Privacy Policy

MiniArcade, made by 2Buns LLC. Last updated 30 September 2026.

MiniArcade is built to collect as little about you as it can while still doing its job. This page explains what we collect, why, and how to get rid of it.

The short version

What we collect, and when

Using MiniArcade

Some basic technical information is generated just by loading a page or opening the app: your IP address and browser type are visible to Firebase Hosting, which serves this site and the app, in the way that is true of any web server. We do not read this information ourselves.

If you create an account

Signing in uses Firebase Authentication, so your account can follow you between the web app and your phone. Depending on how you choose to sign in, this may include your email address, your name and a profile photo from the sign-in provider you pick.

WhatWhy
Your email address, name and photo, as provided by sign-inTo identify your account and personalize the app
An account identifierTo attach your data and any subscription to you
The data you create in the appStored in Firestore so it survives reinstalling or changing device

If you play on the leaderboards

Free play stays on your device while you are signed out. The Daily, the weekly Featured board and the all-time boards need an account, and once you are signed in, a new personal best in free play is sent to that game's all-time board on its own. Anything on a leaderboard is visible to everyone, including people who are not signed in. We show a nickname you choose, never your email address or your name from the sign-in provider.

WhatWho can see itWhy
Your nicknameEveryoneTo show who holds each score
The season badge and flair you choose to show beside your nickname. One from the premium track shows that you bought that season's passEveryoneTo show the rewards you earned
Your scores, with the game, the board, the time and a random account identifierEveryoneTo rank the boards
A recording of the moves you made in a ranked run, and the run's secret starting pointNobody but usTo replay the run on our server and confirm the score is real
Which boards you have playedYouSo the Daily can be played once, and the app can show that you already have
In the iOS and Android apps, a scrambled code made from your phone's device identifier, with the account that played, when you start the DailyNobody but usSo each phone gets one Daily, whichever account is signed in
Counts of recent submissions and reportsNobody but usTo limit abuse
The tokens you spend on free play, each with the game and the time, the tokens you earn by watching an ad, your token balance and your season XPYouTo charge each run once and to award season XP
Reports you make about another player, with your account identifierNobody but usSo a moderator can review the report and stop anyone flooding the queue
Reports other players make about one of your scores, with your account identifier and your nickname at the timeNobody but usSo a moderator can review the report

The device code is made on your phone, by mixing the identifier your phone gives this app with a value unique to MiniArcade and scrambling the result one way. The identifier itself never leaves your phone, and the code cannot be matched to identifiers used by other apps. The website never sends one.

If you report another player's score, or someone reports yours, we keep the report, including the reported nickname, to review it. Resolved reports are deleted 90 days after they were filed. When you delete your account, we delete every report you filed and every report filed about you.

When a moderator acts on a leaderboard entry or account, for example removing a score, banning a player or resetting a nickname, we keep a record of the action for 12 months and then delete it. If you delete your account, we remove your account ID from these records and keep only the record that the action was taken until it is deleted.

If you subscribe or buy something

We never receive or store your card number. On the web, payment is handled by Stripe, and we pass Stripe your account's email address so the checkout and your receipt reach you. In the apps it is handled by Apple or Google, with RevenueCat telling us only whether a subscription is valid and what you bought; RevenueCat knows your account identifier, so a purchase follows you between devices. For a subscription we store the plan, the status and the renewal date. For tokens or a season pass we store what was bought, when, and whether it was refunded, so it is credited only once.

Analytics

In the web version of MiniArcade, we use Google Analytics for Firebase only if you allow it. The first time you visit, we ask whether you want to share usage analytics, and nothing is collected until you choose Allow. You can change your answer at any time with the 'Share usage analytics' switch in Settings. If you turn it off, collection stops immediately and the analytics code is not loaded on later visits. Our website does not show ads.

In the MiniArcade apps, Google's consent form first determines whether your region requires your consent. Where it does, we also ask separately whether you want to share usage analytics, and nothing is collected until you choose Allow; answering Google's ad consent form is not treated as agreement to analytics. Where consent is not required, usage analytics is on by default, and you can turn it off with the 'Share usage analytics' switch in Settings. That switch controls analytics only: ads are non-personalised and follow the choices you made in Google's consent form, which you can review or change at any time from 'Ad privacy choices' in Settings where Google requires it.

