Privacy Policy
MomoSigns, a mobile application published by Mno Go Apps LTD

Effective date: 31.07.2026 · Last updated: 31.07.2026 · Version: 1.0

1. Who we are and how to contact us
1.1 The two companies behind the App
Two companies are responsible for the App and for the personal data described in this policy. In this policy "we", "us" and "our" mean both of them together.

Mno Go Apps LTD — the publisher. A company incorporated in Cyprus under registration number 10409188202005251, with its registered office at 27, 25 Martiou, D. MICHAEL TOWER, Office 105A, Egkomi, 2408 Nicosia, Cyprus. It is the account holder named on both store listings — the field Google Play labels "Developer" — it holds the store accounts, and it holds the accounts with AppLovin and with every other advertising partner named in Annex A.

LLC Karfarol Games — the developer. A company incorporated in Georgia (the country) under identification number 405653430, with its registered office at Tbilisi, Vake District, Z. Paliashvili str., N41, Georgia. It builds the App and its learning content, and holds the accounts for Firebase (Analytics, Crashlytics, Remote Config and Cloud Messaging) and for Singular.

1.2 Joint controllers — who is responsible for what
Under Article 26 of the GDPR the two companies are joint controllers: we decide together why and how your personal data is processed. We have a written arrangement between us allocating our responsibilities, and this section is the essence of it, published as Article 26(2) requires.

Processing

Who decides and holds the accounts

Distribution of the App through the stores

Mno Go Apps LTD

Advertising: AppLovin MAX mediation and every partner in Annex A; the consent screen and its configuration

Mno Go Apps LTD

Product analytics, A/B experiments, crash reporting and push notifications through Firebase

LLC Karfarol Games

Marketing attribution through Singular

LLC Karfarol Games

The content of this policy, security measures and responses to your requests

Both, acting together


This does not make things harder for you. Article 26(3) of the GDPR gives you the right to exercise your rights against each of us, and we have agreed that Mno Go Apps LTD is the single point of contact for every privacy request, whichever company holds the data. You never need to work out which company to write to: send everything to f@karfarol.com and it will be dealt with.

1.3 How to reach us

Purpose

Contact

Privacy questions, data subject and consumer requests

f@karfarol.com

App support and bug reports

f@karfarol.com

Legal, intellectual property, complaints

f@karfarol.com


Our representative in the United Kingdom (appointed under Article 27 of the UK GDPR, because both companies are established outside the UK and offer the App to users in it): f@karfarol.com

We do not need a representative in the European Union. Mno Go Apps LTD is established in Cyprus, and the processing described in this policy — including the processing decided by LLC Karfarol Games — is carried out in the context of that establishment's activities. The GDPR therefore applies to both of us under Article 3(1) and Article 27 does not apply. You can reach a controller inside the Union at the Cyprus registered office given in Section 1.1.

Neither company has appointed a Data Protection Officer. Privacy matters are handled by the contacts above.

2. What this policy covers
This policy applies to the mobile application Silent Words Learner, published on the Apple App Store and Google Play (the "App").
It explains what personal data is collected when you use the App, why, who receives it, how long it is kept, and what rights you have.
This policy does not cover:
  • our website;
  • the App Store and Google Play themselves. Apple and Google collect data about your downloads under their own privacy policies, and we have no control over that;
  • the websites, offers and services of advertisers whose ads appear in the App;
  • third-party services you reach by tapping a link in the App;
  • our other applications, each of which has its own policy.
3. Age: the App is for adults
The App is intended solely for people aged 18 and over, as stated in our Terms of Use. It is not directed to children, is not designed for children, and is not distributed in Google Play's Designed for Families programme or Apple's Kids Category.
We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete what we hold and take the steps available to us, which may include ending the licence to use the App. If you believe a person under 18 has used the App, please write to f@karfarol.com.
Because the App has no accounts and asks for no personal details, we have no way of verifying age beyond the age rating and the store's own controls. See also Section 17.

