HW FanVL studio
  • Home
  • Services
  • Contact
Get in touch
  • Home
  • Services
  • Contact
Get in touch
Home / Privacy

Privacy Policy

This policy explains what data HW FanVL collects, why we collect it, and the choices you have.

Last updated: August 15, 2026

Table of Contents

  1. 1. Introduction and Scope
  2. 2. Information We Collect
  3. 3. How We Use Information
  4. 4. Advertising and Monetization
  5. 5. App Store Compliance
  6. 6. Regulatory Compliance
  7. 7. Age Restrictions
  8. 8. International Data Transfers
  9. 9. Data Retention
  10. 10. Your Rights
  11. 11. Cookies and Tracking
  12. 12. Third-Party Links
  13. 13. Security
  14. 14. Changes to This Policy
  15. 15. Contact Us
  16. 16. Effective Date

1. Introduction and Scope

HW FanVL (“HW FanVL,” “we,” “us,” “our,” or “the Studio”) is an independent mobile application development studio. We design, build, publish, and maintain utility, lifestyle, and entertainment applications distributed through major mobile application stores, and we operate the corporate website located at hwfanvl.com.

This Privacy Policy (the “Policy”) describes the personal information we collect, how we use it, with whom we share it, and the rights you have in relation to that information. It applies to:

  • the website hwfanvl.com and all subdomains operated by HW FanVL; and
  • every mobile application published by HW FanVL on the Google Play Store and the Apple App Store, including any current and future releases bearing the HW FanVL publisher name or developer account.

This Policy does not apply to information collected by:

  • third-party application stores (Google LLC, Apple Inc.) and the rules, policies, and practices they enforce separately from HW FanVL;
  • third-party advertising networks, mediation platforms, and analytics providers integrated into our applications (these providers are described in detail in Section 4);
  • any third-party website, service, or product linked from our applications or website, or that you reach through a redirect, advertisement, or external integration; and
  • any other company, individual, or entity not controlled by HW FanVL.

By downloading, installing, registering for, or otherwise using any HW FanVL application, or by accessing hwfanvl.com, you confirm that you have read and understood this Policy. If you do not agree with any part of this Policy, you must stop using our applications and website and may contact us using the details in Section 15 to request deletion of any information already collected.

2. Information We Collect

We collect information in two ways: (a) automatically, through the operation of our applications and website, and (b) directly, when you choose to provide information to us. The categories of information we collect are described below.

2.1 Device and Hardware Information

When you install or use an HW FanVL application, we automatically receive information about the device on which the application runs, including:

  • device model, manufacturer, and product name;
  • operating system name, version, and build number (e.g., iOS 17.4 or Android 14);
  • device language, locale, and region settings;
  • screen size, resolution, pixel density, and orientation;
  • unique device identifiers, including the Identifier for Advertisers (IDFA on iOS), Google Advertising ID (GAID on Android), and Identifier for Vendor (IDFV);
  • advertising-free status, tracking-preference signals (e.g., Apple App Tracking Transparency responses), and limit-ad-tracking flags;
  • battery level, available storage, and free memory (used solely for diagnostics).

2.2 Application Usage and Performance Data

We collect data about how you interact with our applications so we can maintain, secure, and improve them. This includes:

  • session length, frequency of use, and feature-level engagement;
  • first install date, last session date, app version, and update history;
  • in-application purchases, ad impressions, ad clicks, and reward events;
  • crash logs, error reports, stack traces, ANR (Application Not Responding) reports, and diagnostic telemetry;
  • performance metrics such as launch time, frame rate, and network latency.

2.3 Network and Connection Information

To deliver content, route network requests, and detect abuse, we collect:

  • Internet Protocol (IP) address;
  • mobile carrier name, mobile country code (MCC), and mobile network code (MNC);
  • approximate country, region, and city derived from the IP address;
  • time zone and clock settings reported by the device.

2.4 Information You Provide Directly

When you contact us, request support, or submit feedback, we collect the information you choose to share, including:

  • email address (for our contact form, support inbox, or newsletter);
  • name or display name, if you provide it;
  • the content of your message, feedback, support ticket, or other communication;
  • records of our correspondence with you regarding your request.

2.5 Information We Do Not Collect

HW FanVL does not intentionally collect, and our applications do not request permission to access, the following categories of data:

  • contact lists, address book entries, or phone contacts;
  • SMS or messaging content, call logs, or call recordings;
  • camera or photo library contents (unless you explicitly choose to upload media through a feature that requests such access at that moment);
  • microphone audio (we do not record audio from your device);
  • precise GPS or real-time geolocation data from your device;
  • health, medical, or fitness data;
  • biometric identifiers (face, fingerprint, voice patterns) used for identification;
  • calendar, reminders, or note content;
  • files stored on the device outside of the application’s own sandbox.

