← xptrackerapp.com

Privacy Policy

Last updated: May 15, 2026  ·  XPTracker Inc.

XPTracker is a real-life RPG game. This policy explains what data we collect, why we collect it, how we protect it, and what rights you have. We keep it plain. If something isn't clear, email us at support@xptrackerapp.com.


1. Who We Are

XPTracker is operated by XPTracker Inc., a corporation incorporated in Ontario, Canada. References to "we," "us," or "our" mean XPTracker Inc. The app is available on iOS (App Store), Android (Google Play), and web (xptrackerapp.com). By using XPTracker you agree to this policy. Privacy questions: support@xptrackerapp.com.

2. Age Requirement

XPTracker is intended for users who are 13 years of age or older. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, contact us immediately at support@xptrackerapp.com and we will delete the account and all associated data.

3. Data We Collect

Account data (when you create an account):

Game data (automatically, as you play):

Public profile data (visible to other users):

Payment data (when you purchase a plan):

Usage analytics (automatically, on all platforms):

Device data (automatically):

4. How We Use Your Data

We do not sell your personal data. We do not use your data to train AI models.

5. Third-Party Services

We share data with the following services only as necessary to operate the app:

We do not share your data with advertisers, data brokers, or any other third parties not listed above.

6. Guild Master Partner Program

Some guild leaders are approved as Guild Master Partners. If you make your first in-app purchase while actively in a guild whose leader is an approved partner, we permanently associate your account with that partner for the purpose of compensating them for bringing you to the app. This association is:

Partners see: a count of attributed users, whether those users have active subscriptions, and aggregate earnings - not names, emails, or any identifying information about individual users.

7. Hall of Heroes - Permanent Data

Special notice: If you choose to "Immortalize" your character and enter the Hall of Heroes, your display name, character class, level, XP, day count, and achievement data become a permanent public record. This record is retained even if you later delete your account. Before immortalizing, you will be asked to give explicit consent to this permanent retention and to our use of this data as described in our Terms of Service (including for physical merchandise). Do not immortalize if you do not consent.

8. Data Retention

9. Your Rights

Depending on where you live, you may have the following rights regarding your personal data:

EU/EEA users (GDPR): Our lawful basis for processing is (a) contract performance for running the game, (b) legitimate interest for analytics and abuse prevention, and (c) explicit consent for Hall of Heroes permanent retention. Data is transferred to the US under Supabase's standard contractual clauses.

California users (CCPA): We do not sell your personal information. The Guild Master Partner association described in Section 6 does not constitute a "sale" under CCPA because no personal data is disclosed to partners. You have the right to know what data we collect and to request deletion.

Canadian users (PIPEDA): XPTracker Inc. is based in Ontario, Canada. Your personal information is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA) and the federal laws of Canada. We collect only the information necessary to provide the service, with your knowledge and consent. You have the right to access the personal information we hold about you and to request corrections. To make a request, email support@xptrackerapp.com. If you have an unresolved privacy concern, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.

To exercise any of these rights, email support@xptrackerapp.com. We will respond within 30 days.

10. Security and Breach Notification

We use Supabase Row Level Security (RLS) to ensure that users can only access their own data. Payment processing is handled entirely by Apple, Google, or Stripe - we never transmit or store payment card data. Financial data (partner earnings, payout records) is accessible only via server-side Edge Functions using restricted keys - no direct client access.

No security system is perfect. If you discover a security vulnerability, please report it responsibly to support@xptrackerapp.com.

In the event of a breach of security safeguards involving your personal information that creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as required by PIPEDA's breach of security safeguards regulations. We maintain a record of all security breaches, whether or not notification is required.

11. Changes to This Policy

We may update this policy as the app evolves. If we make material changes to how we collect, use, or share your personal information, we will notify you via in-app notice or email at least 14 days before the change takes effect, and we will seek your consent where required by applicable law. Non-material changes (such as clarifications or corrections) take effect immediately. The "Last updated" date at the top of this page always reflects the current version.

12. Contact

Questions about this privacy policy:
Email: support@xptrackerapp.com
Website: xptrackerapp.com


© 2026 XPTracker Inc. All rights reserved.