Legal
Privacy Policy
This Privacy Policy applies to all games and services published by HouneTeam.
1. Summary
HouneTeam makes casual mobile games published on Google Play and the Apple App Store. To operate our games and improve them, we integrate third-party SDKs for analytics, crash reporting, advertising mediation, install attribution, push notifications, and cloud saves.
This Privacy Policy lists every category of data we or our integrated providers collect, what each provider does with it, how long we retain it, what choices you have, and who to contact. It applies to all HouneTeam games, including Lumo Idle Park, unless a specific game's store listing or in-app notice states otherwise.
HouneTeam is the data controller for the data collected through our games. Contact: info@houneteam.com. Jurisdiction: Japan.
2. Information we collect
2.1 Information you provide directly
- If you contact us by email, we receive your email address, the contents of your message, and any attachments you choose to send.
- On Android, if you sign into Google Play Games Services to enable cloud save, we receive your Play Games player ID and display name.
- On iOS, if you sign into Apple Game Center, we receive your Game Center player ID.
Sign-in is optional. Core gameplay does not require an account. We do not ask for your real name, postal address, or phone number.
2.2 Gameplay and telemetry events
Our games send anonymous gameplay events to Firebase Analytics so we can balance the game, find broken progression paths, and understand where players get stuck. Typical events include:
- Session number, session start time, and session duration.
- Whether a session ended normally or after an interruption or crash.
- Boost and power-up usage.
- First-launch time, total play time, upgrade levels, and the timing of unlocks or purchases.
- Which game objects were unlocked and when.
- Economy milestones (when a player reaches certain currency thresholds).
- Offline-income claim information (reward amount and offline duration).
- Return-to-game timing (how long a player was absent before re-opening the game).
- Ad outcome events: whether a rewarded ad was watched to completion, requested but unavailable, or skipped.
- In-app purchase events (product ID, success/failure — no card or bank information).
2.3 Information collected automatically by integrated SDKs
- Device model, operating system version, app version, language, approximate country or region, and time zone.
- Install source / install referrer where available.
- Pseudonymous identifiers used by analytics, attribution, and advertising SDKs (see §5 for the per-SDK list).
- Advertising identifiers: Apple IDFA on iOS (only when you have granted App Tracking Transparency permission) and Google Advertising ID (GAID) on Android (unless you have opted out at the OS level).
- Ad interaction data: ad requests, impressions, clicks, video completion, reward grants, and fraud-prevention signals.
- IP address, used in transit by service providers and converted to approximate geolocation at the city or country level.
- Crash and error reports collected by Firebase Crashlytics, including stack traces, exception types, device state at the time of the crash, app version, OS version, device model, and a Crashlytics installation UUID.
- Push notification tokens (APNs token on iOS, FCM token on Android) used to deliver push notifications via Firebase Cloud Messaging.
- A Firebase Installations ID used to identify the installation for analytics and remote config.
- A device-attestation result from Firebase App Check used to prevent backend abuse (no personal data is sent; only an attestation token derived from Play Integrity on Android or DeviceCheck / App Attest on iOS).
2.4 Information stored locally on your device
- Session snapshot data used to calculate offline income and restore gameplay state.
- Pending offline reward values until claimed.
- Local save state, game settings, language preference, and similar progression data.
- Cached Remote Config values used to override game balance without a new release.
3. How we use information
- To operate game systems, including offline income, cloud saves, and remote balancing.
- To diagnose crashes, ad-load failures, and performance issues.
- To analyze retention, progression, economy balance, and feature usage.
- To serve advertising, measure ad performance, attribute installs to ad campaigns, and prevent ad fraud.
- To deliver push notifications you have opted into.
- To process in-app purchases via the relevant platform store.
- To respond to your messages and to legal or platform requests.
- To comply with our legal obligations and enforce our Terms of Service.
Legal bases under GDPR are described in §11.
4. How we share information
We share data with the following categories of recipients:
- Service providers / processors — Firebase (Google), AppsFlyer, Unity LevelPlay (IronSource), and the ad networks listed in §5, acting on our instructions.
