Privacy Policy — Kanji Creature Cards
1. Introduction
This Privacy Policy explains how Kanji Creature Cards (the "App") handles information when you use it. The App is published by an individual developer, doing business as DORAYA. The App is distributed in 145 countries and regions. It is not available in the member states of the European Union, in Russia, in Belarus, or in mainland China.
Users of the App include people in the European Economic Area (Norway and Iceland) and in the United Kingdom, so this Privacy Policy is written with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the UK GDPR in mind. We apply the same standard to everyone, wherever you are.
By installing or using the App, you acknowledge that you have read and understood this Privacy Policy.
Note: This document is the MVP draft. It reflects the App's behavior at the time of initial release. Version 1.0 includes optional one-time in-app purchases on iOS, handled by Apple (see Section 5.1). Any change in data handling (for example, adding analytics, crash reporting, or push notifications) will trigger an update to this Privacy Policy together with an in-app or store-listing notice.
2. Information We Do Not Collect
In the current MVP release, the App does not collect, transmit, or share any personal information.
Specifically, the App does not:
- Collect names, email addresses, phone numbers, postal addresses, or any other contact details
- Use any device identifier such as IDFA (Apple) or AAID (Google) for advertising or tracking
- Embed third-party analytics SDKs (for example, Firebase Analytics, PostHog, Plausible, or similar services)
- Embed third-party crash reporting SDKs (for example, Firebase Crashlytics or Sentry)
- Embed third-party push notification SDKs (for example, Firebase Cloud Messaging or APNs)
- Track your activity across other apps or websites
- Use cookies (the App is a native mobile application; no web tracking is performed)
- Sell, rent, or otherwise share information with third parties
If any of the above changes in a future release, we will update this Privacy Policy and notify you through an app update notice or store listing.
3. Information Stored Locally on Your Device
The App stores a small amount of data on your device only — never on our servers, and never on third-party servers.
The data stored locally includes:
- Best score: the highest score you have reached in a run.
- Spirits you have discovered: which spirits you have met, and the date you met them.
- Your choices: which spirit you run as, and which charm (if any) you bring into a run.
- Onboarding completion flag: a simple flag indicating whether you have completed the initial onboarding flow.
- Charm trial and unlock state: how many free-trial runs you have used with each charm, and whether a charm is unlocked. On iOS, an unlock is an App Store purchase; the App keeps a local copy of that unlock so it can work offline, and Apple's own record of your purchase is the authoritative source (see Section 5.1). This is kept separately from the game progress above so that a game-data reset does not restore free trials or remove an unlock.
All of this is stored using a local database library (Hive) inside the App's sandbox. Earlier versions of the App also stored a local card-drawing history; the current version no longer reads it, and the Reset option removes it together with everything above.
This data:
- Never leaves your device
- Is not associated with any personal identifier
- Cannot be accessed by other apps installed on your device (sandboxed by iOS / Android)
4. Your Choices and Controls
You are in full control of the data stored locally by the App.
4.1 Reset Data within the App
You can reset the App's local data at any time:
- Open Settings in the App
- Choose Reset Data
- Confirm the action
This clears your best score, discovered spirits, choices, and onboarding flag. It does not reset charm free-trial counts or charm unlocks. The App will otherwise return to its initial state, as if you had just installed it.
4.2 Uninstall the App
Uninstalling the App removes all locally stored data immediately, including charm trial counts and the local copy of charm unlock state. There is no remote copy of your game data, so uninstalling the App is equivalent to permanent deletion of that data. Charms you have purchased on iOS are not lost: the purchase is recorded by Apple against your Apple Account, and you can restore it with Restore Purchases after reinstalling (see Section 5.1).
5. Third-Party Services
The App does not integrate with any third-party services for data collection, analytics, advertising, or messaging. The one external service the App talks to is Apple's App Store, on iOS only, to handle optional in-app purchases (Section 5.1).
5.1 In-App Purchases on iOS (Apple App Store)
On iOS, charm unlocks are sold as one-time in-app purchases processed by Apple. When you open the unlock screen, buy a charm, or restore purchases, the App uses Apple's StoreKit framework to communicate with the App Store. Through that channel:
- Apple handles the payment. DORAYA never receives your name, email address, Apple Account, payment card, or billing address.
- The App receives from Apple only the product's localized price for display and a signed confirmation of which charms your Apple Account owns. The App stores the resulting unlock flag locally (Section 3) and does not store receipts or transaction identifiers.
- DORAYA operates no server. Purchase data is not sent to us or to any other third party, and we do not use it for analytics.
- Apple's handling of your purchase is governed by Apple's Privacy Policy and the Apple Media Services Terms and Conditions.
- On Android, the App does not offer in-app purchases in this version and does not communicate with Google Play Billing.
