1. Scope & Who We Are
This Privacy Policy applies to (a) the K LmofWY public website at klmofwy.com and any subdomain we control, (b) every mobile application we publish under the “K LmofWY” developer name on Google Play and the Apple App Store, and (c) the supporting customer-support, billing, and analytics tooling that operates those Services.
The data controller for personal data processed under this Policy is K LmofWY, reachable at gideot@theboartech.pics. We operate as a remote-first independent studio; we do not maintain a physical storefront and we do not have a dedicated establishment in the European Union, the United Kingdom, or California. Where required by Article 27 GDPR / UK GDPR, we will appoint and disclose an EU and a UK representative in this Policy prior to placing any App on the market that processes personal data of residents in those jurisdictions on a regular or systematic basis.
Some of our mobile applications are designed for a general audience and may be downloaded by minors. The specific protections we apply to children are described in Section 9. Nothing in this Policy overrides any higher protection required by law.
2. Applicable Laws & Jurisdictions
We design our practices to comply with, at minimum, the following frameworks. Where a framework imposes a higher standard, we follow the higher standard.
- EU General Data Protection Regulation (Regulation 2016/679, “GDPR”) and the national implementing laws of the EU Member States.
- UK GDPR and the Data Protection Act 2018, as amended.
- California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA/CPRA”), and the California Attorney General’s regulations.
- Children’s Online Privacy Protection Act (COPPA) and the FTC’s COPPA Rule (16 C.F.R. Part 312).
- UK Age-Appropriate Design Code (AADC), a statutory code of practice under the Age Appropriate Design Code Act 2020.
- Personal Information Protection and Electronic Documents Act (PIPEDA) of Canada, and the substantially similar provincial laws of Québec Law 25 (formerly Bill 64), Alberta (PIPA), and British Columbia (PIPA).
- Lei Geral de Proteção de Dados (LGPD, Law 13.709/2018) of Brazil.
- Australia Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), as updated by the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022.
- Personal Information Protection Law of the People’s Republic of China (PIPL), referenced for cross-border data-flow risk assessment where our Services are accessed from mainland China.
- EU Digital Services Act (DSA) and Digital Markets Act (DMA) obligations that may apply through our third-party SDKs.
If you are located in a jurisdiction not listed above, we will still respect the data-subject rights you hold under the law of your habitual residence to the extent compatible with our technical and contractual obligations.
3. Data We Collect
We collect personal data directly from your device, from your interactions with our Services, and from third parties such as app stores and ad networks. The categories below describe the data we (or our processors) may process.
3.1 Device & technical data
Device model, operating system and version, locale and language, screen size, mobile carrier, network type, IP address, system uptime, app version, build number, install referrer, and free vs. paid user status.
3.2 Advertising identifiers
Apple Identifier for Advertisers (IDFA) on iOS, Google Advertising Identifier (GAID / AAID) on Android, and the limited ad-tracking / opt-out-preference signals derived from them. We also use app-set UUIDs as a fallback when advertising identifiers are unavailable.
3.3 Crash, diagnostic & performance logs
Stack traces, exception types, breadcrumbs of the actions leading up to a crash, anonymous session replay snippets, latency and frame-rate telemetry, and aggregated heat-maps of feature usage.
3.4 Usage & interaction data
Pages or screens viewed, buttons tapped, ad impressions and clicks, session length, retention cohort, in-app purchases, currency used, and reward grants.
3.5 Approximate & precise location
Coarse location derived from IP address or device locale; precise location only if you explicitly grant the runtime permission. If you decline, we do not collect precise location.
3.6 Purchase & billing data
For in-app purchases, the receipt and the transaction identifier returned by the Apple App Store or Google Play; for premium subscriptions, the masked payment instrument identifier and the billing region. We do not see or store full card numbers.
3.7 User-provided content
Email address, support tickets, in-app feedback, survey responses, and any content you choose to submit through our contact forms or our Apps.
