Privacy Policy

Effective 6 September 2026 · Last updated 7 September 2026 · Bespoque Solutions E.E.

1. Introduction

1.1 This Privacy Policy (the "Policy") explains how Bespoque Solutions E.E. ("we", "us", "our") collects, uses, stores, shares and protects personal data when you play the mobile game GodSmith (the "Game"), use its online features, or visit this website (together, the "Services"). It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), Greek Law 4624/2019, and the other laws named in Article 14.

1.2 "You" means any person who installs or plays the Game or uses the Services. "Personal data" means any information relating to an identified or identifiable person, as defined in the GDPR.

1.3 We built the Game to collect as little as it can. Playing needs no registration, no email, no phone number, no real name. This Policy tells you exactly what remains: when we collect data (Article 2), which data (Article 3), why and on what legal basis (Article 5), who processes it for us (Article 6), how long we keep it (Article 10), what rights you have (Articles 7, 8 and 13) and how to reach us (Article 16).

1.4 This Policy applies together with the Terms of Service. Where a specific feature needs different handling, the Game tells you at the point of use.

  1. 1. Introduction
  2. 2. When we collect personal data
  3. 3. Categories of data we collect
  4. 4. Cookies and similar technologies
  5. 5. How we use personal data and on what basis
  6. 6. How we share, transfer and disclose personal data
  7. 7. Withdrawing consent and deleting your data
  8. 8. Access, correction and portability
  9. 9. Protection of personal data
  10. 10. Retention of personal data
  11. 11. Accuracy of personal data
  12. 12. Children
  13. 13. Your rights under the GDPR
  14. 14. Regional supplements
  15. 15. International transfers
  16. 16. Changes, governing law and contact

2. When we collect personal data

2.1 We collect personal data only in the situations below, and only the data described in Article 3 for each of them:

2.2 We do not buy personal data, we do not enrich your profile from third parties, and we do not import data from social networks. The Game has no chat, no surveys, no newsletters and no advertising.

3. Categories of data we collect

3.1 The full inventory. Nothing outside this table is collected by the Game.

CategoryWhat exactlySource
Account identifier A device identifier (on Android, the Android ID assigned to the Game by the operating system; where the operating system provides none, a random identifier the Game creates on first launch) and the player ID our backend assigns to your account. Your device / generated by us
Recovery link (optional) An email address, only if you choose to link one. There is no password: each time you link or recover, we send a six-digit code to that address and you type it into the Game. The code is stored, hashed, for ten minutes and then discarded. Alternatively, the identifier of your Google Play Games profile (Android) or Game Center profile (iOS), and the display name it carries, if you choose to sign in with one; we receive no contacts, no friends list and no access to your Google or Apple account. You; Google Play Games / Apple Game Center
Profile The display name you choose (filtered against a list of offensive terms), the portrait and showcase items you pick, and your Realm (a cohort of players assigned at account creation). You / generated by us
Game progress Realms conquered and stars earned, spells, units, buildings and passives owned and their copies and stages, currencies (Gold, Silver, Crystals, essence, Siege Marks, Arena Laurels, draw tickets), wishlist and pity counters, VIP points and claimed packs, daily-quest progress, letters read and claimed, gift codes redeemed, settings. Generated by your play
Purchase data The product bought, the store's purchase token or receipt and its signature, the currency and price reported by the store, and the date. We never receive your card number, bank details or billing address: Google Play or Apple handle payment entirely. Google Play / Apple App Store
Ranked-mode telemetry For Siege runs: waves reached, kills, score components and timings, sent at each wave. For the Arena: the match token, the result you report, your and your opponent's power values, and the rating changes. These are checked on our servers against what is physically possible in a match. Generated by your play
Matchmaking data Your hidden matchmaking rating and player ID, placed in a queue ticket so an opponent of similar strength can be found; visible ratings and ladder positions appear on leaderboards. Generated by us
Gameplay and diagnostic events Events such as session start, screen changes, tutorial steps, matches started and ended with their result and duration, draws, claims, purchases and store offers shown, quest claims, mail opened, gift codes tried, account deletion. Each carries the app version, the seconds since launch and the current screen. Once per session on phones: the graphics chip model, memory size, processor core count and the performance tier the Game chose from them. Generated by your play / your device
Support correspondence What you write to us, your email address, and the player ID you give us so we can find your account. You
Website access logs Our hosting provider, Cloudflare, keeps standard server logs (IP address, time, page requested, browser type) for security and to serve the site. We do not read them for any other purpose. Your browser

3.2 What we do not collect: your real name (unless you put it in your display name, which we advise against), your precise or coarse location beyond what the store reports for pricing, your contacts, photos or files, your advertising identifier, your phone number, biometric data, or any special category of data under GDPR Article 9.

