This English text is a reference translation (machine-assisted). The Japanese version is the official text and prevails in case of any discrepancy.
"Keeper's Isle" Privacy Policy
野田晶裕 (the "Operator") handles users' information in the smartphone game "Keeper's Isle" (the "Service") as follows.
1. Information We Collect and How
| Category | Information | How collected |
|---|---|---|
| Account information | The anonymous user ID issued by Unity Authentication, friend code, display name, account creation date and time. If you link an account (to carry over on a device change), the Google Play Games player ID or Apple user ID you linked (we do not receive your name or e-mail address) | Issued automatically at first launch / entered by you / from Google or Apple when you link |
| Year and month of birth; age category | Your year and month of birth (we do not ask for the day) and the age category our server calculates from it (13 to under 16 / 16 to under 18 / 18 and over). Stored with your account data on our server; the category is updated automatically as you age. A year and month of birth indicating under 13 is not stored (nor kept on the device) | Entered by you (at first launch, before connecting to our server; sent after connecting) |
| Record of consent to the Terms and this Policy | The versions of the Terms of Service and Privacy Policy you agreed to and the date and time of consent | Recorded by our server when you consent |
| Device information | Device identifiers (including ones that change on reinstalling the app), device model, OS version, app version, language and region settings | Collected automatically by the app |
| Network information | Source IP address, date and time of communication, latency and other connection status | Collected automatically when connecting to the server |
| Approximate location | Approximate location such as country or region estimated from the IP address (we do not collect precise location such as GPS) | Estimated by the ad SDK and the purchase SDK when they communicate (Section 7) |
| Crash and diagnostic information | Records of app crashes and errors (exceptions) with the device model, OS version, app version at the time, and a per-installation identifier issued by Unity. The only information we add is the app version, build type, server environment, the most recent expedition number and your user ID (if logged in) (no display name or app logs) | Collected automatically by Unity Diagnostics (crash and exception reporting) (Sections 4 and 7). Also collected automatically by the ad and purchase SDKs (Section 7) |
| Bug reports | The text and category you write in "Send a bug report" and the attachments shown on screen for your consent before sending (app version, data version, device model and OS version, screen size, in-game location, most recent expedition number, recent app activity log, user ID) | Only when you send it (never automatically). Other users' names in the log, and IDs, e-mail addresses and IP addresses other than your own, are masked on both the device and the server before storage |
| Play data | Inventory and progress, input logs (records of your controls), battle and dungeon results, ranking records, co-op participation records and result reports, stamp and preset-phrase sending records, friend and request records | Collected automatically through use of the Service |
| Trading records | Market listings, purchases and cancellations, direct exchange offers and acceptances, changes in mist crystals, inbox collections | Same as above |
| Purchase records | Products purchased, date and time, amount, Store transaction ID and receipt, refund notifications, this month's purchase total and the limit you set, paid draw records (selected character, recipient characters and amounts, pity grants, odds table version, date and time, revocation due to refund) | From the Store (Apple, Google) / from the app (via Unity IAP) / created by our server |
| Advertising information | Advertising ID (Android advertising ID; iOS IDFA only if you allow tracking), device identifiers, records of ad impressions, views and clicks, rewarded-ad view confirmation notifications (user ID, ad placement name, per-view number, reward contents, date and time) | Collected through the ad SDK (Unity LevelPlay) (Section 7). View confirmation notifications are relayed from LevelPlay's servers to our server through Cloudflare Workers (Section 4) |
| Inquiry information | E-mail address, contents of the inquiry, user ID | When you contact us (by e-mail) |
| Fraud-prevention information | Hash values (irreversibly transformed values) derived from device identifiers and IP addresses, suspected-fraud determinations, records of operational responses | Created by the Operator from the above |
- We do not collect names, postal addresses, telephone numbers or credit card numbers (payments are processed by the Store).
- We do not collect e-mail addresses within the app (we receive an e-mail address only when you contact us from outside the app).
