Privacy Policy
A complete description of what data Ui BapYG Studio and our apps collect, how we use it, who we share it with (including advertising and mediation partners), and the rights you have under every major global privacy regulation.
1. Scope of this policy
This Privacy Policy ("Policy") applies to all websites, products, services, mobile applications, casual games, daily utility tools and the Ui BapYG Mobile Management Suite (collectively, the "Services") operated by Ui BapYG Studio ("Ui BapYG", "we", "our", or "us"). It also applies to any third-party platforms (such as Google Play, the Apple App Store, alternative app marketplaces, advertising mediation platforms, analytics providers, payment processors and customer support tools) that we engage to deliver the Services.
By installing, accessing or otherwise using any of our Services you confirm that you have read and understood this Policy. If you do not agree with any part of this Policy, please discontinue use of the Services and uninstall our applications.
2. Who is the data controller
The data controller responsible for your personal data is Ui BapYG Studio. You can reach our privacy team at vusuhosayoso93@gmail.com. Where required by law, we have appointed local representatives; details are available on request.
3. Data we collect
We collect the minimum data necessary to operate, secure, improve and monetize the Services. The categories of data we may collect include:
3.1 Data you provide directly
- Account information: display name, email address, password (hashed) and language preference when you create an account.
- Support communications: messages, attachments, screenshots and feedback you send to our support team.
- Newsletter subscriptions: email address and the topics you opt into.
- Form submissions on our website: name, email, project type, budget range, company and free-form message.
3.2 Data collected automatically
- Device information: device model, operating system version, device language, screen size, time zone, advertising ID (IDFA on iOS / GAID on Android) and a randomly generated install ID.
- Log data: IP address (often truncated), access times, app version, referring URL, crash logs and diagnostic events.
- Usage data: features used, session length, levels played, ad interactions (impressions, clicks, completions), in-app purchases, retention events and de-identified cohorts.
- Approximate location: country and city derived from IP address (no precise GPS unless you grant a separate in-app permission).
3.3 Data collected with your permission
- Photo library access for the Ui BapYG Manager (duplicate finder, photo vault). We process photos on-device; they are not uploaded to our servers.
- Storage access permission for cleaning duplicate files. We only enumerate file metadata on-device.
- Camera access for in-app document scanning and QR code reading. Frames are processed locally.
- Notification access for the optional notification digester. We do not transmit notification content off your device.
4. How we use your data
We use the data described in Section 3 for the following purposes:
- Service delivery: to install, authenticate, sync and operate the apps, games and management features you use.
- Improvement: to debug, analyze usage trends, run A/B tests and prioritize engineering work.
- Personalization: to remember your language, preferences and gameplay progress.
- Monetization: to select and serve relevant ads, run rewarded ad flows and measure ad performance.
- Safety & security: to detect fraud, prevent abuse, enforce our terms and protect users.
- Communication: to send critical service notices, security alerts and, with your consent, marketing messages.
- Legal compliance: to comply with applicable law, regulation, court order or lawful governmental request.
5. Legal basis for processing
If you are located in the European Economic Area, the United Kingdom or Switzerland, we rely on the following legal bases under the GDPR / UK GDPR:
- Performance of a contract to provide the Services you have installed or purchased.
- Legitimate interests to operate, secure and improve the Services, provided those interests are not overridden by your fundamental rights.
- Consent for non-essential cookies, advertising personalization, marketing emails and sensitive in-app permissions (camera, photos, notifications).
- Legal obligation to comply with applicable laws, tax and accounting rules, and lawful authority requests.
6. App store compliance
Our apps are distributed through official and alternative app marketplaces. We comply with the policies of each marketplace that hosts our titles, including (without limitation):
- Google Play (Google LLC) - Google Play Developer Distribution Agreement, Google Play Developer Program Policies, Play Console data-safety section, Families Policy, Ads Policy and target-API requirements.
