Skip to main content
Iopex Technologies

Privacy

Privacy policy

Written as a runbook rather than an essay. Each record gets a scope line, a field list, a storage location, a retention clock and a named reader, in that order, because those are the five things a person actually needs from a document like this.

In force 10 August 2026Revision 1.0Privacy Act 1988 (Cth)

01Entity, coverage, name collision

Scope: every record about an identifiable person that this company captures, receives or stores, on any surface it runs.

Entity
IOPEX TECHNOLOGIES PTY LTD
ACN
696 561 609
ABN
54 696 561 609
Form
Australian proprietary company, limited by shares
Base
Melbourne, Victoria
Contact point
[email protected]
Instrument
Privacy Act 1988 (Cth), Schedule 1

"We", "us" and "our" below mean that entity and nothing broader. There is no parent, no group and no affiliate to fold into those words.

Surfaces covered

  • This website, iopex.co.im, served as static files.
  • Any mobile title released under this company name, on any store.
  • Mail to the address above, including whatever is attached to it.

Surfaces not covered

  • Apple and Google, which keep their own store and platform records under their own terms.
  • An advertising network acting for itself rather than on our instruction, dealt with at 14.
  • Anything reached by following a link away from here.

Name collision. iOPEX Technologies, Inc. is a separate and considerably older business in enterprise IT and business process services. No record described in this document is held by it, shared with it, or reachable through it, and mail intended for that company cannot be forwarded from our address.

02What is held, at this revision

Scope: the categories of personal information this company holds on the effective date printed above. Every one of them is listed here, and the sections that follow take each apart field by field.

Correspondence
Mail to the address above and the thread that follows it. Fields at 07, retention clock at 21
Request logs for this site
Held by the hosting provider, on the terms and for the window set out at 06
Analytics on this site
None installed. No tag manager and no third party script, which the cookie notice tells you how to verify in a browser
Telemetry
Runs on handsets this company owns, driven by the capture harness and the session runner described on the company page. Frame timestamps and thermal state off our own devices, keyed to no person

Sections 05, 22 and 23 set out, field by field, what a title of ours writes, what the field is for, and what switches it off. They are written as a specification you can hold the software to, so the design can be argued with off this page instead of reverse engineered out of a binary.

The rights described at 23, 24, 27 and 30 run against every category above. If you have written to us, you can ask what that thread contains, ask for it to be fixed, ask for it to go, and complain about whatever answer you get.

03The Act, and a map of the thirteen principles

Scope: the statute this document answers to, and which section answers each principle.

The governing instrument is the Privacy Act 1988 (Cth). Schedule 1 to that Act sets out thirteen Australian Privacy Principles, and for an organisation of this kind they are close to the whole obligation set. The map below exists so that a reader auditing this document against the Schedule does not have to hunt for the paragraph that answers a given principle.

Australian Privacy Principles, and where each is answered
PrincipleShort nameObligation, in one lineAnswered at
APP 1Open and transparent managementRun practices that ensure compliance, and keep a current, clearly expressed policy available free01, 32
APP 2Anonymity and pseudonymityOffer the option of not identifying yourself unless that is impracticable or the law forbids it11
APP 3Collection of solicited informationCollect only what is reasonably necessary for a function we actually perform05, 06, 07
APP 4Unsolicited informationAssess what arrives unasked, then destroy or de-identify what could not have been collected12
APP 5Notification of collectionSay what is being taken, why, and what happens if it is withheld, at or before collection10
APP 6Use and disclosureUse it for the purpose it was taken for, and for a secondary purpose only on a listed ground13
APP 7Direct marketingDo not use personal information to market unless a narrow set of conditions is met15
APP 8Cross-border disclosureTake reasonable steps before sending anything to a recipient outside Australia17
APP 9Government related identifiersDo not adopt, use or disclose an identifier assigned by a government agency18
APP 10QualityKeep what is collected accurate, current and complete, and relevant when it is used19
APP 11SecurityGuard it for as long as it is held; destroy or de-identify once nothing needs it20, 21
APP 12AccessGive a person the personal information held about them when they ask for it24
APP 13CorrectionCorrect what is wrong, and where asked, tell anyone it was disclosed to24

A reference below to "APP 6", or any other number, means the correspondingly numbered principle in that Schedule.

04The small business exemption is not relied on

Scope: whether the Act binds this company today, and what is done about the gap.

Section 6D of the Act lifts most organisations turning over $3 million a year or less out of the Australian Privacy Principles. This company turns over less than that figure, and on a narrow reading falls inside the exemption.