- We do not collect contacts, photos, videos, audio, files, calendars or precise location.
- The Service does not provide free-text chat.
2. Purposes of Use
We use the information we collect for the following purposes.
- 1. Providing the Service (account management, saving and syncing game data, rankings, co-op connections, processing of the Market and direct exchange, inbox management)
- 2. Confirming, granting and restoring purchases of paid items, and processing refunds
- 2-2. Conducting paid draws, storing and displaying the results to you, verifying that draws follow the displayed odds (aggregating appearance rates), and responding to inquiries
- 3. Calculating the age category from the year and month of birth and applying the monthly purchase limit by age category (under 18), blocking purchases where the year and month of birth or consent to the Terms is missing, restricting use by persons under 13, and age-appropriate advertising settings
- 3-2. Recording consent to the Terms of Service and Privacy Policy and confirming consent upon revision
- 4. Preventing, detecting and investigating fraud (RMT, misuse of multiple accounts, cheating and modification, bots, exploitation of bugs, etc.) and taking measures under the Terms of Service (holding or cancelling trades, recovering items, suspending accounts, etc.)
- 5. Verifying ranking records (replaying input logs to confirm results) and displaying ghosts (movement reproduced from input logs), display names and records to other users
- 6. Delivering advertisements, confirming views of rewarded ads and granting rewards, and measuring ad effectiveness
- 7. Responding to inquiries and sending important notices
- 8. Investigating and improving defects in the Service (including responding to bug reports and crash reports), and producing statistics (in a form that does not identify individuals) for considering new functions and services
- 9. Responding to users who violate the Terms of Service, and complying with laws
3. Provision to Third Parties
We do not provide personal data to third parties except in the following cases.
- 1. With your consent
- 2. Where required by law (such as lawful requests from investigative authorities)
- 3. Where necessary to protect a person's life, body or property and it is difficult to obtain your consent
- 4. Where we entrust handling to the service providers in Section 4 to the extent necessary to achieve the purposes of use
- 5. Where provided in connection with a business succession
Information Visible to Other Users
The following information is displayed to other users as part of how the Service works (we list it here on the premise that this is not provision to third parties).
| Where | Information displayed to other users |
|---|---|
| Name card (profile card) | Display name, master level, titles, appearance (character appearance, name-card background and frame, etc.) |
| Rankings | Name-card information, records (floor reached, time, etc.), ghost (movement reproduced from the input log), equipment |
| Market and direct exchange | The seller's or counterparty's name-card information, listed equipment and price |
| Co-op play (room listing and participation) | Name-card information, room information, character movements and equipment appearance during play, stamps and preset phrases |
| Friends | Friend code, name-card information, sending and receiving of requests |
| Lightkeepers' Monument (supporter pack) | Display name, if you opted to be listed |
4. Service Providers and External Services
To provide the Service, we entrust the handling of information to, or use the services of, the following providers.