- Apple App Store (Apple Inc.) - Apple Developer Program License Agreement, App Store Review Guidelines (including Guidelines 1, 2, 3, 4, 5 and the Kids Category), Privacy Nutrition Labels, ATT (App Tracking Transparency), and iOS 17 Privacy Manifest.
- Amazon Appstore (Amazon.com, Inc.) - Amazon Developer Services Agreement, Appstore Content Guidelines, and Digital Service Provider terms.
- Samsung Galaxy Store (Samsung Electronics) - Samsung Galaxy Store Seller Agreement and Content Policy.
- Huawei AppGallery (Huawei Device Co., Ltd.) - Huawei Developer Service Agreement and AppGallery Review Guidelines.
- Xiaomi GetApps / OPPO Software Store / VIVO App Store - respective developer agreements and privacy requirements.
- Microsoft Store (Microsoft Corporation) - Microsoft Store App Developer Agreement, App Certification Toolkit and privacy requirements.
- Mac App Store / Mac Catalyst - Apple Mac App Store Review Guidelines and sandboxing requirements.
- Alternative storefronts and web distribution - we may also distribute through reputable web channels; each channel's terms apply in addition to this Policy.
Where a marketplace requires a stricter standard than this Policy, the marketplace standard prevails for that distribution channel.
7. Advertising & mediation platforms
To keep our free apps free, we monetize through advertising. The following advertising networks, exchanges, mediation platforms and analytics providers may receive or process data when you use our apps. Each partner operates under its own privacy policy and contractual obligations to us.
7.1 Ad mediation & aggregation platforms
We use industry-standard mediation layers that auction impressions across multiple demand sources in real time:
- Google AdMob (Google LLC) - our primary ad mediation platform and the principal source of banner, interstitial, native and rewarded video demand.
- Google Ad Manager (Google LLC) - for direct-sold and programmatic guaranteed campaigns.
- AppLovin MAX (AppLovin Corporation) - in-app bidding and waterfall mediation across multiple networks.
- ironSource (Unity LevelPlay) (ironSource / Unity Software Inc.) - mediation, rewarded video and offerwall mediation.
- Meta Audience Network Mediation (Meta Platforms, Inc.) - bidding integration via Meta's mediation APIs.
- Digital Turbine (Fyber / AdColony) (Digital Turbine, Inc.) - mediation stack and demand from Fyber and AdColony.
- Pangle by TikTok (ByteDance Ltd.) - mediation and direct demand for global markets.
- Helium by Chartboost (now part of Zucks / Digital Turbine ecosystem) - in-app bidding and waterfall for casual games.
- Liftoff (Vungle) (Liftoff Mobile, Inc.) - video mediation, playable ads and rewarded demand.
- Smaato (Smaato Inc., part of Verve Group) - header bidding and exchange.
- InMobi Mediation (InMobi Technology Services Pvt. Ltd.) - mediation and in-app header bidding.
- Moloco (Moloco, Inc.) - programmatic bidding for app install and re-engagement.
- DT Exchange (Digital Turbine Exchange) - programmatic in-app exchange.
- BidMachine (BidMachine Inc.) - independent in-app header bidding exchange.
- AdTiming / ClickForce - APAC-focused mediation and demand.
- Yandex Advertising Network (Yandex LLC) - served only in jurisdictions where lawful and approved.
- VK Ads (VKontakte / Mail.ru) - served only in jurisdictions where lawful and approved.
7.2 Ad networks, exchanges and direct demand
The following networks and exchanges may receive bid requests and serve ads through our mediation layer. Each is governed by its own privacy policy and applicable laws.
- Google Ads / AdMob Network (Google LLC)
- Google AdSense (Google LLC) - for any web-embedded ad units
- Meta Audience Network (Meta Platforms, Inc.)
- AppLovin Exchange (AppLovin Corporation)
- Unity Ads (Unity Technologies SF)
- ironSource Ads (ironSource / Unity Software Inc.)
- Vungle (Liftoff Mobile, Inc.)