3.3 Local data. Your progress is also stored on your own device, sealed against tampering, so you can play offline. That copy stays on your device and is removed when you delete the account or uninstall the Game.

4. Cookies and similar technologies

4.1 This website sets no cookies and loads no third-party scripts, fonts, or trackers, which is why it shows no cookie banner.

4.2 The Game uses no cookies. It stores an installation identifier and your sealed progress in the Game's private storage on your device, which the operating system removes when you uninstall.

5. How we use personal data and on what basis

5.1 Under the GDPR we may process personal data only on a legal basis listed in Article 6. Here is each purpose with its basis:

PurposeData usedLegal basis
Creating and recognising your account so you can play without registeringAccount identifier Performance of a contract, Art. 6(1)(b)
Saving your progress and restoring it on the same or another deviceGame progress, profile, account identifier Art. 6(1)(b)
Recovering your account on a new device, and sending the one-time code that proves the email is yoursRecovery link Consent, Art. 6(1)(a); withdrawable by unlinking or by deleting the account (Article 7)
Showing you and other players on leaderboards, in matchmaking and on namecardsProfile, ratings, ladder scores Art. 6(1)(b)
Verifying a purchase before granting it, preventing double grants and fraud, restoring an interrupted purchasePurchase data Art. 6(1)(b) and legitimate interest in preventing fraud, Art. 6(1)(f)
Keeping the ranked ladders honest: rejecting impossible results, suspending cheating accountsRanked-mode telemetry, matchmaking data, gameplay events Legitimate interest of us and of every honest player, Art. 6(1)(f)
Understanding how the Game is played so we can fix what confuses people and balance the economyGameplay events, in aggregate Legitimate interest, Art. 6(1)(f); you may object (Article 13)
Choosing graphics settings your phone can sustainDevice capability Art. 6(1)(b)
Delivering letters, gift codes and daily-quest rewards to your accountGame progress Art. 6(1)(b)
Answering your support requests and rights requestsSupport correspondence Art. 6(1)(b) and legal obligation, Art. 6(1)(c)
Complying with tax, accounting and consumer law, and responding to lawful requests from authoritiesPurchase data Legal obligation, Art. 6(1)(c)
Securing the Services and this websiteWebsite access logs, security-related events Legitimate interest, Art. 6(1)(f)

5.2 We do not use personal data for advertising, for profiling that produces legal or similarly significant effects, or for any automated decision of that kind. Offers shown inside the Game are chosen from your progress (for example, after a defeat or on reaching a milestone) by fixed rules; they are not built from a behavioural profile and they do not affect your legal position.

5.3 We do not sell personal data and we do not send marketing communications. The only messages you receive are letters inside the Game's mailbox, which you read at your convenience.

6. How we share, transfer and disclose personal data

6.1 Processors acting on our instructions

ProcessorWhat they doWhere
Microsoft PlayFab (Microsoft Corporation, One Microsoft Way, Redmond, WA, USA) Hosts player accounts, recovery credentials, game progress, leaderboards, matchmaking, the in-game mailbox and gift codes, and the gameplay and diagnostic events. Runs the server logic that grants purchases and verifies ranked results. Microsoft Azure data centres; see Article 15
Google Play (Google LLC / Google Ireland Ltd for EEA users) Processes payments and app distribution on Android; provides us with the purchase token and receipt we verify.Global; Google's own policy applies to the payment
Apple App Store (Apple Inc. / Apple Distribution International Ltd for EEA users) Processes payments and app distribution on iOS; provides us with the receipt we verify. Global; Apple's own policy applies to the payment
Twilio SendGrid (Twilio Inc., San Francisco, USA) Delivers the one-time code emails when you link or recover by email. Receives your address and the code; nothing else.USA; see Article 15
Google Play Games Services (Google LLC / Google Ireland Ltd for EEA users) If you sign in with Play Games, Google authenticates you and gives us your Play Games player identifier and display name. Google's own privacy policy applies to the sign-in.Global
Apple Game Center (Apple Inc.) If you sign in with Game Center, Apple authenticates you and gives us your Game Center player identifier and display name. Apple's own privacy policy applies to the sign-in.Global
Cloudflare, Inc. (San Francisco, USA) Hosts this website and routes email to our support address.Global edge network; see Article 15

Each processor is bound by a data processing agreement under GDPR Article 28 and may use the data only for the purpose we set. We have no other processors and no "partners" who receive personal data.