The exemption is not being used, for two reasons that are engineering reasons rather than moral ones. It keys off turnover instead of sensitivity, so it would disappear on the day a title started earning, without one field of the data having changed. And several carve-outs inside section 6D pull a business back under the Act as soon as it discloses personal information about someone for a benefit or advantage. Meeting the standard from the first line costs less than retrofitting a pipeline that was drawn without it.

Requests and complaints are handled as though the Act applied in full. Should it start binding us as law rather than as a choice, no clause here needs rewriting.

Other Australian instruments in force here

  • Spam Act 2003 (Cth). Consent, sender identification and a functioning unsubscribe on any commercial electronic message. Handled at 15.
  • Australian Consumer Law. Schedule 2 to the Competition and Consumer Act 2010 (Cth) carries guarantees that no contract term is able to strip out.
  • Part IIIC of the Privacy Act. The Notifiable Data Breaches scheme, handled at 27.
  • Privacy and Other Legislation Amendment Act 2024 (Cth). Three consequences here: the tort at 28, the automated decision entry at 26, and a Children's Online Privacy Code awaiting registration, flagged at 25.
  • Do Not Call Register Act 2006 (Cth). No telemarketing is done and no telephone number is collected that would make it possible.

05Ingest: telemetry from a published title

Scope: every field a released title writes, and the clock attached to each. There is no supplementary list held elsewhere.

Performance engineering runs on measurement, which makes this the section to be most suspicious of. "Diagnostics" is the word under which collection is usually hidden, and the only defence against that is an itemised field list that can be checked against a packet capture.

Records a published title writes
RecordFields written at ingestWhy it existsSwitchableClock
Device profile Model, chipset, total and available memory, screen resolution, refresh rate, operating system version, build version, thermal headroom as the platform reports it A frame time means nothing without the hardware that produced it. This record is the axis every other measurement is plotted against No. Removing it makes the rest unreadable 25 months
Frame timing Presentation intervals reduced to a distribution on the handset, missed deadline count, stall durations The 99th percentile and the deadline miss count, which are the two numbers this company works to Yes, in the title's settings. Play is identical either way 25 months, then aggregated
Thermal and power Minutes from cold start to first throttle, thermal state transitions, charge level at session start and end, charging flag Time to throttle, and drain per hour of play Yes, same switch as frame timing 25 months, aggregated thereafter
Crash and ANR Stack trace, thread states, memory state at fault, breadcrumb log Fixing the crash, then proving the fix worked on the hardware that crashed Yes, from the title's settings 90 days
Advertising identifier Identifier for Advertisers on iOS, or on Android the Google Advertising ID Capping how often an advertisement repeats, and attributing an install, where a title carries advertising. Personalisation only after you switch it on Yes: system settings can reset it, or remove it outright 13 months
Purchase Store transaction identifier, product, amount, currency, date, refund state Restoring what you bought, and meeting tax and accounting obligations Written only where a purchase happens 7 years

Aggregation happens on the handset, before anything is sent

Frame timing leaves a device as a distribution, never as a series. Percentiles and the deadline miss count are computed locally and the per-frame array is dropped there. A per-frame series is a second-resolution record of exactly when somebody was holding a phone and for how long; the analysis has no use for it, so the pipeline is built so that it never receives one.

Battery fields are not health fields and not movement fields

Charge level and charging flag are read at session start and session end, in the foreground, and feed exactly one calculation: drain per hour of play. They are not sampled while a title is backgrounded and they are never joined to anything that would suggest where a device is or what its owner's day looks like.

Identifier discipline

Telemetry is keyed to an install identifier generated on the device, not to an account, an email address or a hardware serial. Deleting the app discards the key. The advertising identifier stays in its own store and is never used to look up a telemetry record, which is the join that would turn a performance dataset into an advertising profile.

06Ingest: this website

Scope: what a request to iopex.co.im leaves behind, and where it lands.

Records generated by a page request
RecordFieldsLives withPurposeClock
Request logIP address, path, response status, user agent, timestampHosting providerServing the file, and blocking abusive trafficProvider rotation, under 30 days
Bot management tokenAn opaque value in a strictly necessary cookieHosting providerSeparating automated traffic from human traffic30 minutes, refreshed on activity
Challenge tokenAn opaque value, written only if a challenge is shown and passedHosting providerNot putting the same visitor through a second challengeUp to 30 days

Nothing else is written. No analytics product, advertising tag, pixel, session recorder or fingerprinting script is installed on any page, which is why no page asks for consent to anything. The full inventory, and the reasoning behind the absence of a banner, is in the cookie notice.

