Lopes Games operates Tactical Protocol, a military strategy card game. This policy describes the current Android app, its account and online services, and its Google Play Billing integration. It does not describe the data practices of other Lopes Games games.
Accounts and game information
Local matches can be played without an account. If you register or use account features, we receive your username, email address, chosen display name and password over an encrypted connection. We store a password hash rather than the original password. We assign an account identifier and retain account status, creation/update times, session identifiers and hashed refresh credentials with expiry and revocation information.
Our backend stores your selected starter faction, card collection and entitlements, saved deck names and compositions, cosmetic unlocks and preferences, virtual-currency balances and ledger entries, and pack-opening history. We use these records to provide and synchronize account features, validate ownership, and prevent duplicate or unauthorized grants. Authentication data is used for account management and security, not advertising.
Online play sends authentication, deck selections and game actions to our authoritative server. Match state, reconnection information and the information needed by each opponent are processed in server memory. The game does not provide player chat or uploads of photos, audio or video. Offline match state and local preferences remain on your device unless used in an online/account feature.
Purchases and Google Play
Optional virtual-currency purchases use Google Play Billing. Google handles the payment interface and payment credentials; Lopes Games does not receive your card number or bank-account details. Our backend receives a product identifier and purchase token and verifies the transaction with Google. We store purchase status, related account, product/package identifiers, quantity, timestamps, order identifier when supplied by Google, delivery/consumption state and related virtual-currency ledger records. Refund/void evidence may also be retained for reconciliation and investigation.
The app sends Google an obfuscated account identifier for purchase binding and fraud prevention. This is derived from the game's account identifier; our integration does not send your game username, email or password to Google. War Bonds are in-game virtual currency with no cash-out, banking, lending or investment function.
The Billing library also sends Google technical billing diagnostics and session/app identifiers, including when connecting, querying products or recovering purchases without making a new purchase. This supports operation, troubleshooting and security of billing services. Google controls its own processing and retention under its Privacy Policy and Google Play Terms. Billing diagnostics are separate from game advertising or behavioral analytics.
Diagnostics, recipients and security
We do not integrate advertising, behavioral analytics or a separate third-party crash-reporting service. Our infrastructure may generate operational or error logs to maintain service reliability and security. Network services necessarily receive connection information such as an IP address; the Tactical Protocol API's routine Nginx access log is disabled, and the game does not derive a location from it. The public website may retain ordinary web-server access/error logs. We do not request location, contacts, camera, microphone, health data or an advertising identifier.
Account and game data go to Lopes Games' hosted backend at api.tacticalprotocol.lopesgames.com. Google receives the billing information described above. Infrastructure providers process information needed to host these services. We do not sell personal data or use it for targeted advertising. Necessary data may be disclosed to comply with a valid legal obligation or protect the service.
The app uses HTTPS and secure WebSockets for backend traffic. On Android, a refresh credential is stored locally using Android Keystore encryption; access credentials are kept in memory. Signing out revokes the current refresh session and removes the stored local credential. Signing out or uninstalling does not delete the server account or its purchase history.
Retention and deletion requests
Account and game records persist while your account is maintained; this version has no automatic account-erasure schedule. Access credentials expire after 15 minutes and refresh credentials after 30 days; expiration does not imply immediate deletion of their server records. Operational logs, backups and Google's records have separate retention lifecycles.
You can request account deletion or deletion of specific data through our deletion request page or by contacting joancefet@gmail.com. Requests are handled manually after ownership verification. We explain any information that must be retained for transaction integrity, fraud prevention, legal obligations or backup rotation, and the applicable retention period when handling your request. There is currently no self-service account deletion button inside the app. We do not claim that signing out deletes your data or that all purchase records can be erased immediately.
Your choices and contact
You can play local matches without registering, avoid optional purchases, update your display name, manage saved decks and sign out. Contact us to request access, correction or deletion of information associated with your account. Do not send passwords, refresh credentials or purchase tokens by email.
Tactical Protocol is not directed at children under 13. If you believe a child has provided account information, contact us so we can review it. Age suitability remains subject to the regional content rating shown by Google Play.
We will update this policy when the game's data practices change and revise the date above. Questions may be sent in English or Portuguese.