KaCha Privacy Policy
Last updated: 2026-08-18
ka-cha ("we", "us") respects your privacy. This policy explains what personal data we collect when you use KaCha (the "App"), why we collect it, and what control you have over it. It is written to meet Taiwan's Personal Data Protection Act, the GDPR, and the CCPA/CPRA.
1. Data controller
- Name: ka-cha
- Contact: ka-cha.bouncing089@passinbox.com
2. What we collect and why
| Data | What it is | Purpose | Source |
|---|---|---|---|
| Email address | Returned by Sign in with Apple or Google Sign-In | Create and manage your account; support | Sign in with Apple / Google Sign-In |
| Name | Returned by Apple only on first authorization | Received but not used for any purpose; your public name is always one you type yourself | Sign in with Apple |
| Date of birth | Entered by you at sign-up | Age gate; birthday card | You |
| Player name | A public name you choose | Leaderboards, level credits, printed on cards (see §5) | You |
| Account ID | Internal identifier we generate | Link your progress, cards and wallet | Generated |
| Photos | Photos you upload as a creator to build a level | Generate and publicly display the level | You |
| Gameplay records | Session times, scores, cards held, gem transactions | Provide the game, leaderboards, support and reconciliation | Generated |
| Usage records | Which screen you viewed, for how long, and which button you tapped (see below) | Improve the interface and the flow | Generated (you can turn this off) |
| Purchase records | Store receipts and fulfilment records | Fulfil purchases, handle refunds and support | in_app_purchase |
| Device and usage signals | Signals the ads SDK receives to serve and measure ads | Show rewarded ads; prevent invalid traffic | google_mobile_ads |
We do not collect your location, contacts, calendar, health data, or microphone input.
Usage analytics ("Help improve the game")
We record how you move around inside the App so we can tell which screen people get stuck on and which button nobody can find. This data goes only to our own servers — no third-party analytics service is involved.
What we record:
| Event | Content |
|---|---|
| Screen view | Which screen you viewed (e.g. "home", "collection") and for how many seconds |
| Tap | Which button you tapped (e.g. "play", "share") |
Screens and buttons come from a fixed list we define in advance — the App can only send an identifier from that list, never the text shown on screen.
What we never record:
- Any text you type or see. Level titles, player names, anything you enter.
- Your IP address, user agent, or any device identifier. Our table has no columns for them.
- Anything you do in other apps or on other websites. This data cannot be linked with any other company's data, which is why there is no App Tracking Transparency prompt — and never will be for this feature.
Retention: 90 days. Records older than 90 days are deleted automatically by a scheduled job. Nothing is kept beyond that.
You can turn it off at any time: Settings → Privacy → "Help improve the game". It is on by default. When you turn it off:
- our server stops accepting this data immediately — it is not merely the App choosing not to send it;
- records already collected are deleted at that moment;
- nothing else about the game changes.
Deleting your account also deletes these records (see §8).
3. Third-party services (SDKs)
- Google Gemini API (level generation) — the photo you upload is sent to this service to generate the spot-the-difference image. Card faces do not go through this service — you upload those yourself. This is the only place where we hand your photo to a third party. https://policies.google.com/privacy
- Google Mobile Ads (advertising) — https://policies.google.com/privacy
- Sign in with Apple (authentication) — https://www.apple.com/legal/privacy/
- Google Sign-In (authentication) — https://policies.google.com/privacy
- Google User Messaging Platform (advertising consent in the EEA/UK) — https://policies.google.com/privacy
- in_app_purchase (billing, handled by the App Store / Google Play)
- image_picker (reads the photo you choose; runs entirely on your device)
4. Advertising: we do not track you across apps
The App shows rewarded ads only — ads you choose to watch in exchange for an in-game reward. There are no banner or interstitial ads.
Every ad request we send is flagged non-personalized. Specifically:
- iOS: we do not present the App Tracking Transparency prompt and we do not request the IDFA. Our bundled Privacy Manifest declares
NSPrivacyTracking = falsewith an empty tracking-domains list. - Android: we explicitly remove the
AD_IDpermission from the app manifest, so the ads SDK cannot obtain a resettable advertising identifier.
In other words, we neither do nor are able to link your activity in this App with data from other companies' apps or websites. The ads SDK still receives basic device and usage signals (such as device model, coarse region, and whether an ad finished playing) to deliver, measure, and protect against invalid traffic.
Non-personalized does not mean consent-free
Even non-personalized ads require your consent in the EEA, the UK and Switzerland before anything can be stored on or read from your device. These are two separate things: "non-personalized" is about not using your behaviour to pick the ad; consent is about whether we may touch your device at all.
