CRAZY AXIU PRIVACY POLICY

Scope

Services published and operated by Crazy Axiu

Developer

Crazy Axiu

Effective Date

Sept 20, 2026

Last Updated

Sept 20, 2026

 

1 Introduction

1.1 This Privacy Policy ("Policy") explains how Crazy Axiu ("we", "us", or "our") collects, stores, uses, or otherwise processes personal data of end users of our services, and how you can exercise your privacy rights.

1.2 In this Policy, "services" refers to our games, websites, and any related services or properties we directly control. "Games" refers to online games or applications that we own and operate.

1.3 Please read this Policy before using the services. Where required by applicable law or Google Play policy, we will provide an in-app notice and obtain your consent before collecting or using personal or sensitive data.

1.4 By installing, using, registering to or otherwise accessing the services, you acknowledge this Policy. Where required by law, we will request your consent before collecting or using personal data for personalized advertising or other optional purposes. If you do not agree with this Policy, please do not install, use, register to or otherwise access the services.

1.5 We reserve the right to modify and update this Policy periodically. For material changes, we will provide notice through the Service, email where available, or another prominent channel before the change takes effect, and obtain consent where required. Your continued use of the services after the effective date signifies acceptance of the updated Policy.

 

Summary – Privacy at a Glance

We collect limited account, device, gameplay, advertising and diagnostic information needed to operate, secure and improve the Services. We do not sell personal data for money. Advertising-related disclosures may constitute "sharing" under some laws, and eligible users may opt out.

· Personalized advertising and non-essential analytics are subject to consent where required. Users can change their choice through Settings > Privacy > Privacy Choices.

· Users may request access, correction, deletion or export through the in-app privacy controls or by emailing LoooGAME01@163.com.

· Children's experiences use age screening, restricted advertising and verifiable parental consent where required.

· International transfers use recognized safeguards, including adequacy decisions and applicable Standard Contractual Clauses.

This summary is provided for convenience. The complete Policy below controls if there is any inconsistency.

2 Developer and Privacy Contact

The developer responsible for the Services is:

Google Play developer name: Crazy Axiu

Legal entity / registered name: Crazy Axiu

Registration status: Crazy Axiu is the registered entity responsible for operating the Services

Registered and operating contact address: Available to verified legal or regulatory requesters through the privacy contact below

Privacy contact: LoooGAME01@163.com

Data Protection Officer (DPO): Data Protection Officer, Crazy Axiu

DPO email: LoooGAME01@163.com

Recommended subject line: "DPO / EU Data Protection Request"

The DPO advises on data-protection obligations, monitors compliance, supports impact assessments, cooperates with supervisory authorities and serves as the contact point for users and regulators. The DPO function applies where the Services conduct large-scale, regular and systematic monitoring or where appointment is otherwise required. Privacy complaints sent to the DPO email will be acknowledged within 10 business days.

3 What Data We Process

3.1 Information You Provide

A unique in-game user identifier (UID); Your name, email address, or other contact information (e.g., when registering an account); Customer-support messages and information you submit with a request; Survey responses or other feedback you choose to provide; Information needed to verify an account or data-deletion request; Messages or communications you send to us or through the services (chat messages, support emails); Information from connected third-party accounts (e.g., social media); Purchase validation information from third-party payment providers (not credit card numbers); Any other information you choose to submit; Other information explained to you when asking for your explicit consent.

3.2 Information Collected Automatically

Device and technical information, such as device model, operating-system version, language, app version and screen resolution; Online and device identifiers, such as IP address, app-instance ID, AD-ID, App-Set-ID, where permitted; Approximate location derived from IP address, such as country, state or city; Gameplay and usage information, such as game progress, session events, feature interactions and ad interactions; Information about your interactions with our ads outside the services; Diagnostics, such as crash reports, ANR information, performance data and error logs; Inferences based on your activity. We do not request access to contacts, SMS, call logs, precise location, microphone, camera or files unless the relevant feature genuinely requires it and the access is clearly disclosed to you before permission is requested. We use the automatically collected information described above for service operation, advertising delivery, campaign attribution and analysis, performance improvement, security and fraud prevention. Where consent is required, this collection will not begin until you consent. If you refuse or withdraw consent, we will stop collecting this information for advertising and campaign analysis. You may continue to receive non-personalized or contextual advertising.

