Privacy Policy

Appalex Limited · Last updated: October 4, 2026

This Privacy Policy applies to the following Appalex apps:

Exception — Wordy: The Wordy language-learning app is governed by a separate privacy policy at wordy.info/privacy. This policy does not apply to Wordy.

Our Commitment to Privacy

Appalex Limited (“we”, “our”, “us”) is committed to protecting the privacy and security of our users’ personal information. We strive to be transparent about our data practices and to provide you with control over your personal information.

This Privacy Policy explains how we collect, use, share, and protect your information when you use the Appalex apps listed above (the “Apps”). We comply with the General Data Protection Regulation (GDPR) for our European users and applicable US privacy laws for our American users.

1. Data Controller

Company Name: Appalex Limited
Address: 1012 Budapest, Logodi utca 48. A. lház. 1. em. 2. ajtó, Hungary
Company Registration: 01-09-433441
Tax Number: 32612600-2-41
Email: info@appalex.hu
Phone: +36 70 213 3578

Data Protection Contact:
Email: info@appalex.hu
Phone: +36 70 213 3578

2. Data Processors

We work with trusted third-party service providers who process data on our behalf. Not every processor applies to every App; the actual set used depends on the specific App and platform.

Processor Name and LocationPurpose
Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) (DPF certified)Google Analytics for Firebase, Firebase Crashlytics, Firebase Remote Config, Firebase Cloud Messaging; Google Play Billing (Android apps only)
Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) (DPF certified)Google AdMob and the User Messaging Platform (UMP): advertising, ad measurement and consent management (Torpedo)
Ad networks that bid for ads through Google AdMob (Torpedo): AppLovin Corp. (USA); Unity Technologies SF (Unity Ads, USA); Meta (Meta Audience Network); Liftoff Monetize and Vungle Exchange; Mintegral International Limited; Pangle (ByteDance); InMobi Technology Services Pte. Ltd.; ironSource Mobile (Unity)Competing to fill each ad shown in Torpedo (mediation and bidding), measuring and paying for ads, and preventing ad fraud. Each receives your consent and privacy choices along with the ad request (see 3, “Ad networks”)
Apple Inc. (One Apple Park Way, Cupertino, CA 95014, USA)StoreKit (iOS in-app purchases), App Store services, Apple Ads attribution (AdServices), AdAttributionKit and SKAdNetwork, Game Center (online play, leaderboards, achievements), iCloud (syncing your own game progress), Declared Age Range
RevenueCat Inc. (1032 E Brandon Blvd #3003, Brandon, FL 33511, USA)Subscription and in-app purchase management, purchase and ad-revenue measurement (including Torpedo)
OneSignal Inc. (201 S. B Street, Suite 200, San Mateo, CA 94401, USA) (DPF certified)Push notifications (not used by Torpedo)

3. Information We Collect

The specific data collected depends on which App you use and on the App’s functionality.

3.1. Device and Technical Data

Data collected:

Purpose: Compatibility, troubleshooting, security
Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
Retention: 1 year

3.2. Usage Analytics

Data collected:

Purpose: Service improvement, user experience enhancement, troubleshooting
Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
Retention: 2 years

3.3. Purchase and Subscription Data (only for Apps with in-app purchases)

Data collected:

Purpose: Subscription management, billing, customer support
Legal basis: Contract performance (GDPR Art. 6(1)(b))
Retention: As required by tax law (typically 7–10 years)

3.4. Push Notifications (only for Apps that send notifications)

Data collected:

Purpose: Sending notifications you have opted in to receive
Legal basis: Consent (GDPR Art. 6(1)(a)) — you may revoke this in your device settings at any time
Retention: Until opt-out

3.5. Camera and Photo Library (only for Apps that use the camera)

Apps such as TCG Card Scanner, Tree Identifier, and Photography Poses may request access to your device camera and/or photo library to provide their core functionality (e.g., scanning a card, identifying a tree, viewing reference photos). Camera input is processed on-device or transiently for the requested feature; we do not store your photos on our servers unless explicitly required by the App and disclosed in-app.

Legal basis: Contract performance (GDPR Art. 6(1)(b)) — access is granted by you on first request

3.6. Location Data (only for Apps that use location)

Hungary Public Transit may use location data to find nearby stops and provide route information. Location is accessed only while you are using the relevant feature and is not stored on our servers.

