Brawlit Privacy Policy
Effective date: 2026-08-30 · 한국어
Information we collect
Brawlit has no user accounts and does not ask for or persist a person's real name, email address, password, or advertising ID. Public in-game names and public profile or battle fields returned by the Supercell API may be processed transiently for API response-contract validation or held in short-lived response caches. They are not persisted in the discovery tag-pool database or sent to Firebase. Public Brawl Stars game tags are processed as described below.
- Game tags — recent player/club searches and favorites are stored on your device and are excluded from Android backup. To retrieve public game data, a searched tag is sent through our proxy to the Supercell API. If you save a tag as My Profile or a favorite, its public tag is also sent to the Ranked-history tracker described below.
- Battle archive — battle logs for My profile and favorited accounts are accumulated
on your device only for statistics (e.g. team synergy), and can be deleted anytime in
Settings. If you explicitly choose a Files/Drive folder, the app can also save portable,
unencrypted
.brawlstatsbackups there. These backups are handled by your selected document provider and are never uploaded to Brawlit servers. - Local histories and caches — trophy history, locally derived profile history, cached public game data, and an on-device copy of Ranked history are stored on your device. They are not uploaded as an account backup by Brawlit.
- Ranked history — for My Profile and favorites, our server stores the public game tag, Ranked season, rank, Elo score, and latest completed Ranked-battle timestamp to calculate future per-match score changes. Raw player and battle-log responses used for each check are processed transiently and are not stored in this history.
- Notifications — favorite alerts are generated locally on your device; no push server is used.
- Diagnostics and anonymous usage statistics — in release builds configured for Firebase, Share anonymous usage data (Settings → Privacy) is on by default and can be turned off at any time. While it is on, the app sends bounded events to Google Firebase covering screen/navigation categories; search and profile-load attempts and outcomes; tracking, favorites, alerts, notification, review-flow and optional-feature use; coarse performance bands; refresh and API/server-error categories; and crash diagnostics. Player tags, nicknames, club tags, and search terms are never sent to Firebase. Player or club names, notification content, and other free-form user text are also never sent. Analytics event names and values are restricted to fixed lists defined in the app's source. Crash reports can include a stack trace, device model, OS and app version, the category of screen that was open, and bounded diagnostic keys. The app also records closed installation-evidence categories: Firebase Test Lab or external traffic, Play/other-store/local/unknown installer, organic/campaign/other/unavailable install referrer, number of distinct foreground days as a coarse return signal, and closed Play Integrity verdicts. Raw install referrer text and Integrity tokens are never sent to Firebase. Firebase assigns a resettable app-instance identifier for these services; no advertising ID is collected or requested, and the app does not hold the Android advertising-ID permission. Turning the setting off stops future Analytics and Crashlytics collection from the app.
Server processing
Game-data requests pass through our proxy server (Cloudflare Workers) to the official Supercell API. Request URLs (containing game tags) may appear briefly in standard server logs, but are never linked to your identity, stored separately, or sold. Public game-data responses may be cached temporarily at the Cloudflare edge for reliability and performance, and expire automatically.
To identify the current Ranked map pool and calculate aggregate brawler-use and map-pick statistics, an automated collector temporarily keeps public player tags found in leaderboard and Ranked battle data in a short-lived collection queue with bounded retry delays. These tags are not linked to app users or profiles, and the published aggregate statistics contain no player tags.
For random exploration and related player results, a separate automated discovery service keeps a pool of canonical public player and club tags observed through public leaderboard, player, club, and battle data. It stores only the tag, entity type, bounded source category, verification/retry state, and operational timestamps. Public in-game names, profile fields, and raw battle logs may be read transiently for response validation and candidate extraction, but are not stored in this database; neither are device identifiers or links to app users. Unverified candidate-queue entries become ineligible when they are 30 days old and a scheduled, bounded cleanup then physically removes them from the active database. API-evidenced observed and profile-confirmed public tags may be retained only while the discovery service operates. They are removed from the active database when the API confirms that they are invalid, when an accepted deletion-and-suppression request is applied, or when the service is retired. These tags support random exploration and related player results in the app.
