Legal Hub
Dino AI

Privacy Policy - Dino AI

Effective as of July 4, 2026

This privacy policy is applicable to the Dino AI app (hereinafter referred to as "Application") for mobile devices, which was developed by STC Studios UG (hereinafter referred to as "Service Provider") as a Freemium service. This service is provided "AS IS".

1. What information does the Application collect automatically?

The Application and our essential third-party service providers (such as Google Firebase Analytics or Crashlytics) may collect certain information automatically to ensure the service functions correctly. This includes, but is not limited to, the type of mobile device you use, the IP address of your mobile device, your mobile operating system, device region/locale settings (e.g., to comply with regional legal requirements), and crash reports.

Furthermore, to provide core functionality and save your game progress and chat history without requiring an account, the Application generates an anonymous Firebase Authentication User ID.

2. User Authentication

The Application does not require a traditional registration process to be used in its basic version. If you choose to upgrade or create an account later, we solely use Google Sign-In for authentication and only collect the basic profile information provided by your Google account (such as your email address).

We do not collect, process, or store passwords. Firebase Authentication only processes secure authentication tokens provided by Google and the email address associated with your Google account.

The Service Provider may also use the information you provided them to contact you from time to time to provide you with important information, required notices and marketing promotions.

Registration with the Service Provider is not mandatory. However, bear in mind that you might not be able to utilize some of the features offered by the Application unless you register with them.

3. Does the Application collect precise real time location information of the device?

This Application does not gather precise information about the location of your mobile device (e.g., GPS data). However, please note that our third-party analytics providers may derive your general geographic region (such as your country or city) from your device's IP address.

4. What information does the Application obtain and how is it used?

Processing of voice, image, and text inputs via AI

The core functionality of the Application relies on interactive AI powered by Gemini models via Google Cloud Vertex AI. To provide this service, the Application processes user inputs as follows:

  • Voice and Image Processing (No Storage): When a user uses the voice input feature or uploads an image, the audio recording and image data are transmitted securely via our backend (Google Cloud Functions) to Google Cloud Vertex AI. The AI processing occurs exclusively on servers within the European Union. Vertex AI offers enterprise-grade security and holds multiple rigorous ISO certifications (e.g., ISO/IEC 27001, 27017, 27018), ensuring strict data protection. We do not store or retain these audio recordings or image files. They are processed in real-time solely to transcribe the speech and generate the AI's response and are discarded immediately after the processing is complete.
  • Text Transcription and AI Responses: The transcribed text of the user's spoken input and the resulting text response generated by the AI are temporarily processed to facilitate the conversation.
  • Third-Party Processing: The AI processing is handled by Google Cloud services. Google processes this data in accordance with their strict enterprise data processing agreements, ensuring that your inputs are not used to train Google's public AI models.
  • Data Minimization and PII Filtering: In accordance with the principle of data minimization and 'Privacy by Design', all transcribed text from user inputs is automatically processed through the Google Cloud Data Loss Prevention (DLP) API. This service proactively filters and redacts Personally Identifiable Information (PII) before it is stored in the Google Cloud Firestore database. Furthermore, our AI system prompts are strictly configured to abstract any personal details (such as names or locations) and prevent the AI from repeating or acknowledging them in its responses.

5. Legal Basis for Processing (EU/EEA and UK Users)

If you are a resident of the European Economic Area (EEA) or the United Kingdom (UK), our legal basis for collecting and using the personal information described above depends on the personal information concerned and the specific context in which we collect it.

  • Consent (Art. 6(1)(a) GDPR): We process data based on the explicit verifiable parental consent obtained during the onboarding process to provide the core AI features to children.
  • Performance of a Contract (Art. 6(1)(b) GDPR): Processing is necessary to fulfill our Terms of Service (e.g., providing the game, managing in-app purchases).
  • Legitimate Interests (Art. 6(1)(f) GDPR): We process data for our legitimate interests, such as ensuring security, analyzing usage to improve the App, and preventing fraud, provided these interests are not overridden by your data protection rights.

6. Game Data and Progress

To enhance the user experience, the Application saves your game progress both locally and securely on our cloud database (Google Firestore). This includes data such as your current score, unlocked achievements, in-game currency (e.g., 'bones'), and recent game targets. This data is tied to your anonymous Firebase User ID or your authenticated Google account to ensure your progress is preserved across sessions.

