Privacy
Privacy policy
Written as a runbook rather than an essay. Each record gets a scope line, a field list, a storage location, a retention clock and a named reader, in that order, because those are the five things a person actually needs from a document like this.
In force 10 August 2026Revision 1.0Privacy Act 1988 (Cth)
01Entity, coverage, name collision
Scope: every record about an identifiable person that this company captures, receives or stores, on any surface it runs.
- Entity
- IOPEX TECHNOLOGIES PTY LTD
- ACN
- 696 561 609
- ABN
- 54 696 561 609
- Form
- Australian proprietary company, limited by shares
- Base
- Melbourne, Victoria
- Contact point
- engineering@iopex.co.im
- Instrument
- Privacy Act 1988 (Cth), Schedule 1
"We", "us" and "our" below mean that entity and nothing broader. There is no parent, no group and no affiliate to fold into those words.
Surfaces covered
- This website, iopex.co.im, served as static files.
- Any mobile title released under this company name, on any store.
- Mail to the address above, including whatever is attached to it.
Surfaces not covered
- Apple and Google, which keep their own store and platform records under their own terms.
- An advertising network acting for itself rather than on our instruction, dealt with at 14.
- Anything reached by following a link away from here.
Name collision. iOPEX Technologies, Inc. is a separate and considerably older business in enterprise IT and business process services. No record described in this document is held by it, shared with it, or reachable through it, and mail intended for that company cannot be forwarded from our address.
02What is held, at this revision
Scope: the categories of personal information this company holds on the effective date printed above. Every one of them is listed here, and the sections that follow take each apart field by field.
- Correspondence
- Mail to the address above and the thread that follows it. Fields at 07, retention clock at 21
- Request logs for this site
- Held by the hosting provider, on the terms and for the window set out at 06
- Analytics on this site
- None installed. No tag manager and no third party script, which the cookie notice tells you how to verify in a browser
- Telemetry
- Runs on handsets this company owns, driven by the capture harness and the session runner described on the company page. Frame timestamps and thermal state off our own devices, keyed to no person
Sections 05, 22 and 23 set out, field by field, what a title of ours writes, what the field is for, and what switches it off. They are written as a specification you can hold the software to, so the design can be argued with off this page instead of reverse engineered out of a binary.
The rights described at 23, 24, 27 and 30 run against every category above. If you have written to us, you can ask what that thread contains, ask for it to be fixed, ask for it to go, and complain about whatever answer you get.
03The Act, and a map of the thirteen principles
Scope: the statute this document answers to, and which section answers each principle.
The governing instrument is the Privacy Act 1988 (Cth). Schedule 1 to that Act sets out thirteen Australian Privacy Principles, and for an organisation of this kind they are close to the whole obligation set. The map below exists so that a reader auditing this document against the Schedule does not have to hunt for the paragraph that answers a given principle.
| Principle | Short name | Obligation, in one line | Answered at |
|---|---|---|---|
| APP 1 | Open and transparent management | Run practices that ensure compliance, and keep a current, clearly expressed policy available free | 01, 32 |
| APP 2 | Anonymity and pseudonymity | Offer the option of not identifying yourself unless that is impracticable or the law forbids it | 11 |
| APP 3 | Collection of solicited information | Collect only what is reasonably necessary for a function we actually perform | 05, 06, 07 |
| APP 4 | Unsolicited information | Assess what arrives unasked, then destroy or de-identify what could not have been collected | 12 |
| APP 5 | Notification of collection | Say what is being taken, why, and what happens if it is withheld, at or before collection | 10 |
| APP 6 | Use and disclosure | Use it for the purpose it was taken for, and for a secondary purpose only on a listed ground | 13 |
| APP 7 | Direct marketing | Do not use personal information to market unless a narrow set of conditions is met | 15 |
| APP 8 | Cross-border disclosure | Take reasonable steps before sending anything to a recipient outside Australia | 17 |
| APP 9 | Government related identifiers | Do not adopt, use or disclose an identifier assigned by a government agency | 18 |
| APP 10 | Quality | Keep what is collected accurate, current and complete, and relevant when it is used | 19 |
| APP 11 | Security | Guard it for as long as it is held; destroy or de-identify once nothing needs it | 20, 21 |
| APP 12 | Access | Give a person the personal information held about them when they ask for it | 24 |
| APP 13 | Correction | Correct what is wrong, and where asked, tell anyone it was disclosed to | 24 |
A reference below to "APP 6", or any other number, means the correspondingly numbered principle in that Schedule.
04The small business exemption is not relied on
Scope: whether the Act binds this company today, and what is done about the gap.
Section 6D of the Act lifts most organisations turning over $3 million a year or less out of the Australian Privacy Principles. This company turns over less than that figure, and on a narrow reading falls inside the exemption.
