Drop the Ball Privacy Policy
Last updated: October 6, 2026
This policy describes information handled by the Drop the Ball mobile game and its backend services. It reflects the current game and backend implementation; it should be reviewed whenever the app, advertising configuration, or service providers change.
Who operates the game
Drop the Ball is operated by the publisher identified in the game's Google Play listing. For privacy questions or requests, contact support@mamora.me.
Information we collect
When you use online game features, the backend may process:
- Guest and device identifiers: a random install identifier and a server-issued authentication token. The game stores its token on the device; the backend stores a one-way hash of that token.
- Account information: a username and password when you create an optional account. Passwords are stored as password hashes, not as readable passwords. The game does not ask for an email address.
- Game profile and progress: cloud-save data, D-Coins and their transaction records, cosmetic inventory and selection, and rewarded-ad progress.
- Gameplay and anti-cheat records: session start and finish times, completed levels, selected game events, and configuration/odds verification data used to validate game rewards.
- Support messages: information you choose to include when you contact our support email.
The game reads accelerometer and gyroscope data on your device to control the ball. The current game client uses these readings locally and does not send motion readings to the game backend. The game does not request precise location or collect your contacts.
Our game database does not contain a field for your IP address. The hosting infrastructure may process network information, such as IP addresses and request logs, to deliver and protect the service.
Advertising and third parties
The game uses the Google Mobile Ads SDK through a Godot plugin to load banner and full-screen ads. Google and its advertising partners may collect or receive device, advertising, network, diagnostic, and ad-interaction information under their own policies. The exact information can depend on your device, region, and the ad configuration in use.
Google privacy information is available at policies.google.com/privacy. You can also review Google's advertising information and your device's advertising/privacy settings.
The game also uses hosting and infrastructure providers to operate its backend. Those providers process information as needed to host, secure, and maintain the service. We do not sell your game account data.
The current development configuration uses Google's test ad units. Before release, the publisher may enable production ads and region-specific consent requirements. This policy and the app's consent configuration must be updated to match the production setup.
How we use information
- Provide gameplay, guest profiles, optional account sign-in, cloud saves, and device synchronization.
- Maintain D-Coin balances, cosmetics, and rewarded-ad progress.
- Validate game sessions and investigate suspected abuse of game rewards.
- Serve and measure advertising through the advertising provider.
- Respond to support requests and protect the service.
Where information is stored
Game profile and account data are stored by the backend. The game also keeps a local profile on your device, including its install identifier, authentication token, username, cached balance, and save data. The app stores control preferences separately on the device.
The development project is configured for a local HTTP service by default. Production deployments should use HTTPS and appropriate server security; do not distribute a production build pointed at an unencrypted service.
Retention and deletion
Online profile information is kept while the game profile remains active or as needed to operate and protect the service. We do not currently configure an automatic expiry period for game profiles. Hosting-provider logs and backups may follow separate retention periods set by those providers.
You can request deletion from the in-game Account screen. A browser deletion flow is also available at Delete Drop the Ball account. The browser flow prompts you to sign in and confirm deletion. Deletion removes the game's profile and associated saves, devices, inventory, coin records, rewarded-ad records, and game sessions. The linked login is also removed when it has no other game profiles and is not a staff account; otherwise the login remains while this game's profile data is deleted. Deletion cannot be undone.
Guest players can use the in-game deletion option. If you cannot access the game or your account, contact support@mamora.me. Deletion of server records does not automatically erase copies already stored in device backups or remove information held independently by an advertising or hosting provider.
Children's privacy
The game does not ask for a date of birth. If you believe a child has provided personal information to us, contact support@mamora.me so we can review the request. Advertising availability and consent requirements may vary by age and region; the publisher must configure the applicable protections before distributing the game to children or in regions that require consent.
Security
Account passwords are stored using Django's password hashing, and device authentication tokens are stored as one-way hashes on the backend. No internet service can guarantee perfect security. Use the production service only with HTTPS, restrict access to backend systems, and contact us if you suspect unauthorized access.
Changes to this policy
We may update this policy when the game or its data practices change. The updated date at the top of this page indicates when the current version took effect.
Contact
For privacy questions, access or deletion requests, email support@mamora.me.