The site has no form, so it accepts no submission. Every route on it is a static file plus one stylesheet, one small script and images; the script opens the navigation on a narrow screen and reveals sections on scroll, and it stores nothing.

07Ingest: correspondence

Scope: mail sent to the published address, and every field that mail leaves behind.

Written at ingest
Sender address, subject, message body, attachments, and the routing metadata your provider attaches
Lives with
Our email provider, listed in the register at 16
Support threads
24 months, counted from the newest message in that thread
Complaint threads
7 years from closure
Readers
The people who answer the mailbox. Nothing forwards to a third party
Secondary use
None. A thread is not mined, profiled or used to target advertising

An address that arrives in that mailbox is not added to any list, because no list exists to add it to. That is the quiet route by which small companies build a marketing database, and 15 explains why this one does not.

08Never collected

Scope: fields that no build, endpoint or page on this estate is permitted to capture. This list is as load-bearing as the collection tables and is easier to verify.

  • Location at any precision, including the coarse network kind that needs no prompt.
  • Camera, microphone, photo library, contacts and calendar, call log, phone state, SMS.
  • Body, health and fitness sensors.
  • Usage statistics for other applications. This one would genuinely help, since background load explains a good share of stalls on a loaded handset, and it is still declined.
  • Identifiers assigned by government, of every kind, dealt with at 18.
  • Sensitive information as the Act defines it: health, racial or ethnic origin, political opinion, religious belief, sexual orientation, criminal record, union membership.
  • Biometric templates, and any biometric material at all.
  • Form fields. This estate ships no form, so nothing gets typed into one and no endpoint waits behind it.

A build that requests one of these is a defect, not a product decision. Report it to the address at 33 and it gets handled as a defect.

09Records we hold, traces held on instruction

Scope: the difference between a record this company holds for its own purposes and a trace it would hold because another studio asked for it. The distinction decides who has to answer you, so it is stated before it becomes relevant.

Role A: records held for our own purposes

Everything itemised at 05 through 07 sits here. This company decides what is captured, why, and for how long, and is the entity answerable for it under the Act. Every right in this document runs directly against us, and the clocks at 21 are ours to keep.

Role B: traces captured under a studio's instruction

Profiling can also run the other way around. If this company is engaged to measure another studio's title, the traces produced belong to that engagement: the studio nominates the build, the device set and the field list, the studio sets the purpose and the retention window, and the studio's own privacy policy governs its relationship with its players. Our part is bounded and would be written down as such. Capture what the field list says, hold it for the agreed window, hand it over, destroy it on instruction, and make no secondary use of it, which specifically means never folding a customer's traces into anything of ours.

Which role applies. Role B is set out here because the two roles are handled differently, and because anybody reading this is owed the answer before it starts applying to them. Where it begins to apply, this section and the register at 16 are updated before the first trace is captured, not after.

10Notice at the point of ingest

Scope: how the disclosure APP 5 requires is actually delivered, and where.

APP 5 asks for the notice at or before collection, or as soon as practicable after it, and for the cost of withholding to be spelled out. Three delivery points carry it, this page being only the third.

  1. Store listing. Apple's privacy labels and the Google Play Data Safety declaration set out what a title records before an install begins.
  2. Inside the title. A permission is explained in our own words on the screen before the operating system dialog appears, never on the screen after it.
  3. Here. Every page of this site links to this document, as does the settings screen inside any title.

The consequence of withholding is the Switchable column at 05 and the If declined column at 22, rather than a sentence somewhere in the middle of a paragraph. Where a store declaration and this document disagree, the disagreement is a defect: report it, and whichever of the two is wrong gets corrected.

11Anonymous and pseudonymous dealing

Scope: dealing with this company without telling it who you are.

APP 2 makes anonymity an option unless honouring it is impracticable, or unless the law demands an identified individual. Cheap to honour here, because identity is not an input to anything built. Play needs no account, no name and no address, and the keys described at 05 sit on an install.

Mail may come from a pseudonymous address and gets the same answer as any other. The one place the option genuinely runs out is an access or correction request, where a record has to be tied to the person asking for it before it can be handed over. That trade is described at 24 rather than left to be discovered.

12Records that arrive unasked

Scope: personal information that reaches us without having been requested.

In practice it arrives three ways: a bug report with a full screen recording attached, a diagnostic export produced by some other tool, or a forwarded thread carrying other people's addresses in the quoted history.

Procedure

  1. Assess within a reasonable period whether APP 3 would have allowed the collection at all.
  2. Where it would not, and no Commonwealth record is involved, destroy or de-identify as soon as practicable, so far as that is lawful and reasonable.
  3. Write down the substance of the report without it, so the defect survives and the material does not.

