Blind Sector — Evacuation Protocol
Privacy Policy
This policy describes what the app actually does today, not what it might do later. Where a claim depends on someone else's system, it says so.
Developer and data controller
Goethe47 develops Blind Sector and is the controller responsible for choosing and configuring the advertising services the app uses. Unity Technologies processes advertising data under its own terms and may act as a separate controller or as a service provider depending on the activity and the applicable law. Contact: burteloffluther@gmail.com.
What the game is
Blind Sector is a free single-player arcade game in which you fly an evacuation craft through five districts of a fictional city. There are no in-app purchases, no subscriptions and no virtual currency. It is supported by advertising, described below.
No account, no game server
Blind Sector has no account, no login and no registration. There is no server-side player profile, no leaderboard and no cloud save. Because there is no Blind Sector account, there is no account-deletion URL — see "Deletion and local storage" for what deletion means here.
The game itself is fully playable offline. Internet access is used only by the advertising libraries and by the engine diagnostics described below; the game's own code sends nothing anywhere.
Data stored locally on your device
The following lives in the app's own storage on your device. Goethe47 operates no server, so Blind Sector does not send this data to us and we hold no copy of it. Android itself may still include it in a platform backup or a device transfer — see "Deletion and local storage" below:
- Progress for each of the five sectors — best route percentage, most survivors rescued, number of attempts, whether the sector was cleared, and on which attempt.
- Your settings — language, master audio, music, sound effects, vibration and strong-effects toggles.
- Whether you have seen the opening comic.
- Your privacy age band — only which of three bands your answer fell into (under 13, 13–17, 18 or older). The exact age you set on the slider is not among the things stored here.
- Your language choice, asked once on first launch.
- Your advertising choices — personalized or non-personalized ads, and the sale/share restriction, for adults who were offered that choice.
- Ad-pacing bookkeeping, held in memory for the current session only, so full-screen ads are not shown too often. It is not written to disk.
Advertising actually included in the build
Blind Sector shows ads through exactly two components, both verified present in the shipped package: Unity LevelPlay (Unity's mediation SDK, com.unity3d.ads-mediation:mediation-sdk) running the Unity Ads network through its adapter (unityads-adapter plus com.unity3d.ads:unity-ads). No other advertising network's SDK or adapter is included.
Ads appear in three forms:
- a banner along the bottom edge, on menus and during play alike. It never covers the game: the view is lifted above it, and a press inside the banner strip does not steer the craft, so holding your thumb there neither flies the ship nor taps the ad. It is absent during the opening comic and on the privacy screens themselves;
- an occasional full-screen ad between attempts, shown only after you press Retry or Levels on the result card, never in the middle of a run and never automatically when you lose;
- a rewarded video you choose to watch, offered at most once per attempt after a loss, in exchange for resuming from the last evacuation platform. It never starts on its own, and the continue is granted only if the ad reports that it was actually watched. Declining costs nothing; Retry, Levels and Main Menu all work without it.
Unity's dashboard can change which ad instances are used without an app update. That is not the same as adding a network: a genuinely new advertising network requires its adapter to be added to the build, which means a new app version and an update to this policy and to the Play Console Data safety declaration before it ships.
Gameplay analytics: none
Blind Sector does not use Unity Analytics or any other gameplay-analytics service. Unity Analytics, Unity Performance Reporting and Unity IAP are switched off in this build's project configuration. Nothing about how you play — your scores, attempts, routes or session lengths — is transmitted anywhere. That data exists only on your own device, as listed above.
Crash reporting is a separate thing and it is not fully off. Unity Cloud Diagnostics, which is an optional Unity service, is switched off. Unity's built-in developer data diagnostics is not, and it can still collect crash logs and other technical data about the app. Do not read "Cloud Diagnostics is off" as "no crash data is collected" — the next section describes what is collected.
Crash logs and engine diagnostics (cannot be switched off in-game)
Blind Sector is built with the Unity engine, and Unity's own developer data diagnostics are enabled in this build. Separately from everything above, Unity may receive crash logs, app diagnostics, other app performance data, technical information about the app and the device running it — for example the engine and app version, the operating system version and the device model — and device or other identifiers. This is used to operate and improve the engine and to find faults.
This is collected by the engine itself, not by Blind Sector's code, and there is no in-game switch that controls it. It contains no name, email address, contact, photo, file, message or location more precise than what Unity derives itself, and it is not used to select which advertisements you see. How Unity handles it is described in Unity's Player and App User Privacy Policy.
Whether a given build actually transmits this data is determined by Unity's implementation rather than by Blind Sector. It is disclosed here on the assumption that it does.
