Generator-based review draft — pending final operator approval

Find Friends Privacy Policy

English version for the Android App

Generator draft review status

This draft was generated with a free policy generator and supplemented after comparison with the Android AdMob/UMP, Firebase Analytics/Crashlytics, and optional Play Games configuration. The generator is not legal advice; final release settings and operator approval must be confirmed before treating this as an effective policy.

Operator
Acrevibe Studio (trade name: Bom Studio)
Privacy contact
help@bomstudio.co.kr
Effective date
2026-09-16
Version
1.0

1. Information processed

AreaInformationLocation or stateWhen processed
Local gameplayCharacter and stage IDs, found characters and completed stages, music/effects/haptics settings, local advertising stateAndroid app-private storageOrdinary play
Local recordsStage ID and title, best and recent play time, completion count, last completion time, pending-sync event IDAndroid app-private storageRecords are created or synchronized
Play GamesAccount/player information processed by Google during authentication and a one-time server authorization codeGoogle Play Games and synchronization requestUser explicitly connects and requests synchronization
Remote recordsStage ID and title, play time, completion count, last completion time, pseudonymous identifierApproved records API and databaseOnly if enabled
Advertising and consentAd requests, impressions/interactions, consent state, device/app/SDK diagnostics, advertising identifiersGoogle Mobile Ads SDK, UMP, and related servicesWhen enabled
Product analyticsBounded screen, stage, content, hint, and ad-flow eventsFirebase AnalyticsWhen enabled
Crash and diagnosticsApp crashes, performance and diagnostic informationFirebase CrashlyticsWhen enabled
Network and deliveryIP address, request time, User-Agent, and standard request informationAWS, CloudFront, or similarWhen remote content or records API is contacted

In the inspected code, the App does not directly request a name, phone number, contacts, microphone, camera, precise location, or payment instrument for gameplay. Providers may process information under their own policies.

2. Purposes

  1. save and restore gameplay, settings, and completion records;
  2. provide user-requested Play Games connection and synchronization;
  3. serve ads, operate rewarded features, prevent abusive ad requests, and measure performance;
  4. investigate crashes, errors, and performance and improve stability;
  5. deliver and verify public game content; and
  6. respond to support requests, protect the service, investigate violations, and comply with law.

3. Legal basis, consent, and withdrawal

Local gameplay is processed to provide the requested game features. Play Games and remote records are processed only after an explicit user request, and local play remains available without the connection. Legal bases and regional requirements follow applicable law, Google UMP consent status, and the final release configuration. Users may change choices through UMP consent or Privacy Options when shown.

4. Google Mobile Ads and advertising identifiers

The current Android source includes Google Mobile Ads SDK, an advertising application ID, and interstitial, rewarded, and banner ad hosts. Google states that the mobile ads SDK may collect or share IP address, app interactions, diagnostic information, Android Advertising ID, App Set ID, and other device or account identifiers for advertising, measurement, and fraud prevention. An advertising identifier can be reset or deleted in Android settings. Before release, the SDK, live ad units, UMP, Privacy Options, child settings, and Google Play Data safety disclosure must match the actual build.

5. Firebase Analytics and Crashlytics

  1. Analytics events are designed to use bounded product values such as screen name, public stage/content IDs, success state, elapsed time, hint count, and ad format, placement, and status.
  2. The inspected code is designed not to put a Play Games player ID, Google authorization code or token, email, or name into Analytics events.
  3. Crashlytics may investigate crashes, stability, and diagnostics. Exact automatic fields follow the actual Firebase project configuration and current provider documentation.
  4. Activation, pre-consent behavior, retention, access, deletion, and withdrawal follow the actual Firebase/UMP settings and provider policies.

6. Play Games and remote records

  1. Play Games starts only after a Settings choice. The App does not store an account name, email, raw player ID, or token in the ordinary UI or App storage.
  2. When enabled, the App may send a one-time server authorization code and record events to the records API. The server may use a hashed or pseudonymous provider identifier.
  3. Remote records are limited to stage ID/title, elapsed time, completion count, last completion time, and minimum service metadata.
  4. The Play Games project, server client, API, and deletion procedure must be approved before this becomes a public feature.

7. AWS and content delivery

The App may verify and download public stage, music, and character channels and files over HTTPS. A delivery provider may process IP address, request time, User-Agent, errors, transfer volume, and standard network information. Public content is delivered through AWS, CloudFront, or another service selected by the actual deployment configuration; processing locations, logs, subprocessors, and international transfers follow the provider’s current policy and operating configuration.

8. Processors and third parties

ProviderRoleInformation that may be processed
Google Play Games ServicesOptional connection, record authentication, synchronizationGoogle account/player information and selected records
Google Mobile Ads / UMPAdvertising, measurement, consent managementAd request, IP, interactions, diagnostics, advertising/app identifiers, consent state
Firebase Analytics / CrashlyticsProduct analytics, crash, diagnosticsBounded events and app, device, diagnostic information
AWS, CloudFront, or similarPublic content and records API deliveryStandard network information and minimum record-operation data

See Google Mobile Ads data disclosure and Play Games Services Terms. If a build does not use advertising, analytics, diagnostics, or remote records, those features must not be enabled.

9. Retention

Local gameplay, settings, and records may remain until the user clears App data or uninstalls the App. No approved public operating procedure currently exists for remote records, so their retention period, backups, logs, and retry queues are not defined here; the Operator will set and publish those rules before enabling the feature. Google, Firebase, AWS, and other providers retain information according to their current policies, console settings, and final release configuration.

10. Deletion

  1. Users can delete local data by clearing App data or uninstalling through Android settings.
  2. Disconnecting Play Games does not delete the Google account; provider-held data follows that provider’s controls.
  3. If remote records are operated, contact help@bomstudio.co.kr with the minimum verification information and records to delete. The Operator will publish the request procedure and target before enabling the feature; no approved public remote-record or account-deletion procedure currently exists.
  4. The Operator will not ask for a password, authorization code, access token, refresh token, raw advertising identifier, or raw logs.

11. User rights and requests

Subject to applicable law, users may request access, correction, deletion, restriction, withdrawal of consent, or other remedies by contacting help@bomstudio.co.kr. The Operator will request only the minimum information needed to verify the request and respond within the period required by applicable law. Information held by a third-party provider follows that provider’s request process.

12. International transfers

Google, Firebase, AWS, and other providers may process or store personal and network information outside the user’s country. The categories, destinations, timing, method, recipients, and safeguards follow the providers’ current policies and the final project and deployment settings; this document will be updated for material changes.

13. Children and minors

The App is not designed primarily for children and does not knowingly collect personal information from children under 13. A parent or guardian who believes a child has provided information may contact help@bomstudio.co.kr so the Operator can review the matter. Store and advertising-console age and child-directed settings must match the actual release configuration.

14. Privacy contact

15. Changes

The Operator may update this Policy when law, services, SDKs, processors, or purposes change and will show the version, effective date, and summary.