Privacy Policy for Actify

Effective Date: December 2, 2025

Last Updated: August 28, 2026


Introduction

Thank you for using Actify ("we," "our," or "the app"). Your privacy is extremely important to us, and we designed Actify to collect as little data as possible.

Actify is a charades-style party game. Core gameplay works without an account. Optional features — cloud backup of custom decks, Group Deck invitations, and an Actify Pro subscription use our online services. Group Deck contributors can use an invitation in a browser without installing Actify or creating an account. This policy explains what data is collected in each case.

Account (Optional)

Information We Collect

1. Account Information

Anonymous users (no sign-in):

If you do not sign in, the app may automatically create an anonymous Firebase account. This generates a random user ID that does not contain your name or email. We associate it with free-tier usage counters, Group Deck invitations you organize, notification settings if you opt in, and backend security records needed to operate those features. Ordinary custom decks created during an anonymous session remain on your device.

Google sign-in users:

When you sign in with your Google account (via Android Credential Manager and Firebase Authentication), we receive the following information from your Google account:

This information is used solely to identify your account and associate your custom decks and subscription status with you. We do not use it for advertising or share it with third parties beyond Google Firebase, which provides the authentication service.

2. Custom Deck Content

Ordinary custom decks created without Google sign-in are stored locally on your device and are not uploaded for cloud backup. If you sign in with Google and choose to associate local decks with your account, those decks may be stored in Google Firebase Firestore to make them available across devices. Stored content includes:

They remain local unless you associate them with a Google-linked account.

3. Group Deck Invitations and Contributions

A signed-in organizer can create an unlisted Group Deck invitation for a custom deck. We store the organizer's Firebase user ID, source deck ID, deck name and description, card counts, invitation status, acceptance of the contribution rules, and creation, update, and expiration timestamps.

A guest who opens the invitation can contribute without an account. If the guest submits cards, we store the card text, an optional display name or emoji chosen by the guest, a random browser identifier used for abuse prevention and blocking, acceptance of the contribution rules, moderation/import status, and timestamps. The organizer can view the submitted card text and approve or reject it. The organizer review screen hides the display name; if approved, the name may appear with the card in round results. Guests should not submit sensitive personal information.

The web form uses a strictly necessary cookie named actify_group_contributor to recognize a browser for report/block controls and abuse prevention. Firebase Hosting and Cloud Functions may also process standard web request information such as IP address, user agent, and security logs as needed to operate and protect the service.

If a guest reports an invitation, we store the invitation ID, random browser identifier, report reason/status, and timestamp so we can investigate abuse. Reports may be retained as reasonably necessary for safety, fraud prevention, and legal compliance.

4. Subscription Status

If you purchase an Actify Pro subscription, Google Play processes and manages the payment. Actify receives the subscription product ID, purchase token, status, and expiration information needed to verify access and prevent one purchase from being assigned to multiple active Actify accounts. Purchase-token ownership records are stored in hashed or server-restricted form. We do not receive or store your payment card details.

5. Crash and Diagnostic Data (Optional)

We collect diagnostic information only if you keep crash reporting enabled (on by default, opt-out available in Settings). This helps us understand and fix app crashes.

What we may collect:

6. Analytics Data (Automatically Collected)

We collect usage analytics to understand how Actify is used and to improve the experience. Analytics is pseudonymous rather than directly identifying: Firebase generates an app instance ID and, while a Firebase session is active, Actify may associate events with that random anonymous or Google-linked Firebase user ID.

What we collect:

How it's collected: Using Firebase Analytics, provided by Google LLC. Reports are analyzed in aggregate; event payloads do not include custom-deck names, card text, contributor names, or email addresses.

What analytics helps us do:

7. App Configuration (Firebase Remote Config)

We use Firebase Remote Config to adjust certain app settings (such as free-tier limits) remotely without requiring an app update. This service fetches configuration values from Firebase servers. It does not collect any personal information from you.

8. Bonus Time Notifications (Can Be Disabled)

Bonus Time reminders are enabled by default where device permissions allow them. On Android 13 and newer, Actify asks for notification permission before sending reminders. We use Firebase Cloud Messaging to send a small number of reminders about upcoming unlimited Party Mode windows. To deliver these reminders at the correct local time, we store your Firebase user ID, Firebase Cloud Messaging registration token, notification preference, device time zone setting, locale, app version, and reminder scheduling timestamps.

