At a glance
- You can play without giving us your name, email or anything else, and you never have to sign in: Rank'd makes an anonymous guest account for you.
- We do not sell your data, share it for targeted advertising, or track you across other companies' apps and websites. Rank'd sends usage analytics and selected handled-error reports to PostHog under your account ID, and anonymous native crash and selected error diagnostics to Sentry. These are on unless you turn off Share usage data in Settings.
- The small banner ad is non-personalised. Once you have Pro or Remove ads, the ad software is never started.
- Your photos are private: you decide who sees them. Rank'd never reads your photo library; you pick photos with Apple's picker. A guest's photos, packs and game history never leave the phone. If you sign in, your packs (photos included) and your games are backed up to your account so you can get them on your other devices. Rank'd never sends your photos to other players, and we never use them for ads, analytics or training artificial intelligence.
- Online rooms run on Google's servers in Singapore. Sign-in and the backups of signed-in accounts are in the United States.
- In a multiplayer room, the other players see your display name, and the host's phone receives everyone's moves before they are revealed.
- You can delete your account, guest or signed in, from Settings in the app at any time.
1. Who we are
Rank'd is made by Bhushan Malani, an individual developer based in India ("we", "us" or "our"). We decide how and why your personal data is processed for Rank'd, which makes us the "controller" under the GDPR and UK GDPR and the "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023.
Bhushan Malani
Postal address: B004, Aakruthi Homes, Maheshwarama Temple Road, Mahadevpura, Bengaluru, Karnataka, India. 560038
Telephone: +91 74988 58917
Email: support@bmstudio.in
Grievance Officer: Bhushan Malani, at the same addresses (see section 15).
This policy covers the Rank'd app (the "App"), the online services it uses, and the Rank'd product, support and legal web pages at bmstudio.in. It does not cover what Apple, Google or other companies do with data when they act on their own account; where that matters, we say so and link to their policies. Our Terms of Use, which are also the App's licence agreement, sit beside this policy and are linked from the same places.
2. What we collect and why
Here is everything Rank'd collects, feature by feature: what it is, where it comes from, who can see it and what it is for.
2.1 Your account (everyone)
- Account ID. A random identifier created by Google's Firebase Authentication the first time you open Rank'd. It is your guest account. It is also your player ID in rooms, your customer ID with RevenueCat, which records purchases for us, and the ID our usage analytics are recorded under (2.12).
- Account dates. When the account was created, and when the App last signed in or last contacted our servers with it. We use the last contact date to delete inactive guest accounts after 90 days.
- Sign-in token. Kept in the iOS keychain on your phone so you stay signed in.
- Connection data. When the App contacts Firebase Authentication, Google records the IP address and the user agent (device, system and app version) of the request. Google keeps these IP address logs for a few weeks.
Purpose: to give you an account, which online rooms and purchases need, and to keep it secure.
2.2 If you sign in
- Sign in with Apple: Apple's identifier for you in Rank'd, your email address (or an Apple private relay address if you choose Hide My Email) and, if you choose to share it, your name.
- Google: your Google account identifier, email address, name and profile picture address. The App shows your Google profile picture on your profile. If you have signed in with Google on this phone before, the App may use Google's saved sign-in to sign you back in when it opens.
- Email and password: your email address. Your password is handled by Firebase Authentication, which stores it only in hashed form; we never see it. Firebase sends password reset emails for us.
- Your display name is saved to your account so your other devices can show it.
Purpose: to let you sign in, use the same account on several devices, restore your backups and keep your purchases with your account.
2.3 Your profile
Your display name (one you choose, or one the App suggests) and your player tile, one of four. They are stored on your phone, sent to any room you join, and saved to your account if you sign in.
2.4 Online rooms
When you create or join an online room, these are stored in Google's Firebase Realtime Database, in Singapore, for as long as the room lasts: the room code; your account ID, display name and tile; whether you are ready; whether you are connected and when you were last seen; the game, its settings and the built-in pack being played; your moves (where you place each item or which tier you give it); requests to join and the host's answers; and the times of all of these.
- The other players in the room see your display name, tile, readiness and progress, and everyone's boards once they are revealed.
- Anyone using the App who has the room's code can also see who is in the room: each player's display name, tile and account ID. They cannot see moves or boards.
