Skip to content
DELTA-V

PRIVACY POLICY

LAST UPDATED 2026-08-26

Privacy Policy

This policy covers two things at once: the Delta-V website at deltav-flame.vercel.app and the Delta-V Android app, package com.wyatt.deltav. The website collects nothing about you beyond ordinary server logs, unless you hand it your email address for the mailing list or buy something, in which case Shopify handles the order. The app collects an account identifier, your cloud-saved game progress, purchase records, crash reports, usage analytics and an advertising identifier — each of them described below, with the company that processes it named. Nothing is sold. Last updated 26 August 2026.

AT A GLANCE

SUMMARY
APPLIES TOWebsite and Android app
APP PACKAGEcom.wyatt.deltav
EFFECTIVE2026-08-26
DATA SOLDNo
CONTACTTODO_CONTACT_EMAIL

The summary is a courtesy. The sections below are the policy.

Scope of this policy

One document, two products. Google Play requires that the privacy policy URL attached to an app listing actually describe that app, so this page describes the Delta-V Android app as well as this website. Where a section applies to only one of them, it says so in the heading or the first line.

“We” means the independent developer who publishes Delta-V and operates this site, acting as the data controller for both. Delta-V is not affiliated with, endorsed by, or operated by NASA, SpaceX, ESA, or any other agency or launch operator whose public data appears on this site.

This policy does not cover third-party websites you reach from links here. Once you leave, that operator’s policy governs, not this one.

What the website collects

Server logs

Every request to a web server produces a log line, and this site is no exception. Vercel, the host, records your IP address, the page requested, the time, the referring page, and your browser’s user agent string. Those logs exist to keep the site up and to investigate abuse, errors and traffic spikes. They are held for a short period by the host and then discarded. They are not used to build a profile of you, and they are not combined with anything else on this page.

The mailing list

If — and only if — you submit the signup form, we store the email address you typed and send it through Resend, which delivers the message. The address is used for dispatches about the game and the site. It is not sold, and it is not used to advertise anything that is not ours. To leave the list, reply to any message or write to the contact address below, and the record is deleted.

The signup endpoint also keeps a throwaway rate-limit record — your IP address and a timestamp, held in memory for sixty seconds — so a bored visitor cannot hammer the form. It is never written to disk.

Advertising on the website

Website advertising is served by Google AdSense, and it is switched on only when a publisher account is configured. Until then no ad script loads and no advertising cookie is set. When it is on, Google may set cookies and read device identifiers to select and measure ads. What is set, and how to refuse it, is spelled out in the Cookie Notice. You can also control personalisation directly at Google Ad Settings.

Depot orders

Product pages are rendered by our own servers, but the checkout is not. Pressing checkout hands you to Shopify’s hosted checkout, where Shopify and its payment processors collect the name, shipping address, email address and payment details needed to fulfil the order. Card numbers never reach us and are never stored on our systems. Shopify processes that order data under its own privacy policy, and we see only what is needed to answer questions about an order.

What the website does not do

  • It sets no cookies of its own. There is no first-party session cookie, because there is no account system on the web.
  • It runs no analytics product — no Google Analytics, no Plausible, no pixel from a social network.
  • It does not fingerprint your browser, and it does not attempt to identify you across sites.

What the Delta-V Android app collects

The app does more than the website does, because a game with cloud saves, purchases and leaderboards cannot work otherwise. Everything it collects is listed here.

  • Account identity — Firebase Authentication. On first launch the app signs in anonymously, which produces a random user identifier (a UID) and nothing more. If you choose to sign in with Google or Play Games, that provider gives the app account your name, email address and avatar URL so progress can follow you to another device. Signing in is optional.
  • Cloud-saved progress — Cloud Firestore. Level completions, star ratings, best times, currency balances, unlocked parts and purchase entitlements are written to a document keyed to your UID. Security rules restrict that document to the owning account: it is not publicly readable.
  • Purchases — Google Play Billing and RevenueCat. Product identifiers, purchase and expiry timestamps, receipt data and entitlement status are recorded against an app user identifier derived from your UID. Payment itself is processed by Google Play; card numbers, billing addresses and bank details never reach the developer.
  • Crash diagnostics — Firebase Crashlytics. When the app crashes it sends a stack trace, the device model, the OS and app version, a Crashlytics installation identifier, and a short breadcrumb trail of what the game was doing beforehand. This is how a bug that only reproduces on one chipset ever gets fixed.
  • Usage analytics — Firebase Analytics. Coarse events: app opens, level starts and completions, store screen views, and the app instance identifier Google attaches to them. Google also derives an approximate country and device class from the request. There is no keystroke logging and no screen recording.
  • Advertising — Google AdMob. Ad requests carry your device’s advertising identifier plus standard request data (app version, coarse locale, device type) so an ad can be selected, rendered, capped and measured. See Advertising and consent.
  • Abuse prevention — Firebase App Check. The app attaches a Play Integrity attestation token to its requests, which lets the backend tell a genuine install from a script. Without it a public leaderboard is trivially forged. The token describes the app and the device’s integrity verdict, not you.

