Privacy Policy
What Block Master: Cube Crush collects, why, who receives it, how long it is kept, and how to reach us. It describes how the game works today.
Effective 11 October 2026
The short version
- No account, no sign-in, no ads, and no advertising or analytics SDKs. The game never asks for your name, email address, phone number or location.
- Your Adventure moves, gold, purchases and cloud save go to the game's own server, which checks them against cheating and keeps them for you.
- The game's server never stores your IP address: only a keyed hash of it.
- If your install is matched to a tap on an offer on a rewards site (normally your own tap: see “Shared networks” below), the goals you reach are reported to OpusWall so that site can credit the reward. If no tap is matched, nothing goes to OpusWall.
Who is responsible
Block Master: Cube Crush (“the game”) is published by the developer shown on the App Store page (Furkan Eyüb Yokuş), referred to here as “we”. We decide how the data described here is used, and are its data controller under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and the EU General Data Protection Regulation (GDPR).
This page and the game's support page are hosted on OpusWall (opuswall.net), the offerwall network the game's reward campaign is set up on. Write to legal@opuswall.net about privacy, and to support@opuswall.net about anything else.
What stays on your iPhone
- In the game's own storage: your progress and settings (best score, Adventure stars and unlocked levels, an unfinished Classic game, sound and haptics) and a random install ID. Deleting the game deletes them.
- In the iPhone's Keychain, for this device only — never synced or copied to another device: a random player ID, a recovery key, the identifier of the key that proves requests come from the genuine app (or, where App Attest is unavailable, the random secret used instead), a count of the Adventure levels you have started, and the last gold balance the server confirmed. These stay when the game is deleted, which is how it recognises you when you install it again on the same iPhone.
- Classic mode runs entirely on your iPhone: its games are never sent. Only your best score and the number of Classic games you have played are part of the cloud save.
What the game sends to its server
Apart from the Apple services described below, the game talks only to its own server. Nothing is sent while you play offline: it waits on your iPhone until you are online.
Identifiers
A random install ID made on your iPhone, and a random player ID made by the server. The recovery key is stored on the server only as a one-way hash. None of these is your name, Apple ID, email address or phone number, and the game does not use Apple's advertising identifier (IDFA).
Device verification and app information
Apple App Attest: the first time the game connects, iOS creates a key in your iPhone's secure hardware and Apple confirms that it belongs to the genuine Block Master app. The server keeps the key's public part, Apple's receipt for it and a counter, and every later request is signed with the key. On an iPhone where App Attest is unavailable, a random secret made on the iPhone is used instead, and the server keeps a copy of it to check requests.
With each request: the app version, your iPhone's clock time and a short list of integrity signals — signs of a jailbreak, injected code, an attached debugger, a modified app or a manipulated clock. At registration: your device's language and region setting (for example tr-TR). The iOS version and whether the device is an iPhone are read from the request's technical header for offer attribution (below).
Apple DeviceCheck: the game asks Apple for a one-time device token and sends it when it registers, completes a level or buys gold. This check is switched off on the server today: the token itself is neither used nor stored, and the server notes only when it last received one. If it is switched on, the server will use it only to read and set two yes-or-no values Apple keeps for each device (whether an install reward was already claimed on it, and whether it was flagged for cheating), and this policy will be updated before that.
Adventure play
For each Adventure level: the level number, every move (which piece went where), every booster used (Hammer, Refresh, Undo, Continue), the time of each action in milliseconds, how long the level was active and paused, and the score, stars, cleared lines, goals, gold spent and result. When a level starts, the server also issues a time ticket so it can measure play time by its own clock, and it notes each minute in which the game sent it a request.
Completed levels, and failed or abandoned levels on which you used a booster, are always sent. Other failed or abandoned levels are sent when you are online.
Gold and purchases
Your gold ledger: the 200 gold you start with, gold earned, boosters bought, gold packs bought and refunds.