Exact future Ranked history is collected only for a tag saved as My Profile or a favorite. The app renews a 24-hour observation lease while that saved tag remains active. The stored fields are limited to the public tag, Ranked season/rank/Elo, completed-battle timestamp, observation time, and whether the interval was exact or contained a gap. The history is isolated by tag, is not linked to a real name, email, device identifier, or Firebase identifier, and is automatically deleted 30 days after the last lease renewal.
The proxy can send separate operational incident and recovery signals to Firebase Analytics. These server-generated signals describe only a fixed component, reason, severity, duration and occurrence count. They are marked as server telemetry, are not generated by or attributed to an app user, and contain no game tag, player or club name, search text, or app-instance identifier.
For a Play-installed app, the app can send an opaque, short-lived Play Integrity token and random request hash to the proxy. The proxy forwards the token to Google's Play Integrity API for decoding, does not log or persist the token, and returns only closed app-recognition, licensing and device-integrity categories. These verdicts establish installation environment, not a person's identity.
Third-party services
- Supercell Brawl Stars API — game data
- RoyaleAPI Proxy — official API relay
- Cloudflare Workers and SQLite-backed Durable Objects — proxy processing, Ranked-history storage, and isolated discovery tag-pool storage
- Brawlify CDN — game images
- Your chosen Android document provider (such as Files or Drive) — only when you enable portable battle-archive backup
- Google Firebase (Crashlytics and Analytics) — app crash diagnostics and bounded anonymous usage statistics while the Settings toggle is enabled, plus separate server-generated operational health signals that are not attributed to an app user
- Google Play (Install Referrer and Play Integrity) — coarse install attribution and verification of the distributed app, Play license and device environment while anonymous usage sharing is enabled
The app contains no ads. Diagnostics and usage statistics are limited to the anonymous events described above and can be switched off in Settings.
Data deletion
Recent searches and the battle archive can be deleted from the app's Settings screen, and favorites can be removed from the favorites feature. To remove every other app-local history, cache, and setting, clear Brawlit storage in Android system settings or uninstall the app — no email request is needed.
Portable backup files remain in the folder you selected until you delete them with that document provider. Brawlit cannot access or delete those files after folder permission is removed.
Removing a favorite or My Profile tag stops future Ranked-history lease renewal. Its server history is automatically deleted within 30 days after the last renewal; no separate deletion request is needed.
To request deletion and future suppression of a public player or club tag from the discovery pool, email pulsemediakr@gmail.com with the public tag and whether it is a player or club tag. Do not send a real name or identity document. After the request is accepted, the raw tag and its discovery rows are deleted from the active database; only a one-way keyed suppression value is kept to prevent the tag from being collected again.
Deletion from the active database stops the tag from being collected or served by this feature. Cloudflare's SQLite-backed Durable Objects support point-in-time recovery of the entire database for up to the preceding 30 days, so a deleted row may remain technically recoverable only within that provider recovery history until the window passes. It is not used by the active service. If a recovery is performed, the suppression ledger is replayed and verified before collection resumes so suppressed tags are deleted again and remain blocked.
To stop diagnostics and usage statistics, turn off Share anonymous usage data in Settings → Privacy. Future app collection stops immediately. Clearing app storage or uninstalling also removes the local app-instance state, but does not recall reports already sent. Those reports are retained and deleted under the Firebase retention settings and Google's service deletion lifecycle. Because Brawlit sends neither an email address nor a game tag with these reports and has no user account that maps to the resettable Firebase app-instance identifier, we cannot reliably locate or selectively delete one person's already-sent anonymous Firebase records from an email request.
Contact
pulsemediakr@gmail.com
Brawlit 개인정보처리방침
시행일: 2026-08-30
수집하는 정보
Brawlit은 회원가입 기능이 없으며 이용자의 실명·이메일 주소·비밀번호·광고 식별자를 요청하거나 저장하지 않습니다. Supercell API가 반환하는 공개 게임 내 이름과 공개 프로필·전투 필드는 API 응답 형식 검증을 위해 일시적으로 처리되거나 짧은 응답 캐시에 보관될 수 있습니다. 이 정보는 탐색용 태그 풀 데이터베이스에 저장하거나 Firebase로 전송하지 않습니다. 브롤스타즈의 공개 게임 태그는 아래와 같이 처리합니다.
