1. Who is responsible for your data (Data Controller)
The app “Shake to Enable Torch” (Android package
com.luxebyte.shaketoenabletorch, the “App”) is published by
Luxebyte Labs (the “Developer”, “we”,
“us”). For the limited processing described in this policy, the data
controller is:
- Controller: Matteo Lamarque, trading as Luxebyte Labs
- Contact for privacy matters: luxebytecomp@gmail.com
“Luxebyte Labs” is a trading name of Matteo Lamarque, an independent developer based in Italy. This is a one-person publisher, and the email address above is the contact point for every privacy matter — it reaches the person who can actually act on it. If you need a postal address in order to exercise a right, write to luxebytecomp@gmail.com and it will be given to you.
Important to understand up front: the Developer operates no servers and runs no backend of its own. We do not receive, store, or have access to the advertising data described in Section 3(b). That data is collected and processed by Google (our advertising provider) and its partners. We are the controller only in the sense that we chose to integrate advertising into the App and we decide where and how an ad may appear. Google determines the means and purposes of its own processing of advertising data and acts as an independent (and, where applicable, joint) controller for it.
2. Scope of this policy
This policy applies only to the “Shake to Enable Torch” Android App distributed through the Google Play Store. It does not cover any other product, website, or third-party service except as expressly described here (in particular Google’s advertising services).
The App is distributed globally and its interface is localized into 17 languages. This English text is the primary version; a faithful Italian translation of equal completeness is provided on this same page (“Informativa sulla privacy”).
Changes and versioning
We may update this policy, for example if the App changes or if legal requirements change. When we make a material change we will update the “Last updated” date above and publish the new version at the same web address where you found this policy, before or at the time the change takes effect. Where the change concerns advertising consent, you may be asked again through the in-app consent mechanism (see Section 7). Your continued use of the App after an update takes effect means the updated policy applies to you; if you do not agree, you can stop using the App and uninstall it.
3. What data is processed
The App processes four clearly separate categories of data. We keep them separate on purpose, because they behave very differently: one stays on your device, apart from Android’s own backup into your own Google Drive; one is collected by Google and never reaches us; one is a single request that carries nothing about you but cannot help revealing where it came from; and one is a small set of counts and categories about how reliably the App is working, which is not collected at all in the EEA, the UK and Switzerland, and which you can switch off at any time everywhere else.
3(a) — Data kept on your device, never transmitted to us
To make the App work and to power its features, the App stores a small amount of
information locally on your device only, using Android’s standard
SharedPreferences storage. This includes:
- your shake counts (how many times the App has detected a shake);
- your daily streak (consecutive-day usage counter);
- your achievements (in-app milestones you have unlocked);
- your block mini-game progress, where that feature is switched on for your device (see Section 3(c)) — your best score, and how many rounds you have finished;
- your settings and preferences, such as shake sensitivity and the theme (light/dark) you have chosen.
This on-device data is never sent anywhere by the App as the values you see, with two exceptions stated below and nowhere else — Android’s own backup, and the two coarse bands described under Section 3(d). It is never transmitted to the Developer (who has no servers to receive it), and is never sold or shared with anyone. It is fully under your control: uninstalling the App, or clearing the App’s storage/data in Settings → Apps → Shake to Enable Torch → Storage, deletes it.
One exception, stated here rather than left to be assumed: Android’s own backup. The App leaves Android’s standard Auto Backup switched on, which is the platform default. If you have device backup turned on in your Android settings, then Android — not the App — copies the App’s stored preferences to your own Google Drive, and includes them when you transfer to a new phone. That copy is not limited to the list above: it takes every preference the App has on the device, which also includes the cached copy of the file described in Section 3(c) and the preferences written by Google’s advertising and consent components — among them the record of the advertising-consent choice you made in the consent form described in Section 7. That copy leaves your device and is held by Google under your Google account, so it is the one way the data in this Section 3(a) is transmitted at all. We cannot see it, reach it, or ask for it — app backups are not accessible to app developers, we operate no servers, and we receive nothing from it. You control it entirely: turn backup off, or delete this App’s backup, in Settings → Google → Backup.
One narrow carve-out, stated here rather than buried. Where the usage and reliability statistics described in Section 3(d) are active — never in the EEA, the UK or Switzerland, and elsewhere only until you turn the in-app switch off — two of the values above are also sent as coarse bands, never as the values themselves: which quarter of the sensitivity slider you are on, and roughly how many mini-game rounds you have finished. Your best score, your shake counts, your streak and your achievements are not sent in any form. Apart from Android’s backup and that carve-out, nothing in this Section 3(a) leaves your device.
The App also reads your device’s accelerometer (motion sensor) through a foreground service in order to detect shaking. Where the device provides them, it additionally registers the proximity, tilt, wake-gesture and pick-up-gesture sensors (or a manufacturer’s equivalent of them). Those are not used to observe you: they are used only as a signal that the device has been picked up or moved, so that shake detection can be started again after Android has suspended it. The App does not use the proximity sensor to work out where the device is or what is near it.
All of these readings are processed transiently on the device to decide whether to toggle the flashlight; they are not recorded, stored, profiled, or transmitted. No sample, no trace and no magnitude of any of them leaves your device in any form. Two things derived from them can. The shake counts and streak listed above leave by the Android backup route described immediately above — into your own Google Drive, never to us. And where the statistics in Section 3(d) are switched on, what may be sent is a banded count of how many shakes were detected during a window and a three-way comparison of the strongest reading in that window against the shake threshold you chose (below / near / above) — never a sample, never a trace, never a magnitude. Nothing that leaves your device could reconstruct your movement.
If you switch on the option to stop the torch during phone calls, the App
asks for the Android phone state permission
(android.permission.READ_PHONE_STATE) and then observes whether a call is
ringing, in progress, or finished — and nothing else. It does not read your phone
number, your call history, your contacts, or who is calling. The state is read
transiently on the device, for the sole purpose of not leaving a torch
burning during a call, and is never profiled and never transmitted to us.
One detail rather than a round claim: so that it can put the torch back as it found it, the App stores on the device the time at which a call-related pause began. That timestamp is stored in the same preferences described above, and is therefore included in the Android backup described above. It records nothing about the call itself — no number, no direction, no duration, no identity — and it is never sent to us.
This permission is requested at the moment you enable that option, not at install time, and the feature is entirely optional: refuse it, or leave the option off, and the rest of the App is unaffected. You can withdraw it at any time in Settings → Apps → Shake to Enable Torch → Permissions.
So that shake detection keeps working on devices whose manufacturer shuts background apps down, the App registers a device-local account named “Shake to Torch (keep-alive)”, which you can see in Settings → Accounts. It holds no credentials and no data, it is not linked to any online account, and nothing is ever synchronised through it: Android’s sync scheduler is used purely as a periodic nudge that tells the App to check whether its own flashlight service is still running. Uninstalling the App removes it.
3(b) — Advertising data, collected and shared by Google (AdMob)
The App shows advertising supplied by the Google Mobile Ads SDK (Google AdMob). There is one advertising format and only one: a rewarded video that you choose to watch. Nothing is shown to you that you did not ask for.
Rewarded video ads — opt-in, you choose to watch them
A rewarded ad is never played on its own. You tap something, the App tells you that an ad is involved, and you confirm — or refuse. There are up to three such places, depending on which of the App’s optional parts are switched on for your device (see Section 3(c)):
- the achievements gallery — tapping to view your achievements may first offer you a short video;
- the dark theme — switching the dark theme on may first offer you a short video (switching it off is always free);
- the block mini-game’s “continue”, where the mini-game is switched on — when a round ends, you may be offered one short video in exchange for one extra life.
These ads are never auto-played and are always declinable; declining leaves the App fully usable. On the two torch surfaces, declining simply means you do not open that screen or change that setting at that moment — and if you did agree but the ad cannot actually be shown, the App gives you what you asked for anyway rather than leaving you stuck.
There is no second format — no advertising is imposed on you
The rewarded video described above is the only advertising format the App contains. The App shows no banner ad, no full-screen interstitial, no app-open ad and no native ad — on any screen, including inside the block mini-game.
So every advert in the App is one you started: nothing plays by itself, nothing occupies part of the screen while you use the App, and declining every offer leaves the App fully usable.
What “you choose to watch it” does not mean. So that an ad is ready at the moment you ask for one, the App asks Google’s SDK to fetch one in advance, in the background, while a screen that can offer one is open. That fetch is an ad request, and it is what sends the advertising data listed below. It therefore happens whether or not you go on to accept the offer, and even if you are never shown an ad at all. What your choice controls is whether an advert is ever displayed to you and whether you receive the reward — not whether an advert was requested for you.
No ad is requested, and no advertising identifier is read, until the consent step described in Section 7 has been resolved and the remote advertising switch described in Section 3(c) has been read.
To serve these ads we use the Google Mobile Ads SDK (Google AdMob). When an ad is requested and shown, Google and its advertising partners collect and process the following categories of data for the purposes of serving ads, measuring ad performance, and preventing fraud and abuse:
- the Android Advertising ID (AAID) — a resettable advertising identifier;
- the app-set ID — an identifier scoped to apps from the same developer;
- your IP address;
- device and diagnostic information (e.g. device model, OS version, language/region, and similar technical data);
- your interactions with ads (e.g. whether an ad was shown, viewed, or clicked).
This advertising data is collected by and shared with Google and Google’s advertising partners. The Developer does not receive it. Because Google’s advertising infrastructure is global, this data may be processed on servers located outside the EU/EEA, including in the United States (see Section 6).
If you do not consent (where consent is required — see Section 7) or you opt out, the App still works fully; you simply will not be served personalized ads, and in regions where consent is required no ad identifiers are used without your consent.
So that Google can read the advertising identifier listed above, the App declares the
Android Advertising ID permission
(com.google.android.gms.permission.AD_ID). It is declared explicitly rather than
inherited silently, so that what the App can reach is written down rather than guessed at. It
grants access to that identifier and to nothing else.
3(c) — One request to a static file, so ads can be switched off without an update
The App fetches a single small text file from a fixed address:
https://matteomark.github.io/ads-flag.txt
It does so at most once a day. The App keeps its own copy of the file and re-uses that copy for a day before asking for a fresh one, so opening the App repeatedly does not repeat the request.
The lines in that file say whether advertising is switched on at all, and which of the App’s optional parts are switched on individually — the dark-theme rewarded ad, the block mini-game, and the promotion of our other app. It exists so that any of them can be turned off without publishing a new version of the App. It does not govern the usage and reliability statistics described in Section 3(d); those are governed only by the controls listed there.
The App sends nothing with this request: no identifier, no advertising ID, nothing about you or about how you use the App. But as with any request to any web server, the server that answers it necessarily sees the IP address the request came from, together with ordinary connection information such as the time, the file requested and the type of client. That server is GitHub Pages, operated by GitHub, Inc., which hosts the file as a plain static document. We run no server, and we never see a log of these requests.
