Privacy Policy
Effective Date: September 11, 2026
This Data Integrity & Privacy Protection Charter formally outlines the operating protocols that Yimu Health Care (also identified as "we," "our," or "us") observes to aggregate, analyze, and secure your personal records when you access Star Block Crush: 3D Shooter on Google Play. Our ultimate priority in governing this digital asset is to engineer a flawless interactive experience while strictly enforcing global privacy norms.
1. Mechanisms of Data Aggregation
We deploy structured network methodologies to index and oversee your personal information, operating under a zero-compromise security baseline. The segments below articulate the specific data tiers we intercept and our subsequent handling algorithms.
1.1 Direct Information Indexing The moment Star Block Crush: 3D Shooter initiates on your device, our backend architecture is configured to systematically index the following information tiers:
Routing and Connection Logs: Your Internet Protocol (IP) address, localized network connection timestamps, and general hardware family designations.
Hardware Ecosystem Profiles: Your device manufacturer, specific unit model, base operating system (Android/Google OS), geographic time zone settings, and interface language choices.
Persistent Tracking Anchors: Alphanumeric network identifiers permanently or temporarily tied to your device. This encompasses your Google Advertising ID (GAID), Android Device ID, Google Play Games ID, and the primary Google Account token.
Interactive Event Telemetry: Your sequential progression through the game, peak performance metrics, earned badges, and raw data packets from networked multiplayer sessions.
Commerce and Economy Audits: Logs reflecting in-app fiat purchases, the depletion rates of virtual currency, client-side configuration states, and digital ledger balances.
1.2 External Identity Bridging Should you bypass native registration in favor of a federated identity provider, such as Google Play Games Services, our backend will synchronize permitted profile metrics (e.g., standard display aliases) through their secure APIs. This bridging action is explicitly dependent upon your prior confirmation of the third party's external privacy manifest. We strongly mandate that all users review the data governance protocols of these identity providers:
Google Play Games / Google Services: https://policies.google.com/privacy
By triggering a federated login, you legally warrant that:
Your operational conduct aligns seamlessly with the external provider's Terms of Service.
You clear the legal age threshold required by that specific provider within your local jurisdiction.
2. Operational Justifications for Processing
Every data vector we intercept is correlated with a specific operational mandate. We ground all processing activities in recognized statutory frameworks:
Service Delivery and Ecosystem Maintenance: To authenticate financial transactions, resolve user support tickets, and sustain client-server handshakes; to render foundational gameplay loops, inject saved configurations, and distribute critical security patches or administrative alerts.
Statutory Framework: Grounded in GDPR Article 6(1)(b) (contractual necessity). This processing is structurally inescapable for us to execute the Terms of Service and maintain digital viability.
Iterative Enhancement and Promotional Logic: To broadcast curated marketing communications concerning Yimu Health Care or vetted third-party alliances; to cache your interaction preferences; and to leverage behavioral analytics to architect new mechanics, thereby enhancing software quality and promotional efficacy.
Statutory Framework: Authorized by GDPR Article 6(1)(f) (legitimate interests). We utilize this basis to satisfy a legitimate corporate imperative to elevate our software standard and optimize user retention.
Programmatic Ad Deployment: To render highly targeted commercial advertisements to users who have explicitly authorized our ad-tech partners to access their hardware tracking anchors.
Statutory Framework: Equivalently justified under GDPR Article 6(1)(f). This operationalizes our legitimate interest in securing platform revenue via optimized programmatic advertising.
3. Data Preservation and De-identification
Your personal records are kept active in our infrastructure exclusively for the window required to operate the application, fulfill regulatory reporting, and navigate potential litigations. In specific edge cases—such as legal holds, contract disputes, infrastructure audits, or compliance verifications—we reserve the jurisdiction to freeze relevant data subsets for a legally sanctioned duration. Simultaneously, stripped and hashed usage metrics are leveraged for macro-level system analysis. This de-identified data is routinely purged via standard database flushes, unless a critical security triage necessitates a prolonged preservation cycle.
4. Authorized Information Bridging
Respecting your digital boundaries and acting strictly under GDPR Articles 6(1)(b), 6(1)(c), and 6(1)(f), we may establish secure bridges to share data with external entities in the following scenarios:
Operational Alliances: For the deployment of integrated technical services, corporate restructuring events, legal compliance workflows, or any scenario where we log your explicit opt-in.
Judicial and Regulatory Apparatuses: In the event of a critical policy violation, or if binding legal decrees compel us to unveil records to protect the physical safety, intellectual property, or legal integrity of Yimu Health Care and the global public.
Public Player Forums: Consequent to your active participation in server-side matchmaking, digital message boards, or public high-score ladders.
