Codex GameHawk is developed and operated by Shinro ("we", "us"). You can reach us any time at contact@shin.ro.
When you sign in with Apple or Google, we create an account identified by a random ID and store the identifier your provider gives us, along with your email address when the provider shares it. To run the service, we additionally store:
Codex GameHawk offers two optional upgrades: Silver Hawk, an auto-renewing subscription, and Golden Hawk, a one-time purchase. Payment is taken by Apple's App Store or Google Play under their own terms and privacy policies. We never receive your name, card or bank details from a purchase.
When you buy, the app sends the store's signed purchase receipt to our servers. We verify it with Apple or Google, then store the purchase reference, product and expiry date against your account so the upgrade applies to that account on every device and on the web. We also pass your random account ID to the store with the purchase, so a purchase can be tied to the account that made it and to no other. Apple and Google send our servers renewal, expiry and refund updates for these purchases, and we check subscriptions with Google periodically, so your tier is kept in step with what you have paid for.
Stored data is used for checking storefront prices for the games you track, notifying your devices about deals, and applying the Hawk tier you have paid for. We do not sell data, share it with advertisers, or use it for profiling. There are no advertising frameworks and no analytics or tracking libraries in the apps.
Each sign-in includes a device attestation (Apple App Attest on iOS, Google Play Integrity on Android) that proves to our server that the request comes from a genuine copy of the app on genuine hardware. We verify these tokens and, on iOS, store the public key of the device's attestation identity. This protects the service from abuse; it does not identify you personally.
Our servers keep standard operational logs, which include IP addresses, and apply rate limits keyed to accounts and IP addresses to keep the service available. Logs are used for security and operations only, are deleted after 30 days, and are never linked to any marketing or profiling use.
Both apps use Firebase Crashlytics so crashes can be found and fixed. Crash reports carry the stack trace and device details, and never your credentials, library, or searches. You can turn crash reporting off at any time under Settings → Preferences → Send crash reports.
Price checks, game descriptions, and artwork addresses are fetched from each storefront's public interfaces by our servers using game identifiers only; no account data is included. Game identities are matched across storefronts via IGDB, by title only. Push notifications are delivered by Apple (APNs) and Google (FCM). Cover artwork is loaded from each storefront's own image servers. Purchases are verified with Apple and Google as described in section 4.
The web app at game-hawk.com shows the same account. Signing in there sends a notification to your phone, where you approve the browser in the app. Web sessions are bound to the browser they were created in and expire after 30 days without use. The browser never receives your storefront credentials, because it has none to receive.
Data is kept while your account exists. Settings → Account → Delete account removes your account and everything attached to it, immediately and permanently: wishlist, owned list, alert settings, devices, platform connections, and purchase records. Deleting your account does not cancel a subscription: manage that in your Apple Account or Google Play settings. Sign-in sessions expire on their own after long inactivity, and push tokens for devices not seen in 180 days are removed automatically.
You can also request deletion at game-hawk.com/delete-account, including if you no longer have the app installed.
You may access, correct, or erase your data at any time: most of it directly in the app, and all of it via account deletion or by writing to us. If you are in the EU/EEA, these are your GDPR rights of access, rectification, erasure, and portability, and you may also lodge a complaint with your supervisory authority.
If this policy changes, the new version is published at this address with an updated effective date. Material changes are called out in the app.