- The host's phone receives every player's moves as they are made, before they are revealed, because it referees the game. If the host leaves, the next host's phone receives them in the same way. Other players cannot see your moves before the reveal.
- The data is deleted when the room closes, or within 24 hours of the room's last activity.
Purpose: to run the game you asked to play.
2.5 Nearby rooms
Nearby rooms connect phones directly using Apple's Multipeer Connectivity over Wi-Fi and Bluetooth. The game data (your profile and moves, as in 2.4) travels encrypted between the phones in the room and never reaches our servers. While you host a nearby room, your phone announces to phones nearby that have Rank'd open: the room code, your display name, your player ID, the game and how many players have joined. This needs iOS's Local Network permission, which you can turn off in the Settings app under Privacy & Security, then Local Network.
2.6 Packs you make
The photos you pick with Apple's photo picker (Rank'd only receives the photos you pick, not the rest of your library), which the App copies and resizes, plus your captions and pack names. They are stored on your phone and, if you are signed in, backed up to your account (2.8). Packs you make can only be played on your own or passing one phone around; they are never sent to a room or to other players. If we ever let you play your packs with other players, we will update this policy before that is available.
2.7 Game history
For each finished round: the date, the pack, the game and how it was played, the room code if it was played in a room, the players' display names, tiles and player IDs, their boards, the match scores, and copies of any of your photos the round used. It is stored on your phone and includes the display names of the other players in the round; their phones keep a record with your display name in the same way, and so do their backups if they are signed in (2.8). If you are signed in, your history is backed up (2.8).
2.8 Cloud backup (signed-in accounts only)
If you sign in, Rank'd backs up your game history and the packs you make, with their photos, to your account, and restores them to your other devices when you sign in there. Guests have no backup: a guest's history, packs and photos never leave the phone.
- What is backed up. For each round, what 2.7 lists, including the other players' display names and tiles and the room code, except that every player ID, yours included, is replaced by a seat number, so no other player's account ID reaches our servers. For each pack, its name, category, captions and items in order, and its photos. Photos are stored exactly as the App holds them, named by a fingerprint of their content (a SHA-256 hash), so a photo used by several rounds and packs is stored once. We also record when your backup last changed and when the App last synced it, and how many photos and how much space it uses, so we can apply the storage limit.
- Where. Google Cloud Firestore and Cloud Storage for Firebase, in the United States (Google Cloud region us-central1, Iowa).
- Signing in. The rounds and packs made on the phone as a guest move to the account you sign in to, whether it is new or one you already had, and are backed up with it.
- Signing out. Your account's backed-up rounds and packs are removed from that phone. Anything not yet backed up stays on the phone, hidden, until you sign in to the same account there again. It is never added to a different account.
- Deleting a round or a pack on a phone signed in to your account deletes it from the backup and from your other devices. We keep a marker that it was deleted, holding its identifier and the time but none of its content, for up to 365 days, so that your other devices learn of the deletion. A backed-up photo that no round or pack uses any more is deleted 30 days after the last one stopped using it.
- Inactive backups. If a backup has not been used for 24 months, we delete it. A backup is used whenever you open Rank'd while signed in to that account. We do not send a notice first. The account itself is kept, and nothing on your phones is touched.
- Deleting your account deletes its backup (sections 7 and 9).
Your photos are private: you decide who sees them. We use them only to back them up for you and restore them to your devices. Rank'd never sends them to other players; they see your photos only if you show them your phone or share a card. We never use them for advertising or analytics, never sell them, and never use them to train artificial intelligence. Nobody at Rank'd looks at them unless the law requires it, or to deal with a report made to us by email, for example from someone who says a photo of them was used without their permission. The App has no way to report a photo, because in this version Rank'd never sends your photos to anyone else.
Purpose: to keep your games and packs safe and let you use them on your other devices.
2.9 Purchases
Apple takes all payments. Through RevenueCat, we receive: which product you bought; the transaction identifiers; the dates of purchase, renewal, expiry, cancellation and any refund; the price and currency; the App Store country; whether you used a free trial or offer; and whether your subscription is set to renew. This is linked to your account ID. We never receive your card or bank details or your billing address. Our usage analytics (2.12) also record when a purchase is completed, fails or is restored, and for a completed purchase what it was (the plan's length, or Remove ads) and whether it began a free trial.
Purpose: to unlock what you bought, restore it on other devices, show your renewal date, prevent fraud and see our sales totals.
