Privacy Policy
Version 1.3 | Last Updated: July 15, 2026
1. Introduction
Welcome to Olhoten Apps ("we," "our," or "us"). We are committed to protecting your privacy and ensuring you have a positive experience when using our mobile applications. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use any of our applications ("Apps").
Developer: Olhoten Apps
Contact Email: olhoten.apps@gmail.com
We act as the Data Controller for personal data collected through our Apps. This means we determine the purposes and means of processing your personal data.
1.1 Applications Covered
This Privacy Policy applies to all mobile applications published by Olhoten Apps, including but not limited to:
- Ten Twins - Number Puzzle Game
...and any other applications published under the Olhoten Apps developer account on Google Play Store and Apple App Store.
1.2 Age Restriction
All Olhoten Apps applications are intended for users aged 16 and older. On first launch you must confirm that you are 16 or older. Our Apps are not directed to children, are not designed for use by children, and we do not knowingly collect personal information from anyone under 16.
1.3 Consent and Legal Basis
When you first launch any of our Apps, you will be presented with a consent screen to choose your privacy preferences. All users worldwide receive this consent prompt, regardless of location.
Your choices include:
- Analytics (help us improve the app)
- Personalized advertising (see relevant ads)
You can use our Apps regardless of your choices, and you can change your preferences at any time in Settings > Privacy.
How consent is collected:
- Age attestation: On first launch you confirm that you are 16 years of age or older and accept our Terms of Service and this Privacy Policy before any data-collecting service is enabled.
- EEA, UK and Switzerland: Advertising and analytics consent is collected through Google's User Messaging Platform (UMP) using the IAB Transparency & Consent Framework (TCF v2). Your choices are stored as an industry-standard TCF consent string and forwarded to our advertising partners.
- United States (California and other states): Opt-out signals are recorded using the IAB U.S. Privacy String / Global Privacy Platform and honored by our advertising partners.
- Consent gating: All SDKs that collect personal data or device identifiers (analytics, advertising, push notifications) initialize only after you have provided the applicable consent. If you decline, these services are not started.
- Data deletion: You can erase all data associated with you at any time from within the App via Settings > Privacy > Delete my data (see Section 6).
Legal Basis for Processing (GDPR):
| Processing Activity | Legal Basis | Can You Object? |
|---|---|---|
| Core app functionality | Contract (necessary to provide service) | No |
| Saving app progress | Contract | No |
| Processing purchases | Contract | No |
| Crash reporting | Legitimate Interest (app stability) | Yes* |
| Security and fraud prevention | Legitimate Interest | Yes* |
| Analytics | Consent | Yes |
| Personalized advertising | Consent | Yes |
| Push notifications | Consent | Yes |
*For legitimate interest processing, you may object, but we may continue processing if we demonstrate compelling legitimate grounds.
2. Information We Collect
We collect information automatically when you use our Apps and through third-party services integrated into our Apps. We do not collect sensitive personal information such as precise geolocation, racial/ethnic origin, religious beliefs, health data, sexual orientation, or biometric data.
2.1 Information Collected Automatically
| Data Type | Examples | Purpose | Legal Basis |
|---|---|---|---|
| Device Information | Device model, OS version, unique device identifiers | App functionality, crash reporting | Contract / Legitimate Interest |
| App Usage Data | Scores, progress, features used, session duration | Analytics, app improvement | Consent |
| App Progress | Achievements, in-app currency balance, preferences | Core functionality | Contract |
| Crash Data | Crash logs, error reports, diagnostic data | Bug fixing, stability improvement | Legitimate Interest |
| Advertising Data | Ad interactions, ad views, advertising identifiers | Displaying relevant ads | Consent |
| Purchase Data | Transaction history, purchase timestamps | Processing in-app purchases | Contract |
2.2 Information We Do NOT Collect
- Precise location data (GPS coordinates)
- Contact lists or address books
- Camera or microphone data
- Health or fitness data
- Financial account information (handled by Apple/Google)
- Social Security numbers or government IDs
- Biometric data
- Contents of messages or communications
3. How We Use Your Information
3.1 Core App Functionality (Legal Basis: Contract)
- Providing app features and functionality
- Saving your progress locally on device
- Processing in-app purchases
- Managing your preferences
3.2 Analytics and Improvement (Legal Basis: Consent)
- Understanding how users interact with our Apps
- Identifying popular features and areas for improvement
- Measuring the effectiveness of updates
- A/B testing new features
3.3 Security and Stability (Legal Basis: Legitimate Interest)
- Identifying and fixing bugs and crashes
- Preventing fraud and abuse
- Ensuring app security and integrity
Note: Crash reporting (Firebase Crashlytics) is processed on the basis of our legitimate interest in keeping the App stable and diagnosing failures (GDPR Art. 6(1)(f)). It operates independently of your Analytics choice. Crash reporting is disabled automatically in development/test builds, and it stops — with any unsent crash reports deleted — when you use the in-app Settings > Privacy > Delete my data flow. You may also object to this processing by contacting us.
