Skip to content
ROUTE
Larinae.dev

Builder

  1. 01 Projects
  2. 02 About
  3. 03 Contact
TINY-ACES -- / 03

Tiny Aces / legal

Privacy Policy

Effective date22 July 2026

Tiny Aces (“the game”) is developed by Larinae Games (“we”). The game is free to play, shows advertising through Google AdMob to players without a membership, and offers optional in-app purchases through Google Play: coin packs and an auto-renewing membership subscription. This policy explains how the current version handles data for local progress, its automatic online wallet and run rewards, the public leaderboard, advertising, purchases and the membership, and Google services where those services are available. The game does not use attribution or third-party crash-reporting SDKs, and we do not use its data for cross-app tracking.

01

Data we process

Automatic online wallet and run data

The game generates a random install identifier when it first runs. This is a cryptographically random UUID, not a hardware identifier, advertising ID, phone number, or Google account identifier. It acts as the credential for that installation’s online wallet.

When the game has an internet connection, reaching the start menu automatically sends the install identifier to our server to fetch or create the installation’s wallet. This happens even if you do not submit a leaderboard score, link Play Games, or make a purchase.

After each completed run of at least one meter, the game automatically sends:

  • the install identifier and a random per-run operation identifier;
  • distance, duration, whether the Tailwind modifier appeared, and completed laps or boss defeats; and
  • whether you asked to use a Tailwind charm for that run.

These records are used to credit distance and box rewards, consume a selected charm, prevent duplicate grants, enforce rate limits, and reject implausible or conflicting results. Other economy actions send the install identifier plus the operation identifier, skin identifier, or charm/voucher choice needed to open boxes, buy a plane, or claim a membership perk.

The server stores wallet and economy records including coin balance, lifetime distance, completed boss count, boxes opened and their results, charms, vouchers, feathers, unlocked skins, skin purchases and prices, a coin ledger of grants and deductions with their sources, operation identifiers, and timestamps. The device keeps a local display cache, but the server is authoritative for online rewards, balances, purchases, and membership.

Advertising

The game shows occasional full-screen ads through Google AdMob after a run ends, when you leave the results screen. Members do not see ads, including during a free trial. A small percentage of installations is assigned by the server to a no-ads comparison group derived from the install identifier; those installations see no ads, and the assignment is used only to measure how advertising affects whether players keep playing.

Before the first ad is requested, players in the EEA, UK, and Switzerland are shown a consent form (Google’s UMP) where they can accept or refuse personalized advertising; refusing still shows non-personalized ads.

AdMob and its partners process device and advertising identifiers (including the Android advertising ID), IP-derived coarse location, and ad interaction data to select, deliver, cap, and measure ads, under your consent choices and Google’s own policies. Tiny Aces does not send the ad network your leaderboard name, wallet contents, or gameplay history. See Google’s privacy policy and Google’s ad partner disclosure.

Gameplay analytics

The game records minimal first-party gameplay analytics: how many ads were shown to the installation and when, whether an ad failed to close normally, the no-ads comparison-group assignment described above, and aggregates derived from the run records described earlier (activity days and session patterns). We use this only to measure whether advertising harms retention and to price the membership. This data stays on our own Supabase service, is keyed by the random install identifier, and is never shared with the ad network or any other third party.

Public leaderboard and reports

Submitting a score is optional. If you submit one, the game sends the name you enter (3–16 characters), install identifier, run identifier, distance, duration, and relevant modifier state. The private score record also stores a keyed IP hash and submission time.

Non-hidden leaderboard entries are public. Public fields currently include the entry identifier, submitted name, distance, submission time, and whether the entry carries a member badge. The game shows the leading entries, but public entries may also be accessible through the leaderboard service outside the in-game top list. Choose a name you are comfortable making public and do not enter private information as your name.

If you are a paying member (past any free trial), the leaderboard may additionally show a member badge next to your entry. This is off by default and shown only for entries you submit while you have switched it on, so whether other players can see that you pay is your own choice.

If you report an inappropriate name shown in the game, the report contains the score identifier and your install identifier. The private report record also stores a keyed IP hash and timestamp to prevent duplicate or abusive reports.

