Privacy Policy
How R.A.M handles information
This Privacy Policy applies to the current Android release of R.A.M and these R.A.M legal pages. R.A.M Works, based in Israel, is responsible for the processing described here. The game is distributed worldwide in Google Play countries and regions where it is available.
1. Information we process
Firebase accounts and sign-in
If you continue as a guest, Firebase Authentication creates an anonymous account with a stable Firebase user identifier (UID), authentication credentials, and account metadata such as creation and last-sign-in times. A guest account does not require your name or email address.
If you choose Google Sign-In, Google and Firebase may provide and process your Firebase UID, Google provider identifier, email address, display name, profile-photo URL, email-verification status, and sign-in/account timestamps when those fields are available from your Google account. R.A.M does not receive your Google password. Authentication ID and refresh tokens are processed to keep you signed in and authorize Firebase requests.
Backend-request and technical information
When the game contacts Firebase, Google service infrastructure may process your IP address, user agent, Firebase Android app identifier, Firebase Installation ID, app-instance identifiers or tokens, request timestamps, the Cloud Function name, and your Firebase UID when you are signed in. The Firebase callable-functions SDK may automatically attach an FCM registration token or similar app-instance token even though the current R.A.M release does not provide push-notification messaging.
Authenticated callable Cloud Functions in europe-west1 load and save player progression, delete account data, and provide the optional ping connection test. Firebase attaches authentication and technical tokens. Progression functions derive the Firestore document from the authenticated Firebase UID and reject unauthenticated requests. Google Cloud may process operational request logs and diagnostics needed to run and protect the service.
Cloud game progression
R.A.M stores a private Cloud Firestore progression document under your Firebase UID. It contains per-vehicle research progress, selected national research targets, Credits, researched and purchased vehicles, pending research overflow and completion state, nation lineups, active lineup slots, and identifiers of verified rewards already applied. It also contains a schema version, save revision, and server timestamps. It does not contain your Google email, display name, profile photo, or password.
Advertising, age band, and privacy choices
The Android app asks you to select either age 13–17 or age 18+. That age band is stored on the device and is used to configure advertising protections. For ages 13–17, R.A.M requests non-personalized ads with Google's teen treatment and a maximum PG content rating. For ages 18+, UMP may display regional consent or privacy messages and record the resulting personalized, non-personalized, or limited-ad choice. You can change the age band and reopen available advertising privacy choices in Settings.
AdMob and its advertising infrastructure may process the advertising ID where available, IP address, device and app identifiers, approximate location derived from network information, interactions with ads, consent signals, diagnostic information, ad-unit and reward information, and fraud-prevention signals. R.A.M uses one interstitial placement and optional rewarded placements; it does not show an advertisement merely because the game was opened.
Gems, rewarded claims, and Google Play purchases
Gem balances are held in a server-owned wallet. R.A.M stores wallet balance, refund debt, UTC daily rewarded-ad usage, battle receipts, opaque reward-claim identifiers, AdMob transaction identifiers, purchase-token hashes, product IDs, grant and consumption status, refund state, and related timestamps. Battle receipts contain a bounded match summary needed to calculate rewards. These records prevent replay, apply verified rewards once, reconcile delayed rewards, and handle refunds without showing a negative balance.
For a paid Gem pack, Google Play processes the payment method and purchase. R.A.M receives the product ID, purchase token, purchase state, and an obfuscated account identifier; it does not receive full card or bank details. The backend verifies purchases through the Google Play Developer API and consumes verified consumable products. Google Play may retain transaction and payment records under its own terms and legal obligations.
App Check and Google Play Integrity
Production Android builds use Firebase App Check with Google Play Integrity to help distinguish genuine, untampered installations from abusive requests. This may process the app package name, app version, signing-certificate information, request details, integrity and attestation tokens, device-integrity signals, and Play licensing/account signals available to Google Play Integrity. Monetization callable functions enforce App Check. These checks are used for app and backend security, fraud prevention, and abuse protection.
Information stored on your device
R.A.M continues to store device-specific choices locally, including the advertising age band, ammunition selections and loadouts, selected nation and game modes, and preferences such as graphics, sound, interface mode, aim assist, and controls. Research, Credits, Gems, researched or purchased vehicles, and lineups use the Firebase cloud save instead of local storage. A pre-cloud local progression save may be read once for migration when the selected account has no cloud save, then removed after a successful upload.
Android backup remains enabled. Eligible local preferences may therefore be processed by Android or Google through system-managed backup or device-transfer features, depending on your device and Google settings. Those backups are controlled through Android and your Google account.
Visits to these legal pages
These pages are served by Firebase Hosting. Firebase Hosting may process limited request data such as your IP address, browser or user-agent information, requested URL, and request time to deliver and protect the site. These pages contain no advertising, analytics script, account form, or tracking cookie set by R.A.M Works.
2. Why we process information
We process the information above to:
- create and maintain guest or Google-linked Firebase accounts;
- provide a stable Firebase UID and authenticate protected backend calls;
- load and save private game progression for the authenticated account;
- display age-appropriate ads, record privacy choices, and provide optional rewarded ads;
- verify Google Play purchases, maintain the Gem wallet, prevent replay and fraud, and process refunds;
- let players verify connectivity to the deployed backend;
- operate, secure, troubleshoot, and prevent abuse of the app and services;
- remember local ammunition choices and device preferences; and
- respond to privacy, support, and account-deletion requests.