2.10 Ads
If you have not removed ads, Rank'd uses Google's Mobile Ads SDK (AdMob) to show one small, labelled banner on two screens. When it runs, Google collects from your phone:
- your IP address, which Google uses to estimate your approximate location (such as your city);
- information about your device and the App, such as the model, system version, language and app version;
- identifiers limited to the App or its developer. Google cannot get your device's advertising identifier (IDFA), because Rank'd never asks for permission to track you;
- which ads were shown and whether you tapped them; and
- diagnostic information about how the ad software is performing, including crashes.
The ads are non-personalised: Rank'd tells Google not to personalise them, so they are not chosen from a profile of you. Google chooses them from context and approximate location. Even for non-personalised ads, Google still uses identifiers to limit how often you see the same ad, to count ads for reporting, and to detect fraud and abuse. Where the law requires consent (in the European Economic Area, the United Kingdom and Switzerland), Google's consent message asks you first, and your choice is stored on your phone.
Google decides for itself how it uses this data, as an independent controller. See Google's Privacy Policy and how Google uses information from apps that use its services. The App also contains Google's list of ad networks for Apple's SKAdNetwork, which lets advertisers count app installs without identifying you.
If you have Rank'd Pro or Remove ads, the ad software is never started, so none of this is collected.
Purpose: ads pay for the free version of Rank'd.
2.11 Feedback and reasons for leaving
If you send feedback from the rating card, or pick a reason when you cancel Pro or delete your account, we receive the reasons you tapped, anything you typed (up to 1,000 characters), the App version, your iOS version and the time. It is stored in Google's Firebase Realtime Database without your account ID, name or email, and nobody can read it back through the App. Google's Realtime Database keeps the IP address and user agent of requests for a few days. Please do not type personal information into feedback. Because it is not linked to you, we cannot find your feedback later to delete it unless you tell us exactly what you wrote. Our usage analytics (2.12) do not record that you sent feedback or picked a reason. If you tap the rating card's option to send feedback, they record that choice (2.13), not whether you sent anything or what it says.
Purpose: to learn what to improve.
2.12 Usage analytics and crash reports
Rank'd sends records of how the App is used and selected handled-error reports to PostHog. Sentry receives anonymous native crash reports and selected sanitized App errors. Reporting starts the first time you open the App, before you finish the introduction, for guest and signed-in accounts alike, and carries on unless you turn it off (see "Your choice" below).
- Events we chose. The App sends an event for each moment on a fixed list: a step of the introduction viewed, and the introduction finished or skipped; a round started or finished; a room opened or joined, or failing to open or join; reaching the sign-in prompt, a Pro prompt or the paywall; signing in, a sign-in failing, and signing out; a purchase completed, failing or restored; opening the Cancel Pro screen and continuing to Apple's; opening Delete account, and deleting the account; saving a pack; opening, saving or sharing a result card; and the rating card shown and the choice you made on it. Events carry only kinds and counts, for example: the game and how it was played; how many players; which built-in pack (a pack you made is recorded only as "own"); the round's match score; whether you hosted, and whether the room was online or nearby; the kind of error; the sign-in method, and whether signing in made a new account; the plan length you bought and whether it was a free trial; how many photos a pack has; which kind of card you shared and the kind of app you shared it to (such as Messages); whether you typed your own name during the introduction (not the name).
- Screens and app activity: which of seven screens you open (the introduction, Home, History, round setup, the room lobby, joining a room and Settings), and when the App is installed, updated, opened and sent to the background, with its version.
- Native crashes and selected App errors (Sentry). If the App crashes, a diagnostic report is saved on your phone and sent on the next launch while sharing is enabled. It includes the crash type, where in the App's code it happened (stack traces), loaded software libraries and app/device diagnostics. Selected content-loading and result-card failures use a fixed label saying what the App was doing, an error category and a numeric code. Raw error details and native crash messages are redacted. The reports carry no account or stable installation ID, screenshots, screen hierarchy, activity breadcrumbs, request data or arbitrary extra information. Replay, performance tracing and profiling are disabled.
- Handled store failures (PostHog). When the App fails to open, save, read or delete game history or packs, it sends a manual handled-error report to PostHog under your account ID: the kind of error, the system's description of it, a stack trace and a fixed label saying what the App was doing. PostHog's automatic native crash reporter is disabled.