3(d) — Usage and reliability statistics (Google Analytics for Firebase)
Why this exists, plainly. A large share of the negative reviews the App receives say the same thing: the shake stops working. The App currently cannot tell why on any device except the Developer’s own. Was the background service killed by the phone’s manufacturer? Does the hardware have no usable motion sensor? Was the shake detected but the flashlight refused to come on? Those are three different faults with three different fixes, and a one-star review cannot tell them apart. These statistics are how that question gets answered across many devices instead of one.
We describe this data as pseudonymous, and deliberately not as “anonymous”. Each installation is identified by a random identifier generated by Google’s SDK, and Google sees the IP address the data arrives from. That is enough for the data to count as personal data, so it is treated as personal data throughout this policy.
Where this is active, and where nothing is sent at all
This is stated first because it is the most important fact in this Section.
In the EEA, the UK and Switzerland, nothing is sent at all. Not a reduced set, not an anonymised set — nothing. The consent form described in Section 7 is presented by a Google component that, in the version this release ships, carries no analytics purpose at all, so the App can never receive consent for this purpose in those regions and treats it as never given. That much is a property of the App as built. It rests on one thing that is not: whether a consent form is required for you at all is decided by Google’s consent system, from the consent message we publish for those regions — the same mechanism that already decides whether the advertising described in Section 3(b) is personalised there. The App does not work out your location itself, and does not try to. Should either of those change, that form becomes the control, this Section will say so, and this policy will be updated before any collection begins there.
Everywhere else, these statistics are active. The App carries the Google Analytics for Firebase SDK and is built with the Google project credentials it needs, so what is described below is a collection and not merely a capability. It is on unless you turn it off: the in-app “share usage statistics” switch starts in the on position and turning it off stops the collection immediately and completely, and also discards the identifier described further down, so that switching it back on later starts a new one rather than resuming the old. Section 4 sets out the legal basis, which outside those regions is our legitimate interest in diagnosing a fault we otherwise cannot see, with that opt-out always available.
An earlier draft of this Section said that nothing was being sent from any device and that nothing could be. The first half is still true of the App you have today. The second stops being true with the update described above, which is why this Section now leads with where the line falls, and from when.
What is collected, where it is active — every field, in plain words
Reliability of the background service
- why the App’s background service last stopped — one value from a fixed list of reasons Android itself supplies (for example “out of memory”, “stopped by the system”, “crash”);
- roughly how long ago that happened, as a band (“less than an hour”, “1–6 hours”, “6–24 hours”, “1–2 days”, “more than 2 days”);
- whether the App holds the battery-optimisation exemption on that device;
- whether you had the shake service switched on.
Recovery
- which of the App’s internal recovery paths restarted the service, what the outcome was, and roughly how long the service had been stopped (the same bands as above);
- when Android refused to let the App restart its own service, and which of three kinds of refusal it was.
The device’s motion-sensor capabilities — sent once per installation and once per App update, and not again
- whether an accelerometer exists at all;
- how deep its buffer is, as a band (0 / 1–99 / 100–999 / 1000 or more);
- whether a wake-capable accelerometer exists;
- which kind of “pick-up”-type sensor is the best one available — a category such as “pick up”, “tilt” or “proximity”, never the manufacturer’s own name for the part — and how many such sensors exist.
A periodic summary — at most a few times a day, covering a window of at least 30 minutes whose length is included
- how many shakes were detected, how many flashlight commands were attempted, how many failed, and how many were refused by the camera — each one as a band (“0”, “1–5”, “6–20”, “more than 20”);
- whether the strongest motion reading in that window was below, near, or above the sensitivity threshold you chose;
- which quarter of the sensitivity slider you are on;
- which screen-off strategy was in force.
Product usage
- when the block mini-game is opened, and which doorway you came in through — the toolbar, the settings row, the mini-game column of the home screen’s progress card, an achievement tile, or the invitation popup (or that the screen was merely restored after Android recreated it);
- roughly how long a game session lasted, as a band (under 30 seconds, 30 seconds to 2 minutes, 2–5 minutes, 5–15 minutes, over 15 minutes);
- roughly how many rounds you have finished, as a band;
- when one of the two occasional startup prompts is put on your screen, and which of the two it was: the invitation to the block mini-game, or the offer of our other app. It is counted once when it appears and not counted again until you answer it, so a screen that Android rebuilds does not count twice;
- how that prompt ended, as one of four fixed words: that you accepted it, that you chose “not now”, that you chose “don’t show this again” where the prompt offers that, or that you dismissed it with the back gesture. If you never answer it, nothing is sent;
- when the Google Play listing for our other app is opened, and which of four places you opened it from: the game card in the settings list, the standing bar inside the mini-game, the end-of-run card, or the startup prompt itself;
- taps on a fixed, short list of named controls: the theme toggle, the rate button, the tutorial, the on/off switch, the sensitivity slider, the battery-exemption prompt, and the achievements page. Those named controls, together with the prompts and the store links in the three points above, are the whole of what is recorded about what you touch. This is not a heatmap: there are no coordinates, no session recording, and a control outside those lists is deliberately not recorded at all.
Those three points about the prompts and the store listing are the whole of what each of them records. Each carries only the fixed words listed with it: no free text, no timing figure, no reading from any sensor, nothing about where you are, and no identifier of its own. They travel with the same random installation identifier as every other item in this Section, and with nothing more.
Collected automatically by Google
- Google’s own SDK also records app opens, app updates, operating-system updates and a rough measure of session length, and derives an approximate location (country/region level) from the IP address the data is received from. It may also record that an advert was shown. These are the SDK’s own events, not ours: we do not choose their contents, and the fixed lists described above do not govern them. Two of them we do switch off — no advertising identifier is collected for this purpose, and no screen-view tracking is enabled.
What is deliberately NOT collected
This list is the point of the design, not a footnote:
- No raw accelerometer readings, traces or magnitudes ever leave your device. Only the coarse band comparisons described above do.
- No advertising ID is used for this purpose. The App instructs the SDK not to collect it. The only identifier here is the random, app-scoped, resettable identifier that Google’s SDK generates for the installation. It is reset when you turn the “share usage statistics” switch off, so a switch turned off and later turned back on starts a new identifier rather than resuming the old one.
- No free text of any kind — nothing you type, no strings composed by your device, no error messages, and no manufacturer-supplied text. Android’s own written description of why a process died is mapped to a fixed short list of values before anything is sent, and so is the manufacturer’s own name for a motion sensor. Every value listed above comes from a fixed list the App defines in advance.
- No mini-game scores. They stay on your device (Section 3(a)).
- No information from the phone-state / call-state check. That feature stays entirely on your device (Section 3(a)).
- No record of when or where the torch was switched on — only the banded aggregate counts described above.
- No per-shake events.
- No memory figures, and no precise timestamps as event fields.
How to switch it off — and where it is off already
Either one of these is enough to stop it:
- In the EEA, the UK and Switzerland, these statistics are not collected at all in this version of the App — whichever way you answer any form. The consent form described in Section 7 is provided by a Google component that, in the version this release ships, carries no analytics purpose; the App therefore treats consent for this purpose as never given in those regions and sends nothing. Should that ever change, that same form — reopenable at any time from the App’s “Ad & privacy settings” row — becomes the control, and this Section will say so before any collection begins.
- The in-app “share usage statistics” switch, everywhere else. It starts in the on position; turn it off and nothing is collected, immediately and completely. You can turn it back on again at any time, and nothing else in the App changes either way.
A third control described in an earlier draft no longer exists. A line in the file in Section 3(c) used to let the Developer switch these statistics off for every installation at once. It has been removed and is not relied on anywhere in this policy; the two controls above are the whole of it.
To collect these statistics we use Google Analytics for Firebase (GA4), supplied by Google. Google is the recipient (Section 5), the data may be processed outside the EEA under the safeguards in Section 6, and Google’s event-level retention for it is set to the shortest period Google offers (Section 8).
The App does not collect or use contacts, photos, microphone, camera content (the torch uses the flash hardware, not camera imagery), account information, or any special-category (sensitive) personal data. It uses no location API and no GPS: the only location involved anywhere is the approximate, country/region level location that Google derives from an IP address — for advertising (Section 3(b)) and, where they are switched on, for the statistics in Section 3(d).
4. Why we process data, and the legal basis for each purpose (GDPR)
Under the EU GDPR, the UK GDPR, and the Italian Codice Privacy (D.lgs. 196/2003 as amended by D.lgs. 101/2018), every processing purpose needs a legal basis.
| Purpose | Data involved | Legal basis |
|---|---|---|
| Provide the core flashlight function (detect a shake and toggle the torch) | Transient accelerometer readings (on-device only) | Performance of the service you requested and our legitimate interest (Art. 6(1)(b)/(f) GDPR) in making the App work. The readings themselves never leave your device and are never stored. Two things derived from them can leave it: the shake counts and streak, through the Android backup described in Section 3(a); and the coarse counts and band comparisons in Section 3(d), and then only where those statistics are active and you have not switched them off. Neither can reconstruct any movement. |
| Remember your settings, counts, streak, achievements, and mini-game progress | On-device SharedPreferences data (3(a)) |
Legitimate interest (Art. 6(1)(f) GDPR) in providing the features you use; processing occurs only on your device and is not accessible to us. |
| Serve and measure the advertising described in Section 3(b) — the opt-in rewarded ads, including the requests made in advance so that an ad is ready when you ask for one (incl. fraud/abuse prevention) | Advertising data via Google (3(b)) | In the EEA, UK, and Switzerland: your consent (Art. 6(1)(a) GDPR; and ePrivacy consent to storing/reading identifiers on your device), collected via the Google UMP consent form before any ad is requested. Outside those regions, Google processes this data under the legal bases set out in Google’s own policies. |
| Stop the torch during a phone call, where you have switched that option on | Whether a call is ringing, in progress or finished, read transiently on the device (Section 3(a)) | Your consent to the Android runtime permission (Art. 6(1)(a) GDPR), given when you enable the option and withdrawable in Android’s own permission settings. Nothing about the call is transmitted to us; the only thing stored is the time a call-related pause began (Section 3(a)). |
| Check whether advertising, and the App’s other optional parts, are switched on | The IP address the request comes from, seen by the file host (Section 3(c)) | Legitimate interest (Art. 6(1)(f) GDPR) in being able to switch advertising off without shipping a release. No identifier is sent, and we receive nothing. |
| Understand why the shake stops working on some devices, and which parts of the App are used — the usage and reliability statistics in Section 3(d) | Banded counts, fixed-list reasons and category values, plus the random app-instance identifier and the IP-derived approximate location described in Section 3(d) | In the EEA, the UK, and Switzerland these statistics are not collected at all in this version (Section 3(d)); were that to change, the basis would be your consent (Art. 6(1)(a) GDPR, and ePrivacy consent for the identifier on your device), taken through the same Google UMP form used for advertising. Outside those regions: our legitimate interest (Art. 6(1)(f) GDPR) in diagnosing a fault we otherwise cannot see, with an opt-out available at any time — the in-app “share usage statistics” switch, which is on by default and takes effect the moment you turn it off. |
We rely on legitimate interest for the first two purposes, which are confined to your device and involve no transmission, sharing, sale, or profiling, and for the advertising and feature kill-switch check, which transmits nothing about you; you can object (see Section 9) and exercise full control through Android’s app-storage controls and by uninstalling. For advertising in the EEA/UK/Switzerland we rely on consent, not legitimate interest: no ad identifiers are accessed and no ad is requested until you have made your choice, and you can withdraw consent at any time (Section 7), as easily as you gave it and without affecting the lawfulness of processing already carried out. The Developer receives none of the advertising data.
