Privacy Policy
Brutek · Last updated 4 October 2026
This Privacy Policy explains what information the Brutek game (“Brutek”, “we”, “us”) collects, how we use it, and the choices you have. By using Brutek you agree to this policy.
Information we collect
- Email address — used only to sign you in and to identify your account. Your hero is generated from your verified email.
- Game data — your hero, stats, progress, cosmetics, friends, alliance membership, and in-game messages, so your account works across sessions and devices.
- Purchase records — store customer identifiers, transaction confirmations and subscription status. Payment providers process payments; we do not receive your card details.
- Safety records — the Terms version and time you accepted, age confirmation (13 or older, not your birth date), reports and moderation decisions.
- Activity days — the calendar dates (UTC) on which your account used the game, stored with your game-account identifier. No times, location, device or advertising identifiers are recorded. On days your account is a premium member we also record that date in a separate member-days list, the same way.
- Membership events — when a membership is bought, renewed, cancelled, expires or is refunded, we record the event type, the product, the time and the provider reference, stored with your game-account identifier.
- Membership prompts — when the game shows you an offer to become a member, we count how many times each kind of prompt was shown, tapped or dismissed, and how many memberships it led to, per day. These counts are not stored with your account.
- Campaign tags — if you arrive through a link that carries campaign tags (for example from an ad or a post), we record the campaign name and the website you came from with your new account, to learn which channels bring players. We don't use advertising identifiers or share this with ad platforms.
- Error reports — when the app hits an error it sends the error message, technical details, page address and browser type, which are written to our server logs for troubleshooting. For analytics we keep only a count of reports per day.
- Bug reports — when you choose to report a bug: your description, the category you pick, an optional screenshot you choose to attach (we store a smaller re-encoded copy), and technical details to help us reproduce it: app version, platform (web or Android app), browser user agent, screen size, the screen or mode you were on, your last battle id, and up to ten recent in-game error messages. A report is linked to your hero only (or to no account if you report before signing in). Your IP address is used briefly to limit how many reports can be sent per day; it is not stored with the report.
We do not sell your personal information. The optional Town area may show clearly labelled sponsor placements.
Sponsor placement measurements
To report whether Town placements are useful, we count aggregate events such as Town opens, whether a sponsor board was viewed, sponsor-detail opens, and outbound clicks. These counts are not stored with your hero, email address, or an advertising identifier. We do not use an advertising SDK, cross-app tracking, profiling, or targeted advertising.
First-party analytics
To understand the health of the game we run our own analytics on our own servers: daily, weekly and monthly active players, how many new players return after 1, 7 and 30 days, revenue and refunds per day, the number of paying players, how many new players become members in their first week, how many members renew after their first month, the share of daily players who are members, how paying and non-paying players return, the mix of products and 30-day spend levels among paying players, how membership prompts perform, and error rates. These figures are built from the activity days, member days, membership events, purchase and refund records (provider receipt ID, product, amount and time), daily prompt counts and daily error counts described above, and are only visible to the Brutek operator as totals. We do not use a third-party analytics or advertising SDK for this, and we do not share or sell this information.
How we use it
- To create and run your account and save your progress.
- To operate gameplay features (battles, leaderboards, friends, alliances, chat).
- To deliver purchases and premium membership benefits.
- To investigate and fix bugs you report.
- To keep the service secure and prevent abuse.
- To measure overall game health and revenue with the first-party analytics described above.
Service providers
We use trusted providers to run the game. They process data only to provide their service to us:
- Supabase — sign-in / authentication and database hosting.
- RevenueCat — store purchase verification and subscription status, linked to your game account identifier.
- Stripe — processing web purchases where offered.
- Our hosting provider — runs the game servers and database.
- GitHub — our issue tracker. When we track a fix we may summarise a bug report there; we do not copy your email or account details into it.
- Apple App Store / Google Play — process in-app purchases under their own privacy policies.
Artwork includes AI-generated assets. Optional cosmetic generation, when enabled, uses artwork providers to process cosmetic descriptions and images.
Data retention & deletion
We keep account data while your account exists. You can permanently delete your account from Settings → Privacy & account → Delete account, or use our account deletion page without installing the app.
Bug reports are kept for up to 180 days, then deleted automatically.
Accepting a verified deletion request removes your hero, progress, social connections, direct and public messages, reports involving you, bug reports you sent, and battle records containing your identity. Cached opponent identities are anonymised. Your activity-day and member-day records are deleted; purchase and refund amounts and membership events remain in totals with your account identifier removed. Anonymous gameplay totals and shared game artwork may remain.
Sign-in and purchase-service deletion is requested from Supabase, RevenueCat and Stripe (where a web customer record exists). If a provider is unavailable, the request is kept with the account identifiers needed to retry until it succeeds. A technical deletion receipt, with a one-way token digest, is retained for seven days after completion so retries can confirm the outcome. One-way purchase transaction digests without account identifiers are retained to prevent the same purchase being granted twice.
Deleting a Stripe web customer also cancels its web subscription. Deleting the game account does not cancel a Google Play or Apple store subscription. Cancel it in Google Play or Apple subscription settings. Payment platforms may keep transaction records they are required to retain under their own policies and legal obligations.
Children
Brutek is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
Your rights
Depending on where you live (e.g. the EEA/UK under GDPR, or California under CCPA), you may have rights to access, correct, or delete your data, or to object to certain processing. Contact us to exercise these rights.
Changes
We may update this policy; we will revise the date above when we do. Material changes will be highlighted in the app.
Contact
Questions about privacy? Email hello@brutek.app or message @restingdev on Telegram.
Brutek is operated by HailSaint (Australia). For privacy enquiries, email hello@brutek.app or message @restingdev on Telegram.