| Provider | Service | Main information handled | Country / storage region |
|---|---|---|---|
| Unity Technologies (and affiliates) | Unity Gaming Services: Authentication (anonymous sign-in), Cloud Code, Cloud Save, Leaderboards, Lobby, Relay | Anonymous user ID, play data, trading records, purchase records, IP address, device information | United States ([data storage region: ]) |
| Apple Inc. / Google LLC | App Store / Google Play (payment and purchase confirmation) | Purchase records and receipts | United States |
| Unity Technologies (and affiliates) | Unity IAP (in-app purchase processing; interaction with Google Play Billing / StoreKit) | Purchase records and receipts, device identifiers, approximate location, crash and diagnostic information | United States |
| Unity Technologies (and affiliates; formerly ironSource) | Unity LevelPlay (ad mediation; rewarded-ad view confirmation notifications) | Advertising ID and device identifiers, device information, IP address and approximate location, ad impression/view/click records, crash and diagnostic information, the user ID included in rewarded-ad notifications | United States [and Israel, etc.] |
| Unity Technologies (and affiliates) | Unity Ads (ad network delivered through LevelPlay mediation) | Advertising ID and device identifiers, device information, IP address and approximate location, ad impression/view/click records, crash and diagnostic information | United States [etc.] |
| Google LLC | Google AdMob (ad network delivered through LevelPlay mediation; Google Mobile Ads SDK) | Advertising ID and device identifiers, device information, IP address and approximate location, ad impression/view/click records, crash and diagnostic information | United States [etc.] |
| Cloudflare, Inc. | Cloudflare Workers (relays rewarded-ad view confirmation notifications from LevelPlay's servers to our server) | Contents of the view confirmation notification (user ID, ad placement name, per-view number, reward contents, date and time, signature). The sender is LevelPlay's server; your device's IP address does not pass through | United States (processing takes place at locations worldwide) |
| Unity Technologies (and affiliates) | Unity Diagnostics (Unity Cloud Developer Data; crash and exception reporting) | Crash and exception records, device model and OS version, app version, per-installation identifier, information we add (app version, build type, server environment, most recent expedition number, user ID) | United States [etc.] |
| Microsoft Corporation | Outlook.com (responding to inquiries: sending, receiving and storing e-mail) | E-mail address, contents of the inquiry | United States [and elsewhere] |
5. Provision to Third Parties in Foreign Countries (Storage Abroad)
- 1. As described in Section 4, we may entrust the handling of personal data to, or provide personal data to, providers located in the United States (Unity Technologies, Cloudflare, Inc., Google LLC, Apple Inc., Microsoft Corporation).
- 2. Personal information protection system of the destination country: the United States has no comprehensive federal law equivalent to Japan's Act on the Protection of Personal Information; there are state laws (such as the California Consumer Privacy Act) and sector-specific laws. Please refer to the materials of Japan's Personal Information Protection Commission ( https://www.ppc.go.jp/personalinfo/legal/kaiseihogohou/#gaikoku ).
- 3. Measures taken by the recipients: [Unity Technologies takes the measures of ... under its Data Processing Agreement (DPA).]
- 4. When you first launch the Service (before connecting to our server), we explain that your play records, purchase records and other data are stored on servers of providers located outside Japan (such as the United States) and obtain your consent to this Policy (Act on the Protection of Personal Information, Article 28, paragraph 1).
6. Personally Referable Information (Advertising IDs, etc.)
We allow the advertising providers in Section 7 to collect information that by itself cannot identify a specific individual, such as advertising IDs, device information and ad impression records. Where it is expected that these providers will obtain such information in a way that links it to personal data they hold, we confirm, in accordance with the law, that your consent has been obtained.
7. Data Sent to Third Parties (Information Transmitted from Your Device to Others)
In the Service, information is transmitted from your device to providers other than the Operator as follows.
| Recipient | Program that transmits | Information transmitted | Purpose | Recipient's privacy policy |
|---|---|---|---|---|
