BrickRock
Last updated: 16 September 2026
This privacy policy explains which personal data is processed when you use the mobile app BrickRock (Android and iOS), for what purpose, and on what legal basis.
BrickRock is an arcade game. It needs no access to your location, contacts, camera, microphone, health data or financial services, and it never asks for those permissions. It does not, however, run entirely without processing data: saved progress, leaderboards, abuse prevention, advertising and purchases all require technical and account-related data. The sections below set out exactly what that involves.
Want to delete your account?
You can do this in the app, or without the app installed: Delete your account and data (see also section 15).
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
Patrick GaidaEmail: 23patrock@googlemail.com
Personal data is processed only where this is necessary to provide the app and its features, or where you have given your consent.
The legal bases are:
You can withdraw consent at any time with effect for the future (see section 11).
BrickRock uses Firebase Authentication (Google). When you first launch the app, an anonymous account is created automatically. This produces a random technical identifier (the Firebase UID). The UID is not linked to a name or an email address; it exists purely to attach your saved progress to the right device or account.
You may optionally link your account to a Google account or use Sign in with Apple so that your progress survives across devices. Only then is account data from that provider processed — typically a user identifier and an email address, depending on the provider and your settings. With Sign in with Apple you can limit the sharing of your email address (“Hide My Email”).
The data processed here is:
Linking an account is not required in order to play.
The following data is stored on servers in connection with your account:
| Data | Purpose |
|---|---|
| Display name (chosen by you) | how you appear in leaderboards and in the game |
| In-game currency (“coins”) | the game’s economy |
| Best scores and rounds reached | personal progress and leaderboards |
| Cosmetic items owned and equipped | your collection and in-game appearance |
| Supporter entitlement | unlocking purchased content |
| Identifiers of completed rounds | preventing rewards from being credited twice |
| Identifiers of purchases and ad rewards | proof of purchase and prevention of repeat redemption |
The same information is also cached locally on your device so that the app remains usable without an internet connection. Finished rounds that could not yet be uploaded stay on the device until they have been transmitted successfully.
A note on display names: they are checked server-side for permitted characters, length and prohibited content. They do not have to be unique — several players can use the same display name. Please avoid a name that identifies you, unless that is what you want; see the following section.
BrickRock runs public leaderboards (daily, weekly, monthly and all-time). Visible there to every other player are:
Your Firebase UID, your email address, your coin balance and your purchases are not visible to other users. Because the display name is yours to choose, you decide how much it reveals about you.
BrickRock includes an optional friends feature. It is available only with a permanent account (see section 3); it cannot be used with an anonymous account. If you do not use it, none of the data described in this section is created for you.
So that you can connect with others without handing out email addresses or phone numbers, every participating account is given a friend code in the format “BRK-XXXXXX”. You decide who you give it to. BrickRock does not read your contacts or address book to find anyone.
The data processed here is:
| Data | Purpose |
|---|---|
| Your friend code and its link to your account | letting people you gave the code to find your account |
| Pending friend requests (sender and recipient) | showing and answering requests |
| Your friend connections | friends list and friends leaderboard |
| Daily count of codes entered | protection against bulk guessing of other people’s codes |
Within an existing friendship, the other person can see your display name and your score and position in the friends leaderboard. Your email address, your Firebase UID, your coin balance and your purchases are not visible.
You can end a friendship at any time in the app. Both directions of the connection are removed, including the entry in the other person’s list.
The legal basis is Art. 6(1)(b) GDPR: the processing serves a feature you actively asked for. The daily counter guarding against code guessing rests on Art. 6(1)(f) GDPR (legitimate interest in preventing abuse).
BrickRock can send you notifications. This feature is optional, available only with a permanent account, and off by default: it is set up only after you have switched it on in the app and granted the system permission.
We only send messages about events in your own corner of the game:
You choose which of these you want, individually, in the settings. BrickRock does not send marketing notifications.