If we ever introduce a feature that requires access to a new category of data, we will update this Policy, refresh the App Store and Google Play data-safety disclosures, and obtain any consent required by applicable law before collection begins.

3. How We Use Information

We process the information described in Section 2 for the purposes listed below. Each purpose is supported by at least one of the legal bases described in Section 6, including performance of a contract, our legitimate interests, your consent, and compliance with legal obligations.

3.1 Providing and Maintaining Our Services

We use device and usage information to deliver the core features of our applications, authenticate sessions, synchronize user preferences, and maintain service availability. This processing is necessary to perform the contract you accept when you install our applications.

3.2 Performance Monitoring and Crash Analysis

Crash logs, error reports, and diagnostic telemetry allow us to identify and fix defects, measure the stability of each release, and prioritize engineering work. Aggregated performance metrics inform our release decisions and quality benchmarks.

3.3 Personalization and In-App Recommendations

Where our applications offer personalized content, recommendations, or difficulty settings, we use the limited device and usage data described above to tailor the experience. You may opt out of personalization at any time through the in-app settings menu or by contacting us.

3.4 Security and Fraud Prevention

We use IP address, device identifier, and behavioral signals to detect and prevent fraudulent installs, ad fraud, account takeover attempts, scraping, denial-of-service attacks, and other abusive activity that could harm our users or our service.

3.5 Customer Support

When you contact us, we use the information you provide to respond to your inquiry, troubleshoot issues, resolve disputes, and improve our support processes.

3.6 Legal and Regulatory Compliance

We process information as required to comply with applicable laws, regulations, and valid legal processes, including tax, accounting, and anti-money-laundering recordkeeping where they apply to us, and to enforce our Terms of Service.

3.7 What We Do Not Do

HW FanVL does not:

  • sell your personal information to data brokers or third-party data intermediaries for monetary or other valuable consideration;
  • use your personal information to make automated decisions that produce legal or similarly significant effects concerning you, as defined in Article 22 of the GDPR;
  • engage in cross-context behavioural advertising on the basis of sensitive personal information (such as health, religion, or sexual orientation); or
  • share your information with government authorities except as required by valid legal process or applicable law.

4. Advertising and Monetization

HW FanVL offers its applications free of charge. To support continued development, we display advertising supplied through a number of third-party advertising networks and mediation platforms. This section lists each provider we integrate, the types of ads served, the data each provider processes, where to find the provider’s privacy policy, and how to exercise choice.

4.1 Advertising Networks and Mediation Platforms

Google AdMob (Google LLC)

  • Ad formats: banner, interstitial, rewarded video, native, and app open (splash).
  • Data processed: device identifiers (IDFA / GAID), IP address, app ID, ad interaction events (impressions, clicks, completion), approximate location, and contextual app metadata.
  • Privacy policy: policies.google.com/privacy.
  • Opt-out: enable “Limit Ad Tracking” on iOS or reset / opt out of “Ad personalization” in Android settings. Developers may also surface AdMob’s in-app consent dialog or set npa=1 for non-personalized ads.

TopOn (Mobvista / 广州汇量信息科技有限公司)

  • Ad formats: banner, interstitial, rewarded video, splash, and native.
  • Data processed: device identifiers, IP address, advertising interaction events, app package name, OS version, and SDK version.
  • Privacy policy: toponad.com/en/privacy-policy.
  • Opt-out: use your operating system’s ad-tracking controls, or follow the steps described in TopOn’s privacy policy under “Your Choices.”

TradPlus (TradPlus Inc.)

  • Ad formats: banner, interstitial, rewarded video, native, and splash.
  • Data processed: device identifiers, IP address, session data, ad impression and click events, and aggregated user segments.
  • Privacy policy: tradplusads.com/privacy-policy.
  • Opt-out: TradPlus honours the platform-level “Limit Ad Tracking” signal. Additional opt-out information is available in its privacy policy.

Meta Audience Network (Meta Platforms, Inc.)

  • Ad formats: banner, interstitial, rewarded video, native, and in-stream video.
  • Data processed: device identifiers, advertising ID, IP address, event data (such as in-app actions, ad views, and clicks), and information received from other Meta services where you are logged in.
  • Privacy policy: facebook.com/privacy/policy.
  • Opt-out: disable tracking via the platform-level control (iOS App Tracking Transparency or Android Advertising ID). Meta also provides controls at facebook.com/adpreferences.

