Monash Mosaic

Privacy Policy for Disinformer

Last updated: 2 September 2026

This Privacy Policy explains how Monash Mosaic (“we”, “us”, or “our”) collects, uses, stores, and protects information when you use the Disinformer mobile application (“Disinformer” or the “App”).

1. Information We Collect

Player profile information

When a player is registered in the App, we may collect:

  • A username chosen by the player
  • The player’s selected IFRC National Society
  • A selected in-game avatar
  • Player creation and last-played timestamps

Users should not use their real name or include sensitive personal information in their username.

Gameplay information

We may collect information generated while the App is used, including:

  • Scores and points
  • Number of games played
  • Game roles and results
  • Elimination status
  • Selected topics and game settings
  • Game start and end times
  • Number of rounds and players
  • Survey responses and records of completed surveys
  • Randomly generated game or group identifiers

This information is used to operate the game, maintain player statistics, display leaderboards, evaluate gameplay, and improve the App.

Analytics and technical information

We use Google Analytics for Firebase to understand how the App is used and to identify performance or usability issues. Analytics information may include:

  • App opens and interactions
  • Gameplay events and selected features
  • Session and game identifiers
  • Device type and model
  • Operating system and App version
  • App installation or instance identifiers
  • General regional information derived by the analytics provider
  • Other diagnostic and usage information automatically collected by Firebase

Some analytics events may include a player’s chosen username, such as when recording a survey response.

Disinformer does not request or collect precise GPS location data.

Information stored on the device

Some player and analytics information may be temporarily stored on the user’s device to support offline use, caching, and later synchronisation with Firebase.

2. Information We Do Not Require

Disinformer does not require:

  • An email address
  • A password
  • A phone number
  • Access to the user’s Google Account
  • Precise GPS location
  • Payment or financial information

Disinformer does not use Firebase Authentication. A player profile is identified by its chosen username and is not protected by a password or other identity-verification method.

3. How We Use Information

We use collected information to:

  • Register and identify players within the App
  • Retrieve existing player profiles
  • Operate game sessions
  • Calculate scores and update player statistics
  • Display usernames and statistics on leaderboards
  • Record survey participation and responses
  • Support offline functionality
  • Monitor App usage and performance
  • Investigate errors, misuse, and technical problems
  • Evaluate and improve the game and related educational activities

We do not sell personal information or use it for third-party advertising.

4. Publicly Visible Information

A player’s chosen username and associated gameplay statistics may be displayed to other users or on a public leaderboard.

A selected IFRC National Society may also be displayed where it is relevant to a player profile or leaderboard.

Players should choose a username that does not reveal their real identity or other sensitive personal information.

5. Firebase and Third-Party Services

Disinformer uses services provided by Google LLC, including:

  • Cloud Firestore, to store player profiles, gameplay records, IFRC society options, survey records, and related App data
  • Google Analytics for Firebase, to collect and analyse App usage information

Google processes information in accordance with its applicable terms and privacy practices:

Authorised project personnel may access information where reasonably necessary to operate, maintain, evaluate, secure, or improve Disinformer.

6. IFRC Data Protection

Where applicable to the Disinformer project, information is handled in accordance with relevant project agreements and the IFRC Policy on the Protection of Personal Data.

The IFRC policy is available at:

IFRC Policy on the Protection of Personal Data

This reference does not mean that all Disinformer data is hosted directly by the IFRC. The App currently uses Google Firebase services for its cloud storage and analytics functions.

7. Data Storage and International Processing

The primary production Cloud Firestore database used by Disinformer is configured in a European region.

Google and its service providers may process analytics, technical, or service data in other countries where they operate. Those countries may have data-protection laws that differ from the laws in the user’s country.

8. Data Retention

Player profiles, gameplay records, survey information, and related statistics are retained for as long as reasonably necessary to:

  • Operate Disinformer and its leaderboards
  • Maintain player and game records
  • Support project evaluation and improvement
  • Meet applicable legal, security, contractual, or IFRC project requirements

Firebase Analytics information is retained according to the retention settings configured for the project and Google’s applicable policies.

We may retain aggregated or de-identified information that can no longer reasonably be associated with an individual player.

9. Access, Correction, and Deletion

Users may request access to, correction of, or deletion of information associated with their player profile by contacting:

mosaic@monash.edu

Please use the subject line “Disinformer Data Request” and provide the relevant username and selected IFRC National Society so that we can locate the appropriate record. Do not send passwords, identification documents, or other sensitive information.

Because Disinformer does not use passwords or identity verification, we may need to take reasonable steps to avoid deleting the wrong player record.

Removing a player from a device or uninstalling the App may remove locally stored information, but it may not automatically remove information already stored in Cloud Firestore. Users should contact us to request deletion of cloud-stored information.

Some information may be retained where reasonably required for security, fraud prevention, legal compliance, contractual requirements, or to protect the integrity of aggregated project records. Where possible, retained information will be de-identified.

10. Data Security

We use reasonable technical and organisational measures to protect information handled through Disinformer. Data transmitted to Firebase is encrypted in transit using HTTPS.

Access to project systems and administrative tools is limited to authorised personnel. However, no electronic storage or transmission method can be guaranteed to be completely secure.

11. Children’s Privacy

Disinformer is not intended for children under 13.

We do not knowingly collect personal information from children under 13. If a parent or guardian believes that a child has provided personal information through the App, they may contact us at mosaic@monash.edu to request its deletion.

If Disinformer is offered to younger users through a supervised educational activity, the responsible organisation must ensure that appropriate consent and safeguards are in place.

12. Changes to This Privacy Policy

We may update this Privacy Policy when the App, its data practices, or applicable requirements change.

The updated policy will be published with a revised “Last updated” date. Users should review this policy periodically.

13. Contact Us

For privacy questions, concerns, or data requests, contact:

Monash Mosaic

Email: mosaic@monash.edu