- AdColony (Digital Turbine, Inc.)
- Chartboost (Digital Turbine ecosystem)
- Tapjoy (Tapjoy, Inc.) - offerwalls, rewarded video and engagement
- InMobi (InMobi Technology Services)
- Pangle (TikTok for Business) (ByteDance Ltd.)
- Mintegral (Mintegral International S.A.)
- StartApp (StartApp Inc.)
- Leadbolt (Leadbolt Pty Ltd.)
- Amazon Publisher Services / Amazon Ads (Amazon.com, Inc.)
- Criteo (Criteo S.A.)
- Snap Audience Network (Snap Inc.)
- Twitter / X Ads (X Corp.)
- Reddit Ads (Reddit, Inc.)
- LinkedIn Marketing Solutions (LinkedIn Corporation)
- Pinterest Ads (Pinterest, Inc.)
- Outbrain (Outbrain Inc.)
- Taboola (Taboola.com Ltd.)
- Yahoo Advertising (formerly Verizon Media / Yahoo Gemini) (Yahoo Inc.)
- Microsoft Advertising (formerly Bing Ads / MSN Ads) (Microsoft Corporation)
- Appier (Appier Technology Inc.)
- PubMatic (PubMatic, Inc.)
- Index Exchange (Index Exchange Inc.)
- OpenX (OpenX Technologies, Inc.)
- Sovrn (Sovrn Holdings, Inc.)
- TripleLift (TripleLift, Inc.)
- Sharethrough (Sharethrough, Inc.)
- Adform (Adform A/S)
- Conversant (Conversant LLC, now part of ValueClick / Epsilon)
- LoopMe (LoopMe Ltd.)
- Personali (Personali Ltd.)
- ReigNNN (smartRTB+) - APAC programmatic exchange
- Epom (Epom Ltd.)
7.3 Analytics, attribution and measurement
We use the following analytics and attribution partners to measure installs, in-app events, crashes and the effectiveness of our marketing:
- Google Analytics for Firebase (Google LLC)
- Firebase Crashlytics (Google LLC)
- Firebase Cloud Messaging (Google LLC) - for optional push notifications
- Google Play Services Advertising ID (GAID) and Apple Identifier for Advertisers (IDFA) - subject to ATT on iOS
- Adjust (Adjust GmbH) - mobile attribution and fraud prevention
- AppsFlyer (AppsFlyer Ltd.) - mobile attribution, SKAdNetwork and privacy-cloud
- Branch (Branch Metrics, Inc.) - deep linking, attribution and analytics
- Kochava (Kochava Inc.) - attribution and omni-channel measurement
- Tenjin (Tenjin, Inc.) - attribution and aggregation for mobile games
- Singular (Singular Labs, Inc.) - attribution and marketing analytics
- Mixpanel (Mixpanel, Inc.) - product analytics
- Amplitude (Amplitude, Inc.) - product analytics and experimentation
- GameAnalytics (GameAnalytics Ltd.) - games-specific analytics
- deltaDNA (now part of Unity) - live-ops and player segmentation
- Localytics (now part of Upland) - mobile engagement
- Sensor Tower (Sensor Tower, Inc.) - market intelligence
- data.ai (formerly App Annie) (data.ai, Inc.) - market intelligence
- AppMagic - app intelligence and benchmarks
- Sentry (Functional Software, Inc.) - error monitoring and performance
- Datadog (Datadog, Inc.) - server-side observability
7.4 Payments and customer support
- Google Play Billing (Google LLC) and Apple In-App Purchase (Apple Inc.) - for in-app purchases and subscriptions, subject to each platform's terms.
- Stripe (Stripe, Inc.) and PayPal (PayPal Holdings, Inc.) - for web-based payments and invoicing where applicable.
- Zendesk (Zendesk, Inc.) or Intercom (Intercom, Inc.) - for customer support tickets.
