KRILLION

iOS & Android · Privacy

Privacy policy for the Krillion mobile apps

Last updated: 2026-10-09

Krillion's iOS and Android apps are operated by NOTHING AI, responsible for the personal data described here. For support or privacy requests, contact hello@krillion.to.

Publisher's country: France.

This policy covers the Krillion mobile apps and the online authentication, game and account services they use. The website privacy policy describes the website, including its browser storage, web sign-in, advertising and payment features. Those website features differ from the mobile features explained below.

Krillion is intended for players aged 13 and over. The age rating displayed by each app store is determined separately and may impose a higher age restriction. Follow the applicable store and account restrictions.

Your account

You can try a limited guest dive without creating an account. Account features and additional modes require sign-in. The app processes your email address, account identifier and authentication session to create or access your account, retrieve your available dives and recognise existing Krillion Premium access.

The app offers an email sign-in code and password sign-in for accounts that already have a password. Requesting and verifying an email code can create an account. Supabase handles authentication and the requested sign-in email flow. A sign-in message is sent to complete the account access you requested.

On Android, the app also offers “Continue with Google”, which uses the Google sign-in of Supabase Auth. It opens Google's sign-in page in a browser tab on your device; Google's screen can name Supabase's address as the site requesting access. If you choose a Google account and continue, Krillion receives from Google, through Supabase Auth, your Google account identifier, your email address and whether Google has verified it, your name and the address (URL) of your Google profile picture. Supabase Auth stores them in your Krillion account record. Krillion uses them to create your account and sign you in; signing in with Google can create an account. Your email address then becomes your account email and is used as described in this policy. The app does not display your name or profile picture; the Krillion website can show them in its account menu when you sign in there. Krillion does not receive your Google password and requests no Google data beyond your basic profile and email address. Google processes the data involved in your Google sign-in under Google's privacy policy. Signing out of Krillion does not sign you out of Google. Deleting your account in the app (Account → Delete my account) removes this information with your authentication account.

The mobile app stores its authentication session in the iOS Keychain or in encrypted Android storage protected by Android Keystore. Signing out removes the app's stored authentication credentials. It does not delete your account or server-side game history.

Gameplay and results

Playing requires an Internet connection. The app sends the selected language and mode, game and question identifiers, game-start identifiers and submitted answers to Krillion's online services. Authenticated requests also identify the signed-in account. These services provide questions, score answers, enforce allowances, prevent repeated game starts from using a second allowance and save account features.

When a signed-in dive is synchronised, Krillion stores its identifier, mode, game identifier, score, depth and completion time. This history feature uploads a summary rather than the complete round-by-round local dive log. Scoring and shared-game services separately process answers.

The app also sends identifiers of previously seen and recent pack games when requesting a selection. Together with available account history, these help select a dive and reduce repeated questions.

Recognised answers from a signed-in Daily Dive can appear on the following day's public leaderboard under a generated diver alias. Published answers use recognised catalogue forms; the leaderboard does not display your email address or the raw text you typed.

Private Battle, Challenge Link and Crew Dive services process participant identifiers, game context, timing and results. Their shared services can also process a nickname previously set through the website. In the iOS app, participant lists, rankings and round results show generated numbered diver labels instead of profile nicknames. The Android app and website can show the website-set nickname. Participants can see scores and recognised publisher-catalogue answers according to the mode's reveal rules. The native mobile app has no nickname editor, general text chat, voice chat or photo/video upload.

Answer statistics and network information

The scoring service measures answers to improve the catalogue and understand answer frequency. It can retain filtered, normalised forms of unrecognised answers and counts of recognised catalogue answers. Recognised-answer counts use a keyed player fingerprint to count distinct players. In the native scoring path without a browser authentication cookie, this fingerprint is derived from the network-address fingerprint. This is server-side measurement even though the mobile app does not contain a general-purpose analytics SDK.