Unity Ads (Unity Technologies)

  • Ad formats: banner, interstitial, rewarded video, and playable ads.
  • Data processed: device identifiers, IP address, game / app ID, advertising interaction events, and device hardware information.
  • Privacy policy: unity.com/legal/privacy-policy.
  • Opt-out: use the operating system’s advertising identifier controls, or follow Unity’s opt-out process documented in its privacy policy.

AppLovin MAX (AppLovin Corporation)

  • Ad formats: banner, interstitial, rewarded video, native, and playable.
  • Data processed: device identifiers, IP address, ad impression and click events, app metadata, and aggregated user segments produced by AppLovin’s auction.
  • Privacy policy: applovin.com/privacy.
  • Opt-out: AppLovin honours platform-level “Limit Ad Tracking”. Users in the EEA / UK may also use AppLovin’s web-based opt-out described in its privacy policy.

ironSource (a Unity Technologies company)

  • Ad formats: banner, interstitial, rewarded video, and offerwall.
  • Data processed: device identifiers, IP address, session metadata, ad impression and click events, and event-level ad interaction data.
  • Privacy policy: is.com/privacypolicy.
  • Opt-out: ironSource honours the platform-level “Limit Ad Tracking” signal and provides additional controls in its privacy policy.

InMobi (InMobi Technology Services Pvt. Ltd.)

  • Ad formats: banner, interstitial, rewarded video, native, and splash.
  • Data processed: device identifiers, IP address, coarse location derived from IP, device attributes, and ad interaction events.
  • Privacy policy: inmobi.com/privacy-policy.
  • Opt-out: use the platform-level “Limit Ad Tracking” control, or follow the opt-out steps at inmobi.com/opt-out.

Pangle (ByteDance Ltd. / 字节跳动)

  • Ad formats: banner, interstitial, rewarded video, native, and splash.
  • Data processed: device identifiers, IP address, coarse location, device attributes, and ad interaction events. Some events may be processed on regional servers selected by Pangle.
  • Privacy policy: pangleglobal.com/privacy-policy.
  • Opt-out: Pangle honours platform-level “Limit Ad Tracking.” EEA / UK users may also use Pangle’s consent management flow surfaced in our apps.

BidMachine

  • Ad formats: banner, interstitial, rewarded video, and native, delivered through in-app header bidding.
  • Data processed: device identifiers, IP address, ad request metadata, and ad interaction events.
  • Privacy policy: bidmachine.io/privacy-policy.
  • Opt-out: BidMachine honours platform-level “Limit Ad Tracking.” Additional opt-out information is available in its privacy policy.

Vungle (Liftoff Mobile, Inc.)

  • Ad formats: rewarded video, interstitial, banner, and native.
  • Data processed: device identifiers, IP address, ad interaction events, and aggregated performance data.
  • Privacy policy: vungle.com/privacy.
  • Opt-out: Vungle honours platform-level “Limit Ad Tracking.” Additional controls are described at vungle.com/opt-out.

Chartboost (Zynga Inc.)

  • Ad formats: interstitial, rewarded video, native, and banner.
  • Data processed: device identifiers, IP address, ad interaction events, and in-app behaviour data shared through the Chartboost SDK.
  • Privacy policy: chartboost.com/legal/privacy-policy.
  • Opt-out: Chartboost honours platform-level “Limit Ad Tracking.” Additional opt-out steps are described in its privacy policy.

Tapjoy, Inc.

  • Ad formats: rewarded video, offerwall, and interstitial.
  • Data processed: device identifiers, IP address, advertising interaction events, and offer completion data.
  • Privacy policy: tapjoy.com/legal/privacy-policy.
  • Opt-out: Tapjoy honours platform-level “Limit Ad Tracking” and provides opt-out steps in its privacy policy.

Digital Turbine (parent of AdColony and Fyber)

  • Ad formats: app install, banner, interstitial, and rewarded video.
  • Data processed: device identifiers, IP address, app metadata, ad impression and click events, and aggregated engagement data.
  • Privacy policy: digitalturbine.com/privacy-policy.
  • Opt-out: Digital Turbine honours platform-level “Limit Ad Tracking.” Further opt-out information is available in its privacy policy.

Liftoff (Liftoff Mobile, Inc.)

  • Ad formats: programmatic banner, interstitial, native, and rewarded video, focused on user acquisition and re-engagement.
  • Data processed: device identifiers, IP address, app metadata, and ad interaction events.
  • Privacy policy: liftoff.io/privacy-policy.
  • Opt-out: Liftoff honours platform-level “Limit Ad Tracking.” Additional opt-out information is in its privacy policy.