Every advert is user-initiated, which strengthens rather than replaces the basis above. Consent is still what makes the processing lawful in the EEA/UK/Switzerland, and it is still taken before any ad request, because the App fetches ads in advance of your tap (Section 3(b)). What changed is that no advert is displayed to anyone who did not ask for one, so the App relies on no “imposed format” anywhere in this analysis.
For the statistics in Section 3(d) we rely, outside the consent regions, on legitimate interest — our interest in being able to diagnose a fault that is invisible to us otherwise, balanced by the facts that the data is banded rather than exact, carries no advertising identifier, and can be switched off in the App at any time. You do not have to give a reason to opt out, and the App is fully usable either way. For that purpose the Developer does decide what is collected and why, and is the controller for it; Google acts as our analytics provider and processes the data additionally for its own purposes as described in its policies.
5. Who receives data (third parties / recipients)
Because we run no servers, the parties that receive data through the App are our advertising provider and its ecosystem, our analytics provider, and the host of the single file described in Section 3(c):
- Google — specifically Google Ireland Limited (for users in the EEA/UK/Switzerland) and Google LLC (United States), operating Google Mobile Ads / AdMob; and
- Google again, in a separate role — the same two companies, operating Google Analytics for Firebase, which receives the usage and reliability statistics described in Section 3(d) where they are switched on. This is a different purpose from advertising and we keep it that way deliberately: no advertising identifier is used for it, and the two are not linked; and
- Google’s advertising partners (third-party ad networks, demand partners, and measurement providers involved in serving and measuring the ads described in Section 3(b)); and
- Google once more, in a third and quite different role — as the operator of Android Auto Backup / Google Drive, which holds the backup copy of the on-device data described in Section 3(a) if you have device backup switched on. That copy is held in your own Google account, not ours, and we have no access to it; and
- GitHub, Inc. — only as the host of the one static text file described in Section 3(c). It receives the IP address that request is made from, and nothing else. GitHub privacy statement — https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
References describing how Google processes this data and who its partners are:
- Google Privacy Policy — https://policies.google.com/privacy
- How Google uses information from sites/apps that use its services — https://policies.google.com/technologies/partner-sites
- Google advertising technologies / partners — https://policies.google.com/technologies/ads and AdMob partners list https://support.google.com/admob/answer/9012903
We do not share the on-device data in Section 3(a) with anyone, and we never receive it. It leaves your device by two routes and no others: Android’s own backup into your Google Drive, described in Section 3(a) — a copy held under your account, which we cannot reach — and, where the statistics in Section 3(d) are switched on, the two coarse bands named in the carve-out there.
6. International data transfers
The on-device data in Section 3(a) is not transferred anywhere by the App — it stays on your device. If you have Android’s device backup switched on, Android copies it to your own Google Drive (Section 3(a)), where it is stored on Google’s infrastructure and may therefore rest outside your country. That is a transfer made by the Android platform into your own Google account, on Google’s terms and under your control; the Developer is not a party to it and receives nothing from it.
The static file described in Section 3(c) is served by GitHub, Inc., a company based in the United States, so the IP address that request is made from is received there.
The advertising data in Section 3(b) is handled by Google’s global infrastructure and may be transferred to and processed in countries outside the EU/EEA, the UK, and Switzerland, including the United States.
The usage and reliability statistics in Section 3(d), where they are switched on, are handled by the same company on the same global infrastructure and may be transferred in the same way, under the same transfer mechanism described below.
Where such transfers occur, they are protected by the safeguards Google relies upon, which include:
- the European Commission’s adequacy decision for the United States and Google’s certification under the EU–U.S. Data Privacy Framework (and the UK Extension and the Swiss–U.S. framework), where applicable; and/or
- the Standard Contractual Clauses (SCCs) approved by the European Commission (and the UK International Data Transfer Addendum) under Art. 46 GDPR, with supplementary measures where required.
Details of Google’s transfer mechanisms are in the Google Privacy Policy and its data-transfer / Data Processing Terms at https://policies.google.com/privacy. As the Developer receives none of this data, the transfer safeguards for it are those operated by Google.
7. Consent and how to change or withdraw it
In the EEA, the UK, and Switzerland
Before the App requests any ad, we show you a consent form provided by Google’s User Messaging Platform (UMP) consent SDK. Through it you can agree to or decline the use of advertising identifiers and personalized advertising. No ad is requested and no advertising identifier is read until you have made your choice.
You can change or withdraw your choice at any time, from inside the App, via the “Ad & privacy settings” option — the App’s existing privacy settings row, which reopens exactly the same form. Withdrawing consent is as easy as giving it.
What that form does not cover in this version. The usage and reliability statistics in Section 3(d) are not collected at all in the EEA, the UK and Switzerland in this version of the App, whichever way you answer. The Google component that presents this form carries no analytics purpose in the version the App ships, so the App treats consent for that purpose as never given here and sends nothing. If that ever changes, this same form becomes the control for both purposes and this policy will say so before any collection begins.
Outside the EEA, the UK, and Switzerland
Where no consent form is shown, advertising is governed by Google’s own policies and by the Android Advertising ID controls below. The App still displays no advert you did not ask for, in any region.
The usage and reliability statistics in Section 3(d) are governed here by an in-app switch, “share usage statistics”, which you can turn off at any time and which takes effect immediately.
Everywhere — controlling your Advertising ID at the Android level
Independently of the in-app controls, you can manage the advertising identifier on your device via Settings → Privacy → Ads (the exact path varies by device/Android version), where you can Reset advertising ID or Delete advertising ID and turn off ad personalization. Deleting the advertising ID causes apps to receive a string of zeros instead of an identifier, which limits ad personalization.
8. Data retention — how long data is kept
- On-device data (3(a)): kept on your device until you delete it by clearing the App’s storage/data or uninstalling. We never receive it, hold no copy, and apply no server-side retention to it. Where Android’s backup has copied it to your Google Drive (Section 3(a)), that copy is retained by Google under your account and its retention rules, and you delete it in Settings → Google → Backup.
- Advertising data (3(b)): retained by Google per Google’s own data-retention policies, not by us. We store none of it. See the Google Privacy Policy (https://policies.google.com/privacy) and use the Android Advertising ID controls (Section 7) to reset or delete the identifier.
- Usage and reliability statistics (3(d)): held by Google in Google Analytics for Firebase. Google offers a choice of event-level retention periods, and ours is 2 months — the shortest Google offers, and the value a new property carries by default. It is a setting in the Google Analytics console, applied to the whole property, so it applies to every event described in Section 3(d), and if we ever lengthen it this policy will say so before we do. After that period the event-level records are deleted by Google; aggregated reporting totals that cannot be traced back to an installation may persist longer under Google’s own policies. We store none of it ourselves, because we operate no servers.
9. Your privacy rights
EEA, UK, Switzerland (GDPR / UK GDPR / Italian Codice Privacy)
Subject to the conditions in the law, you have the right to access, rectification, erasure, restriction, objection to legitimate-interest processing, data portability, to withdraw consent at any time (for advertising, and for the statistics in Section 3(d) where they are ever collected on that basis — Section 7), and to lodge a complaint with a supervisory authority. In Italy this is the Garante per la protezione dei dati personali (www.garante.it); you may also complain to the authority in your country of residence or workplace. In the UK this is the Information Commissioner’s Office (ICO) (ico.org.uk).
Because the Developer holds no personal data on any server, in practice: for the on-device data you exercise these rights directly by viewing/changing it in the App and by clearing the App’s storage or uninstalling; for the advertising data, the most effective route is to withdraw consent / change your choice (Section 7), use the Android Advertising ID controls (Section 7), and exercise your rights with Google as the party that holds the data, via the Google Privacy Policy. You may still contact us at luxebytecomp@gmail.com for any request; we respond without undue delay and, under the GDPR, normally within one month.
California (CCPA/CPRA) and other US state privacy laws
You have the right to know/access, delete, correct, opt out of the “sale” or “sharing” of personal information (including “sharing” for cross-context behavioral advertising), limit certain uses, and non-discrimination for exercising your rights. The personal information involved is limited to the advertising identifiers, device/diagnostic information, IP address, and ad-interaction data (Section 3(b)) processed by Google and its partners, and — where they are switched on — the banded usage and reliability statistics, the random app-instance identifier, and the IP-derived approximate location described in Section 3(d), processed by Google as our analytics provider. The statistics in Section 3(d) are not sold or shared for cross-context behavioural advertising, and no advertising identifier is used for them; you can switch them off with the in-app “share usage statistics” control described in Section 3(d). Depending on your settings and region, the use of advertising identifiers for personalized advertising may be a “sale” or “sharing” under California law. Exercise an opt-out by declining consent / changing your choice in the in-app “Ad & privacy settings” and via the Android Advertising ID controls (Section 7). You may also contact us at luxebytecomp@gmail.com. Because we operate no servers and receive none of this data, opt-out and deletion for advertising data are fulfilled through these controls and directly with Google.
10. Children’s privacy
The App is a general-audience utility. On Google Play it is declared as not targeted to, and not primarily appealing to, children, and it is not part of the Google Play “Designed for Families” / Teacher Approved programme. Its declared target audience on Google Play is users aged 16 and over.
That number is chosen for a reason. Under Art. 8 GDPR each EU Member State sets its own age of digital consent, anywhere between 13 and 16 (Italy sets it at 14; some Member States set it at 16). 16 is the highest figure any Member State sets, so every user inside the App’s declared audience is at or above the age at which they can consent for themselves in their own country — including the advertising consent asked for in Section 7.
That is a statement about who the App is declared for, not a claim that nobody younger ever installs it. We cannot verify anyone’s age and we do not try to. What we do is: we do not knowingly collect personal data from children, we ask for no age, name, email address, contacts or account, and we collect nothing that identifies a person to us — we operate no servers and receive none of the data described in Sections 3(b) and 3(d).
The App contains no features directed at children. It does contain a block puzzle mini-game, which is offered as an ordinary general-audience feature of the App and not as content for children. No advertising is imposed inside it, or anywhere else in the App. There is no banner, no full-screen interstitial and no app-open ad; the only advert the mini-game can show is the rewarded video a player asks for in exchange for an extra life, and the only adverts elsewhere are the two rewarded videos described in Section 3(b). Every ad the App requests is requested with a maximum content rating of “PG” (parental guidance), so creatives rated for teen or mature audiences are not requested.