The exemption is not being used, for two reasons that are engineering reasons rather than moral ones. It keys off turnover instead of sensitivity, so it would disappear on the day a title started earning, without one field of the data having changed. And several carve-outs inside section 6D pull a business back under the Act as soon as it discloses personal information about someone for a benefit or advantage. Meeting the standard from the first line costs less than retrofitting a pipeline that was drawn without it.
Requests and complaints are handled as though the Act applied in full. Should it start binding us as law rather than as a choice, no clause here needs rewriting.
Other Australian instruments in force here
- Spam Act 2003 (Cth). Consent, sender identification and a functioning unsubscribe on any commercial electronic message. Handled at 15.
- Australian Consumer Law. Schedule 2 to the Competition and Consumer Act 2010 (Cth) carries guarantees that no contract term is able to strip out.
- Part IIIC of the Privacy Act. The Notifiable Data Breaches scheme, handled at 27.
- Privacy and Other Legislation Amendment Act 2024 (Cth). Three consequences here: the tort at 28, the automated decision entry at 26, and a Children's Online Privacy Code awaiting registration, flagged at 25.
- Do Not Call Register Act 2006 (Cth). No telemarketing is done and no telephone number is collected that would make it possible.
05Ingest: telemetry from a published title
Scope: every field a released title writes, and the clock attached to each. There is no supplementary list held elsewhere.
Performance engineering runs on measurement, which makes this the section to be most suspicious of. "Diagnostics" is the word under which collection is usually hidden, and the only defence against that is an itemised field list that can be checked against a packet capture.
| Record | Fields written at ingest | Why it exists | Switchable | Clock |
|---|---|---|---|---|
| Device profile | Model, chipset, total and available memory, screen resolution, refresh rate, operating system version, build version, thermal headroom as the platform reports it | A frame time means nothing without the hardware that produced it. This record is the axis every other measurement is plotted against | No. Removing it makes the rest unreadable | 25 months |
| Frame timing | Presentation intervals reduced to a distribution on the handset, missed deadline count, stall durations | The 99th percentile and the deadline miss count, which are the two numbers this company works to | Yes, in the title's settings. Play is identical either way | 25 months, then aggregated |
| Thermal and power | Minutes from cold start to first throttle, thermal state transitions, charge level at session start and end, charging flag | Time to throttle, and drain per hour of play | Yes, same switch as frame timing | 25 months, aggregated thereafter |
| Crash and ANR | Stack trace, thread states, memory state at fault, breadcrumb log | Fixing the crash, then proving the fix worked on the hardware that crashed | Yes, from the title's settings | 90 days |
| Advertising identifier | Identifier for Advertisers on iOS, or on Android the Google Advertising ID | Capping how often an advertisement repeats, and attributing an install, where a title carries advertising. Personalisation only after you switch it on | Yes: system settings can reset it, or remove it outright | 13 months |
| Purchase | Store transaction identifier, product, amount, currency, date, refund state | Restoring what you bought, and meeting tax and accounting obligations | Written only where a purchase happens | 7 years |
Aggregation happens on the handset, before anything is sent
Frame timing leaves a device as a distribution, never as a series. Percentiles and the deadline miss count are computed locally and the per-frame array is dropped there. A per-frame series is a second-resolution record of exactly when somebody was holding a phone and for how long; the analysis has no use for it, so the pipeline is built so that it never receives one.
Battery fields are not health fields and not movement fields
Charge level and charging flag are read at session start and session end, in the foreground, and feed exactly one calculation: drain per hour of play. They are not sampled while a title is backgrounded and they are never joined to anything that would suggest where a device is or what its owner's day looks like.
Identifier discipline
Telemetry is keyed to an install identifier generated on the device, not to an account, an email address or a hardware serial. Deleting the app discards the key. The advertising identifier stays in its own store and is never used to look up a telemetry record, which is the join that would turn a performance dataset into an advertising profile.
06Ingest: this website
Scope: what a request to iopex.co.im leaves behind, and where it lands.
| Record | Fields | Lives with | Purpose | Clock |
|---|---|---|---|---|
| Request log | IP address, path, response status, user agent, timestamp | Hosting provider | Serving the file, and blocking abusive traffic | Provider rotation, under 30 days |
| Bot management token | An opaque value in a strictly necessary cookie | Hosting provider | Separating automated traffic from human traffic | 30 minutes, refreshed on activity |
| Challenge token | An opaque value, written only if a challenge is shown and passed | Hosting provider | Not putting the same visitor through a second challenge | Up to 30 days |
Nothing else is written. No analytics product, advertising tag, pixel, session recorder or fingerprinting script is installed on any page, which is why no page asks for consent to anything. The full inventory, and the reasoning behind the absence of a banner, is in the cookie notice.