3.3 Payments and In-App Purchases

The Services currently do not offer in-app purchases. We do not collect or process payment-card details, bank-account information or purchase-verification records.

3.4 Third-Party Login

If you choose to sign in through Google, Facebook or another supported third-party login provider, we may receive the information authorized by you and provided by that service, such as an account identifier, display name or email address. The information received depends on your settings and the provider's policies.

3.5 App Permissions

The permissions requested by a particular Service depend on its features and package manifest. A permission is requested only when needed for the corresponding function. System permission controls remain available through Android settings.

Android permission or access

Function requiring it

Data or capability involved

User control

INTERNET

Connect to game services, retrieve remote content, deliver ads and transmit analytics or diagnostics

Network communications, IP address and transmitted service data

Required for online functions; block network access through device controls where supported

ACCESS_NETWORK_STATE

Detect whether the device is online and select an appropriate connection flow

Connectivity status; does not read message content

Managed through device network settings

ACCESS_WIFI_STATE

Diagnose connection type and network availability

Wi-Fi connection state; not Wi-Fi content

Managed through device Wi-Fi settings

com.google.android.gms.permission.AD_ID

Advertising measurement, frequency control and attribution where permitted

Resettable Android advertising ID

Reset or delete the advertising ID in Android settings; withdraw advertising consent in the Service

POST_NOTIFICATIONS

Deliver optional game or service notifications on supported Android versions

Permission to display notifications

Allow or deny at the system prompt; change later in Android notification settings

WAKE_LOCK

Keep an active game, network request or required download from being interrupted while in use

Temporary device wake state; no personal content

Ends when the relevant operation ends

FOREGROUND_SERVICE

Run a user-visible, time-limited background operation where a Service genuinely uses one

Service status and notification

Stop the feature or revoke relevant permissions in Android settings

 

Each production APK/AAB must be checked against this table before publication. Any permission not present in the package must be removed from this table, and any additional permission must be added with its exact function and user control.

3.6 Special Notice on Advertising ID and App-Set-ID

Android Advertising ID (AD-ID) and App-Set-ID are provided to our third-party SDK providers listed in Section 5.5 - including Firebase Analytics, Adjust Attribution SDK, AppLovin-MAX Advertising SDK, Google AdMob, Firebase Crashlytics, Meta/Facebook SDK, Pangle SDK and Unity SDK - for ad attribution statistics, ad display optimization and conversion analysis. These identifiers help us measure ad traffic sources and optimize ad frequency and ad content.

4 How We Collect Your Data

We collect information:

· Directly from you (registration, subscription, support requests, surveys);

· Automatically from you/your device (cookies, SDK tools including the third-party providers listed in Section 5.5);

· From advertising partners (ad delivery and measurement);

· From connected third-party account providers;

· From payment service providers for purchases;

· From other sources with your consent.

Providing data is not mandatory, but without it we cannot provide all or parts of the services. You can limit data processing by, e.g., not connecting third-party accounts, resetting your advertising ID, withholding consent for personalized ads, or disabling cookies. You may also reset or turn off Android Advertising ID (AD-ID) and restrict usage of App-Set-ID via your device system settings.

5 How We Use Information

We use information only for the following applicable purposes: Providing and operating the Service; Creating and managing user accounts; Saving game progress and delivering game features; Providing customer support; Detecting crashes, errors, abuse, cheating and fraud; Maintaining security and preventing unauthorized access; Analyzing performance and improving the Service; Measuring advertising performance, attribution and campaign effectiveness; Displaying contextual advertising; Displaying personalized advertising only where permitted and after obtaining any required consent; Complying with legal obligations and enforcing our terms; Internal operations (troubleshooting, analysis, testing, statistics); Product improvement and feature provision; Auditing, technical security and administrative messages; Statistical research and behavioral analysis; Payment processing and IT operations; Other purposes with your consent. We do not sell personal or sensitive user data.

5.1 Legal Bases

Where required by applicable law, we process personal data based on: Performance of a contract, when processing is necessary to provide the Service; Consent, including where required for personalized advertising or optional features; Legitimate interests, such as security, fraud prevention and service improvement, where those interests are not overridden by your rights; Compliance with a legal obligation. You may refuse consent when the consent request is shown, withdraw consent through the in-app privacy or consent controls where available, or contact us at LoooGAME01@163.com. We have completed a Legitimate‑Interest Assessment for processing activities relying on legitimate interests. You may request a copy of this assessment by contacting our privacy email.

5.2 Marketing and Advertising

Advertising helps fund our services, allowing us to offer games for free. We may show our own ads and third-party ads, and also advertise our games on third-party properties.

(1) Clear Purpose for Sensitive Permissions

We use Advertising IDs (IDFA on iOS, GAID / AD-ID on Android) for interest-based advertising. We will only share your Advertising ID and IP address for personalized ads after obtaining your explicit consent. If you do not consent, you will still see ads, but they will not be personalized. You can reset or limit use of your Advertising ID via device settings ("Limit Ad Tracking" on iOS, "Opt out of interest-based ads" on Android). App-Set-ID may be used together with the above SDKs for attribution and advertising statistics.

(2) Statement on Non-Essential Permissions

We do not request permissions unrelated to core game functionality (e.g., contacts, SMS, call logs). If a permission is used only for non-essential purposes such as advertising or analytics, we will separately explain and obtain your consent. Declining such permissions will not affect basic game operation. Ad networks may also use your data for frequency capping, re-marketing to existing players, avoiding ads to current users, and ad measurement (impressions, clicks, installs) and fraud prevention.

5.3 Advertising ID, Cookies and Similar Technologies

On Android, advertising and analytics providers may use the resettable advertising ID, app-instance identifiers, SDK storage, local storage, pixels or similar technologies to recognize an app installation, limit ad frequency, prevent fraud, measure campaigns and, where permitted, personalize advertising. Mobile apps do not generally rely on traditional browser cookies, but an in-app browser or a linked website may use cookies under the relevant website or provider notice. We do not combine the advertising ID with persistent hardware identifiers. If you reset or delete the advertising ID, withdraw consent, enable an applicable opt-out or use a child-restricted experience, personalized advertising and non-essential tracking will be disabled or limited as required.

5.3.1 Clearing Local Cache and Tracking Identifiers

Users can remove locally stored data and reset tracking choices using the following controls: Clear app cache: Android Settings > Apps > select the relevant Service > Storage & cache > Clear cache. Clear local app data: Android Settings > Apps > select the relevant Service > Storage & cache > Clear storage or Clear data. Reset in-app privacy choices: open the Service and go to Settings > Privacy > Privacy Choices. Reset or delete the advertising ID: Android Settings > Privacy > Ads, then choose Reset advertising ID or Delete advertising ID, depending on the Android version. Clear website or in-app-browser cookies: use the privacy or browsing-data controls of the relevant browser. Clearing app data may remove local settings, downloaded content and locally stored game progress. Account-linked information stored on our systems is not deleted by clearing the device cache or app data; use the account and data-deletion process in Section 11 for that purpose.

5.4 First-Launch Consent and Withdrawal

Where consent is required, the first launch flow presents a privacy notice before personalized advertising or non-essential analytics SDKs are initialized. The notice identifies the main data categories and purposes and provides equally accessible choices to accept, reject or manage options. Essential processing needed to deliver the Service, maintain security or remember a privacy choice may continue without advertising consent where permitted by law. Users can later review or withdraw consent through: Settings > Privacy > Privacy Choices. After withdrawal, new processing based on consent stops and updated consent signals are sent to applicable SDKs. Previously lawfully processed data is not retroactively invalidated. Users may also contact LoooGAME01@163.com if the in-app control is unavailable.

5.4.1 Separate In-App Tracking Notice

Before enabling advertising-ID access, cross-app or cross-service tracking, personalized advertising, advertising attribution or another non-essential tracking technology, the Service displays a separate, concise tracking notice. This notice is presented independently from the full Privacy Policy and before the relevant SDK or technology begins the optional processing. The notice identifies the tracking technologies and SDK categories involved, the data used, the purposes, whether information may be disclosed for cross-context behavioral advertising and the available controls. It provides equally prominent Allow, Reject and Manage Options choices and includes a direct link to this Policy. Rejecting tracking does not block access to unrelated core gameplay. The user's choice is recorded, transmitted to applicable SDKs and can be changed later through Settings > Privacy > Privacy Choices.

5.5 Third-Party SDK Providers

The Service currently uses the following third-party providers:

Provider

Service

Data involved

Purpose

Policy

Google AdMob

Advertising

IP address, advertising ID, device and app information, approximate location and ad interactions

Ad delivery, measurement, attribution and fraud prevention

https://policies.google.com/privacy

Firebase Analytics (Google)

Analytics

App-instance identifier, device and app information, gameplay and usage events, approximate location

Usage analytics, campaign analysis and service improvement

https://firebase.google.com/support/privacy/

Firebase Crashlytics

Diagnostics

Crash logs, installation identifiers, device and app information, error and performance data

Crash diagnosis and stability improvement

https://firebase.google.com/support/privacy/

Meta/Facebook SDK

Login, advertising and analytics

Third-party account identifier, IP address, device and app information, advertising ID, app events and ad interactions

Login, attribution, advertising measurement and campaign analysis

https://www.facebook.com/privacy/policy/

Pangle SDK

Advertising

IP address, advertising ID, device and app information, approximate location and ad interactions

Ad delivery, measurement, attribution and fraud prevention

https://www.pangleglobal.com/privacy/enduser

Unity SDK

Game technology, analytics and advertising

IP address, device and app information, installation or player identifiers, advertising ID, usage and ad events

Game functionality, analytics, advertising and performance improvement

https://unity.com/legal/game-player-and-app-user-privacy-policy

Adjust Attribution SDK

Attribution

IP address, advertising ID, device and app information, app events and ad interactions

Ad attribution, channel source statistics and conversion performance analysis

https://www.adjust.com/terms/privacy-policy/

AppLovin-MAX Advertising SDK

Advertising

IP address, advertising ID, device and app information, approximate location and ad interactions

Ad loading, display, measurement, attribution and monetization optimization

https://www.applovin.com/privacy/

 

5.6 Responsibilities of SDK Providers

Crazy Axiu determines the purposes and configuration of data processing within the Services and acts as the controller or business for that processing. A provider acting only on documented instructions is a processor or service provider and must apply contractual confidentiality, security, deletion and assistance obligations. A provider that independently determines purposes, such as certain advertising, fraud-prevention, authentication or platform activities, may act as a separate controller or third party for those activities.

Provider / activity

Expected role

Main responsibility

Firebase Analytics and Crashlytics configured for Crazy Axiu

Processor / service provider for configured analytics and diagnostics, subject to applicable terms

Process configured events and diagnostics, secure data, support deletion and honor retention settings

Google AdMob advertising services

Processor, service provider or independent controller depending on product, region and consent mode

Ad delivery, consent signaling, measurement, fraud prevention and provider-level rights handling

Meta/Facebook login and advertising

Independent controller for platform account data; processor only where its specific terms say so

Manage platform account data, advertising systems and provider requests under Meta terms

Pangle advertising

Independent controller or service provider depending on region and contract

Ad delivery, measurement, anti-fraud controls and provider-level disclosures

Unity game technology, analytics and advertising

Processor or independent controller depending on the selected Unity service

Operate selected technology, analytics or advertising and honor configured privacy controls

Adjust attribution and analytics

Processor or independent controller depending on region, consent mode and contract

Install attribution, campaign measurement, fraud detection, support deletion and respect user consent and retention limits

AppLovin-MAX advertising and mediation

Independent controller or service provider depending on region and contract

Ad mediation, ad delivery, measurement, anti-fraud, provider-level privacy disclosures and rights handling

 

The final role allocation must be checked against the current SDK contract, product configuration and region. We remain responsible for selecting compliant SDKs, minimizing transmitted events, configuring consent and child-directed treatment, and keeping this Policy and the Google Play Data safety form accurate.

5.7 SDK Compliance, Remediation and Responsibility

Crazy Axiu remains the primary responsible entity for the selection, integration and configuration of third-party SDKs within the Services and is the primary contact for users concerning data processed through those integrations. We do not disclaim our statutory controller or business responsibilities merely because processing is performed by an SDK provider. Our contracts require applicable SDK providers to follow documented instructions, maintain appropriate security, support rights requests, notify us of incidents, delete or return data when required, restrict subprocessors and comply with applicable transfer safeguards. If an SDK provider violates these obligations, we may suspend data transmission, disable or remove the SDK, require remediation and deletion, conduct an investigation, notify affected users or authorities where required and pursue contractual indemnification or other remedies. These contractual remedies do not reduce any right or remedy available to users under applicable law.

6 Who We Share Your Data With

We may share information only as necessary with:

· Related entities (Crazy Axiu and subsidiaries);

· Selected business and advertising partners;

· Third-party SDK service providers listed in Section 5.5 (including Firebase Analytics, Firebase Crashlytics, Adjust Attribution SDK, AppLovin-MAX Advertising SDK, Google AdMob, Meta/Facebook SDK, Pangle SDK and Unity SDK), for data analytics, crash diagnostics, ad attribution, ad delivery and monetization. Only necessary device identifiers and event data are transmitted;

· Service providers that host, maintain, analyze or support the Service;

· Authentication providers when you choose to use their services;

· Professional advisers where necessary to protect our legal rights;

· Public, regulatory or industry bodies (including anti-money laundering authorities) when required by applicable law;

· A successor organization in connection with a merger, acquisition or transfer of the Service, subject to appropriate notice and safeguards.

Service providers may process information only for the agreed purpose and must protect it appropriately. We do not permit third parties to use personal or sensitive data for unrelated purposes. Third-party SDKs shall only process obtained data in accordance with their own privacy policies. Please review their official privacy links listed in Section 5.5.

7 Data Retention

We keep your data as long as necessary for the purposes collected, including providing services or complying with legal requirements. We periodically delete or de-identify inactive accounts. After the retention period, we delete or de-identify your data, or isolate it until deletion is possible. We generally retain personal and automatically collected information for no longer than 180 days, unless deletion is requested earlier or a longer period is required to maintain an active account, prevent fraud, protect security or comply with law. Any exception is limited to the longest period stated below and is reviewed when that period ends.

Data category

Retention period or criterion

UID and login-related data

Up to 180 days after the user's last activity, unless needed to maintain an active account

Game progress and usage data

Up to 180 days

Support communications

Up to 180 days

Crash and diagnostic data

Up to 180 days

Analytics and advertising-measurement data

Up to 180 days

Deletion-request records

Up to 180 days after completion of the request

Fraud-prevention and security investigation records

Up to 24 months after closure of the investigation

Records retained for an active legal claim

Until final resolution, but normally no more than 24 months after the matter closes

Accounting, tax or legally mandated compliance records

Up to 7 years, or the shorter or longer period expressly required by applicable law

 

Data collected by our third-party SDK providers listed in Section 5.5 shall be subject to the respective retention policies of such third-party service providers. Where technically feasible, we configure these SDK partners to respect our retention limits set out in this Policy. When retention is no longer necessary, we delete or irreversibly anonymize the information. Data retained for fraud prevention, security, accounting or legal compliance is logically segregated from active-service data, access-restricted by role, encrypted in transit and at rest where supported, protected by audit logging, excluded from advertising and product analytics, reviewed at least annually and deleted when the applicable maximum period ends.

8 How We Keep Your Data Secure

We use reasonable administrative, technical and organizational safeguards designed to protect personal data. These safeguards include, where appropriate:

· Encryption in transit using HTTPS/TLS;

· Access controls based on job responsibilities;

· Authentication and logging for administrative systems;

· Restricted access to production data;

· Security monitoring and incident-response procedures;

· Periodic review of service providers and SDKs.

No system is completely secure, but we continuously review our safeguards and address identified risks. No internet transmission is 100% secure, and absolute security cannot be guaranteed.

8.1 Security Vulnerability Reporting

Security researchers and users may report a suspected vulnerability to LoooGAME01@163.com with the subject "Security Vulnerability Report." Please include the affected Service, version, reproduction steps and potential impact, but do not include unnecessary personal data or publicly disclose an unremediated issue.We acknowledge credible vulnerability reports within 10 business days and provide status updates as appropriate.