- 게임 태그 — 최근 검색한 플레이어/클럽 태그와 즐겨찾기는 기기에 저장되며 Android 백업 대상에서도 제외됩니다. 공개 게임 데이터를 조회할 때 검색 태그는 저희 프록시를 거쳐 Supercell API로 전달됩니다. 태그를 내 프로필 또는 즐겨찾기로 저장하면 그 공개 태그는 아래의 경쟁전 기록 수집기에도 전송됩니다.
- 전투 기록 아카이브 — 내 프로필과 즐겨찾기 계정의 전투 기록은 통계(팀 시너지 등) 계산을
위해 기기에만 누적 저장되며, 설정에서 언제든 삭제할 수 있습니다. 이용자가 Files/Drive
폴더를 직접 선택하면 휴대 가능한 비암호화
.brawlstats백업을 해당 폴더에 저장할 수 있습니다. 이 파일은 선택한 문서 제공자가 처리하며 Brawlit 서버에는 업로드되지 않습니다. - 기기 내 기록 및 캐시 — 트로피 기록, 기기에서 계산한 프로필 기록, 캐시된 공개 게임 데이터, 경쟁전 기록의 기기 내 사본은 기기에 저장됩니다. Brawlit은 이를 계정 백업으로 업로드하지 않습니다.
- 경쟁전 기록 — 내 프로필과 즐겨찾기의 향후 경기별 점수 변동을 계산하기 위해 서버에 공개 게임 태그, 경쟁전 시즌·랭크·Elo 점수와 가장 최근 완료된 경쟁전의 시각을 저장합니다. 각 확인에 사용한 원본 플레이어·전투 기록 응답은 일시적으로 처리하며 이 기록에는 저장하지 않습니다.
- 알림 — 즐겨찾기 알림은 기기에서 생성되는 로컬 알림이며 푸시 서버를 사용하지 않습니다.
- 오류 진단 및 익명 사용 통계 — Firebase가 구성된 릴리스 빌드에서 설정 → 개인정보의 익명 사용 데이터 보내기는 기본으로 켜져 있으며 언제든 끌 수 있습니다. 켜져 있는 동안 앱은 Google Firebase로 제한된 이벤트를 전송합니다. 범위는 화면·탐색 분류, 검색·프로필 로딩 시도와 결과, 추적·즐겨찾기·알림·알림함·리뷰 흐름·부가 기능 사용, 대략적인 성능 구간, 새로고침·API·서버 오류 분류, 충돌 진단입니다. 플레이어 태그, 플레이어·클럽 이름, 클럽 태그, 검색 원문, 알림 내용 및 기타 자유 형식 텍스트는 Firebase로 전송하지 않습니다. Analytics 이벤트의 이름과 값은 앱 소스에 미리 정의된 목록으로 제한됩니다. 오류 보고에는 스택 트레이스, 기기 모델, OS·앱 버전, 열려 있던 화면의 분류, 제한된 진단 키가 포함될 수 있습니다. 앱은 Firebase Test Lab/외부 트래픽, Play/기타 스토어/로컬/불명 설치 출처, 자연/캠페인/기타/확인 불가 리퍼러, 앱을 포그라운드에서 연 서로 다른 날의 수, Play Integrity의 제한된 판정 분류도 전송할 수 있습니다. 원본 설치 리퍼러와 Integrity 토큰은 Firebase로 전송하지 않습니다. Firebase는 이 서비스를 위해 재설정 가능한 앱 인스턴스 식별자를 부여합니다. 광고 식별자는 수집하지도 요청하지도 않으며, 앱은 Android 광고 ID 권한을 보유하지 않습니다. 설정을 끄면 앱에서의 향후 Analytics·Crashlytics 수집이 중단됩니다.
