Ninjafish Studios LLC
Effective and Last Updated: September 2, 2026
Ninjafish Studios LLC (“Ninjafish,” “we,” “our,” or “us”) creates games and apps for children and families. This Privacy Policy explains what information is processed when someone uses a Ninjafish mobile application, game, website, customer-support channel, or related service (collectively, the “Services”), why it is processed, when it may be disclosed, how long it is retained, and the choices available to parents and other users.
Use of the Services is also subject to our Terms of Use (EULA).
Privacy at a Glance for Parents
Ninjafish operates more than one type of app, so the privacy practices depend on the app:
- Apple Kids Category Apps: These apps do not include or initialize third-party advertising networks. We may use Apple’s Identifier for Vendors (“IDFV”) internally for limited app operations, but we do not send IDFV to Google, advertising networks, analytics providers, data brokers, or other third parties. The only non-platform third-party SDK used in these apps is a strictly configured implementation of Google Firebase Crashlytics for crash reporting and app stability.
- Other Child-Directed or Family Apps: Some Ninjafish apps outside Apple’s Kids Category display third-party ads. Where an app is directed to children, those ads are contextual rather than behaviorally targeted, and the advertising integrations are configured for child-directed, age-restricted, or COPPA-restricted treatment.
- No IDFA: Ninjafish does not access, collect, use, store, or transmit Apple’s Identifier for Advertisers (“IDFA”) in any Ninjafish app.
- No child account or direct identifiers: Children do not need to create an account or provide a name, email address, home address, phone number, photograph, voice recording, precise location, or payment-card information to play our child-directed apps.
- Limited technical information: Our apps may process limited technical information such as IDFV, an app or installation identifier, IP address, device and app information, gameplay or feature events, crash information, contextual-ad events, and purchase or subscription entitlement information. COPPA and other privacy laws may treat some of these identifiers as personal information even though they do not reveal a child’s name.
- No behavioral advertising to children: We do not serve personalized or behavioral ads to children, create advertising profiles of children, or track children across apps or websites owned by unrelated companies.
- No sale of children’s information: We do not sell children’s personal information or share it for cross-context behavioral advertising.
- Parental rights: A parent may ask us to confirm, review, delete, or stop further collection of personal information associated with their child.
A Simple Note for Kids
You do not need to tell us your name, email address, phone number, home address, or exactly where you are. We do not show you ads based on what you do in other companies’ apps or websites. Ask a parent or another grown-up to contact us with any privacy question.
1. Scope and App Categories
This policy applies to every Service published or operated by Ninjafish unless a Service displays a separate privacy notice.
For this policy:
- “Child-Directed Apps” means apps that Ninjafish directs primarily to children under 13 or otherwise treats as child-directed under applicable law. An app can be child-directed even if it is not listed in Apple’s Kids Category.
- “Apple Kids Category Apps” means Ninjafish apps listed in the Kids Category of Apple’s App Store. These apps use the strict practices described in Section 3.
- “Ad-Supported Child-Directed Apps” means selected Child-Directed Apps outside Apple’s Kids Category that display contextual third-party advertising under the practices described in Section 4.
- “Adult Services” means our main website, customer-support pages, business communications, social-media pages, and any app or feature that is clearly identified as intended for adults or a general audience.
In a Child-Directed App, we apply child-directed privacy protections to all users rather than trying to identify which individual users are children. For purposes of the U.S. Children’s Online Privacy Protection Act and Rule (“COPPA”), a child is a person under 13. Other countries or states may define children or minors differently, and we apply additional protections where applicable law requires them.
Child-Directed Apps do not enable children to create public profiles, post personal information publicly, or communicate publicly with other users. Links that leave an app, purchasing opportunities, account-management functions, and similar adult-facing features are placed in a parent or grown-up area or behind a parental gate where required.
2. Information We Do Not Ask Children to Provide
We do not ask children using a Child-Directed App to provide:
- a name, home or mailing address, email address, or phone number;
- a photograph, video, audio recording, or voice recording;
- precise geolocation, such as GPS-level location;
- contact-list information;
- social-media account information or login credentials;
- payment-card, bank-account, or full billing information;
- school information; or
- other information intended to directly identify or contact a particular child.
