## 1. Who we are
Arrows Puzzle Lover (the "app") is published by Nik Flat Miaz ("we",
"us", or "our"). You can contact us about privacy at didioncentrichefjq3580@gmail.com
.
## 2. Scope of this policy
This policy explains what information the app processes and how. It covers the
current version of the Android app, built with Flutter (application ID
`com.puzzle.arrow.lovepath`). The app is prepared for release on Android; the
store listing is not yet published.
This policy is written for a global audience. It is governed by the laws of Where local law gives you additional rights, Section 14
applies.
## 3. What information the app processes, in short
The app processes three groups of information:
- **Information you give us** — optional star ratings and free-text feedback,
and (if you contact us by email) whatever you write and send.
- **Information stored on your device** — your game progress, preferences and
in-game state. The detailed state is saved on your device; selected
gameplay, daily, advertising and rating values are also transmitted to our
analytics as described in Sections 5 and 8.
- **Information processed by third-party services the app uses** — Google
Mobile Ads (advertising) and Google Firebase (analytics, remote
configuration and a small usage database), described in Sections 7 and 8.
The app itself does not ask you to create an account and does not process any
payments. Section 9 lists the things the app does not do.
## 4. Information you provide
- **Rating.** If you rate the game (1–5 stars) in the in-app rating dialog,
the chosen star count is sent to our analytics and usage counters
(Section 8), and a flag is stored on your device so that we do not ask you
again.
- **Feedback.** If you write feedback — after a low rating, or from
Settings → Feedback — the app attempts to submit the text (up to 500
characters) together with the app version, your device model and your
operating system version. Delivery or acceptance is not guaranteed and
depends on the backend and contact configuration deployed at the time.
Feedback written after a rating is submitted together with that rating and
is stored only if the backend accepts the write; feedback written from
Settings carries no attached rating and may not be accepted by the
database. Section 8 describes how feedback is handled.
- **Contact email.** Settings → Contact opens your device's mail app,
addressed to the contact address configured for the app, with your app
version, device model and OS version pre-filled into the message. The email
is only composed for you — it is sent only if you send it from your mail
app. If no contact address is configured, the row opens the in-app feedback
dialog instead; either way, we receive only what you choose to send.
## 5. Information stored on your device
The app stores the following on your device (in the platform's standard
key-value storage):
- your game progress (highest unlocked level) and first-launch state;
- your preferences: sound, music, vibration and auto-lock toggles, and the
language you chose for the interface;
- your coin balance and the free-coin earning state (how many rewarded ads you
watched today, how many shares, whether you have rated and claimed the
rating reward, how many mini-game rounds you played);
- daily state: daily-challenge completions, check-in days and streak, and
daily-task progress and claims;
- rating prompt state (whether and when you were last asked to rate);
- the timestamp of the last full-screen ad shown, used to space ads out
(frequency capping);
- the raw Google Play install referrer string, and the install source derived
from it (organic traffic or an advertising campaign);
- which gallery rewards you have unlocked, and a random seed used by the
surprise box;
- one-off "tip" flags for the booster explainers.
This detailed state is stored locally on your device. However, selected
gameplay, daily, advertising and rating values are transmitted to us as
analytics telemetry (Section 8), and the install source derived from the Play
install referrer is transmitted to Firebase Analytics and the usage counters;
the raw referrer string itself stays on your device.
Booster balances are held in memory for the current session only and reset
when the app is closed. This data is tied to the app's own storage, not to an
account. Clearing the app's data or uninstalling the app deletes it
(Section 11).
## 6. Media gallery, caching, and saving to your device
The app includes a photo/video reward gallery. The list of available items is
bundled with the app and can be updated by us through Firebase Remote Config.
The media listed in the bundled gallery is streamed over HTTPS from a content
delivery network; the media host in the current bundled source is
`https://s3.appsthe.net`. The app source does not identify the operator of
that host or the region it is hosted in . The
media lists can be updated through Remote Config, and the app source cannot
verify the transport of every live URL.
- **Viewing.** When you view a gallery photo, the app keeps a temporary copy
on your device so it does not have to be downloaded again. The photo cache
holds up to 150 items, refreshes items older than 30 days, and evicts the
least-recently-used files when full (roughly an 80 MB ceiling at current
photo sizes). Videos are streamed and are not kept in this cache.
