Skip to main content
Niya Tech Labs

Privacy

Privacy policy

Written as the questions people actually ask, each with the shortest true answer we can give. If a question you have is missing, send it and we will add it.

Effective 12 August 2026Version 2.0Privacy Act 1988 (Cth)

1Who is answering these questions?

NIYA TECH LABS PTY LTD. ACN 698 379 145. ABN 26 698 379 145. A proprietary company on the Australian register, working out of Melton in Victoria on accessibility in mobile games, and intending to publish games of its own.

Below, "we" means that company and no other. One inbox takes the lot: [email protected].

Is there a privacy officer I should ask for?

No. None has been appointed. Making up a job title for this page would tell you nothing you could use, and would imply a separation of duties that does not exist. Mail about personal information gets read by whoever runs the company. Should that stop being true, this answer stops with it.

2What does this page cover?

Three things. No fourth.

  • This website, niyatech.cc.
  • Games released under this company's name, whichever store they sit on.
  • Anything you post to the address above.

What falls outside it?

  • Apple and Google. Downloading or paying for something sets off their own collection, for their own ends, under their own documents. Ours has no bearing on it.
  • An advertising network working for itself. Question 15 marks the line where our reach ends.
  • Whatever sits at the far end of a link. Following one takes you off this policy.

Read the tenses carefully. Not one game has been released. That means no players, which means no player data whatsoever. Every answer touching games is therefore written ahead of the fact. Writing them afterwards would leave whoever installs the first build with nothing to read at the moment they most need it. Correspondence is the sole category of personal information in our hands today, and every right described here bites on it already.

3Which law is this written to?

Australian law. The Privacy Act 1988 (Cth), and specifically the thirteen Australian Privacy Principles sitting in Schedule 1 to it. A reference below to "APP 6" points at the sixth of them.

Why does a page like this have to exist at all?

APP 1 forces it. That principle wants personal information handled in the open, wants systems built so the handling stays lawful, and wants a current policy that costs nobody anything to read.

APP 1.4 then itemises the contents. What kinds of information get collected and kept. By what means, and held how. To what end, and passed to whom. Whether any travels beyond Australia, and if so to which countries. How you get at it. How you get it corrected. How you complain, and what we do with the complaint.

Each of those items is its own numbered question here. Burying an answer inside a paragraph that technically contains it is not the plain expression APP 1 asks for, and a reader who has to hunt has effectively been refused.

What else applies?

  • Spam Act 2003 (Cth) — governs commercial messages. Wants consent, an honest sender, and an unsubscribe that functions.
  • Do Not Call Register Act 2006 (Cth) — governs telemarketing. Never arises; we make no such calls.
  • Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth) — guarantees no drafting can remove.
  • Part IIIC of the Privacy Act — the Notifiable Data Breaches scheme. Question 23.
  • Privacy and Other Legislation Amendment Act 2024 (Cth) — brought in a privacy tort, made room for a code protecting children, and imposed new disclosure duties around automated decisions.

4Are you not too small for that law?

Probably. We are choosing to ignore that.

Section 6D of the Privacy Act releases most businesses under $3 million of annual turnover from the Australian Privacy Principles. Registration happened in 2026 and revenue sits far beneath the line, so a narrow reading says the principles have no grip on us yet.

Then why write the page as though they do?

Three reasons, none of them noble.

  1. The exemption keys off money, not off harm. Your information does not matter less because our revenue is small.
  2. Section 6D carries exceptions that would pull a business shaped like this one back under the Act as it grows. Building on the exemption means building on something with a known expiry.
  3. A policy resting on staying small must be rewritten the instant that stops being true, and that instant is invariably a bad one to be redrafting in.

So everything here is written as if the principles bind us fully, and requests and complaints get handled that way. Should the Act later bind us as law rather than as choice, not a line needs changing. That is the whole reason for doing it in this order.

5What do you hold about me if I just read the site?

Server logs. Possibly one security cookie. Nothing else exists.