- Mailchimp (Intuit Inc.) or SendGrid (Twilio Inc.) - for transactional and (with consent) marketing emails.
- Cloudflare (Cloudflare, Inc.) - for security, DDoS protection and edge networking.
- Amazon Web Services (AWS) (Amazon.com, Inc.) and Google Cloud Platform (GCP) (Google LLC) - for hosting and storage.
7.5 Children's apps
For any app published in the Designed for Families / Kids category or marked as "Everyone" with child-directed intent, we use only Google AdMob (child-directed treatment), Meta Audience Network (child-directed treatment), and Pangle (child-directed treatment), with contextual ads only, no interest-based advertising, and no tracking of personal data, in line with COPPA, GDPR-K, UK Age-Appropriate Design Code, and the Google Play Families Policy.
8. Ad formats we use
Our apps may display the following ad formats. Each format is described in plain language, and the data signals used are limited to what is necessary.
- Banner ads - small, rectangular image or text ads that appear at the top or bottom of a screen while you are using an app. Banner ads run through AdMob, AppLovin, Meta Audience Network, Pangle, ironSource and InMobi. They use a stable ad unit ID and may use contextual signals (app section, language) to determine relevance.
- Interstitial ads - full-screen ads that appear at natural transition points (for example, between game levels). Interstitials are served through our mediation stack (AdMob, MAX, LevelPlay, Pangle, Vungle, Liftoff, Meta AN, Mintegral) and are clearly labeled as ads. We cap frequency per user per session.
- Rewarded video ads - full-screen video ads that the user actively chooses to watch in exchange for an in-app reward (extra lives, in-app currency, hint). Reward delivery is always honored, even on no-fill. Rewarded inventory is served by AdMob, AppLovin, ironSource, Vungle, Unity Ads, Meta AN, Pangle, Tapjoy and Mintegral.
- Open-screen / App-open ads - ads shown when the app is launched or brought back to the foreground. We use AdMob and Unity Ads app-open formats. We do not show app-open ads immediately after a rewarded video flow to avoid stacking.
- Native ads - ads that match the look and feel of the surrounding content, served by AdMob, Meta Audience Network, Taboola, Outbrain and AppLovin. We always label native ads with an "Ad" or "Sponsored" tag.
- Playable ads - interactive mini-game previews, served by AppLovin, ironSource, Vungle, Mintegral and Pangle. They are opt-in only on rewarded placements.
- Offerwalls - a list of partner offers (surveys, app installs, video views) that the user can complete in exchange for in-app rewards. We use Tapjoy and ironSource offerwalls, with clear points-to-reward disclosures.
- Promoted / sponsored listings in any in-app store, search or recommendation surface we operate, always labeled as "Sponsored".
All ads, regardless of format, are subject to frequency caps, child-directed handling where applicable, and the in-app privacy and ad-choice controls described in Section 15.
9. Children & age protections
We design with children in mind even when we do not target them.
- Our apps and games are not directed at children under 13 (or the higher age of digital consent in your jurisdiction, such as 14 in Spain / South Korea for some processing, 16 in France for non-essential cookies, or 13-16 across the EU member states).
- For any title listed in a children's category (Google Play Designed for Families, Apple App Store Kids Category, or equivalent), we apply COPPA, GDPR-K (Article 8), the UK Age-Appropriate Design Code (AADC), the California Age-Appropriate Design Code Act (CA AADC), and the India Personal Data Protection Bill (PDPB) child provisions where applicable.
- We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, contact vusuhosayoso93@gmail.com and we will delete it within 30 days.
- Child-directed apps disable personalized advertising, do not allow in-app purchases without verifiable parental consent (for paid items), and do not include chat, user-generated content or open links to the open web.
- We do not use behavioral or cross-app tracking in child-directed apps. The only data collected in such apps is anonymous, aggregated install and crash data required to operate the service.
10. Regional privacy rights
Depending on where you live, you may have rights under one or more of the following laws. This section maps your rights to the regulations we comply with.
