Craftia Privacy Policy
Effective date and last updated: July 28, 2026
Craftia is operated by James Jung (“Craftia,” “we,” “us,” or “our”). This Privacy Policy explains how Craftia collects, uses, discloses, retains, and protects information when you use the Craftia application, its backend services, and Craftia content-sharing pages (together, the “Service”).
For privacy questions or requests, contact [email protected].
1. Information we process
The information processed depends on the features you use.
Account and profile information
When you sign in with Google, Google Sign-In and Firebase Authentication process your Google account credentials and authentication tokens. Craftia receives or maintains information such as:
- Firebase user ID (UID), sign-in provider, account email address, display name, and profile photo URL;
- the Craftia display name, normalized display name, profile description, selected profile image, title, role, account creation/update timestamps, and account or moderation status; and
- Firebase ID tokens used to authenticate requests. We do not receive or store your Google password.
Your email address is not displayed publicly. A creator UID may be included in public content records or responses as an internal creator identifier, even though Craftia does not present it as ordinary profile text. The other profile information described in Section 3 may also be visible to users.
Age group and consent choices
Craftia asks for an age to assign the user to a child, teen, or adult group for advertising and consent settings. The exact age entered is used momentarily to calculate the group and is not saved by Craftia. The resulting age group and verification time are stored on the device. This locally stored age group is also used to determine whether content publishing is allowed: only adults aged 18 or older may submit or publish user-generated content. Craftia sends child-directed or under-age-of-consent signals, rather than the exact age, to Google Mobile Ads and the Google User Messaging Platform (“UMP”). Google may also process the consent choices made through UMP.
Uploaded content and files
When you submit or upload content, we process the files and information you choose to provide, including:
- source files such as maps, skins, add-ons, texture-related files, archives, or other supported content;
- selected preview images, thumbnails, filenames, file types, sizes, storage paths, and upload metadata;
- depending on the submission or publication workflow, title, description, category, game version, locale, price or access settings, and other content metadata;
- your UID, uploader profile snapshot, submission status, review/moderation information, and timestamps.
Craftia accesses only the files or images that you choose through the system picker or an upload flow. Uploaded files are stored using Cloud Storage for Firebase. Approved content, its preview images, and the public metadata described in Section 3 may be made public.
Activity, community, and entitlement information
We process activity needed to provide Service features, including:
- likes, saves, libraries, downloads, comments or other user-provided community activity;
- content purchases, diamond balance and transactions, VIP status and expiration, daily rewards, rewarded-ad sessions and reward outcomes;
- search terms sent to Firestore to retrieve matching public content. Craftia does not intentionally save these as a user-linked search-history record; and
- content identifiers, timestamps, counters, and feature state needed to sync these items across devices.
Purchase and subscription information
Purchases are processed by Google Play. Craftia and its Firebase backend process information needed to verify purchases and grant entitlements, including product ID, base-plan ID, order ID, purchase status and time, region code, subscription state and expiration, acknowledgment status, and an obfuscated account identifier. A purchase token is transmitted securely to our backend and the Google Play Developer API for verification; Craftia stores a cryptographic hash of that token rather than the raw token. We do not receive or store full card, bank-account, or other payment-instrument details.
Reports and support
If you report content, we process the reported content ID and metadata, reason, optional details, locale, time, your UID, and your Google account email address and display name so that we can review the report and prevent abuse. If you report or block a user, we process your UID, the target user's UID and available display name, the related content ID, report reason, locale, timestamps, and server-owned anti-abuse counters as applicable; a block record is used to hide that creator's content from you. If you contact us by email, we process your email address, message, attachments, and the information needed to answer or verify your request.
Advertising, diagnostics, device, and network information
The Service and its providers may process:
- IP address and general location inferred from the IP address; Craftia does not collect precise GPS location;
- device model, operating system and version, app version, language/locale, network state, app or installation identifiers, advertising identifiers where permitted, and request timestamps;
- app launches, taps, ad impressions, ad video views, and other interactions used to deliver ads, measure performance, and prevent fraud;
- crash stack traces, exception messages, crash time, process/app state, device specifications, Crashlytics Installation UUID, Firebase installation ID, and related diagnostic data in release builds; and
- server request, security, and operational logs that may contain IP address, request metadata, identifiers, and error information.
