Data & Compliance Overview
This page provides a technical summary of the data collected and processed by TrapMan, Nobilix's live mobile game. It is intended for players who want to understand our data practices in detail. The data table below reflects confirmed fields from engineering review. Categories that are under investigation but not yet confirmed are listed separately.
Confirmed Collected Data
The following data categories have been confirmed by engineering review:
| Data | System | Location | Purpose | Deletable | Notes |
|---|---|---|---|---|---|
User Name | Firestore | users/{uid} | Display name shown on leaderboards and in the player portal. | Yes | — |
User Email | Firebase Authentication + Firestore | Firebase Auth record + users/{uid}.email | Account identity and player communications. Stored in Firebase Auth and mirrored to the users Firestore document. | Yes | Deleting the account removes both the Auth record and the Firestore user document. |
User Country | Firestore | users/{uid}.country | Regional segmentation for leaderboards and applicable law compliance. | Yes | — |
Competitions Won | Firestore | users/{uid} or player_progress/{uid} | Tracks competition wins for leaderboard and in-game rewards. | Yes | — |
Purchases Made | Firestore | users/{uid}.purchases (embedded purchase map) | Records in-app purchase transactions (price, currency, platform, receipt, timestamp) for receipt and dispute resolution. Confirmed by engineering schema review to be stored on the player profile document. | Partial | Purchase receipt records may be retained for financial compliance and dispute resolution. Personal identifiers within receipts are anonymized on account deletion where retention is required. |
Purchased Item | Firestore | users/{uid}.purchases.{purchaseId}.productId | Identifies which in-app product was purchased (e.g., character skin, power-up pack). | Partial | Retained as part of purchase receipt. Personal identifiers are anonymized on account deletion where retention applies. |
Time Played | Firebase Analytics | Analytics event: session_end — parameter: duration_ms | Records total milliseconds of a play session for aggregate playtime analytics. | Partial | Firebase Analytics stores aggregate event data. Per-user event deletion is not instant and depends on Firebase Analytics data deletion processes. Aggregate data without personal identifiers may persist. |
Ads Watched | Firebase Analytics | Analytics event: ad_closed | The ad_closed event is tracked when the player closes a rewarded or interstitial ad. It means the ad was closed; it does not verify full ad completion. | Partial | Subject to Firebase Analytics data deletion timelines. |
Ads Clicked | Firebase Analytics | Analytics event: ad_clicked | Recorded when the player clicks or interacts with an ad unit. | Partial | Subject to Firebase Analytics data deletion timelines. |
Push Notification Token | Firestore | users/{uid}.fcmToken | Firebase Cloud Messaging token used to deliver push notifications to the player's device. Confirmed present via engineering schema review. | Yes | Removed on account deletion; also cleared if the player revokes notification permission on-device. |
Current Level | Firestore | users/{uid}.currentLevel | Tracks the player's current progression level for leaderboard ranking and gameplay state. | Yes | — |
Completed Levels | Firestore | users/{uid}.completedLevels | List of level numbers the player has completed. Used for progression tracking and aggregate level-distribution analytics. | Yes | — |
Guest Account Flag | Firestore | users/{uid}.isGuest | Indicates whether the player is using a guest (non-authenticated) account. Confirmed via engineering schema review: guest accounts receive the same persistent Firestore profile document as registered accounts. | Yes | — |
Under Engineering Verification
The following data categories may be collected or processed by TrapMan's underlying services, but have not yet been formally verified by our engineering team. We do not claim to collect these categories until each has been individually confirmed. These items are marked as: "Under engineering verification; not claimed as collected until confirmed."
- Under engineering verification; not claimed as collected until confirmed. Firebase Analytics automatic events and user properties (e.g., first_open, app_update, os_version, country derived from IP)
- Under engineering verification; not claimed as collected until confirmed. Device identifiers including Google Advertising ID (GAID) and Apple IDFA — depends on consent and attribution SDK
- Under engineering verification; not claimed as collected until confirmed. Crash reporting data (e.g., Firebase Crashlytics — stack traces, device model, OS version)
- Under engineering verification; not claimed as collected until confirmed. Advertising SDKs and their destination processors — depends on which SDKs are integrated and their data sharing practices
- Under engineering verification; not claimed as collected until confirmed. A minority of embedded purchase records carry raw app-store receipt blobs keyed by store purchase tokens (a different shape from the confirmed productId/price/currency/platform/timestamp records) — the internal contents of those raw receipt blobs have not been individually verified
- Under engineering verification; not claimed as collected until confirmed. The dedicated purchases/{purchaseId} and player_progress/{uid} collections no longer exist in the live database as of the most recent engineering schema review — all purchase and progression data lives on the users/{uid} document itself (see purchases, currentLevel, completedLevels above)
Your Data Deletion Rights
To delete your TrapMan account, follow the steps at /trapman/delete-account. On deletion: - Your user profile (username, email, country, competition data) is deleted from Firestore. - Your progress record (player_progress/{uid}) is deleted. - Your leaderboard entry is removed or anonymized. - Your Firebase Auth record is deleted. Purchase receipt records may be retained for financial compliance. Personal identifiers within retained purchase records are anonymized. Firebase Analytics aggregated event data follows Firebase's documented deletion timelines. Aggregated data without personal identifiers may persist.

