- Studio
- N VaulNW ("N VaulNW", "we", "us", "our")
- Contact email
- yangkamiai@outlook.com
- Effective date
- August 26, 2026
- Last updated
- August 26, 2026
This Privacy Policy explains how N VaulNW collects, uses, discloses, and safeguards information when you use our websites, mobile applications, games, utility tools, and related services (together, the "Services"). It also explains the rights you have over your data and how to exercise them.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Services.
1. Who We Are and How To Reach Us
1.1 Data controller
N VaulNW is the data controller for personal information collected through the Services, except where a specific product or integration names a different controller.
1.2 Contact
- Email: yangkamiai@outlook.com
- Subject prefixes that help us route your request:
[Privacy],[DPA],[DSAR],[Deletion],[Children],[Legal].
1.3 Mailing address for formal correspondence
Available on request to verified legal counsel via the email above.
2. Scope of This Policy
2.1 What this policy covers
- Our websites, including nvaulnw.com and any subdomains we operate.
- Our mobile applications and games published on Google Play and the Apple App Store.
- Our utility tools and management app suite.
- Our advertising, marketing and analytics activities linked to the above.
- Our B2B and B2C services, where N VaulNW is the data controller.
2.2 What this policy does not cover
- Third-party websites, apps or services that we do not own or control, even if they are linked from our Services.
- Data you submit directly to an ad network, store, or other third party that we integrate with. Those parties have their own privacy notices, which we encourage you to read.
3. Information We Collect
3.1 Information you give us directly
- Account information: name, email, password (hashed), profile photo where you choose one.
- Support and correspondence: messages you send us, attachments, and the contents of any meeting notes you share.
- Payment and billing information: handled by our payment processors (for example, Stripe or Paddle). We do not store full card numbers on our servers.
- User-generated content: feedback, reviews, ratings, and content you upload to features that allow it.
3.2 Information collected automatically
- Device and log data: IP address, device model, operating system and version, locale, time zone, language, app version, build number, install ID, and crash logs.
- Usage data: screens viewed, features used, button taps, session length, retention and re-engagement events, in-app purchase events.
- Approximate location: country, region, and city derived from IP address, unless you explicitly grant precise-location permission in an app.
- Advertising identifiers: the Google Advertising ID (GAID) and the Apple Identifier for Advertisers (IDFA) where the relevant platform and your consent settings allow.
- Cookies and similar technologies: on our websites, we use first-party cookies and equivalent local storage to remember preferences, run analytics, and (with your consent) measure advertising performance.
3.3 Information from third parties
- Ad networks and mediation partners: aggregated reporting, eCPM data, viewability and fraud signals.
- Attribution and analytics partners: install attribution, in-app event attribution, and aggregated cohort data.
- Store platforms: basic publisher-facing data from Google Play and the Apple App Store.
3.4 Information we do not collect by default
- We do not collect information from children under 13 (or under the higher age defined by your jurisdiction, such as under 14 in parts of the EU/UK or under 18 in Brazil for certain processing). See section 9 for our children's data policy.
- We do not collect special categories of data (race, religion, health, sexual orientation, biometric data for the purpose of uniquely identifying you) through our consumer apps.
- We do not collect precise location from our consumer apps unless you grant explicit, in-app permission.
4. How We Use Your Information (Lawful Basis)
4.1 Purposes
- To provide and operate the Services — including account creation, authentication, in-app purchases, customer support, and the core functionality of each app or game.
- To improve and develop the Services — including bug fixing, performance tuning, A/B testing, and feature research based on aggregated usage data.
- To personalize your experience — remembering your preferences, language, and region, and (where applicable) recommending features or content.
- To deliver advertising — selecting, serving and measuring ads through our ad networks and mediation stack, subject to your consent and the platform settings described in section 7.
- To prevent fraud and abuse — detecting bots, click injection, install hijacking, and policy-violating behaviour.
- To comply with legal obligations — responding to lawful requests, maintaining financial records, and meeting store, tax, and regulatory requirements.
- To communicate with you — sending service messages, security alerts, and (where you have opted in) product updates and marketing.
4.2 Lawful basis under GDPR / UK GDPR
- Performance of a contract — for the service you have signed up for.
- Legitimate interests — for security, fraud prevention, product analytics, and aggregated reporting, balanced against your rights and freedoms.
- Consent — for non-essential cookies, advertising personalization, and any processing of personal data derived from advertising identifiers where the platform treats this as a consent event.
- Legal obligation — for tax, accounting, and compliance with law enforcement.