Hosting, delivery and authentication services receive the IP address and request information needed to provide online services. Krillion's game logic computes a keyed network-address fingerprint for allowances, abuse prevention and answer measurement. Game starts also use account and request identifiers. Hashing and pseudonyms reduce direct exposure of identifiers; they do not mean that no data is collected or that every related record is anonymous.

Recent versions of the app also create a random installation identifier the first time they run and keep it on the device. The app sends it with its requests to Krillion's online services. Krillion's servers do not keep the identifier itself, only a keyed fingerprint derived from it. This fingerprint is used to count the free guest dive per installation rather than per network address, to keep a guest dive valid when the device changes network (for example from Wi-Fi to mobile data), and to help prevent abuse. Game-start receipts and daily counters store it as described under Retention and deletion, and an in-memory abuse counter keeps a value derived from it until the end of the day (UTC). Daily counters keyed by this fingerprint are also included in Krillion's internal aggregate audience, retention, conversion and daily activity statistics, where each installation that played a guest dive counts as one anonymous visitor, including on the later days it returns. These statistics are for Krillion's own use: the fingerprint is not sold, not shared with third parties for their own purposes and not used for advertising. It is not an advertising identifier and is not derived from hardware identifiers. Uninstalling the app or clearing its data erases the identifier; the app then creates a new one.

Preferences, reminders and sharing

Language, sound and haptic preferences, reminder settings and the local dive log are stored on your device. Your selected language is also transmitted when requesting and scoring game content. Some account summaries are separately synchronised as described above.

Daily reminders are optional local notifications. If you enable them, the app requests notification permission and schedules a reminder for 7 pm in the device's local time. This feature does not register a remote push token. You can disable it in the app or manage notification permission in device settings.

Sharing a result or a room invitation opens the device's share controls at your request. You choose the destination. The app does not automatically send invitations to your contacts or read your address book.

Premium access, store purchases and restoration

The mobile apps recognise existing Krillion Premium entitlement. The account service can associate an existing purchase with your verified account and process access and purchase records. The iOS edition supports an optional one-time lifetime Premium purchase through Apple StoreKit when the product and service are available. It does not create an automatically renewing Apple subscription. The App Store price and any purchase restrictions are displayed before you confirm. Older Android versions recognise existing access without offering a native checkout.

Apple-billed purchases are subject to Apple's purchase terms and Standard EULA. The website's Stripe prices, subscription cancellation and website refund clauses concern website purchases, not Apple-billed purchases. Apple handles refund requests under its terms and applicable consumer protections; Apple explains how to request a refund. Deleting the Krillion account does not automatically refund an Apple purchase.

Before opening the Apple purchase or restoration flow, Krillion checks your signed-in account and confirmed email through its authentication service. Its server prepares a licence binding containing the original Krillion account identifier and a private keyed fingerprint of the confirmed email. This preparation does not charge you or grant Premium. It preserves the link needed to process an interrupted or pending purchase and to restore a legitimate lifetime licence if the original account is later deleted.

Licence preparation can remain even if you cancel the Apple payment sheet or do not complete a purchase. A preparation record is not proof that you bought Premium.

When an Apple purchase is requested, Apple receives an app-account token containing your Krillion account UUID, together with information handled by the App Store to complete the transaction. Apple handles its payment and Apple Account flow. StoreKit does not send your payment-card details to Krillion. Apple's services process data under Apple's privacy policy.

Krillion receives and verifies Apple's signed transaction information and server notifications to deliver, restore or revoke access. Its licence records include the product identifier, transaction and original transaction identifiers, original app-account token, associated Krillion account identifier, production or testing environment, purchase and signature dates, entitlement state, relevant refund or revocation information and record dates. Notification records include the notification identifier, type, environment and receipt date. The licence ledger does not store the full signed transaction payload or your payment-card details.

The private email fingerprint is calculated using a server-held secret and the email confirmed by our authentication service. The licence binding stores this fingerprint rather than a plaintext copy of your email; the authentication service still processes your account email as described above. The fingerprint and account identifiers are personal data used for licence ownership, purchase security and recovery, not a claim that these records are anonymous. A current verified owner can update the binding when their verified account email changes.

