Privacy Policy

Last updated: 19 August 2026 · Smash Cards game and website

The short version

1. Who we are

Hola Ash makes and runs Smash Cards, a real-time card battler, and the website at aswinmurali.dev. We decide what the game collects and we're answerable for it.

We're a small independent studio, so we don't publish a postal address. Email is how you reach us for anything on this page, including formal privacy requests and complaints: mail@aswinmurali.dev.

2. What we collect

This is the real list — what the game actually stores, not a catch-all "we may collect" hedge.

Your account

Your email address, and your password stored only as a scrambled hash we can't reverse. Your display name, which other players see. If you sign in with Google or Apple Game Center, the account id those services give us so we recognise you next time. Sign-in tokens, how many times you've signed in, your login streak, and when you last played.

Your progress

Your cards, lineup and decks. Arena rank, league, XP, battle pass, achievements, tutorial progress. Gem and coin balances and how they changed. Match history and per-card win/loss records. Your guild, your friends list, and whether you're online right now.

What you write

Guild and direct chat messages, with who sent them and when, so conversations survive between sessions. Messages and display names run through an automatic profanity filter. Don't put anything private in chat — other players in the channel read it, and we can read it when investigating abuse reports.

Your device

A device identifier, your platform (iOS, Android or desktop) and app version, and your IP address in our server logs. Your push notification token, if you allow notifications. When the game crashes, a crash report with your device model, OS version, and what the app was doing. App start times and network timings, so we can find what's slow. Your device's advertising ID, used by the ad system in the next section.

How you play

Gameplay events like finishing the tutorial, opening the store or completing a match, recorded with the time, your user id, device id, platform, level and league. This tells us which parts of the game work and which don't.

What you buy

Which item, when, the price the store showed, and the receipt id from Apple or Google. Plus a lifetime-spend figure used for support and economy balancing.

We never see your card number, bank details, or billing address. Apple and Google handle payment entirely. We only get a receipt saying a purchase happened, which we verify before granting your items.

3. Ads

Smash Cards shows rewarded ads only, and only when you ask for one.

Win a match and the victory screen offers a "2× — Watch ad" button. Tap it, watch the video, and your coins and gems double. That's the only advertising in the game — no banners, no interstitials, nothing between matches. Never tap it and you'll never see an ad, and the rest of this section won't apply to you.

Who serves them

Ads come through AppLovin MAX, which fills each slot from a pool of ad networks. When you watch one, AppLovin and the network that won the slot receive your device's advertising ID, your IP address and rough country, your device and app details (model, OS, language, screen size, app version), and whether you watched the ad through or dismissed it.

They may use that to pick which ad to show you, to check ads are working, and to personalise advertising — including in other apps you use. We don't get a profile back, and ad data changes nothing in your game except granting the doubled reward.

We're paid for ads being watched, not for your data. But some privacy laws still count handing an advertising ID to an ad network as "selling" or "sharing", which is why you can switch it off.

Switching it off

AppLovin's own policy, listing the networks it works with, is at applovin.com/privacy.

4. What we don't collect

This list matters as much as the one above. Smash Cards never asks for:

The app asks only for internet access, network status, vibration, notifications if you allow them, and — on iPhone, before any ad is personalised — ad tracking permission. There's no marketing or install-tracking SDK, and no ad network beyond the optional rewarded ads above.

5. Why we use it

European law asks us to name a lawful reason for each use. Here they are. India's DPDP Act treats the first four rows as things you agreed to at signup, and the rest as legitimate uses for running the service.

What we use your data for
WhyWhat we useOur basis
Create your account and sign you inEmail, password hash, linked sign-ins, session tokensContract
Run the game — save progress, find you opponents, rank youProgress, match history, rankContract
Deliver purchases and handle refundsReceipts, transaction ids, wallet ledgerContract
Chat, friends, guildsMessages, friends list, online statusContract
Keep the game working — fix crashes, watch performanceCrash reports, timings, device model, OSLegitimate interests
Balance the game and see which features get usedGameplay events, level, league, platformLegitimate interests
Stop cheating, fraud, abusive chat, duplicate accountsDevice id, IP, chat content, purchase recordsLegitimate interests
Send push notificationsPush token, device idConsent
Show a rewarded ad when you ask for oneAdvertising ID, IP, device and app info, ad interactionsConsent
Answer your support and privacy requestsWhatever identifies you and fixes the problemLegal obligation

Where the basis is legitimate interests, we've weighed a stable, fair game against your privacy and kept to the minimum that achieves it — and you can object. Where it's consent, you can withdraw any time: turn off notifications in your device settings, or stop tapping the ad button.

