Approach CTL · 1:25000
Privacy Policy
Approach · last updated 25 September 2026 · applies to Approach on iOS and Android
Approach has no sign-in. It never asks for your email, phone number, contacts, photos or location, and there is no password. It does have leagues and leaderboards, so that other players can see how they rank against you. To make that work, the game sends your shift scores, a replay of each ranked shift so the score can be checked, a display name you choose, and a randomly generated player number to our leaderboard service. It also sends an automatic crash report if it crashes and counts anonymous play statistics, and, only if you allow notifications, it registers a push token. That is the whole list. The rest of this page explains each item.
What stays on your device
Most of what the game remembers never leaves the phone. It is kept in the app's own private storage, and we cannot see it:
- Your career stats and personal bests: shifts played, planes landed, best score
- Which achievements you have earned
- Your settings: sound, music, haptics, reduce motion, and the pause-menu choices (Clear arrivals, Max planes)
- A shift in progress, so leaving the app does not cost you the shift
- Small markers, such as whether you have seen the tutorial
This is deleted when you uninstall the app. Your phone's own backup (an iPhone backup, or Android's backup to your Google account) may include these files along with everything else it backs up. That backup is between your device and your Apple or Google account, and we never see it.
What leaves your device
Leagues and leaderboards
The leagues and leaderboards run on Google Firebase (Cloud Firestore). When you finish a ranked shift, the game submits:
- The shift's result: score, planes landed, crashes, and your Charge (the running total that moves you up the league ladder).
- A replay of the shift: the shift's random seed and the routes you drew, with their timings. The replay is how the server checks that a score was earned rather than invented. It describes what happened inside the game and nothing outside it: no location, no device details, nothing typed.
- A display name. The game gives you a generated one (for example “AmberTower”), and you can change it in Settings. It is free text, up to 16 characters, so it contains something about you only if you put it there. Because other players see it, it is checked against a word filter when you set it, and other players can report it.
- A player number: a random identifier created the first time you open the game, using Firebase Anonymous Authentication. It keeps your entries together on the boards. It is not linked to your real identity, your email or any account, because there is no account. You can see and copy it in Settings.
The game also keeps one player record up to date on the server: your display name, Charge, league division, best shift, number of shifts, and when it was last updated. These are the numbers the ladder is built from.
Other players may see your display name, your scores and your league standing. Shift entries are stamped with an expiry when they are posted and are deleted 90 days later. Your player record stays, so your league standing is kept, until you ask us to remove it. All of this is processed by Google as our service provider, under Firebase's data processing terms.
Taking part is on by default, and you can turn it off with the Leagues switch in Settings. While it is off, the game submits no shifts and no display name. It still signs in to Firebase anonymously when it starts, because that is where the player number comes from, but it sends nothing to the boards.
Reporting a display name
If you report another player's name from the boards, the report contains their player number, the name as you saw it, the time, and your own player number (so that misuse of the report button can be spotted). No player can read reports. They are used only for moderation.
Crash reports (Firebase Crashlytics)
The game uses Firebase Crashlytics, a Google service, so that crashes can be found and fixed. When the game crashes, Crashlytics sends:
- The stack trace, which is the line of code the crash happened on
- Your device model, operating system version and the app version
- Device state at the moment of the crash: free memory and storage, orientation, and whether the device was jailbroken or rooted
- A randomly generated Crashlytics installation identifier. It is not linked to you and resets if you reinstall.
- A short log of the last game events before the crash, so the crash can be traced to what the game was doing. It describes gameplay only, and never includes your name or anything you typed.
Crashlytics keeps these reports for 90 days.
Anonymous play statistics (Google Analytics for Firebase)
The game counts anonymous play events: that the app was opened, that a shift started, how a shift ended (score, planes landed, how long it lasted, whether it was a personal best), and whether a ranked shift was accepted and where it placed. It also records the standard session information that service collects. These describe the game being played, not the person playing it. We use them for one thing: to see how the game is actually played so it can be improved.
Advertising-identifier collection is switched off in the app's configuration, and the events never include your display name or player number. Google derives a general location (country, sometimes region) from a masked IP address, so that the counts can be broken down by place. That approximate figure is all we see. The game never uses your device's location services and never asks for location permission. The current version has no separate in-game switch for these statistics. If one is added, this page will say where to find it.
Rank notifications (only if you allow them)
The game can tell you when another player takes your rank. It does this only if you turn notifications on and your phone asks for, and gets, your permission. If you decline, nothing in this section applies to you. If you allow them, the game registers a push token with Firebase Cloud Messaging and stores it with your player number, so that the server knows which device to notify. A push token is a random string issued by Apple or Google for this app on one device. It is not your phone number and not an advertising identifier. Turning notifications off in your phone's settings, or uninstalling the app, stops it being used.
The connection itself
Whenever the game talks to Firebase (submitting a shift, fetching a board, reporting a crash), Google's servers see your device's IP address, as any server sees the address of anything that connects to it. We never see or store it. Google processes it as our service provider, on servers that may be outside your country, under the data processing terms linked above. Those terms include the EU's standard contractual clauses for international transfers.
Sharing a shift
The share button hands a short block of text (your score, planes landed and time) to your phone's own share sheet. What happens next is between you and the app you pick. The game does not see where you sent it.
What we do not do
- No advertising, and no advertising network in the game
- No in-app purchases
- No account, no email, no phone number, no contacts, no photos, no files
- No location services, precise or coarse
- No advertising identifier and no cross-app tracking (so the game never shows Apple's tracking prompt)
- No selling or sharing of data with anyone other than Google, acting as our service provider for the purposes above
Summary
| Data | Collected? | Leaves your device? | Linked to you? |
|---|---|---|---|
| Email, phone, address, contacts, photos | No | — | — |
| Location | No | — | — |
| Display name (generated, or one you choose) | Yes | Yes, to the leaderboards (unless Leagues is off) | To your player number |
| Shift scores, Charge, league stats | Yes | Yes, to the leaderboards (unless Leagues is off) | To your player number |
| Shift replay (routes and timings) | Yes | Yes, to the leaderboards (unless Leagues is off) | To your player number |
| Player number (random) | Yes | Yes | Pseudonymous |
| Career stats, achievements, settings | Yes, on device | No | No |
| Crash diagnostics and recent game events | Yes | Yes, to Crashlytics | No |
| Anonymous play statistics | Yes | Yes, to Analytics | No |
| Push token (only if you allow notifications) | Yes | Yes | To your player number |
Children
Approach is not directed at children under 13, and we do not knowingly collect personal information from them. The display name is the only free-text field. If you believe a child has put personal information in it, email us with the player number shown in Settings and we will remove it.
Your choices and your rights
- Stop sending leaderboard data: turn off Leagues in Settings.
- Change your display name: Settings → Player name.
- Delete what the server holds: email support@bendigogames.com with the player number shown in Settings, and we will delete your player record and every shift entry under it. We cannot find you by name, and we do not need to.
- Delete what the device holds: uninstall the app.
Data-protection laws such as the GDPR and the CCPA give you rights to access, correct and delete personal data about you. The address above is how to use them.
Changes to this policy
If a version of the game changes what it collects, this page is updated before that version is released, and the date at the top changes with it.
Contact
Approach is made by Bendigo Games. Questions about this policy or about privacy in the game: support@bendigogames.com.
Last updated: 25 September 2026