| Unity Technologies | Unity Gaming Services SDK (Authentication, Cloud Code, Cloud Save, Leaderboards, Lobby, Relay) | Anonymous user ID, device information, app version, IP address, play data, (if linked) Google Play Games player ID or Apple user ID | Providing the Service (login, data storage, rankings, co-op connections, carry-over on device change) | https://unity.com/legal/privacy-policy |
| Google LLC | Google Play Games Services (Play Games Plugin for Unity 2.2.1, Play Games Services v2; used only when you link an account on Android) | Google Play Games player ID, sign-in authorization code, device information | Carry-over on device change (account linking), identity verification for web account deletion | https://policies.google.com/privacy |
| Apple Inc. | Sign in with Apple (iOS version; used only when you link an account) | Apple user ID (name and e-mail address are not requested) | Carry-over on device change (account linking), identity verification for web account deletion | https://www.apple.com/legal/privacy/ |
| Unity Technologies | Unity Diagnostics (built into Unity 6; no added package) | Crash and exception records, device model and OS version, app version, per-installation identifier, information we add (app version, build type, server environment, most recent expedition number, user ID). App logs are not attached | Investigating and fixing defects (crashes and errors) | https://unity.com/legal/privacy-policy |
| The Operator (stored in Unity Gaming Services Cloud Code / Cloud Save) | The Service's "Send a bug report" (only when you choose to send) | Text and category, and the attachments shown before sending (app version, data version, device model and OS version, screen size, in-game location, most recent expedition number, recent app log with other users' names and IDs other than your own masked, user ID) | Investigating and fixing defects, responding to inquiries | This Policy |
| Unity Technologies (formerly ironSource) | Unity LevelPlay SDK (9.3.1) | Advertising ID and device identifiers, device information, IP address (used to estimate approximate location), ad impression/view/click records, crash and diagnostic information, the user ID set when viewing rewarded ads | Ad delivery (mediation), measurement and analytics, prevention of ad fraud, confirmation of rewarded-ad views | [https://unity.com/legal/game-player-and-app-user-privacy-policy ] |
| Unity Technologies | Unity Ads SDK (4.20.1; via LevelPlay mediation) | Advertising ID and device identifiers, device information, IP address and approximate location, ad impression/view/click records, crash and diagnostic information | Ad delivery, measurement, prevention of ad fraud | [same as above] |
| Google LLC | Google Mobile Ads SDK (AdMob; next-generation 1.4.0; via LevelPlay mediation) | Same as above | Same as above | https://policies.google.com/privacy ; how Google uses data from partner sites and apps: https://policies.google.com/technologies/partner-sites |
| Unity Technologies / Google LLC / Apple Inc. | Unity IAP (5.4.3), Google Play Billing / StoreKit | Purchase information and receipts, device identifiers, approximate location, crash and diagnostic information | Payment for paid items, confirming and restoring purchases, preventing fraudulent purchases | https://unity.com/legal/privacy-policy / https://policies.google.com/privacy / https://www.apple.com/legal/privacy/ |
How to Stop Ad Tracking
- Android: you can delete or reset the advertising ID from the device's [Settings → Google → Ads].
- iOS: you can decline tracking in the prompt shown when you first launch the app. You can change this later in [Settings → Privacy & Security → Tracking].
- Advertisements are still displayed even if you stop tracking (they will not be tailored to your interests).
- If the age category calculated from your year and month of birth is under 18 (or no year and month of birth has been entered), we configure the ad SDK to serve ads that do not use the advertising ID (not tailored to your interests).
8. Minors
- Persons under 13 may not use the Service. If under 13 is entered at first launch, we do not connect to our server and do not store the year and month of birth. If we learn that information belongs to a person under 13, we delete it.
- At first launch we ask for your year and month of birth, calculate an age category and use it for the monthly purchase limit for users under 18 (13 to under 16: 5,000 JPY / 16 to under 18: 20,000 JPY; purchases exceeding the limit cannot be made) and for age-appropriate advertising settings.
- If you are a minor, please read this Policy together with a parent or guardian and obtain their consent before use.
