Privacy Policy
Last updated: September 27, 2026
Pito does not sell personal data. This Policy explains what the App and website collect, why, who can see it, how long it is kept, and the choices and rights you have. It also explains how Pito protects younger players.
1. Data Controller
Pito is the data controller responsible for protecting and managing your data. You can reach the operator of Pito at the contact below.
Contact: pito@pito.games
This Privacy Policy is governed by the same laws as our Terms of Service (the Kurdistan Region and federal Iraq) and forms part of those Terms.
2. Information Stored Locally
The App stores gameplay progress and settings on your device. A Google or Apple Account sign-in is required to enter the App. Before sign-in, or when an authenticated session is unavailable, some technical services may still operate: crash diagnostics, content and configuration requests, security checks, and advertising where enabled.
Game statistics:
- Games played, wins, current streak, best streak, win rate
- Game history (words and results)
- Solitaire bankroll (cumulative Klondike Vegas score, may be positive or negative)
Game economy:
- Stars, coins, and suns (Helo currency)
- Hint usage history
- Purchased items (themes, skins, boosters)
Settings and caches:
- Audio and haptic feedback preferences, interface language, and selected theme color
- Cached copies of recently viewed chats, stories and Spotlight content so the App opens quickly
Important: Uninstalling normally removes the App's local data. It does not delete an online Account or Account-bound balances; use the in-app deletion control for that.
3. Account Data
When you create the required Account using Google or Apple Sign-In, the following is stored on our servers:
- Full name and email from your sign-in provider (Google/Apple)
- Username, bio and friend code (including custom friend codes you chose and the codes you used before, which stay linked to your Account so friends can still find you)
- Instagram username (if you choose to add one — displayed publicly on your profile)
- Profile picture (if you upload one, compressed to 400x400)
- Game statistics (scores, stars, coins, streaks, Solitaire bankroll)
- Per-game online ratings for every online game, and your match history
- Purchased and equipped items (themes, colors, frames, backgrounds, chat styles)
- Date of birth, gender and place — declared by you once after sign-in. Place is your country or region (Kurdistan is listed as its own region) and, for some countries and regions, your city or town. The App never uses device location services for this; the place is whatever you choose from a list. Your date of birth and gender are fixed once saved; your place can be changed at any time from your profile. If you entered something by mistake, contact us
How these details are shown. Your full date of birth is never displayed to anyone. Your age (in whole years), gender and place are hidden from other players by default; you can switch each one on separately under Settings → Privacy, and switch it off again at any time. On your birthday, your friends may see a small cake beside your name and receive a notification that it is your birthday (this shows the day, not your age or year of birth); you can turn this off under Settings → Privacy.
How these details are used. We use your date of birth to apply age-based protections and age limits (Section 4), to celebrate your birthday if you allow it, to make the App and its content appropriate for you, and — only as anonymised, aggregated statistics (for example “40% of active players are aged 18–24”) — to understand our audience and report it to advertising and promotional partners. We do not sell or share your individual date of birth, gender or place with any partner.
The primary Supabase project that stores this data is hosted in Sydney, Australia (ap-southeast-2). Data is protected in transit using HTTPS/TLS and by provider and application access controls; no internet service can promise absolute security. Authentication email is not displayed publicly. Public profile and leaderboard information is described in Sections 20–22.
4. How We Use Age to Protect Players
The App places every Account into an age group from the date of birth it declared: under 13, 13 to 17, or 18 and over. We use the age group only to apply protections and age limits, for example:
- Under 13: Spotlight (public stories, public posts, Discover, comments and search) is not available. Stories can be shared with friends only
- 13 to 17: public stories and posts are not shown in Discover to adults who are not their friends, and adults who are not their friends cannot comment on, reply to, or mention their content (and the reverse)
- Everyone: story comments are limited to friends, and message requests from people who are not friends can contain plain text only until they are accepted
See also Section 29 (Children's Privacy & Parental Rights) and our Child Safety Standards.
