This Privacy Policy describes how N VoaWu Studio ("N VoaWu", "we", "us", "our") collects, uses, discloses, and protects information when you (a) visit https://nvoawu.com (the "Website"), or (b) install, access, or use any mobile application published by N VoaWu on Google Play or the Apple App Store (the "Apps"). Collectively, the Website and the Apps are referred to as the "Services". By installing or using any of the Services, you agree to this Privacy Policy. If you do not agree, please do not install or use the Services.
5.1 Introduction & scope
This Privacy Policy applies to all of the following:
- The public website at https://nvoawu.com and any subdomains operated by N VoaWu Studio (for example,
*.nvoawu.com). - Every mobile application published by N VoaWu Studio on Google Play, including but not limited to Pocket Meteorology, Foxglove Solitaire, Tidy Tray, Tiny Trails, FieldKeeper, and Loom Calm, and any future titles published under the developer name "N VoaWu Studio" or any of its trading names.
- Every mobile application published by N VoaWu Studio on the Apple App Store, including any white-label builds distributed under a partner's developer account that are nevertheless operated by N VoaWu.
- Any future product (web, mobile, desktop) that links to or is governed by this policy.
It does not apply to any third-party websites, applications, or services that we do not control. We may link to third-party content (for example, app store listings or social media); please review their policies separately.
5.2 Information we collect
We collect the minimum information necessary to operate, secure, and improve the Services. The categories below apply across the Website and the Apps.
Account information. When you create an account inside one of the Apps (for example, FieldKeeper), we collect a display name, an email address, a hashed password, and any optional profile fields you complete. For white-label deployments, your administrator may provision accounts on your behalf.
Device information. We collect device model, operating system version, app version, locale, time zone, device language, and a stable device identifier such as the Android Advertising ID (AAID/GAID), the iOS Identifier for Advertisers (IDFA), the iOS Identifier for Vendors (IDV), or a randomly generated app-scoped identifier (where the platform disables the advertising identifiers).
Usage information. We collect information about how you use the Services, including features opened, screens viewed, taps, session length, crash logs, performance metrics, and the actions you take inside each app.
In-app events. We collect first-party analytics events such as level starts, level ends, in-app purchases, subscription starts and renewals, rewarded-ad views, and tutorial completions. We use these to maintain and improve the products.
Advertising identifiers and signals. Subject to your consent and the platform settings, we may read or write the AAID/GAID, the IDFA, the Limit Ad Tracking setting (iOS), the Opt out of Ads Personalization setting (Android), and any app-defined pseudonymous identifiers required by our advertising partners.
Cookies and similar technologies (Website). The Website uses first-party cookies and local storage for session, language preference, and analytics. See Section 5.14 for the full list.
Support communications. When you contact us, we collect the contents of your message, your email address, and any attachments you choose to send.
5.3 How we use information
We use the information we collect to:
- Operate, maintain, secure, and improve the Services.
- Authenticate users and provide customer support.
- Process in-app purchases, subscriptions, and refunds through the platform payment systems (Google Play Billing and Apple App Store In-App Purchase).
- Display advertising in apps that include ads, and to measure the performance of that advertising.
- Localize content and remember your preferences (language, region, dark mode).
- Detect, prevent, and respond to fraud, abuse, security incidents, and violations of our terms.
- Comply with legal obligations and respond to lawful requests from public authorities.
- Send you service-related notices (release notes, security alerts, critical product information) and, where you have opted in, the studio newsletter.
We do not sell personal information for monetary consideration. We do share information with the advertising partners listed in Section 5.4 to the extent necessary to deliver and measure advertising in our free apps, and you may opt out at any time as described in Section 5.13.
5.4 Google AdMob & ad SDKs in the Apps
Our free Apps display advertising served by Google AdMob and the additional ad mediation partners listed in Section 5.5. The ad formats we use, and the SDKs that deliver them, are described below.
Splash ads (app-open format). When you open one of our free Apps, a brief splash ad may be displayed before the app's home screen loads. Splash ads are served by Google AdMob and the mediation partners listed below. We do not personalize splash ads based on your activity in other apps; we use a coarse contextual signal (country and language) for ad selection.
Rewarded video ads. Some Apps offer an in-app reward (for example, an extra life, a hint, or a temporary premium feature) in exchange for watching a full-length video ad. Rewarded video ads are served by Google AdMob, Unity Ads, ironSource / Unity LevelPlay, AppLovin MAX, Pangle, Vungle, and Mintegral. You are always shown a clear offer screen before a rewarded ad plays, and you can decline.
