Doorak / project document
Privacy Policy
How the Doorak mobile game processes local game data, network data, diagnostics, and voluntarily submitted materials.
- Effective:
- Updated:
This English translation is provided for convenience. If the versions differ, the Russian version prevails.
1. Scope
This Policy explains how data is handled in the Doorak mobile application
(com.orbis.doorak; the “App”) by the developer identified on the App’s store
listing (“we”, “us”).
The App works without registration and does not create a user account. As of the last updated date, the App contains no advertising or product analytics SDKs. We do not sell personal data or use it for advertising.
The App follows a local-first approach: settings, profile data, game history, and replays remain on the device by default.
2. Data we process
2.1. Local settings and profile
The App stores the following in its protected system directory:
- player name;
- language, rules, controls, sound, dialogue, and accessibility preferences;
- difficulty and other game settings;
- the user’s choice regarding optional crash reporting;
- local statistics, results, favorite games, and profile preferences.
This data is required for user-selected features and is not automatically transmitted to us.
2.2. Saves, history, and game replays
To resume games, maintain local history, and support deterministic debugging, the App may store:
- game rules and roster;
- deck and AI seeds;
- the sequence of game actions;
- game state and result;
- player names, AI roster, and local replays.
An unfinished game is kept until it is completed, replaced, or deleted. Its active save is cleared when the game finishes. The local archive retains up to the 100 most recent non-favorite replays and all replays marked as favorites. Compact facts used for lifetime statistics remain until the user resets the statistics.
Users can delete an individual replay, clear the archive, or reset statistics in Profile. A user-requested export places the selected data on the system clipboard; subsequent clipboard handling is controlled by the user and the operating system.
2.3. Local multiplayer
In local multiplayer, devices connect directly over TCP/IP. The host and room participants exchange:
- the chosen player name;
- technical peer and room identifiers;
- the host’s local network address and connection port;
- room settings, human players, and AI roster;
- game actions, game state, replays, and integrity hashes.
This data is used only to create the room, validate actions, and synchronize the game. It does not pass through a central game server operated by us. The current version does not add application-level end-to-end encryption to the local TCP connection, so local multiplayer should only be used on a trusted local network.
Room network state is removed from memory after the room closes. A game save or archived replay may remain locally on participants’ devices as described in section 2.2. We cannot delete copies retained by another participant on their device.
2.4. Camera and QR codes
Camera access is requested only after the user chooses to scan a local room QR code. Camera frames are processed on the device to recognize the room address. The App does not save photos or videos and does not send camera frames to us. A room QR code may contain a local address, port, and technical room identifier.
2.5. Optional automatic crash reports
On the first launch of an eligible build, the App separately asks for permission to send anonymized technical crash reports. Declining does not restrict gameplay, and consent can be withdrawn in Settings.
If the user consents, a report may contain:
- error type and stack trace;
- App version and build number;
- OS version, platform, and device model;
- current route and App lifecycle events;
- rules variant, player count, difficulty, and network role;
- game phase, state integrity hash, last action type, and technical presentation queue state;
- a short sanitized log of semantic events.
The report payload does not add the player name, room code, cards in hand, seed, full replay or game archive, user-authored text, screenshot, screen recording, or view hierarchy contents. Performance tracing, profiling, Session Replay, and product analytics are disabled.
Like any online service, the diagnostic service operator necessarily receives network connection metadata, including the source IP address, to deliver and secure the service. The App does not add the IP address to the diagnostic event and disables default personal identifiers.
2.6. Optional problem report
Users can open Settings → About → Report a problem. When the user explicitly submits the form, we receive:
- the selected category;
- the entered description and optional reproduction steps;
- an optional email address if the user wants a reply;
- the safe technical context described in section 2.5 if its switch remains enabled;
- a technical identifier of a related crash when the report follows one.
The form is sent only after the user presses the submit button and works independently from automatic crash-reporting consent. If technical context is disabled, only the form text, optional email, and minimum transport fields are sent. The profile name, cards, seed, game history, full replay, and screenshot are not attached.
2.7. Optional submission of games for analysis
In Profile → Local data, a user may explicitly choose Send games for analysis. Before sharing, the App describes the data and purpose and requests separate consent. No game package is transmitted without that action.
The App creates one versioned JSON file containing no more than the ten latest completed games across all modes; if fewer games are available, all available games are included. The package may include rules, deal and AI seeds, seat roster, action sequence, result, integrity hashes, and technical AI metadata. Before the file is created, every human name, including the profile owner’s name and local-room participants’ names, is removed and replaced with ordinal labels such as Player 1 and Player 2.
The package does not contain original human names, email addresses, IP addresses, room codes or addresses, device identifiers, screenshots, diagnostic logs, or contents from other apps. Network participants’ game actions remain in the replay under anonymized seat numbers because they are necessary to analyze the game.