Device permissions

The app declares two Android permissions: internet access, and billing. The Google Mobile Ads SDK adds the advertising-identifier permission when the app is built. It requests no access to location, camera, microphone, contacts, call logs, SMS or your photo library, and it cannot read files outside its own storage.

Public leaderboards and display names

Leaderboards are public by design, and this is the only place where anything you provide becomes visible to other people. When you submit a score, the entry holds your chosen display name (twenty characters maximum), the star rating, the completion time, the level, the app version and the submission timestamp. Anyone can read it.

Pick a handle rather than your legal name. You can change your display name in the app at any time, and you can ask for your entries to be removed entirely using the request route in Your rights.

Advertising and consent

Google AdMob serves the ads inside the Delta-V app. Before the first ad request, the app runs Google’s User Messaging Platform (UMP) consent flow. Where consent is legally required — the EEA, the UK, and anywhere else Google’s consent policy applies — the UMP form is presented and no personalised ad request is made until you have answered it. Your answer is stored by the UMP SDK on your device.

You can change that answer at any time: open Settings → Privacy options in the app. The control appears wherever Google actually provides a form, which in practice means EEA and UK users; elsewhere there is no consent form to reopen. Choosing non-personalised ads does not remove ads, and an ad request is still made — it simply carries less about you.

Ad placement is deliberately narrow. Banners appear on menu screens, and rewarded video is opt-in: it plays only when you tap a control that offers something in exchange. The app does not interrupt a run with a forced full-screen ad.

How Google uses data from apps and sites that use its services is described in Google’s partner-sites notice.

Third-party processors

These are every company that receives personal data through Delta-V, what each one does with it, and where their own policy lives. There are no others.

  • Google LLCFirebase Authentication, Cloud Firestore, Firebase Analytics, Crashlytics and App Check in the app; Google Play Billing for purchases; AdMob for in-app ads; AdSense for website ads. Privacy policy
  • RevenueCat, Inc.Records which in-app products an account owns, so entitlements survive a reinstall or a new device. Privacy policy
  • Shopify Inc.Hosted checkout, payment processing and order fulfilment for anything bought from the depot. Privacy policy
  • ResendDelivers mailing-list and transactional email. Holds the address you submitted and the delivery result. Privacy policy
  • Vercel Inc.Hosts and serves this website, and generates the request logs described above. Privacy policy

Data is shared with a processor only so it can perform the function listed. None of them is permitted to sell it, and Delta-V receives no payment for passing data to anyone.

Children

Delta-V is not directed at children under 13, or under the higher minimum age that applies where you live. The app is not enrolled in a children’s programme, it is not COPPA-certified, and no claim of certification is made here. Ad requests are made without the under-age-of-consent flag set, which is another way of saying the app is built for a general audience.

We do not knowingly collect personal data from a child under 13. If you are a parent or guardian and believe a child has provided data — a real name on a leaderboard, for example, or an email address on the mailing list — write to the contact address below and it will be deleted.

Your rights and how to exercise them

Depending on where you live, you have some or all of these rights: to know what data is held about you, to get a copy of it, to correct it, to have it deleted, to restrict or object to how it is used, and to withdraw consent you previously gave. You do not need a lawyer to use them, and exercising them costs nothing.

To make a request, email TODO_CONTACT_EMAIL and say what you want. If you signed in with Google, send it from that address; if you played anonymously, include your in-game display name and roughly when you started playing, so the right account can be found. Expect an answer within 30 days.

