生效日期:2026年9月29日
資料使用者:Labyrinth Studio Limited(「本公司」、「我們」)

白話摘要(唔係政策一部分,只係幫你快啲明):

我哋收嘅嘢好少:你個登入帳戶(Google/Apple)、暱稱、性別,同埋你喺遊戲入面嘅進度(打卡、積分、角色裝扮、人氣)。你撳打卡嗰一刻,部機會將 GPS 座標交去伺服器,核對你係咪真係喺嗰間健身室附近(防作弊);嗰組座標會連住嗰次打卡紀錄一齊儲低。我哋唔會喺後台跟住你,亦冇你嘅行蹤軌跡。 相機淨係用嚟掃職員證 QR 加好友,唔會影相。你嘅相簿我哋唔會掃,淨係兩個情況你會自己揀一張相交畀我哋:① 公會會長揀「公會章」,部機即場縮做 64×64 像素,管理員人手批咗先出;② 你自己揀要唔要喺「職員證」放一張相(唔放都得)。職員證相片會喺伺服器縮細、剷走晒相入面嘅附加資料(包括影相位置),再交 Google Cloud Vision 自動檢查:唔啱嘅相會被拒,拿不定嘅留低等我哋人手睇,過咗先會喺你張職員證同 GymL龍虎榜(人氣榜同小遊戲排行榜)你個名隔離出現,所有已登入嘅人都睇到;你隨時可以移除。你打咗卡之後,同一個健身品牌全港分店打咗卡嘅人,都可能喺房入面見到你嘅暱稱、角色、地區同人氣。呢個 app 冇廣告、冇賣你資料、冇第三方追蹤分析。你隨時可以要求刪除帳戶,30 日後帳戶同個人資料會剷走(第 5 條講嘅少數例外除外,例如你喺公開頻道同討論區講過嘅嘢)。有問題,電郵搵我哋。

本政策說明我們如何收集、使用、披露及保障你的個人資料,並構成《個人資料(私隱)條例》(香港法例第 486 章)(「私隱條例」)下的收集個人資料聲明(PICS)。


1. 我們收集的資料

1.1 你直接提供的資料

類別內容收集時點
帳戶資料電郵地址(Google/Apple 登入)註冊時
個人檔案暱稱、性別、登入帳戶頭像連結(如你的 Google/Apple 帳戶附有)註冊時
同意紀錄你接受本政策及《服務條款》的版本編號及時間註冊時
遊戲設定虛擬角色配置(身形、服裝)、主場地區遊戲過程中
用戶內容私人訊息、頻道訊息、討論區帖子及回覆、投票、留言你發布時
舉報與封鎖你封鎖的用戶名單、你提交的舉報內容(包括對其他用戶職員證相片的舉報)你使用相關功能時
公會章公會會長為公會提交的標誌圖片:由你相簿中自行選取的一張相片,在你的裝置上裁切並縮小為 64×64 像素 PNG(不多於 32 KB)後上傳你提交公會章時
職員證相片(可選)你由相簿中自行選取的一張相片,顯示於你的「職員證」及 GymL龍虎榜(見第 3 條)。你的裝置先讓你裁切該相片並縮小(裁切後約 512 × 583 像素)才上傳;我們的伺服器再將其轉換為最長邊不超過 384 像素的 JPEG,並移除相片內的所有附加資料(包括 EXIF 拍攝位置、拍攝時間及裝置資料)後才儲存。你原本選取的相片及上傳的版本均不會被儲存你設定職員證相片時
私訊花名你為好友設定、只在你的私訊中顯示的名稱你設定時
邀請碼及邀請關係系統為你產生的專屬邀請碼;如你輸入朋友的邀請碼,我們會記錄「誰邀請了誰」(你的及對方的用戶編號、所用邀請碼、輸入時間)及被邀請人打卡的日數。只用於核對及發放邀請獎勵;該紀錄只有該對邀請人及被邀請人本人讀取得到,不會向其他用戶顯示你取得邀請碼時;你輸入邀請碼時;被邀請人其後打卡時