9 International Data Transfers

Our services are global, and your data may be transferred worldwide. Personal data may be processed internationally by Crazy Axiu and the providers listed in Section 5. International processing remains subject to the contractual, organizational and technical safeguards described below. For transfers from the European Economic Area, United Kingdom or Switzerland, we use an applicable adequacy decision where the destination or recipient is covered. Where no adequacy decision applies, we use the European Commission's 2021 Standard Contractual Clauses, the UK International Data Transfer Addendum or another valid transfer mechanism, together with a transfer-impact assessment and supplementary safeguards where required. Supplementary safeguards may include encryption in transit and at rest, access minimization, pseudonymization, contractual limits on government-access requests and review of recipient security practices. Before enabling a covered transfer to an SDK provider outside the European Economic Area, Crazy Axiu enters into a separate written data-processing and transfer agreement with that provider. The agreement incorporates the applicable module of the European Commission's 2021 Standard Contractual Clauses and identifies the data categories, purposes, security measures, subprocessors, retention requirements and audit or cooperation obligations. Separate SCC arrangements are maintained for Firebase, Adjust, AppLovin-MAX and any other SDK provider receiving covered EEA personal data, unless the transfer is fully covered by an applicable adequacy decision or the recipient is already directly subject to the GDPR in a manner for which those transfer SCCs are not the appropriate mechanism. We do not rely on an invalidated privacy framework. If a provider relies on a current certification or data-privacy framework, the relevant details are stated in that provider's privacy notice. Users may request information about the applicable transfer mechanism by contacting LoooGAME01@163.com.

10 Your Privacy Rights and Choices

Depending on your location, you may have the right to:

· Request access to personal data;

· Request correction of inaccurate data;

· Request deletion of personal data;

· Withdraw consent;

· Object to or restrict certain processing;

· Request data portability;

· Lodge a complaint with a competent supervisory authority;

· Rights related to automated decision-making (including profiling);

· California residents: right to opt out of the "sale" or "sharing" of personal data.

To exercise a right, use Settings > Privacy > Submit a Privacy Request or contact LoooGAME01@163.com with the request type in the subject line. We may request limited information necessary to verify your identity. We will not require a reason for a deletion request. We acknowledge privacy requests within 10 business days and normally complete access, correction, deletion, portability and complaint requests within 30 calendar days after verification. If applicable law permits and a request is unusually complex, we will notify you before the original deadline and explain any extension. California requests follow the specific deadlines in Section 10.2.

10.1 Data Portability and Game Data Export

Open Settings > Privacy > Export My Data, verify the account and choose the available machine-readable export. If the in-app option is unavailable, email LoooGAME01@163.com with the subject "Data Export Request" and identify the relevant Service and player ID. The export may include account data, game progress, entitlement records and selected activity history, but may exclude information that would reveal another person's data, compromise security or violate law.

10.2 California Privacy Rights (CCPA/CPRA)

This section applies to California residents where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to us. California residents may request to know the categories and specific pieces of personal information collected; request deletion or correction; opt out of the sale or sharing of personal information; limit certain uses of sensitive personal information; use an authorized agent; and receive equal service without discrimination for exercising a right. We do not sell personal information for money. Certain disclosures of advertising identifiers, device information and ad interactions for cross-context behavioral advertising may be considered "sharing" under California law. To opt out, use Settings > Privacy > Privacy Choices > Do Not Sell or Share My Personal Information or email LoooGAME01@163.com with the subject "California Opt-Out Request." Where technically applicable to our web resources, we also treat a recognized Global Privacy Control signal as an opt-out request. We process an opt-out request as soon as feasible and no later than 15 business days. Verified requests to know, delete or correct are generally answered within 45 calendar days; if reasonably necessary and permitted by law, we may extend once for an additional 45 days after giving notice. We will use verification information only to handle the request.

10.3 Authorized Agents

A California resident may authorize an individual or a business entity registered with the California Secretary of State to submit a CCPA request on the resident's behalf. The authorized agent should email LoooGAME01@163.com with the subject "California Authorized Agent Request" and provide:

· The consumer's name or player/account identifier;

· The type and scope of request;

· Written and signed permission from the consumer identifying the agent and authorizing the specific request;

· Contact details that allow us to communicate separately with the consumer and the agent.

