Privacy Policy
This policy is written for the Brazilian General Data Protection Law (LGPD, Law 13.709/2018), because that is the law that governs Uppercut Studio. It also tells visitors from the EU and the UK honestly where they stand. It describes what KATAPULT actually stores today — not what a generic template would say.
The short version. To play you create an account with Google or with an email and password. We store your player id, the email or Google identity behind it, the fact that you accepted the Terms and when, your match state, and your win/loss counters. Our servers, hosting and database are Google Firebase — Google processes this data for us. We show only our own house ads: no third-party ad script, no tracking cookie, and no analytics product runs on KATAPULT today. We do not sell data. You can ask us to delete everything at katapult@uppercut.studio.
1. Who is the controller
The controlador (controller) of the personal data described here is Uppercut Studio, the operator of KATAPULT at katapult.cards.
Contact for every privacy matter, including the requests in section 10: katapult@uppercut.studio.
2. Who this policy covers
It covers people who visit katapult.cards (this site) and people who play KATAPULT at katapult-play.web.app (later play.katapult.cards), together the “Service”. KATAPULT is a private alpha; the data practices here are the alpha's, and they will change as the product does.
This site — the landing page you are on, plus these legal pages — is static. It sets no cookie, runs no script of ours, and has no login. The only external request it makes is for the web fonts described in section 5.
3. What we collect
3.1 Your identity
An account is required to play; there is no anonymous play. Accounts are held in Firebase Authentication, which assigns each one a random user id (UID) and keeps the creation and last sign-in timestamps.
- Google sign-in. Google returns to Firebase your Google account identifier and the email address on that account, and may return the display name and profile picture you have set. We use the email to know who the account belongs to and to be able to answer you; we do not send you marketing.
- Email and password. Firebase Authentication stores your email address and a salted hash of your password, and handles password resets by email. Uppercut Studio never sees or stores your password.
We also record, on our own server and not in your browser, which version of the Terms and Privacy Policy you accepted and when. That record is what lets us prove — to you as much as to anyone else — what you actually agreed to, and it is checked on every gameplay request.
3.2 Your player profile
One document per player, readable only by that player: the player id, matches played, wins, losses, current streak, daily-return streak, the date of the last daily reward, the sign-in method behind the account, the accepted-terms record described above, any unlocked art sets, and the creation timestamp.
3.3 Match data
Room and seat membership; a one-way hash of an invite secret (never the secret itself); the authoritative state of a match; each player's own redacted view of it; the accepted commands of a match and the ordered timeline they produce; round, phase and outcome; and, while you are waiting for a quick match, a matchmaking queue entry keyed to your player id.
3.4 Technical and gameplay telemetry
Server-side operational records produced by Google Cloud Logging and Monitoring: which command was called, whether it was accepted or rejected and the reason code, latency, errors, reconnects, and the build, protocol, rules and content versions involved. These are what tell us a match broke. By design our logs exclude authentication tokens, invite secrets and hidden hands.
3.5 Device and browser data
Data your browser sends or that the page reads to lay itself out: browser and version, operating system, device type, screen size and pixel density, language, referrer, and whether you added the game to your home screen. We do not fingerprint your device and we do not collect precise location.
3.6 IP address and request logs
Firebase Hosting and Cloud Functions record each request — including your IP address, timestamp, requested path, response status and user agent — in Google Cloud Logging. This is how the platform works; it is also what lets us investigate abuse and comply with a lawful order.
3.7 What we do not collect
- No payment data. Nothing is for sale in the alpha and we never ask for card details.
- No analytics product. There is no Google Analytics, no
gtag, no product-analytics SDK and no session-replay tool in the client today. - No third-party advertising script today (see section 9).
- No precise location, no contacts, no microphone or camera, no biometric data, and none of the sensitive-data categories of LGPD art. 5, II.
4. Why, and on what legal basis
Each purpose has a legal basis under LGPD art. 7. For readers under the GDPR, the equivalent Art. 6 basis is in the last column.
| What | Why | LGPD basis | GDPR equivalent |
|---|---|---|---|
| Player id, profile, match and room data | To give you the game you asked for: to seat you in a match, keep it consistent, let you reconnect, and show your own progress. | Art. 7, V — performance of a contract and preliminary steps at the data subject's request | Art. 6(1)(b) |
| Your sign-in identity: Google account id and email, or your email address and the password hash Firebase keeps | Because an account is required to play: to know that a seat is yours, to keep your progress on any device, to reset a password, and to identify you if you write to us. | Art. 7, V — performance of a contract | Art. 6(1)(b) |
| The version of the Terms and Privacy Policy you accepted, and when | To know that you agreed before playing, to show you what you agreed to, and to be able to prove it if it is ever disputed. | Art. 7, V (and art. 16, I — retention to comply with a legal obligation and to defend a right) | Art. 6(1)(b) / 6(1)(c) |
| Telemetry, error and latency records | To find and fix defects, protect the alpha's stability, and keep the game fair. | Art. 7, IX — legitimate interest | Art. 6(1)(f) |
| IP address and request logs | Security, abuse and cheating investigation, and legally required access records. | Art. 7, IX (legitimate interest) and art. 7, II (legal obligation) | Art. 6(1)(f) / 6(1)(c) |
| Feedback you send us | To answer you and improve the game. | Art. 7, IX — legitimate interest | Art. 6(1)(f) |
| Third-party personalised advertising | Not used today. If it is ever switched on, it will be on consent, asked for before the ad script loads. | Art. 7, I — consent | Art. 6(1)(a) |
Where we rely on legitimate interest, we have weighed it against your rights: the data involved is operational, it is not used to profile you or to advertise to you, and you can object at katapult@uppercut.studio (LGPD art. 18, §2).
