Desk to Dynasty is a fictional financial-life simulation. We do not collect real bank credentials, card numbers, government identifiers, credit reports, deposits, or investment funds, and we do not enable withdrawals or real trades.
1. Controller and scope
Desk to Dynasty is operated by Baran Özdemir, an independent developer based in Türkiye (“Desk to Dynasty,” “we,” “us,” or “our”). This policy applies to the iPhone game, this website, our API, notifications, and support communications. Privacy requests can be sent to [email protected].
2. Information we collect
Account, authentication, and device data
We create pseudonymous user, device, and session identifiers. We process a hashed installation identifier, hashed refresh credentials, app version, platform, session timestamps, and account status. If you use Sign in with Apple, our backend stores Apple’s stable account subject so it can recognize and restore your account. We do not request or store your Apple password, and the current account-linking flow does not store your Apple name or email address.
Integrity, network, and security data
To protect accounts and the game economy, we process Apple App Attest key identifiers, public-key and receipt material, assertion counters, request identifiers, authentication challenges, IP address and basic HTTP metadata, fraud and abuse signals, rate-limit events, and pseudonymous audit records. Authentication tokens and raw request bodies are not intentionally included in analytics.
Gameplay and user-provided content
We store the fictional character and company names you enter, profile choices, onboarding state, bank and ledger records, active-work progress, businesses, staff, companies, assets, vehicles, property, simulated credit and taxes, market watchlists and trades, achievements, objectives, rewards, experiments, configuration versions, and other progression needed to run and restore the game. These are game records, not real financial accounts or assets.
Purchases and rewarded advertising
Apple processes payment details. We receive and retain the minimum transaction, product, entitlement, revocation, and verification data needed to grant or restore an in-app purchase. When you voluntarily request a rewarded ad, Google Mobile Ads and Google’s User Messaging Platform may process consent status, device and app information, approximate location derived from network information, ad interactions, diagnostics, and advertising-related identifiers where legally allowed. Our backend stores the placement, a country bucket, consent mode, offer/transaction references, reward, timestamps, and verification outcome to prevent duplicate or fraudulent rewards.
Game Center and notifications
If you authenticate with Game Center, Apple handles the Game Center account and displays your Game Center name. The app submits achievement progress to Apple; our server remains the authoritative source for game progress. If you grant notification permission, we store an Apple Push Notification service token, environment, device association, time zone, delivery state, and notification/read timestamps. You can revoke system permission at any time in iOS Settings.
Analytics and diagnostics
We record a limited allowlist of product events, such as app launch, onboarding completion, rewarded-ad placement and outcome, screen name, coarse duration, and event time. When production keys are enabled, PostHog US receives pseudonymous allowlisted product events and Sentry receives redacted crash and performance diagnostics. Session replay is disabled. Sentry is configured not to send default personal information and removes authorization, cookie, request-body, and attestation headers before an event is sent.
Support communications
If you contact us, we process your email address, message, attachments, and any account, device, purchase, or diagnostic information you choose to provide. Never send passwords, authentication tokens, private keys, full payment-card information, or government identifiers.
Website data
The public website does not currently set advertising cookies, run cross-site analytics, offer accounts, or accept payments. Our hosting and security providers may process ordinary server logs such as IP address, user agent, requested URL, timestamp, status code, and security events. See our Cookie Notice.
3. Sources of information
- Directly from you when you play, make choices, or contact us.
- Automatically from the app, device, API, and website.
- From Apple for authentication, integrity, Game Center, purchases, and push notifications.
- From Google when consent is evaluated or an optional rewarded ad is requested and verified.
- From security, hosting, analytics, and diagnostics providers.
Data marked as required in the app is needed to create or secure the account and provide the relevant game feature. If it is not provided, that account or feature may not work. Optional advertising, notifications, Game Center, and support information is not required to play the core game, subject to any clearly disclosed feature-specific limitation.
4. Purposes and legal bases
- Provide the service: create and authenticate accounts, save progress, execute fictional transactions, restore purchases, and provide support. Where applicable, this is necessary to perform our contract with you.
- Protect the service: detect replay, tampering, fraud, abuse, duplicate rewards, and security incidents. We rely on our legitimate interests and legal obligations where applicable.
- Operate and improve: diagnose failures, measure allowlisted product flows, balance the game, and maintain reliability. We rely on legitimate interests or consent where the law requires it.
- Advertising and permissions: request ads and process consent only when permitted by the applicable privacy settings and law. Consent can be withdrawn where required.
- Compliance: respond to lawful requests, enforce our Terms, maintain transaction integrity, and establish or defend legal claims.