The site has no form, so it accepts no submission. Every route on it is a static file plus one stylesheet, one small script and images; the script opens the navigation on a narrow screen and reveals sections on scroll, and it stores nothing.
07Ingest: correspondence
Scope: mail sent to the published address, and every field that mail leaves behind.
- Written at ingest
- Sender address, subject, message body, attachments, and the routing metadata your provider attaches
- Lives with
- Our email provider, listed in the register at 16
- Support threads
- 24 months, counted from the newest message in that thread
- Complaint threads
- 7 years from closure
- Readers
- The people who answer the mailbox. Nothing forwards to a third party
- Secondary use
- None. A thread is not mined, profiled or used to target advertising
An address that arrives in that mailbox is not added to any list, because no list exists to add it to. That is the quiet route by which small companies build a marketing database, and 15 explains why this one does not.
08Never collected
Scope: fields that no build, endpoint or page on this estate is permitted to capture. This list is as load-bearing as the collection tables and is easier to verify.
- Location at any precision, including the coarse network kind that needs no prompt.
- Camera, microphone, photo library, contacts and calendar, call log, phone state, SMS.
- Body, health and fitness sensors.
- Usage statistics for other applications. This one would genuinely help, since background load explains a good share of stalls on a loaded handset, and it is still declined.
- Identifiers assigned by government, of every kind, dealt with at 18.
- Sensitive information as the Act defines it: health, racial or ethnic origin, political opinion, religious belief, sexual orientation, criminal record, union membership.
- Biometric templates, and any biometric material at all.
- Form fields. This estate ships no form, so nothing gets typed into one and no endpoint waits behind it.
A build that requests one of these is a defect, not a product decision. Report it to the address at 33 and it gets handled as a defect.
09Records we hold, traces held on instruction
Scope: the difference between a record this company holds for its own purposes and a trace it would hold because another studio asked for it. The distinction decides who has to answer you, so it is stated before it becomes relevant.
Role A: records held for our own purposes
Everything itemised at 05 through 07 sits here. This company decides what is captured, why, and for how long, and is the entity answerable for it under the Act. Every right in this document runs directly against us, and the clocks at 21 are ours to keep.
Role B: traces captured under a studio's instruction
Profiling can also run the other way around. If this company is engaged to measure another studio's title, the traces produced belong to that engagement: the studio nominates the build, the device set and the field list, the studio sets the purpose and the retention window, and the studio's own privacy policy governs its relationship with its players. Our part is bounded and would be written down as such. Capture what the field list says, hold it for the agreed window, hand it over, destroy it on instruction, and make no secondary use of it, which specifically means never folding a customer's traces into anything of ours.
Which role applies. Role B is set out here because the two roles are handled differently, and because anybody reading this is owed the answer before it starts applying to them. Where it begins to apply, this section and the register at 16 are updated before the first trace is captured, not after.
10Notice at the point of ingest
Scope: how the disclosure APP 5 requires is actually delivered, and where.
APP 5 asks for the notice at or before collection, or as soon as practicable after it, and for the cost of withholding to be spelled out. Three delivery points carry it, this page being only the third.
- Store listing. Apple's privacy labels and the Google Play Data Safety declaration set out what a title records before an install begins.
- Inside the title. A permission is explained in our own words on the screen before the operating system dialog appears, never on the screen after it.
- Here. Every page of this site links to this document, as does the settings screen inside any title.
The consequence of withholding is the Switchable column at 05 and the If declined column at 22, rather than a sentence somewhere in the middle of a paragraph. Where a store declaration and this document disagree, the disagreement is a defect: report it, and whichever of the two is wrong gets corrected.
11Anonymous and pseudonymous dealing
Scope: dealing with this company without telling it who you are.
APP 2 makes anonymity an option unless honouring it is impracticable, or unless the law demands an identified individual. Cheap to honour here, because identity is not an input to anything built. Play needs no account, no name and no address, and the keys described at 05 sit on an install.
Mail may come from a pseudonymous address and gets the same answer as any other. The one place the option genuinely runs out is an access or correction request, where a record has to be tied to the person asking for it before it can be handed over. That trade is described at 24 rather than left to be discovered.
12Records that arrive unasked
Scope: personal information that reaches us without having been requested.
In practice it arrives three ways: a bug report with a full screen recording attached, a diagnostic export produced by some other tool, or a forwarded thread carrying other people's addresses in the quoted history.
Procedure
- Assess within a reasonable period whether APP 3 would have allowed the collection at all.
- Where it would not, and no Commonwealth record is involved, destroy or de-identify as soon as practicable, so far as that is lawful and reasonable.
