Privacy Policy

Achievements for XBOX — last updated 9 August 2026

Achievements for XBOX is an independent Xbox Live companion app built by Indiesoftware. It shows your achievements, games, friends, captures and messages, and adds communities, reviews, game guides and home-screen widgets on top.

This policy covers every version of the app — the free, ad-supported version and the paid PRO version, and older releases as well as the current one — together with the web pages and backend services behind them. Where a version behaves differently, it is called out explicitly.

The short version

Who is responsible

The data controller is Indiesoftware. For anything in this policy, contact [email protected].

Achievements for XBOX is not affiliated with, endorsed by or sponsored by Microsoft. "Xbox", "Xbox Live" and "Microsoft" are trademarks of their respective owners.

Signing in with your Microsoft account

To show your data, the app needs you to sign in to Xbox Live. That sign-in runs through Microsoft's own login page, loaded inside the app. We never receive, see or store your Microsoft password or your account credentials, and two-step verification is handled entirely by Microsoft.

What comes back is a set of access tokens. They are stored on your device only and used to call Microsoft's APIs directly from your phone. They are never sent to our backend.

Your use of Xbox Live is governed by Microsoft's own privacy statement, not this one.

Data that stays on your device

Most of what the app shows you never leaves your phone. It is stored in a local database and in local preferences so the app works quickly and offline:

None of this is transmitted to us. Uninstalling the app removes it. Clearing the app's storage removes it.

Data we store on our servers

Our backend runs on Google Firebase (Firestore, Realtime Database, Cloud Storage, Cloud Functions). The app signs in to Firebase anonymously — that anonymous identity is not a real account and holds no personal details of its own.

Here is everything we hold, and why:

What Why
Xbox user ID and gamertag To attach the items below to you, and to address notifications to your devices
Community posts and chat messages To deliver them to the communities you post in. Includes text, reactions, quotes, sticker and GIF references, and link-preview cards
Images you attach Message attachments, community images and your profile background. Uploaded only when you pick them
Game reviews Your star rating and review text, shown publicly next to the game
Feedback Feedback you send us, any screenshot you attach to it, and the app version it came from
Favourites The players you marked as favourites, so the list follows you across devices
Push registrations A push token, an identifier for that install, your gamertag and Xbox user ID, the app version and a timestamp — one record per device you signed in on
Community presence A short-lived "online in this community" flag and a "typing" flag, so members can see who is around. Both disappear when you close the community or lose connection
Image generation If you use the image generator in a community message, the prompt you typed and a per-account counter used to keep the feature from being abused
Moderation records Reports you file, and reports filed about your messages, reviews or communities, with a copy of the reported content
Bans If your access to communities has been withdrawn, a record of that, keyed by your Xbox user ID — see Deleting your data

Game catalog corrections carry no identifier at all. When the app notices that a game's name or artwork is missing or wrong, it can send that correction to improve the shared catalog everybody sees. What is sent is the game and the correction — never your Xbox user ID, your gamertag or anything else about you — so those contributions cannot be traced back to you, by us or by anyone.

What is deliberately not there

What other people can see

Achievements for XBOX is partly a social app. When you take part in it, other users can see your gamertag and gamerpic, the community messages and reactions you post, the game reviews you write, images you attach to messages, your profile background if you chose to share it, and whether you are currently active in a community.

Community posts and reviews are visible to other users of the app and are not private messages. Treat anything you post there as public.

Your profile background is private until you share it. Until then it is visible only to you, and other players see nothing in its place.

Community content and moderation

Community content is not reviewed before it is published. Anyone can report a message, a review or a community from inside the app; reports reach our moderation tools and a private moderation channel, and a moderator can delete the content and withdraw the author's access to communities. Deleting a message also removes its stored image attachment.

Our community guidelines set out what is allowed.

