BloomStrike Privacy Policy

Effective date: 18 August 2026 · Applies to the BloomStrike web game and the BloomStrike apps for iOS and Android (com.bloomstrike.app).

BloomStrike has no accounts, no sign-in and no player profiles. It never asks for your name, email address, phone number, date of birth or location, and it does not read your contacts, photos, camera, microphone or files. Your game progress is saved on your own device. This page explains the small amount of information that does leave your device, why, and who receives it.

1. Who we are

BloomStrike is published by ARCFIELD STUDIOS LTD (registered in England and Wales, company number 17368040), a company registered in the United Kingdom, of Unit 82a James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE, United Kingdom ("we", "us"). We are the data controller for the processing described in this policy, except where we say otherwise — in particular, Google and Apple act as independent controllers for advertising and for payments.

For any privacy question or request, contact BloomStrike@arcfieldstudios.dev.

2. At a glance

WhatWhere it goesCan it identify you?
Game progress (plants, credits, battles, settings)Stays on your deviceNo — it never leaves your device unless you export it yourself
Product analytics — 14 named gameplay eventsPostHog, EU hostingNo — tied to a random ID created on your device, not to you
Crash and error reports — 1 further eventPostHog, EU hostingNo — message, file name, line number and a short stack trace only
Campaign tags in the link you arrived by (web version only)PostHog, EU hostingNo — it records which advert or link brought you, not who you are
Advertising identifier and ad request data (installed app only — the web version requests no ads)Google (AdMob)Google treats the advertising ID as personal data; we never receive it
In-app purchasesApple or Google — never usWe never see your card, billing address or store account

3. What is stored on your device

BloomStrike is an offline-first game. Your save — plants, seeds, credits, items, battle record, tournament progress, tutorial state and any purchases you have made — is written to your device's local storage, and on the installed iOS and Android apps to the app's own private preferences store as a backup copy. It is not uploaded anywhere, and there is no cloud save.

The app stores these items on your device and nothing else:

Export and Import. Settings → Export produces a backup code containing your save. You choose where that code goes. If you paste it into an email, a notes app or a messaging service, that service — not us — then holds it. We never receive exported codes.

4. Analytics — what we actually collect

We use PostHog as our product analytics provider, on its EU-hosted service (eu.i.posthog.com), to understand how the game is played: whether players get through the tutorial, which parts of the loop they reach, and whether the game is crashing. No analytics SDK or third-party script is loaded into the game; the game posts its own events directly.

Every event carries the same small set of standard properties, and then only the extra properties listed for that event in the table below. The standard properties are:

There is no advertising ID, device model, device name, screen size, language, IP-derived location, email address or account identifier attached to any analytics event. These are the only events that exist:

EventWhen it firesExtra properties
game_startedEvery time the game is openedNone
session_returnEvery open after the first one on that deviceNone
tutorial_completedTutorial finishedNone
tutorial_skippedTutorial skippedNone
seed_plantedA seed is plantedSeed id, species, rarity, whether it can mutate
plant_growth_stage_advancedA plant reaches a new growth stageSpecies, previous stage, new stage, level
battle_startedA battle beginsLeague, mode (mission or tournament), species, growth stage
battle_won / battle_lostA battle endsMode, and round, campaign, stage or boss flag depending on mode
first_battle_wonOnce ever, on the first winNone
rewarded_ad_watchedYou watch an optional rewarded ad to the endNone
interstitial_shownA full-screen ad is shown between sections of the gameWhich point in the game it was shown at
save_exported / save_importedYou use the backup code featureNone (never the code itself)
client_errorThe game hits an uncaught error, at most 5 times per sessionError message (max 300 characters), source file name only, line and column number, and the first few stack frames (max 500 characters)

Crash reports are deliberately narrow. Any query string is stripped from file paths and stack traces before an error is reported, and only the file name — not the full URL — is kept, so that a link you followed can never travel with a crash report.

IP address. As with any request sent over the internet, PostHog's servers receive the network address the request came from. We do not add your IP address to an event, and we do not use it to identify or locate you.

Campaign attribution — web version only

If you reach the web version through a link that carries campaign tags — the standard utm_source, utm_medium, utm_campaign, utm_content and utm_term parameters — those tags are recorded once, on that first visit, together with the address of the site that referred you. Each value is truncated, and any query string is stripped from the referring address before it is stored, so a link you followed cannot carry a token or a search term into our analytics.

This is recorded once and never rewritten, so it tells us which advert or link first brought a player to the game. It is not a browsing history: we see only the one page that linked to us, on the first visit, and referrals from within BloomStrike itself are ignored. The installed iOS and Android apps launch from an icon with no link to read, so they record no attribution at all.