- Platform providers — Google (Play Store, Play Games Services, Play Billing) and Apple (App Store, Game Center, App Store payments) for distribution, sign-in, and purchase processing.
- Authorities when disclosure is required by law, regulation, or legal process, or to protect rights, security, or service integrity.
We do not sell personal information for money. Some of our advertising and measurement activities may qualify as "sharing" or "sale" under certain US state privacy laws because data is shared with ad partners for cross-context behavioral advertising; see §12 for how to opt out.
5. Third-party services and SDKs
The following SDKs are integrated into our games. We list each provider, what data is processed, and a link to that provider's own privacy policy.
5.1 Firebase (Google LLC / Google Ireland Limited)
- Firebase Analytics — usage events, Firebase Installations ID, device info, approximate geolocation.
- Firebase Crashlytics — crash stack traces, device state, Crashlytics installation UUID.
- Firebase Firestore — cloud saves, player profile, in-game gifts.
- Firebase Authentication — pseudonymous user ID used to bind cloud saves to your platform sign-in.
- Firebase Cloud Messaging (FCM) — APNs / FCM push tokens, message delivery receipts.
- Firebase Remote Config — fetches server-side game balance values; no personal data is sent beyond the Installations ID.
- Firebase App Check — device attestation token (Play Integrity / App Attest) to protect backend endpoints; no personal data leaves the device.
Links: Firebase Privacy and Security · Google Privacy Policy · Crashlytics Data Collection
5.2 AppsFlyer (AppsFlyer Ltd., Israel)
We use AppsFlyer for mobile measurement and install attribution.
- Apple IDFA (iOS, if ATT permission granted) or Google Advertising ID (Android).
- Install referrer (Android) or SKAdNetwork postback copy (iOS).
- IP address, used in transit to derive country and detect fraud.
- Device model, OS version, app version, language, time zone.
- In-app events you trigger (purchases, ad views, level completions) for measurement.
AppsFlyer's iOS Privacy Manifest declares the following tracking domains: app.appsflyer.com, events.appsflyer.com, register.appsflyer.com, sdk-services.appsflyer.com, appsflyer-skadnetwork.com.
Links: AppsFlyer Privacy Policy · AppsFlyer Services Privacy Policy · AppsFlyer Opt-Out
5.3 Unity LevelPlay / IronSource (ironSource Ltd., a Unity company)
We use Unity LevelPlay (formerly IronSource Mediation) to orchestrate ad delivery across multiple ad networks. The mediation SDK and the integrated ad networks process advertising identifiers and ad interaction data.
Mediated ad networks currently include:
- IronSource (Unity company) — direct ad serving.
- Unity Ads — bidder.
- Google AdMob — bidder.
Data processed by LevelPlay and the mediated networks: IDFA / GAID, ad opportunity context, bid responses, impressions, clicks, video completion, rewarded grants, IP address (in transit), device model, OS version, app version, and approximate geolocation.
Links: Unity Game Player and App User Privacy Policy · IronSource US State Privacy · AdMob Policies and Restrictions
5.4 Google Play Games / Apple Game Center
- On Android, Google Play Games Services handles optional sign-in. We receive Play Games player ID and display name.
- On iOS, Apple Game Center handles optional sign-in. We receive a Game Center player ID.
Links: Google Play Games Saved Games · Apple Privacy
5.5 In-app purchases
Purchases are processed by Google Play Billing on Android and by the Apple App Store on iOS. We receive a transaction ID and the receipt necessary to verify entitlement, but we do not receive your card number, bank details, or full billing address.
6. Advertising identifiers and ad personalization
6.1 iOS — App Tracking Transparency (ATT)
On iOS, before any third-party SDK accesses your Apple IDFA or links your activity across apps and websites for advertising or measurement, our games show the system App Tracking Transparency prompt. If you choose "Ask App Not to Track," AppsFlyer and our ad partners will not receive your IDFA and will rely on aggregated frameworks such as SKAdNetwork for measurement. You can change your choice at any time in Settings → Privacy & Security → Tracking.
