Privacy Policy

Last updated: September 2, 2026

This Privacy Policy explains how Crypto Legends (the “Application”, “App”, “Service”, “we”, “us”, or “our”, as applicable) accesses, collects, uses, discloses, shares, retains, and protects information relating to users of the Application.

Developer / Data Controller
2goodapps OÜ
Lasnamäe tn 4b-30, 11412 Tallinn, Estonia
Privacy contact: 2goodappspolicy@gmail.com

For purposes of applicable privacy and data protection laws, 2goodapps OU is the controller of personal information processed for its own purposes, unless another role is required by applicable law. Certain advertising, analytics, attribution, mediation, and technology providers may act as our processors, service providers, contractors, or as independent controllers/businesses for their own processing activities.

1. Scope of This Privacy Policy

This Privacy Policy applies to information processed through the Application, including information processed through third-party software development kits (“SDKs”), APIs, advertising networks, mediation platforms, analytics tools, attribution providers, anti-fraud tools, crash reporting services, cloud infrastructure, and similar technologies integrated into the Application.

The Application may be distributed through Google Play and other application stores. Store operators and device operating-system providers may process data independently under their own privacy policies.

2. Categories of Information We May Collect or Process

The specific information processed depends on the version of the Application, device settings, consent choices, country or region, enabled SDKs, and features used. We and our partners may process the following categories of information.

2.1 Device and technical information

2.2 Advertising and device identifiers

Advertising identifiers may be reset, limited, deleted, or made unavailable by the operating system or by your device privacy settings. We and our partners are expected to use such identifiers only in accordance with applicable law, platform rules, consent choices, and contractual restrictions.

2.3 Application activity and gameplay information

2.4 Information you provide directly

2.5 Purchase and transaction information

If the Application offers in-app purchases, subscriptions, or other transactions, transaction status, product identifiers, purchase tokens, receipts, and related technical information may be processed for purchase validation, fraud prevention, entitlement management, and support. Payment card details are normally processed by the relevant application store or payment provider rather than directly by us.

2.6 Sensitive information

The Application is not designed to intentionally collect sensitive personal information such as precise health data, biometric identifiers, government identification numbers, precise geolocation, religious beliefs, or similar sensitive categories unless a specific feature clearly requires such processing and the required notice and consent are provided.

3. How Information Is Collected

Information may be collected:

4. Purposes for Which We Use Information

We may process information for the following purposes:

5. Legal Bases for Processing

Where the GDPR, UK GDPR, or similar laws apply, processing may rely on one or more of the following legal bases:

Consent

We may rely on consent for personalized advertising, advertising storage, analytics storage, certain tracking technologies, or other processing where consent is legally required. Consent may be withdrawn at any time through available privacy controls.

Performance of a contract

Processing may be necessary to provide the Application or a feature you request.

Legitimate interests

We may rely on legitimate interests for security, fraud prevention, diagnostics, service improvement, limited analytics, support, and operation of the Application, where those interests are not overridden by your rights.

Legal obligations

We may process or retain information where required by law, regulation, legal process, accounting requirements, or a valid request from a competent authority.

6. Advertising, Ad Mediation, Analytics, and Attribution SDKs

The Application may contain third-party SDKs that facilitate advertising, ad mediation, analytics, attribution, campaign measurement, fraud prevention, and technical operations. These SDKs may receive information directly from your device or from the Application.

Depending on the Application version and configuration, these providers may process advertising identifiers, IP addresses, device information, app activity, ad interactions, approximate location derived from IP, consent signals, and attribution or conversion data.

Provider / Service Typical role Privacy information
Google AdMob / Google Mobile Ads Advertising, ad serving, measurement, mediation Google Privacy Policy
AppLovin / MAX Advertising, mediation, optimization, measurement AppLovin Privacy Policy
Meta Audience Network Advertising and measurement Meta Privacy Policy
Mintegral Advertising, bidding, measurement Mintegral Privacy Policy
Unity Ads Advertising, mediation, measurement Unity Game Player and App User Privacy Policy
Digital Turbine / Fyber Advertising, mediation, bidding, measurement Digital Turbine Legal & Privacy
InMobi Advertising, monetization, measurement InMobi Privacy Policy
Adjust and/or AppsFlyer, if enabled Mobile attribution, analytics, fraud prevention, campaign measurement Adjust Privacy Policy / AppsFlyer Services Privacy Policy

Advertising partners may participate in real-time bidding or similar ad-selection processes. In such cases, an ad request may be transmitted to one or more eligible advertising or bidding partners so an advertisement can be selected, delivered, measured, protected against fraud, and frequency-capped.