What this data cannot do. No advertising identifier, device identifier or account is ever attached to analytics. We cannot connect these events to you as a person, and we cannot connect them to your activity in any other app or on any other website — and we do not attempt to.

5. Advertising

The installed iOS and Android apps show ads supplied by Google AdMob, in two forms:

The web version at bloomstrike.vercel.app shows only a local placeholder animation — it makes no ad requests, contacts no ad network, and no advertising identifier is involved.

When an ad is requested on the installed app, Google's advertising SDK may collect and use:

Google is an independent recipient, not our processor. Google determines how it uses this information for serving, capping, measuring and — where you have consented — personalising ads, and for detecting invalid traffic. That use is governed by Google's own privacy policy at policies.google.com/privacy. We never receive your advertising identifier, and we receive no ad-level or per-player data from Google — only aggregate revenue and performance figures in the AdMob console.

Google is also told, at initialisation, that BloomStrike is not directed to children, is not tagged for users under the age of consent, and that ad content must be rated no higher than "Parental Guidance".

Consent, and how to change it

Where the UK GDPR, the EU GDPR or ePrivacy rules require it, consent for advertising is collected through Google's User Messaging Platform (UMP) before any ad is requested. If you do not consent, ads that require consent are not requested. On iOS, the system App Tracking Transparency prompt is shown before Google's ad SDK is initialised; if you decline, the app does not get access to the IDFA.

To review or change your advertising choices at any time, open the installed app and go to ⚙️ Settings → 🔒 Advertising Privacy → “Manage privacy choices”. That button reopens Google's own consent form for your region. It is shown whenever Google reports that a privacy-options entry point is required in your region — if you do not see it, Google has determined that no such control applies where you are.

On iOS you can also change tracking permission at any time in iOS Settings → Privacy & Security → Tracking. On Android you can reset or delete your Advertising ID in your device's Google settings.

6. In-app purchases

The installed apps offer optional in-app purchases (credit packs, content bundles and a one-off "Remove Ads" purchase) through Apple's App Store and Google Play, using the cordova-plugin-purchase billing library.

Apple's and Google's own privacy policies govern what they do with your payment information.

7. What we do not collect

To be explicit, BloomStrike has no code path that collects, requests or transmits any of the following:

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

8. Who your information is shared with

RecipientWhat they receiveTheir role
PostHog (EU hosting)The analytics and error events listed in section 4Processor acting on our instructions
Google (AdMob and User Messaging Platform)Advertising identifier and ad request data, from the installed app onlyIndependent controller for advertising purposes
Apple / Google PlayYour purchase and payment details, collected directly by themIndependent controllers
VercelStandard web server logs when you load the web version, including IP address, as part of serving the pageProcessor / hosting provider

We do not share your information with anyone else. We may disclose information if we are legally required to, or to establish or defend legal claims.

9. Where your information is held

Analytics are sent to PostHog's EU-hosted service and stay in the EU. Google and Apple operate globally and may transfer information outside the UK and EEA under their own published safeguards, such as standard contractual clauses and the UK international data transfer addendum. Where we transfer personal data outside the UK or EEA, we rely on those safeguards.

10. Legal basis for processing (UK GDPR and EU GDPR)

11. Children

BloomStrike is not directed to children. We do not knowingly collect personal information from children, and the game asks for none: there is no account, no name, no email address, no location and no messaging. Advertising is explicitly configured as not child-directed and not tagged for users below the age of consent, with ad content capped at a "Parental Guidance" rating.

If you are a parent or guardian and believe a child has provided information to us, contact BloomStrike@arcfieldstudios.dev and we will act on it. Because the game collects no identifying information, the most immediate remedy is on the device itself — see section 12.

12. Keeping, deleting and stopping

How long we keep things

Deleting your data

13. Your rights

If you are in the UK or the EEA you have the right to access your personal data; to have inaccurate data corrected; to have data erased; to restrict or object to processing, including profiling; to data portability; and to withdraw consent at any time where processing is based on consent. Exercising any of these rights is free and we will respond within one month.

You also have the right to complain to a supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk). In the EEA it is your national data protection authority. We would appreciate the chance to address your concern first.

14. Contact

Privacy questions, requests and complaints: BloomStrike@arcfieldstudios.dev, or write to ARCFIELD STUDIOS LTD (registered in England and Wales, company number 17368040), Unit 82a James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE, United Kingdom.

15. Changes to this policy

If we change what BloomStrike collects or who receives it, we will update this page and change the effective date at the top. Material changes affecting how we use your information will be described here rather than silently applied. This policy version is dated 18 August 2026.