Home Legal Privacy Policy

Privacy Policy

Application: Mind Blazer Arcade Operator: Revive Solutions ("we", "our", "us") Effective Date: May 1, 2026 Last Updated: May 1, 2026 Contact: [email protected]


1. Introduction

Mind Blazer Arcade ("the App") is a fun mini-games arcade for kids, teens, and adults. Gameplay is personalized by mood check-ins, supported by quick resets, optional smart reads, and parent-supported routines.

We take the privacy of our users, especially our young users, extremely seriously. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you (and a parent or legal guardian, where applicable) have over that information.

This Policy is written to comply with the:

  • Children's Online Privacy Protection Act (COPPA), United States
  • General Data Protection Regulation (GDPR), European Union and United Kingdom (UK-GDPR)
  • California Consumer Privacy Act / CPRA (CCPA/CPRA), California, USA
  • Apple App Store Review Guidelines (including §5.1)
  • Google Play Families Policy and Data Safety Requirements

2. Who This Policy Applies To

User typeAccount model
Child (under 13)Account is created and managed by a parent or legal guardian. Verifiable parental consent is required before any personal data is collected.
Minor (13 to 17)Account may be created with parental supervision; certain features (camera-based mood detection, public sharing) require explicit parental approval.
Adult (18 and over)Account is self-managed.
Parent / GuardianLinked account with separate login and a dedicated dashboard.

3. Information We Collect

3.1 Information You Provide Directly

DataWhy we collect it
Email addressAccount login, password reset, transactional notices
Full name (or first name only for children)Personalisation in-app
Password (hashed; never stored in plain text)Authentication
Age range (for example 6 to 8, 9 to 12, 13 to 18, 19 and over), never exact birthdateAge-appropriate content gating
Gender (optional)Personalisation, optional
Custom avatar selectionsProfile personalisation
Self-reported mood (emoji, intensity slider, optional note up to 100 chars)Mood tracking and recommendations
Tasks, education progress, game progressCore app functionality
Support correspondenceCustomer support

3.2 Information Collected Automatically

  • Device information: OS, OS version, device model, app version, language, time-zone.
  • Usage data: Screens visited, games played, session length, crash logs, performance metrics.
  • Identifiers: A randomly generated installation ID. We do not use the IDFA (iOS) or Android Advertising ID for advertising.

3.3 Camera & Facial Mood Detection (Optional)

  • The App offers an optional facial-expression-based mood detection feature. The user opens this feature deliberately, sees an in-app explanation, and explicitly taps to capture a single still photo using the front-facing camera.
  • The still image is transmitted over TLS 1.2+ to our backend, where an emotion-classification model processes the image in memory only and returns one of seven mood labels (angry, disgust, fear, happy, neutral, sad, surprise) together with a confidence score.
  • The still image is never written to disk, never persisted in any database, never logged, and never retained. It exists only in process memory for the duration of a single inference request (typically under one second), after which the buffer is discarded.
  • Only the resulting mood label and confidence score are stored against the user's account, together with a timestamp. The image itself is not stored.
  • The image is not shared with any third party. The classifier runs on infrastructure we operate; no third-party face-recognition SDK or cloud service is used.
  • We do not perform identity recognition. We do not create a "faceprint", facial template, or biometric identifier. We do not match a face to any other person, account, or database. The model outputs a single mood label and nothing else.
  • The feature can be disabled at any time in Settings, Privacy, or by a parent in the Parental Dashboard. It is off by default for users under 13.

3.4 Microphone, Photos, Location

  • Microphone (Android MODIFY_AUDIO_SETTINGS): used only to manage in-game audio routing. We do not record audio.
  • Photo Library (iOS): used only if the user chooses to set a custom profile picture. Images stay on the device unless the user uploads them.
  • Location (iOS prompt): requested only for optional context-aware features. Currently unused for any active feature. Denying it does not affect the app.

3.5 Information We Do Not Collect

  • We do not create biometric identifiers, faceprints, or facial-recognition templates. The mood-detection feature classifies a transient still image into a mood label and discards the image.
  • We do not collect government IDs or passports.
  • We do not collect contacts, SMS, call logs, browser history, or files outside what the user explicitly attaches.
  • We do not collect precise (GPS) location.
  • We do not display third-party advertising and do not collect data for advertising purposes.
  • We do not sell or "share" personal information as those terms are defined under CCPA/CPRA.

4. How We Use Information

We use information solely to:

  1. Operate and secure the App and your account.
  2. Suggest games to play based on your mood and recent sessions.
  3. Generate progress charts (7-day mood timeline, weekly summaries).
  4. Send transactional emails (password reset, parental verification, weekly parent report, opt-out available).
  5. Comply with legal obligations.
  6. Detect, investigate, and prevent fraud, abuse, or technical issues.

We do not use personal data to:

  • Practice external AI/ML models.
  • Build advertising profiles.
  • Make consequential automated decisions about a user (no profiling under GDPR Art. 22).