3.8 Children-related fields
For Apps intended for a general audience we do not knowingly collect name, email, photo, geolocation, or persistent identifiers linked to a child. The only data we collect from child users is what is strictly necessary to deliver the service (e.g., the app-set UUID for the duration of a single play session, deleted on app uninstall).
4. How We Use Data
We process personal data on the following legal bases under GDPR/UK GDPR, and for the corresponding business purposes under other regimes:
- Performance of a contract — to install, authenticate, and maintain the Apps you download, to process in-app purchases, to deliver rewards tied to rewarded video ads, and to provide customer support.
- Legitimate interests — to prevent fraud and abuse, to secure our Services, to measure aggregate engagement, and to improve gameplay and tool features. Where we rely on legitimate interests, you may object as described in Section 8.
- Consent — for non-essential cookies, for personalized advertising, and for any processing of precise geolocation. You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Compliance with legal obligations — to respond to lawful requests from public authorities, to retain tax and accounting records, and to honour rights requests under CCPA/CPRA, GDPR, and equivalent laws.
Specifically, we use the data described in Section 3 to (a) deliver and improve the Services; (b) select and serve advertisements; (c) attribute installs to marketing campaigns; (d) detect and prevent crashes, cheating, and abuse; (e) respond to support requests; (f) comply with our legal duties; and (g) enforce our Terms of Service.
6. Data Retention
We retain personal data for as long as necessary to fulfil the purposes described in this Policy and to comply with our legal obligations. Concretely:
- Server logs: 90 days.
- Aggregated analytics: 26 months (then anonymized).
- Support correspondence: 24 months after closure of the ticket.
- Billing and tax records: 7 years in line with applicable accounting rules.
- Crash reports containing personal data: 180 days unless required longer for an active investigation.
- App-set UUIDs: deleted within 30 days of app uninstall or expiry of inactivity, whichever comes first.
Where personal data is no longer needed, we will delete or irreversibly anonymize it.
8. Your Rights & Controls
Subject to your jurisdiction, you have some or all of the following rights. We will respond within the time limits prescribed by law (typically 30 days under GDPR, 45 days under CCPA/CPRA).
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure / deletion — ask us to delete your data, subject to legal exceptions.
- Right to data portability — receive your data in a structured, commonly used, machine-readable format.
- Right to object — object to processing based on legitimate interests, including profiling.
- Right to restrict processing — ask us to pause processing while a complaint is investigated.
- Right to withdraw consent — at any time, without retroactive effect.
- Right to opt out of sale or sharing (CCPA/CPRA) — we do not sell personal data; you may still direct us not to share it for cross-context behavioural advertising.
- Right to non-discrimination — we will not deny service, charge different prices, or provide a lower level of service because you exercised a right.
8.1 Out of targeted advertising on mobile
You may opt out of personalized advertising at the device level:
- iOS: Settings → Privacy & Security → Tracking → toggle “Allow Apps to Request to Track” off, or decline the ATT prompt per app. You can also reset your IDFA from Settings → Privacy & Security → Apple Advertising → “Reset Advertising Identifier”, then toggle “Personalized Ads” off.
- Android: Settings → Google → Ads → “Opt out of Ads Personalization”. On Android 12 and later, you can also delete your advertising ID.
In addition, many of the partners in Section 17 provide their own opt-out tools linked from their individual entries. Where you opt out, you will still see ads, but they will be contextual rather than personalized.
8.2 How to exercise your rights
Email gideot@theboartech.pics with the subject line “Privacy Request” and a description of your request. We may need to verify your identity to prevent fraudulent requests, typically by confirming control of the email address on file or by asking for additional information that only you would know.
