Skip to content
L FanfilCA
Home Services Contact Start a project →
Effective 15 August 2026

Privacy Policy

Plain-English. Every market. Every ad network. Every age. Read it once, and you'll know exactly how L FanfilCA handles your data.

On this page

1. Overview 2. Data controller 3. Scope of this policy 4. Data we collect 5. How we use data 6. Legal basis (GDPR) 7. Ad networks & mediation 8. Ad formats we serve 9. Children & age 10. App store policies 11. Country & region policies 12. Sharing & processors 13. International transfers 14. Retention 15. Security 16. Your rights 17. Account & data deletion 18. Changes to this policy 19. Contact us

Last updated: 15 August 2026. Previous versions are available on request.

1. Overview

L FanfilCA ("we", "us", "our") is a mobile-first studio that publishes casual games, daily utility applications and a mobile management suite (the "L FanfilCA Apps") on Google Play, the Apple App Store and other distribution channels. This Privacy Policy explains in plain English what data we collect, why we collect it, how we protect it, and the choices you have.

We design every L FanfilCA App around three privacy principles:

  • Data minimisation — we collect only what we need to make the app work.
  • No surprise sale — we never sell your personal data. Ever.
  • On-device by default — when we can process data on your device, we do.

2. Data controller

L FanfilCA Studio is the data controller for personal data collected through the L FanfilCA Apps and this website. You can reach our Data Protection team at privacy@lfanfilca.com or by post at the address listed in section 19.

3. Scope of this policy

This policy applies to:

  • All L FanfilCA-branded apps published on Google Play and the Apple App Store.
  • The L FanfilCA website at lfanfilca.com and any subdomains.
  • Marketing, support and account-related communications you receive from us.

It does not cover third-party services we link to (for example Apple, Google, or any advertiser listed in section 7). Those services have their own privacy notices.

4. Data we collect

Depending on which L FanfilCA App you use and which features you enable, we may collect the following categories of data:

CategoryExamplesSource
Account dataEmail address, display name, profile picture, password hashYou, when you create an account
Device dataDevice model, OS version, locale, time zone, screen sizeYour device, automatically
App usage dataFeatures used, level reached, session length, crash logsApp, automatically
DiagnosticsPerformance metrics, error reports, ANR / crash stack tracesApp, automatically
Approximate locationCountry / region derived from IPNetwork, automatically
Purchase dataReceipt ID, product ID, transaction timestamp (handled by Apple / Google)App store, after a purchase
Support dataMessages, attachments, account IDYou, when you contact support
Backups (Mobile Management)Encrypted chunks of files, contacts, app listYou, opt-in only

We do not collect: government ID numbers, biometric data, health data, sexual orientation, political opinions, or any special category data under GDPR Article 9.

5. How we use data

We use the data above for the following purposes:

  • To operate, maintain and improve the L FanfilCA Apps.
  • To authenticate you and keep your account secure.
  • To remember your settings, progress and preferences.
  • To deliver and measure non-personalised advertising (see section 7).
  • To respond to your support requests.
  • To detect and prevent fraud, abuse, cheating and policy violations.
  • To comply with legal obligations and respond to lawful requests.

6. Legal basis (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on the following legal bases under the GDPR:

  • Contract — to provide the L FanfilCA Apps you have signed up for.
  • Legitimate interests — to keep the apps secure, prevent abuse and improve features, balanced against your rights.
  • Consent — for non-essential cookies, optional analytics, optional advertising personalisation and the opt-in backup feature.
  • Legal obligation — to comply with applicable laws and regulations.

7. Ad networks & mediation

Some L FanfilCA Apps display advertising to keep the apps free. We use the ad networks and mediation platforms listed below. Each of them processes certain device, usage and (where permitted) location data in order to deliver, measure and prevent fraud in advertising. We use Google AdMob as our primary mediation layer.

AdMob + mediation stack. Our apps route ad requests through Google AdMob Mediation, which may also fill ads from the networks below. Each network has been vetted for privacy, child safety and store-policy compliance.

