Last updated: October 1, 2026
This policy explains what data the Kalegard mobile game (Android and iOS) collects, why, who it is shared with, and how long it is kept. This is the English translation of the Turkish policy; in case of a conflict, the Turkish version prevails.
In short. You do not need an account or a real name to play; the game creates a guest player tied to your device on first launch. You may optionally link a Google or Apple account to keep your progress across devices — that is when your email address and profile name reach us. The game shows ads and offers in-app purchases; your payment details never reach us, they are handled by Google Play and the App Store.
| Data controller | qbiSoft |
|---|---|
| Contact | support@kalegard.com |
| App | Kalegard — com.qbisoft.kalegard (Google Play, App Store) |
ANDROID_ID on Android, identifierForVendor
on iOS). We do not access hardware serial numbers, phone numbers or IMEI.Linking is optional and only serves to preserve your progress. Authentication runs through Google Firebase Authentication, and we receive: your permanent account identifier (Firebase UID), your email address (with Apple's "Hide My Email", the relay address Apple generates), your name, your profile picture URL, and which provider you used. We never see your password.
Level and experience, gold and gem balance, the history of your gems (when and what they were spent on or refunded), trophies, owned cards and card mastery levels, daily quests and their progress, daily chest counters and play streak, emojis, friend list and pending friend requests, and whether you allow friends to spectate your matches.
Match history. For each ranked match we store both players' identifiers and their player names at that time, the winner, the result, the trophy change, start and end time, and how many turns it lasted. Practice matches against bots and friendly duels are not recorded.
The game shows ads through Google AdMob: rewarded ads you choose to watch, and interstitial ads between matches. Google serves and measures these ads and processes your advertising identifier (AAID on Android only — no advertising identifier is used on iOS, because the game never asks for tracking permission and Google therefore cannot access the IDFA), device and app information, approximate location (typically country or city level derived from IP), and whether an ad was shown, watched or clicked.
This data is processed on Google's infrastructure. From Google we only receive aggregate reports (impressions, views, revenue) and Google's signed verification callback so we can credit your reward.
Reward records. To credit a reward to the right account and to prevent the same reward being granted twice or abused, our server keeps the following linked to your account: when you started a rewarded ad and for which reward (e.g. which match's chest, which quest); the transaction identifier, time and outcome of Google's verification callback (whether the reward was credited, how much gold, or why not); and every extra reward you unlock with an ad or with gems (such as doubling a chest, rerolling a quest or a gold top-up — which day, which use of the day, and by which route). These records are deleted after 35 days.
The game's own counting. To see whether the rewarded ad placements work, the game also sends these events to our server: that a rewarded-ad card was shown, that an ad was watched, closed early or failed to load, how long the reward took to arrive, and your answer to the ad consent prompt (which is only shown in the regions described below). Our server stores these events without linking them to your account or device, only as daily totals (e.g. "watched 40 times on Android today"); they cannot tell who did what. No third-party analytics tool is used for this.
Personalisation and your control. Whether ads are picked to match your interests depends on the platform:
How Google processes this data: policies.google.com/technologies/partner-sites
Purchases are handled by Google Play Billing and the Apple App Store. Your card number, bank details and billing address never reach us — only Google and Apple process them. What we receive is the transaction/receipt identifier, product code, purchase time, and whether the purchase is valid, so we can verify it and deliver the item. Refunds and cancellations are also reported to us so we can reverse the item.
For security and troubleshooting our server keeps access logs: your IP address, request time, requested path and status code. These logs are not matched to your game account and are not used for marketing.
Music and sound volume, haptics level, text size and whether you have seen the tutorial stay on your device and are not sent to us. Notifications (chest reminders) are scheduled entirely on your device — we do not store a push token or send you server-initiated notifications.
Precise location, contacts, photos, microphone, camera, call logs, SMS, health data, biometric data: none of these. We use no third-party analytics or crash-reporting tools beyond advertising.
| Purpose | Data |
|---|---|
| Creating your account, recognising you, preserving progress across devices | 2.1, 2.2 |
| Running the game: matchmaking, matches, rewards, quests, chests, friends, spectating | 2.1, 2.3 |
| Serving ads and verifying/crediting rewarded ads | 2.4 |
| Delivering purchases and processing refunds | 2.5 |
| Preventing cheating, abuse and invalid ad traffic | 2.1, 2.4, 2.6 |
| Troubleshooting, server security, backups | 2.6, 2.1-2.3 |
| Meeting legal obligations (e.g. financial records) | 2.5 |
We do not sell your data. We share only with:
| Who | For | What |
|---|---|---|
| Google (Firebase Authentication) | Google/Apple sign-in | Identity token, account identifier |
| Google (AdMob) | Ad serving and measurement | Data in 2.4 |
| Google (Play Billing) | Purchases on Android | Data in 2.5 |
| Apple | Sign in with Apple, purchases on iOS | Account identifier, data in 2.5 |
| Other players | Matchmaking, friends, ranking, spectating | Your player name, player tag, level, trophies, profile picture and online status |
| Authorities | Only where legally required | Limited to the scope of the request |
Your email address is never shown to other players.
International transfers. Google's and Apple's services also run on servers outside Türkiye, so the data in 2.2, 2.4 and 2.5 is transferred abroad. Our game server and database are located in Türkiye.
| Data | Retention |
|---|---|
| Game account and game data | While the account exists; 24 months after your last sign-in, if unused, your account is de-identified: your name, email address, profile photo and device information are deleted, and game records such as your cards remain in a form that can no longer be linked to you (same scope as Deleting your account) |
| Match history | 24 months |
| Rewarded-ad and extra-reward records (2.4, "Reward records") | 35 days |
| Account deactivated after an account conflict | 12 months, so a wrong choice can be reversed |
| Server access logs (IP) | At most 30 days |
| Database backups | 14 days — a deleted account leaves backups within this window |
| Purchase records | As required by tax law (10 years) |
You can delete your account from inside the game:
Settings → Account → Delete my account
Once you confirm, your account can never be signed into again. Your name, email address, profile photo, device information and any linked-account (Google/Apple) details are deleted; so are your friend connections and any pending friend requests.
Game records such as your cards and match history remain in de-identified form: matches are part of your opponents' own history too, so the records are not deleted — but they can no longer be linked to you, and wherever your name appeared it now reads "Silinmiş oyuncu" (deleted player). Your rewarded-ad and extra-reward records (2.4) also remain de-identified and are deleted entirely no later than 35 days after they were created. Deletion cannot be undone. Removal from backups takes up to 14 days; purchase records are retained for the period stated above as required by law.
If you cannot access the game, email support@kalegard.com to request deletion; we respond within 30 days.
You may ask us whether we process your personal data, request information about it, learn the purpose of processing and whether it is used accordingly, learn the third parties it is transferred to at home or abroad, have inaccurate or incomplete data corrected, request erasure where the conditions are met, ask that corrections and erasures be notified to those third parties, object to outcomes produced solely by automated analysis, and claim compensation for damage caused by unlawful processing.
Write to support@kalegard.com to exercise these rights. If you live in Türkiye, see our KVKK notice for details.
Kalegard is intended for a general audience and is not directed at children. We do not knowingly collect data from users under 13. If you are under 18, use the game with your guardian's knowledge and consent. If you believe your child has provided us data, email support@kalegard.com and we will delete the record.
Traffic between the game and our server is encrypted with TLS. The database is reachable only from the server itself and is not exposed to the internet. Only authorised administrators can access backups and server logs. No system is perfectly secure; in the event of a breach we will notify you and the competent authority within the period required by law.
If this policy changes, the "last updated" date above changes; we also announce significant changes inside the game.