# Privacy Policy for Mandarin Master
**Effective date:** \ 5/25/2026
**Last updated:** \ 5/25/2026
## Who we are
Mandarin Master (“the App”, “we”, “us”, “our”) is operated by:
ANVAR KHUDOYBERDIEV, trading as Anvar Software
Dashtobod, Djizak Region, Uzbekistan
Contact email: xab8101@gmail.com
This Privacy Policy explains what information we collect when you use
Mandarin Master, why we collect it, who we share it with, and the
rights you have over your data.
## Summary
We are a small independent developer. The data we collect is the
minimum needed to deliver the learning experience, save your progress
across devices, enable social features you opt into (friends, clans,
chat), and keep the app working reliably.
We do NOT:
- Sell your personal data to anyone.
- Show third-party advertising.
- Use your data for targeted marketing.
- Track your location.
- Read your contacts, photos, or messages outside the App (with the
single exception of one photo you explicitly pick for your avatar,
if you’re a PRO subscriber — and even then the photo never leaves
your device).
## 1. Information we collect
### 1a. Information you provide
- **Email address** and **password** when you create an account.
- **Display name** you set during sign-up.
- **Username** (optional, public) used for friend search and on the
leaderboard.
- **Profile avatar** — either a built-in icon you select, or a photo
you pick from your device’s gallery (PRO subscribers only). Photos
picked from the gallery are stored only on your device; the file
path is saved to your profile but the image itself is never
uploaded to our servers or shared with other users.
- **Clan name** if you create or join a clan.
- **Chat messages** you send in 1-on-1 friend chats or clan chats.
### 1b. Information collected automatically
- **Firebase Authentication User ID** — a randomly generated
identifier that links your profile across devices.
- **Android device identifier (Settings.Secure.ANDROID\_ID)** — used
to bind your trial / PRO activation status to your specific device
so it survives reinstalls. Not used for advertising, profiling, or
cross-app tracking.
- **Firebase Cloud Messaging (FCM) token** — a per-install
identifier that lets the operating system deliver our push
notifications. Mirrored to your user profile so our notification
backend can target you. Rotated by the OS.
- **Session token** — a random UUID generated when you sign in, used
to enforce the “one active device at a time” rule.
- **Crash diagnostics** — when the App crashes we send a stack
trace, your device model, and your Android version to Firebase
Crashlytics so we can identify and fix bugs. We do not attach your
email, name, or in-app content to crash reports.
- **Gameplay activity** — your XP, coins, current streak, lesson
progress, daily quest completion, and (PRO only) your mistake
history. Stored in your profile so progress syncs across devices.
### 1c. Permissions you may grant
These are off by default. The App only asks when you actively use
the feature that needs them:
- **Microphone** — requested when you start the “Pronunciation”
phase of a lesson. Audio is processed by your device’s built-in
speech recogniser (provided by Android); we receive only the
resulting text transcript, never the audio recording itself.
- **Photo library access** — requested only when you tap “Pick from
gallery” on the avatar selection screen (PRO feature). We use
Android’s system photo picker, which gives us access only to the
single photo you select — never your full library.
- **Notifications** — requested so we can deliver friend requests,
new clan / private messages, and daily streak reminders.
You can revoke any of these at any time from your device’s system
settings (Settings → Apps → Mandarin Master → Permissions).
## 2. How we use your information
- To create and authenticate your account.
- To save and sync your learning progress across devices.
- To deliver the social features you opt into (friends list, clan
membership, in-app chat, leaderboard).
- To send notifications you’ve allowed (friend requests, new
messages, streak reminders).
- To diagnose crashes and improve the App.
- To enforce trial limits and the single-device sign-in rule
(anti-abuse / fraud prevention).
- To respond to your support requests.