If you believe a child has used the App and that advertising data, or the statistics described in Section 3(d), were collected without appropriate consent, contact us at luxebytecomp@gmail.com. Because such data is held by Google rather than by us, we will help direct a deletion request to Google and provide the Android Advertising ID controls (Section 7) that immediately limit and reset the identifier. This approach is intended to be consistent with COPPA and the Google Play Families Policy.
11. Security
We take a proportionate approach matching the App’s minimal data footprint. The App keeps its data on your device, protected by Android’s standard application sandbox and the device’s own protections (lock screen, encryption, OS permissions); we hold no central database to breach. We transmit no personal data to our own infrastructure, because we operate none. The advertising data is transmitted and protected in transit by Google’s security measures as part of the Google Mobile Ads SDK, and the statistics in Section 3(d) likewise, as part of the Google Analytics for Firebase SDK. No method of electronic processing is ever completely secure; however, by keeping data on-device and operating no servers, we structurally minimize the risk to your information.
12. Changes to this policy and how you are notified
We may revise this policy from time to time. When we do, we will update the “Last updated” date at the top, publish the revised policy at the same web address where you found it, and — where the change affects advertising or your consent — ask you again through the in-app consent mechanism (UMP) where required. Material changes take effect when the updated policy is published (or, where the law requires renewed consent, once that consent is collected).
13. How to contact us about privacy
For any question about this policy or to exercise any of your rights, contact Luxebyte Labs at luxebytecomp@gmail.com. This email address is the single point of contact for all privacy requests relating to the App.
1. Chi è responsabile dei tuoi dati (Titolare del trattamento)
L’app “Shake to Enable Torch” (pacchetto Android
com.luxebyte.shaketoenabletorch, l’“App”) è pubblicata da
Luxebyte Labs (lo “Sviluppatore”, “noi”).
Per i trattamenti limitati descritti nella presente informativa, il titolare del trattamento
è:
- Titolare: Matteo Lamarque, operante con il nome commerciale Luxebyte Labs
- Contatto per le questioni privacy: luxebytecomp@gmail.com
“Luxebyte Labs” è il nome commerciale di Matteo Lamarque, sviluppatore indipendente con sede in Italia. Si tratta di un editore composto da una sola persona, e l’indirizzo e-mail sopra indicato è il punto di contatto per ogni questione di privacy: scrive alla persona che può effettivamente intervenire. Se ti serve un indirizzo postale per esercitare un tuo diritto, scrivi a luxebytecomp@gmail.com e ti verrà fornito.
Importante da chiarire subito: lo Sviluppatore non gestisce alcun server e non utilizza alcun backend proprio. Noi non riceviamo, non conserviamo e non abbiamo accesso ai dati pubblicitari descritti alla Sezione 3(b). Tali dati sono raccolti e trattati da Google (il nostro fornitore pubblicitario) e dai suoi partner. Noi siamo titolari soltanto nel senso che abbiamo scelto di integrare la pubblicità nell’App e decidiamo dove e come un annuncio possa comparire. Google determina i mezzi e le finalità del proprio trattamento dei dati pubblicitari e agisce, per tali dati, come titolare autonomo (e, ove applicabile, contitolare).
2. Ambito di applicazione
La presente informativa si applica esclusivamente all’App Android “Shake to Enable Torch” distribuita tramite il Google Play Store. Non riguarda alcun altro prodotto, sito web o servizio di terzi, salvo quanto qui espressamente descritto (in particolare i servizi pubblicitari di Google).
L’App è distribuita a livello globale e la sua interfaccia è localizzata in 17 lingue. Il testo inglese è la versione primaria; questa traduzione italiana, fedele e di pari completezza, è disponibile sulla stessa pagina.
Modifiche e versionamento
Potremmo aggiornare la presente informativa, ad esempio se l’App cambia o se mutano i requisiti di legge. In caso di modifica sostanziale, aggiorneremo la data di “Ultimo aggiornamento” in alto e pubblicheremo la nuova versione allo stesso indirizzo web in cui hai trovato questa informativa, prima o al momento dell’entrata in vigore della modifica. Quando la modifica riguarda il consenso pubblicitario, potrà esserti richiesto nuovamente tramite il meccanismo di consenso in-app (vedi Sezione 7). L’uso continuato dell’App dopo l’entrata in vigore di un aggiornamento comporta l’applicazione dell’informativa aggiornata; se non sei d’accordo, puoi smettere di usare l’App e disinstallarla.
3. Quali dati vengono trattati
L’App tratta quattro categorie di dati nettamente distinte. Le manteniamo separate di proposito, perché si comportano in modo molto diverso: una resta sul tuo dispositivo, salvo il backup di Android sul tuo Google Drive; una è raccolta da Google e non arriva mai a noi; una è un’unica richiesta che non trasporta nulla su di te ma non può evitare di rivelare da dove proviene; e una è un piccolo insieme di conteggi e categorie su quanto affidabilmente l’App stia funzionando, che non viene raccolto affatto nello SEE, nel Regno Unito e in Svizzera e che ovunque altrove puoi disattivare in qualsiasi momento.
3(a) — Dati conservati sul tuo dispositivo, mai trasmessi a noi
Per far funzionare l’App e alimentarne le funzionalità, l’App memorizza una piccola
quantità di informazioni solo localmente sul tuo dispositivo, utilizzando
l’archiviazione standard di Android SharedPreferences. Ciò comprende:
- i tuoi conteggi di scuotimenti (quante volte l’App ha rilevato uno scuotimento);
- la tua serie giornaliera (contatore di utilizzo in giorni consecutivi);
- i tuoi obiettivi/traguardi (achievement sbloccati nell’App);
- i tuoi progressi nel mini-gioco a blocchi, dove tale funzione è attiva per il tuo dispositivo (vedi Sezione 3(c)) — il tuo punteggio migliore e quante partite hai completato;
- le tue impostazioni e preferenze, come la sensibilità allo scuotimento e il tema (chiaro/scuro) scelto.
Questi dati on-device non vengono inviati in alcun luogo dall’App nella forma dei valori che vedi, con due sole eccezioni indicate qui sotto e in nessun altro punto — il backup di Android e le due fasce approssimative descritte nella Sezione 3(d). Non sono mai trasmessi allo Sviluppatore (che non dispone di server per riceverli) e non sono mai venduti né condivisi con alcuno. Sono pienamente sotto il tuo controllo: disinstallando l’App, oppure cancellando l’archiviazione/i dati dell’App in Impostazioni → App → Shake to Enable Torch → Spazio di archiviazione, vengono eliminati.
Un’unica eccezione, dichiarata qui e non lasciata a supposizioni: il backup di Android. L’App lascia attivo il backup automatico (Auto Backup) standard di Android, che è l’impostazione predefinita della piattaforma. Se hai attivato il backup del dispositivo nelle impostazioni di Android, allora Android — non l’App — copia le preferenze memorizzate dall’App sul tuo Google Drive, e le include quando trasferisci i dati su un nuovo telefono. Quella copia non si limita all’elenco sopra riportato: comprende tutte le preferenze che l’App ha sul dispositivo, quindi anche la copia in cache del file descritto nella Sezione 3(c) e le preferenze scritte dai componenti pubblicitari e di consenso di Google — tra cui la registrazione della scelta sul consenso pubblicitario che hai espresso nel modulo descritto nella Sezione 7. Quella copia lascia il tuo dispositivo ed è detenuta da Google sotto il tuo account Google: è l’unico modo in cui i dati della presente Sezione 3(a) vengono trasmessi. Noi non possiamo vederla, raggiungerla né richiederla — i backup delle app non sono accessibili agli sviluppatori, non gestiamo server e da essa non riceviamo nulla. Il controllo è interamente tuo: puoi disattivare il backup, o eliminare il backup di questa App, in Impostazioni → Google → Backup.
Un’unica eccezione circoscritta, detta qui e non sepolta altrove. Dove le statistiche di utilizzo e affidabilità descritte nella Sezione 3(d) sono attive — mai nello SEE, nel Regno Unito o in Svizzera, e altrove soltanto finché non disattivi l’interruttore in-app — due dei valori sopra elencati vengono inviati anche come fasce approssimative, mai come valori veri e propri: in quale quarto del cursore di sensibilità ti trovi e all’incirca quante partite del mini-gioco hai completato. Il tuo punteggio migliore, i tuoi conteggi di scuotimenti, la tua serie giornaliera e i tuoi obiettivi non vengono inviati in alcuna forma. A parte il backup di Android e questa eccezione, nulla di quanto descritto nella presente Sezione 3(a) lascia il tuo dispositivo.
L’App legge inoltre l’accelerometro (sensore di movimento) del dispositivo tramite un servizio in primo piano per rilevare lo scuotimento. Dove il dispositivo li mette a disposizione, registra anche i sensori di prossimità, di inclinazione (tilt), di gesto di risveglio (wake gesture) e di sollevamento (pick-up gesture), o gli equivalenti del produttore. Non servono a osservarti: sono usati unicamente come segnale che il dispositivo è stato sollevato o mosso, così che il rilevamento dello scuotimento possa essere riavviato dopo che Android lo ha sospeso. L’App non usa il sensore di prossimità per stabilire dove si trovi il dispositivo o che cosa gli sia vicino.
Tutte queste letture sono elaborate in modo transitorio sul dispositivo al solo fine di decidere se attivare/disattivare la torcia; non vengono registrate, memorizzate, profilate o trasmesse. Nessun campione, nessuna traccia e nessuna intensità di alcuna di esse lascia il tuo dispositivo, in alcuna forma. Due dati da esse derivati possono uscirne. I conteggi di scuotimenti e la serie giornaliera elencati sopra escono attraverso il backup di Android descritto qui sopra — verso il tuo Google Drive, mai verso di noi. E dove le statistiche della Sezione 3(d) sono attive, ciò che può essere inviato è un conteggio a fasce di quanti scuotimenti sono stati rilevati in una finestra e un confronto a tre valori fra la lettura più intensa di quella finestra e la soglia di scuotimento da te scelta (sotto / vicino / sopra): mai un campione, mai una traccia, mai un’intensità. Nulla di ciò che lascia il tuo dispositivo potrebbe ricostruire i tuoi movimenti.
Se attivi l’opzione per interrompere la torcia durante le telefonate,
l’App richiede l’autorizzazione Android allo stato del telefono
(android.permission.READ_PHONE_STATE) e osserva quindi se una chiamata
sta squillando, è in corso o è terminata — e nient’altro. Non legge il tuo numero di
telefono, il registro delle chiamate, i tuoi contatti né chi ti sta chiamando. Lo stato è
letto in modo transitorio sul dispositivo, al solo fine di non lasciare una
torcia accesa durante una chiamata, e non viene mai profilato né mai trasmesso a
noi.
