Privacy Policy

Version 1.5 | Last Updated: September 3, 2026

1. Introduction

Welcome to Olhoten Apps ("we," "our," or "us"). We are committed to protecting your privacy and ensuring you have a positive experience when using our mobile applications. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use any of our applications ("Apps").

Developer: Olhoten Apps
Contact Email: olhoten.apps@gmail.com

We act as the Data Controller for personal data collected through our Apps. This means we determine the purposes and means of processing your personal data.

1.1 Applications Covered

This Privacy Policy applies to all mobile applications published by Olhoten Apps, including but not limited to:

  • Ten Twins - Number Puzzle Game

...and any other applications published under the Olhoten Apps developer account on Google Play Store and Apple App Store.

1.2 Age Restriction

All Olhoten Apps applications are intended for users aged 16 and older. On first launch you must confirm that you are 16 or older. Our Apps are not directed to children, are not designed for use by children, and we do not knowingly collect personal information from anyone under 16.

1.3 Consent and Legal Basis

When you first launch any of our Apps, you will be presented with a consent screen to choose your privacy preferences. All users worldwide receive this consent prompt, regardless of location.

Your choices include:

  • Analytics (help us improve the app)
  • Personalized advertising (see relevant ads)

You can use our Apps regardless of your choices, and you can change your preferences at any time in Settings > Privacy.

How consent is collected:

  • Age attestation: On first launch you confirm that you are 16 years of age or older and accept our Terms of Service and this Privacy Policy before any data-collecting service is enabled.
  • EEA, UK and Switzerland: Advertising and analytics consent is collected through the Stack Consent Manager provided by our advertising mediation partner Appodeal, which is built on Google's User Messaging Platform (UMP) and supports the IAB Transparency & Consent Framework (TCF v2). Your choices are stored as an industry-standard TCF consent string and forwarded to every advertising vendor in the applicable TCF vendor list, not only to Google.
  • iOS (App Tracking Transparency): On iOS 14.5 and later, Apple's App Tracking Transparency (ATT) prompt is presented before any tracking identifier (IDFA) is accessed. If you decline, the IDFA is not used and you will only see contextual ads.
  • United States (California and other states): Opt-out signals are recorded using the IAB U.S. Privacy String / Global Privacy Platform and honored by our advertising partners. You can opt out of the sale/sharing of your personal information at any time via Settings > Privacy > Do Not Sell or Share My Personal Information (see Section 6.3).
  • Consent gating: Analytics and push notification SDKs are initialized only after you have provided the applicable consent; if you decline, these services are not started. The advertising SDK starts in a restricted mode solely in order to present the consent form, and does not collect or transmit your advertising identifier, IP address or any other personal data until you have made your choice. If you decline, it continues to operate without personalized data and serves contextual ads only.
  • Withdrawing consent: You can reopen the consent form and change or withdraw any consent at any time via Settings > Privacy > Privacy Settings. Withdrawal takes effect immediately and does not affect the lawfulness of processing carried out before withdrawal.
  • Data deletion: You can erase all data associated with you at any time from within the App via Settings > Privacy > Delete my data (see Section 6).

Legal Basis for Processing (GDPR):

Processing Activity Legal Basis Can You Object?
Core app functionalityContract (necessary to provide service)No
Saving app progressContractNo
Processing purchasesContractNo
Crash reportingLegitimate Interest (app stability)Yes*
Security and fraud preventionLegitimate InterestYes*
AnalyticsConsentYes
Personalized advertisingConsentYes
Push notificationsConsentYes

*For legitimate interest processing, you may object, but we may continue processing if we demonstrate compelling legitimate grounds.

2. Information We Collect

We collect information automatically when you use our Apps and through third-party services integrated into our Apps. We do not collect sensitive personal information such as precise geolocation, racial/ethnic origin, religious beliefs, health data, sexual orientation, or biometric data.