Destruction here means the attachment is removed from the mailbox and expires from the provider's backup rotation on its ordinary cycle. Nothing is retained on the theory that it might be useful later.

13Use and disclosure

Scope: what may be done with a record once it has been collected.

APP 6 supplies the rule. A record may serve the purpose it was taken for. A second purpose needs one of three things behind it: your reasonable expectation plus a genuine relationship between the two purposes, your consent, or an exception the Act spells out.

Permitted uses

  • Running the titles and the features you asked for.
  • Diagnosing a crash or a defect, then checking whether the fix moved the number it was meant to move.
  • Catching fraud, cheating and abuse: scripted play, duplicated installs, a tampered client.
  • Serving advertising where a title carries it, on the terms at 14.
  • Answering your mail, and meeting a legal obligation that applies to us.

Uses that are ruled out

  • Selling personal information. No broker gets it, no advertiser buys it, and it goes into no audience product.
  • Assembling a profile of a person across the products of unrelated companies.
  • Using the content of your correspondence to target anything at you.
  • Joining telemetry to advertising records, which is the specific join described at 05 and 14.

Disclosure to courts and enforcement bodies

Disclosure happens only on a ground the Act supplies, and four arise in practice: a requirement or authorisation under Australian law; an order made by a court or by a tribunal; the permitted general situations section 16A supplies, of which a serious threat to health, life or safety is the obvious one; and a request from an enforcement body, where handing the record over is reasonably necessary for an enforcement related activity. APP 6.5 obliges a written note of that last case, and one gets made. Where telling you is permitted, you are told.

14The advertising path, and the wall around telemetry

Scope: what advertising in a title would mean for a record about you.

Default state

An advertising request is marked non-personalised until you change that in the title's settings. A non-personalised advertisement is selected from context rather than from anything held about you.

The wall

Device profile, frame timing, thermal and power records are never transmitted to an advertising network and never used to assemble a segment. The reason is specific rather than decorative: a device model joined to a thermal profile is a good estimate of what handset somebody could afford, which is exactly the inference an advertising system would pay for. The separation is a property of the code path, not a promise in a policy, and the two stores share no key.

App Tracking Transparency

Apple's own prompt controls the Identifier for Advertisers. Ours comes first: the system dialog is raised only once personalisation has been enabled in the title's settings, so it never lands cold.

Play Data Safety

Each title's Google Play Data Safety declaration is kept aligned with this document. A difference between the two is a defect and worth an email to [email protected].

A network is not our processor

An advertising network runs its own fraud checks and its own cross-inventory measurement, for itself, not on instructions from us. Records sitting there are beyond our reach, and no promise to delete them will be offered. Stopping the flow is available, and that is precisely what switching personalisation off performs.

Controls that work whatever we do

  • Android: Settings, Google, Ads, then reset or delete the advertising ID outright.
  • iOS: Settings, Privacy and Security, Tracking, and withdraw the permission there.
  • Either platform: uninstalling stops transmission from that device at once.

15Direct marketing and the Spam Act

Scope: unsolicited messages, and the list that does not exist.

APP 7 limits what a personal record may be used to market. The Spam Act 2003 (Cth) sits over that, reaching email, SMS and instant messaging, with three hard requirements: consent, sender identification that is accurate, and an unsubscribe path live for at least 30 days and honoured inside 5 working days.

Position

No marketing list exists here, and no marketing message has gone out under this name. Should one ever go out, opt in is how it will work: consent stored with its timestamp and the exact wording agreed to, and a first message naming where the address came from.

Advertising inside a title is a different thing

An advertisement shown during play is served by a network into an ad slot. Nobody here addressed it to you, which puts it outside APP 7 and inside 14. The controls still work: personalisation stays off until switched on, and the platform level controls listed at 14 apply regardless of any setting of ours.

16Recipient register

Scope: every party that receives personal information from us, what it gets, and the regions it holds it in. This table is the authoritative list, not an illustrative one.

Recipients, what they receive, and where it sits
RecipientReceivesFunctionRegions
Google Ireland Limited and Google LLCCrash and ANR reports, device profile, purchase records, advertising identifierCrash reporting, Play billing, advertising deliveryIreland, the United States, further Google regions
Apple Inc.Purchase records, crash reportsStore distribution, in-app purchase billing, and iOS crash reportsApple regions, the United States included
Cloudflare, Inc.Request logs including IP addressServing and protecting this websiteGlobal edge, Australia included
Our email providerWhatever an email containsReceiving and storing correspondenceAustralian and United States regions
Our accountantAggregate revenue, and an individual transaction where a query turns on oneStatutory accounts, business activity statements, taxAustralia

Not on the register

None of the following: data broker, marketing platform, customer data platform, enrichment or append service, identity graph, third party performance analytics vendor. The last is worth naming. It is the component a company like this one is expected to adopt, and adopting it would hand a supplier the device profile of every player. The table above changes first.

