Privacy Policy

Clash Companion — how we handle your information
Effective: August 16, 2026 Last updated: September 6, 2026 Contact: [email protected]

1. Introduction

This Privacy Policy explains how Clash Companion ("we", "us", "our") collects, uses, and shares information when you use our mobile application (the "App") and related services (collectively, the "Services").

Developer: Zidan Codes
Location: Amman, Jordan

Fan Content Disclaimer: This App is an unofficial, fan-made companion for Clash of Clans. We are not affiliated with, endorsed by, or sponsored by Supercell Oy. "Clash of Clans" and all related trademarks, logos, and game assets are the property of Supercell Oy. This material is unofficial and is not endorsed by Supercell. For more information see Supercell's Fan Content Policy: www.supercell.com/fan-content-policy

2. Privacy Summary (Quick Overview)

  • No account required: You can use the App without creating an account. If you choose to sign in, an optional account can synchronize supported App data across your devices.
  • Analytics, Crash Reporting & Performance Monitoring: Subject to the consent state described below, we use Firebase Analytics, Firebase Crashlytics, and Firebase Performance Monitoring to understand feature use and diagnose reliability and performance problems. Native automatic collection is disabled until the App applies the resolved consent state.
  • Purpose-limited collection: We collect the account, device, usage, support, purchase, and advertising data described below only for the stated purposes.
  • Local storage: Most of your preferences and data are stored locally on your device.
  • Push notifications (optional): If you allow notifications, we collect an Expo push token and a random app-installation identifier to deliver alerts and process deletion requests.
  • Advertising: The App displays ads through Google AdMob and mediation partners, including Unity Ads and Liftoff Monetize (formerly Vungle). Where Google makes a privacy-options form available, you can revisit those choices in Privacy Settings; platform privacy controls also remain available.
  • No data selling: We do not sell your personal information to third parties.
  • Your rights: You can request access to or deletion of your data in the App's Privacy Settings or by contacting us. Some privacy-related preferences may be available depending on platform capabilities.

3. Information We Collect

Privacy compliance – App Usage and Diagnostics: This section describes our practices under applicable privacy laws and platform requirements, including those of the Apple App Store and Google Play:
  • App Usage & Diagnostics: The App uses analytics, crash reporting, and performance monitoring tools (such as Firebase Analytics, Firebase Crashlytics, and Firebase Performance Monitoring) to understand how users interact with the App, improve features, and ensure stability and reliability. These tools may automatically collect limited usage, performance, network timing, and technical diagnostic information when the applicable measurement consent state permits collection.
  • Advertising: Advertising is displayed to help keep the App free. Ads may be non-personalized by default, and certain limited device or network information (such as IP address or basic device signals) may still be processed by advertising partners for ad delivery, fraud prevention, and measurement. We do not access or store those IP addresses. Where available, you can manage ad personalization through your device settings or in-app privacy controls. Advertising SDKs may process data independently in accordance with their own privacy policies.
  • User Controls: You can revisit Google's available advertising and measurement choices from Privacy Settings when Google requires a privacy options form. On iOS, tracking permission can also be changed in system Settings. If no in-app form is required for your region, the available controls are provided by your platform and the relevant service provider.
  • Transparency: We aim to provide clear information about our data practices in this Privacy Policy and to keep users informed about how analytics, diagnostics, performance, and advertising data are used within the App.

3.1 Information You Provide Directly

  • Optional account information: If you choose Sign in with Apple or Google, we receive the provider account identifier needed to authenticate you. Apple may provide your name and email address (including a private-relay address) on the first authorization; Apple does not provide a profile photo. Google may provide your name, email address, email-verification status, and profile image. We do not receive your Apple or Google password. Provider identifiers are used to keep accounts separate and are not matched by email address alone.
  • Optional cloud sync: For signed-in users, we store the supported data you choose to save in the App, such as favorite players, clans and base layouts, tracked war tags, language, and theme preferences. Guest data remains on the device unless you sign in and synchronize it.
  • Feedback and Support: When you contact us for support or submit feedback or problem reports, we collect the content of your message and any contact information you provide. If you explicitly opt in, the App may also include limited technical information (such as app version, device model, operating system version, and the random installation identifier) to help diagnose and resolve issues.
  • In-App Data: Any information you voluntarily input into the App (such as game statistics, notes, or preferences) is stored locally on your device and is not transmitted to our servers unless required for a specific feature.

