Code Vault Privacy Policy
**Effective date:** August 30, 2026
Budding Tech Studios Inc. ("Budding Tech Studios", "we", "us", or "our") provides *The Code Vault* (the "Game"). This Privacy Policy explains how we process personal information when you play the Game on a web browser, including through CrazyGames, or on a supported mobile platform.
This Policy covers the Game and its game services. If it conflicts with a general Budding Tech Studios privacy policy, this Policy controls for the Game. It does not govern the privacy practices of independent services, including CrazyGames, Unity, or a platform provider, which have their own privacy notices.
Information We Process
We design the Game to avoid asking players for names, email addresses, payment details, or free-form profile information. To provide, secure, and improve the Game, we may process the following information:
- **Pseudonymous game and service identifiers.** These include a randomly generated installation identifier, Unity player identifier, technical session identifiers, and server-generated game/profile identifiers. These are pseudonymous identifiers. Although they do not ordinarily identify a player by name, they may still be personal information under applicable law.
- **Game data.** This includes gameplay progress, completed or active game state, scores, streaks, leaderboard results, recovery/retry state, and technical records needed to prevent duplicate or fraudulent game actions.
- **Limited gameplay analytics.** We process pseudonymous player and session identifiers, the occurrence and time of two gameplay milestones (first code submitted and first lock cleared), code-correctness status, time remaining, and leaderboard score, rank, and related run metadata.
- **Device and connection information.** This includes browser or device type, operating system, app/version information, language, timestamps, IP address, and diagnostic information required to deliver, secure, and troubleshoot the Game.
- **Support communications.** If you contact us, we process the information you choose to include in your message and our response.
The current CrazyGames Basic Launch configuration uses the CrazyGames SDK only to notify CrazyGames when gameplay starts and stops. It does not request CrazyGames advertisements, CrazyGames account information, account exchange, or CrazyGames Data-module storage. CrazyGames may independently process browser, device, cookie, and platform-usage information under its own [Privacy Policy](https://www.crazygames.com/privacy-policy). If a future release enables CrazyGames account integration, advertising, or Data-module storage, we will update this Policy before release to describe the additional information and its use.
Browser and device storage
The Game uses browser or device storage that is necessary for it to function. In a web browser, Unity WebGL may use browser-managed storage (such as IndexedDB) for its PlayerPrefs data. On supported native platforms, equivalent data may be stored in platform-provided app storage.
This storage can contain pseudonymous identifiers, authentication/session material, selected settings, game-operation recovery data, and local state used to resume or safely reconcile gameplay. It is not used by us for behavioural advertising. Clearing browser data or app storage can remove this local state and may affect continuity until the Game can recover from its server-side record.
CrazyGames and other platform providers may use their own cookies, local storage, or similar technologies when they provide their platform. Their use of those technologies is governed by their own privacy notices.
Why we process information
We process the information above to:
- provide and operate the Game, including saving progress and displaying scores;
- authenticate a game session, prevent abuse, protect the Game, and resolve failed or duplicate game actions;
- maintain, debug, and improve reliability and performance;
- respond to support requests; and
- comply with applicable law and enforce our rights.
Where applicable law requires a legal basis, we process information as needed to provide the Game, for our legitimate interests in securing and improving the Game, to comply with legal obligations, or with consent where consent is required for a particular optional activity.
Service providers and disclosures
Depending on the platform and feature used, we use service providers and third-party platform providers to operate the Game. These include:
- **Unity Gaming Services**, including Authentication, Cloud Code, Cloud Save, Leaderboards, Remote Config, and Cloud Code logging/observability;
- **Google Cloud**, including the project-operated backend, Firestore, Cloud Run, and Cloud Storage used for game data and the limited analytics described below; and
- **CrazyGames**, when the Game is played on its platform.
We may also disclose information when required by law, to protect players or the Game, or in connection with a corporate transaction such as a merger, acquisition, or sale of assets.
We do not sell personal information or use the Game's pseudonymous identifiers for targeted advertising in the current Basic Launch configuration.
