Official Salfa app
Skip to content

Privacy Policy – Salfa App

A practical explanation of what stays on your device, what is sent when you play online or contact us, who processes it, and your rights.

Last updated: September 7, 2026 Effective date: September 7, 2026

Quick summary

  • Most preferences stay on your device: This includes your theme, player name, custom games, content preference, and onboarding status.
  • Online play needs operational data: Room and gameplay data, together with an anonymous identifier, are sent to Firebase so participants can play together.
  • We do not sell your data or use it to personalize ads: The current advertising system does not receive your name, email address, answers, location, or contacts.

1. Who is responsible, and what does this policy cover?

This policy explains how i3oma, as the developer of the Salfa app and the data controller, processes data when you use the app and its related services. The legal address is [LEGAL_ADDRESS], and you can contact us about privacy at kh249918@gmail.com. Some technical providers act as processors or independent entities according to their services.

This policy covers the Android and iOS versions, any web features that may be offered, online rooms, contact and suggestion forms, reports, rating feedback, purchases, and sponsored advertisements in the app.

2. Data stored locally on your device

Salfa uses local storage to provide the experience and remember your choices. Data is not sent to our servers merely because it is stored locally, but it may be included in an online service when you choose to share it in a room.

  • Your player name, light or dark theme, and onboarding completion.
  • Your content-level preference and confirmation that you are at least 18 when opening adult-rated content.
  • Custom games and their names, questions, and settings on the device.
  • Information needed to resume an active room and the Salfa+ entitlement status available to the app.
  • Local counters used to manage the frequency of advertisements and rating prompts, such as launch and interaction counts, the last display time, and the app version.
Note: You can usually delete this data by clearing the app’s data in your device settings or uninstalling the app. Uninstalling the app does not cancel a recurring store subscription.

3. Online room and gameplay data

When you create or join a room, Firebase Authentication creates an anonymous or temporary identifier to distinguish your session and protect access. Salfa does not require you to create an account with a real name or password for this purpose.

  • Your chosen player name, session identifier, room code, join and activity times, and connection status.
  • Game type, audience and content level, room settings, subscription status needed to determine access, and number of rounds.
  • Answers, choices, guesses, votes, scores, roles, and round results.
  • For drawing games: drawing points and timing, and your player identifier in the room.
  • For custom rooms: the game name and questions the creator chose to share.
Note: Gameplay data is visible to room members according to each game’s rules. Do not enter confidential or sensitive information, and share the room code only with people you trust.

4. Messages, suggestions, rating feedback, and reports

When you choose to submit them, we may process the following data:

  • Contact Us: the name and email address you enter, the message text, and the submission time.
  • Suggest an Idea: the suggestion topic, its details, and the submission time.
  • Rating-experience feedback: the feedback text, anonymous identifier, operating system, app version, and submission time.
  • Content reports: the content and game identifiers, room code if available, anonymous identifier, reason, status, and report time.

These submissions are optional and are used to respond, provide support, fix problems, improve the product, and review abuse. Do not send medical or financial information, passwords, or unnecessary data about other people.

5. Purchases and subscriptions

Apple or Google processes payments and billing through your store account. Salfa does not receive your full card number. The app uses RevenueCat to check available products, purchases, restorations, and entitlement status through a technical customer identifier and the product, transaction, and status records needed to provide Salfa+.

The stores and RevenueCat may provide information such as the product, subscription status, purchase or expiry time, country or storefront, and refunds. Your store-account and payment data is governed by the relevant provider’s policy.

6. Advertisements and network requests

The free version retrieves an interstitial advertisement from the developer’s server at i3oma.de. The request sends the ad type, app name, and identifiers of recently displayed ads to avoid repetition. When an ad is shown or clicked, the app sends the ad identifier, event type, app name, and operating system.

The advertising system does not send your player name, email address, room answers, custom questions, location, or contacts. Network infrastructure may automatically process your IP address and basic request information for security, delivery, and server logs. Current ads are not based on a personal interest profile created within Salfa.

Note: Clicking an ad opens a third-party destination that may collect data under its own policy. We do not send it form or room data, although the browser or operating system may share ordinary connection information.

7. How and why we use data

We use data for the following purposes:

  • To fulfil your request and operate the app, rooms, purchases, and support.
  • To protect rooms, prevent misuse, verify membership, and handle reports.
  • To remember your preferences, improve performance, and manage the frequency of ads and rating prompts.
  • To understand failures and feedback and improve content and features, without making automated legal decisions about you.
  • To comply with a legal obligation or valid official request and protect rights, users, and the service.