7. Where and how is your conversational data stored?

To allow context-aware conversations, we store the text-based chat history (the transcribed questions and the AI's text responses).

  • Encryption: All chat history data is encrypted at rest to ensure high security.
  • European Servers: This encrypted text data is securely stored using Google Cloud Firestore. We have configured our database servers to be located exclusively in Finland (europe-north1), ensuring compliance with strict European data protection standards.

8. In-App Purchases and Billing

The Application offers in-app purchases and auto-renewing monthly subscriptions, which may include a free trial period. All payment processing is securely handled directly by Google Play Billing. The Service Provider does not process, collect, or store your credit card information, bank details, or specific billing addresses. We exclusively receive and process anonymous purchase tokens and the current status of your purchases or subscriptions (e.g., active, trial, or expired) via secure server-to-server notifications to unlock and maintain your access to premium features within the Application.

9. Do third parties see and/or have access to information obtained by the Application?

The Application transmits certain data to trusted third-party service providers necessary to provide our core features. We do not sell your personal data to third parties for marketing purposes. We share data with the following essential service providers:

  • Google Cloud & Firebase (including Analytics, Crashlytics, DLP API, Firestore, Functions, and Authentication): Used for database hosting, server logic, user authentication (anonymous and via Google Sign-In), app usage statistics, analysis of crashes, and filtering and redaction of Personally Identifiable Information (PII).
  • Google Cloud Vertex AI (Gemini Models): Used to power the AI conversational features. User text inputs, audio recordings, and uploaded images are processed securely by Vertex AI in the European Union in real-time to generate responses. Vertex AI adheres to strict enterprise data processing agreements. (As stated above, audio and image files are discarded immediately after processing).
  • Google Play Services: Used for app distribution, subscriptions, and billing.
  • Kids Web Services (KWS) Parental Verification platform, provided by Epic Games: Ensures legally compliant verification of parental consent in accordance with international children's privacy laws (such as COPPA and GDPR-K).
  • Privacy Policy Links of Third-Party Providers:
  • Google Play Services: https://www.google.com/policies/privacy/
  • Firebase: https://firebase.google.com/support/privacy/
  • Google Cloud: https://cloud.google.com/terms/cloud-privacy-notice
  • Kids Web Services: https://www.kidswebservices.com/privacy-policy and https://www.kidswebservices.com/data-processing-addendum

10. Legal Disclosures

The Service Provider may disclose User Provided and Automatically Collected Information:

  • as required by law, such as to comply with a subpoena, or similar legal process;
  • when they believe in good faith that disclosure is necessary to protect their rights, protect your safety or the safety of others, investigate fraud, or respond to a government request;
  • with their trusted services providers who work on their behalf, do not have an independent use of the information we disclose to them, and have agreed to adhere to the rules set forth in this privacy statement.

11. What are my opt-out rights & In-App Privacy Controls?

You can halt all collection of information by the Application easily by uninstalling the Application. You may use the standard uninstall processes as may be available as part of your mobile device or via the mobile application marketplace or network.

In-App Privacy Controls: We provide you with direct control over your conversational data within the Application's Privacy Screen. You have the right and ability to:

  • Pause History Tracking: You can disable the continuation of your conversation history at any time. When paused, the AI will not remember previous interactions in future sessions.
  • Delete Conversation History: You can permanently delete your entire chat history with the AI directly from the app. Once deleted, this data is removed from our servers and cannot be recovered.

12. What is the data retention policy & How can you delete your information?

The Service Provider strictly adheres to the principle of data minimization and only retains data for as long as necessary to provide the core functionalities of the Application.

  • Chat History (24h TTL): All conversational data (transcribed questions and AI responses) is strictly temporary. It is automatically and permanently deleted from our servers after 24 hours via a Time-To-Live (TTL) mechanism.
  • Game Progress and Authentication Data: Anonymous Firebase User IDs, subscription statuses, compliance status, usage statistics and game progress data are retained to ensure the Application functions properly across sessions. This data is kept until you explicitly request its deletion.

13. How can you delete your information?

If you would like the Service Provider to delete your game progress, account data, or any other provided data, please contact us at support@stc-studios.com and we will respond and execute your request in a timely manner. Please note that deleting certain data will reset your game progress and may prevent access to premium features.