1.2 自動產生的資料

類別內容
遊戲進度打卡紀錄(健身室名稱、所屬品牌及地區、時間,及打卡當刻的位置座標 — 見第 1.3 條)、你去過的健身室清單、積分、代幣、碎片、經驗值、等級、每週連續打卡紀錄、活躍日數、已解鎖服裝及扭蛋收藏、小遊戲分數及排行榜紀錄
社交紀錄好友請求及好友紀錄、對話清單、透過「職員證」QR 加好友時產生的一次性配對碼(內含你的用戶編號及當時所在的健身室)、你在健身室及辦公室空間的在場狀態及所發出的表情動作
人氣你收到的 🔥 總數及每週數目(即人氣及人氣榜紀錄);你每日送出 🔥 的總數及送給每位用戶的數目(只保留最近一個送出日的紀錄);你收到 🔥 時,你的在場紀錄會更新你的人氣數目(不會記下送出者是誰)
安全紀錄打卡距離核對結果、定位精確度、你的裝置是否回報該定位為模擬(mock)位置、操作速率限制計數、職員證相片的每日更換次數、職員證相片的自動審查結果(被拒絕或需人手審核的相片,其 Google Cloud Vision 評級會連同你的用戶編號保存)、你提交或涉及的舉報及其處理結果
裝置資料推送通知登記碼(FCM token)
購買紀錄你透過 App Store 購買的項目、Apple 簽發的交易編號、購買時間及交易環境。付款由 Apple 處理,我們不會收到你的付款卡、帳單或 Apple 帳戶資料

語言偏好只儲存在你的裝置上,不會上傳至我們的伺服器。

1.3 位置資料 — 特別說明

打卡功能需要存取你裝置的位置。當你按下打卡:

  1. 應用程式讀取你當時的 GPS 座標及定位精確度,連同你所選的健身室送交我們的伺服器;
  2. 伺服器計算你與該健身室的距離,超出範圍即拒絕打卡 — 這是防止偽造打卡所必需的核對;
  3. 核對通過後,該次打卡當刻的座標(四捨五入至小數點後 5 位,約 1 米精度)及定位精確度,會連同該次打卡紀錄一併儲存,以便日後覆核打卡真偽。

我們不會在背景持續讀取你的位置,亦不會儲存打卡以外的任何位置點,因此不存在你的移動軌跡。如你的裝置回報該定位為模擬(mock)位置,我們只會收到「是/否」這項訊號並拒絕該次打卡。打卡座標隨該次打卡紀錄保存,並於帳戶永久刪除時一併刪除(見第 5 及第 6 條)。你可隨時於裝置系統設定關閉位置權限(打卡功能將無法使用,其他功能不受影響)。

1.4 我們不會收集的資料

1.5 過往版本的歷史資料

如你由舊版應用程式(GymWorld iOS)遷移而來,你的帳戶或存有舊版功能收集的資料(如個人簡介、健身程度、目標部位、相片集)。新版應用程式不再收集此等資料;現存的歷史資料會按第 5 條的保留政策處理,你亦可電郵要求我們提前刪除。

2. 收集目的

我們只會為以下目的使用你的個人資料:

  1. 建立及管理你的帳戶,提供本服務的核心功能;
  2. 促成遊戲內社交功能(加好友、聊天、討論區、排行榜、人氣榜、職員證);
  3. 發送服務通知及推送訊息(你可隨時於系統設定關閉);
  4. 維持服務安全:核對打卡位置、防止欺詐、濫用、多重帳戶及偽造打卡,審查用戶上載的相片,處理舉報及執行社群規則;
  5. 遵守適用法律或監管要求。

