Privacy Policy & User Service Agreement

Global Compliance Edition · Last updated: September 18, 2026 · Effective immediately

Privacy & security illustration

Table of Contents

  1. Preamble
  2. Part I — Privacy Policy
  3. 1. General Provisions
  4. 2. Scope & Methods of Collection
  5. 3. Purpose of Use
  6. 4. Storage & Security
  7. 5. Transfer & Disclosure
  8. 6. Regional Adaptations
  9. 7. Age Policy
  10. 8. User Rights
  11. 9. Updates & Notices
  12. 10. Disclaimers
  13. Part II — User Service Agreement
  14. 11. Service Overview
  15. 12. Rights & Obligations
  16. 13. IAA + IAP Terms
  17. 14. Suspension & Termination
  18. 15. IP, Disputes, Misc.

Preamble

This document is entered into between Dufengxun Studio ("we," "us," or the "Studio"), a professional mobile application research & development entity, and you ("user" or "you"). It governs your download, installation, and use of every mobile application published by us globally (collectively, the "Apps").

Our Apps are distributed through the Apple App Store, Google Play, and other compliant distribution channels. We monetize through a dual model of IAA (In-App Advertising) and IAP (In-App Purchase), fully compliant with the privacy laws of every country and region we serve, the age-related norms for minors, data security regulations, and the policies of every distribution platform and monetization partner.

This document is composed of two parts — the Privacy Policy and the User Service Agreement — which are integrated, inseparable, and equally binding. By using any of our Apps, you confirm that you have read, fully understood, and voluntarily agreed to every term herein.

Important: All consent dialogs, policy pop-ups, and authorization prompts in our Apps are presented with default-unchecked options. We will only proceed with data collection and service provision after you actively click to confirm — fully protecting your right to informed consent.

Part I — Privacy Policy (Global Compliance Edition)

1. General Provisions

1.1 Purpose & Scope

This Privacy Policy is designed to clearly inform you of the specific scope, methods, and core purposes for which we collect, use, store, transmit, and disclose your personal information. We strictly adhere to the principles of "legality, legitimacy, necessity, and good faith."

We fully comply with the Personal Information Protection Law of the People's Republic of China (PIPL), the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA), the Brazilian General Data Protection Law (LGPD), and all equivalent privacy laws of every country and region in which our Apps operate. Our practices also satisfy the privacy review standards of the App Store, Google Play, and every monetization platform we work with, and we implement the requirements of GB/T 35273-2020 — Information Security Technology — Personal Information Security Specification.

We do not collect any personal information that is unrelated to the functions of our Apps, nor do we abuse or disclose your information.

1.2 Global Application & Regional Adaptation

This Privacy Policy applies to all users of our Apps worldwide. We have explicitly included region-specific adaptation clauses within this document to ensure compliant operation in every jurisdiction. Where your country or region has stricter privacy requirements, those local laws and the requirements of the relevant distribution platform shall prevail.

1.3 Your Rights

You have the legal right to inquire, correct, and delete your personal information; to withdraw your consent to its collection and use; and to request anonymization. We will provide a clear, convenient path for you to exercise these rights, and we fully protect your right to informed consent at every step.

2. Scope & Methods of Personal Information Collection

2.1 Core Necessary Information

The following information is mandatory to provide the core functionality of our Apps. If you refuse to provide it, the corresponding features will not work.

  • Device Information — device model, OS version, device identifiers (IMEI, IDFA, IDFV, Android ID, OAID — all anonymized), device MAC address, screen resolution, network type (Wi-Fi / cellular). Used for app compatibility, core feature delivery, troubleshooting, and security protection. We follow the minimum-necessary principle required by the App Store and Google Play and do not collect device information beyond functional needs.
  • App Usage Information — which feature modules you use, usage duration, operation records, and feature preferences. Used to optimize app features, improve user experience, deliver personalized recommendations (which you can disable at any time), and compile aggregate monetization statistics.

2.2 Optional Information

Collected only when you actively choose to provide it. Refusing to provide it does not affect any core feature.

  • Personal Identity Information — name, email address, phone number. Used solely for account registration, password recovery, in-app purchase (IAP) verification, and customer service. You may use our Apps anonymously without providing any of this information.
  • Location Information — used only for specific contextual features. Collection requires your manual authorization, and you can withdraw that authorization at any time through your device's system settings.
  • Photo Library / File Access — used only for content saving and uploading. Access requires your manual authorization, and you can withdraw it at any time.