2.1 Information Collected Automatically

Data Type Examples Purpose Legal Basis
Device InformationDevice model, OS version, unique device identifiersApp functionality, crash reportingContract / Legitimate Interest
App Usage DataScores, progress, features used, session durationAnalytics, app improvementConsent
App ProgressAchievements, in-app currency balance, preferencesCore functionalityContract
Crash DataCrash logs, error reports, diagnostic dataBug fixing, stability improvementLegitimate Interest
Advertising DataAd interactions, ad views, video completions, advertising identifiers (GAID / IDFA), impression-level revenue dataDisplaying relevant ads, ad measurement, ad fraud preventionConsent
Network InformationIP address, mobile carrier and MCC-MNC, connection type, user agentAd delivery, coarse (country/region-level) targeting, fraud preventionConsent (advertising) / Legitimate Interest (security)
Pseudonymous App User IDRandomly generated in-app identifier, not linked to your name, email address or any accountAd measurement, revenue analytics, fraud preventionConsent
Purchase DataTransaction history, purchase timestamps, product, price and currencyProcessing in-app purchases; ad revenue measurement (shared with our advertising mediation provider only with your advertising consent)Contract / Consent

2.2 Information We Do NOT Collect

  • Precise location data (GPS coordinates)
  • Contact lists or address books
  • Camera or microphone data
  • Health or fitness data
  • Financial account information (handled by Apple/Google)
  • Social Security numbers or government IDs
  • Biometric data
  • Contents of messages or communications

Note on location: Our Apps do not declare or request Android or iOS location permissions. Because our advertising SDK can only access device location when the app itself holds a location permission, neither we nor our advertising partners receive GPS or other precise location data from our Apps. Advertising partners may nevertheless infer your approximate location (typically country or region) from your IP address.

3. How We Use Your Information

3.1 Core App Functionality (Legal Basis: Contract)

  • Providing app features and functionality
  • Saving your progress locally on device
  • Processing in-app purchases
  • Managing your preferences

3.2 Analytics and Improvement (Legal Basis: Consent)

  • Understanding how users interact with our Apps
  • Identifying popular features and areas for improvement
  • Measuring the effectiveness of updates
  • A/B testing new features

3.3 Security and Stability (Legal Basis: Legitimate Interest)

  • Identifying and fixing bugs and crashes
  • Preventing fraud and abuse
  • Ensuring app security and integrity

Note: Crash reporting (Firebase Crashlytics) is processed on the basis of our legitimate interest in keeping the App stable and diagnosing failures (GDPR Art. 6(1)(f)). It operates independently of your Analytics choice. Crash reporting is disabled automatically in development/test builds, and it stops — with any unsent crash reports deleted — when you use the in-app Settings > Privacy > Delete my data flow. You may also object to this processing by contacting us.

3.4 Advertising (Legal Basis: Consent)

  • Displaying advertisements
  • Measuring ad performance
  • Providing personalized ads based on your interests (with your consent)
  • Serving contextual (non-personalized) ads (without consent)
  • Detecting and preventing ad fraud and invalid traffic

3.5 Communications (Legal Basis: Consent)

  • Sending push notifications (with your permission)
  • Notifying you about rewards, events, and updates
  • Responding to your inquiries

4. Third-Party Services and Data Sharing

We use trusted third-party services to provide certain features. Their role under data protection law differs depending on the service:

  • Analytics, crash reporting and messaging providers (Firebase, GameAnalytics, devtodev) act as Data Processors on our behalf and process data according to our instructions and their own privacy policies.
  • Advertising partners (Appodeal and the advertising networks it mediates) act as independent controllers — and in some cases as joint controllers with us — for the advertising data they receive. They determine their own purposes for that data under their own privacy policies, and beyond forwarding your consent choices to them we cannot control their processing. Advertising data is shared with them only after you have provided the applicable consent.

4.1 Firebase (Google)

Service Data Collected Purpose
Firebase AnalyticsApp usage events, device info, user properties, app instance IDAnalytics
Firebase CrashlyticsCrash reports, stack traces, device info, app state, custom diagnostic keysCrash reporting (legitimate interest — app stability)
Firebase Cloud MessagingPush notification tokens (FCM token)Push notifications
Firebase Remote ConfigApp instance ID, country, languageFeature flags, A/B testing

Firebase Privacy Policy: firebase.google.com/support/privacy

4.2 Google Play Billing / Apple StoreKit (In-App Purchases)

In-app purchases are processed natively through Google Play Billing (Android) and Apple StoreKit (iOS). Purchase transactions are handled directly by the platform. We store purchase records locally on the device for purchase restoration purposes.

Google Play Privacy: policies.google.com/privacy
Apple Privacy: apple.com/legal/privacy

4.3 Appodeal (Advertising Mediation) and Advertising Partners

Advertisements in our Apps are delivered through Appodeal, our advertising mediation platform, operated by Appodeal, Inc., a Delaware corporation located at 575 Market St, 5th Floor, San Francisco, CA 94105, USA. Appodeal receives each ad request from the App and fills it through the advertising networks and demand partners connected to our account. We use banner, interstitial, rewarded video, rewarded interstitial, and app-open ad formats.

