Data protection
Privacy policy
Last updated: August 14, 2026
1. Data controller and contact
The data controller is the independent publisher Mazlide Studio, publisher of the game Mazlide.
For any question or to exercise a right, email support-mazlide@gauthierpl.com.
2. Scope
This policy describes processing carried out by the Mazlide application, its API hosted on gauthierpl.com and its public support pages. The game can be used without an account with limited features. Creating an account is optional.
3. Data processed
| Category | Examples |
|---|---|
| Account | Username, email address, password stored only as a cryptographic hash, account creation date and last sign-in. |
| Profile and progress | Levels completed, move counts, optimal results, campaign progress, daily challenge results, leaderboard entries, title, coins, cosmetic items, friend relationships and friend requests. |
| Gameplay activity | Level played, moves submitted, status and timestamps of attempts needed to validate results, participation in duel queues, friendly duel invitations, matched opponent and validated duel score, level difficulty ratings, and weekly boss participation, damage, rank and rewards. |
| Security and connection | IP address, generic device name, cryptographic fingerprint of the user agent, sessions, sign-in attempts and password reset requests. |
| Messages and support | Account ID, selected category and content of messages voluntarily sent to the developer from the application, as well as the email address and username used in support conversations. |
| Local data and preferences | Theme, move buffer size, speedrun setting and interface language, cached campaign progress and recent official-level and duel history, stored only on the device. |
| Advertising | When the Android version displays ads with Google AdMob: IP address, which may be used to estimate a general geographic area; interactions with the app and ads (including app launches, taps and video views); diagnostic information; Android advertising ID; app set ID; and other applicable technical identifiers. To validate an advertising reward, Mazlide sends AdMob a temporary random token and retains the transaction identifier and timestamp returned by Google’s signed callback. This token contains neither the username nor the email address. |
| Purchases and Premium status | Purchased product ID, Google Play purchase token, order ID, purchase status and date. Mazlide never receives payment card details. |
4. Why this data is used
- Provide the game and account: sign-in, progress syncing, profiles, leaderboards, friend management and matching players for duels. This processing is necessary to provide the requested service.
- Validate games: prevent score tampering, verify paths submitted during duels and correctly award progress and cosmetic items. This processing is necessary to operate the service.
- Manage player interactions: search for a player by their exact username, send or process friend requests, show friends’ recent availability and organize a friendly duel requested by the players. This processing is necessary to provide the requested service.
- Secure the service: limit abuse, protect accounts, diagnose errors and keep the API available. This processing is based on the legitimate interest of securing Mazlide and its users.
- Recover an account: send a temporary code to the address associated with the account. This processing is necessary to manage the account.
- Answer requests: provide support, delete accounts and handle data rights requests. This processing is based on the user’s request and, where applicable, a legal obligation.
- Receive player feedback: record ideas, bug reports, feedback and questions voluntarily submitted from the application in order to improve Mazlide and investigate reported problems. This processing is based on the legitimate interest of improving the game.
- Display and measure advertising: present a banner and, only when requested by the player, a rewarded ad granting two bonus coins; measure advertising performance and prevent fraud. Where required by law, advertising processing that requires consent occurs only after the user has made a choice.
- Operate community modes: run the daily challenge, save difficulty ratings and calculate weekly boss contributions, ranks and rewards. This processing is necessary to operate the selected modes.
- Validate Mazlide Premium: verify the purchase with Google Play, permanently activate its benefits on the account and prevent one transaction from being assigned to several accounts. This processing is necessary to fulfil the requested purchase.
Account information is required to create and use a synchronized account. Account creation, developer messages, difficulty ratings and rewarded ads remain optional. Without an account, online features and synchronization are unavailable.
5. Public visibility
The username, certain profile elements, titles and leaderboard results may be visible to other players. The email address, password, IP address and session information are never displayed publicly.
Choose a username that does not reveal your full name, address, phone number or other sensitive information.
6. Recipients and service providers
Data is accessible only to the publisher of Mazlide when required for operation or support, and to Hostinger as the technical provider for hosting, databases and email.