5. Who receives information
We disclose information only as needed to the following categories:
- Apple: Sign in with Apple, App Attest, Game Center, StoreKit/App Store, and APNs.
- Google: AdMob and UMP when advertising functionality is enabled or requested.
- Processors: infrastructure, database, content delivery, backup, security, email, Sentry diagnostics, and PostHog US analytics.
- Authorities or transaction parties: when required by law, needed to protect rights and safety, or involved in a lawful reorganization or transfer subject to appropriate safeguards.
Their handling of information is also governed by their notices, including Apple Privacy, Google Privacy, Sentry Privacy, and PostHog Privacy.
We do not sell personal information for money. At launch, we do not use the AppTrackingTransparency framework or IDFA for cross-app tracking, and we do not share personal information for cross-context behavioral advertising. If this changes, we will update this policy, provide the legally required choice before the change takes effect, and update our App Store privacy disclosures.
6. Automated decisions
Anti-abuse systems may delay, reject, reverse, or flag a fictional game transaction when integrity checks fail. These controls affect only the game and virtual content; they do not make decisions about real credit, employment, insurance, housing, or other legal rights. Contact support if you believe a game-integrity decision was incorrect.
7. Retention
- Account, ledger, purchase entitlement, and gameplay records: while the account is active, followed by the deletion/anonymization process.
- Routine application logs: generally up to 14 days.
- Error logs and traces: generally up to 30 days.
- Raw allowlisted analytics events: up to 90 days before aggregation or deletion.
- Pseudonymous security, ad-verification, and audit records: generally up to 180 days.
- Expired authentication records: deleted on their configured expiry and cleanup schedule; refresh sessions normally expire within 30 days.
- Support records: for the time needed to resolve the request and maintain a reasonable dispute or compliance record.
A deletion request immediately revokes active access and places the account into a 30-day deletion process. At the end of that period, linked identity and profile data are deleted, integrity records are stripped or replaced with non-identifying values, sessions remain revoked, and entitlements are marked inactive. Restricted records may remain when required for fraud prevention, transaction integrity, legal obligations, or protected backup rotation, and are not used to continue gameplay or advertising. Details are on the Account Deletion page.
8. International transfers
We operate from Türkiye and use providers that may process data in the United States and other countries. Where applicable, transfers rely on adequacy decisions, contractual safeguards, provider data-protection terms, or another lawful transfer mechanism. Provider privacy notices describe their locations and safeguards.
9. Your rights and controls
Depending on your location, you may have rights to know or access data, correct it, delete it, receive a portable copy, restrict or object to processing, withdraw consent, opt out of certain advertising uses, and appeal a refused request. You may also complain to your local data protection authority. We may verify your identity and account ownership before acting and may retain information where an exception applies.
- Delete the account from Profile inside the app.
- Manage notification permission in iOS Settings.
- Open the in-app privacy options entry point whenever Google UMP marks it as required to change eligible advertising choices.
- Manage Sign in with Apple and Game Center through Apple settings.
- Email [email protected] for access, correction, deletion, objection, or appeal requests.
10. California and U.S. state disclosures
The categories collected are identifiers; internet or electronic network activity; commercial information relating to App Store transactions; approximate location inferred by advertising or network providers; gameplay and user-created records; and diagnostics or inferences used for security and game operation. They are collected from the sources and used for the purposes described above. We disclose them to the provider categories in Section 5. We do not knowingly sell or share personal information as those terms are defined for cross-context behavioral advertising, and we do not knowingly sell or share the personal information of anyone under 16.
Because the website does not conduct cross-site behavioral tracking, it does not currently respond differently to legacy “Do Not Track” browser signals. Where a legally recognized opt-out preference signal, such as Global Privacy Control, applies to a future website processing activity, we will honor it as required. We do not discriminate against users for exercising a privacy right.
11. Children
Desk to Dynasty is a general-audience service and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If we learn that we have done so, we will disable advertising for the account and delete or otherwise handle the data as required by law. A parent or guardian can contact [email protected]. In regions with a higher digital-consent age, a minor should use the service only with the authorization required by local law.
12. Security
We use encrypted transport, short-lived access tokens, hashed refresh credentials, device-integrity checks, least-privilege access, rate limits, redaction, backups, and auditable server-side economic records. No service can guarantee absolute security. Please report suspected account or security issues to [email protected].
13. Changes to this policy
We will post updates at this URL with a new effective date. If a change materially affects how we use personal information, we will provide additional notice in the app or request consent where required. We review this notice at least annually and whenever the enabled SDK or data flow changes.
14. Contact
Controller: Baran Özdemir, Türkiye
Privacy: [email protected]
Support: [email protected]