- **Saving.** When you choose to download a reward to your device, the app
saves a copy of the photo or video into your device's gallery app, in an
album named "Arrows Puzzle Lover" (on older Android versions this requires a
storage permission). This is a local action on your device; the file is not
uploaded anywhere.
## 7. Advertising
The app shows advertisements served by Google Mobile Ads (AdMob), including
banner ads, full-screen (interstitial) ads, native ads and rewarded ads, on
various screens (start-up, onboarding, gameplay, the win screen, coin rewards
and mini-games). Ads are frequency-capped and can be turned off by us at any
time.
**Consent (UMP).** The app uses Google's User Messaging Platform (UMP) to
manage advertising consent. At startup, the app uses Google's locally cached
UMP eligibility: if the cached state allows ads, the Mobile Ads SDK may
initialize while a fresh consent update runs in the background; otherwise,
initialization waits for UMP. In regions that require consent (such as the
EEA and the UK), you are asked for consent through Google's consent form, and
your choice is stored on your device by Google's consent software. You can
review or change that choice at any time through the "Privacy Preferences"
entry in the app's Settings, which is shown when Google's software reports it
is required. The current code does not explicitly unload already loaded ads
or reconfigure an already initialized advertising SDK after you change your
choice, so a restart may be needed for the choice to be fully reflected. This
describes the app's current technical behavior; it does not change your legal
right to refuse or withdraw consent, and Google's consent software remains
governed by Google's own controls. The consent form also links to a
privacy-policy URL configured in the Google AdMob/UMP console —
[UMP_PRIVACY_POLICY_URL] — which must be set to this document before
publication.
**What Google's ad software may process.** Like all apps that use Google
Mobile Ads, ad requests are made automatically to Google. Google's ad software
may process your device's IP address (from which an approximate location can
be derived), device identifiers such as the Android advertising ID (the app
declares the AD_ID permission that the Google Mobile Ads SDK requires on
Android 13 and later), information about your device and app usage, and, for
signed-in users, Google account identifiers — for the purposes described in
Google's own privacy policy. The app code itself does not read these
identifiers; they are handled by Google's SDKs. Please see:
- Google Privacy Policy: https://policies.google.com/privacy
- AdMob privacy guidance for Flutter apps:
https://developers.google.com/admob/flutter/privacy
## 8. Analytics and product improvement
The app uses Google Firebase for analytics and remote configuration.
- **Firebase Analytics.** The app sends analytics events describing how the
app is used. Event categories include: app opens and screen views;
onboarding steps and language choice; levels started and completed, daily
challenge completion and booster use, with simple parameters such as the
level number; daily check-in activity; rating prompts, submitted ratings and
feedback attempts; ad activity (loads, successes, failures, shows, clicks
and paid impressions); and Remote Config fetch results. Events may carry
simple parameters such as a level number, an ad placement name, or a star
count. Firebase Analytics also uses an installation identifier for the app
instance — an automatically generated ID, not your name or email — to
associate events over time, and may automatically collect standard device
information (such as device model and OS version) as described in Firebase's
privacy documentation. The configured event retention period is
Firebase Analytics.
- **Firebase Remote Config.** The app downloads runtime settings from Firebase
(ad unit IDs, frequency caps, feature switches, and the gallery item lists)
so that behavior can be updated without releasing a new version of the app.
- **Firebase Realtime Database — usage counters.** The app records small
aggregate counters: one per install (bucketed by install source and day),
one per app open, and one per submitted rating (bucketed by day and star
count). These are counts, not individual user profiles.
- **Feedback records.** The app attempts to submit free-text feedback written
after a rating; if the live backend accepts the write, the record contains
the rating, the source, the date, and the automatically attached app
version, device model and OS version. Delivery or acceptance is not
guaranteed or confirmed by the app. Feedback written from Settings carries
no valid star rating in the request and may be rejected depending on the
database rules deployed in the Firebase console, which are a live
configuration the app source cannot verify. For records actually accepted
and stored, the app code contains no deletion of feedback records; their
retention is [RTDB_FEEDBACK_RETENTION].
- **Play Install Referrer (Android).** Once per installation, the app reads
the Google Play install referrer to learn whether the install came from
organic Play traffic or from an advertising campaign. The raw referrer
string is stored on your device, and a derived source name (for example
"Organic" or a campaign name) is sent to Firebase Analytics and the usage
counters above.
