Leaked
Leaked Privacy Policy
Last updated: 2026-07-02
Privacy Policy
Effective date: July 16, 2026
This Privacy Policy explains how Leaked ("Leaked," "we," "us," or "our") handles information when you use the Leaked mobile game and any related services (together, the "Service"). Leaked is a fictional detective game: you play a sleuth who investigates a simulated phone — full of made-up messages, photos, and apps — to solve a story.
Leaked does not access, read, or collect any of the real personal data on your device. The "phones" you investigate are entirely fictional and ship inside the app. The Service never reads your real contacts, messages, photos, call history, location, or files, and it does not request microphone or camera access. (See Section 3.)
We try to collect as little personal data as we can while still running the game, and we explain everything we do collect below in plain English. If you have questions about this policy, email us at support@newdawnhq.com.
1. Who we are
Leaked is the data controller for the personal data described in this policy. For the purposes of the EU and UK General Data Protection Regulation (GDPR), we are the "data controller." Our infrastructure and the third-party processors we use are located in the United States, so your data is processed in the US (see Sections 6 and 9).
2. No account required
Leaked does not require you to create a traditional account. You do not give us a name, email, or phone number to play.
- Anonymous identity. When you first open Leaked we create an anonymous account using Firebase Authentication and store an opaque, device-level identifier. This lets us keep your progress, settings, and subscription entitlement associated with your device.
- We never ask you to sign in with a name or email to play.
3. The game uses fictional data — not your real data
Leaked is an entertainment product. The cases, the simulated phone, and all the messages, photos, contacts, and "apps" inside it are fictional content authored by us and bundled in the app. Investigating an in-game phone never touches your device's real data.
- Leaked requests no access to your device's contacts, photos, microphone, camera, location, health data, or messages, and collects none of them.
- Any resemblance of in-game characters or events to real people or events is coincidental.
4. Information we collect automatically
- Device and app information. Device model, OS version, app version, language, time zone, and country (derived from IP).
- Usage events. Product events such as app opens, case starts, questions answered, hints used, paywall views, and purchases, collected via Firebase Analytics and PostHog (including sampled session replay of in-app screens). We use these to understand which features work and to improve the game.
- Crash and diagnostic data. Crash reports and basic performance metrics via Firebase Crashlytics.
- Identifiers for advertising. With your permission we may receive your device's advertising identifier — the IDFA on iOS (only if you allow it through App Tracking Transparency) or the Google Advertising ID on Android — for advertising: serving ads (including selecting more relevant ones), measuring them, and install attribution. If you decline ATT on iOS, or reset or limit ad tracking on Android, we do not use the advertising identifier to personalize ads. See Sections 6 and 7.
5. Purchases
When you buy a subscription, the store that processed it — Apple's App Store or the Google Play Store — and our subscription manager (RevenueCat) tell us that the purchase happened, what was bought, and the status of your entitlement. We do not see or store your full payment card details.
We do not knowingly collect any other categories of personal data, and we do not ask for sensitive information.
6. How we use your information, and third parties we share it with
We use the information above to provide the game (authenticate your device, save progress and settings), operate billing (verify purchases through Apple or Google and RevenueCat, manage your entitlement), improve the game (understand feature usage, diagnose crashes), measure marketing (attribute installs and conversions where you granted ATT), and comply with legal obligations.
We share the minimum data each provider needs to do its job. We do not sell your personal data.