Analytics
We use a project-operated analytics job on Google Cloud to analyze the limited gameplay and leaderboard information described in Section 2. The job reads the two identified milestone events from Unity Cloud Code logs and selected leaderboard records, then writes analytics records to Google Cloud Storage. We use these records to understand gameplay completion and difficulty, improve the Game, and monitor its operation. We do not use Unity Analytics, and we do not use these analytics records for behavioral advertising.
Operational logs and security diagnostics necessary to operate the Game may be processed by the service providers described above. These records may include pseudonymous player or session identifiers and gameplay-event metadata needed to operate, secure, and troubleshoot the Game. We do not intentionally include access tokens, passwords, or raw external account identifiers in project-owned diagnostic logs.
Retention
We retain information only for as long as reasonably necessary to provide the Game, maintain security and continuity, resolve disputes, meet legal obligations, and enforce our agreements. We delete or anonymize information when it is no longer required, subject to legal retention requirements and any provider records that we do not control.
**Game profile, progress, scores, and recovery records.** We retain these records until the player requests deletion or the Game is discontinued, unless a longer period is required to resolve a live dispute or meet a legal obligation.
**Google Cloud analytics exports.** We retain these exports for 12 months from collection, then manually delete them, unless they are needed for a live dispute or legal obligation.
**Operational and security logs.** Project-operated short-lived records are retained according to their function:
- Gameplay-operation records are retained for 24 hours after their latest update.
- Failover incidents are retained for 24 hours.
- Quota records are retained until the quota window ends plus 24 hours, or for 48 hours from writing if that time cannot be read.
- Probe-run diagnostics are retained for 7 days.
- Processed streak-operation records are retained for 45 days.
- Unity Cloud Code logs are currently available for up to 10 days.
- Google Cloud logs in the `_Default` bucket are retained for 30 days. Required Google Cloud audit logs in the `_Required` bucket are retained for 400 days. The current Google Cloud configuration has no additional Log Router export sinks.
**Support communications.** We retain support communications for 24 months after the case is closed or the last contact, then delete them, unless they are needed for a live dispute or legal obligation. Postal letters are scanned for the case record, and the paper original is securely destroyed after processing.
**Backups.** We do not maintain separate application-controlled backups of player data.
Children
The Game is intended for a general audience and is not directed to children under 13. We do not knowingly collect personal information from children in a manner prohibited by applicable law. If we learn that we have collected personal information from a child under 13 in violation of applicable law, we will review and address the information as required. If you believe this has occurred, contact us using the details below.
International transfers
The Game and its service providers may process information in the United States and other countries where we or they operate. Where required, we use legally recognized transfer safeguards. You may contact us using the details below for information about the applicable safeguards.
Your choices and rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, restriction of, or portability of your personal information, and to object to certain processing. You may also have the right to withdraw consent where processing is based on consent, without affecting processing that occurred before withdrawal.
To make a request or ask a privacy question, contact us at `support@buddingtechstudios.com`. We may need to verify a request before acting on it. Depending on where you live, you may also have the right to lodge a complaint with your local data-protection authority and, where required by law, to appeal our decision on a privacy-rights request.
Notice, not a consent gate
We make this Privacy Policy available through a visible, non-blocking "Privacy Policy" link on the Game's main screen. Players are not required to tick a box or affirmatively accept this Policy merely to start the Game.
Where applicable law requires consent for a specific optional processing activity, we will request that consent at the appropriate time before carrying out that activity. This Policy link by itself is a notice and is not a record of consent.
Changes to This Policy
We may update this Policy as the Game or applicable law changes. We will post the updated version at the same privacy policy URL https://www.buddingtechstudios.com/vaultprivacypolicy and update the "Effective date." If a change requires additional notice or consent, we will provide it as required by applicable law.
Contact Us
For questions or privacy requests, contact:
Joseph Pangilinan, Privacy Officer
support@buddingtechstudios.com
Budding Tech Studios Inc
145 Tyee Dr, PMB 58543
Point Roberts, WA 98281