Controlled beta disclosure
Privacy
This page describes the current Android controlled-beta data boundary. It will be reviewed again before a public store release.
Data used by the beta
- Account identity: Firebase account identifier, sign-in provider, email address, verification state, and public player handle.
- Game and social data: scores, words submitted to authoritative game services, matches, progression, profile selections, friends, challenges, blocks, and presence.
- Support and safety data: your submitted description and only the diagnostic fields shown in the in-app preview; immutable contextual evidence for player/content reports; case messages, status, and audit history.
- Reliability data: Firebase Crashlytics receives automatic beta/release crash and ANR reports plus three fixed terminal gameplay-authority signals. The app does not set a Crashlytics user ID or add player words, messages, support content, account IDs, match IDs, tokens, or arbitrary logs.
- Notifications: a device installation identifier and Firebase Cloud Messaging token when challenge alerts are enabled.
Providers and purpose
Google Firebase and Google Cloud provide authentication, database, callable backend, App Check, notifications, hosting, and crash/ANR infrastructure. Data is used to operate accounts and games, protect integrity and safety, respond to support cases, and diagnose failures. The current website loads no behavioral-measurement or ad-serving service.
Retention and beta resets
Operational game/profile data remains while the beta account is active unless a controlled reset or deletion applies. Technical support diagnostics are scheduled for earlier deletion than ordinary case records; ordinary support authority is scheduled for 12 months after closure, safety evidence for 24 months, and audits last, subject to a documented hold. Beta data may be reset before public release after tester notice when practical.
Your controls
You can disable challenge notifications, block players, submit a support case, appeal a moderation action, and use the authenticated account-deletion route when its controlled admission is available. Email alone never proves account ownership or authorizes deletion.
Contact
For privacy questions, use the in-app Support Center or email privacy@bowlwithwords.com. Do not email passwords, verification codes, or authentication tokens.