← Back to the Bread Defense village

Bread Defense Privacy Policy

This English translation is provided for convenience. If it conflicts with the Korean original, the Korean version prevails.

Effective date: August 31, 2026 · Last revised: September 7, 2026 (Google Analytics for Firebase added; applies from app version 1.5.5) · Service: Bread Defense (ETERNAXCODE)

ETERNAXCODE (hereinafter "Developer") provides the game "Bread Defense" (hereinafter "Service") and processes your personal information as follows.

1. Information Collected and Purposes

ItemCollection MethodPurpose
Account identifierAutomatically generated upon anonymous login via Firebase AuthenticationSaving game progress and synchronizing across devices
Email, display name, social account identifierProcessed through the respective login provider and Firebase Authentication when you choose to link Google or Apple accountsIdentity verification, account linking, restoring progress across devices
Nickname, game progress data (score, stage, owned characters, etc.)Entered directly by you or generated during gameplayProviding rankings, saving progress, service operation
Country code at access (IP-based estimation, e.g., KR)When the app synchronizes server time, the server (Vercel) estimates the country code from the access IP and transmits it to the app; it is stored once when country is not yet set (you can change this in app settings). The IP address itself is not stored.Displaying country flags in rankings and federation member lists
Usage logs (stage start/clear, purchase and ad viewing events, etc.)Automatically collected during service useGame balance improvement, error analysis, operational statistics
Purchase history (product ID, order and transaction identifier, payment status)Upon in-app purchase via Google Play or App StorePurchase verification, currency distribution, preventing duplicate distributions and fraudulent use (card numbers and other payment method information are processed by each store and not collected by the developer)
Advertisement identifier, device and app information, and other advertising-related informationGoogle AdMob SDK (rewarded ads)Ad delivery, frequency management, and prevention of fraudulent use
App instance identifier, account identifier, device, OS, app version, language, screen transitions and game progress events (stage, recruitment, purchase, ad viewing, etc.), user attributes such as progress stage, season, and payment statusGoogle Analytics for Firebase SDK (Android and iOS apps, from version 1.5.5)Usage statistics analysis, feature improvement, identifying errors and drop-off points (nickname and email are not transmitted)
Customer support inquiry content, app version, platform, screen, error code, selected screenshotsWhen you submit an inquiry via customer support in app settingsAnalysis and response to bug, payment, account, balance, suspected abuse, and federation inquiries
Web community account identifier, public nickname and profile picture URLWhen you choose to log in via Google or Apple on the webDisplaying post and comment authors and verifying your permissions
Post and comment content, category, tags, version, reactions, and view countWhen logged-in users use the web communitySharing strategies, handling questions and reports, and operating a public community
Report content, moderation records, server-generated timestampWhen you submit a report or moderators take actionSafe community operation, dispute verification, and audit logging

The Service does not directly request phone numbers, addresses, or precise location information. Country display uses only country codes (two letters) estimated from access IP; more precise locations are neither estimated nor stored. Guests who do not link social accounts can use the service with an anonymous identifier. On iOS, the app does not request App Tracking Transparency (ATT) permission; in regions where advertising privacy choices are required, you can reopen the AdMob consent screen in app settings.

The web community is readable without logging in, but writing posts, commenting, reacting, bookmarking, and reporting require logging in via Google or Apple. Web Firebase ID tokens are used only in request headers and are not stored in URLs or public logs.

2. Processing Delegation and Third-Party Disclosure

Processor / RecipientContent
Google LLC (Firebase Authentication and Cloud Firestore)Account authentication, storing cloud progress data and usage logs (Google Privacy Policy)
Google LLC (Google Analytics for Firebase)App usage statistics analysis (Firebase Privacy Protection, Google Partner Sites and Apps Policy)
Google LLC (AdMob)Rewarded ad delivery (AdMob Policy)
Google LLC (Google Play)Android in-app purchase processing and purchase verification
Apple Inc. (Apple Sign-In and App Store)Optional social sign-in and iOS in-app purchase processing

3. Security Measures

Communication between the Service and Firebase, Google Play, App Store, and AdMob is protected with HTTPS/TLS encryption in transit. Authentication and purchase tokens are used only for the scope necessary to process requests and are not logged in the app's public logs.

Customer support screenshots are stored in a private repository, not a public URL; moderators access them only through temporarily valid access links. Technical summaries (build, platform, reproduction steps, expected/actual results, error codes, etc.) without personal identifiers are recorded in GitHub development issues; user identifiers, emails, nicknames, payment identifiers, or inquiry message text are not transmitted.

4. Retention Period

Account and game progress data are retained for the duration of service provision. Web posts, comments, reactions, bookmarks, reports, and moderation audit logs are retained for periods necessary for service operation and dispute verification; public exposure is first suspended upon deletion request or post deletion. Usage logs for operation and error analysis are stored for a maximum of 90 days; backup data for recovery purposes for a maximum of 60 days before deletion. Event data and user-level data collected via Google Analytics for Firebase are stored in Google Analytics for up to 14 months before automatic deletion. Customer support tickets, messages, and screenshots are retained for up to 2 years after inquiry closure before deletion; thereafter, only de-identified inquiry type and resolution code statistics are retained for operational records. Upon your deletion request, data is promptly deleted; transaction records subject to legal retention obligations (e.g., 5-year retention under e-commerce law) are held separately during the applicable period before deletion.

5. Your Rights

You can request access to, correction of, or deletion of your data (account identifier, nickname, progress records, etc.) at any time. Please select Delete account and data in app settings or use the web deletion request guide. To confirm your identity, we can verify account information linked to your in-game nickname.

6. Children's Personal Information

The Service is a game for all ages and does not intentionally collect additional personal information from children.

7. Contact

Questions about personal information: support@eternaxcode.com

If this policy changes, we will notify you through this page.