- Write down the substance of the report without it, so the defect survives and the material does not.
Destruction here means the attachment is removed from the mailbox and expires from the provider's backup rotation on its ordinary cycle. Nothing is retained on the theory that it might be useful later.
13Use and disclosure
Scope: what may be done with a record once it has been collected.
APP 6 supplies the rule. A record may serve the purpose it was taken for. A second purpose needs one of three things behind it: your reasonable expectation plus a genuine relationship between the two purposes, your consent, or an exception the Act spells out.
Permitted uses
- Running the titles and the features you asked for.
- Diagnosing a crash or a defect, then checking whether the fix moved the number it was meant to move.
- Catching fraud, cheating and abuse: scripted play, duplicated installs, a tampered client.
- Serving advertising where a title carries it, on the terms at 14.
- Answering your mail, and meeting a legal obligation that applies to us.
Uses that are ruled out
- Selling personal information. No broker gets it, no advertiser buys it, and it goes into no audience product.
- Assembling a profile of a person across the products of unrelated companies.
- Using the content of your correspondence to target anything at you.
- Joining telemetry to advertising records, which is the specific join described at 05 and 14.
Disclosure to courts and enforcement bodies
Disclosure happens only on a ground the Act supplies, and four arise in practice: a requirement or authorisation under Australian law; an order made by a court or by a tribunal; the permitted general situations section 16A supplies, of which a serious threat to health, life or safety is the obvious one; and a request from an enforcement body, where handing the record over is reasonably necessary for an enforcement related activity. APP 6.5 obliges a written note of that last case, and one gets made. Where telling you is permitted, you are told.
14The advertising path, and the wall around telemetry
Scope: what advertising in a title would mean for a record about you.
Default state
An advertising request is marked non-personalised until you change that in the title's settings. A non-personalised advertisement is selected from context rather than from anything held about you.
The wall
Device profile, frame timing, thermal and power records are never transmitted to an advertising network and never used to assemble a segment. The reason is specific rather than decorative: a device model joined to a thermal profile is a good estimate of what handset somebody could afford, which is exactly the inference an advertising system would pay for. The separation is a property of the code path, not a promise in a policy, and the two stores share no key.
App Tracking Transparency
Apple's own prompt controls the Identifier for Advertisers. Ours comes first: the system dialog is raised only once personalisation has been enabled in the title's settings, so it never lands cold.
Play Data Safety
Each title's Google Play Data Safety declaration is kept aligned with this document. A difference between the two is a defect and worth an email to engineering@iopex.co.im.
A network is not our processor
An advertising network runs its own fraud checks and its own cross-inventory measurement, for itself, not on instructions from us. Records sitting there are beyond our reach, and no promise to delete them will be offered. Stopping the flow is available, and that is precisely what switching personalisation off performs.
Controls that work whatever we do
- Android: Settings, Google, Ads, then reset or delete the advertising ID outright.
- iOS: Settings, Privacy and Security, Tracking, and withdraw the permission there.
- Either platform: uninstalling stops transmission from that device at once.
15Direct marketing and the Spam Act
Scope: unsolicited messages, and the list that does not exist.
APP 7 limits what a personal record may be used to market. The Spam Act 2003 (Cth) sits over that, reaching email, SMS and instant messaging, with three hard requirements: consent, sender identification that is accurate, and an unsubscribe path live for at least 30 days and honoured inside 5 working days.
Position
No marketing list exists here, and no marketing message has gone out under this name. Should one ever go out, opt in is how it will work: consent stored with its timestamp and the exact wording agreed to, and a first message naming where the address came from.
Advertising inside a title is a different thing
An advertisement shown during play is served by a network into an ad slot. Nobody here addressed it to you, which puts it outside APP 7 and inside 14. The controls still work: personalisation stays off until switched on, and the platform level controls listed at 14 apply regardless of any setting of ours.
16Recipient register
Scope: every party that receives personal information from us, what it gets, and the regions it holds it in. This table is the authoritative list, not an illustrative one.
| Recipient | Receives | Function | Regions |
|---|---|---|---|
| Google Ireland Limited and Google LLC | Crash and ANR reports, device profile, purchase records, advertising identifier | Crash reporting, Play billing, advertising delivery | Ireland, the United States, further Google regions |
| Apple Inc. | Purchase records, crash reports | Store distribution, in-app purchase billing, and iOS crash reports | Apple regions, the United States included |
| Cloudflare, Inc. | Request logs including IP address | Serving and protecting this website | Global edge, Australia included |
| Our email provider | Whatever an email contains | Receiving and storing correspondence | Australian and United States regions |
| Our accountant | Aggregate revenue, and an individual transaction where a query turns on one | Statutory accounts, business activity statements, tax | Australia |
Not on the register
None of the following: data broker, marketing platform, customer data platform, enrichment or append service, identity graph, third party performance analytics vendor. The last is worth naming. It is the component a company like this one is expected to adopt, and adopting it would hand a supplier the device profile of every player. The table above changes first.
