Privacy Policy
This Privacy Policy explains how Lepton Labs s.r.o. collects, uses, stores, and shares personal data when you use the Blockblock.fun website, iOS and Android apps, guest or registered accounts, profiles, live matches, replays, notifications, and related support, advertising, and marketing-measurement flows.
Who we are and what this policy covers
Blockblock.fun is operated by Lepton Labs s.r.o., located at Nogradiho 335/2B, Biskupice, Slovakia 986 01. This policy applies to the Blockblock.fun web game and mobile apps, guest and registered accounts, player profiles, puzzles and guide progress, friend lobbies, notifications, shared replay and game links, and support communications related to the service.
By using Blockblock.fun, you acknowledge that we process personal data as described here. If local law gives you stronger rights than this policy describes, those rights still apply.
Information you provide or generate
- A pseudonymous guest account, player identifier, display name, and session data when you play without registering.
- Email address and password when you register directly.
- Username, display name, avatar image or Google profile-image URL, and profile edits you choose to submit.
- Match records, moves, outcomes, ratings, wins, losses, replay history, and friend lobby activity.
- Premium plan, status, provider, provider customer/subscription or transaction identifiers, and billing dates. Stripe, Apple, or Google processes payment-method details; we do not store full payment-card details.
- Support or feedback messages you send to us.
Data processed automatically
- IP address, browser and device information, timestamps, and request metadata processed by our servers and infrastructure.
- Authentication tokens and essential browser storage used to keep you signed in.
- Session storage used for pending invites, shared replays, shared live games, and similar in-app flows.
- Local device storage used for guide and puzzle progress, puzzle rating and streaks, onboarding completion, gameplay preferences, native advertising cadence, and a pseudonymous push-installation identifier.
- If notifications are enabled, a push provider token, installation identifier, platform, environment, and registration timestamps used to send and manage notifications through APNs or Firebase Cloud Messaging.
- Essential access cookies when the site is operated behind a private preview gate.
- A first-party privacy-choice record retained for up to six months, plus optional sound and animation preferences only when you allow preference storage.
- If you allow Marketing, Meta Pixel may process the page URL and title, referrer, timestamp, IP address, browser and device details, Meta click identifiers, and the
_fbpand_fbcbrowser identifiers. - When Google ads are enabled for a free account, Google may process advertising identifiers, consent signals, IP address, browser or device details, page and app context, and ad interaction data needed to select, deliver, secure, and measure the permitted ads.
- For native ads, RevenueCat may receive the current pseudonymous Blockblock.fun app-user ID, platform, ad unit and placement, network/mediator, load/display/open/failure events, impression identifiers, and impression-level revenue and currency reported by AdMob.
Google and Apple authentication
If you choose Google or Apple sign-in, we receive identity information needed to create or access your Blockblock.fun account, such as a provider-specific subject identifier, your email address when supplied by the provider, email-verification status, display-name information you choose to share, and a Google profile-image URL when Google supplies one. For Apple sign-in, our server exchanges the one-time authorization code and stores the resulting revocation credential encrypted so it can attempt to revoke Apple access if you delete the account. If automatic revocation cannot be confirmed, deletion still proceeds and we ask you to remove access in your Apple Account settings. The credential is not returned to the website or mobile app.
Limited Google ads and optional Meta Pixel
The production website contains Google AdSense ownership information. Auto ads and account-level ad experiments must remain disabled. On the website, free users may see one display ad below the actions in a finished-game dialog. In the native iOS and Android apps, free users may occasionally see a closable full-screen ad at a completed game or puzzle transition, subject to completion, grace-period, cooldown, and frequency limits. Free users may also voluntarily watch one rewarded ad to unlock Performance Analysis for that selected finished match. We do not place ads during active gameplay or on app open, resume, lobby, profile, or leaderboard screens. Premium users do not receive ad placements or ad-unit requests.
Web advertising is provided through Google AdSense; H5 Games Ads remain disabled until Google approves the site for that product. Native iOS and Android advertising is provided through Google AdMob. Google ad units are not activated until an applicable Google-certified consent flow is published and the app can resolve whether the account is eligible and non-Premium. Before requesting a native ad, the app asks Google UMP for current consent information and proceeds only when UMP reports that ads may be requested. The app does not force a personalized or non-personalized outcome after that decision; Google applies the consent and privacy signals available for the request. The privacy flow lets you reject or later revise applicable advertising choices. Rejecting an optional rewarded ad will not prevent ordinary gameplay.
Blockblock.fun is a general-audience game intended for players aged 13 and older, is not directed to children under 13, and is not submitted to Apple's Kids Category or Google Play's Families programme. Native requests are marked as not child-directed and limited to Google's Teen ad-content rating or lower. Because we do not collect or verify your age, app code does not mark you as under the age of consent without an age signal; the platform SDK's defaults apply. UMP and any applicable platform or regional privacy requirements still control whether and how an ad may be served.