提供第 1.1 條所列的帳戶資料屬自願性質,但如不提供,我們將無法為你建立帳戶及提供本服務。職員證相片及私訊花名完全屬自願性質,不提供亦不影響你使用本服務。我們不會將你的個人資料用於直接促銷,如日後擬作此用途,將按私隱條例事先取得你的同意。

3. 其他用戶可見的資料

以下資料會向其他用戶展示,屬本服務社交功能的固有部分:

你的電郵及打卡位置座標不會向其他用戶展示。你的性別不會以文字顯示,但你註冊時選擇的性別決定你虛擬角色的男/女身形,其他用戶可從角色外觀看到。你為好友設定的私訊花名只有你自己看到。

4. 資料的披露及轉移

4.1 我們不會出售你的個人資料。我們只會向以下類別的承讓人披露資料:

承讓人目的地點
Google LLC(Firebase:身份驗證、資料庫、檔案儲存、雲端函數、推送通知)本服務的後端基礎設施Google 數據中心(後端雲端函數位於亞洲東部二區(香港);其他 Google 服務可能位於美國或其他地區)
Google LLC(Google Cloud Vision SafeSearch)自動檢查職員證相片是否可能含成人、暴力或性感內容。我們只傳送經伺服器縮小並已移除附加資料的相片本身,不附你的暱稱或用戶編號。Google 就此服務處理資料的說明:Cloud Vision Data Usage FAQGoogle 數據中心(可能位於香港以外)
Apple Inc. / Google LLC(登入服務)帳戶登入驗證美國
執法機關或監管機構應法律要求或法院命令視乎要求

職員證相片的自動審查結果如下:任何一項被評為「頗有可能」(LIKELY)或「極有可能」(VERY_LIKELY)的相片會被拒絕,不會儲存;任何一項被評為「有可能」(POSSIBLE)、評級不明或檢查未能完成的相片,會留待我們的管理員人手審核,批准後才會顯示;其餘相片會直接顯示於你的職員證。

4.2 上述轉移可能涉及將資料傳送至香港以外地區(主要為美國)。我們的後端雲端函數部署於 Google 的亞洲東部二區(香港),惟身份驗證、資料庫、檔案儲存、推送通知及 Cloud Vision 等其他 Google 服務可能在香港以外的 Google 數據中心處理資料。我們透過與服務供應商訂立的資料處理條款,要求其提供不低於私隱條例標準的保障。

5. 資料保留

資料保留期
帳戶及個人檔案帳戶有效期內;停用後 30 日永久刪除
打卡紀錄(包括打卡座標)、好友請求及好友紀錄、私人訊息及對話(雙方的副本)、QR 配對碼、速率限制紀錄、每日計數(送出 🔥 及更換相片的次數)、私訊花名、儲存檔案隨帳戶永久刪除一併刪除
討論區帖子及回覆、健身室/地區/全港/辦公室頻道訊息為維持其他用戶的對話完整性,於帳戶刪除後繼續保留。該等內容仍附有你原帳戶的用戶編號,惟該編號屆時已不對應任何有效帳戶,亦無法用以查閱你的個人檔案(檔案已刪除)。如你希望移除某項已發布的內容,請於刪除帳戶前自行刪除,或電郵要求我們處理
人氣榜及小遊戲排行榜紀錄帳戶有效期內;於你要求刪除帳戶時即時移除(人氣榜每週榜以最近 27 週為限,更早的每週榜紀錄會保留,但只載有當時的暱稱、虛擬角色及分數)
職員證相片已顯示的相片保存至你更換或移除相片、我們移除該相片,或你提出刪除帳戶為止,屆時隨即刪除;更換相片後,舊相片隨即刪除。被自動審查拒絕的相片不會儲存。需要人手審核的相片於審核完成後處理(批准即顯示,拒絕即刪除)。被舉報而暫時收起的相片會保留至我們審視完畢,其後刪除或恢復顯示
公會章圖片待審核的圖片於審核完成(批准或拒絕)後刪除;已批准的公會章於公會更換會章或解散時刪除
邀請碼及邀請關係帳戶有效期內保存,只用於發放邀請獎勵。你要求刪除帳戶時,你的邀請碼、你自己的「被邀請」紀錄及相關核對紀錄即時移除;你邀請的朋友的邀請紀錄屬於該朋友的帳戶,會保留至該朋友刪除帳戶為止,期間只載有你已失效的用戶編號
購買紀錄(交易編號)為防止重複派發、處理退款爭議及會計目的保留,不會因帳戶刪除而自動刪除;紀錄只載有交易編號、項目及你原帳戶的用戶編號,該編號屆時已不對應任何有效帳戶
舉報紀錄及相關安全紀錄(包括相片審查評級及審批紀錄)為安全、防止濫用及法律目的保留,不會因舉報人或被舉報人刪除帳戶而自動刪除;我們會在不再需要時刪除