3.4 Advertising (Legal Basis: Consent)
- Displaying advertisements (for non-premium users)
- Measuring ad performance
- Providing personalized ads based on your interests (with your consent)
- Serving contextual (non-personalized) ads (without consent)
3.5 Communications (Legal Basis: Consent)
- Sending push notifications (with your permission)
- Notifying you about rewards, events, and updates
- Responding to your inquiries
4. Third-Party Services and Data Sharing
We use trusted third-party services to provide certain features. These services act as Data Processors on our behalf and process data according to our instructions and their own privacy policies.
4.1 Firebase (Google)
| Service | Data Collected | Purpose |
|---|---|---|
| Firebase Analytics | App usage events, device info, user properties, app instance ID | Analytics |
| Firebase Crashlytics | Crash reports, stack traces, device info, app state, custom diagnostic keys | Crash reporting (legitimate interest — app stability) |
| Firebase Cloud Messaging | Push notification tokens (FCM token) | Push notifications |
| Firebase Remote Config | App instance ID, country, language | Feature flags, A/B testing |
Firebase Privacy Policy: firebase.google.com/support/privacy
4.2 Google Play Billing / Apple StoreKit (In-App Purchases)
In-app purchases are processed natively through Google Play Billing (Android) and Apple StoreKit (iOS). Purchase transactions are handled directly by the platform. We store purchase records locally on the device for purchase restoration purposes.
Google Play Privacy: policies.google.com/privacy
Apple Privacy: apple.com/legal/privacy
4.3 Google AdMob (Advertising)
Advertisements shown to non-premium users are served through Google AdMob, our primary advertising system. AdMob delivers rewarded, interstitial, and app-open ad formats and collects advertising identifiers and device information for ad serving, frequency capping, and measurement.
Consent: For users in the European Economic Area, the United Kingdom, and Switzerland, we collect advertising consent through Google's User Messaging Platform (UMP) using the IAB Transparency & Consent Framework (TCF v2) before any advertising data is collected. Without consent, only contextual (non-personalized) ads are shown.
Ad mediation: AdMob operates a mediation waterfall that may fill an ad request through additional advertising networks integrated as mediation partners. The mediation partners currently enabled are Unity Ads, ironSource, and Chartboost. When one of these partners fills an ad, it may collect advertising identifiers and device information under its own privacy policy. Your GDPR and U.S. state privacy choices are forwarded to these partners.
| Data Collected | Purpose |
|---|---|
| Advertising ID (GAID/IDFA) | Ad targeting and frequency capping |
| Device information (model, OS, screen size) | Ad rendering and compatibility |
| Ad interaction data (impressions, clicks, completions) | Ad performance measurement |
| Impression-level revenue data (ILRD) | Revenue analytics |
Google Privacy Policy: policies.google.com/privacy
How Google Uses Advertising Data: policies.google.com/technologies/ads
Unity Ads (mediation partner) Privacy Policy: unity.com/legal/game-player-and-app-user-privacy-policy
ironSource (mediation partner, a Unity company) Privacy Policy: unity.com/legal/game-player-and-app-user-privacy-policy
Chartboost (mediation partner, a LoopMe company) Privacy Policy: docs.chartboost.com/en/legal/privacy-policy
4.4 GameAnalytics (Game Analytics)
Provides game-specific analytics including player progression funnels, retention analysis, and in-game economy tracking. Helps us understand gameplay patterns and improve game balance.
| Data Collected | Purpose |
|---|---|
| Device identifiers | User session tracking |
| Game progression events (levels, scores) | Progression funnel analysis |
| In-game economy events (currency earned/spent) | Economy balancing |
| Business events (IAP purchases) | Revenue analytics |
| Error events | Stability monitoring |
GameAnalytics Privacy Policy: gameanalytics.com/privacy
4.5 devtodev (Product Analytics & Push Notifications)
We use devtodev for product analytics (understanding player behavior and retention) and for delivering push notifications. devtodev is enabled only after you consent to analytics, and push registration occurs only after you enable notifications via the in-app toggle. Push messages are delivered using your Firebase Cloud Messaging (FCM) token.
| Data Collected | Purpose |
|---|---|
| Device identifiers and device information | User/session tracking |
| App activity and engagement events (sessions, progression, in-app events) | Product analytics and retention analysis |
| Push notification token (FCM) | Delivering push notifications |
devtodev Privacy Policy: devtodev.com/policy
4.6 Data Sharing Summary
We do NOT sell your personal information.