Age band and advertising choices
Before Blind Sector initializes the advertising SDK or requests a single advertisement, it asks your age on a plain local slider. Nothing is preselected: until you move it there is no value at all, and the screen cannot be dismissed without one. The number you choose exists only in that screen's temporary state — it is never saved, logged or sent anywhere — and only the band it falls into is stored. Blind Sector never asks for a date of birth.
If you select under 13: the COPPA child flag is set for all supported ad networks, advertising consent is set to denied, and the sale/share restriction is enabled. You are not asked anything further and you cannot enable personalized ads.
If you select 13–17: advertising consent is set to denied and the sale/share restriction is enabled, so you receive non-personalized advertising only. You are not asked anything further. The COPPA child flag is not set, because that flag is defined for under-13 users.
If you select 18 or older: you are then asked two separate questions, each with a real choice and no dark pattern: whether you accept personalized advertising, and whether you want to restrict the sale or sharing of your personal data. Neither answer is preselected in your favour or ours.
These are product settings expressed through the ad SDK's privacy flags. Treating everyone under 18 conservatively is a deliberate choice; it is not a claim that every user under 18 is legally a child under COPPA, nor that this arrangement satisfies every jurisdiction's rules.
You can change all of it later at any time in Settings → Ads and data. Every recheck starts with nothing selected, and changing your band clears any earlier adult personalization choice, so an adult must choose again rather than inherit an old answer. Changes take effect the next time the app starts, because the ad SDK's privacy flags are applied before initialization.
US state privacy choices
Adults can turn the "Do not sell or share my personal data" setting on or off in Settings → Ads and data. An absent saved value is never treated as an opt-in: the permissive value is sent only after you have explicitly left the option off yourself. For everyone under 18 the restriction is enabled automatically and cannot be disabled. Blind Sector does not detect your country or state.
Purposes of processing
Ad delivery and measurement; ad personalization, but only if you are an adult and chose it; frequency capping so full-screen ads are not repeated too often; fraud prevention and security for the advertising system; and, separately, engine diagnostics for operating and improving Unity. Blind Sector's own code performs no profiling and sends nothing to Goethe47: we run no server and keep no player database. Unity may make aggregated advertising reporting — impressions, revenue and similar figures — available to us through its dashboard.
Legal bases, where applicable
What the app actually collects is this: the advertising SDK is not initialized and no ad is requested until the age screen is answered. An adult is then asked, separately and with nothing preselected, whether they accept personalized advertising and whether they want the sale or sharing of their data restricted. A user under 18 is not asked and receives non-personalized advertising with the sale/share restriction on.
The limits of that, stated plainly. Blind Sector does not detect your country or region and does not currently run a consent management platform. In the EEA and the UK, storing or accessing information on a device for advertising purposes — including the technical delivery and measurement of an ad, not only its personalization — generally requires prior consent under Article 5(3) of the ePrivacy Directive and the UK ICO's guidance. Non-personalized advertising is not automatically exempt from that requirement. The screens described above are not presented as satisfying it for every user in every country, and a consent management platform is being integrated so that consent can be requested where local law requires it.
Where consent is validly given, it is the basis relied on. Limited processing needed for ad delivery, measurement, security and fraud prevention may rest on another basis available to Unity, subject to applicable law. This policy does not claim final legal compliance in every jurisdiction, and jurisdiction-specific review remains necessary.
Google Play Data safety
Three components in this build contribute to these categories: the Unity Ads network, the LevelPlay mediation SDK and Unity's developer data diagnostics. Blind Sector's own code adds nothing, because it transmits nothing. Google requires this section and the Play Console declaration to agree; where they ever disagree, the Console declaration for the shipped version is the one to trust, and this page is corrected to match.
- Approximate location — advertising or marketing; analytics; app functionality; fraud prevention, security and compliance.
- Personal identifiers / user IDs — app functionality. These are Unity SDK identifiers, not a Blind Sector account.
- Purchase history — advertising or marketing; analytics. Declared because Unity's own Unity Ads disclosure declares it; Blind Sector having no purchases does not override the embedded SDK's declaration.
- App interactions — page views and taps inside the ad experience.
- Other actions — interactions with advertisements beyond simple views and taps, as reported by the advertising SDKs.
- Crash logs — from Unity's developer data diagnostics. App functionality; analytics.
- App diagnostics — from the advertising SDKs and from developer data diagnostics.
- Other app performance data — from developer data diagnostics.
- Device or other identifiers — advertising or marketing; analytics; app functionality; fraud prevention, security and compliance.
One value must be checked against the live dashboard: Unity states that app usage time is collected only when Acquire Optimization is enabled in the Monetization dashboard. Its Yes/No must match that setting before the Play Console declaration is submitted.
Not applicable according to Unity's table: precise location, contacts, messages, photos, files and calendar.