Children do not need a Ninjafish account to use our Child-Directed Apps.
3. Apple Kids Category Apps
Apple Kids Category Apps follow our strictest app configuration.
3.1 No Third-Party Advertising
Apple Kids Category Apps do not include or initialize third-party advertising networks and do not request or display third-party ads. Advertising SDKs used in some other Ninjafish apps are not used in Apple Kids Category Apps.
An Apple Kids Category App may display a contextual promotion for another Ninjafish app. Any such promotion is selected and controlled by Ninjafish and is not based on a profile created by an unrelated advertising company.
3.2 IDFV Is Used Internally Only
Ninjafish may process IDFV internally for limited purposes such as:
- operating and securing the app;
- recognizing an installation across Ninjafish apps on the same device;
- preventing duplicate records or abuse;
- maintaining settings or entitlements;
- counting installations and app-use events;
- diagnosing technical problems;
- limiting repeated Ninjafish cross-promotions; and
- creating aggregated or de-identified statistics.
We do not disclose, sell, rent, or transmit IDFV from an Apple Kids Category App to Google, advertising networks, third-party analytics providers, data brokers, or other third parties. IDFV is different from IDFA, and Ninjafish does not use IDFA.
3.3 Strictly Configured Firebase Crashlytics
The only non-platform third-party SDK used in our Apple Kids Category Apps is Google Firebase Crashlytics, used solely to identify, diagnose, and fix crashes and stability problems.
Crashlytics may receive limited crash and diagnostic information such as:
- a crash stack trace or exception information;
- the date and time of a crash;
- the app’s bundle identifier and version;
- operating-system version and device model;
- technical information about memory, disk space, processor architecture, and app state; and
- Google-generated Crashlytics or Firebase installation identifiers used to associate and deduplicate crash reports.
For Apple Kids Category Apps, we configure Crashlytics without advertising features and do not configure it to receive:
- IDFV or IDFA;
- a name, email address, phone number, or other direct identifier;
- a custom user ID;
- precise geolocation;
- contact information;
- photos, videos, voice recordings, or user-generated content; or
- behavioral advertising or cross-app tracking information.
We do not use Google Analytics in Apple Kids Category Apps for user-behavior analytics. Crashlytics information is used only for app stability, debugging, security, and support for internal operations.
3.4 Other Limited Information
Depending on the app and feature used, Ninjafish may also process the following internally or receive it from Apple:
- app launches, sessions, screens, features, levels, or tools used;
- general gameplay progress and app settings;
- device type, operating-system version, app version, language, time zone, and similar technical settings;
- IP address and approximate country or region derived from an IP address when necessary for network communications, security, or lawful regional configuration;
- crash, error, and security events; and
- product, transaction, receipt, subscription, and entitlement information needed to provide or restore purchases.
We do not use this information to contact a child, identify a child by name, serve behavioral ads, determine precise location, or build a commercial profile of a child.
4. Other Child-Directed and Ad-Supported Apps
Some Ninjafish Child-Directed Apps outside Apple’s Kids Category display third-party advertising. In those apps:
- ads are contextual rather than personalized or behaviorally targeted;
- ad selection is not based on a child’s activity in unrelated companies’ apps or websites;
- the app and relevant advertising integrations are designated as child-directed, age-restricted, or COPPA-restricted;
- available child-treatment settings are enabled in provider dashboards and, where supported, in the SDK or ad request;
- IDFA is not accessed, collected, used, stored, or transmitted;
- providers are instructed not to contact a child, build an unrelated child profile, or use app information for behavioral advertising; and
- available age-rating and creative controls are used to reduce the delivery of inappropriate ads.
To deliver and secure a contextual ad, an advertising provider may process limited information such as:
- IP address;
- device and app characteristics;
- approximate country or region;
- an app-scoped, vendor-scoped, installation, or provider-generated pseudonymous identifier where permitted by the platform and configuration;
- ad-request, impression, completion, click, or interaction information;
- frequency-cap information; and
- security, fraud-prevention, and invalid-traffic signals.
