Monster Defender Privacy Policy
Vitaliteers | Updated October 8, 2026
This policy explains how Vitaliteers handles information in Monster Defender for Android, including beta and internal test builds. Features and their availability may differ between builds. For privacy questions or requests, contact informationsystemsmgmt@gmail.com.
1. Progress and settings on your device
Monster Defender stores game progress, currencies, souls, heroes, equipment, cards, rune layouts, upgrades, reward and purchase-fulfillment records, story progress, language preferences and other settings on your device. The game also keeps recovery copies and limited diagnostic records. These records help save your progress, deliver features and investigate problems. Clearing Android app storage removes local data; Android backup and restoration settings may affect whether copies return.
2. Optional Google Play Games cloud saves
When you connect cloud saves, the game uses your Google Play Games player identifier to associate a progression backup with your account. The backup can contain currencies, inventory, unlocks, upgrades, completed chapters, story progress, language choices and purchase-fulfillment history. Active combat and device-specific ad-consent choices are not included in that progression snapshot. Google processes information needed to provide its services under its privacy policy. The game does not ask for your Google password or access other games' saved progress.
Turning cloud sync off stops further game-initiated syncing on that device; it does not delete the existing cloud copy. You can manage Google-held game data through Google Play Games: https://support.google.com/googleplay/answer/9130646 . Turn off syncing on all your devices before deleting a cloud backup to prevent a later sync from recreating it. Remove local copies separately if you want those deleted too.
3. Purchases and rewards
Google Play processes payments. The game receives product identifiers, purchase receipts or tokens, purchase state and transaction references to check purchases, deliver benefits, restore eligible ownership and avoid duplicate grants. It does not receive your payment-card number. Some products, including consumed currency purchases, cannot be recovered through the ordinary non-consumable purchase restore process.
Unity In-App Purchasing may process transaction, product, installation/session and device information for purchasing, diagnostics and related service functions. Purchase processing is separate from the optional-ad setting. See https://docs.unity.com/en-us/iap/privacy-and-consent/overview .
4. Optional advertising
Rewarded ads are optional and off by default. The current age gate makes them available only after an adult age-band selection and the player enables ads. The game stores an age category, not an exact date of birth. Google's consent tools present applicable choices before ad requests. Settings offers ad privacy options when required. Development builds use test ads; release builds may request real ads when enabled and permitted. Buying an ad-skip pass does not erase information already processed by an advertising provider.
Google Mobile Ads may process IP addresses and approximate location inferred from them, device or advertising identifiers, app/ad interactions, diagnostics and performance information for advertising, measurement and fraud prevention. Disabling optional ads stops additional game-initiated rewarded-ad requests. You can also use Android's advertising-identifier controls. Google privacy policy: https://policies.google.com/privacy .
For separately enrolled server-economy testing, rewarded ads use server-side verification. The game sends a derived game-account identifier and a one-time reward-ticket identifier to Google with the ad. Google sends our Cloudflare service a signed callback containing those identifiers, the ad unit/network, reward description, transaction identifier and timestamp. We verify that callback and store account-linked tickets, reward decisions and a hash of the transaction identifier to fulfill eligible rewards and prevent replay. These records follow the server retention and deletion practices below. The callback endpoint is configured, but this flow is not yet enabled for general gameplay.
5. Optional tester reporting
Where a build enables tester reporting, choosing to share sends a randomly assigned installation/tester identifier, game version, hero, chapter, outcomes, survival time, combat counters, build information, progression, currency balances and average frame rate to our Google Firebase project. The game does not include your email, Google Play name, advertising identifier, payment receipts or a location field in these reports. Network and service providers may still process connection information such as your IP address.
Reporting requires your choice; declining does not remove rewards or gameplay features. Settings > Tester Data lets you stop sharing and clear unsent reports. Previously uploaded reports are not deleted by that switch. To request their deletion, email us with the tester ID displayed there. Reports are separate from cloud saves. No automatic report-deletion schedule is currently configured. Reporting uploads are disabled in the development candidate reviewed for this policy update.
6. Server-account and security testing
Preview 59 uses local gameplay saves and defers the experimental server economy. Rounds, minigames, merchants and gameplay rewards do not require a game-server session or send economy commands to it. Google Play receipt signatures are checked on the device before purchases are saved and acknowledged. Optional rewarded ads use the advertising SDK completion callback. The game attempts Google Play Games sign-in independently; Google cloud backup remains optional. These local checks do not provide server-authoritative cheat protection. Earlier internal builds and retained server test records follow the practices below. Availability depends on the installed build.
We are preparing a separate server-account and economy service hosted using Cloudflare Workers and D1. It is not yet active for general gameplay, and existing released game balances are not currently protected by that service. The staged connection does not automatically upload or replace a local save.
Earlier internal candidates, previews 52 through 58, attempt Google Play Games sign-in automatically at launch and refresh eligible server sessions while the player is in camp; protected testing candidates can also refresh sessions during a round. Google may show an account-selection or first-time setup prompt. If Google sign-in is declined or unavailable, the player can retry using CONNECT PLAY GAMES; automatic sign-in does not enable ads, enroll a server-economy account, or upload an existing local save. When server sign-in is offered and configured, the game sends a one-time Google Play Games authorization code to our service. The service exchanges it with Google and verifies that the player belongs to this game. It derives an account identifier from the verified player identifier and uses short-lived session credentials. Session credentials are kept in game memory; the server stores a hash instead of the session credential itself. Current sessions expire after 30 minutes, with expired records removed by a scheduled cleanup. Connection IP addresses are processed for request limiting, with hashed identifiers used in those rate-limit records. Cloudflare may independently process network and security information under its policies.