9. Retention Periods
| Information | Retention period (draft) |
|---|---|
| Account and play data | Until the account is deleted. Erased within [30] days after deletion (within [90] days from backups). Items that fall under "trading records and fraud-prevention information" or "purchase records" below are kept for the periods in those rows. Unused accounts: accounts not linked to a Google or Apple account are erased automatically, in the same way as account deletion, one year after the last use (login) (one year and 30 days for accounts that have ever purchased a paid item), because no one can log in to an unlinked account once the app is deleted. After erasure, paid items purchased on that account cannot be restored even by restoring Store purchases |
| Ranking records | Scores for the current period (week or season) are removed from the leaderboard when the account is deleted. Closed past-period leaderboards retain the user ID and score (not the display name) [retention period: ]. Deleted accounts do not receive end-of-period rewards |
| Input logs | Records at the top of rankings or that were reported: [1 year] from the end of the period. Others: [30 days]. After account deletion, only what is needed for fraud investigation is kept in de-identified form; the rest is erased as in the row above |
| Trading records and fraud-prevention information | [1 year] (for fraud investigation and user protection; kept in de-identified form for 1 year even after account deletion) |
| Purchase records (including paid draw records) | [7 years] (as accounting and tax records). You can review your own draw results for the last [90] days in the app. After account deletion, only the amount, date and time, product, Store order number and refund status are kept for 7 years from the date of deletion, separated from your name and game data; the user ID is removed 1 year after deletion. These records are also used to prevent duplicate grants for the same purchase, reuse on another account, and re-attachment by purchase restoration of paid items bought on a deleted account (including accounts erased automatically as unused) (paid items of a deleted account cannot be restored; Terms of Service Article 4, paragraphs 5 and 6) |
| Rewarded-ad view confirmation records | Same as trading records and fraud-prevention information ([1 year]; de-identified after account deletion) |
| Year and month of birth, age category, record of consent | Until the account is deleted (same as account and play data). The year and month of birth is stored only to update the age category automatically. A year and month of birth indicating under 13 is not stored |
| Inquiry records | [3 years] after the inquiry is resolved |
| Bug reports | Erased 1 year after receipt. If you delete your account, the user ID is removed from the report (user IDs in the log are also masked) and the text and remaining attachments are kept for defect investigation until 1 year after receipt |
| Crash and exception reports | Unity Diagnostics' retention period (90 days by default according to Unity). Requests to erase reports containing your user ID are handled from the Unity dashboard |
10. Security Measures
We take the following measures to prevent leakage, loss or damage of personal data.
- Organizational: we designate a person responsible for handling, and record the reason and person for each operation of the administration tools.
- Personnel: we ensure that those who handle data maintain confidentiality and handle it appropriately.
- Physical and technical: server data is protected by access controls so that it cannot be rewritten directly from users' devices, and administration tools can be used only by authorized persons. Device identifiers and IP addresses are hashed when used for fraud prevention.
- Understanding the external environment: because we may store and process personal data in the United States, we take security measures with an understanding of the United States' personal information protection system.
11. Requests for Disclosure, Correction, Suspension of Use, etc.
You may request disclosure, correction, addition, deletion, suspension of use, erasure, suspension of provision to third parties, and disclosure of records of provision to third parties regarding your personal data held by us. Please contact the contact point in Section 12. To verify your identity we will ask for your user ID (shown on the settings screen) and similar information. The fee is [free / [ ] JPY per request].
- You can also delete your account by the following methods.
- In the app: [Settings → Delete account]
- The web account deletion page (URL: [ ]). You can use it after deleting the app or when your device is not at hand. Sign in with the Google (Play Games) or Apple account linked in the app; after verifying your identity and a confirmation screen, the account is deleted immediately. Sign-in information is used only to verify your identity and is not stored.
- If you use the Service without linking a Google or Apple account and the app is on your device, use [Settings → Delete account] in the app. If you have deleted the app or your device is not at hand, no one can log in to that account and it is erased automatically one year after the last use (one year and 30 days if you have ever purchased a paid item) (Section 9). If you wish to delete it sooner, contact the contact point in Section 12. We delete it to the extent we can verify your identity, for example by user ID (if known).
- When you delete your account, game data is erased within the periods in Section 9. Scores for the current ranking period are removed from the leaderboard. Trading records, fraud-prevention information and purchase records are kept in de-identified form for the periods in Section 9.
12. Contact
- Operator: 野田晶裕
- Address: provided promptly by e-mail upon request (same treatment as in the Notice under the Act on Specified Commercial Transactions)
- Representative: 野田晶裕
- Contact (e-mail): tomorinoshima.game@outlook.com
13. Revisions
We may revise this Policy to reflect changes in laws or the Service. Important changes are announced through in-Service notices, and we may present the revised Policy at startup of the Service and ask for renewed consent.
Language
This Policy is written in Japanese. Translations into other languages are provided for reference only; in case of any discrepancy, the Japanese text prevails.
Established on [date]