Interstitial ads. Some Apps display full-screen ads at natural transition points (for example, between game levels). Interstitial ads are served by Google AdMob, Meta Audience Network, Unity Ads, AppLovin MAX, ironSource / Unity LevelPlay, Pangle, Vungle, Chartboost, Mintegral, InMobi, and Tapjoy.
Banner ads. Some Apps display a small banner ad at the top or bottom of the screen. Banner ads are served by Google AdMob, Google Ad Manager, Meta Audience Network, AppLovin, InMobi, Smaato, and Verizon Media / Yahoo.
Native ads. A small number of Apps integrate native ad slots that match the look and feel of the surrounding content. Native ads are served by Google AdMob, Google Ad Manager, and Unity Ads.
Frequency capping. Each mediation partner uses its own frequency capping to limit how many times you see the same ad or the same advertiser's ad in a given period. We configure our own cap of three interstitial ads per user per session for any app that displays interstitials.
5.5 Ad mediation and aggregation partners
To deliver and measure advertising, we work with the ad mediation and aggregation platforms listed below. Each partner may collect, use, and disclose device, usage, and ad-interaction information as described in its own privacy policy. We do not control those third-party practices, and we encourage you to review them. For each partner we list the data shared for ad serving, frequency capping, interest-based advertising, and any child-directed setting we are aware of.
- Google AdMob / Google Ad Manager (Google LLC). Serves all four ad formats above. Receives AAID/GAID or IDFA, IP-derived coarse location (country level), device make/model, OS version, app version, and ad-interaction events. Supports frequency capping, interest-based ads, and Google's "Treat this child-directed" flag, which we enable for any app configured as a child-directed app on Google Play.
- Meta Audience Network (Meta Platforms, Inc.). Serves banner, interstitial, and rewarded video ads. Receives AAID/GAID or IDFA, hashed email (where the user is logged in to Facebook), coarse location, and ad-interaction events. Supports frequency capping and interest-based ads. We do not enable Meta's "child-directed" tag; Meta Audience Network is not used in apps that are configured as child-directed on Google Play or that opt into Apple's Kids Category.
- Unity Ads (Unity Technologies). Serves interstitial, rewarded video, and banner ads. Receives AAID/GAID or IDFA, IP address, device identifiers, and ad-interaction events. Supports frequency capping and interest-based ads.
- AppLovin (AppLovin Corporation). Serves banner, interstitial, rewarded video, and native ads. Receives AAID/GAID or IDFA, device identifiers, coarse location, and ad-interaction events. Supports frequency capping and interest-based ads.
- AppLovin MAX (AppLovin Corporation). Acts as our primary mediation layer, orchestrating waterfall and bidding among the other partners listed here. Receives the same data as AppLovin above.
- ironSource / Unity LevelPlay (Unity Technologies / ironSource). Serves interstitial, rewarded video, and banner ads. Receives AAID/GAID or IDFA, IP address, device identifiers, and ad-interaction events. Supports frequency capping and interest-based ads.
- Pangle (ByteDance / TikTok). Serves banner, interstitial, rewarded video, and native ads. Receives AAID/GAID or IDFA, IP address, device identifiers, and ad-interaction events. Supports frequency capping and interest-based ads. Pangle is not used in child-directed apps.
- Vungle (Vungle, Inc., a Liftoff company). Serves interstitial and rewarded video ads. Receives AAID/GAID or IDFA, device identifiers, coarse location, and ad-interaction events. Supports frequency capping and interest-based ads.
- Chartboost (Zynga Inc.). Serves interstitial, rewarded video, and banner ads. Receives AAID/GAID or IDFA, device identifiers, and ad-interaction events. Supports frequency capping and interest-based ads.
- Digital Turbine (Digital Turbine, Inc.). Serves interstitial, rewarded video, and offer-wall ads. Receives AAID/GAID or IDFA, device identifiers, and ad-interaction events. Supports frequency capping and interest-based ads.
- Mintegral (Mintegral, a Mobvista company). Serves interstitial, rewarded video, and banner ads. Receives AAID/GAID or IDFA, IP address, device identifiers, and ad-interaction events. Supports frequency capping and interest-based ads.
- InMobi (InMobi Technology Services). Serves banner, interstitial, rewarded video, and native ads. Receives AAID/GAID or IDFA, device identifiers, coarse location, and ad-interaction events. Supports frequency capping and interest-based ads.
- Tapjoy (Tapjoy, Inc.). Serves offer-wall, interstitial, and rewarded video ads. Receives AAID/GAID or IDFA, device identifiers, and ad-interaction events. Supports frequency capping and interest-based ads.
