The short version. Carnetics runs on a random device identifier instead of your name, email or phone number. We keep the minimum needed to run the game — your progress, your purchases, your support messages and a small legal record of your Terms acceptance. There is no email address on your account — even Google sign-in, when it is offered, gives us only a player ID — so support replies happen inside the game. A one-time Restore Key (stored by us only as a hash) lets you move your account to a new device yourself. We never sell personal data, there are no ads anywhere — not in the game, not on this website — and you can permanently delete your account from inside the game at any time. The details follow.
The data controller for the Carnetics game and the carnetics.app / playcarnetics.com websites is Hareful Concepts, established in Türkiye; correspondence address: as published on our Google Play developer listing. The full identity of the developer and data controller is stated at the end of this policy (Developer & Data Controller). Privacy contact: privacy@carnetics.app. For individuals in Türkiye, the Turkish-language disclosure required by Law No. 6698 (KVKK) is published separately at carnetics.app/kvkk; it describes the same processing as this policy.
This policy covers personal data processed (a) in the Carnetics mobile game and its backend services, and (b) on our websites. It does not cover third-party services acting as independent controllers — most importantly Google Play (your Google account, payments, refunds) — which are governed by their own privacy policies.
| Data | What it is | Why we process it |
|---|---|---|
| Device identifier | A random identifier generated on your device at first launch. It is your account key — no name, email or password is required to play. | Creating and operating your account; keeping your progress; security and abuse prevention. |
| Username | Auto-assigned starter name, changeable by you (subject to filters). Visible to other players on leaderboards and race results. | Identifying you in social features; content moderation. |
| Gameplay & progress data | Inventory (parts, cars, batteries, skins), currency balances, scans, races, levels, rewards, cargo mail (system mails without rewards auto-expire after 30 days), team membership, leaderboard scores, timestamps such as account creation and last activity. | Running the game — this is your save file; balancing and fixing the game; preventing cheating. |
| Restore Key & device session | If you claim your account's one-time Restore Key, we store only a one-way cryptographic hash of it — the key itself appears once on your screen and is never saved by us in readable form. We also hold a random session token marking the one device your account is currently active on, related timestamps, and a counter of wrong key entries (three wrong entries lock a device's restore attempts for 24 hours). | Letting you move and recover your account yourself; keeping the account active on a single device at a time; protecting the key against guessing. |
| Terms-acceptance record | The Terms version you accepted, the acceptance timestamp, the IP address at the moment of acceptance and the coarse country derived from it. | Proving that consent to the Terms was actually given (legal record-keeping). This is the only place the game deliberately stores an IP address on your account. |
| Purchase records | For each real-money purchase: the Google Play order identifier, purchase token, product/SKU, amount and currency, and timestamps. We never receive card or bank details — Google processes the payment. | Crediting your purchase; fraud prevention; refund handling; bookkeeping and tax obligations under Turkish law. |
| Support requests | Your message text plus an automatic context snapshot taken at submit time: ticket number, your device identifier, account age, current premium balance, your last 5 top-ups, and — as provided by your app — device model, OS version, app version, locale and region. Where your account carries them, pseudonymous identifiers such as a linked Google Play Games player ID may be attached. No email address is attached — we do not have one. | Diagnosing and answering your request, investigating problems and fraud, keeping a record of support history. Weekly/monthly submission limits use the same record to prevent abuse. |
| Security & enforcement records | Rate-limit and anti-abuse counters and cooldowns; audit entries for administrative actions on your account; and — where an account is banned — the associated device identifier and (once linking ships) Google Play Games identifier, ban reason and duration, kept as historical records even after a ban ends. Deletion confirmation codes and Restore Keys are stored only as one-way hashes, never in plain text. | Keeping the game fair; enforcing bans (including preventing ban evasion through new accounts); protecting the service from attacks; accountability for administrative actions. |
| Technical request data | Standard connection data that any online service sees when your app talks to it: your IP address and request metadata (for example, the app-version header your client sends). Processed transiently at our edge provider (Cloudflare) and in short-lived server logs and in-memory rate-limit counters. | Delivering the game, its downloadable art assets and the website; blocking attacks and abuse. Except for the Terms-acceptance record above, the game does not store IP addresses on your account. |
| Optional account linking (when offered) | Your Google Play Games player identifier — an opaque ID. Google does not share your email address with us for this, and we never receive or store it. | A second recovery layer next to the Restore Key; keeping enforcement meaningful across devices. |
| App integrity signals (planned) | Verdict tokens from Google's Play Integrity API confirming the app is genuine and unmodified. | Anti-cheat and anti-fraud. The verdict comes from Google; we verify it server-side. |
The scan mechanic reads your device's motion/orientation sensors (e.g. gyroscope) so that turning with your phone drives the scanner. This sensor stream is processed on your device only and is not transmitted to or stored on our servers.