Un dettaglio, anziché un’affermazione assoluta: per poter riportare la torcia com’era, l’App memorizza sul dispositivo l’ora in cui è iniziata una pausa dovuta a una chiamata. Tale marcatura temporale è conservata nelle stesse preferenze descritte sopra ed è quindi inclusa nel backup di Android descritto sopra. Non registra nulla della chiamata in sé — né numero, né direzione, né durata, né identità — e non ci viene mai inviata.
L’autorizzazione viene richiesta nel momento in cui attivi quell’opzione, non al momento dell’installazione, e la funzione è del tutto facoltativa: rifiutala, o lascia l’opzione disattivata, e il resto dell’App non ne risente. Puoi revocarla in qualsiasi momento in Impostazioni → App → Shake to Enable Torch → Autorizzazioni.
Affinché il rilevamento dello scuotimento continui a funzionare sui dispositivi il cui produttore chiude le app in background, l’App registra un account locale del dispositivo denominato “Shake to Torch (keep-alive)”, visibile in Impostazioni → Account di Android. Non contiene alcuna credenziale e alcun dato, non è collegato ad alcun account online e attraverso di esso non viene mai sincronizzato nulla: lo scheduler di sincronizzazione di Android è usato unicamente come promemoria periodico che dice all’App di verificare se il proprio servizio torcia è ancora in esecuzione. Disinstallando l’App, viene rimosso.
3(b) — Dati pubblicitari, raccolti e condivisi da Google (AdMob)
L’App mostra pubblicità fornita dal Google Mobile Ads SDK (Google AdMob). Il formato pubblicitario è uno soltanto: un video con premio (rewarded) che sei tu a scegliere di guardare. Non ti viene mostrato nulla che tu non abbia chiesto.
Annunci video con premio (rewarded) — opt-in, sei tu a scegliere di guardarli
Un annuncio rewarded non parte mai da solo. Tocchi qualcosa, l’App ti avvisa che è previsto un annuncio, e tu confermi — oppure rifiuti. I punti in cui ciò accade sono al massimo tre, a seconda di quali parti facoltative dell’App siano attive per il tuo dispositivo (vedi Sezione 3(c)):
- la galleria degli obiettivi — toccando per visualizzare i tuoi obiettivi può esserti prima proposto un breve video;
- il tema scuro — attivando il tema scuro può esserti prima proposto un breve video (disattivarlo è sempre gratuito);
- il “continua” del mini-gioco a blocchi, dove il mini-gioco è attivo — quando una partita finisce, può esserti proposto un breve video in cambio di una vita in più.
Questi annunci non vengono mai riprodotti automaticamente e sono sempre rifiutabili; rifiutandoli, l’App resta pienamente utilizzabile. Nei due punti dell’app torcia, rifiutare significa semplicemente che in quel momento non apri quella schermata o non modifichi quell’impostazione — e se hai acconsentito ma l’annuncio non può essere mostrato, l’App ti concede comunque ciò che avevi chiesto anziché lasciarti bloccato.
Non esiste un secondo formato — nessuna pubblicità ti viene imposta
Il video con premio descritto sopra è l’unico formato pubblicitario presente nell’App. L’App non mostra alcun annuncio banner, alcun interstitial a schermo intero, alcun annuncio all’apertura dell’app (app-open) e alcun annuncio nativo — in nessuna schermata, mini-gioco a blocchi compreso.
Ogni annuncio dell’App è quindi un annuncio che sei tu ad avviare: nulla parte da solo, nulla occupa una parte dello schermo mentre usi l’App, e rifiutando ogni proposta l’App resta pienamente utilizzabile.
Che cosa NON significa “sei tu a scegliere di guardarlo”. Affinché un annuncio sia pronto nel momento in cui lo chiedi, l’App chiede all’SDK di Google di scaricarne uno in anticipo, in background, mentre è aperta una schermata che può proportelo. Quel download è una richiesta di annuncio, ed è ciò che invia i dati pubblicitari elencati di seguito. Avviene quindi indipendentemente dal fatto che tu accetti la proposta, e anche se non ti viene mai mostrato alcun annuncio. Ciò che la tua scelta controlla è se un annuncio ti venga mai mostrato e se tu riceva il premio — non se un annuncio sia stato richiesto per te.
Nessun annuncio viene richiesto e nessun identificativo pubblicitario viene letto finché non si è conclusa la fase di consenso descritta nella Sezione 7 e non è stato letto l’interruttore pubblicitario remoto descritto nella Sezione 3(c).
Per mostrare questi annunci utilizziamo il Google Mobile Ads SDK (Google AdMob). Quando un annuncio viene richiesto e mostrato, Google e i suoi partner pubblicitari raccolgono e trattano le seguenti categorie di dati per le finalità di erogazione degli annunci, misurazione delle prestazioni pubblicitarie e prevenzione di frodi e abusi:
- l’ID pubblicità di Android (AAID) — un identificativo pubblicitario reimpostabile;
- l’app-set ID — un identificativo riferito alle app dello stesso sviluppatore;
- il tuo indirizzo IP;
- informazioni sul dispositivo e diagnostiche (modello del dispositivo, versione del sistema operativo, lingua/area geografica e dati tecnici simili);
- le tue interazioni con gli annunci (se un annuncio è stato mostrato, visualizzato o cliccato).
Questi dati pubblicitari sono raccolti da e condivisi con Google e con i partner pubblicitari di Google. Lo Sviluppatore non li riceve. Poiché l’infrastruttura pubblicitaria di Google è globale, tali dati possono essere trattati su server situati al di fuori dell’UE/SEE, inclusi gli Stati Uniti (vedi Sezione 6).
Se non presti il consenso (ove richiesto — vedi Sezione 7) o effettui l’opt-out, l’App continua a funzionare pienamente; semplicemente non ti verranno mostrati annunci personalizzati e, nelle aree in cui il consenso è richiesto, non viene utilizzato alcun identificativo pubblicitario senza il tuo consenso.
Affinché Google possa leggere l’identificativo pubblicitario sopra indicato, l’App dichiara
l’autorizzazione Android Advertising ID
(com.google.android.gms.permission.AD_ID). È dichiarata esplicitamente anziché
ereditata in silenzio, così che ciò a cui l’App può accedere sia messo per iscritto anziché
lasciato a supposizioni. Dà accesso a quell’identificativo e a nient’altro.
3(c) — Una richiesta a un file statico, per poter disattivare gli annunci senza un aggiornamento
L’App scarica un unico piccolo file di testo da un indirizzo fisso:
https://matteomark.github.io/ads-flag.txt
Lo fa al massimo una volta al giorno. L’App conserva una propria copia del file e la riutilizza per un giorno prima di richiederne una nuova, per cui aprire l’App ripetutamente non ripete la richiesta.
Le righe di quel file indicano se la pubblicità è attiva e quali parti facoltative dell’App sono attive singolarmente — l’annuncio rewarded del tema scuro, il mini-gioco a blocchi e la promozione della nostra altra app. Esiste per poter disattivare ciascuna di esse senza pubblicare una nuova versione dell’App. Non governa le statistiche di utilizzo e affidabilità descritte nella Sezione 3(d): quelle sono governate soltanto dai controlli elencati in quella Sezione.
Con questa richiesta l’App non invia nulla: nessun identificativo, nessun ID pubblicitario, nulla che riguardi te o il modo in cui usi l’App. Ma come per qualsiasi richiesta a qualsiasi server web, il server che risponde vede necessariamente l’indirizzo IP da cui proviene la richiesta, insieme alle normali informazioni di connessione quali l’orario, il file richiesto e il tipo di client. Quel server è GitHub Pages, gestito da GitHub, Inc., che ospita il file come semplice documento statico. Noi non gestiamo alcun server e non vediamo mai un log di queste richieste.
3(d) — Statistiche di utilizzo e affidabilità (Google Analytics per Firebase)
Perché esistono, detto chiaramente. Buona parte delle recensioni negative che l’App riceve dice la stessa cosa: lo scuotimento smette di funzionare. Ad oggi l’App non è in grado di dire perché su nessun dispositivo che non sia quello dello Sviluppatore. Il servizio in background è stato ucciso dal produttore del telefono? L’hardware non dispone di un sensore di movimento utilizzabile? Lo scuotimento è stato rilevato ma la torcia si è rifiutata di accendersi? Sono tre guasti diversi con tre soluzioni diverse, e una recensione da una stella non può distinguerli. Queste statistiche sono il modo in cui quella domanda trova risposta su molti dispositivi anziché su uno solo.
Descriviamo questi dati come pseudonimi, e deliberatamente non come “anonimi”. Ogni installazione è identificata da un identificativo casuale generato dall’SDK di Google, e Google vede l’indirizzo IP da cui i dati arrivano. Ciò è sufficiente perché tali dati costituiscano dati personali, e come dati personali sono trattati in tutta la presente informativa.
Dove sono attive e dove non viene inviato nulla
Lo diciamo per primo perché è il fatto più importante di questa Sezione.
Nello SEE, nel Regno Unito e in Svizzera non viene inviato nulla. Non un insieme ridotto, non un insieme anonimizzato: nulla. Il modulo di consenso descritto nella Sezione 7 è presentato da un componente Google che, nella versione distribuita con questa release, non include alcuna finalità analitica: l’App non può quindi ricevere il consenso per questa finalità in tali aree e lo considera come mai prestato. Questo è una proprietà dell’App così come è compilata. Poggia però su una cosa che non lo è: se per te sia richiesto un modulo di consenso lo decide il sistema di consenso di Google, in base al messaggio di consenso che pubblichiamo per tali aree — lo stesso meccanismo che già decide se la pubblicità descritta nella Sezione 3(b) sia personalizzata. L’App non determina da sé la tua posizione e non tenta di farlo. Se una delle due cose dovesse cambiare, quel modulo diventerà il controllo, questa Sezione lo dirà e la presente informativa verrà aggiornata prima che qualsiasi raccolta abbia inizio.
Ovunque altrove, queste statistiche sono attive. L’App contiene l’SDK di Google Analytics per Firebase e quell’aggiornamento è compilato con le credenziali del progetto Google necessarie: quanto descritto di seguito è quindi una raccolta e non soltanto una capacità. È attiva salvo tua disattivazione: l’interruttore in-app “Condividi statistiche d’uso” parte in posizione attiva e disattivarlo ferma la raccolta immediatamente e del tutto, e cancella anche l’identificativo descritto più avanti, così che riattivandolo in seguito ne inizi uno nuovo invece di riprendere il precedente. La Sezione 4 indica la base giuridica, che al di fuori di tali aree è il nostro legittimo interesse a diagnosticare un guasto che altrimenti non possiamo vedere, con quell’opt-out sempre disponibile.
Una precedente bozza di questa Sezione diceva che non veniva inviato nulla da alcun dispositivo e che nulla poteva esserlo. La prima metà è ancora vera per l’App che hai oggi. La seconda smette di esserlo con l’aggiornamento descritto sopra: per questo la Sezione ora si apre indicando dove passa la linea, e da quando.
