Pickles Save Pickles
‹ Back to home Terms & Conditions
Privacy Policy
Save Pickles — a casual match‑3 mobile puzzle game
Effective date: July 15, 2026
Operator & contact
Operator: Appsgenx, Inc — a For Profit Corporation organized under the laws of Wyoming, USA
Privacy contact & Data Protection Officer: appsgenx@gmail.com
EU representative (Art. 27 GDPR) & UK representative (Art. 27 UK‑GDPR): appsgenx@gmail.com
Support: appsgenx@gmail.com

This Privacy Policy (the "Policy") explains how the Company collects, uses, discloses, retains, secures, and transfers personal information in connection with the mobile game and related services known as "Save Pickles" (the "Game" or "Service"), including the native applications distributed through the Apple App Store and Google Play, any browser‑based version, our supporting websites, servers, and back‑office systems, and any customer‑support, social, or community features (collectively, the "Services"). Please read it carefully, together with our Terms of Service and any in‑Service notices. If you do not agree with this Policy, please do not use the Services.

1. Introduction & Scope

1.1 Who we are

The Company operates the Game "Save Pickles," a casual, animal‑rescue‑themed match‑3 puzzle game. The Company is the "controller" (or, under certain U.S. laws, the "business") responsible for the personal information described in this Policy, except where this Policy states that a third party is an independent controller of certain data (for example, the app stores' own handling of your payment and account data).

1.2 What this Policy covers

This Policy applies to personal information the Company collects and processes when you:

  • download, install, open, or play the Game on iOS or Android via native apps built with a web‑to‑native wrapper (Capacitor), or play any browser‑based version;
  • create or sign in to an optional account, or play offline as a guest;
  • make in‑app purchases or manage subscriptions;
  • use social features (clans, display names, restricted canned chat, gifting of virtual lives, leaderboards);
  • contact our support team or otherwise communicate with us; or
  • visit our marketing or support pages.

1.3 What this Policy does not cover

This Policy does not cover: (a) the practices of Apple, Google, or other platform or device operators, which handle certain data as independent controllers under their own policies; (b) third‑party websites, services, or SDK providers that you access through the Services and that operate under their own privacy policies; or (c) information you choose to make public. Links to third‑party policies are provided in Sections 10, 11, and 27. We encourage you to review those policies.

1.4 Relationship to other terms

This Policy is incorporated into and supplements the Company's Terms of Service. Capitalized terms not defined here have the meaning given in the Terms of Service. Where a region‑specific Appendix (Sections 28–35) conflicts with the body of this Policy, the Appendix controls for residents of that region to the extent required by applicable law.

1.5 Age scope; audience

The Services are intended for a general adult audience and are marketed primarily to adults (in particular, adults aged approximately 35–65). The Services are not directed to, and are not intended for, children under the age of 13 (or, in the European Economic Area ("EEA") and the United Kingdom, under the applicable minimum digital‑consent age, which ranges from 13 to 16 depending on the country). See Section 5. If you are below the applicable age, you must not use the Services or provide any personal information to us.

1.6 Roles under data‑protection law

For most processing described in this Policy, the Company acts as a controller/business that determines the purposes and means of processing. Our vendors act as processors/service providers/sub‑processors that process personal information only on our documented instructions. Apple and Google act as independent controllers for the authentication, payment, push‑delivery, and store‑analytics functions they operate. Where two or more parties jointly determine purposes and means, they may be joint controllers; we will identify any such arrangement and the essence of the arrangement where required.

1.7 How to read this Policy

The main body (Sections 1–27) describes our global practices. The Appendices (Sections 28–35) provide additional, jurisdiction‑specific disclosures and rights and are designed to be read on a stand‑alone basis by residents of the relevant region. A plain‑English FAQ (Section 36) and a Glossary (Section 37) are provided for convenience and do not override the operative text.

2. Definitions

For clarity and consistency, the following terms have the meanings set out below. Where a specific statute defines a term differently for residents of a particular jurisdiction, that statutory definition governs for those residents (see the Appendices). Additional plain‑language explanations appear in the Glossary (Section 37).

TermMeaning
Personal information / Personal dataAny information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. Includes "personal data" under the GDPR/UK‑GDPR, "personal information" under U.S. state laws, and "personal information" under PIPEDA, Law 25, and the LGPD. Does not include lawfully de‑identified, aggregated, or anonymized information.
Sensitive personal information / Special categoriesCategories that receive heightened protection, such as government identifiers (SSN, passport, driver's licence), financial account numbers with access codes, precise geolocation, racial or ethnic origin, national origin, citizenship or immigration status, religious or philosophical beliefs, union membership, mental or physical health, sex life or sexual orientation, genetic data, biometric data processed to uniquely identify a person, account log‑in credentials, and (under some laws) the contents of mail, email, and text messages where we are not the intended recipient. We aim to minimize collection of such data; see Sections 4, 17, and the Appendices.
Processing / ProcessAny operation performed on personal information, whether automated or not, including collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Controller / BusinessThe entity that, alone or jointly, determines the purposes and means of processing. The Company is the controller/business for the personal information covered by this Policy unless otherwise stated.
Processor / Service provider / Sub‑processorAn entity that processes personal information on behalf of, and under the documented instructions of, a controller/business — for example, our hosting, analytics, email, and purchase‑verification vendors. A "sub‑processor" is a processor engaged by another processor.
Third partyAn entity that is neither you, the Company, nor a processor acting on the Company's behalf under contract.
ConsentA freely given, specific, informed, and unambiguous indication of your wishes by which you signify agreement to processing. Consent must be as easy to withdraw as to give.
Legitimate interestsA lawful basis under the GDPR/UK‑GDPR that permits processing necessary for interests pursued by the controller or a third party, except where overridden by your interests or fundamental rights, as assessed in a documented balancing test (a "legitimate interests assessment").
De‑identified dataInformation that cannot reasonably be used to infer information about, or otherwise be linked to, a particular individual or device, and that we maintain and use only in de‑identified form, commit not to re‑identify (except to test the de‑identification), and require recipients to keep de‑identified.
Pseudonymized dataPersonal data processed so it can no longer be attributed to a specific individual without additional information kept separately and subject to technical and organizational safeguards. Pseudonymized data remains "personal data" under the GDPR.
Aggregated dataStatistical or summary information about a group or category of individuals from which individual identities have been removed and which is not linked to any individual.
SDKA "software development kit": third‑party code integrated into the Game that provides functionality (e.g., analytics, crash reporting, messaging) and may itself collect data.
Device identifierAn identifier associated with your device or app installation, such as an Identifier for Advertisers (IDFA), an Android Advertising ID (AAID/GAID), a Firebase installation ID, an app‑instance ID, or a vendor identifier (IDFV).
Targeted / cross‑context behavioral advertisingAdvertising selected based on personal information obtained from your activity across businesses, distinctly‑branded websites, applications, or services other than the one you are interacting with. We do not currently engage in this.
SaleAs defined by applicable law — generally, disclosing personal information to a third party for monetary or (in some states) other valuable consideration. See Section 13.
SharingAs defined by the CCPA — disclosing personal information to a third party for cross‑context behavioral advertising, whether or not for money. See Section 13.
Guest / Guest modePlaying the Game without creating an account, in which progress is stored locally on your device and, unless you later create an account, is not linked to an email address.
Data subject / ConsumerThe identified or identifiable individual to whom personal information relates ("data subject" under GDPR‑style laws; "consumer" under U.S. state laws).
Supervisory authority / RegulatorThe public body responsible for enforcing data‑protection law in a given jurisdiction (e.g., an EU DPA, the UK ICO, a U.S. State Attorney General, the OPC/CAI in Canada, or the ANPD in Brazil).
You / UserThe individual using the Services.
App stores / PlatformsApple App Store (Apple Inc.) and Google Play (Google LLC), and their associated account, payment, push‑notification, and attribution services.

3. Quick Reference Summary

This summary is provided for convenience only and does not replace the full Policy, which controls. It is not a substitute for reading the relevant sections and Appendices.

TopicIn short
Do you need an account?No. You can play offline as a Guest. An optional account (email/password, Sign in with Apple, or Sign in with Google) enables cloud save, cross‑device sync, and social features.
Do you use behavioral advertising?Not currently. We do not use third‑party behavioral advertising SDKs today. We reserve the right to introduce advertising or measurement in the future, with disclosure and, where required, consent (see Sections 10 and 13).
Do you sell my data?We do not sell personal information for money. Certain analytics/attribution activity may constitute "sharing" or a "sale" under some U.S. state laws' broad definitions; you can opt out (see Section 13 and Appendices B–C).
Is the Game for children?No. It is not directed to children under 13 (or under the applicable EEA/UK consent age). See Section 5.
Can I delete my data?Yes. See Sections 15 and 21 and the Appendices for how to request access, deletion, correction, portability, and opt‑outs.
Where is data stored?Primarily on Google Cloud infrastructure (Cloud Run + Firestore), with data processed in the United States and potentially other locations; international transfer safeguards apply (Section 14).
Who can I complain to?Contact us first at the address in Section 26; you may also complain to your local regulator (see the Appendices).

4. Information We Collect

We collect personal information in three ways: (i) information you provide to us; (ii) information collected automatically when you use the Services; and (iii) information we receive from third parties and platforms. We aim to practise data minimization: we collect only what is reasonably necessary for the purposes described in Section 6. The specific data we hold about you depends on how you use the Services (for example, Guests provide less data than account holders).

4.1 Information You Provide to Us

DataDescription / examplesWhen collected
Account credentialsEmail address and password (stored hashed and salted), or an authentication token and associated identifier from Sign in with Apple or Sign in with Google. With Sign in with Apple, you may choose Apple's private email relay.If you create or sign in to an account.
Profile / display informationPlayer display name, chosen avatar/animal, clan name (if you create or lead a clan), and other optional profile settings.When you set up a profile or social features.
Purchase‑related informationRecords that you initiated a purchase or subscription, the product identifier, and the purchase/subscription status returned by the platform. We do not collect or store your full payment‑card number, CVV, or bank details; payment is processed by Apple or Google.When you make in‑app purchases or subscribe.
Support communicationsThe content of your messages to support, your contact details, screenshots you attach, and metadata about the request (e.g., app version, device model).When you contact us for help.
Social contentSelection of pre‑written ("canned") chat messages, directed canned messages to clan members, gifting actions (e.g., sending virtual lives), and leaderboard participation. The Game does not offer free‑text chat.When you use clan/social features.
Survey / feedback / marketing preferencesOptional responses to surveys, feedback, beta sign‑ups, contest entries, and your marketing and notification preferences.If you choose to participate.