Published figures

Any performance figure this company publishes will be an aggregate computed from de-identified records, with no cell small enough to point at one person and no individual device row. No dataset will be released.

Sale of the business

Records may move to a buyer when the company or a title is sold. Notice goes up here ahead of completion wherever the law permits it, and the buyer inherits this document as the binding one until it publishes something of its own.

17Disclosure outside Australia

Scope: records that leave the country, and who wears it when something goes wrong offshore.

APP 8 covers a recipient sitting outside Australia. The provision that matters is section 16C: an act by that recipient which would have breached the Australian Privacy Principles counts as our act, and the liability lands here.

That accountability rule, rather than the list of exceptions, is what shapes the register at 16. It is why the list is short, why every entry is a named company instead of a category, and why adding one is a decision rather than a default.

Reasonable steps taken before a disclosure

  • Contract. Provider data processing terms, which oblige it to follow our instructions, hold the records securely, support an individual's request, and report a breach to us.
  • Region choice. Where a provider offers a region, the closest one that supports the workload is selected, and the register records where it landed.
  • Field minimisation. A recipient gets the fields its function needs, which is why the Receives column at 16 differs from row to row.

Exceptions not used

The APP 8.2(a) route, which permits disclosure where the recipient is subject to a substantially similar law, is not relied on. Judging that country by country is not work this company is qualified to do, and getting it wrong would move the risk onto the person whose record it was. Consent as a standalone basis under APP 8.2(b) is not used either, because consent buried in an install flow is not a real decision.

Regions listed in the column at 16 are the countries where a record may sit or be reached. Move a provider to another region and that column is what changes.

18Government related identifiers

Scope: identifiers government issues. Passport number, driver licence number, Medicare number, tax file number.

APP 9 bars three things outside narrow exceptions: taking a government identifier as our own, putting one to use, and passing one on. Nothing here collects one. No age check, identity check or payout step exists that would want one, and no field anywhere is shaped to receive one.

If one arrives anyway, typically as a photograph of a licence attached to an email, it is handled as unsolicited material under 12 and destroyed. It is not filed, and it is not used to verify an access request either, which 24 explains.

19Record quality

Scope: keeping what is held accurate enough to be used, as APP 10 requires.

Machine-written records dominate, and they are accurate in the narrow sense that they report what a handset reported. What ages is the human part: an address in a support thread, a device description in a bug report, something that was true in March and is wrong by August.

Those are not periodically re-verified, because re-verification means writing to people whose business with us closed long ago, purely to ask whether an old address still works, which is intrusion wearing the costume of diligence. The remedy is the correction right at 24, available at any time and free.

Where a record is used for a decision that matters to a person, it is checked at the point of use rather than trusted because it is on file.

20Security controls on a held record

Scope: the controls that protect a record while it is held, under APP 11.

In transit
HTTPS only, on the website and on every application endpoint
At rest
Platform encryption on stored records
Administrative access
Multi-factor on every account able to reach production records or a store console
Reader set
Need to know, reviewed whenever somebody joins or leaves
Environments
Split credentials, so a development key has no path to live records
Strongest control
Not collecting the field, which is why 05 and 08 are as short as they are

Perfect security is not a state a system arrives at, and a supplier implying otherwise is mistaken, or selling. The controls listed above are the ones in force at this revision, and this section changes when one of them does.

21Retention clocks and destruction

Scope: the life of each record, the event that starts its clock, and what destruction performs. APP 11.2 obliges destruction or de-identification once no permitted purpose remains, unless a law compels the record to be kept.

Retention schedule
RecordClockStarts atReason for that number
Crash and ANR reports90 daysReceiptLong enough to reproduce, fix and verify against the build that faulted
Device profile25 monthsLast contact from that installHardware generations turn over slowly. Two annual cycles is the shortest window that supports a comparison across device ages, and it is longer than everything else for that stated reason rather than by drift
Frame timing, thermal and power25 months, then irreversibly aggregatedLast contact from that installSame reason. After the clock expires only distributions remain, with nothing that points back at an install
Attribution, and the advertising ID13 monthsLast eventMatches the attribution window the platforms operate
Support correspondence24 monthsLast message in the threadEnough to recognise a problem that keeps coming back
Complaint correspondence7 yearsClosureTracks the limitation period Victoria applies generally, so the record outlives any right to sue on it
Purchase, tax and accounting7 yearsTransactionStatutory: Income Tax Assessment Act 1936 s 262A, Corporations Act 2001 s 286
Request logs from this websiteUnder 30 daysRequestThe hosting provider's rotation, not a period we set

What the words mean here

Destruction: the record leaves live systems, then ages out of the backup rotation, a process finishing inside 35 days. No backup is ever replayed to undo a deletion.