- PostHog device and session details, with every product event: the device model, system name and version, App version and build, language, time zone, screen size, whether you are on Wi-Fi or mobile data, whether it is a test build, a random session identifier, the last screen you opened, and when the event happened.
- PostHog identifiers. Your account ID (2.1), and a random identifier the analytics software creates the first time the App opens, used until your account ID is known and then joined to it. With the account ID go two facts about the account: whether it is a guest or signed in with Apple, Google or email, and whether it has Pro, Remove ads or neither. This lets us see rounds, sign-ins and purchases together. When a different account takes over the phone (after you sign out, delete your account, or sign in to an account you already had), analytics continue under the new account ID, and what was recorded under the old one stays with it until that account is deleted (section 9).
Never sent to PostHog: your display name, your email address and anything else you type (names, captions, pack names, notes and what your feedback says), your photos, room codes, other players' names or IDs, your moves and boards, your precise location, and the advertising identifier. There is no screen recording, and taps are not captured automatically. Your IP address reaches PostHog with each upload, as it does with any internet connection, but our PostHog project is set to discard it rather than store it, and not to work out a location from it.
Sentry privacy controls. Sentry reports carry no account ID or stable installation identifier and are not joined to your PostHog profile. Our US Sentry project prevents storing IP addresses and removes geographic information server-side. An IP address still reaches a provider during the network connection. Sentry receives no names, email addresses, room codes, photos, captions, pack titles, notes or game boards from our diagnostic hooks.
Your choice. Usage analytics and diagnostic reporting are on when you start using Rank'd. Share usage data, in Settings in the App, controls PostHog and Sentry together. It stays off, even after the App restarts or another account takes over the phone, until you turn it back on; if you delete the App and install it again, it starts on again. Turning it off prevents new event/error capture, closes Sentry's native crash handler and deletes its app-owned diagnostic cache. Previously captured reports or queued events may still be sent while the software shuts down; uploads already in progress may finish. It does not delete data already received by either provider (section 9). Buying Rank'd Pro or Remove ads does not change it.
The App keeps your choice, PostHog's random identifier and any events waiting to be sent in its storage on your phone. Sentry keeps pending anonymous diagnostics in a separate app-owned cache while sharing is enabled; turning sharing off clears that cache.
PostHog Inc. processes product analytics and manual handled-error reports for us in the United States (PostHog's US Cloud). Sentry processes anonymous native crash and selected error diagnostics for us in our US project. Both act as service providers. We do not combine this data with data from other companies, use it for advertising, or sell it.
Purpose: to understand how Rank'd is used and where people get stuck, and to find and fix crashes and faults.
2.13 Ratings
If you choose to rate Rank'd, Apple's own rating window handles it. We only see the ratings and reviews Apple publishes. Our usage analytics (2.12) record when the App shows its rating card and which of its choices you make, never your rating.
2.14 Emails to us
If you email us, we receive your email address and whatever you write, and use them to answer you.
2.15 Only on your phone
Some things never leave your phone: whether you have finished the introduction; how many games you have finished and when you finished the first (used to time the suggestions to sign in and to make a pack, and the rating card); whether and when you were shown each of those; which account each round and pack on the phone belongs to and whether it has been backed up; your ad consent choice; and your settings. These counts and dates stay on the phone as they are; our usage analytics (2.12) separately record the events they come from, such as a round finished or the rating card shown. Share cards are made on your phone; you decide where to share them. Saving a card to Photos uses add-only access: Rank'd can add an image to your library but cannot see what is in it.
2.16 These web pages
We add no analytics, advertising cookies or trackers to the Rank'd product, support or legal pages at bmstudio.in. The pages are hosted through OpenAI Sites on Cloudflare infrastructure. The hosting providers receive visitors' IP addresses and browser/request details and may use essential security cookies, such as Cloudflare's bot-protection cookie, to operate and protect the service. These are not used by us for advertising or cross-site tracking. The short ranking demo runs only in your browser; it does not save your choices or send them to us.
3. What we never do
- We do not sell or rent your personal data, and we do not share it for cross-context behavioural advertising or use it for targeted advertising.
- Rank'd never uses the advertising identifier and never tracks you across other companies' apps or websites. Its usage analytics (2.12) tell us only how Rank'd itself is used: we never combine them with data from other companies, use them for advertising, or sell them.
