support@playcoldfront.com
1. The short version
Coldfront is a strategy game made by one person. It contains no advertising, no tracking, and no third-party analytics or SDKs of any kind — that is not a promise about intent, it is a property of the build. The one measurement it takes, it takes to a server we run ourselves: the Game counts which of its features get used, as anonymous event totals with nothing in them that identifies you — §3(g) lists everything such a count contains — and Settings › Legal has a switch that turns it off in one tap. No third party receives it. There is no account, no sign-in and no password of ours. The Game does ask iOS when it starts whether you are signed in to Game Center, and reads your Game Center player id if you are. Sign-in is never required to play — but if you are signed in, that id is now used for two things, both online-only and both described in §3: it travels to the other players in a room you play in, so that blocking someone can survive them renaming themselves; and when you play a rated Quick Match it is sent to our server with Apple's signature over it, so your rating can belong to a verified player rather than to a string anyone could type. That rating, and the win-loss record behind it, are then shown to everyone on a public leaderboard, under an opaque handle rather than your name (§3(f), §4, and §6 for how to come off it). Beyond that, the Game never reads a device advertising identifier, your location, your contacts, your photos, your microphone or your camera — it never asks iOS where you are, and holds no location permission at all. One thing about where you are is nevertheless written down, and we would rather say so here than only in §3(g): when one of those anonymous usage messages reaches our own server, the server works out from the connection which country and which region — state or province — it came from, and keeps that beside the anonymous row. Not the city, and not the address it worked that out from.
The very first launch is counted before you have seen the switch that stops it. We would rather put that here than leave it to §3(g). The Game counts a launch the moment it starts — every launch, and that includes the first one on a new install: the count goes out from the app's start-up code, before the title screen is drawn, before the first-run card offers you the boot camp, and before the conduct terms card you meet on your way into online play. The switch is on unless you turn it off, so on a device that has never run Coldfront the first thing the Game sends anywhere is that count. It carries what the other counts carry and nothing more — no name, no identifier, nothing about you (§3(g) is the full list) — but it is sent before you have had the chance to decline it, and we are not going to describe it as a choice you made. Turning it off is one tap, in Settings › Legal › SHARE ANONYMOUS USAGE, and from then on the Game sends nothing of the kind; what it cannot do is un-count the launches that came before it.
Nothing you do in single-player or the campaign ever leaves your device, and neither do your saves, your replays or the maps you draw — with one exception, which you control: if you host an online match on a map you drew, that map is sent to the players who join you, because their device has to draw the same battlefield. That is the only way anything from the editor leaves your device.
Beyond those anonymous usage counts, online play is the only part of the Game that sends anything anywhere, and it sends the minimum needed to run a match between people who already have each other's room code.
We do not sell your data and we do not share it with advertisers. We keep one record about a person and it is the rated Quick Match row in §4 — a rating, a win-loss count and standing counters against a verified Game Center id, published on the leaderboard. Nothing else about you is compiled anywhere, and you can delete that row yourself, in the app, from Settings › Multiplayer › DELETE MY LADDER RECORD. §6 says exactly what deleting it removes and what it keeps.
2. What stays on your device
The Game stores the following in its own app sandbox. None of it is uploaded to us automatically. The rows marked † also travel to the other players in your room when you play online — see §3.