2.3 Third-Party Collection (Ad Networks & Distribution Platforms)

Because our Apps monetize through the IAA model, they integrate globally compliant third-party ad mediation and exchange platforms. These networks may collect your device information, app usage information, and ad-viewing / click records in order to deliver relevant advertising. Their data-collection behavior strictly follows each network's own privacy policy and the laws of the jurisdictions in which they operate.

Our Apps currently integrate the following ad SDKs and platforms (this list is reviewed quarterly):

  • Google AdMob / Google Ad Manager — banner, interstitial, rewarded video, native, app-open, MREC
  • Meta Audience Network (Facebook) — banner, interstitial, rewarded video, native
  • Unity Ads (Unity LevelPlay / ironSource mediation) — banner, interstitial, rewarded video
  • AppLovin MAX / AppLovin Exchange — banner, interstitial, rewarded video, MREC
  • Pangle (by ByteDance) — banner, interstitial, rewarded video, splash
  • Mintegral — interstitial, rewarded video, native
  • Chartboost — interstitial, rewarded video
  • Vungle (by Liftoff) — interstitial, rewarded video
  • AdColony (by Digital Turbine) — interstitial, rewarded video
  • Tapjoy — offerwall, rewarded video
  • InMobi — banner, interstitial, native, rewarded video
  • Smaato — banner, interstitial, native, video
  • Verizon Media / Yahoo Native — native, video
  • Start.io (Startapp) — interstitial, rewarded video
  • Digital Turbine (Fyber) — interstitial, rewarded video
  • Moloco — programmatic bidding, native
  • Liftoff (Vungle) — interstitial, rewarded video
  • Apple Search Ads / iAd attribution — search ads, attribution

Each SDK is integrated with the corresponding consent flags, ATT prompt, and Privacy Sandbox APIs. We strictly constrain the data-collection scope of every third-party network, define the compliance boundaries of their data processing, and prohibit them from collecting personal information unrelated to ad delivery.

For the IAP monetization mode, the Apple App Store and Google Play handle the collection of your payment information (such as payment account and transaction records). We do not directly obtain your payment-sensitive information; we only receive transaction-success verification, which is used solely to complete the in-app purchase service. This ensures the security of your payment information.

2.4 Collection Methods

All personal information is collected either through your active authorization, manual operation (e.g., registration, upload, sign-in), or automatic collection by the App for necessary information only. We never collect personal information through hidden, fraudulent, or coercive means. Before collection, we will clearly inform you of the purpose, scope, method of use, and retention period, and we will only proceed once we have obtained your explicit consent. We strictly implement the informed-consent review requirements of the Personal Information Protection Compliance Audit Management Measures and GB/T 35273-2020 — we never use default-checked or forced-consent patterns.

3. Purposes & Scope of Use

3.1 Core Functional Use

To provide you with the complete functional services of our Apps, ensure stable operation, troubleshoot faults in a timely manner, and continuously optimize features. We meet your needs in daily use, efficiency improvement, and similar scenarios, and we do not use personal information for any purpose unrelated to the App's functions.

3.2 Monetization-Related Use

For IAA, to deliver advertising (only ads matching your interests — which you can disable at any time in the App's settings), and to compile ad-performance statistics. For IAP, to verify in-app purchases, query transaction records, and manage orders. We ensure the monetization process is compliant and transparent, fully aligned with Apple's App Tracking Transparency (ATT) Framework and Android's Privacy Sandbox requirements, and we do not use personal information for any non-compliant monetization activity.

3.3 Optimization & Security Use

To analyze App usage data, optimize interface layout and operational flow, and improve user experience. For security, to identify abnormal logins, malicious operations, fraud, and cheating, protecting your account and personal information and maintaining the stability of our App ecosystem.

3.4 Compliance & Audit Use

In accordance with the laws and regulations of every country and region, as well as the requirements of distribution platforms and monetization partners, to retain relevant personal information, cooperate with compliance audits and regulator inspections, implement the requirements of the Personal Information Protection Compliance Audit System, and proactively accept regulatory supervision.

3.5 Prohibited Use

We never sell, rent, or lend your personal information to any third party (other than compliant monetization platforms, distribution platforms, and regulators required by law). We never use personal information for purposes unrelated to App functionality or monetization needs. We never use personal information to conduct illegal or non-compliant activities, nor do we leak, alter, or misuse it.