Everything reading this website causes to be written down
WhatFieldsWhyHeld for
Request logsYour IP address, the timestamp, the path asked for, the user agent string, the response codeGetting the page to you, and shutting out abuse. Written by the hosting provider, not by usThe provider's cycle, at present under 30 days
Security cookieOne strictly necessary cookie the provider may writeSorting machines from peopleUp to 30 days

Nothing measures you here. No analytics package, no advertising, no pixel, no recording of your session, no fingerprint, no effort to spot you coming back a second time. Building a profile is not something this site is equipped to do, which is also why nothing asks you to dismiss a banner on arrival.

And if I email you?

Then we have your address, your words, and whatever routing detail your mail provider stapled on. As of today that is the only personal information about anybody in this company's possession.

6What would a game collect once one ships?

Read the table as exhaustive. A category absent from it is a category we do not gather.

Personal information a released game would gather
CategoryFieldsWhy it is neededCan you refuse?Held for
Device and buildModel, screen size and density, OS version, game version, locale, store countryPainting the screen properly. Without the physical screen size, the reach test in part 2 of our specification cannot run at allNo13 months
Accessibility settings stateWhether motion is reduced, whether timers are off, text scale, which paletteObeying the setting, plus a count of how often each gets used, which tells us whether a specification is paying for itselfNo, and it hangs off a pseudonym25 months, then aggregated
Gameplay telemetryLevel begun, level cleared, attempts, the point a run ended, elapsed timeLocating the level where people give up, which almost always turns out to be a defect wearing the costume of difficultyNo25 months, then aggregated
Crash diagnosticsThe stack trace, the state of threads and memory at the moment it died, and the breadcrumb log leading up to itRepairing crashesYes — there is a switch in settings90 days
Advertising identifierGoogle Advertising ID, or Apple's Identifier for AdvertisersStopping one advertisement repeating endlessly, plus attribution, in a game that carries advertising. Personalisation only where you have switched it onYes — resettable and deletable from system settings13 months
PurchasesStore transaction ID, product, amount, currency, date, refund statusGiving you back what you bought, and satisfying the tax officeOnly arises where you buy7 years
Optional accountEmail or store sign-in token, chosen name, progress, settingsMoving your progress and your accessibility settings onto a second deviceYes — playing never requires oneUntil you end it, then 30 days

7Is my accessibility setting health information?

No. And considerable effort goes into stopping it becoming that.

Switching motion off says motion bothers you. It does not say why, and nothing here asks. One person kills the timers because of a tremor. Another does it on a crowded train. Identical flag, and the flag is the outer limit of our knowledge.

So it lives in our systems as a preference and stops there. No diagnosis is guessed at. Nothing is filed as information about disability. No advertisement is chosen from it. It rides on no ad request. No audience segment is cut from it.

Health information counts as sensitive information, and APP 3.3 sets a deliberately high bar before sensitive information may be gathered at all. Spelling the boundary out beats staying quiet about it, because a company in the business of counting accessibility settings is exactly the sort that could wander over that line without noticing and then insist afterwards it never did.

The single thing that changes this. Mention a condition of yours in an email and that sentence is health information, now sitting in our inbox because you put it there. It stays inside the thread. Answering you is the only use it gets. It dies with the thread. It is never copied across into anything that measures how the games are played.

8Do you run play sessions with disabled testers?

Not yet. Zero sessions run. Nobody recruited. No tester data in existence. Every check described on the lab page points at our own builds, on our own hardware.

Answering a question about something that has not happened is worth the space here because this is the part of the work most likely to pull in sensitive information. Settling the rules while the room is still empty beats drafting them afterwards to fit whatever we turned out to have done.

So what are the rules if that starts?

  • Consent comes first and comes separately. APP 3.3 consent, in writing, ahead of the session, and distinct from agreeing to take part at all. Sensitive information cannot ride in on a general willingness to be a participant.
  • Nobody is asked to name a condition. What a control does to you is the useful thing, and you can describe that without a diagnosis. Volunteer one and it reaches the notes only if you say it may.
  • Withdrawal keeps working later. Not just in the moment. Ask afterwards and the recording and the notes go, with no reason required from you.
  • Findings surface as specification changes. Never as footage, a transcript, or a name. Nothing from a session goes into marketing.
  • Paying a participant creates a payment record. That is a tax record, and it sits under the 7 year rule in question 17 alongside every other one.