Apple lifetime restoration is an explicit action: sign in to Krillion and choose Account → My Premium access → Restore Apple purchases. Use the Apple Account that made the purchase. After deleting and recreating a Krillion account, use the same verified email previously bound to the licence. Recovery requires a verified Apple transaction, a matching server licence binding and an eligible deleted-owner record. A licence assigned to another existing Krillion account cannot be moved by simply supplying an email or purchase identifier. Restoring does not recreate deleted game history and does not reverse an Apple refund or revocation. Contact hello@krillion.to if you cannot access the original email or if the purchase cannot be verified.

Google Play annual subscriptions

Android versions supporting Google Play billing offer optional annual Premium access when the product and service are available. The price and currency are supplied by Google Play and shown before confirmation. An eligible Google Play account may receive a 7-day free trial. After that trial, the full annual price is charged in one payment, and the subscription renews yearly until cancelled. Trial eligibility is determined by Google Play; creating a new Krillion account does not itself grant a trial.

Use Account → My Premium access to open Google Play subscription management, or follow Google's cancellation instructions. Cancel before the free trial ends to avoid its annual charge. Signing out, uninstalling Krillion or deleting the Krillion account does not cancel a Google Play subscription. Google Play refund rules and applicable consumer protections govern refund requests; see Google Play's refund information. Website Stripe cancellation and prices concern website purchases.

Before Google Play purchase verification or restoration, Krillion checks your signed-in account and confirmed email. Its server prepares a binding with the original Krillion account identifier and a private keyed fingerprint of the confirmed email. The app supplies Google Play with an opaque, keyed account identifier to associate a purchase with the correct Krillion account. This identifier and the retained bindings are personal data; they are not anonymous. Preparation does not charge you or grant Premium, and a preparation binding can remain even if you cancel or do not complete a purchase.

Google handles its Google Account and payment flow. Krillion does not receive payment-card details from Play Billing. Google processes data under Google's privacy policy. Krillion receives a purchase token from the app and verifies the subscription with Google's server before relying on it for Premium access. Server notifications and further verification keep the subscription state current.

The Google billing ledger retains an encrypted purchase token, its private association with the original and current Krillion account, a private keyed fingerprint of the verified email, purchase and product identifiers, plan, relevant dates, subscription and renewal state, trial/testing status, acknowledgement and verification records, and links between replaced purchases. Notification records retain a message identifier, relevant purchase-token fingerprint and receipt date. These records support purchase ownership, pending purchases, restoration, renewals, refunds, expiry and billing security. Raw purchase tokens and plaintext emails are not kept in this billing ledger; the authentication service separately holds the account email. These records have no automatic fixed expiry in the current billing flow. Their encrypted or keyed form does not make them anonymous.

Restoration is an explicit action: sign in to Krillion and choose Account → My Premium access → Restore Google Play purchases, using the Google Account that made the purchase. If the original Krillion account was deleted, an eligible purchase can be recovered to a recreated account with the same verified email previously bound to it, after Google verification and server ownership checks. A purchase belonging to another existing Krillion account cannot be transferred this way. Restoration does not recover deleted game history or undo a refund, revocation or expired access. Contact hello@krillion.to if verification or email access is interrupted.

Providers, announcements and external pages

Supabase provides authentication and database services. Krillion's server provides game, account and licence verification services, with Cloudflare delivering and protecting online requests. Apple provides iOS in-app purchase and restoration services. Google provides Android billing, subscription management and purchase verification services, and the optional Google sign-in on Android. Resend delivers game announcements. Stripe processes existing website purchases and subscriptions. These services receive the information needed for those tasks. If you contact support, we use your email address and the information you include to handle your request.

