The Player ID is generated automatically when you first open the app, even before you create an account. It is stored on your device and linked to your Supabase account record.
None of these events include your name or email — only your anonymous Player ID.
Game functionality: Your pit selections and sow sequence are stored in Supabase to enable async multiplayer — your opponent reads your moves when they take their turn. Without this, online multiplayer is not possible.
Leaderboard and ranking: Your username, ELO score (Kalah ranked ladder), and match results appear on the public leaderboard. Other players can see your username and rank. Your email is never shown publicly.
Personalisation: Your chosen avatar, active theme, and settings preferences are stored on your account so they sync across devices when you are logged in.
Analytics: Usage events (matches started, challenges completed, etc.) are stored to help us understand how players use the game and where to improve it. These events are associated with your anonymous Player ID — never with your name or email in analytics queries.
Notifications: If you grant notification permission, your device's Expo push token is stored to send multiplayer turn alerts (e.g., "Your opponent has played — it's your turn"). The daily reward reminder is scheduled locally on your device and does not require sharing any data with our servers.
Mancala relies on a small number of trusted services. Each has its own privacy policy:
| Service | Purpose | Their Policy |
|---|---|---|
| Supabase | Database, authentication, realtime sync (self-hosted on our own server) | supabase.com/privacy |
| Google AdMob | Advertisements — interstitials and rewarded videos, non-personalised by default | policies.google.com/privacy |
| Google AdSense | Advertisements on the 2DGameClub website (non-personalised) | policies.google.com/privacy |
| Google Play Games Services | Sign-in, achievements sync | policies.google.com/privacy |
| Google Play Billing | In-app purchases | play.google.com/about/play-terms |
| RevenueCat | Purchase management and entitlement tracking | revenuecat.com/privacy |
| Expo / React Native | App framework and push notification delivery | expo.dev/privacy |
We do not sell your data to any third party. The third-party services listed above receive only the data necessary for their specific function. We do not use the Facebook SDK — Mancala has no Facebook integration.
Mancala requests non-personalized ads from Google AdMob (and Google AdSense on the website). AdMob does not build a behavioural profile based on your identity or cross-app activity, and does not use interest-based targeting or remarketing. It may still use contextual signals (e.g., general location derived from IP, language) to select relevant ads. Ad content is restricted to a general-audience (G) rating. You are not asked for consent to personalized advertising — if Google's regional requirements change this default, an in-app consent dialog will be displayed before any ad is shown. Ads are shown in two formats only: full-screen interstitials (after every 5th completed game) and rewarded videos (player-initiated — you choose to watch an ad to earn coins). No banner ads. No ads during active gameplay, tutorials, or within 3 seconds of app launch.
RevenueCat receives your Google Play purchase receipts and the entitlements they unlock (e.g., coin packs, Remove Ads, avatar bundles). RevenueCat does not receive your name, email, or gameplay data. It uses an anonymous user ID to associate purchases with your account.
Access: You can request a copy of the data we hold about you by emailing [email protected]. We will respond within 30 days.
Deletion: You can delete your account from within the app: Settings → Account → Delete Account. This begins a 30-day grace period. After 30 days, all personal data (username, email, match history, ELO, move history) is permanently deleted from our servers. Analytics events are anonymised (the Player ID replaced with NULL) rather than deleted, as they are already aggregated into statistical reports.
Correction: You can change your username at any time from Settings → Profile (up to 3 times per 30 days for logged-in accounts; no frequency limit for guest accounts).
Portability: You can request your complete match history as a JSON file by emailing [email protected]. We will respond within 30 days.
Opt out of analytics: Contact [email protected] and we will flag your account to exclude it from all analytics aggregation. Operational data (game moves for multiplayer) cannot be excluded while your account is active.
All gameplay data, account data, and analytics events are stored in our own self-hosted Supabase (PostgreSQL) instance, which we operate on our own server rather than a third-party cloud provider. Data is not shared with any external analytics or tracking service. By creating an account, you acknowledge that your data will be transferred to and stored on our server for the purpose of providing the game service.
If you are located in the EEA, you have the following additional rights under the General Data Protection Regulation:
Our lawful basis for processing your data is contract performance (your game data is necessary to provide the service you signed up for) and legitimate interest (anonymised analytics to improve the game). To exercise any of these rights, email [email protected]. We will respond within 30 days.
If you are a California resident, you have the right to know what personal information we collect about you and how it is used, request deletion of your personal information, and opt out of the sale of your personal information. We do not sell your personal information. We do not share it with third parties for their own marketing purposes. To exercise your rights under CCPA, email [email protected].
Mancala is rated Everyone (E) on Google Play. The target audience is 13 and older. Mancala is not directed at children under 13, and we are not in the Google Play Families Program. We do not knowingly collect personal data from children under 13. If we learn that we have collected personal data from a child under 13 without verifiable parental consent, we will delete that data promptly and within 30 days. If you are a parent or guardian and believe a child under 13 has created an account or provided us with personal data, please contact [email protected] and we will investigate and delete the data within 30 days.
We take reasonable technical and organisational measures to protect your data: all data in transit is encrypted using TLS; Supabase enforces Row Level Security (RLS) — you can only read and write your own records; passwords are never stored by us, they are handled by Google or Supabase Auth (bcrypt-hashed at rest); your email address is stored encrypted in Supabase and never exposed via the app or API; analytics events are write-only for users — no user can read another user's events. No method of transmission or storage is 100% secure. If you become aware of a security concern, please contact [email protected].
We will notify players of significant changes via the What's New screen in the app the next time they open it after an update. Minor corrections (spelling, clarifications that do not change how we use your data) may be made without notification. The "Last updated" date at the top of this policy reflects the most recent revision.
2DGameClub Studio
[email protected]