BloomStrike has no accounts, no sign-in and no player profiles. It never asks for your name, email address, phone number, date of birth or location, and it does not read your contacts, photos, camera, microphone or files. Your game progress is saved on your own device. This page explains the small amount of information that does leave your device, why, and who receives it.
BloomStrike is published by ARCFIELD STUDIOS LTD (registered in England and Wales, company number 17368040), a company registered in the United Kingdom, of Unit 82a James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE, United Kingdom ("we", "us"). We are the data controller for the processing described in this policy, except where we say otherwise — in particular, Google and Apple act as independent controllers for advertising and for payments.
For any privacy question or request, contact BloomStrike@arcfieldstudios.dev.
| What | Where it goes | Can it identify you? |
|---|---|---|
| Game progress (plants, credits, battles, settings) | Stays on your device | No — it never leaves your device unless you export it yourself |
| Product analytics — 14 named gameplay events | PostHog, EU hosting | No — tied to a random ID created on your device, not to you |
| Crash and error reports — 1 further event | PostHog, EU hosting | No — message, file name, line number and a short stack trace only |
| Campaign tags in the link you arrived by (web version only) | PostHog, EU hosting | No — it records which advert or link brought you, not who you are |
| Advertising identifier and ad request data (installed app only — the web version requests no ads) | Google (AdMob) | Google treats the advertising ID as personal data; we never receive it |
| In-app purchases | Apple or Google — never us | We never see your card, billing address or store account |
BloomStrike is an offline-first game. Your save — plants, seeds, credits, items, battle record, tournament progress, tutorial state and any purchases you have made — is written to your device's local storage, and on the installed iOS and Android apps to the app's own private preferences store as a backup copy. It is not uploaded anywhere, and there is no cloud save.
The app stores these items on your device and nothing else:
Export and Import. Settings → Export produces a backup code containing your save. You choose where that code goes. If you paste it into an email, a notes app or a messaging service, that service — not us — then holds it. We never receive exported codes.
We use PostHog as our product analytics provider, on its EU-hosted service (eu.i.posthog.com), to understand how the game is played: whether players get through the tutorial, which parts of the loop they reach, and whether the game is crashing. No analytics SDK or third-party script is loaded into the game; the game posts its own events directly.
Every event carries the same small set of standard properties, and then only the extra properties listed for that event in the table below. The standard properties are:
There is no advertising ID, device model, device name, screen size, language, IP-derived location, email address or account identifier attached to any analytics event. These are the only events that exist:
| Event | When it fires | Extra properties |
|---|---|---|
| game_started | Every time the game is opened | None |
| session_return | Every open after the first one on that device | None |
| tutorial_completed | Tutorial finished | None |
| tutorial_skipped | Tutorial skipped | None |
| seed_planted | A seed is planted | Seed id, species, rarity, whether it can mutate |
| plant_growth_stage_advanced | A plant reaches a new growth stage | Species, previous stage, new stage, level |
| battle_started | A battle begins | League, mode (mission or tournament), species, growth stage |
| battle_won / battle_lost | A battle ends | Mode, and round, campaign, stage or boss flag depending on mode |
| first_battle_won | Once ever, on the first win | None |
| rewarded_ad_watched | You watch an optional rewarded ad to the end | None |
| interstitial_shown | A full-screen ad is shown between sections of the game | Which point in the game it was shown at |
| save_exported / save_imported | You use the backup code feature | None (never the code itself) |
| client_error | The game hits an uncaught error, at most 5 times per session | Error message (max 300 characters), source file name only, line and column number, and the first few stack frames (max 500 characters) |
Crash reports are deliberately narrow. Any query string is stripped from file paths and stack traces before an error is reported, and only the file name — not the full URL — is kept, so that a link you followed can never travel with a crash report.
IP address. As with any request sent over the internet, PostHog's servers receive the network address the request came from. We do not add your IP address to an event, and we do not use it to identify or locate you.
If you reach the web version through a link that carries campaign tags — the standard utm_source, utm_medium, utm_campaign, utm_content and utm_term parameters — those tags are recorded once, on that first visit, together with the address of the site that referred you. Each value is truncated, and any query string is stripped from the referring address before it is stored, so a link you followed cannot carry a token or a search term into our analytics.
This is recorded once and never rewritten, so it tells us which advert or link first brought a player to the game. It is not a browsing history: we see only the one page that linked to us, on the first visit, and referrals from within BloomStrike itself are ignored. The installed iOS and Android apps launch from an icon with no link to read, so they record no attribution at all.