4.3 Lawful basis under LGPD
We rely on the equivalent bases provided for in the Lei Geral de Proteção de Dados, including consent, legitimate interests, compliance with legal obligations, and the regular exercise of rights in legal proceedings.
4.4 Lawful basis under CCPA / CPRA
For California residents, the CCPA/CPRA framework applies. We do not "sell" or "share" personal information as those terms are defined under California law without your right to opt out. See section 10 for the rights you have under California law.
5. Cookies, SDKs and Similar Technologies
5.1 Cookies on our websites
We use:
- Strictly necessary cookies — to keep you signed in and to remember your cookie preferences. These do not require consent.
- Analytics cookies — to understand aggregate traffic patterns. Set only with your consent.
- Advertising cookies — to measure campaign performance. Set only with your consent.
5.2 Mobile SDKs
In our apps we integrate SDKs from the partners listed in section 7. Each SDK may collect device and usage data as described in that partner's privacy notice and in this policy.
5.3 Your choices
- Manage cookie preferences via the cookie banner or your browser settings.
- Reset or limit advertising identifiers via your device settings (Google "Ads" settings on Android; "Tracking" settings on iOS).
- Use in-app privacy controls where we surface them.
6. Ad Monetization, Mediation and Ad Formats
6.1 What we do
We monetize many of our consumer apps through advertising. Ads are served directly by us and through third-party ad networks and mediation platforms. We use a layered approach: a managed waterfall plus in-app bidding to maximize yield while respecting user experience and policy.
6.2 Ad networks and mediation partners we work with
We work with the following networks and mediation platforms. The list is current as of the effective date of this policy; an up-to-date list is also published in the privacy section of each app where it is required.
- Google AdMob (Google LLC)
- Google Ad Manager (Google LLC)
- Meta Audience Network (Meta Platforms, Inc.)
- Unity Ads (Unity Technologies)
- AppLovin MAX (AppLovin Corporation)
- ironSource (now part of Unity)
- Pangle (ByteDance / TikTok)
- Mintegral (Mintegral International)
- InMobi (InMobi Technology Services)
- Chartboost (now part of Zynga / Take-Two via Digital Turbine affiliates)
- Vungle (now part of Liftoff)
- Digital Turbine (Digital Turbine, Inc.)
- AdColony (now part of Digital Turbine)
- Tapjoy (Tapjoy, Inc.)
- MyTarget (VK / Mail.ru Group)
- Smaato (Smaato, Inc.)
- Verizon Media / Yahoo (Yahoo Inc., now part of Verizon Media)
- Start.io (Start.io Inc.)
- Equativ (formerly Smart AdServer / SSPnet)
- Mobvista (Mobvista Inc.)
- Adikteev (Adikteev SA)
6.3 Ad formats we serve
- Rewarded video — users opt in to watch a video in exchange for an in-app reward. We always disclose the reward clearly.
- Interstitial — full-screen ads shown at natural transition points. We never show interstitials on first launch. We apply frequency caps (typically one per user per 60–120 seconds of app use) and avoid showing them during gameplay or while a user is completing a task.
- Banner — adaptive banners placed in non-intrusive positions. We do not place banners in ways that obscure content or trigger accidental clicks.
- Splash / App-Open — short ads shown on app launch. We provide a clear skip control, respect back-button behaviour, and never auto-redirect to the store.
6.4 Children and ads
We do not serve personalized advertising to users we know to be under 13 (or under the higher age defined by the user's jurisdiction). Where a product is clearly directed at children, we configure mediation to disable personalized ads and use only contextual, age-appropriate creatives supplied by TAG-certified child-directed networks. See section 9.
6.5 Consent and platform signals
- We honour the ATT (App Tracking Transparency) prompt on iOS. The IDFA is only accessed after you tap "Allow" on the ATT prompt.
- On Android, we honour the GAID opt-out and the platform-provided "Delete advertising ID" control.
- In the EU/EEA, UK and (for users in Brazil) Brazil, we surface a consent management platform (CMP) that meets IAB TCF v2.2 standards before we load any non-essential SDK or set any non-essential cookies.
7. Sharing and Disclosure of Your Information
7.1 Service providers
We share information with vetted processors who act on our instructions, including cloud hosting, email delivery, payment processing, customer support tooling, analytics, attribution, and ad mediation.
7.2 Ad networks and mediation partners
We share the data described in section 3.2 with the partners listed in section 6.2 for the purpose of serving and measuring ads. Each partner acts as an independent controller for the data it receives, subject to its own privacy notice.
7.3 Store platforms
We share information with Google Play and the Apple App Store as required to publish our apps, respond to reviews, and meet store policies.