“COPPA mode” does not mean that no technical information is processed. It means the provider is instructed and configured to apply child-directed restrictions, including restrictions on behavioral advertising and unrelated profiling.
Not every Ninjafish app uses every advertising provider listed in Section 7. The advertising services identified there are not used in Apple Kids Category Apps.
5. Other Limited Technical and Purchase Information
Depending on the app, platform, app version, and features used, Ninjafish and authorized service providers may process:
5.1 Vendor-, Installation-, and App-Scoped Identifiers
This may include:
- IDFV;
- an app-instance, installation, or randomly generated identifier;
- a provider-generated identifier used for contextual ad delivery, security, or crash reporting; and
- limited transaction, receipt, or entitlement identifiers related to purchases and subscriptions.
These identifiers are pseudonymous. They do not directly reveal a child’s name, but they may still be personal information under COPPA or personal data under other laws.
5.2 Device, App, and Network Information
This may include:
- device type or model;
- operating-system and app version;
- language, time zone, screen characteristics, and similar technical settings;
- internet-connection or network information;
- IP address; and
- approximate country, state, province, or region derived from an IP address.
We do not collect precise GPS location from children for advertising.
5.3 App-Use and Performance Information
This may include:
- app launches and session information;
- screens or features viewed;
- levels played or completed;
- buttons or tools used;
- general gameplay progress;
- whether a contextual ad was requested, shown, completed, skipped, or interacted with;
- crash logs, error reports, load times, and diagnostic information; and
- security, abuse-prevention, and fraud-detection events.
5.4 Purchase and Subscription Information
Apple or another app-store provider processes purchases and subscription payments. We may receive limited information needed to provide and restore purchased content, such as:
- product identifier;
- transaction or receipt identifier;
- subscription status;
- purchase date or expiration date; and
- entitlement status.
We do not receive or store a user’s full credit-card number or full app-store account payment details.
6. How We Use Limited Technical Information
We use limited technical information only for purposes such as:
- providing requested app features and remembering app settings;
- maintaining app functionality, stability, compatibility, and performance;
- saving or restoring progress where the app supports that function;
- verifying, providing, and restoring purchases and subscription entitlements;
- counting installations, active users, sessions, and feature use;
- understanding which features work well and improving our games;
- diagnosing crashes, bugs, loading problems, and technical errors;
- securing the Services and detecting fraud, abuse, invalid traffic, or malicious activity;
- complying with app-store, legal, tax, accounting, and regulatory obligations;
- serving contextual ads in Ad-Supported Child-Directed Apps;
- limiting how often the same contextual ad or Ninjafish promotion is shown;
- measuring whether a contextual ad or Ninjafish promotion was displayed or selected; and
- creating aggregated or de-identified statistics that are no longer reasonably linked to a particular device or user.
We do not use information from Child-Directed Apps to:
- contact a child;
- determine a child’s real-world identity;
- serve personalized or behavioral advertising;
- infer a child’s interests for advertising;
- create a commercial profile of a child;
- track a child across apps or websites operated by unrelated companies;
- determine precise location; or
- sell information about a child.
7. COPPA Internal Operations and Operators
Under COPPA, an IP address, IDFV, or another persistent identifier may be personal information. COPPA permits limited processing of a persistent identifier without prior verifiable parental consent when it is used solely to support the internal operations of a child-directed service.
We rely on that limited exception only for activities reasonably necessary to:
- maintain or analyze the functioning of an app;
- perform network communications;
- authenticate users or maintain app settings without creating an advertising profile;
- serve contextual advertising in an Ad-Supported Child-Directed App;
- apply frequency caps;
- protect the security or integrity of a user or app;
- comply with law;
- fulfill a permitted request; and
- conduct permitted debugging, statistics, and internal analytics.
We use technical and contractual controls intended to prevent identifiers processed under this exception from being used to contact a child, serve behavioral ads, build an unrelated profile, or serve another unrelated purpose.