Legal basis: Contract performance (GDPR Art. 6(1)(b))

3.7. Torpedo: Sea Battle 2 Player (iOS)

This section describes everything Torpedo collects and who receives it. Where it differs from the general sections above, this section applies to Torpedo.

No account. Torpedo has no sign-up or login. It never asks for your name, email address, phone number, contacts, photos or precise location. The app creates a random ID when it is first opened; it identifies the install, not you, and is synced through your own iCloud so a new device keeps the same ID.

Who receives what

ServiceWhat it receivesWhy
Google AdMob with the User Messaging Platform (Google)The app-specific device identifier (IDFV); the advertising identifier (IDFA) only if you allow tracking; coarse location derived from your IP address; ad requests, impressions, clicks and the revenue of each ad; device and diagnostic information; your consent choices.Showing ads that keep the game free, measuring them, preventing ad fraud, and asking and storing your consent where the law requires it.
Ad networks through AdMob mediation: AppLovin, Unity Ads, Meta Audience Network, Liftoff Monetize (Vungle), Mintegral, Pangle, InMobi, ironSourceWhen their software starts with the ad SDK and when they bid for an ad: the IDFV; the IDFA only if you allow tracking; coarse location derived from your IP address; device, network and app information; ad requests, impressions and clicks; your privacy choices (the EU consent signals from the privacy form, a US “do not sell or share” choice, and whether you are a minor).Bidding for and showing ads, measuring them and preventing ad fraud. Each network uses the data under its own privacy policy: AppLovin, Unity, Meta, Liftoff, Mintegral, Pangle, InMobi, ironSource.
Google Analytics for Firebase (Google)Gameplay and shop events (for example battles started and finished, rewards claimed, offers seen, purchases and refunds with their value), ad impressions with their revenue, the Apple Ads campaign that led to the install, the random app ID, the Firebase app instance ID, device model, OS and app version, language, and country or region derived from your IP address.Understanding how the game is played, balancing it, fixing problems and measuring our own advertising. Purchases are also reported to Google Ads as conversions, but only when ad signals are allowed (see “Your choices”).
Firebase Crashlytics (Google)Crash reports and other diagnostics (stack traces, device model, OS version, free memory and disk), the random app ID and the Firebase installation ID.Finding and fixing crashes.
Firebase Remote Config (Google)The Firebase installation ID, app version, language and country.Tuning game settings and running experiments (for example offer prices or ad frequency) without an app update.
RevenueCatYour App Store transactions (product, price, currency, dates, renewal status) under the random app ID; the Apple Ads attribution token; the IDFV; the Firebase app instance ID; and each AdMob ad load, impression, click and paid event.Confirming what you own, restoring purchases, managing the Admiral Club subscription, and measuring revenue from purchases and ads. RevenueCat forwards purchases and renewals to Google Analytics under the Firebase app instance ID.
AppleStoreKit purchases; Game Center (your Game Center name, matches, scores, achievements); your iCloud key-value storage (your own progress); the Declared Age Range answer.Payments, online and turn-based play, leaderboards, syncing your progress, and age-appropriate protections. Apple handles this data under its own privacy policy; we never receive your payment details or your Apple Account.
AdAttributionKit / SKAdNetwork (Apple)A small conversion value (for example “finished the first battle” or “made a purchase”) that Apple adds to an anonymous, Apple-signed report, only when an ad led to the install.Measuring which ad campaigns work, without identifying you.

Stays with you. Your rank, medals, statistics, battle history, coins, pearls, layouts and settings are stored on your device and in your own iCloud storage. Nearby battles are sent directly between the two devices. The age range you share through Declared Age Range stays on the device; only the resulting “child” or “under the age of consent” flag reaches ad requests.

Your choices

Children

Torpedo is rated 9+. Where available, it asks iOS for your age range through Apple’s Declared Age Range feature (never your birth date). If you are declared to be under 13, Torpedo:

Players declared to be 13 to 17 get ads tagged as under the age of consent, and every ad network is told not to sell or share their data, and the protections described in the app. Analytics and crash reports are used only to run, secure and improve the game.