9. Children & Minors
Our Services are not directed to children under the age of 13 in the United States (COPPA), 13 in the United Kingdom (AADC / ICO Children’s Code), 13 in California (CCPA/CPRA), 16 in most of the European Union (Article 8 GDPR — lowered to 13 by Member State law in some countries, including the UK after Brexit and France for under-15s), and 14 in Brazil (LGPD). The default age-gate shown the first time you launch a K LmofWY App follows the strictest applicable threshold for the user’s detected region.
We do not knowingly collect personal data from children below the applicable threshold. If we learn that we have inadvertently collected such data, we will delete it as soon as possible. Parents and guardians may contact us at gideot@theboartech.pics to request review or deletion.
For Apps that are clearly designed for a mixed-age audience, we (a) disable personalized advertising and high-impact ad formats (rewarded video is shown only after an explicit tap on a clearly-labelled button), (b) prohibit third-party SDKs from collecting precise location, (c) avoid any in-app purchase flow that does not pass through the parental gate of Google Play or the App Store, and (d) apply the IARC general-audience rating by default unless the App’s content warrants a higher tier (see Section 16).
10. International Data Transfers
Personal data collected in the European Economic Area, the United Kingdom, Switzerland, or other regions may be transferred to, and processed in, the United States, Singapore, or other jurisdictions where our processors and advertising partners operate.
Where this occurs, we rely on one or more of the following transfer mechanisms:
- Standard Contractual Clauses (SCCs) adopted by the European Commission (Module 1 for controller-to-controller, Module 2 for controller-to-processor, Module 3 for processor-to-processor, as applicable) and the UK International Data Transfer Addendum issued by the ICO.
- EU–US Data Privacy Framework (DPF), the UK Extension to the DPF, and the Swiss–US DPF, where the recipient is self-certified with the U.S. Department of Commerce.
- Derogations under Article 49 GDPR (explicit consent, contract performance, public interest) for occasional, non-systematic transfers not covered by the mechanisms above.
- Equivalent regional instruments, including the UK Addendum, the Swiss FDPIC SCCs, and the APEC Cross-Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP) systems where applicable.
You may request a copy of the transfer safeguards we rely on by emailing gideot@theboartech.pics with the subject line “Transfer Safeguards”.
11. Third-Party Links & Ads
Our Apps and our website may contain links to third-party websites, app stores, or services that we do not control. This Policy does not apply to those third parties. We are not responsible for the privacy practices of any third party, and we encourage you to review the privacy notices of every site or app that collects personal data from you. Ads served through the partners listed in Section 17 are governed by the partner’s own privacy policy and the controls described per partner below.
12. Security
We employ administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. These include:
- TLS 1.2 or higher for data in transit between your device and our servers.
- AES-256 encryption for personal data at rest in our production databases.
- Least-privilege role-based access controls, mandatory multi-factor authentication, and quarterly access reviews for staff.
- Vendor security review before onboarding any new SDK or processor.
- An incident-response plan that targets a 72-hour breach-notification window to supervisory authorities and affected users in line with GDPR Article 33, and equivalent California, Canadian, and Australian rules.
No system is perfectly secure. If we determine that a security incident has materially affected your personal data, we will notify you and the competent authorities as required by law.
13. Complaints & Supervisory Authorities
If you have an unresolved concern, you have the right to lodge a complaint with a data protection authority. Relevant authorities include:
- EEA residents: your national supervisory authority, listed at edpb.europa.eu.
- UK residents: the Information Commissioner’s Office (ICO), ico.org.uk.
- California residents: the California Privacy Protection Agency (CPPA) and the California Attorney General.
- Canadian residents: the Office of the Privacy Commissioner of Canada (OPC), and the Commission d’accès à l’information du Québec (CAI) for Québec residents.
- Brazilian residents: the Autoridade Nacional de Proteção de Dados (ANPD).
- Australian residents: the Office of the Australian Information Commissioner (OAIC).
We would, however, appreciate the chance to address your concerns directly before you approach a regulator. Please email gideot@theboartech.pics first.
14. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the “Last Updated” date at the top of this page, and, for material changes, we will provide reasonable advance notice through our website and (where technically feasible) an in-app notice. The previous version of the Policy will be archived and remain available on request for at least 12 months.
15. App Store Compliance
15.1 Google Play
Our Apps comply with the Google Play Developer Program Policies, the Google Play Families Policy (including the requirement that Apps targeting children do not transmit Advertising ID, device location, or personally identifiable information from children), the User Data Policy, and the Device and Network Abuse Policy. Each App’s store listing includes an up-to-date Data Safety section declaring the categories of data the App collects, shares, and the security practices in place.
15.2 Apple App Store
Our Apps comply with the App Store Review Guidelines, in particular Guidelines 1 (Objectivity and Usability), 2 (Functionality), 3 (Accuracy), 5 (Privacy), and 5.1.1 (Privacy — Data Collection and Storage). Each App’s App Privacy section (“Privacy Labels”) declares our use of data for tracking, linked to you, and not linked to you, in line with Apple’s categories. We use ATT (App Tracking Transparency) to surface a tracking prompt before the first invocation of any advertising identifier.
15.3 Advertising Identifiers
We disclose on the store listing and in the in-app notice that the App uses the Apple IDFA and Google GAID for advertising attribution and frequency capping, and that the user can reset or limit those identifiers through the device settings described in Section 8.1.
16. Age Rating & Classification
Each App is rated through the International Age Rating Coalition (IARC) questionnaire at the time of submission to Google Play, and through Apple’s App Age Rating system for the App Store. The available tiers are:
- 4+ — suitable for all ages; no objectionable content.
- 9+ — mild cartoon or fantasy violence, mild suggestive themes.
- 12+ — non-realistic violence toward human or animal characters, mild profanity, simulated gambling.
- 17+ — unrestricted access to mature themes, intense violence, sexual content, or real gambling.
For Google Play we additionally map our Apps to the target age groups defined in the Google Play Families Policy (“Everyone”, “Everyone 10+”, “Teen”, “Mature”). For general-audience and children-eligible Apps we disable personalised ads, real-money transactions, and any data collection that requires the User-Generated Content or Personal Information permissions.
17. Advertising Networks & SDKs
The Apps integrate the following advertising partners. Each partner acts as an independent controller of the data it receives and operates under its own privacy policy, but we have summarized, for each partner, the data we believe it processes, the purposes, the user controls available, and the opt-out options. The App may call multiple partners in a single session through real-time bidding or waterfall mediation; the disclosure below covers the union of all partners we have configured at the date of this Policy.
Ad formats served across our Apps include: App Open / Splash, Rewarded Video, Interstitial, Banner, Native, and MREC (Medium Rectangle). The presence of a particular partner in a particular format depends on the App and the region.
17.1 Google AdMob Vendor
- Owner
- Google Ireland Ltd. / Google LLC
- Policy
- policies.google.com/privacy · ads policy
- Data collected
- Device identifiers (IDFA on iOS, GAID on Android), IP address, coarse location derived from IP, app version, device model, OS version, language, ad impression and click events, frequency-cap state.
- Purpose
- Ad serving, frequency capping, ad attribution, fraud prevention, measurement, and (with consent) personalized advertising.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), reset advertising ID, or visit adssettings.google.com to manage Google ad personalization across signed-out devices.
- Opt-out
- Disable via the device controls above; managed via Google Play Services on-device settings.
17.2 Meta Audience Network (Facebook) Vendor
- Owner
- Meta Platforms Ireland Ltd. (EEA/UK) / Meta Platforms, Inc. (rest of world)
- Policy
- facebook.com/privacy/policy · advertising policy
- Data collected
- Advertising ID, IP address, device/OS metadata, event data, ad impressions and clicks, cookie and SDK identifiers, hashed email if you link your account.
- Purpose
- Audience-matched advertising, conversion measurement, frequency capping, fraud and abuse detection.
