Legal
Privacy Policy
Last updated September 22, 2026
Doomstack (“Doomstack,” “we,” “us,” or “our”) is currently operated as a sole proprietorship based in Florida, USA. This Privacy Policy explains what personal information we collect through doomstack.lol and the Doomstack app (the “Service”), why we collect it, who we share it with, and the choices and rights you have. It’s written to work alongside the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and comparable US state privacy laws. By using the Service, you agree to the collection and use of information as described here.
1. Who we are
Doomstack is a skill-based climbing game: a free endless-climbing game (“Free Climb”) with a public leaderboard, ranked chip duels, and bracket tournaments with cash prizes. We are the “data controller” (GDPR) or “business” (CCPA/CPRA) responsible for the personal information described in this policy. If we form a corporate entity to hold the Doomstack business, this policy will be updated to name it as the operator without otherwise narrowing your rights.
2. Information we collect
Information you give us directly
- Account information — email address, and if you set one, a display name. If you sign up with a password, it is created and verified through Firebase Authentication; we never see or store your plaintext password.
- Public username — if you choose one, we store a unique, user-chosen handle that creates a public creator page at
/c/your-usernameshowing your saved social handles and public climbing record. It’s optional; you can clear it at any time, which removes the page. Choose a username you’re comfortable being public — see Sharing & disclosure. - Google sign-in — if you continue with Google, we receive your name, email address, and profile photo from Google as part of the OAuth flow.
- Guest play — you can play Free Climb without an account via anonymous authentication. This creates a temporary, unlinked identifier with no email or personal profile attached.
- Saved social handles — you can save a handle for a social platform (TikTok, X, YouTube, Instagram, or Twitch), which we show as a link on your public creator page. This is a handle you type — we do not connect to, log into, or access your social account. Saved handles are shown publicly on your creator page — see Sharing & disclosure.
- Payment information — payments (chip purchases and tournament entry fees) are handled by Stripe. We receive confirmation that a payment succeeded, the amount, and a Stripe transaction/session identifier. For chip purchases we store a record (the Stripe session id, amount, and timestamp). Tournament prize payouts are processed via Stripe Connect — winners complete Stripe's onboarding, and we store the Stripe Connect account id and transfer status. We never receive or store your full card number, CVC, or bank details — those go directly to Stripe.
- Age confirmation (chip duels & tournaments) — these features are restricted to users 18 and older. The first time you buy chips or enter a tournament, you confirm you are 18+ and we store the date and time of that confirmation. This is your self-confirmation; we rely on it and do not independently verify your age at that step. If you never use paid features, we don't collect this.
- Chip balance & activity — if you use chip duels, we maintain a non-cashable chip balance for your account and keep a ledger of the entries that change it — chip purchases, stakes, wins, and refunds — with amounts, timestamps, and the related duel. For tournament participants, we store your entry, placement, and prize information. We keep this as a financial and anti-fraud record.
- Correspondence — if you email us or contact support, we keep that correspondence and any information you choose to include in it.
- Native app beta — if you join our native iOS beta, we record that you joined. To enroll you in the Apple TestFlight beta, we share your email address with Apple so it can add you as a tester and send you an invite. Joining is optional.
- Friends, challenges & notifications — if you use our social features, we store the friend requests and friend connections you make, the head-to-head challenges you send and receive, and the in-app notifications we generate about that activity (for example, a challenge or friend request, a duel result, or a tournament update). Other players you add or challenge can see your display name.
Information collected automatically
- Gameplay data — climb runs, peak height reached per category, duel results, and (for ranked runs) a replay token used to verify results.
- Device & usage data — IP address, browser and device type, pages and features used, timestamps, and general (city/region-level) location inferred from IP address, collected via server logs and our hosting/CDN provider.
- Approximate location for eligibility — when you take a paid action (buying chips, entering a tournament), our hosting provider (Vercel) gives us a coarse, IP-derived country and US state/region signal. We use it only to enforce the geo allow-list for paid features. It is an approximation, not precise or GPS-level location. If you don't use paid features, we don't rely on it for this purpose.
- Abuse detection — to deter multi-accounting and manipulation in chip duels and tournaments, we may compare session and device signals. We do not store raw IP addresses for this purpose beyond what is needed for the life of a matchmaking session.
- Session & security identifiers — an authentication session cookie issued by Firebase, and rate-limiting counters (e.g., requests per IP) used to prevent abuse.