Ninjafish is the operator responsible for responding to parent inquiries about the practices described in this policy. The following companies may collect or maintain limited information through a Ninjafish Service as operators or service providers. The specific combination varies by app and platform.
| Company or service | Where it may be used | Purpose and limited information that may be processed |
|---|---|---|
| Ninjafish Studios LLC | All Services | App operation, first-party analytics, security, support, purchase entitlements, contextual Ninjafish cross-promotion, and compliance. This may include IDFV or app-instance identifiers, IP address, device/app information, app-use events, diagnostics, contextual-ad events, and transaction or entitlement information. In Apple Kids Category Apps, IDFV is used internally by Ninjafish and is not transmitted to third parties. |
| Apple Inc. | Apple-platform apps | App Store distribution, updates, StoreKit purchases and subscriptions, purchase restoration, platform services, and Apple Search Ads or AdServices attribution. Apple may process Apple-controlled account, payment, transaction, receipt, entitlement, device/platform, and campaign information under Apple’s own terms. |
| Google LLC — Firebase Crashlytics | Apple Kids Category Apps and selected other apps | Crash reporting, stability, debugging, and security. Crashlytics may process crash traces, technical device/app information, and Google-generated Crashlytics/Firebase installation identifiers. In Apple Kids Category Apps, Ninjafish does not send Crashlytics IDFV, IDFA, custom user IDs, direct identifiers, precise location, advertising data, or user-generated content. |
| Google LLC — AdMob or Google Ad Manager | Selected ad-supported apps outside Apple’s Kids Category only | Contextual ad delivery or mediation, frequency capping, ad reporting, security, and fraud prevention. Limited information may include IP address, device/app characteristics, approximate region, permitted pseudonymous identifiers, contextual-ad events, and fraud signals. |
| Unity Technologies and ironSource services, including Unity Ads and LevelPlay | Selected ad-supported apps outside Apple’s Kids Category only | Contextual advertising, mediation, frequency capping, ad reporting, security, and fraud prevention. Limited information may include IP address, device/app characteristics, approximate region, permitted pseudonymous identifiers, contextual-ad events, and fraud signals. |
| Liftoff Mobile, Inc., including Vungle or Liftoff Monetize | Selected ad-supported apps outside Apple’s Kids Category only | Contextual advertising, ad delivery, frequency capping, ad reporting, security, and fraud prevention. Limited information may include IP address, device/app characteristics, approximate region, permitted pseudonymous identifiers, contextual-ad events, and fraud signals. |
| Mintegral / Mobvista | Selected ad-supported apps outside Apple’s Kids Category only | Contextual advertising, ad delivery, frequency capping, ad reporting, security, and fraud prevention. Limited information may include IP address, device/app characteristics, approximate region, permitted pseudonymous identifiers, contextual-ad events, and fraud signals. |
Provider privacy information is available at:
- Apple: https://www.apple.com/legal/privacy/
- Google: https://policies.google.com/privacy
- Firebase: https://firebase.google.com/support/privacy
- Unity: https://unity.com/legal/game-player-and-app-user-privacy-policy
- Liftoff: https://liftoff.io/privacy-policy/
- Mintegral: https://www.mintegral.com/en/privacy
The ad providers listed above are not used in Apple Kids Category Apps. In other Child-Directed Apps, we do not authorize them to use children’s information for personalized advertising, cross-context behavioral advertising, contacting a child, or building an unrelated child profile.
We take reasonable steps to select service providers capable of protecting children’s information and seek appropriate contractual assurances concerning confidentiality, security, use restrictions, and deletion.
We do not currently offer a Child-Directed App feature that asks a child to submit personal information requiring verifiable parental consent. If we introduce such a feature, we will provide direct notice to the parent and obtain verifiable parental consent before collecting, using, or disclosing that information, unless a specific legal exception applies.
8. Purchases and Subscriptions
Some apps offer optional purchases or auto-renewing subscriptions. Purchases should be completed by a parent or another authorized adult.
Apple or the applicable app store is responsible for payment processing, billing, cancellation, and refund handling. Ninjafish may use limited transaction and entitlement information to validate a purchase, determine whether a subscription is active, unlock paid features, prevent fraud, provide support, and restore purchases. Subscription status does not reduce the privacy protections applied to a Child-Directed App.