What is shared: In order to request, render, frequency-cap and measure ads, the Appodeal SDK and the advertising partner that fills the request receive your advertising identifier, your IP address, and technical device and network information. This data leaves your device and is processed by Appodeal and by that advertising partner under their own privacy policies.

Data Collected Purpose
Advertising ID (GAID / IDFA)Ad targeting, frequency capping, attribution
IP addressAd delivery, coarse (country / region-level) geo targeting, fraud prevention
Device information (model, OS version, screen size, language, available memory and storage, user agent)Ad rendering, compatibility, fraud prevention
Network information (mobile carrier, MCC-MNC, connection type)Ad delivery and formatting
Ad interaction data (impressions, clicks, video completions, rewards)Ad delivery and performance measurement
Impression-level revenue data (ILRD)Revenue analytics
Pseudonymous app user identifierLinking ad activity to an app installation for measurement, revenue analytics and fraud prevention
In-app purchase events (product, price, currency, timestamp)Ad targeting and ad revenue analytics

User identifier and purchase events: Where this feature is enabled in the App, we pass a pseudonymous, app-generated user identifier and in-app purchase events to Appodeal so that ad performance and revenue can be measured and ad fraud detected. This identifier is not your name, email address, or any account credential, we do not use it to contact you, and it is not disclosed for any purpose other than advertising measurement. It is regenerated — and the previous value is disassociated from you — when you use Settings > Privacy > Delete my data.

Location: Our Apps do not declare or request location permissions, so neither Appodeal nor its advertising partners receive GPS or other precise location data from our Apps. They may infer your approximate location (typically country or region) from your IP address.

Consent: For users in the European Economic Area, the United Kingdom, and Switzerland, advertising consent is collected through the Stack Consent Manager included in the Appodeal SDK, which is built on Google's User Messaging Platform (UMP) and supports the IAB Transparency & Consent Framework (TCF v2), before any advertising data is collected. Your TCF consent string is forwarded to every advertising vendor in the applicable vendor list. On iOS 14.5 and later, Apple's App Tracking Transparency prompt is shown before the IDFA is accessed. Without consent, only contextual (non-personalized) ads are shown. In the United States, your opt-out choice is transmitted to advertising partners using the IAB U.S. Privacy String / Global Privacy Platform.

Advertising partners: Appodeal fills ad requests through connected advertising networks and demand-side platforms participating in real-time bidding, including but not limited to Google AdMob, AppLovin, Unity Ads, ironSource, Meta Audience Network, Liftoff (Vungle), and Amazon. Because bidding partners change over time, the authoritative and current list of Appodeal's advertising partners, together with their privacy policies, is published by Appodeal at the link below. Your GDPR and U.S. state privacy choices are forwarded to these partners.

Appodeal Privacy Policy: appodeal.com/privacy-policy
Appodeal Advertising Partners (full current list): appodeal.com/home/partners-privacy-policies
Appodeal SDK Opt-Out: appodeal.com/sdk-opt-out
Google Privacy Policy: policies.google.com/privacy
How Google Uses Advertising Data: policies.google.com/technologies/ads
AppLovin Privacy Policy: applovin.com/privacy
Unity Ads and ironSource (Unity) Privacy Policy: unity.com/legal/game-player-and-app-user-privacy-policy
Meta Audience Network Privacy Policy: facebook.com/privacy/policy
Liftoff (Vungle) Privacy Policy: liftoff.ai/privacy-policy
Amazon Ads Privacy Notice: advertising.amazon.com/legal/privacy-notice

4.4 GameAnalytics (Game Analytics)

Provides game-specific analytics including player progression funnels, retention analysis, and in-game economy tracking. Helps us understand gameplay patterns and improve game balance.

Data Collected Purpose
Device identifiersUser session tracking
Game progression events (levels, scores)Progression funnel analysis
In-game economy events (currency earned/spent)Economy balancing
Business events (IAP purchases)Revenue analytics
Error eventsStability monitoring

GameAnalytics Privacy Policy: gameanalytics.com/privacy

4.5 devtodev (Product Analytics & Push Notifications)

We use devtodev for product analytics (understanding player behavior and retention) and for delivering push notifications. devtodev is enabled only after you consent to analytics, and push registration occurs only after you enable notifications via the in-app toggle. Push messages are delivered using your Firebase Cloud Messaging (FCM) token.