4. Storage & Data Security

4.1 Storage Location

We follow the principle of "local storage first, cloud backup optional." By default, your personal information is stored locally on your device. If you choose to enable the cloud-backup feature, the relevant information will be stored on our compliant cloud servers, distributed across globally compliant data centers that meet GDPR's data-storage regional requirements — EU users' data is stored exclusively on servers located within the European Union.

4.2 Retention Period

We retain your personal information only for the period reasonably necessary to achieve the purposes of this Policy. After that period expires, your personal information will be automatically anonymized or permanently deleted. You may manually delete your personal information at any time; once deleted, it cannot be recovered. If you cancel your account, we will permanently delete all of your personal information within 15 business days (except where retention is required by law).

4.3 Data Security Safeguards

We employ security technologies that meet global industry standards, including but not limited to AES-256 encryption at rest, HTTPS / TLS 1.3 encryption in transit, access-control management, and security auditing. We have obtained ISO 27001 (Information Security Management System) and ISO 27701 (Privacy Information Management System) certifications, ensuring the reliability of our data-security governance.

4.4 Data-Breach Handling

In the event of a personal-information breach, we will immediately activate our emergency-response mechanism. In accordance with GDPR requirements, we will notify affected users and relevant regulatory authorities within 72 hours, provide a detailed explanation of the cause, remedial actions, and subsequent prevention plan, and actively cooperate with regulatory investigations.

5. Transfer & Disclosure of Personal Information

5.1 Transfer Scope

Personal information is transferred only between our Apps, compliant cloud servers, third-party monetization platforms, and distribution platforms — only to the extent necessary. All transfers are fully encrypted end-to-end.

5.2 Disclosure Scenarios

We disclose personal information only in the following lawful scenarios:

  • With your explicit consent — to a third party (e.g., third-party login or content share).
  • To compliant monetization and distribution platforms — only the minimum information required (anonymized device data, transaction-verification information).
  • To comply with laws, judicial authorities, or administrative regulators — every disclosure follows statutory procedure, and we retain complete disclosure records.
  • To protect your legitimate rights or prevent malicious behavior — within a reasonable and necessary scope.

5.3 Cross-Border Transfer

Where cross-border transfer of personal information is involved, we strictly follow the cross-border data-transfer policies of every country and region (such as GDPR's adequacy decisions, China's Provisions on Promoting and Regulating the Cross-Border Flow of Data). We clearly identify which transfers are exempt from filing and which require filing.

6. Regional Privacy Policy Adaptations

6.1 European Union (GDPR Adaptation)

We explicitly safeguard users' rights to information, access, rectification, erasure, withdrawal of consent, and data portability. We have appointed a Data Protection Officer (DPO) and established a complete 72-hour data-breach notification mechanism. All EU users' data is stored on servers located within the European Union. We do not transfer personal information to countries or regions without GDPR adequacy decisions.

6.2 United States (CCPA / CPRA Adaptation)

Users have the right to require us to disclose the scope of personal information we collect and use, to require deletion, and to refuse the use of personal information for targeted advertising. We strictly follow COPPA requirements and do not collect or use personal information of children under 13. We provide California users with an explicit "Do Not Sell My Personal Information" option.

6.3 China (PIPL, Cross-Border Data Provisions, GB/T 35273 Adaptation)

We strictly follow the principles of "legality, legitimacy, necessity, and good faith." Collecting personal information requires the user's explicit consent. We do not collect personal information unrelated to App functionality. We implement the Personal Information Protection Compliance Audit System — for processors handling the personal information of more than 10 million individuals, we conduct a compliance audit at least once every two years.

6.4 Brazil (LGPD Adaptation)

Collecting personal information requires the user's explicit authorization, and we safeguard users' rights to inquire, correct, and delete personal information. Without completing the local data filing, we do not commence related business operations.

6.5 Southeast Asia (Local Policy Adaptation)

We adapt to Thailand's ETDA filing requirements and Singapore's MAS-related regulations, completing local-operator filings and data-compliance filings.

6.6 Other Countries & Regions

We fully adapt to the privacy laws and regulations of every other country and region, ensure our personal-information processing is compliant, and — where local laws impose stricter privacy requirements — give precedence to those local laws.

7. Age Policy (Global Baseline + Regional Supplement)

7.1 Global Age Requirements

  • Under 13: We are prohibited from providing service to children under 13 (in adaptation to COPPA, GDPR, and global norms). If we discover a child under 13 using our Apps, we will immediately terminate service and permanently delete their personal information.
  • Ages 13–18: Use of our Apps by minors between 13 and 18 must be conducted with the consent of their legal guardian. The guardian has the right to inquire, correct, and delete the minor's personal information, and to require us to terminate the minor's use of our Apps.
  • Content & Ads: All App content and advertising is strictly adapted to the requirements of minor protection — no violent, pornographic, vulgar, or illegal content, and no advertising unsuitable for minors. We have established a dual AI + human review mechanism to ensure content compliance.