3.2 Information Collected Automatically

When you use the App, we and our service providers may automatically collect:

  • Account and security data: For optional accounts, we process provider subject identifiers, encrypted provider tokens where needed for Sign in with Apple revocation, hashed session refresh tokens, account/session identifiers, installation IDs, and session timestamps. Mobile session credentials are stored in the device's protected secure storage. This information is used only for authentication, account security, synchronization, account switching, and deletion.
  • Installation and Device Information: The App creates a random UUID for this installation and stores it in the platform secure store. It is used for device-scoped sessions, notifications, support diagnostics you choose to include, and deletion requests. It is not derived from Android ID, IDFV, or an advertising identifier and is not used for advertising. Technical diagnostics may also include device type/model, operating-system version, app version, language, and platform.
  • Push Notification Data: If you enable push notifications, the App collects a push notification token associated with your device in order to deliver notifications. The token may be associated with the random installation identifier to deliver notifications and process deletion requests. This token and installation identifier may be transmitted to our backend services and to push delivery providers to enable notification delivery. We do not store or use the raw Android ID or IDFV. The token and installation identifier are not used for advertising or profiling purposes, and you can disable notifications in your device settings.
  • Backend Service Data: The App communicates with our backend services to fetch content, submit feedback or reports, synchronize certain features, and deliver push notifications. These interactions may include IP address, request metadata, and limited device information necessary to operate the service.
  • Game-Related Identifiers: When using features such as player or clan tracking, the App may process game-related identifiers (such as player tags or clan tags) and transmit them to our services and/or third-party game data providers solely to retrieve and display the requested game information.
  • IP Address: The App does not read or send your public IP address directly. When you use online features (including feedback, bug reports, and feature requests), our servers receive your IP address automatically as part of standard network requests (for example, in server logs). Advertising partners may also receive IP addresses when serving ads; those are processed on their systems and are not shared with us. We use IP addresses only for the following limited purposes:
    1. Security and fraud prevention to detect and prevent malicious activity.
    2. Rate limiting and spam prevention on feedback submissions to protect our services.
    Advertising partners may independently infer an approximate location from an IP address for regional compliance, ad delivery, measurement, and fraud prevention. Retention: ordinary hosting and security logs are retained only for the operational period configured by the relevant hosting service, unless longer retention is needed for security, troubleshooting, or legal compliance. If an IP address is stored with a feedback or report submission to prevent abuse or duplicates, it is retained only as long as the submission is kept and removed when that submission is deleted. We do not use IP addresses for precise geolocation, user profiling, or sell them to third parties.
  • App Usage Data: Information about how you interact with the App, including features accessed, screens viewed, buttons clicked, session duration, and frequency of use.
  • Performance Data: App performance metrics, crash reports, error logs, startup timing, screen rendering metrics, HTTP/S network timing data, and diagnostic information to help us identify and fix technical issues and improve responsiveness.
  • General Location: Approximate location (country or region level only) may be inferred by our servers or advertising partners from IP address or region settings (not precise GPS) to comply with regional requirements and support advertising delivery/measurement.

3.3 Advertising and Analytics Data

Important: The App currently displays advertisements to support development and keep the app free. The App displays advertisements through Google AdMob. Our advertising setup may also include mediation partners such as Unity Ads and Liftoff Monetize (formerly Vungle). Liftoff participates only as an AdMob mediation bidding partner. When an advertising partner is eligible to bid on or serve an ad, it may receive and process advertising-related information on its own systems for ad delivery and measurement, including IP addresses. We do not receive or store IP addresses from these partners. Information collected may include:
  • Advertising identifiers (such as Google Advertising ID or IDFA)
  • IP address and approximate location (collected by ad partners)
  • Device information and app usage patterns
  • Ad request, impression, interaction, conversion, diagnostic, and anti-fraud signals
  • Consent and other applicable advertising privacy signals
This data is collected and processed according to the privacy policies of our advertising partners. You can opt out of personalized ads through your device settings or in the app's Privacy Settings screen.