Data Collected Purpose
Device identifiers and device informationUser/session tracking
App activity and engagement events (sessions, progression, in-app events)Product analytics and retention analysis
Push notification token (FCM)Delivering push notifications

devtodev Privacy Policy: devtodev.com/policy

4.6 Ad Revenue Measurement and Attribution

The Appodeal SDK reports impression-level ad revenue (ILRD) back to the App. We forward this revenue data to our own analytics providers — Firebase Analytics, GameAnalytics and devtodev (Sections 4.1, 4.4 and 4.5) — so that we can measure how the App performs. No personal data beyond what is already described in this Section 4 is collected for this purpose.

Appodeal also offers optional integrations with third-party mobile attribution and user-acquisition providers (such as Meta, Adjust and AppsFlyer). We do not currently enable any of these integrations, and no data is sent to them. If we enable one in the future, we will update this Privacy Policy and name the provider before the integration goes live.

4.7 Data Sharing Summary

We do not sell your personal information for money, and we never disclose your name, email address, or contact details to advertisers.

However, if you consent to personalized advertising, we disclose your advertising identifier, IP address and ad interaction data to Appodeal and its advertising partners for cross-context behavioural advertising. Under the California Consumer Privacy Act (CCPA/CPRA) and comparable U.S. state privacy laws, this kind of disclosure is treated as a “sale” and/or “sharing” of personal information, even though we receive no money for the data itself. You can opt out at any time — see Section 6.3.

We share data with third parties only:

  • To provide services described above (analytics, crash reporting and messaging providers acting as Data Processors)
  • To deliver, cap and measure advertising, with your consent (advertising partners acting as independent controllers)
  • When required by law or legal process
  • To protect our rights, safety, and property
  • With your explicit consent
  • In connection with a merger, acquisition, or sale of assets (with notice)

5. Data Retention

Data Type Retention Period Deletion Method
App progress (local)Until you delete the App or clear dataDevice settings or uninstall
Firebase Analytics data14 months (Firebase default)Automatic expiration
GameAnalytics data6 monthsAutomatic expiration
Crash reports90 daysAutomatic expiration
Purchase recordsAs required by law (typically 7 years)Legal retention requirement
Push notification tokensUntil you disable notifications or delete the AppDevice settings
Advertising dataPer advertising partner retention policiesSee the Appodeal privacy policy and the privacy policies of the advertising partners listed in Section 4.3

6. Your Rights and Choices

6.1 Universal Rights (All Users)

Right How to Exercise
Access your dataSettings > Privacy or contact us
Delete all your data (in-app)Settings > Privacy > Delete my data
Delete local dataDevice Settings > Apps > Clear Data or uninstall
Opt-out of analyticsSettings > Privacy > toggle off Analytics
Opt-out of personalized adsSettings > Privacy > toggle off Personalized Ads
Opt-out of the sale / sharing of personal information (U.S.)Settings > Privacy > Do Not Sell or Share My Personal Information
Disable push notificationsDevice Settings > Apps > Notifications
Change consent preferencesSettings > Privacy (at any time)
Withdraw advertising / analytics consent (EEA, UK, Switzerland)Settings > Privacy > Privacy Settings (reopens the consent form)

6.2 European Union Users (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under GDPR:

  • Right to Access - Request a copy of your personal data (30 days)
  • Right to Rectification - Request correction of inaccurate data (30 days)
  • Right to Erasure - Request deletion of your personal data (30 days)
  • Right to Restrict Processing - Request limitation of data processing (30 days)
  • Right to Data Portability - Receive your data in a portable format (30 days)
  • Right to Object - Object to processing based on legitimate interests (30 days)
  • Right to Withdraw Consent - Withdraw consent at any time via Settings > Privacy > Privacy Settings, which reopens the consent form (Immediate)

To exercise your GDPR rights: Email us at olhoten.apps@gmail.com with "GDPR Request" in the subject line.

6.3 California Residents (CCPA/CPRA)

California residents have rights under CCPA/CPRA including: Right to Know, Right to Delete, Right to Correct, Right to Opt-Out of Sale or Sharing, Right to Limit Use of Sensitive Personal Information, and Right to Non-Discrimination. Residents of other U.S. states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana) have comparable rights, including the right to opt out of targeted advertising.