Android permissions
Blind Sector's own code requests exactly one permission — vibration, used for the short buzz when the craft is hit, and switchable off in Settings. Vibration carries no data and reads nothing from the device. The game's code does not use the camera, microphone, contacts, files or device location.
The advertising libraries add internet access, network-state access, the advertising identifier permission (com.google.android.gms.permission.AD_ID) and a small number of supporting Android system permissions that those libraries need to function. They support the ad SDK's operation and are not by themselves evidence of a data category beyond those listed above.
Data recipients
Blind Sector integrates only Unity LevelPlay and the Unity Ads network directly; no other advertising network's SDK or adapter is present in the build. Unity also receives data through its engine diagnostics.
That is a statement about what this app contains, not a promise about what Unity does afterwards. Unity may pass data to its own service providers, advertising partners, demand sources and other recipients as described in Unity's policy, and advertising inventory may be sold to demand sources that Blind Sector neither chooses nor sees. Goethe47 has no visibility into and no control over those onward transfers beyond what Unity discloses.
To exercise a right over data held in Unity's systems, contact Unity using the details in their policy, or write to Goethe47 at the address above and we will help route the request. Goethe47 chose and configured the advertising SDK in this app and does not disclaim responsibility for that choice merely because we run no server of our own.
International transfers
Unity's advertising and diagnostics infrastructure may process data outside your own country. The safeguards applied to those transfers are described in Unity's own policy; Goethe47 does not operate that infrastructure and cannot describe it beyond what Unity discloses.
Retention
Data processed by Unity is retained under Unity's own schedule, not one Goethe47 sets. Data on your device is kept until you clear the app's storage, uninstall the app, or change the setting yourself.
Deletion and local storage
Uninstalling Blind Sector or clearing its storage removes the app's own local copy of everything listed above, including your progress and your privacy choices. Because there is no account and no server, there is no separate account-deletion step.
Android backup is at the platform default for this build: Blind Sector does not currently set android:allowBackup="false", so Android may independently include the app's local data in a cloud backup or a device-to-device transfer under the platform's own rules. Such a backup is created and controlled by Android and your device settings, not by Blind Sector, and it may survive uninstalling the app. To remove it, use the backup controls of your Google account or your device. The data involved is the progress and settings listed above; it contains no account credentials.
Children
Blind Sector is not directed to children. Its Google Play target audience is 13 and older, children are not among the selected age groups, and it is not enrolled in the Designed for Families programme. The under-13 band exists so that a child who reaches the game anyway is treated conservatively — COPPA flag set for every supported ad network, advertising consent denied, sale and sharing restricted — rather than being ignored.
Why this section is detailed. The age screen means Blind Sector can end up with actual knowledge that a particular user is under 13. COPPA applies on that basis to a general-audience service, not only to a service directed at children, so the handling of that band is set out here in full rather than left implied.
Advertising is not switched off for that band, and profiling is. A user marked as under 13 still sees advertisements, but only contextual ones — chosen from the app they are in rather than from anything about them. Before the SDK starts, Blind Sector marks the user as child-directed and opts out of the advertising identifier, so the Android advertising ID is not read for them and no persistent identifier is shared with third-party bidders.
Persistent identifiers for a user in that band. Identifiers that remain available, principally the IP address, may be used for support for the internal operations of the service and for nothing else. Those permitted uses are: delivering an advertisement chosen from the context rather than from the user, limiting how often the same advertisement is shown, maintaining and analysing the functioning of the app and the advertising system, protecting the security and integrity of that system, detecting and preventing fraud, and complying with legal obligations.
In that mode the identifier is not used to build a profile of the user, to select advertising from their behaviour or interests, or to contact them. The measure preventing other uses is the COPPA flag itself, which Blind Sector sets before the SDK is initialized and which instructs every supported ad network to operate in its child-directed mode; Blind Sector requests no personalized advertising for that band under any circumstances, and the setting cannot be changed by the user without going through the age screen again. Enforcement of the restriction inside Unity's own systems is Unity's, described in Unity's policy.
Your rights
Depending on where you live you may have rights to access, correct, delete or object to processing of your data, and in the United States to opt out of sale, sharing or targeted advertising. Where processing rests on your consent, you can withdraw it at any time in Settings → Ads and data; withdrawal does not affect processing that already took place. You may also have rights to restrict processing, to obtain a portable copy, and to complain to your local data protection authority. For data Goethe47 holds directly there is nothing to produce — it is all on your own device. For data in Unity's systems, use the routing described above.
Security
Local data is protected by standard Android app sandboxing. No method of electronic storage or transmission is completely secure, and that applies to our advertising partner's systems as much as to anyone else's.
Changes to this policy
This policy will be updated when the app or its advertising configuration changes, including before any new advertising network is added. Material changes appear here with a new "Last updated" date.