4. What we do not do
To make the rest of this policy easier to read, here is what we deliberately do not do:
  • We do not operate user accounts, logins, profiles or cloud saves.
  • We do not ask for or collect your name, postal address, telephone number or date of birth. We hold an email address only if you choose to write to us (Section 6.7).
  • We process no payments at all. The App is free, contains no in-app purchases and no subscriptions, and we never collect payment card numbers, bank details or billing addresses.
  • We do not use the microphone, camera, photo library, contacts, calendar, files, SMS or call logs. The App does not request these permissions.
  • We do not collect precise (GPS) location.
  • We do not upload the contents of your saved progress, your custom word lists or any display name you enter in the App.
  • We do not run user-to-user chat, messaging, public leaderboards, or any other user-generated content feature.
  • We do not use your personal data to train our own artificial intelligence models, and we do not send it to a general-purpose AI service.
  • We do not sell personal data for monetary consideration.
5. Data that stays on your device
The following is stored on your device. We hold no copy of it, it is not uploaded to us, and we cannot access, recover or restore it:
  • your saved learning progress, streaks, statistics and completed lessons;
  • your selected languages and courses, including any downloaded content, and your settings;
  • any display name or custom word list you enter in the App;
  • your balances of in-game currency, hints and boosters — all of them earned by playing or by watching optional rewarded ads, since nothing in the App can be bought.
Separately from this stored file, our analytics SDKs send us events about your activity — for example that a lesson was completed or a streak was reached — tied to a device identifier. Those events are described in Section 6.2 and are not the same thing as the progress data above.
Deleting the App, resetting your device, or switching to a different device erases the data stored on your device. Because we hold no accounts and no server-side copy, progress and in-game balances cannot be recovered or transferred at all.

6. Personal data we and our partners collect
Some data is transmitted off your device by the third-party software development kits ("SDKs") built into the App — for analytics, crash reporting, attribution and advertising. Under privacy law this counts as collection by us as well as by those partners, even where we only ever see it in aggregate.
Much of this data does not identify you by name, but because it is tied to a device or advertising identifier it is treated as personal data under the GDPR, the UK GDPR and US state privacy laws, and we treat it accordingly.

6.1 Identifiers and device data

Data

Detail

Advertising identifier

The Google Advertising ID (Android) or Identifier for Advertisers / IDFA (iOS). On iOS the IDFA is only available if you allow tracking through the App Tracking Transparency prompt; otherwise it reads as zeros. On Android you can delete or reset it in your device settings.

App-scoped and vendor identifiers

The Firebase app instance and installation IDs, the Singular device identifier, the AppLovin-generated device identifier, and on iOS the Identifier for Vendor (IDFV). These are specific to the App and are regenerated if you reinstall it.

Device and technical data

Device model and manufacturer, operating system and version, screen size and orientation, language and locale, time zone, network connection type, mobile carrier, App version and build, and whether the device appears to be rooted or emulated.

IP address

Received automatically whenever the App or an SDK connects to the internet. Used for delivery, security and fraud prevention, and to derive approximate location (Section 6.6).


Why: to run and secure the App, to serve and cap advertising, to measure installs and campaign performance, and to produce aggregate product analytics.

6.2 App activity and gameplay events
Events such as App opens and session length, screens viewed, lessons and mini-games started and completed, exercises answered, languages selected, streaks and progress milestones, settings changed, and feature usage.
These are events — a record that something happened, with a timestamp and a device identifier. They are not a copy of your saved progress, and they do not include free text you have typed into the App.
Why: to understand how the App is used, to fix what does not work, to decide what to build next, and to run A/B experiments on features through Firebase Remote Config.

6.3 Advertising data
Ad requests, impressions, clicks, video completions, rewarded-ad rewards, ad placements and formats shown, ad revenue attributed to your device, frequency-capping data, and signals our advertising partners use to select, deliver, cap and measure ads. Where you have consented to personalised advertising, our partners may combine this with data they hold about your device from other apps and services.
Why: advertising is the App's only source of revenue — it is what pays for the App to exist and to stay free — and we also use this data to measure whether our own advertising works.

