1. Scope
This Privacy Policy describes how Lazy Lion Studios PTE. LIMITED (“Lazy Lion Studios,” “we,” “us,” or “our”) handles information when you use the MyStats iOS application. It covers information handled by the app and by the service providers used to operate scanning, subscriptions, security, and advertising.
This policy does not cover the privacy practices of the Apple App Store itself. Apple processes App Store downloads, payments, and related account activity under Apple’s own policies.
2. Data summary
The following table summarizes information that may leave your device. Collection varies by the features you use, whether you have Pro, your region, and your privacy choices.
| Information | Why it is processed | Recipient |
|---|---|---|
| Selected screenshot and gamertag | Extract a game stat line after you consent | Firebase / Google Cloud and OpenAI |
| Anonymous app user ID and security signals | Authentication, App Check, abuse prevention, and scan limits | Firebase / Google Cloud |
| Purchase history and entitlement status | Recognize Pro access and restore purchases | Apple and RevenueCat |
| Approximate area from IP, device/ad identifiers, ad activity, and diagnostics | Serve, measure, secure, and improve ads for non-Pro users | Google Mobile Ads and User Messaging Platform |
| Function metadata, IP address, and technical diagnostics | Operate, protect, troubleshoot, and monitor the service | Firebase / Google Cloud and relevant service providers |
3. Data kept on your device
MyStats stores your builds, game statistics, preferences, consent status, and saved gamertag locally on your device. This information is used to provide the app’s core tracking and comparison features.
You can delete individual builds and games inside the app. Removing the app from your device also removes locally stored app data, subject to the normal behavior of your device backups and Apple services.
4. AI screenshot scanning
Consent and transmission
Before the first AI scan, MyStats asks for your permission. If you choose Allow & Scan, MyStats sends the screenshot you selected and the gamertag you entered to OpenAI through MyStats’ secure Firebase server. MyStats does not send the screenshot or gamertag for AI processing before you consent.
Purpose
The information is used to locate the gamertag in the screenshot and extract the corresponding game statistics. The extracted values are returned to the app so you can review and save them.
Storage and provider retention
MyStats processes the screenshot and gamertag in server memory and does not intentionally write either item to Firestore or Firebase Cloud Storage. The request to OpenAI sets response storage to false.
OpenAI documents that API content may still be included in abuse- monitoring logs retained for up to 30 days unless different account controls apply or longer retention is required for legal or safety reasons. OpenAI also states that image inputs flagged by its safety systems may be retained for manual review. See OpenAI’s API data controls.
Revoking consent prevents future AI scans until you consent again. It cannot recall a scan request that has already been processed.
5. Firebase and service security
MyStats uses Firebase and Google Cloud for:
- Anonymous authentication;
- App Check and Apple App Attest verification;
- Secure Cloud Function invocation;
- Scan quotas and abuse prevention; and
- Operational logging and service reliability.
Firebase assigns an anonymous app user ID. “Anonymous” means the app does not ask Firebase for your name, email address, or password, but the identifier can still distinguish the same app account or installation. Firebase and Google Cloud may also process app-attestation objects, request metadata, device or SDK information, and the caller’s IP address.
MyStats stores quota records containing protected or hashed identifiers and expiration timestamps to enforce scan limits. Application logging is designed not to include screenshot contents, base64 image data, gamertags, extracted OCR text, or OpenAI response bodies.
The production Cloud Logging bucket used for operational and security logs is configured with a seven-day retention period. Those logs are designed to contain request IDs, error classes, timing, and service metadata—not screenshots or gamertags.
Learn more from Firebase Privacy and Security.
6. Subscriptions
MyStats uses RevenueCat to recognize Pro subscriptions, validate entitlements, and support Restore Purchases. RevenueCat receives an anonymous app user ID, transaction or receipt information, purchase history, and subscription entitlement status.
MyStats uses the Firebase anonymous user ID as the RevenueCat app user ID. MyStats does not provide RevenueCat with your name or email address through this integration. Apple processes payment information; MyStats and RevenueCat do not receive your full payment-card details from the app.
