Privacy Policy
Effective Date: July 11, 2026
This Privacy Policy applies to the Territory Run Android mobile application and its optional Wear OS companion application (together, the “Application”) created by Irina Sizikova (the “Service Provider”, “we”, “us”, or “our”). The Application is currently provided as a free location-based territory capture game. Paid features may be introduced in the future.
1. Developer and Privacy Contact
Application: Territory Run
Service Provider: Irina Sizikova
Privacy contact: territoryrun.dev@gmail.com
2. Information We Collect
When you download, register for, access, or use the Application, we may collect the following categories of information.
a) Account and profile information
- Email address
- Firebase user ID and other account identifiers
- Display name, username, nickname, and profile photo/avatar
- Gender selection, country selection, and language settings
- Optional profile information you choose to provide
- Account status, privacy settings, blocking settings, sound settings, game mode settings, Attacker synchronization settings, and deletion request data
b) Location, route, and gameplay information
- Precise device location while you use route tracking, territory capture, or Traveler mode features
- Location data during a user-initiated active tracking or capture session
- Route points, movement data, distance, duration, speed, pace, and calorie-related estimates
- Territory ownership data, Traveler territory data, route track data, capture request data, capture ledger data, map/cache synchronization data, H3 cell data, territory geometry, league data, medals, stars, rankings, and gameplay status
- Monthly starting point data used for district league grouping and map-related social features
- Technical gameplay metadata such as capture IDs, month keys, cell counts, area values, route validation results, and server-side capture decisions
c) Game mode and synchronization information
The Application includes two gameplay modes:
- Attacker mode: the public competitive mode where territories may be captured from other users and your current Attacker territories may also be captured by others.
- Traveler mode: a personal archive mode where your Traveler routes and territories are saved separately from public Attacker territory ownership.
The Application also includes an Attacker synchronization setting.
When Attacker synchronization is enabled:
- Starts from Attacker mode and Traveler mode may participate in the public competitive game.
- Public territory, shared statistics, rankings, leagues, medals, stars, and gameplay status may be updated.
- Successful public captures are saved to your Traveler archive as a personal route and territory history.
- The Application opens in Attacker mode by default.
When Attacker synchronization is disabled:
- The Application works only as Traveler.
- Attacker mode is blocked.
- Your current Attacker territories may be released and become available to other users.
- Public rankings, league participation, and public/shared statistics may be cleared.
- New routes are saved only in Traveler.
- Traveler archive routes and Traveler territory history remain saved.
- Traveler-only routes do not capture public Attacker territories from other users.
If you later enable Attacker synchronization again:
- Public competitive play may start from zero.
- Shared/public statistics may be reset for a clean Attacker start.
- Existing Traveler archive routes and Traveler territory history remain saved.
- Old Traveler-only territory is not automatically moved into Attacker territory.
d) Wear OS companion and connected-device information
- If you install and enable the Wear OS companion, the Application may process precise watch location during a user-initiated active route, including latitude, longitude, timestamp, accuracy, speed, bearing, altitude, and a device-provided mock-location indicator where available
- Route state, current speed, distance, pace, calories, elapsed time, completion eligibility, a compact active-route preview, and start, finish, discard, map, and synchronization commands exchanged between your paired watch and Android phone
- Wear OS connection state, paired-device node identifiers used by Google Play services, Bluetooth permission state, and technical delivery or synchronization status
- Watch-assisted location samples are sent to the paired phone for active-route processing. The Wear OS companion does not directly determine territory ownership, update public statistics, or write capture results to Firestore
e) Social, communication, and user-generated content
- Friend requests, friend relationships, blocked users, reports, and moderation actions
- Online or last activity status
- Messages, dialog metadata, and message timestamps
- Feedback, support messages, reports, screenshots, or images you choose to submit
- Content and information you choose to send or make visible through Application features
f) Technical, diagnostic, analytics, and security information
- Device IP address
- Device manufacturer, model, operating system version, API level, app version, build version, device language, and similar technical data
- Application logs, crash diagnostics, performance data, memory states, breadcrumbs, synchronization diagnostics, and error reports
