Privacy Policy
This Privacy Policy explains how Raging Bucket ("Raging Bucket", "we", "us", or "our") collects, uses, shares, and protects personal information when you play Hearthline (the "Game") or visit hearthline.dev (the "Site"). It also describes the rights available to you under the EU and UK General Data Protection Regulation ("GDPR") and US state privacy laws such as the California Consumer Privacy Act, as amended by the CPRA ("CCPA").
For the purposes of the GDPR, Raging Bucket is the data controller of personal data processed through the Game and Site. You can reach us at developer@ragingbucket.com.
1. Information we collect
We collect the following categories of information:
- Account identifiers. When you first play, the Game creates an anonymous account identified by a unique ID. If you choose to link your account with Google, Apple (Sign in with Apple), or an email link, we receive the identifiers those methods share with us (such as a provider account ID and, where applicable, your email address) so your progress can be recovered and synced.
- Gameplay data. Your settlement's server-authoritative state and activity ledger. This is required for the Game to function and is stored on our servers.
- Device and technical data. Information such as device model, operating system, app version, language, and IP address, processed when your device communicates with our services.
- Usage and analytics data. Event-level data about how the Game is used (for example, which features are opened and how far players progress), collected through Google Analytics for Firebase to help us understand and improve the Game. Some of these events are linked to your account identifier (a random Firebase user ID) so we can measure progression and return over time; we also derive aggregate, non-identifying statistics from them. The Game's web loader uses Google Consent Mode. Before the consent-aware release, analytics storage is defaulted off. In consent-aware releases, requests Google classifies into configured consent-required regions default to denied until you consent; requests classified outside those regions, and requests without a usable classification, default to granted. On the granted path, Google may set first-party analytics cookies and use a durable browser identifier to measure acquisition, users, and sessions. On the classified-region denied path, limited cookieless measurements may still be sent to Google Analytics and included in our BigQuery export, but without analytics cookies or a durable browser identifier. Google's classification can be unavailable, outdated, or inaccurate, so a visitor who is actually in a consent-required region may remain treated as outside it for as long as the classification is unavailable or inaccurate, unless the visitor records a different choice. Pre-sign-in reliability events never include your account identifier, but they carry a random per-page-load correlation identifier that we can join to your signed-in session once you sign in; they are therefore pseudonymous — linkable to you — rather than fully anonymous.
- Advertising data. If you choose to watch an optional rewarded advertisement, our advertising partner (Google AdMob) processes data — which may include advertising identifiers — to serve and verify that ad. Ads are never required to play.
2. How we use information, and our legal bases
We use the information above to:
- operate, maintain, and sync your settlement across your devices;
- provide optional rewarded advertising that you choose to engage with;
- understand usage, fix problems, and improve the Game; and
- protect against fraud, abuse, and security threats.
Where the GDPR applies, we rely on these legal bases: performance of a contract (to run the Game you are playing), our legitimate interests (to secure and improve the Game), your consent (for optional advertising and any non-essential analytics, where required), and compliance with legal obligations. You may withdraw consent at any time.
3. How we share information
We do not sell your personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined under US state privacy laws. We disclose information only to service providers who process it on our behalf, under contract, including:
- Google — Firebase Authentication, Cloud Firestore, Hosting, Google Analytics for Firebase, and BigQuery (cloud infrastructure and analytics);
- Google AdMob — optional rewarded advertising;
- Apple — Sign in with Apple, where you choose to use it;
- Linear — when you send in-app feedback, your feedback message, technical and gameplay context (such as your settlement's scale, resource counts, app version, platform, and browser user-agent), and a stable pseudonymous identifier derived from your account ID by a one-way hash (not your raw account ID) are processed to create and track a support/issue ticket;
- Apple App Store and Google Play — app distribution and, if offered, payments.
We may also disclose information where required by law, or to protect the rights, safety, and property of Raging Bucket, our players, or the public.
4. International data transfers
Our service providers may process your information in the United States and other countries. Where we transfer personal data out of the EEA or the UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.