Learn more in RevenueCat’s Privacy Policy and Apple’s App Store privacy information.
7. Advertising
Non-Pro users may see banner advertisements supplied by Google Mobile Ads. Pro users are not shown these banner ads. MyStats uses Google’s User Messaging Platform to obtain and respect applicable advertising privacy choices before requesting ads.
MyStats marks every ad request as non-personalized. Before Google Mobile Ads starts for a non-Pro user, MyStats may show Apple’s App Tracking Transparency prompt. If you decline, iOS withholds the advertising identifier and MyStats disables Google’s publisher first-party identifier. Core features and non-personalized ads remain available whether you allow or decline the request.
Depending on your region, settings, and consent choices, Google may process your IP address and infer a broad geographic area, as well as process device or advertising identifiers, ads you have seen, product interactions, crash information, performance information, and other diagnostics for advertising, measurement, analytics, fraud prevention, and service operation.
MyStats does not request GPS coordinates or precise location for advertising. A broad area inferred from an IP address is considered “coarse location” under Apple’s privacy categories. MyStats does not attempt to bypass Apple’s device privacy or tracking settings.
Where required, you can revisit Google advertising choices under Settings → Privacy & AI → Advertising Privacy Options. Learn more in Google’s Privacy Policy.
9. Retention and deletion
- On-device data: kept until you delete it in the app, remove the app, or your device’s normal backup lifecycle removes it.
- AI scan inputs: not intentionally stored by MyStats in Firestore or Cloud Storage. OpenAI’s documented default abuse- monitoring retention may be up to 30 days, with safety and legal exceptions.
- Quota records: Firestore scan-count records contain a hashed anonymous identifier, counters, and timestamps—not the screenshot or gamertag. They are configured to expire eight days after the most recent write. Firestore’s TTL process generally deletes expired documents within approximately 24 hours after that expiration time.
- Operational and security logs: the production Cloud Logging bucket is configured with a seven-day retention period. The application is designed not to log screenshot contents, base64 image data, gamertags, extracted OCR text, or provider response bodies.
- Subscription records: retained by Apple and RevenueCat as needed to validate purchases, maintain transaction history, prevent fraud, and meet legal obligations.
- Advertising and diagnostics: retained by Google according to Google’s policies, applicable consent choices, and legal requirements.
10. Your choices
- Choose Not Now when asked for AI-processing consent; no AI scan is sent.
- Review or revoke future AI-processing consent under Settings → Privacy & AI.
- Delete locally stored builds and games inside MyStats.
- Review Google advertising privacy options in the app when that entry is required for your region.
- Manage your subscription through your Apple ID subscription settings and use Restore Purchases inside MyStats.
- Contact us to ask a privacy question or request deletion of data that MyStats can reasonably identify and control.
11. Security
MyStats uses measures intended to protect information in transit and reduce unauthorized service use, including HTTPS, server-side API credentials, Firebase Authentication, App Check, Apple App Attest, restricted database access, rate limits, and minimized application logging. No security method is perfect, and we cannot guarantee that unauthorized access will never occur.
12. Children’s privacy
MyStats is not directed to children below the minimum age required to consent to data processing in their jurisdiction. We do not knowingly request a child’s name, email address, or other contact information. If you believe a child has provided information through MyStats without appropriate permission, contact us so we can review the request.
13. International processing
The service providers identified in this policy may process information in the United States and other countries. Privacy protections and legal requirements may differ from those in your location. Those providers are responsible for the transfer mechanisms and safeguards applicable to their processing.
14. Changes to this policy
We may update this Privacy Policy when MyStats features, providers, or legal obligations change. We will update the effective date and policy version on this page. If a change requires renewed AI-processing consent, the app will ask again before sending a future scan.
15. Contact
Contact us with privacy questions or requests. Please do not send screenshots, payment details, passwords, or API credentials by email.
Lazy Lion Studios PTE. LIMITED
MyStats Privacy
Email:
support@lazylionstudios.sg