IP addresses and request records

Your IP address necessarily reaches Supabase whenever the game makes an online request. Our application database records only a keyed, one-way hash of the IP address for rate limiting, security, fraud prevention, and abuse review; the raw address is not stored in the game database. Supabase and network infrastructure may process raw addresses and other request metadata in their own operational and security logs.

Data stored on your device

The game stores the following in its private app storage as needed:

  • the random install identifier, last leaderboard name, and acceptance of the leaderboard name rules;
  • best distance, music and sound settings, selected plane, and locally cached unlock, wallet, and membership information;
  • ad-pacing counters (runs since the last ad and when the last ad was shown) and the last-known membership state, used to decide when an ad may appear;
  • pending box-operation identifiers, charm attachment choices, and whether first-use guides, the trial offer, or the member welcome have been shown;
  • a short Play Games account fingerprint, declined restore choices, and a crash-recovery journal if account linking is available; and
  • pending purchase and subscription product IDs, purchase tokens, times, states, and platform while a payment is being verified or recovered.

This local data is not shared with the ad network; advertising uses only the identifiers described in the Advertising section. Android cloud backup is disabled for the game. Clearing the app’s storage or uninstalling normally removes it, although that does not delete corresponding server or Google Play records.

Play Games account linking and restore

Play Games linking is optional and operates only in versions where it has been configured. When available, the game may automatically ask Google Play Games whether you are already authenticated after the menu appears and when the app resumes. You can decline a sign-in request and continue using the core game.

When Play Games is used:

  • Google’s SDK may provide a player identifier and associated player profile data, such as display name, title, profile or banner images, level/experience information, friend-visibility or friend-status information, and a retrieval timestamp. Tiny Aces uses the player identifier for wallet linking. The current plugin may process and cache available profile images in private app storage while loading the player.
  • The game requests a one-time server authorization code. Our Supabase function sends that code to Google’s OAuth service and asks the Play Games API to verify the stable player identifier.
  • The verified player identifier is stored with the server wallet so one Play Games identity links to one wallet. The game save stores a short hash of that identifier to recognize account changes and restore choices. We do not ask Google for your email address, contacts, or payment credentials for linking.
  • If the authenticated Play Games identity already owns another wallet, the server returns a read-only restore offer containing that wallet’s install identifier and a summary such as coin balance, lifetime distance, unlock count, and whether the current wallet has purchase records.
  • Replacing the current wallet with the previously linked wallet requires your explicit confirmation. Declining leaves the current wallet unchanged; balances are never merged, and an explicit restore action can ask again.

Google Play purchases and refunds

Opening the coin store connects to Google Play Billing to retrieve product availability and localized prices and to query unfinished or recoverable purchases. The game also connects to Google Play Billing at launch and when the app resumes to restore an active membership subscription. After a checkout attempt, the game may reconnect and repeat purchase recovery on later launches or app resumes.

Google Play Billing may provide a purchase record containing the product ID, purchase token, order ID, package name, purchase time and state, quantity, acknowledgement or suspension status, signature, and original signed purchase data. The game processes the callback and locally retains only the product ID, purchase token, purchase time, purchase state, and platform while verification or recovery is pending. It also sends Google a one-way hashed wallet/account attribution value to bind the checkout to the correct wallet.

Before granting coins, our server sends the product ID and purchase token to the Google Play Developer API for verification. The server stores the token, product ID, associated wallet, coins granted, creation time, consumption attempts/status, and later refund or void status. Google Real-time Developer Notifications and the Voided Purchases API are used to process refunds or chargebacks safely and only once. A refund can reduce a wallet below zero so refunded value cannot be spent twice.

Google Play processes the payment. Tiny Aces and Larinae Games do not receive or store your raw payment card number, bank details, or Google account password.

Membership subscription

The membership is an optional auto-renewing subscription sold through Google Play, with monthly and yearly plans and, for eligible players, a one-time free trial. It grants daily coin claims, bonus coins for boss defeats, a one-time free plane unlock, the optional leaderboard badge, and removes ads.

When you subscribe, and whenever the game restores a subscription as described above, the game sends the install identifier and the Google Play purchase token to our server. The server verifies the token with the Google Play Developer API and stores a subscription record: the purchase token, subscription state, expiry time, plan, whether it is in a free-trial phase, the latest order identifier, acknowledgement status, the linked wallet, and timestamps. The wallet stores its membership expiry time and, if a trial was used, when the trial was redeemed — a wallet can use a free trial only once, and the trial offer unlocks after a lifetime-distance threshold that the server also checks.