4.2 Information Collected Automatically

DataDescription / examplesTypical source / tech
Gameplay & progress dataLevels attempted/completed, scores, stars, lives, in‑game currency and boosters, session length, level difficulty progression, feature usage, and similar telemetry.Game client; backend (Firestore).
Device & app informationDevice model, operating system and version, app version and build, language and region settings, screen metrics, time zone, and (for the web/Capacitor wrapper) browser/user‑agent details.Client; analytics SDKs.
IdentifiersApp‑instance / installation IDs, Firebase installation ID, IDFV, and — only where permitted and, on iOS, only if you grant ATT permission — advertising identifiers (IDFA/AAID). A pseudonymous user/account ID.Client; Firebase; platform.
IP address & coarse locationYour IP address, and coarse/approximate location (e.g., country, region, or city) inferred from your IP address. We do not collect precise GPS geolocation.Network; analytics; server logs.
Diagnostics & crash logsCrash reports, error logs, performance metrics, stack traces, and device state at time of error.Firebase Crashlytics / crash reporting.
Server & security logsRequest metadata, timestamps, endpoints accessed, rate‑limiting and anti‑fraud signals used to detect abuse, cheating, and unauthorized access.Google Cloud (Cloud Run); backend services.
Local storageData stored on your device (e.g., local save files for Guest mode, preferences, cached assets, and web‑storage tokens for the wrapped web app).Device local storage.

Cookies and similar technologies. The native Game generally relies on device/local storage and SDK identifiers rather than browser cookies. Any browser‑based version of the Game, and our websites, may use cookies and similar technologies as described in Section 10.

4.3 Information From Third Parties & Platforms

SourceWhat we may receive
Apple / Google sign‑inA unique identifier, an authentication token, and (depending on your choices) your name and email or a private relay email. Apple's private relay may forward emails without exposing your real address.
App stores & payment verification (incl. RevenueCat, if used)Confirmation that a purchase or subscription occurred, product identifiers, transaction/receipt validation results, subscription renewal/expiration/refund status, and (in aggregate/anonymized form) store analytics. We do not receive your full payment instrument details.
Analytics & attribution providersAggregated or pseudonymous metrics about installs, sessions, retention, and events (see Sections 10–11).
Anti‑fraud / security providers & platform integrity signalsSignals used to detect fraudulent purchases, cheating, bot activity, or abuse.
Other playersIf another player invites you to a clan, gifts you virtual lives, or interacts with you via canned messages, we receive the fact of that interaction and the associated identifiers/display names.

4.4 Master Table — Categories of Personal Information

The following master table maps the personal information we process to the statutory categories used by U.S. state laws (notably CCPA/CPRA). "Collected?" reflects our current practices and may vary by user and over time.

Statutory categoryExamples in our ServiceCollected?Sources
IdentifiersEmail, display name, account/user ID, device identifiers, IP addressYesYou; device; platforms
Customer records (Cal. Civ. Code §1798.80)Name/email in support tickets, purchase recordsYes (limited)You; platforms
Protected classification characteristicsAge band (only as needed for age‑gating); we do not intentionally collect race, religion, etc.LimitedYou (age gate)
Commercial informationPurchase/subscription history, virtual items owned, transaction recordsYesYou; platforms
Biometric informationNo
Internet/network activityGameplay telemetry, feature usage, session data, diagnostics, interactions with the ServiceYesDevice; analytics
Geolocation dataCoarse location inferred from IP (country/region/city). No precise GPS.Yes (coarse only)Network; analytics
Sensory data (audio/visual)Screenshots you voluntarily attach to support ticketsLimitedYou
Professional/employment informationNo
Education informationNo
InferencesInferred preferences/skill/segment for gameplay balancing and product analytics (non‑advertising)Yes (limited)Analytics
Sensitive personal information (CPRA)Account log‑in credentials (email + password). We do not intentionally collect other sensitive categories. Precise geolocation is not collected.LimitedYou

We use account credentials (email/password) as the only routinely collected "sensitive" category, and only to authenticate you and secure your account — not to infer characteristics about you or for advertising. See Section 17 and Appendix B for the CPRA "right to limit" and why it may not apply to this use.

5. Children's Privacy (COPPA, EEA/UK Consent Age & Age‑Appropriate Design)

5.1 The Services are not for children

The Services are intended for a general adult audience and are not directed to children under 13 (United States) or under the applicable minimum age for digital consent in the EEA/UK (which ranges from 13 to 16 depending on the Member State or the UK). We do not knowingly collect, use, or disclose personal information from children under these ages. Our marketing, themes, and features are designed for adults, and we do not use child‑oriented advertising channels to promote the Services.

5.2 COPPA "directed to children" multi‑factor analysis

The FTC's COPPA Rule determines whether an online service is "directed to children" under 13 using a multi‑factor, totality‑of‑the‑circumstances test. We have assessed the Game against these factors and take the position that it is a general‑audience service, not a child‑directed one:

COPPA factor (16 C.F.R. §312.2)Application to "Save Pickles"
Subject matterCasual match‑3 puzzle with a light animal‑rescue theme; puzzle mechanics appeal broadly to adults.
Visual content & art styleDesigned for an adult casual‑game aesthetic, not a cartoon/child‑targeted style intended to attract children.
Use of animated characters / child‑oriented activitiesCharacters serve a rescue theme common to adult casual games; no child‑oriented incentives, mascots, or activities designed to attract children.
Music & audioNeutral casual‑game audio, not child‑targeted.
Presence of child celebrities / celebrities appealing to childrenNone used.
LanguageWritten for adults.
Advertising on the service directed to childrenNo child‑directed advertising is used or accepted.
Intended and actual audience; audience‑composition evidenceMarketed primarily to adults ~35–65; store category, creative, and campaign targeting focus on adults. We monitor actual‑audience signals.
Reliable empirical audience evidenceThe Company will retain audience/marketing evidence supporting the general‑audience determination.

Because we treat the Game as general‑audience, we do not apply COPPA's "actual knowledge" standard by seeking to identify children; instead, we use a neutral age gate (Section 5.4) and act on any actual knowledge we obtain.

5.3 Verifiable parental consent (contingency)

If the Company ever offers a feature that is child‑directed or through which it obtains actual knowledge that it collects personal information from a child under 13, it will first obtain verifiable parental consent ("VPC") using a method reasonably calculated, in light of available technology, to ensure that the person providing consent is the child's parent. Acceptable VPC methods under the COPPA Rule may include, without limitation: (a) a signed consent form returned by mail, fax, or electronic scan; (b) a monetary transaction via credit/debit card or online payment that provides notice of each transaction; (c) a toll‑free telephone or video‑conference call staffed by trained personnel; (d) verification of a government‑issued ID against databases (deleting the ID promptly thereafter); or (e) a "knowledge‑based authentication" or facial‑recognition‑matching method to the extent approved. We would also honour the COPPA "email plus" method only where collection is for internal use. This Section is a contingency; the Company does not currently collect children's data.

5.4 Age assurance / neutral age gate

We use a neutral, non‑incentivized mechanism to discourage under‑age use. Consistent with FTC guidance, our age screen: (a) is presented neutrally and does not encourage users to falsify their age; (b) does not default to an age at or above the threshold; and (c) does not permit users who indicate they are under the applicable age to proceed to registration or data collection. We do not use age data collected at the gate for any purpose other than compliance and safety, and we do not retain it longer than necessary.

5.5 What happens if we learn a child is using the Services — deletion workflow

If we become aware that we have collected personal information from a child under the applicable age without appropriate consent, we will follow this workflow:

Parents or guardians who believe their child has provided us with personal information may contact us at appsgenx@gmail.com to request review, access, and deletion, and to refuse further collection; we will respond consistent with COPPA and other applicable law.

Parental rights (COPPA)

To the extent COPPA applies, a parent or legal guardian has the right, after we verify their identity and relationship to the child, to:

  • review the personal information we have collected from their child;
  • refuse to permit any further collection or use of the child's personal information;
  • direct us to delete the child's personal information; and
  • revoke any consent previously given and withdraw the child from the Service.

We will not condition the exercise of these rights on providing more information than reasonably necessary to verify the request, and we will honour a valid deletion or opt‑out request even if it means the child can no longer use features that require the information.

5.6 Default settings & contact features (avoiding "unfair" designs)

Consistent with FTC enforcement treating certain default settings as "unfair" under Section 5 of the FTC Act, we design the Game so that: (a) chat is restricted to pre‑written ("canned") messages only, with no free‑text or voice communication; (b) we do not place users into direct, real‑time, free‑form contact with strangers by default; (c) we do not publicly broadcast identifying information by default beyond what is necessary for the social features you choose to use; and (d) we avoid manipulative "dark pattern" designs that could nudge users of any age into unwanted data sharing or purchases.

5.7 EEA/UK minimum age & the UK Children's Code

Under the GDPR (Article 8) and UK‑GDPR, the minimum age at which a child can consent to information‑society services is 16, unless a Member State (or the UK) sets a lower age (not below 13). Because the Services are not directed to children, we rely on other legal bases and our age gate rather than child consent. Where the UK Age Appropriate Design Code ("Children's Code") or comparable guidance applies, we adopt its risk‑based, best‑interests‑of‑the‑child principles as design guidance, including data minimization, high‑privacy defaults, and transparency.

5.8 Age‑appropriate design principles (voluntary adoption)

Even though the Services are not directed to children, we voluntarily apply age‑appropriate design principles as a matter of good practice, including: privacy‑protective defaults; data minimization; restricting social contact features to non‑free‑text formats; avoiding manipulative designs; and transparent, plain‑language notices. Certain age‑appropriate‑design statutes (for example, the California Age‑Appropriate Design Code Act) have been subject to litigation and may not be fully enforceable in all respects; we monitor these developments and adjust our practices accordingly.

5.9 Teens (13–17)

Although the Services are marketed to adults, if applicable law affords additional protections to minors under 18 (for example, restrictions on targeted advertising or on the "sale"/"sharing" of a known minor's data, or opt‑in requirements for teens), we will honour those protections for users we know to be minors. We do not knowingly sell or share for cross‑context behavioral advertising the personal information of consumers we know to be under 16 without the required opt‑in consent.

6. How and Why We Use Information

We use personal information for the purposes below. For each purpose, the table identifies the primary GDPR/UK‑GDPR Article 6 legal basis we rely on for users in the EEA/UK (see also Sections 8 and 9). Where we rely on legitimate interests, we have conducted or will conduct a balancing assessment, and you may object as described in Appendix A.