6. 帳戶刪除

你可於應用程式內「背囊 → 設定 → 刪除帳戶」提出刪除要求,亦可電郵至下述地址提出。流程如下:

  1. 帳戶即時停用,登入功能同時封鎖,其他用戶無法再看見你;你的職員證相片同時刪除(如你其後於復原期內恢復帳戶,相片不會恢復,你可重新設定);
  2. 30 日復原期內,你可電郵至下述地址要求復原帳戶(由於登入已被封鎖,無法以重新登入的方式取消刪除);
  3. 30 日屆滿後,系統自動永久刪除你的帳戶、個人檔案、打卡紀錄(包括打卡座標)、好友請求及好友紀錄、私人訊息及對話、QR 配對碼、每日計數、私訊花名及儲存檔案,並註銷你的登入憑證。此操作不可逆轉,所有虛擬物品同時失效。第 5 條所述已與其他用戶共享的內容及安全紀錄除外。

你的人氣榜及小遊戲排行榜紀錄亦會於你要求刪除帳戶時移除(見第 5 條)。其他用戶為你設定的私訊花名屬於該用戶的帳戶,只有該用戶看到。

7. 資料保安

我們採取合理可行的措施保障你的個人資料,包括:傳輸加密(TLS)、伺服器端存取規則(每名用戶只可存取自己的資料)、後端函數的身份驗證及速率限制、以及員工存取限制。惟互聯網傳輸無法保證絕對安全,如發生涉及你個人資料的重大資料外洩事故,我們會按私隱公署的指引通知你及相關監管機構。

8. 你的權利

根據私隱條例,你有權:

行使查閱或改正權,請電郵至下述地址。我們會於 40 日內回覆。我們可就查閱要求收取合理費用。

9. 未成年人

本服務並無最低年齡限制,我們亦不會要求用戶提供年齡或出生日期。如你未滿 18 歲,請先徵得家長或監護人同意方使用本服務。家長或監護人可電郵聯絡我們,要求查閱或刪除未成年人的個人資料(見第 8 及第 11 條)。

10. 政策修訂

我們可不時修訂本政策。重大修訂會透過應用程式內通知提前告知。修訂後的政策於公布的生效日期起適用。

11. 聯絡我們及投訴


文件版本:v1.1(2026年9月29日)

ENGLISH

Effective date: 29 September 2026
Data user: Labyrinth Studio Limited ("the Company", "we", "us")

Plain-language summary (not part of the Policy):