A subscription entitles one installation’s wallet at a time. Verifying the same subscription from a different installation (for example a new phone) moves the entitlement to that wallet, ends it on the previous one, and records the change.

Using membership perks creates additional server records: daily-claim identifiers, claim times, the streak counter and streak-shield state; every perk coin grant is written to the coin ledger together with the subscription that funded it; and the free plane unlock stores the chosen plane, the claim time, and its value at claim time.

Google notifies our server of subscription renewals, cancellations, refunds, and revocations through Real-time Developer Notifications, and the server re-verifies the subscription with Google before updating membership. If a subscription payment is refunded or revoked, membership ends immediately and the value granted during the refunded period (perk coins and the free plane’s claim-time value) is deducted from the wallet, which may go below zero. Cancelling normally is different: perks simply continue until the end of the paid period and nothing is removed or deducted. You can manage or cancel the subscription at any time through Google Play, including via the manage link in the game’s membership screen.

Google Play Integrity and security data

Play Integrity operates only in versions where it is configured. In those versions, the game may prepare the Integrity service at launch and when the app resumes. For protected box, skin-purchase, perk-claim, and real-money-purchase actions, it can request a token that binds the app package, the specific action, and a recent timestamp. Our server asks Google to decode it and processes app-recognition and device-integrity verdicts to detect modified apps, replayed requests, fraud, and unsupported devices.

The raw Integrity token is not stored in the game database or intentionally written to application logs. Security logs record the endpoint, allow/deny verdict and reason, and only the first eight characters of the install identifier. Integrity can initially run in a non-blocking shadow mode before failed verdicts are enforced. Authorized test devices may be recorded in an internal allowlist using their install identifier, an operator note, and an expiry time.

Support and deletion communications

If you contact us by email, Larinae Games and our email provider receive your email address, message, and any identifiers, screenshots, receipts, or other information you choose to include. We use that information to answer the request, locate relevant records, investigate problems, and meet security, legal, or recordkeeping obligations. Do not send passwords, payment-card details, or raw purchase tokens by email.

02

How we use the data

We use the data described above to:

  • create and operate the online wallet, credit runs and rewards, and provide the leaderboard and unlocks;
  • show and pace ads for non-members, honor consent choices, and measure the effect of advertising on the game;
  • verify purchases and the membership subscription, grant the correct product or perk once, consume it, and process refunds, revocations, or chargebacks;
  • operate membership perks such as daily claims, the boss bounty, the free plane unlock, and the optional badge;
  • link a wallet to the Play Games account you authenticate and offer a consent-first cross-device restore;
  • prevent duplicate grants, cheating, fraud, abuse, and excessive requests;
  • moderate public leaderboard names, respond to support and deletion requests, diagnose failures, and meet legal, accounting, and platform obligations.

We do not sell this data, build advertising profiles from it, or use it for cross-app tracking. The ad network processes the identifiers described in the Advertising section under its own policies and your consent choices.

03

Service providers and data location

We use these service providers/processors to operate the features above:

  • Supabase hosts the database and Edge Functions in the European Union. Requests are encrypted in transit with HTTPS. See Supabase’s privacy policy.
  • Google provides AdMob advertising (including the UMP consent form), Google Play Billing for purchases and subscriptions, the Google Play Developer APIs and Real-time Developer Notifications, and — where the relevant feature is configured — Play Games Services and OAuth, Play Integrity, and the email service used for our contact address. Google receives the profile, identifiers, purchase evidence, security data, or support message needed for the particular service. Google may also process Play data under its own relationship with you. See Google’s privacy policy and Google Play’s terms.

We disclose data only to providers needed to run these features, when you use an account, purchase, or support feature, or when required by law or necessary to protect users and the service. Google and Supabase may process data in other countries under their own infrastructure and legal transfer arrangements. Whether a provider transfer is labelled “sharing” in Google Play’s Data Safety form follows Google’s specific Data Safety definitions.

04

Security

Client-server requests use HTTPS. Private wallet, run, report, purchase, subscription, and identity tables are protected by database access controls and are not directly readable with the public key shipped in the app. Server functions validate requests and use idempotency identifiers, rate limits, purchase and subscription verification, and optional Integrity checks. The public leaderboard exposes only the public fields described above, not install identifiers, raw IP addresses, purchase tokens, or wallet contents. No storage or transmission method can be guaranteed perfectly secure.