PurposeWhat this involvesLegal basis (GDPR/UK‑GDPR)
Provide and operate the GameLoad levels, save progress, sync across devices, run the core match‑3 experience, and maintain Guest saves.Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interests (for Guests)
Accounts & authenticationCreate accounts, verify identity via email/Apple/Google sign‑in, and secure log‑in.Art. 6(1)(b) contract; Art. 6(1)(f) security
Purchases & subscriptionsEnable and verify in‑app purchases and subscription status; grant virtual items; handle refunds/entitlements.Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation (tax/records)
Social featuresOperate clans, display names, leaderboards, canned/directed messages, and gifting of virtual lives.Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interests
Customer supportRespond to inquiries, troubleshoot, and manage complaints and refunds.Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interests
Analytics & product improvementUnderstand usage, retention, difficulty balancing, and feature performance using GA4/BigQuery and Firebase; develop new features.Art. 6(1)(f) legitimate interests; consent where required for non‑essential SDKs
Diagnostics, crash & performanceDetect, diagnose, and fix crashes, bugs, and performance issues.Art. 6(1)(f) legitimate interests
Security, anti‑fraud & integrityDetect and prevent cheating, fraudulent purchases, bots, abuse, and unauthorized access; enforce Terms.Art. 6(1)(f) legitimate interests; Art. 6(1)(c) legal obligation
Push notifications & messagingSend gameplay reminders, lives‑refilled alerts, event notices, and (where permitted) marketing.Consent (Art. 6(1)(a)) where required; otherwise Art. 6(1)(f)
Marketing (first‑party)Promote features/events by email or push, subject to your preferences and applicable law.Consent (Art. 6(1)(a)); or Art. 6(1)(f) soft opt‑in where permitted
Legal compliance & enforcementComply with law, respond to lawful requests, establish/exercise/defend legal claims.Art. 6(1)(c) legal obligation; Art. 6(1)(f) legitimate interests
Corporate transactionsEvaluate, negotiate, or complete a merger, acquisition, financing, or asset sale.Art. 6(1)(f) legitimate interests
Future advertising/measurement (if introduced)Serve or measure advertising, if we introduce it, with disclosure and, where required, consent.Consent (Art. 6(1)(a)) where required

We will not use your personal information for materially different, unrelated, or incompatible purposes without providing notice and, where required, obtaining your consent.

7. Purchases, Subscriptions & Virtual Items

7.1 How purchases work

In‑app purchases and subscriptions are processed by Apple (App Store) or Google (Google Play), and — where we use it — validated through a subscription‑management provider such as RevenueCat. We do not receive or store your full payment‑card number, security code, or bank account details. We receive confirmation of the transaction, the product purchased, and the subscription/entitlement status, which we use to deliver virtual items, unlock content, and provide support.

7.2 Subscriptions, renewals & cancellation

Subscriptions may renew automatically until cancelled. You manage, and can cancel, subscriptions through your Apple or Google account settings; cancellation and refund mechanics are governed by the applicable app store. We aim to present pricing, renewal terms, and cancellation paths clearly and without manipulative "dark pattern" designs, consistent with applicable consumer‑protection and negative‑option rules (including the U.S. FTC's negative‑option/"click‑to‑cancel" posture and analogous laws elsewhere).

7.3 Virtual items

Virtual currency, lives, boosters, and other virtual items have no monetary value, are not redeemable for cash, and are governed by the Terms of Service. Records of virtual items are personal information associated with your account or device.

7.4 Records & tax

We retain transaction records as necessary to provide support, prevent fraud, and comply with tax, accounting, and consumer‑protection record‑keeping obligations (see Section 15).

8. Legal Bases for Processing (GDPR/UK‑GDPR Articles 6 & 9)

For individuals in the EEA and the UK, we process personal data only where we have a valid legal basis under Article 6 of the GDPR/UK‑GDPR. Depending on the specific processing activity (see Sections 6 and 9), the legal basis is one or more of the following:

8.1 Special category data (Article 9)

We do not intend to collect "special category" data (such as data revealing health, religion, race/ethnicity, sexual orientation, or biometric data used to identify you). We ask you not to submit such data (for example, in support messages or display names). If special category data is processed incidentally, we rely on an applicable Article 9 condition, such as your explicit consent (Art. 9(2)(a)) or the establishment/exercise/defense of legal claims (Art. 9(2)(f)), and we minimize and promptly delete such data where feasible.

8.2 Our legitimate interests

Where we rely on legitimate interests (Art. 6(1)(f)), we have identified the following interests and, before relying on this basis, carried out a balancing test weighing those interests against your interests, rights, and freedoms, taking into account your reasonable expectations and the safeguards we apply (such as data minimization, pseudonymization, access controls, and the ability to object). Our legitimate interests include:

  • operating, maintaining, and improving the Services and developing new features;
  • understanding how the Game is used so we can balance difficulty and improve the player experience;
  • keeping the Services, our users, and our systems safe by preventing and detecting fraud, cheating, abuse, and security incidents;
  • administering our relationship with you, including support and service communications;
  • protecting our legal rights and managing legal claims and disputes; and
  • evaluating and carrying out corporate transactions in a confidential and protected manner.

You may object to processing based on legitimate interests as described in Appendix A, and we will stop unless we have compelling legitimate grounds that override your interests, or the processing is necessary for legal claims. You may request further information about a specific balancing assessment.

8.3 Changing legal basis

If we need to rely on a new legal basis for a purpose, we will update this Policy and, where the new basis is consent, obtain it before the new processing begins.

9. Processing Activities Register (Records of Processing)

This Section provides worked examples of our principal processing activities, in the manner of a record of processing activities under Article 30 of the GDPR. For each activity it states the data categories, source, purpose, legal basis, recipients/sub‑processors, international‑transfer mechanism, and retention. It is illustrative and should be read together with Sections 4, 6, 11, 14, and 15.

9.1 Account creation & authentication

Data categoriesEmail address, hashed/salted password or Apple/Google identifier and token, account/user ID, device & app info, IP address.
SourceYou; Apple/Google sign‑in; device.
PurposeCreate and secure your account; authenticate log‑in; enable cloud save/sync.
Legal basisArt. 6(1)(b) contract; Art. 6(1)(f) security.
Recipients / sub‑processorsGoogle Cloud (hosting/Firestore); Apple/Google (as independent controllers for sign‑in).
Transfer mechanismSCCs / UK Addendum / DPF where applicable (US processing).
RetentionLife of account; deleted/de‑identified within 30–90 days of account deletion, subject to legal holds.

9.2 Gameplay & progress telemetry

Data categoriesLevels, scores, stars, lives, currency, boosters, session/feature telemetry, pseudonymous user ID, device/app info.
SourceGame client; backend.
PurposeProvide the Game; save/sync progress; balance difficulty; improve features.
Legal basisArt. 6(1)(b) contract; Art. 6(1)(f) legitimate interests (analytics/improvement).
Recipients / sub‑processorsGoogle Cloud (Firestore); Google Analytics 4 / BigQuery; Firebase.
Transfer mechanismSCCs / UK Addendum / DPF where applicable.
RetentionActive account life; aggregated/de‑identified thereafter; analytics per configured retention.

9.3 Purchases & subscriptions

Data categoriesProduct IDs, purchase/receipt validation results, subscription status, pseudonymous purchase ID, device/app info. No full card/bank details.
SourceYou; Apple/Google billing; RevenueCat (if used).
PurposeEnable and verify purchases/subscriptions; grant entitlements; support; fraud prevention; tax/records.
Legal basisArt. 6(1)(b) contract; Art. 6(1)(c) legal obligation.
Recipients / sub‑processorsApple/Google (controllers for payment); RevenueCat (processor); Google Cloud.
Transfer mechanismSCCs / UK Addendum / DPF where applicable.
RetentionUp to 7–10 years where required by tax/accounting/consumer law (jurisdiction‑dependent).

9.4 Push notifications

Data categoriesPush token, device/app info, notification preferences, event triggers.
SourceDevice/OS; you (preferences).
PurposeDeliver gameplay/event notifications and, where permitted, promotional messages.
Legal basisConsent (Art. 6(1)(a)) where required (device permission / marketing); otherwise Art. 6(1)(f).
Recipients / sub‑processorsApple APNs; Firebase Cloud Messaging (Google).
Transfer mechanismSCCs / UK Addendum / DPF where applicable.
RetentionToken retained while valid/subscribed; removed on opt‑out or invalidation.

9.5 Crash & diagnostic logs

Data categoriesCrash reports, stack traces, device state, app version, pseudonymous installation ID.
SourceGame client (crash SDK).
PurposeDetect, diagnose, and fix crashes and performance issues.
Legal basisArt. 6(1)(f) legitimate interests (stability/security).
Recipients / sub‑processorsFirebase Crashlytics (Google).
Transfer mechanismSCCs / UK Addendum / DPF where applicable.
RetentionTypically 90 days–18 months per provider settings.

9.6 Product analytics

Data categoriesEvent telemetry, pseudonymous IDs, app‑instance ID, device/OS, coarse location from IP, IP (truncated where configured).
SourceGame client; analytics SDKs.
PurposeUnderstand usage/retention; measure features; improve the Game.
Legal basisArt. 6(1)(f) legitimate interests; consent where required for non‑essential SDKs.
Recipients / sub‑processorsGoogle Analytics 4; BigQuery; Firebase.
Transfer mechanismSCCs / UK Addendum / DPF where applicable.
RetentionPer configured retention; event‑level data limited, then aggregated.

9.7 Clan & social features

Data categoriesDisplay name, clan name, leaderboard standing, canned/directed message selections, gifting actions, pseudonymous IDs.
SourceYou; other players.
PurposeOperate clans, leaderboards, canned messaging, and gifting.
Legal basisArt. 6(1)(b) contract; Art. 6(1)(f) legitimate interests (community integrity).
Recipients / sub‑processorsGoogle Cloud (Firestore); other players (inherent to the feature).
Transfer mechanismSCCs / UK Addendum / DPF where applicable.
RetentionWhile account/clan active; moderation records retained as needed.

9.8 Account recovery & transactional email

Data categoriesEmail address, message content/metadata, delivery status.
SourceYou; system triggers.
PurposeSend account‑recovery, receipts, security, and service messages.
Legal basisArt. 6(1)(b) contract; Art. 6(1)(f) security.
Recipients / sub‑processorsSendGrid/Twilio (or equivalent email provider).
Transfer mechanismSCCs / UK Addendum / DPF where applicable.
RetentionDelivery logs for a limited period; content per support retention.

9.9 Support requests

Data categoriesContact details, message content, attachments/screenshots, device/app metadata.
SourceYou.
PurposeResolve inquiries, troubleshoot, handle complaints/refunds.
Legal basisArt. 6(1)(b) contract; Art. 6(1)(f) legitimate interests.
Recipients / sub‑processorsSupport tooling; email provider; Google Cloud.
Transfer mechanismSCCs / UK Addendum / DPF where applicable.
RetentionTypically 12–36 months after resolution unless needed for claims.

9.10 Anti‑fraud, security & integrity

Data categoriesIP address, device/app info, request metadata, rate‑limit and anti‑cheat signals, purchase‑validation results, pseudonymous IDs.
SourceClient; backend; platform integrity signals.
PurposeDetect/prevent cheating, fraudulent purchases, bots, abuse, and unauthorized access; enforce Terms.
Legal basisArt. 6(1)(f) legitimate interests; Art. 6(1)(c) legal obligation.
Recipients / sub‑processorsGoogle Cloud; platform providers; professional advisers as needed.
Transfer mechanismSCCs / UK Addendum / DPF where applicable.
RetentionSecurity/audit logs typically 30 days–24 months; longer for active investigations.