None of this is live. The day it becomes live, this page will say so before the first session rather than after it.

9Can I stay anonymous?

Almost everywhere, yes.

The principle is APP 2. You may deal with an organisation without handing over your name, or under one you made up, and the organisation gets out of that only where it is genuinely impracticable or where a law demands a real identity. Honouring it costs us nothing, because identity is not wired into any of the products.

  • A game will play with no account, no email and no name. Walk past the sign-in and you stay unknown to us.
  • Identifiers mentioned elsewhere on this page attach to hardware, not to a person. You can reset them, and alone they say nothing.
  • Mail us from a pseudonymous address if that suits you better. It gets an answer like any other.

Where does that break down?

At the point you ask to see what we hold, or ask us to change it. Answering means being reasonably satisfied you are the person concerned, and no amount of goodwill gets round that. Question 19 sets out how far the checking goes, which is not as far as people brace for.

10What if I send you something you never asked for?

We test whether collecting it would have been open to us. Where it would not, it goes.

APP 4 covers this, and in daily life it arrives attached to a bug report. Someone helpfully includes a full screen recording, or a diagnostic dump, or a message thread carrying other people's names.

When something unasked-for lands, we decide inside a reasonable period whether APP 3 would have permitted us to gather it. Where the answer is no, and the material is not a Commonwealth record, it gets destroyed or stripped of identifiers as soon as is practical, provided that step is itself lawful and reasonable.

In concrete terms: the attachment leaves the inbox, it falls out of the backup rotation on the usual cycle, and the bug itself gets written down without it.

11What do you actually do with it?

APP 6 draws the boundary. Whatever purpose information was gathered for, it may serve. Anything beyond that needs your consent, or a closely related purpose you would obviously have expected, or one of the narrow exceptions the Act spells out.

The permitted list

  • Making the game work, and delivering features you asked for.
  • Tracking down crashes and defects, then confirming a repair held.
  • Blocking fraud, cheating and abuse — automated play and duplicated installs included.
  • Putting advertising in a free game, on the terms question 15 sets.
  • Replying to you, and obeying a legal obligation.

The never list

  • Selling personal information is not something we do. Brokers, advertisers, bundled "audiences" — none of it.
  • Following you around other companies' products is not something we do, nor is feeding anything that does.
  • Reading your correspondence to aim advertising at you is not something we do.

What about police and courts?

Only where the Act allows. Four situations, in practice.

  1. An Australian law obliges or authorises the disclosure.
  2. A court or a tribunal orders it.
  3. One of the permitted general situations listed in section 16A applies. Danger to a person's life, to their health, or to their safety is the clearest example.
  4. An enforcement body needs it, and reasonably needs it, for enforcement work.

Handing anything to an enforcement body gets written down, which APP 6.5 requires anyway. Where telling you is legally open to us, you will be told.

12Who else ever sees it?

Five organisations, for five reasons. There is no sixth.

Every recipient of personal information from us
WhoWhat forWhat reaches themWhere they keep it
Google LLC and Google Ireland LimitedCrash reporting, analytics infrastructure, Play billing, ad deliveryThe device fields, crash reports, gameplay events, the advertising identifier and records of purchasesUnited States, Ireland, other Google regions
Apple Inc.Distribution through the App Store, billing for in-app purchases, and crash reporting on iOSPurchase records, crash reportsUnited States and other Apple regions
Cloudflare, Inc.Serving and shielding this websiteRequest logs, your IP address among themGlobal edge network, Australia included
Our email providerReceiving and storing mailWhatever you chose to put in itAustralia and the United States
Our accountantStatutory accounts, activity statements, taxRevenue in aggregate, plus single transactions where a query demands oneAustralia

Who is deliberately absent from that list?

Data brokers. Marketing platforms. Customer data platforms. Enrichment services. Identity graphs. Research partners. Adding any one of them means this table changes first, and question 29 governs how that gets announced.

What if you publish research?