Delivery runs through Firebase Cloud Messaging (FCM), a Google service (see section 16). This involves:
| Data | Purpose |
|---|---|
| The FCM device token, the platform (Android/iOS) and your app language | delivering to the right device in the right language |
| The link between the token and your account | making sure a device only receives messages for the account currently signed in |
| Your choice of notification types | respecting your settings when sending |
| Daily count of “beaten score” notifications sent | capping how many are sent per day |
A device token is a technical identifier that Google assigns to the app installation on your device. It is not an advertising identifier and is never used for advertising.
When someone beats your best score, a short-lived processing job is created on the server so that we can work out who needs to be notified. It holds the identifier of the account that triggered it, that account’s display name at the time of the round, and the scores involved.
In normal operation these jobs are deleted automatically after 30 days at the latest; deletion is handled by a retention rule stored in the database, not manually. If you delete your account, the jobs created by your own rounds are deleted immediately rather than being kept until that period expires (see section 15).
You can stop notifications at any time, either in the app’s settings or in your device’s system settings. When you switch the feature off in the app, the device token is removed from the server. A token that has become permanently unreachable is deleted at the next delivery attempt.
The legal basis is Art. 6(1)(a) GDPR (consent, given by switching the feature on in the app and granting the system permission). You may withdraw that consent at any time with effect for the future. The daily cap rests on Art. 6(1)(f) GDPR.
The server side of BrickRock runs on Google’s Firebase platform. The services used are:
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, together with Google LLC (USA). Every connection to these services necessarily transmits your IP address as well.
The database (Cloud Firestore) runs in a multi-region within the European Union. The server functions run mostly in a region in the United States; one function runs in a region within the European Union. See section 17 on this.
Further information: Firebase privacy information and Google’s privacy policy.
To ensure the server functions can only be called by a genuine, unmodified copy of BrickRock, the app uses Firebase App Check. It verifies the authenticity of the installation through:
In doing so, technical information about the app installation and the device is transmitted to Google or Apple, and a time-limited authenticity token is issued. No game content and no account data is transmitted.
The purpose is protection against modified app versions, automated access and forged scores. The legal basis is Art. 6(1)(f) GDPR; without this protection, the leaderboards and the game’s economy could not be secured against manipulation.
Further information: Google and Apple.
BrickRock shows advertising only as optional “rewarded ads”. These never appear on their own: they start only when you explicitly choose to watch one in exchange for an in-game reward. BrickRock has no banners, no interstitials and no advertising that starts by itself.
The provider is Google AdMob (Google Ireland Limited / Google LLC). When an ad is served, Google processes, among other things:
Whether the advertising served is personalised or non-personalised depends on your choice in the consent dialog (section 11) and on your device’s advertising-ID settings.
So that a reward cannot be obtained by manipulation, Google reports the outcome directly to our server once an ad has been watched in full (“server-side verification”). What is transmitted is the technical identifier of the transaction and your user identifier, carrying a cryptographic signature that we verify. We do not receive the ad’s content or any advertising profiles.
Further information: AdMob and privacy and how Google uses data from partner apps.
BrickRock uses Google’s User Messaging Platform (UMP) to obtain and manage your advertising consent. If you are in the European Economic Area, the United Kingdom or Switzerland, a dialog appears at launch in which you decide about personalised advertising.
Your decision is stored on the device and applied every time an ad is served. You can change or withdraw it at any time — the app settings contain an entry point for this. You can also reset the advertising ID in your device’s system settings, or disable personalised advertising there system-wide.
BrickRock offers one optional in-app purchase (“Supporter”). It is handled exclusively through:
We do not receive payment data. Card numbers, bank details, billing addresses and similar payment information are processed solely by Google or Apple; we have no access to them.
All that is transmitted to us and stored on our side is the technical proof of purchase (the purchase token or transaction identifier) together with your user identifier. We verify it server-side with the respective provider in order to unlock the entitlement you bought and to prevent the same purchase being redeemed more than once. The legal basis is Art. 6(1)(b) GDPR.
Further information: Google and Apple.
Calling the server functions produces technical log data, in particular the time of access, the function called, the result or error code, and technical connection data including the IP address. These logs serve operation, troubleshooting and the prevention of abuse.