- Guests' photos never leave the phone. Rank'd never reads your photo library, and never sends your photos to other players.
- Rank'd does not use your precise location, contacts, camera or microphone.
- We do not use your data for automated decisions that have legal or similarly significant effects on you, and we do not profile you to make decisions about you or to choose ads for you.
- We do not use your photos, captions or pack names for advertising or analytics, and we do not use them or your games to train artificial intelligence. Our usage analytics record facts about a round, such as the game, the number of players and the match score, but never the boards, photos, captions or names.
4. Our legal bases
If you are in the European Economic Area, the United Kingdom or Switzerland, the law requires a legal basis for each use of your personal data. These are ours:
| What we do | Legal basis |
|---|---|
| Create and run your account, guest or signed in, and keep you signed in | Performing our contract with you (the Terms of Use) |
| Run online and nearby rooms | Performing our contract with you |
| Back up and restore history and packs for signed-in accounts | Performing our contract with you |
| Keep your display name and tile in the rounds backed up for the signed-in players you played with | Our legitimate interest, and theirs, in keeping a faithful record of the games they played |
| Process, restore and honour purchases | Performing our contract with you; complying with legal obligations, such as keeping records |
| Show non-personalised ads to fund the free version | Our legitimate interest in funding Rank'd; your consent, collected by Google's consent message, where the law requires consent to store or read information on your device |
| Record usage analytics and crash reports (2.12) | Our legitimate interest in understanding how Rank'd is used and in finding and fixing what goes wrong. You can object at any time and stop new recording by turning off Share usage data in Settings in the App; already captured uploads may finish during shutdown |
| Keep Rank'd secure and prevent fraud, cheating and abuse; enforce our Terms | Our legitimate interests, and yours, in a safe game |
| Delete inactive guest accounts and inactive backups | Our legitimate interest in not keeping data we no longer need |
| Read feedback and answer emails | Our legitimate interest in improving Rank'd and helping you; performing our contract where your email is about it |
| Comply with the law, answer lawful requests, and establish or defend legal claims | Complying with legal obligations; our legitimate interests |
You can object to any use based on legitimate interests (section 8); for usage analytics and crash reports, turning off Share usage data is enough. In India, we process your personal data with the consent you give by using Rank'd after reading this notice, which you can withdraw at any time by deleting your account, and for the legitimate uses the Digital Personal Data Protection Act, 2023 permits, such as data you give us voluntarily for a stated purpose and complying with the law. You can withdraw your consent to usage analytics and crash reports alone, at any time, by turning off Share usage data in Settings in the App.
5. Who receives your data
| Who | What they receive | Their role | Where |
|---|---|---|---|
| Google (Firebase Authentication) | Account ID, sign-in details, IP address and user agent | Service provider (processor) acting for us | United States |
| Google (Firebase Realtime Database, Cloud Functions) | Online rooms, feedback, and account housekeeping: deleting inactive guests, old rooms and a deleted account's data | Service provider (processor) acting for us | Singapore (Google Cloud region asia-southeast1) |
| Google (Cloud Firestore, Cloud Storage for Firebase, Cloud Functions) | Backups of signed-in accounts, and their housekeeping: storage limits, clearing unused photos and deleting inactive backups | Service provider (processor) acting for us | United States (Google Cloud region us-central1, Iowa) |
| RevenueCat, Inc. | Account ID and purchase records | Service provider (processor) acting for us | United States |
| PostHog Inc. | Usage events, manual handled-error reports, device details, the analytics software's random identifier and your account ID (2.12). Our project discards IP addresses and does not derive geographic information | Service provider (processor) acting for us | United States |
| Sentry | Anonymous native crashes and selected sanitized errors, stack traces and app/device diagnostics (2.12). No account linkage, stored IP addresses or geographic information | Service provider (processor) acting for us | United States (US project) |
| Google (AdMob and its consent message) | The ad data in 2.10 | Independent controller | Worldwide |
| Apple | Payments, Sign in with Apple, App Store downloads and ratings | Independent controller | Worldwide |
| Google (Google Sign-In) | Your sign-in, if you choose Google | Independent controller | Worldwide |
| Other players | Your display name, tile, readiness, moves and results in rooms you join, which stay in their game history. If they are signed in, their backup with us keeps your display name and tile, but not your account ID. | Other users | Wherever they are |
Our service providers may use your data only to provide their services to us, under their data processing terms (for Google, the Firebase and Google Cloud data processing terms; for RevenueCat, PostHog and Sentry, their data processing agreements).