6.2 Android — Advertising ID and Privacy Sandbox
On Android, our ad partners may use your Google Advertising ID for personalized advertising and measurement. You can reset or delete the advertising ID and opt out of personalized advertising in Settings → Google → Ads (or Settings → Privacy → Ads, depending on the device). On devices that support Android Privacy Sandbox, the platform may further constrain or replace ID-based targeting.
6.3 Consent for personalized advertising (EEA / UK)
In the EEA, the UK, and other regions where consent is required, our games display a consent message before personalized advertising or non-essential analytics. You can change your choice at any time through the in-game privacy settings, where available, or by reinstalling the app.
7. Push notifications
If you allow notifications, our games use Firebase Cloud Messaging (FCM) to deliver them. FCM stores your APNs token (iOS) or FCM token (Android) so it can route messages to your device. You can disable notifications at any time in the system settings:
- iOS: Settings → Notifications → [game name]
- Android: Settings → Apps → [game name] → Notifications
8. Cloud saves
Cloud saves are optional. If you do not sign in, your progress remains only on your device.
- Android: after you sign into Google Play Games Services, save data is written to Firebase Firestore under a Firebase Authentication user ID linked to your Play Games account. Saved data includes progression, currencies, upgrade state, and timestamps.
- iOS: after you sign into Apple Game Center, save data is written to Firebase Firestore under a Firebase Authentication user ID linked to your Game Center player ID. Saved data is the same as on Android.
HouneTeam does not use Apple CloudKit / iCloud for cloud saves. All cloud-save data is stored in Firebase Firestore (Google Cloud).
9. Data retention
- Local save and offline-income data — stored on your device until the app is uninstalled or app storage is cleared.
- Cloud saves in Firestore — retained while the linked account exists so you can resume later. On request to info@houneteam.com, we delete the record within 30 days.
- Firebase Analytics events — retained for up to 14 months by default; aggregated, non-identifying reports may be retained longer.
- Firebase Crashlytics — crash records retained for up to 90 days.
- FCM push tokens — kept until the token is revoked, the app is uninstalled, or the token rotates.
- AppsFlyer attribution data — retained according to AppsFlyer's standard retention (typically up to 24 months for raw data; longer for aggregated reports). See the AppsFlyer policy linked in §5.2.
- Ad-network logs (LevelPlay, IronSource, Unity Ads, AdMob) — retained according to each network's own policy linked in §5.3.
- Email correspondence — retained for up to 24 months after the last reply, unless a longer period is required for legal or accounting reasons.
- Purchase receipts — retained as long as required by tax and consumer-protection law (typically 7 years in Japan).
10. International transfers and processing locations
HouneTeam is based in Japan. Our service providers process data in multiple regions, including the United States, the European Union, Ireland, Israel (AppsFlyer, IronSource), and other jurisdictions. Where data leaves the EEA, UK, or Switzerland, transfers rely on the European Commission's Standard Contractual Clauses (SCCs), the UK's International Data Transfer Addendum, or another lawful transfer mechanism offered by the relevant provider. Each provider's privacy policy describes its specific safeguards (see §5).
11. Your rights under GDPR (EEA, UK, Switzerland)
Data Controller: HouneTeam, Japan. Contact: info@houneteam.com.
Legal bases we rely on:
- Performance of a contract — to operate the game you have installed and to process purchases.
- Legitimate interests — to diagnose crashes, prevent fraud, secure our backend, and conduct aggregated analytics that does not materially affect your privacy.
- Consent — for personalized advertising, attribution involving IDFA / GAID, non-essential analytics, and push notifications. You can withdraw consent at any time through the in-game settings or the device controls described in §6 and §7.
- Legal obligation — to retain purchase and tax records and to respond to lawful authority requests.
Your rights: access, rectification, erasure, restriction, portability, and objection. You also have the right to lodge a complaint with your local supervisory authority in the EU or with the UK Information Commissioner's Office (ICO).