De-identification: strip every identifier, plus any field capable of reconstituting one. For a device profile that means discarding the install identifier and coarsening the model into a hardware class, so what remains describes a population and cannot be narrowed to a person.

22Device permissions, ATT, Data Safety

Scope: the permissions a title asks a device for, and what happens when one is refused.

Permissions a title requests
PermissionFunctionPromptedIf declinedWhere to revoke
InternetTelemetry upload, crash reports, advertisingGranted at install, not separately promptableNot applicableSystem settings, where network access for the app can be withdrawn
App Tracking Transparency (iOS)The Identifier for Advertisers, used for personalised advertisingYes, after our own setting is switched onAdvertising stays non-personalised and the title is otherwise unchangediOS Settings, under Privacy and Security, at Tracking
Advertising ID (Android 13+)Attribution, and capping how often an advertisement repeatsManifest declaration, never a promptDeleted in system settings, after which the app reads a zeroed valueSettings, Google, Ads
VibrationHaptic feedbackNoNo hapticsTitle settings

What performance work does not need

Frame timing, thermal state and charge level are all readable through ordinary platform interfaces that raise no prompt at all. No special permission is required for any of it, none is requested, and a build asking for one is either defective or somebody else's.

Store declarations

The Google Play Data Safety form and Apple's privacy labels are filled in from the tables at 05 and 21, so that the store answer and the answer here come from the same source. App Tracking Transparency is treated as a genuine choice rather than a formality: if the prompt is declined, no advertising identifier is read and no fallback identifier is substituted for it.

23Delete your data

Scope: the switch that prevents collection, and the request that removes what was already collected.

The switch comes first

Frame timing, thermal and power telemetry can be turned off inside a title's settings, and the game runs identically without it. That switch is the strongest control on this page, it takes effect immediately, and it needs no request to us and no reply from us.

Two routes to delete your data

  • In a title: Settings, then Data, then Delete my data. One confirmation queues the request.
  • By email: subject line "Delete my data", sent to [email protected], quoting the support identifier shown on the settings screen inside the title so the record can be located.
Effect of a deletion request, by record
RecordEffectWhy
Device profile and telemetry carrying your install keyDeleted or irreversibly aggregated within 30 daysDistributions survive, and nothing in them leads back to an install
Crash and ANR reportsDropped on their 90 day cycleShort lived to begin with, and detached from the install key on request
Advertising identifier recordsDeleted within 30 daysNothing downstream of them needs to persist
Purchase and tax recordsKept for 7 yearsStatutory, per 21. These cannot be deleted, and saying so is better than deleting and hoping nobody audits it
Complaint correspondenceKept for 7 yearsIt is the evidence of how a complaint was handled, including for you
BackupsOverwritten by the ordinary rotation inside 35 daysA deleted record is never restored from backup

Completion is confirmed in writing. A record is not flagged as deleted and quietly retained, which is the usual implementation and is not the one used here.

24Access and correction

Scope: seeing what is held about you, and fixing it. APP 12 carries the access right, APP 13 the correction right.

Route
Email with "Privacy request" as the subject
Clock
30 days from receipt
Cost
Nothing, for either right
Identity documents
Not requested and not accepted
Refusal
Written reasons, the ground relied on, and the complaint route

What to include

Describe what you are after, with enough detail for it to be found. A record keyed to a device rather than an account needs the in-app support identifier from the settings screen, or else the advertising identifier. With neither of them, nothing joins a record to the person writing.

Verification

Before anything is handed over, reasonable satisfaction is needed that the request comes from the person a record describes, or from their authorised representative. An account-linked request verifies through the address on that account. A request resting on a device identifier verifies possession of the identifier and nothing beyond it, and the answer will say exactly that instead of dressing it up as a stronger check.

Timing, and what happens inside it

The 30 day window is the whole process, verification included, not 30 days measured from the moment verification finished. Where producing an export in an unusual form would cost real work, the charge is quoted before the work starts and will not be excessive; there is no charge for making the request, and none for a correction.

