← Blame the Button

AMALGYTE · UPDATED 8 SEPTEMBER 2026

Your game.
Your information.

This notice covers the Blame the Button game. It is currently in private testing; public store downloads and rewarded ads are not yet available. The website privacy notice explains this site and invitation links.

Who looks after your information

Blame the Button is operated by Simon Johnson trading as Amalgyte, the controller of the game information described here. Contact blamethebutton@amalgyte.co.uk for privacy questions or requests. Never email your password, recovery code or payment-card details.

The game is intended for people aged 13 and over. Optional rewarded advertisements are for adults aged 18 and over. We do not sell your information or use it for resale.

The short version

We save your player identity and progress so the shared game works and you can recover your account. Your chosen identity and some game actions are public. A location is optional and private. Background photos stay on your device. A custom button image is uploaded only when you submit it for moderation; an approved image is shared in the community collection. Notifications are optional and off by default. Optional usage analytics and crash reporting are available only to adults aged 18 and over, with separate opt-ins. Advertising is optional too.

Your private age range

We ask for an age range: under 13, 13–17, or 18 and over. We store the range and when you saved it, not your date of birth. It stays private and follows your account when recovered. It controls age-appropriate access, including adult-only ad rewards. An under-18 answer can be reviewed after a year; contact support if a saved answer is incorrect. Age-range data is included in your account export and removed when the account is deleted. This is an age declaration, not identity-document verification.

Your account and the shared game

The service assigns a random account identifier and stores your chosen public identity, account credentials, recovery-code hash, game decisions, predictions, coins, collection, achievements, referrals, squad membership and safety reports. This lets us run a consistent shared game, restore progress, prevent duplicate rewards and handle abuse.

Your saved identity is unique and cannot be renamed in the profile. A recovery code restores the original account and identity. Credentials are protected using the device's secure storage; the service stores hashes of recovery secrets. If you choose to link an email login, Firebase handles that login and we keep its account reference. You do not need to use your real name as your player identity.

Your identity can appear alongside a press, resist, historical cycle or approved community design. Referrals use a shareable code to credit a qualifying new account once; your profile shows how many referrals joined. Sharing is voluntary. Anyone receiving a link can forward it.

Optional location and photographs

You can leave your location blank, choose only a country, or enter a region and locality. These details are returned to your authenticated account and data export, not included in public game messages, community designs or stream statistics. We do not request GPS permission or track your precise location. Avoid entering a street address, school or other identifying details.

A private background is selected through the system photo picker or camera. Camera access is requested when you choose that option. We do not upload background images. They are held in the app's account-scoped device cache, which you can clear or replace and which the operating system may remove. Account recovery does not transfer the image to a new device.

A private custom-button crop also stays on your device until you choose to submit it. Submitted images are re-encoded to remove ancillary metadata and stored for moderation. Pending or rejected images are accessible to their creator and authorised moderators. Approval makes the fixed image and your player identity available in the community collection. Reports and moderation decisions are recorded. Only submit pictures you have permission to share; do not include private information about other people. Removing a design or deleting its creator removes community access and refunds the community coin purchases.

Optional services and advertising

Notifications use a device push token and time zone to deliver requested messages and respect quiet hours. Usage analytics and crash reporting help diagnose and improve the game when an adult account opts in. Under-18 and unknown-age accounts cannot enable either service. The two choices belong to the current account on this device; another device requires a new opt-in, and account recovery or switching suspends collection until the restored account is checked. We do not add your player name, email, photos, chosen location or recovery secrets to analytics events. Each preference can be changed in Settings.

If an adult chooses a rewarded ad, Google AdMob processes an ad request and relevant device/network information. The app requests non-personalised ads, which still involve data processing. The consent screen explains the available choices; ad privacy choices are accessible in Settings. Declining an ad does not stop you playing.

Our server uses an opaque reward reference, provider transaction identifier, amount and completion time to check a completed reward and prevent duplicate coins. Your public identity, chosen location and images are not included in that reward reference. Google's handling of advertising data is explained in Google's partner-services notice.

