Privacy Policy

Effective Date: September 29, 2026

This Information Stewardship & Governance Code delineates the exact regulations Yimu Health Care ("we," "us," or "our") follows to extract, manage, and safeguard your personal information during your engagement with Color Bottle: Water Sort via the Google Play distribution network. Our primary directive in governing this data is to orchestrate a superior digital gaming experience while strictly adhering to data protection mandates.

1. Information Ingestion Protocols

We utilize a multi-tiered approach to collect and oversee your personal data, governed by an uncompromising stance on digital security. The following sections define the precise categories of data we log and our standard operating procedures.

1.1 Data Taxonomies Extracted Upon the execution of Color Bottle: Water Sort , our network infrastructure automatically intercepts the following data streams:

Network Telemetry: IP routing information, exact server connection timestamps, and base hardware categorizations.

Device Schematics: The manufacturer, precise hardware model, operating system environment (Android/Google OS), localized time parameters, and system UI language.

Hardware Trackers: Unique alphanumeric strings tethered to your device, specifically the Google Advertising ID (GAID), Android Device ID, Google Play Games profile ID, and your overarching Google Account identifier.

Behavioral Gameplay Metrics: Progression timelines, zenith scores, achievement milestones, and data payloads from multiplayer engagements.

Economic Ledgers: Histories of virtual asset consumption, fiscal transactions, tailored account configurations, and records of digital currency acquisition.

1.2 Integrated Third-Party Gateways Should you elect to authenticate your identity via external hubs like Google Play Games Services, we shall import approved profile vectors (e.g., public aliases) in strict adherence to their API authorization logic. This importation is fundamentally contingent on your prior ratification of the third party's data syndication policies. Users are legally advised to scrutinize the compliance frameworks of these external entities:

Google Play Games / Google Services: https://policies.google.com/privacy

By authenticating via a third-party gateway, you formally stipulate that:

Your operational usage is in complete harmony with the prevailing Terms of Service of that external platform.

You satisfy the legal age of consent mandated by the third party within your specific legal jurisdiction.

2. Statutory Basis for Data Processing

We process your personal information exclusively to satisfy the operational mandates listed below, ensuring every action is supported by a codified lawful foundation:

Service Fulfillment & Helpdesk: To clear commercial transactions, resolve support tickets, and maintain communication pipelines; to execute fundamental game mechanics, apply custom user states, and distribute software patches, security warnings, and administrative notifications.

Lawful Foundation: Anchored in GDPR Article 6(1)(b) (contractual necessity). This processing is a mandatory requirement to uphold our Terms of Service and maintain software viability.

Product Refinement & Promotions: To dispatch curated marketing materials concerning Yimu Health Care or authorized partners; to archive user preferences; and to conduct analytical research aimed at feature development, software refinement, and optimization of our marketing apparatus.

Lawful Foundation: Authorized by GDPR Article 6(1)(f) (legitimate interests). We utilize this provision to fulfill our legitimate corporate interest in refining our product and elevating consumer satisfaction.

Targeted Commercial Advertising: To project customized marketing content to users who have explicitly permitted our advertising affiliates to interface with their device identifiers.

Lawful Foundation: Equally supported by GDPR Article 6(1)(f). This serves our legitimate commercial necessity to monetize the platform effectively through targeted ad placements.

3. Data Archival and Expiration Guidelines

Your personal information is retained strictly for the duration necessary to provision our software, comply with legislative mandates, and manage legal liabilities. For scenarios encompassing arbitration, contract enforcement, infrastructural auditing, or regulatory compliance, we retain the jurisdiction to archive specific data segments for the legally mandated epoch. Additionally, anonymized and aggregated Usage Data is retained for internal auditing. Such data is typically purged rapidly unless an extended retention period is compelled by law or is necessary to secure our network infrastructure against identified threats.

4. Authorized External Disclosures

In strict observance of user privacy entitlements and governed by GDPR Articles 6(1)(b), 6(1)(c), and 6(1)(f), we may facilitate the transfer of your data to authorized external parties under the following conditions:

Strategic Partners: For the delivery of integrated services, legal compliance, corporate restructurings, or any initiative demanding your explicit consent.

Law Enforcement & Regulatory Bodies: In the event of a verified breach of our policies, or if statutory obligations necessitate disclosure to protect the physical safety, legal rights, or intellectual property of Yimu Health Care and the general public.

Public Player Communities: Consequent to your engagement in networked multiplayer environments, message boards, or global leaderboards.

