Privacy Policy

Rhythm Orbits · Last updated: August 24, 2026
Deutsche Fassung · Delete data

This policy explains what data the Rhythm Orbits app processes.

Controller

Maurice Putinas
Kapellenweg 2a
59457 Werl
Germany
Email: putinasmaurice@gmail.com

Summary

Rhythm Orbits requires no user account. We never ask for your real name or email address; a freely chosen pseudonym is sufficient for community and ranking features. Data leaves your device only for advertising, voluntary community and feedback features, analytics that you explicitly enable, or Google Play Games cloud save.

1. Game progress (device and Google Play Games)

Progress, stars, coins, settings and owned cosmetics are stored locally on your device. If you use Google Play Games, a Saved Games copy is also stored in your Google Play account. We do not receive that save. “Reset progress” removes the local copy completely — and the cloud save only if you are signed in to Google Play Games at that moment; otherwise the app tells you so. It does not remove data held on our server under your community id: published levels, votes you cast, ranking and time-trial entries. Section 9 covers the erasure request for those.

1a. Optional Google Play review

If you deliberately choose “Rate app” in settings, the app requests Google's official in-app review dialog. Any rating entered there is processed directly by Google; our app server receives neither its text nor its star value. Google decides whether the dialog is actually shown based on the account, Play Store installation and usage quotas.

2. Advertising (Google AdMob)

The app shows ads via Google AdMob. Google may process device and advertising identifiers (Advertising ID), IP address, coarse location and interaction data to serve ads and prevent abuse. The provider is Google Ireland Limited.

3. Community levels (voluntary)

When you publish a level you built, the following is stored on our server (Cloudflare, EU) and is visible to all players:

We additionally store a pseudonymous community identifier. On Android, the app derives it from a domain-separated SHA-256 hash of the operating-system-provided ANDROID_ID. The original Android value never leaves the native part of the app. Development environments use a random fallback identifier. The community identifier lets you find your own levels, prevents repeated actions and limits spam; it is not visible to other players.

During the one-time upgrade of an older installation, the app submits the previous random identifier together with the new Android identifier. The server uses possession of the old secret identifier as a migration token, atomically transfers levels, action markers, upload counters and ranking ownership, then stores SHA-256 of the old identifier and the stable target identifier so the transfer cannot be repeated or redirected.

Each community identifier may successfully publish no more than five times in a rolling 24-hour window, may store no more than 30 levels including hidden levels, and may successfully publish no more than 300 levels over its lifetime. Deleting a level does not reduce the lifetime counter. As a further abuse safeguard, the server derives a non-reversible HMAC value from the network address, time window and a secret key. Our app server does not store the raw network address.

You can delete your published levels at any time in the app under “Community → Mine”. Reporting: levels are automatically hidden once enough reports accumulate relative to the play count (from five reports at fifty or more plays) or a high absolute report count is reached. A hidden level stays visible to its creator under “Mine” including its level code and is only permanently deleted after the period in section 8.

When you rate someone else's level with a like or a dislike, the server stores one entry per level carrying your pseudonymous community id. It exists solely to count each vote once; other players only ever see the totals, never who voted. The same applies to reports. When you clear someone else's level, the server stores a clear marker per level and id the same way — this feeds the level's public clear rate without revealing who is behind it. Votes cast without a connection stay on your device until the next connection and are sent then.

4. Progress ranking and abuse protection

The in-app Orbit Ranking displays your chosen display name, highest reached world and level, and total stars. Until you choose a name, the app uses a random pseudonym in the format “Orbit-XXXX”. For ranking, the community identifier is pseudonymised again with SHA-256 before transmission and is not visible to other players.

To protect the ranking, the app and server check completed campaign runs for implausible input patterns. We store only the level ID, expected and actual tap count, failed attempts, shortest tap interval, verification result and timestamp. Touch coordinates, typed content and full movement traces are not transmitted. Private run audits are automatically deleted after no more than 30 days.