6.4 Diagnostics and crash data
Crash stack traces, exception reports, ANRs and freezes, performance and load-time metrics, error logs, and the device state at the moment of a crash. Collected through Firebase Crashlytics.
Why: to find and fix defects and to keep the App stable.

6.5 Push notifications
If you allow notifications, Firebase Cloud Messaging generates a push token for your installation of the App. We use it to send you learning and streak reminders, and — if you have separately opted in — occasional messages about features or changes to the App.
Notifications are optional. You can turn them off at any time in your device settings or in the App, and no feature of the App depends on them being switched on.

6.6 Approximate location
We do not collect precise location and do not request location permission. Our partners derive an approximate location — typically country, and sometimes region or city — from your IP address.
Why: to comply with the privacy rules that apply where you are, to show content in the right language, to select appropriate ads, and to detect fraud.

6.7 Support correspondence
If you write to us, we receive your email address, the contents of your message, and whatever you choose to include — often a device model, App version or screenshot. We use it only to answer you and to fix the problem, and we keep it for 4 years.

7. Purposes and legal bases
If you are in the EEA, the UK or Switzerland, we must have a legal basis for each use of your personal data. These are ours:

Purpose

Legal basis

Providing the App and its content

Performance of a contract (our Terms of Use), Art. 6(1)(b) GDPR

Storing information on, and reading information from, your device for analytics and advertising

Your consent, Art. 5(3) of the ePrivacy Directive, given through the consent screen

Personalised advertising and advertising measurement

Your consent, Art. 6(1)(a) GDPR

Serving non-personalised advertising, frequency capping and ad fraud prevention

Your consent under Art. 5(3) ePrivacy for the storage and access on your device, and legitimate interests, Art. 6(1)(f) GDPR — funding a free App — for the subsequent use of that information

Product analytics, A/B experiments and crash reporting

Your consent under Art. 5(3) ePrivacy, and legitimate interests, Art. 6(1)(f) — understanding and improving the App

Sending learning and streak reminders

Your consent, given through the notification permission and the reminder settings in the App

Sending promotional messages about features and changes

Your consent, given through a separate opt-in in the App which you can withdraw at any time

Security, anti-fraud, and preventing manipulation of advertising and of rewarded-ad mechanics

Legitimate interests, Art. 6(1)(f) — protecting the App from abuse

Answering support requests

Performance of a contract and legitimate interests, Art. 6(1)(b) and (f)

Keeping records required by tax, accounting and consumer law

Legal obligation, Art. 6(1)(c)


Where the legal basis is performance of a contract, Art. 6(1)(b), the controller relying on it is Mno Go Apps LTD, the party to our Terms of Use. LLC Karfarol Games relies on your consent and on legitimate interests for the processing allocated to it in the table in Section 1.2.
Where we rely on legitimate interests, we have weighed those interests against your rights, kept the data to what is necessary, and you may object at any time (Section 16.1). Where we rely on consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of what was done before.
Advertising is not a condition of using the App. You can refuse consent to personalised advertising and to analytics and still use every feature of the App. You will still see advertising — non-personalised advertising — because advertising is how the App is funded and there is no paid, ad-free version of it.

8. Advertising and your choices
8.1 How ads are served
The App shows banners, interstitials, native placements and optional rewarded videos. We use AppLovin MAX as our advertising and mediation platform, together with the additional advertising networks and exchanges listed in Annex A. Mediation means several networks compete for each ad slot, so the network that fills a given ad may differ from one impression to the next.
Ads are of two kinds:
  • Personalised (interest-based) ads are selected using your advertising identifier and data our partners hold about your device, including from other apps. These are shown only where you have given the consent required by the law that applies to you.
  • Non-personalised ads are selected from context and coarse signals such as country and App content. They still involve limited data processing — including for frequency capping, fraud prevention and reporting — but do not use your advertising profile.
Rewarded ads are always optional: you choose to watch one in exchange for an in-game reward.
There is no ad-free version. The App contains no purchases and no subscriptions, so there is no way to pay to remove advertising. Everyone sees ads; your choices decide whether they are personalised.