Crashlytics collection is disabled in Craftia debug builds and enabled in release builds.
Craftia also uses the google_fonts package. When a requested font is not already bundled with or cached by the app, the package may retrieve it from Google Fonts. That request discloses the IP address, requested font URL, and HTTP/device headers needed to deliver the font.
AppsFlyer deep links
Craftia uses AppsFlyer to resolve links that open shared Craftia content, including deferred links that continue after installation. The SDK may process IP address, device and app information, AppsFlyer-generated identifiers, link clicks, installation information, launches, and sessions needed for those links.
Craftia configures AppsFlyer to disable advertising-identifier collection and, on Android, App Set ID collection. We do not set a Craftia customer user ID, send custom in-app events or advertising revenue to AppsFlyer, or share AppsFlyer data with integrated advertising partners. These AppsFlyer restrictions do not disable identifiers that Google Mobile Ads may process for advertising as described above.
2. Why we process information
We use information to:
- authenticate users, maintain accounts and profiles, and provide requested Service features;
- store, review, publish, deliver, and share content;
- sync likes, saves, libraries, downloads, balances, purchases, rewards, and subscriptions;
- verify Google Play transactions, provide paid entitlements, prevent duplicate claims, and detect fraud or abuse;
- serve and measure ads, record consent choices, and verify rewarded-ad results;
- resolve direct and deferred content links;
- moderate content, investigate reports, enforce our terms, protect users, and comply with law;
- diagnose crashes, maintain security and reliability, answer support requests, and improve the Service.
Where applicable data-protection law requires a legal basis, we rely on:
- performance of a contract to provide the account and features you request;
- legitimate interests in security, fraud prevention, moderation, support, and Service improvement, balanced against your rights;
- consent for personalized advertising or other processing where consent is required; and
- legal obligations and the establishment, exercise, or defense of legal claims.
You may withdraw consent through the available privacy controls. Withdrawal does not affect processing already lawfully completed.
3. Information visible to other people
Depending on how you use Craftia, the following may be public:
- your Craftia display name, selected profile image, and title;
- a pseudonymous creator UID or similar internal creator identifier associated with published content;
- content you publish, including source/download files, previews, thumbnails, title, description, category, version, locale, price/access status, and uploader profile snapshot;
- public counts such as likes or downloads; and
- information included in a content link that you choose to share.
Your email address, authentication tokens, raw or hashed purchase tokens, private balances, private libraries, and report details are not intentionally made public. Do not upload personal information that you do not want others to see.
4. Providers and recipients
We disclose information only as needed for the purposes described in this Policy:
- Google Sign-In, Google Play Services, and Firebase — authentication, Firestore database, Cloud Functions, Cloud Storage, Firebase Hosting, and Crashlytics. These services process account identifiers, Service data, uploaded files, network information, and diagnostics as applicable. See the Google Privacy Policy and Firebase Privacy and Security information.
- Google Play Billing and Google Play Developer API — payment processing, purchase/subscription verification, entitlement delivery, and fraud prevention. See the Google Payments Privacy Notice and Google Privacy Policy.
- Google Mobile Ads (AdMob) and UMP — ads, consent management, measurement, and fraud prevention. Depending on consent, device settings, and applicable law, Google Mobile Ads automatically collects and shares IP address, general location derived from IP, product interactions, diagnostic data, and device/account identifiers for advertising, analytics, and fraud prevention. See Google’s AdMob privacy information and Google Privacy & Terms.
- Google Fonts — runtime delivery of fonts that are not bundled or cached. Google receives network request information such as IP address, the requested URL, and HTTP/device headers and states that Google Fonts data is not used for targeted advertising. See Google Fonts privacy and data collection information.
- AppsFlyer — direct and deferred deep-link operation, subject to the restrictions described above. See the AppsFlyer Services Privacy Policy and user-level data retention information.
- Backblaze B2 and Cloudflare — storage and delivery of public Craftia content through
cdn.mcpecraftia.com. When a file or image is requested, these providers may process the requested URL or object path, IP address, HTTP/device headers, cache and transfer information, and security logs. See the Backblaze Privacy Notice and Cloudflare Privacy Policy. - Email service providers, including Google/Gmail — delivery and retention of support, privacy, and deletion-request emails and attachments that you choose to send. See the Google Privacy Policy, or the policy of the email provider you use.