Published figures
Any performance figure this company publishes will be an aggregate computed from de-identified records, with no cell small enough to point at one person and no individual device row. No dataset will be released.
Sale of the business
Records may move to a buyer when the company or a title is sold. Notice goes up here ahead of completion wherever the law permits it, and the buyer inherits this document as the binding one until it publishes something of its own.
17Disclosure outside Australia
Scope: records that leave the country, and who wears it when something goes wrong offshore.
APP 8 covers a recipient sitting outside Australia. The provision that matters is section 16C: an act by that recipient which would have breached the Australian Privacy Principles counts as our act, and the liability lands here.
That accountability rule, rather than the list of exceptions, is what shapes the register at 16. It is why the list is short, why every entry is a named company instead of a category, and why adding one is a decision rather than a default.
Reasonable steps taken before a disclosure
- Contract. Provider data processing terms, which oblige it to follow our instructions, hold the records securely, support an individual's request, and report a breach to us.
- Region choice. Where a provider offers a region, the closest one that supports the workload is selected, and the register records where it landed.
- Field minimisation. A recipient gets the fields its function needs, which is why the Receives column at 16 differs from row to row.
Exceptions not used
The APP 8.2(a) route, which permits disclosure where the recipient is subject to a substantially similar law, is not relied on. Judging that country by country is not work this company is qualified to do, and getting it wrong would move the risk onto the person whose record it was. Consent as a standalone basis under APP 8.2(b) is not used either, because consent buried in an install flow is not a real decision.
Regions listed in the column at 16 are the countries where a record may sit or be reached. Move a provider to another region and that column is what changes.
18Government related identifiers
Scope: identifiers government issues. Passport number, driver licence number, Medicare number, tax file number.
APP 9 bars three things outside narrow exceptions: taking a government identifier as our own, putting one to use, and passing one on. Nothing here collects one. No age check, identity check or payout step exists that would want one, and no field anywhere is shaped to receive one.
If one arrives anyway, typically as a photograph of a licence attached to an email, it is handled as unsolicited material under 12 and destroyed. It is not filed, and it is not used to verify an access request either, which 24 explains.
19Record quality
Scope: keeping what is held accurate enough to be used, as APP 10 requires.
Machine-written records dominate, and they are accurate in the narrow sense that they report what a handset reported. What ages is the human part: an address in a support thread, a device description in a bug report, something that was true in March and is wrong by August.
Those are not periodically re-verified, because re-verification means writing to people whose business with us closed long ago, purely to ask whether an old address still works, which is intrusion wearing the costume of diligence. The remedy is the correction right at 24, available at any time and free.
Where a record is used for a decision that matters to a person, it is checked at the point of use rather than trusted because it is on file.
20Security controls on a held record
Scope: the controls that protect a record while it is held, under APP 11.
- In transit
- HTTPS only, on the website and on every application endpoint
- At rest
- Platform encryption on stored records
- Administrative access
- Multi-factor on every account able to reach production records or a store console
- Reader set
- Need to know, reviewed whenever somebody joins or leaves
- Environments
- Split credentials, so a development key has no path to live records
- Strongest control
- Not collecting the field, which is why 05 and 08 are as short as they are
Perfect security is not a state a system arrives at, and a supplier implying otherwise is mistaken, or selling. The controls listed above are the ones in force at this revision, and this section changes when one of them does.
21Retention clocks and destruction
Scope: the life of each record, the event that starts its clock, and what destruction performs. APP 11.2 obliges destruction or de-identification once no permitted purpose remains, unless a law compels the record to be kept.
| Record | Clock | Starts at | Reason for that number |
|---|---|---|---|
| Crash and ANR reports | 90 days | Receipt | Long enough to reproduce, fix and verify against the build that faulted |
| Device profile | 25 months | Last contact from that install | Hardware generations turn over slowly. Two annual cycles is the shortest window that supports a comparison across device ages, and it is longer than everything else for that stated reason rather than by drift |
| Frame timing, thermal and power | 25 months, then irreversibly aggregated | Last contact from that install | Same reason. After the clock expires only distributions remain, with nothing that points back at an install |
| Attribution, and the advertising ID | 13 months | Last event | Matches the attribution window the platforms operate |
| Support correspondence | 24 months | Last message in the thread | Enough to recognise a problem that keeps coming back |
| Complaint correspondence | 7 years | Closure | Tracks the limitation period Victoria applies generally, so the record outlives any right to sue on it |
| Purchase, tax and accounting | 7 years | Transaction | Statutory: Income Tax Assessment Act 1936 s 262A, Corporations Act 2001 s 286 |
| Request logs from this website | Under 30 days | Request | The hosting provider's rotation, not a period we set |
What the words mean here
Destruction: the record leaves live systems, then ages out of the backup rotation, a process finishing inside 35 days. No backup is ever replayed to undo a deletion.