- User control
- Use Facebook Ad Preferences; for EEA/UK users, see Meta’s “Audience Network for Developers” consent flow; on iOS the ATT prompt is required.
- Opt-out
- Disable in the device settings or via the “Audience Network” opt-out page at facebook.com/help/568137493302217.
17.3 Unity Ads Vendor
- Owner
- Unity Technologies Finland Oy (EEA/UK) / Unity Software Inc. (rest of world)
- Policy
- unity.com/legal/privacy-policy
- Data collected
- Advertising ID, IP address, device and OS metadata, install referrer, IDFV (iOS), coarse location, ad impression and click events, IAB Open Measurement signals.
- Purpose
- Ad serving, attribution, frequency capping, fraud detection, analytics on ad performance.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), Unity’s privacy choices, and the IAB Europe Transparency & Consent Framework when applicable.
- Opt-out
- Opt out through the device-level controls; Unity will respect those signals in its SDK.
17.4 AppLovin (MAX) Vendor
- Owner
- AppLovin Corporation
- Policy
- applovin.com/privacy
- Data collected
- Advertising ID, IP address, device/OS metadata, app metadata, ad impression and click events, session information, OPT (idfa-sync) signals, IAB signals.
- Purpose
- Mediation between multiple demand sources, real-time bidding, frequency capping, fraud detection, performance analytics.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), and AppLovin’s “Do Not Sell or Share My Personal Information” page where required by US state law.
- Opt-out
- Use the device-level controls or contact AppLovin through the privacy page above.
17.5 ironSource (now Unity LevelPlay) Vendor
- Owner
- ironSource Ltd. (now part of Unity) — operated under Unity Technologies
- Policy
- is.com privacy policy · unity.com/legal/privacy-policy
- Data collected
- Advertising ID, IP address, device and OS metadata, app metadata, install referrer, ad impression and click events.
- Purpose
- Mediation (now LevelPlay), ad serving, attribution, frequency capping, fraud prevention, ad performance reporting.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), and Unity’s privacy choices.
- Opt-out
- Through device-level controls; ironSource will respect the platform opt-out signal.
17.6 Vungle Vendor
- Owner
- Vungle, Inc. (a Liftoff company)
- Policy
- vungle.com/privacy
- Data collected
- Advertising ID, IP address, device and OS metadata, app metadata, ad impression and click events, crash diagnostics.
- Purpose
- Ad serving, frequency capping, performance measurement, fraud prevention.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), and the opt-out page at vungle.com/opt-out.
- Opt-out
- Use the device-level controls or Vungle’s opt-out form.
17.7 Chartboost Vendor
- Owner
- Chartboost, Inc. (a Zynga company)
- Policy
- chartboost.com/privacy
- Data collected
- Advertising ID, IP address, device and OS metadata, app metadata, ad impression and click events, hashed user IDs for cross-promotion.
- Purpose
- Direct-sold and cross-promoted ads, in-app bidding, frequency capping, analytics.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), and the “Do Not Sell or Share” link where required.
- Opt-out
- Use device-level controls or contact Chartboost via the privacy page above.
17.8 InMobi Vendor
- Owner
- InMobi Technology Services Pvt. Ltd. / InMobi Pte. Ltd.
- Policy
- inmobi.com/privacy-policy
- Data collected
- Advertising ID, IP address, device and OS metadata, coarse location, app metadata, ad impression and click events.
- Purpose
- Ad serving, frequency capping, audience segmentation (where consent is given), fraud prevention, measurement.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), and InMobi’s preference center at inmobi.com/privacy-policy.
- Opt-out
- Device-level controls or InMobi’s opt-out portal.
17.9 Pangle (TikTok Audience Network) Vendor
- Owner
- ByteDance Ltd. / TikTok Technology Ltd.
