This policy explains what Spark Rush (Chinese name 招招带火花) does with your information. It covers every version of the game: the iOS app, the browser version distributed on portals such as CrazyGames, Poki, GameDistribution and GamePix, and the WeChat and Douyin mini-game versions.
The game is published by Changsha Shengyue Network Technology Co., Ltd. ("we", "us"), a company registered in Hunan, China.
1. The short version
- You do not need to create an account or password. In the WeChat version, the leaderboard uses WeChat's one-time platform login to keep your score together after reinstalling. With your consent, a separate login also supports Tencent advertising attribution described in section 4.
- We do not ask for your name, email address, phone number, or location.
- Your progress is stored on your own device.
- If you use the WeChat leaderboard, our server derives a pseudonymous leaderboard ID from the WeChat login result. Our first-party databases do not store OpenID or session keys; with your consent, a verified OpenID is passed to the Tencent attribution SDK, which maintains its own local cache. If you choose to authorise it in WeChat, we also store your display nickname and avatar for leaderboard display.
- We use limited first-party gameplay analytics to count anonymous users and understand how long each mini-game is actively played.
- We do not sell or rent your data to anyone, ever.
- Advertising is served by the platform you are playing on. Their rules are linked in section 4.
2. What we store on your device
The game saves the following locally (in browser localStorage, or the equivalent
storage on iOS / WeChat / Douyin). This data stays on your device and is not transmitted to us
unless stated otherwise:
- Best scores, levels reached and achievements for each of the 12 mini-games
- Energy count, daily sign-in record, quest progress and Daily Three challenge progress
- Your chosen interface language
- A randomly generated installation ID (for example
u7f3k92ba1cd8) and a randomly generated nickname (for example "Swift Comet 482") - In the WeChat version only, a short-lived leaderboard authentication token and an opaque leaderboard ID returned by our server; neither is your OpenID or WeChat session key
- Whether you have purchased the ad-free full version (iOS only)
Clearing your browser data, or deleting the app, erases all of it permanently.
3. What we send to our own server
Our first-party server is at www.tiaoying2026.com/sparkrush-api. It receives
leaderboard submissions and limited gameplay analytics:
| Field | Example | What it is |
|---|---|---|
| uid | u7f3k92ba1cd8 |
A random installation string created on your device. It is used for anonymous gameplay analytics and, during a one-time WeChat upgrade, can be used to move the scores still on that device to the stable leaderboard identity. It is not linked to an advertising identifier. |
| WeChat login code / rank identity | code… / opaque ID |
In the WeChat version, a one-time wx.login code is sent over HTTPS to our
server. The server exchanges it with WeChat and stores a one-way, pseudonymous leaderboard ID,
score records, and first/last verified authentication times. With your consent, a separate opt-in
response passes OpenID to the Tencent SDK; it is not stored in our databases. Session keys are
discarded and never returned. A short-lived token authenticates leaderboard requests. |
| name / avatar | Swift Comet 482 / WeChat avatar | A random nickname by default. If you explicitly authorise WeChat profile information, your display nickname and avatar are used only to show your entries in the leaderboard. |
| game | panic | Which of the 12 mini-games the score is for. |
| score | 227 | The score itself. |
| event | game_start |
Whether the app or a mini-game was opened, hidden, resumed, or ended. |
| session_id / play_id | s… / p… |
Random identifiers used to join events from the same app session or play session. |
| time and duration | 2026-08-14… / 42000 ms |
Event time and active gameplay duration. Time spent in the background, ads, menus, or result dialogs is excluded where technically possible. |
| gameplay context | wx / release / panic |
Platform, app version/environment, launch scene, mini-game, result, level and score. |
| launch diagnostics | attempt_id / game_ready |
A random launch-attempt ID links lobby display, game selection, loading/readiness, tutorial steps, first gameplay input, result and retry. We record loading latency and predefined failure categories, not touch coordinates, recordings, raw error stacks or free-text query parameters. |
| feature action | daily_skill / duel_start |
Anonymous progress for the Daily Three challenges and friend score duels, such as completing a skill, opening a score challenge, or beating its target. Tapping Share is recorded only as an attempt; we do not receive confirmation that a share was delivered. |
The analytics database does not contain your nickname, avatar, phone number, location, advertising identifier, share ticket, or referrer payload. We do not use tracking cookies or third-party SDKs for these first-party gameplay metrics. The separate Tencent advertising attribution SDK is explained in section 4. Our HTTPS hosting provider may process IP addresses temporarily in ordinary security/access logs, but IP addresses are not written to the gameplay analytics database or used to build player profiles.