| What | Why |
|---|---|
| Your display name † and the relay address you connect to | So you don't retype your name. The address is the one the Game ships with, unless an older version of the Game saved a different one you had typed |
| Music and sound-effect levels, the "seen the intro", "seen the editor hint" and "seen the low-power hint" flags, and a note that you agreed to the Terms before playing online | Your preferences, and so you are not asked again |
| Whether the Share anonymous usage switch is on, and which one-time usage milestones have already been counted | So your choice is remembered, and so a first-time event (§3(g)) is only ever counted once |
| Which campaign missions you have completed | So the campaign remembers where you got to |
| Which paid items you own — today only the Frost faction — as one line per App Store product id, and nothing about the payment itself: no card, no price, no receipt, no date | So the Game knows what you paid for without asking the App Store every launch, and so a faction you bought still works with no network. This is a copy of an answer that belongs to your Apple Account, not the purchase: the Game asks Apple again quietly at every launch, and Settings › Purchases › Restore Purchases asks on demand — so losing this device, or deleting the app, loses the copy and not the purchase |
| Custom maps you draw † | The map editor itself |
| Saved games and replays | The features themselves |
| A Quick Match device key † — sixteen random bytes the Game makes up the first time you use Quick Match, meaning nothing about you or your device | So unrated Quick Match play can be attributed to a device consistently without any sign-in; see §3(f) |
| Your own place on the Quick Match ladder as it was last shown to you — your rank and rating, or a short word or count — which is a copy of the §4 row, not a second record about you | So the menu can show where you stand immediately, instead of a blank space while the leaderboard is asked |
| A Quick Match result the relay has not acknowledged yet — the match id and its report token, your device key †, who won, how long the match ran, a checksum of the match's final state, and how many times that match had to resync. It is deleted as soon as the relay records the result, or refuses it for good | So a finished match still counts if your connection drops as it ends; the Game resends it the next time it connects |
| Your blocked-player list — for each block, that player's display name, the room code you met them in, the date, and, when that player was signed in to Game Center, their Game Center player id | So blocks survive a restart — and, with the id, survive the blocked player renaming themselves |
| A copy of every report you submit — its reference id, the category you chose, the reported player's display name and their slot, the room code, your own display name and your own slot, the app and build number, the date, and for a map report that map's name, its id, its layout (size, biome, number of starting positions and control points), the size in bytes and the sha256 checksum of the exact map data that was on the wire, and every row of its painted terrain | So you keep your own record of what you sent |
Nothing about a purchase leaves your device, and nothing about it reaches us. Buying the Frost faction is a transaction between you and Apple; we are never told who bought it, and no payment detail is ever handed to the Game. What the Game keeps is one line saying that this Apple Account owns that item, so it does not have to interrupt you with a store round-trip every time it starts. The purchase itself is not kept here — it is held against your Apple Account — which is why it follows you to a new phone, and why Restore Purchases can always fetch it back.
Replays and saves can contain someone else's map. The Game records a replay of every match automatically, online matches included. You can also save a match in progress, but only in single-player — an online match is live-only and the Game refuses to save it. When a match is played on a custom map rather than a built-in one, a copy of that map is written into the replay file, and into the saved game where there is one, so that it can still be opened later. If you join a room and the host has chosen a map they drew, your device therefore keeps a copy of their map inside your replay of that match, until you delete that replay.
Submitting a report also uses your clipboard. When you tap SEND REPORT, the Game puts the full report text on your device's clipboard as well as saving it, so you can paste it in if your mail app drops it. The clipboard is shared across the whole device: whatever app you paste into next receives it, and if you have Handoff switched on, iOS copies it to your other Apple devices. That text contains another player's display name and, for a map report, the map they drew — so copy something else afterwards if you would rather not leave it sitting there. The Game itself reads your clipboard only when you tap PASTE on the join screen, and takes nothing from it but a room code.
Deleting things. Every saved game and every replay has a DELETE control in its own browser, every custom map has one in the editor, and Settings › Blocked Players lets you review and undo any block. Deleting a replay or a saved game also deletes the copy of any custom map that match was played on. In this version there is no in-Game control for deleting a saved report copy: removing those means deleting the app, which removes everything at once.
Like every iOS app, Coldfront's data is included in your iCloud or computer backups. So a backup made before you deleted the app can still hold a copy — of your block list, or of a report you filed. That backup is held by you and by Apple, not by us; we never see it, and it goes when the backup is replaced or removed.
We cannot read anything on your device. The only way any of it reaches us is if you choose to send us a report, which is §3(e).
Coldfront also remembers how you like the screen set up — for example the size you chose for the radar — in a small settings file on your device. It is a display preference, nothing about you, and it is never sent anywhere.
3. What the Game sends, and to whom
Parts (a) through (f) are about online play: online matches run through a small relay server we operate (see §4), and when you host or join a room, this is what is processed. Part (g) is the one thing sent outside online play — the anonymous usage counts — and it is the only part of this section you can switch off in the Game itself.
a. Your display name. Sent to the relay and shown to the other players in your room. The relay keeps it in memory for as long as that room exists, sends it to everyone in the room whenever the roster changes, and holds it briefly after you disconnect so you can rejoin the same slot. When the room empties or the server restarts, it is gone.
