Last updated: 26 June 2026
This Privacy Policy explains how Cinny ("we", "us", or "our") collects, uses, and shares information when you use the SecureIDLE mobile application (the "App"). SecureIDLE is an idle/incremental game in which you run a simulated security operations centre.
By using the App, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the App.
We use Sign in with Apple as the only sign-in method. When you sign in, we receive from Apple:
We use this to create and secure your account.
We store the following in our cloud database (Google Firebase Firestore), linked to your account:
In-app purchases are processed by Apple. When you buy a Cipher pack, Apple provides us with a signed receipt that we verify on our servers to grant your purchase. We store the transaction identifier and the product purchased to deliver your items, prevent duplicate or fraudulent grants, and support your purchase. We never receive, see, or store your credit/debit card number or other payment details — those are handled entirely by Apple.
We use Firebase Analytics (provided by Google) to collect non-identifying gameplay and "funnel" events — for example, completing onboarding, investigating an alert, hiring an analyst, levelling up, or completing a purchase or rewarded ad. These events contain gameplay parameters only and are not used to identify you personally. Firebase Analytics also collects standard device and usage information such as device model, operating system version, app version, and mobile advertising / device identifiers.
We use Google AdMob to display optional rewarded ads. To do so, the AdMob SDK may access your device's advertising identifier (IDFA) and related device information, and may collect advertising interaction and diagnostic data. Whether the advertising identifier is used for tracking depends on your choice in the App Tracking Transparency prompt (see Section 4).
We use Firebase App Check with Apple's App Attest / DeviceCheck. This produces a device-attestation token that helps us verify requests come from a genuine, unmodified copy of the App. It is used to protect our backend from abuse and does not identify you personally.
The App can schedule local notifications (reminders to return to the game) directly on your device, if you grant notification permission. These are generated on-device and are not push notifications; no notification data is sent to or from our servers.
We do not collect precise or coarse location, your contacts, photos, microphone audio, camera input, or health/financial data beyond the purchase information described above.
We use the information described above to:
If you are in a region with data-protection laws such as the EU/UK GDPR, our legal bases are: performance of a contract (providing the game and your account), your consent (advertising-related tracking and notifications), and our legitimate interests (analytics, security, and improving the App).
The first time advertising features start, the App presents Apple's App Tracking Transparency (ATT) prompt. If you allow tracking, the advertising identifier may be used to personalise ads and measure ad performance. If you deny tracking, you will still see ads, but they will not use the advertising identifier for cross-app tracking.
You can change this at any time in iOS Settings → Privacy & Security → Tracking. You can also limit ad personalisation in iOS Settings → Privacy & Security → Apple Advertising.
Advertising is provided by Google AdMob. For details on Google's practices, see Google's Privacy Policy at https://policies.google.com/privacy.
We share information only as needed to operate the App:
These providers process data on our behalf or as independent controllers for their own described purposes. We do not sell your personal information, and we do not share it with data brokers.
We may also disclose information if required by law, to enforce our Terms of Service, or to protect the rights, safety, and security of our users or the App.
We retain your account and game data for as long as your account exists. Purchase/transaction records may be retained as long as necessary to provide your entitlements, prevent fraud, and meet legal and accounting obligations. Analytics data is retained according to the provider's default retention settings. When you delete your account (see Section 7), we delete your associated profile and game-save data.
SecureIDLE is not directed to children under 13 (or the minimum age of digital consent in your country), and we do not knowingly collect personal information from children under that age. If you believe a child has provided us with personal information, please contact us and we will delete it.
We use industry-standard measures to protect your information, including authenticated access controls, server-side validation of purchases and entitlements, and App Check device attestation. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
We use Google Firebase and Google AdMob, which may process and store data on servers located outside your country, including in the United States. Where required, these providers rely on appropriate safeguards for international data transfers.
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, provide additional notice within the App. Your continued use of the App after changes take effect constitutes acceptance of the updated policy.
If you have questions or requests regarding this Privacy Policy or your data, contact us at: