Privacy Policy
This Privacy Policy explains how Quiz Flux collects, uses, shares, and protects information when you use the Quiz Flux mobile application and related services.
1. Information We Collect
Depending on how you use Quiz Flux, we may collect the following information:
- Account information: user ID, email address, display name, username, authentication provider information, and profile photo URL when provided through email sign-in, Google Sign-In, Apple Sign-In, or your account settings.
- Sign-in provider contact data: the privacy disclosure bundled with our Google Sign-In SDK also declares phone-number processing for app functionality. This is a provider disclosure; Quiz Flux does not ask you to enter a phone number, request an additional phone-data permission from Google, or access your device address book.
- Game progress and profile data: XP, total points, level, streaks, completed categories, rewards, jokers, achievements, selected profile frame, username change count, and related gameplay state.
- Leaderboard and score data: quiz scores, category IDs, daily/weekly/monthly leaderboard bucket keys, ranking-related information, timestamps, username, profile picture URL, selected frame, and streak days shown in leaderboard surfaces.
- Social features: friend lists, friend requests, blocked user IDs, reports, and activity feed events such as perfect scores, level-ups, achievement unlocks, streak milestones, and leaderboard podium events.
- Profile images and moderation: images you choose or import from your sign-in provider. Our moderated image flow also processes a private pending copy, the approved public rendition, and the moderation result needed to process that choice. Images may be decoded, resized, and re-encoded to remove embedded metadata before automated safety checks. Older Android photo flows remain in use during the compatibility transition described below.
- Diagnostics, analytics, and usage events: app events such as quiz start, quiz completion, joker use, ad reward events, and similar interactions used to understand app performance and improve gameplay. While you are signed in, Analytics events and Crashlytics reports can be associated with your account ID and gameplay properties. Advertising consent does not itself switch off these separate analytics and diagnostic services.
- Advertising data: information processed by Google AdMob and its partners to load, measure, limit, and reward ads. This may include device identifiers, approximate location, ad interactions, and other data described by Google and its partners.
- Device and technical information: device type, operating system, app version, language or locale, time zone, network status, and crash or performance-related information where available.
- Notifications and app installations: notification permission and master-switch status, reminder scheduling preferences, Firebase installation ID, Firebase Cloud Messaging registration token, platform, selected language, and the time the installation record was last updated. These identifiers are used to address notifications to this installation and are not used as your public profile identity.
2. How We Use Information
We use information to:
- create, authenticate, and manage user accounts;
- save progress, scores, achievements, rewards, streaks, and profile customization;
- operate leaderboards, social features, friend requests, blocking, and reports;
- provide rewarded ads and confirm ad-based rewards;
- send social notifications and schedule daily reminders when you enable the notification master switch;
- detect abuse, prevent cheating, protect users, and enforce our Terms of Service;
- analyze gameplay and app performance; and
- respond to support, deletion, privacy, or legal requests.
3. Third-Party Services
Quiz Flux uses third-party services that may process data under their own privacy policies:
- Firebase Authentication for account sign-in and authentication.
- Cloud Firestore for user profiles, game progress, scores, social features, reports, notifications, and related app data.
- Firebase Storage for uploaded profile images.
- Cloud Functions for Firebase for server-authoritative friendship operations, account cleanup, and notification dispatch.
- Firebase Cloud Messaging and Firebase Installations for installation registration, token management, and social push delivery.
- Firebase App Check to help verify legitimate app requests and reduce abuse.
- Firebase Analytics, Firebase Crashlytics, and related performance tooling for app event analytics, crash diagnostics, and reliability monitoring where enabled.
- Google Sign-In and Apple Sign-In when you choose those sign-in methods.
- Google AdMob for rewarded ads and ad measurement.
- Google Cloud Vision SafeSearch for automated screening of images submitted through our moderated profile flow before their approved rendition is published. We send normalized image bytes for screening, without adding your account ID to the image request. Google states that online image requests are processed in memory and are not used to train its models; temporary request metadata may be retained under its service policies.
These providers may collect and process data such as device identifiers, IP address, app interactions, crash or performance information, and ad interaction data according to their own terms and privacy policies.
4. Sharing of Information
We do not sell your personal information. We may share information in these limited situations:
- with service providers that operate authentication, hosting, storage, analytics, advertising, and app infrastructure;
- with other players where the app intentionally displays public gameplay information, such as username, profile image, selected frame, score, rank, streak, friend activity, and achievement-related events;
- when required to comply with law, legal process, or enforceable government requests;
- to investigate fraud, cheating, abuse, security issues, or violations of our Terms; and
- in connection with a merger, acquisition, financing, or transfer of the app or related assets, subject to appropriate protections.
5. Public Gameplay Information
Quiz Flux includes competitive and social features. Your username, profile picture, selected frame, scores, ranks, streaks, achievements, and certain activity events may be visible to other users, especially in leaderboards, friend lists, search results, and activity feeds. Do not choose a username or profile image that contains sensitive personal information.
We are introducing moderated profile images in updated releases. During the Android compatibility transition, older releases can still use their previous photo flow. Not all existing photos have been screened, and the new image checks do not yet cover every older upload path.