De-identification: strip every identifier, plus any field capable of reconstituting one. For a device profile that means discarding the install identifier and coarsening the model into a hardware class, so what remains describes a population and cannot be narrowed to a person.
22Device permissions, ATT, Data Safety
Scope: the permissions a title asks a device for, and what happens when one is refused.
| Permission | Function | Prompted | If declined | Where to revoke |
|---|---|---|---|---|
| Internet | Telemetry upload, crash reports, advertising | Granted at install, not separately promptable | Not applicable | System settings, where network access for the app can be withdrawn |
| App Tracking Transparency (iOS) | The Identifier for Advertisers, used for personalised advertising | Yes, after our own setting is switched on | Advertising stays non-personalised and the title is otherwise unchanged | iOS Settings, under Privacy and Security, at Tracking |
| Advertising ID (Android 13+) | Attribution, and capping how often an advertisement repeats | Manifest declaration, never a prompt | Deleted in system settings, after which the app reads a zeroed value | Settings, Google, Ads |
| Vibration | Haptic feedback | No | No haptics | Title settings |
What performance work does not need
Frame timing, thermal state and charge level are all readable through ordinary platform interfaces that raise no prompt at all. No special permission is required for any of it, none is requested, and a build asking for one is either defective or somebody else's.
Store declarations
The Google Play Data Safety form and Apple's privacy labels are filled in from the tables at 05 and 21, so that the store answer and the answer here come from the same source. App Tracking Transparency is treated as a genuine choice rather than a formality: if the prompt is declined, no advertising identifier is read and no fallback identifier is substituted for it.
23Delete your data
Scope: the switch that prevents collection, and the request that removes what was already collected.
The switch comes first
Frame timing, thermal and power telemetry can be turned off inside a title's settings, and the game runs identically without it. That switch is the strongest control on this page, it takes effect immediately, and it needs no request to us and no reply from us.
Two routes to delete your data
- In a title: Settings, then Data, then Delete my data. One confirmation queues the request.
- By email: subject line "Delete my data", sent to engineering@iopex.co.im, quoting the support identifier shown on the settings screen inside the title so the record can be located.
| Record | Effect | Why |
|---|---|---|
| Device profile and telemetry carrying your install key | Deleted or irreversibly aggregated within 30 days | Distributions survive, and nothing in them leads back to an install |
| Crash and ANR reports | Dropped on their 90 day cycle | Short lived to begin with, and detached from the install key on request |
| Advertising identifier records | Deleted within 30 days | Nothing downstream of them needs to persist |
| Purchase and tax records | Kept for 7 years | Statutory, per 21. These cannot be deleted, and saying so is better than deleting and hoping nobody audits it |
| Complaint correspondence | Kept for 7 years | It is the evidence of how a complaint was handled, including for you |
| Backups | Overwritten by the ordinary rotation inside 35 days | A deleted record is never restored from backup |
Completion is confirmed in writing. A record is not flagged as deleted and quietly retained, which is the usual implementation and is not the one used here.
24Access and correction
Scope: seeing what is held about you, and fixing it. APP 12 carries the access right, APP 13 the correction right.
- Route
- Email with "Privacy request" as the subject
- Clock
- 30 days from receipt
- Cost
- Nothing, for either right
- Identity documents
- Not requested and not accepted
- Refusal
- Written reasons, the ground relied on, and the complaint route
What to include
Describe what you are after, with enough detail for it to be found. A record keyed to a device rather than an account needs the in-app support identifier from the settings screen, or else the advertising identifier. With neither of them, nothing joins a record to the person writing.
Verification
Before anything is handed over, reasonable satisfaction is needed that the request comes from the person a record describes, or from their authorised representative. An account-linked request verifies through the address on that account. A request resting on a device identifier verifies possession of the identifier and nothing beyond it, and the answer will say exactly that instead of dressing it up as a stronger check.
Timing, and what happens inside it
The 30 day window is the whole process, verification included, not 30 days measured from the moment verification finished. Where producing an export in an unusual form would cost real work, the charge is quoted before the work starts and will not be excessive; there is no charge for making the request, and none for a correction.
Grounds for refusing access
The Act lists them, and the list is shorter than its reputation: an unreasonable effect on another person's privacy, a frivolous or vexatious request, material bound up in existing or anticipated proceedings that discovery would not reach, and access that would itself be unlawful. A partial release, or a different route to the same need, is offered ahead of an outright refusal.