Apple takes the payment for a gold pack. The game then sends the server Apple's signed record of the purchase — transaction ID, product, date, App Store country, price and currency — so it can credit your gold. The purchase carries your player ID to Apple as an app account token, and Apple's servers tell the game's server about refunds and refund reversals. We never receive your name, Apple ID, email address or payment details.
Cloud save
Best score, the number of Classic games, whether you have seen the tutorial, Adventure stars and the highest unlocked level, and your sound and haptics settings — so your progress can come back after a reinstall. For Adventure, the server keeps only the progress it has verified.
Your IP address
The server sees your IP address with every request, as any internet service does. It is used while the request is handled and is never written to the game's database. What is stored is a keyed hash of it (HMAC-SHA-256 with a secret kept in the database): to limit how often one address can call the server, with your player record when you register (to spot one person running many players), and for offer attribution.
Anti-cheat results
From the data above, the server works out whether each level's result matches a replay of its moves, how its timing compares with human play, signs of automated play, cheating strikes, and whether offer rewards may be reported. The game does not show these.
Offer attribution and rewards (OpusWall)
The game runs a reward campaign on OpusWall, an offerwall network: rewards sites and apps (publishers) show the game as an offer, and their members earn rewards for installing it and reaching goals. None of this is in the game — no link, no code, no sign-in — and the server does all of it by itself.
The tap
When someone taps the offer, OpusWall sends them through the game's server on the way to the App Store. The server records OpusWall's click ID, the time, keyed hashes of the IP address and of its IPv6 network (/64), and the device type and iOS version from the browser. Only taps from an iPhone or iPad are recorded.
The match
When the game first connects (and during its first hour), the server looks for the most recent tap from the same address or IPv6 network in the 24 hours before, from a compatible device. If there is one, your player is linked to it; earlier taps from that address are left unused. Only players whose iPhone passes Apple App Attest can be linked.
The reports
While your player is linked, the server reports each goal to OpusWall in a signed server-to-server message that contains only the click ID, the goal, whether it is a new goal or a cancellation, the time and a transaction ID. The goals are installing the game, first reaching Adventure level 5, 20, 30, 40, 50, 60, 70, 80, 90, 100 and 1000, and the first purchase of each gold pack.
A purchase goal is reported 14 days after the purchase, and cancelled if the purchase is refunded. A goal reached by cheating is never reported, and goals already reported can be cancelled if cheating is found later. OpusWall passes the result to the publisher where the offer was tapped, which credits its member under its own and OpusWall's terms.
Shared networks
Because the match uses the network address, on a shared address — a mobile carrier's shared address, an office or school Wi-Fi — an install can be linked to another person's tap from that address. That person's rewards site then sees which goals were reached, never who you are.
If no tap matches your player, nothing about you is ever sent to OpusWall. Tap records that match nobody are deleted after 14 days.
Why we use it, and the legal basis
- Running the game you installed — your player, gold, progress, purchases and cloud save: performance of a contract (KVKK art. 5(2)(c); GDPR art. 6(1)(b)).
- Keeping the game fair and secure — checking that requests come from the genuine app, replaying levels, anti-cheat checks, limiting abuse and spotting one person running many players: our legitimate interest in a fair game and in protecting purchases and rewards (KVKK art. 5(2)(f); GDPR art. 6(1)(f)).
- Linking installs to offer taps and reporting goals to OpusWall: our legitimate interest in paying for the campaign that brought a player, and only for genuine play (KVKK art. 5(2)(f); GDPR art. 6(1)(f)).
- Handling refunds and keeping the purchase records the law requires: legal obligations (KVKK art. 5(2)(ç); GDPR art. 6(1)(c)), and establishing, exercising or defending legal claims (KVKK art. 5(2)(e); GDPR art. 6(1)(f)).
The anti-cheat checks run automatically. They never stop you from playing. They decide whether a level's gold is credited when its result does not match the replay, and whether offer rewards may be reported; doubtful cases are held for a person to review, and you can ask for a person to look at yours.
