Bahasa Indonesia

Privacy Policy — Kiri Bang!


In short

Kiri Bang! never asks who you are. You can play it to the end without ever typing a name, an email address, or a phone number.

Three things leave your device, and you can recognise all three:

We run no analytics. The only technical data for ourselves is a crash report when the app crashes or an ad you asked for fails to play (Section 5), and you can turn it off. The technical data Google's ads SDK collects is described as it is in Section 3.

If that answers your question, the rest of this document is only the detail.


1. Data stored on your device

The app keeps the following in local device storage (SharedPreferences):

What Contents Why
Saved game Fleet, drivers, routes, balance, in-game transaction history To carry on where you left off
Installation identifier A random string generated on your device To tell this device apart from another when syncing backups
Session timestamps When the app was last opened, and how far the in-game clock has run To work out what you earned while you were away
Language preference id or en To show the interface in your language
Game mode Easy or Hard To remember which one you are playing
Introduction flags Whether the opening screens and guided tour are done So the introduction does not repeat every launch
Reminder settings Which reminders are on, and whether notification permission has been asked for To schedule setoran reminders the way you chose

The installation identifier is not your identity. It is generated at random on your device, is not derived from a device serial or any identity, and is not linked to a name, email, phone number or account. It disappears when the app is uninstalled. It travels with the backup (Section 2) for one reason only: so the app can tell "this is my own backup, sent again" from "this is a backup from my other device".

The game is fully playable with no internet connection. What stops working offline is backup, rewarded ads, and buying coins.

Reminders. If you allow notifications, the app schedules reminders — "setoran ready to collect" and "setoran pot full" — on your own device when you leave the game, and cancels them when you come back. They are created and shown entirely on the device: no data is sent to a server for them. You can turn them off under Profile → Settings → Notifications, or in Android's notification settings.

2. Data sent to a server

The app backs your saved game up to Google Cloud Firestore. What is sent:

What When
The saved game (the same contents as Section 1, compressed) On launch, on leaving for the background, and at each in-game day rollover
The installation identifier and a save revision number Alongside the save above

To file that backup in the right place, the app creates an anonymous account through Firebase Authentication. An anonymous account has no name, email or password — only a random number (uid), a creation date and a last-access time. You are never asked to register, and it cannot be used to sign in anywhere.

As with any network request, Google receives your device's IP address when a backup is sent or fetched. We do not store, log, or use it.

Backups are held in Google's data centres in the asia-southeast2 region (Jakarta, Indonesia).

Signing in with Google (optional)

You can link that backup to your Google account so your save can be recovered after changing or reinstalling on a device. This is your choice, and the game runs fully without it.

If you do link it, that Google account's email address is received by Firebase Authentication and recorded there as the marker of who owns the backup. The game itself does not display it, use it, or send it anywhere — the Profile screen shows only that your backup is safe.

If you do not link it, the anonymous account lives and dies with the installation: uninstalling and reinstalling, or moving to a new device, gives the app a new number, and the old backup cannot be recovered.

3. Advertising

The app shows rewarded ads from Google AdMob.

You play every one of them. An ad plays only after you press a button offering something in return — doubling a collection, speeding up a repair, restoring a login streak. There are no banners, no full-screen ads interrupting play, and no ad you did not ask for.

But the SDK is at work from the moment the app opens. So that an ad is ready the instant you press the button, rather than after several seconds of waiting, the app starts the Google Mobile Ads SDK on launch and loads one ad in the background, then loads the next each time one finishes. According to Google, in doing so the SDK collects the following and shares it with Google:

Data For example Used for (according to Google)
Approximate location Estimated from the device's IP address Advertising, analytics, fraud prevention
Interactions App launches, taps, ads watched Advertising, analytics, fraud prevention
Diagnostics App launch time, hang rate, energy use Advertising, analytics, fraud prevention
Device identifiers Advertising ID and app set ID Advertising, analytics, fraud prevention

This data goes directly to Google, not to us — we cannot read, store or delete it. This SDK is why the app lists the AD_ID permission on its Google Play page. Google's own details: https://developers.google.com/admob/android/privacy/play-data-disclosure

You are asked first, wherever that is required. Before a single ad request goes out, the app runs Google's own consent form (User Messaging Platform). In regions that require consent — the EEA, the UK, and anywhere else Google has extended it — that form appears, and your answer decides what kind of ad may be requested. In regions that do not require it, Indonesia included, the form does not appear. Wherever the form does apply, you can change your answer at any time through the Ad privacy settings row on the Settings screen.

