Privacy policy
Last updated: 2 September 2026
The short version
- Contextual advertising, by default. Ads are not chosen using a profile of you or of what you play, unless you have told the app you are 13 or over.
- As a guest you give us no name, no email address and no location. That is what you are unless you choose otherwise, and all 48 games are playable that way. The app asks for a year of birth once, on the friends screen, and nothing else about your age anywhere.
- Signing in is optional, and it is what gives us your details. There is a Sign in button on the Profile tab, Google is the only way in, and it exists so a friends list and a purchase have an account to point at. Use it and Google gives us your name and your email address, and those two are what we keep. We do not keep your Google profile picture.
- You can take a copy, or delete the lot, from Settings. Two taps each, no email required.
- We never sell personal information.
- There is a friends list, and no messaging. No screen in PlayBurst lets you send another player a message, and the only text you type that anybody else sees is your own display name, which our servers check before they accept it. Anyone on your list, or asking to be, can be blocked or reported from the row they appear on.
The app and this website are not the same thing, and they collect different amounts, so they are described separately. Everything down to this website is about the app.
What the app collects
As a guest: a year of birth, and nothing else. The first time you open the app it creates an anonymous guest account so your scores and saves have somewhere to live, and that is the account you keep unless you sign in. The Profile tab lets you change your display name, which is the one thing in PlayBurst you type that somebody else can read, and nothing asks you to type an email address, a photograph or a location. What a display name may be is decided on our servers rather than in the app: 2 to 24 characters, no invisible characters, and not a word on a shared blocklist.
If you sign in: your name and your email address. The Profile tab has a Sign in button, Google is the only way in, and it is there because a friends list and a purchase both need an account that survives a reinstall. When you use it we ask Google for the name on your Google account, its email address, and whether Google has verified that address. We keep those three, they are in your data export, and deleting your account deletes them. Google offers us the web address of your profile picture as well and we throw it away: nothing in PlayBurst displays it, so there is no reason to hold it. Those are the permissions Google grants by default and we ask for nothing beyond them: nothing here reaches your contacts, your calendar, your mail or anything else in your Google account, and we cannot post as you anywhere.
You do not have to. Every game, your saves, your coins, the daily reward and the leaderboard work as a guest, and nothing in the app pushes you at the Sign in button. An account buys three things: a friends list, progress that follows you to a second device, and the ability to buy something in the shop, since a purchase has to belong to an account rather than to a device.
The friends screen asks for a year of birth on the press that would put you in touch with another player, and nowhere else, so that friends can be turned off for players under 13. It is asked once, only a year is asked for, and it cannot be retyped afterwards. The answer is kept on your device, and if it makes you 13 or over it is stored on your account as well, because a device can be wiped and reinstalled and a protection that a reinstall clears is not one. An answer under 13 never leaves your device. A stored year is in your data export and deleting your account deletes it. The copy on the device goes when you delete the app.
From the app, automatically, sent to our own servers against whichever of those two accounts you have:
- Scores, achievements, coins, daily reward streaks, statistics, and saved unfinished games
- Product events: that a session started or ended, which screen you are on, which game you started, how it ended, and whether a full-screen ad was shown. Each carries a timestamp and a session identifier
- Your display name and score, on the public leaderboard for any game you submit a score to
- If you use the friends screen: who is on your list, who has asked to be, who you have blocked, and the year of birth described above if it makes you 13 or over. No note, message or free text travels with any of it, because there is nowhere to type one. Reporting somebody records that you reported them and which reason you picked from a fixed list, and nothing else
On supported Android devices, guest recovery sends us an app-scoped Android identifier. We store a hash to recognise the same guest after reinstalling. This association is removed when the guest links an account or deletes their account. It is not used for advertising or to sign into a linked account. The app sends us no device model or operating system, no advertising identifier, no location, no push token and no contacts. Your settings and saved games are also kept on your own device, and that copy is not collected. Optional daily reminders are scheduled on your device. They are off by default, use no push token, and can be switched off in Settings. Completion information used to adjust reminders is stored on your device.