Where the EU/UK GDPR applies, and in parallel under Articles 5–6 of Turkish Law No. 6698 (KVKK), we rely on:
We use a small set of service providers (processors) and partners. We share only what each needs:
| Recipient | Role | Data involved |
|---|---|---|
| Google (Play Billing, Play Games Services, Play Integrity) | App distribution, payments, optional account linking, app integrity. For payments and your Google account, Google acts as an independent controller. | Purchase/order data; Play Games player ID if you link (no email); integrity verdicts. |
| Fly.io | Application/server hosting — our game backend runs on Fly.io machines in Singapore | All game/API traffic and the data in Section 3.1, in transit and in processing. |
| MongoDB Atlas | Database hosting — our database cluster runs in the Asia-Pacific (Singapore) cloud region | All account/game data listed in Section 3.1, at rest. |
| Cloudflare | Website, API and game-asset delivery (CDN), DDoS/security protection and edge rate-limiting, DNS, email routing for our @carnetics.app addresses | IP addresses and request metadata of visitors/players; emails sent to our addresses. |
| Resend | Transactional email delivery of new-ticket notifications to the operator's own inbox | Support ticket content and its context snapshot. |
| Slack | Internal notification of new support tickets to the operator | Support ticket content and its context snapshot. |
We may also disclose data where required by law or a valid authority request, to enforce our Terms, to protect players or the service, or as part of a business transfer (with this policy's protections travelling with the data). We do not sell personal data.
Our providers listed above may store or process data outside Türkiye and outside the EEA — primarily in Singapore (our application servers and database cluster) and, depending on the provider, also in the EU or the United States. Where that happens:
| Data | Retention |
|---|---|
| Account & gameplay data | For as long as your account exists. Erased on deletion (Section 9). Accounts continuously inactive for 36 months may be deleted through the same process. |
| Restore Key hash & session records | Life of the account; destroyed with the account on deletion — a written-down key for a deleted account stops working. |
| Terms-acceptance record (version, time, IP, country) | Life of the account; removed with the account on deletion. |
| Purchase records | Up to 10 years after the transaction, to meet Turkish commercial and tax record-keeping duties (Turkish Commercial Code and Tax Procedure Law). After account deletion these records are kept in anonymised form: your identifiers are stripped and only the financial trail (e.g. Google order numbers, amounts, dates) remains, which no longer identifies you. |
| Support tickets | Up to 3 years after closure for quality and dispute purposes; anonymised immediately if you delete your account. |
| Ban/enforcement records | Ban history entries (identifier, reason, period) are kept as audit records even after a ban expires or is lifted. On account deletion, device-level anchors are released; only for permanently banned accounts a minimal person-level anchor is retained (Section 9). |
| Server & security logs | Short rolling windows appropriate to security operations, typically days to a few weeks; in-memory rate-limit counters last minutes. |
| Email correspondence | As long as needed to handle the matter and any follow-up, then deleted in periodic clean-ups. |
You can delete your account from inside the game at any time. The flow asks for a short confirmation code so that a stolen or shared device can't silently destroy your account. Deletion runs as a single atomic operation on our servers, and we believe you deserve to know precisely what it does:
If you cannot access the game (lost device, uninstalled app): first, if you claimed your Restore Key, you can restore the account on any device (Options → Restore Management) and use the in-app deletion flow yourself. If you never claimed a key, contact privacy@carnetics.app and we will try to verify that you control the account — normally by matching a Google Play order number of a purchase made on it. If we cannot reasonably verify control, we may refuse the request, as GDPR Article 11 provides for data we cannot attribute to a requester: acting on an unverified claim would put the real owner's account at risk. The in-app deletion flow remains the authoritative path, and accounts we can no longer attribute to anyone are in any case removed by the inactivity policy above.
Depending on where you live, you have rights under the GDPR (Articles 15–22), the KVKK (Article 11) and similar laws, including the right to:
How to exercise them: your Restore Key already gives you self-service control of the account from any device. For everything else, email privacy@carnetics.app (Türkçe or English). Because accounts are pseudonymous, we will ask you to prove control of the account — normally by sending the request from inside the game's support form, or by providing your username plus a matching Google Play order number. We respond within 30 days (KVKK) / one month (GDPR), extendable where the law allows.
Complaints: you may lodge a complaint with the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu — kvkk.gov.tr) or, where the GDPR applies, with your local supervisory authority.
The Service is not directed to children under 13, and we do not knowingly collect personal data from them. The game does not ask for names, contact details or precise location from anyone, which limits exposure by design. If you believe a child under 13 (or under the applicable digital-consent age in your country) is using the Service, contact privacy@carnetics.app and we will delete the account.
We design server-first: authoritative game state, purchases and rewards are decided and validated on our servers, never trusted from the client. Additional measures include TLS encryption in transit, access to production data limited to the operator, one-way hashing of deletion codes and Restore Keys (never stored in plain text), single-active-session enforcement, atomic transactions to prevent corrupted half-states, rate limiting at both the edge and the application, layered anti-abuse checks, and infrastructure protections (Cloudflare security, restricted database network access, backups). No online service can promise absolute security; if a breach ever creates a high risk for you, we will notify you and the competent authority as the law requires (including the KVKK's 72-hour notification practice).
The website uses only strictly necessary storage (your cookie choice and Cloudflare's security cookies). Full detail, including how to change your choice at any time, is in the Cookie Policy.
We will update this policy as the Service evolves (for example, when Google Play Games sign-in or Play Integrity goes live). The version and date at the top always tell you what you are reading; material changes will be announced in-game and/or on this site. Questions and requests: privacy@carnetics.app · Hareful Concepts, Türkiye — correspondence address: as published on our Google Play developer listing.