8.2 European Economic Area and United Kingdom
In the EEA and the UK — and in any other country where we have enabled the same screen — the App shows a consent screen before any advertising or analytics SDK stores information on, or reads information from, your device. The screen is provided by a Google-certified consent management platform integrated with the IAB Transparency and Consent Framework (Google's User Messaging Platform). There you can accept or refuse the storing of information on your device and the use of your data for advertising and analytics.
If you refuse, you will still be able to play, and you will still see ads — but non-personalised ones.

8.3 iOS — App Tracking Transparency
On iOS, before any tracking begins, the system asks you to Allow or Ask App Not to Track. If you do not allow it, your IDFA is not available to us or to our partners, and we do not permit them to link your data with data collected from other companies' apps and websites for advertising purposes. Apple's App Tracking Transparency rules and our agreements with those partners prohibit it.
You can change this choice at any time in Settings → Privacy & Security → Tracking on your device. No feature of the App depends on it, and we do not offer any reward for allowing tracking.

8.4 Android — advertising ID controls
In Settings → Google → Ads on your device you can delete your advertising ID, reset it, or opt out of ads personalisation. If you delete it, apps receive a string of zeros instead.

8.5 Changing your mind
In the App: open Settings → Privacy. There you can switch personalised advertising off, and — where the consent screen applies to you — reopen it and change any choice, including withdrawing consent entirely.
Withdrawing consent stops future processing. It does not delete data already collected — for that, make an erasure request under Section 16.

9. Analytics, attribution and the events we send
We use two categories of measurement partner:
  • Firebase (Google) — Analytics, Crashlytics, Remote Config and Cloud Messaging. Product analytics, crash reporting, A/B experiments and push notifications. The Firebase project is held by LLC Karfarol Games, and Google acts as its processor.
  • Singular (Singular Labs, Inc.) — mobile measurement and attribution. Tells us which marketing campaign led to an install and how those users behave afterwards, so we can measure what our advertising is worth. The Singular account is held by LLC Karfarol Games, and Singular acts as its processor.
The advertising accounts, by contrast, are held by Mno Go Apps LTD (Section 8 and Annex A).
Both receive device and advertising identifiers, App and device data, and the gameplay and advertising events described in Section 6, subject to your consent choices. Because the App has no purchases, no purchase, subscription or revenue-per-user events are sent; the only revenue signal is ad revenue attributed to a device by our mediation platform.
We do not attach any age category, parental-consent status, health, financial or biometric data to these events, and we do not send free text you have typed into the App.

10. The App is free — there are no payments
The App costs nothing, contains no in-app purchases and no subscriptions, and has no paid tier.
  • We have no billing relationship with you, hold no order history, and process no payment data of any kind. Neither Apple nor Google sends us any purchase or subscription record for this App, because there is none.
  • There is no "Restore Purchases" function, because there is nothing to restore.
  • Everything you unlock in the App is earned by playing or by watching an optional rewarded ad, and is stored on your device (Section 5).
If we ever introduce paid features, we will publish an updated policy describing the data involved before those features become available, with the notice period in Section 19.

11. Who we share data with 11.1 Categories of recipients
Advertising networks, exchanges and mediation platforms — to select, deliver, cap and measure ads. Contracted by Mno Go Apps LTD and named in Annex A.
  • Analytics and attribution providers — Google (Firebase) and Singular, contracted by LLC Karfarol Games.
  • Each other. The two companies described in Section 1 share this data between themselves so that each can do its part. That involves personal data reaching LLC Karfarol Games in Georgia — see Section 13.
  • Cloud and infrastructure providers — hosting for the systems on which we receive and analyse reports.
  • The app stores — Apple and Google, in connection with distribution of the App.
  • Professional advisers — accountants, auditors and lawyers, where necessary and under a duty of confidentiality.
  • Authorities and courts, where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims, or to protect the rights and safety of users or the public. We will not disclose more than the law requires.
  • A buyer or successor, if our business or the App is sold, merged or reorganised. Where this happens we will update this policy and, where the law requires it, give notice in the App before your data becomes subject to a different privacy policy.
Apart from these recipients, we do not share your personal data ourselves. Where an ad is filled through a real-time auction, the exchange concerned passes the ad request — including your advertising identifier, IP address and approximate location — to the demand partners bidding in that auction. Those partners are identified in that exchange's own vendor list, published on the exchange's site and reachable from the privacy policy linked in Annex A, and in the vendor list shown in the consent screen.