10. Cookies, SDKs, and Similar Technologies; ATT; GPC/Do‑Not‑Track

10.1 Technologies we use

The native Game primarily uses device/local storage and integrated SDKs rather than browser cookies. Any browser‑based version and our websites may use cookies, web storage, pixels, and similar technologies. These technologies support essential functionality (authentication, security, saving progress), analytics and diagnostics, and preferences. We classify them as: (a) strictly necessary; (b) functional/preferences; (c) analytics/performance; and (d) advertising (not currently used in the Game).

TypePurposeConsent needed?
Strictly necessaryAuthentication, security, load balancing, saving progress, fraud prevention.No (essential)
Functional / preferencesRemember language, settings, and choices.Sometimes (per local law)
Analytics / performanceMeasure usage, retention, crashes, and feature performance.Yes, where required (EEA/UK)
Advertising (not currently used)Would support ads/measurement if introduced.Yes (opt‑in/ATT/consent)

10.1.1 Illustrative cookies (websites / browser version)

Where cookies and similar technologies are used on our websites or any browser‑based version of the Game, they fall into the following representative categories. The specific names, providers, and durations will be listed in our cookie preferences/banner where required.

CategoryExample functionTypeTypical duration
Strictly necessaryMaintain your session, authenticate, and secure the Service; balance load; prevent fraud.First‑partySession / short‑lived
PreferencesRemember language, region, and settings.First‑partyUp to 12 months
Analytics/performanceMeasure usage, sessions, and feature performance (e.g., Google Analytics).First/third‑partyUp to 24 months
AdvertisingNot currently used; would support ads/measurement if introduced, subject to consent.Third‑partyN/A currently

10.2 SDK/processor summary

The table below summarizes the third‑party SDKs and processors currently integrated or reasonably anticipated; per‑processor detail (identity, role, data, purpose, location, safeguards, links) is in Section 11. The exact set may change; the Company will keep this current and update the "Last updated" date.

Provider / SDKPurposeData involvedPolicy link
Google Analytics 4 (Google LLC)Product analytics, usage & retentionPseudonymous IDs, app‑instance ID, events, device/OS, coarse location from IP, IP (truncated where configured)policies.google.com/privacy
Google BigQuery (Google LLC)Analytics data warehouse/queriesExported analytics events (as above), stored/queried in our projectcloud.google.com/terms
Firebase (Google LLC)Crash reporting, push messaging, install IDsCrash logs, device state, Firebase installation ID, push tokens, app versionfirebase.google.com/support/privacy
Google Cloud — Cloud Run & FirestoreBackend hosting, database, server logsAccount data, gameplay/progress, IP, request logs, security signalscloud.google.com/terms/data-processing-addendum
Apple (Sign in with Apple, APNs, App Store)Authentication, push, purchasesApple identifier, relay email (optional), push tokens, purchase/receipt statusapple.com/legal/privacy
Google (Sign in with Google, Play Billing)Authentication, purchasesGoogle identifier, email (if granted), purchase/subscription statuspolicies.google.com/privacy
RevenueCat, Inc. (if used)Subscription/purchase validationPseudonymous app‑user ID, product IDs, receipts, subscription status, device/OSrevenuecat.com/privacy
SendGrid / Twilio (or equivalent)Transactional emailEmail address, message content/metadata, delivery statustwilio.com/legal/privacy
AdMob / AppLovin (future — not integrated)Advertising/measurement (reserved)Would be disclosed before use; may include advertising IDs with ATT/consentTo be provided if/when introduced

10.3 Consent management

Where the law requires consent for non‑essential cookies/SDKs (notably in the EEA/UK), we obtain it through a consent mechanism before those technologies are activated, present accept/reject options with equal prominence, record consent, and allow you to change your choices at any time. We do not deploy non‑essential analytics/advertising technologies until valid consent is obtained where required.

10.4 App Tracking Transparency (ATT) — iOS

On iOS, apps must obtain your permission through Apple's App Tracking Transparency framework before "tracking" you across apps and websites owned by other companies or accessing your device's advertising identifier (IDFA) for that purpose. Because we do not currently use third‑party behavioral advertising, we generally do not track you across other companies' apps and websites and therefore may not present an ATT prompt. If we introduce advertising or cross‑context measurement that requires it, we will request ATT permission, and we will not track you for those purposes unless you grant permission. The ATT flow is: (1) you continue using the app; (2) if/when a tracking‑dependent feature is introduced, the system prompt asks you to Allow or Ask App Not to Track; (3) we honour your choice and you can change it any time in Settings > Privacy & Security > Tracking. ATT operates independently of any GDPR consent prompt; where both apply, each governs its own purpose.

10.5 Global Privacy Control (GPC) & Do‑Not‑Track

For our websites and any browser‑based version, where required by law we treat a recognized opt‑out preference signal — such as the Global Privacy Control (GPC) — as a valid request to opt out of "sale"/"sharing" and targeted advertising for that browser or device (see Sections 13 and Appendices B–C). Because there is no common industry standard for "Do‑Not‑Track" (DNT) browser signals, we may not respond to DNT signals other than as described for GPC. Within the native app, you can control tracking via ATT (iOS) or your Android advertising‑ID settings, and via in‑app privacy controls where offered.

10.6 Managing SDKs, cookies & identifiers

  • iOS: Settings > Privacy & Security > Tracking (ATT); and Settings > Privacy & Security > Apple Advertising.
  • Android: Settings > Privacy / Ads to reset or delete your advertising ID and opt out of ad personalization.
  • Browser: use your browser's cookie controls; where offered, our cookie banner/preferences center lets you accept or reject non‑essential cookies.
  • In‑app: where offered, use in‑app privacy settings to limit optional analytics.

11. Detailed Sub‑Processor / SDK Directory

This Section provides per‑processor detail beyond the summary tables. The Company maintains a current sub‑processor list, executes data‑processing agreements (and, where needed, SCCs/UK Addendum) with each processor, and conducts due diligence.

Google LLC — Google Cloud (Cloud Run & Firestore)

Role: Processor / sub‑processor.

Data received: Account data, gameplay/progress, IP address, request/security logs.

Purpose: Backend hosting, application runtime, database, and logging.

Location: United States and other Google data‑center regions.

Safeguards: Data Processing Addendum; SCCs/UK Addendum for international transfers; encryption in transit and at rest; access controls.

Terms/policy: cloud.google.com/terms/data-processing-addendum; policies.google.com/privacy.

Google LLC — Google Analytics 4 & BigQuery

Role: Processor (analytics on our behalf) / data warehouse in our project.

Data received: Pseudonymous IDs, app‑instance ID, event telemetry, device/OS, coarse location from IP, IP (truncated where configured).

Purpose: Product analytics, retention/usage measurement, feature evaluation.

Location: United States; Google infrastructure.

Safeguards: DPA; SCCs where applicable; configurable data‑retention and IP handling; consent gating in the EEA/UK.

Terms/policy: policies.google.com/privacy; cloud.google.com/terms.

Google LLC — Firebase (Crashlytics, Cloud Messaging, Installations)

Role: Processor.

Data received: Crash logs, device state, Firebase installation ID, push tokens, app version.

Purpose: Crash reporting, push message delivery, install identification.

Location: United States; Google infrastructure.

Safeguards: DPA; SCCs where applicable; access controls; provider‑side retention limits.

Terms/policy: firebase.google.com/support/privacy.

Apple Inc. — Sign in with Apple, APNs, App Store

Role: Independent controller (platform).

Data received/handled by Apple: Apple user identifier, optional private‑relay email, push tokens, purchase/receipt/subscription status.

Purpose: Authentication, push delivery (APNs), in‑app purchases.

Location: United States; global.

Safeguards: Governed by Apple's own privacy policy and developer terms; we receive limited data as described.

Terms/policy: apple.com/legal/privacy.

Google LLC — Sign in with Google & Google Play Billing

Role: Independent controller (platform).

Data received/handled by Google: Google identifier, email (if granted), purchase/subscription status.

Purpose: Authentication, Google Play purchases.

Location: United States; global.

Safeguards: Governed by Google's own privacy policy and developer terms.

Terms/policy: policies.google.com/privacy.

RevenueCat, Inc. (if integrated)

Role: Processor.

Data received: Pseudonymous app‑user ID, product IDs, receipts/validation results, subscription status, device/OS.

Purpose: Purchase/subscription validation and entitlement management.

Location: United States.

Safeguards: DPA; SCCs where applicable; no full payment‑instrument data received.

Terms/policy: revenuecat.com/privacy.

Twilio Inc. (SendGrid) or equivalent email provider

Role: Processor.

Data received: Email address, message content/metadata, delivery status.

Purpose: Transactional/account‑recovery email delivery.

Location: United States.

Safeguards: DPA; SCCs where applicable; transport security.

Terms/policy: twilio.com/legal/privacy.

Advertising / measurement providers (e.g., AdMob, AppLovin) — future, not currently integrated

Role: To be determined (processor and/or third party/controller).

Data received: To be disclosed before use; may include advertising IDs subject to ATT/consent.

Purpose: Advertising and/or measurement, if introduced.

Location: To be disclosed.

Safeguards: ATT/consent gating; opt‑out mechanisms; updated disclosures before any launch.

Terms/policy: To be provided if/when introduced.

12. How We Share and Disclose Information

We disclose personal information only as described below. We do not disclose personal information to third parties for their own independent marketing without your consent.

12.1 Government and law‑enforcement requests

We disclose personal information to government authorities or law enforcement only where we believe in good faith that disclosure is required by applicable law, regulation, legal process (such as a subpoena, court order, or warrant), or a lawful governmental request, or is reasonably necessary to protect rights, property, or safety. Where permitted by law and appropriate in the circumstances, we review requests for validity and scope, seek to narrow overbroad requests, decline requests that lack a lawful basis, and notify affected individuals — unless we are legally prohibited from doing so or notice would be counterproductive to preventing serious harm or a crime. We do not provide governments with direct, unfettered access to our systems.

12.2 No independent third‑party marketing

We do not disclose your personal information to third parties for those third parties' own independent marketing purposes without your consent. Our service providers are contractually restricted to using personal information only to perform services for us.

13. "Sale" and "Sharing" of Personal Information

We do not sell your personal information for money. We also do not currently use third‑party behavioral advertising.

However, some U.S. state privacy laws define "sale" and "sharing" very broadly. Under the California Consumer Privacy Act, as amended by the CPRA:

  • a "sale" includes disclosing personal information to a third party for monetary or other valuable consideration; and
  • "sharing" includes disclosing personal information to a third party for "cross‑context behavioral advertising," whether or not for money.

Because certain analytics or attribution activities could be characterized as a "sale" or "sharing" under these broad definitions, we treat the relevant signals as opt‑out‑eligible. You can opt out of any such "sale"/"sharing" and of targeted advertising as described in Appendices B and C, including by using a recognized opt‑out preference signal (GPC) on our websites/browser version, and via your device tracking controls (ATT/advertising‑ID) in the app. If we introduce advertising in the future, we will update this Section and provide the required opt‑out and, where applicable, opt‑in mechanisms. We do not knowingly "sell" or "share" the personal information of consumers under 16 without the required opt‑in consent.