Figures about how often accessibility settings get used would be counts, computed from data already stripped of identifiers, with no group left small enough to point at a person. A dataset is not something we will release.

What if the company is sold?

Personal information can move with it. We give notice here before completion wherever we are lawfully free to. Whoever buys is held to this document until it publishes one of its own, and that replacement cannot shrink your rights over anything gathered beforehand without asking you first.

13Does any of it leave Australia?

It does. The final column of the table above is the authoritative answer, and it gets edited the day a provider shifts region.

What does the law make you do about that?

APP 8 governs sending personal information to a recipient outside the country. Section 16C is the sharp part. Should a recipient abroad do something that would have broken the Australian Privacy Principles had it happened here, the Act deems us to have done it ourselves. Their mistake becomes our liability.

Taking that as the operative rule, instead of as an obstacle worth routing around, is why the overseas list names five organisations rather than gesturing at trusted partners.

How do you meet APP 8 in practice?

Contractually, before anything moves. Every provider publishes data processing terms, and those terms are the mechanism. They commit the provider to four things: working to our instructions instead of its own preferences, holding what it has securely, helping when you exercise a right, and raising the alarm with us when something goes wrong at its end. Confirming those terms are in place and current is our job, and we take reasonable steps to do it.

One shortcut goes unused. APP 8.2(a) lets an organisation skip those steps where the destination country runs substantially similar law with a comparable way of enforcing it. Judging that correctly, country by country, is legal work we are not equipped for, and a wrong judgement quietly moves the consequences onto you.

14Will you put me on a mailing list?

No. No list exists to be added to.

Zero marketing messages have gone out under this company's name. Should that change, it changes as opt-in: consent stored with its date and the precise words you agreed to, and a first message that tells you where your address came from.

Mailing the support address signs you up to nothing. Quietly assembling a list that way is the standard small-company move, and it is not ours.

What rules would apply if you did?

APP 7 constrains using personal information for direct marketing. On top of it sits the Spam Act 2003 (Cth) for anything electronic, and that statute is the stricter of the two: genuine consent, an honestly identified sender, and an unsubscribe facility that stays alive at least 30 days and gets actioned inside 5 working days.

Are ads inside a game the same thing?

Not legally. An advertisement in a game gets picked by a network and dropped into a slot. It is not a message we addressed to you, so APP 7 is not the rule that governs it. Question 15 is. Control stays with you regardless, both in the game's settings and at the level of the operating system.

15What happens with advertising in a game?

Here is the standing position every game we publish is held to.

Is personalisation on by default?

No. Requests go out flagged non-personalised until you say otherwise inside the game. A non-personalised advertisement gets chosen from the surroundings it appears in rather than from anything known about you. Turning personalisation on is yours to decide, and turning it back off takes away no feature and no content.

Would an ad request know my accessibility settings?

Never. Reduced motion, disabled timers, an alternative palette — none of it travels with an ad request, and none of it ever will. Those signals stay behind inside the game. Putting it this bluntly is deliberate: the audience segment those settings would imply is precisely what an advertising system would happily pay for, so a soft reassurance would be worth nothing.

What about Apple's tracking prompt?

Getting at the Identifier for Advertisers on iOS needs your permission, granted through App Tracking Transparency. That prompt appears only once you have already switched personalisation on in our own settings, so the system dialog never ambushes you.

And Google Play?

Every game's Play Data Safety declaration is held in step with this page, as are Apple's privacy labels. Any daylight between them is our defect. Point at it and whichever one is wrong gets fixed.

Can you delete what a network holds?

No, and pretending otherwise would be worse than useless. Running its own fraud checks and measuring across inventory, an advertising network is working for itself, not to our instruction. Our power stops at cutting off what we send, which is exactly what switching personalisation off does. Independently of us: Android hides the control under Settings, then Google, then Ads, where the advertising ID can be deleted outright. iOS keeps the equivalent under Settings, then Privacy and Security, then Tracking. Either way, uninstalling ends collection from that handset on the spot.

16Will you ever want my licence number?

No. Nor a tax file number, a Medicare number or a passport number.