14. How does the Application address children's privacy?

The Application is designed to be engaging and safe for children under the age of 13. However, complying with international children's privacy laws (such as COPPA), we require verifiable parental consent before a child can access the Application.

For most users, during the initial onboarding process, an adult must successfully complete an 'Age Gate' challenge. By passing this gate, parents or legal guardians acknowledge and explicitly consent to this Privacy Policy and the data processing activities described herein.

However, to comply strictly with United States privacy laws (such as COPPA), if the device's system region or locale indicates the user is located in the United States (US), the local Age Gate is bypassed. Instead, these users are mandatorily required to use the Kids Web Services (KWS) Parental Verification platform, provided by Epic Games, as a trusted third-party service.

For users outside the US who do not pass the local Age Gate, the KWS platform is also utilized as a fallback. This mandatory process ensures legally compliant verification of parental consent in accordance with international children's privacy laws (such as COPPA and GDPR-K) before any data collection occurs or access to the Application is granted.

If we discover that personal data from a child has been collected without the requisite parental consent, we will take immediate steps to delete that information. Parents can contact the developer at any time to review, request the deletion of, or prohibit further collection of their child's account and associated data.

15. How is your information kept secure?

The Service Provider is concerned about safeguarding the confidentiality of your information. The Service Provider provides physical, electronic, and procedural safeguards to protect information we process and maintain. For example, we limit access to this information to authorized employees and contractors who need to know that information to operate, develop or improve their Application. Please be aware that, although we endeavour to provide reasonable security for information we process and maintain, no security system can prevent all potential security breaches.

16. How will you be informed of changes to this Privacy Policy?

This Privacy Policy may be updated from time to time for any reason. The Service Provider will notify you of any changes to the Privacy Policy by updating this page with the new Privacy Policy. You are advised to consult this Privacy Policy regularly for any changes, as continued use is deemed approval of all changes.

This privacy policy is effective as of 2026-07-04.

17. How do you give your consent?

By passing the parental verification process and using the Application, you are giving your explicit consent to the Service Provider's processing of your information as set forth in this Privacy Policy now and as amended by us. "Processing" in the context of this mobile Application means interacting with data on your mobile device, including the use of local storage, device identifiers, and anonymous user IDs, as well as collecting, transmitting, temporarily storing, deleting, using, combining, and disclosing information strictly as outlined in this policy.

18. Your Data Protection Rights (EU/EEA and UK Users)

Under the General Data Protection Regulation (GDPR) and the UK GDPR, you have the following rights regarding your personal data:

  • The right to access: You have the right to request copies of your personal data.
  • The right to rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
  • The right to erasure: You have the right to request that we erase your personal data, under certain conditions.
  • The right to restrict processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
  • The right to object to processing: You have the right to object to our processing of your personal data, under certain conditions.
  • The right to data portability: You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
  • The right to withdraw consent: If we are processing your personal information based on your consent, you can withdraw your consent at any time.

19. Exercising GDPR Rights & Supervisory Authority

To exercise any of these rights, please contact us at support@stc-studios.com. You also have the right to complain to a Data Protection Authority about our collection and use of your personal information.

20. Your Privacy Rights in the United States (including California CCPA/CPRA)

If you are a resident of California or other US states with applicable privacy laws, you have specific rights regarding your personal information:

  • Right to Know and Access: You can request information about the categories of personal data we have collected, the sources, the purpose of collection, and the specific pieces of data.
  • Right to Delete: You can request the deletion of your personal data.
  • Right to Correct: You can ask us to correct inaccurate personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.
  • Notice of No Sale: We do not sell your personal information to third parties, nor do we "share" it for cross-context behavioral advertising purposes.
  • Additional COPPA Rights for Parents: In accordance with the Children's Online Privacy Protection Act (COPPA), parents or legal guardians can review their child's personal information, direct us to delete it, and refuse to allow any further collection or use of the child's information.

21. Imprint & Contact Information

Responsible for this application and this privacy policy:

STC Studios UG

Am Langwieder Bach 21 C

81245 Munich

Germany

If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at support@stc-studios.com.

This privacy policy page was generated with help of App Privacy Policy Generator: https://app-privacy-policy-generator.nisrulz.com/

STC STUDIOS UG (haftungsbeschränkt)Questions regarding this policy? Contact Support →