14. International Data Transfers

The Company and its service providers may process personal information in countries other than the country in which you reside, including the United States, where privacy laws may differ from those in your jurisdiction. When we transfer personal data internationally, we implement appropriate safeguards required by applicable law, which may include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA;
  • the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs for transfers from the UK;
  • reliance on adequacy decisions where available;
  • where applicable, certification of the data importer under the EU–U.S. Data Privacy Framework (and the UK Extension and Swiss–U.S. framework), to the extent such frameworks remain valid; and
  • for transfers subject to Brazil's LGPD, the ANPD Standard Contractual Clauses or other lawful transfer mechanism; and for Canada/Quebec, contractual and assessment measures consistent with PIPEDA and Law 25.

Where required, we conduct transfer impact assessments to evaluate the laws of the destination country and apply supplementary measures (such as encryption and access controls). You may request more information about the safeguards we use, and (where applicable) a copy of the relevant clauses, by contacting us at appsgenx@gmail.com. Where we rely on your consent for a specific transfer, you may withdraw it, subject to the consequences described at the time of collection.

15. Data Retention

We retain personal information only for as long as necessary to fulfil the purposes described in this Policy, including to provide the Services, comply with legal obligations, resolve disputes, prevent fraud, and enforce our agreements. When personal information is no longer needed, we delete, de‑identify, or anonymize it, or securely restrict its further processing. The schedule below is indicative; actual periods may vary based on legal requirements and legitimate business needs.

Data categoryIndicative retention periodRationale
Account data (email, credentials, profile)For the life of the account; then deleted or de‑identified within a defined window (e.g., 30–90 days) after account deletion, subject to legal holds.Provide the Service; security; support
Guest local savesStored on your device until you delete the app or clear data; not linked to an email unless you create an account.Provide Guest experience
Gameplay / progress telemetryRetained while account is active; aggregated/de‑identified for analytics thereafter.Operate & improve the Game
Purchase / subscription recordsRetained for the period required by tax, accounting, and consumer‑protection law (commonly up to 7–10 years, jurisdiction‑dependent).Legal obligation; fraud prevention
Support communicationsTypically retained for a limited period after resolution (e.g., 12–36 months), unless needed for legal claims.Support quality; dispute handling
Analytics data (GA4/BigQuery)Retained per configured retention settings; event‑level data limited, then aggregated. Pseudonymous IDs subject to platform retention controls.Product analytics
Crash / diagnostic logsTypically 90 days to 18 months, depending on provider settings.Stability & debugging
Server / security logsTypically 30 days to 24 months for security, audit, and fraud purposes.Security; anti‑fraud
Marketing preferences & suppression listsRetained as needed to honour your choices (e.g., to keep you unsubscribed).Respect opt‑outs
Records of rights requestsRetained as required to demonstrate compliance (e.g., 24 months under CCPA regulations).Legal compliance
BackupsRolling backups retained for a limited window; deletions propagate on the next backup rotation.Resilience; disaster recovery

15.1 How deletion works

When you delete your account or we grant a valid deletion request, we take the following steps, subject to legal exceptions:

15.2 Anonymization

Where deletion is not required or feasible for all data, we may instead anonymize or aggregate information so that it can no longer reasonably be linked to you, and retain and use it in that form for lawful purposes (Section 18).

16. Security & Data‑Breach Notification

16.1 Technical measures

  • Encryption of data in transit (TLS) and, where appropriate, at rest.
  • Hashing and salting of passwords; secure credential storage; no storage of full payment‑card data.
  • Network segmentation, firewalls, and managed cloud security controls on Google Cloud.
  • Access controls based on least privilege and role‑based access; authentication for administrative systems.
  • Logging, monitoring, and alerting for anomalous activity; rate‑limiting and anti‑abuse controls.
  • Secure software‑development practices, dependency management, and periodic vulnerability review.
  • Backups and disaster‑recovery measures.

16.2 Organizational measures

  • Confidentiality obligations for personnel and contractors; security awareness practices.
  • Vendor due diligence and data‑processing agreements with processors (Sections 11, 27).
  • Data‑minimization and retention governance (Section 15).
  • Incident‑response procedures and an internal incident register.
  • Privacy‑by‑design and, where relevant, data‑protection impact assessments.

16.3 No guarantee

No method of transmission or storage is completely secure. While we strive to protect your personal information, we cannot guarantee absolute security, and you provide information at your own risk. You are responsible for keeping your credentials confidential and for using strong, unique passwords.

16.4 Privacy by design & impact assessments

We embed data‑protection considerations into the design of new features and material changes ("privacy by design and by default"). Where a processing activity is likely to result in a high risk to individuals' rights and freedoms — for example, large‑scale processing, new tracking technologies, or processing that could affect minors — we conduct a data‑protection impact assessment (DPIA) or equivalent (including privacy impact assessments under Quebec Law 25 and, where relevant, assessments under U.S. state laws for targeted advertising, sale, sensitive‑data processing, or profiling that presents a heightened risk of harm). These assessments identify risks and the measures we adopt to mitigate them, and are reviewed by the DPO or Privacy Officer where applicable.

16.5 Incident response

If we suspect or detect a security incident, we will investigate, contain, and remediate; assess the risk to affected individuals; notify authorities and affected persons where required; and document the incident and our response. We will cooperate with regulators and, where appropriate, law enforcement.

16.6 Breach‑notification timelines by regime

RegimeNotify authorityNotify individualsTrigger / notes
GDPR / UK‑GDPRSupervisory authority without undue delay and, where feasible, within 72 hours of awareness.Without undue delay where high risk to rights/freedoms.Risk‑based; document all breaches internally.
U.S. state breach laws (all 50 states)State AG/agencies where required (thresholds vary).In the most expedient time possible / without unreasonable delay; some states set outer limits (e.g., 30–60 days).Triggered by unauthorized access to defined personal information (often name + identifier/financial/credential).
CCPA (private right of action)Statutory damages possible for breaches of certain unencrypted/unredacted data due to failure to maintain reasonable security.
Canada PIPEDAOffice of the Privacy Commissioner as soon as feasible.As soon as feasible where real risk of significant harm; keep records of all breaches.Record‑keeping obligation applies to all breaches.
Quebec Law 25Commission d'accès à l'information promptly.Promptly where risk of serious injury; maintain incident register.Risk‑of‑serious‑injury standard.
Brazil LGPDANPD within a reasonable time.Affected data subjects within a reasonable time.Where risk or relevant damage to data subjects.
Australia (NDB scheme)OAIC as soon as practicable.Affected individuals where likely serious harm.Eligible data breaches under the Privacy Act.

Timelines are summarized and simplified; the operative statute controls.

17. Sensitive Personal Information — Handling & Minimization

We take a minimization‑first approach to sensitive personal information (as defined in Section 2 and the Appendices):

  • What we collect: the only sensitive category we routinely collect is account log‑in credentials (email + password), used solely to authenticate and secure your account.
  • What we do not collect: we do not intentionally collect government identifiers, financial account numbers, precise geolocation, health data, biometric identifiers, or data revealing race/ethnicity, religion, sexual orientation, or similar categories. Please do not submit such data in display names, clan names, or support messages.
  • How we use it: credentials are used only for authentication, security, and integrity — not to infer characteristics about you and not for advertising. This is why the CPRA "right to limit the use of sensitive personal information" generally does not apply to this use (see Appendix B).
  • Consent where required: in U.S. states and other jurisdictions that require opt‑in consent to process sensitive data, we will obtain it before any processing that would trigger the requirement, and in the EEA/UK we rely on an Article 9 condition (Section 8.1) for any special‑category data processed incidentally.
  • Incidental sensitive data: if we become aware that sensitive data has been provided incidentally, we minimize, restrict, and delete it where feasible.

18. De‑identified, Pseudonymized & Aggregated Data

We use pseudonymized identifiers (such as account/user IDs and app‑instance IDs) to operate the Service while limiting direct identification. We also create de‑identified and aggregated datasets for analytics, research, difficulty balancing, and reporting. With respect to de‑identified data, we commit to:

  • maintain and use the information only in a de‑identified form and not attempt to re‑identify it, except as necessary to test that the de‑identification is effective;
  • implement technical safeguards and business processes that prohibit re‑identification;
  • contractually obligate recipients of de‑identified data to comply with these commitments; and
  • treat pseudonymized data that remains linkable to an individual as personal data subject to this Policy.

Aggregated and properly de‑identified data is not "personal information" and may be used and disclosed for lawful business purposes.

19. Social Features, Clans, Chat, Gifting & Leaderboards

19.1 What is visible to others

If you use social features, certain information is visible to other players by design: your display name, your clan name (if you create or lead one), your leaderboard standing, and the fact that you sent a gift (e.g., virtual lives) or a canned message. Do not include personal or sensitive information in your display name or clan name.

19.2 Restricted, canned chat only

The Game does not provide free‑text or voice chat. Communication between players is limited to a curated set of pre‑written ("canned") messages and directed canned messages. This design reduces the risk of harassment, exposure of personal information, and unsafe contact — particularly important given regulatory scrutiny of real‑time, free‑form contact features in games.

19.3 Gifting & invitations

When you gift virtual lives or interact within a clan, the recipient can see that the interaction came from you (via your display name/identifier). If you invite others, please read Section 24 (Data About Other People).

19.4 Moderation & safety

We may monitor, review, and take action on social activity (including display names, clan names, and message usage) to enforce our Terms, protect users, and comply with law. We may suspend or remove content or accounts that violate our rules.

19.5 User‑chosen identifiers

Display names and clan names are the limited forms of free text you can contribute, and they are visible to other players. Because they are public, we ask that you not include personal information (such as your real full name, email, phone number, or address) or offensive, misleading, or infringing content. We may reject, change, or reset identifiers that violate our rules or applicable law, and we process reports about inappropriate identifiers as part of moderation. Information you make public through these features may be seen, copied, or retained by other users outside our control.

19.6 Leaving a clan or social features

You can stop using social features, leave a clan, or change your display name at any time in the Game. Leaving a clan removes your ongoing participation, though records necessary for integrity, moderation, or dispute handling may be retained for a limited period as described in Section 15. Historical leaderboard entries and prior interactions that other players received may persist as an inherent part of those features.

20. Marketing Communications & Push Notifications

20.1 Push notifications

With your permission (managed by your device settings and, on iOS, the system notification prompt), we send push notifications via Apple Push Notification service (APNs) and Firebase Cloud Messaging, such as lives‑refilled alerts, event reminders, and, where permitted, promotional messages. You can disable push notifications at any time in your device settings or in‑app settings.

20.2 Email marketing

If you have an account and where permitted by law, we may send promotional emails about features, events, and offers. Every marketing email includes an unsubscribe link, and you can opt out at any time. Transactional messages (e.g., account‑recovery, receipts, security, and important service notices) are not marketing and may still be sent.

20.3 Your controls

You can manage marketing preferences via in‑app settings, unsubscribe links, device notification settings, or by contacting us. We honour opt‑outs promptly and maintain suppression lists to respect your choices.