Two copies can outlive the room, and they sit on other people's devices rather than ours. If another player blocks you, your display name, the room code and the date are saved to a block list on their device until they unblock you. If another player reports you, your display name is written into a copy of the report kept on their device, and is sent to us inside that report. Neither is something we control or can undo for you.
It is a self-chosen handle. If you put your real name in it, that is what other people see and store — please don't.
b. Custom maps, if you host and choose one. The whole map file is relayed to everyone who joins your room: its name, the terrain you painted (that is, arbitrary imagery you drew), its size and biome, its starting positions and control points, and the id it was saved under. It is sent more than once. The lobby broadcasts a preview copy so joiners can see the map before the match, and re-sends it every time the roster changes — so a room that fills up, or that people join and leave, relays it again each time — and the binding copy is sent once more when the match starts.
On a joiner's device the map is loaded into memory for the match and dropped when they return to the main menu; it is never added to their saved map library. But the replay their device records of that match keeps a copy of it — see §2. That file is on their device, not ours, and we cannot delete it. If you would rather not hand a map you drew to the people in your room, do not host a match with it.
c. Gameplay commands. The moves and orders every player makes, relayed so that everyone's copy of the match stays in step, along with a short numeric fingerprint of the game state used to detect when two copies have drifted apart. They are about the game — where you sent a tank, what you chose to build — not about you or your device. They do travel through the same room as your display name and are tagged with your slot, so treat them as part of what the other players in that room can see. We do not store them: they pass through the relay and are gone.
d. Connection metadata. Like any internet service, the relay has to see the network address a connection arrives from — that is how a connection works. It is not written down.
The relay writes one line to its host's log stream for each connection event: connect, room created, joined, rejoined, slot freed, dropped, reconnect grace expired, room removed, idle socket reaped, disconnect. Those lines carry, depending on the event, the room code, the slot number and a short connection label — a connect or disconnect line, for instance, has no room to name yet. They never carry a display name, and they never carry anything that was relayed — no map, no command, no message contents.
That connection label is not your address. It is a scrambled six-character stand-in, computed with a secret the relay generates fresh in its own memory each time it starts, keeps nowhere, and never writes down. It exists so we can tell that three lines came from one connection while we are fixing a fault. It cannot be turned back into an address — not by us, not by our hosting provider, not by anyone who obtained the logs — and after the relay restarts, the same person's connections get an entirely different label.
Those lines go to our hosting provider's log stream and nowhere else. We keep no copy of them, and there is no database. The provider deletes them on its own automatic cycle, currently about seven days. We use them to diagnose faults in the relay. We do not use them for advertising, and because no line contains a display name or an address, we cannot connect a line to a person.
e. If you send us a report or an email. The Game does not email us for you. Tapping SEND REPORT writes a copy of the report to your own device, puts the same text on your clipboard, and opens your own email app with the message ready — nothing leaves your device until you tap Send there. If your email app does not open, the report is still on your clipboard and saved on your device, and you can send it to us any way you like.
When you do send it, we receive what your mail app sends: your email address, the text of the report, the display name of the player you are reporting, the room code, your own display name, and for a report about a map, that map's name and its painted terrain. Your email provider carries it, and a copy stays in your Sent folder. We use it only to look into the report and to enforce our Terms, and we reply from the same address.
There is no account system. No password, no sign-in of ours, no contact list, no location permission, no device advertising identifier, no photos, no microphone or camera access. The Game never asks for those permissions and never reads them. (§3(g) covers the one thing recorded about where you are. It is worked out at our end, from the connection, and is never read from your phone.)
f. Game Center, if you are signed in. When the Game starts it asks iOS whether you are signed in to Game Center. If you are, it reads your Game Center player ids — the game-scoped id and the team-scoped id Apple issues for this developer's games; both identify your Game Center account only within this developer's games and are not your Apple ID, your name or your email — and the flags iOS attaches to that account: whether it is an underage account, and whether Screen Time restricts multiplayer or messaging.