Depending on your location, these activities are carried out to provide the service you request, based on our legitimate interests in operating and securing R.A.M, with consent where applicable, and to comply with legal obligations.
3. Service providers and disclosures
R.A.M uses Google as a service provider, including AdMob, UMP, Google Play Billing and the Android Publisher API, Google Sign-In, Firebase Authentication, Cloud Firestore, Firebase Cloud Functions, Firebase App Check, Firebase Installations, Firebase Hosting, Google Cloud infrastructure, Google Play Integrity, and Android system backup where enabled by you or your device. Google processes information under its own terms and privacy documentation. See the Google Privacy Policy, Firebase Privacy and Security documentation, and Google advertising information.
Information may also be disclosed if reasonably necessary to comply with law, protect users or the service, investigate abuse, or establish and defend legal rights. R.A.M Works does not sell or rent personal information.
4. International processing
R.A.M Works is based in Israel and uses Google services that operate internationally. Information may be processed in Israel, the United States, Europe, and other locations where Google or its subprocessors operate, subject to applicable safeguards. Firebase Authentication data is handled according to Firebase's documented data-location practices, which may differ from the Cloud Function's europe-west1 processing region.
5. Retention
Firebase account information is generally retained while the Firebase account exists. After deletion, Google states that relevant Firebase Authentication data is removed from live systems and later from backups according to its documented deletion cycle, which may take up to 180 days. Firebase Authentication IP logs may be retained for a limited period, and Firebase Hosting request IP data may be retained for a period of months under provider practices.
Cloud progression, the Gem wallet, battle receipts, reward claims, AdMob transaction deduplication records, and R.A.M purchase ledgers are generally retained while the Firebase account exists and are deleted by the in-app account-deletion flow. Cloud Functions and Google Cloud may temporarily process request metadata and operational logs. Google may separately retain advertising, Play transaction, fraud, tax, or legal records under its policies and obligations. R.A.M Works has not configured custom Cloud Logging retention or log sinks and therefore does not claim an exact project-specific log-retention period in this policy. App Check and Play Integrity tokens and attestation data follow Google's service-specific retention practices.
Local preferences remain on the device until they are overwritten, cleared by the user or operating system, or the app's data is removed. Copies in system-managed Android backups may remain until removed or expired under Google's backup practices.
6. Account and data deletion
You can use Settings → Firebase account → Delete account, or the Delete account action in the Firebase account panel. After a strong confirmation, R.A.M deletes the current Cloud Firestore progression, wallet, battle-receipt, reward-claim, ad-transaction, purchase-ledger and entitlement data, then deletes the Firebase Authentication account. If a recent login is required for a Google-linked user, R.A.M asks for Google reauthentication and verifies that the selected Google identity resolves to the same Firebase UID before deletion.
After successful in-app deletion, R.A.M also resets locally stored ammunition selections/loadouts on that installation. Harmless device preferences such as graphics, audio, interface, and control settings may remain. No replacement anonymous account is created automatically. Deleting an R.A.M account does not delete your Google account.
You may also request deletion without opening or reinstalling the app by following the Account Deletion instructions or emailing okninmatan@gmail.com. We will verify requests where reasonably possible. Provider security logs, legally required records, and backup copies may remain for limited periods and are not promised to disappear instantly.
7. Your choices and rights
You may play using a guest Firebase account instead of Google Sign-In, choose whether to watch rewarded ads, change the stored age band, reopen available UMP privacy choices, sign out, delete your account, reset the Android advertising ID through device settings, clear app data through Android settings, and manage Android backup in your device or Google account settings. Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or a copy of personal information, withdraw consent, and complain to a data-protection authority. Contact us to exercise a right. We may request reasonable verification before acting.
8. Security
We use platform and provider safeguards appropriate to the current service, including Firebase Authentication tokens, App Check-protected monetization functions, HTTPS transport, default-deny direct Firestore rules, server-side wallet transactions, AdMob ECDSA callback verification, Google Play Developer API purchase verification, replay-resistant transaction and purchase ledgers, Android application signing, Google Play Integrity, conservative Cloud Function scaling, and UID verification for account deletion. No system can guarantee absolute security.
9. Children's privacy and intended audience
R.A.M is intended for players in the 13–15, 16–17, and 18+ age groups selected in its Google Play target-audience settings. It is not intended for children under 13. Players who select age 13–17 receive Google's teen treatment, non-personalized advertising, and a PG maximum ad-content rating. Google Sign-In is optional because a guest-account option is available. R.A.M Works does not knowingly seek more personal information from a minor than is needed for the account, security, and age-appropriate advertising functions described in this policy.
If a player is below the age at which they can consent to data processing in their country, a parent or legal guardian should authorize use where required by law. A parent or guardian who believes a child's information was processed without the required authorization may contact us to request review and deletion.
10. Changes to this policy
We may update this policy when the app, service providers, or legal requirements change. The effective date at the top will be updated, and material changes will be communicated in the app, store listing, or this page as appropriate. Planned features are not treated as active until they are actually included in a release.
11. Contact
R.A.M Works
Israel
okninmatan@gmail.com