Summary
Kerfline has no account and no sign-up. Installing the app mints a random identity on the developer's server, used to record your deaths and clears, show you the leaderboard, and let you delete everything if you choose to. The app also shows ads from Google AdMob, which collects data of its own. The sections below explain each of these in plain terms.
1. Who I am
Mohammad Nabulsi ("I", "me", or "my") makes Kerfline (the "Game") and runs the server it talks to. Questions go to support@mnabulsi.io.
2. Your player identity
The first time you launch Kerfline, and before you do anything else, the app asks my server for an identity. The server generates a random player key and a random display name, and your device stores both. This happens automatically on first launch, for every install — not only if you post a leaderboard run. Your device presents the player key on every later request so the server knows a report, a rename or a deletion is yours; it is not derived from your device, your name, or anything else about you.
3. What gets sent, and what it's used for
Every time you die, clear a level or leave one part-way through, that attempt is queued and sent to the server tagged with your player key. Each record carries: the level you were on, the outcome (death, clear or left part-way), how many simulation ticks it lasted, and the date and time it started, to the second, as your device's clock reported it. For at most two attempts per level — your best run and the death that got furthest — it also carries a recording of the taps you made and their exact timing. No separate location or usage log is kept alongside it.
That stream of records does two things:
- Powers the completion percentage shown on each level — the share of players who have reached and finished it — computed from everyone's records combined.
- Powers the leaderboard, ranked by fewest deaths. When you clear a level, the tap recording is replayed through the game's own simulation on the server to work out your result — nothing about your rank is taken on trust from your device.
These two are not kept apart, and an earlier draft of this policy said they were. Your player key is attached to every attempt you ever report, whether or not you ever open the leaderboard, so your deaths, your clears and your leaderboard runs all sit against the same identity on the server. If you never open the leaderboard, your gameplay is still recorded under your player key — it just never gets a public display name attached to it.
4. Your display name
When your identity is minted, the server picks a display name for you from its own list. Settings → CHANGE lets you type a name of your own instead, or leave the field empty to have the server pick a different one. The server refuses names that break its rules or its word filter, and names that look like a real person's — a common first name with a surname, a first name with a year, or a phone number. A refused name is not stored. No two players can hold the same name.
Your display name is public. It appears next to your ranking on the global leaderboard, where every other player can see it. Don't use your real name, or anything else that identifies you — whatever you type is shown to strangers, and I can't tell whether a name is someone's real one. Your player key itself is never shown to anyone, never appears on a leaderboard row, and is redacted from device logs.
4.1 Reporting a name
Names typed by players can still read badly despite the filter. If one does, email me with the name and I will review it; a name I remove is replaced on the leaderboard by a generic one. A reported name is recorded with the reason and the day, and never with who reported it.
5. What is not collected
- No account, email or device identifier is asked for or attached to your player key. The only text you can supply is the display name in section 4.
- Your IP address is not recorded by the game's own server. The server does not read forwarded-address headers, does not log requests, and rate-limits by player key rather than by network address — the API host's request logging is switched off entirely for this reason. (This is separate from Google's ad SDK, described in section 7 below, which is outside my control.)
- No age is asked or inferred, for the reasons in section 10.
6. How long data is kept
Right now, attempt records are kept indefinitely — there is no fixed deletion schedule, and I want to say that plainly rather than invent a number. This is a deliberate default rather than an oversight: each reported attempt carries an id that the server uses to avoid double-counting it if your device resends it (for example after being offline for a while), and that protection only works for as long as the record exists. A time-limited deletion window would eventually be shorter than some player's longest offline stretch, and a resend after that point would get counted twice. A firm retention period is on my list to set, once there's a safe way to summarize old records before removing them.
Whatever this policy eventually says about retention, you do not have to wait for it: see section 9 for how to remove everything tied to your identity right now, regardless of how long it's been kept.
7. Advertising
Kerfline shows interstitial ads from Google AdMob. Every so often after you die, the game offers you an optional ad: if you choose to watch, one plays. If you turn down several of those offers in a row, one ad is shown anyway. Dying never waits on an ad — the level restarts instantly either way.
Before any ad is requested, the app asks Google's consent tool (the User Messaging Platform) to determine what consent applies in your region and, where required, shows you Google's consent message. The AdMob SDK is not started until that step has resolved. If you decline personalised advertising, ads still appear, but Google is told not to use your data to choose them. Where your region gives you the right to change that decision, Settings carries a Privacy options row that reopens the same form. The app never tells Google anything about your age.
Google AdMob collects data independently of the game's own server — ad requests go directly from your device to Google, not through Kerfline's backend, and what Google collects and how it's used is governed by Google's own policies, not by this document: see Google's Privacy Policy and Google's disclosure of AdMob's data collection. I have not audited AdMob's own data handling beyond configuring the consent flow described above, and I'm not going to describe what it collects beyond pointing you to Google's own disclosure of it.
On iPhone, Kerfline asks for tracking permission. After the consent step above and before the ad SDK starts, iOS shows Apple's App Tracking Transparency prompt, which asks whether the app may track you across other companies' apps and websites. It is asked once. Declining costs you nothing — the game is identical either way, ads still appear, and they are simply less targeted. There is no prompt on Android, which has no equivalent system permission.
Kerfline also offers optional rewarded video: from the wardrobe, you can choose to watch one to unlock a cosmetic trail or skin. It only ever starts when you tap to request it — nothing plays automatically. Banner ads and app-open ads do not appear anywhere in Kerfline.
If you ever see an ad that seems inappropriate, misleading or malicious, you can report it — see the support page for how.
8. In-app purchases
Kerfline has no in-app purchases. If one is ever added, it will be processed by Apple or Google under Apple's Privacy Policy or Google's Privacy Policy, I will never see your payment details, and this section will say so before it ships.
9. Deleting your data
From Settings → Delete my data (behind a two-tap confirmation, so it can't happen by accident), Kerfline asks the server to erase your player record entirely. This removes your player key, your display name, and every attempt you've ever had recorded against it — deaths, clears and leaderboard runs alike — from every table the server keeps about you; nothing about your identity is left behind for it to reattach to. If you keep playing afterward, a brand-new, unrelated identity is minted the next time the app needs one. Step-by-step instructions are here.
This is not undoable, and there is no way for me to recover it once it's done — that's the point.
10. Children
Kerfline does not ask your age and has no way of knowing it. Deliberately: asking would give me actual knowledge of a player's age, which creates the exact obligation an age gate is usually meant to avoid. There is no chat and no comments. The one place to type is the optional display name (section 4), which is shown publicly on the leaderboard. Kerfline never asks for a real name, and the name field says not to use one. If you are a parent and believe your child has entered their real name or other personal details as a display name, email me and I will remove it, or use Settings → Delete my data to erase the whole record.
11. Changes
If this policy changes materially, the date at the top will change and the updated version will be posted at this URL.
12. Contact
- Developer: Mohammad Nabulsi
- Email: support@mnabulsi.io
That mailbox is read by me and nobody else, and it is not connected to anything inside the game. Writing to it necessarily tells me your email address and whatever you put in the message — that is the one place where Kerfline and an identifiable you meet, and it happens only because you chose to write. I keep the thread for as long as it is useful to answer you, never link it to your player key or to any leaderboard entry, and use it for nothing but replying. Ask me to delete the correspondence and I will.
Deleting your game data does not require emailing me: section 9 does it from inside the app, without you having to identify yourself to me at all.