CODE K ESCAPE
Effective: August 12, 2026
CODE K ESCAPE does not ask for your name, email address, or phone number, and it has no member account system.
The app and web Companion use Firebase Anonymous Authentication and Realtime Database to store per-case escape records under a device- or browser-specific anonymous user ID and to synchronize real-time progress when several people play the same game. Temporary progress for an interrupted solo game remains on your device.
The interphone hint includes the Unity LevelPlay rewarded-ad SDK, ironSource Ads and Unity Ads demand, and its ad-quality component. The app requests advertising consent just before the first game and does not initialize the ad SDK before consent. Interphone hints are provided only after a rewarded ad is watched to completion; there is no ad-free hint option. There are no banner or interstitial ads. The app contains no separate gameplay analytics or crash-reporting SDK.
When the app or web Companion starts, Firebase creates a random anonymous user ID or restores the existing ID kept on the device or browser. When you successfully escape a case, the following data is stored in that ID's private path. A timeout or giving up is not recorded as a clear.
| Item | Purpose |
|---|---|
| Random anonymous user ID generated by Firebase | Distinguish records from the same installation and enforce access permissions |
| Case ID, clear state, and cumulative clear count | Display clear status in the case list |
| First and most recent clear times | Confirm record creation and updates and troubleshoot failures |
We do not connect this record to a name, email address, or phone number, and we do not automatically merge it with records from another device or a new anonymous ID created after reinstalling the app or clearing browser site data.
When you create a 2–4 player room or join through a Companion link, the following data is processed:
| Item | Purpose |
|---|---|
| Random anonymous user ID generated by Firebase | Distinguish Host and Guest permissions and prevent unauthorized access |
| Session ID, role-specific invite token, player count and role | Join the same room and assign roles |
| Case/content version and six-character game code | Generate the same puzzle for both players |
| Start/end times and connection presence | Shared timer and participant status |
| Solved steps, hint/wrong-answer counts, escape result | Synchronize progress and results in real time |
We do not connect the anonymous ID to a name, email address, or phone number. As part of operating Firebase, Google may process IP addresses, browser/device/app information, and network diagnostic data in service logs.
If you expressly allow rewarded ads just before starting a game, Unity LevelPlay is initialized. The following data may then be processed when the interphone requests or displays an ad:
| Item | Purpose |
|---|---|
| Device and advertising identifiers made available by the operating system (such as Android Advertising ID and iOS IDFV) | Ad selection and frequency control, deduplication, and fraud prevention |
| Country or approximate area inferred from IP address, device model, OS/app version, language, and connection information | Select available ads, compatibility, security, and troubleshooting |
| Ad request, creative, impression, click, completion, and reward events | Deliver and review ad quality, determine hint rewards, reporting, and settlement |
| Purchase-history signals that Unity Ads may process under its SDK disclosure | Advertising measurement and analytics; CODE K ESCAPE itself does not sell in-app products |
The current app does not display Apple's App Tracking Transparency (ATT) authorization request, so it does not request access to the iOS advertising identifier (IDFA). Available identifiers may vary with operating-system and Unity policies and with actual ad demand.
To resume an interrupted solo game and remember your display language and completed advertising consent, the app stores the following in internal app storage:
Temporary game progress on the device is deleted when the game ends or you tap “Discard.” The completed advertising-consent state remains until you clear app data or uninstall the app. A real-time multiplayer game is not stored as a local resumable game. Case-clear records are stored separately in Firebase as described in Section 1.
The following providers process data for case-clear records, real-time multiplayer and, only when you allow it, rewarded ads:
| Provider | Data | Purpose | Location and transfer | Retention |
|---|---|---|---|---|
| Google LLC and Google affiliates (Firebase, Google Play) | Anonymous ID, case-clear and session-progress data, service access/diagnostic data described above, and Android app/device integrity attestations | Anonymous authentication, clear-record storage, real-time sync, web Hosting, app integrity verification (App Check and Play Integrity), security and reliability | Transmitted over encrypted networks when the service is used. The default Realtime Database region is Singapore; Google infrastructure may also process data in the United States and other locations | Section 3 and the Google Privacy Policy |
| Apple Inc. | iOS app/device integrity attestations (App Attest or DeviceCheck) | Verify that a request comes from the genuine CODE K ESCAPE app | Transmitted over encrypted networks to Apple infrastructure, including in the United States, when iOS requests an integrity attestation | The Apple Privacy Policy |
| Unity Technologies and affiliates (LevelPlay, ironSource Ads, and Unity Ads) | Device/ad identifiers, approximate area, device/connection information, ad events, and Unity Ads purchase-history signals described above | Mediate and deliver rewarded ads, determine rewards, frequency control, fraud prevention, reporting, and settlement | Transmitted over encrypted networks to Unity infrastructure, including in the United States, after you allow and the app initializes the SDK or requests an ad | Section 3 and the Unity Game Player and App User Privacy Policy |
CODE K ESCAPE does not combine Firebase game-progress data with data sent to Unity, and does not sell it. LevelPlay is the release build's only mediation SDK, and it uses ironSource Ads and Unity Ads demand. Before enabling another ad-demand SDK, we will disclose that network, its data practices, and its policy here and in the store disclosures.
The app uses internet access for case-clear records, real-time multiplayer and, after consent, rewarded ads. Traffic is encrypted with HTTPS/TLS. LevelPlay is not initialized before advertising consent. After consent, the app sends its GDPR and U.S. state privacy choices and a not-child-directed flag to the SDK.
Firebase App Check verifies that server requests come from the genuine CODE K ESCAPE app. Android uses Google Play Integrity and iOS uses Apple App Attest (falling back to DeviceCheck on devices that cannot attest), which sends app/device integrity attestations to Google and Apple respectively. These attestations are used only to judge whether the app is genuine. They are not combined with gameplay or advertising data and are not used to identify or track you.
The only rewarded-ad surface is the interphone hint. There are no banner or interstitial ads. If an ad is unavailable or closed before completion, no hint or score deduction is applied. A hint is revealed only after ad reward and ad closure are both confirmed.
Realtime Database Security Rules enforce that:
Anyone who receives an invite link can use the participation capability embedded in that link. Do not post it publicly.
This app is intended for users aged 14 and older, and the app reports to LevelPlay that it is not child-directed. Children under 14 should not use this app.
You can delete locally stored progress by:
You may contact us to request access to, deletion of, or restriction of Firebase case-clear and session records. We will ask only for the minimum information needed to process the request. Clearing app data, reinstalling, or clearing browser site data can create a new anonymous ID, so contact us first if you need Firebase records deleted.
Clearing app data or uninstalling also deletes the completed advertising-consent state stored on the device, so consent is requested again before the next game. Android also lets you delete or reset its Advertising ID in device settings. For data held by Unity, use the rights-request instructions in the Unity Game Player and App User Privacy Policy.
If this policy changes, we will update the effective date and publish the revision here.
| Developer | JHUD |
| Data protection contact | Jongho Han |
| tkrdmsdl@gmail.com |
Users in the Republic of Korea may contact:
Users elsewhere may contact their local data protection authority.