Page 1 of 1

DarkShort — Privacy Policy

Effective date: December 15, 2025 Controller: Mobile Entertainment Srl, Via Molino delle Armi, 11 – 20123 Milano (MI), Italy — info@upji.me" target="_blank">info@upji.me" target="_blank">info@upji.me" target="_blank">info@upji.me If you do not agree with this Policy, please do not use DarkShort. 1. Audience & Age DarkShort is not intended for users under 16. We do not knowingly collect personal data from users under 16; if we learn this occurred, we will delete it. 2. What We Process (Aggregate-First) We apply data minimization and, where possible, use aggregated or de-identified data for analytics and performance. We do not build individual marketing profiles in the EEA/UK without the required consent. Device & technical. Device model, OS/app version, language, time zone, IP-derived general region (country/region). Usage & diagnostics. In-app interactions, session metadata, performance metrics, crash logs. Subscriptions (via RevenueCat). Non-card purchase metadata from Apple/Google (e.g., subscription status, product/offer, success/failure). We do not receive or store your card details. Paywalls & offers (via Superwall). Paywall impressions/clicks, selected A/B variant ID, start/cancel trial events, purchase attempts/outcomes, and basic technical context (app/OS version) to present paywalls, optimize offers, and measure conversion. Advertising/measurement (if shown). Advertising IDs (IDFA/GAID) only if permitted by OS settings and/or your consent (EEA/UK). Support. Information you send to info@upji.me (email, message content, attachments). DarkShort does not access your photos, camera, microphone, or contacts. 3. Purposes & Legal Bases (GDPR) Provide and operate DarkShort & subscriptions (including paywall presentation and offer experiments via Superwall): contract/legitimate interest; where required, consent. Analytics & performance (incl. Crashlytics): legitimate interest or consent where required. Advertising & attribution (if enabled): consent in EEA/UK; elsewhere, legitimate interest or OS permission, as applicable. Security & fraud prevention: legitimate interest. Legal compliance: legal obligation. 4. SDKs, Providers & Recipients RevenueCat — subscription validation and status. Superwall — paywall presentation, A/B testing, and conversion analytics related to paywalls/offers. Firebase Analytics / Crashlytics (Google) — analytics/diagnostics. Google Ads SDK / AdMob, AppLovin — advertising/mediation (if enabled). App stores (Apple/Google) — billing, anti-fraud, compliance. Depending on the service, these parties act as processors or independent controllers. We limit access to what is necessary and review providers periodically. 5. Consent, ATT & Your Choices EEA/UK. We request consent before using non-essential identifiers (e.g., IDFA/GAID) for ads/measurement. You can withdraw consent any time in-app (where available) or by contacting us. iOS ATT. If you tap “Don’t Allow”, we do not access the IDFA. OS controls. You can reset your advertising ID, limit ad tracking, or disable personalized ads in device settings. Paywall experiments. A/B tests of paywalls/offers via Superwall are used to deliver offers and measure conversion; where required, we run them with your consent. If you prefer not to participate, contact us and we will take reasonable steps to accommodate your request where technically feasible. 6. AI Training We do not use your viewing data or any personal data to train AI models (ours or third-party) without your explicit opt-in. 7. International Transfers Primary hosting is in the EU. Some providers (e.g., Superwall, RevenueCat) may process data outside the EEA/UK/CH (e.g., USA). In such cases we rely on Standard Contractual Clauses (SCCs) and apply appropriate safeguards. 8. Retention Analytics: 12–24 months (then aggregated/anonymized). Crash logs: ~12 months. Purchase/subscription records: per tax/accounting obligations (5–10 years). Support tickets: up to 24 months after resolution. You can request earlier deletion where applicable. 9. Security We implement appropriate technical and organizational measures (encryption in transit, access controls, least-privilege, monitoring, vendor review). No system is 100% secure; we will notify users and authorities when legally required. 10. Your Rights Depending on your location (e.g., GDPR/UK GDPR; CPRA), you may have the rights to access, rectify, delete/erase, restrict/object, data portability, withdraw consent, and lodge a complaint with your data-protection authority. Contact info@upji.me to exercise rights; we may need to verify your identity. 11. Websites & Cookies Our websites may use cookies/SDKs for essential functions, analytics, and (if present) advertising. In the EEA/UK, non-essential cookies/SDKs are used only with consent. You can manage choices via the site banner or your browser settings. 12. Changes We may update this Policy from time to time. If changes are material, we will notify you in-app or on our website. Continued use after the effective date means you accept the updated Policy. 13. Contact Mobile Entertainment Srl — Via Molino delle Armi, 11 – 20123 Milano (MI), Italy — info@upji.m