What this data cannot do. No advertising identifier, device identifier or account is ever attached to analytics. We cannot connect these events to you as a person, and we cannot connect them to your activity in any other app or on any other website — and we do not attempt to.
The installed iOS and Android apps show ads supplied by Google AdMob, in two forms:
The web version at bloomstrike.vercel.app shows only a local placeholder animation — it makes no ad requests, contacts no ad network, and no advertising identifier is involved.
When an ad is requested on the installed app, Google's advertising SDK may collect and use:
Google is an independent recipient, not our processor. Google determines how it uses this information for serving, capping, measuring and — where you have consented — personalising ads, and for detecting invalid traffic. That use is governed by Google's own privacy policy at policies.google.com/privacy. We never receive your advertising identifier, and we receive no ad-level or per-player data from Google — only aggregate revenue and performance figures in the AdMob console.
Google is also told, at initialisation, that BloomStrike is not directed to children, is not tagged for users under the age of consent, and that ad content must be rated no higher than "Parental Guidance".
Where the UK GDPR, the EU GDPR or ePrivacy rules require it, consent for advertising is collected through Google's User Messaging Platform (UMP) before any ad is requested. If you do not consent, ads that require consent are not requested. On iOS, the system App Tracking Transparency prompt is shown before Google's ad SDK is initialised; if you decline, the app does not get access to the IDFA.
To review or change your advertising choices at any time, open the installed app and go to ⚙️ Settings → 🔒 Advertising Privacy → “Manage privacy choices”. That button reopens Google's own consent form for your region. It is shown whenever Google reports that a privacy-options entry point is required in your region — if you do not see it, Google has determined that no such control applies where you are.
On iOS you can also change tracking permission at any time in iOS Settings → Privacy & Security → Tracking. On Android you can reset or delete your Advertising ID in your device's Google settings.
The installed apps offer optional in-app purchases (credit packs, content bundles and a one-off "Remove Ads" purchase) through Apple's App Store and Google Play, using the cordova-plugin-purchase billing library.
Apple's and Google's own privacy policies govern what they do with your payment information.
To be explicit, BloomStrike has no code path that collects, requests or transmits any of the following:
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
| Recipient | What they receive | Their role |
|---|---|---|
| PostHog (EU hosting) | The analytics and error events listed in section 4 | Processor acting on our instructions |
| Google (AdMob and User Messaging Platform) | Advertising identifier and ad request data, from the installed app only | Independent controller for advertising purposes |
| Apple / Google Play | Your purchase and payment details, collected directly by them | Independent controllers |
| Vercel | Standard web server logs when you load the web version, including IP address, as part of serving the page | Processor / hosting provider |
We do not share your information with anyone else. We may disclose information if we are legally required to, or to establish or defend legal claims.
Analytics are sent to PostHog's EU-hosted service and stay in the EU. Google and Apple operate globally and may transfer information outside the UK and EEA under their own published safeguards, such as standard contractual clauses and the UK international data transfer addendum. Where we transfer personal data outside the UK or EEA, we rely on those safeguards.
BloomStrike is not directed to children. We do not knowingly collect personal information from children, and the game asks for none: there is no account, no name, no email address, no location and no messaging. Advertising is explicitly configured as not child-directed and not tagged for users below the age of consent, with ad content capped at a "Parental Guidance" rating.
If you are a parent or guardian and believe a child has provided information to us, contact BloomStrike@arcfieldstudios.dev and we will act on it. Because the game collects no identifying information, the most immediate remedy is on the device itself — see section 12.
If you are in the UK or the EEA you have the right to access your personal data; to have inaccurate data corrected; to have data erased; to restrict or object to processing, including profiling; to data portability; and to withdraw consent at any time where processing is based on consent. Exercising any of these rights is free and we will respond within one month.
You also have the right to complain to a supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk). In the EEA it is your national data protection authority. We would appreciate the chance to address your concern first.
Privacy questions, requests and complaints: BloomStrike@arcfieldstudios.dev, or write to ARCFIELD STUDIOS LTD (registered in England and Wales, company number 17368040), Unit 82a James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE, United Kingdom.
If we change what BloomStrike collects or who receives it, we will update this page and change the effective date at the top. Material changes affecting how we use your information will be described here rather than silently applied. This policy version is dated 18 August 2026.