Network / PlatformOperatorPurposeCompliance notes
Google AdMob (primary)Google Ireland Ltd.Ad serving, mediation, measurement, fraud preventionGDPR & ePrivacy compliant; supports UMP consent; child-directed treatment flag honoured
Google Ad ManagerGoogle Ireland Ltd.Direct-sold and programmatic ads on some titlesHonours IAB TCF v2.2 signals
Meta Audience NetworkMeta Platforms Ireland Ltd.Banner, interstitial and rewarded video fillRestricted for users under 18; supports Limited Data Use flag in California
Unity AdsUnity TechnologiesRewarded video, interstitial and bannerCOPPA / GDPR ready; supports age-gate signalling
AppLovin (MAX)AppLovin CorporationMediation + direct network fillSupports COPPA flag; IAB TCF v2.2
ironSource (Unity)Unity TechnologiesMediation and rewarded videoCompliant with Google Play Families Policy
Vungle (Liftoff)Liftoff Mobile, Inc.Rewarded and interstitial videoGDPR-compliant; honours child-directed signal
Pangle (ByteDance)Pangle (TikTok for Business)Banner, interstitial, rewarded videoAvailable in selected regions; supports age gating
InMobiInMobi Technology ServicesBanner, interstitial, rewarded video, nativeGDPR & CCPA compliant; IAB TCF v2.2
MintegralMintegral InternationalRewarded video, interstitial, bannerCOPPA flag supported; not used in child-directed titles
Chartboost (now AdColony / Digital Turbine)Digital TurbineInterstitial and rewarded videoHonours child-directed treatment
Liftoff / Vungle / Digital TurbineAs aboveVideo mediation fillCompliant with Google Play Families Policy
SmaatoSmaato, Inc.Header bidding & mediationIAB TCF v2.2 compliant
OpenMediation (Bytedance / Pangle parent)OpenMediationMediationRegional availability
TapjoyTapjoy, Inc.Offerwall & rewardedNot used in child-directed titles
Digital Turbine (Fyber)Digital Turbine / FyberRewarded video, interstitialGDPR compliant; supports CCPA opt-out
CriteoCriteo SARetargeting on web companion propertiesHonours IAB TCF v2.2 & CCPA opt-out
TaboolaTaboola.com Ltd.Native content recommendations (web)GDPR & CCPA compliant
OutbrainOutbrain Inc.Native content recommendations (web)GDPR & CCPA compliant

Each of the above networks has its own privacy notice, opt-out tools and standards commitments. We contractually require them to:

  • Comply with applicable privacy laws (GDPR, CCPA/CPRA, COPPA, PIPEDA, LGPD, PDPA, etc.).
  • Not use L FanfilCA data to build cross-app behavioural profiles for users we have flagged as children.
  • Honour the signals we send (child-directed, non-personalised, Limited Data Use, GDPR consent).
  • Provide opt-out mechanisms for end users.

7.1 Consent management (UMP)

For users in the EEA, the UK and Switzerland we surface the Google User Messaging Platform (UMP) consent form before any personalised advertising or analytics is loaded. You can change your choices at any time from Settings → Privacy → Ad choices inside each app.

7.2 California Limited Data Use

For users in California we honour the "Limited Data Use" signal. We do not allow the networks listed above to use your data for cross-context behavioural advertising unless you opt in.

8. Ad formats we serve

The L FanfilCA Apps may show any combination of the following ad formats, depending on the title and your region:

  • Banner ads — small rectangular ads that sit at the top or bottom of a screen. These are static or animated and refresh at intervals.
  • Interstitial ads — full-screen ads shown at natural transition points (for example between levels). They are skippable after 5 seconds.
  • Rewarded video ads — opt-in videos the user watches in exchange for an in-app reward (extra life, bonus currency, hint). These are never auto-played.
  • Open screen / app-open ads — full-screen ads shown when the app is cold-launched or resumed from the background. Frequency-capped to avoid fatigue.
  • Native ads — ads that match the visual style of the surrounding content. Always labelled "Ad" or "Sponsored".
  • Offerwall ads (in some titles) — opt-in lists of partner offers that reward the user for completing tasks. Not used in child-directed titles.

