Privacy Policy
Effective Date: August 25, 2026
This Privacy & Data Security Commitment details the strict measures Yuan Lai Yuan (also referenced as "we," "us," or "our") implements to ingest, steward, and protect your private data while you use Prism Fish: Deep Adventure on the Google Play store. Our overarching mission in managing your digital footprint is to provide an uninterrupted, high-tier entertainment journey while upholding the highest standards of data confidentiality.
1. Information Ingestion Framework
We maintain robust methodologies to accumulate and supervise your personal details, driven by an unyielding dedication to cyber hygiene. The subsequent breakdown explains the specific data vectors we monitor and how we administer them.
1.1 Categories of Processed Data The moment you install and load Prism Fish: Deep Adventure, our network architecture is designed to capture the following distinct data sets:
Connectivity Logs: Internet Protocol (IP) addresses, precise session initiation times, and broad hardware family details.
Hardware Telemetry: The manufacturer name, specific device model, active OS platform (Android/Google OS), designated language preferences, and your regional time zone.
Distinct Device Tags: Unique identifiers hardcoded or assigned to your device, such as the Google Advertising ID (GAID), Android Device ID, Google Play Games ID, and the overarching Google Account identifier.
Engagement Statistics: Your journey through the game, peak scores, badge collections, and comprehensive multiplayer session logs.
Monetization Activity: Ledgers of bought virtual assets, transaction chronologies, digital coin depletion rates, and bespoke interface configurations.
1.2 Linked Ecosystems If you prefer to authenticate via an integrated platform like Google Play Games Services, our system will query and retrieve permissible profile points (e.g., public aliases) via secure API endpoints. This retrieval is entirely dependent on your prior endorsement of the third-party ecosystem’s sharing rules. We strongly suggest auditing the privacy portals of these external networks:
Google Play Games / Google Services: https://policies.google.com/privacy
By linking a third-party account, you formally guarantee that:
Your participation aligns seamlessly with the prevailing terms of the third-party entity.
You are of the legal age required by that third-party platform within your sovereign jurisdiction.
2. Motivations for Data Utilization
Every piece of data we process serves a predetermined function. We anchor all our data-handling activities in recognized legal frameworks:
Core Game Operations and Care: To finalize in-app purchases, address your support tickets, and maintain our networking channels; to deliver the baseline interactive experience, save user states, and push out necessary bug fixes, security patches, and administrative alerts.
Lawful Basis: Executed under GDPR Article 6(1)(b) (contractual necessity). Processing this information is indispensable for us to honor the Terms of Service and keep our application functional.
Platform Refinement and Marketing: To circulate curated marketing messages about Yuan Lai Yuan or trusted allies; to memorize your game state; and to study user behavior to forge new gameplay mechanics and amplify our support and promotional efficiency.
Lawful Basis: Driven by GDPR Article 6(1)(f) (legitimate interests). We depend on this clause to satisfy our legitimate corporate drive to deliver superior digital entertainment.
Precision Advertising: To broadcast tailored promotional campaigns to players who have granted our ad-tech partners permission to view their device tags.
Lawful Basis: Concurrently justified by GDPR Article 6(1)(f). This sustains our legitimate interest in generating revenue via highly relevant ad placements.
3. Data Lifespan and Archiving
Your private data is held within our databases only for the time period required to power our application, abide by governmental laws, and navigate legal disputes. In scenarios involving contract enforcement, infrastructural health, statutory holding periods, or security audits, we reserve the right to lock away specific data logs for an extended, legally compliant duration. Separately, anonymized Usage Metrics are kept for overarching performance analysis. Such aggregated data is typically wiped rapidly, unless a specific security threat or legal mandate dictates a prolonged retention span.
4. Information Disclosure Framework
Honoring your right to privacy, and acting in accordance with GDPR Articles 6(1)(b), 6(1)(c), and 6(1)(f), we may route your data to vetted external organizations under these strict boundaries:
Operational Partners: To orchestrate combined services, meet regulatory demands, execute corporate mergers, or any other action where you have supplied explicit consent.
Governmental and Legal Bodies: If we detect a severe breach of our terms, or if the law compels us to unveil data to defend the intellectual property, safety, or legal standing of Yuan Lai Yuan and the general public.
The Global Player Base: Whenever you engage in online matchmaking, post on community boards, or secure a spot on global ranking ladders.