After confirmation, the system share sheet opens and the user chooses the app and recipient. The selected email service, messenger, cloud storage, or other provider processes the file under its own policy. The developer receives the package only when the user sends it to the developer. In that case, an anonymized extract may be submitted to OpenAI through a business/API service to produce a personalized review. Under OpenAI’s published terms, business and API data is not used to train models by default. See OpenAI Business Data Privacy and OpenAI API Data Usage Policies.
3. Purposes and legal bases
We process data only to:
- provide saves, profile features, settings, QR connection, and local multiplayer;
- maintain game integrity and reproducibility;
- identify and fix crashes when the user has consented to automatic reports;
- respond to a voluntarily submitted problem report;
- produce a personalized review of recent games when separately requested by the user;
- comply with applicable law and protect the App’s security.
Where applicable law requires a legal basis, we rely on performing a feature requested by the user, the user’s consent, our legitimate interest in security and error correction, or a legal obligation. Consent can be withdrawn at any time without affecting processing that occurred before withdrawal.
4. Recipients
We do not sell or rent user data.
Data may be received by:
- Other local-room participants — only data required for direct multiplayer as described in section 2.3.
- Sentry Cloud (Functional Software, Inc.) — our processor for optional diagnostic events and problem reports. We use Sentry’s European ingestion endpoint in Germany. Sentry and its infrastructure subprocessors may process data in other countries under their stated safeguards. See the Sentry Privacy Policy and Sentry Data Processing Addendum.
- The sharing app and provider chosen by the user — only when the user explicitly opens the system share sheet for a game package. The user chooses the recipient and channel.
- OpenAI, L.L.C. and its infrastructure subprocessors — a processor of anonymized game extracts when a user sends a package to the developer for a personalized review. We use business/API services for which training on submitted data is disabled by default. See the OpenAI Privacy Policy and OpenAI Data Processing Addendum.
- Public authorities or other legally authorized recipients — only where disclosure is required by law or necessary to protect legal rights and safety.
If the project is reorganized, data may be transferred to a successor only subject to this Policy and applicable law.
5. System backups
The operating system may include App files in a device or account backup and restore them after reinstallation or transfer to another device. Such a backup is controlled by the user and the operating-system provider; the App developer does not receive it.
To permanently remove all local data, the user must clear the App’s storage in system settings and, where necessary, remove or disable the corresponding system backup. Uninstalling the App alone may not remove a platform backup or data the user explicitly chose to retain.
6. Retention and deletion
- Settings, profile data, and local statistics remain on the device until the user changes or deletes them or clears the App’s storage.
- The active save is cleared after a game is completed; archive and statistics are retained and deleted as described in section 2.2.
- Temporary local-room data is removed from memory when the connection ends.
- A temporary analysis-package file remains in the App’s system cache and is replaced on the next share; the operating system may also delete it automatically. If the user sends a package to the developer, the source package is retained for no more than 30 days, while the resulting review and related correspondence are retained for no more than 90 days unless longer retention is required by law, to protect legal rights, or to resolve an open user request.
- Diagnostic events and submitted problem reports remain in the active Sentry project for no longer than 90 days unless longer retention is required by law, to protect legal rights, or to resolve an open user request. Data is then deleted or anonymized; residual protected backups are handled by the provider until scheduled deletion.
Users can withdraw consent for future automatic reports in Settings. To
request access, correction, or deletion of previously submitted data, use
Report a problem with the Other category or the developer contact published
on the App’s store listing. Locating a specific report may require its optional
email address, approximate submission time, problem description, or the
requestId contained in a submitted game package. Without such information,
an anonymous event may not be reliably attributable to a particular user.
7. Security
Local files are kept in the App’s protected directory. Diagnostic reports are sent to Sentry over HTTPS. We minimize diagnostic data and disable screenshots, Session Replay, profiling, tracing, logs, default PII, and automatic UI/HTTP breadcrumbs. Game packages are anonymized before they are written to the temporary file. The user chooses the transmission channel and should select a trusted app; the App cannot control how the chosen provider retains the file after handoff.
No storage or transmission method is absolutely secure. Users should consider the local TCP limitation described in section 2.3 when choosing a network.
8. Children
The App does not request age or date of birth and does not create accounts. We do not seek to knowingly collect children’s personal data. If a parent or legal guardian believes that a child submitted personal data through the feedback form or game-analysis sharing without the consent required by law, they can request deletion using the method in section 6.
9. User rights
Depending on applicable law, users may have rights to request access, correction, deletion, restriction, or portability, to object to processing, or to lodge a complaint with a supervisory authority.
Most data can be viewed or managed locally through the App or device settings. A request concerning data transmitted to us can be made using the method in section 6. We may request only the additional information needed to verify and fulfil the request.
10. Policy changes
We may update this Policy when the App, providers, or legal requirements change. The current date is shown at the top. If data processing changes materially, we will provide notice or request consent again where required by law.
11. Contact
For privacy questions, use Settings → About → Report a problem with the Other category or the developer contact published on the App’s store listing.