Breakline: privacy policy

Last updated 1 October 2026

In short

Breakline has no ads. The daily board sends your chosen board name and results; anonymous gameplay statistics can be switched off in Settings. Where the optional paid-scrap wallet is available, Play Games or Game Center sign-in connects you to server-held purchase and balance records. Free play and earned scrap do not require wallet sign-in.

What stays on your device

Your campaign progress, earned scrap, unlocked cards, settings, the run in progress and a short play log are saved on your device only. They are never sent anywhere. Uninstalling the game deletes them. Bought scrap and cosmetics paid for with bought scrap are separate server records when you use the wallet.

Anonymous gameplay statistics

So we can see how the game is played and fix what is too hard, too easy or confusing, the game sends short gameplay events. It is on by default; turn off SHARE ANONYMOUS STATS in Settings and nothing more is sent, and events not yet sent are deleted from your device. Each event carries:

We do not collect your name, email address, contacts, location, advertising ID, device model or any device identifier. We do not share these statistics with advertisers or sell them. They are stored in Cloudflare Workers Analytics Engine, which deletes them after about three months.

What the daily board keeps

The first time you open the game with a connection, it asks our server for an anonymous player number and a secret key. The server keeps:

Your name and daily results are shown to everyone who plays that day. We do not collect your email address, phone number, contacts, location, advertising ID or any device identifier.

Optional paid-scrap wallet

Signing in sends a single-use Play Games authorization code or a Game Center identity signature to our server for verification with Google or Apple. We keep the verified platform player identifier and a random wallet identifier, not your platform password, email address, real name or contacts. Apple and Google wallets are separate; recovery uses the same platform account and requires internet access.

To deliver and protect bought scrap, we verify purchases with the store and keep purchase tokens or transaction identifiers, their wallet binding, credits, paid spends, refunds, balances, operation identifiers, and cosmetics bought with paid scrap. Refunds may make the paid balance negative; subsequent credits first cover that amount. Turning anonymous statistics off does not stop this transactional processing.

Wallet sessions expire after 15 minutes. The server stores session hashes and expiry times, never raw session tokens; the app keeps its token in memory. We also keep short-lived proof hashes to prevent login replay. Proof guards expire after 5 minutes. Expired records are removed by the scheduled cleanup, including while new wallet access is disabled. Active wallet and transaction records are kept for balances, recovery and refund handling until you delete the wallet; the analytics three-month retention period does not apply to these records.

Where it is kept

The daily board, wallet and statistics run on Cloudflare Workers. Wallet records use durable SQLite storage. Cloudflare handles each request, including your IP address, to deliver it, and keeps request logs for a few days so we can fix problems. Our game server itself does not store IP addresses; it uses them only for a moment, to refuse floods of requests.

Board names and reports

Names are checked before they reach the board: offensive words, slurs, links and names that pose as the game are refused, in every language the game speaks. Tap a name on a daily board to report it or to hide that player on your device. A report sends only which name you reported and your anonymous player number. A name several players report is replaced at once with a neutral one and reviewed; a player whose names keep breaking these rules loses the choice of name. To report anything else, write to support@kalimalabs.com.

Purchases

Purchases are made through Google Play or Apple's App Store under that store's privacy policy. We never see your card or bank payment details. One-time products are recorded locally. Paid-scrap purchases also use the verified server records described above; store transaction identifiers are not payment-card details.

Removing your data

Choose a new name at any time from the title screen; the board updates today's and yesterday's entries. To have your board entries removed, write to support@kalimalabs.com and give your board name. We will delete them. Gameplay statistics are not linked to your name or your board entries, so we cannot find yours to delete them; switch them off in Settings, and what was sent expires on its own after about three months.

To delete your wallet, open SHOP → SCRAP WALLET → DELETE WALLET. Confirm the loss of bought scrap and paid-scrap cosmetics, then verify the same Play Games or Game Center owner. Server deletion removes the platform identity link, wallet, every wallet session, raw purchase identifiers, balances, credits, spends, refunds, operations and paid-scrap cosmetics together. Completion is shown in the app; a lost connection or failed local save leaves a retry state rather than claiming success. Resolve pending local scrap spends before starting. Undelivered earned reservations are safely returned if the wallet was deleted elsewhere. Earned scrap, game progress and separately purchased non-consumable packs remain.

For Android, you can also delete your Breakline wallet on the web without reinstalling. It verifies ownership with Google Play Games and requires a separate confirmation; it does not create an account. A short-lived, secure browser cookie and server state protect that request. Game Center ownership is verified inside the app, not by this Google web flow. Never send passwords, login proofs or purchase tokens to support.

After deletion, old receipts cannot restore the removed paid value. A new sign-in creates a new empty wallet. Pending store charges are not cancelled by deletion and will not restore scrap; unfinished receipts for a removed wallet are closed without new credit. Refunds remain subject to the store's process. Other devices remove their wallet cache when they next connect to the wallet server; offline local copies cannot be remotely erased. Disconnecting or uninstalling alone does not delete the server wallet.

For duplicate-delivery protection, we retain keyed receipt digests without wallet or player links for 30 days. For in-flight login safety, a keyed player digest and deletion generation expire after 5 minutes; proof replay hashes also expire after 5 minutes. Browser verification state expires after 10 minutes, or 5 minutes after verification/completion. Our five-minute scheduled cleanup removes expired rows; a service outage can delay physical removal, but expired rows cannot authorize requests. These hashes are not described as anonymous, and these are technical retention periods, not claimed legal requirements. No whole identifiable wallet ledger is retained after deletion in the live database. Cloudflare's database recovery backups may contain prior records for up to 30 days; our app does not restore deleted wallets from those backups.

Children

Wallet sign-in is optional. Players should not use their real name or anything that identifies them as their board name.

Changes

If the game starts keeping anything new, this page will say so first, with a new date above.