When store purchases become available, Apple or Google processes payment. We receive transaction/ownership information needed to verify, restore or refund items, not payment-card details. Coins are game items and have no cash value.

Service providers and operational statistics

Cloudflare hosts the game server, its database and submitted images. Firebase provides native app verification and configured login, notification, analytics and diagnostic services. Hostinger hosts the game website and support mailbox. These services receive relevant account, device or network information needed for their functions. Authorised moderators see the information needed to review images and reports. Public stream displays use aggregate counts, not lists of connected accounts or private locations.

Operational statistics record account presence by hour, active-player samples and press/resist/timeout events. These support day, week, month and year statistics and are separate from optional Firebase analytics. These providers can process information outside the UK. Firebase Authentication operates in the United States; other Firebase services use global infrastructure. Google's published safeguards include the UK Extension to the EU–US Data Privacy Framework. Cloudflare and Hostinger publish contractual transfer safeguards using standard contractual clauses and the UK Addendum where applicable. You can ask us for information about the safeguards and copies of relevant terms. See Firebase's processing information, Cloudflare's data-processing terms and Hostinger's data-processing terms.

Why we use it

We rely on performance of our agreement with you for the account and progress needed to provide the game you request. We rely on consent for optional usage analytics, crash reporting and advertising processing that requires consent. Our legitimate interests are protecting the service, keeping rewards fair, moderating content, understanding operational game activity and answering support enquiries. Where we must process information to comply with a legal obligation, including applicable privacy-rights requirements, that obligation is our basis. Optional location and image submission are choices; they are not needed for ordinary play. We do not use personal data to make a decision producing legal or similarly significant effects solely by automation. Game selection and reward calculations are game mechanics; integrity checks can prevent a session from connecting. Contact support to ask for a review of an account restriction.

Keeping and deleting information

Account information is retained while needed to provide your account and progress. Settings offers an account export and deletion. Deletion revokes game sessions, removes identity/location and progression records, removes presence records and queues deletion of uploaded images and linked sign-in data. Provider outages may delay queued cleanup. Public-facing history replaces the deleted player's displayed name. Restricted security or transaction records can require separate retention for disputes, fraud prevention or legal obligations.

The current operational presence and active-player samples expire after up to 400 days. Push delivery records expire after 7 days and inactive push registrations after 90 days; disabling notifications removes the registration. Local photographs remain until replaced, removed, account deletion on that device or cache removal. An unlocked background entitlement can be restored independently of its photograph.

The publisher-approved release schedule removes raw troubleshooting events and rejected or revoked image files after 30 days, and expired image metadata, resolved moderation reports and eligible operator audit/configuration history after 180 days. Operational activity is retained for 400 days to support the yearly dashboard. Open moderation cases and unfinished deletion requests remain until resolved. Active account balances, collections and recovery data remain until account deletion; the shared cycle archive is game history with deleted identities redacted.

Firebase publishes separate provider retention periods: Authentication deletion can take up to 180 days across live and backup systems; Crashlytics retains crash information and associated identifiers for 90 days before beginning removal. Google Analytics user and event retention is set to two months, with renewal on new activity switched off. These controls do not limit most standard aggregate reports. Analytics deletion controls operate separately from the game database. Contact us about information already sent to these providers; switching off a local preference does not recall a completed upload.

Removal is processed in scheduled batches and may be delayed during an outage or backlog. Cloudflare's database recovery copies can remain within its 30-day recovery window; a restoration must reapply account deletions before reopening the game. Local exports and support correspondence require separate owner-managed review. This does not promise immediate removal from every copy or describe pseudonymous records as anonymous.

Your choices and rights

Use Settings to export or delete your account and manage optional services. You can contact us to request access, correction, deletion, restriction or portability where applicable. You can object to processing based on legitimate interests, and withdraw consent without affecting processing that was lawful before withdrawal. The permanent-name game rule does not remove your data-protection rights; contact us about information that needs correcting. We may need proportionate confirmation that a request concerns your account.

You can complain to the UK Information Commissioner's Office or your local data-protection authority. We will update this notice when relevant processing changes and explain changes that affect your choices.