Sale and sharing of personal information. We do not sell your personal information for money. However, when you consent to personalized advertising, we disclose your advertising identifier, IP address and ad interaction data to Appodeal and its advertising partners for cross-context behavioural advertising. Under CCPA/CPRA and comparable state laws this disclosure is treated as a “sale” and/or “sharing” of personal information. We do not knowingly sell or share the personal information of consumers under 16 years of age.

How to opt out of the sale or sharing of your personal information:

  • In the App: Settings > Privacy > Do Not Sell or Share My Personal Information. This control is always available and requires no account.
  • In the App: turning off Settings > Privacy > Personalized Ads has the same effect.
  • On your device: Android — Settings > Google > Ads > Delete advertising ID; iOS — Settings > Privacy & Security > Tracking.
  • Directly with Appodeal: appodeal.com/sdk-opt-out.
  • Opt-out preference signals: we honour Global Privacy Control (GPC) signals where they are technically transmitted to us.

To submit a CCPA/CPRA request: Email us at olhoten.apps@gmail.com with "CCPA Request" in the subject line. We will not discriminate against you for exercising any of these rights.

7. Children's Privacy

All Olhoten Apps applications are intended for users aged 16 and older and are NOT directed to children. Our Google Play target-audience declaration is 18+, and the App requires a 16-or-older age attestation on first launch.

We do not knowingly collect, use, or disclose personal information from anyone under 16. In particular, consistent with the U.S. Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13.

Parents and Guardians: If you believe a child under 16 has accessed any of our Apps and provided personal information, please contact us immediately at olhoten.apps@gmail.com. We will investigate and delete any such data within 48 hours.

8. Data Security

We implement appropriate technical and organizational measures to protect your information:

  • Encryption in Transit: All data transmitted using TLS 1.2+ encryption
  • Encryption at Rest: Local data stored on device using platform-standard storage
  • Secure APIs: All third-party service communications authenticated and encrypted
  • Access Controls: Limited access to user data on need-to-know basis

Important: No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States.

In particular, our advertising mediation provider Appodeal, Inc. is established in the United States (San Francisco, California) and processes advertising data there and through its global network of advertising partners, which may be located outside the EEA and the United Kingdom.

We ensure appropriate safeguards for international transfers through Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework, and Data Processing Agreements with all service providers.

10. Advertising and Tracking

Advertisements in our Apps are delivered through the Appodeal mediation platform (Appodeal, Inc., USA), which fills ad requests through connected advertising networks and demand-side platforms such as Google AdMob, AppLovin, Unity Ads, ironSource, Meta Audience Network, Liftoff (Vungle) and Amazon (see Section 4.3 for the full description and the authoritative partner list).

Ad personalization:

  • With consent: We show personalized ads based on your interests
  • Without consent: You will see contextual (non-personalized) ads

App Tracking Transparency (iOS): On iOS 14.5 and later, the App presents Apple's App Tracking Transparency prompt through the Appodeal Stack Consent Manager before any tracking identifier (IDFA) is accessed. If you decline, the IDFA is not used and you will only see contextual ads.

No ad-removal purchase or premium subscription is currently offered. If we introduce one in the future, users who purchase it will not see advertisements.

Opt-out of personalized ads and of the sale / sharing of your data:
In-App: Settings > Privacy > Personalized Ads
In-App (U.S.): Settings > Privacy > Do Not Sell or Share My Personal Information
iOS: Settings > Privacy & Security > Tracking
Android: Settings > Google > Ads > Delete advertising ID / Opt out of Ads Personalization
Appodeal SDK opt-out: appodeal.com/sdk-opt-out

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting a prominent in-app notice. We encourage you to review this Privacy Policy periodically.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:

Email: olhoten.apps@gmail.com

Subject Line Guidelines:

  • General questions: "Privacy Question"
  • GDPR requests: "GDPR Request - [Your Request Type]"
  • CCPA requests: "CCPA Request - [Your Request Type]"
  • Data deletion: "Data Deletion Request"
  • Children's data concerns: "URGENT: Children's Data"
Request Type Response Time
General questions14 days
GDPR requests30 days
CCPA requests45 days
CCPA opt-out15 business days
Children's data48 hours

By using any Olhoten Apps application, you acknowledge that you have read and understood this Privacy Policy.

This Privacy Policy complies with GDPR, CCPA/CPRA, COPPA, LGPD, and other applicable privacy regulations.

Version: 1.5 | Effective Date: September 3, 2026