Privacy Policy

Updated October 8, 2026

Keepsweeper is made by Flarup Industries ApS, Denmark. Questions about privacy: desk@pixelresort.com.

Your kingdom stays on your device

Quest progress, Royal Seals, Legacy unlocks, your current run and settings are stored locally. There is no account, social profile, advertising or cross-app tracking. Removing the app or clearing website data may remove your progress. Game progress is not synchronized between devices.

Online multiplayer

Online matches run on Cloudflare. We send and temporarily store your chosen display name, room details, seat credentials, game actions and match state to connect players and run the game. Other players can see your display name and the game information allowed by the rules. Use a nickname instead of your real name, and do not include contact information. Your solo saved game and Legacy progress are not uploaded for multiplayer.

Cloudflare processes connection information such as your IP address to deliver and secure the service. Match records expire under the lobby and disconnect rules; finished rooms expire after ten minutes. Expired records are removed when the server next handles a request. A seat credential is also stored in your browser for rejoining, for up to 24 hours; leaving or forgetting a game removes it. See Cloudflare’s privacy policy.

Community maps

Publishing is optional. Submitting a map sends its layout, rules, names, description, your chosen creator name and a stable creator identifier to our Cloudflare service. A random creator key stored on your device lets you manage your publications; the service identifies it by a cryptographic hash. Do not include real names, contact details or other personal information in public content. Maps are reviewed before publication. Approved maps and creator names can be browsed, downloaded, shared and played by anyone.

We store submitted maps and review decisions, reports and report text to operate and moderate the library. Connection IP addresses are processed by Cloudflare; hashed IP addresses are used for rate limiting and report deduplication. You can report a map, block its creator on this device, or contact developer@flarup.co. Blocking hides that creator’s maps on your device and is reversible in Community. Moderators can remove maps and block creators from publishing.

Current listed maps remain stored while published. Unlisting removes a map from public access but does not delete downloaded copies or an already-running match. Unlisted or removed versions are eligible for cleanup after 30 days, and superseded versions after 90 days. Cleanup requires a recent verified backup; these periods are minimums, not guaranteed deletion dates. Pending submissions remain stored until reviewed or removed. Moderation records and reports are retained to handle complaints and prevent repeated abuse. Backups retain up to 30 complete snapshots. Contact us about removal or deletion requests; local copies held by other players cannot be recalled. We process this information to provide the publication service you request and to operate and protect the community.

Optional multiplayer notifications

If you enable multiplayer alerts, we store a random device credential, your browser push subscription or Apple push token, your notification preference, timezone offset and recent alert counts on Cloudflare. These let us send requested game invitations through your browser’s push provider or Apple. Public-game alerts are optional and can be turned off in Settings. A host can separately request a join alert for a waiting game, lasting up to 15 minutes, and cancel it from that room. No contacts or address book are accessed; sharing an invitation uses the recipient you choose in the system share sheet.

Inactive notification registrations expire after 30 days and are removed during subsequent registration maintenance. Invalid destinations are removed when the push provider reports expiration. Notification frequency records are used only to limit alerts. You can also revoke notification permission in your device or browser settings; the app removes its registration when next opened with a working notification connection.

Purchases

The iPhone app uses Apple and RevenueCat; the Android app uses Google Play and RevenueCat to process and restore the optional full-game purchase. RevenueCat receives a randomly generated app user identifier, purchase and transaction information, entitlement status, app/device software information and network information such as IP address needed to provide its service. We do not receive your payment card details or Apple or Google account password.

We use this information to deliver your purchase, restore access, prevent errors or fraud, and understand aggregate purchase performance. We do not send your name, email, contacts, precise location or game progress to RevenueCat. Advertising identifier collection and optional SDK diagnostics are disabled.

See RevenueCat’s privacy policy and Apple’s privacy policy, and Google’s privacy policy. These providers may process information outside your country, including in the United States, under their applicable transfer safeguards.