To exercise any right, email info@houneteam.com from the address associated with your request. We respond within 30 days. If you are in the EEA and need an EU representative under Article 27 GDPR, contact us and we will share current representative details where one is appointed.
12. Your rights under California (CCPA / CPRA) and other US state laws
If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. Comparable rights exist for residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other US states with comprehensive privacy laws.
Categories of personal information we may collect, by Cal. Civ. Code §1798.140(v):
- Identifiers — IDFA, GAID, Firebase Installations ID, IP address, Play Games / Game Center player ID, Firebase Auth user ID, email address (if you contact us).
- Commercial information — in-app purchase records (product, timestamp, transaction ID).
- Internet or other electronic network activity — gameplay events, ad interactions, in-app interactions.
- Geolocation — approximate (city / country level) derived from IP address. We do not collect precise geolocation.
- Inferences — segments and audiences derived from gameplay events for analytics and advertising.
We do not knowingly collect sensitive personal information as defined in §1798.140(ae) (such as government identifiers, precise geolocation, biometric or health data, or the contents of mail / email / text messages not directed to us).
"Sale" / "Sharing": we do not sell personal information for money. We may "share" personal information with ad partners for cross-context behavioral advertising as that term is defined under CCPA. To opt out of this sharing, use the in-game privacy settings where available, or contact info@houneteam.com. On iOS, choosing "Ask App Not to Track" in the ATT prompt also opts you out for that device.
Rights: to know, to delete, to correct, to limit use of sensitive personal information (where applicable), to opt out of sale / sharing, and to non-discrimination. To exercise a right, email info@houneteam.com. We will respond within 45 days.
13. Children's privacy
Our games are not directed to children under 13 (or under 16 where applicable, such as in parts of the EEA). We do not knowingly collect personal information from children. If you believe a child has provided personal information through our games, please contact info@houneteam.com and we will review and, where appropriate, delete the information.
14. Security
We take reasonable technical and organizational measures to protect data, including HTTPS / TLS in transit, Firebase Security Rules for Firestore, and Firebase App Check for backend abuse prevention. No method of storage or transmission is completely secure; we encourage you to keep your device, operating system, and game up to date.
15. Changes to this Privacy Policy
We may update this Privacy Policy. The effective date at the top of this page reflects the latest version. Material changes will be communicated through the game, the store listing, or another appropriate channel before the change takes effect, where required.
16. User data deletion
You can ask us to delete the data associated with your game account at any time. This section explains how to request deletion, what gets removed, and what stays.
16.1 How to request deletion
Email info@houneteam.com with the subject line Data deletion request and include:
- The game (for example, Lumo Idle Park).
- Your platform (Android or iOS).
- Your sign-in identifier where available — Google Play Games player ID or in-game display name on Android, Apple Game Center player ID or display name on iOS.
If you never signed into Play Games or Game Center, your progress lives only on the device and uninstalling the game removes it.
16.2 What we delete
- Your cloud-save document in Firebase Firestore (progression, currencies, upgrade state, gift records).
- Your Firebase Authentication user ID linked to your Google Play Games or Apple Game Center sign-in.
- The pseudonymous profile we maintain for cloud saves and in-game gifts.
- Email correspondence tied to the deletion request once the request is closed, subject to the retention limits in §9.
16.3 What we cannot delete on your behalf
- Local data on your device — uninstall the game to remove it.
- Logs held by third-party processors (Firebase Analytics, Crashlytics, AppsFlyer, Unity LevelPlay and the mediated ad networks). To exercise rights against those providers directly, use the links in §5.
- Purchase records retained by Google Play or the Apple App Store, and tax / accounting records we are legally required to keep (see §9).
16.4 Timeline
We acknowledge requests within 7 days and complete the deletion within 30 days of confirming your identity, unless a longer period is required by law. If we cannot fulfil the request we will tell you why.
17. Contact
HouneTeam
Japan
info@houneteam.com