서버 처리
게임 데이터 조회 요청은 저희 프록시 서버(Cloudflare Workers)를 거쳐 Supercell 공식 API로 전달됩니다. 이 과정에서 요청 URL(게임 태그 포함)이 표준 서버 로그에 짧은 기간 남을 수 있으나, 이용자 식별 정보와 연결하거나 별도로 저장·판매하지 않습니다. 공개 게임 데이터 응답은 안정성과 성능을 위해 Cloudflare 엣지에 일시적으로 캐시될 수 있으며 자동으로 만료됩니다.
현재 경쟁전 맵 풀을 확인하고 경쟁전의 브롤러 사용·맵 선택 통계를 집계하기 위해, 자동 수집기는 순위표와 경쟁전 기록에 공개된 플레이어 태그를 짧은 수집 대기열에 보관하고, 제한된 간격으로 다시 조회합니다. 이 태그는 앱 사용자나 프로필과 연결하지 않으며, 공개되는 집계 통계에는 플레이어 태그가 포함되지 않습니다.
무작위 탐색과 연관 플레이어 검색을 위해 별도로 격리된 자동 수집 서비스가 공개 순위표·플레이어·클럽· 전투 데이터에서 관측된 플레이어와 클럽의 정규화된 공개 태그 풀을 보관합니다. 저장 항목은 공개 태그, 대상 종류, 제한된 출처 분류, 검증·재시도 상태와 운영 시각뿐입니다. 공개 게임 내 이름·프로필 필드·원본 전투 기록은 응답 검증과 후보 추출을 위해 일시적으로 읽을 수 있지만 이 데이터베이스에는 저장하지 않으며, 기기 식별자나 앱 사용자와의 연결 정보도 저장하지 않습니다. 검증되지 않은 후보 대기열 항목은 생성 후 30일이 되면 수집 대상에서 제외되고, 예약된 범위 제한 정리 작업이 활성 데이터베이스에서 실제로 삭제합니다. API 자료에서 관측되었거나 프로필 확인을 마친 공개 태그는 탐색 서비스가 운영되는 동안에만 보관할 수 있습니다. API에서 유효하지 않다고 확인되거나, 승인된 삭제·재수집 차단 요청이 적용되거나, 서비스를 종료하면 활성 데이터베이스에서 삭제합니다. 이 태그는 앱의 무작위 탐색과 연관 플레이어 검색 결과에 사용됩니다.
정확한 향후 경쟁전 기록은 내 프로필 또는 즐겨찾기로 저장한 태그에 대해서만 수집합니다. 저장된 태그가 활성 상태인 동안 앱이 24시간 관측 기간을 갱신합니다. 서버 저장 항목은 공개 태그, 경쟁전 시즌·랭크·Elo, 완료된 경기 시각, 관측 시각, 그리고 해당 구간이 정확한지 또는 관측 공백이 있는지로 제한됩니다. 이 기록은 태그별로 분리되며 실명, 이메일, 기기 식별자 또는 Firebase 식별자와 연결하지 않습니다. 마지막 관측 기간 갱신 후 30일이 지나면 자동으로 삭제됩니다.
프록시는 Firebase Analytics에 별도의 운영 장애·복구 신호를 보낼 수 있습니다. 이 서버 생성 신호는 미리 정해진 구성 요소, 사유, 심각도, 지속 시간, 발생 횟수만 담습니다. 서버 계측으로 표시되며, 특정 앱 사용자가 발생시킨 신호로 귀속하지 않습니다. 게임 태그, 플레이어·클럽 이름, 검색 원문, 앱 인스턴스 식별자는 포함하지 않습니다.
Google Play로 설치된 앱에서는 짧게 유효한 Play Integrity 토큰과 무작위 요청 해시를 프록시에 전송할 수 있습니다. 프록시는 Google Play Integrity API에서 토큰을 해독하고, 토큰을 로그나 저장소에 남기지 않으며, 앱 인식·Play 라이선스·기기 무결성의 제한된 분류만 앱으로 반환합니다. 이 판정은 설치 환경만 확인하며 사람의 신원을 확인하지 않습니다.