5. Online Multiplayer Data
When you play any of our online games (وێنەکەم, Biliard, Chess, Dama, Tawla, Okey, Domino, Aznif, Barricade and Snake and Ladder), the following additional data is collected and stored on our servers:
- Ratings: Per-game skill ratings calculated from your results, publicly visible on leaderboards
- Match History: Game results (win/loss/draw), opponent ID, game duration, and timestamps
- Matchmaking Queue Data: Your user ID and rating are temporarily stored in a matchmaking queue while searching for an opponent; this data is deleted once a match is found or you cancel
- Real-Time Game State: Moves, drawings, guesses, dice rolls, tile and card plays, chat and emoji reactions are transmitted between players during a match via our self-hosted game servers
- Completed Match Records: When a rated online match ends we keep a record of it — the players, the result, the rating change and the sequence of moves — so that match history, leaderboards and ratings work
- Fair-Play Signals: For our rated strategy games (currently Chess and Dama) we also store, per move, how long you took and whether the App was in the foreground on your device. This is used solely to detect the use of chess engines and other outside assistance in rated games. It is never used for advertising or profiling. Early leaves, disconnections and matchmaking penalties are also recorded to keep matches fair
- Game Invites: Invite links contain only a game or room identifier or a friend code. No other personal information is embedded in invite links
Online play requires a Pito Account and an active connection. Match data is collected only when you use an online mode.
6. وێنەکەم (Drawing Game) Data
- What is shared: your drawings (the pen strokes you draw), guesses, chat messages, character, username and score are sent in real time to the other players in the room. In public games these players may be strangers
- Room settings: the room code, settings and any custom words the host adds are stored while the room is open
- Safety records: so a drawing can be reported, a copy of the current drawing is kept for about 20 minutes and details of each round for about 24 hours. A reported drawing, the report, and moderation decisions (such as removals from rooms and game bans) are kept until the report is resolved and then for up to 90 days
- Automated checks: chat in the game is checked automatically for prohibited words
- Results: game results and scores are stored with your Account
7. Voice Chat & Calls
Online matches and friends include optional voice features. Voice is not activated automatically — you must tap the microphone or call button to connect.
- Microphone Access: The App requests microphone permission when a voice or recording feature first needs it. You can deny or revoke this permission at any time in your device settings
- Audio Transmission: Voice audio is processed and streamed in real time through a self-hosted LiveKit service. Pito does not intentionally record or store the live audio stream
- Technical data: Connection metadata and diagnostics may be logged to operate, secure, and troubleshoot the service. The audio stream ends when the call or voice session disconnects
Voice chat requires a Pito Account and a supported call or online match. The stream is necessarily processed by the transport service to deliver it, but is not used for advertising.
8. Text Chat Data
When you use in-app chat (one-to-one and group conversations), the following data is collected and stored on our servers:
- Messages: Text messages, GIF and sticker references, reactions, the chat bubble style you chose, and shared Spotlight cards sent between you and others
- Read Receipts: We track whether a message has been delivered and read
- Mute Preferences and Pinned Messages: stored with your account
- Conversation Wallpaper: If you set a shared chat wallpaper, your choice is stored with the conversation. If you use your own photo as a wallpaper, it is stored at an unlisted web link so both people in the conversation can see it
- Custom stickers: stickers you cut out of your own photos are stored at an unlisted web link so they can be shown in the chats you send them to
Disappearing messages: If you enable disappearing messages, content is hidden after the applicable timer and the records are removed by recurring cleanup. A daily cleanup currently deletes expired, unsaved message records after an additional operational delay of up to about 24 hours. Copies in backups, delivery queues, abuse reports, or another user's screenshots may last longer.
Friends can message directly. If your privacy setting permits it, another user may send a message request, which can contain plain text only until it is accepted; group members can communicate inside shared groups. Messages are not public, but they pass through our service providers and are checked automatically for prohibited words and abuse. Reported or flagged content and enough context to assess it may be reviewed for safety, abuse prevention, and legal compliance. If a Spotlight post or story shared into a chat is later deleted, hidden or expires, the shared card stops showing its content.
