Effective Date: April 25, 2026
Valid Until: April 25, 2028
This Privacy Policy explains how our service collects, uses, stores, and manages limited technical data required for authentication, security, and system integrity.
By using this service, you agree to the practices described in this policy.
We collect only the minimum technical data necessary to operate and secure the service:
IP address
Device identifier (non-reversible hashed device fingerprint)
Attestation tokens (device authenticity verification)
Nonce values (replay protection and request validation)
Session identifiers and temporary authentication tokens
Request metadata (timestamps, endpoints accessed, and integrity checks)
We do not collect personal information such as names, emails, contacts, or user-generated content unless explicitly stated elsewhere.
Collected data is used strictly for:
Authentication and session management
Verifying device integrity and preventing spoofing
Preventing unauthorized access and replay attacks
Detecting abuse, fraud, or anomalous behavior
Ensuring service stability and security
We use the following data processor to operate backend services:
Microsoft Azure PlayFab (authentication, session management, and secure data storage)
PlayFab and its underlying infrastructure may process data in multiple regions, including but not limited to:
United States
Ireland (EU)
Netherlands (EU)
Singapore
Japan
Australia
These providers process data solely on our behalf and do not use it for independent purposes.
We do not sell or share personal data with unrelated third parties.
Session tokens and nonces are short-lived and automatically expire.
Authentication sessions are retained only while actively in use.
Security logs and metadata may be retained temporarily for abuse prevention, diagnostics, and system integrity.
Data is stored using industry-standard security practices.
We may disclose limited data only when required to:
Comply with applicable laws or legal requests
Enforce system security
Investigate abuse, fraud, or unauthorized access
We implement security controls including:
Cryptographic request validation
Device attestation verification
Rate limiting and abuse detection systems
Secure token generation and expiration handling
All users, regardless of location or jurisdiction, may request access to or deletion of applicable stored data associated with their device identifiers.
To request data deletion:
Join our official Discord server.
Contact Kurova (Discord: kurova_gm) with your deletion request.
Alternatively, you may submit a deletion request by emailing:
yuta67yuji@gmail.com
Deletion requests may require verification to ensure the request is associated with the correct account or device.
Some data may be retained where necessary for:
Security monitoring
Fraud prevention
Abuse investigations
Legal compliance obligations
This Privacy Policy may be updated periodically. Continued use of the service after updates constitutes acceptance of the revised policy.
For questions, privacy requests, or data deletion requests:
Discord: kurova_gm
Email: yuta67yuji@gmail.com
This system collects only minimal technical data required for authentication, security, and integrity. No personal content or unnecessary user data is collected or sold.
All users may request deletion of applicable stored data regardless of region by contacting Kurova through Discord or by emailing the address provided above. Data is processed securely through trusted backend infrastructure providers.