7.4 Corporate transactions
If N VaulNW is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, your information may be transferred as part of that transaction. We will notify you of any such change.
7.5 Legal and safety
We may disclose information where we believe in good faith that it is necessary to:
- Comply with a valid legal process (subpoena, court order, search warrant).
- Enforce our Terms of Service.
- Protect the rights, property, or safety of N VaulNW, our users, or the public.
7.6 Aggregated or de-identified data
We may share aggregated or de-identified information with partners, industry analysts, and the public. Such data is not reasonably capable of identifying you.
8. International Data Transfers
8.1 Where your data is processed
N VaulNW is a global studio. Your data may be processed in the United States, the European Union, the United Kingdom, Brazil, Singapore, and other jurisdictions where our processors operate.
8.2 Transfer mechanisms
Where data is transferred across borders, we use appropriate safeguards, including:
- For EU/EEA → United States: the EU–US Data Privacy Framework where applicable, supplemented by Standard Contractual Clauses.
- For UK → United States: the UK International Data Transfer Addendum to the EU SCCs, or the UK–US Data Bridge where applicable.
- For Brazil: compliance with the LGPD transfer rules, including adequacy decisions, standard contractual clauses, or other mechanisms approved by the ANPD.
- For other jurisdictions: contractual and technical safeguards such as encryption in transit and at rest, access controls, and audit.
8.3 Your rights in respect of transfers
You can contact us to request more information about the safeguards we use for your specific transfer path.
9. Children's Privacy (COPPA, UK Age-Appropriate Design, EU Minors, LGPD)
9.1 Our general rule
N VaulNW does not knowingly collect personal information from children under 13 (the COPPA threshold in the United States) or under the higher age of digital consent in the user's jurisdiction, including:
- United Kingdom: under 13 (UK GDPR / Children's Code baseline).
- EU/EEA: member-state thresholds, typically 13–16, as defined by local law.
- Brazil: under 18 where consent is the lawful basis and under 13 for general personal data processing.
- California: under 13, with additional protections for under-16 users.
- Other jurisdictions: as defined by applicable local law.
9.2 What this means in practice
- We do not use our consumer apps to collect personal information from children under the applicable age.
- We do not serve personalized advertising to children. Where a product is child-directed, we serve only contextual ads from TAG-certified child-directed networks (for example, AdMob's "tag for child-directed treatment" or equivalent configuration).
- We do not enable chat, social, or other open-communication features in child-directed products without parental consent and age-gating.
9.3 Age-gating
Where a product's audience plausibly includes minors, we use an age gate that asks for date of birth or equivalent. Users below the applicable age are routed to a non-personalized, child-safe experience with no advertising identifiers and no third-party tracking.
9.4 If we learn we have collected data from a child
If we become aware that we have collected personal information from a child in violation of this policy, we will delete the data as soon as possible. Parents and guardians can contact us at yangkamiai@outlook.com with the subject [Children] to request deletion.
9.5 UK Age-Appropriate Design Code
For products likely to be accessed by children in the UK, we follow the Age-Appropriate Design Code: high privacy by default, no detrimental use of data, no nudging children to weaken privacy, no unnecessary profiling, and clear, age-appropriate language.
10. Your Rights and How To Exercise Them
10.1 Rights under GDPR and UK GDPR (EU/EEA and UK users)
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — request deletion in defined circumstances.
- Restriction — limit how we process your data while a complaint is resolved.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Objection — object to processing based on legitimate interests and to direct marketing.
- Withdraw consent — at any time, where processing is based on consent.
- Lodge a complaint — with your local data protection authority. For the UK, the ICO (https://ico.org.uk); for EU users, your national supervisory authority.
10.2 Rights under CCPA / CPRA (California users)
- Right to know what personal information we have collected, used, shared, or sold.
- Right to delete personal information we have collected from you, subject to defined exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing of personal information. N VaulNW does not "sell" personal information as traditionally understood under the CCPA. Some ad-tech integrations may be considered "sharing" for cross-context behavioural advertising; you can opt out via the in-app privacy controls and the "Do Not Sell or Share My Personal Information" link on our websites.
- Right to limit use of sensitive personal information — we do not collect sensitive personal information for purposes that would trigger this right in our consumer apps.
- Right to non-discrimination for exercising any of the above rights.
10.3 Rights under LGPD (Brazilian users)
- Confirmation of the existence of processing.
- Access to your data.
- Correction of incomplete, inaccurate, or outdated data.
- Anonymization, blocking, or deletion of unnecessary or excessive data.
- Portability.
- Deletion of personal data processed with consent.
- Information about public and private entities with which we have shared data.
- Information about the possibility of not providing consent and the consequences.