4.1 Ad Tech Collaborators Subject to registering your active consent per GDPR Article 6(1), we will bridge your device tracking anchors to advertising syndicates to facilitate precision ad targeting. Our integrated matrix of ad tech collaborators includes:
Applovin Corporation: https://www.applovin.com/privacy/
AdColony: https://yandex.com/legal/international_ads_privacy_policy
Amazon Publisher Services: https://www.amazon.com/privacyprefs
Meta (Facebook, Inc.): https://www.facebook.com/about/privacy/
Google LLC: https://policies.google.com/privacy
Google Admob: https://support.google.com/admob/
Unity Technologies: https://unity3d.com/legal/privacy-policy
IronSource: http://www.ironsrc.com/wp-content/uploads/2019/03/ironSource-Privacy-Policy.pdf
Vungle, Inc.: https://vungle.com/privacy/
Fyber: https://www.fyber.com/privacy-policy/
InMobi: https://www.inmobi.com/privacy-policy/
Notice: This Charter does not dictate the downstream algorithmic logic of these external firms. Users are advised to audit the respective privacy portals of these entities.
4.2 Backend Sub-processors To preempt server latency and guarantee uptime, we lease computational resources and analytical dashboards from specialized enterprise sub-processors:
Firebase (Google LLC): https://firebase.google.com/support/privacy
Adjust: https://www.adjust.com/terms/privacy-policy/
5. Minor Shielding Policy
The Star Block Crush: 3D Shooter software architecture is strictly not compiled for, nor commercially targeted at, audiences under the age of 13. We maintain a zero-tolerance filter against the intentional indexing of personally identifiable information (PII) from this specific demographic. Upon confirming that such restricted data has bypassed our safety nets, immediate database scrubbing protocols will be executed. Custodians identifying an unauthorized data transmission by a minor are compelled to contact our support desk for an immediate purge.
6. Cybersecurity Perimeters
We deploy commercially resilient cryptographic standards to lock down your personal records. Nevertheless, the digital community must concede the axiom that no cloud storage framework or TCP/IP transmission is flawlessly impenetrable. As such, we cannot issue an absolute legal warranty against sophisticated zero-day exploits.
7. Device-Level Broadcasting
Contingent upon a positive opt-in flag, we may transmit OS-level payloads, including game updates, marketing prompts, and maintenance logs, directly to your Android/Google interface. You wield absolute authority to revoke this broadcasting permission and kill these payloads via your device’s native OS notification manager.
8. Statutory Rights and Jurisdictional Privileges
8.1 European Economic Area (EEA) Directives We SLA our privacy resolution desk to a standard 30-day window (one month). For heavily fragmented queries, GDPR Article 12 grants us the legal flexibility to delay resolution by an additional two months. We will proactively transmit an explanatory log regarding any such delay.
(1) Data Access Entitlement: Authorized by GDPR Article 15, you may petition for a granular breakdown of your retained records, processing motives, external recipients, and archival lifespans. A digital payload can be extracted, barring IP conflicts.
(2) Processing Objection: Governed by GDPR Article 21, you can contest processing tied to "legitimate interests" (Article 6(1)(f)). We will kill the active processing threads unless we establish overriding legal justifications. Objecting to direct marketing data usage remains an absolute, unconditional right.
(3) Data Rectification: Under GDPR Article 16, you wield the authority to compel the overwrite of corrupted, inaccurate, or partial database records.
(4) Processing Restriction: Per GDPR Article 18, you may mandate a system-level quarantine on the active processing of your data under narrowly defined legal parameters.
(5) Consent Revocation: Dictated by GDPR Article 7, if a specific workflow hinges upon your consent, you may nullify that consent instantly. This revocation is forward-looking and does not invalidate prior computational actions.
(6) Data Portability Extraction: Under GDPR Article 20, you have the clearance to extract your personal files in a standardized, machine-readable format and route them to an alternate data controller without systemic friction.
8.2 California Resident Privileges (CCPA)
(1) Execution Timeline: We target a 45-day statutory turnaround for verifiable consumer inquiries. If technical complexities necessitate a prolongation (up to a 90-day absolute ceiling), a formal written status log will be dispatched.
(2) Retroactive Lookback: Evidentiary data disclosures provided to you are strictly limited to the 12-month trailing window preceding your formal inquiry.
(3) Opt-Out Directive: The CCPA enshrines your undeniable right to set a "Do Not Sell" command regarding your personal telemetry.
(4) Right to Know: You are granted full transparency regarding the exact data vectors we index and our operational motives, as transparently hardcoded in this Charter.
(5) Access to Ledgers: Twice every calendar year, completely free of charge, you may execute a demand for a comprehensive audit of the personal information logged over the trailing 12 months.
(6) Deletion Command: You can issue a mandate for the permanent wiping of personal data collected over the preceding 12 months, provided it does not trigger statutory exemptions (e.g., critical bug fixing, legal compliance, or security auditing).
9. Enacting Data Purges
Should your personal records no longer serve a functional requirement for our services, you possess the authority to mandate a permanent data purge. To trigger this systemic erasure protocol, please route your formal directive to the designated compliance email below.
10. Compliance Contact
For regulatory clarifications, security feedback, or the execution of your formal privacy rights, direct all correspondence to: Contact Email: [email protected]