None of it is required. You do not need Game Center to play, online or otherwise; nothing in the Game is locked behind it except a rating (below), and if Game Center is switched off in your iOS Settings the Game simply gets no answer and carries on exactly as before. Because iOS handles the question itself, you may see Apple's own Game Center panel appear; that panel is Apple's, not ours, and what you tell it goes to Apple under Apple's privacy policy.
What becomes of what it reads, when you are signed in:
- It is held in this app's memory for the session, and your player ids are never shown to you. The Game reads them to do the two things below and never puts one on a screen; what Settings › About tells you is whether you are signed in, and whether Screen Time is blocking Game Center multiplayer. The ids are never written to a file on your device, and closing the Game discards everything it read.
- In an online room, your game-scoped player id is sent to the other players in that room (through the relay, like everything else in §3), so that if a player blocks you the block can be filed against your id as well as your display name — meaning you cannot reappear to them simply by renaming yourself. A player who blocks you keeps your id in the block list on their device (the same list described in §2), until they unblock you. This is the change §2's block-list row describes from the other side.
- When you play a rated Quick Match, your team-scoped player id is sent to us, together with a short-lived cryptographic signature Apple creates on your device (Apple calls this the identity-verification signature: the signature itself, a salt, a timestamp, and the address of Apple's public key). Our server checks the signature against Apple's key and then knows — rather than trusts — which Game Center player it is talking to. We keep the verified id, and the match results, rating and standing attached to it, in a small database on our server (see §4): that record is what makes a ladder mean anything, and it follows you across devices and reinstalls because the id does. The signature itself is used for the check and not kept beyond a short replay-protection window. Other players never see this id. What reaches your Quick Match opponent is your display name and an opaque handle — a one-way scrambled form of the id — and their screen shows only the name. The public leaderboard shows that same handle and nothing else about you. It is one fixed string per player, the same wherever it appears and for as long as your record lasts, so anyone who has played you can recognise your row on the board and read the rating and win-loss record on it. The id itself is never shown to another player and never published.
- If you are not signed in, none of the above happens and Quick Match still works — your matches are simply unrated, attributed to an anonymous per-device key that never leaves the dev namespace, and a rating is the only thing you give up. Anonymous match history does not join a Game Center record later: if you sign in, your rated record starts fresh, because we cannot verify that any anonymous history was really yours.
g. Anonymous usage counts — the one thing sent outside online play. So that one developer can tell which features earn their keep, the Game counts moments like "a match finished", "the store was opened", "the map editor was opened", or which of the two buttons was pressed on the invitation card shown at the very first launch. The list of countable events is fixed and built into the app — twelve of them, nothing free-form — and each is sent as a small message to an analytics server we run ourselves (an open-source program, self-hosted on the same provider as the relay — see §4). No analytics company is involved and no third party receives anything.
What one of those messages contains, in full — and this list is no longer maintained by hand: a test compares it against the columns the server actually stores, and fails if the two ever differ, so an upgrade to the analytics software cannot quietly make this paragraph untrue. The list is: the event's name; the moment the event happened; for a finished skirmish, which built-in map it was (a map you drew is reported only as the word "custom" — its name never leaves your device this way), the match shape (1v1, teams or free-for-all), whether you won, and the match length rounded into five coarse buckets; for a campaign win, which built-in mission it was; for the invitation card at first launch, which of its two buttons you pressed — one of exactly two fixed words, "boot_camp" or "skip", and the app can send no third one; plus the app's version and build number, the operating system's name and version, your language code (just the language — "en", not where you live), a tag naming the version of the counting code inside the app, whether the build came from the App Store or is one of our own test builds — test builds are counted separately and never mixed in with players — a session token, and a deletion date, which is how long the server keeps the record: five years for a released build, six months for one of our test builds. That is the whole list.
About that session token: the Game makes one up fresh at every launch, never writes it to your device and never reuses it. It exists so a handful of events from one sitting can be counted as one sitting. It is not purely random, and we would rather say so than round the description off: the second the app started is embedded in it, because the server checks that a session did not claim to begin in the future. So it records when a launch happened, and nothing whatever about who launched it.
There is no name in any of this, no display name, no Game Center id, no device identifier, no advertising identifier, no coordinates, and no free text of yours — and the app refuses at the door to send any event or field that is not on its built-in list, so a future mistake cannot widen this quietly. Nothing the Game sends says where you are. The one thing recorded about that is worked out at the other end, from the connection itself, and the next paragraph is about exactly that.