Mintegral (汇量科技 / Mobvista group)

  • Ad formats: banner, interstitial, rewarded video, native, and splash.
  • Data processed: device identifiers, IP address, coarse location, device attributes, advertising interaction events, and SDK diagnostic data.
  • Privacy policy: mintegral.com/en/privacy-policy.
  • Opt-out: Mintegral honours platform-level “Limit Ad Tracking.” EEA / UK users may also use the consent flow surfaced in our apps.

AdColony (a Digital Turbine company)

  • Ad formats: interstitial, rewarded video, banner, and native.
  • Data processed: device identifiers, IP address, device attributes, ad impression and click events, and aggregate performance data.
  • Privacy policy: adcolony.com/privacy-policy.
  • Opt-out: AdColony honours platform-level “Limit Ad Tracking.” Additional opt-out information is available in its privacy policy.

4.2 Types of Ads We Display

The ad formats listed above are surfaced in the following ways:

Splash (App Open) Ads

Splash ads are displayed when an HW FanVL application is launched or resumed from the background. They occupy the full screen for a brief moment before the user can dismiss them or proceed to the application’s main content. Splash ads are used to monetise the cold-start moment of an app session.

Rewarded Video Ads

Rewarded video ads are opt-in by the user. The user actively chooses to watch a short video in exchange for an in-app reward (such as extra lives, virtual currency, a hint, or another benefit clearly disclosed in the app). If a user chooses not to watch, the feature remains fully usable without the reward.

Interstitial Ads

Interstitial ads are full-screen ads shown at natural transition points within an application — for example, between levels of a game, after completing a task, or before returning to the home screen. Interstitials are not shown in a way that interrupts an active task in progress.

Banner Ads

Banner ads are small, fixed-position ads placed at the top or bottom of an application screen. They remain visible while the underlying content is interacted with, and they are explicitly labelled as advertising within the app.

Native Ads

Where used, native ads are designed to match the visual style of the surrounding content. They are clearly identified as “Sponsored,” “Ad,” or “Promoted” so that you can distinguish them from organic content.

Offerwall

Where offered, an offerwall allows you to choose from a list of partner offers (install another app, complete a survey, sign up for a service) in exchange for an in-app reward. Completion of an offer is verified by Tapjoy or the relevant partner; we do not see the details of offers you complete beyond confirmation of the reward.

4.3 Targeting and Personalisation

Some ad networks deliver contextual ads (selected based on the content of the current screen) while others deliver personalised ads (selected based on your prior activity, inferred interests, and device characteristics). Where required by applicable law — including in the European Economic Area, the United Kingdom, and other jurisdictions that require informed consent for behavioural advertising — we surface a consent dialog before any personalised advertising begins and we honour the “Limit Ad Tracking” / “Opt out of Ads Personalisation” setting on your device.

You may reset your advertising identifier at any time:

  • iOS: Settings → Privacy & Security → Tracking → toggle off “Allow Apps to Request to Track” or “Ask App Not to Track.”
  • Android: Settings → Google → Ads → tap “Delete advertising ID” or toggle “Opt out of Ads Personalisation.”

5. App Store Compliance

Our applications are distributed through the Google Play Store operated by Google LLC and the Apple App Store operated by Apple Inc. We comply with the policies of each store as set out below.

5.1 Google Play Compliance

  • Google Play Developer Policy. We comply with the Google Play Developer Policy, including the Spam and Minimum Functionality, Metadata, and User Generated Content rules applicable to all apps distributed through the store.
  • Google Play Families Policy. If we publish any application designed for or marketed to children, we comply with the Google Play Families Policy, including its requirements for neutral age gates, ad restrictions, and disclosures about the data we collect from children.
  • Google Play Console Requirements. We keep our developer account information current, pay applicable registration fees, and respond to policy and store-listing reviews within the timeframes required by Google.
  • Data Safety Form. For every application, we complete the Google Play Data Safety Form accurately, describing the data the application collects, whether it is shared with third parties, the purposes of collection, and whether users can request deletion. We update the form before any change in our data practices is shipped to production.
  • Content Rating (IARC). Every application is assigned a content rating through the International Age Rating Coalition (IARC) questionnaire, and we ensure the rated category matches the actual content of the application.
  • SDK Disclosure. All advertising and analytics SDKs integrated into our applications are listed in the Data Safety Form and, where required, in the store listing itself, in accordance with Google’s SDK disclosure rules.