Confirmed Krillion accounts can receive announcements about the game and its offers. We use account email addresses, language, account creation dates and send records to deliver these messages through Resend. Each announcement provides an unsubscribe link. A minimal refusal record is retained to respect your choice and avoid sending further announcements. Requested sign-in messages and payment receipts are separate from announcements.

The mobile bundle contains no native advertising SDK. Help, Privacy and Terms open Krillion's website through the platform browser interface. The website policy describes its separate advertising and browser-data processing. The app has no feature requesting access to the camera, microphone, contacts or precise device location.

Security

The app's Krillion and Supabase service requests use HTTPS. Android cleartext network traffic is disabled. Native authentication sessions use the protected storage described above. These measures protect transport and stored sessions; they are not a claim of independent security certification.

Retention and deletion

We keep account details and synchronised history while the account exists, subject to account deletion. Daily leaderboard cleanup removes entries older than 90 days in batches during game processing. The statistics cleanup process removes recognised-answer fingerprints older than 90 days and unrecognised answer forms seen only once that have not been seen for 90 days. Statistics remain until that cleanup runs. Normalised unrecognised forms seen repeatedly can be retained without a fixed expiry as a catalogue-improvement worklist.

Battle cleanup removes completed rooms after seven days and abandoned rooms after three hours of inactivity, in batches as room processing triggers cleanup. Challenge and Crew links expire after seven days; their records are removed at a later game creation or maintenance step. Expiry of a link and deletion of its records can therefore happen at different times. Daily counters use date-specific keys and can remain stored after the day has passed. Game-start receipts expire after one hour and are eligible for cleanup after a further seven days. Hosting, authentication, email and billing services may also hold records needed to deliver their services and meet applicable obligations.

To request account deletion in the app, sign in, open Account → Delete my account, type your account email address and confirm. You can also request account deletion without reinstalling the app by following the instructions at krillion.to/mobile-delete-account. Verification and confirmation protect against someone else deleting your account. You can contact hello@krillion.to for help with access or a privacy request.

Deleting an account removes identified account analytics, the authentication account and linked game data. Confirming deletion and cancellation also cancels existing Krillion website Stripe subscriptions. Deleting your Krillion account does not automatically refund an Apple lifetime purchase. This iOS purchase is a one-time non-consumable, not an Apple subscription. Google Play subscriptions require separate cancellation as explained above.

Limited purchase, subscription and invoice records can remain where needed for billing, fraud prevention, valid licence ownership, restoration, refunds, disputes or applicable legal obligations. Apple licence preparation and purchase records retain the original app-account token, relevant transaction and account identifiers, private keyed email fingerprint, dates and status information after the live account link is removed. These records are kept separately from deleted game history so an interrupted or pending purchase can still be verified and an eligible deleted-account licence can be restored. The current licence flow has no automatic fixed expiry for these records; retention depends on the continuing licence/recovery purpose and applicable obligations. You can contact hello@krillion.to about these retained records and an applicable privacy request. This statement does not claim every retained record has a mandatory statutory retention period.

A retained announcement refusal record is used to respect an earlier unsubscribe request. Network-derived answer measurements are not directly attached to the account and can remain until statistics cleanup. Repeated normalised unrecognised answer forms can remain in the catalogue-improvement worklist as explained above.

Deleting a Krillion account does not cancel a Google Play subscription. The app explains this and lets you acknowledge that the subscription continues before deleting the account. You can manage or cancel it in Google Play independently. Google billing identity and purchase records can remain after the account link is removed, including a preparation binding created before an incomplete purchase, so subscription updates, ownership and eligible deleted-owner recovery can be handled. These records do not restore deleted game history and currently have no automatic fixed retention period. Contact hello@krillion.to about retained records and applicable privacy requests.

To remove only the local log, choose Account → Clear local dive log. That does not delete the account or records already synchronised to it. Local preferences and logs otherwise remain until you clear them or remove the app's data.

For access, correction, deletion or other privacy requests, write to hello@krillion.to and identify the account concerned. Applicable rights and limitations depend on your location and the processing involved.