11.2 Protection by third parties
We share personal data only with third parties that are bound — by the data protection terms one of our two companies has accepted with each of them, and by the Apple and Google developer programme policies they participate in — to protect user data to a standard at least equal to the one described in this policy and required by those programmes.
Firebase and Singular act as processors for LLC Karfarol Games: they use the data only for the purposes it instructs, under the Firebase Data Processing and Security Terms and Singular's data processing terms respectively.
Our advertising partners act as independent controllers. Mno Go Apps LTD contracts with them and accepts each partner's data protection terms, but they use the data for the purposes set out in their own privacy policies, which are linked in Annex A. We do not integrate an SDK partner whose published terms fall below the standard above, and we remove SDK partners that do. Where an exchange passes the ad request to demand partners bidding in a real-time auction, we do not select those partners individually; they are bound by that exchange's participation terms and appear in its vendor list.
We cannot control what an advertiser does on its own website after you tap its ad; that is between you and the advertiser.

11.3 The partners themselves
Annex A names every advertising, analytics and attribution SDK integrated into the App, with a link to its privacy policy and, where one exists, its opt-out mechanism. In the EEA and the UK, the consent screen also lists the partners registered under the IAB Transparency and Consent Framework and lets you decide about them.
12. Selling and sharing of personal dataWe do not sell personal data for money.
However, several US state privacy laws define "sale" and "sharing" broadly enough to include the disclosure of identifiers and advertising data to advertising partners for cross-context behavioural advertising, even where no money changes hands. On that broader definition:
  • We share, and may be deemed to sell, the following categories to our advertising partners for personalised advertising and advertising measurement: identifiers (advertising ID, device and installation identifiers, IP address), internet and app activity, advertising data, approximate location and inferences drawn from them.
  • We do not sell or share the contents of your support correspondence.
  • We do not knowingly sell or share the personal data of anyone under 18.
Do Not Sell or Share My Personal Information. Open Settings → Privacy in the App and switch off Personalised ads. That single control opts you out of sale, of sharing for cross-context behavioural advertising, and of targeted advertising. You can also refuse or withdraw consent on the consent screen, opt out of tracking on iOS, or email f@karfarol.com and we will apply it for you. There is no charge and no penalty: every feature of the App works the same either way, and you will continue to see non-personalised ads.
Sensitive data. We do not deliberately collect special categories of data under the GDPR or sensitive personal information under US state law, and we do not use any signal to label users by ethnicity, nationality, religion or health. The languages you choose to study are collected as app-activity data; we do not treat them as an indicator of your origin and we do not ask our partners to do so.
Opt-out preference signals. Global Privacy Control and similar universal signals are browser technologies; there is currently no reliable equivalent inside a native mobile app. The in-App and device controls above are the mechanism we provide.