6. Who else sees it

We don't sell your personal data for money. We share it only with the services that make the game work, and only what each one needs. The single case some laws count as "selling" or "sharing" is the optional ad system in section 3 — which you can switch off.

Who receives what
WhoWhat they getWhy
Google Firebase Crash reports, device model and OS, app version, push token, app-usage events Crash reporting, push notifications, live config, analytics
AppLovin MAX and its ad networks Advertising ID, IP, device model and OS, app version, ad interactions — only when you choose to watch an ad Serving and measuring the optional rewarded ads
Google Your email and basic profile if you use Google sign-in; purchase receipts via Google Play Sign-in and in-app purchases
Apple Your Game Center player id if you sign in with it; purchase receipts via the App Store Sign-in, achievements, in-app purchases
Google Cloud Platform All game data — they host our servers and database Running the game

Our servers run on Google Cloud. These providers operate globally, so your data may be processed outside your country, including in the United States. Where it leaves the EU, UK or India we rely on the standard contractual clauses our providers have in place, plus encryption in transit. We'll confirm the hosting region for your data if you ask.

Other players can see your display name, rank and arena, guild, achievements, whether you're online, and whatever you write in chat. Nothing else.

We'll also hand over data if the law genuinely compels us — a valid court order, a lawful government request, or to stop someone being harmed. We'll push back on requests we think are improper, and tell you where we're allowed to. If Smash Cards is ever sold, your data moves with it; we'll tell you in the game first, and the new owner stays bound by this policy until they give you notice of their own.

7. How long we keep it

Retention
WhatHow long
Your account and progressAs long as your account exists
In-game mail and rewards29 days, then deleted automatically
Match and card statistics30 days for individual records. Aggregate win/loss counts are kept for good and aren't linked to you
Ladder history2 months, then deleted automatically
Chat messagesUntil the channel goes, or you delete your account
Purchase recordsUp to 7 years — tax law requires it. This one survives account deletion
Server logs, including IPUp to 90 days
Crash and analytics data at FirebaseGoogle's own schedule, usually up to 14 months
Ad data at AppLovin and its networksTheir own schedules — see their policy

Delete your account from the in-game Settings page and your profile, progress, chat, friends, guild membership and linked sign-ins are removed straight away — not queued, not held in a recycle bin. If you email us instead, we do the same within 30 days. Either way we keep only the purchase records the law makes us keep, stripped of anything not needed for that.

8. Your rights

Email mail@aswinmurali.dev from your account's address, or from any address if you tell us your in-game name. We reply within 30 days. It's free, and we'll never charge you or make the game worse because you asked.

Whoever and wherever you are, you can:

These come from India's Digital Personal Data Protection Act 2023, the EU and UK GDPR, and California's CCPA/CPRA. The laws use different words but land in much the same place, so we've written one list and we honour it for everyone rather than making you prove where you live.

Two extras worth knowing: in India you can nominate someone to exercise these rights if you die or can't act for yourself, and if we don't resolve your grievance you can escalate to the Data Protection Board of India. We don't make any decisions about you purely by machine, and we don't collect the kind of sensitive information California singles out for extra limits.

9. Players under 16

Smash Cards is for players aged 16 and over. It isn't aimed at children and we don't knowingly collect data from anyone under 16 — an age floor that sits at or above what both US and European child-privacy law requires. We don't knowingly show ads to children either.

If we find out someone under 16 has an account, we delete it and its data promptly.

Parents and guardians: if you think your child has given us data, email mail@aswinmurali.dev with their in-game name or the email they used. We'll check, delete the account, and confirm — normally within 7 days.

10. How we protect it

We won't claim to be unbreakable; no honest service can. If a breach touches your data we'll tell you and the relevant regulator as fast as the law requires — within 72 hours in Europe, and without delay in India.

11. Changes and contact

When this policy changes we update the date at the top. If a change actually affects your rights or how we use your data, we'll tell you in the game or by email before it takes effect, so you can object or leave. We won't quietly apply a worse policy to data we already hold.

Questions, requests, complaints, or ad opt-outs all go to one place:

Not happy with our answer? You can go to the Data Protection Board of India, your EU supervisory authority, the UK Information Commissioner's Office, or the California Privacy Protection Agency, depending on where you live.

↑ Back to top