Privacy Policy: Plate Atlas
Effective date: 31 August 2026
Applies to: the Android app Plate Atlas
(com.lelobyte.plateatlas)
Developer / contact: Altug Ataalp —
ataalpaltug92@gmail.com
The short version
Plate Atlas has no accounts, no login, no chat, and no server of its own. The developer runs no backend, receives no personal data, and keeps no profile of you.
Two Google services do run inside the app, and they are the only things in it that reach the internet:
- Google AdMob, which serves the banner and the occasional full-screen ad;
- Google Analytics for Firebase, which counts how the app is used — how often a match is started, how it ended, which screens are opened.
Both are described in full below. In the EEA, the UK and Switzerland the app asks for your consent before either one stores anything on your device or uses any identifier, and you can change that answer at any time in Settings → Ad privacy settings.
Everything else — your name, your settings, your progress — stays on your own device and is gone when you uninstall the app.
What the app keeps on your device
A small preferences file in the app’s private storage (Android DataStore),
which no other app can read. It holds:
- Your player name and your list of bot opponent names, as typed in Settings.
- Game settings — language, sound, vibration, animation speed, theme, table appearance and the optional house rules.
- Your progress — level, total EXP, wins, win streak, prestige, unlocked achievements and daily challenge progress.
- Your consent answer, recorded by Google’s consent SDK.
That is the whole of it. There is no address book access, no photo access, no location, and no record of what you do beyond the progress above.
Ads
Ads are served by Google AdMob. The app shows:
- a banner at the bottom of the menu, setup, settings, help, progress, lobby and results screens — never while adding a plate;
- an occasional full-screen ad between matches: never the first one of a session, and at most one every few minutes.
To fill an ad slot, the AdMob SDK sends Google what an ad request is made of: your device’s advertising ID, its IP address, the app and its version, and technical details such as device model, operating system version, language, screen size, and the coarse (city-level) location derived from the IP address. Google acts as an independent controller of that data; what it does with it is governed by its own policies:
- Google’s advertising privacy terms: policies.google.com/technologies/partner-sites
- Google’s ad technology providers: support.google.com/admob/answer/6128543
Ads are capped at Google’s “T” (teen) content rating or lower.
The developer never sees this data, receives no report identifying you, and cannot connect an ad request to a player.
Analytics
Usage measurement is Google Analytics for Firebase, in the developer’s Firebase project. It records:
- automatic events — first open, session start, app updates, and time spent in the app;
- screen views, named by screen (menu, setup, table, results, settings, and so on);
- two custom events —
match_start(mode: single player, remote host or remote guest; number of players; the difficulty of the hardest bot) andmatch_end(the same, plus how many rounds were played and whether you finished first).
Alongside those, the SDK sends a randomly generated app instance identifier, the device model and operating system, the app version, the language, and the coarse (country/region) location derived from the IP address.
None of it contains your name, the names you gave your bots, the plates you entered, or anything else typed into the app. Nothing identifies you personally. It is used only in aggregate — to see which features are used and where players stop playing — and it is not sold or shared with anyone beyond Google, which processes it on the developer’s behalf. The project’s data-retention setting is the shortest Google offers — 2 months, after which the event data expires and is gone.
The app instance identifier is not permanent, and you control it: Settings → Reset analytics ID throws it away and starts a new one that cannot be joined to the old. See Your rights, below.
Your consent, and how to change it
Where the GDPR or UK GDPR applies, the app shows Google’s certified consent message on first launch and requests no ad and stores no analytics identifier until you have answered it. Until then all four consent categories — analytics storage, ad storage, ad user data and ad personalisation — start denied. That is the app’s declared default, not something you have to switch off.
- If you consent, ads may be personalised and analytics may store its identifier on your device.
- If you refuse, the app works in full and still shows ads, but non-personalised ones: a request is still sent, because that is how any ad arrives at all, but it is not selected from a profile of you, and analytics keeps no identifier.
You can reopen the choice at any time in Settings → Ad privacy settings, which appears wherever a consent form exists for your region.
Independently of the app, Android lets you reset or delete the advertising ID itself, in Settings → Privacy → Ads. That stops personalised ads on the device for every app, not just this one.
What else leaves your device
Local multiplayer. A two-player match over Bluetooth or Wi-Fi uses Google Play services’ Nearby Connections to talk directly to the other player’s device in the same room. What crosses that link is the player name you chose and the moves of the game in progress — to that one device and nowhere else. There is no relay server, no matchmaking service, and no copy kept by the developer. Nearby Connections is a part of Google Play services running on your device, and Google’s privacy policy governs that service.
