Privacy Policy
Effective Date: 2026-08-28
This Privacy Policy describes how doodleX
collects, uses, discloses, and safeguards personal information when you use the doodleX mobile
and web applications, websites, and related services (collectively, the “Services”). By using
the Services, you agree to this Policy.
Scope
This Policy applies to users worldwide. Additional notices may apply based on your region (e.g.,
EEA/UK under GDPR, California under CCPA/CPRA). Where local laws provide stronger protections,
we will follow those laws.
Information We Collect
- Account and Profile Data: username, display name, avatar, email (if you register or sign
in), password (hashed), and player preferences. [If social login is enabled, we receive
profile basics permitted by your provider.]
- Gameplay and Content: room IDs, game events, drawing strokes and guesses, in-room chat
messages, scores, and moderation flags consistent with community guidelines.
- Friends, Direct Messages, and Attachments: friend requests and connections, one-to-one
direct messages (DMs) between friends, and any photos or images you choose to share in a
DM. See “Friends, Direct Messages, and Chat” below for details on how this content is
stored, retained, and deleted.
- Reports, Blocks, and Safety Actions: if you report another user, we collect the report
(who you reported, the reason, any comment you add, and — for in-room reports — a short
snippet of the relevant chat). If you block another user, we store that block so the
feature keeps working. See “Reporting and Blocking” below.
- Technical and Device Data: app version, OS version, device model, unique device identifiers,
IP address, language, time zone, crash logs, performance metrics.
- Usage and Analytics: session timestamps, features used, in-app interactions, referral
sources, engagement and retention metrics.
- Payments and Purchases: transaction IDs, product SKUs, timestamps, and non-sensitive billing
metadata via app store processors; we do not receive full card data.
- Support and Communications: messages sent to support, bug reports, email communications,
feedback forms.
- Cookies and Similar Technologies (web): session cookies, authentication tokens, analytics
cookies, and local storage necessary for functionality and measurement.
Sources of Information
- Directly from you when you create an account, play, add friends, message other users,
share images, or make purchases.
- Automatically from your device when you access the Services.
- From third parties: analytics providers, crash reporters, ad networks (if enabled), cloud
storage providers (for shared images), and payment processors.
How We Use Information
- Provide and operate the Services: matchmaking, rooms, WebSocket gameplay, leaderboards,
moderation, friends, direct messaging, and other social features.
- Improve performance, stability, and safety: debugging, crash analysis, anti-cheat, and abuse
prevention.
- Personalize experience: saved preferences, language, recommended rooms, and content.
- Communications: service updates, security alerts, policy changes, and—with consent or where
permitted—marketing messages.
- Analytics and Research: usage metrics, A/B testing, product decisions.
- Compliance: legal obligations, dispute resolution, enforcement of Terms.
Friends, Direct Messages, and Chat
doodleX includes social features that let you connect and communicate with other players. This
section explains how that content is handled.
- Friends: you can send, accept, or decline friend requests. We store your friends list and
pending requests so the feature works across sessions and devices.
- In-room chat: messages sent in a game room’s chat are visible to other players currently in
that room, consistent with the “User-Generated Content and Moderation” section below.
- Direct messages (DMs): messages you send to a friend in a one-to-one conversation are
visible only to you and that friend (and, where necessary, our moderation and safety
processes). DMs are not visible to other players.
- Shared images and attachments: if you choose to share a photo or image in a DM, it is
uploaded to our cloud object storage provider and a link to it is included in the message.
Only you and the recipient can access it through the app.
- Deleting a message or conversation (soft delete): when you delete a message or an entire
conversation, it is immediately removed from your own view and, for a full conversation
deletion, from your conversation list. This is a “soft delete” — the underlying message
data (and any attached images) is retained on our systems for up to 30 days after deletion
for backup, safety, and abuse-investigation purposes, and is then permanently removed.
Deleting a message or conversation on your side does not delete it from the other
participant’s view.
- Room chat retention: chat sent in a game room may be retained after the room ends (archived
along with the match record) for a limited period for moderation, safety, and abuse
investigation purposes.
Reporting and Blocking
doodleX provides in-app tools to report and block other users, consistent with app store
requirements for apps that let users communicate with each other.
- Reporting a user: when you submit a report (from a game room, a friend, or a DM), we
record who filed it, who was reported, the reason you selected, any optional comment, and
— for in-room reports — a short snippet of the relevant chat, so our team can review it.
Report records are retained for as long as necessary for safety, moderation, and legal
purposes, which may be longer than our normal chat retention window.
- Automated safety action: to limit abuse, an account that receives multiple reports from
different users within a short period may be automatically muted for a period of time. This
is an automated decision based on report volume; you can contact us if you believe it was
applied in error.
- Blocking a user: blocking removes any existing friend connection between you and that
user, prevents new friend requests in either direction, and stops them from messaging you
through the app. We keep a record of who you’ve blocked, retained while your account is
active or until you unblock them. Blocking is not disclosed to the blocked user.
Legal Bases for Processing (EEA/UK)
- Contract: to deliver core functionality you request.
- Legitimate Interests: security, fraud prevention, analytics, service improvement, and
customer support (balanced against your rights).