Saying no does not limit the app in any way. What we send is a list of things that happened, not free text and not anything you typed, and it is never tied to your account.

Keeping the leaderboards honest

Before the app can start a ranked game or post a score, it proves to our servers that it is the real MiniArcade using Firebase App Check. On the web that uses Google reCAPTCHA Enterprise, on iPhone Apple's App Attest, and on Android Google Play Integrity. These look at your browser or device to tell a genuine app from a script, and the result is a short-lived pass rather than anything that identifies you. What Google and Apple see is covered by their own privacy policies.

Errors

When something crashes we send a report to Sentry so it can be fixed. These are configured to strip personal data before the report leaves your device: authentication tokens, sign-in links, query strings and full URLs are all removed first.

Ads

The iOS and Android apps show occasional ads from Google AdMob: a full-screen ad between some free-play games, and a video you can choose to watch for a second chance at a free-play game. They are non-personalised: they are chosen by context rather than by anything about you, and we do not ask for tracking permission. Where the law requires it, Google's consent form asks you first, and your answer there, not the analytics switch, decides whether ads are requested. There is never an ad after a Daily or Featured game, no ads on this website, and none anywhere for subscribers.

To show an ad, count it and catch ad fraud, AdMob itself receives your IP address, your device's advertising identifier and which ads you saw and tapped. Google explains how it uses that information.

This website

These pages ask before they count visits with the same Google Analytics property as the app, and nothing loads unless you agree. It tells us how many people arrived and roughly from where; it does not tell us who you are. Your answer is remembered in this browser; clearing this site's data brings the question back.

Where the data is

Account data, application data and analytics are all stored with Google, through Firebase, in the United States. If you are in the UK or the EEA, using an account or agreeing to analytics means your data is transferred to the United States under Google's standard contractual clauses.

How long we keep it

Account data and the data you create in the app are kept until you delete your account. Analytics events are kept for twelve months. Error reports are kept for ninety days.

Leaderboards are cleared on a schedule. Daily boards and their scores are deleted thirty days after the board closes, and weekly boards twelve weeks after. All-time scores stay until you delete your account or a moderator removes them. Recordings of ranked runs, the record of which boards you played and the Daily device code are deleted thirty days after the run, and the record of each token you spent or earned from an ad thirty days after it. Open reports are kept until a moderator resolves them, and resolved reports are deleted ninety days after they were filed. The record of moderator actions is deleted twelve months after each action.

Deleting your data

In the app, go to Settings, then Account, then Delete Account. That removes your account and everything attached to it, including your nickname, your scores on every leaderboard, your ranked run recordings, the Daily device codes stored with your account, your token balance, the record of tokens you spent and your season progress, every report you filed and every report filed about you. A record that a token or season pass purchase was already credited is kept without your account ID, so the same purchase cannot be credited again. Any record of a moderator action taken against your account loses your account ID and is deleted on the twelve-month schedule above. We also delete your customer record at Stripe and your subscriber record at RevenueCat, where you had one. Stripe keeps the payment records the law requires it to keep, and Apple or Google keep their own records of store purchases, which we cannot delete. Deleting your account never cancels a store subscription; cancel it in your Apple ID or Google Play settings. You can also ask us to delete it by writing to support@2bunsllc.com. The full instructions are here.

Your rights

If you are in the UK or the EEA you have the right to access, correct, export or delete your data, to object to processing, and to complain to your data protection authority. If you are in California you have the right to know what is collected, to delete it, and not to be discriminated against for asking. We do not sell personal information, and we never have. Write to support@2bunsllc.com and we will answer within thirty days.

Children

MiniArcade is not directed at children, and we do not knowingly collect anything from anyone under 13.

Changes

If this policy changes in a way that matters, we will say so in the app before the change takes effect rather than quietly updating the date at the top of this page.