We also disclose personal data when the law requires it, for example in response to a valid court order; when it is needed to protect the rights, safety or property of players, the public or us; to professional advisers bound by confidentiality; and to a person or company that takes over Rank'd, who must then protect it as this policy says. We will tell you before such a transfer.
6. International transfers
We are based in India and read feedback and emails there. Our service providers store and process your data outside India and outside the country where you live:
- Singapore (Google Cloud region asia-southeast1): online rooms, feedback, and the functions that delete inactive guest accounts, old rooms and a deleted account's data.
- United States: Firebase Authentication; the backups of signed-in accounts, including their photos (Google Cloud region us-central1, Iowa); RevenueCat's purchase records; PostHog's usage analytics and manual handled-error reports; and Sentry's anonymous native crash and selected error diagnostics.
- Google's ad services and Apple work worldwide, as section 5 says.
So if you live in India, the European Economic Area, the United Kingdom, Switzerland or anywhere else, your personal data is transferred to Singapore and the United States, and, if you sign in, your photos are stored in the United States. When personal data from the European Economic Area, the United Kingdom or Switzerland goes to a country without an adequacy decision, we rely on the provider's certification under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) where it has one, or on the Standard Contractual Clauses approved by the European Commission, with the UK and Swiss additions, which are part of our providers' data processing terms. You can ask us for a copy. Transfers from India are made as the Digital Personal Data Protection Act, 2023 permits.
7. How long we keep it
| Data | How long |
|---|---|
| Guest account without a purchase | Until you delete it, or until 90 days after the App last contacted our servers with it, whichever comes first |
| Guest account used to buy Pro or Remove ads | Until you delete it |
| Signed-in account | Until you delete it, or until we end it under our Terms of Use |
| Backup of a signed-in account | Until you delete the account, or until the backup has not been used for 24 months (2.8), whichever comes first. We do not send a notice before deleting an inactive backup. |
| A round or pack you delete on a signed-in phone | Deleted from the backup when that phone next syncs. A marker that it was deleted, with no content, is kept for up to 365 days. |
| Backed-up photos no round or pack uses any more | 30 days after the last round or pack stopped using them |
| After an account is deleted | The account, its backup, its RevenueCat record and its linked PostHog usage analytics and handled-error reports are removed from our live systems at once where we can, and in every case within 30 days. For linked PostHog usage analytics and handled-error reports, we ask PostHog to delete them at the same time; PostHog removes the account's analytics profile at once or within minutes and deletes the recorded events in a background job it runs at quiet times (at weekends), so the events can take up to about a week longer than the rest. Anything the App sends after that request is not covered (section 9). Copies in Google's backup systems are deleted on Google's schedule: Google states that it removes Firebase Authentication data from its live and backup systems within 180 days, and its data processing terms commit it to deleting other deleted data from its systems within at most 180 days. |
| Firebase Authentication IP address logs | A few weeks (kept by Google) |
| Realtime Database IP address and user agent logs | A few days (kept by Google) |
| Online room data | Deleted when the room closes, or within 24 hours of the room's last activity |
| Nearby room data | Only on the players' phones while the room lasts, then in each phone's own game history |
| RevenueCat customer record | Deleted when the account is deleted, by you or for inactivity. A guest account with a purchase is never deleted for inactivity, so its RevenueCat record is kept until you delete the account. The records Apple keeps of your purchases are Apple's, under Apple's privacy policy. |
| Usage analytics and manual handled-error reports (PostHog) | up to 12 months, or until the account they were recorded under is deleted, whether you delete it or we delete it as an inactive guest account, whichever comes first (see "After an account is deleted"). Turning off Share usage data does not delete them. We delete them sooner if you ask and we can find them (section 9). |
| Anonymous native crashes and selected error diagnostics (Sentry) | Kept according to our Sentry project's configured retention. These reports carry no account ID, so deleting an account cannot locate or delete them by that ID. Turning off Share usage data clears their app-owned cache and stops new capture; it does not delete reports already received by Sentry. |
| Feedback and reasons for leaving | 12 months from when it is sent; a daily job then deletes it. |
| Emails to us | Until your request is resolved and for up to 24 months after our last reply, then deleted. |
| Ad data collected by Google | As Google's own policies say |
| Data on your phone (profile, history, packs, settings, ad consent choice, the analytics software's random identifier and unsent events) | Until you delete it in the App, erase it when deleting your account, or delete the App. When you sign out or delete a signed-in account, that account's rounds and packs are removed from the phone (2.8 and section 9). iOS may keep the App's keychain entry (your sign-in token) after the App is deleted, so reinstalling can sign you back in to the same account. |
| Share cards you export | Under your control, wherever you saved or shared them |
We keep data longer only where the law requires it, or where it is needed to establish, exercise or defend a legal claim, and only for as long as that lasts.