In addition, verification records are stored to prevent rounds, ad rewards or purchases from being credited more than once. The legal basis is Art. 6(1)(f) GDPR.
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
→ Deleting your account: instructions and request form
That page explains step by step how to delete your account in the app — and how to request deletion if the app is no longer installed.
You can request deletion of your account and the associated data at any time. The app settings contain a function for deleting your account. If the app is no longer installed, an informal message to 23patrock@googlemail.com is enough.
Deletion is carried out server-side. The following is removed:
Your previous friend code is permanently retired and never issued again. All that remains is a technical block entry recording the time it was retired; the user identifier and display name are removed. For anyone who still has the code, it therefore leads nowhere.
Technical purchase and ad records are not deleted. These records are needed to provide the relevant entitlement and to prevent abuse: they stop the same purchase or the same ad reward being redeemed a second time. After your account has been deleted, they point to an identifier behind which no account and no profile exists any more. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in preventing the same purchase or ad reward from being redeemed repeatedly. Where statutory retention obligations additionally apply to individual proofs of purchase, retention follows Art. 6(1)(c) GDPR and the periods prescribed there.
Nor do we delete a technical deletion record containing your former user identifier and the time of deletion. It is retained permanently and is what makes it possible to transfer a previously purchased entitlement safely to a new account after an account has been deleted: without it there would be no proof that the earlier account really was deleted. The record holds no name, no progress and no sign-in data. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is keeping paid purchases transferable while preventing anyone from taking over someone else’s purchase.
Entitlements you have already acquired are lost when the account is deleted. Also excluded from deletion is data we are legally required to retain, as well as payment-processing data held by Google or Apple; its deletion is governed by those providers’ own terms.
Uninstalling the app alone does not delete the account on the server.
Your data is not sold. It is passed on only to the following service providers, and only where this is necessary to operate the app:
| Provider | Purpose | Privacy information |
|---|---|---|
| Google Ireland Limited / Google LLC (Firebase, Cloud Functions, Firestore, App Check, Play Integrity) | account, data storage, server functions, abuse prevention | policies.google.com/privacy |
| Google Ireland Limited / Google LLC (Firebase Cloud Messaging) | delivery of notifications, only when the feature is switched on (section 7) | firebase.google.com/support/privacy |
| Google (AdMob, UMP) | optional rewarded ads, consent management | support.google.com/admob |
| Google (Google Play Billing) | payment processing on Android | policies.google.com/privacy |
| Apple Inc. / Apple Distribution International (in-app purchase, DeviceCheck, Sign in with Apple) | payment processing, authenticity checks, sign-in on iOS | apple.com/legal/privacy |
The Google and Apple services used also process data outside the European Union, in particular in the United States.
BrickRock’s database runs in a multi-region within the European Union. The server functions run mostly in a US region; one function runs in a region within the European Union. Even where data is stored in the European Union, access by the provider from a country outside the EU cannot be ruled out, since this is a group of companies with a US parent.
Such transfers are based on the EU-US Data Privacy Framework, where the recipient in question is certified, and additionally on the European Commission’s Standard Contractual Clauses under Art. 46(2)(c) GDPR. Despite these safeguards, access by authorities in third countries to transferred data cannot be entirely excluded.
You have the following rights against the controller:
A message to the contact address given in section 1 is enough to exercise these rights. Because anonymous accounts are not linked to an identifiable person, we will need details that allow us to identify the account in such cases — for example the user identifier shown in the app.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State where you live or work.
BrickRock is not aimed at children and is not designed as an offering in the “Families” category on Google Play. The app does not knowingly collect data from children below the age required under national law for valid consent (in Germany, 16 years, Art. 8 GDPR).
If you become aware that a child has created an account without their guardian’s permission, please contact the address given in section 1. The account will then be deleted.
This privacy policy is updated whenever the app, the services it uses, or the legal requirements change. The version published here is the one that applies. You will find the date of the most recent change at the top, under “Last updated”.
For questions about data protection and to exercise your rights, you can reach the controller at:
Patrick Gaida
Email: 23patrock@googlemail.com
The full postal address is given in section 1.