10.1 European Union / European Economic Area / United Kingdom / Switzerland
You have the rights under the GDPR (Regulation (EU) 2016/679), the UK GDPR and the Swiss FADP to: access, rectify, erase, restrict or object to processing of your personal data, request data portability, withdraw consent at any time (without affecting prior lawful processing), and lodge a complaint with your local supervisory authority (for example, the CNIL in France, BfDI in Germany, ICO in the UK, AEPD in Spain, Garante in Italy, AP in the Netherlands).
10.2 United States - California
You have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the California Online Privacy Protection Act (CalOPPA), the Shine the Light law (Cal. Civ. Code § 1798.83) and the California Age-Appropriate Design Code Act (CA AADC). These include the right to know, delete, correct, limit the use of sensitive personal information, opt out of sale or sharing for cross-context behavioral advertising, and non-discrimination for exercising your rights. We do not sell personal data for money. We may share identifiers with advertising partners which, under California law, may be considered "sharing"; you may opt out at any time using the in-app "Do Not Sell or Share My Personal Information" link or the email in Section 17.
10.3 United States - other states
We also comply with the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the Texas Data Privacy and Security Act (TDPSA), the Oregon Consumer Privacy Act (OCPA), the Tennessee Information Protection Act (TIPA), the Iowa SF 262, the Indiana Consumer Data Protection Act, the Montana Consumer Data Privacy Act, the New Hampshire SB 255, the Kentucky Consumer Data Protection Act, the Rhode Island Data Transparency and Privacy Protection Act, the Maryland Online Data Privacy Act, the New Jersey SB 332, the Delaware Personal Data Privacy Act (DPDPA), the Illinois Biometric Information Privacy Act (BIPA) where biometric processing occurs, the New York SHIELD Act, and the Washington My Health My Data Act (MHMD) for health-adjacent data.
10.4 Brazil
We comply with the Lei Geral de Proteção de Dados (LGPD, Law No. 13.709/2018). The National Data Protection Authority (ANPD) is the supervisory authority; you have rights of access, correction, anonymization, portability, deletion and confirmation of processing.
10.5 People's Republic of China
We comply with the Personal Information Protection Law (PIPL), the Data Security Law (DSL), the Cybersecurity Law (CSL) and the Minor Protection Provisions by the Cyberspace Administration of China (CAC). Cross-border transfers are made only under PIPL-compliant mechanisms (security assessment, standard contract or certification).
10.6 Other regions
- Canada - Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec Law 25, Alberta PIPA, BC PIPA.
- Australia - Privacy Act 1988, Australian Privacy Principles (APPs), Notifiable Data Breaches scheme.
- New Zealand - Privacy Act 2020.
- Singapore - Personal Data Protection Act 2012 (PDPA).
- Malaysia - Personal Data Protection Act 2010 (PDPA).
- Thailand - Personal Data Protection Act 2019 (PDPA).
- Indonesia - Personal Data Protection Law No. 27/2022.
- Vietnam - Personal Data Protection Decree 13/2023/ND-CP.
- Philippines - Data Privacy Act of 2012 (RA 10173).
- India - Digital Personal Data Protection Act 2023 (DPDPA) and Information Technology (Reasonable Security Practices) Rules 2011.
- Japan - Act on the Protection of Personal Information (APPI).
- South Korea - Personal Information Protection Act (PIPA), Information and Communications Network Act, Act on Promotion of Information and Communications Network Utilization and Information Protection.
- Hong Kong SAR - Personal Data (Privacy) Ordinance (PDPO).
- Taiwan - Personal Data Protection Act (PDPA).
- Israel - Privacy Protection Law 5741-1981, Protection of Privacy Regulations (Data Security) 2017.
- South Africa - Protection of Personal Information Act (POPIA).
- United Arab Emirates - Federal Decree-Law No. 45/2021 on Personal Data Protection.
- Saudi Arabia - Personal Data Protection Law (PDPL).
