Privacy Policy
Overview
Mooncall ("the Game") is published by RootNode Oy ("we", "us", "our"). We respect your privacy and are committed to protecting it. This policy explains what data we collect, why, how we use it, and your rights.
The short version: We collect pseudonymous gameplay data to run online leaderboards and improve the game. We do not collect your real name, email, precise location, or any data that directly identifies you. You can control online leaderboards and gameplay telemetry independently — see Section 5. Error reporting is always active when an internet connection is available (see Section 1.4). If you choose to share a party with friends online, that party's scoreboard is kept on our servers for a limited time and is visible only to people you gave its join code (see Section 1.5). If you are signed in to your platform account (Steam, Google Play Games, Apple Game Center), a copy of your save file is stored in your own account's cloud storage by that platform. It never passes through our servers.
1. Data We Collect
1.1 Player Identifier
When you first play the Game, a random unique identifier (UUID) is generated and stored locally on your device. This ID is used to associate your scores with your device and prevent duplicate leaderboard entries. It is not linked to your real identity.
1.2 Leaderboard Scores
Online leaderboards are a core feature of the Game. When you submit a score, data must be transmitted to our servers to verify score legitimacy and display rankings. We collect:
- Your chosen display name: either a name you enter yourself (up to 16 characters) or a gamer nickname from your platform, whichever you choose to use. No real name is ever required or requested.
- Platform username (e.g., your Steam, Google Play, or Apple Game Center display name), if you chose to link it — stored separately from your chosen display name
- Game score, rescued count, mushroom count
- Game duration, shields remaining, upgrade level
- Whether you used walker mode
- Extenders placed count
- Difficulty level
- Device locale (e.g., "en", "fi")
- Game version and platform (e.g., Steam, iOS, Android, Web)
Your chosen display name (entered name or gamer nickname) is publicly visible on leaderboards. You control what is displayed — you can change it at any time in the Game's settings.
1.3 Gameplay Telemetry (Optional)
If online features are enabled (they are on by default, and you can turn them off — see Section 5.1), we collect a pseudonymous session summary after each completed game, other than a game played in a party (see Section 1.5), to improve game balance, detect bugs, and verify score legitimacy. Each summary includes:
- Score and score breakdowns by source (asteroids, ship's direct fire, ship turrets, extender turrets, rescues, mushrooms, other)
- Game duration and time distribution (flying, walker mode, parked in the landed ship)
- Rescue counts and mushroom breakdown (total, red, cyan)
- Asteroids destroyed count, asteroid kill counts by source (ship's direct fire, ship turrets, extender turrets, walker), and bullet fire rate
- Phase statistics: how playtime is split between flying, walking, and parked over the course of the run (in coarse time buckets), and kill/score totals for the early, middle, and end phases of the run
- Upgrade progression (highest upgrade level, total upgrades unlocked)
- Extender statistics (lost, shut down, maximum chain length)
- Total temporary effects triggered
- Death mode (how the game ended)
- Input method used (keyboard, gamepad, touch)
- A random session identifier (distinguishes one game session from another; not linked to your real identity)
- Your chosen leaderboard display name, if you have set one
- Game version, difficulty, and platform (e.g., Steam, iOS, Android, Web)
- Device locale (e.g., "en", "fi") — used for aggregate language statistics
- Operating system category (e.g., "Windows", "macOS", "iOS") and detailed OS string (e.g., "Windows 10 Pro 10.0.19045") — used to identify platform-specific bugs and optimize performance
- GPU renderer name (e.g., "ANGLE (Intel HD Graphics)") — obtained from WebGL; used to diagnose rendering issues and ensure compatibility across hardware
- Country (derived server-side by Cloudflare from your connection, not from GPS or precise geolocation) — used only in aggregate geographic statistics; your individual country is not displayed or shared
We do not collect individual in-game events, performance samples, timestamps of specific actions, or a hash of your settings. Only the aggregated session summary described above is transmitted.
Why we need the operating system and graphics details. These two fields are the ones we are asked about most, so it is worth being plain about why they are collected rather than leaving it to a one-line purpose:
- Operating system. A large share of faults happen on one operating system and not others — a crash that only occurs on a particular Windows build, or a control that behaves differently on macOS or on the Steam Deck's Linux. When a report arrives without the operating system, there is nothing to reproduce it on, and the fault stays unfixed for everyone it affects. We also use the operating system counts to decide which platforms are worth continuing to support: if a platform turns out to have no players at all, we would rather stop maintaining it honestly than claim support we do not test.