- Firebase Authentication, Firebase Cloud Firestore, Firebase Cloud Storage, Firebase Crashlytics, Firebase Analytics, Firebase Cloud Messaging, Firebase App Check, and related identifiers or signals
- Anti-abuse, anti-cheat, fraud-prevention, service-protection, speed-limit, route-reset, capture-processing, update, and synchronization diagnostic events
g) User-initiated achievement sharing
- Achievement cards generated from your selected Today, This Month, or All Time statistics
- The selected period, distance, calories, duration, average pace, territory amount, unit system, language, mode styling, and Application branding shown on the generated image
- Achievement cards are generated locally on your device and are not uploaded by us merely because you create them
- If you choose Instagram, Facebook, or another application through the Android share interface, the generated image and any text you add are disclosed to that selected service at your direction and then handled under that service’s privacy policy
- The current achievement card is designed not to include your email address, Firebase user ID, exact route, or raw GPS points
3. How We Use Information
We use collected information to:
- Create, authenticate, secure, and manage accounts
- Provide route tracking, territory capture, Traveler archive, map display, globe display, league, ranking, medal, star, and statistics features
- Process Attacker and Traveler route/capture requests
- Save successful public captures into the Traveler archive when Attacker synchronization is enabled
- Synchronize territory ownership, Traveler archives, route tracks, map data, and account data across devices and sessions
- Provide Wear OS controls, watch-assisted GPS samples, active-route metrics, and a compact route map between a paired watch and phone
- Generate achievement cards locally and transfer them to a social or sharing application only when you choose to share
- Display profile, league, friend, social, and gameplay information to other users where required by the Application’s features and your settings
- Enable messages, reports, blocking, feedback, and support
- Diagnose bugs, crashes, performance issues, synchronization issues, and capture issues
- Detect, investigate, prevent, and respond to cheating, GPS spoofing, fraud, abuse, harassment, spam, security incidents, and violations of our Terms and Conditions
- Enforce fair-play limits, including speed limits, route validation, capture validation, and server-side corrections
- Send service-related notices, mandatory update information, and gameplay-related notifications where supported
- Improve Application reliability, safety, performance, and user experience
- Comply with legal obligations, enforce our rights, and protect users, the Service Provider, and the Application
We do not sell personal data or personal and sensitive user data. We do not use precise location data for third-party advertising.
4. Location Data
Location data is essential to the core functionality of the Application.
The Application uses location data to:
- Record your movement during user-initiated runs, walks, captures, or Traveler sessions
- Calculate distance, duration, speed, pace, and related gameplay statistics
- Determine territory capture results
- Save Traveler territories and route tracks
- Save successful public captures into the Traveler archive when Attacker synchronization is enabled
- Synchronize territory, Traveler archive, and map data
- Support leagues, district grouping, rankings, and map-based gameplay
- Support globe display, focused-player display, social navigation, and gameplay-related map features
- Detect unreliable, suspicious, or abusive route behavior, including speed-limit violations and GPS spoofing
The Application accesses location when you start an active tracking or capture session. The Application is not designed to track your location at all times.
Where permitted by your device, operating system, and Android permission settings, the Application may continue tracking during a user-initiated active session while the Application is running in the foreground, through a foreground service, or while temporarily in the background. This is used only to continue the active route/capture session and stops when the session is stopped, completed, reset, rejected, or no longer needed.
We do not use location tracking to monitor you outside active gameplay sessions. You can control location permissions through your device settings, but disabling location may prevent core features from working.
The Application may provide guidance about Android settings such as foreground service notifications, battery optimization, autostart, or vendor-specific power-saving settings to improve tracking reliability.
If you enable the Wear OS companion and grant location permission on the watch, the watch may also collect location during the same user-initiated active route. Watch location is used as an additional route source and is transferred to the paired Android phone through Google Play services. Watch location collection stops when the active route ends, is discarded, is rejected, or the watch location service is otherwise stopped. The watch companion is not designed to track you continuously outside an active route.
