HackerAI Privacy Policy
HackerAI is a fictional cyber strategy game published by Elysra. This policy explains what data the online version of HackerAI collects, how that data is used, and how players can request deletion.
HackerAI's hacking systems, IP addresses, targets, modules, malware names, and network activity are fictional gameplay content. The game does not scan, attack, or interact with real third-party devices, networks, accounts, or servers. Credits, loot, recurring services, and market values are fictional game resources with no real-cash value. HackerAI does not support deposits, withdrawals, cash-out, or real-money trading.
Data We Collect
The online version of HackerAI may collect and store:
- Account identifiers, including operator handle, email address for password accounts, and session identifiers.
- Guest account identifiers when a player chooses to continue as guest.
- Google account identifier, verified email, and profile details returned during Sign in with Google. The backend stores the provider subject/email and may use the name to derive a new operator handle; the native profile image URI is not uploaded to HackerAI.
- Play Games player identifier and profile details such as display name, title, and profile image URLs returned while checking the secondary platform identity. The backend links the verified player ID and does not currently persist the returned PGS profile images.
- Gamer identity (such as gamertag/avatar), analytics, diagnostics, and enabled achievement activity that Play Games Services processes for game-service functionality and stability.
- Game progress, reputation, rig inventory, modules, defenses, simulated targets, rewards, and trade activity.
- Forum posts, thread activity, public in-game handle, and fictional in-game IP address shown in forums.
- Optional player-submitted feedback and issue reports (a category, a short subject, and a message) sent to Elysra for support and moderation. The backend may apply automatic personal-data redaction when the privacy filter is enabled; otherwise the submitted text is stored verbatim for operator review and then deleted according to the retention window below.
- Session tokens, trusted-device records, device public-key fingerprints, install identifiers, platform, app version, client type, timezone bucket, and related security challenge data.
- Limited first-party usage events such as app opens, successful logins, screen views, session activity, and tutorial completion, recorded with a hashed installation identifier and/or player identifier, platform, app version, client type, timestamp, and bounded event properties.
- Play Integrity signals for sensitive Android actions, such as hack completion, forum posting, and market actions.
- Google Play age-range signals when Google Play provides them on supported Android devices so HackerAI can apply age-appropriate access handling.
- Standard backend logs and abuse-prevention data such as IP address, user agent, request time, error data, hashed network-prefix audit records, rate-limit events, and security risk events.
Data We Do Not Collect
HackerAI does not request or collect real device contacts, precise location, camera, microphone, SMS, calendar, phone state, or external storage data. The Android app requests internet access so it can connect to the HackerAI backend and Google services. It also declares Android's normal VIBRATE permission for optional haptic feedback; that permission controls the vibrator and does not provide access to personal data. Google Play services may separately process device, account, and game-service data under Google's own terms when its platform features are available.
Local Sound, Haptics, And Preferences
Theme, accent, scanline, guide, sound, ambience, volume, and haptic preferences are stored locally on the device and are not currently synced to the HackerAI account. (Player-submitted feedback is handled separately and stored server-side — see Data We Collect above.) Interface sounds and ambience are synthesized and played on the device. Optional haptic feedback uses vibration. HackerAI does not open the microphone, record voice or gameplay audio, or upload recordings.
How We Use Data
We use data to:
- Operate online sessions and authenticate players through their selected primary identity.
- Optionally associate an authenticated Play Games platform profile with the player's Google operator.
- Sync progress across sessions and devices.
- Run in-game forums, trading, rankings, PvP, and multiplayer simulation features.
- Apply age-appropriate access handling when Google Play shares an age range with the app.
- Protect accounts, detect abuse, enforce rate limits, and validate trusted-device or Play Integrity checks.
- Debug service issues, monitor reliability, and provide support.
- Understand, in aggregate, which features and onboarding steps players use so we can improve future updates.
Authorized Elysra operators may review existing account, support, security, feedback, and aggregate usage data through an internal console for the purposes listed above. That console adds no player-side telemetry or new categories of player data, and it does not use third-party analytics.
Android Authentication Behavior
On Android, Credential Manager may automatically return one previously authorized Google account when the player has not explicitly signed out and Google permits auto-select. This silent request restores existing HackerAI operators only and cannot create a new operator. Creation requires a deliberate Continue with Google selection or another explicit account-creation action. Play Games Services v2 may separately recognize the device's platform gaming profile at launch. HackerAI treats that Play Games profile as secondary and links it only after the server verifies the platform proof.
Sharing
Elysra does not sell personal data. Data may be processed by backend hosting providers, database providers, Google identity services or Credential Manager, Google Play services used for Play Games, Play Integrity, or Play Age Signals, and security infrastructure needed to operate the service. These providers process data only as needed to provide the relevant service. Play Games Services automatically processes gamer identity, analytics, and diagnostics; its handling is also governed by Google's policies and the player's Google/Play Games settings.
Retention
Account and gameplay data is retained while an account remains active so the game can restore progress. By default, pseudonymous device/security events and orphaned install hashes are bounded to 7 days, expired or revoked sessions to 30 days, and action logs to 30 days; deployment settings may shorten those windows. First-party usage events are retained in raw form for up to 90 days; aggregated statistics that no longer identify an installation or account may be kept longer. Player-submitted feedback is retained for up to 365 days for operator review and then automatically deleted. HMAC values are pseudonymous, not anonymous, because the service can correlate them while it holds the secret. Public forum records are handled as described below.
Data Deletion
Signed-in players can permanently delete their HackerAI account from Settings > Danger zone > Delete account. The player must enter the exact case-sensitive operator handle. A recently authenticated session is accepted; an older session requires a signed device challenge or fresh sign-in. Successful deletion signs the player out and removes the account identity, gameplay progress, sessions, linked sign-in identities, device trust links, inventory, and private account spaces.
Step-by-step instructions are available on the public account deletion page. A player who cannot access the account can email [email protected] with the subject "HackerAI account deletion" and include the operator handle or account email. Elysra may require reasonable verification so another person cannot delete the account.
Private forums owned by the player and their contents are deleted. Public forums owned by the player become
read-only archives so other players do not lose their contributions. The deleted player's public threads and posts
remain only as generic [deleted] tombstones; the handle, simulated IP, audit identifier, title/preview,
and original body are removed. Active PvP jobs and attack sessions are canceled, counterpart references are removed
or anonymized while earned numeric outcomes remain, and shared organizations transfer to an eligible remaining member
or dissolve. Security records required for fraud prevention or legal obligations may be retained only for the applicable disclosed period.
Children
HackerAI is not directed to children under 13. Players under the age required by their country or region should not create an account or use online features without appropriate permission.
Security
HackerAI uses HTTPS for production network traffic and account-security measures such as session tokens, trusted-device checks, and Play Integrity checks for selected sensitive actions. No method of transmission or storage is completely secure, but we use these measures to reduce unauthorized access and abuse.
Changes
This policy will be updated before adding ads, additional third-party analytics, crash reporting, push notifications, purchases, or new third-party account providers. HackerAI's first-party usage events, together with Play Games Services automatic analytics, diagnostics, and enabled achievement activity, are disclosed above and must remain represented in the Play Console Data safety form.
Contact
For privacy questions, contact [email protected].