1. Scope and current status
This policy covers the LOCKFRAME iOS game and lockframe.games. “We” and “LOCKFRAME” mean the game developer. The public game is not yet available on the App Store. As of the date above, the rewarded-ad and wallet systems are implemented in code, but their production services still require final external setup and live-device validation. This policy must be checked again against the exact shipping build before release.
No website tracking: this website sets no cookies, runs no analytics, contains no advertising scripts and has no forms or login wall. The Privacy Policy is available publicly without consent prompts.
2. Information handled
On-device game data
The game stores progress and settings on your device, including scores, distance, tutorial state, missions, world mastery, inventory, selected language, recent openings and currency state. This information supports gameplay and restoring your local experience. Uninstalling or resetting the app may remove local data, except information separately held by Apple, Google or the Prism wallet service.
Prism wallet and server-side player account
When the production wallet service is enabled, the game automatically creates a pseudonymous player account. It does not ask for a profile name, email address, phone number or password. The service is designed to store:
- Account and authenticationA random player UUID; a one-way hash of each device credential; account creation, last-seen and credential timestamps; and the credential source. The newest ten credential hashes may be retained so multiple devices do not sign each other out.
- Wallet and gameplay ledgerPurchased and earned Prism balances, refund debt, wallet version and timestamps; and ledger entries such as operation ID, grant/spend/refund type, amount, reason, product ID, environment and time.
- Apple purchase recordsApple transaction and original transaction identifiers, product ID, credited Prism amount, StoreKit environment, purchase date, revocation date and record creation date. LOCKFRAME does not receive your payment-card details.
- Apple-linked recovery identifiersAn Apple-signed App Transaction identifier and environment may be stored to recover the wallet across reinstall or devices. If Sign in with Apple is used, the stable Apple subject identifier is stored. The current implementation requests an identity token only and does not request your name or email address.
The device keeps an authentication credential in Apple Keychain for convenience. The server stores only a SHA-256 hash of the secret, not the secret itself.
Apple in-app purchases
Prism purchases use Apple In-App Purchase through StoreKit. The game sends Apple-signed transaction data to the wallet service so it can verify the purchase, credit it once, restore the remaining purchased balance and process refund or revocation notices. Apple processes payment and may handle information under the Apple Privacy Policy.
Sign in with Apple
The client and backend include Sign in with Apple for wallet protection and recovery. On supported systems the game first tries automatic recovery using Apple’s App Transaction. Sign in with Apple is optional when that durable identity is available; it may be required before a real-money purchase when no durable Apple-verified identity exists. Nothing is charged before that identity step succeeds.
Google AdMob rewarded ads
The game includes Google Mobile Ads for rewarded ads only. The planned placement is the first death in an Adventure run. Ads do not appear in the tutorial, Daily Frame, later deaths or the Apple Watch app. Watching is optional; closing early or an ad failure grants no reward, and declining consent does not block the rest of the game.
Google’s SDK may process information needed to serve, measure, secure and diagnose ads, including IP address and approximate location, device or app identifiers, ad and product interactions, advertising data, performance data, crash data and other diagnostics. Google’s exact handling depends on device settings, region, consent choices and the mode of ad delivery. See Google’s Privacy Policy.
The current LOCKFRAME configuration does not request App Tracking Transparency authorization and is not intended to access the IDFA or track you across other companies’ apps and websites. Google may still use other identifiers and data for limited advertising, frequency capping, aggregated reporting, security and fraud prevention where permitted.
Google User Messaging Platform (UMP)
UMP asks for updated consent information before the game requests an ad and shows Google’s consent form when required for your region. Ads are requested only when the SDK reports that they may be requested. Where required, the Help screen offers a Privacy Options entry so you can revisit your choice. The exact message still has to be configured in the AdMob console before public release.
Analytics and diagnostics
LOCKFRAME has no separate third-party gameplay analytics SDK. Gameplay event tracking in the reviewed build is local: in developer builds it can write event names to the device log when a debug flag is enabled, and it is not uploaded by LOCKFRAME. Unity Analytics and Unity Cloud Diagnostics are disabled in the reviewed project settings. Google Mobile Ads and UMP may independently collect ad-related interaction, performance, crash and diagnostic information as described above. Apple may provide App Store or TestFlight diagnostics according to your Apple settings and Apple’s terms.
This website
The site does not deliberately collect personal information. It has no accounts, forms, cookies, analytics pixels or ad SDKs. Cloudflare Pages hosts the site and may process network and security information such as IP address, request time, requested URL and user-agent data to deliver and protect it. See the Cloudflare Privacy Policy.
3. Why information is used
- Provide game progress, purchases, Prism balances and wallet recovery.
- Verify Apple transactions, prevent duplicate credit and handle refunds or revocations.
- Authenticate devices, protect accounts and prevent abuse or fraud.
- Offer an optional rewarded-ad revive and record the consent choices needed for advertising.
- Diagnose failures, secure services and answer support or privacy requests.
- Comply with legal duties and enforce applicable terms.
The legal basis for each use can depend on where you live and requires final legal confirmation before launch. Expected bases include performing the game service you request, legitimate interests in security and fraud prevention, consent for advertising where required, and legal obligations for transaction records.
5. Retention
- Local game data: kept on the device until you reset the game or remove it, subject to Apple backup and Keychain behavior.
- Wallet account and ledger: the current backend does not yet implement an automatic retention period or deletion endpoint. Records are expected to remain while the wallet is active and until a verified deletion request is completed, except transaction, refund, anti-fraud, security or accounting records that must be retained for a legally required or reasonably necessary period.
- Support messages: retained as long as reasonably needed to answer the request, keep a record of the resolution and meet legal obligations.
- Google, Apple, Cloudflare and infrastructure logs: retained under the relevant provider settings and policies. Final production log retention has not yet been selected.
Legal confirmation required: exact production retention periods, the legal-entity/controller details, hosting regions, international-transfer terms and the final legal bases must be approved before public launch.
6. Your choices and deletion
You can decline an optional rewarded ad or, where offered by UMP, revisit advertising choices through Help → Privacy Options. You may also manage Apple privacy and device settings directly in iOS.
To request access, correction, a copy or deletion of information controlled by LOCKFRAME, email [email protected] with the subject “LOCKFRAME privacy request.” Include enough information to locate the wallet, such as the in-game player or wallet identifier if available. Never send a password, Apple ID password, Keychain secret, identity token or full signed transaction. We may need to verify that the wallet belongs to you. Data that must be retained for legal, fraud-prevention, transaction-integrity or dispute purposes may be isolated and kept for the required period.
The reviewed app does not yet provide an in-app account-deletion control, and the backend has no deletion endpoint. Because the game automatically creates a server-side account, an in-app way to initiate deletion should be added before App Store submission. Email is the current pre-release contact route, not a substitute for that required product change.
7. Security
The wallet design uses HTTPS, hashed device credentials, Apple-signed transaction verification, unique transaction and operation identifiers, database transactions and rate limits. No method of transmission or storage is completely secure. Do not send sensitive credentials through support email.
8. Children
The game’s final age rating and child-directed treatment have not yet been confirmed. The current advertising request code does not set a child-directed or under-age-of-consent flag. This must be reviewed against the intended audience and launch regions before release. Parents or guardians can contact us about a child’s information using the address below.
9. Contact and changes
For privacy questions or requests, email [email protected]. The developer’s full legal identity and postal address need legal confirmation before launch and will be added here if required.
We may update this policy as the shipping build, providers or legal requirements change. Material changes will be reflected by the “Last updated” date and, when appropriate, an in-game notice.