9. Voice Messages & Snaps in Chat
In addition to text, chat supports optional voice messages and view-once photo "snaps":
- Voice Messages: Audio clips are stored on access-controlled Supabase Storage or Cloudflare R2 so recipients can play them. Listen-once clips are queued for deletion after listening
- Snaps (view-once media): Photos and short videos are stored while delivery or viewing is pending. Once the applicable recipients view a snap, the database marks it viewed and a server-side deletion worker removes the object. Retries can cause a short delay
- Streaks: we record when friends exchange snaps to keep the streak count, and record streak restores
- Media is delivered to the recipients or group members you selected and processed by the storage/delivery providers named below. It is not used by Pito to personalize ads
This is separate from real-time voice chat (Section 7), whose live audio stream Pito does not intentionally record or store.
10. Spotlight, Stories & Posts
Spotlight is available to Accounts aged 13 and over. When you use it, we process:
- What you share: photo stories (taken with the camera or chosen from your photos), captions, text posts with an optional photo, comments, replies, mentions, and your likes
- Your audience choice: each story or post is shared with your friends or with "Everyone" (Everyone requires Pito Plus). Content shared with Everyone appears in the Discover grid, where any Spotlight user can see it, subject to the age protections in Section 4. It can be found through Spotlight search
- Views and interactions: when you view a story, its author can see that you viewed it and whether you liked it. Like and comment counts are shown with posts and stories. Likes, comments and mentions are shown in the recipient's activity list and may trigger a notification
- Ranking: the Discover grid is ordered by how recent content is, how many likes and comments it has, and whether its author is your friend. We do not use your personal details (such as age, gender or place) to rank content for advertising purposes
- Your settings: hidden posts, muted people, notification choices and search history on your device
- Storage: story photos are kept in access-controlled storage and shown through short-lived links. Photos in posts are stored on Cloudflare and served from a public content-delivery address, so anyone who has the exact link to such a photo can open it. We create smaller preview copies (thumbnails) of photos
How long Spotlight content is kept: a story is shown for 24 hours and is deleted from our systems within about a day after it expires. A post is shown in Spotlight feeds for seven days and stays stored with your Account until you delete it or your Account; when you delete a post it is removed from view at once and deleted from our systems about 24 hours later. These periods can be longer where Section 11 applies, for example when content has been reported.
11. Safety, Moderation & Reports
- Automated text checks: usernames, bios, chat messages, in-game chat, captions, posts and comments are checked automatically against lists of prohibited words in Kurdish and other languages
- Automated image checks: profile pictures, photos shared with "Everyone" in Spotlight, and custom stickers used publicly are checked on Pito's own servers by an image-classification model, before or shortly after others can see them. Images are not sent to an outside company for this check. Photos shared only with friends are not classified
- Digital fingerprints: we calculate a digital fingerprint (a cryptographic hash) of uploaded images, and keep the fingerprints of images we removed, so the same file cannot be uploaded again
- Reports: when you report someone we store the report, the reason, the content and enough context to review it. We do not tell the reported person who reported them. Content that several people report, or that is reported as a child-safety concern, may be hidden automatically until it is reviewed
- Human review: Pito's moderators may review reported or flagged content and the related account information to decide what action to take
- Evidence: reported content is kept for at least 14 days, and content we hide is kept for 90 days, in private storage (including storage located in the European Union), so that decisions can be checked and appealed. Material escalated as suspected child sexual abuse is kept securely for as long as needed by the authorities and the law
- Enforcement records: warnings, restrictions and bans, and the device identifiers used to enforce device bans, are kept while needed to enforce them. If an Account was banned, we may keep its sign-in email address after the Account is deleted, so that the ban cannot be escaped by starting again
- Authorities: we report confirmed child sexual abuse material to the NCMEC CyberTipline and to relevant authorities, and we may disclose information where required by law or necessary to protect someone's safety (see our Child Safety Standards)
12. In-App Purchases, Gifts & Rewards
Pito offers optional purchases of Pito Coin packs. Pito Coins can then be spent on cosmetics, chat styles, gifts, custom friend codes, streak restores, or a fixed-term Pito Plus membership. Every game is free to access; purchases are not stakes or entry fees and no balance can be wagered or cashed out. Real-money purchases are processed by the Apple App Store or Google Play using your store account.