- StartApp (StartApp Inc.). Serves banner, interstitial, and rewarded video ads. Receives AAID/GAID or IDFA, device identifiers, and ad-interaction events. Supports frequency capping and interest-based ads.
- Smaato (Smaato Inc.). Serves banner and native ads. Receives AAID/GAID or IDFA, device identifiers, coarse location, and ad-interaction events. Supports frequency capping and interest-based ads.
- Verizon Media / Yahoo (Yahoo Inc., a Verizon Media company). Serves banner and native ads. Receives AAID/GAID or IDFA, device identifiers, and ad-interaction events. Supports frequency capping and interest-based ads.
- Amazon Publisher Services (Amazon.com, Inc.). Acts as a header-bidding partner on the mediation stack. Receives AAID/GAID or IDFA, device identifiers, and ad-interaction events. Supports frequency capping and interest-based ads.
- MobFox (MobFox USA LLC, part of Verve Group). Serves banner and interstitial ads. Receives AAID/GAID or IDFA, device identifiers, and ad-interaction events. Supports frequency capping and interest-based ads.
- MyTarget (VK Group / Mail.ru Group). Serves banner and interstitial ads. Receives AAID/GAID or IDFA, device identifiers, and ad-interaction events. Supports frequency capping and interest-based ads.
Child-directed settings. None of the partners above are used inside apps that are configured as child-directed on Google Play or that opt into Apple's Kids Category. For all other apps, you can limit interest-based advertising on your device at any time: on iOS, enable Limit Ad Tracking under Settings → Privacy → Tracking; on Android, enable Opt out of Ads Personalization under Settings → Google → Ads.
5.6 Google Play policies
Our apps on Google Play comply with Google Play's policies in force at the time of publication, including but not limited to:
- Data safety form. Every app submits an accurate Google Play Data safety form that describes the data the app collects, whether it is shared with third parties, and the security practices in place (encryption in transit, the ability to request deletion).
- Families Policy. Apps that are designed for children follow the Google Play Families Policy. Child-directed apps do not transmit AAID/GAID to third-party ad networks, and we use only Google AdMob's "Families" SDKs where applicable.
- Ads policy. Ads in our apps comply with Google Play's Ads policy, including the rules on interstitial placement, rewarded ad disclosure, and prohibition of ads that interfere with system functionality or impersonate system notifications.
- Target API level. Our Android apps target the API level required by Google Play for new and existing apps in the year of release, and we ship updates to maintain that target.
- Permissions policy. We request the minimum Android runtime permissions necessary for the feature. Sensitive permissions (for example, camera, location, microphone) are requested only with in-context prompts at the moment the feature is first used.
- Account deletion. Apps that support accounts offer an in-app path to request account and data deletion, in line with Google Play's user data policy.
5.7 Apple App Store policies
Our apps on the Apple App Store comply with Apple's policies in force at the time of publication, including but not limited to:
- App Tracking Transparency (ATT / IDFA). We do not access the IDFA in any app until you have granted tracking permission through the iOS ATT prompt. If you decline ATT, we serve contextual ads only.
- Privacy nutrition labels. Every app submits an accurate App Store privacy label describing the data it collects, the data it links to you, and the data used for tracking, in line with Apple's requirements.
- App Store Review Guidelines §5 (Privacy). Our apps comply with Section 5 of the App Store Review Guidelines, including the requirements on data collection, data use, data sharing, and health-research disclosures.
- Kids Category compliance. Apps that participate in the Kids Category comply with the additional restrictions in Section 1.4 of the Review Guidelines, including the prohibition of behavioral advertising and the prohibition of third-party SDKs that perform tracking as defined by Apple.
- Sign in with Apple. Where an app offers a third-party or first-party sign-in, the app also offers Sign in with Apple as an option, in line with Section 4.8 of the Review Guidelines.
- GDPR / CCPA disclosures. For users in the EEA, the UK, and California, the app surfaces a clear opt-in or opt-out choice consistent with the regional rules described in Section 5.9.
5.8 Children's privacy
We do not knowingly collect personal information from children below the applicable age threshold without verifiable parental consent. We comply with the following:
- United States — COPPA. The Children's Online Privacy Protection Act applies to children under 13. We do not direct our consumer apps at children under 13, and we do not use ad SDKs that build profiles of users we know to be under 13.
- European Union — GDPR-K. Article 8 of the GDPR sets the default age of consent at 16, with member states able to lower it to no less than 13. We apply the higher threshold (16) by default in the EEA and the UK.
- United Kingdom — Age-Appropriate Design Code (AADC). Our apps that are likely to be accessed by children follow the AADC's standards, including the duty to assess and mitigate risks to the best interests of children.
- Other regions. We respect the higher of the local age threshold or 16 wherever our apps are made available.
If you believe we have collected information from a child below the applicable threshold without verifiable parental consent, please contact us at elefnarin@gmail.com and we will delete the information within 30 days.
5.9 Regional and country-specific compliance
Depending on where you live, the following regional privacy laws apply to the information we collect. The list below is non-exhaustive; it covers every jurisdiction in which our apps are actively distributed as of the effective date of this policy.
- GDPR (EU/EEA). The General Data Protection Regulation (Regulation (EU) 2016/679) applies to personal data of individuals in the European Economic Area. Our lawful bases are consent (for advertising and analytics) and legitimate interest (for security, fraud prevention, and product operation). You have the rights listed in Section 5.13.
- UK GDPR and Data Protection Act 2018. The UK GDPR applies to personal data of individuals in the United Kingdom. We are regulated by the Information Commissioner's Office (ICO). The lawful bases and rights are aligned with the EU GDPR.
- CCPA / CPRA (California, USA). The California Consumer Privacy Act, as amended by the California Privacy Rights Act, grants California residents the rights to know, delete, correct, and opt out of the sale or sharing of personal information, and the right to limit the use of sensitive personal information. We honor all five rights, including a clearly labeled "Do Not Sell or Share My Personal Information" link on the Website and inside every app that displays advertising.
- VCDPA (Virginia, USA). The Virginia Consumer Data Protection Act grants Virginia residents rights to access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising and the sale of personal data.
- CPA (Colorado, USA). The Colorado Privacy Act grants similar rights, with effect from July 2023.
- CTDPA (Connecticut, USA). The Connecticut Data Privacy Act grants similar rights, with effect from July 2023.
- UCPA (Utah, USA). The Utah Consumer Privacy Act grants rights to access, delete, and opt out of targeted advertising and the sale of personal data.
- LGPD (Brazil). The Lei Geral de Proteção de Dados applies to personal data of individuals in Brazil. You have the rights listed in Section 5.13, and the data controller is N VoaWu Studio, with the data protection officer reachable at elefnarin@gmail.com.
- PIPEDA + Law 25 (Canada). The Personal Information Protection and Electronic Documents Act, as amended by Quebec's Law 25 (and similar provincial statutes), applies to personal data of individuals in Canada. You have the right to access and correct personal data, and Law 25 adds rights to data portability and de-indexation.
- PDPA (Singapore). The Personal Data Protection Act 2012 applies to personal data of individuals in Singapore. You may request access, correction, and withdrawal of consent.
- PIPL (China). The Personal Information Protection Law applies to personal data of individuals in the People's Republic of China. Where our apps are accessed from mainland China, we limit data collection to what is necessary and apply the consent, notice, and cross-border transfer rules required by PIPL. We do not currently target our apps at users in mainland China; if this changes, this section will be updated before any launch.
- Australia Privacy Act / OAIC. The Privacy Act 1988 and the Australian Privacy Principles apply to personal data of individuals in Australia. You may request access, correction, and complaint through the Office of the Australian Information Commissioner.
- India DPDP Act. The Digital Personal Data Protection Act, 2023 applies to personal data of individuals in India. You have rights to access, correction, erasure, grievance redressal, and the right to nominate another individual to exercise your rights.
- Japan APPI. The Act on the Protection of Personal Information applies to personal data of individuals in Japan. We comply with the rules on use, third-party provision, and cross-border transfer, including the requirement to obtain consent before transferring personal data outside Japan.
- South Korea PIPA. The Personal Information Protection Act applies to personal data of individuals in South Korea. We comply with the rules on collection, use, retention, and cross-border transfer, and we register required cross-border transfers with the Personal Information Protection Commission.
- California SB-976 (Protecting Our Kids from Social Media Addiction Act). Where applicable, our apps do not provide feed-style content to users we know to be under 18, and we do not use notification, autoplay, or other design patterns prohibited by the Act.
5.10 Age restrictions
The minimum age to use the Services is:
- 16 in the EEA and the UK, in line with the GDPR default and the UK Age-Appropriate Design Code.
- 13 in the United States, in line with COPPA.
- 13 in the United Kingdom for non-child-directed apps, with parental consent required for users below 16.
- The higher of 13 or the local minimum age in every other market where the Services are made available.
If you are below the applicable minimum age, you may use the Services only with the verifiable consent of a parent or legal guardian. We use a self-declaration flow inside every app that requests age and, where the user is below the threshold, blocks account creation and limits features to the maximum extent compatible with the platform's distribution rules. Parents or legal guardians may contact us at elefnarin@gmail.com to review, correct, or delete information collected from a child.