- Consent: where required for marketing, certain cookies, or personalized ads.
- Legal Obligation: to comply with applicable laws.
Sharing and Disclosure
- Service Providers (Processors): hosting (e.g., cloud VPS), cloud object storage for shared
images and attachments, content delivery, analytics (e.g., privacy-focused analytics or
[provider]), crash reporting (e.g., [provider]), email delivery, moderation tools.
Providers are bound by contracts and process data on our instructions.
- Payment Partners: app stores or payment gateways process your payments and share transaction
confirmations with us.
- Advertising Partners (if enabled): ad networks may receive device identifiers and
performance metrics; you can opt out or withdraw consent where required.
- Legal and Safety: to comply with law, enforce our Terms, or protect rights, property, and
safety of users or the public — including reviewing reported chat, direct messages, or
shared images where necessary to investigate abuse.
- Business Transfers: in mergers, acquisitions, or asset sales, subject to this Policy’s
protections.
International Transfers
We may process and store your information in countries outside your own. When transferring
personal data internationally, we implement appropriate safeguards (e.g., Standard Contractual
Clauses) as required by law.
Data Retention
- Account data: retained while your account is active and for a reasonable period thereafter
for backup, auditing, legal, and fraud-prevention purposes.
- Gameplay logs: retained for operational, anti-abuse, and analytics needs on a time-limited
basis.
- Friends: your friends list and friend requests are retained while your account is active,
or until you remove a friend or the request is withdrawn/declined.
- Direct messages and shared images: retained while your conversation exists. If you delete a
message or a conversation, it is removed from your view immediately (soft delete) and the
underlying data is retained for up to 30 days for backup, safety, and abuse-investigation
purposes before permanent deletion.
- In-room chat logs: may be archived with the match record after a room ends and retained for
a limited period for moderation and safety purposes.
- Reports: retained for as long as necessary for safety, moderation, and legal purposes —
this may extend beyond normal chat retention and beyond account deletion where needed to
investigate abuse or comply with legal obligations.
- Blocks: retained while your account is active, or until you unblock the user.
- Crash and analytics data: retained per our analytics/crash tools’ configured windows.
- Support communications: retained as necessary to support you and maintain records.
Security
We apply administrative, technical, and organizational measures appropriate to the risk,
including access controls, encryption in transit, network security, and monitoring. No system is
100% secure; promptly notify us of any suspected security incident.
Your Rights
- Access/Portability: request a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Deletion: request deletion where legally permitted, including of direct messages, shared
images, and friend connections.
- Restriction/Objection: restrict or object to certain processing, including direct
marketing.
- Consent Withdrawal: withdraw consent at any time (does not affect prior lawful
processing).
- Complaint: you may complain to your local data protection authority.
Submit requests via the contact details below. We may need to verify your identity.
California Privacy Notice (CCPA/CPRA)
- Categories collected: identifiers (e.g., username, device IDs), internet/network activity,
geolocation (approximate), in-app purchase data, friends/social-graph data, direct message
and chat content, images you choose to share, and inferences for personalization.
- Sources: as described above.
- Business/Commercial purposes: as described above.
- Sharing/Selling: we do not “sell” personal information for money. If we use ad networks or
cross-context behavioral advertising, that may be a “share” under CPRA; you can opt out via
in-app settings or by contacting us.
- Your rights: know, delete, correct, opt-out of sharing/sale, non-discrimination for
exercising rights.
Children’s Privacy
The Services are not directed to children under 13 (or the equivalent minimum age in your
jurisdiction). We do not knowingly collect personal information from children under this age. If
you believe a child has provided personal information, contact us for deletion.
Cookies and Tracking Technologies
We use essential cookies for authentication and security. With consent where required, we may use
analytics cookies for measuring usage and improving features. On web, you can manage preferences
via browser settings and any provided cookie banner.
User-Generated Content and Moderation
Drawings, guesses, usernames, in-room chat, friend interactions, direct messages, and shared
images are user-generated content. In-room chat and drawings are visible to other players in
your room; direct messages and their attachments are visible only to you and the friend you are
messaging. We may use automated and manual review — including of reported direct messages and
shared images — to enforce community guidelines and prevent abuse. Please do not share images
or messages containing sensitive personal information about yourself or others.
Third-Party Links and Integrations
Our Services may link to third-party sites or include SDKs (e.g., analytics, crash reporting,
cloud storage for shared images, ads). Their practices are governed by their policies. Review
their privacy policies before use.
Data Controller
Podzi, [Registered Address], [Country]. If operating as a sole
developer, include a valid business contact and jurisdiction details appropriate for app
stores.
Contact Us
Email: ahmed.nader1994@gmail.com
Postal: [Address Line 1], [City], [Postal Code], [Country]
Changes to This Policy
We may update this Policy to reflect changes to our practices or legal requirements. We will post
updates here and revise the “Effective Date.” Material changes may be communicated in-app or via
email where appropriate.
Region-Specific Addenda
We may provide addenda for specific jurisdictions (e.g., EEA/UK, California, Brazil). If an
addendum conflicts with this Policy, the addendum controls for residents of that region.