The App therefore integrates the Google User Messaging Platform (UMP), a Google-certified consent management platform:
- If you are in a region where consent is required, the App shows the consent form before any ad is displayed.
- We send no ad request until there is a decision. If the consent flow cannot complete (no network, for example), we show no ads rather than showing them anyway.
- You can reopen the form at any time under Settings → Privacy → Ad preferences to change or withdraw your consent.
- Users outside those regions never see the form.
If we ever move to personalized advertising, we will update this policy, obtain your consent on iOS as required (App Tracking Transparency), and update our store privacy declarations before enabling it.
5. User-generated content: what becomes public, and the permanent name on cards
Levels in this App are made by players. Before you upload, please understand:
- Your photo becomes public. Once published it becomes a level that every player can see. Do not upload recognizable faces, license plates, addresses, identity documents, or anything you do not have the right to publish. (The comparison image and the answer coordinates are kept in non-public storage and are only accessible for the duration of a session.)
- Your player name is printed into the card image, and cannot be changed afterwards. Cards awarded on completion carry your player name burned into the public card artwork. That image lives in other players' collections and may be shared — even if you later change your name or delete your account, cards already issued keep the name they were printed with. It is part of the record of who obtained which serial number, and when. Choosing your name is therefore a deliberate step in sign-up.
- Levels and leaderboards display your player name. Levels you publish are credited to you.
User-generated content is automatically screened, then reviewed by a person if reported, and can be reported afterwards. Confirmed violations may result in the level being removed, cards being voided, or the account being suspended.
6. Retention, location, recipients
- Retention: for as long as the purpose lasts, or as required by law. Usage analytics is the exception: it is kept for 90 days only (see §2, "Usage analytics").
- Location: processed and stored on Cloudflare's global edge network, which may involve cross-border transfer; protected by encryption in transit and access controls.
- Recipients: only us and the services listed in §3, for the purposes above. We do not sell your personal data and do not share it with data brokers.
7. Your rights
Under Taiwan's Personal Data Protection Act you may request access, a copy, correction, cessation of processing, or deletion. If you are in the EU/EEA you additionally have the GDPR rights of access, rectification, erasure, restriction, portability, objection, and complaint to a supervisory authority. If you are a California resident you have the CCPA/CPRA rights to know, delete, correct, and opt out of "sale or sharing" of personal information, without discrimination for exercising them.
To exercise any of these, email ka-cha.bouncing089@passinbox.com. If you do not provide sign-in information you cannot create an account or save progress.
8. Account and data deletion
You can delete your account in the App (Profile → Settings → Delete account) or request deletion at https://ka-cha.cc/account-deletion.
What actually happens:
- Identifying fields are cleared immediately. Your player name becomes "deleted user"; the link to your Apple/Google identity and your date of birth are erased. Afterwards there is no path back from your Apple/Google account to that record.
- Remaining fields are purged after 30 days. That window exists to handle refunds, chargebacks and minor-consent disputes, which often arrive after deletion.
- The card issuance ledger and gem transaction log are kept, but no longer contain anything identifying you. They record which card was issued at what time for which win — the issuance history shared by every holder. Deleting a row would undermine the scarcity record of cards other players hold.
- Usage analytics records are deleted — not retained, not kept in anonymized form. They record only which buttons one account tapped, which is of no significance to anyone else.
- Cards already issued keep the name printed on them (see §5.2).
- Transaction records required by law are deleted when the statutory retention period ends.
Deletion is irreversible. Signing in again with the same Apple/Google account creates a brand-new account; previous progress, cards and balances do not return.
9. Children
You must be 16 or older to use this service.
We ask for a date of birth at sign-up. Accounts under 16 enter a restricted state: they can sign in and view or delete their own data, but cannot play, cannot purchase, and are shown no ads.
We flag every ad request with tagForUnderAgeOfConsent so the ads SDK serves only content suitable for minors. That is an additional safeguard; it does not replace the age gate above.
We do not knowingly collect personal data from anyone under 16 for the purpose of providing the game; if you believe we have, contact us and we will delete it promptly.
10. Security
We protect your data with encryption in transit (HTTPS/TLS), access controls, and least-privilege design. Level answers and comparison images are kept in non-public storage and served only through short-lived, session-scoped authorization. Back-office actions are role-gated and audit-logged.
11. Changes
We will post revisions on this page and update the "Last updated" date; significant changes will also be announced in the App.
12. Contact
ka-cha.bouncing089@passinbox.com
Generated with assistance from ShipReady based on an actual scan of the project, then corrected clause by clause against the App's real behaviour. Legal review is recommended before publication.