APP 9 shuts three doors on an organisation, subject only to a handful of narrow exceptions. Taking a government related identifier and treating it as its own. Putting one to use. Handing one onward. We sidestep the question entirely. Nothing we build checks an age or proves an identity, which is why no such number would ever be called for, and why no field anywhere in our systems was built to store one.

Send one regardless — photographing a licence into an email, say — and it becomes unsolicited material under question 10 and is destroyed.

17How long do you keep it?

APP 11.2 demands that information be destroyed or stripped of identifiers once no permitted purpose still needs it, unless some other law insists it be kept. Turning that obligation into actual dates produces the retention schedule below.

Retention schedule
CategoryPeriodWhy that period
Crash diagnostics90 daysEnough to repair the crash and prove the repair worked
Device and build data13 monthsOne full year of handsets and OS releases
Advertising identifier and attribution13 monthsLines up with the attribution window the providers run
Gameplay and settings telemetry25 months, then irreversibly aggregatedTwo cycles, after which nothing individual is left standing
Optional accountUntil you end it, then 30 daysYours to close whenever you feel like it
Dormant account36 months untouched, then deleted after notice to the address on itAn account nobody opens is a liability rather than an asset
Support correspondence24 monthsEnough to spot the same fault turning up twice
Complaint correspondence7 yearsLines up with the general limitation period in Victoria
Purchase, tax and accounting records7 yearsStatute leaves no choice
Website request logsUnder 30 daysWhatever cycle the hosting provider runs

What do "destroy" and "de-identify" actually mean here?

Destroying: the record leaves live systems, then ages out of backups on the ordinary rotation, complete inside 35 days. De-identifying: out go the identifiers, and out go any fields that would let one be rebuilt. Dropping a name column and calling the remainder anonymous does not qualify.

18What if what you hold is wrong?

Say so and it gets fixed. No charge, no form.

APP 10 requires that what we gather stays accurate, current and complete, and that anything we use or hand on is relevant as well. Most of what a game writes down is generated by machine, so it is accurate in the thin sense of faithfully reporting whatever a handset said.

What actually goes stale is anything you typed yourself, usually an email address buried in an old support thread. Writing round periodically asking people to confirm details is not something we do, because it means disturbing people who finished with us years ago in order to tidy a record they have no interest in.

The remedy that works is the correction right under APP 13, available whenever you want it. Question 19 explains the mechanics.

19How do I see it and get it fixed?

APP 12 entitles you to see what is held about you. APP 13 entitles you to have it put right. Neither costs anything.

How do I ask?

Mail [email protected], subject line "Privacy request". Say what you are after, and hand us enough to find it. Where a record attaches to a handset instead of to an account, that normally means either the advertising identifier or whichever support code the game prints on its settings screen. Absent one of those, nothing connects a record to you and there is nothing we can retrieve.

How will you check I am who I say?

Account records: through the email address the account runs on. Device records: possession of the identifier is the only thing checkable, so that is what gets checked, described honestly rather than dressed up as stronger proof than it is. Nobody will be asked to post identity documents to a games company.

How long does it take, and what does it cost?

Thirty days. Nothing. Working out who you are happens within those thirty days rather than being bolted onto the front of them. Should some unusual export format genuinely cost us money to produce, the figure comes to you before any work starts, and it will not be padded.

Can you refuse?

In a short list of situations the Act names, and that list is tighter than most people brace for. Access that would unreasonably intrude on somebody else's privacy. A request that is frivolous or vexatious. Material bound up in legal proceedings that would not be discoverable anyway. Access that would itself break a law.

A refusal, whether total or partial, arrives in writing, names the ground it rests on, and points you at question 27. Where some of it can be released, or where a different format would answer your actual need, that offer comes instead of a flat no.

What if you will not correct something?

Then you can make us attach your own statement to the record, recording that you consider it wrong, and we take reasonable steps to put that statement where anyone reading the record afterwards will see it. Hardly anybody knows the right exists, which is reason enough to say so here. And where the information already went to somebody else, asking us to pass on a correction obliges us to take reasonable steps to do it, unless doing so is impracticable or unlawful.