On iOS and Android, RevenueCat Ad Monetization reports lifecycle and impression-level revenue for the post-completion interstitial and Performance Analysis rewarded placements. This reporting is tied to the current app-user ID so subscription and ad value can be measured together. RevenueCat does not serve these ads and does not grant the Performance Analysis reward; our backend verifies that reward through AdMob server-side verification.
Google-provided ad attribution, AdChoices, report, close, and skip controls must remain visible and unobstructed. You can use an ad's own controls or report an inappropriate or age-inappropriate ad to us. Please attach a screenshot and include the approximate date, time, and platform; do not include a password or payment details.
When a Meta Pixel ID is configured and you affirmatively allow Marketing, we load Meta Pixel from connect.facebook.net. We use it to measure selected page visits, understand whether a future Meta ad led to a visit, and create or measure advertising audiences. Our legal basis for this processing is your consent.
We disable Meta’s automatic configuration and currently send only PageView events. Our code does not provide advanced-matching identifiers or intentionally send your email address, username, Blockblock.fun user ID, match IDs, or form values. Before the Pixel is activated, Meta’s account-level Automatic Advanced Matching setting must be disabled and verified in Events Manager. URLs containing account tokens, private game/invite identifiers, billing session IDs, unsupported query parameters, or public-profile usernames are excluded from PageView tracking.
Meta may use the _fbp and _fbc cookies for advertising and site measurement for up to 90 days. You can withdraw Marketing permission at any time through . We then stop future Pixel events, ask Meta’s Pixel to revoke consent, and remove accessible Meta browser cookies from our domain where possible. Withdrawal does not undo processing that occurred while your consent was valid.
Why we process personal data
- To create and manage accounts, authenticate users, and keep the service secure.
- To run matchmaking, live games, replays, profiles, ratings, and review features.
- To send transactional emails such as verification and password-reset messages.
- To investigate abuse, bugs, fraud, and service instability.
- To respond to support requests and improve product quality.
- With the required choices, to deliver, secure, and measure the two permitted free-account ad experiences.
- With your consent, to measure selected visits and future Meta advertising performance.
Depending on the situation, our legal bases include performance of our contract with you, our legitimate interests in operating and securing the service, your consent where required, and compliance with legal obligations.
What other players may see
Blockblock.fun is a social multiplayer game. Your username, display name, avatar, rating, wins, losses, member-since date, and some gameplay information may be visible to other players through profiles, match history, leaderboards, live games, and replays.
If you share a friend invite, replay link, or live-game link, anyone you send that link to may be able to use it to access the shared experience, subject to the app’s access controls at that time.
How we store and protect data
We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or disclosure. No system can be guaranteed perfectly secure, but we work to reduce risk and limit access.
Uploaded avatars are stored on our servers. Authentication data and gameplay records are retained for as long as reasonably needed to operate the service, maintain match history, handle disputes, comply with law, and enforce our rules.
When account deletion completes, we remove login and contact credentials, user-linked push registrations, checkout attempts, and most billing and ad-reward associations stored with the account. Managed avatar files, Stripe customer records, and RevenueCat subscriber records are placed into a restricted deletion queue and retried if a storage or provider service is temporarily unavailable. Pseudonymized match records, ratings, minimal deletion timestamps, and detached AdMob callback-validation or audit entries may remain where needed to preserve match history, prevent duplicate rewards or abuse, resolve disputes, or comply with law.
Privacy choices are retained for up to six months. If you allow Marketing, Meta lists the _fbp and _fbc identifiers used by its business tools with a lifespan of up to 90 days. Google controls the retention of information processed by its advertising services as described in its own policies and the choices presented through the certified consent flow.
Access, correction, and deletion
- You can update your username, display name, and avatar from your profile settings.
- You can request access to, correction of, or deletion of your personal data by contacting us.
- You can stop using optional OAuth providers and can manage those relationships through your Google or Apple account settings.
- You can independently change or withdraw optional Preferences and Marketing permission at any time through .
- You can ask us to close or delete your account, subject to any data we must retain for legal, security, or fraud-prevention reasons.
Age limits
Blockblock.fun is a general-audience game intended for people aged 13 and older. It is not directed to children under 13, and we do not knowingly collect personal data from children under 13. We do not use a date-of-birth or age-verification screen. If you believe a child has provided personal data to us, contact us so we can investigate and delete it where appropriate.
Cross-border processing
Because Blockblock.fun may be accessed internationally and some service providers operate in more than one country, your data may be processed outside your home jurisdiction. Where required, we rely on contractual, legal, or other recognised safeguards for those transfers.
When you use billing or allow optional advertising or Marketing processing, Google, Apple, Stripe, RevenueCat, and Meta may process relevant data in countries where they or their service providers operate. See their privacy policies for descriptions of international processing and safeguards.
Questions, requests, and complaints
Nogradiho 335/2B, Biskupice, Slovakia 986 01
If you believe we have handled your data improperly, please contact us first so we can try to resolve the issue. You may also contact your local data protection authority where applicable.