- Graphics hardware. Rendering faults and performance problems are very often specific to one graphics chip or driver — an effect that draws incorrectly, or a frame rate that collapses, on that hardware and nowhere else. The renderer name is what makes such a report actionable; without it, "the game looks wrong" cannot be traced to anything.
Neither field is used to profile you, and neither is combined with any other source to identify you. They are collected because the alternative is being unable to fix faults that we can see are happening but cannot locate.
Accessibility display modes — counted only, never stored against you. Separately from the session summary above, we count how many sessions use each accessibility display mode: the selected colorblind palette (none, deuteranopia, protanopia, or tritanopia), high contrast mode, and flash reduction. Because these settings can reflect personal circumstances, they are handled differently from everything else on this page:
- They are never stored against your session or your player ID. No record exists that links an accessibility setting to you.
- We keep only a daily count per combination of modes, per game version and platform — for example, "on 12 August, 4 sessions on Windows used the deuteranopia palette with flash reduction on". Once counted, there is nothing to trace back.
- We use this solely to decide whether these features are used enough to keep developing. Turning telemetry off (Section 5.1) stops this counting too.
Telemetry data is pseudonymous — it is associated with your random player UUID, not your real identity.
1.4 Error Reports (Always Active)
The Game automatically reports software errors to our servers whenever an internet connection is available, so we can identify and fix bugs. Error reporting is not controlled by the leaderboard or telemetry settings — it is always active to ensure we can detect and resolve issues that affect all players, including those who play offline.
If no internet connection is available, error reports are silently discarded — they are not queued or retried.
Each report may include:
- Error message and stack trace (technical details about what went wrong)
- Game version and platform
- Source file location (file name, line number, column number)
- Additional context about the error (e.g., which game system was active)
- Your player UUID (if available at the time of the error)
Error reports are pseudonymous — they contain technical diagnostic information and your random player UUID (when available), but are not linked to your real identity. Reports are capped at 20 per session, deduplicated (the same error is only reported once per session), and do not block gameplay. Reports are automatically deleted after 30 days.
1.5 Shared Party Data (Optional)
A party is a competition among friends on a shared scoreboard. By default a party is local to one device and no party data is sent to us at all. (Error reporting, described in Section 1.4, behaves during party play exactly as it does at any other time. Gameplay telemetry, described in Section 1.3, does not: no session summary is sent for a run played in a party, because a party run can start with a boost and can be time-limited, so party runs would distort the figures that describe normal play.) If you choose to share a party online, or join one a friend shares with you, that party's scoreboard is kept on our servers so everyone in it can see the same results.
This is off unless you turn it on for a given party. When you do, we store:
- The party's name and settings (chosen difficulties, time limits, starting boost) and its join code
- The join password, if the creator set one — stored only as a hashed value, so we cannot read the password itself
- Your player UUID, to record that you are a member of that party
- For each run you play in the party: the name you entered for that run, your score, rescues, mushrooms, upgrades, run length and difficulty, and which platform and control method (keyboard, gamepad, touch) you played it with
- Which one-time party milestones you were first to reach
We count these rows to see how much shared parties are played, by how many people, with which settings and on which platforms and controls. That counting is done on the party database alone and produces totals only — never a list of who played what. Because a shared party has to reach our servers in order to work at all, these counts include players who have gameplay telemetry turned off; the setting is not bypassed and nothing extra is collected to make this possible, it is the same party rows listed above.
Party results are kept separately from the global leaderboard, in a different database. They never appear on the global leaderboard and are never public.
Who can see it: only people holding that party's join code — and its password, if the creator set one — which means whoever the creator chose to share it with. Every party has a member limit, chosen by its creator from a fixed set of sizes when the party is made. Because the code is what grants access, anyone the code is passed on to can see the party's results; share it only with people you intend to play with.
The name on each run is text you type, per run. It is shown to everyone in the party, so do not enter anything you would not want them to see.
How long we keep it: party data deletes itself. A party ends when its creator ends it, or 30 days after it was created at the latest. Its results stay available for roughly 30 more days so members can look at them, and are then permanently deleted from our servers, along with the membership record and the milestones. A party board you have opened is also saved on your own device, and that copy stays until you delete it.
Shared parties work independently of the Online Leaderboards setting. You can create or join a shared party with online leaderboards turned off, because a shared party cannot function without reaching our servers — that is what the join code connects to. When you do, the Game tells you so at the moment you create or join, and what is sent is exactly the party data listed above and nothing else. Your runs in that party still do not go to the global leaderboard, and turning online leaderboards off still means none of your solo scores are submitted. A party you never share stays entirely on your own device.
