Gazuacup logo Gazuacup

TanoChat Privacy Policy

Effective date: 2026-10-04

This privacy policy applies to the TanoChat app for mobile devices, together with any related services operated by Isu (Google Play: Gazuacup) (collectively, the "Application"). Isu (Google Play: Gazuacup) is hereby referred to as the "Service Provider".

Information Collection and Use

The Application collects information when you download, access, and use it. Depending on the features you use and the permissions you grant, this information may include information such as:

  • Your device's Internet Protocol address
  • The screens of the Application that you visit, the time and date of your visit, and the time spent on those screens
  • Application interactions, session information, and feature usage events
  • The time spent on the Application
  • Your mobile operating system, device model, Application version, language, and country or region
  • App-instance IDs, Firebase installation IDs, advertising identifiers, and similar device or Application identifiers, where available and permitted
  • Crash reports, crash stack traces, diagnostic information, and technical performance data
  • Purchase information, product identifiers, transaction identifiers, and purchase status

Google Analytics for Firebase may collect Application usage events, app-instance identifiers, approximate geolocation derived from masked IP addresses, device information, and in-app purchase events. Firebase Crashlytics may collect crash traces, installation identifiers, device and operating-system information, and related diagnostic data.

Cookies and tracking technologies

The Application or its third-party SDKs may use SDK-based identifiers, local storage, cookies where applicable, and similar technologies to support functionality, analytics, crash diagnostics, advertising, and service delivery.

Where required by applicable law, the Service Provider will obtain consent before using non-essential tracking technologies. Advertising consent is managed before advertising requests are made in regions where consent is required. On iOS, advertising requests are also subject to the applicable App Tracking Transparency setting.

Location Information

The Application does not require or continuously track your precise device location.

You may choose to provide location information as an optional profile field. If provided:

  • Exact location information is not displayed to other users.
  • It may be used only as a secondary matching factor when waiting times are otherwise similar.
  • A city that you separately choose to provide may be displayed as part of your public profile.
  • The information may be processed by the Service Provider's infrastructure providers as necessary to store and operate the feature.

Separately, Google Analytics for Firebase may derive approximate geographic information from masked IP addresses for analytics purposes. This is distinct from the optional location information you provide to the Application.

Your Rights

You may request access to, correction of, or deletion of your personal data held by the Service Provider. You may also request account deletion through the Application where that feature is available.

To exercise these rights, or to withdraw consent where processing is based on consent, contact the Service Provider at playkorkis@gmail.com.

Your California privacy rights (CCPA/CPRA)

If you are a California resident, you may have the right to know what personal information is collected, request correction or deletion of personal information, opt out of the sale or sharing of personal information where applicable, and receive non-discriminatory treatment for exercising these rights.

To exercise your CCPA/CPRA rights, contact the Service Provider at playkorkis@gmail.com.

Artificial Intelligence

The Application uses Artificial Intelligence ("AI") technologies for limited service and safety purposes.

AI processing may include:

  • Processing proposal-time public profile snapshots to create a short group introduction, group title, shared interests, or light conversation topics
  • Processing group-room content where necessary for group introduction, progression, conversation support, and safety
  • Checking nicknames and uploaded images for potentially harmful or prohibited content
  • Classifying and summarizing reports and limited supporting evidence for review by the Service Provider's administrators

The Application does not use AI to select or re-rank group matching candidates. Matching candidates are selected using predetermined service rules.

AI must not infer sensitive characteristics, personality, compatibility, popularity, or romantic suitability from profile information. AI-generated moderation recommendations do not automatically suspend or permanently restrict an account; administrative decisions are reviewed by a human operator.

One-to-one friend messages are not used for AI conversation analysis. Safety filters may nevertheless be applied to both group and one-to-one content. In particular, uploaded images may be processed by an external AI moderation provider before they are made visible to other users.

The Application uses OpenAI as an external AI processor. Data submitted through the OpenAI API is not used to train OpenAI models by default unless the Service Provider separately opts in. Depending on the API endpoint and configured data controls, API inputs and outputs may be retained for abuse monitoring for up to 30 days, unless a different retention control or legal obligation applies. See the OpenAI API data controls.