4. How We Use Your Information

We use the collected information for the following purposes:

  • Provide and Operate the App: To deliver core functionality and features of the Services.
  • Improve and Optimize: To analyze usage patterns, understand user preferences, and enhance the App's performance and user experience.
  • Performance Monitoring: To measure app startup, screen responsiveness, network request timing, and key loading flows so we can diagnose slowdowns and improve reliability.
  • Maintain and Troubleshoot: To monitor stability, identify crashes and bugs, fix technical issues, and ensure security.
  • Customer Support: To respond to your inquiries, feedback, and support requests.
  • Advertising: To display, personalize, and measure the effectiveness of advertisements, subject to the choices and permissions described in this policy.
  • Analytics: To generate usage and performance reports used to improve the App.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, and enforce our Terms of Service.

5. How We Share Your Information

We do not sell your personal information. We may share information in the following circumstances. We require service providers that process personal data on our behalf to protect it consistently with this Privacy Policy and applicable law:

  • Service Providers: We share data with third-party service providers who help us operate the App, including:
    • Cloud hosting and storage providers
    • Analytics, crash reporting, and performance monitoring services (including Firebase Analytics, Firebase Crashlytics, and Firebase Performance Monitoring)
    • Customer support and email services
  • Advertising Partners: To display and measure ads. See section 6 for details on specific partners.
  • Legal Requirements: When required by law, legal process, or government request; to protect our rights, property, or safety; to prevent fraud, abuse, or security threats.
  • Business Transfers: In connection with any merger, acquisition, sale of assets, or bankruptcy, your information may be transferred to the successor entity.
  • With Your Consent: We may share information for other purposes with your explicit consent.

6. Third-Party Services and SDKs

The App integrates with the following third-party services that may collect data:

Service Provider Purpose Data They May Collect
Google Play Services Core Android functionality, app distribution, security, and updates. Device identifiers, app diagnostics, and performance data as required by the platform.
Apple and Google Sign-In Optional account authentication and connecting additional sign-in methods. Provider account identifier and, depending on your provider settings and consent, name, email address, email-verification status, and profile image. Clash Companion does not receive your provider password.
Firebase Crashlytics Stability monitoring, bug fixing, and crash reporting. Crash traces, device state (battery, orientation), stack traces, and custom event breadcrumbs to identify technical issues.
Firebase Analytics Usage analysis, feature optimization, and user behavior tracking. App events, screen views, session information, feature categories, content identifiers, coarse gameplay attributes such as town-hall level, and technical app/device metadata. Search text and player/clan tags are not intentionally sent as analytics event values.
Firebase Performance Monitoring Performance monitoring on supported Android builds, including app startup analysis, screen rendering analysis, HTTP/S request monitoring, and lightweight custom trace collection for key loading flows. Performance trace durations, app startup timing, screen rendering metrics, HTTP/S request timing and payload size, app version, country/region, device and OS attributes, and custom trace metrics used to diagnose slow or failing app flows.
Unity Ads (Mediation) Bidding-based ad demand, ad delivery, and ad quality measurement through mediation. Advertising ID, IP address, device/app information, ad events, diagnostics, and anti-fraud signals.
Liftoff Monetize (formerly Vungle) Independent AdMob mediation bidding partner for ad bidding, delivery, measurement, and fraud prevention. Advertising and device identifiers (such as GAID or IDFA when available and permitted, and App Set ID or Android ID where applicable), IP address, device/OS/app information, approximate location inferred from IP, ad request and interaction data, diagnostics, anti-fraud signals, and applicable consent or privacy signals. We do not provide Liftoff with your Clash Companion account profile, email address, saved content, or an account-level user identifier.
RevenueCat In-app purchase and subscription management, cross-platform subscription sync, and purchase receipt validation. Purchase history (transaction receipts, purchase timestamps, product IDs), subscription status (active/expired/cancelled, renewal dates, trial periods), and app user identifiers (anonymous user IDs for entitlement tracking across devices). Apple or Google, not RevenueCat or Clash Companion, processes full payment-card details.
Expo Push Notification Service Routes optional remote notifications to Apple or Google. Expo push token, notification payload, platform, and delivery diagnostics.
Apple Push Notification service / Firebase Cloud Messaging Platform delivery of optional remote notifications. Platform push token, notification payload, and delivery metadata.
Amazon Web Services Hosts uploaded editorial media and sends support-notification email through S3/CDN and SES. Requested media/network metadata; support submission content may be included in operational email sent to our support address.
Supercell Clash of Clans API Returns public player, clan, war, and game data requested through our backend proxy. Requested player or clan tag and ordinary network request metadata received by our backend; responses contain public game data.
Privacy Policies: We configure third-party SDK integrations to align with applicable Apple App Store, Google Play, and privacy requirements, and keep this policy updated as integrations change. Each provider processes data under its own privacy policy.

7. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Here are specific retention periods for different types of data:

  • IP Addresses: Ordinary hosting and security logs are retained for the operational period configured by the relevant hosting service, and longer only when needed for security, troubleshooting, or legal compliance. IP addresses stored with feedback or report submissions are removed with those submissions under the 30-day submission schedule described below.
  • Push notification tokens and installation ID: Retained while notifications are enabled and for as long as needed to deliver notifications and handle deletion requests. Tokens may be disabled after extended inactivity (for example, 90 days).
  • Firebase Analytics Data: Retained according to the retention controls configured for our Firebase property and Google's service-level retention rules. Console configuration must be kept consistent with this policy and applicable law.
  • Crash Reports (Crashlytics): Retained according to Firebase Crashlytics' service-level retention rules and deleted or de-identified by the provider when no longer retained.
  • Performance Monitoring Data: Retained by Firebase in accordance with Google's operational retention and console availability practices for Performance Monitoring. We use the resulting reports only for performance analysis, issue diagnosis, and service improvement.
  • Feedback, feature requests, and problem reports: Our scheduled backend cleanup is configured to remove these submissions and related support-reply notifications after 30 days, unless a longer period is required for security, legal compliance, or an unresolved support matter.
  • Purchase and entitlement records: Apple, Google, and RevenueCat retain transaction and entitlement records under their own service rules and legal obligations. Deleting a Clash Companion account does not cancel an App Store or Google Play subscription and does not delete records that a store is independently required to retain. The current in-app deletion flow does not automatically erase the separate RevenueCat customer record; contact us through the web deletion resource or support email to request that processor-side deletion while we complete the automated integration.
  • Optional account and synchronized data: Retained while the account remains active. When you delete the account in the App, the account, linked identities, active sessions, registered devices, and synchronized App data are deleted from our account service. Separate records that a store or payment provider must retain remain governed by that provider and applicable law.
  • Advertising Data: Managed by our advertising partners (such as Google AdMob, Unity Ads, and Liftoff Monetize) under their published retention policies and your applicable privacy choices.
  • Local Device Data: Stored locally on your device until you uninstall the App or manually clear the App’s data through your device settings.

You can request deletion in the App's Privacy Settings. You can also use our web account and data deletion resource. If the in-app request cannot be completed, contact us at [email protected].

If you created an optional account, you can delete it directly from the Account screen. Account deletion is permanent and does not cancel an App Store or Google Play subscription; subscriptions must be managed through the applicable store.

8. Security

We implement reasonable technical, administrative, and physical safeguards designed to protect your information from unauthorized access, disclosure, alteration, and destruction. These measures include:

  • Encryption of data in transit using industry-standard protocols (HTTPS/TLS)
  • Protected mobile credential storage, hashed refresh tokens, and encrypted Apple provider tokens where those tokens are retained
  • Access controls, dependency updates, and security monitoring
  • Limited access to personal information by employees and contractors

However, please be aware that no method of transmission over the internet or method of electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

9. Children's Privacy

The App is intended for general audiences and is not specifically directed at children under the age of 13 (or the minimum age required in your jurisdiction to provide consent for data processing).

We do not knowingly collect personal information from children under 13 without verifiable parental consent. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at [email protected], and we will take steps to delete such information.

If you are under 13 (or the applicable minimum age in your region), please do not use the App or provide any personal information without your parent or guardian's permission and supervision.

10. Your Privacy Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

10.1 Access and Portability

You have the right to request access to the personal information we hold about you and, in some cases, receive a copy in a portable format.

10.2 Correction and Update

You can request that we correct or update inaccurate or incomplete personal information.

