Privacy Policy

Effective date: September 9, 2026
Codex GameHawk is built so that the sensitive things never reach us: your storefront sign-ins happen on your device and stay there. This policy explains what the service does store (your account identity, the games you track, your alert settings, and a push token), what it is used for, and how to remove all of it.

1. Who We Are

Codex GameHawk is developed and operated by Shinro ("we", "us"). You can reach us any time at contact@shin.ro.

2. What We Store

When you sign in with Apple or Google, we create an account identified by a random ID and store the identifier your provider gives us, along with your email address when the provider shares it. To run the service, we additionally store:

3. What Never Reaches Us

4. How We Use It

Stored data is used for exactly one thing: checking storefront prices for the games you track and notifying your devices about deals. We do not sell data, share it with advertisers, or use it for profiling. There are no advertising frameworks and no analytics or tracking libraries in the apps.

5. App Integrity Checks

Each sign-in includes a device attestation (Apple App Attest on iOS, Google Play Integrity on Android) that proves to our server that the request comes from a genuine copy of the app on genuine hardware. We verify these tokens and, on iOS, store the public key of the device's attestation identity. This protects the service from abuse; it does not identify you personally.

6. Server Logs & Abuse Prevention

Our servers keep standard operational logs, which include IP addresses, and apply rate limits keyed to accounts and IP addresses to keep the service available. Logs are used for security and operations only, and are never linked to any marketing or profiling use.

7. Crash Diagnostics

The Android app uses Firebase Crashlytics so crashes can be found and fixed. Crash reports carry the stack trace and device details, and never your credentials, library, or searches. The iOS app sends us no crash reports beyond what Apple provides with your consent.

8. Third Parties

Price checks, game descriptions, and artwork addresses are fetched from each storefront's public interfaces by our servers using game identifiers only; no account data is included. Game identities are matched across storefronts via IGDB, by title only. Push notifications are delivered by Apple (APNs) and Google (FCM). Cover artwork is loaded from each storefront's own image servers.

9. The Web Companion

The web app at game-hawk.com shows the same account. Signing in there sends a notification to your phone, where you approve the browser in the app. Web sessions are bound to the browser they were created in and expire after 30 days without use. The browser never receives your storefront credentials, because it has none to receive.

10. Retention & Deleting Your Account

Data is kept while your account exists. Settings → Account → Delete account removes your account and everything attached to it, immediately and permanently: wishlist, owned list, alert settings, devices, and platform connections. Sign-in sessions expire on their own after long inactivity, and push tokens for devices not seen in 180 days are removed automatically.

11. Your Rights

You may access, correct, or erase your data at any time: most of it directly in the app, and all of it via account deletion or by writing to us. If you are in the EU/EEA, these are your GDPR rights of access, rectification, erasure, and portability, and you may also lodge a complaint with your supervisory authority.

12. Changes to This Policy

If this policy changes, the new version is published at this address with an updated effective date. Material changes are called out in the app.

13. Contact Us

Questions about this policy or your data:

contact@shin.ro