Last updated 2026-09-26.
Zaparo Quiz Arena collects the following, and nothing else.
| What | Specifically | Why | Shared |
|---|---|---|---|
| App activity | A report's reason from a fixed list of six, and a small map of ids the app already has. No free-text field anywhere; A score this user submitted to an app-defined board, when they achieved it, and an optional opaque proof string the app supplies - keyed on their Zaparo ID user id; Link token opened, and the Play install referrer used to match a deferred link after install; Screen views and feature-used events the host app chooses to log; The duels this user is in, the moves they made as opaque app-defined payloads, and when each one arrived - keyed on their Zaparo ID user id; The progress records an app saves for a player (for example the game sets they finished, their streak days, a duel rating), keyed on their Zaparo ID user id; Which applications within this one tenant the account has been seen in. Recorded when an application registers a device or completes a sign-in under its own application id, so `me().apps` can answer it back to the person.; Which leagues this user is in, when they joined, and the scores they pushed into them; and, where the app uses weekly divisions, the tier this user stands in and each week's total with the group it was played in - keyed on their Zaparo ID user id | Account management, Analytics, App functionality, Fraud prevention, security, and compliance | No |
| App info and performance | Crash stack traces, ANRs and breadcrumbs | Analytics, Fraud prevention, security, and compliance | No |
| Device or other IDs | An identifier for the phone, sent with an ad request and with the report that an ad was shown or tapped. It is the advertising identifier only where the app has been declared for it in Play; everywhere else it is an identifier this SDK generates for that install alone, which no other app can read and which dies when the app is removed. Neither is stored as it arrives: the server keeps a keyed hash of it, so the ads cannot be traced back to the identifier.; Crashlytics installation UUID; FCM registration token; Firebase installation ID (app instance ID); The account identifier, and the public half of a key generated in the device key store; The caller's user id and the id of the person being blocked or reported | Account management, Advertising or marketing, Analytics, App functionality, Fraud prevention, security, and compliance | No |
| Messages | A name or a message the player typed, sent for a yes-or-no verdict and kept by nobody | App functionality, Fraud prevention, security, and compliance | No |
| Personal info | Display name - generated by default, editable by the user; Email address, and the name a provider reported, from the sign-in the person chose. Those two and nothing else: a browser provider is asked for `openid email profile` and only the address and the name are read out of what comes back. | Account management, App functionality, Personalization | No |
| Photos and videos | Profile photo the user chose to upload | App functionality, Personalization | No |
You can ask for your data to be deleted at any time, at the address below.
Questions about this policy, or a deletion request: privacy@kbsoap.com