Privacy Policy
Last updated: September 5, 2026Data Controller: Volchron Studio, acting as data controller under applicable law, including Turkish Personal Data Protection Law No. 6698 (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR).
Contact: support@volchron.com
1. About the Game
Umbrella can be played without creating an account. Core progress remains on your device. A verified Apple sign-in or verified email account is required only for the optional Gem account service, native purchases, purchase restoration, Gem spending and account deletion. This account requirement keeps purchased currency and inventory with the original game account.
2. Information We Process
Depending on the features you use, the following data may be processed:
- Account data: sign-in provider, Firebase user ID, verification state, and an email address or Apple private relay address when supplied by the sign-in method, plus password-reset or verification events where applicable.
- Purchase and Gem data: store product identifiers, purchase and event times, RevenueCat customer and entitlement state, Gem grants and debits, purchased inventory, utility use, refund-review state, and hashed references that bind a store transaction to its original game account.
- Gameplay needed for Gem services: run identifier, mode, timing, paid-revive state, and the inventory or utility action being applied. Device-only scores, progression and tournament nicknames are not sent by the Gem service.
- Security data: Firebase App Check App Attest or DeviceCheck verification material, app and device details needed to verify the request, and an IP address processed temporarily by Cloudflare Workers for rate protection. The commerce database does not retain your IP address, password, payment-card details or raw store receipt.
- Advertising data: Google Mobile Ads may process the iOS IDFA or Android advertising ID, ad views and interactions, diagnostics, performance data and an approximate region derived from network information, subject to consent and platform settings. Umbrella does not request GPS or precise location.
- Support data: the address and message you send when you contact support.
Firebase manages credentials and the App Store or Google Play handles payment-card information. Volchron Studio does not receive your payment-card number.
3. Purposes and Legal Bases
| Purpose | Basis |
|---|---|
| Run the game and secure Gem account actions | Performance of contract / legitimate interest |
| Authenticate accounts, restore purchases and prevent duplicate or transferred purchases | Performance of contract / legitimate interest |
| Validate purchases, grant Gems, record spending and handle verified refund events | Performance of contract / legal obligation |
| Measure service quality and diagnose SDK performance | Legitimate interest |
| Personalised advertising where enabled | Consent where required |
| Contextual advertising | Legitimate interest or applicable consent choice |
| Respond to support and legal requests | Legitimate interest / legal obligation |
You can withdraw advertising consent through Umbrella's Privacy Options or your device settings. Withdrawal does not affect processing already completed lawfully.
4. Providers and Transfers
We use Sign in with Apple as an optional account provider and Apple App Store and Google Play for distribution and billing; Firebase Authentication, Firestore and App Check for account and integrity services; RevenueCat for purchase validation, entitlements and virtual-currency events; Cloudflare Workers for the authenticated commerce API; and Google Mobile Ads for advertising and consent management. These providers process data under their own terms and privacy notices and may process it outside your country under appropriate legal safeguards.
5. Advertising and Consent
The free version may show ads. Google Mobile Ads can use advertising identifiers and ad interaction data for delivery and measurement when platform consent permits it. If you do not consent, contextual ads may still be shown. Ads are removed by the Remove Ads or Ultra Pass purchase; VIP Pass and individual cosmetic purchases do not remove ads.
- iOS: Settings → Privacy & Security → Tracking
- Android: Settings → Privacy → Ads
6. Account Ownership, Refunds and Abuse Prevention
Apple or Google decides whether a refund is granted. If a platform reports an approved Gem-package refund, the service can pause Gem commerce while it verifies the event, remove unused Gems and inventory paid entirely from that purchase, and reconcile items paid from multiple valid purchases. Past utility or revive use cannot be undone; its source record is kept for the review. Independently earned or separately purchased rights are preserved. We do not decide whether the platform should grant a refund.
We use idempotent server records, App Check replay protection, purchase ownership hashes, rate limits and signed RevenueCat events to reduce duplicate grants, account switching and automated abuse. No online service can guarantee absolute security or prevent every fraudulent platform transaction.
7. Retention and Account Deletion
Account-linked commerce records are retained while the account is active so that purchases, spending and refund events can be reconciled. From Settings → Gem account → Delete account, authenticated users can request deletion. The service removes the account's email-linked data, unused Gems, inventory, spending, run, refund and purchase-index records after pending transactions are reconciled. Minimal opaque tombstones may remain to stop delayed store events from recreating a deleted purchase; records required by law or unresolved store investigations may remain. Firebase states that deleted Authentication data can remain in live or backup systems for up to 180 days, and App Check replay material may be retained for up to 30 days.
Store subscriptions, if any are offered by a platform, must be cancelled in that platform. Device-only progress is separate from account deletion.
8. Data Sharing
We do not sell, rent or trade personal data. Data is shared only with the providers described above, with authorities when legally required, or as part of a permitted merger or asset transfer.
9. Security
Access is restricted by role. The client never contains RevenueCat webhook secrets, Firebase service-account keys or store private keys. Commerce mutations require Firebase authentication, App Check and server-side validation; signed webhook bodies are verified before event routing. These measures reduce risk but cannot make digital infrastructure infallible.
10. Your Rights
Subject to applicable law, you may request access, correction, deletion, restriction, objection, portability or withdrawal of consent. Contact support@volchron.com; we normally respond within 30 days and may verify your identity. You may also complain to your local data-protection authority.
11. Children's Privacy
Umbrella is intended for users aged 13 and older, or the higher minimum age required in your jurisdiction. It is not directed to children below that age. If you believe a child supplied personal data, contact support@volchron.com so we can investigate and delete it where appropriate.
12. Changes
We may update this policy. The new version is effective when published here; material changes may also be shown in the app's legal-consent screen.
13. Governing Law
This policy is governed by the laws of the Republic of Turkey. Mandatory rights in your place of residence, including GDPR rights where applicable, remain unaffected.
Contact
Questions or privacy requests: support@volchron.com.