6. Your Choices and Controls
- You can edit certain profile information in the app, including username and profile customization options.
- You can remove friends, block users, and report inappropriate usernames or profile images through available social controls.
- You can disable daily reminders and social push notifications together with the in-app notification master switch. You can also revoke notification permission through your device settings.
- You can manage advertising privacy choices through the in-app privacy options where required, and tracking permission through iOS Settings. Declining optional permissions does not prevent you from playing quizzes.
- If a profile photo or username is rejected, you can choose another or contact support to appeal. Automated screening can make mistakes. In the moderated image flow, pending or rejected copies are not published as your new avatar.
- You can request account and data deletion from inside the app or by following the instructions at /account-deletion.
7. Account and Data Deletion
You may request account deletion in Settings or through the instructions at /account-deletion. We verify control of the account before destructive processing. Cancelling or failing reauthentication does not submit a new deletion request; a request accepted earlier may still be processing. Accepted requests are processed by a retryable server job; acceptance and completion are different stages.
Account-record cleanup normally takes about two hours, but interruptions or failed cleanup steps can delay it. Updated releases provide a deletion-status view on the requesting installation, including after sign-out. Only an explicit server confirmation establishes that this cleanup has finished. A missing receipt, sign-out or elapsed estimate is not a completion confirmation. See the account-deletion instructions for status access and separate device/provider limits.
Completed deletion removes the authentication account, private and public profiles, account-linked scores and attempts, relationships, notifications, installation records, pending and approved images, moderation records, and other identifiable operational records under our control. We do not retain identifiable records merely for fraud prevention, leaderboard auditing, or product analytics after deletion. A specific legal obligation may require an exception; provider technical retention is described separately below.
Cleanup also requests deletion of Analytics data associated with your account user ID and Crashlytics reports associated with that ID in our configured Android and iOS apps. A provider accepting a request is different from completing removal. Analytics uses separate app-instance identifiers for some data; an account-ID request cannot identify every pre-login event or unrelated installation, and deleting a Firebase installation does not delete Analytics data.
After the server accepts an in-app deletion request, that device separately queues deletion of its push token and Firebase installation. If it is offline or interrupted, this device step retries when the app can run and connect again. Server cleanup does not prove that every device has completed its local step. Deleting Quiz Flux does not delete your Google or Apple account or the original photo held by a sign-in provider.
We may retain anonymous score totals grouped by category and UTC calendar month. Each aggregate contains only its category, month window, submission count, and combined score. It contains no account ID, replacement player ID, username, photo, exact event history, or account mapping. These aggregates cannot be used to restore an individual player's account or history.
8. Data Retention
While your account is active, we keep the information needed to provide the features you use. During deletion, a temporary job keeps the account reference only while cleanup remains unfinished; completed jobs do not retain a permanent account-linked tombstone.
For requests made with completion tracking, a random status key is kept in private app preferences on the requesting installation, separately from the account preferences cleared at sign-out. The server stores its hash with status and timing fields, without an account ID, email, username or permanent account mapping. Completed status receipts are available for seven days and then eligible for routine cleanup. A confirmation already downloaded remains locally until dismissed. An explicit action to forget an unavailable status removes only local access; it neither cancels nor confirms server deletion.
Deletion from active application records does not mean that every managed provider copy disappears immediately. Firestore historical versions, configured backups, Storage recovery features, and provider audit records can have technical expiry windows. We remove optional account-linked copies where supported and do not use recovery copies to reactivate deleted accounts. These technical limits are not, by themselves, a legal reason for us to keep personal information. Contact us for the configuration and limits applicable to your request.
For example, Firestore documents a one-hour historical version window without point-in-time recovery and up to seven days with that feature enabled. Cloud Vision describes its separate temporary request metadata. We do not promise instant erasure from infrastructure outside our direct control.
Our current Analytics retention settings are two months for event data and fourteen months for user data, with the user retention period reset by new activity. These settings do not limit every aggregate report. Account-linked deletion requests are separate from those general retention settings.
Firebase describes technical retention of up to 180 days after Authentication account deletion and a default 90-day period before removal of Crashlytics records begins. We also use the available per-user Crashlytics deletion request, whose response supplies a target completion time. Firebase installation deletion can take up to 180 days across applicable live and backup systems. These are provider processing limits, not a promise that identifiable app records remain active for those periods.
A disabled push installation may remain associated with your account with its delivery flag set to disabled so it can be re-enabled without creating duplicate installations. Installation records are removed on logout or account deletion, and invalid or expired messaging tokens are removed after delivery failures.
9. Security
We use technical and organizational measures designed to protect user data, including authenticated access controls and managed Firebase infrastructure. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Children
Quiz Flux is not intended for children under 13, or the minimum age required by local law. We do not knowingly collect personal information from children below the applicable age. If you believe a child has provided personal information, contact us so we can review and take appropriate action.
11. International Processing
Your information may be processed and stored in countries other than your own, including countries where our service providers operate. Those countries may have data protection laws different from your country.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the effective date above and, when appropriate, provide additional notice in the app or through other reasonable means.
13. Contact
For privacy questions, requests, or complaints, contact us at: nacar.dev@gmail.com.