Brilbox operates Dungeon Merge. This policy explains how the game handles information for account access, cloud saves, Challenges, purchases, analytics and support, including the features introduced in version 1.0.36. The information processed depends on your platform and the features you use.
Information we process
- Account and authentication: Google/Apple sign-in identifiers, PlayFab account identifiers, and authentication/session credentials used to sign in and maintain access. We do not receive your Google or Apple password.
- Game and cloud-save data: progress, player level, heroes, skills, equipment, currency, purchase entitlements and play records. Cloud backup and restore transmit the relevant saved data when you use those features.
- Challenge data: your chosen nickname, entries, results, scores, ranking records and integrity/moderation information. Your nickname, score and shared run details may be visible to other players.
- Usage and diagnostics: installation/session identifiers, app version, platform, device/OS information, language, activity times, progression, battle and balance events, acquisition/conversion events, crash logs and errors. Analytics can run without signing in; when signed in, some analytics are associated with your account through hashed identifiers. Hashing does not make all such data anonymous.
- Network information: the server uses the connection IP address to estimate country and limit requests. The custom analytics store records the country and a hashed value for IP-based request limits, rather than a raw IP address. Infrastructure and third-party diagnostic logs are subject to their own settings.
- Purchases: product identifiers, purchase times, transaction identifiers and entitlement status for granting/restoring content and reflecting entitlement changes. Azure sales analytics receive hashed transaction identifiers, not raw store receipts or transaction tokens. Payments are handled by Google Play or Apple; we do not directly collect payment-card details.
- Support: your email address, message and information you choose to send when contacting us.
Why we use information
We use information to provide sign-in, save/restore, purchases, Challenge rankings and support; maintain login sessions; protect service integrity and handle abuse; diagnose problems; and understand engagement, game balance, acquisition and purchases to improve the game.
Sharing and public information
We do not sell personal information. Information is processed by the service providers below as needed to operate the game. This is separate from the Challenge information you make visible through participation in public rankings. We may also disclose information where required by applicable law.
Service providers
- Microsoft PlayFab and Azure: accounts, cloud saves, Challenge services, authentication-session support, hosting and gameplay/sales analytics.
- Google sign-in, Google Play, Firebase Analytics and Firebase Crashlytics: authentication, purchases, acquisition/conversion analytics and diagnostics.
- Sign in with Apple and Apple App Store/StoreKit: authentication, purchases, restoration and entitlement checks.
Retention
These are expiry targets for the custom Azure records, not a promise that every copy is erased at the exact expiry time. Scheduled cleanup can be delayed. Firebase, platform authentication, store records and infrastructure logs have separate retention settings and provider policies. Minimal deletion/security markers may remain to prevent duplicate processing or account reactivation.
- Account, cloud-save and Challenge data: retained to provide these features until account deletion is processed, subject to the exceptions below.
- Custom Azure presence and request-limit records: a 1-day expiry target.
- Custom Azure sales detail: a 2-day expiry target; transaction deduplication records: 60 days.
- Custom Azure gameplay analytics, account-level daily activity and buyer-level records: a 90-day expiry target.
- Custom Azure account analytics summaries: 2 years after the last observation. These summaries use hashed account identifiers and are not treated as fully anonymous.
- Sales daily aggregates without individual account identifiers: approximately 2 years.
Your choices and deletion
To delete your account, use Settings → Account Info → Delete Account in the game while signed in to the account concerned. You do not need to send your account ID separately when using this feature. If you cannot access the game, you can request deletion at [email protected]. Include the game name and your account ID if you know it. We may request additional information to identify the account and verify ownership; deletion may not be possible if we cannot verify these. Never send passwords, sign-in codes, authentication tokens or full payment-card details.
The account-deletion process requests deletion of the PlayFab account and cloud data, removes the associated Challenge profile/run data, and invalidates stored Apple sessions. Some provider-side operations complete asynchronously. Deleting a game account does not itself refund purchases or erase the store’s own transaction records.
The in-app account-deletion function does not immediately erase separately stored Azure analytics. Those records otherwise follow the retention periods above. Contact us to request deletion of related personal data; we will verify the request and explain the scope and timing of processing, including any applicable retention exception.
Depending on applicable law, you may request access, correction, deletion or restriction of processing, or withdraw consent where processing relies on consent. Contact [email protected]. Signing out does not by itself stop installation-based analytics, and opening this policy is not consent to data collection.
Security and processing locations
We use HTTPS for game-service communications and restrict access to operational systems. Providers may process information in countries other than where you live. No storage or transmission method is completely secure.
Children
Dungeon Merge is not directed at children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided personal information.
Changes and contact
We update this page when our practices change and revise the date above. Where required, we provide additional notice or obtain consent. For privacy questions and requests, contact Brilbox at [email protected].