By other companies, inside the app: Google AdMob collects what it needs to serve advertising, which by its own disclosure includes a device identifier, an approximate location worked out from your network address, and diagnostic, performance and crash information. Sentry receives crash reports and a sample of performance traces, so we can find out what broke. It is the only crash reporting in the app.
RevenueCat handles purchases. When you buy something, or when the app checks whether you already have, we send them the account identifier described above so they can tell us what that account has bought. They receive the purchase itself from the app store, and we receive their answer. They are not told your name or your email address, and nothing about which games you play reaches them.
What we use it for
- Running the games, and saving your progress
- Leaderboards, achievements and daily rewards
- Understanding which games are played and how, so we know what to fix and what to build next
- Deciding when a full-screen ad is allowed, which is a matter of counting games and minutes
- Diagnosing crashes
- Meeting legal obligations
We do not build a profile of you, and none of it is used to choose which advertisement you see. We do not send marketing either: there is no mailing list, no newsletter, and no mail service wired into our servers to send one with. If you signed in, the email address Google gave us identifies your account when you sign in again, and it is used for nothing else.
Advertising
PlayBurst is a general audience app rather than a children’s one, and rather than ask every player their age, it applies children’s privacy protections to all of them by default. Google AdMob serves our ads and is instructed to treat you as a child for advertising purposes, which switches off personalised and interest-based ad selection. That is the setting for every player who has not answered the age question described above.
Those two sentences are not in tension, and the reason is worth stating. Personalised advertising would mean knowing you are an adult. Knowing that would mean asking everybody their age before they could play, and an age gate in front of 48 casual games is a worse experience for every player than the advertising is worth to us. Treating everyone protectively costs us some ad revenue and costs you nothing, so that is the trade we made.
If you answer it with a year that makes you 13 or over, that instruction stops being sent for you, and from the next launch the advertising you see can be personalised. Nothing about how often ads appear or where they appear changes with it, and ad content stays limited to a “G” rating for every player, at any age. There is no setting for any of this, and the age answer cannot be retyped; deleting and reinstalling the app clears it and returns you to the default.
Where the law requires a consent form before advertising can be requested, the app shows Google’s consent form before its first ad, and Settings then carries an “Ad privacy choices” entry so you can reopen it. That entry appears only where a consent form applies, which today means the EEA, the United Kingdom and Switzerland.
How often ads appear, and where they are allowed to appear, is described in full on how ads work.
Children
PlayBurst is not directed to children. It is a general audience service, it is not listed in Apple’s Kids Category, in Amazon Kids or in Google Play’s Designed for Families programme, and its Play Console target audience is 13 and over. We also recognise that children play games like these. So rather than ask every player their age, we apply children’s privacy protections to everyone by default. In practice:
- No personalised or interest-based advertising for any player who has not told us they are 13 or over
- Ad content limited to a “G” rating, for everybody
- One age question, a year of birth, asked on the friends screen. It is kept on your device, and stored on your account too if it makes you 13 or over
- No account is needed to play. Signing in with Google is optional, is needed for a friends list and for buying anything, and is the only thing that gives us a name or an email address
- The friends screen turns off entirely for a player who answers under 13
- No messaging. The only text one player types that another can read is a display name, and what one may be is decided on our servers, against a length, a character rule and a blocklist
- Data collection limited to what running the games requires
A reviewer reading those two paragraphs together should not think one of them is a mistake. Saying we are not directed to children is a statement about who the app is for; treating every player protectively is a statement about what we do with them once they are here, and it is the setting that lets us ask nothing of anybody at the door.
We do not knowingly collect personal information from a child under 13. If we learn that we have, we delete it. A player who answers under 13 keeps every game, coin, streak, score, achievement and daily reward: the friends screen is the only thing that changes, and it is simply absent rather than restricted.
