Generator draft review status
This draft was generated with a free policy generator and supplemented after comparison with the Android AdMob/UMP, Firebase Analytics/Crashlytics, and optional Play Games configuration. The generator is not legal advice; final release settings and operator approval must be confirmed before treating this as an effective policy.
- Operator
- Acrevibe Studio (trade name: Bom Studio)
- Privacy contact
- help@bomstudio.co.kr
- Effective date
- 2026-09-16
- Version
- 1.0
1. Information processed
| Area | Information | Location or state | When processed |
|---|---|---|---|
| Local gameplay | Character and stage IDs, found characters and completed stages, music/effects/haptics settings, local advertising state | Android app-private storage | Ordinary play |
| Local records | Stage ID and title, best and recent play time, completion count, last completion time, pending-sync event ID | Android app-private storage | Records are created or synchronized |
| Play Games | Account/player information processed by Google during authentication and a one-time server authorization code | Google Play Games and synchronization request | User explicitly connects and requests synchronization |
| Remote records | Stage ID and title, play time, completion count, last completion time, pseudonymous identifier | Approved records API and database | Only if enabled |
| Advertising and consent | Ad requests, impressions/interactions, consent state, device/app/SDK diagnostics, advertising identifiers | Google Mobile Ads SDK, UMP, and related services | When enabled |
| Product analytics | Bounded screen, stage, content, hint, and ad-flow events | Firebase Analytics | When enabled |
| Crash and diagnostics | App crashes, performance and diagnostic information | Firebase Crashlytics | When enabled |
| Network and delivery | IP address, request time, User-Agent, and standard request information | AWS, CloudFront, or similar | When remote content or records API is contacted |
In the inspected code, the App does not directly request a name, phone number, contacts, microphone, camera, precise location, or payment instrument for gameplay. Providers may process information under their own policies.
2. Purposes
- save and restore gameplay, settings, and completion records;
- provide user-requested Play Games connection and synchronization;
- serve ads, operate rewarded features, prevent abusive ad requests, and measure performance;
- investigate crashes, errors, and performance and improve stability;
- deliver and verify public game content; and
- respond to support requests, protect the service, investigate violations, and comply with law.
3. Legal basis, consent, and withdrawal
Local gameplay is processed to provide the requested game features. Play Games and remote records are processed only after an explicit user request, and local play remains available without the connection. Legal bases and regional requirements follow applicable law, Google UMP consent status, and the final release configuration. Users may change choices through UMP consent or Privacy Options when shown.
4. Google Mobile Ads and advertising identifiers
The current Android source includes Google Mobile Ads SDK, an advertising application ID, and interstitial, rewarded, and banner ad hosts. Google states that the mobile ads SDK may collect or share IP address, app interactions, diagnostic information, Android Advertising ID, App Set ID, and other device or account identifiers for advertising, measurement, and fraud prevention. An advertising identifier can be reset or deleted in Android settings. Before release, the SDK, live ad units, UMP, Privacy Options, child settings, and Google Play Data safety disclosure must match the actual build.
5. Firebase Analytics and Crashlytics
- Analytics events are designed to use bounded product values such as screen name, public stage/content IDs, success state, elapsed time, hint count, and ad format, placement, and status.
- The inspected code is designed not to put a Play Games player ID, Google authorization code or token, email, or name into Analytics events.
- Crashlytics may investigate crashes, stability, and diagnostics. Exact automatic fields follow the actual Firebase project configuration and current provider documentation.
- Activation, pre-consent behavior, retention, access, deletion, and withdrawal follow the actual Firebase/UMP settings and provider policies.
6. Play Games and remote records
- Play Games starts only after a Settings choice. The App does not store an account name, email, raw player ID, or token in the ordinary UI or App storage.
- When enabled, the App may send a one-time server authorization code and record events to the records API. The server may use a hashed or pseudonymous provider identifier.
- Remote records are limited to stage ID/title, elapsed time, completion count, last completion time, and minimum service metadata.
- The Play Games project, server client, API, and deletion procedure must be approved before this becomes a public feature.
7. AWS and content delivery
The App may verify and download public stage, music, and character channels and files over HTTPS. A delivery provider may process IP address, request time, User-Agent, errors, transfer volume, and standard network information. Public content is delivered through AWS, CloudFront, or another service selected by the actual deployment configuration; processing locations, logs, subprocessors, and international transfers follow the provider’s current policy and operating configuration.
8. Processors and third parties
| Provider | Role | Information that may be processed |
|---|---|---|
| Google Play Games Services | Optional connection, record authentication, synchronization | Google account/player information and selected records |
| Google Mobile Ads / UMP | Advertising, measurement, consent management | Ad request, IP, interactions, diagnostics, advertising/app identifiers, consent state |
| Firebase Analytics / Crashlytics | Product analytics, crash, diagnostics | Bounded events and app, device, diagnostic information |
| AWS, CloudFront, or similar | Public content and records API delivery | Standard network information and minimum record-operation data |
See Google Mobile Ads data disclosure and Play Games Services Terms. If a build does not use advertising, analytics, diagnostics, or remote records, those features must not be enabled.
9. Retention
Local gameplay, settings, and records may remain until the user clears App data or uninstalls the App. No approved public operating procedure currently exists for remote records, so their retention period, backups, logs, and retry queues are not defined here; the Operator will set and publish those rules before enabling the feature. Google, Firebase, AWS, and other providers retain information according to their current policies, console settings, and final release configuration.
10. Deletion
- Users can delete local data by clearing App data or uninstalling through Android settings.
- Disconnecting Play Games does not delete the Google account; provider-held data follows that provider’s controls.
- If remote records are operated, contact help@bomstudio.co.kr with the minimum verification information and records to delete. The Operator will publish the request procedure and target before enabling the feature; no approved public remote-record or account-deletion procedure currently exists.
- The Operator will not ask for a password, authorization code, access token, refresh token, raw advertising identifier, or raw logs.
11. User rights and requests
Subject to applicable law, users may request access, correction, deletion, restriction, withdrawal of consent, or other remedies by contacting help@bomstudio.co.kr. The Operator will request only the minimum information needed to verify the request and respond within the period required by applicable law. Information held by a third-party provider follows that provider’s request process.
12. International transfers
Google, Firebase, AWS, and other providers may process or store personal and network information outside the user’s country. The categories, destinations, timing, method, recipients, and safeguards follow the providers’ current policies and the final project and deployment settings; this document will be updated for material changes.
13. Children and minors
The App is not designed primarily for children and does not knowingly collect personal information from children under 13. A parent or guardian who believes a child has provided information may contact help@bomstudio.co.kr so the Operator can review the matter. Store and advertising-console age and child-directed settings must match the actual release configuration.
14. Privacy contact
- Operator: Acrevibe Studio (trade name: Bom Studio)
- Privacy officer: Kim Tae-su (representative)
- Privacy contact: help@bomstudio.co.kr
- Response target: Initial response targeted within 2–3 business days after receipt
15. Changes
The Operator may update this Policy when law, services, SDKs, processors, or purposes change and will show the version, effective date, and summary.
- Effective date: 2026-09-16
- Version: 1.0
- Change history: Generator draft supplemented with the verified operator, contact, and Android SDK boundaries.