The server works out the country and the region a message arrived from, and nothing finer. As each message reaches the analytics server, the server looks up the network address it came from in a geographic database and keeps two things about it: a two-letter country code, and the name of the region — the state or province — inside that country. That is the whole of it: no city is worked out and none is stored. The field that would hold a city is written empty on every row by the analytics program itself, so that is a property of the software rather than a habit of ours, and a test counts that field on the live server and fails if a single row is ever found carrying one.
The network address itself is not kept. It is used for that one lookup, in memory, as the message arrives, and then it is gone — the stored rows have no address column at all. What is left is a row saying that a message came from, say, California in the United States: never who sent it, and never where in California they were.
Why we keep even that much, when the rest of this section is about keeping as little as possible. One developer with one server, in the United States, cannot otherwise tell whether the game is slow for people far from it, or which places it is played in enough to be worth translating for. A country and a region answer those questions. A city would not answer them any better, so the coarser answer costs us nothing to prefer.
The anonymous token the server uses to group one day's events together is scrambled with a secret it throws away daily, so yesterday's events cannot be connected to today's, let alone to you.
When the first of these is sent: the moment the app starts, including the very first time. One of the twelve events is simply that the app was launched, and it is sent from the app's start-up code — before the title screen is drawn, before the first-run card offers you the boot camp, and before the conduct terms card you are shown on your way into your first online match. On a device that has never run Coldfront before, that message is the first thing the Game sends anywhere. It contains exactly what the list above describes and nothing else: no name, no identifier, nothing about you. But the switch that stops it is on unless you turn it off, and on a first launch you have not been able to reach it yet — so that first count is not something you agreed to, and we would rather say so than let "on by default" carry the whole weight of it.
Two smaller things belong in the same breath rather than under the word "twelve". Agreeing to the conduct terms is itself one of the twelve events: when you accept that card, the app counts that it was accepted — not who accepted it, and nothing you typed. And the two buttons on the first-run card are counted the same way; that is the "boot_camp" or "skip" described above. The screens that ask you things are counted like every other screen, and we would rather name that than leave you to work it out from the list.
You can turn this off in one tap: Settings › Legal › SHARE ANONYMOUS USAGE. It is on by default; switched off, the Game sends nothing of the kind, immediately and for as long as you leave it off. The switch is stored only on your device (§2). The one thing switching it off cannot do is un-count the launches that happened before you got to it — on a new install, at least the one that opened the app you are turning it off in.
4. Where the relay runs, and who else touches the data
The relay we operate is hosted on Fly.io, in the United States (region sjc, US West). Fly.io acts as our hosting provider and processes this data only on our instructions; it is contractually required to protect it to the same standard this policy sets out.
Room state — who is in the room, their display names, the host's chosen map — lives in the memory of the relay process and nowhere else. When a room empties, or the server restarts, that state is gone. Nothing about your friend-code matches is archived by us.
Quick Match is the one exception, and it is a small, deliberate one. A ranked ladder cannot exist without a record, so the relay keeps a matchmaking ledger in a database on its disk: for each Quick Match, which two identities played (the verified Game Center team id for signed-in players, or the one-way scrambled form of the anonymous device key — the raw key is never stored), the map, when it was played, the reported outcome, each player's rating before and after where the match was rated, and per-player standing counters (games played, matches abandoned) that keep the queue fair. That is the whole list: no display of your id to other players, no chat, no addresses, nothing from inside the match itself. The ledger lives on the same encrypted volume as the relay, is covered by its provider snapshot cycle, and is what the public leaderboard is computed from — the leaderboard shows an opaque handle, never a display name and never a Game Center id.
The anonymous usage counter in §3(g) runs the same way: an open-source analytics program we host ourselves on Fly.io, in the United States, beside the relay but on its own server. It is our instance on our infrastructure — the software's maker never receives anything, and neither does anyone else.
We use no other sub-processors: no analytics vendor, no crash reporter, no advertising network, no content delivery network for user data. The Game is distributed by Apple through the App Store, and anything Apple collects in the course of that is covered by Apple's own privacy policy, not by this one. We do not sell or share personal information as those terms are defined under California law, and we have not done so in the preceding twelve months.