When you erase your data, moderation records are anonymized rather than deleted: the identifiers are replaced with [deleted] and the record itself is kept. Deleting them outright would let abuse history be erased on demand; keeping the identifiers would defeat the erasure. Anonymizing satisfies both. A ban is the one record that keeps your Xbox user ID — see Deleting your data for why.

Analytics and crash reporting

Firebase Analytics records which screens are opened and which features are used — aggregate usage, so we know what is worth improving. It records that something happened, never what you typed: a search records that you searched, not what you searched for. Firebase Crashlytics records crashes and errors: the stack trace, device model, OS version, app version and configuration, and the time it happened.

Neither is linked to your Xbox identity. These are switched on for all versions and are used only to keep the app working.

This website

Some of our web pages — the home page, the FAQ, the release notes, the community guidelines and the data deletion page — use Google Analytics to count visits, in a cookieless configuration.

No cookies are set and no identifier is stored in your browser, so there is nothing to consent to and no banner to dismiss. What is recorded is the page you opened, the approximate region it was opened from, the page that linked you here, and the browser and device type. Visits cannot be tied together into a profile, and cannot be tied to you or to your Xbox account.

This page and the child safety standards page are exempt. They carry no analytics of any kind — no counting, no measurement, nothing. Reading a privacy policy, or looking up how to report the abuse of a child, is not something we record.

Advertising free version only

The free version is supported by Google AdMob. AdMob may use your device's advertising ID, your IP address (from which it derives approximate location) and ad interaction data to select and measure ads. That data is handled by Google under its own policies — we do not receive it and we do not build profiles of you.

Consent, if you are in Europe or the UK

If you are in the EEA, the UK or Switzerland, the app asks for your consent before any ad loads and before the ads SDK starts. The dialog is provided by Google's certified consent platform (the User Messaging Platform) and lists the advertising partners involved; nothing is requested until you answer it.

You can change that answer whenever you like, in Settings → About → Ad privacy options. That row also shows what you chose last time, and re-opens the same dialog so you can grant or withdraw consent per purpose.

Refusing does not remove ads — it makes them non-personalised: contextual ads chosen without profiling you. Your decision is stored on your device in the industry-standard format the consent platform publishes, and is passed to Google with each ad request so it is honoured.

Outside those regions no consent dialog is shown, and the row above does not appear.

Wherever you are, you can reset or delete your advertising ID, and turn off ad personalisation, in Android Settings → Privacy → Ads. Doing so does not remove ads; it makes them less targeted.

The PRO version contains no ads: the ads SDK is not even included in the app, no ad request is made, and no consent dialog is ever shown. It does still carry an advertising ID, which Google Analytics for Firebase may read — for analytics only, never for advertising. The controls described above, in Android Settings → Privacy → Ads, apply to it too.

Purchases

Donations, the ad-free upgrade, the separate PRO app and any subscription are sold and processed entirely by Google Play Billing. Payment details, billing address and purchase history go to Google, never to us — we only learn whether an entitlement is currently active, and that is stored on your device rather than on our servers. Manage or cancel subscriptions in the Play Store.

AI-generated content

The app shows AI-written summaries of the community's game reviews. These are generated on our backend by Google Gemini, from the review text and star ratings for that game. Author identifiers are not included in what is sent, and the summaries are produced per game, not per person. Your own reviews are not used to build a profile of you.

The community message composer can also generate an image from a prompt you type. The prompt is sent to OpenAI through our backend, which handles it under its own policies, and the generated image is stored with the message you post it in. The prompt itself is stored so the feature can be rate-limited and moderated.

Notifications and background activity

With your permission, the app sends notifications about new achievements, messages, community activity and friends coming online. Delivery uses Firebase Cloud Messaging, which needs the push registration described above.

To do this the app refreshes in the background and schedules alarms, and a one-off refresh of your game statistics may run as a visible foreground task with a progress notification you can stop. You can turn notifications off entirely in the app's settings or in Android's notification settings; the push registration for that device is removed when you sign out or erase your data.