For separately enrolled server-economy testing, our service can store account-linked balances, progression and inventory snapshots, reward claims and their status, purchase-token hashes/product references, transaction history and reviewed migration records. Their purpose is to provide account continuity, fulfill rewards and purchases, investigate disputes and prevent duplicate or unauthorized grants. A legacy-save review can include the original exported progression and the review record. Local progress is not automatically accepted as proof of legitimate earnings. For protected rounds, the service also records a round identifier, selected hero and stage, elapsed time and difficulty exposure, reported enemy-defeat and boss/elite counts, earned weapon gold, merchant offers and purchases, and minigame entry, outcome and reward records. These observations support reward calculations, recovery and bounded anti-abuse checks; they are not an independent simulation of each fight. These features remain staged; connecting the sign-in component alone does not activate them. Cloudflare privacy policy: https://www.cloudflare.com/privacypolicy/ .
The secure testing candidate also uses Google Play Integrity. The game requests an integrity token and sends it to our server with a hash binding it to the request. Google returns app recognition, installation licensing and device-integrity results used to reject unauthorized requests. The hash binds the request without placing its original content in Google's requestHash field. This verification is separate from optional advertising and does not prove that every gameplay result is legitimate. This protection is not yet active in generally released gameplay.
7. Stories, languages and optional narration
Story text and language content are bundled with the game. Story progress and language choices are saved with your progression. Reading the bundled story or switching its language does not itself send that text to an AI service. Live AI story generation is not enabled.
Voice-enabled tester builds offer optional, pre-generated English narration. These builds can download separate voice packs for heroes you own; automatic downloads default to Wi-Fi and can be turned off in Story Voices settings. You can also request an owned hero's pack manually. Downloaded audio and voice settings are stored on your device for later offline playback. The game loads the recording for the current chapter rather than sending your play session to a speech service.
Voice files are delivered over HTTPS through Cloudflare. A download request identifies the requested hero voice-pack file, and Cloudflare processes connection information such as your IP address and ordinary HTTP request information to deliver and protect the service. The voice download does not send your game-account ID, purchase receipts, inventory, saved story progress or microphone audio. Ownership is checked in the game before initiating the download. Narration was generated during development using ElevenLabs; the game does not contact ElevenLabs to narrate individual players' sessions. Voice-enabled builds are being tested separately and this feature is not yet available in every released build.
8. Support, recipients and security
If you contact support, we receive your email address, message and attachments. Send only what is needed to resolve the issue; never send passwords, sign-in codes or payment-card details. Data is processed by Vitaliteers and the relevant service providers described above, including Google, Unity and Cloudflare. Their processing may take place outside your country. Their own privacy policies describe their practices and controls.
We use HTTPS for the game services described here and restrict administrative access. No device, network or service can be guaranteed completely secure. Optional reporting is not a substitute for purchase verification or account-security controls.
9. Retention and deletion requests
Local and cloud progression remains until removed or replaced. Server profile, review, reward and transaction records are retained as needed to provide the service, recover accounts, handle purchases and disputes, and prevent abuse. There is no general automatic deletion schedule for those staged records. Support correspondence is retained only as long as reasonably needed to resolve the issue and related follow-up or legal obligations. Providers maintain their own retention practices.
To request access, correction or deletion of information we control, email informationsystemsmgmt@gmail.com with the subject “Monster Defender data deletion” or “Monster Defender privacy request.” Include your tester/server account ID if available and describe the data or account involved. Do not include passwords or purchase tokens. We may request minimal information to verify ownership. We will explain if particular records must be retained for legal, transaction-dispute or fraud-prevention reasons. This is a manual support process; it is not an instant in-game deletion feature.
Turning off reporting, signing out, disabling cloud sync or uninstalling the app does not by itself delete previously stored server/provider records. Deleting game data does not itself cancel or refund a purchase. For Google-held cloud data, use the controls in section 2; for local data, use Android app-storage controls. Contact us if you need help identifying which copies to remove. Your privacy rights may vary by location.
Preview 59 offers Settings > Save & Account, optional Google cloud backup and email privacy support. It does not automatically erase earlier server test records. In earlier secure testing candidates, Settings > Server Account includes a deletion-request option for connected server accounts and an email-support option. Once the server confirms a deletion request, it freezes server spending and revokes sessions while the request is reviewed; this confirmation does not mean erasure is complete. Deletion requests include an account identifier, request status and date. Until that candidate is released, or if you cannot sign in, use the email request above without installing or reopening the game. We verify ownership, remove the account's gameplay profile, inventory and associated data we control, and explain any transaction/security records that must be retained and why. Google Play purchase records and Google cloud saves require the separate controls described above.
10. Age settings and policy changes
Monster Defender's current Play listing targets ages 13 and older. Optional ads are unavailable in its under-18 mode. We do not intentionally request personal information from children under 13. Please contact us if you believe such information has been provided.
We may update this policy as features and data practices change. The date at the top identifies this revision. Material new collection will be accompanied by updated disclosures and any required choices.