We never auto-play audio. We respect the system "Limit Ad Tracking" / "Opt out of Ads Personalisation" signal. We do not serve ads to users we have identified as children (see section 9).

9. Children & age

L FanfilCA cares deeply about children. We do not direct any of our apps to children under 13 (or higher where local law requires, such as under 14 in Korea, under 16 in certain EU member states and under 18 in the UK ICO children's code).

  • We do not knowingly collect personal data from children under the age limits above.
  • For apps in the Google Play Designed for Families programme or the Apple Kids category we configure the ad SDKs to call only child-directed treatment APIs and to disable interest-based advertising, remarketing and personalised ads.
  • We use a neutral age gate and, where required, a verifiable parental consent flow (e.g. via Google Families parental consent).
  • Parents can request review or deletion of any information collected from their child by contacting privacy@lfanfilca.com.
  • We comply with COPPA (US), GDPR-K (EU/UK), Article 8 GDPR, the UK Age-Appropriate Design Code, the California SB-1424 / AADC, the India DPDP Rules 2025 for children, the Australia OAIC Children's Privacy Code and the Brazil LGPD child provisions.

10. App store policies

10.1 Google Play

All of our Android apps comply with the Google Play Developer Policy, the Google Play Families Policy (where applicable), the Google Play User Data Policy, the Google Play Store Listing and Promotion Policy, the Targeting API requirements and the Device and Network Abuse Policy. We honour the "Data safety" form on every store listing and keep it up to date with the actual data practices in the binary.

10.2 Apple App Store

All of our iOS, iPadOS and tvOS apps comply with the Apple App Store Review Guidelines (notably Guidelines 1 (Safety), 2 (Performance), 5 (Privacy) and the Kids Category rules), the Apple Developer Program License Agreement, App Tracking Transparency (ATT) (we display the ATT prompt where required and only access the IDFA after explicit consent), the Privacy Manifest requirement (we publish a Privacy Manifest describing all Required Reason APIs we call) and the App Store Connect privacy labels.

10.3 Other stores

Where we publish on alternative stores (Amazon Appstore, Samsung Galaxy Store, Huawei AppGallery, Aptoide, GetJar, F-Droid for open-source titles), we additionally comply with the privacy and developer agreements of those stores.

11. Country & region policies

In addition to the app store rules above, we comply with the following regional and country-level privacy laws. Where multiple laws apply to you, we apply the most protective standard.

