Introduction
Apparanto, the developer of YOXYX, ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our word-guessing game application.
By using YOXYX, you consent to the data practices described in this policy.
1. Information We Collect
1.1 Information Automatically Collected
When you use YOXYX, we automatically collect certain information, including:
- IP Address: We collect your IP address for security purposes, fraud prevention, and to enforce rate limiting. IP addresses are retained for 90 days and then automatically deleted.
- Cookies: We use essential cookies to maintain your game session (session_id) and player identity (player_id). These cookies are necessary for the game to function.
- Gameplay Data: We store your game sessions, guesses, timestamps, and results to provide game functionality and statistics.
1.2 Information You Provide
- Username: An automatically generated username (e.g., "swift-otter-427") is created for you. You can regenerate it during initial setup but cannot change it after playing.
- Email Address: Optional. Currently not collected but reserved for future account features.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Provide Game Functionality: To maintain your game sessions, track progress, and display statistics.
- Security & Fraud Prevention: To detect and prevent abuse, automated bots, and malicious activity using IP address tracking and rate limiting.
- Improve Our Service: To understand how users interact with the game and identify technical issues.
- Legal Compliance: To comply with legal obligations and respond to law enforcement requests.
3. Data Retention
- Active Player Data: Game sessions, usernames, and statistics are retained indefinitely while your account is active.
- IP Addresses: Retained for 90 days from last activity, then automatically deleted.
- Deleted Accounts: If you request account deletion, all personal data is removed within 30 days.
- Security Logs: Security-related logs may be retained longer for fraud investigation purposes, but are anonymized where possible.
4. Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
- Legal Requirements: When required by law, court order, or government regulation.
- Service Providers: With hosting providers and infrastructure services necessary to operate YOXYX. These providers are contractually obligated to protect your data.
- Protection of Rights: To enforce our terms of service, protect our rights, or investigate fraud and security issues.
5. Your Privacy Rights
Depending on your location, you may have the following rights:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Correction: Request correction of inaccurate or incomplete data.
- Right to Deletion: Request deletion of your account and associated personal data.
- Right to Data Portability: Request export of your data in a machine-readable format.
- Right to Object: Object to certain processing of your personal data.
- Right to Withdraw Consent: Withdraw consent for data processing where consent is the legal basis.
To exercise these rights, please contact us using the information provided below.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- HTTPS encryption for all data transmission
- Secure database storage with access controls
- Secure cookies with HttpOnly and SameSite flags
- Rate limiting to prevent abuse
- Security logging and monitoring
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.
7. Children's Privacy
YOXYX is intended for general audiences. We do not knowingly collect personal information from children under 13 (or the applicable age in your jurisdiction) without parental consent. If you believe we have inadvertently collected information from a child, please contact us immediately.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using YOXYX, you consent to such transfers.
9. Cookies and Tracking
YOXYX uses only essential cookies required for game functionality:
- player_id: Unique identifier for your player account (persistent)
- session_id: Tracks your current game session (persistent)
- csrftoken: Security token to prevent cross-site request forgery attacks (session)
These cookies are essential for the game to function and cannot be disabled. By accepting cookies during welcome, you consent to their use.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last Updated" date at the top of this policy. Continued use of YOXYX after changes constitutes acceptance of the updated policy.
For material changes, we will provide notice through the game interface or via email (if we have your email address).
11. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how we handle your data, please contact us at:
Email: privacy.yoxyx@apparanto.com
We will respond to privacy requests within 30 days.
12. GDPR Compliance (EU Users)
If you are located in the European Union, you have additional rights under the General Data Protection Regulation (GDPR):
- We process your data based on legitimate interests (security and service provision) and your consent (cookies).
- Apparanto (info@apparanto.com) is the data controller for your personal information.
- You have the right to lodge a complaint with your local data protection authority.
- We do not use automated decision-making or profiling.
13. California Privacy Rights (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information we collect, use, and share
- Right to request deletion of personal information
- Right to opt-out of sale of personal information (we do not sell your data)
- Right not to be discriminated against for exercising these rights