You can turn Bonus Time reminders off at any time in Actify Settings or in your device notification settings.

What we do not collect:

How We Use Information

We do not:

Data Storage and Security

Firebase Authentication & Firestore (Google LLC)

If you sign in with Google, your account information and synced custom deck content are stored in Google Firebase services in accordance with Google's privacy policies and security standards.

Data Retention: Account data and synced custom decks are retained for as long as your account exists. Group Deck links accept contributions for one hour. Unresolved contributions can carry into a replacement invitation for the same deck. The invitation and its contributions remain available to the organizer during that collaboration and for a seven-day review period after the last link closes; automated daily cleanup then removes the invitation documents and submissions, normally within 24 hours. Ending a link early stops new contributions immediately but does not shorten the review period. Abuse reports may be retained longer when reasonably necessary for safety, fraud prevention, or legal compliance. If you delete your account or request deletion, associated account data is removed from our servers, subject to limited safety/legal retention. To stop an already-issued authentication token from recreating deleted data, we keep a server-only deletion work record containing the Firebase user ID and security timestamps. Unfinished records remain blocking and are retried by an automated 15-minute recovery job. After deletion completes, the record blocks that deleted ID for 24 hours and is then removed by scheduled cleanup. The link between your Actify account and Google Play purchase token is removed, while the subscription itself remains managed by Google Play and may be restored after you create and sign in to another Actify account.

Firebase Crashlytics (Google LLC)

Crash data is processed and stored by Google. Retained for up to 90 days, then automatically deleted.

Firebase Analytics (Google LLC)

Usage analytics are pseudonymous and reported to us primarily in aggregate. They are retained according to our Firebase Analytics retention settings.

Firebase Cloud Messaging (Google LLC)

Bonus Time notification tokens and scheduling metadata are retained while reminders are enabled. If you turn reminders off, Actify disables reminder delivery, removes the local Firebase Cloud Messaging token, and removes the server token record when possible. Server token records are also deleted if they become invalid or stale.

Security: Google implements industry-standard safeguards to protect data from unauthorized access or misuse. We use Firebase App Check where supported for app-only requests. Public Group Deck browser submissions are instead protected with unlisted high-entropy links, server-side validation and limits, moderation, expiration, and report/block controls.

Your Privacy Rights

Opt Out of Crash Reporting

To stop sending crash reports:

  1. Open Actify
  2. Go to Settings
  3. Turn Crash Reports to OFF

Opt Out of Bonus Time Notifications

To stop Bonus Time reminders:

  1. Open Actify
  2. Go to Settings
  3. Turn Bonus Time reminders to OFF

Sign Out

You can sign out of your Google account at any time in Settings → Sign Out. After signing out, no new ordinary custom-deck data is uploaded. Local decks that are available to the signed-out session remain on your device; synced account decks remain associated with the Google-linked account unless you delete it.

Group Deck Controls

Organizers can end an invitation early in Actify; otherwise it stops accepting cards automatically after one hour. Browser contributors can report and block an invitation from its contribution page. To request access to or deletion of a contribution, contact us with the invitation link and any details needed to locate the submission. We may need additional verification to protect other users' data.

Right to Deletion

If you have signed in with Google, you have a cloud account with associated data (account info and synced custom decks). You can delete it in Actify Settings, or use our account deletion page. You can also contact us at actify.game@gmail.com.

If you have not signed in with Google, Actify may still hold data under an anonymous Firebase ID or a browser Group Deck contribution. You may request deletion of that data through the account deletion page or the same email address above; include an invitation link or other details needed to locate browser contribution data. Crash data follows Firebase's diagnostic retention settings.

GDPR Information (EU Users)

If you reside in the European Union, you have the right to:

We rely on contract performance as the legal basis for processing account and deck data when you sign in. We rely on legitimate interest for optional crash diagnostics and anonymous analytics. You may opt out of crash reporting and Bonus Time reminders at any time in Settings.

To exercise any of these rights, contact us at actify.game@gmail.com.