Location from a phone or watch may be inaccurate, delayed, interrupted, or unavailable. The Application may warn about poor GPS quality, omit unreliable points, close or reset a route, or reject a capture to protect gameplay integrity. A map or route preview on the watch may contain a reduced number of points and is for convenience only; it is not the authoritative capture record.
5. Social Features and Visibility to Other Users
The Application includes map-based, globe-based, league, friend, and messaging features. By using these features, you understand that some information may be visible to other users.
a) Attacker mode, leagues, and rankings
When Attacker synchronization is enabled, other users may see:
- Your display name
- Your avatar/profile photo
- Your territory area, distance statistics, status, medals, stars, and ranking
- Territory shapes or territory-related map information needed for gameplay
For district league functionality, the Application stores your monthly starting point and uses it to group you with users whose monthly starting points are within the district league range used by the Application.
b) Map, globe, and focused-player visibility
Territory shapes, territory locations, owner avatars, display names, and gameplay information may be visible to other authenticated users through map, globe, league, and focused-player features where this is part of gameplay.
If you capture territories in different places or countries, those territory locations may be shown on the map or globe as part of gameplay.
c) Traveler mode visibility
Traveler mode is a personal archive mode. Traveler routes and Traveler territories are stored separately from public Attacker territory ownership.
Traveler territories may be visible to your friends if you enable the “Show Traveler territories to friends” setting. You can change this setting in the Application. Traveler tracks are intended for your own map display and diagnostics unless a feature or setting clearly allows sharing.
d) Friends and map navigation
Friends or other users, depending on your settings and Application features, may be able to:
- See your basic profile and gameplay information
- See online or last activity information
- Open the map near gameplay-related points such as your monthly starting point, territory centroid, visible territory area, or visible Traveler territory
You should not use social or map features to stalk, harass, intimidate, dox, or target other users.
e) Messaging and reports
Messages are stored to provide dialogs between users. Reports, blocked-user data, and moderation-related data may be reviewed and used to enforce safety rules, investigate abuse, respond to legal requests, or protect the Application.
6. Third-Party Services and Data Sharing
We use trusted third-party service providers to operate the Application. These services may process data as necessary to provide their services to us.
Third-party services may include:
- Google Play Services
- Google Maps SDK for Android and Wear OS
- Wear OS and the Google Play services Wearable Data Layer
- Firebase Authentication
- Firebase Cloud Firestore
- Firebase Cloud Storage
- Firebase Analytics
- Firebase Crashlytics
- Firebase Cloud Messaging
- Firebase App Check and related Google security services
- Instagram, Facebook, or another application selected by you when you use the optional sharing feature
We may share or disclose information:
- To service providers that help operate, secure, analyze, or support the Application
- To other users, only as part of the Application’s visible gameplay, league, friend, social, map, globe, focused-player, Traveler visibility, or messaging features
- To comply with law, legal process, or enforceable governmental requests
- To protect the rights, safety, property, or security of users, the Service Provider, the Application, or the public
- To investigate cheating, abuse, fraud, security incidents, or violations of our Terms and Conditions
- At your direction, to the social or sharing application you select for an achievement card or other content
Third-party services have their own privacy policies and terms.
The Wearable Data Layer may transfer paired-device data directly over Bluetooth or through Google-managed network infrastructure when direct connectivity is unavailable. Google Play services controls that transport. We do not use the Wearable Data Layer as a public profile or advertising channel.
We do not automatically publish achievement cards. Once you intentionally send content to Instagram, Facebook, or another third-party application, that third party independently controls its processing, retention, audience, and deletion tools. Review your audience and content before publishing.
7. Analytics, Diagnostics, and Service Protection
We collect technical, diagnostic, analytics, and security data to keep the Application stable, fair, and secure.
This data may include crash reports, performance events, app version, device data, route validation diagnostics, speed-limit warnings, capture ledger status, map synchronization diagnostics, update diagnostics, App Check signals, and other technical events.
We use this information for:
- Debugging and reliability monitoring
- Fixing capture, map, route, Traveler, and synchronization problems
- Protecting against cheating, abuse, fraud, spam, and security threats
- Improving Application performance and stability
8. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, security needs, dispute resolution, anti-abuse protection, or enforcement of our rights.
