Privacy Policy
Last updated: September 28, 2026 · Version 1.2
This policy explains what data is collected when you visit this site or take part in the private test of the game Blackout: Reborn, developed by Spirit Forge (sole proprietorship, France).
1. Who is responsible
The data controller is Spirit Forge (sole proprietorship, France). Contact: privacy@spiritforge.games.
2. Data we collect
On this site (blackout-reborn.com)
- No email address is collected by this site.
- No advertising cookies and no tracking are used on the site.
In the game
You can play as a guest, or sign in with Google or Apple, depending on your device. Either way, your device receives an automatically generated technical identifier (device-id).
If you sign in with Google or Apple, authentication is handled by Firebase Authentication, a Google service, for both providers. Firebase keeps its own user directory, holding whatever the provider passes on, your email address, and your name where the provider supplies one. Apple, for instance, does not include a name in its identity token.
In the game's own database we keep only the provider's name and the stable identifier it gives us, so we can recognise you across devices. Google and Apple, for their part, know that you signed in to this game and handle that under their own policies.
We collect:
- Game data: in-game resources and progress, in-game actions, statistics needed for the game to function.
- Display name, which you choose in the game and other players can see.
- Chat messages, with your display name. The game has two chat spaces: your faction's and a general channel. The game only displays the last seven days; beyond that, messages are hidden but remain stored. You can ask for them to be deleted.
- Push notification token from your device, if you allow notifications, so we can send them. We stop using it as soon as the notification service reports it invalid, and it is deleted along with your account.
- Device attestation: on startup the app asks your operating system for proof that it has not been tampered with, Play Integrity on Android, DeviceCheck on iPhone. This happens before any sign-in and for every player, guests included.
- App usage log: screens opened, interactions with the app, network calls, errors, performance measurements and device model, sent to our servers to diagnose failures and slowdowns. Present on Android as well as iPhone.
- Usage & diagnostic data: usage statistics and crash reports (via Google Firebase services), to understand how the game is used and fix bugs. The identifiers they carry are set out below.
- Server logs: technical data (timestamps, technical identifier, events) needed for server operation and security.
Usage statistics and crash reports carry no player identifier of ours. They do carry identifiers belonging to the measurement tools themselves, notably an installation identifier that Firebase assigns to the app on your device. So they do not name you, without our claiming that no correlation is possible.
3. Why (purposes) and legal basis
| Data | Purpose | Legal basis |
|---|---|---|
| Game data | Operate the game | Legitimate interest / service delivery |
| Usage & diagnostic | Improve the game, fix bugs | Legitimate interest |
| Server logs | Operation, security, anti-abuse | Legitimate interest |
4. Third-party providers (processors)
Some data is processed by third-party services, solely for the purposes above:
- Cloudflare, site hosting and delivery.
- Google (Firebase), authentication if you sign in with a Google account, usage statistics, crash reports, notification delivery, and device attestation (Play Integrity) for every player on Android, guests included.
- Apple, authentication if you sign in with an Apple account, and device attestation (DeviceCheck) for every player on iPhone, guests included.
- Scaleway, hosting of the game servers and their databases (France, EU).
- Hetzner, storage of the encrypted database backups, off the game server (Germany, EU).
Some of these providers (notably Google) may process data outside the EU, under appropriate contractual safeguards.
5. Retention
- Game data: for the duration of the test, deleted at the end of the project or on request.
- Chat messages: kept with no time limit as of today. The game displays only the last seven days, which hides them without erasing them. An automatic purge is being prepared; until then, deletion happens on request.
- Push notification token: kept until your account is deleted. We stop using it sooner if the notification service declares it invalid, ceasing to use it and deleting it are two different things.
- Server logs and app usage log: kept for a limited period for security and diagnostics.
6. Your rights
Under the GDPR, you have the right to access, rectify, erase, object to, and port your data. To identify you: if you signed in with a Google or Apple account, say so; if you play as a guest, include your technical identifier, which the game shows in its settings. Email privacy@spiritforge.games. You may also lodge a complaint with the French authority CNIL (cnil.fr).
7. Minors
Blackout: Reborn is intended for people aged 15 and over. We do not knowingly collect data from children under 15.
8. Changes
This policy may change. The last-updated date appears at the top.
9. Contact
Spirit Forge, privacy@spiritforge.games