9. Website, Support, and Adult-Provided Information
Our main website, customer-support channels, business communications, and social-media pages are intended for parents and other adults.
When an adult contacts us, we may process:
- name;
- email address;
- phone number, if voluntarily provided;
- message content;
- app, device, purchase, or troubleshooting information; and
- attachments voluntarily submitted.
When someone visits our website, our hosting and security providers may process standard technical information such as IP address, browser type, requested pages, timestamps, device information, and security logs. We may use essential cookies or similar technology needed to operate and secure the website. We do not combine adult website information with information from a Child-Directed App to target advertising to a child.
Children should not submit support requests or personal information. If we learn that a child sent personal information through an adult-facing support or website feature without appropriate parental involvement, we will delete it unless retaining it is necessary to protect the child, respond once to the request as legally permitted, or comply with law.
10. When Information May Be Disclosed
We may disclose limited information:
- to the operators and service providers listed in Section 7 for the purposes and app categories described there;
- to Apple or another platform provider to distribute an app, process a purchase, or restore an entitlement;
- when required by law, subpoena, court order, or a valid government request;
- when reasonably necessary to protect a child, another person, our rights, or the security and integrity of the Services;
- to investigate fraud, abuse, invalid traffic, or a security incident;
- to professional advisers under confidentiality obligations; or
- in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business, subject to continued protection of the information and applicable notice or consent requirements.
Child-Directed Apps do not enable children to make personal information publicly available.
We do not sell children’s personal information. We do not share children’s personal information for cross-context behavioral advertising, and we do not knowingly permit behavioral advertising or profiling of users under 16.
11. Data Retention and Deletion Schedule
We retain personal information only for a defined business or legal need and do not retain children’s personal information indefinitely.
Unless a shorter period applies or a longer period is reasonably necessary for a documented security incident, legal obligation, dispute, or legal claim, our retention schedule is:
| Information | Purpose and maximum retention period |
|---|---|
| Raw Ninjafish network and security logs, including IP addresses | Network operation, security, fraud prevention, and debugging; generally up to 30 days. |
| Ninjafish first-party IDFV-linked, app-instance-linked, or event-level app-use records from Child-Directed Apps | App operation, permitted internal analytics, performance, security, entitlement support, and contextual Ninjafish cross-promotion; up to 24 months from collection, after which the data is deleted or de-identified. In Apple Kids Category Apps, IDFV is not transmitted to third parties. |
| Firebase Crashlytics reports and associated Crashlytics/Firebase identifiers | Crash diagnosis and app stability. Google currently retains Crashlytics crash traces and associated identifiers for 90 days before beginning removal from live and backup systems. |
| Ninjafish-controlled contextual-ad and ad-reporting records from apps outside Apple’s Kids Category | Contextual ad delivery, frequency capping, aggregate reporting, security, and fraud prevention; up to 24 months from collection, after which the data is deleted or de-identified. Advertising providers may retain provider-controlled records under their posted retention policies and applicable service settings, but may not retain children’s information indefinitely or use it for an unauthorized purpose. |
| Purchase, subscription, receipt, and entitlement records | Providing and restoring paid content, customer support, fraud prevention, and accounting; while the purchase or subscription remains relevant and generally up to 24 months afterward. Records required for tax, accounting, fraud, or legal compliance may be retained for up to 7 years. |
| Adult support requests and correspondence | Responding to the request and maintaining a limited support history; up to 12 months after the request is closed, unless a longer period is needed for an active purchase dispute, security matter, or legal obligation. |
| Backups containing information scheduled for deletion | Disaster recovery and system integrity; ordinarily overwritten or deleted within 90 days. |
Where we control a service provider’s retention setting, we configure it consistently with the periods above or a shorter period. We require or instruct service providers not to retain children’s information longer than reasonably necessary for the authorized purpose and to delete or de-identify it when that purpose ends.