## 3. Who we share your information with
We share data only with service providers that are necessary to run
the App. We do not sell or rent your personal data to anyone.
| Provider | What we share | Why | Where stored |
|—|—|—|—|
| Google Firebase (Auth, Firestore, FCM, Crashlytics) | Account data, gameplay data, push tokens, crash reports | Backend infrastructure | Google data centres (primarily US, with global replication for FCM) |
| Render Inc. | Read-only access to the same Firebase data | Listens for new messages and dispatches push notifications | US data centres |
| jsDelivr CDN | Your IP address (standard HTTP) | Fetches Chinese character stroke-order data on first use of each character; cached locally afterwards | Global CDN |
| Google Play (for paid subscribers) | Your Play purchase token | Verifies and renews your subscription | Google data centres |
Other clan members and friends you’ve accepted will see your public
username, display name, avatar, total XP, current streak, and any
messages you send in shared chats.
## 4. How long we keep your data
- **Active account data** — as long as your account exists.
- **Clan chat messages** — only the most recent 200 messages per
clan are kept; older messages are auto-deleted.
- **Private chat messages** — only the most recent 100 messages per
conversation are kept, and messages older than 3 days are filtered
out client-side.
- **Crash reports** — retained by Firebase Crashlytics for up to 90
days, then automatically deleted.
- **After you delete your account** (see section 6) — all profile
data, social graph, chat messages tied to your account, and trial
/ subscription state are removed from our database immediately.
## 5. Your rights
You can:
- **Access your data** by viewing your profile inside the App.
- **Correct your name / username / avatar** from the in-app
Settings → Manage account screen.
- **Delete your account** at any time inside the App
(Settings → Manage account → Delete account), or by email if you
cannot sign in (see section 6 below).
- **Withdraw permissions** (microphone, notifications) via your
device’s system settings.
If you are in the European Union, United Kingdom, or another GDPR
jurisdiction, you additionally have the right to data portability
and the right to lodge a complaint with your local data protection
authority.
If you are a resident of California, the CCPA gives you the rights
to know, delete, and not be discriminated against for exercising
your privacy rights. We do not “sell” personal information as
defined by the CCPA.
## 6. Account deletion
You can delete your Mandarin Master account at any time. Two paths:
### Inside the App (recommended)
1. Sign in.
2. Open Settings → Manage account.
3. Tap “Delete account” and confirm. You may be asked to re-enter
your password (a Firebase security requirement).
### Without signing in
If you cannot sign in (forgot password, lost device), email us at
xab8101@gmail.com with the subject line “Mandarin Master account
deletion” and the email address on the account. We will verify the
request and complete the deletion within 30 days, and send you an
email confirmation when it’s done.
Once your account is deleted, the following is permanently removed:
- Your profile (name, username, email, avatar, XP, coins, streak,
energy, lives)
- Your social graph (friends, friend requests, clan membership)
- Chat messages you sent (note: messages you sent that other
participants quoted or replied to may remain in their copies of
the conversation, since we cannot edit other users’ chat history)
- Trial credits and subscription state
- Mistake history (PRO feature)
The following may persist:
- Anonymised crash reports in Firebase Crashlytics (no personal
identifiers attached; auto-deleted after 90 days)
## 7. Children’s privacy
Mandarin Master is intended for users aged 13 and older. We do not
knowingly collect personal information from children under 13. If
you are a parent or guardian and believe your child under 13 has
provided us personal information, contact us at xab8101@gmail.com
and we will delete it.
## 8. International data transfers
Firebase and Render store data on servers operated by Google and
Render respectively, primarily in the United States. By using the
App you consent to this transfer. Both providers maintain
industry-standard data protection safeguards (including standard
contractual clauses where applicable under EU law).
## 9. Security
We rely on Firebase’s built-in encryption (in transit via TLS, at
rest by Google’s infrastructure) and our own Firestore security
rules to restrict who can read and write each piece of data. We
cannot guarantee absolute security; if you become aware of a
security issue, please report it to xab8101@gmail.com.
## 10. Changes to this policy
We may update this policy from time to time. When we do, we will
revise the “Last updated” date at the top of this document.
Material changes will be announced inside the App on next launch.
## 11. How to contact us
For any privacy question, data request, or complaint:
- Email: xab8101@gmail.com
- Telegram: @Anvar_Baxtiyarovich
- Mail: ANVAR KHUDOYBERDIEV, Dashtobod, Djizak Region, Uzbekistan