- Google Firebase (Authentication, Analytics, Crashlytics, App Check) — anonymous account ID, app/device metadata, crash logs, usage events, and a device-attestation token (App Check uses Apple's App Attest/DeviceCheck on iOS or Google Play Integrity on Android to confirm requests come from a genuine, unmodified copy of the app and to block abuse). firebase.google.com/support/privacy · policies.google.com/privacy
- PostHog — product analytics and sampled session replay. Usage events, device metadata, sampled recordings of in-app screens. posthog.com/privacy
- Adjust — mobile attribution. Device identifiers (IDFA on iOS or Google Advertising ID on Android, when allowed), install/event data, IP. adjust.com/terms/privacy-policy
- Meta / Facebook SDK — ad attribution and conversion measurement. Device identifiers (IDFA on iOS or Google Advertising ID on Android, when allowed), install/event data, IP. facebook.com/privacy/policy
- AppLovin MAX (ad mediation) and the ad networks it serves — advertising and ad measurement. To show a rewarded ad, AppLovin MAX runs an auction and may share your device's advertising identifier (IDFA on iOS or Google Advertising ID on Android, when allowed), IP address, and coarse device and ad-interaction data with the winning ad network so it can serve and measure the ad. The networks MAX may use include Google (AdMob / Ad Manager), Meta Audience Network, Unity Ads, Mintegral, Pangle (ByteDance), ironSource, Liftoff/Vungle, InMobi, BidMachine, Bigo, and Yandex — each is an independent controller of the data it receives and is subject to its own privacy policy. applovin.com/privacy · unity.com/legal/privacy-policy · policies.google.com/privacy
- RevenueCat — subscription and entitlement management. Anonymous user ID, purchase events, subscription status, device/platform metadata. revenuecat.com/privacy
- Apple (In-App Purchase, SKAdNetwork) — payment processing and privacy-preserving ad attribution on iOS. Apple ID, payment, purchase receipt; SKAdNetwork conversion signals. apple.com/legal/privacy
- Google (Google Play Billing) — payment processing and purchase validation for subscriptions bought on Android. Google Play account, purchase token, subscription status. policies.google.com/privacy
We may also share information with professional advisors, with a successor in a merger or acquisition, or with authorities where required by law.
7. Advertising and App Tracking Transparency (ATT)
Leaked shows short rewarded video ads — optional ads you can choose to watch to unlock an in-game hint. You are never required to watch an ad to play, and an active subscription removes them. Ads are delivered through AppLovin MAX mediation, which selects and serves ads from the networks listed in Section 6 and shares the data described there with them.
On iOS we present Apple's App Tracking Transparency prompt before any tracking that requires it. If you choose "Ask App Not to Track":
- We will not access your device's IDFA.
- Our advertising and attribution partners (AppLovin MAX and the ad networks it serves, Adjust, and the Facebook SDK) run in a limited mode that does not link your activity to your identity across other apps and websites. You may still see ads, but they are not personalized using your IDFA.
- Core analytics (crash reporting, product event counts) still operate using non-tracking identifiers, because they are necessary to run the game.
- Apple's SKAdNetwork may still provide privacy-preserving, aggregate attribution that does not identify you.
You can change your choice any time in iOS Settings → Privacy & Security → Tracking.
Android
Android does not use App Tracking Transparency. On Android, our advertising and attribution partners may use your Google Advertising ID to serve and measure ads and for install attribution. You can reset or delete that identifier, or opt out of ad personalization, any time in Android Settings → Privacy → Ads. Core analytics and crash reporting still operate using non-tracking identifiers, because they are necessary to run the game.
8. Data retention
- Anonymous account, progress, and settings: kept while your anonymous account exists.
- Logs and analytics events: typically kept up to 14 months, then deleted or anonymized.
- Purchase and billing records: kept for as long as required by tax and accounting law.
9. Security & international transfers
We use industry-standard measures including TLS in transit, encryption at rest with our cloud providers, scoped credentials for third-party providers, and team access controls. No system is perfectly secure, so we cannot guarantee absolute security. Leaked and its providers are based in the United States; if you use the Service from elsewhere, your data is transferred to and processed in the US, and where required we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to object to or restrict certain processing, to withdraw consent, and to lodge a complaint with your data protection authority. California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, to opt out of the "sale" or "sharing" of personal information, and not to be discriminated against for exercising them. When you allow tracking and see personalized ads, our sharing of your advertising identifier with the ad networks described in Sections 6–7 may qualify as "sharing" for cross-context behavioral advertising under the CPRA. You can opt out at any time through App Tracking Transparency (iOS) or your Android ad settings, after which we and our partners do not use your advertising identifier to personalize ads. We do not knowingly sell or share the personal information of anyone under 16.
To exercise any right, email support@newdawnhq.com. We respond within the time frames required by law and may need to verify your identity first.
11. Children
Leaked is not directed to children under 13 and we do not knowingly collect personal information from children under 13. Because the game depicts mature themes (relationships, infidelity, mild crime/drama), it is rated for older teens and adults. If you believe a child has provided us with personal information, contact support@newdawnhq.com and we will delete it.
12. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date above and, for significant changes, notify you in-app. Continued use of the Service after a change means you accept the updated policy.
13. Contact us
For privacy questions, requests, or complaints, email support@newdawnhq.com.