20How do I make you delete it?

If a game gave me an account

  • From inside the game: Settings, then Account, then Delete account. A single confirmation queues the job immediately.
  • By mail: [email protected], subject "Delete my data", sent from whichever address the account runs on.

If I never made one

Uninstalling halts collection from that handset instantly. Clearing records already held needs the support code from the game's settings screen, or the advertising identifier. Whatever hangs off it then goes.

What does deletion actually reach?

Effect of a deletion request
WhatWhat happensWhy
Account, name, email, progress, saved settingsGone inside 30 daysNo remaining reason to have it
Gameplay and accessibility telemetryDeleted or irreversibly aggregated inside 30 daysThe counts live on; nothing that leads back to you does
Crash reportsExpire on their 90 day cycleShort-lived to begin with
Purchase and tax recordsHeld the full 7 yearsTwo statutes require it: Income Tax Assessment Act 1936 s 262A, and Corporations Act 2001 s 286. Deleting them is not lawfully open to us, so we say so rather than deleting and hoping nobody checks
Complaint correspondenceHeld 7 yearsIt is the record of how your complaint got handled
BackupsOverwritten on the rotation, inside 35 daysEditing inside a backup image is not reliable, so the rotation is left to clear it, and a record once deleted never comes back

Confirmation comes to you in writing once it is finished. Flagging a record as deleted while keeping it is not something we do.

21What will an app ask my phone for?

Device permissions a game would request
PermissionWhat forRequired?If you say noHow to revoke
InternetAdvertising, optional account sync, crash reportsComes with installation; nothing prompts separatelyNot applicableCut network access for the app in system settings
NotificationsSaying a timed event finished, in a game that has oneNoNothing gets sent and the game plays as normaliOS: Settings, the app, Notifications. Android: Settings, Apps, the app, Notifications
App Tracking Transparency (iOS)Reaching the advertising identifier for personalised adsNoAdvertising stays non-personalisedSettings, Privacy and Security, Tracking
Advertising ID (Android 13+)Capping repeats, and attributionDeclared, never promptedDelete the ID from system settings and what reaches the app is zerosSettings, Google, Ads
VibrationHaptics, one of the non-visual channels part 1 of our specification leans onNoNo haptics; shape and luminance carry the state regardlessThe game's own settings

What will never be asked for?

Location at any precision. Camera. Microphone. Contacts. Calendar. Photos. SMS. Call log. Phone state. Body sensors. Nearby devices. A build of ours asking for any item on that list is either a mistake or not ours.

Why not the Android accessibility service?

Wrong tool, and a dangerous one. Granting it lets an app observe and act on the whole screen, other apps included, and it gets abused routinely by software posing as a helper. No game has a legitimate use for it. Our accessibility work happens inside our own app. It does not involve reaching into anybody else's.

22How well is it protected?

APP 11 asks for reasonable steps against information being lost, tampered with, misused, or reached, altered or handed on by somebody with no business doing so — plus destruction or de-identification once nothing needs it any more.

What does "reasonable steps" mean at this size?

  • Everything encrypted in transit. Site and app endpoints alike are HTTPS and nothing else.
  • Encryption at rest, which comes from the platform the data sits on rather than from anything clever of ours.
  • Multi-factor authentication wherever an administrative login could reach production data or a store console.
  • Access granted only where the work needs it. Few people can reach production data, and the list gets reviewed whenever somebody arrives or leaves.
  • Development and production credentials kept apart, so a leaked development key opens nothing live.
  • Gathering less in the first place. Not holding data is the single most reliable control a small studio has, which is why the tables further up are short.

Perfect security does not exist, and an organisation claiming its own is either wrong or selling. The controls above are the reasonable steps APP 11 asks for at this size, and they get revisited whenever the work behind them changes.

23What happens if you get breached?

Part IIIC of the Privacy Act builds the Notifiable Data Breaches scheme, and we work to it.

Everything turns on the phrase "eligible data breach". Three ingredients have to line up together. Something happened to personal information: somebody reached it who had no business doing so, or it went somewhere it should not have gone, or it was simply lost. A reasonable person looking at the situation would judge serious harm to somebody caught up in it to be likely. And whatever was done afterwards has failed to take that likelihood away.