We collect very little: your sign-in account (Google/Apple), nickname, gender, and your in-game progress (check-ins, points, avatar outfit, popularity). When you tap check-in, your phone sends its GPS coordinates to our server to verify you are really at that gym (anti-cheat), and those check-in coordinates are stored with that check-in record. We do not track you in the background and we hold no movement history. The camera is used only to scan a staff-card QR to add a friend — no photos are taken. We never scan your photo library; there are only two cases where you hand us one photo you picked yourself: ① a clan owner picks a clan crest, which your phone shrinks to 64×64 pixels on the spot and a human admin reviews before it appears; ② you choose to put a photo on your staff card (optional). A staff card photo is shrunk on our server, stripped of all embedded data (including where it was taken), then checked automatically by Google Cloud Vision: unsuitable photos are refused, uncertain ones wait for a human review, and only then does it appear on your staff card and next to your name on the GymL leaderboards (popularity and mini-game boards), where every signed-in user can see it; you can remove it any time. Once you check in, people checked in at any branch of the same gym brand across Hong Kong may see your nickname, avatar, district and popularity in the room. No ads, no selling your data, no third-party tracking. You can request account deletion any time; after 30 days your account and personal data are wiped (with the few exceptions in section 5, such as what you said in public channels and the forum). Questions? Email us.

This Policy explains how we collect, use, disclose and protect your personal data, and constitutes our Personal Information Collection Statement (PICS) under the Personal Data (Privacy) Ordinance (Cap. 486, Laws of Hong Kong) (the "Ordinance").


1. Data We Collect

1.1 Data you provide directly

CategoryDataWhen
AccountEmail address (Google/Apple sign-in)At registration
ProfileNickname, gender, the link to your sign-in account's profile picture (if your Google/Apple account has one)At registration
Consent recordThe version and timestamp of the Terms and this Policy you acceptedAt registration
Game settingsAvatar configuration (body, costumes), home districtDuring play
User contentPrivate messages, channel messages, forum threads and replies, votes, commentsWhen you post
Invite code and invite linkThe personal invite code we generate for you; if you enter a friend's invite code, we record who invited whom (both user ids, the code used, the time) and how many days the invited player has checked in. Used only to verify and pay the invite reward; the record can be read only by that inviter and that invited player themselves and is never shown to other usersWhen you get your code; when you enter a code; when the invited player later checks in
Reports & blocksUsers you block, reports you submit (including reports about another user's staff card photo)When you use those features
Clan crestThe crest image a clan owner submits for their clan: one photo you pick yourself from your library, cropped and downscaled on your device to a 64×64 pixel PNG (at most 32 KB) before uploadWhen you submit a crest
Staff card photo (optional)One photo you pick yourself from your library, shown on your "staff card" and on the GymL leaderboards (see section 3). Your device first lets you crop it and shrinks it (about 512 × 583 pixels after cropping) before upload; our server then converts it to a JPEG of at most 384 pixels on the long side and removes all embedded data (including EXIF location, capture time and device details) before storing it. Neither the photo you originally picked nor the uploaded copy is storedWhen you set a staff card photo
Private aliasA name you give a friend, shown only in your own private messagesWhen you set one

1.2 Data generated automatically

CategoryData
Game progressCheck-in records (gym name, its brand and district, time and the coordinates at the moment of check-in — see 1.3), the list of gyms you have visited, points, tokens, fragments, XP, level, weekly streak, active days, unlocked costumes and gacha collection, mini-game scores and leaderboard entries
Social recordsFriend requests and friend records, conversation list, the one-time pairing code generated when you add a friend by "staff card" QR (it carries your user id and the gym you were at), your presence in gym and office spaces and the emotes you send
PopularityThe total and weekly number of 🔥 you receive (your popularity and popularity-board entries); how many 🔥 you gave in a day in total and to each user (only the most recent day you gave is kept); when you receive 🔥, your presence record is updated with your popularity count (it does not record who gave it)
Safety recordsCheck-in distance verification result, location accuracy, whether your device reports the fix as a mock location, rate-limit counters, how many times you changed your staff card photo in a day, automated screening results for staff card photos (for a photo that is refused or held for human review, its Google Cloud Vision ratings are kept with your user id), reports you file or that concern you and how they were handled
DevicePush-notification token (FCM)
Purchase historyThe items you buy through the App Store, the Apple-issued transaction identifier, the purchase time and the transaction environment. Payment is handled by Apple; we do not receive your payment card, billing or Apple account details

Your language preference is stored on your device only and is not uploaded to our servers.