5. Data retention
We keep your account and gameplay data for as long as your account exists. Raw, account-linked analytics event records that we export to BigQuery are retained for up to 90 days, after which they are deleted. Event data held within Google Analytics itself is retained for the period configured in Google Analytics' data-retention settings. Aggregate, non-identifying statistics derived from those events — figures that cannot be traced back to you — may be kept indefinitely.
When you delete your account, we delete or irreversibly anonymise the personal data we hold about you, except where we are required to retain it by law. Two things can survive account deletion: some device-local settings may remain on your own device (see §9); and any in-app feedback you have submitted stays in our support/issue tracker (Linear), where it is keyed by a pseudonymous hash rather than your account ID and is not automatically removed. You can ask us to delete submitted feedback by emailing us at the address below.
When the consent-aware release records an analytics choice, the choice, its recorded time, and this policy version are stored with your account so the choice follows you across devices. That record is deleted with your account; we do not keep a separate proof-of-consent copy after deletion.
6. Your rights
You can delete your account and associated data at any time from within the Game. If you linked your account to a sign-in method, you can also request deletion by emailing developer@ragingbucket.com from the linked address. See Delete your account for the full steps.
EU/UK (GDPR). You have the right to access, rectify, erase, restrict, and port your personal data, to object to certain processing, and to withdraw consent. Once the consent-aware release is available, you can change your analytics choice at any time using the Analytics control in the Game's profile menu. You also have the right to lodge a complaint with your local data protection supervisory authority.
United States (including California). Subject to your state's law, you have the right to know what personal information we collect and how we use it, to request deletion or correction, and to opt out of any "sale" or "sharing" of personal information (we do not sell or share). We will not discriminate against you for exercising these rights.
To exercise any right, contact us using the email above. We will verify your request through your account and respond within the time required by applicable law.
7. Children's privacy
Hearthline is not directed to children under 13 (or the minimum age required by your local law, such as 16 in parts of the EEA), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
8. Security
We use industry-standard measures to protect your information, including authentication and access controls on our servers. No method of transmission or storage is completely secure, but we work to protect your data and to address issues promptly.
9. Cookies and local storage
The Site uses only what is necessary to serve the pages and does not use advertising
or cross-site tracking cookies. The Site applies the same geo-aware analytics consent
model as the Game: requests Google classifies into a configured consent-required region
default to denied and set no analytics cookies, while requests classified outside those
regions and requests without a usable classification default to granted and may set
first-party Google Analytics cookies such as _ga and _ga_*.
The Site itself has no consent prompt, so a request classified into a consent-required
region stays on the cookieless path for the whole visit. The Site may record which
campaign or link brought you to it (for example, a referral label) to understand where
players come from, in aggregate.
In consent-aware Game releases, requests that Google classifies outside the configured
consent-required regions, requests without a usable classification, and requests made
after you consent default to granted. Google Analytics may then set first-party cookies
such as _ga and _ga_* to recognise a browser across visits
and build users, sessions, and acquisition reports. If Google classifies the request
into a configured consent-required region and you have not consented, those cookies are
not set; limited cookieless measurements may still be sent without a durable browser
identifier. Classification can be unavailable, outdated, or inaccurate, so a visitor
who is actually in a consent-required region may continue to receive analytics cookies
for as long as the classification is unavailable or inaccurate, unless they record a
different choice. Withdrawing consent will stop analytics storage and clear the Game's
Google Analytics cookies from that browser.
The Game stores data locally on your device so it can function and remember your progress and preferences (for example, sound and onboarding settings). Some of these local settings are keyed to your account identifier (a random Firebase user ID) and can persist on your own device after you delete your account or sign out. They hold only these device-local preferences — no gameplay, contact, or payment data — but because the key includes that identifier, you can clear them by removing the app's local data or the app itself.
On web, the consent-aware release will also mirror your last explicit analytics choice in browser local storage so it can honour that choice before the Game finishes loading. The account record remains the cross-device authority. The local mirror can remain after sign-out or account deletion until you change the choice, clear browser data, or remove the site's stored data.
10. Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, notify you in the Game.
11. Contact us
Questions or requests about this policy or your data? Email developer@ragingbucket.com.