Bloop · DenLabs
Bloop Privacy Policy
Effective and last updated: September 16, 2026
Who operates Bloop
Bloop is a casual game operated by Good Wolf Labs / DenLabs (“Bloop,” “we,” “us”). This policy covers the Bloop Android app (package app.denlabs.bloop) and this public website.
Information Bloop collects
Bloop does not ask Android players for a name, email address, password, contacts, precise location, IMEI, MAC address, or hardware fingerprint. It creates an anonymous player identity to run the game.
The Android app creates a random installation identifier. The Bloop server stores a one-way hash of that identifier, an internal actor ID, and records showing when the installation was created and last seen. The server issues a session credential; only a hash of that credential is stored server-side.
We also store gameplay records needed to operate the game: game-session ID, start and end times, status, score, number of continues, and your best score. The public leaderboard displays the best score with an automatically generated anonymous label such as “BLOOPER 0001.”
Local storage and technical information
In the Android app's WebView, Bloop stores the random installation identifier and current session credential in local WebView storage so the same anonymous player can continue playing after reopening the app. Clearing Bloop's app data removes those local values. Bloop's audited application code does not implement website cookies, product analytics, or crash-reporting services.
Our backend code does not save IP addresses, device identifiers, or user-agent strings to the Bloop database. Like most internet services, hosting, network, and infrastructure providers may process request metadata in their own systems to deliver and secure the service.
Advertising, rewarded ads, and Server-Side Verification
Bloop may offer an optional Google Mobile Ads (AdMob) rewarded ad after a game ends. Choosing not to watch an ad does not stop normal gameplay. If you complete an eligible ad, the reward is one in-game continue.
To protect against invalid rewards, Bloop creates a short-lived reward challenge. Its internal anonymous actor ID and challenge data are supplied to AdMob for the rewarded-ad Server-Side Verification (SSV) flow. AdMob sends a signed verification callback to our server; Bloop records the reward challenge, expiry, whether a reward was granted, and the AdMob transaction ID before granting a continue. Bloop does not rely only on the device's reward callback.
Google Mobile Ads may independently collect or process device, advertising, and ad-interaction information under Google's own policies and available consent controls. Bloop does not control that independent processing. Read Google's Privacy Policy and information about advertising technologies. Where applicable, the app presents Google's consent flow before requesting ads.
How we use and share information
We use the information described above to create and maintain an anonymous game session, save scores, display the leaderboard, prevent invalid score or reward claims, and operate and secure Bloop. We do not use the audited Bloop code to run product analytics.
Third-party services used to provide Bloop include Vercel for hosting, Supabase for the database, Cloudinary for game-image delivery when configured, and Google Mobile Ads when rewarded ads are used. We share information with them only as needed to provide Bloop; their handling of information is subject to their respective policies.
Retention and security
Anonymous identity, session, gameplay, score, and reward-verification records are kept in the Bloop database while needed to operate the game, maintain the leaderboard, prevent abuse, or meet legal obligations. Mobile sessions expire after 30 days; replacing a session revokes the prior active session. When a player uses the in-app deletion flow, Bloop hard-deletes that player's operational records, including rewarded-ad verification and transaction records; no actor-linked fraud or security record is retained by Bloop.
We use access controls, hashed installation and session credentials, HTTPS, and server-side validation designed to protect Bloop data. No method of transmission or storage is completely secure.
Your choices and deletion requests
You can permanently delete your Bloop data in the Android app: open the ⋮ menu, choose Ajustes, then select Eliminar mis datos and confirm the notice. Bloop verifies the active anonymous session, deletes the associated server records, and then clears the local installation ID and session credential. A later installation creates a new anonymous identity.
Read full deletion instructions at bloop.denlabs.app/delete-data. If you no longer have access to the app, you can also request deletion by emailing support@denlabs.app and stating that you want your Bloop data deleted. We may ask for limited information to verify the request and identify the correct anonymous player data. We can delete data only if we can reliably match it to your request.
Children, international processing, and third-party services
Bloop is a general-audience game and is not directed to children. If you believe a child has provided personal information to Bloop, contact us so we can review the request.
Bloop and its providers may process information in countries other than the one where you live. The web-based Telegram Mini App uses Telegram authentication and services; that is separate from the anonymous Android identity and is not used by the Android mobile build.
Changes and contact
We may update this policy when Bloop or its data practices change. The current version will remain available at this URL and its update date will be revised.
For privacy questions or requests, contact Good Wolf Labs at support@denlabs.app.