What would you do, in what order?

  1. Contain. Shut the hole. Revoke the credential. Take a component down where stopping it demands that.
  2. Assess. Where grounds exist to suspect an eligible breach, a reasonable and prompt assessment starts and finishes inside the 30 days section 26WH allows, counted from the moment those grounds first appeared.
  3. Remediate. Where the repair makes serious harm no longer likely, notification is not triggered, and the reasoning behind that conclusion gets written down.
  4. Notify. Where it does qualify, a statement goes to the Commissioner as soon as practicable, lodged with the Office of the Australian Information Commissioner, and the people affected are told. Where reaching them one by one is not practical, the statement is published on this site and reasonable steps are taken to get it seen.

What would a notification say?

Four things. Our name and a way to reach us. An account of what went wrong. Which kinds of information were involved. The steps we think you should take. It will not be padded with comfort nobody has earned, and where something is still unknown it will say so rather than leaving the hole for you to notice.

What if I think you have been breached?

Mail [email protected], subject "Security". Chasing a false alarm costs us an afternoon. Missing a real one costs you. Reports made in good faith get treated as reports, and get answered by a person rather than by a lawyer.

24Does a machine decide anything about me?

Nothing that matters to your rights or interests. Nothing here decides whether a loan is approved, whether somebody gets hired, whether a service or a benefit is granted, or whether a legal entitlement exists.

A fresh disclosure duty arrives with the 2024 amendment Act described in question 3. Two things have to be named under it: the categories of personal information feeding any substantially automated decision that weighs significantly on somebody, and the categories of decision reached that way. Commencement falls on 10 December 2026. Publishing our answer early seemed better than waiting for the date to arrive.

Where does automation happen at all?

  • Anti-cheat and abuse detection. Automated signals can hold a handset or an account off a leaderboard. Restrictions landing on a whole account, rather than on a single score, get reviewed by a human being whenever somebody asks. Write and say so.
  • Picking which advertisement appears. Settled by the network in the instant. It changes nothing about your access to the game or to anything you paid for.

Neither clears the bar the Act sets. Should something we build ever clear it, this is the section that will describe it, and the description will land before the processing starts.

Is there a privacy right I can use against you directly?

Yes, and hardly any policy mentions it. Schedule 2 to that same amendment Act commenced a statutory tort of serious invasion of privacy on 10 June 2025. It opens the door to suing over intrusion into seclusion, or over misuse of information, where the intrusion was deliberate or reckless, where somebody standing where you stand would reasonably have expected privacy, and where the whole thing is serious. It runs against anybody, ourselves included, and it works independently of the complaints route in question 27. A right nobody has told you about is barely a right.

25Are your games for children?

No. Nothing is aimed at children, and nothing is designed to pull children in. Stores asking for an age rating, or for a declared target audience, get told the audience is a general one.

What age counts as old enough to decide?

Australian law fixes no age. Regulator guidance points towards assessing capacity person by person wherever that is practical, and towards a working presumption that somebody of 15 or over can consent unless something suggests otherwise. That presumption is the one we apply.

Room was also made by the 2024 amendment Act for a dedicated code protecting children online, to be drafted by the Information Commissioner and aimed at services children are likely to reach. Compliance follows once it is registered and in force, to whatever extent it reaches us. This page waits until then instead of guessing at wording nobody outside the drafting has seen.

What do you do about it in the meantime?

  • Gathering personal information from anyone under 15, knowingly and without a parent or guardian agreeing to it, is not something we do.
  • Inside an advertising-carrying game, a store signal indicating a child means personalisation is never requested. The call leaves marked child-directed, which obliges the network to serve non-personalised inventory.
  • Nothing we build has chat, user-generated content, or messaging between players. Those are the features that turn a young audience into a safety problem, and we have none of them.

What if my child's information has already reached you?

Mail [email protected] and it gets deleted. Proving a legal relationship is not required beyond whatever satisfies us the request is genuine, and confirmation follows once it is done.