- Push notification token — if you install our native app and allow notifications, your device gives us a push token (via Firebase Cloud Messaging) that we store to send you notifications about your games and account. You can turn notifications off in your device settings, which stops delivery and lets us drop the token.
Information from third parties
Beyond Google/Firebase (sign-in) and Stripe (payment confirmation) described above, we do not purchase or receive personal information about you from data brokers or advertising networks.
3. How we use information
- Create and secure your account, and authenticate sign-in.
- Operate the Service: run gameplay, compute and display leaderboard rankings, run chip duels and tournaments (maintaining your chip balance, settling stakes, and processing tournament prizes), and power social features — letting you add friends, send and accept challenges, and receive the related notifications.
- Process payments, maintain the chip ledger, and prevent fraudulent, duplicate, or disputed transactions.
- Enforce eligibility for paid features — confirm the 18+ attestation and apply the geo allow-list — and comply with related legal and anti-fraud obligations.
- Send transactional communications: email verification, password resets, and purchase confirmations.
- Operate our native apps and, if you opt in, send push notifications about game activity (such as challenges, duel results, friend requests, and tournament updates) and run the TestFlight beta program.
- Maintain security, detect and prevent abuse, and enforce our Terms of Service.
- Understand and improve the Service — e.g., which categories or features are used, and where errors occur.
- Comply with legal obligations (tax, accounting, and responding to lawful requests).
We do not use your account email or gameplay data for third-party advertising, and we do not build advertising profiles about you. If we ever add optional marketing emails, they will be opt-in (or you’ll be able to opt out with one click), separate from transactional emails you can’t opt out of while your account is active.
6. Data security
We use administrative and technical safeguards designed to protect your information, including: encryption in transit (TLS/HTTPS) for all traffic to the Service; credential handling delegated to Firebase Authentication rather than storing passwords ourselves; PCI-DSS-compliant payment processing via Stripe, so full card data never reaches our servers; and access controls limiting who can reach production data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and relevant authorities as required by applicable law.
7. International data transfers
We’re based in the United States, and our service providers (Vercel, Firebase/Google Cloud, Stripe, Neon, Upstash, Ably, OpenAI, Apple) process data in the US and, in some cases, other countries where they operate infrastructure. If you’re located in the European Economic Area, the UK, or Switzerland, your information will be transferred outside of those regions. Where required, we rely on our providers’ own compliance mechanisms for cross-border transfers (such as Standard Contractual Clauses) to protect that data. Contact us if you’d like more information about a specific transfer.
8. Data retention
We keep account information for as long as your account is active, plus a reasonable period afterward in case you return or to resolve disputes, and as needed to meet legal, tax, or accounting obligations (typically up to 7 years for financial records related to payments). Chip-purchase records, the wallet ledger, tournament entry and prize records, and your 18+ confirmation are treated as financial and compliance records and are retained on that same basis even after your account is closed, to the extent needed to meet legal, tax, accounting, and anti-fraud obligations.
Your peak climbing height is, by design, a lasting competitive record. If you delete your account, we will delete or de-identify your personal information (email, display name), but historical leaderboard rank/height data may be retained in de-identified or aggregated form as part of the Service’s competitive record.
9. Your rights
Depending on where you live, you may have the right to: access the personal information we hold about you; correct inaccurate information; delete your information; receive a portable copy of it; restrict or object to certain processing; and, under CCPA/CPRA, to know, delete, correct, and opt out of the sale or “sharing” of personal information (we don’t sell or share it for advertising, so there’s nothing to opt out of today) and to non-discrimination for exercising these rights.
To exercise any of these rights, email us at hello@doomstack.lol from the email address on your account (or provide enough information for us to verify your identity). We’ll respond within the time required by applicable law — generally within 30 days (GDPR) or 45 days (CCPA/CPRA). You may also designate an authorized agent to make a request on your behalf. If you’re in the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local data protection authority.
10. Children’s privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13, in accordance with the Children’s Online Privacy Protection Act (COPPA). If you believe a child under 13 has provided us with personal information, please contact us at hello@doomstack.lol and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we’ll update the “Last updated” date above and, where appropriate, provide additional notice (such as an in-app notice or email). Continued use of the Service after a change takes effect means you accept the updated policy.
12. Contact us
Questions, requests, or concerns about this policy or your personal information? Reach us at hello@doomstack.lol.