Links, previews and embedded content

When you paste a link into a community message, the app fetches that page's public preview information (title, description, preview image) so the message shows a card. The preview image is copied to our storage so it stays available. Opening a link takes you to a third-party site that has its own privacy policy and is outside our control.

Searching for a GIF or a sticker sends your search term to Giphy, which handles it under its own privacy policy; the picker is Giphy's own, so what you do inside it is subject to that policy too. Game artwork, gamerpics and achievement icons are loaded directly from Microsoft's servers.

Third-party services

Service Role
Microsoft / Xbox Live Sign-in, achievements, games, friends, messages, captures — privacy statement
Google Firebase Database, storage, functions, messaging, remote config, App Check — privacy & security
Google Analytics for Firebase Usage analytics
Google Analytics website only Visit counts on some of our web pages, cookieless — not on this page or the child safety page
Firebase Crashlytics Crash and error diagnostics
Google AdMob free version Advertising — how AdMob uses data
Google User Messaging Platform free version The advertising-consent dialog and the record of your choice
Google Play services & Play Billing Platform services, integrity checks, purchases — privacy policy
Google Gemini AI review summaries
OpenAI Image generation from a prompt you type in a community message — privacy policy
Giphy GIF and sticker search and picker — privacy policy
Cloudflare Serves and caches our web content and images
Discord Private channel where moderation reports are delivered to the moderation team

Why we are allowed to hold this (legal bases)

If you are in the EEA or the UK, our legal bases under the GDPR are:

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to a use. Write to [email protected] — we answer within 30 days. If you are in the EEA or UK you may also complain to your national data protection authority.

We do not sell personal information, and we do not share it for cross-context behavioural advertising beyond the AdMob processing described above.

Deleting your data

Settings → Account → Delete my data, inside the app. A confirmation naming exactly what goes, and then everything listed above is removed from our servers and the app signs you out. Deletion is immediate — there is no grace period and nothing is archived, though routine infrastructure backups may hold copies for up to 30 days before rotating out.

If you have already uninstalled the app or cannot sign in, email us with the subject "Data deletion request" and your gamertag. Full details are on the delete your data page.

Communities you created. A community nobody else joined is deleted with the rest of your data. One that other members did join is not — that would delete their messages and their space because of your decision. It loses its owner instead: your name is replaced with [deleted] and the community is closed, so nobody can post, react or ask to join. With no new messages possible it drops out of the app after 30 days, and is then deleted outright. Your own messages in it are removed either way, and your name comes off the member list of every community you had joined.

What deletion does not reach:

Retention

Community messages are removed automatically about 30 days after they are posted; they cannot be deleted individually, though a moderator can remove one sooner and erasing your data removes them all at once. Everything else you create is kept until you erase your data. A community left ownerless by an erasure request is deleted 30 days after its last message. Push registrations are removed when you sign out, delete your data, or when the device stops accepting notifications. Crash reports and analytics follow Google's own retention periods. Moderation records are kept for as long as they are useful for moderation, in anonymized form after an erasure request; bans are kept until they are lifted.

Security

All traffic — to Microsoft, to our backend, and to third parties — runs over HTTPS/TLS. Newer backend endpoints verify that requests come from a genuine, unmodified install of the app before doing anything. No system is perfectly secure, and we cannot guarantee absolute security, but we treat anything you entrust to us accordingly.

International transfers

Our backend runs on Google Cloud infrastructure, and data may be processed in the United States and other countries where Google operates. Google's transfer safeguards, including the European Commission's standard contractual clauses, apply to that processing.

Children

The app is not directed at children under 13 (or under 16 in countries where that is the applicable age), and we do not knowingly collect their personal information. If you believe a child has provided us with personal information, contact us and we will remove it. Our child safety standards set out how we handle child safety reports.

Changes to this policy

We may update this policy as the app changes. The date at the top always reflects the current version, and material changes will be announced in the app. Continuing to use the app after an update means you accept the revised policy.

Contact

Questions, requests or complaints: [email protected].