1.6 What We Do NOT Collect
- Real names, email addresses, or phone numbers
- Precise location data (GPS coordinates, street address, or IP-based geolocation beyond country level)
- Device identifiers (IDFA, GAID, IMEI)
- Photos, contacts, or any data from other apps
- Payment information (handled entirely by the platform: Steam, Apple, Google)
- Advertising identifiers
- IP addresses — never stored alongside your scores, session summaries, party data or error reports, and never linked to your player UUID. Your connection's address is used to make the HTTPS connection, is what Cloudflare derives your country from server-side (see 1.3), and is held briefly in an abuse-prevention counter, so that a party join code cannot be guessed by brute force and score sessions and error reports cannot be flooded. That counter holds nothing but a tally, and expires about a minute after your last request.
2. How We Use Your Data
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Player UUID | Leaderboard deduplication, score attribution, anti-cheat | Contract performance |
| Display name (entered name/nickname) | Public leaderboard display | Contract performance |
| Platform username | Public leaderboard display (if linked by player) | Contract performance |
| Leaderboard scores & gameplay stats | Public leaderboard display, score verification | Contract performance |
| Shared party membership and results (party name and settings, join code, your per-run name, run statistics) | Running a private party scoreboard you chose to create or join | Contract performance |
| Shared party platform and control method, counted in aggregate | Seeing how much shared parties are played and on what, so the feature can be maintained and its limits (such as the member cap) set sensibly | Legitimate interest |
| Join password (stored hashed) | Limiting a party to the people its creator invited | Contract performance |
| Session summaries | Game improvement, balance tuning, score legitimacy | Legitimate interest |
| Device locale | Aggregate language statistics | Legitimate interest |
| OS category & detailed OS string | Platform-specific bug diagnosis, performance optimization | Legitimate interest |
| GPU renderer name | Rendering issue diagnosis, hardware compatibility | Legitimate interest |
| Error reports (message, stack trace, context) | Bug detection and resolution | Legitimate interest |
| Country (coarse) | Aggregate geographic statistics for game development | Legitimate interest |
| Accessibility display modes (colorblind palette, high contrast, flash reduction) — daily counts only, never linked to a session or player | Measuring whether accessibility features are used enough to keep developing | Legitimate interest |
| Save-file copy in your own platform account's cloud (Steam Cloud / Google Drive app data / iCloud) | Restoring your profile across your own devices | Contract performance |
| Per-run gameplay counters sent to Google Play Games (Android, signed in, Telemetry on) | Play Games profile stats shown on your own Gamer profile | Legitimate interest |
We do not use your data for advertising, profiling, or sale to third parties. No accurate location is ever transferred or stored.
Online Connectivity
The Game has five types of online communication, each serving a different purpose:
- Online leaderboards (controllable — see Section 5.1): Score submission, verification, and display of global rankings
- Gameplay telemetry (controllable — see Section 5.1): Pseudonymous session summaries for game balance improvement
- Error reporting (always active): Pseudonymous diagnostic reports sent when an internet connection is available (see Section 1.4)
- Platform cloud save (a save feature, not analytics, and not controlled by the Telemetry setting): a copy of your save file stored by your platform in your own account's cloud storage, so your profile survives a device change (see Sections 3 and 4)
- Play Games gameplay events (Android only, and controlled by the Telemetry setting — see Section 5.1): per-run gameplay counters sent to Google when you are signed in to Google Play Games (see Section 4)
You can disable leaderboards and telemetry independently in Settings. The Game remains fully playable with both disabled — only online rankings and score submission are unavailable. Error reporting cannot be disabled separately, but contains only pseudonymous technical data.
3. Data Storage & Retention
- Where: All server-side data is stored on Cloudflare Workers + D1 (Cloudflare's global edge network). Data may be processed in any Cloudflare data center worldwide.
- Encryption: All data is transmitted over HTTPS (TLS 1.2+). Data at rest is managed by Cloudflare's infrastructure security.
- Retention:
- Error reports: Automatically purged after 30 days
- Session summaries: Retained in pseudonymized form for long-term game balance analysis. Because summaries are not linked to any real identity and are used for aggregate statistical purposes, permanent retention is proportionate to the purpose.
- Leaderboard scores: Stored for as long as the leaderboard service is operational
- Shared party data (Section 1.5): Deleted automatically. A party ends when its creator ends it, or 30 days after creation at the latest; its results remain readable for roughly 30 days after that, and the party, its membership records, its results and its milestones are then permanently deleted. Nothing is retained afterwards.
