App Privacy Policy
This Privacy Policy applies to all mobile and web applications developed and published by LZpreneur OÜ (hereinafter “the Company”), collectively referred to as “this App”. This includes but is not limited to:
- Who Is The Spy (The Gaming Product)
- Course Kit
- Any other applications using the same data processing structure
If you download or make purchases through third-party platforms (e.g., Apple App Store, Google Play), please also review those platforms’ privacy policies and terms of service.
1. Scope
This Policy describes how this App collects, uses, and protects data generated during your download, installation, and use.
Unless otherwise stated, the Company does not actively collect, transmit, or store any data that can directly identify you personally (e.g., name, email, or phone number) on our own servers.
2. Types of Data We Collect and Process
This App operates on a data minimisation principle, collecting only the limited data necessary for core functionality, purchase verification, troubleshooting, and ad serving:
2.1 Data Stored Locally on Your Device
- Usage records, settings, and content (e.g., course data, game sessions)
- Your selected plan status (trial, free, or one-time purchase)
This data is stored exclusively in your device’s local database and is not uploaded to any Company servers.
When you uninstall the App, all local data is deleted.
2.2 Purchase and License Verification Data
To confirm your purchase status and enable “Restore Purchases” functionality, this App may process the following via official platform mechanisms:
- Anonymous platform account identifiers (e.g., Apple ID or Google account anonymised ID), order ID, product ID, purchase status, and transaction time sent to App Store/Google Play for transaction validation.
- In Cloud Firestore, only essential technical data such as:
- Purchase order ID
- Platform info (iOS/Android/Web)
- Product ID and license status
- Anonymised device identifier (e.g., device ID or installation ID)
The App does not create user accounts on Company servers or use this data for marketing or user profiling.
When reinstalling or switching devices, you can use “Restore Purchases” to re-verify with Apple/Google and recover your license.
2.3 Firebase Anonymous Authentication (If Applicable)
Certain Apps use Firebase Authentication for anonymous sign-in to enhance system security and prevent malicious attacks (e.g., repeat purchase fraud or abnormal usage), enabling:
- Creation of an anonymous user ID without name, email, or other identifiable information
- Secure matching of your purchase and usage status across devices or reinstalls, preventing unauthorised access
This anonymous ID is generated and managed entirely by Google/Firebase. The Company does not combine it with directly identifying information or use it for marketing or tracking.
2.4 Crashlytics Error and Crash Information
For stability improvements and debugging, this App may use Firebase Crashlytics to collect:
- Technical crash/error logs (e.g., stack traces, line numbers)
- App version
- Device model and OS version
This data is used solely for error analysis and product improvement; it does not intentionally capture your in-app content or inputs.
2.5 Advertising and Third-Party Ad Identifiers (AdMob)
If using the free version, this App may display ads via Google AdMob. For ad serving and measurement, AdMob may process:
- Device ad identifiers (e.g., Google Advertising ID/IDFA)
- Ad cookies, online identifiers, and device info
- Basic interaction and impression records for ad delivery, performance measurement, and invalid traffic prevention
This data is handled by Google per its privacy policy and developer agreements, not used by the Company to identify you directly.
3. Purposes and Legal Bases under GDPR (EEA/UK)
For users in the EU/EEA or UK, processing of your data relies on the following GDPR bases:
3.1 Performance of Contract/Necessary for Services (Art. 6(1)(b) GDPR)
- Verifying and maintaining your purchase/license status
- Providing core App functionality (including anonymous sign-in and local settings)
- Responding to support requests and troubleshooting
3.2 Legitimate Interests (Art. 6(1)(f) GDPR)
- Ensuring App stability and security
- Aggregated/anonymised usage analysis for feature improvements
We balance these interests against your rights and freedoms.
3.3 Consent (Art. 6(1)(a) GDPR)
- Personalised ads or advanced AdMob/Analytics features require explicit opt-in consent via prompts, per Google and legal requirements.
- You can adjust ad tracking preferences in App settings or device system settings and withdraw consent anytime.
If refused/withdrawn, non-personalised ads may still appear, using only essential technical data.
4. Plan Types and Status Records
This App may offer:
- Time-limited trial: Full features, no ads
- Free version: Ads, limited features
- One-time purchase: No ads, full unlock
Your plan status is stored locally or via anonymised Firebase identifiers for license checks/“Restore Purchases”. It is not used for marketing lists or sold.
5. Third-Party Services and Processors
We use Google cloud services for certain features, where Google typically acts as a data processor under its Data Processing and Security Terms and EU SCCs:
- Firebase Authentication (anonymous sign-in)
- Cloud Firestore (limited technical/purchase data)
- Firebase Crashlytics (crash reports)
- Google AdMob/AdSense (ads/performance)
See Firebase/Google official privacy policies for details.
6. Data Retention
- Anonymous auth/purchase data: Retained as needed for license recognition/“Restore Purchases”; deleted/anonymised when no longer required.
- Crashlytics logs: Limited to Google/Firebase defaults (typically ~90 days) for debugging, then deleted/anonymised.
- Ad data: Per Google’s policies and legal requirements, with deletion/aggregation as applicable.
7. Your Rights (GDPR/Applicable Laws)
Subject to law, you may have rights to:
- Access/confirmation of your data
- Rectification of inaccurate/incomplete data
- Erasure (where no longer needed/no retention obligation)
- Restriction of processing
- Portability (structured/machine-readable format, if applicable)
- Object to legitimate interests processing
- Withdraw consent (no effect on prior lawful processing)
Note: Deleting/restricting purchase verification data may impact “Restore Purchases”. Contact us to exercise rights.
8. International Transfers and Security
Data for Firebase/AdMob may be processed/stored outside EU/EEA (e.g., Google servers). We use SCCs and other safeguards per GDPR.
Security measures include:
- HTTPS encrypted transmission
- Strict access controls/API key management
- Least-privilege access and regular audits
9. Children’s Data
Unless specified, this App is not for children under 16. We do not knowingly collect such data. Parents/guardians: contact us to request deletion.
10. Contact Us
For questions, requests, or complaints about this App’s privacy/data practices:
- Email: support@lzpreneur.io
EU/EEA/UK residents may complain to local data protection authorities if dissatisfied.
11. Policy Updates
We may update this Policy for service/tech/legal changes. Latest version posted here/in-App with effective date. Continued use post-update means acceptance.