When the App connects to external services in future releases (for example, analytics or crash reporting), we will:
- Update this Privacy Policy to clearly describe what data is shared, with which service, and for what purpose
- Provide an opt-in consent UI within the App where required by GDPR
- Re-submit the App's data declarations to the App Store and Google Play
Apart from the App Store channel described in Section 5.1, no information leaves your device through the App.
6. Your Privacy Rights
Even though the App does not collect personal data, you retain your privacy rights under applicable law (including the GDPR for users in the European Economic Area and the UK GDPR for users in the United Kingdom). We summarize the most relevant rights below.
6.1 Right to Access (Article 15)
The App does not store any personal data on our servers. There is no record of your usage outside your device. If you wish to confirm this, please contact us using the address in Section 9.
6.2 Right to Erasure (Article 17)
You can erase the App's locally stored data at any time:
- Using the in-app Settings → Reset Data option (see Section 4.1)
- By uninstalling the App (see Section 4.2)
Because we do not transmit data to any server, there is no off-device copy that requires a separate deletion request.
6.3 Right to Data Portability (Article 20)
Because the App does not transmit data to any external server, DORAYA does not hold an off-device copy to export. Automated data export is not included in the MVP release.
6.4 Right to Object and Restrict Processing (Articles 21–22)
The App performs no profiling, no automated decision-making, and no targeted advertising. There is no processing to object to or restrict.
6.5 Right to Lodge a Complaint
You have the right to lodge a complaint with the data protection authority of the country where you live. Among the countries where the App is distributed, the authorities for the ones covered by the GDPR or the UK GDPR are:
- United Kingdom: Information Commissioner's Office (ICO)
- Norway: Datatilsynet
- Iceland: Persónuvernd (Data Protection Authority)
If you live elsewhere, the equivalent authority in your own country applies.
7. Children's Privacy
The MVP release is intended for users aged 13 and over as the store age rating. We do not knowingly direct the App at children below the minimum age set by the applicable store rating in each country.
Store age rating and GDPR Article 8 consent age are separate concepts:
- The store age rating (13+) is the minimum age set by the App Store and Google Play for downloading and using the App.
- The GDPR Article 8 consent age is the minimum age for processing personal data, which varies by country (13 to 16 years under the GDPR, and 13 under the UK GDPR). The MVP release of the App does not process personal data, so GDPR Article 8 consent does not apply to the App itself. If future releases introduce data processing, the consent ages of the countries where the App is distributed will be addressed in an updated version of this Privacy Policy.
Before each run the App draws three kanji at random from a small fixed set. There is no rarity and no paid draw; the draw is made available without monetary payment. No purchase is required to use the App. On iOS, the only items for sale are two optional one-time charm unlocks (Section 5.1). They go through Apple's own purchase flow, so Apple's parental controls such as Ask to Buy apply to them, and the App adds no purchase prompts of its own during play.
If you are a parent or guardian and you believe your child has installed the App, you can uninstall it from the device, or contact us using the information in Section 9.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time, for example when we add a new feature, integrate a new service, or expand to new countries.
When we update the Privacy Policy:
- We will revise the Last Updated date at the top of this document
- If the changes are material (for example, introducing analytics), we will provide a notice through an app update and the relevant store listing
- A copy of the updated Privacy Policy will be available at the same URL where this document is hosted
You are encouraged to review this Privacy Policy periodically to stay informed.
9. Contact Us
If you have any questions or concerns about this Privacy Policy or the App's privacy practices, you can contact us at:
- Email: owner@dorayasweets.com
- Publisher: an individual developer, doing business as DORAYA
We aim to respond to privacy-related inquiries within a reasonable time.
Note: The App is made and operated by one person. Email is the contact channel; no postal address is published. The App is not distributed in the European Union, so the trader disclosure the EU's Digital Services Act requires does not apply to it.
10. Hosting and Availability
This Privacy Policy is planned to be hosted at https://dorayasweets.com/legal/kanji-creature-cards/privacy.html. The URL pattern is provisional and the final URL will be confirmed during the public release preparation phase. The URL will be referenced in the App Store and Google Play listings for the App.
The most recent version of this Privacy Policy will always be available at the URL provided in the store listings. If the App becomes available in additional countries or languages, this document may be updated to reflect that availability.
Note: Governing law is asserted in the App's Terms of Use §11 and is not duplicated here.
Document Metadata
| Item | Value |
|---|---|
| App name | Kanji Creature Cards |
| Publisher | an individual developer, doing business as DORAYA |
| Target jurisdiction | 145 countries and regions (EU member states, Russia, Belarus and mainland China excluded) |
| Document language | English (fixed for MVP) |
| Status | Draft (MVP release preparation) |
| Last updated | 2026-09-23 |