Legal protocol

Novara Blast Privacy Policy

Version 2026-07-23-v4 Published July 23, 2026

Last updated: 21 July 2026 · Version 2026-07-21-v3

Controller: The operator of the Novara Blast service (“Novara Blast”, “we”, “us”). For privacy and support requests, we use our secure contact form instead of publishing an email address in page source.

1. Scope and purpose

This Privacy Policy explains how personal data is collected, used, shared, protected and deleted across the Novara Blast mobile game, website, player accounts, support channels and related online services. It is designed with Turkish KVKK, the GDPR where applicable and relevant platform rules in mind.

2. Data categories we process

  • Account and identity: Guest player ID, install ID, display name and, for registered accounts, email address and password hash; provider user ID and verification result when an enabled social login is used.
  • Device and application: Device / install keys, operating system, platform, application and content version, locale, time zone, security signals derived from IP address and push notification token.
  • Gameplay and economy: Level, score, progress, gold, inventory, quests, achievements, wheel / reward records, leaderboard results and game session summaries.
  • LiveOps and preferences: Campaign impression / click / dismiss events, announcement views, survey answers, notification, language, audio, theme, analytics and advertising preferences.
  • Security and technical logs: Request IDs, API access logs, session times, error and crash data, performance signals, suspicious transaction and abuse indicators.
  • Purchases: Store product and transaction ID, verification result, currency and amount. Full card or payment instrument details never reach us.
  • Contact and support: Name, email, subject, message, screenshots, technical device information and support history submitted through contact forms or bug reports. For web forms, the IP address is transformed into a pseudonymous HMAC digest rather than stored in plaintext, while limited browser information is retained.
  • Referral and social features: Referral code, referral relationship and reward status; display name and score shown on leaderboards.

If a feature is disabled or you have not granted a required permission, data specific to that feature is not processed. We do not collect plaintext passwords, full payment card numbers or unrelated content from your device.

3. Why we use data

  • To create accounts, authenticate users and synchronize progress across devices.
  • To operate game rules, economy, quests, rewards, leaderboards and LiveOps.
  • To validate purchases against store records and deliver entitlements.
  • To send notifications and transactional emails you request.
  • To answer support requests and troubleshoot technical issues.
  • To detect cheating, fraudulent transactions, unauthorized access, automation and service abuse.
  • To run analytics, measure the experience and personalize advertising to the extent you consent.

4. Legal bases

  • Contract performance: Accounts, gameplay progress, synchronization, support and purchase entitlements.
  • Legitimate interests: Service security, fraud prevention, essential measurement, debugging and maintaining service quality.
  • Consent: Non-essential analytics, personalized advertising and similar processing where consent is legally required.
  • Legal obligations and legal claims: Financial records, lawful authority requests, disputes and rights requests.

5. Consent and privacy choices

Where these controls are available in the application version, optional analytics and personalized-advertising choices can be managed at device / platform level. Core account, security and gameplay functions do not depend on those permissions. Where an advertising feature requires tracking on iOS, App Tracking Transparency (ATT) permission is requested separately. Withdrawal does not invalidate processing lawfully carried out before withdrawal.

6. Service providers and transfers

Data may be shared, only as necessary to operate the service, with:

  • Cloud hosting, database, cache, content delivery, security and technical logging providers.
  • Apple App Store and Google Play for distribution and purchase processing.
  • Google, Apple or Meta (Facebook) when the relevant social login provider is enabled and selected.
  • Firebase Cloud Messaging / Apple Push Notification Service and Brevo or an equivalently configured transactional-email provider.
  • Depending on configuration and your choices, Google Mobile Ads (AdMob), Firebase Analytics / Crashlytics, AppsFlyer and Sentry.
  • When enabled, Cloudflare Turnstile for web-form bot protection and Telegram for optional social-task verification.
  • Public authorities and professional advisers where legally required.

Providers process data under instructions and security obligations. Infrastructure or providers may be located in other countries; where applicable, contractual and technical transfer safeguards are used. We do not sell personal data.

7. Retention and deletion

  • Account and gameplay data is kept while the account remains active or as needed to provide the service.
  • In-app account deletion removes email, password hash, display name, linked social identities, verification data, active sessions and push tokens. Gameplay progress and the same technical player ID may remain as a non-identifying guest profile for continuity and integrity records.
  • Purchase / entitlement records, security and session audits, referral relationships, support records and legally required financial records may remain under a pseudonymous player ID for the limited period needed to prevent fraud, protect legal rights and meet legal obligations.
  • Push tokens are removed when a device is unregistered; temporary verification and session records are deleted after their purpose expires.
  • Support records are kept until the request and potential dispute period ends; technical logs are retained for a limited period needed for security and troubleshooting.

8. Security

We use administrative and technical controls such as transport security, access controls, password hashing, token expiry, rate limiting, audit logs and abuse detection. No system can guarantee absolute security; please report suspected incidents through the secure contact form.

9. Automated security decisions

Anti-cheat and fraud signals may reject a suspicious transaction or temporarily restrict access to specific features. If you believe a result is incorrect, you may ask support for human review.

10. Your rights

Under KVKK Article 11 and the GDPR where applicable, you may have rights to information, access, rectification, erasure, restriction, objection, withdrawal of consent and data portability. Use the in-app account deletion tool or our secure contact form. We may need to verify your identity and relationship to the account.

11. Children’s privacy

Novara Blast is not specifically directed to children under 13 or a higher digital-consent age required by local law. If we learn that we knowingly collected data from such a child, we take steps to delete it and close the related account.

12. Changes

We may update this Policy as the service or law changes. The version and publication date appear at the top; material changes may be announced in the application and renewed consent may be requested where required.

13. Contact and requests

For privacy questions, data-subject requests or security reports, we do not publish a personal email address in source code. Use our secure encrypted contact form and enter “Privacy / KVKK” as the subject.