7.2 Regional Supplement

We adapt to the age definition and protection requirements of minors in different countries and regions (some countries define minors as those under 16), defer to local laws, strictly implement local minor-privacy protection policies, and proactively accept supervision by local regulators.

8. User Privacy Rights & Operational Paths

8.1 User Rights

You have the legal rights to information, access, rectification, erasure, withdrawal of consent, data portability, and complaint / report.

8.2 Operational Paths

  • Inquire / Rectify / Erase: Open the App → "Me" → "Privacy Settings" → "Personal Information Management".
  • Withdraw Authorization: Open the App → "Me" → "Privacy Settings" → "Permission Management", or via your device's system settings.
  • Cancel Account: Open the App → "Me" → "Account Settings" → "Cancel Account". We will permanently delete your personal information within 15 business days.
  • Complaint / Report: Open the App → "Me" → "Customer Service" → "Privacy Complaint". We will respond within 3 business days and provide a definitive resolution within 7 business days.

9. Updates & Notices to This Privacy Policy

9.1

We will periodically update this Privacy Policy in line with updates to global laws and regulations, the policies of distribution and monetization platforms, optimizations to App features, and changes in regulatory requirements. Updated policy content will more closely align with compliance requirements, will not reduce our privacy-protection responsibilities, and will not lower the standard of protection we afford users.

9.2

After an update, we will clearly inform you of the changes through in-App pop-ups, push notifications, and in-App announcements. You may choose to review the updated policy at your discretion. Your continued use of our Apps indicates your agreement with the updated Privacy Policy. If you do not agree, you may uninstall the App and terminate use of our services; we will immediately stop collecting and using your personal information and delete the relevant data (except where retention is required by law).

10. Disclaimers

10.1 Force Majeure

We are not liable for personal-information leakage, loss, or alteration caused by force majeure (such as earthquakes, floods, typhoons, network outages, server failures, or other unforeseeable and unavoidable events), but we will make every effort to take remedial measures to reduce loss, promptly notify users, and cooperate with related handling.

10.2 User-Side Causes

Leakage, loss, or alteration of personal information caused by your own improper operation (such as leaking account credentials, authorizing untrusted third parties, or losing a device) is your own responsibility. We remind you to safeguard your personal information and device security.

10.3 Third-Party Liability

Where a third-party monetization platform, distribution platform, or cloud-service provider violates applicable rules by independently collecting, using, or disclosing your personal information, that third party bears full responsibility. We will actively assist you in pursuing that third party's liability, while strengthening our oversight of third parties and conducting regular compliance reviews.

10.4 Legal Disclosure

Where we disclose your personal information in accordance with the requirements of laws, judicial authorities, or administrative regulators, we are not liable for such disclosure. The disclosure strictly follows statutory procedure, and complete records are retained.

10.5 Voluntary Provision

Your voluntary provision of personal information is deemed your consent to our processing of that information in accordance with this Privacy Policy. Losses resulting from the provision of inaccurate or incomplete personal information are your own responsibility.

Part II — User Service Agreement (Global Compliance Edition)

11. Service Overview

11.1

This User Service Agreement is the legal agreement between you and us regarding your use of the Apps and related services (collectively, the "Services") we develop. It applies to all users of our Services worldwide, and adapts simultaneously to the terms of the App Store, Google Play, and other distribution platforms, the relevant rules of every monetization platform, and the laws and regulations of every country and region.

11.2

By downloading, installing, or using our Apps, you confirm that you have read, fully understood, and voluntarily agreed to this User Service Agreement, the Privacy Policy, and any other related in-App rules. If you do not agree to any term, please do not download, install, or use our Apps.

11.3

We may update this User Service Agreement in response to changes in global laws, distribution-platform policies, monetization-platform requirements, service-optimization needs, or regulatory changes. After an update, we will inform you through in-App pop-ups, push notifications, and in-App announcements.

12. User Rights & Obligations

12.1 User Rights

  • To use all compliant Services we provide (subject to this Agreement and applicable rules).
  • To submit suggestions and feedback on App features and service quality.
  • To enjoy the privacy protection and security safeguards stipulated in this Agreement.
  • To apply for a refund of in-app purchases (subject to eligibility).
  • To cancel your account, uninstall Apps, and terminate use of our Services at any time.

