Our Commitment to Privacy
Kop Wheel is intentionally designed to collect as little user data as possible. The application is offline-first and stores all wheel configurations, spin results, preferences and history locally on your device. When you purchase the optional Pro upgrade, we use the minimum necessary information retention practices permitted under Apple App Store, Google Play and global data protection laws (GDPR, CCPA, COPPA).
Design principle: Information that never leaves your device belongs to you. We operate a privacy-by-default model: any collection is documented, lawful and limited strictly to enable Pro features, transactional obligations and customer support.
1. What We Do Not Collect
- No UsUCdata / No Advertising IDs: Kop Wheel contains no third-party advertisement SDKs, analytics advertising trackers, or App Tracking Transparency framework-linked identifiers. Marketing campaigns appear only within the App itself; no cross-app tracking occurs.
- No Wheel Content: The names, items, colors, labels, photos, audio prompts, or spin results you create are never transmitted to our servers or third parties.
- No Device Fingerprinting: We do not collect IMEI, MAC addresses, Bluetooth identifiers, carrier details or unique hardware serial numbers.
- No Contact / Address Book: The app does not request access to your contacts, calendar, camera, microphone, photo library or precise location.
- No Payment Card Data: We do not see, hold or store your credit card number, CVV or bank information. Payments are processed securely by Apple and Google Payment Service providers.
2. What We Collect & How We Use It
Collection is limited to what is technically necessary to validate, maintain and sensibly enforce non-consumable and subscription purchases while operating a reliable support channel.
Anonymous Account ID
We create a pseudonymous, random UUID when the Pro purchase sync feature is enabled. This identifier links purchases to an abstract in-app identity rather than a real person. It never exposes your email, phone number or real-world name.
- Anonymous Account ID (Auto-generated): A v4 UUID used by our Supabase backend strictly to reconcile your Pro subscription or lifetime purchase across your devices. This value is hashed (HMAC-SHA-256) before being associated with Google Play `obfuscatedAccountId`.
- Purchase Transaction Metadata: Product ID (e.g. `pro_lifetime`), order ID, timestamp, entitlement status (e.g. active, expired, refunded) used to verify and restore purchase entitlements, respond to chargeback disputes and provide you with license receipts.
- Purchase Token (encrypted at rest): Used only for server-to-server receipt validation with Apple App Store / Google Play. We store an encrypted copy (AES-GCM) and expose only anonymized fingerprints for diagnostics. No token is used for advertising or event correlation.
- Technical Event Logs (anonymized): We record aggregated, de-identified events such as "purchase_verified", "entitlement_restored", "sync_failed" for reliability monitoring and service availability. These do not contain names, spin results or nearby people.
3. Legal Basis for Processing (GDPR)
- Contractual Necessity: To fulfill your license and restore purchases directly preventing payment disputes.
- Legal Obligation: Commercial records retention (receipts), tax reporting and responding to valid law enforcement requests.
- Legitimate Interest: Maintaining service integrity, preventing fraud and enabling secure customer support for purchase issues.
4. Data Sharing & Transfers
We do not sell user data. We share only with verified sub-processors strictly to provide purchase processing, under Data Processing Agreements (DPAs) mandated by GDPR/CCPA:
- Apple Inc. / Google LLC — App Store / Google Play payment processing, license verification and regulatory compliance. Governed by Apple Media Services Terms and Google Play Terms.
- Supabase Inc. — Backend-as-a-Service infrastructure (PostgreSQL, Edge Functions, JSON Web Tokens) for anonymized purchase entitlement storage. Located in secure regions you control via project settings in accordance with Supabase Privacy Policy.
5. Data Security & Storage
- Offline-first: Default storage happens exclusively via Apple SharedPreferences / Android Keystore / iOS Keychain on-device encryption at rest.
- Transport Security: All transmission occurs over TLS v1.2+ with certificate pinning between the mobile client and your chosen App Store or Supabase endpoints.
- Access Control: Internal access follows Role-Based Access Control (RBAC). No support team inherits real user identifiable information; only anonymized account IDs and order IDs.
- Retention: Active subscription, purchase and audit logs are retained until you request deletion or pursuant to regulatory limitation periods required for commercial tax records. Delete requests are technically completed within 30 days and legal obligations only when mandatory.
6. International Data Subject Rights
Depending on your jurisdiction, you may have statutory rights regarding your personal data. To make a privacy-related request, please contact:
- Right to Access: Receive a copy of anonymized transaction records associated with your Anonymous ID.
- Right to Deletion / Erasure: Delete your Anonymous ID, Pro licenses and synced purchase bindings. Note: deleting your ID does not stop you from spinning wheels; local wheel data will remain on your device until manually removed by you.
- Right to Object: Opt-out of future anonymized analytics processing if you wish. This will not delete your local wheel content from your device because we do not acquire it.
To assert any of these rights, email:[email protected]. We will respond within 30 days as required by GDPR.
7. Children's Privacy (COPPA Compliance)
Kop Wheel is widely used in classrooms. We expressly do not require accounts or collect personal information from minors as understood in the US Children's Online Privacy Protection Act (13 U.S.C. §§ 6501 et seq.). Teachers may enter student names into wheels locally; under no circumstances are these transmitted. For parents or educators concerned about rotation labels, only procedural, non-identifying "handle" or "list title" strings remain in the local filesystem.
8. Age Ratings & Regional Compliance
- United States (CCPA): No personal information sharing for behavioral advertising purposes. We treat purchase transaction records strictly as contracted-service data per California Consumer Privacy Act regulations.
- European Union (GDPR): Processed based on contractual necessity (purchase activation) and legitimate interest (fraud prevention). No profiling or automated decision making on individual behavior occurs.
- United Kingdom (UK GDPR): Managed through App Store's UK-based operation or via standard contractual clauses alongside our independent controller responsibilities.
- 其他地区: 颜色绘侧边栏提交的应用均可使用,但条款基于美国法律解释。你去联系邮箱可引起额外地区主管机关认证请求。
9. App Store Family Sharing
Pro purchases support Apple Family Sharing natively. When one family member purchases a Lifetime or Yearly plan, all approved family members gain access to Pro features under the same Family Sharing group, sharing the same privacy guarantees described above.
10. Changes to This Policy
Material changes will be prominently announced on this webpage, within the App in the paywall sheet, and optionally embedded in your next release notes. For significant shifts that broaden data collection beyond anonymized purchase handling, we will request new consent before activation.
11. Contact Us
If you have questions, concerns or requests regarding this Privacy Policy, your anonymous purchases or entitlements:
Privacy Email: [email protected]
Subject Line Suggestion: "Privacy Inquiry — Kop Wheel [Apple App Store ID]"
Response Timeline: 30 days maximum. Most simple restoration or token queries receive a solution within 3-5 business days.