13. International data transfers
Our two companies sit in different countries, and our partners operate globally, so your personal data is transferred across borders — including outside the EEA and the UK, to countries whose data protection laws differ from yours.
Depending on which partner serves a given ad or processes a given event, the destinations include Cyprus, Georgia, the United States, Ireland, Singapore, India, Israel, Hong Kong SAR, China and Russia. Annex A identifies where each partner is based.
Between our own two companies. Mno Go Apps LTD is in Cyprus, inside the EEA. LLC Karfarol Games is in Georgia, which is not covered by an adequacy decision of the European Commission or the UK government. Personal data therefore leaves the EEA when we share it between us, and also when the analytics, crash and attribution data collected from your device is made available to LLC Karfarol Games in Georgia through the Firebase and Singular accounts it holds. For both routes we have signed the European Commission's Standard Contractual Clauses (controller-to-controller module) and, for UK data, the International Data Transfer Addendum, and we have carried out a transfer impact assessment.
To our processors. Firebase and Singular process on behalf of LLC Karfarol Games under terms that incorporate the Standard Contractual Clauses or, where the receiving entity is certified, the EU–US Data Privacy Framework and its UK Extension.
To our advertising partners. Each of them acts as an independent controller and is responsible for the transfer safeguard it relies on. Each identifies that safeguard in its own privacy policy, linked in Annex A.
Where no other safeguard is available, we rely on an adequacy decision covering the destination, or on your explicit consent.
Please read this if it matters to you. Some of the advertising networks we mediate are based in, or belong to groups based in, countries for which there is no adequacy decision — including China (Mintegral, and the group behind Pangle) and Russia (Yandex). You should be aware that the protection available in those countries may be weaker than in your own, and that local authorities may have access rights that could not be exercised in the EEA or the UK.
If you would prefer that your data not reach these partners, refuse or withdraw consent to personalised advertising (Section 8). You can ask us for a copy of the safeguards we rely on, including our Standard Contractual Clauses, by writing to f@karfarol.com.

14. How long we keep data

Data

Retention

Analytics events and identifiers (Firebase)

365 days at user level, after which data is retained only in aggregate form that does not identify a device

Attribution data (Singular)

365 days

Crash and diagnostic reports (Crashlytics)

90 days — Firebase Crashlytics' standard retention period

Advertising data held by our advertising partners

Under each partner's own retention policy — see the partner's privacy policy, linked in Annex A

Ad performance and revenue reports in our mediation console

24 months, at device level for as long as the platform makes it available and in aggregate thereafter

Push notification token

Until you turn notifications off, delete the App, or the token expires

Support correspondence

4 years

Records of the consent choices you made

For as long as the consent is valid, and afterwards for a reasonable period to demonstrate compliance — generally up to 4 years

Everything stored on your device

Until you delete it or uninstall the App — we hold no copy

When a retention period ends, data is deleted or irreversibly aggregated so that it can no longer be linked to a device. To ask us to delete data before the end of a retention period, see Section 16.

15. How we protect data
Data in transit between the App, our partners and our systems is encrypted using TLS.
  • We deliberately minimise what we collect: no accounts, no name, no date of birth, no precise location, no payment data at all, and learning progress kept on the device rather than on a server. The only contact detail we ever hold is an email address you choose to write to us from (Section 6.7).
  • Access to the analytics, attribution and advertising consoles that hold this data is limited to the staff of the two companies who need it, protected by multi-factor authentication where the provider supports it, and reviewed when someone joins or leaves.
  • We contract with our processors on written terms that require appropriate technical and organisational security measures, and we choose established providers that maintain recognised security programmes.
  • Because we hold no accounts, no payment data and no directly identifying data, the harm a breach of our systems could cause is limited by design.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required, and inform affected users where the law requires it. Because we hold no contact details for you, we do this by a notice in the App and on our website; if you do not open the App you may not see it.