- We never see your payment details: card numbers, bank information, and billing addresses are handled by Apple and Google. Pito does not receive, store, or have access to this information
- Purchase verification: after a purchase, we verify the store receipt with Apple/Google to confirm it is genuine, and we store a transaction record (such as a product identifier, store transaction ID, and timestamp) tied to your account to prevent fraud and to deliver what you bought
- Entitlements: we record what you are entitled to (for example, an active Pito Plus membership and its expiry) so your benefits work across your devices
- Pito Coins balance & ledger: we keep your Pito Coins balance and a ledger of how coins were earned, purchased, gifted, spent, awarded, or redeemed, so the in-app economy is accurate and disputes can be resolved
- Gifts and gift codes: if you send a gift or redeem a voucher/gift code, we record the related transaction so the recipient receives the item and codes cannot be reused. Gifts you send under your name are shown to the recipient; anonymous gifts hide your name from them
- Supporters and weekly awards: gifts sent under your name are used to show a person's top supporters on their profile (up to three people, from the last 90 days) and to calculate the weekly gifter board, which shows the top six players' usernames and places to other players in Spotlight. Anonymous and declined gifts are never used for either. We record award results and the rewards paid
- Invite-a-friend: if you enter someone's friend code or invitation link, we record who invited whom and when, and before paying the reward we check the new Account's activity (such as the number of ranked games played) and whether the two Accounts share a device, to prevent fake referrals
Refund requests are handled through the applicable App Store. Pito Plus does not auto-renew as a separate real-money subscription; it lasts for the period bought with Pito Coins. Store refund/reversal notifications may cause the corresponding Pito Coins or entitlement to be removed.
13. Push Notifications
If you allow notifications, we use them to alert you about things like game invites, your turn in an online match, chat messages, gifts, friend requests, likes, comments and mentions in Spotlight, friends' birthdays, weekly award results, streak reminders, Pito Plus expiry reminders, and important account updates.
- Push notifications are delivered through Firebase Cloud Messaging. We store a device push token with delivery settings and technical details such as platform, device model, OS version, and App version
- You can turn notifications off at any time in your device settings, and some types (such as Spotlight activity) can also be turned off inside the App; doing so does not affect your ability to use the App
- We do not include sensitive personal data in notification payloads beyond what is needed to take you to the relevant screen
14. Crash Diagnostics
Firebase Crashlytics may automatically collect stack traces, relevant App state, device and OS metadata, an installation identifier, and developer-provided diagnostic logs or keys. A report may be linkable to an Account or session when we deliberately attach an identifier for debugging. Crash diagnostics can be sent even when you are not signed in and are used for reliability, security, and troubleshooting.
15. Profile & Cosmetic Data
Your account profile includes optional personalization that is stored with your account, and some of it is shown publicly to other players:
- Profile basics: your username, friend code, optional profile picture, optional Instagram handle, and online status
- Cosmetics: any cosmetic items you own or have equipped — such as avatar frames, couple frames, name styles/colors, profile-card backgrounds, chat bubble styles, a "verified" badge, and other unlockables — are stored with your account and displayed alongside your profile in games, leaderboards, Spotlight, and chat
- Verification status: if you have an active Pito Plus membership or verified status, the related badge and benefits are reflected on your profile until that status lapses
Cosmetic ownership is recorded so your items persist across your devices. This data contains no full card or bank details and is removed after permanent Account deletion.
16. Purpose of Data Use
Primary: Providing game and social services, saving progress, enabling features (hints, store, chat, Spotlight), preserving settings, displaying game history.
Safety: Applying age-based protections, filtering and checking content, handling reports, and preventing harassment, exploitation, fraud, and ban evasion.
Technical and security: Improving performance, fixing bugs, preventing data loss, validating purchases and scores, enforcing bans, detecting fraud or cheating, and protecting Accounts and infrastructure.
First-party analytics: For signed-in users, Pito may store session, economy, purchase, notification, and button-interaction events together with user ID, session ID, screen context, platform, App version, and basic OS information. High-volume screen-view and game-start/game-end events are currently dropped. Events queue locally and are uploaded only when an authenticated session is available and analytics is enabled by App/server settings.
Educational: Supporting Kurdish language learning and promoting Kurdish culture.
