Privacy Policy
Last updated: July 7, 2026
This Privacy Policy explains how Zachary Cleversley, doing business as GloomDeep (“GloomDeep,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use the GloomDeep mobile game and related services (the “Service”). GloomDeep is a multiplayer game available on Apple’s App Store.
If you have questions about this policy or your data, contact us at [email protected] or by mail at GloomDeep, 1712 Genesee Street, Corfu NY 14036.
This policy is written for users in the United States. The Service is intended for players in the United States and is not directed to children under 13.
1. Summary
GloomDeep collects the account identifiers needed to sign you in and keep your account secure (username, a Google or Apple account identifier, session tokens, and a generated device token). We store gameplay progress such as your class, level, currency balances, inventory, equipment, quests, active dungeon runs, daily-challenge results, guild membership, friends, blocks, and other game state. If you use chat, direct messages, guild or world messages, reports, or the in-game mailbox, those messages and related moderation records are stored so the features work, you can report abuse, and we can moderate the Service. If in-app purchases are enabled, we process the Apple purchase and transaction information needed to grant and maintain in-game credits.
We do not use advertising SDKs, analytics SDKs, or cross-app/cross-site tracking, and we do not track you across other companies’ apps or websites for advertising or data-broker purposes.
2. Information We Collect
2.1 Account and Sign-In Information
- The username / display name that you choose.
- An internal numeric user ID we assign to your account.
- A provider account identifier from your sign-in method: your Google subject identifier (Google sign-in); your Apple subject identifier (Apple sign-in, when available); or a development/testing identifier used only in non-production builds.
- For legacy password accounts, a password hash (we store only a scrypt hash; we do not store your password in plain text).
- Session tokens we issue to keep you signed in.
When you sign in with Google (and, in the future, Apple), we receive your name, email address, and email-verified status from the sign-in provider so we can verify the sign-in. We do not store your Google name or email address for your player account — we store only the provider subject identifier. (The narrow exception is administrator accounts used by our staff; see Section 2.8.)
2.2 Device and Security Information
- A device token generated on your device and associated with your username, stored locally on your device and on our server to help protect your account.
- Your IP address, derived from your network connection or our network provider’s headers, used in memory for login rate-limiting and abuse prevention. We do not maintain a dedicated persistent IP-address database in the application.
- Internal security and session data (for example, gate keys and session/CSRF tokens) used to operate and protect the Service.
2.3 Gameplay and Progress Information
Stored under your username, including: class; gold; credits; XP; level; HP and combat stats; stat points and upgraded stats; dungeon clears; inventory; equipped items; slot-upgrade levels; shop state; quest state; an active-run snapshot for resuming dungeons; cooperative dungeon completions and first-completion records; guild name, guild points, and guild perks; guild-chat seen markers; and your daily login streak.
We also store daily-challenge records (day, username, class, level, attempt count, cleared flag, completion time, kills, and reward status), which are used to generate leaderboards.
2.4 Social and Presence Information
- Friend requests and friendships (requester, addressee, status, timestamp).
- Block list (blocker, blocked user, timestamp).
- Online presence, held in memory and shared with your accepted friends.
- Co-op party state (usernames, class, dungeon tier, invites, join requests, ready state, membership).
- Guild records (guild name, tag, leader, policy, members, shop, join requests, level, points, and update time).
2.5 User-Generated Content
- Direct messages (sender, recipient, body, read status, timestamp). DM history is limited to the most recent 200 messages per conversation.
- World and guild channel messages (channel, sender, body, timestamp). Channel history is limited to the most recent 200 messages per channel.
- Mailbox / system notices (username, type, title, body, payload, actions, read status, timestamp).
- Reports you submit or that concern you (reporter, reported user, context, message snapshot, reason, status, timestamps, and reviewer information).
- Co-op lobby chat is temporary and is not stored.
Messages are passed through automated server-side moderation/masking before they are stored.
2.6 Purchases and Virtual Currency
- Your credits (in-game virtual currency) balance, which can be earned or spent through gameplay (for example, respecs, shop refreshes, daily retries, rewards, and login streaks).
- When Apple in-app purchases are enabled, we will process the purchase and transaction information needed to grant and maintain entitlements — such as Apple transaction identifiers, product IDs, purchase status, transaction-verification responses, the credit package purchased, timestamps, and your resulting credit balance.
Apple processes your payment and payment-credential information under Apple’s own privacy policy. We do not receive or store your payment card details; we receive only the purchase/transaction verification data needed to grant your purchase.
2.7 On-Device Local Data
The app stores the following locally on your device: UI preferences (ability-side preference, music volume, SFX volume, font scale), your last-used username, your saved session token, and your per-username device token. This data supports your settings and keeps you signed in.
2.8 Administration, Support, and Moderation Data
- Administrator sign-in uses Google sign-in restricted to an internal allow-list; admin sessions store the administrator’s email address and a security token.
- An admin audit log records the administrator’s email, the action taken, the target, details, and timestamp.
- Account-administration views may show username, class, level, clears, credits, guild, friend count, last-seen time, provider type, account-creation date, and suspension status/reason.
- Suspension records (suspended-until time and reason) and the reports queue (including message snapshots and review status).
2.9 Server Logs and Operational Data
We log operational events such as server start-up, connect/disconnect events by username, co-op reconnections, account deletions, device-token mismatches, and errors. Our hosting, container, reverse-proxy, and network providers may separately record operational metadata such as IP addresses, user agents, timestamps, request paths, and errors. We do not use any third-party crash-reporting, analytics, or advertising SDKs in the app; the diagnostic reporting described in §2.10 is first-party.