- Aggregate daily snapshots: Stored permanently. These contain only statistical averages and counts grouped by date, version, and platform — no individual player data. Geographic and language breakdowns are included as aggregate counts only.
- Accessibility mode counts (Section 1.3): Stored permanently as daily totals. These are counts only, with no link to any session or player, so they cannot be exported or deleted on request — there is no record of your settings to retrieve or remove. Disabling telemetry stops any further counting.
- Local data: Game settings, save data, and cached scores are stored locally on your device using platform-standard storage (localStorage, app sandbox, etc.). If you are signed in to Steam, Google Play Games, or Game Center, a copy of your save file is also stored by that platform in your own account's cloud storage (Steam Cloud, your Google Drive app data, or your iCloud), so your profile survives a device change. That copy is stored by the platform, not by us — it is never sent to or through our servers. You can erase the local save and that cloud copy from inside the Game; see Section 5.4.
4. Data Sharing
We do not sell, rent, or share your data with third parties, except:
- Other members of a shared party: if you choose to share a party online or join one (Section 1.5), the name you enter for each run and that run's results are shown to everyone holding that party's join code. This is the purpose of the feature, it applies only to parties you opt into, and it is limited to that party — nothing from it reaches the global leaderboard or any other player.
- Cloudflare: Our hosting provider processes requests and stores data on our behalf. Cloudflare acts as a data processor under our instructions. See Cloudflare's Privacy Policy.
- Platform services: If you use Steam, Apple Game Center, or Google Play Games features, those platforms may collect data according to their own privacy policies. We do not control or have access to data collected by these platforms. Your platform display name (if you choose to use it as your leaderboard name) is provided to us by the platform — we store it only for leaderboard display purposes.
When you use platform cloud save, your save file is stored by the platform in your own account as described in Section 3. On Android, if Gameplay Telemetry (Section 5.1) is on and you are signed in to Google Play Games, the Game also sends Google a summary of each completed solo run — gameplay counters such as score, rescues, mushrooms, survival time and difficulty, and never your name, player ID, locale, country, device details or accessibility settings. Google associates these with your Play Games identity and uses them to show stats on your Gamer profile. That data is held by Google under your own Google account and Google's privacy policy.
5. Your Rights
5.1 Control Online Features
The Game provides two independent settings to control online data transmission:
Online Leaderboards (Settings > Privacy > Online Leaderboards):
- When OFF: No scores are submitted to or fetched from our servers. The Game uses a local-only scoreboard stored on your device. Shared online parties remain available, because they cannot work without a server; if you choose to create or join one while this setting is off, the Game says so at that moment and only the party data in Section 1.5 is sent. Your runs still never reach the global leaderboard.
- When ON (default): Scores are submitted for verification and displayed on global leaderboard rankings. Sharing a party is a separate choice made per party; this setting does not share anything by itself.
Gameplay Telemetry (Settings > Privacy > Telemetry):
- When OFF: No session summaries are sent to our servers, and no gameplay events are sent to Google Play Games. Platform cloud save is not affected — it is a save feature, not analytics.
- When ON (default): Pseudonymous session summaries are sent after each completed game, other than a game played in a party (Section 1.5), for game balance improvement, and, on Android while signed in to Play Games, per-run gameplay counters are sent to Google (Section 4).
Both settings are stored locally and take effect immediately. The Game remains fully playable with both disabled. You can re-enable either setting at any time.
Note: Pseudonymous error reporting (Section 1.4) is always active when an internet connection is available and is not affected by these settings.
5.2 Access & Export Your Data
You can request a full export of all data associated with your player account directly from the Game:
- In-game: Settings > Privacy > Export My Data
This will retrieve all data stored on our servers (leaderboard scores, session summaries, error reports, and your shared party memberships, party results and milestone claims) and present it to you in JSON format. The export uses your device's player UUID automatically — you do not need to know or enter the UUID yourself. To prevent abuse, data exports are limited to once per 30 days per player.
You may also contact us at [email protected] to request a data export manually.
5.3 Delete Your Data
You can request deletion of all server-side data associated with your player account:
- In-game: Settings > Privacy > Delete My Data
This action requires confirmation and will permanently remove:
- All leaderboard scores
- All session summaries
- All error reports
- Your membership of any shared party, and every party result you submitted
Milestone claims you made in a shared party are not removed but are stripped of any link to you, so the other members' scoreboard does not silently gain unclaimed milestones. A party you created keeps working for its other members until it expires normally, with your identity as its creator erased.
After deletion, your online leaderboard history cannot be recovered. Local save data and settings on your device are not affected — including any party scoreboard already saved there, which only you can see and only you can remove.
