1. Introduction
This mobile application ("ECHOES," "we," "our," or "us") provides two gaming experiences: ECHOES (13+) and FORMS (18+). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and services.
Games Offered:
• ECHOES - Asynchronous multiplayer adventure (13+)
• FORMS - Strategic placement game (18+)
2. Information We Collect
2.1 Personal Information
We collect the following personal information:
- Email address (required for account creation)
- Nickname (username, displayed to other players)
- Date of birth (for age verification and COPPA compliance)
- Country of residence
- Payment information (if purchasing ECHOES Plus or Echo Tokens, processed securely through Stripe)
- Parental consent (for users under 13, COPPA requirement)
2.2 Game Activity Data
- ECHOES: Trails, karma ratings, achievements, daily world completions, notes left for other players
- FORMS: Form placements, influence scores, global leaderboard rankings
- Friends list and social interactions
- In-game purchases and subscriptions
- Login streaks and daily rewards
2.3 Automatically Collected Information
- Device information (device ID, model, operating system)
- IP address (for fraud detection and security)
- App usage analytics and crash reports
- Push notification tokens (if you opt-in)
3. How We Use Your Information
We use your information to:
- Provide and maintain our games (ECHOES and FORMS)
- Generate daily procedurally-generated worlds (ECHOES)
- Display trails, karma, and leaderboards to other players
- Process in-app purchases and subscriptions
- Enforce age restrictions (13+ for ECHOES, 18+ for FORMS)
- Send notifications about achievements, friends, and game updates
- Detect and prevent cheating, fraud, and abuse
- Moderate user-generated content (notes, trails)
- Comply with legal obligations (COPPA, GDPR, CCPA)
- Improve game balance and user experience
4. Data Sharing
We may share your information with:
- Other Players: Your nickname, avatar, trails (ECHOES), and form placements (FORMS) are visible to other users
- Payment Processors: Stripe for secure payment processing (ECHOES Plus, Echo Tokens)
- Service Providers: Third-party services that help us operate our app (analytics, cloud hosting, push notifications)
- Legal Requirements: When required by law or to protect our rights and users' safety
- Business Transfers: In connection with a merger, sale, or acquisition
We do NOT sell your personal information to third parties.
5. Children's Privacy (COPPA Compliance)
We are COPPA compliant and take children's privacy seriously.
ECHOES (13+): Users aged 13+ can play without parental consent.
Users under 13: Require verifiable parental consent before accessing ECHOES.
FORMS (18+): Strictly age-gated. Users under 18 cannot access FORMS.
5.1 Parental Consent Process
For users under 13 who want to play ECHOES:
- We require a parent or guardian to provide consent
- Parents can review our Privacy Policy before consenting
- Parents can request deletion of their child's data at any time
- We collect only the minimum necessary information from children
5.2 Parental Rights
Parents/guardians can:
- Review their child's personal information
- Request deletion of their child's account and data
- Refuse to allow further collection of their child's information
- Contact us to exercise these rights
6. Data Security
We implement industry-standard security measures to protect your information, including:
- Encryption of data in transit (HTTPS/TLS)
- Secure password hashing (Argon2)
- Access controls and authentication
- Regular security audits
- Fraud detection systems
However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
7. Your Rights
You have the right to:
- Access your personal information
- Correct inaccurate information
- Request deletion of your data (see Data Retention below)
- Export your data in a portable format
- Opt-out of marketing communications
- Withdraw consent at any time (where consent is the legal basis)
- Object to certain processing activities
To exercise these rights, contact us at the email below or use the in-app "Delete Account" feature.
8. Data Retention
We retain your information for as long as necessary to provide our services and comply with legal obligations:
- Account data: Until you request deletion
- Game trails/placements: Indefinitely (contributes to gameplay for other users)
- Purchase history: 7 years (tax/legal requirements)
- Moderation logs: 2 years (safety and fraud prevention)
Note: When you delete your account, your personal information is removed, but anonymized game data (trails, forms) may remain visible to preserve game integrity for other players.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers, including:
- Standard contractual clauses (EU)
- Privacy Shield principles (where applicable)
- Encryption and security measures
10. Cookies and Tracking
We use minimal tracking technologies:
- Authentication tokens: To keep you logged in
- Analytics: To understand app usage and crashes (anonymized)
- No third-party advertising cookies
You can control some tracking through your device settings.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Posting the new policy on this page
- Updating the "Last updated" date
- Sending an in-app notification or email (for material changes)
Continued use of the app after changes constitutes acceptance of the new policy.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
Email: privacy@echoesgame.com
Support: support@echoesgame.com
Data Protection Officer: dpo@echoesgame.com
GDPR Compliance (EU Users)
If you are located in the European Economic Area (EEA), you have additional rights under GDPR, including:
- Right to data portability
- Right to object to processing
- Right to lodge a complaint with a supervisory authority
- Right to restrict processing
California Privacy Rights (CCPA/CPRA)
California residents have specific rights regarding their personal information under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell data)
- Right to non-discrimination for exercising CCPA rights