1. Information we collect and use
Core service functions
- Account registration and sign-in: email address, encrypted password, and device identifiers such as OAID or Android ID to secure your account.
- Third-party sign-in: with your consent, an account identifier from the selected provider to link your sign-in.
- Identity verification: information required by law for specific verification scenarios.
- Device and diagnostic information: device model, IP address, network status, and limited logs used to maintain service quality and security.
- Messages and support: email notifications, support conversations, and relevant account details to answer requests and resolve issues.
SDKs and cookies
We may use payment or analytics SDKs and cookies to provide core functions, maintain sign-in state, and protect the service. These tools may process limited, anonymized device information as described in their applicable notices.
2. Storage location and retention
- Location: information may be processed on servers outside your country, including Singapore, to support global service continuity. We apply appropriate protections for such transfers.
- Retention: we retain information only for as long as necessary for the purposes described here or as required by law, then delete or anonymize it.
3. Transfers and disclosure
If a merger, acquisition, or similar transaction occurs, information may be transferred to a successor subject to this policy. We do not publicly disclose personal information unless you authorize it or law permits or requires it.
4. Security measures
We use encryption, access controls, and incident-response measures to protect information. No internet transmission is completely secure, so please use a strong password and safeguard your account.
5. Your privacy rights
- Access and correction: update certain account details in your account settings.
- Deletion: request deletion when the processing purpose has been completed or when you withdraw consent, subject to legal obligations.
- Account closure: request account deletion through support. After verification, information is deleted or anonymized except where retention is legally required.
6. EEA users and GDPR
If you are in the European Economic Area, processing may be based on contract performance, legitimate interests, legal obligations, or your consent. You may have rights to access, export, restrict processing, object, and lodge a complaint with a supervisory authority.
7. Children
Users under 18 should use the service with a parent or guardian's guidance. Where consent is required for a child, we seek parental authorization. Information collected without required authorization will be deleted as soon as reasonably possible.
8. Changes to this policy
We may revise this policy from time to time. Material changes will be communicated prominently through the website or app. Continued use after the effective date indicates acceptance where permitted by law.
9. Contact
For privacy questions or requests, please contact us through in-app support.