// Clash of Beams privacy

Clash of Beams Privacy Policy

What Clash of Beams stores, how online profiles and matches work, how long records remain, and how to delete an account.

This policy applies to Clash of Beams 1.0.0 for Android, including the application com.martnexs.clashofbeams. It covers the installation-bound online profile used by Private Online and Ranked Online play. Tutorial and Practice can be used offline.

The short version

Controller and contact

Salvatore Matteo Martorelli, operating as MartNexS, is the data controller for the processing described in this policy. Privacy questions and requests can be sent to martnexs.trrr@gmail.com.

Please mention Clash of Beams in the subject. Never send a session token, private lobby code, password, signing credential, or unnecessary identity document.

Information kept on the device

Clash of Beams stores music and effects volume, haptics and reduced-motion preferences, Tutorial progress, and Practice records locally. Android also stores the signed session used to reconnect to Online play. App updates and restarts normally keep that session. Clearing app data or uninstalling the app removes the local session and can permanently remove access to the online profile because version 1.0.0 has no recovery or transfer feature.

Removing local data does not by itself delete an online profile. Use the in-app deletion control or the Clash of Beams account-deletion page.

Information used for Online play

The first visit to Online creates a random account and signed session for that installation. The player then chooses a globally unique public name. The service processes:

Better Auth also stores a random internal address ending in @device.invalid because its generic user schema requires that field. The app does not ask the player for this value, display or verify it, send mail to it, or use it to recover the profile.

Clash of Beams does not request a personal email address, password, contacts, precise location, advertising identifier, chat message, photo, microphone recording, or uploaded content. It does not maintain a public leaderboard or match-history page.

Who can see information

An opponent sees the public player name and the viewer-safe state required to join, plan, resolve, and finish a match. A public name is not a secret and must not be treated as proof that someone owns the corresponding profile.

Server-private seeds, unseen queue values, private internal identifiers, authoritative random state, and another player’s session are not sent to opponents. MartNexS does not sell online information or share it with advertisers or data brokers, and does not use it for behavioral advertising.

Why information is processed

Online information is used to create and authorize the installation-bound profile; provide private and ranked matchmaking; run matches; reconnect interrupted play; calculate results and ratings; and protect the service from misuse.

Where applicable, the legal basis is performance of the online service requested by the player under Article 6(1)(b) GDPR. MartNexS also relies on legitimate interests under Article 6(1)(f) GDPR to secure the service, enforce authorization, apply rate limits, prevent abuse, and diagnose technical failures.

Providing the public name, signed identifiers, and match state is not a legal requirement. Without them, Private Online and Ranked Online cannot work. Tutorial and Practice remain available offline.

Service providers and international processing

Convex hosts the authoritative multiplayer functions, database, scheduling, presence, and result settlement. Better Auth and its Convex component provide the anonymous signed sessions. When enabled, a Cloudflare relay can carry short-lived, viewer-safe planning previews to reduce latency; Convex remains authoritative.

These providers process network requests and may retain their own security and service logs. Their infrastructure may process information outside the player’s country. Applicable transfer safeguards depend on each provider’s current terms and configuration. Contact MartNexS for more information about the providers used for Clash of Beams.

How long information is kept

The installation-linked profile, current public name, Online access state, and minimal Ranked rating records remain while the online account exists. A replaced or deleted name is quarantined for 90 days before it can be reused.

Internal sessions have a rolling lifetime of up to 365 days and can refresh after seven days of continued use. Terminal match, lobby, pairing, and cancelled queue records are scheduled for removal after approximately 24 hours. Most game rate-limit and behavior records expire after approximately one to 24 hours. Provider security or service logs may follow the provider’s own documented retention periods.

After account deletion, short-lived terminal, security, provider, and name-quarantine records may remain for the periods above where needed to complete deletion safely, prevent abuse, and protect the service.

Account deletion

The fastest route is inside the authenticated app: open Settings, choose Delete online account, type the current public player name, and confirm after active Online play has ended. This removes the profile, public name, ratings and record counters, authorization rows, and linked Better Auth user and sessions. Offline settings, Tutorial progress, and Practice data remain separately on the device and can be removed by clearing app data or uninstalling.

Someone who no longer has the authenticated installation can initiate a request through the public account-deletion page. A public name alone is not proof of ownership. MartNexS will use a proportionate manual review and will not collect extra identification solely to make a match. If the available information cannot safely identify the requester, MartNexS will explain that limitation instead of deleting another person’s profile.

Your rights

Depending on the applicable law, a player may request access to, correction of, deletion of, restriction of, or portability of their personal information, and may object to processing based on legitimate interests. Requests are handled without charge and within the time required by applicable law.

A player may also complain to the data-protection supervisory authority for the country where they live, work, or believe an infringement occurred. In Italy, this is the Garante per la protezione dei dati personali.

Security

The service uses HTTPS, random anonymous identities, signed sessions, server-side authorization, viewer-safe multiplayer messages, rate limits, bounded retention, and independent emergency controls. No online service or storage method can be guaranteed absolutely secure. Keep private lobby codes private and never share a session or signing credential.

Children

Clash of Beams does not ask for a player’s age and is not designed to collect sensitive information about children. A parent or guardian who believes a child created an online profile can use the account-deletion page or contact MartNexS with the public player name and enough non-sensitive context to locate the profile. Please do not send unnecessary identity documents.

Advertising, analytics, and purchases

Version 1.0.0 contains no advertising SDK, analytics SDK, crash-reporting SDK, behavioral tracking, billing flow, premium currency, subscription, consumable, boost, or in-app donation link. External official links open only when selected and do not unlock gameplay.

Changes to this policy

This policy will be updated if the release, providers, retention rules, or data practices change. The effective and updated dates at the top show which version is current.