Privacy Policy of WoofChat
This Privacy Policy describes how WoofChat (the “Application”) collects, uses, and shares Personal Data of its Users. Please read it carefully before using the Application.
1. Owner and Data Controller
WoofChat Team — WeilanHaian 2nd, Shenzhen (China)
Contact email: stansphere.jp@gmail.com
2. Personal Data We Collect
2.1 Data you provide
- Account data: email address and password (stored only as a salted hash), or the identifier and email address provided by your third-party sign-in provider (Google or Apple, see Section 4).
- Profile data: nickname, gender, date of birth, and profile introduction. Your nickname, avatar, and profile may be visible to other Users.
- Chat messages: text messages you send in the Application. Messages are transmitted to and stored on our servers so they can be delivered, displayed, and moderated.
- User-created content (avatars): images you create or upload to build a custom character. If you make an avatar public, it may be displayed to, and used (“worn”) by, other Users. Avatar images are stored on cloud object storage (Tencent Cloud COS).
- Photos: if you choose to import an image, the Application accesses only the specific photos you select. On Android this uses the system Photo Picker, which does not require any storage permission; on iOS this uses the Photo Library permission, which you may revoke at any time in device settings.
- Reports: if you report another User, we record the report, the reported content, and the identities of the reporter and the reported User, to review the report and keep the Service safe.
2.2 Data collected automatically
- Usage Data: IP address, device model, operating system and version, app version, language, session times, in-app events (such as screens viewed, features used, purchase funnel steps), and error/crash information.
- Device identifiers: a unique installation identifier (UUID) generated when the Application is installed, and — only with your consent where required — the advertising identifier of your device (IDFA on iOS, subject to the AppTrackingTransparency prompt; Advertising ID on Android). These identifiers are used solely for analytics; the Application does not display third-party advertising.
- Purchase status: your subscription status and purchase receipts as provided by the Apple App Store or Google Play, used to activate and verify your subscription. We never receive your payment card details.
2.3 Data we do NOT collect
- No voice recording. The character “voices” you hear are synthesized locally on your device from the text of chat messages. The Application never accesses your microphone and no audio is recorded or transmitted.
- No location data. The Application does not request or collect your geographic location.
- No camera access. The in-game photo features render game scenes only.
- No third-party advertising. The Application contains no ad networks.
- No push notifications. The Application does not send system push notifications.
3. Purposes of Processing
We process Personal Data to: provide and operate the Service (accounts, chat, avatars, multiplayer rooms, subscriptions); keep the Service safe (content moderation, report handling, abuse and fraud prevention); analyze and improve the Application; send transactional emails (verification codes, password reset); comply with legal obligations; and protect our rights and the rights of Users and third parties.
4. Third-Party Services and Data Recipients
We share Personal Data only with the service providers listed below, only to the extent necessary for the stated purpose. Each provider processes data under its own privacy policy.
| Service | Provider | Purpose | Data involved |
|---|---|---|---|
| GameAnalytics | GameAnalytics ApS (Denmark) | Usage analytics and error reporting | Usage Data; device identifiers (advertising identifier only with consent) |
| Photon Cloud | Exit Games GmbH (Germany) | Real-time multiplayer session relay (used for some game rooms) | Connection data (IP address), in-room game state and chat relay |
| Tencent Cloud COS | Tencent Cloud | Storage and delivery of avatar images and game assets | User-created avatar images |
| Tencent Cloud content moderation (TMS / IMS) | Tencent Cloud | Automated review of text (nicknames, profiles, messages) and images (avatars) for illegal or harmful content | Submitted text and images |
| Tencent Cloud SES | Tencent Cloud (Hong Kong region) | Sending verification-code and password-reset emails | Email address |
| Google Sign-In | Google LLC | Optional sign-in method | We receive your Google account identifier, email address, and email verification status |
| Sign in with Apple | Apple Inc. | Optional sign-in method | We receive your Apple account identifier, email address (or Apple's private relay address), and email verification status |
| App Store / Google Play billing | Apple Inc. / Google LLC | Subscription purchase and verification | Purchase receipts and subscription status (no payment card data reaches us) |
In addition, data may be accessible to persons involved in the operation of the Application (administration, moderation, system administration) under confidentiality obligations. Personal Data may also be disclosed where required by law or upon lawful request of public authorities.