This deletion covers the data on our servers only. The copy of your save file held in your own platform account's cloud (Section 3) is stored by Steam, Google or Apple under that account, and is removed by deleting the game's saved data there, or by deleting your save in the Game (Section 5.4). Gameplay stats already recorded by Google Play Games (Section 4) are held by Google under your own Google account and are removed through your Google account controls, not through the Game.
When you request deletion through the Game, your data is scheduled for permanent removal after a 7-day grace period. During this period you can cancel the request in Settings > Privacy and your data will be fully restored. After 7 days, deletion is carried out automatically and cannot be reversed. You may also contact us at [email protected] to request deletion manually; manual requests are processed within 30 days.
5.4 Delete Your Save
Your save file is not data we hold. It lives on your device and, while you are signed in to your platform account, as a copy in that account's own cloud storage (Section 3). Neither ever reaches our servers, so neither is covered by the deletion in Section 5.3. The Game lets you erase both yourself:
- In-game: Settings > Privacy > Delete My Save
This action requires confirmation and permanently erases:
- The save on this device — your progress, personal records, unlocks and in-game achievements
- The copy of your save in your own platform account's cloud
- On Steam, the gameplay statistics Steam holds for the Game on your account (lifetime totals and personal bests)
Steam achievements you have already earned are not withdrawn. Gameplay stats already recorded by Google Play Games (Section 4) cannot be removed this way — they are held by Google under your own Google account and are removed through your Google account controls.
Your leaderboard scores are unaffected: those are held on our servers and are removed through Section 5.3 instead. Deleting your save cannot be undone, and the Game starts a new local profile afterwards.
5.5 Data Portability
Your data export (Section 5.2) is provided in a standard, machine-readable JSON format, fulfilling your right to data portability under GDPR Article 20.
5.6 Right to Object
Under GDPR Article 21, you have the right to object to processing based on legitimate interest.
You can exercise this right by disabling online leaderboards and gameplay telemetry independently in Settings (see Section 5.1). With both disabled, no scores or session summaries are sent to our servers, and no per-run gameplay counters are sent to Google Play Games. Shared party data (Section 1.5) is sent only for a party you actively choose to create or join, and stops entirely once you stop using the feature.
Pseudonymous error reporting (Section 1.4) remains active when an internet connection is available. Error reports contain technical diagnostic data (error messages, stack traces, game version) and your random player UUID when available, and are not linked to your real identity. We rely on legitimate interest for error reporting because timely bug detection is essential to maintaining game quality and stability for all players, and the data is limited to pseudonymous technical diagnostics with automatic 30-day deletion.
If you have concerns about our legitimate interest assessment, contact us at [email protected]. We will cease the contested processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
6. Children's Privacy
Mooncall does not knowingly collect personal information from children under 13 (COPPA and Finnish implementation of GDPR Article 8). As the developer is based in Finland, Finnish law applies — Finland has set the age of digital consent at 13 under its national implementation of the GDPR. Players in other countries may be subject to different age thresholds under their local implementation of the GDPR (ranging from 13 to 16 depending on the country), but the Game's data practices are designed to comply with the strictest applicable standard.
The random player UUID used for leaderboard deduplication qualifies as an "internal operations" identifier under COPPA and does not constitute personal information collection requiring parental consent.
Platform accounts and their cloud-save and profile features (Steam, Google Play Games, Apple Game Center/iCloud) are governed by the platform's own age requirements and parental controls.
The Game:
- Has no chat, messaging, or social features
- Has no advertising
- Does not share data with advertisers
- Does not request or store real names, emails, or other personal details
- Only displays a player-chosen display name or a gamer nickname on leaderboards (never a real name)
7. International Data Transfers
Data is processed on Cloudflare's global network, which includes data centers in the European Economic Area (EEA), the United States, and other countries. Cloudflare participates in Standard Contractual Clauses (SCCs) for international data transfers from the EEA. See Cloudflare's Data Processing Addendum.
8. Changes to This Policy
We may update this privacy policy from time to time. The "Last updated" date at the top of this page indicates when it was last revised. If we make material changes, we will notify you through an in-game notice.
9. Contact
For privacy inquiries, data requests, or questions about this policy:
- Email: [email protected]
- Data Controller: RootNode Oy (Y-tunnus 3589808-4)
- Location: Kirkkonummi, Finland
10. Supervisory Authority
If you are in the European Economic Area and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection supervisory authority. In Finland, this is the Office of the Data Protection Ombudsman (tietosuojavaltuutettu):
- Website: https://tietosuoja.fi/en/
- Email: [email protected]