5.11 International data transfers
We are a European studio with team members and service providers in the European Economic Area, the United Kingdom, the United States, Canada, and Singapore. When we transfer personal data outside the country of collection, we rely on the lawful transfer mechanisms required by the destination country's privacy law, including:
- Standard Contractual Clauses (SCCs). For transfers from the EEA to third countries without an adequacy decision, we use the SCCs adopted by the European Commission, including the module-to-module variants for transfers between controllers and processors.
- UK International Data Transfer Agreement (IDTA). For transfers from the UK to third countries without an adequacy decision, we use the IDTA or the UK Addendum to the EU SCCs.
- Adequacy decisions. We rely on the European Commission's adequacy decisions where they apply (for example, for transfers to the UK, Canada (PIPEDA), Japan, and South Korea under the current adequacy framework).
- Supplementary measures. For transfers to third countries without an adequacy decision, we apply supplementary technical and organizational measures, including encryption in transit and at rest, access controls, and vendor due diligence.
5.12 Data retention
We retain personal data only for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Specifically:
- Account data is retained for the life of the account and deleted within 30 days of account closure, except where retention is required by law (for example, tax and accounting records).
- Usage and analytics data is retained for up to 24 months in identifiable form, after which it is aggregated or deleted.
- Ad data is retained by the ad partners listed in Section 5.5 according to each partner's own retention rules; we configure our own analytics windows at 13 months.
- Support communications are retained for up to 24 months from the last interaction.
- Backup copies of encrypted backups are retained for up to 90 days on a rolling basis.
5.13 User rights
You have the right to:
- Access the personal data we hold about you.
- Deletion of the personal data we hold about you, subject to the exceptions in applicable law.
- Correction of inaccurate or incomplete personal data.
- Portability of the personal data you have provided, in a structured, commonly used, machine-readable format.
- Opt out of targeted advertising at any time, on the device (Limit Ad Tracking on iOS, Opt out of Ads Personalization on Android) or by contacting us.
- "Do Not Sell or Share My Personal Information". California residents may exercise this right at any time via a clearly labeled link in the footer of the Website and inside the Settings → Privacy screen of every app that displays advertising. We do not sell personal information for monetary consideration, but we may share limited identifiers with the ad partners listed in Section 5.5 for cross-app advertising; the "Do Not Sell or Share" link covers those disclosures.
- Withdraw consent at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Lodge a complaint with a supervisory authority, in particular in the EEA member state of your habitual residence, place of work, or place of the alleged infringement.
To exercise any of these rights, contact us at elefnarin@gmail.com or use the in-app data request tool (Settings → Privacy → Manage my data). We respond within 30 days, or within the shorter window required by applicable law.
5.14 Cookies and tracking technologies on the Website
The Website uses the following cookies and local storage entries:
- Strictly necessary.
nvw_session(session cookie) andnvw_csrf(anti-CSRF token). These are required for the inquiry form and cannot be turned off. - Preferences.
nvw_lang(selected language) andnvw_theme(light / dark preference). These are optional; if you clear them, the site falls back to your browser language and the system theme. - Analytics. We use a privacy-respecting first-party analytics tool that does not require consent under the ePrivacy Directive for the collection of pseudonymous, aggregated statistics. We do not use Google Analytics on the Website.
- Marketing. We do not set marketing or advertising cookies on the Website.
You can manage cookies from the "Cookie settings" link in the footer, or by clearing cookies in your browser. The cookie banner is shown only to EEA and UK visitors, in line with the ePrivacy Directive; for all other visitors, the strictly necessary cookies are set without a prompt.
5.15 Security measures
We employ technical and organizational measures designed to protect personal data, including encryption in transit (TLS 1.2+ for all client-server communication) and at rest (AES-256 for primary storage), role-based access control for internal systems, two-factor authentication for production access, periodic vulnerability scanning, an incident-response process with a 72-hour notification window, and staff training on data protection. No system is perfectly secure; we will notify affected users and the relevant supervisory authorities of a personal data breach in line with our legal obligations.
5.16 Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page, post a notice in our apps for at least 30 days, and, for material changes, request renewed consent where required by applicable law. Your continued use of the Services after the effective date of the updated policy constitutes acceptance of the changes.
5.17 Contact
For any question, complaint, or data request related to this Privacy Policy, contact us at:
N VoaWu Studio
Email: elefnarin@gmail.com
Subject line: "Privacy"
We aim to respond to all privacy requests within 30 days.
5.18 Effective date
This Privacy Policy is effective as of 2026-01-15 and supersedes all previous versions.