5. Legal Bases for Processing (GDPR / UK-GDPR)

PurposeLegal basis
Account creation and authenticationPerformance of contract (Art. 6(1)(b))
Mood tracking, progress dashboardsConsent (Art. 6(1)(a)) and explicit consent for health-related data (Art. 9(2)(a))
Camera-based mood detectionExplicit, opt-in consent (Art. 9(2)(a)); the still image is processed in memory by our backend and immediately discarded; only the mood label and confidence score are retained
Parental verificationLegal obligation (Art. 6(1)(c))
Security, fraud preventionLegitimate interest (Art. 6(1)(f))
Customer supportPerformance of contract

6. Children's Privacy (COPPA & GDPR-K)

6.1 Verifiable Parental Consent

Before a child under 13 (or under the applicable digital-consent age in the EEA, generally 16, but as low as 13 depending on the Member State) can use the App:

  1. The parent creates the child's account.
  2. We verify parental identity using one of: a credit-card transaction of nominal value (refunded), a signed digital consent form, or a government-approved e-ID method.
  3. The parent receives the COPPA-required direct notice (a summary of what we collect and why, and how they can revoke consent).

6.2 Parental Rights

A verified parent can at any time:

  • View all personal information collected about their child.
  • Revoke consent and delete the account and all associated data.
  • Disable the camera-based mood detection feature.
  • Set daily time limits, quiet hours, or "study mode".
  • Export mood and game data as CSV or PDF.

6.3 No Behavioural Advertising

Mind Blazer Arcade does not show third-party ads, does not include in-app purchases for users under 13, and does not link out to external social networks.

6.4 Limited Disclosures

Personal information of a child is only disclosed to:

  • The verified parent/guardian.
  • Service providers (see §8) acting under contract and bound to confidentiality.
  • Authorities, where legally required.

7. Not Medical Advice

Mind Blazer Arcade is a casual arcade game, not a medical device. It does not provide medical advice, diagnosis, or treatment, and is not a substitute for the advice of a qualified professional. Mood and progress information is for in-app personalization and self-tracking only. If you're in distress, contact your local emergency services.


8. Service Providers (Sub-processors)

We rely on a small set of vetted vendors. Each is contractually bound to use data only on our instructions and to comply with COPPA / GDPR equivalent obligations.

VendorPurposeData sharedRegion
Google Firebase AuthenticationLogin & session tokensEmail, hashed UIDUS / EU
Google Sign-InOptional federated loginEmail, name, Google IDUS
Amazon Web Services / our self-hosted backendApp hosting, database, file storageAll app dataEU / US (region pinned)
SendGrid (or equivalent)Transactional emailEmail address, message bodyUS
Sentry / Crashlytics (crash reporting)Diagnose crashesDevice model, OS, stack trace (no personal data)US / EU

We do not integrate any advertising, analytics-for-advertising, or social-media-tracking SDK.


9. International Data Transfers

If data is transferred outside the EEA / UK, transfers are protected by the EU Standard Contractual Clauses (2021/914) and additional safeguards where required (e.g. encryption-in-transit and at-rest, IP-allowlisting for admin access).


10. Data Retention

Data categoryRetention period
Active account dataUntil the account is deleted
Mood entries, game sessionsUp to 24 months, then automatically aggregated/anonymised
Crash logs90 days
Support emails24 months from last contact
BackupsEncrypted backups rotated; oldest backup ≤ 35 days
Deleted accountsSoft-deleted for 30 days (recovery window), then permanently erased

11. Your Rights

Subject to your jurisdiction, you (or a verified parent) may:

  • Access the personal data we hold about the user.
  • Rectify inaccurate data.
  • Erase ("right to be forgotten") all data, see Account & Data Deletion.
  • Object to or restrict specific processing.
  • Port your data to another service (CSV or JSON export).
  • Withdraw consent at any time, without affecting prior lawful processing.
  • Lodge a complaint with a supervisory authority (EU: your national DPA; UK: ICO; California: CPPA).

To exercise any right, email [email protected]. We respond within 30 days (extendable by 60 days for complex requests, with notice).


12. Security

We apply industry-standard safeguards:

  • TLS 1.2+ for all data in transit.
  • AES-256 encryption for data at rest.
  • Bcrypt/Argon2 password hashing.
  • Role-based access control with audit logs.
  • Regular dependency, penetration, and OWASP Top 10 reviews.
  • Principle of least privilege for staff access.

No system is 100% secure; in the event of a breach affecting personal data, we will notify the relevant authority within 72 hours and affected users without undue delay, in accordance with applicable law.


13. Cookies & Local Storage

The mobile app uses local device storage (MMKV, AsyncStorage, Keychain/Keystore) to keep the user signed in and to cache settings and game configurations. The app does not use third-party advertising cookies. See the Cookie & Local Storage Policy.


14. Changes to this Policy

If we make material changes, we will:

  • Post the revised Policy in the App and on our website.
  • Notify registered users by email at least 14 days before the change takes effect.
  • For users under 13, request renewed parental consent if the change broadens the scope of data collection.

15. Contact

ChannelAddress
General privacy queries[email protected]
Data Protection Officer[email protected]
EU representative (Art. 27 GDPR)_to be designated upon EU launch_
PostalRevive Solutions, [Registered office address], India

If you believe a child's data has been collected without proper consent, contact us immediately at [email protected] and we will investigate and, if necessary, delete the data within 7 days.