RegionLaw(s)What it means for you
European Union / EEAGDPR, ePrivacy Directive, national implementationsRight of access, rectification, erasure, restriction, portability, objection; UMP consent; 30-day response window; DPO contactable
United KingdomUK GDPR, Data Protection Act 2018, Age-Appropriate Design Code, PECRSame GDPR rights as above; ICO complaints; children's code applies to apps likely to be accessed by children
United States — CaliforniaCCPA / CPRA, SB-1424, CalOPPA, SHINE Act (2025)Right to know, delete, correct, opt out of sale/share, limit use of sensitive PI; honour LDU signal; do not sell under 16 without opt-in
United States — other statesVirginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MDPA, Tennessee TIPA, Delaware DPDPA, Iowa, Indiana, Kentucky, Maryland, Minnesota, New Hampshire, New Jersey, Rhode IslandSimilar rights; we honour universal opt-out signals (GPC) globally
United States — federalCOPPA, FTC Act Section 5, GLBA (where relevant)Verifiable parental consent for under 13; no deceptive practices
CanadaPIPEDA, Quebec Law 25, Alberta PIPA, BC PIPAExpress consent for sensitive data; right to challenge compliance; privacy officer contactable
BrazilLGPDConfirmation, access, correction, anonymisation, portability, deletion; ANPD complaints
MexicoLFPDPPP, Federal Telecommunications LawARCO rights (access, rectification, cancellation, opposition); privacy notice in Spanish for in-app overlays
ArgentinaPersonal Data Protection Law 25.326Derecho de acceso, rectificación, supresión, oposición
ChileLaw 19.628 (as reformed)Consent-based; right to deletion
ColombiaStatute 1581/2012, Decree 1377/2013Authorization regime; habeas data rights
PeruLaw 29733Consent; data subject rights
JapanAPPIUse within purpose, opt-in for sensitive data, right to erasure
South KoreaPIPA, K-MyData, NIA guidelinesConsent for cross-border transfers; separate consent for sensitive data; users under 14 require guardian consent
China (mainland)PIPL, DSL, CSLSeparate consent for sensitive data and cross-border transfers; security assessment for large transfers; localisation where required
Hong KongPDPOPersonal Data (Privacy) Ordinance; PCPD complaints
TaiwanPDPACollection notice, opt-in for sensitive data, right to access/correct/delete
SingaporePDPA, MAS TRM (for finance), NRC (for minors)Consent or deemed consent; Do-Not-Call registry respected; DPO contactable
MalaysiaPDPA 2010Registration with JPDP where required; data subject rights
ThailandPDPA (B.E. 2562)Consent regime; cross-border restrictions; minor protections
PhilippinesData Privacy Act 2012, NPC CircularsConsent; right to file complaint with NPC
VietnamPDPD 2023 (effective from 1 July 2023)Consent; cross-border transfer impact assessment; data subject rights
IndonesiaUU PDP, Government Regulation 71/2019Explicit consent; cross-border restrictions; minor protections
IndiaDPDP Act 2023 + DPDP Rules 2025Verifiable consent; Data Protection Board; children's data (under 18) requires guardian consent; data principals' rights
AustraliaPrivacy Act 1988, OAIC Children's Code 2025, Notifiable Data Breaches schemeAPP; data breach notification within 30 days; children's code applies to services likely to be accessed by children
New ZealandPrivacy Act 2020IPP; cross-border transfer rules; OPC complaints
United Arab EmiratesPDPL (Federal Decree-Law 45/2021)Consent; cross-border restrictions; DPO appointment
Saudi ArabiaPDPL (2021), NDMO regulationsConsent; cross-border; localisation for certain data
IsraelPrivacy Protection Law 5741-1981, Amendment 13/2024Database registration; data subject rights; children protections
TurkeyKVKK, cross-border rulesExplicit consent; data subject rights; KVKK board complaints
South AfricaPOPIALawful processing; information officer; data subject rights
NigeriaNDPR, NDPR Implementation FrameworkConsent; data subject rights; filing with NITDA
KenyaData Protection Act 2019Consent; data subject rights; ODPC complaints
EgyptPDPL No. 151/2020Consent; data subject rights; PCSC complaints
RussiaFederal Law 152-FZ, Roskomnadzur rulesLocalisation; consent; cross-border restrictions
SwitzerlandnDSG / revFADPGDPR-equivalent; FDPIC complaints
Norway, Iceland, LiechtensteinEEA GDPR extensionsSame as EU; respective DPA complaints

If a law in your jurisdiction requires a higher standard than what is described here, that higher standard prevails.

12. Sharing & processors

We share data only with vetted processors who act on our instructions under a written data processing agreement:

  • Cloud hosting and storage (encrypted at rest, TLS 1.2+ in transit)
  • Authentication and account infrastructure
  • Crash and performance monitoring (with PII minimised)
  • Customer support tooling
  • Email and transactional messaging providers
  • Payment processors (Apple, Google) — for purchase receipts only; we never see your card number
  • Advertising networks and mediation (listed in section 7)
  • Analytics — only with explicit consent and only using anonymised or pseudonymous IDs
  • Law enforcement, courts or regulators when compelled by valid legal process

We do not sell personal data, and we do not share it for cross-context behavioural advertising unless you have given us informed opt-in consent (or it is permitted under applicable law).

13. International transfers

Some of our processors are located outside your country. Where required, we rely on the following transfer mechanisms:

  • EU Standard Contractual Clauses (SCCs) — for transfers from the EEA, UK and Switzerland to third countries.
  • UK International Data Transfer Agreement (IDTA) and the UK Addendum — for transfers from the UK.
  • EU–US Data Privacy Framework (DPF) and the UK Extension — where the recipient is DPF-certified.
  • Swiss–US Data Privacy Framework — for transfers from Switzerland.
  • Binding Corporate Rules — where applicable.
  • Explicit consent — for occasional one-off transfers, with full information about the destination and the risks.