12.2 User Obligations

  • Strictly observe this User Service Agreement, the Privacy Policy, and all other in-App rules; do not engage in any illegal or non-compliant behavior.
  • Do not maliciously use the Apps. Do not engage in click-fraud, fake-volume activity, dissemination of illegal or non-compliant content, or infringement of others' legitimate rights.
  • Do not alter App code, crack App permissions, bypass security protection or payment restrictions, or use third-party plug-ins or scripts.
  • Safeguard your account and device information; in case of theft or loss, notify us promptly.
  • Provide true and complete personal information (where you choose to provide it).
  • Use of our Apps by minors must be conducted with the consent of their legal guardian.
  • Do not transfer, rent, or lend the Apps or related Services, and do not use them for commercial profit without our written authorization.

13. Monetization Supplementary Terms (IAA + IAP)

13.1 IAA Advertising Terms

Ad Sources: We integrate globally compliant third-party ad networks, including Google AdMob, Meta Audience Network, AppLovin, Unity Ads, Pangle, Mintegral, InMobi, Chartboost, Vungle, AdColony, Tapjoy, Smaato, Verizon Media, Start.io, Digital Turbine, Moloco, Liftoff, and platform-native Apple Search Ads / iAd.

Ad Formats: Banners, interstitials, rewarded videos, native ads, app-open ads, MREC units, splash ads.

Ad Liability: Where ad content is non-compliant, false, or fraudulent, the third-party ad platform and the advertiser bear full responsibility. All ad delivery is adapted to Apple's ATT Framework and Android's Privacy Sandbox.

13.2 IAP In-App Purchase Terms

Purchase Process: In-app purchases are completed through the Apple App Store, Google Play, and other distribution platforms.

Price & Validity: Prices will be clearly displayed in the App. The validity period of paid features will be clearly marked.

Refunds: Refunds are processed in accordance with the official refund policies of the App Store and Google Play. We will actively assist you in submitting refund requests.

14. Suspension & Termination of Service

14.1 Suspension

Due to server maintenance, system upgrades, compliance checks, force majeure, or regulatory requirements, we may temporarily suspend part or all of the Services. We will notify you through in-App pop-ups, push notifications, and in-App announcements in advance.

14.2 Termination

  • You may at any time uninstall the App, cancel your account, and terminate use of our Services.
  • If you violate this Agreement, the Privacy Policy, or applicable laws, we reserve the right to terminate service, delete your account and related information, and not refund any fees you have paid.
  • If we cease operation of an App or terminate Services due to legal or regulatory changes, we will notify you at least 30 days in advance through in-App announcements and push notifications, and properly handle your personal information and unused paid entitlements.

15. Intellectual Property, Dispute Resolution, Miscellaneous

15.1 Intellectual Property

All intellectual property in the Apps and related Services we develop (including but not limited to App code, interface design, logos, written content, and feature algorithms) belongs to us and is protected by the intellectual-property laws of every country and region. Without our written authorization, you may not copy, modify, distribute, transfer, rent, or sell any related intellectual property content.

15.2 Dispute Resolution

The signing, performance, interpretation, and dispute resolution of this Agreement are governed by the laws of the People's Republic of China (excluding conflict-of-laws rules). Where your country or region has stricter legal requirements, those local laws shall prevail. Disputes between you and us should first be resolved through friendly negotiation; if negotiation fails, either party may bring suit before the people's court with jurisdiction at our location.

15.3 Miscellaneous

If any provision of this Agreement is found to be invalid, revocable, or unenforceable, the validity of the remaining provisions shall not be affected. Our failure to exercise or delay in exercising any right under this Agreement shall not constitute a waiver of that right.

Any notice or communication between you and us may be made through in-App announcements, push notifications, or customer-service channels. Notices shall be deemed delivered as of the date of sending.

This Agreement takes effect on the date you download, install, or use our Apps. It terminates automatically upon termination of use and account cancellation (but the Privacy Policy's provisions on information retention and disclaimers shall continue in effect).

15.4 Contact

If you have any questions, feedback, or complaints, please contact us through the following channels:

  • Customer Service Email: contact@dufengxun.com
  • Address: Hoa Lac Hi-Tech Park, Hanoi, Vietnam

End of Document — Privacy Policy & User Service Agreement (Global Compliance Edition)

This document is also accessible as a separate User Service Agreement.

View Terms of Service →