Privacy Policy
Evo Legion is a mobile game for iOS and Android run by Solmatter Inc. (주식회사 솔매터, “we”), a company based in the Republic of Korea. This policy explains what the game and this website collect, why, how long we keep it, and what you can do about it.
The short version
- The game never asks for your name, email address, phone number, address, location, contacts or photos. There is no sign-up and no login screen.
- Your progress and purchases are saved under a random, anonymous account ID created the first time you open the game.
- Apple (App Store) or Google (Google Play) handles payment. We never see your card details.
- Usage stats are sent only if you say yes. Crash reports are on by default and you can switch them off in Settings.
- The only ads are rewarded ads you choose to watch (iOS version). The first time, you are asked whether to allow tracking; the ad reward is the same if you say no.
- You can erase your account at any time from Settings → Delete account.
1. What we collect, why, and for how long
| Data | When and how | Why | Kept |
|---|---|---|---|
| Anonymous account ID (a random ID from Firebase Authentication), plus when it was created and last signed in | Created automatically on first launch | To tell accounts apart and save progress, rewards and purchases | Until you delete the account |
| Game progress: stages cleared, species star ranks and fragments, Nebulite balance and history, summon results and pity counts, missions, check-ins and feats, Season Pass progress, battle records (starting values, card picks, result summary) | When the game talks to our server | To run the game, settle rewards, catch cheating and answer support requests | Until you delete the account |
| Purchase records: product ID, time of purchase and verification, subscription expiry, status (purchased or refunded), a hash of the transaction ID, Nebulite granted, and an encrypted copy of the store’s transaction identifiers (Apple transaction ID and original transaction ID; Google Play purchase token) | When you buy, the app sends the store’s signed transaction to our server to be verified | To confirm payment, deliver items, apply refunds and renewals, and restore purchases | 5 years, as explained in section 6 |
| A hash of your transfer code, its expiry, and the link between devices that share an account | When you create or enter a transfer code | To move your account to a new device | Codes expire after 7 days or once used; device links until you delete the account |
| Crash reports (Firebase Crashlytics): where the error happened (stack trace), device model, OS version, app and content version, memory and storage state, a short log of what the game was doing, and a Crashlytics installation ID | Sent automatically when the app crashes or hits an error (on by default) | To find and fix bugs | 90 days |
| Usage stats (Firebase Analytics): in-game events such as stage starts and results, card picks, store and summon screen views, and performance samples; device model, OS and language; an app instance ID; approximate region (country or city level) inferred from your IP address | Only if you agree (off by default) | To tune difficulty and rewards | Up to 14 months |
| Ad reward records: ad session ID, placement (result bonus, summon, Abyss continue), date, whether the reward was granted, the ad transaction ID sent by Google AdMob | When you choose to watch a rewarded ad, and when Google tells our server the ad was completed | To grant the ad reward, apply the daily limit and prevent double grants | Until the account is deleted (the ad transaction ID remains, detached from any account) |
| Remote configuration (Firebase Remote Config): Firebase installation ID, app version, OS version, device language | Automatically at launch | To switch certain features off or on without an app update | Per Google Firebase retention |
| Server access logs: IP address, time, request path, the app’s user agent | Recorded automatically by Google Cloud when the game talks to our server | Security and troubleshooting | 30 days |
| Rate-limit counters for transfer codes (hashed IP address and hashed account ID) | When you enter a transfer code | To stop people guessing codes | 1 hour |
| Support emails: your email address, your message, and anything you send us (such as a transfer code or an Apple order ID) | When you email us | To answer you and handle deletion requests | 3 years after we close the request (Korean e-commerce law on complaint records) |
What we never collect: name, date of birth, email address (unless you email us), phone number, postal address, precise location, contacts, photos or files, payment card details, or the advertising identifier (IDFA). The advertising identifier is processed by Google directly (section 8) and never reaches our server.
What stays on your device: your save files, settings such as sound, language and consent choices, and your sign-in credential (kept in the device’s secure storage). None of these are sent to us; the credential is used only to sign in to Firebase.
2. Purchases on the App Store
- On iOS, paid items are sold only through Apple’s In-App Purchase. Apple handles the payment and your payment details. We never receive your Apple Account, name, card number or billing address.
- After a purchase we receive the transaction Apple has signed: transaction ID, original transaction ID, product ID, purchase date, subscription expiry, whether it was refunded, and the environment. Our server checks Apple’s signature and keeps only the purchase record described in section 1. The signed original is not stored.
- To make sure a purchase lands in the right account, the app adds a random-looking value derived from your anonymous account ID (Apple calls it an appAccountToken) to the purchase request. It does not reveal who you are.
- Apple tells our server when a subscription renews or a purchase is refunded (App Store Server Notifications). We use this only to deliver or withdraw items.
- Whatever Apple collects itself is covered by Apple’s Privacy Policy.
3. Android only
- On Android, Google Play handles payment. We receive the purchase token and order ID and verify and store them the same way (the purchase token is stored encrypted).
- The Android version is built to support optional rewarded ads (Google AdMob). Only when ads are switched on, and only when you choose to watch one, Google processes data such as the Android advertising ID to serve it, and in some regions asks for your consent first. We do not store the advertising ID.
4. Who else handles your data
We do not sell your personal information or give it to anyone else, except when the law requires us to (for example, a valid request from Korean authorities). Apple and Google, as app stores, and Google as the ad provider (Google AdMob, section 8), collect data from you directly under their own policies.