제3자 서비스
- Supercell Brawl Stars API — 게임 데이터 제공
- RoyaleAPI Proxy — 공식 API 중계
- Cloudflare Workers 및 SQLite 기반 Durable Objects — 프록시 처리, 경쟁전 기록 저장 및 격리된 탐색용 태그 풀 저장
- Brawlify CDN — 게임 이미지 제공
- 이용자가 선택한 Android 문서 제공자(Files, Drive 등) — 휴대용 전적 백업을 켠 경우에만 사용
- Google Firebase(Crashlytics·Analytics) — 설정의 토글이 켜져 있는 동안 앱 오류 진단과 제한된 익명 사용 통계를 처리하고, 특정 앱 사용자에게 귀속되지 않는 별도의 서버 운영 상태 신호를 처리
- Google Play(Install Referrer·Play Integrity) — 익명 사용 데이터 전송이 켜져 있는 동안 대략적인 설치 유입 분류와 배포 앱·Play 라이선스·기기 환경 검증
앱에는 광고가 없습니다. 오류 진단과 사용 통계는 위에 설명한 익명 이벤트로 한정되며 설정에서 끌 수 있습니다.
데이터 삭제
최근 검색과 전투 기록 아카이브는 앱 설정에서 삭제할 수 있고, 즐겨찾기는 즐겨찾기 기능에서 해제할 수 있습니다. 그 밖의 모든 앱 내부 기록·캐시·설정을 삭제하려면 Android 시스템 설정에서 Brawlit의 저장공간을 삭제하거나 앱을 제거하면 되며, 이메일 요청은 필요하지 않습니다.
휴대용 백업 파일은 이용자가 선택한 폴더에서 직접 삭제할 때까지 남습니다. 폴더 권한을 해제한 뒤에는 Brawlit이 해당 파일에 접근하거나 삭제할 수 없습니다.
즐겨찾기를 해제하거나 내 프로필 태그를 제거하면 경쟁전 기록의 관측 기간을 더 이상 갱신하지 않습니다. 서버 기록은 마지막 갱신 후 30일 이내에 별도 요청 없이 자동 삭제됩니다.
탐색용 태그 풀에서 공개 플레이어 또는 클럽 태그를 삭제하고 향후 재수집도 차단하려면, 공개 태그와 플레이어/클럽 구분을 적어 pulsemediakr@gmail.com으로 문의해 주세요. 실명이나 신분증은 보내지 마세요. 요청이 승인되면 원본 태그와 관련 탐색 행을 활성 데이터베이스에서 삭제하고, 재수집 방지에만 쓰이는 단방향 키 기반 차단값만 보관합니다.
활성 데이터베이스에서 삭제하면 이 기능의 수집과 제공에 해당 태그를 더 이상 사용하지 않습니다. Cloudflare의 SQLite 기반 Durable Objects는 전체 데이터베이스를 이전 최대 30일 시점으로 복구할 수 있으므로, 삭제된 행은 그 기간이 지날 때까지 제공자의 복구 기록 안에서만 기술적으로 복구 가능할 수 있습니다. 활성 서비스에서는 사용하지 않습니다. 실제 복구를 수행한 경우에는 수집을 재개하기 전에 재수집 차단 원장을 다시 적용하고 검증하여, 차단된 태그를 다시 삭제하고 계속 수집되지 않게 합니다.
오류 진단과 사용 통계를 중단하려면 설정 → 개인정보에서 익명 사용 데이터 보내기를 끄면 됩니다. 앱에서의 향후 수집은 즉시 중단됩니다. 앱 저장공간을 삭제하거나 앱을 제거하면 기기의 앱 인스턴스 상태도 삭제되지만, 이미 전송된 보고를 회수하지는 않습니다. 해당 보고는 설정된 Firebase 보관 정책과 Google 서비스의 삭제 절차에 따라 보관·삭제됩니다. Brawlit은 이 보고와 함께 이메일 주소나 게임 태그를 보내지 않고, 재설정 가능한 Firebase 앱 인스턴스 식별자와 이용자를 연결하는 계정을 보유하지 않습니다. 따라서 이메일 문의만으로 특정 개인의 이미 전송된 익명 Firebase 기록을 신뢰성 있게 찾아 선별 삭제할 수는 없습니다.
문의
pulsemediakr@gmail.com
This material is unofficial and is not endorsed by Supercell. For more information see Supercell's Fan Content Policy.