When deletion is required, we use reasonable measures intended to protect against unauthorized access to or use of the information during deletion. Aggregated or de-identified information that can no longer reasonably be linked to a child or device may be retained for legitimate business analysis.
12. Parental Rights and Requests
A parent or legal guardian may ask us to:
- confirm whether we maintain personal information associated with their child;
- review the information, where reasonably identifiable;
- correct inaccurate information;
- delete the information;
- refuse further collection or use; or
- receive information about the types of information collected, how it is used, and the operators that receive it.
To submit a request, contact us using Section 17. Please identify the Ninjafish app, device platform, approximate dates of use, and any support or transaction information needed to locate the record. Because our Child-Directed Apps do not use a child’s name or account, we may need limited technical information to identify the relevant data. Please do not send unnecessary information about the child.
We may take reasonable steps to verify that the requester is the child’s parent or legal guardian. We will not require disclosure of more information than reasonably necessary to verify and fulfill the request. We will respond within the period required by applicable law.
A request to stop further collection may affect features that need limited technical information to function. A parent may stop further app collection by deleting the app from the device. Deleting the app does not necessarily delete information already held by us or a service provider, so a parent should contact us to request deletion of existing records.
We may retain information when legally required or reasonably necessary to complete a transaction, prevent fraud, protect security, or establish, exercise, or defend legal claims. We will explain an applicable exception when required.
13. Security
We maintain administrative, technical, and physical safeguards designed for the sensitivity and limited amount of information processed through our Child-Directed Apps. These measures include data minimization, access controls, service-provider review, security monitoring, and procedures for responding to suspected incidents.
We maintain a written information-security program for children’s information, designate responsibility for that program, assess risks periodically, review safeguards, and seek appropriate written assurances from service providers. No storage or transmission system can be guaranteed to be completely secure.
14. International Users, EEA, and United Kingdom
Ninjafish Studios LLC is based in the United States. Information may be processed in the United States and other countries where authorized service providers operate.
For users in the European Economic Area or United Kingdom, Ninjafish is generally the controller of information processed for its own purposes. Depending on the activity, our legal basis may be:
- performance of a contract with a parent or user, including providing app functionality and purchases;
- our legitimate interests in operating, securing, debugging, and improving the Services, when those interests are not overridden by the user’s rights;
- compliance with a legal obligation; or
- consent, including parental authorization where applicable law requires it.
Users in these regions may have rights to access, correct, erase, restrict, or object to processing; receive portable data in certain circumstances; withdraw consent where processing is based on consent; and complain to a local data-protection authority.
Where local law requires consent or another authorization for a child, we will apply the required process or refrain from the relevant processing. International transfers are handled using legally recognized safeguards where required.
15. U.S. State Privacy Rights
Residents of certain U.S. states may have rights to know, access, correct, delete, or obtain a copy of personal information and to appeal a denied request. Where applicable, users may also opt out of sale, targeted advertising, or certain profiling.
Ninjafish does not sell personal information and does not share personal information for cross-context behavioral advertising. Child-Directed Apps do not serve targeted or behavioral advertising. We do not knowingly sell or share the personal information of users under 16.
A parent or another authorized person may exercise applicable rights using the contact information below. We will not discriminate against a user for exercising a privacy right. Where legally required, we recognize supported browser-based opt-out signals, although our Services are not designed to sell or share information for behavioral advertising.
16. Changes to This Policy
We may update this policy to reflect changes in our Services, providers, technology, or legal obligations. We will post the updated policy and revise the “Last Updated” date.
If a change materially expands how we collect, use, or disclose children’s personal information, we will provide the notice required by law. Where new verifiable parental consent is required, we will obtain it before applying the new practice to a child’s information.
17. Contact Us
Parents, guardians, and other users may contact us with questions or privacy requests:
Ninjafish Studios LLC
Attn: Privacy
7901 4th St N #7203
St. Petersburg, FL 33702
United States
Email: [email protected]
Phone: +1 (347) 835-8474
Contact Form: https://www.ninjafish.com/contact
Ninjafish Studios LLC will respond to parent inquiries concerning Ninjafish and the operators and service providers listed in Section 7.
