01 Legal

Privacy
Policy

Altare is a mobile game studio. This policy explains what our games, our website and Altare Panel — the live-ops service we run for our own titles and offer to other studios — collect about you, why we collect it, who we share it with, and how you can have it exported or erased.

Last updated 13 September 2026 Controller Altare, İstanbul Applies to KVKK · GDPR

01Scope

This policy covers three different things we operate:

  • Our games — the mobile titles Altare publishes on Google Play, including ChopHero: Relic Quest.
  • This website — altarestudio.com.tr and its pages.
  • Altare Panel — our live-ops and analytics service. We use it on our own games, and we also offer it to other studios. When another studio uses the Panel on their game, that studio is the controller of their players' data and we act as their processor; this policy then describes what we do on their instruction.

Where a specific game or storefront listing publishes its own privacy notice, that notice applies to that product in addition to this one.

02Who is responsible

The controller is Altare, a mobile game studio based in İstanbul, Türkiye. For any privacy request, write to berkantdogrusoz@gmail.com. We answer within 30 days, which is the deadline set by Turkish data protection law (KVKK).

03What we collect

In our games

  • Gameplay and progression — levels started and completed, in-game actions, item and booster usage, win and loss states, session length, progression milestones.
  • Device and technical data — device model, GPU model, memory class, operating system, app version, language, country or region, crash and performance diagnostics.
  • Advertising and purchase data — ad impressions and rewarded-ad engagement, purchase and refund state, and the transaction metadata the storefront returns to us. In ad-supported games, Google AdMob additionally processes your device's advertising identifier; see section 04.
  • Consent state — whether you accepted, refused or later changed your choice about analytics and personalised advertising.

Through Altare Panel

Our own SDK sends the following fields, and nothing else. This list is the complete payload as it exists in the SDK source:

Field What it is
playerAnonId A random identifier the app generates on the device on first launch and stores locally. It is not your advertising ID and is not derived from anything about you. Clearing the app's data produces a new one.
sessionId Groups events belonging to one play session.
platform, appVersion Which platform and build the event came from.
deviceModel, gpuModel, totalMemoryMb Coarse hardware class, used to separate performance problems from design problems.
eventName, clientTimestamp, eventParams What happened in the game, when, and its parameters (for example a level number).
Player state snapshot A copy of progression state, kept so progress can be restored after a bug or a bad update.
Experiment assignment Which A/B variant the device was assigned. It is computed from playerAnonId by a hash, so it is stable without storing anything extra about you.

What the Altare Panel SDK does not collect: no name, no e-mail address, no phone number, no precise location, no advertising identifier (GAID / IDFA), no contacts, no photos, no microphone or camera access.

On this website

You do not need an account to browse this site and we do not run advertising trackers on it. Our hosting and content-delivery providers process the technical request data any web server receives — IP address, user agent, requested page, timestamp — in order to serve the page and to protect against abuse.

Altare Panel accounts (studios, not players)

If you sign in to the Panel as a studio, we process your e-mail address and authentication credentials, your studio and game names, and an audit record of administrative actions — who changed which setting, exported or deleted player data, started or stopped an experiment, and when. Those audit records are append-only: they exist so that privileged actions can be reviewed later, and they are not editable from the Panel.

04Advertising

Our games are free and funded by advertising and optional in-app purchases. Where a game shows ads, we use Google AdMob. AdMob operates inside the game and processes device and ad-interaction data — including your device's advertising identifier — under Google's own privacy policy, in order to select, deliver, cap and measure ads and to detect invalid traffic.

In Türkiye, the EEA, the UK and other regions where the law requires it, we ask for your consent before personalised advertising is enabled, using the Google User Messaging Platform (UMP) consent screen. If you refuse, ads still appear but are non-personalised — they are selected without an advertising profile. You can change this choice later from the game's privacy settings, and you can reset or delete your advertising identifier from your device settings at any time.

Advertising data is handled separately from Altare Panel data: as described above, the Panel SDK never receives your advertising identifier.

05Why we process it

  • To run, maintain and secure the games, the website and the Panel.
  • To understand retention, level difficulty, drop-off points and monetisation, so that we can fix what is not working.
  • To run A/B experiments and to measure whether an automatic change actually improved the game rather than assuming it did.
  • To detect crashes, anomalies, cheating, invalid traffic and payment fraud.
  • To deliver and measure advertising, and to handle purchases and refunds.
  • To answer support and business messages.
  • To comply with legal, tax and accounting obligations.

Under KVKK art. 5 and GDPR art. 6 we rely on:

  • Consent — personalised advertising, and optional analytics where local law requires consent for it.
  • Performance of a contract — providing the game or the Panel service you asked for, including purchases and progress restoration.
  • Legitimate interest — security, fraud and cheat prevention, crash diagnostics, and product improvement using pseudonymous data.
  • Legal obligation — tax, accounting and lawful requests from authorities.

07Who else processes it

We do not sell personal data. We use these providers to operate the service:

  • Google Firebase (Authentication, Firestore, Cloud Functions) — the backend that stores and processes Altare Panel data.
  • Google Play — app distribution, billing, purchase validation and refunds.
  • Google AdMob and the Google User Messaging Platform — ad delivery, ad measurement, invalid-traffic detection and the consent screen in ad-supported games.
  • GitHub Pages and Cloudflare — static hosting, DNS and content delivery for this website.
  • AI model providers — the Panel's assistant features send aggregate, pseudonymous metrics (for example a funnel's conversion rates) to generate a written analysis. Raw event records and Panel account credentials are not sent.

We may also disclose data where the law requires it, to protect our rights or our users, or in connection with a merger, acquisition, financing or transfer of assets.

08How long we keep it

Event and progression data is kept for as long as the game is operated, because retention and funnel analysis are inherently historical. Player state snapshots are kept until the player's data is erased or the game is shut down. Audit records are kept for the lifetime of the Panel account, since their purpose is accountability. Purchase and invoicing records are kept for the period tax law requires.

When a game is deleted from the Panel, its entire data tree — events, player records, snapshots, experiments and funnels — is deleted with it.

09International transfers

Our providers — principally Google — process data on servers outside Türkiye. Those transfers rely on the safeguards available under KVKK art. 9 and Chapter V of the GDPR, including the providers' standard contractual clauses.

10Children

Our games are not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided personal data to us, contact us and we will review and erase it.

11Your rights

Under KVKK art. 11 and GDPR art. 15–22 you may ask whether we process data about you, request a copy of it, have it corrected or erased, object to processing, ask for it to be restricted or ported, and withdraw a consent you previously gave.

These are not only written commitments. The Panel has a built-in erasure and export path, so a request can be executed rather than filed:

  • Export returns your event history, your player record and your saved progression snapshots.
  • Erasure deletes your events, your player record and your snapshots from the game's data — from both stores we keep them in, the operational database and the analytics warehouse. If either deletion fails, the request is reported as failed rather than reported as done.

One honest limit. Erasure does not recompute aggregate statistics that were already calculated — daily totals, retention curves and funnel conversion rates. Those are counts, they contain no identifier, and a single player cannot be recovered from them. We would rather state this plainly than claim an erasure is more complete than it is.

To exercise a right, write to berkantdogrusoz@gmail.com. Because we do not collect your name or e-mail inside the games, we may need you to provide the in-game player identifier so we can find the right records. You also have the right to complain to your local supervisory authority — in Türkiye, the Personal Data Protection Authority (KVKK).

12Changes and contact

We may update this policy. When we do, we change the “last updated” date above, and where the change is significant we give notice in the product as well.

Questions, complaints and data requests: berkantdogrusoz@gmail.com.