REEF
GUARDIAN

Studio Spark · Reef Guardian

Privacy Policy

Updated 3 October 2026. This notice describes the Reef Guardian native testing build prepared from version 1.1.9 (22), with rewarded-ad integration, and this website. We update this notice when a release changes how information is handled.

Who operates the game

Reef Guardian is operated by Saewok Park, a sole proprietor trading as Studio Spark in the Republic of Korea. The operator also handles privacy enquiries. Contact s.park.dxbb@gmail.com.

Game records on your device

The game saves a randomly generated guest identifier, progress, inventory, equipment, balances, checkpoints, gameplay records and reward receipts on your device. These records let you continue play, recover a save and prevent duplicate rewards. Local recovery copies may also be kept. This testing build does not synchronize game saves with our game backend. Local records remain until removed or replaced through the app or device storage facilities; operating-system backups may retain separate copies. Removing local data can permanently lose guest progress.

Rewarded ads and privacy choices

The build integrates Google AdMob for optional rewarded ads and Google's User Messaging Platform for advertising privacy choices. You choose whether to request a rewarded ad. Google may process IP addresses and approximate location, app and device identifiers, diagnostic and performance data, ad views and interactions to provide, measure and protect its advertising services. Test ads and non-personalized requests still involve data processing.

Where a consent message is required, the app requests updated consent information before requesting ads. When Google reports that privacy options are required and available, the game settings provide a Privacy options entry to revisit your choices. Refusing optional ad consent does not require you to stop playing; an ad or its reward may be unavailable. The current testing configuration does not request Apple's tracking permission. This is not a statement that every SDK is free of all identifying data.

See Google's privacy policy, Google advertising information and Mobile Ads data disclosures.

Firebase services in the testing build

The build includes Firebase Analytics and Authentication SDKs. Analytics collection defaults to disabled. If previously stored analytics consent enables it, selected gameplay records can be sent to Google Analytics with a pseudonymous guest identifier: stage starts and results, progress, kills, revives, currency changes and checkpoints. This may include records already in the local event queue. Google Analytics also handles technical SDK information when collection is enabled.

Developer-only test controls, when separately enabled, may temporarily test analytics or create or reuse an anonymous Firebase account. Firebase Authentication may maintain an existing testing session and process authentication identifiers, tokens and connection/security information. These controls are not ordinary player sign-in. This build does not promise Apple/Google account linking or cloud-save recovery. Contact us about any testing account or analytics record. No universal player-facing analytics switch is claimed by this notice.

See Firebase privacy and security information and Google Analytics data practices. Analytics retention depends on the service's configured retention rules; a fixed publisher retention period is not represented here as verified.

Website and customer support

This static website is hosted by Cloudflare. It has no web login, checkout, third-party analytics script or embedded third-party video player. Cloudflare may process IP addresses, request details and security information to deliver and protect the website under its privacy policy.

If you email us, we receive your email address, message, attachments and any player or transaction reference you choose to send. We use them to respond, investigate problems and handle privacy requests. The support mailbox uses Google Gmail. Do not send passwords, verification codes, card numbers or identity documents unless a separately explained process requires them.

Service providers and processing locations

Google advertising and consent services, Google Analytics/Firebase, Google Gmail and Cloudflare process information for the functions described above. Their respective terms determine whether they process information on our behalf or for their own service purposes. The app currently integrates Google’s advertising SDK. Google and its advertising partners may process advertising information under their respective privacy terms.

These services may process information outside your country, including in the United States. Firebase Authentication operates from US data centres. Other Google and Cloudflare services may use facilities in additional countries; this notice does not assert US-only processing. See Firebase processing locations, Google's international processing information and Cloudflare's processing terms. Provider information is transparency about their practices; it does not replace any separate notice, consent or transfer safeguard required for a particular service and region.

How long information is kept

Local saves and reward receipts have no automatic time limit in this testing build. Provider-held advertising, security and service records follow the applicable provider retention and deletion rules. We retain support messages and attachments while handling your request. After resolution, we review and delete information that is no longer needed. Information needed for an ongoing dispute or a specific legal duty is restricted to that purpose and deleted when that reason ends. Support review and deletion are handled manually; this is not an assertion that historical mailbox records have already been deleted.

Your choices and requests

You may contact the privacy email above to request access, correction, deletion, restriction or information about your records, and to withdraw consent where it is the basis for processing. We may need a limited player or request reference to locate records and confirm that a request concerns you. A request does not authorize deletion of another player's information. See Account & data requests. We explain any applicable legal retention exception and respond within the time required by applicable law.

Device-only records cannot be remotely found in our game backend in this testing build. We can explain local storage controls before you remove data. Provider deletion and backups may take additional time; immediate erasure everywhere is not promised. You may also complain to your local data protection authority. Where applicable, essential gameplay/support processing serves the requested service, optional consent-based processing depends on your choice, and security or legally required records serve their specified purposes.

Younger players and security

The initial release plan is not actively directed at children. Store age ratings are not the same as a privacy consent age. If you believe a child has provided information without required permission, contact us so we can investigate and take appropriate action.

We limit support access and use provider security measures appropriate to the relevant service. Local saves rely on device storage protections; app-level encryption of every saved record is not promised. No system can guarantee absolute security.

Changes

Material changes to enabled services or data handling will be reflected in an updated notice and any additional notice or consent required for that change. Privacy and support contact: s.park.dxbb@gmail.com.