Advertising: Pito does not give Account profile data, age, chat content, or Spotlight content to advertisers. The ad SDKs described below process device/network identifiers, consent signals, approximate location inferred from network information, and ad interactions to deliver, measure, secure, and—where permitted—personalize ads.
17. Legal Basis for Processing
Depending on your location and the activity, we rely on consent, performance of our agreement with you, legitimate interests, and legal obligations or protection from fraud and harm:
- Consent: when you make an optional choice that requires consent, such as an ad/tracking choice, uploading a profile picture, or sharing content with "Everyone" — and, for children, the consent of a parent or guardian where the law requires it
- Contract: to provide the Services you request under our Terms
- Legitimate interests: to operate, secure, and improve the App, keep the community safe, and prevent abuse, balanced against your rights
- Legal obligation / vital interests: to comply with law, to report child sexual abuse material, and to prevent fraud, cheating, and harm
Where processing relies on consent, you may withdraw it through the available App, provider, or device control, or by contacting us. Withdrawal does not affect processing that was lawful before withdrawal.
18. Third-Party Services
We do not sell personal data. We use the following providers to operate, secure, support, and fund the App:
- Apple and Google — App distribution, Sign in with Apple/Google, in-app payment processing, purchase receipts, refunds, and platform security. Pito does not receive full card or bank details
- Supabase — authentication, the primary database, first-party analytics, server functions, and Storage. The primary project is in Sydney, Australia
- Oracle Cloud and self-hosted services — game, chat/WebSocket, image-checking, moderation, and operational services. Logs can contain user IDs, game/conversation IDs, actions, timestamps, device/app context, and error details needed for security, fair play, delivery, and debugging
- Cloudflare — R2 storage and content delivery for chat media, voice messages, profile pictures, stories, post photos, stickers, and moderation evidence (including a private storage location in the European Union), and network protection
- Firebase Crashlytics and Firebase Cloud Messaging (Google) — crash diagnostics and push delivery as described above
- Google Mobile Ads / AdMob — banner and rewarded ads, consent management, delivery, measurement, fraud prevention, and personalization when permitted
- Meta Audience Network — an AdMob mediation/bidding partner that may receive an ad request and related device, network, consent, and interaction data when selected by AdMob
- TikTok (TikTok App Events SDK) — advertising measurement and attribution. When Pito advertises on TikTok, the SDK reports app events (installation, app launch, and return visits) together with advertising or app-scoped identifiers, IP address, and device/App information, so we can tell which advertising led to an install. Pito does not send your name, email address, phone number, chat content, voice recordings, or photos to TikTok
- KLIPY — GIF and sticker search. The search text and technical request information are sent to KLIPY; Pito does not intentionally include your Account identity in the search request
- LiveKit (self-hosted) — real-time voice transport during supported calls or matches. Pito does not intentionally record or store the real-time audio stream
- Apple App Attest, Google Play Integrity, and Talsec/freeRASP — device/app integrity and tamper signals used to protect Accounts, scores, purchases, and the service
- Vercel — hosting of the pito.games website
- Google Workspace, Instagram and TikTok — if you contact us by email or by messaging our Instagram or TikTok accounts, those services process your message under their own policies, and our support team may record your friend code and the details you send in our internal support tools
These providers process data under their own terms and privacy policies. Pito Plus suppresses ads in the App, but does not retroactively delete information previously processed by an ad provider.
19. International Data Transfers
Pito is operated from Iraq and uses providers in multiple countries. The primary Supabase database and Storage are in Sydney, Australia; moderation evidence is kept in the European Union; edge functions, authentication, content delivery, advertising, crash, security, App Store, website, and support services may process data in other regions, including the United States. We use provider contractual, organizational, and technical safeguards appropriate to the service and applicable law.
20. Public Information & Others' Conduct
Some information is public by design and is shown to other users: your username, profile picture, friend code, Instagram handle (if you add one), online status, scores, ratings, badges, anything you share with "Everyone" in Spotlight, and — depending on your choices — your birthday cake, age, gender, place, top supporters and weekly-board place.