For access, correction or deletion requests, we may ask the consumer to verify identity directly with us and directly confirm that the agent has permission. A valid power of attorney may be accepted where applicable. We do not require notarization unless specifically required by applicable law, and we use authorization and verification information only to process the request and prevent fraud. If authority or identity cannot be reasonably verified, we will explain the additional information needed or why the agent request cannot be completed. We do not knowingly sell or share the personal information of users under 16 without affirmative authorization. For a user under 13, authorization must come from a parent or legal guardian. For a user aged 13 through 15, authorization must come from the user. A user or guardian may later opt out, and we will wait at least 12 months before asking the user to opt in again unless the user initiates the request.

10.4 Complaints to Regulatory Authorities

Users may contact us or the DPO first so that we can investigate, but this is not required before making a regulatory complaint where applicable law provides a direct complaint right. Examples include:

· European Economic Area: the data-protection authority where the user lives or works, or where the alleged infringement occurred. The official list is available at https://www.edpb.europa.eu/about-edpb/our-members_en.

· United Kingdom: the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/.

· California: the California Privacy Protection Agency at https://cppa.ca.gov/ or the California Attorney General consumer complaint channel at https://oag.ca.gov/contact/consumer-complaint-against-business-or-company.

· Other locations: the privacy, consumer-protection or data-protection authority responsible for the user's country or region.

We will not retaliate or discriminate against a user for making a good-faith complaint or cooperating with a regulator.

11 Account and Data Deletion

If a Service allows users to create an account, users can request deletion both inside and outside the Service. Deletion is irreversible: you will permanently lose all game progress, virtual currency, and virtual goods without refund. Some data may be retained for legal or technical reasons (e.g., financial records, fraud prevention). Public information cached on other players' devices (e.g., username, avatar, high scores) may not be removable. After account deletion, we will stop sending new data to Firebase Analytics, Adjust and AppLovin-MAX. After successful identity verification, we will issue corresponding deletion instructions to our third‑party SDK partners (Firebase Analytics, Adjust, AppLovin‑MAX) to erase relevant user‑linked data within their systems, in compliance with applicable law. We will follow‑up to confirm completion as far as contractually permitted.

11.1 In-App Request

Open the relevant Service and use the readily discoverable Delete Account option in the account or settings area. The exact menu name may vary by Service. If the Service provides an in-app link to the web deletion resource instead, open that link and follow the instructions to submit the request.

· Open the game and go to "Settings" or "Account" page;

· Click "Delete Account" or "Request Data Deletion";

· After identity verification, deletion will be completed within 30 calendar days after successful identity verification.

11.2 Web Request

Submit a request at: https://jpu1oc1fkp.feishu.cn/share/base/form/shrcnlASzXIG6r2GojUbBoxgLih. The form will ask you to provide:

· Confirmation of the game name;

· Your in-game User ID (UID);

· Which third-party accounts you have connected (e.g., Apple ID, None);

· Your primary device information;

· The main reason for deletion;

· Confirmation that you understand the consequences of deletion.

Once submitted, we will verify your identity and process the deletion within 30 calendar days after successful identity verification. A confirmation will be sent to your registered email address upon completion.

11.3 Email Request

Alternatively, email LoooGAME01@163.com with the subject "Account Deletion Request" and provide:

· Information identifying the relevant Service;

· Only the player ID or account information needed to identify the account.

We will verify your identity and process the request within 30 calendar days after successful identity verification.

11.4 Facebook Disconnect and Deletion Request

Go to Facebook Settings > "Apps and Websites"; find our app and remove it; in the "Removed" tab, find our app and click "Send Request to Delete Data".

11.5 What Will Be Deleted

After verification, we will delete the account and associated personal data, including:

· Account profile information;

· Account-linked game progress and service records;

· Account-linked identifiers;

· Other personal data associated with the account.

Deletion will generally be completed within 30 calendar days after successful identity verification, unless a shorter period is required by applicable law.We may retain limited records only where necessary for security, fraud prevention, dispute resolution, accounting or legal compliance. Any retained information will be isolated, protected and deleted when the retention obligation ends. Disconnecting a Google, Facebook or other third-party account only revokes that provider's connection. It does not itself delete information held by us unless the deletion process above is also completed. We do not charge any fee for account deletion. If you encounter any issues, please contact us at the email above.