- Revocation of consent.
- Complaint to the ANPD (https://www.gov.br/anpd).
10.4 How to exercise your rights
Email us at yangkamiai@outlook.com with the subject [DSAR], [Privacy], or [Deletion]. To protect your data, we may need to verify your identity before acting on a request. Verification is limited to what is necessary to confirm you are who you say you are.
We respond to verifiable requests within the time limits set by the applicable law:
- GDPR / UK GDPR: within 1 month (extendable by 2 further months for complex requests, with notice).
- CCPA / CPRA: within 45 days (extendable by 45 days, with notice).
- LGPD: in a prompt and timely manner as required by the ANPD.
10.5 Account deletion
Where a product offers an account, you can request account deletion from within the app (typically under Settings → Account → Delete Account) or by emailing yangkamiai@outlook.com with the subject [Deletion]. We will:
- Confirm the request within 7 days.
- Verify your identity.
- Delete or de-identify your personal data within 30 days, except where we are required to keep it (for example, financial records for tax purposes) or where a short retention window is required for fraud prevention.
10.6 Authorized agents
Under the CCPA/CPRA, you may designate an authorized agent to make a request on your behalf. We will require proof of the agent's authorization and may still verify your identity directly.
11. Data Retention
11.1 General principles
We keep personal data only as long as necessary for the purposes described in this policy, or as required by law.
11.2 Typical retention windows
- Account data: for the life of the account, plus up to 30 days after deletion for backup propagation.
- Support correspondence: up to 3 years from the last interaction.
- Financial and tax records: as required by applicable tax law (typically 5–7 years).
- Server logs: up to 90 days, unless required for an active security investigation.
- Ad event data: up to 13 months, aligned with common industry practice and platform requirements.
- Aggregated analytics: indefinitely, in de-identified form.
11.3 Anonymization
Where data is no longer needed in identifiable form, we will either delete it or de-identify it so that it can no longer be associated with you.
12. Security
12.1 What we do
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS 1.2+) and at rest, role-based access controls, least-privilege engineering practices, audit logging, and regular vulnerability scanning.
12.2 What we cannot promise
No system is perfectly secure. We will notify affected users of material breaches without undue delay and as required by applicable law.
12.3 Your role
Use a unique, strong password for any account you create with us. Do not share your credentials. Tell us immediately if you suspect unauthorized access.
13. Automated Decision-Making and Profiling
13.1 Limited use
We do not make decisions about you that produce legal or similarly significant effects solely by automated means.
13.2 Where it does apply
We do use automated processing for:
- Ad selection and frequency capping.
- Fraud and abuse detection.
- Aggregated analytics and A/B test bucketing.
- Ranking of search results inside our apps.
These do not produce legal or similarly significant effects on you. You can object to ad-related profiling via the in-app privacy controls, your device's advertising settings, or the "Do Not Sell or Share" link on our websites.
14. Third-Party Services and Links
The Services may contain links to third-party websites, stores, or services we do not control. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy notices.
Third-party services we may link to or integrate with include app stores, payment processors, customer support tooling, and the ad partners listed in section 6.2.
15. Do Not Track and Global Privacy Control
We honour Global Privacy Control (GPC) signals as a valid opt-out of "sale" or "sharing" of personal information under the CCPA/CPRA. We also honour platform-level advertising opt-outs (Limit Ad Tracking on iOS, Opt out of Ads Personalization on Android) where they are technically compatible with our SDK integrations.
16. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top and, if the changes are material, we will provide additional notice — for example, by an in-app banner or an email to the address associated with your account.
Your continued use of the Services after the effective date of the updated policy means you accept the changes. If you do not agree, please stop using the Services and contact us about deleting your data.
17. Contact, Complaints and Data Protection Authority
17.1 Contact us
- Email: yangkamiai@outlook.com
- Subject prefixes that help us route your request:
[Privacy],[DSAR],[Deletion],[Children],[DPA],[Legal].
17.2 Right to complain to a supervisory authority
You have the right to lodge a complaint with your local data protection authority. Examples:
- EU/EEA: your national supervisory authority. A list is available from the European Data Protection Board at https://edpb.europa.eu.
- United Kingdom: the Information Commissioner's Office (ICO) at https://ico.org.uk.
- Brazil: the Autoridade Nacional de Proteção de Dados (ANPD) at https://www.gov.br/anpd.
- California: the California Privacy Protection Agency (CPPA) and the California Attorney General.
We would prefer the chance to address your concerns directly. Please contact us first.
18. Effective Date
This Privacy Policy is effective as of August 26, 2026.
End of Privacy Policy.