← Echo Crawler

Privacy Policy

Effective date: May 26, 2026 · Last updated: May 26, 2026

1. Who We Are

Echo Crawler is a mobile game published by wmkc, based in Israel. This privacy policy applies to the Echo Crawler mobile application on Android (Google Play) and iOS (Apple App Store), and to the website at echo-crawler.wmkc.net.

Data controller: wmkc
Contact: privacy@wmkc.net
Website: wmkc.net

2. Data We Collect

Echo Crawler stores game data locally on your device. When you sign in with Google and enable cloud save, your data is also stored on Firebase servers. Additional data is collected by Firebase Analytics (when consented) and Crashlytics to help improve the game.

A. Data Stored Locally on Your Device

All game data is stored on your device using AES-256 encrypted local files. This data never leaves your device unless you explicitly opt into cloud save.

CategoryExamplesPurpose
Game progressDungeon level, endless mode best score, completed regionsTrack player progression
Stats & achievement countersEnemies defeated, ads watched, currencies earned/spent, abilities picked, runs completedAchievement tracking and player stats
Currencies & balancesGold, Gems, Souls, Essence, AshIn-game economy
Equipment & inventoryOwned gear, equipped items, upgrade levelsGameplay
Settings & preferencesAudio volume, haptics, languageUser preferences
Purchase historyProduct ID, price, timestampPurchase verification
Daily reward timestampsLast claim date per reward typePrevent duplicate claims
Lucky Draw stateBoard layout, cards drawn, draw countsDaily Lucky Draw feature
Chest guarantee countersOpens since last guaranteed rarity dropGuarantee system (pity timer)
Ad bypass stateRemove Ads flag, Skip Ads token balance, temporary ad-free expiryAd bypass features
Consent preferencePersonalized ads consent choiceGDPR compliance
Region detectionCountry code derived from device localeGeo-restriction compliance

wmkc cannot access, view, or retrieve any locally stored data. It exists only on your device. Uninstalling the app or clearing app data permanently deletes it.

B. Data Managed by Third-Party Services

ServiceDataWhenUser Control
Firebase AuthenticationGoogle account identifier (UID, email)When you sign in with GoogleSign out via Settings → Cloud Save; delete cloud data via Settings → Cloud Save → Delete Cloud Data
Firebase Cloud FirestoreCloud save data (progress, currencies, equipment, settings)When you sign in and cloud save is activeDelete via Settings → Cloud Save → Delete Cloud Data, or contact privacy@wmkc.net
Firebase AnalyticsApp usage events (session duration, run outcomes, purchases), device model, OS version, countryOnly when you have granted consentWithdraw consent via the analytics toggle in Settings → Privacy; data retained per Google's retention policy
Firebase CrashlyticsCrash logs, stack traces, device state, OS version, app version, anonymized user IDWhen the app crashes and crash reporting is enabledDisabled if first-launch consent is declined; independently toggle via crash reporting in Settings → Privacy; user ID cleared on sign-out
Firebase Cloud MessagingDevice push token (stored in Firestore under your account)When push notifications are enabled and you are signed inDisable notifications in device settings; token deleted when cloud data is deleted
Google AdMobAd interaction data, device advertising ID, IP addressWhen rewarded ads are shownReset or delete advertising ID in device settings; in-app consent controls personalization
Google Play / Apple App StorePurchase transaction recordsWhen you make an in-app purchaseManaged by Google/Apple

C. Data We Do Not Collect

Echo Crawler does not collect: names, contact lists, precise location data, photos, camera or microphone data, health or fitness data, browsing history, user-generated content, or financial information (all payments are processed by Google Play / Apple). Your Google account email is only accessed when you explicitly sign in for cloud save and is used solely for authentication purposes.

D. Website

This website (echo-crawler.wmkc.net) does not use cookies, tracking pixels, analytics services, or any other tracking technologies. No data is collected from visitors to this website.

3. How We Use Data

DataPurposeLegal Basis (GDPR)
Local game dataCore gameplay functionalityContractual necessity (Art. 6(1)(b))
Cloud save dataBack up and restore progress across devicesConsent (user opts in)
Analytics dataUnderstand app usage, improve features, monitor performanceConsent (first-launch prompt + Settings toggle)
Crash reportsIdentify and fix bugs and stability issuesConsent (first-launch prompt + Settings toggle)
Push notification tokensSend game updates and event notificationsConsent (user opts in via device settings)
Ad interaction dataServe rewarded video ads; personalize if consentedLegitimate interest / Consent
Purchase recordsFulfill purchases, handle refunds, prevent fraudContractual necessity / Legal obligation
Consent preferenceRemember ad personalization choiceLegal obligation (GDPR)
Region detectionEnforce geo-based monetization restrictionsLegal obligation