These providers process data on our behalf to run the game:
| Provider | What they do for us | Where |
|---|---|---|
| Google LLC — Google Cloud (Cloud Run, Cloud SQL, Secret Manager) | Runs the game server, stores the database, keeps encryption keys | Republic of Korea (Seoul region, asia-northeast3) |
| Google LLC — Google Cloud Logging | Stores server access logs | Google data centers (including the US) |
| Google LLC — Firebase (Authentication, Crashlytics, Analytics, Remote Config) | Anonymous sign-in, crash reports, usage stats (if you agree), remote configuration | Google data centers (including the US) |
5. International transfers
Korea’s Personal Information Protection Act asks us to spell out data that leaves Korea. These transfers are needed to provide the game to you and are disclosed here.
| Recipient | Google LLC (contact: googlekrsupport@google.com; Google Privacy Policy) |
|---|---|
| Countries | United States and other countries where Google has data centers |
| Data | Anonymous account ID and sign-in times (Firebase Authentication), crash reports, usage stats (if you agree), remote configuration data, server access logs, and the data Google AdMob processes when you watch a rewarded ad (section 8) |
| When and how | Whenever needed while you play, over encrypted connections (HTTPS) |
| Purpose and retention | As listed in section 1 |
| How to refuse | Don’t choose to watch an ad, and no ad data is sent. Don’t agree to usage stats, or switch them off in Settings. Switch crash reports off in Settings. Anonymous sign-in and the game server are required for online features such as saving progress, the shop and summons; to refuse them, stop playing and ask us to delete your account. |
The game database itself is in Seoul, Korea, but the company that operates it, Google LLC, is based in the United States.
6. How long we keep data, and how we delete it
- When you delete your account, we immediately erase your progress, transfer codes, device links and the encrypted store transaction identifiers from our server, delete your anonymous Firebase account, and then the game erases its save files on your device.
- What the law makes us keep: Korean e-commerce law requires records of payments and delivered goods to be kept for 5 years. We keep the product ID, times, status, the hash of the transaction ID and the amount granted, but we replace your account ID with a one-way value so the record can no longer be tied to you.
- Deletion marker: so that a sign-in token left on an old device cannot recreate a deleted account, we keep a hash of the deleted account ID and the time of deletion for the same period as purchase records.
- Backups: copies in automatic database backups disappear when those backups expire (up to 7 days).
- How: electronic data is deleted so that it cannot be recovered. We do not keep personal data on paper.
7. Your rights
- You can ask to see, correct or delete your data, ask us to stop processing it, or withdraw consent at any time.
- In the game: Settings → Delete account; Settings → Usage data (off); Settings → Crash reports (off); Settings → Notifications (off).
- By email: kimsol@solmatter.kr. We act on requests within 10 days and let you know the outcome. A parent, guardian or someone you authorize can also ask on your behalf.
- Finding your account: accounts are anonymous, so we may ask for something linked to your account, such as a transfer code or an Apple order ID. We will never ask for ID documents. See Delete your account for the steps.
8. SDKs, tracking and cookies
- The game includes the Firebase SDKs (Crashlytics, Analytics, Remote Config). Analytics starts switched off and stays off until you agree.
- The iOS version includes the Google Mobile Ads SDK (Google AdMob) and Google’s consent SDK (UMP). An ad plays only when you choose to watch a rewarded ad; before that the game makes no ad requests. There are no forced ads.
- When you watch an ad, Google directly collects your IP address (used to estimate a general location), device information, ad views and interactions, diagnostics and your consent choices, to serve and measure ads and to prevent fraud. We do not receive this data. See How Google uses information from sites or apps that use our services.
- Tracking: before your first ad, iOS asks whether to allow tracking. Only if you allow it does Google use the advertising identifier (IDFA) to show personalized ads and combine it with data from other companies’ apps and websites. If you do not allow it you see non-personalized ads, and the ad reward is the same. You can change this at any time in iOS Settings → Privacy & Security → Tracking.
- In the European Economic Area, the United Kingdom, Switzerland and some US states a consent screen appears before ads, and you can change your choice under “Ad privacy” in the game’s Settings. US residents can use it to opt out of the sale or sharing of personal information for advertising.
- We do not sell personal information ourselves.
- This website uses no cookies and no analytics. It is served by GitHub Pages, and GitHub may log visitors’ IP addresses for security (GitHub Privacy Statement).
9. Children
We don’t check ages and we don’t collect names or contact details from anyone. The game processes only the anonymous data it needs to work, and nothing is collected specifically from children under 14. A parent or guardian can ask us to show or delete a child’s account using the contact below, and we will do it promptly.
10. How we protect data
- All traffic between the game and our servers is encrypted (HTTPS).
- Store transaction identifiers are encrypted with AES-256-GCM, and the key lives separately in Google Secret Manager.
- Our database and logs hold hashes of purchase tokens and transaction IDs, never the originals. Transfer codes are never stored in readable form.
- Server logs contain neither account IDs nor request bodies, and only the people who need operational access have it.
11. Privacy officer
- Name
- Sol Kim (CEO)
- kimsol@solmatter.kr
Send any privacy question, complaint or request to this address.
12. If you are not satisfied
You can also contact these Korean public bodies about a privacy complaint:
- Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr
- Personal Information Infringement Report Center (KISA): 118, privacy.kisa.or.kr
- Supreme Prosecutors’ Office: 1301, www.spo.go.kr
- Korean National Police Agency: 182, ecrm.police.go.kr
If you live elsewhere, you may also have the right to complain to your local data protection authority.
13. Changes to this policy
We post changes on this page at least 7 days before they take effect, and announce them in the game when it matters. Changes that significantly affect your rights are posted 30 days ahead.
- September 27, 2026: first version
- October 10, 2026: added optional rewarded ads (Google AdMob) and the tracking permission request on iOS; updated the short version and sections 1, 4, 5 and 8 (announced October 2, 2026)
This policy is published in Korean and English. If they differ, the Korean version prevails.