4. Third parties, by platform
iOS App Store version
- Google AdMob serves the optional rewarded video ads (you only ever see one if you tap "Watch ad"). AdMob may use an advertising identifier to limit repeat ads and measure performance. On first launch iOS asks for your permission via the App Tracking Transparency prompt — if you decline, ads still work, they are simply less personalised. See Google's policy.
- Apple processes the one-time purchase of the ad-free full version. We never see your payment details — Apple only tells the app whether the purchase succeeded.
Browser versions (CrazyGames, Poki, GameDistribution, GamePix, itch.io …)
- Ads are served entirely by the portal hosting the game, through their own SDK. We receive no advertising data from them and set no advertising cookies ourselves.
- Each portal's own privacy policy governs that advertising: CrazyGames · Poki · GameDistribution · GamePix.
WeChat and Douyin mini-game versions
- For leaderboard continuity after reinstall, the WeChat version sends a one-time
wx.logincode to our first-party server in mainland China to derive a pseudonymous, stable leaderboard ID. Our databases do not store OpenID or session keys. A separate consented SDK login may pass the verified OpenID to Tencent as described below; the leaderboard ID itself is not sent to Tencent or used in gameplay analytics. With your explicit consent, we may also read your WeChat profile nickname and avatar to display your own entries in the friend, all-time and daily leaderboards. You can decline profile authorisation; the game works the same with a generated display name. - The friend leaderboard uses WeChat's open data context. Your friends' avatars and nicknames are rendered by WeChat inside a sandbox that our code cannot read, and are never transmitted to our server.
- Rewarded video ads are served by Tencent's or ByteDance's own ad platform under their respective privacy policies.
- Tencent Marketing Mini-game SDK, provided by Shenzhen Tencent Computer Systems Company Limited, supports advertising measurement, attribution and effectiveness optimisation in the WeChat version. After the SDK disclosure is effective and you consent, it processes device basics (brand/model, system/WeChat/library versions, screen size, performance tier and network type), de-identified user identifiers (including verified OpenID and an SDK-generated local ID), launch scene and advertising click/source parameters, app lifecycle/login/share and actual tutorial-completion events. The SDK sends these to Tencent and maintains its own local identifiers and retry queue. Our integration does not report ad rewards as purchases, and does not report unverified new registrations. SDK processing follows Tencent's SDK privacy rules. Declining initial SDK authorisation leaves gameplay available. SDK receipt/queue diagnostics kept by our wrapper contain numeric codes/counts only. Contact us or Tencent using the policy's privacy channels for data rights requests.
5. Children
Spark Rush is suitable for a general audience and contains no violent, sexual, gambling or frightening content. It is not directed at children under 13, and we do not knowingly collect personal information from children.
The game does not ask a child for direct identifiers. It may send the same limited anonymous gameplay analytics described in section 3. If you are a parent or guardian and want those records removed, contact us with the in-game nickname and we will delete the associated data.
The one-time in-app purchase on iOS can be blocked entirely using Apple's Screen Time → Content & Privacy Restrictions.
6. Where data is stored, and for how long
- Leaderboard records are stored on a server located in mainland China.
- Records are kept for as long as the leaderboard exists, or until you ask us to delete yours.
- Pseudonymous account authentication records (first and last verified login) are kept separately from gameplay events for account continuity and duplicate-registration prevention, until that account record is deleted or the related service ends.