Some providers may determine the purposes and means of certain processing independently. Their processing is governed by their own privacy notices and applicable contractual and legal obligations.

7. Personalized and Non-Personalized Advertising

Where legally permitted and where the required consent or other valid legal basis exists, advertising may be personalized based on information such as advertising identifiers, app activity, ad interactions, inferred interests, or information processed by advertising partners.

If personalized advertising is unavailable, declined, or not permitted, you may still receive contextual, non-personalized, or limited ads. Even non-personalized advertising may require limited data processing for purposes such as ad delivery, frequency capping, security, fraud prevention, aggregated reporting, and compliance.

8. Consent Management in the EEA, UK, and Switzerland

Where required, users in the European Economic Area, the United Kingdom, and Switzerland are presented with a consent interface before personal data or device storage is used for personalized advertising and related purposes.

The Application may use Google’s User Messaging Platform (“UMP”) or another Google-certified Consent Management Platform (“CMP”) integrated with the IAB Transparency and Consent Framework (“TCF”) where required for Google advertising products.

Consent choices may include advertising storage, ad personalization, ad user data, analytics storage, and choices relating to advertising technology providers. Consent or objection signals may be transmitted to participating partners so they can apply your privacy choices.

You may be able to revisit or change your choices from app's settings

Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.

9. Google Play, Google Advertising ID, and Data Safety

The Android version of the Application may use the Google Advertising ID (“Advertising ID” or “AAID”) where made available by Android and permitted by applicable rules and user choices. Certain advertising SDKs may declare the Android AD_ID permission through their library manifest.

The Advertising ID may be used for advertising, attribution, fraud prevention, frequency capping, and measurement, subject to applicable law and Google Play policies. Users may reset, delete, or otherwise limit availability of the Advertising ID through Android settings where supported.

We maintain Google Play Data safety disclosures describing the categories of data collected and shared by the Application, including data handled by third-party SDKs. Those disclosures are intended to remain consistent with this Privacy Policy and with the Application’s actual technical behavior.

10. Sharing and Disclosure of Information

We may disclose or make information available to:

We do not sell personal or sensitive user data for monetary consideration in a manner prohibited by Google Play policy.

However, under some U.S. state privacy laws, disclosure of identifiers or activity data to advertising partners for cross-context behavioral advertising may be defined as “sale”, “sharing”, or “targeted advertising” even when no money is paid for the data. Where applicable, we provide legally required opt-out rights.

11. California Privacy Notice

If you are a California resident and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), applies to our processing, you may have rights regarding your personal information.

Categories of personal information

Depending on your use of the Application, categories processed during the preceding 12 months may include identifiers, internet or electronic network activity, approximate geolocation, commercial or transaction information where applicable, and inferences associated with advertising or analytics.

California rights

Subject to applicable limitations and verification requirements, you may have the right to:

We do not sell personal information for monetary consideration. Certain advertising activities may nevertheless constitute “sharing” under California law because information may be disclosed for cross-context behavioral advertising.

To exercise an applicable opt-out right, contact 2goodappspolicy@gmail.com.

12. Other U.S. State Privacy Rights

Residents of states with comprehensive consumer privacy laws, including where applicable Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other jurisdictions, may have additional rights depending on the law applicable at the time of the request.

Such rights may include:

Definitions and exceptions vary by state. For example, some state laws define “sale” broadly, while others require monetary or other valuable consideration. The availability of a right therefore depends on your jurisdiction and our processing activities.

Universal opt-out mechanisms

Where required by applicable law, we honor recognized universal opt-out preference signals or mechanisms, such as Global Privacy Control (“GPC”), when the signal is received in a legally applicable and technically supported context.

Because mobile applications and advertising SDKs do not always receive browser-based signals, users should also use the Application’s privacy controls or contact us to exercise applicable opt-out rights.

