1. Scope and operator
This policy covers the app, this website and support inquiries. Our operator details and contact information appear on this page. External services also have their own policies.
2. Records on your device
You can play without an account. Cards, seals, decks, achievements, pending rewards, settings and backup copies are stored locally. Battles and journeys in progress are not saved. Deleting a cloud account does not remotely erase local records.
3. Optional sign-in and backups
You may link a Google account. Apple is available only in supported builds where that option appears. Firebase Authentication processes identifiers, email, authentication and connection information, and provider-supplied profiles such as display names and photo URLs. The app does not use profile photos for its own features.
After linking, follow the prompts to choose the records to continue with; automatic backup then starts. Changes to cards, seals, decks and achievements are saved in Firestore, with failed uploads retried. You can disable automatic progress backups or save manually. Backups include some settings, a random device identifier, timestamps, revisions and integrity information. Records from different devices are not automatically combined; restoring requires your choice.
4. Optional usage analytics
App analytics is off by default. With permission on each device, Google Analytics receives screens, tutorial progress, battle and collection results, seal changes, action outcomes, and app/device information to improve usability and understand usage.
We do not attach names, emails, custom deck names or save files, or link the authentication user ID to analytics. SDK installation identifiers mean reports are not completely anonymous. We do not use advertising IDs, serve ads or personalize advertising. You can stop analytics in settings.
5. Diagnostics and notices
Diagnostics has separate, optional consent and is off by default. If enabled, Firebase Crashlytics processes error categories, code locations, app/OS/device information and installation identifiers for troubleshooting. App-reported Dart exception messages are replaced by categories; we do not add names, emails or saved progress. Not all OS/SDK diagnostic information can be removed.
Choosing to fetch notices contacts Firebase Remote Config, which processes installation identifiers and related information. It does not change battle rules, rewards or draws.
6. Website and support
Optional analytics on the KAMOSUBI landing and policy pages stays off until you allow it. If accepted, page views, device/browser information and analytics identifiers help improve the site. Your choice is stored in localStorage and can be changed or withdrawn through “Website analytics settings” in the footer. Google, our Firebase App Hosting provider, processes ordinary connection logs, including IP addresses, to deliver and secure the site.
Optional analytics uses cookies to measure visits and clicks. Withdrawal stops further reporting. You can remove existing analytics cookies in your browser settings.
Support uses your reply address, message and optional attachments to respond, investigate, verify identity and address rights requests. Do not send passwords, authentication codes, save files or unnecessary information.
7. Providers and overseas processing
We use Google services for sign-in, backups, analytics, diagnostics, notices and web hosting. Providers may process information outside Japan, including in the United States. Japanese storage locations do not mean all processing stays in Japan. We review provider policies and terms and handle information under applicable law.
We do not sell information or disclose it without a lawful basis, such as service-provider processing, consent or legal requirements. We use protections including encrypted connections and access controls.
8. Retention and deletion
Local records remain until you clear app data, delete the app or otherwise remove them. Manage OS backups separately. Cloud records remain until individual or account deletion. Google states that removal of Firebase Authentication data from its systems and backups may take up to 180 days after deletion is requested.
We retain only the deleted account identifier and deletion status to prevent delayed uploads from restoring deleted records. This marker contains no saved-game content and currently has no automatic expiry. You may contact us about the need to retain it.
GA user/event retention follows the service settings; aggregate statistics have different conditions. Google begins deleting Crashlytics data after 90 days. Support records are deleted when no longer needed for the inquiry, disputes or legal obligations. Stopping collection or deleting an account does not erase every report already sent.
9. Your information rights
Contact us to request information about purposes, access, correction, deletion, restriction or withdrawal of consent as provided by applicable law. We verify identity as necessary and respond under that law. Where available, you may also contact or complain to the competent supervisory authority.
Because analytics and diagnostics are not linked to authentication user IDs, we may be unable to identify particular reports. We will explain limitations and available action. See the account deletion page for instructions.
10. Minors
Minors must obtain parental or guardian consent where applicable law requires it. If you cannot legally consent to optional reporting yourself, leave it disabled and consult your guardian. Contact us if you believe a child submitted information without required consent; we will investigate and take appropriate action, including deletion where required.
11. Changes
We update the effective date when this policy changes. Material changes affecting purposes or rights will be announced in advance on the site or in the app; we will obtain fresh consent where legally required.