Correction
Wrong, stale, incomplete, irrelevant, misleading: each of those gets corrected. Where the record had gone to somebody else and you ask for that person to be told, reasonable steps follow, unless taking them is impracticable or unlawful.
A refused correction leaves a second right in your hands. Require a statement to sit with the record saying you consider it inaccurate, and reasonable steps then put that statement in front of whoever reads the record later. The Act buries this one, so it is repeated here.
25Age, capacity, young people
Scope: how age is handled, given that mobile games are the category where this question is asked most often and answered worst.
Nothing built here is directed at children or designed to appeal primarily to children, and where a store asks for a target audience declaration, a general audience is declared.
Capacity
No age of self-consent is fixed by the Act. OAIC guidance points to assessing capacity individually where that is practicable, and to presuming it from 15 upwards unless something signals otherwise. That presumption is the working rule here.
Measures in place now
- No personal information is knowingly taken from a child under 15 unless a parent or guardian has consented to it.
- A store signal identifying the user as a child marks the advertising request child directed, and personalised advertising is then not requested at all.
- There is no chat, no player to player messaging, no social feature and no user generated content in anything built here, which removes the largest category of harm before it exists.
Children's Online Privacy Code
A code covering services children are likely to reach is provided for by the 2024 amendment Act named at 04, with the Information Commissioner drafting it. Compliance follows its registration and commencement. This document changes at that point, once the terms are known rather than guessed at.
Where a child's record has arrived here
Write to engineering@iopex.co.im. Deletion follows, without a demand that you evidence a legal relationship past whatever makes the request credible, and confirmation follows the deletion.
26Automated decisions
Scope: decisions made by software about a person, and the disclosure the amended Act will require from 10 December 2026.
From 10 December 2026 the amendments made by the Privacy and Other Legislation Amendment Act 2024 oblige a privacy policy to name the categories of personal information driving a substantially automated decision that significantly affects somebody's rights or interests, and to name which decisions get made that way. The disclosure below is published early rather than on the commencement date.
Nothing here makes a decision of that weight. No process decides access to credit, to employment, to a service, to a benefit or to a legal entitlement. Two automated paths exist, and neither one clears the threshold.
- Abuse and cheat detection. Automated signals can bar an install, or an account, from a leaderboard. Restrictions landing on an account, as opposed to one score, get a human review whenever one is asked for, and asking is the whole procedure.
- Advertising selection. Which advertisement appears is decided by the network's own system. It has no effect on access to a title or on anything already paid for.
Should that change, the description lands in this section, and it lands before the processing starts rather than after it.
27Breach procedure, and the NDB scheme
Scope: what happens between the moment something goes wrong and the moment you hear about it.
Part IIIC of the Privacy Act carries the Notifiable Data Breaches scheme. Its trigger is an eligible data breach: personal information reached without authority, released without authority, or lost, in circumstances where a reasonable person would expect serious harm to follow for someone the information describes, and where remedial action has failed to remove that expectation.
| Step | Action | Clock |
|---|---|---|
| Contain | Cut the access path, revoke the credential, pull the component offline where that is the only thing that works | Immediately on becoming aware |
| Assess | Reasonable and expeditious assessment of whether an eligible data breach has occurred | Within 30 days of the grounds for suspicion arising, which is what section 26WH allows |
| Remediate | Where remediation removes the likelihood of serious harm, notification is not owed, and the reasoning gets written down | Inside the assessment window |
| Notify | Statement prepared for the Commissioner, then notice to affected individuals | As soon as practicable after the assessment concludes |
Where a notification goes
- Regulator
- Office of the Australian Information Commissioner
- Post
- GPO Box 5218, Sydney NSW 2001
- Telephone
- 1300 363 992
- Online
- oaic.gov.au
- If individual notice is impracticable
- The statement goes up on this website, with reasonable steps taken to publicise it
What a notice will say
Identity and contact details for us, an account of the incident, which categories of information it touched, and the steps worth taking in response. Gaps get stated as gaps: an early notice that is honest has them, and packing them with reassurance is how a notice stops being worth reading.
Reporting one to us
Write to engineering@iopex.co.im with "Security" in the subject. A false alarm costs less than a missed incident. Reports made in good faith draw a technical answer, never a legal one.
28The statutory tort
Scope: a right you have against us that does not depend on the complaints process at 30.
Since 10 June 2025 the statutory tort for serious invasions of privacy has been available, created by Schedule 2 of the Privacy and Other Legislation Amendment Act 2024. Two forms exist: intrusion upon seclusion, and misuse of information. Three elements are wanted: intent or recklessness; a reasonable expectation of privacy held by someone standing where the plaintiff stands; and seriousness.