6.2 Other players

Your display name, portrait, showcase, Realm, Arena rating and tier, and your ladder scores and positions are visible to other players on leaderboards, in the Arena and on your namecard. That is the whole of what other players can see. Your player ID is shown on your own namecard so you can quote it to us.

6.3 Disclosure required by law

We disclose personal data to courts, authorities or law enforcement only when a law, a court order or a binding request obliges us to, and only what is required.

6.4 Business transfers

If Bespoque Solutions E.E. transfers the Game to another company (for example, on a sale of the business or its transfer to a new company set up to publish it), your data may be transferred with it. The recipient will be bound by this Policy, and the Game will tell you at the next launch.

6.5 Anonymised and aggregated data

Data from which you can no longer be identified (for example, how many players reached a level, or the average length of a Siege) is not personal data and we may use and publish it freely.

7. Withdrawing consent and deleting your data

7.1 Where we rely on your consent (the optional email, Play Games or Game Center link), you may withdraw it at any time by deleting your account, or by writing to us (Article 16) to remove the link. Withdrawal does not affect processing that took place before it.

7.2 You may delete your account yourself, at any time, inside the Game: Settings → Delete account → ERASE EVERYTHING. The account is deleted from our servers first; only then does the Game wipe your device and restart as a new player. Deletion covers every category in Article 3 that is tied to your account: progress, purchases, letters, quests, leaderboard entries, matchmaking data, ratings and any linked email. Purchased virtual items are deleted with the account and cannot be restored.

7.3 If you no longer have the Game installed, email us (Article 16) with the subject "GodSmith account deletion" and your player ID, or write from the linked email address. We delete the account within 30 days and confirm by reply. Full instructions are at godsmithgame.com/account-deletion.

7.4 Deletion is immediate in the live service. Copies in server backups are overwritten within 30 days. Purchase records that tax and accounting law oblige us to keep (Article 10) are kept only in a form that no longer identifies you.

8. Access, correction and portability

8.1 You may ask us for a copy of the personal data we hold about you, for a correction of anything inaccurate, or for your data in a machine-readable format (JSON) for transfer elsewhere. Write to us (Article 16) with your player ID or from the linked email address so we can verify that the account is yours.

8.2 Your display name, portrait and showcase you can correct yourself in the Game's namecard. Your linked email you can change by linking a new address, which replaces the old one.

8.3 We answer within one month. If a request is complex we may take up to two further months and will tell you why. Requests are free; only where a request is manifestly unfounded or excessive may we charge a reasonable fee or refuse it, and we will say so.

9. Protection of personal data

9.1 We apply measures appropriate to the risk, including: anonymous-by-default accounts; encryption of all traffic between the Game, this website and our servers (TLS); one-time codes stored only in hashed form by our backend provider; server-side verification of every purchase and of ranked results, so that no client can grant itself items or scores; the local save on your device sealed with a message authentication code so tampering is detected and discarded; access to production systems restricted to named people with multi-factor authentication; secret keys kept out of the source code and out of the client; and processors chosen for their own certified security programmes (Microsoft Azure, Cloudflare).

9.2 No method of transmission or storage is perfectly secure. If a breach affecting your data occurs, we will notify the competent supervisory authority within 72 hours where the GDPR requires it and will inform you directly where the breach is likely to result in a high risk to you.

10. Retention of personal data

DataKept for
Account identifier, profile, game progress, recovery credentials, letters, quests, ratings As long as your account exists. Deleted on account deletion (Article 7).
Purchase data tied to your account As long as your account exists; afterwards only in anonymised, aggregate form for the period Greek tax and accounting law requires (currently five years from the end of the financial year).
Ranked-mode telemetry and matchmaking tickets Match tokens and tickets expire within hours; per-run telemetry is kept while the daily ladder it belongs to is live and for a further 30 days for dispute handling, then aggregated.
Gameplay and diagnostic events Retained in identifiable form by our backend provider for 90 days, then only in aggregate.
Support correspondence Two years after the case is closed, to handle follow-ups and disputes.
Website access logs Kept by Cloudflare for its standard short period (days) for security purposes.
Inactive accounts An account not used for 24 months may be deleted after we have attempted to notify you through the in-game mailbox, since it is the only channel we have unless an email is linked.