- User-level gameplay events and sessions are retained for up to 180 days. Anonymous aggregate totals that no longer contain a player or session identifier may be retained for longer.
- All data in transit is encrypted with HTTPS/TLS.
- If you play from outside China, leaderboard submissions and the limited gameplay analytics described in section 3 are transferred to and stored in China. The game remains playable without a network connection and displays local scores while offline.
7. Your rights
Depending on where you live, you may have rights under the GDPR (Europe), the CCPA/CPRA (California), or the Personal Information Protection Law (China), including the right to access, correct, delete, or restrict processing of your information, and to withdraw consent.
Because we hold almost nothing about you, most of these are easy to exercise:
- Delete everything held locally — clear your browser data, or delete the app. No request to us is needed.
- Delete your leaderboard entry — email us the nickname; we action it within 30 days.
- Delete gameplay analytics — email us the in-game nickname so we can locate the associated random player ID; we action it within 30 days.
- Opt out of personalised ads — decline the iOS tracking prompt, or use your platform's ad settings.
We do not sell personal information. Consented advertising measurement and attribution involve sharing the information listed in section 4 with the named platform providers. You can contact us to withdraw consent or request restrictions on this processing.
8. Contact
Questions, complaints, or deletion requests:
Email: zhaodadao123456@gmail.com
Publisher: Changsha Shengyue Network Technology Co., Ltd.
Registered in: Hunan Province, China
We reply to privacy requests within 30 days.
9. Changes to this policy
If we change how we handle your information, we will update this page and move the "last updated" date at the top. Material changes will also be announced inside the game. New processing that requires consent starts only after the required notice and consent; continuing to play alone does not authorise the advertising attribution SDK.
