Last Updated: May 25, 2026
Your privacy matters to us. This Privacy Policy explains what personal information Emoji Slap (the “Service”) collects, how we use it, who we share it with, and the rights you have over it. It applies to emojislap.com, app.emojislap.com, and the Emoji Slap iOS application. The Service is operated by Enigma Design Group, a corporation organized under the laws of Wyoming, USA. See also our Terms and Conditions.
1. Information We Collect
- Account information: If you create an account, we collect your email address and (if you sign in with Google) your name and profile picture from your authentication provider. Passwords are handled by our authentication provider and are not stored by us in plaintext.
- Date of birth (age confirmation): Collected at signup to verify you meet our minimum age requirement (13+). Stored as your year of birth only.
- IP address and approximate geographic location: Automatically logged when you use the Service for security, abuse prevention, and aggregated analytics.
- Gameplay telemetry: Game start/end timestamps, scores, modes played, unlock progress, and similar in-game events. Used to operate leaderboards and improve the Service.
- Payment metadata: When you make a purchase, we receive a confirmation token, the product purchased, the amount, and the payment provider’s transaction ID. We do not store credit card numbers, CVV codes, or banking details — payment information is handled directly by Stripe (web) or Apple (iOS).
- Device information (iOS): Operating system version, device type, and app version, collected for diagnostics and crash reporting.
- Cookies and local storage: Used for sign-in sessions, game settings, and (where applicable) consent state. See section 5.
2. How We Use Your Information
- To provide, operate, and maintain the Service.
- To authenticate your account, save your scores, and display leaderboards.
- To process purchases and provide entitlements such as “Go Ad Free.”
- To serve advertisements (subject to your consent and ad-free entitlement).
- To analyze usage patterns, fix bugs, prevent abuse, and improve the Service.
- To communicate with you about account, security, or service updates.
- To comply with legal obligations and enforce our Terms and Conditions.
3. Third-Party Services
The Service relies on the following third parties. Their handling of your data is governed by their own privacy policies:
- Supabase — backend database and authentication (hosted in the United States).
- Stripe — payment processing for web purchases.
- Apple StoreKit — in-app purchase processing for iOS.
- Google Sign-In (OAuth) — optional federated sign-in.
- Google AdSense — web display advertising.
- Google AdMob — mobile in-app advertising (if and when enabled).
- Cloudflare — static site hosting and DNS for emojislap.com.
4. Data Storage & Security
- Account data, scores, telemetry, and payment audit records are stored securely with Supabase, hosted in the United States.
- All data is transmitted over encrypted HTTPS/TLS connections.
- Authentication uses industry-standard hashing and token-based session management.
- Database access is restricted by row-level security policies so users cannot access each other’s data.
- We monitor for unauthorized access and apply security patches promptly.
- While we use industry-standard safeguards, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
5. Cookies & Local Storage
- Essential: Sign-in sessions, account state, and security tokens. These cannot be disabled without breaking core functionality.
- Functional: Game settings, sound preferences, hand-side preference, selected music track, and similar preferences stored in browser localStorage.
- Analytics & advertising: When you have consented (and where required by law), cookies and local storage may be used by Google AdSense and similar services to measure ad performance.
- In regions covered by the EU ePrivacy Directive, non-essential cookies are only set after explicit consent via our cookie banner.
6. Advertising & Personalization
- Where required by law, by your consent choice, or by age (users under 13), the Service requests non-personalized advertising only (the
npa=1signal for AdSense /setRequestNonPersonalizedAds(true)for AdMob). - Users who purchase “Go Ad Free” will not see ads from us.
- On iOS, the Service does not currently track users across other companies’ apps and websites, so no App Tracking Transparency (ATT) prompt is displayed. If this changes in the future, the Service will request ATT permission first.
7. Children’s Privacy (COPPA)
- The game itself is playable anonymously by anyone, including children under 13, without an account and without any personal information being collected.
- Account creation requires users to be at least 13 years old. We verify this at signup using date-of-birth confirmation.
- We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, please contact us at the email below so we can delete it.
8. Your Rights (GDPR, CCPA / CPRA, and Others)
Depending on your location, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion of your account and associated data.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Opt out of personalized advertising.
- Withdraw consent at any time (where processing is based on consent).
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at info@emojislap.com. We will respond within 30 days (or sooner where required by law). California residents: we do not sell or share your personal information for cross-context behavioral advertising as defined by the CCPA/CPRA.
9. International Data Transfers
Our service providers (Supabase, Stripe, Apple, Google, Cloudflare) operate in the United States and may operate in other jurisdictions. By using the Service, you consent to the transfer and processing of your information in those countries. Where required, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.
10. Data Retention
- Account data: Retained while your account is active. Deleted within 30 days of an account deletion request, except where retention is required to resolve disputes, prevent fraud, comply with legal obligations, or enforce our Terms.
- Gameplay telemetry: Aggregated/anonymized telemetry may be retained indefinitely for service improvement. Personal-level telemetry is retained for up to 12 months.
- Payment records: Retained for at least 7 years for tax and audit purposes (independent of account deletion).
- Server logs: Retained for up to 30 days for security and abuse prevention.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last Updated” date above will reflect the most recent revision. Material changes will be communicated through the Service or via email when reasonably practical.
12. Contact
For privacy questions or to exercise your data rights, contact us at:
See also: Terms and Conditions