The specific AI processing scope, external processor, and retention practices are described in this privacy policy. The Application does not present a separate AI-consent prompt for the group features described above.

The Service Provider may use the information you provide to send important service information and required notices, including group proposals, group formation notices, friend requests or acceptances, and approved message notifications, according to your notification settings. The Service Provider does not use this information to send marketing communications unless separate notice and any legally required consent are provided.

For a better experience while using the Application, the Service Provider may require or allow you to provide personally identifiable or account-related information, including but not limited to:

  • Email address and authentication information
  • Firebase user ID
  • Nickname
  • Birth year and gender
  • Introduction
  • Optional current activity or occupation description
  • Language and country or region
  • Optional city and location
  • Profile avatar or uploaded profile image
  • Notification settings
  • Group-search, proposal, session, and game participation information
  • Game answers and reactions
  • Friend requests, friendship, blocking, and conversation information
  • Text messages and uploaded images
  • Reports, report details, and limited related evidence
  • Purchase and participation-credit information

Your nickname, avatar, age group, introduction, optional current activity or occupation, optional city, account-creation month, and completed group-session count may be displayed to other users as part of your public profile.

Your exact birth year and exact location are not displayed to other users. Individual cooperative-quiz answers are not disclosed to other participants. For game types where individual selections are intentionally revealed as part of the game, the Application may display each participant's revealed selection after the answer period ends.

The information requested by the Service Provider will be retained and used as described in this privacy policy.

Third Party Access

The Application transmits personal, pseudonymous, and technical information—not only aggregated or anonymized information—to service providers where necessary to operate the Application.

Such processing may include:

  • Authentication, database, file storage, server functions, hosting, and push notifications
  • Application analytics and crash diagnostics
  • Advertising delivery, consent management, and advertising measurement
  • Purchase validation and entitlement management
  • AI-generated group introductions and content-safety processing

The Service Provider limits these disclosures to information reasonably necessary for the relevant service. Third-party service providers process information under their own privacy policies and applicable contractual terms.

International Data Transfers

The Service Provider or its third-party service providers may transfer personal data to countries outside your country of residence, including outside the European Economic Area ("EEA").

Where applicable law requires safeguards for international transfers, the Service Provider will use legally recognized transfer mechanisms, which may include:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions or other legally recognized transfer mechanisms
  • Your consent, where required and legally permitted

Data protection laws in other countries may differ from those in your jurisdiction. Where required by law, the Service Provider will apply appropriate safeguards and obtain any consent required for the transfer.

Please note that the Application utilizes third-party services that have their own privacy policies regarding the handling of data. These services may include:

  • Google Play Services and Google Privacy Policy
  • Firebase services
  • AdMob
  • Google Analytics for Firebase
  • Firebase Crashlytics
  • RevenueCat
  • OpenAI API services
  • Apple, when Apple authentication or Apple platform services are used

The Service Provider may disclose User Provided and Automatically Collected Information:

  • As required by law, such as to comply with a subpoena or similar legal process
  • When the Service Provider believes in good faith that disclosure is necessary to protect its rights, protect your safety or the safety of others, investigate fraud or abuse, or respond to a lawful government request
  • To trusted service providers that process information on behalf of the Service Provider and are subject to applicable confidentiality, security, and data-processing obligations

Opt-Out Rights

You can stop further collection of information from your mobile device by uninstalling the Application. Uninstalling stops the Application from collecting new information from that device, but it does not automatically delete information already transmitted to the Service Provider or third parties.

Where available, you may manage analytics, advertising, notification, and tracking choices through the Application, the consent interface, or your device settings. Restricting certain processing may affect related features.

To request account or personal-data deletion, you may use the account-deletion function in the Application or contact the Service Provider at playkorkis@gmail.com.