Google's policy covering data AdMob receives: https://policies.google.com/technologies/ads

4. In-app purchases

Coins can be bought through Google Play Billing.

We never see your payment details. Card numbers, balances and the whole payment flow are handled by Google Play; this app does not receive, display or store any of it.

What the app does receive once a purchase completes is a receipt: a transaction number, the product bought, and one random code from Play identifying that transaction. That code is sent to our server, which asks Google whether the payment genuinely happened before the coins are handed over. That is its only use; it is not stored, not logged, and not used for anything else.

Your in-game purchase history is kept on your device and travels in the backup (Sections 1 and 2), as rows in the coin history.

5. Data not collected

The app does not collect:

That last point needs explaining, because the Google Play page lists this app as requesting biometric permissions (USE_BIOMETRIC and USE_FINGERPRINT).

Those come with the Google sign-in screen, not from the game. That screen uses Android's built-in credential manager, which lets you sign in with a fingerprint instead of typing a password. It is the operating system that checks your fingerprint, not this app — the result reaches us only as "succeeded" or "failed". Kiri Bang! never receives, reads or stores any biometric data, and could not, even if we wanted to.

Nor will you ever be asked to use it. A fingerprint appears only if you yourself choose to sign in with Google, and that is optional.

Crash reports

If the app crashes, Firebase Crashlytics sends us the technical details: a trace of the code that failed, the device model and Android version, the app version, the time, and a random installation identifier Crashlytics generates. A report does not contain your name, email, or the contents of your saved game, and is used only to find and fix crashes.

The same kind of report is sent when you tap a rewarded-ad button and the ad fails to play: the error code from the ad network, and how many ads have played and failed since the app was opened. This tells us how often it happens and on which devices — something one phone cannot answer. The same failure is reported at most once each time the app is opened.

You can turn this off at any time under Profile → Settings → Privacy → Send crash reports. Once off, no reports are sent.

6. Sharing with third parties

We do not sell or rent your data.

The only other party that receives data from this app is Google, in four separate roles:

Service For what Policy
Firebase Authentication & Cloud Firestore Storing the save backup (Section 2) https://policies.google.com/privacy
Google AdMob Serving rewarded ads (Section 3) https://policies.google.com/technologies/ads
Google Play Billing Processing coin purchases (Section 4) https://policies.google.com/privacy
Firebase Crashlytics Receiving crash reports (Section 5) https://firebase.google.com/support/privacy

For Firebase and Play Billing, Google processes data on our behalf. AdMob is different: the data in Section 3 is shared with Google, which also uses it for its own purposes — advertising, analytics and fraud prevention — under its own policy.

For Crashlytics, Google also processes data on our behalf. The app contains no analytics SDK.

7. Deleting your data

On the device. Uninstalling the app deletes everything in Section 1. You can also clear it without uninstalling, through Android Settings → Apps → Kiri Bang! → Storage → Clear data.

On the server: your account and backup. The account in Section 2 and the backup stored under it are not deleted when the app is uninstalled. To ask for both to be deleted, email the address in Section 10:

We delete your account together with its backup, including the recorded email address if the account was ever linked, within 30 days, and confirm once it is done.

If your account was never linked, the app is already gone, and the number was never copied, that account and its backup can no longer be traced by anyone, us included.

Data received by AdMob (Section 3) is held by Google, not by us, so there is nothing on our side to delete. You can manage your advertising ID yourself in your Android device's Google ad settings (Settings → Google → Ads, or Settings → Privacy → Ads on newer Android versions), including deleting it or opting out of personalised advertising.

8. Children

The app does not ask anyone for their identity, children included.

It does show advertising and does sell in-game coins, so it is not directed at children and is not built to Google Play's Designed for Families programme. The applicable age rating is shown on the app's Google Play page.

9. Changes to this policy

If a future version starts collecting anything else, this policy will be updated before that version is released, and the "last updated" date above will change.

10. Contacting us

ilhamraksa.2805@gmail.com