We have a sustainable business model and are not too far from profitable with 16 employees.
We also have an API and will make it very easy for developers to download all the data if they ever want it. Openfeint is unfortunately not allowing that at all.
This URL: http://www.heyzap.com/api/v1/users/search?q=mike
Allows me to anonymously see numerous (limited by # of results) users records.
When I choose one from the list and go to this URL: http://www.heyzap.com/api/v1/users/mike_midkiff/activity
I see all of Mike Midkiff's info. All the games he has, WHERE he played (are you f'in kidding me??????), HOW MUCH he paid, and even his unique ID.
hackers, wake up. Bad engineering is bad.
Only the developer whose game Mike bought should be able to request his information, and ONLY relative to that developers game.
Hell. If someone gets mad at him in game, they can use YOUR API to track him down and beat the crap out of him.
Nice.
Edit: Location is optional (based on user) and we only give city level with a truncated Lat/Long. Again this is the same as twitter/instagram etc.
I wasn't missing the point. OpenFeint was built on the backs of indie developers, and they sold out and didn't protect the indie developer. Okay, so selling out isn't so bad, but why then make the developers do all the work to get compatibility when THEY were the ones that made you rich?
Except with Twitter and Instagram, I need to authenticate to get the information about WHERE an action occurred, so at least there's a trail.
With your implementation, I can scan all my competitors users with public profiles (at the very least) and see who's buying what.
If this is a transparency play, then say that and make a stink about it. But when Mike gets the crap kicked out of him, also step up and cover his medical bills.
Edit: Okay.. so the location IS truncated, kudos. Why is this an unauthenticated API?
I fail to see your point. I could also just go here http://www.heyzap.com/profile/mike_midkiff and scrape for the same data.
HeyZap didn't build the games that power them, the developers did. HeyZap, in releasing information such as installs, etc., to unauthenticated API calls is saying "This is HEYZAP's data".
It's not. It's the developers data too.
Without that developers game, you'd have NO data, and each player is a customer of the developer once they buy the game. They're not just HeyZap's users, they are paid customers of that developer.
Treat your developers businesses with respect and limit information to the developer and let them decide if they want to release it.
It seems like twitters API is just authenticated because they want control over the apps that access use it, and not expressly for user's privacy.
For example, this trends map (http://trendsmap.com/) is presumably based on twitters API, has location data, and is open for anyone to access.
http://www.heyzap.com/api/v1/games/Kqh-bubble-shoot
{ "game": { "checkins_count": 876134, "developer_name": "RUNNERGAMES", "activity_url": "http://www.heyzap.com/api/v1/games/Kqh-bubble-shoot/activity, "android_package": "com.game.BubbleShoot", "tips_and_questions_count": 773, "checkins_url": "http://www.heyzap.com/api/v1/games/Kqh-bubble-shoot/activity..., "description": null, "players_count": 52612, "questions_url": "http://www.heyzap.com/api/v1/games/Kqh-bubble-shoot/activity..., "web_url": "http://www.heyzap.com/game/Kqh-bubble-shoot, "players_url": "http://www.heyzap.com/api/v1/games/Kqh-bubble-shoot/players, "url": "http://www.heyzap.com/api/v1/games/Kqh-bubble-shoot, "tips_url": "http://www.heyzap.com/api/v1/games/Kqh-bubble-shoot/activity..., "thumbnail_url": "http://d2ruqtjkg8og7r.cloudfront.net/mobile_game_icon_com.ga..., "name": "Bubble Shoot", "id": "Kqh-bubble-shoot", "android_price": "Free" } }
AND if I go HERE, I can see ALL the checkins with their locations, again without authentication: http://www.heyzap.com/api/v1/games/Kqh-bubble-shoot/activity
{ "activity": [ { "type": "checkin", "like_count": 0, "message": "", "comment_count": 0, "created_at": 1353111191, "user": { "display_name": "emil", "profile_image_url": "http://www.heyzap.com/legacy/images/users/default_user_photo..., "web_url": "http://www.heyzap.com/profile/emilgousfendi, "url": "http://www.heyzap.com/api/v1/users/emilgousfendi, "username": "emilgousfendi", "id": "emilgousfendi" }, "location": { "truncated_longitude": 106.963, "city": "Bekasi", "truncated_latitude": -6.356, "country": "ID" }, "updated_at": 1353111191, "id": 192146287, "time_ago": "just now", "game": { "android_package": "com.game.BubbleShoot", "web_url": "http://www.heyzap.com/game/Kqh-bubble-shoot, "url": "http://www.heyzap.com/api/v1/games/Kqh-bubble-shoot, "thumbnail_url": "http://d2ruqtjkg8og7r.cloudfront.net/mobile_game_icon_com.ga..., "name": "Bubble Shoot", "android_price": "Free", "id": "Kqh-bubble-shoot" } },
...
They can't tell you that their servers will be compromised, and all your users will be open game. They can't promise you that they won't bring in a CEO that just wants to get the company sold, and doesn't care about the developers or their customers.
They can't tell you that when they pivot, all your games will be busted. Not because they're hiding this gem from you.
It's simply because they don't know it.
When you roll your own, you know it's going to survive because YOU are responsible for it.
No BS politics are going to force you down an ridiculous migration path you don't already know about, and since YOU are the CEO, you can sell out and not worry about screwing companies who are dependent on your product or service.
Even IF you choose to use a third party, you owe it to yourself to write your own and mirror that data on to yours so that when, not IF, they go down or out, you can flip a switch and you're back in business within seconds, not days.
The deal with GREE stinks of potential currency manipulation, IMHO, and I wouldn't put my livelihood in their hands for one minute. Again, not because they're bad people - I don't know them from Adam, but because they've already shown that they're willing to allow the customer, we developers, to do ALL the work to satisfy THEIR migration to their API instead of requiring OpenFeint to develop a transparent proxy layer and make it turnkey.
Don't indie developers have enough to do already?