Before ranked campaign runs, the server also issues random one-time sessions valid for up to seven days. This lets prepared runs sync in their fixed order after an offline period. Each contains the pseudonymous player identifier, level ID, creation and expiry times, and whether it has been consumed. Jumps to levels that are not yet reachable, reused sessions and implausible star gains are not accepted as trusted ranking progress. A separate HMAC value limits mass session requests without storing the raw network address in our database.

4a. Time-trial leaderboard

Starting a time trial while online creates a random single-use session on the server: pseudonymised player id, chosen route, start and expiry time, and whether it has been consumed. The ranked time is the difference between start and finish measured on the server — your device clock does not decide it. The finish request also carries the per-level splits so implausible runs can be detected.

We keep one row per player and route: your pseudonymised id, the best time, the splits and the timestamp. The board shows your chosen display name, the time and the rank. If a finish request never reaches the server, the run counts locally only; it is not sent later, because the recorded time would then be wrong.

4b. Daily leaderboard

Finishing the daily level while online can enter your result into the daily leaderboard. On start the server issues a random single-use session (pseudonymised player id, day, start and expiry times, consumption state); finishes without a plausible minimum run time are not ranked. We keep one daily best per player and day: pseudonymised id, accuracy, best combo and timestamp. The board shows the display name, value and rank, plus your standing (“better than …%”). Catch-up clears of past days are not entered into other days' boards.

4c. Endless leaderboard

Endless mode runs on the same path every day, generated from the date. If you start it while online, the server issues a random single-use session as for the daily (pseudonymised player id, day, start and expiry times, consumption state). When the run ends we keep one entry per player and day: pseudonymised id, platform reached, accuracy and timestamp. The board shows the display name, platform reached and rank.

5. Feedback (voluntary)

If you send feedback from the settings, we transmit your message, the app version and a technical device string (browser/system identifier) to our feedback server. This helps us reproduce issues. Please do not include sensitive data.

6. Anonymous usage analytics (voluntary)

Only when you enable “Anonymous usage analytics” in settings, we send technical events such as app start, level start, completion, menu access and ad completion to our Cloudflare server. We send no names, level content, Advertising ID or messages. A random installation identifier is pseudonymised with SHA-256 before transmission. You can disable analytics at any time.

7. Legal bases

8. Retention

Published levels remain stored until you delete them or they are removed after reports. Feedback messages are deleted once handled. Advertising data follows Google's retention periods. Pseudonymous analytics events are automatically deleted after no more than 45 days. Private run audits are deleted after no more than 30 days. Expired one-time sessions and HMAC limit values are deleted after no more than two additional days. Community play-count markers are deleted after two days; hidden levels and their markers after no more than 90 days from being hidden. Daily- and endless-leaderboard sessions expire after no more than two days; daily bests and endless entries are deleted after no more than 35 days. Votes, clear markers and reports remain for as long as the rated level exists. The pseudonymous lifetime upload counter remains stored to enforce the 300-upload limit even when individual levels are deleted. The public ranking entry and time-trial best times remain until an erasure request. The mapping between the old community identifier's SHA-256 fingerprint and the stable target identifier remains stored for idempotency and to prevent ownership from being split again.

9. Your rights

You have the right to access, rectification, erasure, restriction, data portability and objection, as well as the right to lodge a complaint with a supervisory authority. Contact us at putinasmaurice@gmail.com. As we keep no accounts, please state your display name or level name so we can identify your data. Step-by-step instructions are on the Delete data page.

9a. Withdrawing advertising consent

You can withdraw your consent to personalised advertising at any time (Art. 7(3) GDPR). Withdrawal takes effect for the future; processing that already happened is unaffected.

Without consent, the app does not request personalised ads.

10. Children

The app is not directed at children under 13. We do not knowingly collect data from children under 13.

10a. Tools used

The music in this app was generated with Stable Audio 3Powered by Stability AI. This notice lived in the app settings until 24 August 2026 and moved here with the new stage artwork; the licence explicitly names “a related website” as an acceptable place. It is not required: the Community License ties its attribution duty to distributing the model or a derivative model, not to distributing generated output.

11. Changes

We update this policy when the app changes. The current version is always available at this address.