16. Your rights
16.1 If you are in the EEA, the UK or Switzerland
You have the right to:
  • access the personal data we hold about you, and receive a copy;
  • have inaccurate data corrected;
  • have your data erased ("right to be forgotten");
  • restrict how we process it;
  • object to processing based on our legitimate interests, and to object at any time to processing for direct marketing, including profiling for advertising;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we take no such decisions — see Section 18);
  • lodge a complaint with a supervisory authority (Section 16.5).
16.2 If you are in the United States
Depending on your state of residence, you may have the right to know what personal data we collect and to receive a copy; to have it corrected or deleted; to opt out of its sale, of its sharing for cross-context behavioural advertising, and of targeted advertising; to opt out of profiling used to make decisions that produce legal or similarly significant effects; to limit the use of sensitive personal information; to appeal a refusal; and not to be discriminated against for exercising any of these rights. The App and its features work identically whether or not you exercise them.
These rights currently apply in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Florida, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island, subject to each state's own thresholds and definitions. Residents of other states are welcome to make the same requests and we will handle them the same way.
To opt out of sale, sharing and targeted advertising, use the Do Not Sell or Share My Personal Information control described in Section 12, or write to f@karfarol.com. You may use an authorised agent; we will ask for proof of their authority. We will confirm to you when your request has been processed.
Minnesota residents may additionally ask for a list of the specific third parties to which we have disclosed personal data; Rhode Island residents may ask which third parties we have sold, or may sell, personal data to. Annex A lists the partners that receive data from the App and is the basis of our answer to both. Where an ad is filled through a real-time auction we will also point you to the exchange's own vendor list, and we will confirm the answer in writing on request.
16.3 If you are somewhere else
Many other countries — including Brazil, Canada, Japan, South Korea, Australia, Turkey, Saudi Arabia, the UAE and Georgia — give you comparable rights. Write to f@karfarol.com and we will apply the same process regardless of where you live.
16.4 How to make a request, and what we can actually doWrite to f@karfarol.com with the subject line "Privacy request". We will respond within one month (EEA/UK), 45 days (most US states), or the period your own law requires, and will tell you if we need an extension.
Because the App has no accounts, we cannot identify you from your email address. We locate your records by the identifiers our SDKs generate. Open Settings → Privacy in the App, copy the privacy identifiers shown there, and include them in your message — those are the keys we use to find and delete your analytics and attribution records, and to produce a copy of them where our providers offer per-device export. Where a provider offers deletion but not export, we will tell you so and give you the categories of data we hold instead of a raw copy.
If you have already deleted the App, send us your advertising identifier, device model, App version and approximate first-use date, and we will try to match them. If you have already deleted or reset your advertising ID, or refused tracking, the link between you and any remaining data may be gone, and we may be unable to locate anything to give you or delete. Where that is the case we will say so plainly rather than ask you for more identifying information than we need. We will never ask you to create an account in order to exercise a right.
For data held by an advertising partner acting as an independent controller, the fastest route is usually that partner's own privacy contact or opt-out mechanism. Annex A gives the privacy policy for every partner and, where the partner offers one, its opt-out page or privacy contact address. Tell us if you would like us to pass the request on instead, and we will.
We do not charge for handling requests. If a request is manifestly unfounded or excessive, particularly because it is repetitive, we may charge a reasonable fee or refuse it, and we will explain why and how to challenge that.

16.5 Complaints
Please raise any concern with us first at f@karfarol.com — most issues are resolved quickly. If you remain dissatisfied:
  • EEA: complain to the supervisory authority of the country where you live or work, or where you believe the problem occurred. The list is at edpb.europa.eu/about-edpb/board/members_en. Because our publisher is established in Cyprus, you may also complain to the Office of the Commissioner for Personal Data Protection of Cyprus, dataprotection.gov.cy.
  • United Kingdom: the Information Commissioner's Office, ico.org.uk/make-a-complaint.
  • Switzerland: the Federal Data Protection and Information Commissioner, edoeb.admin.ch.
  • United States: your state Attorney General, or the California Privacy Protection Agency for California residents.
  • Georgia: the Personal Data Protection Service of Georgia, personaldata.ge, which supervises LLC Karfarol Games.
17. Children
The App is for adults (Section 3). We do not knowingly collect personal data from children, and we do not knowingly show personalised advertising to, or sell or share the personal data of, anyone under 18.
We are aware that language learning appeals to people of all ages. If we learn that a user is a child, we will delete the personal data we hold about that device and take the steps described in Section 3. Parents and guardians who believe their child has used the App can write to f@karfarol.com, and we will act on the request without asking for more information than we need to find the data.
If we ever change the App's audience — for example by publishing a version intended for families — we will publish a revised policy with the additional protections that the US Children's Online Privacy Protection Act, the GDPR's rules on children's consent and the app stores' families programmes require, before that version is released.
18. Automated decision-makingWe do not make decisions about you that produce legal effects or similarly significantly affect you on the basis of automated processing alone.
We do use automated processing in two limited ways, neither of which has that effect. Our advertising, analytics and attribution partners use automated and machine-learning systems to select and measure ads and to detect fraud, as described in their own privacy policies (Annex A). And we run automated A/B experiments through Firebase Remote Config that may show different users different feature layouts, content or ad placements. Nothing in the App costs money, so no experiment can affect a price you pay.