Data Retention Policy

The Service Provider retains personal data based on its necessity for the stated purposes:

  • Account and profile data: Retained while your account is active. Following an account-deletion request, the account is immediately excluded from matching, proposals, sessions, friend interactions, conversations, and message sending. Account and profile data is scheduled for cleanup after 60 days.
  • Conversation data: Messages and photos you sent remain visible to other participants after account deletion. Conversations, including their messages, photos, and game records, are deleted 60 days after all participants have left.
  • Report evidence: Deleted 60 days after the relevant case is closed, unless retention is legally required.
  • Moderation audit metadata: Metadata that does not contain message or report body content is deleted 60 days after a suspension ends or a warning is recorded.
  • Rejected input: Rejected message and profile text is deleted 60 days after rejection.
  • Firebase Crashlytics data: Crash traces, relevant minidump data, and associated identifiers are generally retained by Firebase Crashlytics for 90 days before the removal process begins, subject to Google's current provider policy.
  • Google Analytics data: Retained according to the retention settings configured for the applicable Google Analytics property and Google's provider policies.
  • OpenAI API data: May be retained for up to 30 days under default API data controls for abuse monitoring, depending on the endpoint used. Different controls may apply to eligible endpoints.
  • Purchase and transaction data: Retained as necessary to validate purchases, prevent duplicate grants or fraud, resolve disputes, and comply with accounting or legal obligations.
  • Aggregated and anonymized data: May be retained for longer periods where it no longer identifies or can reasonably be linked to you.
  • Data required for legal compliance: Retained for as long as required by applicable law.

A legal preservation order, fraud investigation, dispute, security requirement, or other legal obligation may require limited information to be retained beyond the periods above.

Data Deletion

You can request deletion of your account and personal data through the Application or by contacting the Service Provider at playkorkis@gmail.com.

When you confirm account deletion:

  1. Your account is immediately marked for deletion and disabled from using matching and communication features.
  2. The Application clears or schedules deletion of locally cached account data.
  3. Account and profile data, including the Firebase Authentication account, is scheduled for cleanup after 60 days.
  4. Report evidence, moderation audit metadata, transaction records, or information subject to a legal preservation obligation may be retained for the periods stated above.

The Service Provider may request reasonable information to verify your identity before processing an email-based access or deletion request.

Children

The Application is not intended for anyone under 18 years of age, or such higher age as may be required by applicable law. A user who does not meet the minimum-age requirement cannot complete the required profile or use the group-matching features.

The Service Provider does not knowingly solicit personal data from children or market the Application to them. If the Service Provider discovers that an underage person has provided personal information in violation of this policy or applicable law, the Service Provider will take appropriate steps to disable the account and delete the information, subject to applicable legal and safety-retention requirements.

If you are a parent or guardian and believe that a child has provided personal information to the Service Provider, please contact playkorkis@gmail.com.

Security

The Service Provider uses physical, electronic, and procedural safeguards designed to protect information processed and maintained through the Application.

Access to private profile information, private game answers, pending content, reports, safety records, and moderation records is restricted according to the relevant user, conversation membership, or administrator role. Uploaded profile and message images are isolated and are not made available to other users until the required safety review is completed.

No method of electronic transmission or storage is completely secure, and the Service Provider cannot guarantee absolute security.

Data Breach Notification

If a personal-data breach occurs, the Service Provider will investigate and provide notifications required by applicable law, including information about the nature of the breach and the steps being taken to address it where required.

Changes

The Service Provider may update this Privacy Policy from time to time. The Service Provider will notify you of material changes by posting the updated Privacy Policy with an effective date. Where required by law, the Service Provider will seek consent before a material change takes effect.

Previous versions of this Privacy Policy will be maintained and made available upon request by contacting the Service Provider at playkorkis@gmail.com.

This privacy policy is effective as of 2026-10-04.

Your Consent

Creating an account requires agreement to the Terms of Service and acknowledgment of this Privacy Policy through the Application's sign-up or social-authentication flow.

Where processing is separately based on consent, such as certain advertising or tracking activities, consent is obtained through the relevant affirmative choice. You may withdraw such consent at any time without affecting processing carried out before withdrawal.

Processing based on contract performance, legal obligations, safety, fraud prevention, or other lawful grounds may continue where permitted even if consent for an unrelated optional activity is withdrawn.

Contact Us

If you have any questions regarding privacy while using the Application, or questions about the Service Provider's practices, please contact:

playkorkis@gmail.com