For transfers from mainland China, Hong Kong, Taiwan, Korea, Indonesia, Vietnam, Russia, UAE, Saudi Arabia and other jurisdictions with localisation rules, we either use a local data centre or implement an approved cross-border transfer mechanism (security assessment, standard contract, certification, etc.).

14. Retention

We keep personal data only as long as necessary for the purposes described in this policy, or as required by law. Concretely:

  • Account data — for the life of the account, plus 30 days after deletion (for grace period), then permanently deleted from primary systems and backups within 90 days.
  • Crashes and diagnostics — 90 days.
  • Support tickets — 3 years.
  • Server logs — 30 days.
  • Purchase receipts — 10 years (tax law).
  • Backups you have opted into (Mobile Management) — until you delete them or your account.

15. Security

We use industry-standard technical and organisational measures to protect your data, including:

  • TLS 1.2+ for all data in transit.
  • AES-256 encryption for data at rest.
  • End-to-end encryption for backups inside the L FanfilCA Mobile Management Suite, where the key is derived from your password and is never sent to our servers.
  • Regular third-party penetration testing of the L FanfilCA Apps and infrastructure.
  • Role-based access control, hardware MFA, and just-in-time access for production systems.
  • Vendor risk reviews before engaging new subprocessors.
  • An internal incident response plan with breach notification in line with GDPR (72 hours), CCPA, the EU NIS2 Directive, US state breach laws, and other applicable rules.

No system is perfectly secure. If we ever become aware of a security incident affecting your data, we will notify you in line with applicable law.

16. Your rights

Depending on where you live, you may have some or all of the following rights. We extend these rights globally wherever feasible:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure / deletion — ask us to delete your data.
  • Restriction — ask us to suspend processing of your data.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interest or for direct marketing.
  • Opt out of sale or sharing — we do not sell, but you can still opt out of any sharing for cross-context advertising.
  • Limit use of sensitive personal information — under CCPA / CPRA.
  • Withdraw consent — at any time, where processing is based on consent.
  • Non-discrimination — we will not penalise you for exercising your rights.
  • Lodge a complaint with your local data protection authority.

To exercise any right, email privacy@lfanfilca.com. We will respond within 30 days (15 days for some US state laws, 7 days for some Indian requests under DPDP). For your security we may need to verify your identity before acting on the request.

17. Account & data deletion

You can delete your L FanfilCA account and all associated data in two ways:

  1. Inside any L FanfilCA App: Settings → Privacy → Delete account. You will receive an email confirmation link and the deletion will complete within 30 days.
  2. By emailing privacy@lfanfilca.com from the email address associated with your account.

After deletion we will erase your data from primary systems and from backups within 90 days, except where we are required to retain certain records (e.g. tax invoices) for legal reasons.

18. Changes to this policy

We may update this policy from time to time. When we do, we will bump the "Last updated" date, post a notice in our apps, and — if the changes are material — send you an email and ask for fresh consent where required. Previous versions are available on request.

19. Contact us

If you have any questions about this policy or how we handle your data, please contact us:

  • By email: privacy@lfanfilca.com
  • For business: spencerk@ho-weicar.pics
  • By post: L FanfilCA Studio — Data Protection Team, see our registered address at contact.

If you are unhappy with our response, you have the right to lodge a complaint with your local data protection authority.

Thank you for trusting L FanfilCA. We take that trust seriously — and we will keep earning it. 🐼🦊🐰

L FanfilCA

A mobile-first studio publishing joyful casual games, everyday utility apps and a mobile management suite for users worldwide.

Studio

  • Home
  • Services
  • Contact

Products

  • Casual games
  • Daily tools
  • Mobile management

Stores

  • Google Play
  • App Store
  • Press & partnerships
© 2026 L FanfilCA Studio. All rights reserved. Made with care for users around the world 🌍
Privacy Policy Terms of Service Contact