What a friend can see about you is your display name, the emoji the app uses as your avatar, and your level. Not your country, not your statistics, and not whether you are online, because PlayBurst records none of that about anybody. You can block or report any of them from the row they appear on. A report blocks that account and records the report on our servers, both in one step, with a reason picked from a short list. There is no box to type in, nothing you write reaches the other player because there is nothing to write, and they are not told.
Parents: if you believe your child has given us personal information, email privacy@playburstgames.com and we will delete it. You can also ask what we hold and tell us to stop collecting it.
Your rights
Wherever you live, two of these are buttons in the app:
- Take a copy of your data. Settings, then Account, then “Download my data”. It returns everything we hold about you as a JSON file and hands it to your device’s share sheet
- Delete your account and your data. Settings, then Account, then “Delete account”. It removes the account and everything keyed to it, including your leaderboard entries and product events. There is no grace period and nothing is held back
And for the rest, or if you have already uninstalled the app, email us:
- Correct anything that is wrong
- Restrict or object to how we process it
- Delete what we hold, when you can no longer reach Settings
Write to privacy@playburstgames.com and we will respond within 30 days, or sooner where the law requires it. California residents should include “CCPA Request” in the subject line. Residents of the EU and the UK have the additional rights the GDPR grants, including the right to complain to a supervisory authority.
Our lawful bases, for readers who need them named: performance of the contract, which covers running the games and saving your progress; our legitimate interests, which cover understanding how the games are used, finding crashes, and funding a free app with contextual advertising; and consent where the law requires it, which is the ad consent form described above.
How long we keep it
These periods are enforced by a job that runs every day at 03:00 UTC.
- Product events and error logs: 30 days
- Scores and game play history: five years
- Your account and everything keyed to it: while active, then three years of inactivity
- Expired sign-in sessions: deleted daily
- Support email: three years after the issue is resolved
An account counts as inactive only when four things are true at once: no live session, nothing written to the account in three years, no game played in three years, and no score submitted in three years. Support email lives in a mailbox rather than in the database, so that period is a matter of how we run the mailbox. Crash reports are held by Sentry under its own retention schedule rather than in our database, so they are not on the clock above. Anything held on your own device stays there until you delete the app.
Security, and where your data is processed
Our servers, our database and our leaderboards are hosted in the United States, so if you are outside the United States your information is transferred there. Where that transfer needs a legal basis, we rely on the standard contractual clauses or an adequacy decision, as applicable.
- Everything between the app and our servers travels over HTTPS, and is encrypted at rest by our hosts
- Access to personal data is limited to the people who need it
- Only the session that owns an account can read or delete it, so knowing somebody’s user identifier does not let you act as them
- Your export leaves out anything that could be used to sign in as you, so a file you have shared is a copy of your data rather than a copy of your account
No independent security review has been carried out.
This website
Everything above is about the PlayBurst app. This website is a separate thing, and it collects less.
We use Google Analytics here, to see how many people find the site and which pages they read. It is set to store nothing on your device. It sets no cookies, and it cannot recognise you when you come back, so two visits from you look like two visits from two strangers. There is no cookie banner on this site because there are no cookies to ask you about.
What Google receives when you open a page here:
- The address and title of the page you are on, and the site or search that sent you
- Your browser, your operating system and the size of your screen
- The language your browser asks for
- An approximate location, which Google works out from your network address
That is the whole list. No name, no email address, and nothing you have typed. If you would rather not be counted at all, a content blocker will stop it, and nothing on this site needs it to work.
The app does not use Google Analytics, and there is none of it in the app to switch off. The app’s analytics are our own, and they are the ones described above.
Changes
We will post any update here with a new date at the top, and tell you about material changes in the app or by email. For significant changes we will ask for consent again where that is required.
Contact
Privacy questions and requests: privacy@playburstgames.com.