- Nigeria - Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act 2023.
- Kenya - Data Protection Act 2019.
- Egypt - Personal Data Protection Law No. 151/2020.
- Argentina - Personal Data Protection Act 25.326.
- Chile - Personal Data Protection Law 19.628.
- Colombia - Statutory Law 1581/2012 and Decree 1377/2013.
- Mexico - Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP).
- Turkey - Law No. 6698 on the Protection of Personal Data (KVKK).
- Russia - Federal Law No. 152-FZ on Personal Data.
- Serbia - Personal Data Protection Law.
If a law not listed here applies to you, you may still exercise the rights described in Section 15 of this Policy; we will honor them consistent with that law.
11. Data sharing & sub-processors
We do not sell personal data. We share data only as described in this Policy, with:
- Service providers and sub-processors listed in Section 7 acting on our documented instructions and under data processing agreements.
- App marketplaces (Google Play, Apple App Store and the alternatives in Section 6) for the limited purposes of distributing, updating, securing and supporting the Services.
- Advertising and analytics partners as described in Sections 7.1, 7.2 and 7.3.
- Law enforcement, regulators, courts and other authorities when we believe in good faith that disclosure is necessary to comply with a legal obligation, protect our rights, or ensure user safety.
- A successor entity in the event of a merger, acquisition, reorganization or sale of all or substantially all of our assets, with notice to affected users where required.
- Other third parties only with your prior consent or at your direction.
12. International data transfers
Ui BapYG operates globally, so the data we collect may be transferred to, stored and processed in countries other than your country of residence. When we transfer personal data out of the EEA, the UK, Switzerland, China or other jurisdictions with transfer restrictions, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (2021/914), the UK International Data Transfer Addendum, the EU-US Data Privacy Framework (where applicable), the China CAC Standard Contract for Cross-Border Transfer of Personal Information, the Asia-Pacific Cross-Border Privacy Rules (CBPR), and equivalent legal mechanisms. You may request a copy of the relevant safeguards via the contact details in Section 17.
13. Data retention
We retain personal data only for as long as necessary to provide the Services, comply with legal obligations, resolve disputes and enforce our agreements. Specifically:
- Account data: for the life of the account plus 30 days after deletion, unless we are required to retain it longer for tax, accounting or legal reasons.
- Server logs: typically 90 days, then aggregated or deleted.
- Ad measurement data: up to 13 months, then aggregated.
- Support tickets: up to 3 years for quality and training purposes.
- Financial records: as required by applicable tax and accounting law (typically 5-7 years).
14. Security
We use industry-appropriate technical and organizational measures to protect personal data, including encryption in transit (TLS 1.2+) and at rest, role-based access control, least-privilege principles, regular vulnerability scanning, code review, employee training, vendor due diligence and incident response procedures. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
15. Your rights & how to exercise them
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data ("right to be forgotten").
- Restrict or object to certain processing.
- Port your data in a machine-readable format.
- Withdraw consent at any time where processing is based on consent.
- Opt out of sale or sharing for cross-context behavioral advertising (CCPA/CPRA).
- Limit the use of sensitive personal information (CPRA).
- Object to automated decision-making including profiling that produces legal or similarly significant effects (GDPR Art. 22).
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, send your request to vusuhosayoso93@gmail.com from the email address associated with your account (so we can verify your identity). We respond within 30 days, or earlier where required by law. If you are an EU/UK/Swiss resident, you may also contact our lead supervisory authority. If you are a California resident, you may designate an authorized agent to act on your behalf.
16. Changes to this policy
We may update this Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page and, for material changes, notify you through the Services or by email. We encourage you to review this Policy periodically. Your continued use of the Services after a change indicates that you accept the updated Policy.
17. Contact us
For any question, comment or request relating to this Policy or our processing of your personal data, please contact us at vusuhosayoso93@gmail.com. We will respond as soon as we can, and in any case within the timeframes required by applicable law.