We may also disclose information when required by law, to respond to a lawful government request, to investigate fraud or security incidents, to protect rights or safety, or as part of a business transfer subject to appropriate safeguards.
We do not sell personal information for money. Advertising data may nevertheless be considered “sharing” or “targeted advertising” under some laws; use the privacy choices described in Section 7 where available.
5. Retention and deletion
We keep account, profile, activity, entitlement, report, and upload data while your account is active and for as long as needed to provide the relevant feature, resolve disputes, maintain security, prevent fraud, or meet legal obligations.
You can permanently delete your Craftia account from Settings > Delete Account. The server deletes the Firebase Authentication account and user-linked profile, balances and entitlements, likes, saves, libraries, downloads, purchase and reward records, reports, comments, and other private account records handled by the deletion process.
Content already uploaded, including files and images, is not deleted with the account. Craftia removes account attribution from the primary public and submission database records handled by the deletion process, replaces the public uploader with a deleted-user label, and preserves the content for other users. Retained private or legacy records, storage paths, or object metadata may still contain the former UID, original filename, submission identifier, or other upload metadata for content integrity, moderation, and abuse investigation; these values are not intentionally displayed publicly. A deleted account can no longer manage that content. Contact us before deleting your account if you also want us to review deletion of uploaded content and its retained storage metadata.
Deleting Craftia does not cancel an active Google Play subscription. Cancel it separately in Google Play > Payments & subscriptions > Subscriptions. Google Play may retain transaction records under its own legal and retention requirements.
Firebase states that Crashlytics keeps crash reports and associated installation identifiers for 90 days before beginning removal from live and backup systems. AppsFlyer and Google Mobile Ads retain provider-processed data according to their policies and applicable settings. Security logs, backups, and deletion records may remain for limited periods on normal deletion cycles or where law requires retention.
Uninstalling the app stops future app-originated collection but does not delete information already stored on our servers or by providers. Use the in-app deletion control or contact us for a data request.
Account deletion does not automatically erase files already downloaded to the device or all locally cached likes, saves, downloads, libraries, and age-group settings. Remove downloads in the app where available and clear the app’s storage or uninstall the app to remove remaining local data.
6. Security and international processing
We use reasonable administrative and technical safeguards, including authenticated access, Firebase security controls, access restrictions, hashing of purchase tokens, and HTTPS/TLS for data in transit. Firebase states that the Firebase services used by Craftia encrypt applicable customer data at rest. No system can guarantee absolute security.
Craftia and its providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, transfers are made using provider contractual protections or other lawful transfer mechanisms.
7. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or receive a copy of your information; object to certain processing; withdraw consent; and complain to a data-protection authority.
You can:
- update profile information in the app;
- delete the account from Settings > Delete Account;
- open Craftia’s Privacy choices when shown to review available Google UMP advertising choices;
- reset or delete the Android advertising ID through device settings and manage Google ad personalization through Google controls;
- manage or cancel subscriptions in Google Play; and
- request access, correction, deletion, or assistance by emailing [email protected].
We may ask for information reasonably necessary to verify that you control the relevant account. For applicable AppsFlyer deletion requests, we will submit the request to AppsFlyer.
8. Children and teens
Craftia uses an age screen to apply age-appropriate advertising settings. For a child or an unknown age group, Craftia requests child-directed treatment and limits the maximum ad content rating; for a teen, it sends an under-age-of-consent signal. The exact age is not sent to AdMob by Craftia.
If local law requires parental or guardian consent for a child to use account, community, or advertising features that remain available to minors, the parent or guardian must provide that authorization. Regardless of such consent, users under 18 cannot submit or publish user-generated content. A parent or guardian may contact us to review or delete a child’s information. We will take reasonable steps to verify the request.
9. Changes to this Policy
We may update this Policy when the Service, providers, or legal requirements change. We will change the effective date and provide additional notice in the app when a change is material. Continued use after an update is subject to the updated Policy, but we will obtain consent when the law requires it.
10. Contact
Operator and data controller: James Jung / Craftia
Email: [email protected]