Grounds for refusing access

The Act lists them, and the list is shorter than its reputation: an unreasonable effect on another person's privacy, a frivolous or vexatious request, material bound up in existing or anticipated proceedings that discovery would not reach, and access that would itself be unlawful. A partial release, or a different route to the same need, is offered ahead of an outright refusal.

Correction

Wrong, stale, incomplete, irrelevant, misleading: each of those gets corrected. Where the record had gone to somebody else and you ask for that person to be told, reasonable steps follow, unless taking them is impracticable or unlawful.

A refused correction leaves a second right in your hands. Require a statement to sit with the record saying you consider it inaccurate, and reasonable steps then put that statement in front of whoever reads the record later. The Act buries this one, so it is repeated here.

25Age, capacity, young people

Scope: how age is handled, given that mobile games are the category where this question is asked most often and answered worst.

Nothing built here is directed at children or designed to appeal primarily to children, and where a store asks for a target audience declaration, a general audience is declared.

Capacity

No age of self-consent is fixed by the Act. OAIC guidance points to assessing capacity individually where that is practicable, and to presuming it from 15 upwards unless something signals otherwise. That presumption is the working rule here.

Measures in place now

  • No personal information is knowingly taken from a child under 15 unless a parent or guardian has consented to it.
  • A store signal identifying the user as a child marks the advertising request child directed, and personalised advertising is then not requested at all.
  • There is no chat, no player to player messaging, no social feature and no user generated content in anything built here, which removes the largest category of harm before it exists.

Children's Online Privacy Code

A code covering services children are likely to reach is provided for by the 2024 amendment Act named at 04, with the Information Commissioner drafting it. Compliance follows its registration and commencement. This document changes at that point, once the terms are known rather than guessed at.

Where a child's record has arrived here

Write to [email protected]. Deletion follows, without a demand that you evidence a legal relationship past whatever makes the request credible, and confirmation follows the deletion.

26Automated decisions

Scope: decisions made by software about a person, and the disclosure the amended Act will require from 10 December 2026.

From 10 December 2026 the amendments made by the Privacy and Other Legislation Amendment Act 2024 oblige a privacy policy to name the categories of personal information driving a substantially automated decision that significantly affects somebody's rights or interests, and to name which decisions get made that way. The disclosure below is published early rather than on the commencement date.

Nothing here makes a decision of that weight. No process decides access to credit, to employment, to a service, to a benefit or to a legal entitlement. Two automated paths exist, and neither one clears the threshold.

  • Abuse and cheat detection. Automated signals can bar an install, or an account, from a leaderboard. Restrictions landing on an account, as opposed to one score, get a human review whenever one is asked for, and asking is the whole procedure.
  • Advertising selection. Which advertisement appears is decided by the network's own system. It has no effect on access to a title or on anything already paid for.

Should that change, the description lands in this section, and it lands before the processing starts rather than after it.

27Breach procedure, and the NDB scheme

Scope: what happens between the moment something goes wrong and the moment you hear about it.

Part IIIC of the Privacy Act carries the Notifiable Data Breaches scheme. Its trigger is an eligible data breach: personal information reached without authority, released without authority, or lost, in circumstances where a reasonable person would expect serious harm to follow for someone the information describes, and where remedial action has failed to remove that expectation.

Breach runbook
StepActionClock
ContainCut the access path, revoke the credential, pull the component offline where that is the only thing that worksImmediately on becoming aware
AssessReasonable and expeditious assessment of whether an eligible data breach has occurredWithin 30 days of the grounds for suspicion arising, which is what section 26WH allows
RemediateWhere remediation removes the likelihood of serious harm, notification is not owed, and the reasoning gets written downInside the assessment window
NotifyStatement prepared for the Commissioner, then notice to affected individualsAs soon as practicable after the assessment concludes

Where a notification goes

Regulator
Office of the Australian Information Commissioner
Post
GPO Box 5218, Sydney NSW 2001
Telephone
1300 363 992
If individual notice is impracticable
The statement goes up on this website, with reasonable steps taken to publicise it

What a notice will say

Identity and contact details for us, an account of the incident, which categories of information it touched, and the steps worth taking in response. Gaps get stated as gaps: an early notice that is honest has them, and packing them with reassurance is how a notice stops being worth reading.

Reporting one to us

Write to [email protected] with "Security" in the subject. A false alarm costs less than a missed incident. Reports made in good faith draw a technical answer, never a legal one.

28The statutory tort

Scope: a right you have against us that does not depend on the complaints process at 30.

Since 10 June 2025 the statutory tort for serious invasions of privacy has been available, created by Schedule 2 of the Privacy and Other Legislation Amendment Act 2024. Two forms exist: intrusion upon seclusion, and misuse of information. Three elements are wanted: intent or recklessness; a reasonable expectation of privacy held by someone standing where the plaintiff stands; and seriousness.