本政策说明《招招带火花》(英文名 Spark Rush)如何处理你的信息,适用于本游戏的所有版本: iOS App、发布在 CrazyGames / Poki / GameDistribution / GamePix 等平台的网页版,以及微信小游戏和抖音小游戏版本。
本游戏由长沙晟跃网络技术有限公司(以下称"我们")发行,公司注册于中国湖南省。
一、一句话版本
- 玩游戏不需要注册账号或设置密码;微信版使用平台登录保持卸载重装后的排行榜成绩,经你同意的独立登录还可用于第四节所述的腾讯广告归因。
- 我们不索取你的姓名、邮箱、手机号和位置信息。
- 你的游戏进度存在你自己的设备上。
- 微信版服务器从微信登录结果派生不可逆的伪匿名榜单 ID;第一方数据库不保存 OpenID、session_key。经你同意,验证后的 OpenID 会交给腾讯归因 SDK,SDK 维护独立本地缓存。仅在你主动授权微信资料后,才保存用于榜单展示的昵称与头像。
- 我们使用有限的第一方玩法统计,用于计算匿名用户数和各玩法的实际活跃时长。
- 我们永远不会出售或出租你的数据。
- 广告由你所在的平台投放,各平台的规则见第四节。
二、存在你设备上的数据
以下内容保存在本地(浏览器 localStorage,或 iOS / 微信 / 抖音的对应存储)。除非本政策另有说明,
这些数据不会传给我们:
- 12 个玩法各自的最好成绩、通关进度和成就
- 体力值、签到记录、每日任务进度和“今日三招”挑战进度
- 你选择的界面语言
- 一个随机生成的安装 ID(例如
u7f3k92ba1cd8)和随机昵称(例如"疾风彗星482") - 仅微信版:服务器返回的短期榜单认证令牌和不透明榜单 ID;两者都不是 OpenID 或微信 session_key
- 是否已购买去广告完整版(仅 iOS)
清除浏览器数据或卸载 App,以上内容会被永久删除。
三、会传到我们服务器的数据
第一方服务器地址为 www.tiaoying2026.com/sparkrush-api,用于接收排行榜成绩和有限的玩法统计:
| 字段 | 示例 | 说明 |
|---|---|---|
| uid | u7f3k92ba1cd8 |
在设备上随机生成的安装字符串,用于匿名玩法统计;微信版首次升级身份时,也会仅用于把仍在该设备上的旧成绩迁入稳定榜单身份。不关联广告标识符。 |
| 微信登录 code / 榜单身份 | code… / 不透明 ID |
仅微信版:一次性的 wx.login code 通过 HTTPS 发到服务器。服务器换取登录结果,只保存单向派生的伪匿名榜单 ID、成绩和首次/最近已验证登录时间;经你同意的独立 opt-in 响应将 OpenID 交给腾讯 SDK,第一方数据库不保存它。session_key 丢弃且绝不返回。短期签名令牌用于榜单认证。 |
| name / avatar | 疾风彗星482 / 微信头像 | 默认是随机昵称;只有你主动授权微信资料后,才使用昵称与头像展示你在排行榜中的记录。 |
| game | panic | 这个分数属于 12 个玩法中的哪一个。 |
| score | 227 | 分数本身。 |
| event | game_start | 应用或玩法的打开、隐藏、恢复、结束等状态。 |
| session_id / play_id | s… / p… |
随机生成,用于把同一次应用会话或同一局玩法的事件连起来。 |
| 时间与时长 | 2026-08-14… / 42000 毫秒 |
事件时间和实际活跃玩法时长;在技术可行范围内排除后台、广告、大厅和结算面板停留。 |
| 玩法上下文 | wx / release / panic |
平台、版本/运行环境、启动场景、玩法、结果、关卡和分数。 |
| 开局诊断 | attempt_id / game_ready |
随机开局尝试 ID,用于连接大厅展示、选择游戏、加载就绪、教程、首次玩法操作、结算和重玩。 记录加载耗时及预定义故障分类,不收集触摸坐标、录屏、原始错误堆栈或自由文本查询参数。 |
| 功能操作 | daily_skill / duel_start |
“今日三招”和好友成绩擂台的匿名进度,例如完成一招、打开战书或超过目标分。 点击分享只记录为一次尝试;我们不会收到分享是否真正送达的确认。 |
玩法统计数据库不保存昵称、头像、手机号、位置、广告标识符、分享票据或来源应用附加数据。 这些第一方玩法指标不使用追踪类 Cookie 或第三方 SDK;另行接入的腾讯广告归因 SDK 见第四节。HTTPS 托管服务可能在常规安全/访问日志中临时处理 IP 地址,但 IP 地址不会写入玩法统计数据库,也不会用于建立玩家画像。
四、各平台涉及的第三方
iOS App Store 版本
