Privacy policy
Last updated 4 September 2026
Stridefall is a walking game. It needs your step count to work, and it needs an account if you want your progress backed up. This page says exactly what we collect, why, where it goes, and how to get rid of it. It is written to be read, not skimmed past.
Who we are
Stridefall is published by Mandooist, based in Australia. We are bound by the Australian Privacy Act 1988 and the Australian Privacy Principles. If you are in the United Kingdom or the European Union you also have the rights described under "Your rights" below.
For anything about this policy you can reach us by email at support@stridefall.com.
What this covers
The Stridefall app for Android (and iOS, when it ships), and this website,stridefall.com. It does not cover other services you choose to connect to the game, such as Strava, which have their own policies.
The app
Playing without an account
You can play without signing in. Your save then lives only on your phone, in the app's private storage, and nothing about your play leaves the device except as described under "Step data" below. Uninstalling the app deletes it.
Your account
If you create an account we collect your email address and a password. Sign-in is handled by Firebase Authentication, a Google service. Firebase stores your password as a salted hash; we never see it and cannot read it. We use your email address to identify your account, to let you reset your password, and to answer you when you contact us. We do not send marketing email to app accounts.
Your cloud save
With an account, the game backs up your save to Google Cloud Firestore so you can restore it on another phone. The save is your whole game state: character, levels, inventory, quests, settings, and the running step totals the game has counted. It is written when the app goes into the background and when you tap "Back up now" in Settings. Only your own account can read or write your save; that is enforced by server rules, not by the app.
Step data
Steps are the currency of the game, so with your permission the app reads your step count from the health platform on your phone: Health Connect on Android, and Apple's Motion framework on iOS. It reads step counts and nothing else. No routes, no location, no heart rate, no sleep, no other health record.
The counts are turned into game progress on your phone. The raw records stay in the health platform; what the game keeps is the total it has spent, which becomes part of your save and, if you have an account, of your cloud save. We use step data only to run the game. We do not sell it, share it, use it for advertising, or use it to make decisions about you outside the game. This is a condition of Google's Health Connect policy as well as a promise of ours.
You can withdraw the permission at any time in your phone's Health Connect or Motion settings. The game keeps working; it just stops counting.
Fair play records
Because the game runs on your phone, it cannot prove a step count is genuine. To keep races and leaderboards honest we keep a server-side record of how each account's step total has moved over time, timestamped by our servers rather than by the phone. Only our own tools can write or read it. It contains totals and times, not individual steps or locations. It exists to spot tampering and for no other purpose.
Strava (optional)
Some in-game races can be completed with real runs. If you choose to connect Strava, the game asks Strava for permission to read your activities, and then reads only what it needs: the activity type, distance, moving time and start date of runs inside a short window around the race. Strava's access tokens are stored on your phone. The one server step, exchanging Strava's sign-in code for a token, runs on a Cloudflare Worker we operate and keeps Strava's client secret off your device. You can disconnect Strava in Settings at any time, and revoke the game's access from your Strava account. Strava's own privacy policy applies to Strava.
Messages from us
We can leave a message in your account's in-game mailbox, for example to hand you an item after a bug. These are written only by our own tools and can be read only by your account.
Notifications
Reminders are scheduled on your phone by the app itself. We do not use a push service and the app does not send a push token anywhere.
What the app does not do
- No analytics or usage-tracking SDK.
- No advertising and no ad network.
- No location, contacts, camera or microphone access.
- No crash reporting service. If we add one we will name it here first.
- No sale of personal information, ever.
This website
The site is static and sets no cookies. It has no analytics. It is served by Cloudflare, which keeps ordinary server logs (your IP address, browser and the pages requested) for security and operations under its own policy.
If you sign up to hear about the launch, your email address is stored byButtondown, who send the email on our behalf. It is used for that and nothing else. Every email has an unsubscribe link, and unsubscribing deletes the address from the list.
Who else sees your data
| Service | What for | What they hold |
|---|---|---|
| Google (Firebase Authentication, Cloud Firestore) | Accounts and cloud saves | Email address, password hash, your save, fair play records, mailbox |
| Cloudflare | Hosts this site and the Strava sign-in step | Server logs |
| Strava | Only if you connect it | Your Strava account, under Strava's policy |
| Buttondown | Launch mailing list, only if you sign up | Email address |
These providers store data in data centres that may be outside Australia, including the United States. We choose providers that commit to protecting personal information to a standard at least equivalent to the Australian Privacy Principles.
How long we keep it
Your account, cloud save, fair play records and mailbox are kept for as long as the account exists. When you delete your account, all of it is deleted within 30 days, including from backups. Theaccount deletion page explains how. Newsletter addresses are kept until you unsubscribe.
Your rights
You can ask us what personal information we hold about you, ask us to correct it, and ask us to delete it. We answer within 30 days. If you think we have mishandled your information you can complain to us first, and to the Office of the Australian Information Commissioner at oaic.gov.au. If you are in the UK or EU you have the additional rights the GDPR gives you, including to object to processing and to take your data with you, and you can complain to your local supervisory authority.
Children
Stridefall is not directed at children under 13 and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us and we will delete it.
Security
Everything between the app and our providers travels over TLS. Cloud saves are protected by server-side rules that let only the owning account touch them. No system is perfectly secure, and if we learn of a breach affecting your information we will tell you.
Changes
If we change what we collect or why, we will update this page and the date at the top, and for a material change we will tell you in the app before it takes effect.
Contact
You can reach us by email at support@stridefall.com.