5.2 Apple App Store Compliance

  • App Store Review Guidelines. We comply with the App Store Review Guidelines in full, including the rules on safety, performance, business, design, and legal requirements.
  • Apple Developer Program License Agreement (DPLA). We comply with the DPLA, including the rules on use of Apple APIs, certificate handling, and the prohibition on undisclosed in-app purchase mechanisms.
  • App Tracking Transparency (ATT). Where our applications access the IDFA or use any data for tracking as defined by Apple, we present the ATT prompt and only proceed with tracking if the user grants permission. Our applications are designed to function fully even if the user declines.
  • Privacy Nutrition Labels. For every application, we complete the App Store privacy information (Nutrition Labels) accurately and update it whenever our data practices change. Each label declares the data linked to the user, the data not linked to the user, and the purposes of each category.
  • App Store Connect. We keep the App Store Connect metadata accurate and current, including app name, description, screenshots, and privacy information.
  • Kids Category. If we publish an application in the Kids Category, we comply with the additional rules in the App Review Guidelines, including restrictions on behavioural advertising and on the use of third-party SDKs that collect data from children.

6. Regulatory Compliance

HW FanVL makes its applications available worldwide. Where the laws of your country or region apply to our processing of your personal information, we comply with the obligations described in this section.

6.1 GDPR (EU General Data Protection Regulation, Regulation (EU) 2016/679)

The GDPR applies to the processing of personal data of individuals in the European Economic Area (EEA).

  • Legal bases. We rely on the legal bases set out in Article 6 of the GDPR, including performance of a contract (Article 6(1)(b)), compliance with legal obligations (Article 6(1)(c)), our legitimate interests (Article 6(1)(f)) — where these are not overridden by your rights — and your consent (Article 6(1)(a)) for non-essential processing such as personalised advertising.
  • User rights. You have the rights described in Section 10, including the right of access, rectification, erasure, restriction, portability, objection, and the right not to be subject to a decision based solely on automated processing.
  • Children. Article 8 GDPR applies: we do not knowingly process the personal data of children under 16 (or the lower age set by a Member State, down to 13).
  • Supervisory authority. You have the right to lodge a complaint with the data protection authority of your habitual residence, place of work, or place of the alleged infringement. A list of national supervisory authorities is available at edpb.europa.eu.

6.2 ePrivacy Directive (Directive 2002/58/EC, as amended)

The ePrivacy Directive and its national implementations govern, among other things, the use of cookies and similar tracking technologies in the EEA. Our website uses only the strictly necessary cookies described in Section 11. Where optional cookies, analytics, or similar technologies are introduced, we will request consent through a consent banner before they load.

6.3 CCPA / CPRA (California Consumer Privacy Act and California Privacy Rights Act)

The CCPA, as amended by the CPRA, applies to residents of the State of California.

  • Rights. You have the right to know what categories of personal information we collect, the right to delete personal information we have collected, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information, the right to limit the use of sensitive personal information, and the right of non-discrimination for exercising these rights.
  • Sales and sharing. HW FanVL does not sell personal information for monetary consideration. We may “share” personal information for cross-context behavioural advertising, as defined in California law. You may opt out of such sharing through the “Limit Ad Tracking” / “Opt out of Ads Personalisation” control on your device, or by contacting us.
  • Shine the Light. California Civil Code § 1798.83 permits California residents to request information about the categories of personal information disclosed to third parties for those third parties’ direct marketing purposes. HW FanVL does not disclose personal information to third parties for their direct marketing purposes.

6.4 Other U.S. State Privacy Laws

The following state laws apply to residents of the named states. Under each, you have the right to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising and the sale of personal data.

  • VCDPA — Virginia Consumer Data Protection Act (effective January 1, 2023).
  • CPA — Colorado Privacy Act (effective July 1, 2023).
  • CTDPA — Connecticut Data Privacy Act (effective July 1, 2023).
  • UCPA — Utah Consumer Privacy Act (effective December 31, 2023).
  • Other states. Similar laws are in force or coming into force in additional U.S. states. We extend the rights described in Section 10 to residents of any U.S. state with an applicable comprehensive privacy law, regardless of the law’s name.

6.5 LGPD (Lei Geral de Proteção de Dados, Brazil)

The LGPD applies to the processing of personal data of individuals in Brazil. You have the rights of confirmation, access, correction, anonymisation, portability, deletion, and information about sharing. The Brazilian data protection authority is the Autoridade Nacional de Proteção de Dados (ANPD).

6.6 UK GDPR and Data Protection Act 2018

Following the United Kingdom’s withdrawal from the European Union, the UK GDPR (the UK version of the General Data Protection Regulation) and the Data Protection Act 2018 govern the processing of personal data of individuals in the United Kingdom. The Information Commissioner’s Office (ICO) is the supervisory authority. The rights, legal bases, and safeguards described in this Policy for GDPR also apply under the UK regime.

