Privacy Policy
Last updated: 2 July 2026
This policy explains what information Rivalz collects when you use the game at rivalz.io or through the Rivalz mobile app, how we use it, and the choices you have.
Information we collect
- Account details. Your display name and email address, provided when you sign up. Rivalz uses passkeys for sign-in: your device stores the private key and we store only the public credential needed to verify it. We never see or store a password you could reuse elsewhere.
- Game activity. The games you play — moves, battles, cards, results, match history — and any chat messages or feedback you submit. Chat is visible to the other participants of that game.
- Notification tokens. If you enable push notifications, a device token used to deliver turn reminders through Firebase Cloud Messaging (a Google service).
- Usage data. We use Google Analytics on the website to understand aggregate usage. Our servers also produce operational logs (such as errors and request metadata) used to keep the service running.
How we use it
- To run the game: matchmaking with the people you invite, taking turns, history.
- To notify you: turn reminders, game invitations, and results by email (sent via Resend from mail.rivalz.io) and optional push notifications. You can turn off turn reminder emails in your account settings at any time.
- To keep the service secure, debug problems, and improve the game.
We do not sell your personal information, and we do not use it for third-party advertising.
Who we share it with
Your information is shared only with the service providers that host and operate Rivalz: our hosting provider (Vercel), our database provider, Resend (email delivery), Google (Firebase Cloud Messaging for push notifications and Google Analytics), and our logging provider (Mezmo). Each receives only what it needs to perform its function. Other players see your display name and your in-game actions in shared games.
Retention and deletion
We keep your account and game history while your account is active. Finished games remain part of the shared match history of their participants. To delete your account and associated personal information, contact us at the address below and we will action the request within a reasonable period.
Your choices
- Turn reminder emails can be disabled in account settings.
- Push notifications can be disabled in your browser or device settings.
- You can manage or revoke passkeys and active sessions from your account.
- You can request a copy or deletion of your data by contacting us.
Children
Rivalz is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from them.
Changes and contact
We may update this policy as the game evolves; material changes will be reflected on this page with a new “last updated” date. Questions or requests: hello@rivalz.io.