Data is neither sold nor rented. The Android version of Mazlide uses the Google Mobile Ads SDK to display AdMob advertising. In this context, Google and the advertising partners listed in the consent interface may receive and process the technical data described above to deliver and measure ads, provide security and prevent fraud.
For a Premium purchase, Google Play processes the payment and sends Mazlide a purchase token and its status. Mazlide sends this token to the Google Play API solely to verify and acknowledge the purchase. Mazlide never receives payment card details.
Mazlide does not disclose the email address, username, password or progress stored in its own service to Google. Google’s practices are described in its Privacy Policy and advertising information.
Depending on the location of these providers’ infrastructure, some data may be processed outside the user’s country. Where required by law, these transfers rely on the safeguards and contractual mechanisms offered by the relevant providers. Applicable details may be requested from support.
7. Retention periods
- The account, profile, progress, friend relationships and gameplay history are retained for the lifetime of the account.
- Friendly duel invitations expire after 90 seconds. Their technical status may be retained with the account history to maintain service consistency and security.
- Premium status and technical purchase references are retained for the lifetime of the account and as long as needed to prove and restore the purchase and prevent fraudulent attribution.
- An active session token expires no later than 30 days after creation. Associated technical data may be retained for the lifetime of the account for security and is deleted with it.
- Password reset codes expire after 10 minutes. Only their cryptographic hashes are stored, and expired or used requests are removed from the service.
- Anti-abuse limitations are retained for the time required by their security window and attack-prevention purpose.
- Messages sent to the developer from the application and support conversations are retained while they are being handled, then for no more than three years if follow-up or evidence is necessary. They are deleted earlier if the associated account is deleted.
- When a rewarded ad is validated, Mazlide may retain the bonus coin award, the unique AdMob transaction identifier and the technical elements needed to prevent duplicate awards for the lifetime of the account. Unvalidated temporary requests expire after 30 minutes and are removed from the service.
Residual copies may remain temporarily in technical backups until their normal rotation. They are not used for any other purpose and are used only to restore the service after an incident.
Data processed directly by Google is retained according to the periods and criteria described in Google’s retention policy.
8. Security
Communications with the API use HTTPS. Passwords are hashed using the secure algorithm provided by PHP. Session tokens, recovery codes and game tokens are stored on the server only as hashes. On Android, the sign-in token is stored in the system’s secure storage. Access to the hosting environment and database is restricted.
No system can guarantee absolute security. If an incident presents a risk, the required measures and notifications will be implemented.
9. Local storage and tracking technologies
Mazlide uses strictly functional local storage to remember preferences, cached campaign progress and recent official-level and duel history. Duel history may contain both players’ usernames. This information remains on the device and is not used to track the user across different applications or websites.
On Android, Google’s consent management platform is used to collect and remember advertising choices for affected users in the EEA, the United Kingdom and Switzerland. These choices can be changed from Mazlide’s privacy settings.
If consent is given, AdMob may use identifiers and other information to personalize and measure ads. If consent is refused, Mazlide does not request personalized advertising; depending on technical availability and the recorded choices, a limited ad may be shown or no ad may be available. Certain data required for transmission, security and fraud prevention, such as the IP address, may still be processed.
These Web pages use no advertising, personalization or audience measurement cookies.
They use browser local storage only to remember the selected language. This preference is not sent to the server and cannot be used to track browsing activity.
10. Your rights
Subject to applicable law, you may request access to, correction, erasure or portability of your data, restriction of processing, or object to processing based on legitimate interests.
Email support-mazlide@gauthierpl.com from the address associated with the account. Reasonable identity verification may be requested, but you will never be asked for your password or a recovery code.
You may also lodge a complaint with the data protection authority competent for your situation, including the CNIL where it is competent.
Advertising choices can be changed from Mazlide, and the advertising ID can be reset or deleted in Android settings. For data processed directly by Google, Google’s own controls and request mechanisms are also available through its Privacy Policy.
11. Account deletion
The account and its associated data can be deleted directly in the application or through an external request if the application is no longer accessible.
12. Children
Mazlide is not specifically designed or marketed as a service for children. A minor user must seek help from their legal representative where required by applicable law.
13. Changes to this policy
This policy will be updated if Mazlide’s features, providers or practices change. The update date will appear at the top of this page.