- Google AdMob 提供可选的激励视频广告(只有你主动点"看广告"才会出现)。 AdMob 可能使用广告标识符来控制重复投放和衡量效果。首次启动时 iOS 会通过 ATT 弹窗征求你的同意, 拒绝也照样能看广告拿奖励,只是广告相关性下降。详见 Google 的说明。
- 苹果处理去广告完整版的一次性内购。我们看不到你的任何支付信息, 苹果只告诉 App"购买是否成功"。
网页版(CrazyGames / Poki / GameDistribution / GamePix / itch.io 等)
- 广告完全由承载游戏的平台通过它们自己的 SDK 投放。我们不从中获取任何广告数据, 自身也不设置任何广告 Cookie。
- 该部分广告适用各平台自己的隐私政策: CrazyGames · Poki · GameDistribution · GamePix。
微信 / 抖音小游戏版本
- 为保持卸载重装后的排行榜成绩,微信版将一次性的
wx.logincode 发到位于中国大陆的第一方服务器,派生稳定的伪匿名榜单 ID。第一方数据库不保存 OpenID、session_key;该榜单 ID 不会发送给腾讯或用于玩法统计。经你同意的独立 SDK 登录会将验证后的 OpenID 交给下述腾讯 SDK。你明确同意后,我们还可能读取微信昵称和头像用于榜单展示;拒绝昵称头像授权时仍可使用随机昵称游玩。 - 好友排行榜和游戏内“超过好友”提示使用微信的开放数据域。好友的头像和昵称由微信在一个我们的代码无法读取的 沙箱里渲染,不会传输到我们的服务器;未授权时不会在游戏过程中反复弹窗。
- 激励视频广告由腾讯或字节跳动自有广告平台投放,适用其各自的隐私政策。
- 腾讯营销小游戏 SDK,提供方深圳市腾讯计算机系统有限公司:用于微信版广告监测、广告归因及广告效果优化。SDK 披露生效且你同意后,会处理设备基础信息(品牌型号、系统/微信/基础库版本、屏幕尺寸、性能档位及网络类型)、去标识化用户标识(包括验证后的 OpenID、SDK 随机本地 ID)、启动场景及广告点击/来源参数,以及使用状态、登录、分享、实际完成新手教程等行为。上述信息发送至腾讯,SDK 维护自己的本地标识与重试队列。当前接入不会把广告奖励上报为付费,也不上报未经确认的新注册。处理规则见 腾讯营销小游戏 SDK 个人信息保护规则。拒绝首次 SDK 授权仍可游玩;我们适配层的回执诊断仅保留数字状态码及次数。你可通过本政策或腾讯政策中的隐私渠道提出数据权利请求。
五、未成年人
《招招带火花》面向一般受众,不含暴力、色情、赌博或恐怖内容,并非专门面向 13 周岁以下儿童, 我们也不会有意收集儿童的个人信息。
本游戏不要求儿童提供直接身份信息,但可能发送第三节所述的有限匿名玩法统计。 若您是家长或监护人并希望删除相关记录,可提供游戏内昵称联系我们,我们会删除关联数据。
iOS 上的一次性内购可以通过苹果的屏幕使用时间 → 内容和隐私访问限制完全关闭。
六、数据存放位置与保存期限
- 排行榜记录存放在位于中国大陆的服务器上。
- 记录保存至排行榜下线为止,或直到你要求删除。
- 伪匿名账号的首次、最近已验证登录时间与玩法事件分开保存,用于账号连续性与防止重复认定注册, 保存至对应账号记录删除或相关服务结束。
- 用户级玩法事件和会话最多保存 180 天;不再包含玩家或会话标识的匿名汇总数据可保存更久。
- 所有传输过程均使用 HTTPS/TLS 加密。
- 如果你在中国境外游玩,排行榜数据和第三节所述的有限玩法统计会传输并存储至中国境内。 游戏在没有网络连接时仍可游玩,离线期间只显示本地成绩。
七、你的权利
根据你所在地区,你可能依据《个人信息保护法》(中国)、GDPR(欧盟)或 CCPA/CPRA(美国加州)享有 查阅、更正、删除、限制处理个人信息以及撤回同意的权利。
由于我们几乎不掌握你的信息,这些权利行使起来很简单:
- 删除本地全部数据 —— 清除浏览器数据或卸载 App,无需联系我们。
- 删除排行榜记录 —— 把昵称发邮件给我们,30 天内处理。
- 删除玩法统计 —— 把游戏内昵称发邮件给我们,以便定位关联的随机玩家 ID,30 天内处理。
- 关闭个性化广告 —— 在 iOS 的追踪弹窗中选择拒绝,或使用所在平台的广告设置。
我们不出售个人信息。经你同意的广告监测、归因涉及向第四节列明的平台提供方共享相应信息。 你可联系我们撤回同意或请求限制此类处理。
八、联系我们
咨询、投诉或删除请求:
邮箱:zhaodadao123456@gmail.com
发行方:长沙晟跃网络技术有限公司
注册地:中国湖南省
我们会在 30 天内回复隐私相关请求。
九、政策变更
如果我们改变处理信息的方式,会更新本页面并修改顶部的"最近更新"日期。 重大变更还会在游戏内公告。需要同意的新增处理仅在充分告知并取得相应同意后开始; 仅继续游玩不代表授权广告归因 SDK。