2.10 Diagnostics and Error Reporting
To detect and fix bugs and keep the game stable, the app reports diagnostic information to our own servers when it encounters an error or unexpected condition (for example, a failed action, a lost connection, or an unrecognized server response). Each report may include a short description of the error, a label indicating where it occurred, your device platform (e.g., iOS), and the app version. If you are signed in at the time, the report is associated with your username so we can correlate recurring problems.
This diagnostic data is collected first-party. We do not use any third-party crash-reporting or analytics SDK, it is not used for advertising or to track you across other apps or websites, and it is not sold or shared with data brokers. We retain these diagnostic records for up to 30 days, after which they are automatically deleted.
3. How We Use Information
We use the information above to:
- Create, authenticate, secure, and maintain your account.
- Provide and operate the game, including saving and restoring your progress.
- Provide multiplayer and social features (friends, guilds, parties, presence, chat, mail).
- Enable and process in-app purchases and maintain your virtual-currency entitlements.
- Detect, prevent, and respond to fraud, abuse, cheating, and security incidents.
- Moderate content, review reports, and enforce our Terms.
- Respond to support requests and administer accounts.
- Maintain leaderboards and game events.
- Comply with legal obligations and protect our rights and users.
We do not sell your personal information, and we do not use it for cross-app advertising or profiling.
4. How We Share Information
- With other players, as part of the game’s social features — for example, your username and presence are visible to accepted friends, your guild information is visible to guild members, and chat/messages are delivered to their recipients.
- With sign-in providers (Google, and Apple when enabled), which process information during their sign-in flows under their own privacy policies.
- With Apple, which processes payments and store transactions for in-app purchases under Apple’s privacy policy.
- With service providers that host and operate the Service on our behalf (for example, our database, session store, and network/CDN providers), bound to use the information only to provide services to us.
- For legal and safety reasons, when we believe disclosure is necessary to comply with law, enforce our Terms, or protect the rights, safety, or property of GloomDeep, our users, or others.
- In a business transfer, such as a merger, acquisition, or sale of assets, subject to this policy.
5. Third-Party Services
The Service relies on the following third parties, each governed by its own privacy policy:
- Google Sign-In (player and administrator authentication) — see the Google Privacy Policy.
- Apple (Sign in with Apple and App Store / in-app purchase processing, when enabled) — see the Apple Privacy Policy.
- Our hosting, database, session-store, and network/CDN providers.
These providers may process information when you sign in or make a purchase. This policy describes what GloomDeep itself receives, stores, and uses.
6. Tracking and Advertising
The current app does not include advertising or analytics SDKs and does not track you across third-party apps or websites for advertising or data-broker purposes. If this changes, we will update this policy before introducing such features.
7. Data Retention
We keep personal information only for as long as it is needed for the purposes described in this policy — generally while your account is active — and then delete it or keep it only for a limited additional period where needed for security, abuse-prevention, or legal reasons. Specific retention behavior in the current app:
- Account and gameplay data is kept while your account exists and is removed when you delete your account, as described in Section 8.
- Player session tokens expire after 30 days by default.
- Administrator sessions expire after 12 hours by default.
- Direct messages are limited to the most recent 200 per conversation, and channel messages to the most recent 200 per channel; older messages beyond these limits are removed automatically.
- Co-op lobby chat is temporary and is not stored.
- Server logs are short-lived operational records that are deleted or overwritten in the normal course of running the service.
The Game runs on third-party cloud infrastructure located in the United States, and we do not store your data longer than needed for the purposes above. Backups of the server — including database contents — are retained on a short rolling schedule (currently the most recent several daily backups) for disaster recovery and are overwritten automatically as newer backups are taken. Network traffic to the Service is routed through a third-party network/CDN provider. We will update this policy if these arrangements materially change.
After you delete your account, we may keep a limited amount of moderation-related information — such as abuse reports and administrator action logs — for a reasonable period to protect players, prevent abuse, and comply with law, after which it is deleted.
8. Your Choices and Rights
8.1 Account Deletion
You can delete your account from within the app: open Settings, confirm by typing your username, and submit the deletion request. When you do, we revoke your current session and remove your account data, including your user and player records, guild membership, friendships, blocks, direct messages involving you, channel messages you authored, mail, and daily-challenge records.
Some records may be retained after deletion where needed for safety, fraud prevention, legal compliance, or operational integrity — including moderation reports, administrator audit entries, and server/provider logs and backups, which are removed according to their normal retention cycles.
8.2 Local Data
You can clear locally stored data (preferences, saved session token, and device token) by signing out where available or deleting and reinstalling the app.
8.3 California Residents
If you are a California resident, you may have the right to request access to the personal information we hold about you, to request its deletion, and to not be discriminated against for exercising these rights. We do not sell personal information or share it for cross-context behavioral advertising. To make a request, contact us at [email protected]. We may need to verify your identity before responding.
9. Security
We use measures such as hashed passwords, issued session tokens, device tokens, login rate-limiting, HTTP-only/secure session cookies for administration, and server-side moderation to help protect the Service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Children’s Privacy
The Service is intended for users 13 years of age and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, contact us at [email protected] and we will take appropriate steps to delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact
Questions or requests regarding this policy or your personal information:
- Email: [email protected]
- Mail: GloomDeep, 1712 Genesee Street, Corfu NY 14036