8. Your rights
8.1 Everyone
Wherever you live, you can: change your display name and tile in Settings; delete your account and, if you choose, the data on your phone (section 9); change your ad choices where Google asks for consent (section 10); turn usage analytics and crash reports off with Share usage data in Settings (2.12); and ask us by email for a copy of your personal data, or to correct or delete it. We answer within one month, and in any case within the time the law that protects you allows. Guest accounts have no email or name attached, so we may ask you to make the request from the App, or for details that let us find your account, before we act on it. Usage analytics carry no name or email either, which limits what we can find (section 9).
8.2 European Economic Area, United Kingdom and Switzerland
You have the right to access your personal data, to have it corrected, erased or restricted, to receive it in a portable format, and to object to processing based on legitimate interests. Where we rely on consent, you can withdraw it at any time, without affecting what was done before. You can also complain to the data protection authority where you live or work; in the United Kingdom that is the Information Commissioner's Office, and in Switzerland the Federal Data Protection and Information Commissioner. We would welcome the chance to help first.
8.3 India
Under the Digital Personal Data Protection Act, 2023, you have the right to a summary of the personal data we process and of what we do with it, and to know who we have shared it with; to have it corrected, completed, updated or erased; to have your grievances addressed; and to nominate someone to exercise your rights if you die or cannot act yourself. You can withdraw your consent at any time, as easily as you gave it, by deleting your account, or, for usage analytics and crash reports alone, by turning off Share usage data in Settings. If you are not satisfied with how our Grievance Officer handles your complaint, you can complain to the Data Protection Board of India.
8.4 United States
Depending on your state, including California, Colorado, Connecticut, Virginia and others, you may have the right to know what personal data we collect and how we use and disclose it, to get a copy, to correct it, to delete it, and to opt out of its sale, of "sharing" for cross-context behavioural advertising, of targeted advertising and of profiling used for decisions that have legal or similarly significant effects. We do none of those four things, so there is nothing to opt out of. Our usage analytics (2.12) are none of them either: PostHog processes them only for us, as our service provider. You can still turn them off with Share usage data. We honour these rights for every user whether or not a state law applies to us, and we will not treat you differently for using them. An authorised agent may make a request for you with your signed permission. If we refuse a request, you can appeal by replying to our answer; if we refuse the appeal, you can contact your state attorney general.
In the past 12 months we have collected these categories of personal information, for the purposes in section 2: identifiers (account ID, email address, IP address, and the random identifier our analytics software creates); customer records (name and email address, if you sign in); commercial information (purchase records); internet or other electronic network activity (ad interactions, collected by Google; and how you use the App and its crash reports, collected by our analytics provider); approximate location (estimated by Google from your IP address, for ads); and audio or visual information (photos in the backups of signed-in accounts). Your sign-in email and password together are sensitive personal information; we use them only to let you sign in.
Do Not Track. Rank'd does not track you across other companies' apps or websites, so it has nothing to switch off when it receives a Do Not Track or Global Privacy Control signal, and it treats every user as having opted out of sale and sharing. We do not disclose personal information to third parties for their own direct marketing.
9. Deleting your data
- In the App: Settings, then Delete account. This works for guest accounts as well as signed-in accounts. You confirm with Apple, Google or your password, or with a confirmation for a guest. It deletes your account and the name saved to it, the backup of a signed-in account (its rounds, packs and photos), your RevenueCat customer record, and your linked PostHog usage analytics and handled-error reports (below), and if you signed in with Apple, it tells Apple to remove Rank'd's access to your Apple sign-in. A signed-in account's rounds and packs are also removed from your phones. For a guest account, a switch lets you also erase the game history and packs on that phone; otherwise they stay there. A new guest account then takes over the phone.