4.1 Syndication to Ad Networks Contingent on acquiring your opt-in consent as mandated by GDPR Article 6(1), we will route your device tracking IDs to advertising syndicates to power personalized ad delivery. Our network of current and anticipated ad-tech partners encompasses:
Applovin Corporation: https://www.applovin.com/privacy/
AdColony: https://yandex.com/legal/international_ads_privacy_policy
Amazon Publisher Services: https://www.amazon.com/privacyprefs
Meta (Facebook, Inc.): https://www.facebook.com/about/privacy/
Google LLC: https://policies.google.com/privacy
Google Admob: https://support.google.com/admob/
Unity Technologies: https://unity3d.com/legal/privacy-policy
IronSource: http://www.ironsrc.com/wp-content/uploads/2019/03/ironSource-Privacy-Policy.pdf
Vungle, Inc.: https://vungle.com/privacy/
Fyber: https://www.fyber.com/privacy-policy/
InMobi: https://www.inmobi.com/privacy-policy/
Notice: This document does not dictate the data handling philosophies of these third-party corporations. Please navigate to their respective privacy pages to comprehend their unique protocols.
4.2 Backend Infrastructure Providers To prevent server outages and maintain backend stability, we lease processing power and analytical tools from specialized third parties:
Firebase (Google LLC): https://firebase.google.com/support/privacy
Adjust: https://www.adjust.com/terms/privacy-policy/
5. Protecting Younger Audiences
The Prism Fish: Deep Adventure application is emphatically not built for, nor advertised to, users under 13. We enforce a zero-tolerance stance against the deliberate ingestion of personal data from this age group. Should an audit reveal the accidental capture of such data, immediate eradication protocols will be launched. Guardians who suspect their child has transmitted data to us must contact our support team immediately to trigger this purge.
6. Information Security Posture
We do not take your trust lightly, which is why we enforce commercially robust cryptographic protocols to lock down your personal data. However, users must accept the reality that no digital storage vault or internet transmission is flawlessly secure. Therefore, we cannot legally guarantee the total invulnerability of your information.
7. Direct Device Notifications
If you explicitly opt-in, we may push system alerts, promotional offers, and update reminders directly to your Android/Google interface. You wield the absolute power to revoke this permission at any point by toggling the relevant settings within your device’s operating system.
8. Your Data Privacy Entitlements
8.1 European Economic Area (EEA) Jurisdictions We pledge to resolve standard privacy requests within a one-month window. For particularly arduous requests, GDPR Article 12 grants us the flexibility to extend this by a maximum of two additional months. We will proactively email you to explain any such extension.
(1) The Right of Access: Empowered by GDPR Article 15, you can demand an itemized breakdown of the data we hoard, the reasons for it, the recipients, and the intended storage length. A digital export of this data is available, assuming it doesn't violate proprietary rights.
(2) The Right to Object: Shielded by GDPR Article 21, you can dispute data processing rooted in "legitimate interests" (Article 6(1)(f)). We will halt the processing unless we present undeniable, overriding legal reasons to continue. Your right to block direct marketing is absolute and unconditional.
(3) The Right to Rectification: Backed by GDPR Article 16, you hold the authority to force the correction of flawed or partial data profiles.
(4) The Right to Restriction: Referencing GDPR Article 18, you may instruct us to quarantine and pause the active processing of your data under specific statutory conditions.
(5) The Right to Withdraw Consent: Codified in GDPR Article 7, if our data use is predicated on your prior consent, you can retract it instantly. This does not invalidate the processing that occurred before your retraction.
(6) The Right to Portability: Permitted by GDPR Article 20, you have the right to extract your data in a standardized, machine-readable syntax and transport it to an entirely different data controller.
8.2 California Resident Entitlements (CCPA)
(1) Processing Speed: We aim to finalize verifiable user requests within 45 days. If technical hurdles force a delay (up to a 90-day absolute maximum), we will issue a written explanation.
(2) Retroactive Boundaries: Data summaries provided to you will exclusively cover the 12-month period immediately preceding your formal inquiry.
(3) The Right to Opt-Out: The CCPA enshrines your absolute right to dictate that we cease the commercial sale of your personal information.
(4) The Right to Know: You have the right to full transparency regarding the exact categories of data we ingest and our motives, all of which are documented in this annually revised commitment.
(5) Access to Records: Twice every calendar year, completely free of charge, you may demand a comprehensive ledger of the personal information we've collected about you over the past 12 months.
(6) The Right to Deletion: You can mandate the permanent scrubbing of personal data collected over the last year, provided it does not fall under statutory exemptions (e.g., necessary for bug squashing, security, or legal compliance).
9. Initiating the Erasure Process
Once your personal data is no longer integral to our service provision, you can demand its permanent destruction. To set this erasure protocol in motion, please transmit your request to the compliance email listed below.
10. Compliance Contact Information
For regulatory clarifications, feedback, or to exercise your statutory rights tied to this Commitment, direct all correspondence to: Contact Email: modungkhankjg6362@gmail.com