Last updated 2026-09-26.
Zaparo Word Duel collects the following, and nothing else.
| What | Specifically | Why | Shared |
|---|---|---|---|
| App activity | A report's reason from a fixed list of six, and a small map of ids the app already has. No free-text field anywhere; Link token opened, and the Play install referrer used to match a deferred link after install; Recorded runs a player uploads through GhostPoolClient: the game, the language and the replay the app recorded (in a word game the word played, each guess and when it was made), keyed on their Zaparo ID user id; Screen views and feature-used events the host app chooses to log; The duels this user is in, the moves they made as opaque app-defined payloads, and when each one arrived - keyed on their Zaparo ID user id; Which applications within this one tenant the account has been seen in. Recorded when an application registers a device or completes a sign-in under its own application id, so `me().apps` can answer it back to the person.; Which leagues this user is in, when they joined, and the scores they pushed into them; and, where the app uses weekly divisions, the tier this user stands in and each week's total with the group it was played in - keyed on their Zaparo ID user id | Account management, Analytics, App functionality, Fraud prevention, security, and compliance | No |
| App info and performance | Crash stack traces, ANRs and breadcrumbs | Analytics, Fraud prevention, security, and compliance | No |
| Device or other IDs | An identifier for the phone, sent with an ad request and with the report that an ad was shown or tapped. It is the advertising identifier only where the app has been declared for it in Play; everywhere else it is an identifier this SDK generates for that install alone, which no other app can read and which dies when the app is removed. Neither is stored as it arrives: the server keeps a keyed hash of it, so the ads cannot be traced back to the identifier.; Crashlytics installation UUID; FCM registration token; Firebase installation ID (app instance ID); The account identifier, and the public half of a key generated in the device key store; The caller's user id and the id of the person being blocked or reported | Account management, Advertising or marketing, Analytics, App functionality, Fraud prevention, security, and compliance | No |
| Messages | A name or a message the player typed, sent for a yes-or-no verdict and kept by nobody | App functionality, Fraud prevention, security, and compliance | No |
| Personal info | Display name - generated by default, editable by the user; Email address, and the name a provider reported, from the sign-in the person chose. Those two and nothing else: a browser provider is asked for `openid email profile` and only the address and the name are read out of what comes back.; The display name and profile picture reference the app writes into a recorded run's label, shown to other players of that app beside the run | Account management, App functionality, Personalization | No |
| Photos and videos | Profile photo the user chose to upload | App functionality, Personalization | No |
You can ask for your data to be deleted at any time, at the address below.
Questions about this policy, or a deletion request: privacy@kbsoap.com