- What deleting your account does not delete: your purchases, which belong to your Apple Account and can be restored; what other players have, such as your display name in the game history on their phones and, if they are signed in, in their backups, which hold your display name and tile but not your account ID; feedback, which is not linked to your account; rooms other players are still in, which are deleted when the room closes or within 24 hours of its last activity; and data Google holds for ads, which Google's own controls cover.
- PostHog usage analytics and manual handled-error reports (2.12) recorded under your account ID are deleted with the account, whether you delete it in the App or we delete it as an inactive guest account. We ask PostHog to delete them when the account is deleted. PostHog removes the analytics profile at once or within minutes and deletes the events in a background job at quiet times (at weekends), so the events can take up to about a week longer. The request covers only what PostHog has received by then. Just before the deletion, the App sends PostHog anything it is still holding, and it records nothing under the deleted account ID afterwards; if some of what it sent has not reached PostHog by the time PostHog handles the request, it can arrive afterwards under the deleted account ID and is kept for up to 12 months (section 7). Signing out does not delete them; they stay with the account you signed out of. Turning off Share usage data stops new ones being recorded but does not delete these. To have them deleted without deleting your account, ask us; they carry no name or email, only the account ID, and the App does not show that ID, so email us from the address you sign in with. For a guest account we may not be able to find them.
- Anonymous Sentry diagnostics carry no account ID, so they cannot be found or deleted by your Firebase account ID. Their provider-configured retention applies separately (section 7). Turning off Share usage data stops new capture and clears the app-owned Sentry cache; it does not delete reports already stored by Sentry.
- Deleting your account does not cancel Rank'd Pro. Cancel it in the Settings app on your iPhone: tap your name, then Subscriptions.
- You can also delete single packs and rounds in the App (on a signed-in phone this deletes them from the backup too), sign out to remove a signed-in account's rounds and packs from a phone, delete the App, or email us if you cannot use the App.
10. Ads and your privacy choices
- Where Google asks for consent, Settings in the App shows Privacy choices, where you can change or withdraw your choice at any time.
- Rank'd never asks for permission to track you, so the advertising identifier is never available to it or to Google through it.
- Rank'd Pro or Remove ads turns the ad software off completely.
- Share usage data, also in Settings, turns our usage analytics and crash reports off (2.12). It is separate from the ad choices, and buying Pro or Remove ads does not change it.
11. Children
Rank'd is not meant for children under 13, and we do not knowingly collect personal data from them. Anyone aged 13 to 17 needs a parent or guardian's permission to use Rank'd. If we learn that we hold personal data from a child under 13, or from a child below the age at which their country allows them to use Rank'd without a parent's consent, we will delete it. If you are a parent or guardian and think your child has used Rank'd, please contact us. We also ask Google to limit ads to content suitable for general and parental-guidance audiences.
12. Security
Data travels between the App and our providers encrypted, and Google encrypts the data it stores for us. Security rules on our database and storage limit each account to what it needs: a player cannot read moves in a room they are not in, or anyone else's backups, and nobody can read feedback through the App. Nearby rooms encrypt the traffic between phones. Passwords are stored only in hashed form by Firebase Authentication, and access to our provider consoles is limited to the developer. No system is perfectly secure, and the host of a room receives every player's moves before they are revealed, as explained in 2.4.
13. If something goes wrong
If a security incident affects your personal data, we will notify the authorities that the law requires, such as the Data Protection Board of India, and, where the GDPR or UK GDPR applies, the relevant supervisory authority within 72 hours of becoming aware of it where that is required. We will also tell you without undue delay where the law requires it, with what happened, what it means for you and what we are doing about it.
14. Changes to this policy
We may update this policy when Rank'd or the law changes. The version and effective date at the top show which version applies. If a change is material, we will tell you in the App, and by email if we have your email address, before it takes effect. Earlier versions are available on request.
15. Contact and grievances
For any question or request about your personal data, or to complain, contact us at support@bmstudio.in, by post at B004, Aakruthi Homes, Maheshwarama Temple Road, Mahadevpura, Bengaluru, Karnataka, India. 560038 or by telephone at +91 74988 58917.
Grievance Officer: Bhushan Malani, at the same addresses. We acknowledge a grievance within 48 hours of receiving it and resolve it within one month, or sooner if the law requires. If you are not satisfied, you can go to the authorities listed in section 8.