5. Content Moderation
To keep the community safe and to comply with platform rules, content submitted to the Application — including chat messages, nicknames, profile text, and avatar images — is screened by automated moderation systems (provided by Tencent Cloud) and may additionally be reviewed by our human moderation staff, in particular when content is reported by other Users or flagged by the automated systems. Content that violates our Terms may be removed, and the account involved may be restricted, suspended, or deleted.
6. Data Retention
- Chat messages: retained for a maximum of 180 days, then deleted, except where a message is subject to an ongoing report, abuse investigation, or a legal obligation, in which case it is retained only as long as needed for that purpose.
- Account and profile data: retained for as long as your account exists. When your account is deleted, associated Personal Data is deleted or anonymized, except where retention is required by law (e.g. purchase records).
- User-created avatars: retained until you delete them or your account. Public avatars adopted by other Users may remain available in anonymized form.
- Usage Data: retained in aggregated or pseudonymized form for analytics.
7. Place of Processing and International Transfers
Data is processed on servers operated by us and by the service providers listed in Section 4, located in various countries, including China, Hong Kong SAR, the European Union, and the United States. Where Personal Data of Users in the European Economic Area, the United Kingdom, or Switzerland is transferred to countries that do not provide an equivalent level of protection, we rely on appropriate safeguards permitted by applicable law, such as standard contractual clauses. You may contact us for more information about the applicable transfer mechanisms.
8. Security
We take appropriate technical and organizational measures to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, including encrypted transport, hashed password storage, and access controls. No method of transmission or storage is completely secure; please also keep your login credentials confidential.
9. Legal Bases of Processing (EEA/UK Users)
We process Personal Data on the following legal bases: performance of the contract with you (providing the Service); our legitimate interests (safety, moderation, abuse prevention, service analytics); your consent (e.g. access to the advertising identifier via the iOS ATT prompt); and compliance with legal obligations. Where processing is based on consent, you may withdraw it at any time.
10. Your Rights (GDPR)
To the extent granted by applicable law, you have the right to: withdraw consent at any time; object to processing (including, at any time and free of charge, processing for direct-marketing purposes); access your Data and obtain a copy; verify and seek rectification; restrict processing; have your Data deleted; receive your Data in a portable format; and lodge a complaint with your competent data protection authority.
Requests can be sent to the contact email above. They are free of charge and will be answered as early as possible, and in any case within one month.
11. Information for California Users
11.1 Rights under the CCPA/CPRA
California residents have the right to know what Personal Information we collect and how it is used and shared; to request deletion of their Personal Information; to correct inaccurate Personal Information; and to not be discriminated against for exercising these rights. The categories of Personal Information collected and the purposes are described in Sections 2–4. We do not sell Personal Information, and we do not share Personal Information for cross-context behavioral advertising. To exercise these rights, contact us at the email above; we will verify your request and respond within the timeframes required by law.
11.2 Rights of registered California Users under 18 (“Online Eraser”)
Registered Users under 18 who reside in California may request removal of content they posted by contacting us at the email above. In response, we may make the content invisible to other Users and the public rather than deleting it entirely, in which case it may remain on our servers; content copied or reposted by third parties may remain publicly available elsewhere.
12. Children
The Application is not directed to children under 13 (or the higher minimum age required in your jurisdiction), and we do not knowingly collect Personal Data from them. Users aged 13–17 may use the Application only under parental or guardian supervision. If we learn that Personal Data of a child under the applicable minimum age has been collected without valid parental consent, we will delete it. Parents or guardians may contact us at the email above.
13. Account Deletion
You may delete your account at any time using the account-deletion function inside the Application, or by contacting us at the email above. Upon deletion, your Personal Data is handled as described in Section 6.
14. Changes to This Privacy Policy
We reserve the right to change this Privacy Policy at any time by notifying Users on this page and, where feasible, within the Application. Please check this page regularly, referring to the date of the latest update above. If changes affect processing based on your consent, we will collect new consent where required.
15. Definitions
Personal Data (or Data / Personal Information): any information that directly, indirectly, or in connection with other information allows for the identification of a natural person. Usage Data: information collected automatically through the Application, such as IP address, device and OS characteristics, timestamps, and interaction details. User (or You): the individual using the Application, who coincides with the Data Subject unless otherwise specified. Owner (or We): WoofChat Team, the Data Controller.