Legal basis (EEA, UK, Switzerland)

Consent for personalized advertising, the advertising identifier and Google Analytics storage (GDPR Art. 6(1)(a)); legitimate interest for non-personalized advertising that keeps the game free, for crash reports, fraud prevention, Remote Config and ad and purchase measurement (GDPR Art. 6(1)(f)); contract performance for purchases, restoring them and game features (GDPR Art. 6(1)(b)); legal obligation for keeping purchase records (GDPR Art. 6(1)(c)).

How long we keep Torpedo data

Google’s use of data from apps that use its services is described at policies.google.com/technologies/partner-sites; RevenueCat’s at revenuecat.com/privacy; Apple’s at apple.com/legal/privacy.

4. Cookies and Tracking Technologies

We use only the tracking technologies necessary to operate the Apps and improve user experience:

4.1. Opt-out Options

4.2. Advertising Data

We do not sell your personal data for money. In our ad-supported apps (Torpedo), Google receives identifiers, ad interactions and coarse location to show and measure ads, and purchase events to measure our own ad campaigns. Some US state laws treat this as a “sale” or “sharing” of personal information; see section 12.1 to opt out.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

6. Your Rights

Under data protection laws, you have the following rights:

6.1. Right to Access

You can request information about what personal data we process about you.

6.2. Right to Rectification

You can request correction of inaccurate personal data.

6.3. Right to Erasure (“Right to be Forgotten”)

You can request deletion of your personal data when:

6.4. Right to Restriction

You can request restriction of processing in certain circumstances.

6.5. Right to Data Portability

You have the right to receive your personal data in a structured, machine-readable format. Upon request, we provide your data within 30 days in JSON or CSV format.

6.6. Right to Object

You can object to processing based on legitimate interests.

6.7. Right to Withdraw Consent

You can withdraw previously given consent at any time.

7. International Data Transfers

Some of our processors are located outside the European Economic Area. We ensure appropriate safeguards:

7.1. EU-US Data Privacy Framework (DPF) Certified Partners

7.2. Standard Contractual Clauses (SCC) Protected Partners

7.3. Safeguards

8. Children’s Privacy

Our Apps are not directed primarily at children under 13. We do not knowingly collect personal information from children under 13 except as the Children’s Online Privacy Protection Act (COPPA) allows for supporting an app’s internal operations. Torpedo is rated 9+ and applies the protections for players declared to be under 13 described in section 3.7. If you believe we have collected personal information from a child under 13 without these protections, email info@appalex.hu and we will delete it promptly. In the EEA, we follow the age of digital consent of your country (13 to 16).

9. Data Retention

10. Automated Decision-Making

We do not engage in automated decision-making or profiling that produces legal effects or similarly significant impacts on you.

11. Data Breach Management

In case of a data breach:

12. Your California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

Residents of other US states with consumer privacy laws (for example Colorado, Connecticut, Virginia, Utah, Texas and Oregon) have similar rights. To appeal a decision on your request, reply to our answer with “Appeal” in the subject.

12.1. Do Not Sell or Share My Personal Information

In the last 12 months, Torpedo has disclosed the following categories to Google for advertising, which some US state laws treat as a “sale” or “sharing”: identifiers (IDFV, and the IDFA if you allowed tracking), internet or other electronic network activity (ad interactions, gameplay and purchase events) and coarse geolocation derived from the IP address. We do not sell or share the personal information of anyone we know to be under 16 without the required consent; players declared to be under 13 get only child-directed, non-personalized ads.

To opt out:

After an opt-out, Torpedo stops sending ad signals to Google for personalized advertising and ad conversions; you will still see non-personalized ads.

13. Contact Us

For privacy-related questions or to exercise your rights, contact us:

Appalex Limited
Email: info@appalex.hu
Phone: +36 70 213 3578
Address: 1012 Budapest, Logodi utca 48. A. lház. 1. em. 2. ajtó, Hungary

14. Supervisory Authority

EU users can file complaints with their local data protection authority. Our lead supervisory authority is:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Email: ugyfelszolgalat@naih.hu
Phone: +36 (1) 391-1400

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of changes via the Apps. Changes become effective 30 days after posting.

16. Governing Law

This Privacy Policy is governed by the laws of Hungary. However, this does not affect your rights under applicable data protection laws in your country of residence, including GDPR for EU residents and state privacy laws for US residents.


Last Updated: October 4, 2026
Version: 2.1

← Back to home