5. Cookies, local storage and the offline cache
KATAPULT sets no advertising and no analytics cookie. What it does put in your browser is listed here exactly, because a vague answer would be worthless:
| Where | Name | What it holds | Why |
|---|---|---|---|
| IndexedDB (Firebase Authentication) | firebaseLocalStorageDb |
Your Firebase sign-in session and its refresh token. | Keeps you signed in as the same player between visits. Strictly necessary for the game to work. |
| localStorage | katapult:match |
The id of your unfinished match and room, and when it was saved. | Lets a refresh, a phone call or a closed tab return you to the match you were in. |
| localStorage | katapult.ads.notice.v1 |
A timestamp, written only if you dismiss the advertising notice. | So the notice is not shown again. Written only if third-party ads are enabled, which today they are not. |
| localStorage | katapult:terms |
The version identifier of the Terms you accepted. | A local mirror of the acceptance recorded on our server, so you can still practise offline without the game inventing an agreement you never made. The server record, not this copy, is what counts. |
| localStorage | katapult:audio |
Your sound settings: muted, music on or off, volume. | So the game sounds the way you left it. Never leaves your device. |
| Service worker cache | k-shell-6 |
A copy of the app's own files: HTML, CSS, scripts, icons. | Makes the game start fast and tolerate a bad connection. It caches the app shell only — identity and match state are never cached, and requests to Firebase are never intercepted. |
Web fonts. Our design system loads the Cinzel, EB Garamond and Inter typefaces from Google Fonts
(fonts.googleapis.com and fonts.gstatic.com). That request necessarily discloses your IP
address and user agent to Google, on this site as well as in the game. It sets no cookie.
How to remove all of it. Clearing site data for the KATAPULT domain in your browser settings deletes the storage, the cache and the session in one step, and signs you out. Your account and its data stay on our servers until you ask us to delete them (section 10).
6. Who else touches the data
Google is our operador (processor): Firebase Authentication, Cloud Firestore, Cloud Functions, Firebase Hosting, Cloud Logging and Cloud Monitoring. Google processes the data on our instructions, under its data processing terms, to run the Service. If you sign in with Google, Google is also an independent controller of your Google account itself under its own privacy policy. Google Fonts is described in section 5.
We may also disclose data:
- to a competent authority or court, where we are legally required to (including under the Marco Civil da Internet and the Code of Criminal Procedure);
- to defend our rights in a legal proceeding;
- to a successor, if the KATAPULT project is transferred — in which case this policy, or one at least as protective, continues to apply, and we will announce it before the transfer takes effect.
We do not sell personal data, we do not share it with data brokers, and we do not use it for cross-context behavioural advertising.
7. Where the data is, and international transfer
KATAPULT's data lives in a Google Cloud / Firebase project operated by Uppercut Studio, in a namespace dedicated to
KATAPULT and separate from the studio's other data. Our server logic (Cloud Functions) runs in Google's
São Paulo region, southamerica-east1, so gameplay commands are processed in
Brazil.
Some Google services are global by nature. Firebase Authentication and Google's logging and operational infrastructure may process your data on servers outside Brazil, including in the United States. That is an international transfer under LGPD art. 33, and it relies on the safeguards in Google's data processing terms, including standard contractual clauses, together with the necessity of the transfer for performing the contract with you (art. 33, II and VI). If you have questions about a specific transfer, write to us.
8. How long we keep it
| Data | Retention |
|---|---|
| Account and player profile | While your account exists. Deleted on request, and deleted if we end the alpha. |
| Record of the Terms version you accepted | While your account exists, and afterwards only for as long as a claim about the agreement could still be made. |
| Match state, views and timelines | Kept while they are useful to the alpha, and may be reset or deleted at any time during it (Terms, section 8). |
| Rooms, invitations and reconnect data | Short-lived by design, removed automatically after they expire. |
| Matchmaking queue entry | Deleted when you are matched or cancel. |
| Telemetry and request logs (including IP) | Google's configured Cloud Logging retention. See the note below. |
| Emails you send us | While needed to deal with your request, and afterwards only where a law requires or a right must be defended. |
We may keep data for longer where a law requires it, or where it is necessary to exercise or defend a right in a proceeding (LGPD art. 16). Data that is no longer necessary is deleted or anonymised.