Firebase documentation:
- Firebase privacy and security: https://firebase.google.com/support/privacy
## 9. What the app does not do
Based on the current version of the app, it does **not**:
- implement an account, login or registration system;
- process payments or in-app purchases of any kind (coins are earned in-game
only);
- let you upload photos, videos, or any other user-generated content;
- access your device's precise location or request location permissions (the
advertising SDKs may derive an approximate location from your IP address, as
described in Section 7);
- access your camera, microphone, or contacts;
- send push notifications;
- use crash-reporting services such as Crashlytics or Sentry;
- provide an in-app data export or deletion feature.
This list reflects the current source only and is not a promise about future
versions.
## 10. Consent and your choices
- **Ad consent.** You can give, refuse, or withdraw ad consent through the
Google consent form and the "Privacy Preferences" entry in Settings
(Section 7). At startup the app uses Google's locally cached consent state
to decide whether to initialize ads. Because the app does not unload
already loaded ads or reconfigure an already initialized ad SDK after you
change your choice, a restart may be needed for the change to be fully
reflected.
- **On-device data.** You can delete the app's on-device data at any time by
clearing the app's storage in your device settings or by uninstalling the
app. This removes the app's private state and cache, but not copies of
gallery rewards you saved to your device's gallery — delete those separately
in your gallery app.
- **Advertising IDs.** You can reset your Android advertising ID or turn off
ad personalization in your device's Google settings.
- **Media.** Saving gallery rewards to your device's gallery is always your
choice (Section 6).
## 11. Data retention and deletion
- **On your device:** the data in Section 5 remains until you clear the app's
storage or uninstall it. The gallery photo cache expires items after 30 days
and evicts older items when it reaches its 150-item limit. Clearing the
app's storage or uninstalling it does not remove gallery copies you saved to
your device's gallery — you must delete those separately.
- **In Firebase Analytics:** event retention is a Firebase console setting;
the current configured value is [FIREBASE_ANALYTICS_RETENTION].
- **Feedback records:** for feedback records that were actually accepted and
stored, the app code contains no automatic deletion; they are retained until
manually removed, with a planned retention period of
[RTDB_FEEDBACK_RETENTION].
- **Deletion requests:** because the app has no in-app deletion or export
flow, requests to delete or obtain a copy of data associated with feedback
must be made to us directly. [DELETION_REQUEST_PROCESS]
## 12. International data transfers
The third-party services in Sections 7 and 8 (Google Mobile Ads and Firebase)
are operated by Google and its sub-processors, which may process your data on
servers in countries other than your own, including outside the EEA and the
UK. Where such transfers take place, we rely on the safeguards described in
[CROSS_BORDER_TRANSFER_SAFEGUARDS], together with the mechanisms Google itself
provides (see the links in Sections 7 and 8).
The app also requests gallery media from a content delivery network host
(currently `s3.appsthe.net`). Each media request exposes ordinary network
metadata — such as your IP address, user-agent and device request data — to
that host. The operator of the host and the region where it is hosted is
[CDN_OPERATOR_AND_REGION].
## 13. Security
The media URLs bundled with the current version of the app use HTTPS. Transfers
to Firebase and Google's ad services are handled by those providers; please see
their security documentation (linked in Sections 7 and 8) for details. The app
source cannot verify the transport of every live Remote Config URL or every
individual provider transfer, and we cannot guarantee that any transmission or
storage is completely secure. On-device game data is protected by the standard
security of your device's operating system. The app does not process payment
data or passwords.
## 14. Your rights
Depending on where you live (for example, in the EEA, the UK, or other
jurisdictions with similar laws), you may have the right to access, correct,
or delete information about you; to object to or restrict certain processing;
to data portability; and to lodge a complaint with your local data protection
authority. To exercise these rights, contact us at didioncentrichefjq3580@gmail.com;
we will respond in line with applicable law. Because the app does not use
accounts, most requests will concern the feedback records described in
Section 8. [DELETION_REQUEST_PROCESS]
## 15. Children
The app code does not include an age gate and does not configure Google's
child-directed consent treatment. 16+ — confirm how the app
should be positioned for children (for example, as not directed at children
under the age set by your target regions) and what age rating the store
listing will carry, and adjust this section and the ad configuration
accordingly.]
## 16. Changes to this policy
We may update this policy from time to time. When we do, we will update the
effective date at the top of this page and, where practicable, publish a
notice in the app. Material changes will not apply retroactively.
## 17. Contact us
For questions about this policy or about your data, contact us at
didioncentrichefjq3580@gmail.com