If you are in the UK or the EEA. The relay runs in the United States, so when you play online your display name, any map you host and your gameplay commands leave your country. We rely on the standard contractual clauses in Fly.io's data processing agreement to protect that transfer.
5. Why we process it (legal bases)
Where the GDPR or similar law applies, we rely on:
- performance of a contract (our Terms of Use) to relay your display name, your custom maps and your gameplay commands — without them, online play cannot function;
- performance of a contract also to keep the rated Quick Match record in §4 and to show it on the public leaderboard, for as long as you take part in rated play: a ranked ladder is what a rated match is for, and it cannot exist without a durable record that others can be ranked against. You choose rated play by signing in to Game Center and using Quick Match, and §6 says how to have the record deleted;
- legitimate interests to keep short-lived connection logs so we can diagnose faults in the relay, to count feature use as the anonymous totals in §3(g) — which contain nothing that identifies you and which you can switch off in Settings — and to read and act on reports about objectionable content, including replying to you about a report you sent;
- compliance with a legal obligation where we must retain something in order to answer a lawful request.
Do you have to give us a display name? No law requires it and no contract compels it. It is simply needed for online play, because the other people in your room have to see something. Everything else in the Game works without one.
Automated filtering. The Game checks display names and custom-map titles against a list of objectionable words and refuses ones that match. That check runs entirely on your own device, on the text you type, and again on your device on every name that arrives from another player before it is drawn — nothing is sent anywhere to perform it, and we never see a name that was refused. It can refuse a name or a map title, and it tells you that it was refused, but not which word matched: naming the word would repeat it back at you and would show anyone testing the list what to change, so the message is deliberately the same every time. You are free to try another name. It makes no other decision about you, and it is not automated decision-making that produces legal or similarly significant effects.
6. How long we keep things
- Room state (names, the host's map, match sync): in memory only, deleted when the room ends or the relay process restarts. Never written to disk by us.
- The Quick Match ledger (§4): kept for as long as the ladder exists, because a rating is a running total of its matches — or until you delete it, which you can do yourself, in the app, without asking us and without waiting for us. Open Settings › Multiplayer › DELETE MY LADDER RECORD, and confirm. It uses the identity your device already holds, so there is nothing for you to look up, transcribe or email, and it works whether or not you are signed in to Game Center — an anonymous record is keyed to a number that exists only on your device, so this control is the only thing in the world that can delete one. Deleting it is also the way off the public leaderboard. Exactly what happens:
- Deleted: your rating, your win-loss record, your standing on the ladder, the counters we keep about how you leave matches, and the log of when you searched for a game. That is the record, and it is erased from our database rather than hidden.
- Kept: the matches themselves — who played whom, on which map, and who won. Every rating on our ladder is a running total of the matches that produced it, so erasing your matches would silently rewrite the record of every opponent you ever played, and none of them agreed to that. Those match rows still carry the identifier your device is known by. What they no longer carry is your rating: the numbers written against your seat in each match — what your rating was going in and coming out of it — go with everything else in the Deleted list above. We would rather tell you that plainly than describe a tombstone as an erasure. Nor do they carry what we saw you do in that match. Whether your side dropped, came back, left, or ran out of time to reconnect, and what result you told us at the end, are wiped from your seat and from the server's own moment-by-moment log of that match, because a counter we promised to erase is not erased if it can be added up again from what we kept. What the match itself still says is how it was decided — and when a game ended because a side stopped answering, the record of that decision stays, since it is your opponent's result and not a count of anything about you.
- Gone, but not a ban: what we erase is erased for good — there is no undo and no archive, and we cannot put your old rating back. What deleting does not do is shut you out. If you play rated matches again, a new rating is worked out from those new matches alone and you can appear on the leaderboard again, starting from nothing: no part of the record you deleted comes back with it. Deleting a second time erases whatever has been rebuilt since — the deletion is not a receipt for one moment, it is an act you can repeat.