20.4 Compliance with marketing laws

Our commercial messaging practices are designed to comply with applicable electronic‑marketing laws, including: the U.S. CAN‑SPAM Act (accurate sender and subject information, a valid physical postal address, a functioning unsubscribe mechanism honoured promptly); Canada's Anti‑Spam Legislation ("CASL," which generally requires consent, sender identification, and an unsubscribe mechanism); and the EU/UK ePrivacy rules and PECR (which generally require consent for marketing, subject to a limited "soft opt‑in" for existing customers regarding similar products). Where consent is required, we obtain it before sending, and we keep records of consents and opt‑outs.

21. Your Rights and Choices (General)

Depending on where you live and applicable law, you may have some or all of the following rights. Region‑specific details and how to exercise them are in the Appendices (Sections 28–35).

  • Access / know — request access to, and information about, the personal information we hold.
  • Correction / rectification — request that we correct inaccurate or incomplete data.
  • Deletion / erasure — request that we delete your personal information, subject to exceptions.
  • Portability — request a copy of certain data in a portable, machine‑readable format.
  • Opt‑out of sale/sharing/targeted advertising — where applicable (see Section 13, Appendices B–C).
  • Limit use of sensitive personal information — where applicable (see Appendix B).
  • Object to or restrict processing — including processing based on legitimate interests, and to withdraw consent (see Appendix A).
  • Non‑discrimination / no retaliation — we will not discriminate against you for exercising your rights.
  • Appeal — where provided by law, to appeal a decision on your request (see Appendix C).
  • Lodge a complaint — with a supervisory authority or regulator (see the Appendices and Section 26).

21.1 How to exercise your rights

Submit requests to appsgenx@gmail.com or via appsgenx@gmail.com. We will verify your identity before acting on a request (for example, by confirming control of the account email), to protect your information. We respond within the timeframes required by applicable law (for example, generally within 45 days under U.S. state laws, extendable as permitted; and within one month under the GDPR/UK‑GDPR, extendable for complex requests). Authorized agents may submit requests where the law permits, subject to verification (see Appendix B). We do not charge a fee for most requests, unless permitted by law for excessive or repetitive requests.

21.2 Request lifecycle & verification

To help us handle your request efficiently and securely, our process is as follows:

21.3 Common exemptions to requests

Across jurisdictions, applicable law recognizes circumstances in which we may lawfully decline, or partially fulfil, a request. We will tell you when an exemption applies. Common examples include where fulfilling the request would:

  • compromise the privacy, rights, or safety of another individual;
  • reveal trade secrets or confidential commercial information, or another person's personal information that cannot be separated;
  • interfere with legal obligations, a legal‑hold, or the establishment, exercise, or defense of legal claims;
  • undermine the security or integrity of the Services, or our fraud‑prevention and anti‑abuse measures;
  • require us to retain information for tax, accounting, or other record‑keeping duties;
  • concern data that is de‑identified or aggregated, or that we cannot reasonably link to you or verify as yours; or
  • be manifestly unfounded, excessive, or repetitive.

Where only part of a request is exempt, we fulfil the remainder to the extent required by law.

21.4 Fees

We do not charge a fee to respond to most requests. Where permitted by law, we may charge a reasonable fee, or refuse to act, if a request is manifestly unfounded, excessive, or repetitive, and we will explain our decision and, where applicable, how to appeal or complain.

21.5 Guests

If you play as a Guest without an account, much of your data is stored locally on your device and may not be identifiable to us; you can delete it by clearing app data or uninstalling. Where we cannot reasonably link data to you, some rights may not apply, and we are not required to re‑identify data solely to respond to a request, though we will explain this and, where feasible, help you delete local data.

22. Automated Decision‑Making & Profiling

We do not use automated decision‑making that produces legal or similarly significant effects concerning you within the meaning of Article 22 of the GDPR/UK‑GDPR. We do perform limited, non‑significant profiling for product purposes — for example, difficulty balancing, matchmaking within clans/leaderboards, analytics segmentation, and fraud/abuse detection.

22.1 What our profiling does and does not do

These processes support the Service and its security and do not, by themselves, make decisions that produce legal or similarly significant effects. Where anti‑fraud measures could result in account restrictions, a human reviews material decisions on request where required by law, and you can contest the outcome.

22.2 If we ever introduce significant automated decisions

If we introduce automated decisions with legal or similarly significant effects, we will provide the disclosures and safeguards required by law, including, where applicable: meaningful information about the logic involved and the significance and envisaged consequences; the right to obtain human intervention, express your point of view, and contest the decision (GDPR Art. 22); and, under Quebec Law 25 and similar laws, information about the personal information used and the principal factors and parameters that led to the decision, and an opportunity to submit observations.

23. Third‑Party Links and Services

The Services may contain links to third‑party websites, services, or resources (for example, the app stores, social platforms, or support articles) that we do not operate or control. This Policy does not apply to those third parties. We are not responsible for their content or privacy practices. We encourage you to review the privacy policies of any third‑party services you use.

24. Data About Other People (Invites & Gifting)

If you invite another person to the Game, gift virtual items, or otherwise provide us with information about someone else, you represent that you have the right to do so and that the information is accurate. Please do not provide us with another person's personal information unless you have their permission. We use invitation/gifting information only to facilitate the interaction you request and as described in this Policy, and we do not use it to independently market to the invited person without a lawful basis. The recipient may exercise their rights with respect to any personal information we hold about them as described in this Policy.

If you act as a clan leader or otherwise administer a group of players, you may see limited information about members that is inherent to those features (such as their display names and participation). You must use that information only for the social purpose it is provided and consistent with our Terms; you must not collect, retain, or repurpose other players' information for your own or third parties' purposes. We remain responsible as controller/business for the personal information we process, and members may contact us directly to exercise their rights.

25. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make material changes, we will update the "Last updated" date and, where required by law, provide additional notice (for example, an in‑app or email notice) and, where required, obtain your consent. If you continue to use the Services after the effective date of an updated Policy, you acknowledge the updated Policy to the extent permitted by law. We encourage you to review this Policy periodically. Prior versions will be made available on request where required.

26. How to Contact Us & Escalate Complaints

For any questions, requests, or complaints regarding this Policy or your personal information, contact us:

  • Privacy contact: appsgenx@gmail.com
  • Data Protection Officer (where applicable): appsgenx@gmail.com
  • Postal: Appsgenx, Inc, Wyoming, USA
  • Support: appsgenx@gmail.com
  • EU representative (Art. 27 GDPR): appsgenx@gmail.com
  • UK representative (Art. 27 UK‑GDPR): appsgenx@gmail.com

If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection or privacy authority (see the Appendices for authority details by region). We ask that you contact us first so we can try to resolve your concern.

27. Master Table — Third Parties / Sub‑Processors

The following summarizes the principal categories of recipients and sub‑processors. See Sections 10–11 for SDK‑level detail and links. The Company maintains a current sub‑processor list and executes data‑processing agreements (and, where needed, SCCs) with each.

Recipient / categoryRolePurposeLocation(s)
Google LLC (Google Cloud, Firebase, GA4, BigQuery)Processor / sub‑processorHosting, database, analytics, crash reporting, messagingUnited States; global data centers
Apple Inc.Independent controller (platform)Authentication, push (APNs), App Store purchasesUnited States; global
Google LLC (Play, Sign in with Google)Independent controller (platform)Authentication, Google Play purchasesUnited States; global
RevenueCat, Inc. (if used)ProcessorPurchase/subscription validation & managementUnited States
Twilio Inc. (SendGrid) or equivalentProcessorTransactional/account‑recovery emailUnited States
Advertising/measurement providers (future)To be determinedAdvertising/measurement, if introducedTo be disclosed
Professional advisers (legal, accounting, auditors)Processor/recipientCompliance, audit, dispute handlingAs applicable
Government/regulators/law enforcementRecipientLegal compliance, lawful requestsAs applicable
Acquirers/investors (in a transaction)RecipientCorporate transactions (Section 12)As applicable

28. Appendix A — EEA/EU & United Kingdom (GDPR / UK‑GDPR)

This Appendix supplements the Policy for individuals in the European Economic Area, the United Kingdom, and (where applicable) Switzerland, and is intended to be read on a stand‑alone basis. It controls to the extent required by the GDPR, UK‑GDPR, and Swiss FADP.

28.1 Controller, DPO & representatives

The controller is Appsgenx, Inc, Wyoming, USA. Our Data Protection Officer (where appointed) is appsgenx@gmail.com. Our EU representative under Article 27 is appsgenx@gmail.com and our UK representative is appsgenx@gmail.com. You may contact the DPO or representative directly on any matter relating to the processing of your personal data or to exercise your rights.

28.2 Legal bases

See Sections 6, 8, and 9 for the legal bases we rely on for each purpose. Where we rely on legitimate interests, you may request information about our balancing assessment.

28.3 Your rights in detail

28.4 How to exercise; procedure, verification & timing

Submit requests to appsgenx@gmail.com or the DPO, indicating the right you wish to exercise. We verify identity proportionately (e.g., by confirming control of the account email) and may request limited additional information to locate your data. We respond within one month, extendable by two further months for complex or numerous requests (we will tell you within the first month if we extend). We will explain any refusal and your right to complain. Requests are generally free; we may charge a reasonable fee or refuse where a request is manifestly unfounded or excessive, and we will justify any such decision.

28.5 Limits and exemptions of rights

The rights above are not absolute and are subject to conditions and exemptions under the GDPR/UK‑GDPR and applicable Member State or UK law. For example: the right to erasure does not apply where processing is necessary to comply with a legal obligation or to establish, exercise, or defend legal claims; the right to portability applies only to data you provided that is processed by automated means on the basis of consent or contract; and we may decline or charge a reasonable fee for requests that are manifestly unfounded or excessive. Where an exemption applies, we will tell you and explain the basis, unless the law prevents us from doing so. Restricting or objecting to certain processing (for example, security or fraud‑prevention processing) may limit or prevent your use of the Services.

28.6 International transfers

See Section 14. We rely on SCCs, the UK IDTA/Addendum, adequacy decisions, and/or the EU–U.S. Data Privacy Framework (and UK/Swiss extensions), as applicable, with supplementary measures where needed. You may request details of the safeguards applied to a specific transfer.

28.7 Complaints / supervisory authority

You have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA Member State of your habitual residence, place of work, or place of the alleged infringement; in the UK, with the Information Commissioner's Office (ICO) (ico.org.uk); and in Switzerland, with the Federal Data Protection and Information Commissioner (FDPIC). A list of EEA authorities is available via the European Data Protection Board (EDPB). We ask that you contact us first so we can address your concern.

28.8 Consequences of not providing data

Where data is necessary to provide the Services (e.g., account or purchase data), not providing it may mean we cannot provide the relevant feature. Providing analytics/marketing data is optional where consent‑based.

29. Appendix B — California (CCPA/CPRA)

This Appendix applies to California residents and supplements the Policy as required by the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"). It is intended to be read on a stand‑alone basis.