It reaches any defendant, this one included, and it does not wait on a complaint having been made to us or to the Commissioner. Most policies leave it out. An unknown right is a weak one.

29Storage on this website

Scope: what is written to your device by this site, summarised. The full inventory is at the cookie notice.

Nothing our own code ships writes a cookie, a local storage entry, a session storage entry or a database. The host may write two strictly necessary cookies, both aimed at telling a human request from an automated one, and both appear with their lifetimes on that page.

No consent banner runs, because no storage here is of the kind consent exists for. Nor does this country operate a separate cookie consent regime; the Privacy Act governs storage, on the terms the cookie notice sets out.

30Complaints, and the route to the OAIC

Scope: what to do when the answer you got was wrong, slow, or evasive.

Step one, to us

Route
Email with "Privacy complaint" as the subject
Contents
What happened, and the outcome you want
Acknowledgement
Within 5 business days
Answer on the substance
Within 30 days
If it will take longer
You are told why, and given a date

Step two, to the Commissioner

Where our answer fails to settle it, or 30 days go by without one arriving, the matter can be taken to the Office of the Australian Information Commissioner.

Post
GPO Box 5218, Sydney NSW 2001
Telephone
1300 363 992
Cost
Free, and no legal representation is needed
Our consent
Not required, and not something we could withhold

The Commissioner ordinarily expects an organisation to have had its turn, which is the purpose of the step above, while keeping the discretion to take a complaint that skipped it.

What will not happen

No non-disclosure agreement will be required as the price of a privacy complaint being handled, and lodging one is not treated as a breach of the terms of use.

31Requests from outside Australia

Scope: rights that come from somewhere other than the Privacy Act.

Australian law binds this company, so Australian law is what this document answers to. A right of yours going unmentioned here is not a right being refused.

European Economic Area and United Kingdom

Processing of ours falling under the EU General Data Protection Regulation, or under the UK GDPR, carries the usual set: objection, portability, restriction, erasure, rectification, access, and a complaint lodged with your national supervisory authority. An objection to processing grounded on legitimate interests ends that processing, absent compelling grounds overriding yours. Consent, where it is the ground, can be pulled at any point, and what was done before it was pulled stays lawful. One month is the answering period.

California

The California Consumer Privacy Act, as amended, supplies a right to opt out of a sale or a sharing, alongside rights to know, to correct and to delete. Nothing here is sold. Nothing is shared for cross context behavioural advertising within that Act's definition, since personalisation stays off until a person switches it on. A Global Privacy Control signal arriving at this site is read as an opt out.

Anywhere else

Cite the law you are invoking, so the correct clock gets applied. A request backed by a right that exists where you live is answered on its merits, not on whether it technically binds us.

32Revision control

Scope: how this document changes, and how you find out that it did.

Current revision
Version 1.0, effective 10 August 2026
Earlier revisions
None. This is the first version in force
Where the version lives
The line under the heading at the top of this page
Notice for a material change
At least 30 days, on this page and in any title on next launch
Retrospective effect
None. A material change applies from its effective date forward

A material change means one that cuts a right or widens what is collected. A correction to a typographical error, a clearer sentence or a renumbered cross-reference is not one, and dressing it up as one would only teach people to ignore the notices.

Superseded revisions are kept, though none is published as a page of its own. Ask what this document held on a given date and that revision comes back to you.

A structured operating document, then, and not legal advice. It replaces nothing an Australian legal practitioner would tell you about your own position.

33Contact register

Scope: one address, several subject lines, and the clock attached to each.

Privacy matters, subject lines and clocks
Subject lineMatterClock
Privacy requestAccess to the records held about you, under APP 1230 days
Privacy requestCorrection of a record, under APP 1330 days
Delete my dataRemoval of the records tied to one install30 days
Privacy complaintThe handling of a privacy matterAcknowledged inside 5 business days, answered inside 30 days
SecurityA suspected incident, or a breachSame or next business day
PrivacyAnything else raised by this document5 business days
Entity
IOPEX TECHNOLOGIES PTY LTD, ACN 696 561 609, ABN 54 696 561 609
Jurisdiction
Victoria, Australia
Service of documents
ASIC's record of the registered office for ACN 696 561 609, which is the address carrying legal effect
Going straight to the regulator
Office of the Australian Information Commissioner, GPO Box 5218, Sydney NSW 2001, 1300 363 992, oaic.gov.au

No postal address appears anywhere on this site. An address without legal effect for service adds a line of text and nothing else.