Codex GameHawk is developed and operated by Shinro ("we", "us"). You can reach us any time at contact@shin.ro.
When you sign in with Apple or Google, we create an account identified by a random ID and store the identifier your provider gives us, along with your email address when the provider shares it. To run the service, we additionally store:
Stored data is used for exactly one thing: checking storefront prices for the games you track and notifying your devices about deals. We do not sell data, share it with advertisers, or use it for profiling. There are no advertising frameworks and no analytics or tracking libraries in the apps.
Each sign-in includes a device attestation (Apple App Attest on iOS, Google Play Integrity on Android) that proves to our server that the request comes from a genuine copy of the app on genuine hardware. We verify these tokens and, on iOS, store the public key of the device's attestation identity. This protects the service from abuse; it does not identify you personally.
Our servers keep standard operational logs, which include IP addresses, and apply rate limits keyed to accounts and IP addresses to keep the service available. Logs are used for security and operations only, and are never linked to any marketing or profiling use.
The Android app uses Firebase Crashlytics so crashes can be found and fixed. Crash reports carry the stack trace and device details, and never your credentials, library, or searches. The iOS app sends us no crash reports beyond what Apple provides with your consent.
Price checks, game descriptions, and artwork addresses are fetched from each storefront's public interfaces by our servers using game identifiers only; no account data is included. Game identities are matched across storefronts via IGDB, by title only. Push notifications are delivered by Apple (APNs) and Google (FCM). Cover artwork is loaded from each storefront's own image servers.
The web app at game-hawk.com shows the same account. Signing in there sends a notification to your phone, where you approve the browser in the app. Web sessions are bound to the browser they were created in and expire after 30 days without use. The browser never receives your storefront credentials, because it has none to receive.
Data is kept while your account exists. Settings → Account → Delete account removes your account and everything attached to it, immediately and permanently: wishlist, owned list, alert settings, devices, and platform connections. Sign-in sessions expire on their own after long inactivity, and push tokens for devices not seen in 180 days are removed automatically.
You may access, correct, or erase your data at any time: most of it directly in the app, and all of it via account deletion or by writing to us. If you are in the EU/EEA, these are your GDPR rights of access, rectification, erasure, and portability, and you may also lodge a complaint with your supervisory authority.
If this policy changes, the new version is published at this address with an updated effective date. Material changes are called out in the app.