Summary
Hopstone is an independent studio making mobile apps and casual games. This page is the studio-wide policy. Where a product publishes its own privacy policy, that policy governs the product and takes precedence over this one.
Product-specific policies: Bubble Splash. What a product collects depends on what it does. Some can be used entirely as a guest, with everything you save kept on your device; others offer an optional account so progress syncs across devices, and in-app purchases. This page describes the outer limits of what any Hopstone product does with data.
Information We Collect
Stored on your device
- Whatever the product needs to work: your notes, saved items, scores, level or progress.
- In-app balances such as coins or lives, and any achievements unlocked.
- Preferences such as sound on or off, and any randomly generated guest name.
Collected only if you create an account
Accounts are optional and only some products offer them. Where one does, we collect:
- Your email address, received from Google when you sign in with Google Sign-In. We never see or store a password.
- The display name on your Google account.
- An approximate country, derived from the IP address of your request when you sign in, so a product can place you on a country leaderboard. We do not use device location and we do not ask for location permission. We store only a two-letter country code: never your IP address, and never a precise location.
Account data also carries the same game data listed above, so your progress follows the account across devices. Used as a guest, none of this is collected.
Processed by third parties
- Your device's advertising identifier and technical device data, used by Google AdMob to serve and measure ads.
- Purchase receipts, so a purchase can be validated and what you bought can be granted. Payment itself is handled by the app store, so we never see your card details.
- Standard technical information such as device type, operating-system version, app version, coarse region and crash diagnostics, which our providers need to deliver and troubleshoot their services.
- A crash report, sent to Firebase Crashlytics when a product crashes or hits a serious error. It contains a stack trace, the device model and operating-system version, the app version, device state at the time, and a random installation identifier that is not tied to your account. Crash reporting runs whether or not you have an account, and a report carries no profile or game data.
- In-app events, sent to Firebase Analytics: which screens you open and in what order, what you do in the product such as a round or level played, how long a session lasts, the app version, the device model and operating-system version, and your country or region. This is tied to a pseudonymous app instance identifier rather than to your name or email address, it is used only to see how a product is used so it can be improved, and it identifies nobody.
Public information
Where a product has leaderboards, the display name you choose and its tag, your country, and your scores are shown to other players. Your email address is never shown to other players.
Reports and blocks
Where a product lets you report or block another player, we store the accounts involved and the reason selected so we can review it. Blocking is private: the blocked player is not notified.
How We Use Information
- To provide and operate the product and its features.
- To create and manage an account, and sync progress across devices, where a product offers one.
- To process and validate in-app purchases and grant what was bought.
- To display advertising, including optional rewarded ads.
- To maintain security, prevent fraud and abuse, and fix bugs.
- To detect, diagnose and fix crashes and stability problems.
- To understand how a product is used, in aggregate, so we can improve it.
- To comply with legal obligations.
Third-Party Services
Each product names the exact services it uses in its own policy. Across the studio these are the providers we rely on, each processing data under its own privacy policy.
- Google AdMob, advertising. Privacy policy: policies.google.com/privacy
- Google Play and the Apple App Store, distribution and payment processing for all in-app purchases. Privacy policy: policies.google.com/privacy and apple.com/legal/privacy
- RevenueCat, purchase validation and management. Privacy policy: revenuecat.com/privacy
- Firebase Crashlytics, crash and stability reporting (Google). Privacy policy: policies.google.com/privacy
- Firebase Analytics, screen-view and app-usage analytics (Google). Privacy policy: policies.google.com/privacy
- Supabase, account authentication and data storage for products that offer accounts. Privacy policy: supabase.com/privacy
Advertising Choices
Most Hopstone products are free and funded by ads served through Google AdMob. To do that, AdMob may access your device's advertising identifier (the Android Advertising ID or Apple's IDFA), IP address, coarse device and network information, and whether an ad was shown or interacted with. Ads may be personalised on that basis, and you can turn personalisation off or reset the identifier at any time. The product keeps working, the ads are just less tailored. Where the law requires it we ask for consent first, and you can change that answer later.
Consent
Where a product serves ads or records analytics and you are in the European Economic Area, the United Kingdom or Switzerland, we ask for your consent before any advertising or analytics identifier is stored on your device. The request uses Google's consent form, shown inside the product, and nothing is stored until you answer it.
You can change your answer at any time from the product's own privacy options, under Profile › Account where the product has an account area.
Data Retention
Data stored on your device stays there until you clear the app's data or uninstall it. Without an account it cannot be restored afterwards. Account data is kept for as long as the account is active. Purchase records are kept as long as financial and legal record-keeping requires. Data held by AdMob and the app stores is retained under their own policies, and Firebase Crashlytics keeps a crash report for 90 days from the date it is received. In Firebase Analytics, event data is retained for 14 months and user data is retained for 14 months, after which both are deleted automatically by Google.
Your Rights & Choices
- Use a product as a guest, where it offers a guest mode, and provide nothing personal at all.
- View and edit your profile in-app if you have an account.
- Delete your account and its server-side data yourself, or ask us to do it, and have a leaderboard entry removed with it. See "Deleting your account" below.
- Turn off ad personalisation, or reset your advertising ID, in your device settings.
- Depending on where you live, you may also have rights of access, correction, deletion or objection under laws such as the GDPR or CCPA. Contact us and we will honour them.
Deleting your account
Where a product offers accounts, you can delete yours from inside the app, at Profile › Account › Delete account. The app asks you to confirm, and then permanently removes the account.
You can also request deletion by email, writing to the address at the foot of this page from the address the account was created with, so we can be sure the request comes from the account holder.
What is deleted
Your sign-in credentials, your display name and country, the progress held against the account such as level, score and any in-app balances, and your entry on any leaderboard. Data the product stored on your device is removed at the same time.
What is kept, and why
Records of purchases are kept to meet tax and accounting obligations. The account identifier is stripped from them, so they are no longer linked to you. Crash reports are not linked to your account and cannot be deleted individually.
Children's Privacy
Hopstone products are intended for a general audience and are not directed at children under 13, or the equivalent minimum age in your country. We do not knowingly collect personal information from children. Where a user is identified as a child, ad requests are marked so that only non-personalised, child-appropriate ads are served, in line with COPPA and Google Play's Families policy. If you are a parent or guardian and believe a child has provided personal information, contact us and it will be deleted promptly.
Data Security
We and our providers use industry-standard safeguards, including encrypted transport and access controls. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
International Transfers
Our service providers may process and store data on servers located in countries other than yours. Where required, such transfers are carried out with appropriate safeguards.
Changes to This Policy
We may update this policy from time to time. The date at the top always reflects the current version, and material changes are also noted in the store release notes.
Contact Us
Questions about this policy, or about anything a Hopstone product does with data:
Hopstone is an independent one-person studio. There is no support call centre, just an inbox that gets read.