Android backup. The app allows Android’s standard backup
(allowBackup="true"). If device backup is switched on in your Android settings, your
settings and progress — including the player name you entered — may be included in the
backup your device makes to your own Google account. That backup is yours and is governed by
Google’s privacy policy; the developer has no access to it, and you can turn device backup
off in Android’s settings.
Nothing else leaves the device, and no data about you is sold to anyone.
Permissions and why they exist
| Permission | Why the app asks | When |
|---|---|---|
INTERNET, ACCESS_NETWORK_STATE |
Request ads and the consent form, and send analytics events | Always |
com.google.android.gms.permission.AD_ID |
Read the device’s advertising ID for the ad request. Added by the AdMob SDK; the ID can be reset or deleted in Android’s settings | Always |
BLUETOOTH_SCAN, BLUETOOTH_ADVERTISE,
BLUETOOTH_CONNECT |
Find and connect to the other player’s device for a local match | Android 12+, requested when you start a two-player match |
BLUETOOTH, BLUETOOTH_ADMIN |
The same, on older Android versions | Android 11 and below (maxSdkVersion="30") |
NEARBY_WIFI_DEVICES |
Use Wi-Fi Direct as the faster transport for a local match | Android 13+ |
ACCESS_WIFI_STATE, CHANGE_WIFI_STATE |
Bring up the direct Wi-Fi link between the two devices | Local multiplayer |
ACCESS_COARSE_LOCATION, ACCESS_FINE_LOCATION |
Older Android versions required a location permission before an app was allowed to scan for nearby Bluetooth devices | Android 12 and below (maxSdkVersion="32") |
VIBRATE |
Haptic feedback when a match connects and during play | Always |
About the location permissions: they are a legacy requirement of older Android
versions for Bluetooth scanning. The app never requests your position, never reads GPS, and never
stores or transmits a location. On Android 13 and newer they are not part of the app at all, and
the scanning permissions it does use are declared neverForLocation.
Children
The app is not directed at children, and neither the developer nor the app builds a profile of anyone. It does carry ads and usage analytics, both of which involve the identifiers described above, and its ads are capped at Google’s “T” content rating. If a child uses this app, ad personalisation can be limited further from the device’s own Google settings and from the family controls on the Google account.
Purchases
There is one, and it is optional: Remove ads, a one-time purchase that turns off the banner and the between-match ads permanently. There are no subscriptions and nothing else is for sale.
The purchase is sold and processed by Google Play. Payment happens inside Play, not inside this app: the developer never receives, sees or stores your card details, billing address or name — only Play’s record that the purchase exists. Whether you own it is kept on your device and re-checked with Play at each launch, which is also how it comes back after a reinstall or on a second device signed in to the same Google account.
Buying it stops all ad requests, and with them everything described under Ads above. The analytics described in this policy is unaffected and stays under the same consent.
Your rights (GDPR, KVKK, and similar laws)
The developer holds nothing about you, so there is nothing on the developer’s side to access, correct, export or erase. For the data Google receives as ad and analytics provider, those rights are exercised through Google, under the policies linked above.
What you can do directly:
- Change your consent: Settings → Ad privacy settings, at any time. Withdrawing it stops personalised ads and analytics storage from that moment on.
- Reset the advertising ID: Android Settings → Privacy → Ads.
- Erase everything local: uninstall the app, or use Android’s Settings → Apps → Plate Atlas → Storage → Clear data. Either removes all settings, names and progress permanently.
- Stop the backup copy: turn off device backup in Android’s settings, or delete the app’s backup from your Google account.
- Cut the analytics data loose from you: Settings → Reset analytics ID. This deletes the analytics data held on the device and issues a new app instance identifier, so everything recorded from that moment belongs to a fresh identity that cannot be joined to the previous one. Statistics already uploaded stay in the Firebase project until they expire under its retention setting (see Analytics, above), but nothing links them to you or to your new identifier any more.
A note on requesting erasure by email. What Firebase holds carries no name, no email address and no account — only that random identifier. The developer therefore cannot look you up, cannot tell which rows are yours, and would have to collect more data about you to try. Where a controller cannot identify the data subject, the GDPR does not require them to acquire further data purely to service a request (Art. 11), and the reset above is offered instead: it is immediate, it needs nothing from the developer, and it does not ask you to hand over an email address to exercise a privacy right. Write to the address below with any question about this, of course.
Questions and requests: ataalpaltug92@gmail.com. Residents of the EU/EEA and of Türkiye may also lodge a complaint with their national data protection authority (in Türkiye, the KVKK — Kişisel Verileri Koruma Kurumu).
Changes to this policy
A revised version is published at the same address with a new effective date and, where the change concerns how data is handled, noted in the app’s release notes. This version is published before the first release carrying ads and analytics ships, and the Play Store listing’s Data safety declaration is updated to match it.
Contact
Altug Ataalp
ataalpaltug92@gmail.com