Lunavect is provided by Yurii Kolinko. For support or questions about access, correction and deletion of data, email yuriikolinko@icloud.com.
Game profile and progress
The game creates a random guest identifier and stores your chosen nickname and avatar, profile dates, level progress, stars, PvE/PvP results and ranking, achievements, events, in-game currency, rewards, themes and access or subscription status. Processed attempts, matches and store transaction identifiers help validate results and prevent duplicate rewards. Advertising reward sessions and frequency limits are associated with your profile.
These data support progress synchronization, result and purchase validation, leaderboards, multiplayer matching and rewards. Your nickname, selected appearance, achievements and ranking can be visible to opponents and other players. Use a nickname rather than information you do not want to make public.
Invitations use referral relationships and a hash of a random installation identifier. The game does not read your contacts; sharing an invitation is your choice.
Purchases and notifications
When purchases are available, the server stores verified store transaction identifiers and access or subscription dates and status. The game does not receive your bank-card details. Deleting a profile does not cancel a store subscription; manage subscriptions through your store account.
If you opt into notifications, the game can submit your push token, locale and selected notification categories. You can revoke notification permission in device settings. Permission does not guarantee notification delivery.
Analytics and advertising
Server gameplay analytics record an allowlisted set of events, timestamps and limited properties with a derived pseudonymous identifier. These data are not fully anonymous: the association with your profile allows related events to be deleted.
The iOS app includes CAS.AI mediation and partner advertising SDKs. They can process device and advertising identifiers, ad impressions and interactions, usage and technical diagnostics for advertising, measurement, fraud prevention and service operation. Partners may combine information with data from other apps and websites for targeted advertising and measurement, subject to applicable consent and permissions. Disabling CAS location collection does not exclude advertising services inferring approximate location from network addresses. See the CAS.AI privacy policy.
Adapty supports purchase, access and analytics services and receives a customer identifier associated with your guest profile. The integration disables Adapty IP and iOS advertising-identifier collection; that setting does not apply to separate advertising SDKs. See the Adapty end-user privacy policy.
You can change the app’s tracking permission in iOS Settings. Refusing tracking does not delete your game profile.
Hosting and retention
Game-server data are hosted on Railway in the United States. Service providers may process information in other countries under their applicable policies. The game server uses IP addresses in process memory for rate limiting; application code does not write routine HTTP requests or IP addresses to its game-data files or logs. Hosting infrastructure may separately process connection and operational information under the Railway privacy policy.
Guest profiles remain until deleted by the player. Server gameplay analytics retain the latest 10,000 events without a fixed time-based expiry; deleting a profile removes associated events. The server currently keeps one automatically updated recovery copy on the same storage volume, not an independent backup. Separate external production backups are not currently configured.
Export and deletion
In “Profile → Progress and data” you can export your profile or request deletion. Deletion removes your profile, progress, statistics, confirmed-purchase records, push tokens and associated pseudonymous analytics from the game server’s active storage and current recovery copy. Referral links are removed or anonymized. The game clears its local session, synchronization queues and progress.
The old session is revoked. Its guest ID remains in a security list to prevent reuse of the old token. This list is limited to the latest 100,000 IDs and has no fixed time-based expiry. Game-profile deletion does not automatically erase independent records held by payment, advertising or infrastructure providers. Contact us for help with data requests; do not send passwords, session tokens or payment-card details.
Children
Lunavect is not specifically directed at children. A chosen nickname, not a required real name, identifies your game profile. Parents or guardians with questions about a child’s data can contact us to have their request reviewed.