05

Retention and deletion

  • Local settings, progress, cached wallet data, ad-pacing counters, and recovery records remain on the device until they are overwritten, app storage is cleared, or the game is uninstalled. Google SDK cache files may remain until app storage is cleared or the game is uninstalled.
  • The database currently has no fixed automatic deletion date for leaderboard, wallet, run-audit, box-open, unlock, skin-purchase, account-link, report, purchase, subscription, perk-claim, ledger, or ad-analytics records. Unless removed earlier after a valid request, they may be retained while the relevant online service operates and as needed to restore purchases, prevent duplicate grants, resolve refunds or disputes, secure the economy, and meet legal, accounting, or platform obligations.
  • Purchase and subscription tokens and grant/refund/clawback records may be retained after other data is deleted when necessary to prevent duplicate grants, process refunds, address fraud, or satisfy transaction recordkeeping duties. Where possible, retained records will be disconnected from data that is no longer needed.
  • One-time Play Games authorization codes and Google API access tokens are used for verification and are not intentionally stored after the exchange. Raw Play Integrity tokens are not retained in the game database or intentionally logged by the application.
  • Short-window rate-limit records are eligible for cleanup after their active window, although stale records may remain until a later matching request or maintenance operation. IP hashes attached to score, run, report, or other audit records may remain for the same period as those records.
  • Supabase, Google, and our email provider retain operational, security, and support logs according to their configured settings and policies.

To request access to or deletion of a leaderboard entry, an installation’s online wallet, a Play Games link, or other associated online data, email the address below. We may ask for information needed to locate the records and verify that you are entitled to control them. We will delete or anonymize eligible data within a reasonable period, subject to the transaction, fraud prevention, security, legal, accounting, and platform retention described above.

Uninstalling removes the game’s local data, including its local install identifier and pending choices, but does not by itself delete server records, Google Play transaction records, or an active subscription — cancel a subscription through Google Play, as uninstalling does not cancel it.

06

Your choices

  • You can play the core game without submitting a public leaderboard name, linking Play Games, opening the coin store, or making any purchase. When the game is online, the automatic wallet refresh and qualifying run-credit calls described above still occur; playing offline prevents those calls but also prevents online rewards from synchronizing.
  • In the EEA, UK, and Switzerland you can refuse personalized advertising in the consent form; non-personalized ads are shown instead. You can also reset your consent state by clearing the app’s storage, after which the form is shown again.
  • The membership subscription is optional. Becoming a member removes ads; you can cancel at any time through Google Play and keep the perks until the end of the paid period. The leaderboard member badge stays off unless you turn it on.
  • You can decline Play Games sign-in. Linking a new wallet follows successful Google authentication; replacing the current wallet with a previously linked wallet requires a separate restore confirmation.
  • You can decline a restore offer and keep the current wallet. If the current wallet has purchase records, the restore dialog warns you and defaults to keeping it. Wallet balances are never merged.
  • You can avoid opening the coin store or beginning a checkout. Purchase history and refund controls are also available through Google Play. After a checkout attempt, the game may still query Google Play later to recover or finish it.
  • You can use the in-game restore action to ask about a previously linked wallet again later.
  • You can contact us to request access to or deletion of eligible online data.
07

User-generated content

Leaderboard names are user-generated content visible publicly as described above. Names are checked for length, allowed characters, and prohibited words before acceptance. Entries displayed in the game can be reported there; reported or inappropriate names can be hidden or removed by moderation. You can email us about a public entry that is not currently displayed in the game.

08

Children

The game is suitable for a general audience but is not directed at children under 13. We do not ask players for their age, email address, contact list, precise location, or payment-card details in the game. A player chooses any public leaderboard name, so children should not enter their real name or other private information. Online features process the identifiers, gameplay, advertising, purchase, and security data described above. A parent or guardian can contact us about access to or removal of eligible data associated with a child.

09

Changes

If this policy changes, the updated version will be published at the same public address with a new effective date.

10

Contact

Larinae Games — menno@larinae.dev

Tiny Aces All selected work
Larinae.dev Building from The Netherlands