26Does this website set cookies?

None of its own, and it runs neither analytics nor advertising. One strictly necessary security cookie may come from the hosting provider, whose job is telling machines apart from people.

No consent banner appears because consent has nothing here to attach to. The reasoning, the exact list, and the single request this site makes to somebody else's servers all sit in the cookie notice.

Cookies belong to browsers. A game would lean on the device identifiers in question 6 instead, and controls for those live in questions 15 and 21.

27I am not happy. What can I do?

First, tell us

Mail [email protected], subject "Privacy complaint". Lay out what took place and what you want done about it. An acknowledgement reaches you inside 5 business days, and the real answer inside 30 days. Where it will run longer, you get told why, with a date attached.

Then, the Commissioner

Where our answer leaves you unsatisfied, or where 30 days pass without one, the regulator is next. Nothing is charged, no lawyer is needed, and neither our agreement nor our knowledge is required for you to go.

Office of the Australian Information Commissioner
RouteDetail
Weboaic.gov.au
Phone1300 363 992
PostOAIC, GPO Box 5218, Sydney NSW 2001

As a general matter the OAIC prefers to see the issue put to the organisation first, with 30 days allowed, though it can take a complaint without that where circumstances justify it.

What will you not do?

Demanding a non-disclosure agreement as the price of dealing with a privacy complaint is not something we will do. Complaining will never be treated as though it had broken our terms of use. Both happen elsewhere, and both ought to cost a company its credibility.

28What if I am not in Australia?

This page answers to Australian law, that being the law with a grip on this company. Rights elsewhere may still be yours, and silence here should not be mistaken for a refusal.

Europe and the United Kingdom

Should the General Data Protection Regulation, or its United Kingdom counterpart, reach what we do, the familiar set belongs to you. You may see what is held. You may have it rectified, erased, or its use restricted. You may take it elsewhere, and you may object. On top of all that sits a complaint to whichever supervisory authority covers where you live. Where legitimate interests are the basis, objecting stops us unless compelling grounds override you. Where consent is the basis, withdrawing it works at any moment, and processing that was lawful beforehand stays lawful. Naming the law you are invoking when you write means the right clock gets started. One month is the answer time for a GDPR request.

California

Four rights come from the California Consumer Privacy Act as amended: knowing what is held, having it deleted, having it corrected, and refusing the sale or sharing of personal information. Neither of the two things that Act polices happens here. Selling personal information: no. Sharing it for the sort of behavioural advertising that follows a person between sites, in the specific sense that Act gives the word: also no. Personalised advertising staying off until you switch it on puts us outside that definition by default. Global Privacy Control signals arriving at this website are honoured.

Anywhere else

Hold a right where you live, tell us which one, and the request gets dealt with on its merits rather than on whether a court could force us.

29What happens when this page changes?

Both fields at the head of the page — effective date, version number — move with it. Those two fields answer the question of whether you are reading what you read last time.

Trim your rights or widen what gets gathered, and notice has to land first — inside the app at next launch, and across the head of this page for 30 days at minimum. A material change never applies backwards.

Older wording never gets a page of its own, though none of it is thrown away. Name a date, ask what stood here at the time, and that version gets sent to you.

One disclaimer, meant literally. Care went into structuring this document. It is still not legal advice, and it still does not replace advice from an Australian legal practitioner who knows your circumstances.

30Where do I write?

One address covers all of it: [email protected]. Sorting happens on the subject line.

Subject lines and the reply you should expect
If you wantPut this in the subjectReply
To see what we hold (APP 12)Privacy request30 days
Something corrected (APP 13)Privacy request30 days
An account and its data deletedDelete my data30 days
To complain about how we handled your informationPrivacy complaintAcknowledgement inside 5 business days, answer inside 30 days
To report a suspected breach or security flawSecuritySame day, or the next business day
Anything else hereWhatever describes it5 business days

NIYA TECH LABS PTY LTD, ACN 698 379 145, ABN 26 698 379 145, Melton, Victoria, Australia. No postal address gets published here. Whatever registered office stands against the ACN is the one carrying legal effect for service.