← Back to Spirepact

Privacy Policy

Version 2026-10-10-release1

This policy explains how the Spirepact iOS app and web service process personal data. The operator is Kuji Information Ltd. (酷傑資訊股份有限公司), Taiwan business number 93666000. Contact us about support or privacy at [email protected].

Optional game notifications

We explain notifications only after your first clear and return to camp. iOS permission is requested only when you choose to enable notifications. Declining does not prevent play. Account settings provide separate switches for unclaimed co-op rewards, arena rewards and defense results, daily quest/arena attempt resets, and announcements/maintenance.

When enabled, we store the Apple push token, a random installation identifier, the associated game account and session, game language, device time zone, notification preferences and last synchronization time to send your selected reminders through Apple APNs. These are not advertising identifiers and are not used for cross-app tracking. Notifications do not contain email addresses, character names or transaction amounts. iOS controls their display on the lock screen. Apple processes APNs delivery, which may involve international transfers.

Each category sends at most two notifications a day (one for co-op and daily reminders). Quiet hours are 22:00–08:00 in the device's time zone; daily reset reminders are sent after 09:00. Disabling a category cancels queued notifications. Logging out or deleting the account removes that session's device registration. Delivery stops when the session expires or synchronization has been inactive for 30 days. Registrations inactive for 60 days are deleted; queue and delivery records are kept for up to 30 days. Backups follow the schedule below. Account export includes preferences and registration dates, but excludes security tokens.

1. Data we process

2. Purposes and retention

We use this data to authenticate accounts, save characters and progression, provide rankings, chat, game-gold trades and purchases, respond to support and privacy requests, operate the service and prevent abuse. We do not sell personal data, use account data for advertising tracking or send it to AI services for model training.

Account and character data is kept while the account exists, until you delete it or the service ends. Sessions last at most 30 days; logout or account deletion invalidates the relevant credentials. Expired session records are removed during maintenance. The live database is backed up every six hours; regular backups are normally kept for 14 days, with at least three retained. If backups stop, the last three may be kept longer. Pre-deployment recovery backups are removed after rollback operations finish. Backups are stored in a restricted directory in Singapore, not used for ordinary queries, and may temporarily contain deleted data until rotation. Operators must reconcile deletion requests after disaster recovery. Off-site backups are not yet established. Legally required records are retained only to the necessary extent and for the applicable period.

Third-party login attempts last ten minutes and are cleaned up one day after expiry during subsequent login activity. Deletion reauthentication grants last five minutes and are single-use. Provider identifiers and encrypted credentials are normally kept until account deletion or provider revocation. Necessary credentials move to a restricted revocation queue on deletion and are removed after the provider confirms revocation; failed requests are retried. Apple account-change notifications invalidate revoked logins; notification deduplication hashes older than 30 days are cleared during later notifications.

3. Storage, transfers and providers

We use DigitalOcean hosting and PostgreSQL in Singapore, with Cloudflare for DNS, HTTPS and network protection. Account email is delivered through Twilio SendGrid in the United States: we supply the recipient address, subject and body including one-time links. SendGrid keeps delivery records under its privacy policy for delivery and abuse prevention. Data may therefore be processed in Singapore, the United States and other infrastructure-provider locations. The operator and infrastructure providers process data as needed to provide this service.

The native Google Sign-In SDK also processes data under Google’s privacy policy. Its bundled privacy declaration lists name, email, phone number, user/device identifiers, approximate location, usage information and other data, for sign-in/security functionality and SDK analytics. Google explains that IP addresses can be used to estimate general location for fraud prevention. These provider-side practices do not mean we request GPS access or copy those fields into your game profile. You can choose Apple, email or guest access instead of Google sign-in. See Google’s SDK data disclosure.

Google/Apple handle their authorization flows. We send authorization codes, application identifiers and verification data to authenticate logins and revoke authorization. Their own policies cover provider connection and authorization records: Google Privacy Policy and Apple Privacy Policy. Google user data is used only for the login/account-management purposes above, in accordance with the Google API Services User Data Policy, including applicable Limited Use requirements.

The database does not accept direct public connections. Web login uses HttpOnly cookies; iOS session credentials are stored in Keychain. Except for the necessary providers above, your authorization or legal requirements, we do not disclose account data to third parties.

4. Cookies and device storage

The website uses essential login cookies, not advertising or analytics cookies. The app uses Keychain for login. Browser-based third-party login temporarily stores verification binding in that tab's sessionStorage and clears it on completion/cancellation; the flow cannot start if this storage is blocked. Game language, audio and other preferences use local device storage. You may log out, delete your account or clear browser data. Losing an unlinked guest credential may make the character unrecoverable. Uninstalling the app does not delete the server account.

5. Your rights and choices

Account settings show your account information and provide an export and deletion option. You may also email us to request access, a copy, correction, restriction/cessation of processing or deletion, as provided by applicable law. We may require reasonable account verification to protect your data. You can use guest mode without an email address; withholding data necessary for account functions may prevent those functions from working.

Use Account Settings → Delete Account and Characters to delete your account in the app or website. After confirmation, all characters, linked login methods and sessions are removed and other devices are signed out. A linked provider requires reauthentication with the same identity and a separate deletion confirmation. Provider revocation may finish later, without delaying game-account deletion. Revoking Google/Apple authorization alone does not request deletion of the whole game account; another linked method may still allow login.

Deletion also removes arena defense/reports/rankings/medals/redemptions, chat, blocks, reports and your own marketplace operations. Unsold listings are removed; equipment already transferred to another player is not reclaimed. Gold, Starstones, cosmetics and summon history are removed. Apple purchase binding and transaction records are retained after their game-account association is removed to prevent reuse of deleted-account purchases and support refunds/reconciliation. There is currently no automatic deletion period for these records. They do not contain email, character name, Apple ID or card details. Apple's payment records are governed by Apple's policy.

6. Minors

The game is not specifically directed at children and does not request dates of birth. Minors should review this policy and the terms with their legal guardian. Contact us if personal data has been provided without required consent.

7. Updates and contact

Material changes to data categories, purposes or providers will be reflected in a new version and an in-game notice. Where renewed consent is required, we will ask separately. Contact [email protected] with privacy questions.