13. Rights in the EEA, UK, and Similar Jurisdictions

Where applicable, you may have the right to:

Some advertising and analytics providers may maintain separate mechanisms for exercising rights with respect to data for which they act as independent controllers.

14. Brazil and Other Jurisdictions

Users in Brazil may have rights under the Lei Geral de Proteção de Dados (“LGPD”), including confirmation of processing, access, correction, anonymization or blocking in certain circumstances, deletion, portability where applicable, information about sharing, withdrawal of consent, and objection to unlawful processing.

Users in other jurisdictions may have equivalent or additional rights under local privacy laws. We will respond to valid requests as required by applicable law.

15. Privacy Choices and Device Controls

Depending on your device, region, and Application version, privacy choices may be available through:

Changing an advertising preference does not necessarily stop all advertisements. It may instead result in contextual, non-personalized, or limited advertising.

16. Data Retention and Automatic Deletion

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including operation of the Application, analytics, security, fraud prevention, advertising measurement, dispute resolution, and compliance with legal obligations.

Data associated with an inactive user or Application profile that is under our direct control is automatically deleted or anonymized after 30 consecutive days of inactivity, meaning that the user has not opened or used the Application during that period.

When the user returns to the Application after the applicable deletion period, certain identifiers, preferences, analytics information, or Application data may be created or collected again as part of a new active session, subject to the user's current consent choices, device settings, and applicable law.

Some information may be retained for longer where reasonably necessary or legally required for purposes such as security, fraud prevention, accounting, compliance with legal obligations, resolving disputes, enforcing agreements, or establishing, exercising, or defending legal claims.

Third-party advertising, analytics, attribution, mediation, and technology providers integrated into the Application may apply their own retention periods to information they process. Their retention and deletion practices are governed by their respective privacy policies and applicable legal obligations.

When information is no longer required, we delete, anonymize, aggregate, or otherwise de-identify it in accordance with applicable law and our applicable retention practices.

17. User Accounts and Data Deletion Requests

The Application does not require users to create a user-facing account in order to use the Application. Accordingly, there is no separate Application account that the user must delete through an account-deletion webpage.

Data under our direct control is subject to the automatic deletion or anonymization process described above after 30 consecutive days of inactivity.

Where applicable privacy law gives you a right to request access, deletion, correction, restriction, or another privacy action before the automatic deletion period expires, you may submit a request by contacting .

We may need information reasonably necessary to identify the relevant Application data or device relationship before fulfilling a request. Certain information may be retained where permitted or required by law, including for security, fraud prevention, legal claims, accounting, or regulatory compliance.

18. Data Security

We use reasonable administrative, organizational, and technical measures designed to protect information against unauthorized access, disclosure, alteration, loss, misuse, and destruction. Measures may include access controls, secure transport, restricted administrative access, logging, contractual safeguards, and security practices appropriate to the nature of the information processed.

No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

19. International Data Transfers

Advertising, analytics, attribution, hosting, and other providers may process information in countries other than the country in which you reside, including countries that may have different data protection laws.

Where required, international transfers are protected through legally recognized mechanisms such as adequacy decisions, Standard Contractual Clauses, contractual safeguards, or other valid transfer mechanisms.

20. Children's Privacy

The Application is not intended to knowingly collect personal information from children in violation of applicable child-privacy laws.

If the Application is directed to children or knowingly serves child users, we apply the additional requirements applicable to child-directed applications, including restrictions on personalized advertising, data collection, SDK use, and consent where required.

If you believe that a child has provided personal information in a manner that violates applicable law, please contact us at 2goodappspolicy@gmail.com.

21. Legal and Safety Disclosures

We may preserve, use, or disclose information where reasonably necessary to:

22. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the Application, SDK integrations, legal requirements, advertising practices, or business operations.

The updated version will be made available through the Application, our website, or another appropriate location. Where required by law, we will provide additional notice or request renewed consent before materially changing processing based on consent.

23. Contact and Privacy Requests

To ask a privacy question or exercise an applicable privacy right, contact:

2goodapps OÜ
Lasnamäe tn 4b-30, 11412 Tallinn, Estonia
Email: 2goodappspolicy@gmail.com

We may need to verify your identity or device relationship before fulfilling certain requests. Authorized-agent requests may be subject to additional verification where permitted by law.