12 Children's Privacy and COPPA Controls

Unless a specific store listing expressly identifies a child-directed experience, the covered Services are intended for a general audience and are not directed to children under 13. We do not knowingly collect personal data from children under 13 without legally valid parental consent.

12.1 Neutral Age Screen

Where age screening is used, a neutral age or birth-year prompt appears before personalized advertising, optional analytics or account features are enabled. The prompt does not suggest that a user should enter an older age and does not store a full birth date when an age-band result is sufficient.

12.2 Under-13 and Guardian Flow

If the age screen indicates that the user is under 13, or the applicable local minimum age, the Service switches to a child-restricted mode. Personalized advertising, advertising-ID access, cross-app tracking, third-party login and non-essential analytics are disabled before the relevant SDKs initialize. Only data reasonably necessary for internal operations or to obtain consent may be processed. If a child-directed account or feature requires personal information, the Service first requests a parent or guardian email address solely to send a direct privacy notice and consent request. The notice describes the data, purposes, recipients, retention and available controls. The guardian must complete a legally‑accepted verifiable parental‑consent method (which may include a signed consent form) before collection begins. Support staff verify that the consent applies to the relevant child account and record only the minimum evidence needed to demonstrate consent. If consent is not completed, the feature remains unavailable and the pending contact information is deleted within a reasonable period.

12.3 Parent and Guardian Rights

A verified parent or guardian may contact LoooGAME01@163.com with the subject "Child Privacy Request" to review the child's personal information, request deletion, refuse further collection or revoke consent. We will verify the requester's authority using only the minimum information necessary, disable the affected processing while a valid revocation is handled and notify relevant processors to delete the data where required.

12.4 Children's Advertising Controls

In child-restricted mode, only contextual or otherwise legally permitted advertising may be shown. SDK child-directed-treatment flags, maximum-content-rating controls and non-personalized-ad settings must be enabled. Interest-based advertising, remarketing, profiling, advertising-ID collection and sale or sharing for cross-context behavioral advertising are disabled. If an advertising provider cannot reliably honor these settings, it must not load in child-restricted mode. If you believe a child has provided personal data without appropriate authorization, contact LoooGAME01@163.com. We will investigate promptly, suspend non-essential processing and delete the information where required. The app's target-audience declaration, advertising SDK configuration and age-related experience must remain consistent with this section and Google Play's Families requirements.

13 Changes to This Policy

We may update this Privacy Policy to reflect changes to the Service, data practices or legal requirements. For a material change, we will provide notice through the Service, email where available or another prominent channel at least 30 days before the change takes effect, unless an earlier change is required to address an urgent security risk or binding legal obligation. The notice will summarize the material change, the effective date and the available choices. If a new purpose requires consent, it will not apply to a user who refuses consent. A user who does not accept a material change may stop using the affected Service, withdraw optional consent, export available game data and request account and data deletion before the new version takes effect. Refusing an optional new purpose will not affect unrelated core functions where those functions can reasonably continue without the new processing.

13.1 Language Versions

We may provide this Privacy Policy and privacy notices in multiple languages to improve accessibility. Users should be shown a version appropriate to the language selected in the Service or device settings where a translation is available. Material changes should be reflected in supported translations at or before the time the updated Policy becomes effective. Translations are intended to communicate the same rights, purposes, data categories, retention periods and contact methods as the English version. If a translation conflicts with the English version, the English version controls to the extent permitted by applicable law. Where local law requires a local-language notice or gives that notice mandatory effect, the locally required version controls for users covered by that law. Users may request clarification or another available language version by contacting LoooGAME01@163.com.

14 Contact Us

For privacy questions, complaints or requests, contact:

Developer: Crazy Axiu

Legal entity / registered name: Crazy Axiu

Registered and operating contact address: Available to verified legal or regulatory requesters through the email below

Email: LoooGAME01@163.com

Data Protection Officer: Data Protection Officer, Crazy Axiu

DPO email: LoooGAME01@163.com

Complaint acknowledgment: Within 10 business days

Covered services: Games, applications, websites and related services published or operated by Crazy Axiu