- Once information is public, it may be viewed, copied, screenshotted, or re-shared by others — both inside and outside the App
- We cannot control how others use your Public Information, and we are not responsible for the conduct of other users
- If someone misuses your information or photos, report it in the App or to pito@pito.games and we will review and, where appropriate, act
21. Leaderboards
If you have an Account, casual scores and online ratings may be publicly visible. Leaderboards and linked profile sheets may show username, profile picture, score/rating, rank, badges, achievements, selected cosmetics, and other public profile details. Authentication email and payment information are not displayed.
22. Profile Pictures
You can upload a profile picture from your camera or gallery. The image may be resized or compressed, is checked automatically on our own servers for prohibited content, and is stored on Supabase Storage and Cloudflare.
- Your profile picture is public: it is shown to other users of the App on leaderboards, your profile, chat, Spotlight, and online games
- Other users can see it and — like any image on a screen — may screenshot or copy it, which we cannot prevent
- Only upload a picture you are comfortable being public; if you do not want your photo to be public, do not set it as your profile picture
- You can delete or change it anytime
- Permanent Account deletion queues the profile photo for removal; backups or deletion queues may take additional time
23. Website, Cookies, Advertising and Device Identifiers
Website: the pito.games website does not use advertising or analytics cookies. It stores your language choice in your browser's local storage. Our hosting provider (Vercel) processes technical request information such as IP address and browser type to deliver the site and protect it. The homepage shows our latest TikTok and Instagram posts; to display them, your browser loads their preview images from TikTok's and Instagram's servers, which can receive your IP address and browser information.
The mobile App uses SDKs and identifiers rather than browser cookies.
- Advertising: Google Mobile Ads and its mediation partners may process advertising or app-scoped identifiers, IP address, device/OS/App information, approximate location inferred from IP, consent choices, and ad views, clicks, or reward events. The exact data depends on device settings, region, consent, provider configuration, and whether an ad is requested
- Consent and choices: Google UMP requests consent where required. On iOS, Pito asks through App Tracking Transparency before the IDFA can be accessed. If permission is denied, IDFA is unavailable and the App requests non-personalized advertising; platform and in-ad privacy controls may provide more choices. Apple and Google family controls limit advertising tracking on children's devices
- Advertising measurement: when Pito runs advertising campaigns on TikTok, the TikTok App Events SDK reports installation, launch, and return-visit events together with advertising or app-scoped identifiers, IP address, and device/App information, so we can measure which campaigns work. On iOS this is subject to App Tracking Transparency: if permission is denied the IDFA is unavailable and measurement falls back to Apple's aggregated SKAdNetwork reporting. On Android it uses the advertising ID and the Google Play install referrer
- Device identifier: we record an App-specific device identifier together with your device model, operating-system version, and App version. We use it to associate notification/call delivery tokens, enforce bans (including device bans), check invite-a-friend rewards, detect cheating or fraud, and protect the Service. Pito does not use this identifier to track you across unrelated apps or websites
- Location: Pito does not request precise GPS location. Service providers can infer an approximate city/region from IP address as part of ordinary network and ad processing
24. Content Updates
Pito may download updated game content (word lists, impostor words, bomb prompts) from secure servers. These downloads:
- Use HTTPS only
- May be requested automatically so the App can receive current content or configuration
- Normally fall back to bundled content when the network is unavailable
- Expose ordinary network information, such as IP address and technical request headers, to the hosting provider; the content request is not intended to contain chat, profile, or gameplay content
25. Data Security
- Data encryption in transit and at rest
- Access controls and authentication, including short-lived links for private media
- Security monitoring, integrity checks, and network protections
- Automated backups
However, no method of transmission or storage over the internet is completely secure. While we work hard to protect your data, we cannot guarantee absolute security, and you provide information at your own risk. If a data breach affects your personal data, we will take reasonable steps to address it and notify you or the competent authorities where required by law.