We do not sell your data and do not use it to build advertising profiles.
Who receives it
Apple
App Attest and DeviceCheck (device verification), and the App Store (payments, purchase records, refund notices), under Apple's own privacy policy. If you share analytics with app developers in your iPhone's settings, Apple may also give us aggregated usage statistics and crash reports.
Supabase
Supabase, Inc. hosts the game's server and database. The database is in Supabase's Frankfurt, Germany (EU) region. The server code runs on Supabase's worldwide edge network, so a request can be handled in a data centre near you before it reaches the database. Supabase keeps short-lived technical logs of requests, which can include the IP address.
Cloudflare
Cloudflare, Inc. runs the network in front of Supabase's servers. It carries the game's requests, and so sees your IP address.
OpusWall
Only the goal reports described above, and only for a player linked to an offer tap.
Authorities
When the law requires it.
Supabase, and Cloudflare as part of Supabase's service, process the data on our behalf (as data processors). The database stays in the EU, but these providers and Apple operate worldwide, including in the United States, so data can also be handled outside Türkiye and the EU — for example while a request passes through a data centre near you. Only what is needed to run the game is transferred, under the providers' data processing terms, which include the EU standard contractual clauses.
How long it is kept
- Rate-limit counters and one-time registration challenges: 2 days.
- Offer tap records: 14 days. If a tap was linked to your player, the link itself stays with your player record — the click ID and time, the device type and iOS version of the tap and of your iPhone, and the click IDs of any earlier taps it replaced — because the goals reported for it may still need to be cancelled. When your player is deleted, only a one-way digest (SHA-256) of those click IDs stays, linked to nothing else, so that the same tap can never be rewarded twice.
- Failed device verifications — the verification data the device sent, the app version and the request's technical header, with no player, install or address: 14 days.
- The record of the minutes in which the game sent a request: 30 days.
- The moves of a level that was not completed, used no gold and raised no anti-cheat flag: 30 days; a short summary of the level stays.
- Level time tickets: 90 days.
- Everything else — your player record, completed levels and their moves, verified progress, the gold ledger, purchases and refund notices, the cloud save, anti-cheat results and goal reports — is kept for as long as the game is offered and the data is needed for it, and deleted when you ask (see Your rights). When you ask, a purchase or refund record the law requires us to keep stays only as long as the law requires, linked to nothing but the bare random player ID.
Deleted data can stay in the hosting provider's routine backups for a short time, until they are overwritten.
Children
The game is not directed at children under 13, and we do not knowingly collect personal data from them. The game shows no ads and targets no one by age. If you believe a child under 13 has played it and want their data deleted, write to legal@opuswall.net.
Your rights
Under KVKK (article 11) and the GDPR you can ask whether data about you is processed and why; for a copy of it, also in a machine-readable form; to have it corrected or deleted, and the recipients told about it; to restrict its use; to object to processing based on legitimate interests; which recipients it went to; and for a person to review an automated decision. If unlawful processing has caused you damage, you can claim compensation.
Write to legal@opuswall.net. We answer within 30 days, free of charge. The game has no account, so include the details listed on the support page. If we cannot identify a record with confidence, we will tell you what else would help rather than act on someone else's data.
Deleting the game from your iPhone removes what is stored in the game, but not the Keychain entry or anything on the server. Reset progress in Settings replaces only your cloud save, with one that has no progress; the rest of the server's data stays. How to ask for deletion.
You can also complain to the Personal Data Protection Board in Türkiye (Kişisel Verileri Koruma Kurulu, kvkk.gov.tr) or, in the EU, to the data protection authority where you live.
Security
Everything between the game and its server is encrypted (HTTPS). Requests are signed with the key Apple verified; the database is closed to the public and reachable only through the server's own functions; IP addresses and recovery keys are stored only as hashes; and only the developer can access the data.
Changes to this policy
If the game starts handling data differently, this page is updated first and its effective date changes. It is published in English and Turkish, with the same content in both.