Examples of retention behavior:
- Account, profile, territory, Traveler archive, league, friend, messaging, and gameplay data are generally retained while your account remains active
- Traveler territories and route tracks may be retained while your account remains active, unless deleted, anonymized, or otherwise handled according to account deletion or applicable settings
- Temporary capture processing records may be retained for up to 30 days
- Applied capture ledgers, audit data, anti-abuse records, and important technical logs may be retained for up to 90 days or longer where necessary for security, fraud prevention, dispute resolution, or legal compliance
- Debug logs may be retained for a shorter period, such as up to 7 days, unless needed for investigation
- Monthly starting point data used for district league grouping may be retained for a limited period, such as the current month and recent previous months, unless needed for league results, dispute resolution, security, or legal reasons
- Support, feedback, and report data may be retained as long as reasonably necessary to investigate, resolve, or document the issue
- Local temporary route, cache, and synchronization data may be deleted automatically after processing or during storage cleanup
- Wear OS location samples and route state are used during an active session and transferred to the paired phone. They are not maintained by the Wear companion as a separate permanent cloud archive; if incorporated into a route, their retention follows the applicable route, capture, diagnostic, and account records described above
- Generated achievement cards are stored only in the Application’s local cache and are normally eligible for automatic deletion after approximately 24 hours. Copies shared to another application are controlled by that application and may remain until you delete them through that service
9. Account Deletion and Data Rights
You may request deletion of your account and associated data by:
- Using the “Delete Account” function inside the Application, where available
- Contacting us at territoryrun.dev@gmail.com
- Using the account deletion web page or external account deletion method provided in the Google Play store listing for the Application, where available
After receiving a valid deletion request, we will delete or anonymize personal data associated with your account unless retention is required or permitted for legal, security, anti-abuse, fraud-prevention, dispute-resolution, or legitimate operational reasons.
Some gameplay records, territory records, Traveler records, capture ledgers, anti-abuse logs, moderation records, and technical audit records may be retained or anonymized where necessary to preserve game integrity, security, dispute resolution, legal compliance, or fair-play enforcement.
Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You may contact us at territoryrun.dev@gmail.com to exercise privacy rights. We may need to verify your identity before processing a request.
10. International Data Processing
The Application uses Google and Firebase services, and data may be processed or stored in countries other than your country of residence. Where required by applicable law, we rely on appropriate safeguards for international data transfers.
11. Children’s Privacy
The Application is not directed to children under 13 years of age and is not designed for children. If the law in your country requires a higher age for using online services without parental consent, you must meet that age or have valid parental/guardian consent.
We do not knowingly collect personal information from children under 13. If we learn that we have collected personal data from a child under 13 without required consent, we will delete it as soon as reasonably possible.
12. Security
We use reasonable administrative, technical, and organizational safeguards to protect personal information and sensitive data, including use of Firebase/Google security features, access controls, App Check where supported, and encrypted transmission where supported.
Communication between the phone and Wear OS companion is handled through Google Play services and is restricted to matching application packages and signing identities. No security measure, Bluetooth connection, wearable transport, cloud service, or local device storage can be guaranteed to be completely secure.
However, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the Effective Date above. Continued use of the Application after an update means you accept the revised Privacy Policy, where permitted by law.
14. Legal Bases and Automated Gameplay Processing
Where applicable law requires a legal basis, we process data as necessary to provide the service you request and perform our agreement with you; based on your consent or choices for optional permissions, visibility, Wear OS, and sharing features; for our legitimate interests in securing, debugging, improving, and operating the Application where those interests are not overridden by your rights; and to comply with legal obligations.
The Application uses automated server-side processing to validate routes, evaluate GPS quality, speed, distance, topology, duplicate requests, and anti-abuse signals, and to calculate or correct territory, statistics, rankings, and related gameplay results. These decisions affect virtual gameplay only and are not intended to produce legal or similarly significant real-world effects. If you believe a gameplay result is incorrect, you may contact us for review.
15. Contact Us
If you have questions about this Privacy Policy or privacy-related requests, please contact:
territoryrun.dev@gmail.com