9. Advertising
The game has advertising slots. Today they carry only our own house advertising for KATAPULT and its Deck Art Sets. Concretely, that means: no third-party ad script is loaded, no advertising cookie is set, no identifier is shared with an ad network, and nothing that happens in your matches is used to choose what you see. The creative is ours and it cannot track anyone.
We may enable third-party advertising (for example Google AdSense) later. If we do:
- this policy will be updated with a new version date before or at the time it goes live;
- ads will be requested non-personalised by default;
- a plain notice will appear in the client, linking here;
- if personalised advertising is ever offered to visitors in the EEA or the UK, it will require a certified consent management platform asking for opt-in before the ad script loads. We will not switch that on quietly.
10. Your rights, and how to use them
Under LGPD art. 18 you may ask us at any time for:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or out-of-date data;
- anonymisation, blocking or deletion of data that is unnecessary or excessive, or processed unlawfully;
- portability to another provider, on express request and subject to trade and industrial secrecy;
- deletion of data processed with your consent, except where a law lets us keep it (art. 16);
- information about the public and private entities we share data with;
- information about your option not to consent, and the consequences of refusing;
- revocation of consent;
- to object to processing carried out on a basis other than consent, where it does not comply with the law (art. 18, §2);
- to petition the ANPD, the Brazilian National Data Protection Authority, or a consumer protection body.
How. Email katapult@uppercut.studio with “LGPD” in the subject and tell us what you want. It is free.
What we will ask you for. We must be sure we are answering the right person. Write from the email address on your account — the one you signed up with, or the one on the Google account you use. If you cannot, include the player id the game shows you. We ask for the minimum needed to identify you and nothing else.
How fast. We answer promptly, and in any case within 15 days of a request for access or for a full declaration (LGPD art. 19, II). If we cannot do what you ask — for example, because we cannot confirm that the account is yours, or a law requires us to keep something — we will tell you why, and what you can do next.
Deleting your account. Ask us and we will delete your Firebase Authentication account, your player profile and your match views, and disassociate what must be retained. Records we are legally required to keep, and aggregate or anonymised data that can no longer be linked to you, may remain.
11. Visitors from the EU and the UK
KATAPULT is operated from Brazil and is not directed at the European Economic Area or the United Kingdom: we do not advertise there, we do not offer prices in euros or pounds, and the alpha is invitation-based. The GDPR may nonetheless apply to you if you use the Service from there.
If it does, we will honour the equivalent rights — access, rectification, erasure, restriction, portability, objection, and the right to complain to your supervisory authority (GDPR arts. 15–22 and 77) — through the same channel in section 10. The legal bases are mapped in the table in section 4, and transfers outside the EEA rely on Google's standard contractual clauses. We have not appointed an Article 27 representative in the EU or the UK; if the Service is ever directed at those markets, we will appoint one and say so here.
12. Children and adolescents
The Service is for people 18 or older (Terms, section 4), and the game asks you to confirm that in the same box in which you accept the Terms, before an account is created. We do not verify age documents, and we do not want to collect them. We do not knowingly collect personal data from children or adolescents, and the alpha is not designed for them. Under LGPD art. 14, data of a child under 12 may be processed only with specific and highlighted consent from at least one parent or legal guardian — we do not operate such a consent flow, which is precisely why the Service is not open to them.
If you are a parent or guardian and believe we hold data about a child or adolescent, write to katapult@uppercut.studio and we will delete it and close the account.
13. Security and incidents
Measures in place today (LGPD art. 46):
- all traffic is served over HTTPS;
- the browser cannot write match state: every rule runs on the server inside a transaction, and the database rules deny client writes outright;
- each player can read only their own redacted view and their own profile; an opponent's hidden plan and the authoritative state are unreadable from any client;
- invitations are stored as a one-way hash, never as the secret in the link;
- server credentials live in the managed runtime, never in the client or the repository, and logs are written so as to exclude tokens, invite secrets and hidden hands.
No system is perfectly secure. If a security incident occurs that may create relevant risk or damage to you, we will notify you and the ANPD within a reasonable period, as LGPD art. 48 requires.
14. Automated decisions
Matchmaking, the deterministic rules engine and the anti-abuse limits are automated. They decide who you play against and whether a command is accepted — they do not profile you and they do not produce legal or similarly significant effects on you. If an automated decision affects your account, you may ask us to review it (LGPD art. 20) at katapult@uppercut.studio.
15. Changes to this policy
When this policy changes we update the version number and effective date at the top of the page. For a change that materially affects how we use your data — enabling third-party advertising, for example — we will give notice inside the Service before it takes effect, and, where the law requires consent, we will ask for it rather than assume it. This is version 2026-09-03, effective 3 September 2026.
16. Contact
Uppercut Studio, controller — katapult@uppercut.studio. Write in Portuguese or English; both are answered.