26. Data Retention
- Local data: Stored until cleared by an App control, operating-system cleanup, or uninstallation. Requesting Account deletion also wipes Pito's local account/cache data on that device after the server accepts the request
- Account, profile, social, chat, entitlement, and active game data: Kept while needed to provide the Account and feature, then deleted or de-identified after permanent Account deletion, subject to the exceptions below
- Stories and posts: as described in Section 10 — stories are deleted within about a day after they expire; posts are kept until you delete them or your Account, then deleted about 24 hours later
- Drawing-game records: as described in Section 6
- Reports and moderation evidence: as described in Section 11 — reported content at least 14 days, hidden content 90 days, and child-safety escalations as long as the law requires
- First-party analytics events: Current server cleanup retains a short rolling history of roughly two to three months; aggregated, non-user-identifying statistics may be kept longer
- Expiring messages/media: Removed according to the selected timer or view-once workflow plus operational deletion delays and retries. Other users may keep screenshots or copies
- Completed games, financial, receipt, fraud, safety, ban, and audit records: May be kept as long as reasonably necessary for ratings and game integrity, accounting, refunds, disputes, security, abuse and ban-evasion prevention, and legal duties. On permanent deletion, records designed for historical integrity are severed from the user's identity or otherwise de-identified where practicable
- Logs, backups, and provider records: May persist for limited operational, security, backup, or legal periods before being overwritten or deleted under provider schedules
27. Your Rights
- Access: View your data
- Rectification: Correct inaccurate information
- Erasure: Delete your data (via account deletion in Settings, or by deleting individual posts, stories, comments and messages)
- Restriction: Limit processing
- Portability: Receive your data
- Objection: Object to processing
- Consent: Withdraw consent you gave, for example by changing your privacy settings
These rights depend on applicable law and may have exceptions. To request access, portability, correction, restriction, or objection, email pito@pito.games from the address linked to your Account (a parent or guardian may make a request for their child). We may verify identity before responding, and we aim to respond within 30 days. You may also complain to your local data-protection authority.
28. Account & Data Deletion
You can delete your Account in Settings and choose when:
- After 30 days: the Account is immediately deactivated, signed out, hidden from other users, and scheduled for permanent deletion after 30 days. During that period, signing in with the same Google or Apple identity lets you restore the Account or delete it permanently at once
- Right now: there is no recovery period and it cannot be undone. Your sign-in, email and username are released immediately so they can be used again, and the rest of the Account's data is then permanently removed by the deletion process
Either way, the request also wipes local Pito account/cache data on the requesting device. Permanent deletion removes user-linked profile, social, Spotlight, active-game, chat, media, balance, entitlement, and authentication data. Some completed-match, financial/audit, safety and ban records are retained only as described in Section 26. Limited backups, logs, and provider deletion queues may take longer to expire. More detail: pito.games/delete-account.
If you cannot sign in, email us at pito@pito.games from the address linked to your account and we will process your deletion request.
29. Children's Privacy & Parental Rights
Pito is a general-audience app for Kurdish speakers. Children under 13, or under the age at which they can agree to online services where they live (in some countries this is up to 16), may use Pito only with the permission of a parent or legal guardian, who is responsible for their use and purchases.
Every Account is asked for a date of birth, and we use the declared age to protect younger players (Section 4): for example, Accounts under 13 cannot use Spotlight, and players aged 13 to 17 have extra protections from adults they do not know. Profile details such as age, gender and place are hidden from other players by default for everyone. A child's profile information (such as their date of birth) is never used for advertising and never shared with partners except as anonymised aggregate statistics that cannot identify anyone. We may add further age-based protections at any time.
Parents and guardians can at any time:
- ask us what information we hold about their child, and ask us to correct or delete it;
- ask us to remove their child's profile picture or other content, or to close their child's Account;
- control purchases with Apple's Ask to Buy or Google Play's family and purchase controls;
- report anything that concerns them in the App or to us.
Contact pito@pito.games with the child's friend code (shown under their name in the App). We may ask for information to confirm that you are the child's parent or guardian. If we learn that a child's information was collected without the permission required where they live, we will delete it or close the Account.
30. Changes to This Policy
We will update the date above when this Policy changes and provide additional notice when reasonably appropriate or legally required. If a change requires consent, we will request it before that processing.
31. Contact
Email: pito@pito.games
Child safety: see our Child Safety Standards
Supported languages: Kurdish (Sorani and Badini), Arabic, English