Where the General Data Protection Regulation (GDPR) applies, the legal basis depends on the situation and may include performing a contract or taking steps at your request, legitimate interests in operating and improving a secure service and funding the free version, consent where required by law, and legal obligations. You may object to processing based on legitimate interests in light of your circumstances.

8. Service providers and data sharing

We do not sell your personal data, share it with data brokers, or use it for behavioural advertising across other apps and websites. We disclose only what is necessary to service providers, for legal compliance and protection, or as part of a lawful transfer of the project with appropriate notice.

  • Google Firebase: anonymous authentication; Cloud Firestore for rooms, messages, and reports; and Remote Config for update settings.
  • RevenueCat: management of products, purchases, entitlements, and purchase restoration.
  • Apple and Google: app distribution, billing, refunds, and subscription management.
  • i3oma.de: delivery of sponsored ads and recording of impressions or clicks.
  • Public authorities or professional advisers: where legally required or necessary to defend legitimate rights.

9. International data transfers

Service providers may process data in your country or in other countries, including the United States or locations in their global infrastructure. The laws in those countries may differ from those in your country.

Where required, we rely on contractual arrangements, safeguards offered by the provider, or other appropriate legal transfer mechanisms. Each provider describes its processing locations and safeguards in its documentation. The actual Firestore location may depend on the Firebase project configuration.

10. Retention periods

  • Local data: until you delete it, clear the app’s data, or uninstall the app, unless an in-app feature removes it earlier.
  • Room data: an operational expiry time of approximately two hours is assigned. Data may remain for a limited period afterwards until actual deletion or within backups and technical logs.
  • Support messages, suggestions, and feedback: for as long as needed to respond, improve the service, and document handling, after which they are deleted or anonymised unless retention is legally required.
  • Reports and security data: for as long as needed to review issues, prevent misuse, resolve disputes, and comply with legal obligations.
  • Purchase data: for the record-keeping period required by the stores, service provider, and applicable financial or consumer law.
Note: We do not intentionally keep personal data longer than necessary for its purpose, although legal obligations or legitimate technical constraints may prevent immediate deletion.

11. Security and its limits

We use HTTPS connections, anonymous authentication, and Firestore access rules that restrict reads and writes according to room membership and data type. We also restrict ad links to HTTPS and seek to minimise the data we collect.

No transmission or storage method is completely secure. Protect your device and room code, and do not share sensitive information in a group game. Contact us promptly if you suspect a security incident.

12. Your choices and rights

Depending on the law in your country, you may have rights to access, correct, delete, restrict, or object to processing; receive or transfer certain data; withdraw consent; and complain to a data-protection authority. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

  • You can avoid cloud processing by using local games and not submitting forms or opening ads.
  • You can delete local data through your device settings. Store subscriptions must be managed and cancelled through your store account.
  • For a data request, use the Contact Us page and provide information that helps us identify the record, such as the room code, approximate time, and player name or identifier if available.
Note: Because Salfa does not require a traditional personal account, we may be unable to link a record to you without enough information. We may request proportionate verification to protect other people’s data.

13. Children’s privacy

We do not intentionally seek to collect personal data from a child who cannot legally consent without a parent or guardian’s permission. A parent or guardian should supervise use where necessary and must not allow a minor to access 18+ content or share sensitive data in rooms.

If you believe a child submitted data to us inappropriately, contact us with enough detail and we will take reasonable steps to verify and delete it where required.

14. If the app is discontinued or removed from stores

If we discontinue the app or a cloud feature, or a store removes it, new collection may stop because the service no longer operates. Data processed earlier does not disappear automatically; we will continue to protect it and delete or anonymise it in line with retention periods and legal obligations.

Where practical, we will try to keep an appropriate channel available for privacy requests during a reasonable transition period. Apple, Google, or RevenueCat may retain independent transaction records under their laws and policies after Salfa has stopped operating.

15. Changes to this policy

We may update this policy when data, features, providers, or legal requirements change. We will change the update date and provide prominent notice or request consent when a change is material and the law requires it.

We recommend reviewing this page after app updates. A new version applies from the effective date shown above. We do not treat continued use alone as new consent where the law requires explicit consent.

16. Contact and complaints

For privacy requests or questions, use the Salfa contact page or email kh249918@gmail.com, and identify the message as a “privacy request.” The responsible party is i3oma, at [LEGAL_ADDRESS]. We will try to respond within the period required by law after appropriate verification.

If you are dissatisfied with the response and the law in your country gives you this right, you may complain to the data-protection authority responsible for your place of residence, place of work, or the location of the alleged infringement.