Che cosa viene raccolto, dove è attivo — ogni campo, in parole semplici
Affidabilità del servizio in background
- perché il servizio in background dell’App si è fermato l’ultima volta — un valore tratto da un elenco fisso di motivi che Android stesso fornisce (ad esempio “memoria esaurita”, “arrestato dal sistema”, “crash”);
- all’incirca quanto tempo fa è accaduto, come fascia (“meno di un’ora”, “1–6 ore”, “6–24 ore”, “1–2 giorni”, “più di 2 giorni”);
- se l’App dispone dell’esenzione dall’ottimizzazione della batteria su quel dispositivo;
- se avevi il servizio di scuotimento attivo.
Ripristino
- quale dei percorsi di ripristino interni dell’App ha riavviato il servizio, quale ne è stato l’esito e all’incirca per quanto tempo il servizio era rimasto fermo (le stesse fasce di cui sopra);
- quando Android ha rifiutato all’App di riavviare il proprio servizio, e quale dei tre tipi di rifiuto si è verificato.
Le capacità del sensore di movimento del dispositivo — inviate una volta per installazione e una volta per ogni aggiornamento dell’App, e mai più
- se esiste un accelerometro;
- quanto è profondo il suo buffer, come fascia (0 / 1–99 / 100–999 / 1000 o più);
- se esiste un accelerometro in grado di risvegliare il dispositivo;
- quale tipo di sensore “di sollevamento” è il migliore disponibile — una categoria come “sollevamento”, “inclinazione” o “prossimità”, mai il nome che il produttore dà al componente — e quanti di questi sensori esistono.
Un riepilogo periodico — al massimo poche volte al giorno, riferito a una finestra di almeno 30 minuti la cui durata è inclusa
- quanti scuotimenti sono stati rilevati, quanti comandi di accensione della torcia sono stati tentati, quanti sono falliti e quanti sono stati rifiutati dalla fotocamera — ciascuno come fascia (“0”, “1–5”, “6–20”, “più di 20”);
- se la lettura di movimento più intensa di quella finestra era sotto, vicino o sopra la soglia di sensibilità da te scelta;
- in quale quarto del cursore di sensibilità ti trovi;
- quale strategia a schermo spento era in vigore.
Utilizzo del prodotto
- quando viene aperto il mini-gioco a blocchi e da quale porta d’accesso sei entrato — la barra degli strumenti, la voce nelle impostazioni, la colonna del mini-gioco nella scheda dei progressi della schermata principale, una targhetta obiettivo o il messaggio di invito (oppure che la schermata è stata semplicemente ripristinata dopo che Android l’ha ricreata);
- all’incirca quanto è durata una sessione di gioco, come fascia (meno di 30 secondi, da 30 secondi a 2 minuti, 2–5 minuti, 5–15 minuti, oltre 15 minuti);
- all’incirca quante partite hai completato, come fascia;
- quando uno dei due messaggi occasionali di avvio ti viene messo sullo schermo e quale dei due fosse: l’invito al mini-gioco a blocchi o la proposta della nostra altra app. Viene contato una volta sola quando compare e non viene contato di nuovo finché non gli dai una risposta, così una schermata che Android ricrea non lo conta due volte;
- come si è concluso quel messaggio, con una di quattro parole fisse: che l’hai accettato, che hai scelto “non ora”, che hai scelto “non mostrare più” dove il messaggio lo prevede, oppure che l’hai chiuso con il gesto indietro. Se non gli dai mai una risposta, non viene inviato nulla;
- quando viene aperta la scheda su Google Play della nostra altra app e da quale dei quattro punti l’hai aperta: la scheda del gioco nell’elenco delle impostazioni, la barra fissa dentro il mini-gioco, la scheda di fine partita oppure il messaggio di avvio stesso;
- i tocchi su un elenco fisso e breve di comandi nominati: l’interruttore del tema, il pulsante di valutazione, il tutorial, l’interruttore di accensione/spegnimento, il cursore di sensibilità, il messaggio sull’esenzione dalla batteria e la pagina degli obiettivi. Quei comandi nominati, insieme ai messaggi e ai collegamenti allo store dei tre punti precedenti, sono tutto ciò che viene registrato di quello che tocchi. Non si tratta di una mappa di calore: nessuna coordinata, nessuna registrazione della sessione e un comando che non figura in quegli elenchi non viene deliberatamente registrato.
Quei tre punti sui messaggi e sulla scheda dello store sono tutto ciò che ciascuno di essi registra. Ognuno porta con sé soltanto le parole fisse elencate accanto: nessun testo libero, nessun dato temporale, nessuna lettura di alcun sensore, nulla su dove ti trovi e nessun identificativo proprio. Viaggiano con lo stesso identificativo casuale dell’installazione di ogni altra voce di questa Sezione, e con nulla di più.
Raccolti automaticamente da Google
- L’SDK di Google registra inoltre le aperture dell’app, gli aggiornamenti dell’app, gli aggiornamenti del sistema operativo e una misura approssimativa della durata della sessione, e ricava una posizione approssimativa (a livello di Paese/regione) dall’indirizzo IP da cui i dati vengono ricevuti. Può inoltre registrare che è stato mostrato un annuncio. Sono eventi propri dell’SDK, non nostri: non ne scegliamo il contenuto e gli elenchi fissi descritti sopra non li governano. Due cose le disattiviamo noi: nessun identificativo pubblicitario viene raccolto per questa finalità e nessun tracciamento delle schermate è attivo.
Che cosa NON viene deliberatamente raccolto
Questo elenco è il senso stesso del progetto, non una nota a piè di pagina:
- Nessuna lettura grezza dell’accelerometro, nessuna traccia e nessuna intensità lascia mai il tuo dispositivo. Lo fanno soltanto i confronti a fasce approssimative descritti sopra.
- Nessun ID pubblicitario viene utilizzato per questa finalità. L’App istruisce l’SDK a non raccoglierlo. L’unico identificativo qui presente è l’identificativo casuale, riferito alla sola App e reimpostabile che l’SDK di Google genera per l’installazione. Viene reimpostato quando disattivi l’interruttore “Condividi statistiche d’uso”: se in seguito lo riattivi, ne inizia uno nuovo invece di riprendere il precedente.
- Nessun testo libero di alcun tipo — nulla che tu scriva, nessuna stringa composta dal tuo dispositivo, nessun messaggio di errore e nessun testo fornito dal produttore. La descrizione testuale che Android stesso fornisce sul perché un processo è terminato viene mappata su un elenco fisso e breve di valori prima di qualsiasi invio, e lo stesso vale per il nome che il produttore dà a un sensore di movimento. Ogni valore elencato sopra proviene da un elenco fisso definito in anticipo dall’App.
- Nessun punteggio del mini-gioco. Resta sul tuo dispositivo (Sezione 3(a)).
- Nessuna informazione proveniente dal controllo sullo stato del telefono / delle chiamate. Quella funzione resta interamente sul tuo dispositivo (Sezione 3(a)).
- Nessuna traccia di quando o dove la torcia è stata accesa — soltanto i conteggi aggregati a fasce descritti sopra.
- Nessun evento per singolo scuotimento.
- Nessun dato sulla memoria e nessuna marca temporale precisa come campo di evento.
Come disattivarle — e dove sono già disattivate
Ne basta uno dei due per fermare tutto:
- Nello SEE, nel Regno Unito e in Svizzera queste statistiche non vengono raccolte affatto in questa versione dell’App, qualunque risposta tu dia a qualsiasi modulo. Il modulo di consenso descritto nella Sezione 7 è fornito da un componente Google che, nella versione distribuita con questa release, non include alcuna finalità analitica; l’App considera quindi il consenso per questa finalità come mai prestato in tali aree e non invia nulla. Se ciò dovesse cambiare, quello stesso modulo — riapribile in qualsiasi momento dalla voce “Annunci e privacy” dell’App — diventerà il controllo, e questa Sezione lo dirà prima che inizi qualsiasi raccolta.
- L’interruttore in-app “Condividi statistiche d’uso”, in tutte le altre aree. Parte in posizione attiva; disattivalo e non viene raccolto nulla, immediatamente e del tutto. Puoi riattivarlo quando vuoi, e nulla d’altro nell’App cambia in un senso o nell’altro.
Un terzo controllo descritto in una precedente bozza non esiste più. Una riga nel file della Sezione 3(c) consentiva allo Sviluppatore di disattivare queste statistiche per tutte le installazioni in una sola volta. È stata rimossa e non è richiamata in alcun punto della presente informativa: i due controlli sopra indicati sono tutto.
Per raccogliere queste statistiche utilizziamo Google Analytics per Firebase (GA4), fornito da Google. Google è il destinatario (Sezione 5), i dati possono essere trattati al di fuori dello SEE con le garanzie indicate nella Sezione 6, e la conservazione a livello di singolo evento presso Google è impostata sul periodo più breve che Google offre (Sezione 8).
L’App non raccoglie né utilizza contatti, foto, microfono, contenuti della fotocamera (la torcia usa l’hardware del flash, non le immagini della fotocamera), informazioni di account o categorie particolari (dati sensibili) di dati personali. Non utilizza alcuna API di geolocalizzazione e alcun GPS: l’unica posizione coinvolta è la posizione approssimativa, a livello di Paese/regione, che Google ricava da un indirizzo IP — per la pubblicità (Sezione 3(b)) e, quando sono attive, per le statistiche della presente Sezione 3(d).