We share data with third parties only:
- To provide services described above (Data Processors)
- When required by law or legal process
- To protect our rights, safety, and property
- With your explicit consent
- In connection with a merger, acquisition, or sale of assets (with notice)
5. Data Retention
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| App progress (local) | Until you delete the App or clear data | Device settings or uninstall |
| Firebase Analytics data | 14 months (Firebase default) | Automatic expiration |
| GameAnalytics data | 6 months | Automatic expiration |
| Crash reports | 90 days | Automatic expiration |
| Purchase records | As required by law (typically 7 years) | Legal retention requirement |
| Push notification tokens | Until you disable notifications or delete the App | Device settings |
| Advertising data | Per ad partner retention policies | See Google AdMob and mediated network (Unity Ads / ironSource / Chartboost) privacy policies |
6. Your Rights and Choices
6.1 Universal Rights (All Users)
| Right | How to Exercise |
|---|---|
| Access your data | Settings > Privacy or contact us |
| Delete all your data (in-app) | Settings > Privacy > Delete my data |
| Delete local data | Device Settings > Apps > Clear Data or uninstall |
| Opt-out of analytics | Settings > Privacy > toggle off Analytics |
| Opt-out of personalized ads | Settings > Privacy > toggle off Personalized Ads |
| Disable push notifications | Device Settings > Apps > Notifications |
| Change consent preferences | Settings > Privacy (at any time) |
6.2 European Union Users (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under GDPR:
- Right to Access - Request a copy of your personal data (30 days)
- Right to Rectification - Request correction of inaccurate data (30 days)
- Right to Erasure - Request deletion of your personal data (30 days)
- Right to Restrict Processing - Request limitation of data processing (30 days)
- Right to Data Portability - Receive your data in a portable format (30 days)
- Right to Object - Object to processing based on legitimate interests (30 days)
- Right to Withdraw Consent - Withdraw consent at any time (Immediate)
To exercise your GDPR rights: Email us at olhoten.apps@gmail.com with "GDPR Request" in the subject line.
6.3 California Residents (CCPA/CPRA)
California residents have rights under CCPA/CPRA including: Right to Know, Right to Delete, Right to Correct, Right to Opt-Out, Right to Non-Discrimination.
We do NOT sell your personal information.
To submit a CCPA/CPRA request: Email us at olhoten.apps@gmail.com with "CCPA Request" in the subject line.
7. Children's Privacy
All Olhoten Apps applications are intended for users aged 16 and older and are NOT directed to children. Our Google Play target-audience declaration is 18+, and the App requires a 16-or-older age attestation on first launch.
We do not knowingly collect, use, or disclose personal information from anyone under 16. In particular, consistent with the U.S. Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13.
Parents and Guardians: If you believe a child under 16 has accessed any of our Apps and provided personal information, please contact us immediately at olhoten.apps@gmail.com. We will investigate and delete any such data within 48 hours.
8. Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption in Transit: All data transmitted using TLS 1.2+ encryption
- Encryption at Rest: Local data stored on device using platform-standard storage
- Secure APIs: All third-party service communications authenticated and encrypted
- Access Controls: Limited access to user data on need-to-know basis
Important: No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States.
We ensure appropriate safeguards for international transfers through Standard Contractual Clauses (SCCs), EU-US Data Privacy Framework, and Data Processing Agreements with all service providers.
10. Advertising and Tracking
Non-premium users see advertisements in our Apps served through Google AdMob, with Unity Ads, ironSource, and Chartboost participating as AdMob mediation partners (see Section 4.3).
Ad personalization:
- With consent: We show personalized ads based on your interests
- Without consent: You will see contextual (non-personalized) ads
Premium subscribers do not see any advertisements.
Opt-out of personalized ads:
iOS: Settings > Privacy & Security > Tracking
Android: Settings > Google > Ads > Opt out of Ads Personalization
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting a prominent in-app notice. We encourage you to review this Privacy Policy periodically.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:
Email: olhoten.apps@gmail.com
Subject Line Guidelines:
- General questions: "Privacy Question"
- GDPR requests: "GDPR Request - [Your Request Type]"
- CCPA requests: "CCPA Request - [Your Request Type]"
- Data deletion: "Data Deletion Request"
- Children's data concerns: "URGENT: Children's Data"
| Request Type | Response Time |
|---|---|
| General questions | 14 days |
| GDPR requests | 30 days |
| CCPA requests | 45 days |
| CCPA opt-out | 15 business days |
| Children's data | 48 hours |
By using any Olhoten Apps application, you acknowledge that you have read and understood this Privacy Policy.
This Privacy Policy complies with GDPR, CCPA/CPRA, COPPA, LGPD, and other applicable privacy regulations.
Version: 1.3 | Effective Date: July 15, 2026