CCPA Information (California Users)

If you are a California resident, you have the right to:

We do not sell or share data for advertising purposes.

Third-Party Services

Google Account Sign-In (Credential Manager) / Firebase Authentication (Google LLC)

Purpose: Optional account sign-in

Data Collected: Display name, email address, profile photo URL, unique user ID

Privacy Policy: https://firebase.google.com/support/privacy

Firebase Firestore (Google LLC)

Purpose: Cloud backup and sync of signed-in users' custom decks, plus storage and moderation of unlisted Group Deck invitations and contributions

Data Collected: Custom deck names, descriptions, and card text; Group Deck metadata, submitted card text, optional contributor display name, random contributor identifier, moderation status, rule acceptance, reports, and timestamps

Privacy Policy: https://firebase.google.com/support/privacy

Firebase Cloud Functions (Google LLC)

Purpose: Server-side subscription verification, free-tier usage limits, and Group Deck invitation, contribution, moderation, expiration, and abuse-report operations

Data Collected: Firebase user ID (anonymous or Google-linked), subscription status, usage counters, and the Group Deck data described above. Standard web request/security information may be processed for browser contributions.

Privacy Policy: https://firebase.google.com/support/privacy

Firebase Remote Config (Google LLC)

Purpose: Fetching app configuration values (e.g., free-tier limits)

Data Collected: None — configuration only, no personal data

Privacy Policy: https://firebase.google.com/support/privacy

Firebase Crashlytics (Google LLC)

Purpose: Crash reporting and diagnostics

Data Collected: Device info, crash logs, app version, game state at crash time, app instance ID, and Firebase user ID when a Firebase session is active

Privacy Policy: https://firebase.google.com/support/privacy

Firebase Analytics (Google LLC)

Purpose: Usage analytics and app improvement

Data Collected: App interactions, screen views, game sessions, device info, app instance ID, subscription tier, and Firebase user ID when a Firebase session is active

Privacy Policy: https://firebase.google.com/support/privacy

Firebase Cloud Messaging (Google LLC)

Purpose: Optional Bonus Time reminders

Data Collected: Firebase Cloud Messaging registration token, Firebase user ID, notification preferences, device time zone setting, locale, app version, and reminder scheduling timestamps

Privacy Policy: https://firebase.google.com/support/privacy

Google Play Billing (Google LLC)

Purpose: Subscription purchase and management for Actify Pro

Data Collected: Payment is handled entirely by Google Play. We receive a purchase token, product ID, subscription status, and expiration information, but no payment card details.

Privacy Policy: https://policies.google.com/privacy

Children's Privacy

Actify includes family-friendly content and does not knowingly collect personal information from children under 13.

If you believe we have collected information from a child under 13, please contact us immediately at actify.game@gmail.com.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When updated, a revised "Last Updated" date will appear at the top of this page. Your continued use of the app after changes are made means you accept the updated Privacy Policy.

Google Play Data Safety Summary

Personal info (collected if signed in):

App activity and user-generated content (collected when the relevant feature is used):

App info and performance:

Device or other IDs:

Not Collected:

All data shared with third parties goes only to Google Firebase (our service provider). Data is not sold or used for advertising.

Contact Us

If you have any questions about this Privacy Policy or our data practices, contact us at:

Email: actify.game@gmail.com
App Name: Actify

Quick Summary

Question Answer
Do you collect personal information? Only if you sign in with Google (name & email). Anonymous users get a random ID with no personal info attached.
Is an account required? No — sign-in is optional, for cloud sync and Pro subscription
Are my custom decks stored in the cloud? Ordinary custom decks stay local until you sign in with Google; Google-linked decks may be synced. Group Deck invitation content is stored online even when a contributor uses the browser without an account.
Do you store payment details? No — payments are handled by Google Play
Do you collect crash data? Yes, but only if enabled (optional — off in Settings)
Do you collect analytics data? Yes, pseudonymous and automatic
Can I delete my account data? Yes — use Settings, the account deletion page, or contact actify.game@gmail.com
Do you sell or share data? No
Do you use data for ads? No
Who processes data? Google Firebase (our service provider)

By using Actify, you agree to this Privacy Policy.

Last Updated: August 28, 2026