11. Accuracy of personal data

Nearly everything we hold is generated by your play and is accurate by construction. What you enter yourself (display name, linked email) you can correct in the Game or by writing to us. Please keep a linked email current, because it is the only way to recover an account whose device is lost.

12. Children

12.1 The Game is not directed at children. You must be at least 16 years old to play, or have the consent of a parent or guardian, which is the age of digital consent under GDPR Article 8 as applied in Greece (15) and in most of the European Union.

12.2 We do not knowingly collect personal data from anyone under 16. Because the Game does not ask for a date of birth, we rely on the store's age rating and on parents. If you believe a child under 16 has an account without consent, write to us (Article 16) and we will delete it.

12.3 Parents and guardians: the Game contains optional purchases. Both Google Play and Apple offer purchase approval and parental controls, and we recommend enabling them on a child's device.

13. Your rights under the GDPR

13.1 If you are in the European Economic Area, and wherever else the GDPR applies to you, you have the following rights:

13.2 To exercise a right, use the Game where it offers the action (deletion, name change) or write to us (Article 16). We may ask for your player ID or a reply from the linked email address to confirm the account is yours. We respond within one month (Article 8.3). Exercising your rights is free.

13.3 Digital Markets Act. We do not share personal data with any "gatekeeper" platform for advertising or service personalisation, and the Game shows no consent banner because it needs none.

14. Regional supplements

14.1 United Kingdom

For players in the UK, the references to the GDPR in this Policy include the UK GDPR and the Data Protection Act 2018. The rights in Article 13 apply in the same way. Complaints may be made to the Information Commissioner's Office, ico.org.uk. Transfers from the UK rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.

14.2 California and other US states

For residents of California (CCPA/CPRA) and of other states with comparable laws: in the past twelve months we have collected the categories in Article 3 — identifiers, commercial information (purchases), internet activity (gameplay events), and device information — for the purposes in Article 5. We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the past twelve months; there is therefore nothing to opt out of, and we do not use the "sensitive personal information" categories. You have the right to know, to delete, to correct, to portability, and not to be discriminated against for exercising these rights. An authorised agent may act for you with written permission. Requests: Article 16.

14.3 Brazil

For players in Brazil, this Policy serves as the notice required by the Lei Geral de Proteção de Dados (LGPD). The legal bases in Article 5 correspond to LGPD Article 7 (contract, consent, legitimate interest, legal obligation). You have the rights in LGPD Article 18, exercisable as in Article 13. International transfers rely on standard contractual clauses recognised by the ANPD.

14.4 Other countries

Where local law grants you further rights or requires further notices, we honour them on request. Write to us (Article 16).

15. International transfers

15.1 We are established in Greece, in the European Union. Our backend provider, Microsoft PlayFab, stores the Game's data in Microsoft Azure data centres; the title's data may be held in the United States. Cloudflare serves this website from its global network.

15.2 Every transfer of personal data outside the European Economic Area is protected as the GDPR requires: by the European Commission's adequacy decision for the EU–US Data Privacy Framework where the recipient is certified under it (Microsoft and Cloudflare are), and in every case by the EU Standard Contractual Clauses incorporated in our processors' data protection terms, together with the supplementary measures (encryption in transit and at rest, access controls) described in Article 9.

15.3 You may ask us (Article 16) for more information about the safeguards for a particular transfer.

16. Changes, governing law and contact

16.1 We may update this Policy when the Game or the law changes. Changes that matter are announced inside the Game at the next launch and by a new "last updated" date at the top of this page. Continuing to play after the change means the new version applies; if you disagree with it, you may delete your account (Article 7).

16.2 This Policy is governed by Greek law and the GDPR. Nothing in it removes the protection of the mandatory data-protection law of the country where you live.

16.3 Contact for anything in this Policy, including rights requests and complaints:

Bespoque Solutions E.E.
Aristotelous 11-15, 10432 Athens, Greece
Email: contact@bespoquesolutions.com
Subject line for rights requests: "GodSmith privacy request"

16.4 We have not appointed a Data Protection Officer, as the GDPR does not require one for processing of this scale and nature; the address above reaches the person responsible for data protection directly.

Home · Terms of service · Account deletion