1.3 Location data — special note

Check-ins need access to your device location. When you tap check-in:

  1. the app reads your current GPS coordinates and location accuracy and sends them, with the gym you selected, to our server;
  2. the server computes your distance to that gym and refuses the check-in if you are outside the radius — this verification is necessary to prevent spoofed check-ins;
  3. once verified, the coordinates at the moment of that check-in (rounded to 5 decimal places, roughly 1 m) and the location accuracy are stored on that check-in record, so the check-in can be re-verified later.

We do not read your location in the background and we store no location point other than your check-ins, so no movement history exists. If your device reports the fix as a mock location, we receive only that yes/no signal and refuse the check-in. Check-in coordinates are kept with the check-in record and are deleted when your account is permanently deleted (see sections 5 and 6). You can disable location permission in your device settings at any time (check-ins will stop working; everything else is unaffected).

1.4 What we do not collect

1.5 Legacy data from previous versions

If you migrated from the previous app (GymWorld iOS), your account may hold data collected by retired features (e.g. bio, fitness level, target body parts, photo gallery). The current app no longer collects such data; existing legacy data is handled under the retention rules in section 5, and you may email us to request earlier deletion.

2. Purposes of Collection

We use your personal data only to:

  1. create and manage your account and provide the Service's core features;
  2. enable in-game social features (adding friends, chat, forums, leaderboards, the popularity board, staff cards);
  3. send service and push notifications (you can turn these off in system settings);
  4. keep the Service safe: verify check-in location, prevent fraud, abuse, multi-accounting and spoofed check-ins; screen photos users upload; handle reports; enforce community rules;
  5. comply with applicable legal or regulatory requirements.

Providing the account data in section 1.1 is voluntary, but without it we cannot create an account or provide the Service. A staff card photo and private aliases are entirely voluntary; leaving them out does not affect your use of the Service. We do not use your personal data for direct marketing; if we ever intend to, we will first obtain your consent as required by the Ordinance.

3. Data Visible to Other Users

The following is shown to other users as an inherent part of the Service's social features:

Your email and check-in coordinates are never shown to other users. Your gender is not shown as text, but the gender you chose at sign-up sets your avatar's male or female figure, which other users can see. The private aliases you give friends are visible only to you.

4. Disclosure and Transfer of Data

4.1 We do not sell your personal data. We disclose it only to the following classes of transferees:

TransfereePurposeLocation
Google LLC (Firebase: authentication, database, file storage, cloud functions, push notifications)Backend infrastructure of the ServiceGoogle data centres (our backend cloud functions run in asia-east2 (Hong Kong); other Google services may run in the United States or elsewhere)
Google LLC (Google Cloud Vision SafeSearch)Automated check of whether a staff card photo is likely to contain adult, violent or racy content. We send only the photo itself, after our server has shrunk it and removed its embedded data — not your nickname or user id. Google's description of how this service handles data: Cloud Vision Data Usage FAQGoogle data centres (may be outside Hong Kong)
Apple Inc. / Google LLC (sign-in services)Account authenticationUnited States
Law-enforcement or regulatory authoritiesWhere required by law or court orderAs required

The automated screening of staff card photos works as follows: a photo rated LIKELY or VERY_LIKELY in any of these categories is refused and not stored; a photo rated POSSIBLE in any of them, or with an unclear rating, or whose check could not be completed, is held for human review by our admins and shown only once approved; any other photo appears on your staff card straight away.

4.2 These transfers may involve sending data outside Hong Kong (mainly to the United States). Our backend cloud functions are deployed in Google's asia-east2 (Hong Kong) region, but other Google services — authentication, the database, file storage, push notifications and Cloud Vision — may process data in Google data centres outside Hong Kong. Through data-processing terms with our service providers we require protection no less stringent than the Ordinance's standards.