4. Perché trattiamo i dati e la base giuridica di ciascuna finalità (GDPR)
Ai sensi del GDPR UE, del GDPR del Regno Unito e del Codice Privacy italiano (D.lgs. 196/2003 come modificato dal D.lgs. 101/2018), ogni finalità di trattamento richiede una base giuridica.
| Finalità | Dati coinvolti | Base giuridica |
|---|---|---|
| Fornire la funzione torcia di base (rilevare uno scuotimento e attivare/disattivare la torcia) | Letture transitorie dell’accelerometro (solo on-device) | Esecuzione del servizio richiesto e nostro legittimo interesse (art. 6, par. 1, lett. b)/f) GDPR) a far funzionare l’App. Le letture in sé non lasciano mai il tuo dispositivo e non vengono mai memorizzate. Due dati da esse derivati possono uscirne: i conteggi di scuotimenti e la serie giornaliera, tramite il backup di Android descritto nella Sezione 3(a); e i conteggi approssimativi e i confronti a fasce della Sezione 3(d), e soltanto dove quelle statistiche sono attive e non le hai disattivate. Né gli uni né gli altri possono ricostruire alcun movimento. |
| Memorizzare impostazioni, conteggi, serie, obiettivi e progressi nel mini-gioco | Dati on-device in SharedPreferences (3(a)) |
Legittimo interesse (art. 6, par. 1, lett. f) GDPR) a fornire le funzionalità che utilizzi; il trattamento avviene solo sul tuo dispositivo e non è a noi accessibile. |
| Erogare e misurare la pubblicità descritta nella Sezione 3(b) — gli annunci rewarded opt-in, comprese le richieste effettuate in anticipo affinché un annuncio sia pronto quando lo chiedi (inclusa la prevenzione di frodi/abusi) | Dati pubblicitari tramite Google (3(b)) | Nello SEE, nel Regno Unito e in Svizzera: il tuo consenso (art. 6, par. 1, lett. a) GDPR; nonché il consenso ePrivacy alla memorizzazione/lettura di identificativi sul tuo dispositivo), raccolto tramite il modulo Google UMP prima che venga richiesto qualsiasi annuncio. Al di fuori di tali aree, Google tratta questi dati sulla base delle proprie informative. |
| Interrompere la torcia durante una telefonata, se hai attivato tale opzione | Se una chiamata sta squillando, è in corso o è terminata, letto in modo transitorio sul dispositivo (Sezione 3(a)) | Il tuo consenso all’autorizzazione runtime di Android (art. 6, par. 1, lett. a) GDPR), prestato quando attivi l’opzione e revocabile nelle impostazioni delle autorizzazioni di Android. Nulla della chiamata ci viene trasmesso; l’unico dato memorizzato è l’ora in cui è iniziata una pausa dovuta a una chiamata (Sezione 3(a)). |
| Verificare se la pubblicità, e le altre parti facoltative dell’App, sono attive | L’indirizzo IP da cui proviene la richiesta, visto dal soggetto che ospita il file (Sezione 3(c)) | Legittimo interesse (art. 6, par. 1, lett. f) GDPR) a poter disattivare la pubblicità senza pubblicare una nuova versione. Non viene inviato alcun identificativo e noi non riceviamo nulla. |
| Capire perché lo scuotimento smette di funzionare su alcuni dispositivi e quali parti dell’App vengono usate — le statistiche di utilizzo e affidabilità della Sezione 3(d) | Conteggi a fasce, motivi ed elenchi fissi di valori di categoria, oltre all’identificativo casuale dell’installazione e alla posizione approssimativa ricavata dall’IP descritti nella Sezione 3(d) | Nello SEE, nel Regno Unito e in Svizzera queste statistiche non vengono raccolte affatto in questa versione (Sezione 3(d)); se ciò dovesse cambiare, la base sarebbe il tuo consenso (art. 6, par. 1, lett. a) GDPR, e il consenso ePrivacy per l’identificativo sul tuo dispositivo), raccolto tramite lo stesso modulo Google UMP usato per la pubblicità. Al di fuori di tali aree: il nostro legittimo interesse (art. 6, par. 1, lett. f) GDPR) a diagnosticare un guasto che altrimenti non possiamo vedere, con un opt-out disponibile in qualsiasi momento — l’interruttore in-app “Condividi statistiche d’uso”, attivo per impostazione predefinita e con effetto immediato dal momento in cui lo disattivi. |
Ci basiamo sul legittimo interesse per le prime due finalità, che restano confinate al tuo dispositivo e non comportano alcuna trasmissione, condivisione, vendita o profilazione, e per la verifica del kill-switch di pubblicità e funzionalità, che non trasmette nulla che ti riguardi; puoi opporti (vedi Sezione 9) ed esercitare il pieno controllo tramite i controlli di archiviazione delle app di Android e disinstallando. Per la pubblicità nello SEE/Regno Unito/Svizzera ci basiamo sul consenso, non sul legittimo interesse: nessun identificativo pubblicitario viene letto e nessun annuncio viene richiesto finché non hai effettuato la tua scelta, e puoi revocare il consenso in qualsiasi momento (Sezione 7), con la stessa facilità con cui lo hai concesso e senza pregiudicare la liceità del trattamento già effettuato. Lo Sviluppatore non riceve alcun dato pubblicitario.
Ogni annuncio è avviato dall’utente, il che rafforza la base giuridica sopra indicata anziché sostituirla. Ciò che rende lecito il trattamento nello SEE/Regno Unito/Svizzera resta il consenso, ed esso viene raccolto prima di qualsiasi richiesta di annuncio, poiché l’App scarica gli annunci in anticipo rispetto al tuo tocco (Sezione 3(b)). Ciò che è cambiato è che nessun annuncio viene mostrato a chi non lo ha chiesto: l’App non si basa quindi su alcun “formato imposto” in alcun punto della presente analisi.
Per le statistiche della Sezione 3(d), al di fuori delle aree in cui si raccoglie il consenso, ci basiamo sul legittimo interesse: il nostro interesse a poter diagnosticare un guasto che altrimenti ci resta invisibile, bilanciato dal fatto che i dati sono a fasce anziché esatti, non recano alcun identificativo pubblicitario e possono essere disattivati nell’App in qualsiasi momento. Non devi motivare l’opt-out, e l’App resta pienamente utilizzabile in entrambi i casi. Per tale finalità lo Sviluppatore decide invece che cosa viene raccolto e perché, ed è titolare per essa; Google agisce come nostro fornitore di analytics e tratta i dati anche per finalità proprie, come descritto nelle sue informative.
5. Chi riceve i dati (terze parti / destinatari)
Poiché non gestiamo server, le parti che ricevono dati tramite l’App sono il nostro fornitore pubblicitario con il suo ecosistema, il nostro fornitore di analytics e il soggetto che ospita l’unico file descritto nella Sezione 3(c):
- Google — in particolare Google Ireland Limited (per gli utenti nello SEE/Regno Unito/Svizzera) e Google LLC (Stati Uniti), che gestiscono Google Mobile Ads / AdMob; e
- Google ancora, in un ruolo distinto — le stesse due società, che gestiscono Google Analytics per Firebase, destinatario delle statistiche di utilizzo e affidabilità descritte nella Sezione 3(d) dove siano attive. È una finalità diversa dalla pubblicità e la teniamo tale di proposito: per essa non viene usato alcun identificativo pubblicitario e le due non sono collegate; e
- i partner pubblicitari di Google (reti pubblicitarie di terzi, demand partner e fornitori di misurazione coinvolti nell’erogazione e nella misurazione degli annunci descritti nella Sezione 3(b)); e
- Google ancora una volta, in un terzo ruolo del tutto diverso — quale gestore del backup automatico di Android / Google Drive, che detiene la copia di backup dei dati on-device descritti nella Sezione 3(a) se hai attivato il backup del dispositivo. Tale copia è detenuta nel tuo account Google, non nel nostro, e noi non vi abbiamo accesso; e
- GitHub, Inc. — unicamente in quanto soggetto che ospita l’unico file di testo statico descritto nella Sezione 3(c). Riceve l’indirizzo IP da cui proviene la richiesta, e nient’altro. Informativa privacy di GitHub — https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
Riferimenti che descrivono come Google tratta questi dati e chi sono i suoi partner:
- Informativa privacy di Google — https://policies.google.com/privacy
- Come Google utilizza le informazioni provenienti da siti/app che usano i suoi servizi — https://policies.google.com/technologies/partner-sites
- Tecnologie pubblicitarie / partner di Google — https://policies.google.com/technologies/ads ed elenco partner AdMob https://support.google.com/admob/answer/9012903
Non condividiamo con alcuno i dati on-device della Sezione 3(a) e non li riceviamo mai. Lasciano il tuo dispositivo per due vie e per nessun’altra: il backup di Android sul tuo Google Drive, descritto nella Sezione 3(a) — una copia detenuta sotto il tuo account, che noi non possiamo raggiungere — e, dove le statistiche della Sezione 3(d) sono attive, le due fasce approssimative indicate nell’eccezione ivi descritta.
6. Trasferimenti internazionali di dati
I dati on-device della Sezione 3(a) non vengono trasferiti in alcun luogo dall’App: restano sul tuo dispositivo. Se hai attivato il backup del dispositivo di Android, Android ne effettua una copia sul tuo Google Drive (Sezione 3(a)), dove è conservata sull’infrastruttura di Google e può quindi trovarsi al di fuori del tuo Paese. Si tratta di un trasferimento effettuato dalla piattaforma Android verso il tuo account Google, alle condizioni di Google e sotto il tuo controllo: lo Sviluppatore non ne è parte e da esso non riceve nulla.
Il file statico descritto nella Sezione 3(c) è servito da GitHub, Inc., società con sede negli Stati Uniti: di conseguenza l’indirizzo IP da cui proviene la richiesta viene ricevuto lì.
I dati pubblicitari della Sezione 3(b) sono gestiti dall’infrastruttura globale di Google e possono essere trasferiti e trattati in Paesi al di fuori dell’UE/SEE, del Regno Unito e della Svizzera, inclusi gli Stati Uniti.
Le statistiche di utilizzo e affidabilità della Sezione 3(d), dove siano attive, sono gestite dalla stessa società sulla stessa infrastruttura globale e possono essere trasferite allo stesso modo, con lo stesso meccanismo di trasferimento descritto di seguito.
Ove tali trasferimenti avvengano, sono protetti dalle garanzie su cui Google fa affidamento, che comprendono:
- la decisione di adeguatezza della Commissione europea per gli Stati Uniti e la certificazione di Google nell’ambito del Data Privacy Framework UE–USA (e dell’estensione per il Regno Unito e del quadro Svizzera–USA), ove applicabile; e/o
- le Clausole Contrattuali Standard (SCC) approvate dalla Commissione europea (e l’International Data Transfer Addendum del Regno Unito) ai sensi dell’art. 46 GDPR, con misure supplementari ove necessarie.
I dettagli sui meccanismi di trasferimento di Google sono nell’informativa privacy di Google e nei relativi Data Processing Terms all’indirizzo https://policies.google.com/privacy. Poiché lo Sviluppatore non riceve alcuno di questi dati, le garanzie di trasferimento relative a tali dati sono quelle attuate da Google.
7. Consenso e come modificarlo o revocarlo
Nello SEE, nel Regno Unito e in Svizzera
Prima che l’App richieda qualsiasi annuncio, ti mostriamo un modulo di consenso fornito dal SDK User Messaging Platform (UMP) di Google. Tramite esso puoi acconsentire o rifiutare l’uso di identificativi pubblicitari e la pubblicità personalizzata. Nessun annuncio viene richiesto e nessun identificativo pubblicitario viene letto finché non hai effettuato la tua scelta.
Puoi modificare o revocare la tua scelta in qualsiasi momento, dall’interno dell’App, tramite l’opzione “Annunci e privacy” — la voce di impostazioni privacy già presente nell’App, che riapre esattamente lo stesso modulo. Revocare il consenso è facile quanto concederlo.
Che cosa quel modulo non copre in questa versione. Le statistiche di utilizzo e affidabilità della Sezione 3(d) non vengono raccolte affatto nello SEE, nel Regno Unito e in Svizzera in questa versione dell’App, qualunque risposta tu dia. Il componente Google che presenta questo modulo non include alcuna finalità analitica nella versione distribuita con l’App, per cui l’App considera il consenso per quella finalità come mai prestato qui e non invia nulla. Se ciò dovesse cambiare, sarà questo stesso modulo il controllo per entrambe le finalità, e questa informativa lo dirà prima che inizi qualsiasi raccolta.