29.1 Notice at collection

The categories of personal information we collect are listed in Section 4.4. We collect these categories for the business/commercial purposes in Section 6, and we retain them as described in Section 15. We do not use or disclose sensitive personal information for purposes that would trigger the "right to limit" beyond those permitted without a limit option (see 29.8).

29.2 Categories collected, disclosed, "sold," and "shared" (statutory format)

Category (Cal. Civ. Code §1798.140)Collected?Disclosed for a business purpose to"Sold"?"Shared"?
IdentifiersYesHosting, analytics, crash, email, purchase‑validation, security providers; platformsNo (money)Potentially, via analytics — opt‑out available
Customer records (§1798.80)Yes (limited)Support tooling, purchase‑validation providersNoNo
Protected classificationsLimited (age band)Not disclosed for advertisingNoNo
Commercial informationYesPurchase‑validation, analytics, supportNoPotentially, via analytics — opt‑out available
Internet/network activityYesAnalytics, crash, security providersNoPotentially, via analytics — opt‑out available
Geolocation (coarse)YesAnalytics, securityNoPotentially, via analytics — opt‑out available
Sensory (screenshots in support)LimitedSupport toolingNoNo
InferencesLimitedAnalytics (non‑advertising)NoNo
Sensitive PI (log‑in credentials)YesAuthentication/security providersNoNo

We do not sell personal information for monetary consideration. We do not knowingly sell or share the personal information of consumers under 16 without opt‑in consent. "Potentially, via analytics" reflects the broad statutory definition of "sharing"; you may opt out as described below.

29.3 Sources of personal information

We collect personal information from the following categories of sources: (a) directly from you (account details, profile, support messages, preferences); (b) automatically from your device and use of the Services (identifiers, gameplay telemetry, diagnostics, IP/coarse location); (c) from platforms and payment/authentication providers (Apple, Google, and, if used, RevenueCat); (d) from our service providers (analytics, crash reporting, email, security/anti‑fraud); and (e) from other players (for social interactions you receive).

29.4 Business and commercial purposes for collection

We collect and use each category of personal information for the business/commercial purposes described in Section 6, which include: providing and operating the Game; authenticating and securing accounts; enabling and verifying purchases; operating social features; providing support; performing analytics and product improvement; diagnosing crashes and performance; detecting and preventing fraud, abuse, and security incidents; sending service and (where permitted) marketing communications; complying with law; and evaluating or completing corporate transactions. We do not use personal information for incompatible purposes without notice and, where required, consent.

29.5 Retention

We retain each category of personal information for the periods described in Section 15, based on the criteria of: the duration of your relationship with us; the purpose for which the data was collected; our legal, tax, accounting, and record‑keeping obligations; the need to prevent fraud and secure our systems; and the establishment, exercise, or defense of legal claims. We do not retain personal information longer than reasonably necessary for the disclosed purposes.

29.6 Your California rights

  • Right to know/access — the categories and specific pieces of personal information we collected, the sources, purposes, and the categories of recipients.
  • Right to delete — subject to statutory exceptions (e.g., completing a transaction, security, legal compliance).
  • Right to correct — inaccurate personal information.
  • Right to opt out of sale/sharing — see 29.7.
  • Right to limit use of sensitive personal information — see 29.8.
  • Right to non‑discrimination — we will not deny services, charge different prices, or provide a different level of service for exercising your rights (financial incentives permitted by law require your opt‑in consent).

29.7 How to opt out of "sale"/"sharing"

You can opt out by: (a) emailing appsgenx@gmail.com or using appsgenx@gmail.com; (b) on our websites/browser version, enabling a recognized opt‑out preference signal such as the Global Privacy Control (GPC), which we treat as a valid opt‑out for that browser/device; and (c) in the app, using device tracking controls (iOS ATT / Android advertising‑ID). A "Do Not Sell or Share My Personal Information" and "Limit the Use of My Sensitive Personal Information" link/control will be provided where required.

29.8 Right to limit sensitive personal information

We use sensitive personal information (account log‑in credentials) only for purposes permitted under the CCPA without triggering the right to limit — namely to perform the Service, ensure security and integrity, and verify/maintain quality — and not to infer characteristics about you. If we ever use sensitive PI for other purposes, we will offer a "Limit the Use of My Sensitive Personal Information" option.

29.9 Authorized agents

You may use an authorized agent to submit requests. We may require the agent to provide proof of authorization (e.g., a signed permission or power of attorney) and may require you to verify your identity directly or confirm you gave the agent permission.

29.10 Verification & timing

We verify requests using information associated with your account or request, matching data points to the sensitivity of the request. We confirm receipt within 10 business days and respond within 45 days, extendable by an additional 45 days with notice. We may decline requests as permitted by law and will explain why.

29.11 Notice of financial incentives; metrics; "Shine the Light"

We do not currently offer financial incentives for personal information. Where required, we will publish annual request metrics. Under California's "Shine the Light" law (Civ. Code §1798.83), we do not disclose personal information to third parties for their own direct marketing.

29.12 Contact for California requests

Email appsgenx@gmail.com or visit appsgenx@gmail.com. If we deny your request, you may contact the California Privacy Protection Agency (CPPA) or the California Attorney General.

30. Appendix C — Other U.S. States

This Appendix applies to residents of U.S. states with comprehensive privacy laws, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other states whose laws are or become effective (including Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island, and any newly‑effective state law). Rights and mechanics vary by state; we honour the rights the applicable law provides. It is intended to be read on a stand‑alone basis.

30.1 Rights (as applicable by state)

  • Confirm & access the personal data we process about you.
  • Correct inaccuracies (most states; not Iowa/Utah).
  • Delete personal data.
  • Portability — obtain a copy in a portable, readily usable format.
  • Opt out of: (i) targeted advertising; (ii) the sale of personal data; and (iii) certain profiling in furtherance of decisions producing legal or similarly significant effects.
  • Sensitive data — most states require opt‑in consent before processing sensitive data (Utah/Iowa generally require notice and an opportunity to opt out instead).

30.2 How to exercise; procedure, verification & timing

Submit requests to appsgenx@gmail.com or appsgenx@gmail.com. We provide at least two methods where required. We verify your identity using account/request information; if we cannot authenticate a request, we may decline and will tell you. We respond within 45 days, extendable by 45 additional days where reasonably necessary, with notice. Where a state requires, we provide at least one free response in a 12‑month period.

30.3 Appeals

Where provided (e.g., VA, CO, CT, TX, OR, MT, and others), you may appeal our decision on your request by replying to our response or contacting appsgenx@gmail.com within the period stated. We will respond to an appeal within the statutory window (commonly 45–60 days). If we deny the appeal, we will provide a written explanation and information on how to contact your State Attorney General to submit a complaint (in Colorado, the Attorney General; in others, the designated regulator).

30.4 Universal opt‑out mechanisms (UOOM)

In states that require it (including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas), we honour a recognized universal opt‑out mechanism, such as the Global Privacy Control (GPC), as a valid opt‑out of targeted advertising and/or sale for the relevant browser/device.

30.5 Sensitive data & minors

We aim not to process sensitive data except account credentials for authentication. Where a state requires opt‑in consent for sensitive data, we will obtain it before any such processing. We do not process the sensitive data of a known child except in compliance with COPPA (Section 5). Several states prohibit targeted advertising to, or the sale of data of, consumers known to be minors without consent; we honour these where applicable.

30.6 State‑specific detail

30.6.1 Virginia (VCDPA)

Virginia residents may confirm access, correct, delete, obtain a portable copy of, and opt out of the sale of personal data, targeted advertising, and profiling with legal or similarly significant effects. Processing of sensitive data requires opt‑in consent. If we decline a request, you may appeal by contacting appsgenx@gmail.com; we respond to appeals within 60 days. If your appeal is denied, you may submit a complaint to the Virginia Attorney General. Virginia does not currently mandate recognition of universal opt‑out signals, but we may honour them.

30.6.2 Colorado (CPA)

Colorado residents have rights to access, correct, delete, obtain a portable copy, and opt out of sale, targeted advertising, and certain profiling. Sensitive data requires opt‑in consent. We honour a recognized universal opt‑out mechanism (such as GPC). You may appeal a declined request within a reasonable time; we respond within 45 days (extendable by 60 days). If denied, you may complain to the Colorado Attorney General, who enforces the CPA and its rules.

30.6.3 Connecticut (CTDPA)

Connecticut residents may access, correct, delete, obtain a portable copy, and opt out of sale, targeted advertising, and certain profiling; sensitive data requires opt‑in consent. We honour recognized universal opt‑out mechanisms. Appeals are handled within 60 days; if denied, you may complain to the Connecticut Attorney General. Additional protections apply to consumers known to be minors, including restrictions on targeted advertising and sale.

30.6.4 Utah (UCPA)

Utah residents may access, delete, obtain a portable copy, and opt out of sale and targeted advertising. Utah does not provide a correction right or an appeal right, and generally requires notice and an opportunity to opt out for sensitive data rather than opt‑in consent. We respond within 45 days (extendable by 45 days). Enforcement is by the Utah Attorney General (with the Division of Consumer Protection).

30.6.5 Texas (TDPSA)

Texas residents may access, correct, delete, obtain a portable copy, and opt out of sale, targeted advertising, and certain profiling; sensitive data requires opt‑in consent. We honour a recognized universal opt‑out mechanism. Appeals are handled within 60 days; if denied, you may complain to the Texas Attorney General. Note the TDPSA's small‑business provisions and its specific sensitive‑data consent requirements.

30.6.6 Oregon (OCPA)

Oregon residents have rights to access (including, on request, a list of specific third parties to which we have disclosed personal data), correct, delete, obtain a portable copy, and opt out of sale, targeted advertising, and certain profiling; sensitive data requires opt‑in consent. We honour recognized universal opt‑out mechanisms. Appeals are handled within 45 days (extendable); if denied, you may complain to the Oregon Attorney General.

30.6.7 Montana (MCDPA)

Montana residents may access, correct, delete, obtain a portable copy, and opt out of sale, targeted advertising, and certain profiling; sensitive data requires opt‑in consent. We honour a recognized universal opt‑out mechanism. Appeals are handled within 60 days; if denied, you may complain to the Montana Attorney General.

30.6.8 Other effective states (Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island, and later‑effective laws)

These states provide broadly similar rights (access, correction where applicable, deletion, portability, and opt‑outs of sale/targeted advertising/certain profiling), generally with opt‑in consent for sensitive data (Iowa is a notable exception, using a notice/opt‑out model), and most with an appeal right and, in many cases, universal‑opt‑out recognition. Minnesota additionally provides a right to obtain a list of the specific third parties to which personal data has been disclosed and rights concerning profiling. Maryland imposes stricter data‑minimization limits and additional restrictions on sensitive data and minors. We honour the rights the applicable state law provides; enforcement is by the relevant State Attorney General (or designated regulator).