6.7 PIPEDA (Personal Information Protection and Electronic Documents Act, Canada)

PIPEDA applies to commercial activities in Canada. We process personal information only with your knowledge and consent, for purposes that a reasonable person would consider appropriate in the circumstances, and only the information necessary for those purposes. You may request access to and correction of your personal information as described in Section 10. Additional rights are available under Quebec’s Law 25 and other Canadian provincial laws.

6.8 Privacy Act 1988 (Australia)

Under the Privacy Act 1988 and the Australian Privacy Principles (APPs), you have the right to request access to and correction of personal information we hold about you, and to make a complaint to the Office of the Australian Information Commissioner (OAIC). We do not transfer your personal information outside Australia in a manner inconsistent with the APPs.

6.9 APPI (Act on the Protection of Personal Information, Japan)

The APPI applies to the processing of personal information of individuals in Japan. You have the right to request access, correction, and cessation of use of your personal information, and to opt out of the sharing of your personal information with third parties. We process data only within the scope of the stated purpose of use.

6.10 PDPA (Personal Data Protection Act 2012, Singapore)

Under the PDPA, you have the right to request access to and correction of your personal data, and to withdraw consent for our continued use or disclosure of your data. The Personal Data Protection Commission (PDPC) is the supervisory authority.

6.11 PIPL (Personal Information Protection Law of the People’s Republic of China)

If we make our applications available to individuals in the People’s Republic of China, we comply with the PIPL and related Chinese standards and rules. This includes obtaining separate consent for sensitive personal information, cross-border data transfers, and decisions made through automated means, and providing the rights of access, correction, deletion, portability, and explanation described in the PIPL.

6.12 DPDP Act (Digital Personal Data Protection Act, 2023, India)

The DPDP Act applies to the processing of digital personal data of individuals located in India. We process personal data only for the lawful purposes notified to you, and we honour the rights of access, correction, erasure, grievance redressal, and the right to nominate another individual to exercise your rights in the event of death or incapacity. The Data Protection Board of India is the adjudicatory body.

6.13 POPIA (Protection of Personal Information Act, South Africa)

POPIA applies to the processing of personal information of individuals in South Africa. The Information Regulator is the supervisory authority. You have the right to be notified about the collection of your personal information, to access and correct it, to object to its processing, and to lodge a complaint with the Regulator.

6.14 COPPA (Children’s Online Privacy Protection Act, United States)

COPPA applies to the online collection of personal information from children under 13 in the United States. We do not direct our applications or website at children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected such information, we will delete it as soon as possible. Parents and guardians may contact us using the details in Section 15 to request deletion of information collected from a child.

7. Age Restrictions

HW FanVL’s applications and website are intended for users of at least the minimum age set out below, depending on the user’s jurisdiction.

  • United States and other countries following the COPPA standard: users must be at least 13 years of age.
  • European Economic Area: users must be at least 16 years of age, unless a Member State has set a lower age not below 13 for the use of information society services directly offered to a child.
  • United Kingdom: users must be at least 13 years of age to use our services on their own.
  • Republic of Korea, Russian Federation, and other jurisdictions with higher minimum ages for online services: we apply the higher local minimum age.
  • Children’s applications. Where we publish an application specifically designed for children (for example, in the Apple Kids Category or under Google Play’s Designed for Families program), we comply with the additional rules of that program, including the restrictions on advertising and third-party SDKs.

We do not knowingly collect personal information from anyone below the applicable minimum age. If you are below the applicable minimum age, please do not use our applications, do not provide any information to us, and ask a parent or guardian to do so on your behalf.

Parents and guardians who believe that a child in their care has provided personal information to HW FanVL may contact us at the address in Section 15 to request access, correction, or deletion of that information. We will respond within 30 days.

8. International Data Transfers

HW FanVL is headquartered in the United States. We, and the service providers we use, may transfer, store, and process personal information in countries other than the country in which you reside, including the United States, the European Union, Singapore, and other locations where our providers operate data centres.

When we transfer personal information out of the country where it was collected, we rely on one or more of the following safeguards:

  • Adequacy decisions. Transfers to countries whose data-protection laws have been recognised as adequate by the European Commission, the UK Government, or other competent authorities.
  • Standard Contractual Clauses (SCCs). The European Commission’s 2021 Standard Contractual Clauses (Module 1, 2, or 3 as applicable), and the UK International Data Transfer Addendum issued by the ICO.
  • EU–US Data Privacy Framework. Where our service providers self-certify under the EU–US Data Privacy Framework, the UK Extension, and/or the Swiss–US Data Privacy Framework, transfers to those providers are treated as providing adequate protection under applicable law.
  • Consent and contract. In limited cases, your explicit consent or the necessity of performing a contract with you.