10.3 Deletion (Right to Be Forgotten)

You can delete your personal information from our servers by following the in-app steps below, subject to limited legal exceptions that we will explain if they apply. Users can request data deletion at any time.

Signed-in users can permanently delete their account from the Account screen. Guests can request deletion of device-scoped notification and support data in Privacy Settings. If you no longer have the App, use our web deletion resource or email support. We may ask for the minimum information needed to verify the account or installation and prevent unauthorized deletion; never send us an Apple/Google password or authentication token.

When you confirm signed-in account deletion, the account service deletes the account, linked sign-in identities, sessions, registered devices, and synchronized App data. It also requests removal of the account association from active push-notification records. A limited deletion audit record may be kept to document and troubleshoot the request. Support submissions follow the retention schedule in section 7. Requests made through the web or support channel may take up to 30 days to verify and complete, unless applicable law requires a different period.

10.4 Objection and Restriction

You may object to or request that we restrict certain processing of your personal information.

10.5 Advertising Controls

You can control personalized advertising through your device settings or within the app's Privacy Settings screen:

  • Android: Use the App's Google privacy options when available and Android's Privacy/Ads controls to reset or delete the Advertising ID and manage ad privacy choices
  • iOS: Settings → Privacy & Security → Tracking, where you can change the App Tracking Transparency permission for apps that request it

10.6 Consent

Where applicable, consent may be required by law for certain data processing activities. Analytics, crash, and performance collection follows the resolved measurement-consent state. Advertising follows Google's consent flow, and iOS cross-company tracking additionally requires the applicable App Tracking Transparency permission.

In the EEA, UK, and Switzerland, advertising choices are requested through Google's User Messaging Platform (UMP) where required. Liftoff supports reading compatible GDPR consent recorded through Google's Additional Consent specification, including UMP. We remain responsible for listing Liftoff in the applicable consent message and verifying that the required choice is available to Liftoff before it participates in advertising.

How to Exercise Your Rights: To exercise any of these rights, submit a request in the App's Privacy Settings. If the in-app request cannot be completed, contact us at [email protected]. We will respond to your request within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.

11. International Data Transfers

Your information may be transferred to, stored, and processed in countries other than your country of residence, including the United States and other jurisdictions where our service providers operate.

These countries may have data protection laws that differ from those in your country. Where required, we and our providers use applicable contractual, adequacy, or other lawful transfer mechanisms and provider security terms.

12. Additional Rights for California Residents

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: You can request information about the categories and specific pieces of personal information we've collected, the sources, purposes, and third parties we've shared it with.
  • Right to Delete: You can request deletion of your personal information, subject to certain exceptions.
  • Right to Opt-Out: You can opt out of the "sale" or "sharing" of personal information (though we do not sell personal information).
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
  • Right to Correct: You can request correction of inaccurate personal information.
  • Right to Limit: You can limit the use and disclosure of sensitive personal information.

To exercise these rights, contact us at [email protected].

Google states that its restricted-data setting for U.S. state privacy laws is not automatically applied to every ad network in an AdMob mediation chain. A request made to us applies to our processing and will be handled with relevant advertising partners as required. You may also use Liftoff's privacy choices. We do not treat Google's setting alone as confirmation that a partner-specific Liftoff signal was transmitted.

13. Additional Rights for EEA/UK Residents

If you are in the European Economic Area (EEA) or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) and UK GDPR:

  • Right to access, rectification, erasure, and restriction of processing
  • Right to data portability
  • Right to object to processing based on legitimate interests
  • Right to withdraw consent at any time
  • Right to lodge a complaint with your local data protection authority

Legal Basis for Processing: We process your data based on:

  • Performance of a contract (to provide the App)
  • Legitimate interests (to improve and secure the App)
  • Consent (for analytics and advertising, where required by applicable law)
  • Legal obligations (to comply with applicable laws)

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, new features (such as enabling advertising), or for other operational reasons.

When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify you through the App or by other reasonable means (such as email if we have your contact information)
  • In some cases, obtain your consent if required by law

We encourage you to review this Privacy Policy periodically. Your continued use of the App after changes are posted constitutes your acceptance of the updated policy.

15. Contact Us

If you have any questions, concerns, requests, or complaints about this Privacy Policy or our data practices, please contact us:

We will respond to your inquiry within 30 days (or as required by applicable law).