30.7 State‑by‑state quick reference

StateLawCorrect?Appeal?Sensitive dataHonour GPC/UOOM?
VirginiaVCDPAYesYesOpt‑inNot mandated (we may honour)
ColoradoCPAYesYesOpt‑inYes
ConnecticutCTDPAYesYesOpt‑inYes
UtahUCPANoNoNotice/opt‑outNot mandated
TexasTDPSAYesYesOpt‑inYes
OregonOCPAYesYesOpt‑inYes
MontanaMCDPAYesYesOpt‑inYes
Delaware, NH, NJ, MD, MN, NEVariousYesYesOpt‑inYes
IowaICDPANoLimitedNotice/opt‑outNot mandated
Tennessee, Indiana, Kentucky, Rhode Island, othersVariousGenerally yesGenerally yesGenerally opt‑inVaries

This table is a simplified summary; the operative statute controls, and amendments are frequent.

31. Appendix D — Nevada

Nevada law (NRS Chapter 603A) allows Nevada consumers to opt out of the "sale" of certain covered information — defined as the exchange of covered information for monetary consideration to a person who will license or sell it to others. We do not sell covered information as defined by Nevada law.

How to submit a request. If you are a Nevada resident and wish to submit a verified opt‑out request, contact us at appsgenx@gmail.com with your name and the email associated with your account. We will verify and respond as required by law (generally within 60 days, extendable by 30 days). You may also contact the Nevada Attorney General with concerns.

32. Appendix E — Canada (PIPEDA & Quebec Law 25)

This Appendix applies to individuals in Canada and is intended to be read on a stand‑alone basis.

32.1 PIPEDA (federal)

We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial laws, guided by PIPEDA's ten fair information principles:

PrincipleHow we apply it
1. AccountabilityOur Privacy Officer is responsible for compliance and for handling inquiries and complaints.
2. Identifying purposesWe identify why we collect personal information at or before collection (Section 6).
3. ConsentWe obtain consent (express or implied, appropriate to sensitivity) for collection, use, and disclosure, and let you withdraw it subject to legal/contractual limits.
4. Limiting collectionWe collect only what is necessary for the identified purposes, by fair and lawful means.
5. Limiting use, disclosure & retentionWe use and disclose personal information only for the purposes for which it was collected (or as permitted/required by law) and retain it only as long as necessary (Section 15).
6. AccuracyWe keep personal information as accurate, complete, and up to date as necessary.
7. SafeguardsWe protect personal information with security safeguards appropriate to its sensitivity (Section 16).
8. OpennessWe make our privacy practices readily available through this Policy.
9. Individual accessOn request, we tell you what personal information we hold, how it is used and disclosed, and give access, subject to legal exceptions.
10. Challenging complianceYou may challenge our compliance by contacting our Privacy Officer.

Your rights and how to exercise them

  • Access — request access to your personal information and information about its use and disclosure.
  • Correction — request correction of inaccurate or incomplete information.
  • Withdraw consent — subject to legal or contractual restrictions and reasonable notice.

Submit requests to our Privacy Officer at appsgenx@gmail.com; we generally respond within 30 days. If unsatisfied, you may complain to the Office of the Privacy Commissioner of Canada (OPC).

32.2 Quebec Law 25

For Quebec residents, the Act to modernize legislative provisions as regards the protection of personal information ("Law 25") applies. Consistent with Law 25:

  • we have a designated Person in charge of the protection of personal information (Privacy Officer): appsgenx@gmail.com;
  • we obtain consent as required, provide clear information at collection, and use privacy‑by‑default settings;
  • we conduct privacy impact assessments for relevant projects and for transfers of personal information outside Quebec;
  • we provide rights of access, correction, portability (to receive computerized personal information in a structured, commonly used technological format), and de‑indexing / cessation of dissemination / withdrawal of consent;
  • we provide, on request, information about automated decision‑making, including the personal information used and the principal factors, and an opportunity to submit observations (Section 22); and
  • we report confidentiality incidents presenting a risk of serious injury to the Commission d'accès à l'information (CAI) and to affected individuals, and keep an incident register.

Quebec residents may contact our Privacy Officer and may complain to the Commission d'accès à l'information du Québec. Where required, we respond to access/correction requests within 30 days.

33. Appendix F — Brazil (LGPD)

For individuals in Brazil, we process personal data in accordance with the Lei Geral de Proteção de Dados ("LGPD"). This Appendix is intended to be read on a stand‑alone basis.

33.1 Legal bases

We rely on one or more legal bases under Article 7 (and Article 11 for sensitive data), such as: consent; performance of a contract or preliminary procedures; compliance with a legal or regulatory obligation; the regular exercise of rights; legitimate interests; and protection of credit, among others as applicable.

33.2 Your rights (Art. 18)

  • confirmation of the existence of processing;
  • access to the data;
  • correction of incomplete, inaccurate, or out‑of‑date data;
  • anonymization, blocking, or deletion of unnecessary or excessive data or data processed unlawfully;
  • portability to another provider, subject to regulation;
  • deletion of personal data processed with consent;
  • information about entities with which we shared data;
  • information about the possibility of denying consent and the consequences;
  • revocation of consent.

33.3 How to exercise; DPO; authority; transfers

To exercise your rights, contact appsgenx@gmail.com or our DPO/Encarregado, appsgenx@gmail.com. Our supervisory authority is the Autoridade Nacional de Proteção de Dados (ANPD), to whom you may submit complaints. Where required, foreign controllers appoint a local representative in Brazil. For international transfers, we use a lawful mechanism, which may include the ANPD Standard Contractual Clauses or other permitted safeguards (Section 14).

34. Appendix G — Australia (Privacy Act / APPs)

For individuals in Australia, we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"). We collect personal information by lawful and fair means and only where reasonably necessary for our functions; we notify you of collection; we take reasonable steps to keep it accurate and secure; and we provide access and correction rights (APP 12 and APP 13).

34.1 Overseas disclosure

We may disclose personal information to overseas recipients (e.g., in the United States) as described in Section 14, and we take reasonable steps to ensure appropriate handling consistent with APP 8.

34.2 How to exercise; complaints; breaches

To access or correct your information, contact appsgenx@gmail.com. If you are unsatisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC). The Notifiable Data Breaches (NDB) scheme applies to eligible data breaches (Section 16).

35. Appendix H — Other Jurisdictions

We offer the Services in multiple jurisdictions and endeavour to comply with applicable data‑protection laws wherever we operate, including but not limited to laws in Switzerland (FADP), Japan (APPI), South Korea (PIPA), Singapore (PDPA), New Zealand (Privacy Act 2020), South Africa (POPIA), and other countries and regions. Where local law grants you rights beyond those described in this Policy, we will honour those rights to the extent required. If you have questions about how a specific local law applies to you, contact us at appsgenx@gmail.com. Where a conflict exists between this Policy and mandatory local law, mandatory local law prevails for residents of that jurisdiction.


36. Frequently Asked Questions (Plain English)

This FAQ is a plain‑language convenience and does not override the operative text of this Policy.

Do I have to give you my email to play?
No. You can play offline as a Guest with your progress saved on your device. An account (email/password, Apple, or Google) is optional and unlocks cloud save, cross‑device sync, and social features.
Do you show me ads or track me across other apps?
Not currently. We don't use third‑party behavioral advertising today. If that ever changes, we'll tell you and, where required, ask for your permission (including via Apple's App Tracking Transparency on iOS).
Do you sell my data?
No — we don't sell your information for money. Some U.S. state laws define "sale" and "sharing" very broadly, so certain analytics could count; if so, you can opt out (Section 13 and Appendices B–C).
Can other players see my information?
They can see your display name, clan name, leaderboard position, and any canned messages or gifts you send. Chat is limited to pre‑written messages — there's no free‑text or voice chat.
How do I delete my account and data?
Contact us at appsgenx@gmail.com or use in‑app settings where available. We'll verify it's you and delete your data within the timeframes the law allows (Sections 15 and 21).
Is this game for kids?
No. It's made for adults and isn't directed to children under 13 (or the applicable teen age in Europe). If we learn a child used it, we delete their data (Section 5).
Where is my data stored?
Mostly on Google Cloud (in the U.S. and other regions). When data crosses borders, we use legal safeguards like Standard Contractual Clauses (Section 14).
How do I stop notifications or marketing emails?
Turn off notifications in your device settings, use the unsubscribe link in emails, or adjust in‑app settings (Section 20).
What if there's a data breach?
We investigate, contain it, and notify regulators and affected users where the law requires (Section 16).
Who do I contact with a privacy question or complaint?
Email appsgenx@gmail.com. You can also complain to your local privacy regulator (see the Appendices).
What if I signed in with Apple or Google — do you get my email?
You control what is shared. With Sign in with Apple you can hide your email and use Apple's private relay, so we only ever see a forwarding address. With Google, we receive your email only if you grant it. In all cases we use it to run your account and send service messages, not to sell to anyone.
Will my progress transfer if I switch phones?
If you have an account, your progress is saved to the cloud and syncs when you sign in on another device. Guest progress is stored only on the device and does not transfer unless you create an account first.

37. Glossary

Plain‑language explanations of common terms. Where a term is defined in Section 2 or by statute, that definition controls.

TermPlain‑English meaning
Controller / BusinessThe company that decides why and how your data is used — here, the Company.
Processor / Service providerA vendor that handles data only on the Company's instructions (e.g., our hosting or email provider).
Personal information / dataInformation that can identify you or be linked to you.
Sensitive informationEspecially private categories (like log‑in passwords, precise location, health, or ID numbers) that get extra protection.
SDKThird‑party code inside the app that adds features and may collect some data.
Device / advertising identifierA code tied to your device or app install (e.g., IDFA on iOS, advertising ID on Android).
CookieA small file used mainly on websites/browsers to remember information.
ATT (App Tracking Transparency)Apple's iOS system that asks your permission before an app tracks you across other companies' apps and websites.
GPC (Global Privacy Control)A browser signal that automatically tells websites you want to opt out of sale/sharing.
Sale / SharingLegal terms for giving data to others — "sale" often for value, "sharing" for cross‑app advertising. We don't sell for money.
Targeted advertisingAds chosen based on your activity across different apps/sites. We don't do this currently.
De‑identified / Aggregated dataData with identities removed so it can't reasonably be tied back to you.
Pseudonymized dataData using a code instead of your name, but still linkable with extra information — still counts as personal data.
Legal basisThe lawful reason (under GDPR) that lets us process your data — e.g., a contract, your consent, or our legitimate interests.
Legitimate interestsA lawful reason based on a real business need, balanced against your rights.
Data subject / ConsumerYou — the person the data is about.
Supervisory authority / RegulatorThe government body that enforces privacy law where you live.
SCCs / IDTAStandard legal contracts that protect your data when it's transferred across borders.
DPO / EncarregadoThe Data Protection Officer — the person responsible for privacy compliance.
COPPAThe U.S. children's privacy law for kids under 13.
GDPR / UK‑GDPREurope's and the UK's comprehensive data‑protection laws.
CCPA / CPRACalifornia's consumer‑privacy laws.
LGPDBrazil's general data‑protection law.
© 2026 Save Pickles. All rights reserved. 🐾  ·  Home  ·  Terms & Conditions