- Policy
- pangleglobal.com/privacy · TikTok privacy policy
- Data collected
- Advertising ID, IP address, device and OS metadata, app metadata, ad impression and click events, coarse location.
- Purpose
- Ad serving, frequency capping, performance reporting, fraud detection, audience matching within the TikTok Business ecosystem.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), and Pangle’s “Manage Ad Preferences” tool.
- Opt-out
- Device-level controls or Pangle’s preference tool.
17.10 Digital Turbine (Fyber) Vendor
- Owner
- Digital Turbine Media, Inc. (Fyber)
- Policy
- fyber.com/privacy-policy
- Data collected
- Advertising ID, IP address, device and OS metadata, app metadata, ad impression and click events.
- Purpose
- FairBid mediation, ad serving, frequency capping, yield optimization, fraud detection.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), and Fyber’s privacy choices page.
- Opt-out
- Device-level controls or Fyber’s opt-out form.
17.11 AdColony Vendor
- Owner
- AdColony, Inc. (a Digital Turbine company)
- Policy
- adcolony.com/privacy-policy
- Data collected
- Advertising ID, IP address, device and OS metadata, app metadata, coarse location, ad impression and click events.
- Purpose
- Ad serving, frequency capping, fraud prevention, performance reporting, video completion verification.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), and the AdColony privacy choices page.
- Opt-out
- Device-level controls or AdColony’s opt-out portal.
17.12 Start.io Vendor
- Owner
- Start.io (formerly StartApp)
- Policy
- start.io privacy policy
- Data collected
- Advertising ID, IP address, device and OS metadata, app metadata, list of installed apps (subject to platform policy), coarse location.
- Purpose
- Ad serving, frequency capping, audience targeting, fraud detection, measurement.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), and Start.io’s opt-out page. On Android, you may also revoke the “QUERY_ALL_PACKAGES” permission where granted.
- Opt-out
- Device-level controls or Start.io’s opt-out form.
17.13 Tapjoy Vendor
- Owner
- Tapjoy, Inc.
- Policy
- tapjoy.com/privacy-policy
- Data collected
- Advertising ID, IP address, device and OS metadata, app metadata, reward grant events, ad impression and click events.
- Purpose
- Rewarded ad serving, reward verification, frequency capping, fraud prevention, performance measurement.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), and Tapjoy’s opt-out page.
- Opt-out
- Device-level controls or Tapjoy’s opt-out form.
17.14 Mintegral Vendor
- Owner
- Mintegral International S.A.R.L. (Mobvista group)
- Policy
- mintegral.com/en/privacy
- Data collected
- Advertising ID, IP address, device and OS metadata, app metadata, coarse location, ad impression and click events.
- Purpose
- Ad serving, frequency capping, audience segmentation, attribution, fraud detection.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), and Mintegral’s opt-out page.
- Opt-out
- Device-level controls or Mintegral’s opt-out portal.
17.15 Amazon Publisher Services / Amazon Mobile Ads Vendor
- Owner
- Amazon.com Services LLC / Amazon Europe Core S.àr.l.
- Policy
- aps.amazon.com privacy policy · amazon.com/privacy
- Data collected
- Advertising ID, IP address, device and OS metadata, app metadata, ad impression and click events, hashed user IDs for matching across Amazon properties.
- Purpose
- Header bidding / mediation, ad serving, frequency capping, attribution, fraud detection, performance reporting.
- User control
- Limit Ad Tracking (iOS), Opt out of Ads Personalization (Android), and Amazon’s “Interest-Based Ads” preference center at amazon.com/adprefs.
- Opt-out
- Device-level controls or Amazon’s ad preference center.
18. Contact Us
If you have any questions about this Privacy Policy, want to exercise a right, or need to notify us of a concern, please contact:
K LmofWY — Privacy Office
Email: gideot@theboartech.pics
Website: klmofwy.com
We acknowledge privacy enquiries within 5 business days and respond substantively within the time limits imposed by applicable law.