You may request a copy of the safeguards applicable to your data by contacting us at the address in Section 15. To protect commercially sensitive information, we may redact non-essential parts of long-form agreements before sharing.

9. Data Retention

We retain personal information for the period necessary to fulfil the purposes described in this Policy, unless a longer retention period is required or permitted by law. The retention periods below are illustrative; the actual period for any specific record depends on the legal basis, the user’s activity, and applicable law.

  • Device identifiers (IDFA, GAID, IDFV). Retained for the duration of the user’s active use of our applications. Upon uninstall of the application, the identifier is no longer refreshed and is deleted from our systems within 30 days.
  • Crash logs, ANR reports, and diagnostic telemetry. Retained for up to 90 days from the date of capture, after which they are aggregated or deleted.
  • Customer support correspondence. Retained for up to 2 years from the date of the last interaction, to support continuity of support and resolution of any follow-up questions.
  • Analytics data. Where we use Google Analytics 4, event data is retained for the default period of 2 months, and aggregated trend data for up to 26 months, in line with Google’s default retention schedule.
  • Server logs. Retained for up to 30 days for security, fraud, and operational purposes, and then deleted or anonymised.
  • Records subject to legal hold. Where a record is subject to a legal hold, litigation, or regulatory investigation, we retain the record for as long as required by that obligation.
  • Tax and accounting records. Retained for the period required by the tax laws of the jurisdictions in which we operate (typically 7 years).

At the end of the applicable retention period, we delete the personal information or irreversibly anonymise it so that it can no longer be associated with you.

10. Your Rights

Subject to the laws of your jurisdiction, you have some or all of the following rights with respect to the personal information we hold about you.

10.1 Right of Access

You have the right to confirm whether we process personal information about you and to obtain a copy of that information, together with the purposes of processing, the categories of data, the recipients, and the retention period.

10.2 Right to Rectification

You have the right to have inaccurate personal information corrected without undue delay, and to have incomplete personal information completed.

10.3 Right to Erasure (Right to be Forgotten)

You have the right to request that we delete personal information about you, where one of the grounds set out in Article 17 of the GDPR (or the equivalent provision of other applicable law) applies — for example, where the data is no longer necessary for the purposes for which it was collected, or where you withdraw consent and no other legal basis applies.

10.4 Right to Restriction of Processing

You have the right to require that we limit the processing of your personal information to storage only, in the circumstances set out in Article 18 of the GDPR.

10.5 Right to Data Portability

Where processing is based on consent or contract and is carried out by automated means, you have the right to receive the personal information you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

10.6 Right to Object

You have the right to object, on grounds relating to your particular situation, to processing based on our legitimate interests. You also have the right to object to processing for direct marketing purposes, including profiling related to such marketing.

10.7 Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects concerning you, except in the limited circumstances permitted by law.

10.8 Right to Withdraw Consent

Where processing is based on your consent, you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

10.9 Right of Non-Discrimination (CCPA / CPRA)

You have the right not to receive discriminatory treatment for exercising any of your privacy rights under the CCPA, CPRA, or other applicable law.

10.10 Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection authority or other competent supervisory body. A list of national supervisory authorities is available from the European Data Protection Board at edpb.europa.eu.

10.11 How to Exercise These Rights

To exercise any of the rights described in this section, send your request to silasr@theboartech.pics from the email address you wish to verify, or use the contact form at contact.html. To protect your information, we may need to verify your identity before fulfilling the request (for example, by confirming control of the email address or device in question). We will respond to your request within 30 days. If we require additional time, we will notify you of the extension and the reasons for it.

11. Cookies and Tracking

Our website hwfanvl.com uses cookies and similar technologies. This section explains what we use and why.

11.1 Strictly Necessary Cookies

We use a small number of strictly necessary cookies to operate the website, including a session cookie that maintains navigation state and a security cookie that helps us detect and prevent abuse. These cookies are set on the basis of our legitimate interest in operating a secure, functional website and do not require your consent under the ePrivacy Directive.

11.2 Analytics

We use Google Analytics 4 to understand how visitors interact with the website. Google Analytics 4 is configured to honour the “Limit Ad Tracking” signal from your browser and to anonymise IP addresses. You may opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on, or by using your browser’s “Do Not Track” or “Global Privacy Control” setting where supported.