19. Changes to this policy
We may update this policy — for example when we add or remove an SDK, change an advertising partner, add a feature, or when the law changes. The "Last updated" date at the top shows when the current version took effect, and we keep the previous version available on request from f@karfarol.com.
Where a change materially affects how we use your personal data, we will give you at least 30 days' notice in the App before it takes effect, and where the law requires it we will ask for your consent again. Section 23 of our Terms of Use applies the same 30-day notice period to changes to those Terms that are material and adverse to you. Continued use of the App after that notice period means the updated policy applies to you. We never treat continued use as consent where separate consent is required.

20. Contact us
Send anything about privacy to f@karfarol.com. Mno Go Apps LTD is our single point of contact and will handle your request whichever company holds the data.
Mno Go Apps LTD — publisher, and the entity named on the App Store and Google Play listings 27, 25 Martiou, D. MICHAEL TOWER, Office 105A, Egkomi, 2408 Nicosia, Cyprus Registration number: 10409188202005251
LLC Karfarol Games — developer Tbilisi, Vake District, Z. Paliashvili str., N41, Georgia Identification number: 405653430
Privacy requests and questions: f@karfarol.com Support: f@karfarol.com Legal and complaints: f@karfarol.com
Annex A — Our SDK partners
This annex names every advertising, analytics and attribution SDK integrated into the App, what it does, where the company is based, and where to find its privacy policy and opt-out. Advertising partners act as independent controllers; Firebase and Singular act as processors for LLC Karfarol Games.

Mediation and advertising

Partner

Role

Based in

Privacy policy

Opt-out

AppLovin Corporation (AppLovin MAX)

Mediation platform and advertising network

United States

https://www.applovin.com/privacy/

https://www.applovin.com/optout/

Google LLC / Google Ireland Ltd (AdMob, Google Mobile Ads)

Advertising network bidding in mediation

United States, Ireland

https://policies.google.com/privacy

https://adssettings.google.com

Mintegral (Mobvista)

Advertising network bidding in mediation

China, Hong Kong SAR, Singapore

https://www.mintegral.com/en/privacy/

https://www.mintegral.com/en/privacy/

Pangle (ByteDance)

Advertising network bidding in mediation

Singapore, China

https://www.pangleglobal.com/privacy

https://www.pangleglobal.com/privacy

Yandex Ads

Advertising network bidding in mediation

Russia

https://yandex.com/legal/confidential/

https://yandex.com/support/mobile-ads/


Analytics, attribution and infrastructure

Partner

Role

Based in

Privacy policy

Opt-out

Google LLC / Google Ireland Ltd — Firebase (Analytics, Crashlytics, Remote Config, Cloud Messaging)

Product analytics, crash reporting, A/B experiments, push notifications. Processor for LLC Karfarol Games

United States, Ireland

https://firebase.google.com/support/privacy

In-App: Settings → Privacy

Singular Labs, Inc.

Mobile measurement and attribution. Processor for LLC Karfarol Games

United States

https://www.singular.net/privacy-policy/

https://www.singular.net/privacy-policy/

Apple Inc.

App distribution

United States

https://www.apple.com/legal/privacy/

Google LLC

App distribution (Google Play)

United States

https://policies.google.com/privacy


We update this annex whenever we add or remove an SDK. The "Last updated" date at the top of the policy shows when the current version took effect.