Hatchkeep Privacy Policy
Effective date: September 27, 2026 Operator: Joshua Green, United States Contact: joshgreen4515@gmail.com
1. What Hatchkeep is
Hatchkeep is a creature-building game. You raise creatures from parts, fight stages, and can release copies of your creatures into a shared pool ("the Wilds") where other players meet them. This policy says what data the game collects, why, who else handles it, and how to get it deleted.
2. What we collect
Account
- A guest account is created the first time you open the game. It is an anonymous sign-in with Google Firebase Authentication. We store its identifier and a player id of our own.
- If you attach an email address, Firebase stores the address and a hashed password. We store only the Firebase identifier; we never see your password.
- If you sign in with Steam, or link Steam to an existing account, we store your 64-bit Steam id. The sign-in is a Steam session ticket that our server verifies with Valve.
- If you sign in with Google (on Android), or put your Google account on a guest account, Firebase stores the identifier Google issues for the game and the email address, name and picture on that Google account. We store only the Firebase identifier. Sign in with Apple will work the same way when it is offered.
- Your keeper name, which you choose. It is shown to other players on released creatures, rankings and reports.
Game data
- Your creatures, parts, builds, research, expeditions, currencies (Chitin, Essence, Amber), stage results, subscription tier, and cosmetics owned and worn.
- Released creatures. When you release a creature into the Wilds, a copy of its build and your keeper name become visible to other players, who fight it and can view your keeper page. Recalling a creature removes it from the pool.
- Reports. If you report another player's creature or name, we store the report and which account filed it.
Purchases
- Purchases are made through the Apple App Store, Google Play or Steam. **We never receive card numbers or billing addresses.**
- On phones, RevenueCat processes store receipts for us. RevenueCat and we receive: the product bought, the time, the store's transaction and subscription identifiers, and your player id (used as RevenueCat's app user id).
- On Steam, Valve tells our server that an order was approved and for which Steam id.
Rewarded ads (phones only, off by default)
- The game shows no ads unless you turn on Rewarded offers on your keeper page (tap your name at the top left). Until then the ad SDK is not even started.
- When on, Google AdMob shows the ads. Google collects the device's advertising identifier, IP address, and device and app information under Google's own policy (https://policies.google.com/privacy). You can reset or limit the advertising identifier in your phone's settings.
- When you finish an ad, Google sends our server a signed message containing your player id and which reward it was for. That is the only thing our server learns from an ad.
Technical
- Our servers log the IP address, time, and path of each request, for 30 days, to keep the service running and to investigate abuse.
- Gameplay events (for example a stage started, a creature hatched, a purchase completed) are recorded against your player id. Today they are kept only in our server logs; there is no third-party analytics SDK in the game. If that changes, this section will name the provider.
- The game stores settings (such as the Rewarded offers switch) on your device only.
Bug reports
- If you send a report from Options > Report a problem, we store what you wrote, the category you picked, the game's version, your device model and operating system, your player id, and the email address on your account if it has one. The report is emailed to us through Resend so we can read it and, if your account has an email, reply to you.
3. Why we process it
- To run the game you asked for (your account, progress, the Wilds, purchases): performance of our contract with you.
- To keep the service and other players safe (rate limits, abuse investigation, report handling, purchase verification): our legitimate interest.
- To show rewarded ads: your consent, given by turning offers on and withdrawn by turning them off.
4. Who else handles your data
| Provider | What it does | Where |
|---|---|---|
| Google Firebase Authentication | Sign-in and account identity | United States |
| Neon (PostgreSQL on AWS) | The game database | AWS us-west-2, United States |
| Fly.io | Runs our game servers | San Jose, United States |
| RevenueCat | Processes App Store and Play receipts | United States |
| Apple, Google Play, Valve (Steam) | Sell the game's products; their own policies apply | — |
| Google AdMob | Shows rewarded ads, only if you turn them on | United States |
| Resend | Delivers bug reports you send to our inbox | United States |
We do not sell personal data. We do not share it with anyone else except when the law requires it.
Other players can see: your keeper name, your title and frame, and the creatures you have released, including their build and the cosmetics they wear.
5. How long we keep it
- Your account and game data: until you delete the account.
- Server request logs: 30 days.
- Purchase records: as long as required for tax and dispute purposes, 7 years.
- Reports on other players' Wilds: until resolved, then 90 days.
- Bug reports you send: until you delete the account.
6. Deleting your account
- In the game: tap your name at the top left to open your keeper page, then Delete account under Account, and type DELETE to confirm. It takes effect at once.
- If you can no longer open the game: email joshgreen4515@gmail.com from the address on the account, or include your keeper name and player id, and we will delete it within 30 days.
- Deletion removes your account, creatures, progress, currencies, cosmetics and purchase entitlements from our servers, and deletes the Firebase sign-in behind it. Creatures you released into the Wilds are anonymised, not removed: the build stays in the pool with no keeper name attached, because other players' stage histories reference it.
- Deleting the account does not cancel a subscription. Cancel it in the App Store, Google Play or Steam; those stores control billing.
- Steam, Apple, Google, RevenueCat and AdMob keep whatever their own policies say about the data they collected.
7. Your rights
Depending on where you live (including the EU/EEA, the UK, and California) you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict processing, and to complain to a supervisory authority. Write to joshgreen4515@gmail.com; we answer within 30 days. We do not discriminate against anyone for exercising these rights.
8. Children
Hatchkeep is not for children under 13 (or the higher age your country sets for consent to data processing). We do not knowingly collect data from them. If you believe a child has an account, email joshgreen4515@gmail.com and we will delete it.
9. Changes
We will post changes here and update the effective date. If a change matters (a new provider, a new kind of data), the game will tell you when you next open it.