1. Purpose and Scope
This policy governs how we respond when a public authority asks us to disclose the personal information of a Card Quest player. It applies to every such request, whatever its source: law enforcement, regulators, intelligence or national security agencies, courts, and authorities in any country.
Card Quest is operated by a solo developer. The developer named at the end of this policy is the sole decision-maker for every request and is personally responsible for applying the steps set out below.
2. Definitions
- Public authority: any government body, agency, court, regulator, police force, or intelligence service, in any jurisdiction.
- Request: any demand, order, warrant, subpoena, notice, or informal ask for player personal information, or for the preservation of that information.
- Player personal information: any information we hold that relates to an identified or identifiable player, including platform account identifiers received from Meta, Telegram, Apple, or Google; display names; and gameplay, session, and purchase records.
3. Review of Legality
We disclose nothing until the request has been reviewed. Every request is assessed against the following before any data leaves our systems:
- that it comes from a genuine public authority, verified through official contact channels rather than the contact details supplied in the request itself;
- that it cites a specific legal basis, and that the cited law applies to us and to the data sought;
- that it is properly issued and served, and is valid and current on its face;
- that the authority has jurisdiction over us or over the data, taking into account that player data is held in Singapore by a hosting provider contracted through Australia;
- that responding would not require us to breach another law to which we are subject.
An unverified, informal, or purely voluntary request is refused unless and until it is put on a proper legal footing. Where a request appears legally sound but its scope or basis is unclear, we seek written clarification before responding.
4. Challenging Unlawful or Overbroad Requests
Where a request appears unlawful, invalid, improperly served, or broader than its stated legal basis permits, we will:
- obtain qualified legal advice before responding;
- object to the authority in writing, and seek to have the request withdrawn or narrowed to what the law actually permits;
- pursue available avenues to challenge or set aside the request where it is not withdrawn or narrowed;
- withhold disclosure while an objection or challenge is pending, unless we are legally compelled to produce the data sooner.
We do not treat the cost or inconvenience of objecting as a reason to comply with a request we believe to be unlawful.
5. Data Minimisation
Where disclosure is required, we disclose the minimum necessary to satisfy the request. In practice this means:
- producing only the specific records identified in the request, for only the accounts and date range it identifies;
- never providing bulk exports, whole-database extracts, or standing or ongoing access to our systems;
- preferring our internal pseudonymous player identifiers over platform identifiers received from Meta or other platforms, wherever the request can be satisfied that way;
- redacting unrelated fields and any third-party personal information caught incidentally in the records produced;
- never disclosing credentials, access tokens, or application secrets.
6. Documentation
We keep a written record of every request we receive, whether or not we disclose anything. Each entry records:
- the date received, and the authority and officer making it;
- the legal basis cited and the data sought, with a copy of the request retained;
- the legality review and its outcome, including the reasoning applied and any legal advice obtained;
- any objection or challenge made, and the authority’s response;
- exactly what was disclosed, to whom, and on what date — or that the request was refused or withdrawn;
- who made the decision.
Records are retained for at least seven years and are kept separately from the game’s production systems.
7. Emergency Requests
Where an authority asserts a genuine emergency involving a risk of death or serious physical harm, we may disclose the narrow set of data necessary to address that specific risk without awaiting formal process. Such disclosures are documented under section 6 in the same way, and the emergency justification is recorded.
8. Notice to Affected Players
We will notify a player whose data has been disclosed where we are lawfully able to do so, unless a legal prohibition, a court-ordered non-disclosure obligation, or a genuine emergency prevents it. Where notice is barred only for a fixed period, we will give notice once that period expires.
9. Responsibility and Review
The developer JUDGE GAMES STUDIO is responsible for this policy and for every decision made under it. The policy is reviewed at least annually, and whenever our hosting arrangements, service providers, or legal obligations change materially.
Questions about this policy, and any request falling within it, should be directed to:
Judge Games Studio
UDYAM-PB-10-0168435
India
support.cardquest@gmail.com
See also our Privacy Policy and Terms of Service.