Last updated 2026-10-01.
Zaparo Chess collects the following, and nothing else.
| What | Specifically | Why | Shared |
|---|---|---|---|
| App activity | A report's reason from a fixed list of six, and a small map of ids the app already has. No free-text field anywhere; A score this user submitted to an app-defined board, when they achieved it, and an optional opaque proof string the app supplies - keyed on their Zaparo ID user id; How far each person has read in each conversation, and a short-lived rate-limit counter per person per conversation; Link token opened, and the Play install referrer used to match a deferred link after install; Recorded runs a player uploads through GhostPoolClient: the game, the language and the replay the app recorded (in a word game the word played, each guess and when it was made), keyed on their Zaparo ID user id; The message payloads, opaque to this module and relayed rather than stored; The moves, result, time control and clock of each online game, and the four ratings computed from them; Which applications within this one tenant the account has been seen in. Recorded when an application registers a device or completes a sign-in under its own application id, so `me().apps` can answer it back to the person.; Which leagues this user is in, when they joined, and the scores they pushed into them; and, where the app uses weekly divisions, the tier this user stands in and each week's total with the group it was played in - keyed on their Zaparo ID user id; Who a signed-in user is friends with, who they have a pending request with, and the short code they hand out - all keyed on their Zaparo ID user id | Account management, App functionality, Fraud prevention, security, and compliance | No |
| App info and performance | App sessions, as Firebase Sessions reports them to Crashlytics: when the app came to the foreground and started a session, with the package name, OS and SDK versions, network type, and device manufacturer and model; Crash reports: what went wrong, the phone model and the Android version; Crash stack traces and performance diagnostics; Crash stack traces, ANRs and breadcrumbs | Analytics, App functionality, Fraud prevention, security, and compliance | No |
| Device or other IDs | An identifier for the phone, sent with an ad request and with the report that an ad was shown or tapped. It is the advertising identifier only where the app has been declared for it in Play; everywhere else it is an identifier this SDK generates for that install alone, which no other app can read and which dies when the app is removed. Neither is stored as it arrives: the server keeps a keyed hash of it, so the ads cannot be traced back to the identifier.; Crashlytics installation UUID; Crashlytics installation UUID, attached to each crash report; FCM registration token; Firebase installation ID, from the Firebase Installations SDK that Crashlytics brings in; it is sent with each app session and used to renew the Crashlytics installation UUID; The account identifier, and the public half of a key generated in the device key store; The caller's user id and the id of the person being blocked or reported; The caller's user id, carried on each message so the other players know who sent it; The caller's user id, sent with each heartbeat so others in a scope can be shown who is here | Account management, Advertising or marketing, Analytics, App functionality, Fraud prevention, security, and compliance | No |
| Messages | A name or a message the player typed, sent for a yes-or-no verdict and kept by nobody; Free-text messages sent to the person you are playing; The text of messages a person sends, and who sent each one, hung on an opaque topic key the app chooses - keyed on their Zaparo ID user id | App functionality, Fraud prevention, security, and compliance | No |
| Personal info | A Zaparo ID, and the email address and display name if the player chooses to sign in; Email address, and the name a provider reported, from the sign-in the person chose. Those two and nothing else: a browser provider is asked for `openid email profile` and only the address and the name are read out of what comes back.; The display name and profile picture reference the app writes into a recorded run's label, shown to other players of that app beside the run | Account management, App functionality | No |
Who holds each kind of data listed above, and when it is deleted:
You can ask for your data to be deleted at any time, at the address below.
Questions about this policy, or a deletion request: privacy@kbsoap.com