- One deletion every 30 days: you can do this more than once, and the only limit is time. We refuse a second deletion until 30 days have passed since the last one, and the app tells you the date you can next delete — before you confirm, and again if you ask too soon. The reason is narrow: because nothing carries over a deletion, the one thing it could otherwise be used for is dropping a bad win-loss record after a bad night, and a month's wait makes that not worth doing. We mark the identifier as deleted and keep that mark; it is what the 30 days are counted from.
- Untouched: everything on your device (§2) — the game, your saved games, your replays, your settings and your purchases. This deletes a record on our server, not the app.
If the app cannot reach our server, nothing is deleted and the app says so rather than pretending it worked; try again when you have a connection. You are welcome to email support@playcoldfront.com if it never goes through, but be aware of the limit that made the in-app control necessary: your record is keyed to an identifier we never show you, we hold no display name and no email address against it, and so we usually cannot find your row from an email at all.
- Connection logs (no addresses — see 2d): held by our hosting provider on its own retention cycle, currently about seven days, then deleted automatically. We keep no copy.
- Anonymous usage counts (§3(g)): kept on our own server for as long as they are useful for improving the Game. They identify nobody — there is no identifier in them we could match a deletion request against, and that is by construction, not by policy. Switching SHARE ANONYMOUS USAGE off stops new ones immediately; the ones already counted are just tallies in a crowd.
- Reports you send us by email: kept while we look into them and for as long as we need them to enforce our Terms against a repeat offender — no more than 12 months — then deleted.
- Everything on your device: until you delete it, or delete the app. That includes replays and saved games, which keep a copy of any custom map the match was played on, and the copies of reports you have filed, which in this version go only when the app does.
7. What we declare to the App Store
Apple asks every developer to declare what their app collects. Our declaration for Coldfront is:
- Identifiers — User ID: your display name. Linked to you. Used for app functionality only. Not used for tracking.
- User Content — Gameplay Content: the custom maps you choose to share when you host. Linked to you. Used for app functionality only. Not used for tracking.
- Contact Info — Email Address: only if you email us or send us a report. Linked to you. Used for app functionality and customer support only. Not used for tracking.
- User Content — Other User Content: only if you send us a report. A report carries the reported player's display name, and for a map report the name of the map they shared and the terrain they drew — that is, another person's content, sent to us by you. Linked to you, because it arrives with your email address. Used for app functionality and customer support only. Not used for tracking.
- Diagnostics — Other Diagnostic Data: the connection metadata in §3(d). Not linked to you. Used for app functionality and to diagnose faults. Not used for tracking.
- Identifiers — Gameplay Content / Player ID: your Game Center player id, if you are signed in and play online — sent to the players in your room, and, for rated Quick Match, to us with Apple's signature, where it keys your rating and match record (§3(f), §4). Linked to you. Used for app functionality only. Not used for tracking. (An earlier version of this section said Game Center had nothing to declare, because the check was read-only then; §3(f) is the change, posted here as promised before the build that makes it shipped.)
- Identifiers — Device ID: the Quick Match device key in §2 — random bytes minted by the Game, not a hardware or advertising identifier — sent to us when you use Quick Match without Game Center, stored only in one-way scrambled form, and keying only unrated play. Not linked to you. Used for app functionality only. Not used for tracking.
- Usage Data — Product Interaction: the anonymous usage counts in §3(g) — which features get used and coarse match outcomes, sent to our own server, with an off switch in Settings › Legal. Not linked to you. Used for analytics only. Not used for tracking.
- Location — Coarse Location: the country and the region worked out from the connection when one of those anonymous usage messages reaches our own server (§3(g)). Never read from your phone — the Game holds no location permission and never asks iOS where you are — never a city, never coordinates, and it stops when you turn the switch in Settings › Legal off. Not linked to you. Used for analytics only. Not used for tracking.
- Gameplay Content — match records: the Quick Match ledger in §4 (outcomes, ratings, standing). Linked to the identifier above that played the match. Used for app functionality only. Not used for tracking.
- No tracking. The Game contains no tracking technology, and no data is shared with data brokers or advertisers.
8. Children
Coldfront is not directed at children. Our Terms set a minimum age of 13, or 16 where local law requires — but the Game has no account system and never asks your age, so that minimum is self-declared and we cannot check it. We do not knowingly collect personal information from children under those ages.