It reaches any defendant, this one included, and it does not wait on a complaint having been made to us or to the Commissioner. Most policies leave it out. An unknown right is a weak one.
29Storage on this website
Scope: what is written to your device by this site, summarised. The full inventory is at the cookie notice.
Nothing our own code ships writes a cookie, a local storage entry, a session storage entry or a database. The host may write two strictly necessary cookies, both aimed at telling a human request from an automated one, and both appear with their lifetimes on that page.
No consent banner runs, because no storage here is of the kind consent exists for. Nor does this country operate a separate cookie consent regime; the Privacy Act governs storage, on the terms the cookie notice sets out.
30Complaints, and the route to the OAIC
Scope: what to do when the answer you got was wrong, slow, or evasive.
Step one, to us
- Route
- Email with "Privacy complaint" as the subject
- Contents
- What happened, and the outcome you want
- Acknowledgement
- Within 5 business days
- Answer on the substance
- Within 30 days
- If it will take longer
- You are told why, and given a date
Step two, to the Commissioner
Where our answer fails to settle it, or 30 days go by without one arriving, the matter can be taken to the Office of the Australian Information Commissioner.
- Post
- GPO Box 5218, Sydney NSW 2001
- Telephone
- 1300 363 992
- Online
- oaic.gov.au
- Cost
- Free, and no legal representation is needed
- Our consent
- Not required, and not something we could withhold
The Commissioner ordinarily expects an organisation to have had its turn, which is the purpose of the step above, while keeping the discretion to take a complaint that skipped it.
What will not happen
No non-disclosure agreement will be required as the price of a privacy complaint being handled, and lodging one is not treated as a breach of the terms of use.
31Requests from outside Australia
Scope: rights that come from somewhere other than the Privacy Act.
Australian law binds this company, so Australian law is what this document answers to. A right of yours going unmentioned here is not a right being refused.
European Economic Area and United Kingdom
Processing of ours falling under the EU General Data Protection Regulation, or under the UK GDPR, carries the usual set: objection, portability, restriction, erasure, rectification, access, and a complaint lodged with your national supervisory authority. An objection to processing grounded on legitimate interests ends that processing, absent compelling grounds overriding yours. Consent, where it is the ground, can be pulled at any point, and what was done before it was pulled stays lawful. One month is the answering period.
California
The California Consumer Privacy Act, as amended, supplies a right to opt out of a sale or a sharing, alongside rights to know, to correct and to delete. Nothing here is sold. Nothing is shared for cross context behavioural advertising within that Act's definition, since personalisation stays off until a person switches it on. A Global Privacy Control signal arriving at this site is read as an opt out.
Anywhere else
Cite the law you are invoking, so the correct clock gets applied. A request backed by a right that exists where you live is answered on its merits, not on whether it technically binds us.
32Revision control
Scope: how this document changes, and how you find out that it did.
- Current revision
- Version 1.0, effective 10 August 2026
- Earlier revisions
- None. This is the first version in force
- Where the version lives
- The line under the heading at the top of this page
- Notice for a material change
- At least 30 days, on this page and in any title on next launch
- Retrospective effect
- None. A material change applies from its effective date forward
A material change means one that cuts a right or widens what is collected. A correction to a typographical error, a clearer sentence or a renumbered cross-reference is not one, and dressing it up as one would only teach people to ignore the notices.
Superseded revisions are kept, though none is published as a page of its own. Ask what this document held on a given date and that revision comes back to you.
A structured operating document, then, and not legal advice. It replaces nothing an Australian legal practitioner would tell you about your own position.
33Contact register
Scope: one address, several subject lines, and the clock attached to each.
| Subject line | Matter | Clock |
|---|---|---|
| Privacy request | Access to the records held about you, under APP 12 | 30 days |
| Privacy request | Correction of a record, under APP 13 | 30 days |
| Delete my data | Removal of the records tied to one install | 30 days |
| Privacy complaint | The handling of a privacy matter | Acknowledged inside 5 business days, answered inside 30 days |
| Security | A suspected incident, or a breach | Same or next business day |
| Privacy | Anything else raised by this document | 5 business days |
- Address
- engineering@iopex.co.im
- Entity
- IOPEX TECHNOLOGIES PTY LTD, ACN 696 561 609, ABN 54 696 561 609
- Jurisdiction
- Victoria, Australia
- Service of documents
- ASIC's record of the registered office for ACN 696 561 609, which is the address carrying legal effect
- Going straight to the regulator
- Office of the Australian Information Commissioner, GPO Box 5218, Sydney NSW 2001, 1300 363 992, oaic.gov.au
No postal address appears anywhere on this site. An address without legal effect for service adds a line of text and nothing else.