Optional gameplay and error reports

When reporting is enabled, we use PostHog in its EU region to understand gameplay and improve reliability. Reports include a random installation identifier, app version and build identity, device/browser software information, game mode, quest and level, run identifier and map seed, progress statistics, buildings and upgrades, wins and losses, tutorial completion or skipping, multiplayer connection and match outcomes, purchase-flow outcomes, sanitized JavaScript error locations, and aggregate performance measurements such as frame times and response times for game controls, with the active screen and weather. We do not upload your saved game, record your screen, collect typed text or connect this identifier to your Apple, Google or RevenueCat account.

In the iPhone, iPad, Android and desktop apps, reporting is on by default unless you previously turned it off. In the browser edition it stays off until you turn it on. Your saved reporting choice is preserved across updates. You can turn reporting off in Settings at any time to stop future reports and reset the analytics identifier. Previously received reports are not automatically erased. IP-based analytics and location collection are disabled; network requests necessarily expose an IP address to the provider. See PostHog’s privacy policy. Apple may also provide app diagnostics under your device and TestFlight sharing settings.

Reporting also sends a smaller set of gameplay events to Coal (coal.nexus), a game analytics service. Coal receives a random installation and session identifier created only for Coal, app version and platform (iPhone/iPad, Android, desktop or browser), game mode, quest and level, when a run starts, resumes, is won or lost, simulation time and cause of defeat, milestones such as placing your Keep and your first excavation, building, soldier and dragon, and foreground play time. Coal does not receive purchase information, your device model, error reports, multiplayer data, your saved game or the PostHog identifier. The same Settings choice controls both services: turning reporting off stops Coal reports and resets its identifier. Previously received reports are not automatically erased. Network requests necessarily expose an IP address to Coal's hosting provider.

Understanding free and premium play

When reporting is enabled, gameplay reports also include whether the purchase service reports full-game ownership or is unavailable, content gates and purchase-screen outcomes, foreground and engaged play time, session counts, and whether progress already existed when measurement began. Store country, currency and catalog price help us understand regional differences; store country is not your physical location. We count hypothetical between-game advertising opportunities to evaluate possible future options. No advertisements are loaded or shown by this measurement. Small local counters remember observation history and are cleared when reporting is turned off. These reports do not include transaction receipts or your RevenueCat account identifier.

Support and website

If you contact us, we use the information you provide to answer and resolve your request. Our website host processes ordinary connection and security logs to serve pages. The web edition stores progress locally and does not initialize the native purchase SDK.

Retention and your choices

We keep support correspondence only as long as needed to handle your request and meet legal obligations. Purchase records are retained as needed to recognize your permanent unlock, handle refunds and comply with accounting or legal requirements. Local progress remains until you remove it.

Where applicable, you may request access, correction, deletion, restriction or portability of your personal information, or object to processing. Contact us above. Purchase records required by law may need to be retained. You may complain to your local data-protection authority, including Datatilsynet in Denmark. Our legal bases are providing the purchase or support you request, legitimate interests in operating and securing the service, and legal obligations.

Children and changes

Keepsweeper does not require a real name or contact information to play. Purchases are controlled by the device’s App Store or Google Play purchase settings. We will update this page when our practices change.


Support   Privacy   Terms   Play Keepsweeper

Stability diagnostics

When gameplay and error reporting is enabled, reports may include your native iOS version and device model (not a unique hardware identifier), sanitized startup error types and code locations, and counts of memory warnings and game WebView restarts. Periodic foreground iOS reports may include thermal pressure, Low Power Mode, battery charge level and charging state to investigate heat and battery-use reports. Battery changes describe the whole device, not energy attributed to Keepsweeper. Gameplay reports include Research active in a run and treasure alternatives, selections and paid rerolls. Small pending diagnostic records are kept locally for a later reporting session. Turning reporting off clears pending diagnostics and stops this collection. These reports do not contain saved kingdoms, arbitrary error messages or personal text.