Türkçe  ·  Data Deletion  ·  Support

Colorama — Privacy Policy

Last updated: 13 August 2026

This page is an English translation of the Turkish original. If the two versions conflict, the Turkish version prevails.


1. Who and which app

2. Short summary

Colorama is a colour memory game. The whole game — categories, the daily challenge and duels against bots — can be played offline. If you never sign in, nothing is sent to any server.

Once you sign in (the anonymous or game-account sign-in needed for live duels), two things are sent:

  1. Cloud backup: your statistics, daily streak, nickname and country are stored under your own identity so they survive a change of device. Only you can read that record.
  2. Live duel records: the minimum needed to pair two players and run the match.

There is no ad network, no analytics, no crash reporter and no tracking library. The app does not access location, contacts, photos, microphone or camera, and it does not use an advertising ID (GAID/IDFA); it does not request permissions for any of these.

3. Stored on your device

The following is kept in your phone's app storage (AsyncStorage). Uninstalling the app deletes all of it. The backed up column shows whether a copy of that record also lives in the cloud backup once you have signed in (see 4.2).

WhatWhereWhyBacked up
Category stats, duel record, daily stats, top 5 guessescolorama.kayit.v1Your progress on the profile screenyes
Today's daily guesses (colour code + time) and streakcolorama.gunluk.v2Resuming an unfinished daily challengeyes
Nickname and countrycolorama.profil.v1The identity your opponent sees in a live duelyes
Sound, vibration, high contrastcolorama.ayarlar.v1Your preferencesno
Interface languagecolorama.dil.v1Your preferenceno
Session id (uid) and display-name cachecolorama.kimlik.v1Not having to sign in for every live matchno
Session ids of players you blockedcolorama.engellenenler.v1Not being matched again with a player you reportedno
Firebase session tokenFirebase Authentication SDK's own recordKeeping the session across restartsno

About the nickname: you type it yourself. If you enter your real name, your email address or anything else that identifies you, that information will be visible to your opponent in a live duel and written to the match room on the server. A nickname is optional; leave it empty and your opponent sees a neutral label.

4. Sent to the server

Only once you have signed in. The server is Google's Firebase Realtime Database, and the data region is set to europe-west1 (Belgium).

4.1 Identity

A session is opened before a live duel. There are two paths:

4.2 Cloud backup

After you sign in, a copy of your progress is kept under your own identity (oyuncular/<uid>). It contains:

The record is updated with a few seconds' delay as you play, and also when the app goes to the background. Server rules open this branch only to its owner: no other player can read or write it.

Its limit, plainly: with anonymous sign-in the identity is tied to this installation only. Uninstall the app and that identity is gone, together with access to the backup. For the backup to genuinely survive a change of device you need to sign in with a Play Games / Game Center account.

4.3 Matchmaking queue

While looking for an opponent, a temporary record is written to the queue: your session id, the code of the room you created, and a timestamp. The record is deleted when a match is found or the search ends; if your connection drops, the server deletes it automatically.

4.4 Match room

During a match the room holds:

The correct colour of an object is never sent to the server; scores are computed separately on each device. Only the two players in a room can read it.

4.5 Reporting an offensive name

At the end of a match you can report your opponent's name. Doing so writes a single record to the server: the session id of the reported player, the name shown at that moment, and a timestamp. The record does not say who reported it — we do not need that and we do not store it. No player can read these records; they are used only to understand how a name got past the filter, and to fix the filter.

Reporting also blocks that player, and the block list is kept only on your device (see 3). The "Delete my data" flow deletes that list as well; the report record on the server remains, because it does not identify you.

4.6 Firebase's own processing

While providing the service, Firebase processes connection metadata (IP address, connection time) and authentication records (creation and last sign-in time of the identity). This processing is carried out by Google LLC under its own privacy policy and data processing terms:

The app does not use Google Analytics for Firebase, Crashlytics or any similar measurement service; the Firebase project deliberately has no Analytics measurement id configured.

5. Not collected

No data is sold, shared for advertising, or used for marketing.

6. Legal basis

7. Retention

RecordDuration
Everything stored on the deviceUntil you delete it or uninstall the app
Queue recordUntil the search or match ends; at most a few minutes
Cloud backupUntil you delete it
Match roomUntil manually deleted; automatic cleanup is planned
Firebase identityUntil you delete it

8. Your rights

Under GDPR Art. 15–22 and KVKK Art. 11 you have the right to access your data, to have it corrected or erased, to restrict processing, to object to processing, and to data portability. To exercise these rights, write to fetihcagioyun@gmail.com. We respond within 30 days.

9. Deleting your data

9.1 From inside the app

Settings → Data → Delete my data (the same button is also on the Settings → About → Privacy screen). When you confirm:

Deliberately kept: sound, vibration, high contrast and language. These describe how the interface behaves rather than who you are, never leave the device, and are not tied to any identity.

What cannot be deleted from inside the app — stated plainly:

  1. Rooms of matches already played. The app keeps no list of the rooms you played in, and room codes cannot be enumerated from the server. Your nickname, guesses and times may remain in those rooms. To have them removed, write to fetihcagioyun@gmail.com.
  2. The second-player field in a room someone else created. By design this field is written once: after it is set it cannot be changed or removed, because it is the very mechanism that locks the second player slot. What remains is a raw identifier string, and after deletion that identifier no longer belongs to any account.

After your identity is deleted the app keeps working; a new identity is created if you enter a live duel again.

9.2 From outside the app (web)

If you have uninstalled the app or the in-app path does not work for you, use the form at https://ahmetsarica.github.io/colorama-gizlilik/veri-silme.html or write to fetihcagioyun@gmail.com. To process the request we need your session id (uid); you can find it at Settings → Player → Account.

10. Children

Colorama is not directed at children under 13 and does not knowingly collect personal data from children under 13. If we learn that such data has been collected, we delete it and give notice. The app is not part of the Google Play "Families" programme.

11. International transfers

Data is held on Google's infrastructure inside the European Union (europe-west1). Some metadata may be transferred outside the EU as part of Google's operation; Google relies on standard contractual clauses for such transfers (see Google's data processing terms).

12. Security

13. Changes

If this policy changes, the date at the top is updated. For a significant change (for example collecting a new type of data) a notice is also shown in the app.

14. Contact

fetihcagioyun@gmail.com