If you believe a child is using the Game and has sent us something, email support@playcoldfront.com. In practice there is very little that could exist: a display name held in a server's memory for the length of one match, any report email, and — if that person signed in to Game Center and played rated Quick Match — the ladder row described in §4, which is published on the leaderboard. We will delete whatever we hold and stop processing it; for the ladder row, §6 says what we need in order to find it.
9. Your rights, and what you can do without asking us
Depending on where you live you may have the right to access, correct, delete, restrict or port your personal data, and to object to processing. You can also complain to the data protection authority of the country where you live or work — in the United Kingdom that is the Information Commissioner's Office, ico.org.uk.
Most of it you can do yourself, immediately, without writing to anyone. To stop what online play sends (§3(a)–(f)), stop playing online; to stop the anonymous usage counts, switch off Settings › Legal › SHARE ANONYMOUS USAGE (§3(g)). With those two done, nothing in the Game sends anything anywhere. It is worth knowing before you go looking for that switch that some counting has already happened by the time you reach it: the Game counts each launch as it starts, including the first one on a new install, which is before that screen — or any other — has been drawn. §3(g) sets out what those counts contain and why we will not call the first one consented to. Inside the Game, every saved game, replay and custom map has a DELETE control, and Settings › Blocked Players lets you review and undo any block. Deleting the app removes everything held on your device at once.
To ask us to delete something we hold — in practice, a report you or someone else sent us — email support@playcoldfront.com. We will respond without undue delay and in any event within one month of receiving your request; if the request is complicated we may take up to two further months, and we will tell you inside the first month if that happens.
There is one more thing we hold, and it is the one this section exists for. If you have played a rated Quick Match while signed in to Game Center, the relay keeps a row for you — your rating, your win-loss record and your standing counters, against your verified Game Center id (§4) — and while it qualifies that row is published on the public leaderboard. You can delete it yourself, in the app: Settings › Multiplayer › DELETE MY LADDER RECORD. §6 says exactly what that deletes and what it keeps, and deleting it is the way off the board. Read §6 before you use it, because what it erases cannot be brought back, the match rows are kept, and you can only delete once every 30 days. You do not need to write to us and you do not need to find an identifier — the control uses the identity your device already holds, and it is the only way an anonymous record can be deleted at all. Nothing else about you is kept alongside that row: no account, no password, no email address of yours unless you have written to us, and nothing you do offline.
Your display name and any map you share exist only for the life of a room. Connection logs are held by our hosting provider on its own cycle and age out by themselves; we cannot delete an individual line from them, and since no line contains a display name we could not identify which line was yours in any case.
10. Security
Traffic between your device and the relay we operate is encrypted in transit (TLS, wss://). There are no passwords or credentials to protect, because the Game has none.
The larger risk in online play is social rather than technical, and it is worth knowing exactly how a room works. A room is protected by its five-character code and by nothing else. Anyone holding that code joins straight away — there is no approval step and no invite list — and codes are short enough that one could be guessed. The moment someone joins, they are shown the display names of everyone already in the room, and if you have chosen a custom map they receive that map, its name and the terrain you drew, before the match even starts. Once someone is in, the host cannot remove them: to get rid of an unwanted joiner you leave and host again, which gives you a fresh code.
So treat anything you put in your display name, or draw into a map you host, as visible to whoever ends up in that room — and share codes privately. You can block a player from the report sheet in a lobby, while you are still in the room with them: their name and their map disappear from your screen immediately, nothing they send reaches your game after that, and the match will not start. There is no block control once you have left the room, so block before you go; Settings › Blocked Players lets you review and undo blocks, not add one. And a block only applies from that moment on — a replay your device recorded earlier still holds that player's map and still draws its terrain on playback, so delete the replay to remove it.
11. Changes
We will post changes on this page with a new "Last updated" date. This page is linked from the Game's Settings › Legal screen and opens in your browser, so you can check it whenever you like — and it is worth a look before you play online after an update.
12. Severability, and how this fits with our Terms
If any part of this policy is found to be unenforceable, the rest of it still applies. Where this policy and our Terms of Use say different things about how we handle your data, this policy governs.
13. Contact
support@playcoldfront.com Support page: https://playcoldfront.com/support