4. Third-Party Services

ServicePurposePrivacy Policy
Firebase AuthenticationUser identity for cloud savefirebase.google.com/support/privacy
Firebase Cloud FirestoreCloud save storagefirebase.google.com/support/privacy
Firebase AnalyticsApp usage analyticsfirebase.google.com/support/privacy
Firebase CrashlyticsCrash reportingfirebase.google.com/support/privacy
Firebase Cloud MessagingPush notificationsfirebase.google.com/support/privacy
Google AdMobOpt-in rewarded video adspolicies.google.com/privacy
Google Play BillingIn-app purchases (Android)policies.google.com/privacy
Apple StoreKitIn-app purchases (iOS)apple.com/legal/privacy

AdMob may use the following data for ad serving: device advertising identifier, IP address, device type, operating system version, and app interaction data. When you have not consented to personalized ads (or are in the EEA/UK and have denied consent), only non-personalized ads are served.

Firebase Analytics is consent-gated: event collection is only active when you have granted consent via the first-launch prompt or the analytics toggle in Settings → Privacy. When consent is denied or withdrawn, analytics collection is fully disabled — no events are logged or transmitted.

Firebase Crashlytics is also disabled if you decline the first-launch consent prompt. You can independently re-enable or disable crash reporting at any time via the crash reporting toggle in Settings → Privacy.

Note: Firebase services (Analytics, Crashlytics, Cloud Messaging, Auth, Firestore) are currently available on Android. On iOS, these features will be enabled in a future update. This policy will apply to both platforms once available.

5. Advertising & Consent

All ads in Echo Crawler are opt-in rewarded video ads. The game never shows interstitial, banner, or forced ads. You always choose whether to watch an ad in exchange for an in-game reward.

On first launch, all users are shown a consent prompt for usage data and crash report collection. Your consent choice controls whether Firebase Analytics and Crashlytics are enabled. You can change each independently at any time via the toggles in Settings → Privacy.

For ad personalization, users in the EEA/UK will be shown a separate consent prompt (via Google's User Messaging Platform) before personalized ads are served. When personalized ads are not consented to, only non-personalized ads are shown.

The "Remove Ads" in-app purchase permanently removes all ad prompts and automatically grants all ad-gated rewards without showing ads.

6. Children's Privacy

Echo Crawler is not directed at children under 16. The game contains paid randomized items (loot boxes), which under PEGI guidelines requires a minimum rating of PEGI 16. wmkc does not knowingly collect personal information from children under 16.

If a parent or guardian believes their child has provided personal information through a third-party service used by the game, they should contact the relevant platform (Google or Apple) directly.

7. Data Retention

8. Your Rights

EEA, UK, and Israel

Under the GDPR and Israeli Privacy Protection Law (as amended by Amendment 13, effective August 14, 2025), you have the right to:

To request a copy of your data, email privacy@wmkc.net with your Player ID (found in Settings → Cloud Save). Please send the request from the email address associated with your account so we can verify your identity. We need your Player ID to locate your data on our servers.

For data stored on Firebase servers (cloud save), you can exercise these rights directly via the Delete Cloud Data option in Settings → Cloud Save, or by contacting privacy@wmkc.net. See the Data & Account Deletion page for instructions.

California (CCPA/CPRA)

Under the California Consumer Privacy Act, you have the right to know what personal information is collected, delete your personal information, and opt out of the sale or sharing of your personal information.

wmkc does not sell or share personal information as defined by the CCPA. Ad personalization is consent-based and can be controlled via the in-game consent prompt or device advertising settings.

9. Data Security

In the event of a data breach affecting your personal data, wmkc will notify affected users and relevant authorities within the timeframes required by applicable law, including 72 hours under Israel's Privacy Protection Law (Amendment 13).

10. International Data Transfers

Firebase services (Authentication, Firestore, Analytics, Crashlytics, Cloud Messaging) and Google AdMob may process data on Google servers located outside your country of residence, including the United States. Google maintains appropriate safeguards for such transfers (Standard Contractual Clauses, adequacy decisions). For details, see Firebase's privacy documentation.

11. Changes to This Policy

wmkc may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. For significant changes, a notice may be provided within the game. Continued use of the game after changes constitutes acceptance of the updated policy.

12. Contact

For privacy-related inquiries or to exercise your data rights:

If you are in the EEA and believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority. In Israel, complaints can be filed with the Privacy Protection Authority (PPA).