Raid & Rescue ‹ Back to base

The fine print

Privacy Policy

Last updated: August 2026 · Applies to the Raid & Rescue iOS app and this website

The short version

We collect what the game needs to work, and we keep a recording of each battle so we can tune and rebalance it. We do not sell anything to anyone, and there is no analytics or attribution SDK in the app. The app shows ads in one place only — when you choose to open a supply crate you caught mid-battle — and those ads are not personalised. This website sets no cookies.

Who we are

Raid & Rescue is made and operated by Diretek Solutions, LLC, a company registered in Texas, United States. We are the data controller for everything described here, and privacy@raidandrescue.com reaches us for any question about it.

What we collect

Your account

One of the following, depending on how you sign in:

  • Guest — created silently on first launch. A generated device identifier and a secret held in your device's Keychain. No email, no name.
  • Email — your address and a hash of your password. We never store the password itself.
  • Sign in with Apple — the opaque identifier Apple gives us, plus your address if you chose to share rather than hide it. A verified Apple address matching an existing email account links the two instead of duplicating them.

Alongside that: your callsign, your pilot portrait, and a country code for the boards.

Your progress

Unlocked missions, per-level completions and best times, research lab state, currencies and prize boxes — the things that have to survive a reinstall or follow you to another device.

Battle recordings

When a battle ends, the app uploads a recording of the match — the same idea as a replay file. It is a log of what happened on the battlefield: the units you bought and lost, shots fired, how your funds rose and fell, periodic snapshots of the field, and the random seed that lets us play the match back exactly as it happened.

It describes the simulation, not the person running it. The app asks for no camera, no microphone, no location and no contacts, and it can see nothing else about your device. What we get out of a recording is which missions are too hard, which units are overtuned and where the enemy AI plays badly — it is the reason the game can be rebalanced without you having to install an update. A recording stays linked to your account until you delete the account, which severs the link.

While a battle runs the app also sends a short presence ping every twenty seconds, which is how the server tells a finished match from an abandoned one. If something goes wrong it reports the error code, build number and time; those entries are kept thirty days.

Leaderboard data

Your callsign, your clear time, the mission and difficulty level, and your country code are shown publicly on the boards — in the app and on this site. Nothing else about you is published.

Advertising

There is one ad in the game, and you choose whether to see it. Catch a supply crate during a battle and you are offered the crate sealed: open it and a short rewarded ad plays first, or decline and nothing plays. That reward is the only place the game shows an ad today. Buying the Ad-Free Commission removes it permanently.

The ads are served by Google AdMob. We request non-personalised ads, which means Google is told not to use profile data to pick what you see; the ad is chosen from context rather than from a history of you. Because of that we never ask for tracking permission, so the app does not read your device's advertising identifier (IDFA) and cannot pass it to anyone.

When an ad loads, Google receives what it needs to serve and count it: your IP address, an identifier for the device, the app and its version, and whether you watched the ad through. That happens inside Google's SDK and is governed by Google's privacy policy. We do not receive it — all we learn is that an ad finished, so the crate can be opened. We also do not use Google's advertising data to identify you or add it to your account.

This website

Nothing, unless you type it in. If you give us an address for launch notification we store that address and the date, in a database kept separate from the game's, and use it for that one message. Every message carries an unsubscribe link. The web server keeps standard request logs, including IP addresses, for security.

What we don't do

  • We do not sell, rent or trade personal information.
  • We do not read your advertising identifier (IDFA), and we never ask for permission to track — ads are served non-personalised instead.
  • There is no advertising outside the supply-crate reward, and no ad banners anywhere.
  • There is no analytics or attribution SDK in the app.
  • We do not track you across other apps or websites.
  • This site sets no cookies and loads nothing from a third-party domain.

Where your data lives

Our servers, and four others in the course of doing their jobs:

  • Apple — if you use Sign in with Apple, to authenticate you. Apple's privacy policy governs their side.
  • Groq — a proposed callsign is sent to a hosted language model for moderation before it is accepted. Only the candidate text goes, with nothing identifying you.
  • Google — AdMob serves the supply-crate ad, and receives the request data described above. Non-personalised, and no advertising identifier from us.
  • DreamHost — our hosting provider, who stores the data on our behalf.

Those are the providers we use today. If we add another we will list it here and move the date at the top of this page.

How long we keep it: account data until you delete the account; battle recordings for as long as they remain useful for balancing the game; diagnostic logs thirty days; your launch-notification address until you unsubscribe or the launch message has gone out.

Deleting your data

Settings → Account → Delete Account in the app, then confirm. It happens immediately: your login, callsign, email and any Apple identity are removed, our Apple token is revoked, and your leaderboard entries go with them. Recorded battles remain, with every link to you severed — once detached from an account there is nothing personal left in them.

You can also ask for a copy of what we hold, or ask us to correct it. Write from the account's address to privacy@raidandrescue.com and we will answer within thirty days. Depending on where you live you may have further rights under laws such as the GDPR or the CCPA; we will honour them. There is a fuller walkthrough on the support page.

How we check it is really you

We will not hand your data to someone else, so before we act on a request we confirm it came from the account it concerns. Usually that is simple: write from the address on the account and we reply to that address. If you signed in with Apple and chose to hide your address, we hold Apple's forwarding address rather than your real one — mail you send us will not match it, so we confirm by writing to the forwarding address instead and acting on your reply.

Guest accounts are the exception. A guest has no address on file at all — only an identifier belonging to the device and a secret held in its Keychain. There is no way for us to tell a guest apart from anyone claiming to be that guest, so we cannot answer an emailed request about one, and we will say so rather than guess. Holding the device is the proof, which is why deletion lives in the app itself and works without signing in. The same applies if you signed in with Apple and no address ever reached us.

Why we are allowed to hold it

If you are in the UK or the EU, the law wants us to name the grounds we rely on, so: your account and progress exist because you asked us to run the game for you (performance of a contract). Battle recordings, error reports and the presence ping rest on our legitimate interest in a game that works and can be balanced — they measure the simulation, and you can delete the account they attach to at any time. A launch-notification email address is consent, withdrawable from the unsubscribe link in every message. Serving a rewarded ad you chose to watch is also our legitimate interest, kept narrow by requesting non-personalised ads and never touching your advertising identifier.

Our servers are in the United States, so using the game moves your data there. Where that transfer needs a legal footing we rely on the European Commission's standard contractual clauses with our providers.

For California: we do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in the CCPA. There is nothing to opt out of, which is why you will not find a "do not sell" switch here.

Children

Raid & Rescue is not directed at children under 13 — or under the higher minimum age where you live, which is 16 in some countries — and we do not knowingly collect their information. If you believe a child has created an account, write to us and we will remove it.

Changes & contact

If this policy changes materially we will update the date at the top and, where it matters, say so in the app. Traffic is encrypted in transit, passwords are stored only as hashes, access tokens expire, and recorded battles sit outside the web root. None of that makes any system perfect, and we will not pretend otherwise.

privacy@raidandrescue.com