5. Data Retention

DataRetention
Account and profileLife of the account; permanently deleted 30 days after deactivation
Check-in records (including check-in coordinates), friend requests and friend records, private messages and conversations (both sides' copies), QR pairing codes, rate-limit records, daily counters (🔥 given and photo changes), private aliases, stored filesDeleted together with the account
Forum threads and replies, gym/district/Hong Kong-wide/office channel messagesRetained after account deletion, to preserve conversation integrity for other users. Such content still carries your former user id, but that id no longer corresponds to any live account and cannot be used to reach your profile (which has been deleted). If you want a specific post removed, delete it before deleting your account, or email us
Popularity board and mini-game leaderboard entriesLife of the account; removed at once when you request account deletion (weekly popularity boards are cleared for the most recent 27 weeks; older weekly boards keep their entries, which hold only the nickname, avatar and score of that time)
Staff card photoA displayed photo is kept until you replace or remove it, we remove it, or you request account deletion, and is then deleted; when you replace your photo the old one is deleted. A photo refused by the automated screening is never stored. A photo held for human review is dealt with once reviewed (shown if approved, deleted if rejected). A photo temporarily hidden after reports is kept until we have reviewed it, then deleted or shown again
Invite code and invite linkKept for the life of the account and used only to pay the invite reward. When you request account deletion, your invite code, your own "invited by" record and the related verification records are removed at once; the record of a friend you invited belongs to that friend's account and is kept until they delete theirs, holding only your (by then dead) user id
Clan crest imagesA pending image is deleted once the review is decided (approved or rejected); an approved crest is deleted when the clan replaces it or is dissolved
Purchase history (transaction identifiers)Kept to prevent duplicate grants, to handle refund disputes and for accounting, and not deleted automatically when an account is deleted; the record holds only the transaction identifier, the item and the user ID of your former account, which by then no longer matches any active account
Report records and related safety records (including photo screening ratings and review decisions)Kept for safety, abuse-prevention and legal purposes; they are not automatically deleted when the reporter's or reported user's account is deleted. We delete them when they are no longer needed

6. Account Deletion

Request deletion in-app via Backpack (背囊) → Settings → Delete Account, or by email (below):

  1. your account is deactivated immediately, sign-in is blocked and you are hidden from other users; your staff card photo is deleted at the same time (if you later restore the account within the recovery window, the photo does not come back — you can set a new one);
  2. during a 30-day recovery window you can email us to restore the account (because sign-in is blocked, simply logging back in cannot cancel the deletion);
  3. after 30 days, your account, profile, check-in records (including check-in coordinates), friend requests and friend records, private messages and conversations, QR pairing codes, daily counters, private aliases and stored files are permanently deleted and your sign-in credentials revoked. This is irreversible; all Virtual Items lapse with the account. Content already shared with other users, and the safety records described in section 5, are excepted.

Your popularity board and mini-game leaderboard entries are also removed when you request account deletion (see section 5). Private aliases other users have given you belong to their accounts and are visible only to them.

7. Data Security

We take reasonably practicable steps to protect your personal data, including: encryption in transit (TLS), server-side access rules (each user can access only their own data), authentication and rate-limiting on backend functions, and restricted staff access. No internet transmission is completely secure; in the event of a material data breach affecting your personal data we will notify you and the relevant authorities in line with PCPD guidance.

8. Your Rights

Under the Ordinance you may:

To exercise access or correction rights, email us (below). We respond within 40 days. A reasonable fee may apply to access requests.

9. Minors

There is no minimum age for the Service, and we do not ask users for their age or date of birth. If you are under 18, please obtain a parent's or guardian's consent before using the Service. Parents and guardians may email us to access or delete a minor's personal data (see sections 8 and 11).

10. Changes to This Policy

We may revise this Policy from time to time. Material changes will be notified in-app in advance. The revised Policy applies from its stated effective date.

11. Contact and Complaints


Document version: v1.1 (29 September 2026). In case of discrepancy with the Chinese version, the Chinese version prevails.