4.1 Syndication to Advertising Coalitions Subject to the receipt of your explicit consent as dictated by GDPR Article 6(1), we shall transfer your device identifiers to advertising coalitions to power targeted ad campaigns. Our authorized roster of advertising affiliates encompasses:

Applovin Corporation: https://www.applovin.com/privacy/

AdColony: https://yandex.com/legal/international_ads_privacy_policy

Amazon Publisher Services: https://www.amazon.com/privacyprefs

Meta (Facebook, Inc.): https://www.facebook.com/about/privacy/

Google LLC: https://policies.google.com/privacy

Google Admob: https://support.google.com/admob/

Unity Technologies: https://unity3d.com/legal/privacy-policy

IronSource: http://www.ironsrc.com/wp-content/uploads/2019/03/ironSource-Privacy-Policy.pdf

Vungle, Inc.: https://vungle.com/privacy/

Fyber: https://www.fyber.com/privacy-policy/

InMobi: https://www.inmobi.com/privacy-policy/

Disclaimer: This Governance Code does not regulate the independent data processing logic of these external corporations. Users must consult the respective privacy notices of these organizations to understand their data stewardship.

4.2 Infrastructure Sub-processors To sustain backend operations and prevent server degradation, we engage specialized data sub-processors, including hosting facilities and analytical engines:

Firebase (Google LLC): https://firebase.google.com/support/privacy

Adjust: https://www.adjust.com/terms/privacy-policy/

5. Child Privacy Mandates

The Color Bottle: Water Sort application is strictly not engineered for, nor commercially marketed to, individuals under the age of 13. We enforce a strict prohibition against the intentional capture of personally identifiable information from this age bracket. Upon confirmation that such data has been inadvertently collected, permanent erasure protocols will be executed immediately. Legal guardians identifying unauthorized data submissions by minors are instructed to contact us forthwith to initiate remediation.

6. Cybersecurity Posture

We acknowledge the sensitivity of your data and deploy commercially robust cryptographic and operational safeguards to defend your personal information. Notwithstanding these protocols, users must concede that no digital transmission or data storage network can ensure absolute invulnerability. We therefore cannot offer an absolute legal warranty against unauthorized data exfiltration.

7. OS-Level Alert Authorizations

Conditioned upon your explicit opt-in flag, we may transmit system alerts, promotional notifications, and critical update logs directly to your Android/Google operating system. Users possess the absolute right to rescind this authorization and disable such push communications globally via their device’s native notification settings.

8. Jurisdictional Privacy Entitlements

8.1 European Economic Area (EEA) Stipulations We are bound to process valid privacy inquiries within a standard operational window of one month. For submissions of significant complexity, GDPR Article 12 permits an extension of an additional two months. We shall proactively issue written notification detailing the rationale for any such extension.

(1) Right of Access: Under GDPR Article 15, you may formally request granular disclosures concerning your retained data, including processing motives, data classifications, recipients, and retention limits. A digital copy may be requested, provided it does not infringe upon trade secrets.

(2) Right to Object: Pursuant to GDPR Article 21, you may formally contest data processing activities justified by "legitimate interests" (Article 6(1)(f)). We shall suspend operations unless we demonstrate overriding legal justifications. The right to object to direct marketing is absolute.

(3) Right to Rectification: Mandated by GDPR Article 16, you hold the legal right to compel the correction of inaccurate or incomplete profile records.

(4) Right to Restriction: Under GDPR Article 18, you may compel our organization to restrict the active processing of your data under stringently defined legal conditions.

(5) Right to Withdraw Consent: Dictated by GDPR Article 7, if processing hinges upon your consent, you may nullify said consent at any time. This revocation is prospective and does not invalidate prior processing.

(6) Right to Data Portability: Authorized by GDPR Article 20, you possess the entitlement to extract your personal data in a standardized, machine-readable format and transfer it to an alternate data controller without systemic interference.

8.2 California Resident Stipulations (CCPA)

(1) Execution Timeline: We adhere to a 45-day statutory turnaround for verifiable consumer inquiries. Should constraints necessitate a prolongation (up to a 90-day maximum), formal written notification shall be dispatched.

(2) Disclosure Scope: Evidentiary data disclosures are strictly limited to information aggregated within the 12-month trailing window preceding your formal request.

(3) Right to Opt-Out: The CCPA guarantees your right to explicitly instruct our organization to cease the commercial sale of your personal information.

(4) Right to Know: You are empowered to comprehend the exact data categories we harvest and our operational motives, as codified in this annually reviewed Code.

(5) Access Petitions: You may demand a comprehensive audit of the personal information logged over the trailing 12 months (executable twice per calendar year without penalty).

(6) Right to Erasure: You may instigate the permanent deletion of personal data gathered over the preceding 12 months, subject strictly to statutory exemptions (e.g., legal compliance, security auditing).

9. Execution of Data Erasure

Upon the cessation of the operational necessity for your personal data, you are authorized to mandate its secure destruction. To formally trigger these erasure protocols, submit your explicit directive to the compliance contact email designated below.

10. Corporate Communication Hub

For regulatory inquiries, compliance clarifications, or the execution of formal privacy rights, direct all communications to: Contact Email: sisknxbxxt78902@gmail.com