A deletion request removes your cloud save, your leaderboard entries and your stored display name, and asks the relevant processors to delete the analytics and crash identifiers tied to your installation where their tooling allows. It cannot undo a purchase — Google Play holds those records under its own retention rules, and a refund is a Play Store matter. Uninstalling the app removes the local copy of your progress but not the cloud copy; ask for deletion if you want both gone.

If you are in the EEA or the UK, the legal bases used are: performance of a contract (cloud saves, purchases and order fulfilment), legitimate interests (security, abuse prevention, crash diagnostics), and consent (personalised advertising and the mailing list). You may also complain to your national supervisory authority. If you are in California, we do not sell or share personal information as the CCPA uses those terms, and you will never be treated differently for exercising a privacy right.

How long data is kept

  • Cloud saves and leaderboard entries are kept while the account exists — they are the product — and are deleted when you ask.
  • Server logs are kept briefly by the host for operational and security purposes, then rotated out.
  • Crash reports are retained by Firebase Crashlytics for a limited window set by Google, currently 90 days for the detailed report.
  • Analytics events follow the retention period configured in Firebase; aggregate counts may persist after the underlying events expire, but they no longer identify a device.
  • Mailing-list addresses are kept until you unsubscribe or ask for deletion.
  • Order records are kept by Shopify for as long as tax and consumer-protection law requires.

International transfers

Every processor named above is based in, or operates infrastructure in, the United States, so using Delta-V means your data crosses a border. If you are in the EEA, the UK or Switzerland, those transfers rely on the safeguards each processor publishes — Standard Contractual Clauses, the EU-US Data Privacy Framework, or both, as set out in their policies. No additional transfer happens beyond what running the service requires.

Security

Traffic to the website and to the game backend is encrypted in transit. Cloud saves are protected by Firestore security rules that allow a document to be read or written only by the account that owns it, and writes are shape-checked so a modified client cannot smuggle extra fields in. App Check rejects requests that do not come from a genuine install. Payment credentials are handled entirely by Google Play and Shopify and never touch our infrastructure.

None of that makes a system perfectly secure, and anyone who tells you otherwise is selling something. If you find a vulnerability, please report it to the contact address rather than demonstrating it on other players.

Changes to this policy

This policy changes when the product does — a new processor, a new data type, a removed feature. The revision date in the rail at the top of this page is the date of the current version. For a change that materially affects how your data is used, notice will be given in the app or on the site before it takes effect. Continuing to use Delta-V after that means the current version applies.

Common questions

Does the Delta-V app collect my location?

No. The Delta-V Android app declares no location permission, and neither the game nor its analytics collect GPS coordinates. Google's advertising and analytics services can infer an approximate country or region from the IP address that every internet request carries, but that is the limit of it.

Can I play Delta-V without creating an account?

Yes. On first launch the app signs in anonymously to Firebase, which produces a random account identifier and nothing else — no email address, no name. Signing in with Google or Play Games is optional and exists so progress can move between devices.

How do I delete my Delta-V data?

Email TODO_CONTACT_EMAIL from the address you signed in with, or include your in-game display name, and ask for deletion. Your cloud save, leaderboard entries and display name are removed. Uninstalling the app clears the copy held on the device but does not remove the cloud copy.

Does the Delta-V website use tracking cookies?

The website sets no cookies of its own. When Google AdSense is switched on, Google may set advertising cookies from its own domains; where consent is legally required, it is requested before those load.

Is any of this data sold?

No. Personal data is never sold, rented or traded. It is shared only with the named processors — Google, RevenueCat, Shopify, Resend and Vercel — and only so they can perform the function they are listed for.

Contact

Privacy questions, access requests and deletion requests all go to the same address.

CONTACT — PLACEHOLDER

UNSET
EMAILTODO_CONTACT_EMAIL

TODO_CONTACT_EMAIL is a placeholder, not an address. Set NEXT_PUBLIC_CONTACT_EMAIL to a monitored mailbox before this policy is linked from a Google Play listing — Play requires a working contact route, and a deletion request that bounces is a compliance failure rather than a broken link.

Postal address available on request. This policy is governed by the same law as the Terms of Use, and sits alongside the Cookie Notice.