Al di fuori dello SEE, del Regno Unito e della Svizzera
Dove non viene mostrato alcun modulo di consenso, la pubblicità è disciplinata dalle informative di Google e dai controlli dell’ID pubblicità di Android indicati di seguito. Anche lì l’App non ti mostra alcun annuncio che tu non abbia chiesto.
Le statistiche di utilizzo e affidabilità della Sezione 3(d) sono qui disciplinate da un interruttore in-app, “Condividi statistiche d’uso”, che puoi disattivare in qualsiasi momento e il cui effetto è immediato.
Ovunque — gestire l’ID pubblicità a livello di Android
Indipendentemente dai controlli in-app, puoi gestire l’identificativo pubblicitario sul tuo dispositivo tramite Impostazioni → Privacy → Annunci (il percorso esatto varia in base al dispositivo/versione di Android), dove puoi reimpostare l’ID pubblicità o eliminare l’ID pubblicità e disattivare la personalizzazione degli annunci. L’eliminazione dell’ID pubblicità fa sì che le app ricevano una stringa di zeri anziché un identificativo, limitando la personalizzazione degli annunci.
8. Conservazione dei dati — per quanto tempo sono conservati
- Dati on-device (3(a)): conservati sul tuo dispositivo finché non li elimini, cancellando l’archiviazione/i dati dell’App o disinstallando l’App. Non li riceviamo mai, non ne deteniamo copia e non applichiamo ad essi alcuna conservazione lato server. Ove il backup di Android ne abbia effettuato una copia sul tuo Google Drive (Sezione 3(a)), tale copia è conservata da Google sotto il tuo account e secondo le relative regole di conservazione, e la elimini tu in Impostazioni → Google → Backup.
- Dati pubblicitari (3(b)): conservati da Google secondo le proprie politiche di conservazione, non da noi. Noi non ne conserviamo alcuno. Vedi l’informativa privacy di Google (https://policies.google.com/privacy) e usa i controlli dell’ID pubblicità di Android (Sezione 7) per reimpostare o eliminare l’identificativo.
- Statistiche di utilizzo e affidabilità (3(d)): detenute da Google in Google Analytics per Firebase. Google offre una scelta fra diversi periodi di conservazione a livello di singolo evento, e il nostro è di 2 mesi: il più breve che Google offra, nonché il valore predefinito di una nuova proprietà. È un’impostazione della console di Google Analytics, applicata all’intera proprietà, e vale quindi per ogni evento descritto nella Sezione 3(d); se mai dovessimo allungarlo, la presente informativa lo dirà prima che accada. Trascorso tale periodo i record a livello di evento vengono eliminati da Google; i totali aggregati dei report, non riconducibili a una singola installazione, possono persistere più a lungo secondo le politiche di Google. Noi non ne conserviamo nulla, poiché non gestiamo server.
9. I tuoi diritti in materia di privacy
SEE, Regno Unito, Svizzera (GDPR / GDPR UK / Codice Privacy)
Nei limiti e alle condizioni previsti dalla legge, hai il diritto di accesso, rettifica, cancellazione, limitazione, opposizione al trattamento basato sul legittimo interesse, portabilità, di revocare il consenso in qualsiasi momento (per la pubblicità e, dove mai fossero raccolte su tale base, per le statistiche della Sezione 3(d) — Sezione 7) e di proporre reclamo a un’autorità di controllo. In Italia è il Garante per la protezione dei dati personali (www.garante.it); puoi inoltre rivolgerti all’autorità del tuo Paese di residenza o di lavoro. Nel Regno Unito è l’Information Commissioner’s Office (ICO) (ico.org.uk).
Poiché lo Sviluppatore non detiene alcun dato personale su alcun server, in pratica: per i dati on-device eserciti questi diritti direttamente visualizzandoli o modificandoli nell’App e cancellando l’archiviazione dell’App o disinstallandola; per i dati pubblicitari la via più efficace è revocare il consenso / modificare la tua scelta (Sezione 7), utilizzare i controlli dell’ID pubblicità di Android (Sezione 7) ed esercitare i tuoi diritti nei confronti di Google, quale soggetto che detiene i dati, tramite l’informativa privacy di Google. Puoi comunque contattarci a luxebytecomp@gmail.com per qualsiasi richiesta; rispondiamo senza ingiustificato ritardo e, ai sensi del GDPR, di norma entro un mese.
California (CCPA/CPRA) e altre leggi sulla privacy degli Stati USA
Hai il diritto di conoscere/accedere, cancellare, correggere, rinunciare alla “vendita” o “condivisione” delle informazioni personali (inclusa la “condivisione” per pubblicità comportamentale cross-contesto), limitare determinati usi e di non discriminazione per aver esercitato i tuoi diritti. Le informazioni personali coinvolte sono limitate agli identificativi pubblicitari, alle informazioni su dispositivo/diagnostica, all’indirizzo IP e ai dati di interazione con gli annunci (Sezione 3(b)) trattati da Google e dai suoi partner e — dove siano attive — alle statistiche di utilizzo e affidabilità a fasce, all’identificativo casuale dell’installazione e alla posizione approssimativa ricavata dall’IP descritte nella Sezione 3(d), trattate da Google quale nostro fornitore di analytics. Le statistiche della Sezione 3(d) non sono vendute né condivise per pubblicità comportamentale cross-contesto, e per esse non viene usato alcun identificativo pubblicitario; puoi disattivarle con il controllo in-app “Condividi statistiche d’uso” descritto nella Sezione 3(d). A seconda delle tue impostazioni e della tua area, l’uso di identificativi pubblicitari per la pubblicità personalizzata può essere una “vendita” o “condivisione” ai sensi della legge californiana. Esercita l’opt-out rifiutando il consenso / modificando la tua scelta nelle “Annunci e privacy” in-app e tramite i controlli dell’ID pubblicità di Android (Sezione 7). Puoi anche contattarci a luxebytecomp@gmail.com. Poiché non gestiamo server e non riceviamo alcuno di questi dati, l’opt-out e la cancellazione per i dati pubblicitari sono soddisfatti tramite questi controlli e direttamente con Google.
10. Privacy dei minori
L’App è un’utilità per il pubblico generale. Su Google Play è dichiarata come non destinata né principalmente attraente per i minori e non fa parte del programma “Designed for Families” / Teacher Approved di Google Play. Il suo pubblico di destinazione dichiarato su Google Play è costituito da utenti di età pari o superiore a 16 anni.
Quel numero è scelto per una ragione precisa. Ai sensi dell’art. 8 GDPR ciascuno Stato membro dell’UE fissa la propria età per il consenso digitale, tra i 13 e i 16 anni (l’Italia la fissa a 14 anni; alcuni Stati membri la fissano a 16 anni). 16 è la soglia più elevata fissata da qualsiasi Stato membro: di conseguenza ogni utente compreso nel pubblico dichiarato dell’App ha un’età pari o superiore a quella in cui può prestare da sé il consenso nel proprio Paese — compreso il consenso pubblicitario richiesto nella Sezione 7.
Questa è un’affermazione su a chi l’App è dichiaratamente destinata, non la pretesa che nessuno più giovane la installi mai. Non possiamo verificare l’età di nessuno e non tentiamo di farlo. Ciò che facciamo è: non raccogliamo consapevolmente dati personali dai minori, non chiediamo età, nome, indirizzo e-mail, contatti o account, e non raccogliamo nulla che identifichi una persona per noi — non gestiamo server e non riceviamo alcuno dei dati descritti nelle Sezioni 3(b) e 3(d).
L’App non contiene funzionalità destinate ai minori. Contiene però un mini-gioco rompicapo a blocchi, proposto come normale funzionalità dell’App per il pubblico generale e non come contenuto per minori. Al suo interno, come in ogni altra parte dell’App, non viene imposta alcuna pubblicità. Non vi è alcun banner, alcun interstitial a schermo intero e alcun annuncio all’apertura dell’app; l’unico annuncio che il mini-gioco può mostrare è il video rewarded che il giocatore chiede in cambio di una vita in più, e gli unici annunci altrove sono i due video rewarded descritti nella Sezione 3(b). Ogni annuncio richiesto dall’App è richiesto con una classificazione massima dei contenuti “PG” (parental guidance), quindi non vengono richiesti creativi classificati per un pubblico adolescente o adulto.
Se ritieni che un minore abbia usato l’App e che siano stati raccolti dati pubblicitari, o le statistiche descritte nella Sezione 3(d), senza un consenso adeguato, contattaci a luxebytecomp@gmail.com. Poiché tali dati sono detenuti da Google e non da noi, aiuteremo a indirizzare una richiesta di cancellazione a Google e a fornire i controlli dell’ID pubblicità di Android (Sezione 7) che limitano e reimpostano immediatamente l’identificativo. Questo approccio è inteso come coerente con la COPPA e con la Google Play Families Policy.
11. Sicurezza
Adottiamo un approccio proporzionato all’impronta minima di dati dell’App. L’App conserva i suoi dati sul tuo dispositivo, protetti dalla sandbox applicativa standard di Android e dalle protezioni del dispositivo stesso (schermata di blocco, cifratura, autorizzazioni del sistema operativo); non deteniamo alcun database centrale che possa essere violato. Non trasmettiamo alcun dato personale alla nostra infrastruttura, poiché non ne gestiamo alcuna. I dati pubblicitari sono trasmessi e protetti in transito dalle misure di sicurezza di Google nell’ambito del Google Mobile Ads SDK, e altrettanto vale per le statistiche della Sezione 3(d) nell’ambito del SDK di Google Analytics per Firebase. Nessun metodo di trattamento elettronico è mai completamente sicuro; tuttavia, mantenendo i dati sul dispositivo e non gestendo server, riduciamo strutturalmente il rischio per le tue informazioni.
12. Modifiche alla presente informativa e come ne vieni informato
Potremmo rivedere la presente informativa di tanto in tanto. Quando lo faremo, aggiorneremo la data di “Ultimo aggiornamento” in alto, pubblicheremo l’informativa rivista allo stesso indirizzo web in cui l’hai trovata e — ove la modifica riguardi la pubblicità o il tuo consenso — te lo chiederemo nuovamente tramite il meccanismo di consenso in-app (UMP), ove richiesto. Le modifiche sostanziali hanno effetto al momento della pubblicazione dell’informativa aggiornata (o, ove la legge richieda un rinnovo del consenso, una volta raccolto tale consenso).
13. Come contattarci per questioni di privacy
Per qualsiasi domanda sulla presente informativa o per esercitare uno qualsiasi dei tuoi diritti, contatta Luxebyte Labs a luxebytecomp@gmail.com. Questo indirizzo e-mail è l’unico punto di contatto per tutte le richieste in materia di privacy relative all’App.