11.3 No Marketing Cookies

We do not use cookies for behavioural or interest-based advertising on the website, and we do not embed third-party advertising scripts on the website.

11.4 Resetting Your Advertising Identifier

Our mobile applications use the operating system’s advertising identifier (IDFA on iOS, GAID on Android) for the purposes described in Section 4. You may reset or limit the use of this identifier at any time:

  • iOS: Settings → Privacy & Security → Tracking. You can also reset the IDFA by going to Settings → General → Transfer or Reset → Reset Advertising Identifier.
  • Android: Settings → Google → Ads. You can reset the GAID or opt out of ad personalisation.

12. Third-Party Links

Our applications and website may contain links to websites, services, or content that are not operated by HW FanVL. This includes links to social networks, support articles, partner offers surfaced through an offerwall, and links to the privacy policies of advertising providers.

When you click a third-party link, you leave the HW FanVL environment. HW FanVL does not control, endorse, or warrant the content, security, or privacy practices of any third-party site or service. We encourage you to read the privacy policy and terms of every third-party site you visit, and to understand the choices available to you through their platforms.

The inclusion of a link to a third-party site does not imply endorsement by HW FanVL of the site, its operator, or its content.

13. Security

HW FanVL takes the security of your information seriously. We use administrative, technical, and physical safeguards designed to protect personal information against unauthorised access, disclosure, alteration, and destruction.

13.1 Encryption in Transit and at Rest

All network traffic between your device and our servers is encrypted using HTTPS and current versions of Transport Layer Security (TLS). Sensitive data stored on our servers is encrypted at rest using industry-standard algorithms.

13.2 Access Controls

Access to personal information is restricted to employees, contractors, and service providers who need the information to perform their job. Access is granted on the principle of least privilege and reviewed periodically.

13.3 Security Audits and Testing

We periodically review our systems, dependencies, and infrastructure for vulnerabilities, and we apply security patches in a timely manner. We engage third-party security specialists to perform independent testing where appropriate.

13.4 Personnel and Training

Personnel who handle personal information receive training on data protection, secure development, and incident response, and are bound by confidentiality obligations.

13.5 Incident Response

We maintain a written incident response plan covering detection, containment, eradication, and recovery from security incidents. Where a security incident is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority within 72 hours of becoming aware of the incident, in accordance with Article 33 of the GDPR, and we will notify affected users without undue delay where Article 34 requires it.

13.6 No System is Completely Secure

Despite our efforts, no security measure is perfect or impenetrable. We cannot guarantee the absolute security of your information, and you use our applications and website at your own risk.

14. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, our applications, the advertising ecosystem, or applicable law. When we make a change, we will revise the “Last updated” date at the top of this Policy and, where the change is material, we will provide additional notice through one or more of the following means:

  • an in-app banner, modal, or update notice within each affected application;
  • an email to the address you have provided to us, where we have one on file;
  • a prominent notice on hwfanvl.com; or
  • a release-notes entry on the relevant app store listing.

Your continued use of any HW FanVL application or of the website after the effective date of the updated Policy constitutes your acceptance of the changes. If you do not agree with the updated Policy, you must stop using the affected application or website and may contact us to request deletion of your information.

You may request a copy of any prior version of this Policy by contacting us at the address in Section 15.

15. Contact Us

If you have any questions about this Policy, our processing of your personal information, or your rights, please contact us using the details below.

Data controller: HW FanVL

Email: silasr@theboartech.pics

Website: hwfanvl.com

Postal contact: Available on request by email. We will provide our postal address, or the address of our EU / UK representative where applicable, in response to verified requests.

EU representative (Article 27 GDPR): To be appointed if and when our processing activities require one. Updates will be posted in this section.

UK representative: To be appointed if and when our processing activities require one. Updates will be posted in this section.

We will acknowledge receipt of your request within 7 days and respond substantively within 30 days. If we need additional time, we will notify you of the extension and the reasons for it.

For general questions about the studio, you may also use the contact form at contact.html. Please note that the contact form is not a dedicated privacy request channel; for privacy rights requests, please email us directly.

16. Effective Date

This Policy is effective as of August 15, 2026 and supersedes all prior versions.

This Policy is written in the English language. In the event of any conflict between the English version and any translation, the English version prevails.

HW FanVL studio

Studio
  • Home
  • Services
  • Contact
Resources
  • Privacy policy
  • Terms of service
  • Press & partnerships
  • app-ads.txt
Stay in the loop

Quarterly notes on new releases, growth experiments, and what we ship next.

© 2026 HW FanVL. All rights reserved.
Privacy Terms app-ads.txt
Worldwide · English