🐧 Penguin Privacy Policy
Welcome to Penguin. We value your privacy and are committed to protecting your personal
information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when
you use our mobile app (iOS and Android).
Please read this policy carefully to understand our views and practices regarding your personal
data and how we will treat it.
Effective Date: February 7, 2026
1. Information We Collect
Personal Information
When you create an account and use Penguin, we may collect the following personal information:
- Account Information: Name, email address, nickname, avatar/profile picture
- Demographics: Age, gender
- Authentication Data: Apple User ID (for Apple Sign-In users), Google account
information (for Google Sign-In users)
- Partner Connection: Partner code, partner relationship details, connection date
User-Generated Content
When using Penguin's features, we collect content you create and share:
- Messages & Chat: Text messages exchanged with your partner through the app
- Scribbles & Drawings: Digital drawings you create and send to your partner
- Photos & Videos: Images and videos uploaded as part of daily challenges or shared
puzzles
- Voice Recordings: Audio messages recorded within the app
- Game Data: Tic Tac Toe moves, Wordle games, jigsaw puzzle images
- Question Responses: Answers to daily challenges and topic questions (including "Never
Have I Ever", "Most Likely To", and other relationship questions)
- Mood Data: Your current mood status and mood history
Technical & Usage Information
We automatically collect certain technical information:
- Device Information: Device type, operating system, device identifiers
- Push Notification Tokens: Firebase Cloud Messaging (FCM) tokens for delivering
notifications
- Activity Data: Online status, last seen timestamps, app usage patterns
- Topic Progress: Your progress through question categories
2. How We Use Your Information
To Provide Core Services
- Creating and managing your account
- Connecting you with your partner
- Enabling real-time messaging, scribbles, and content sharing
- Facilitating games (Tic Tac Toe, Wordle, Jigsaw Puzzles)
- Delivering daily challenges and relationship questions
- Syncing mood status with your partner
- Powering home screen widgets
To Improve Our Services
- Enhancing user experience and app functionality
- Analyzing usage patterns to improve features
- Fixing bugs and technical issues
- Developing new features
To Communicate With You
- Sending push notifications about partner activity
- Notifying you of new messages, game invites, or daily challenges
- Sending important service announcements
- Responding to support inquiries
3. Data Protection & Security
Security Measures
We implement robust security measures to protect your personal information:
- Encryption in Transit: All data transfers between your device and our servers are
protected using industry-standard TLS (Transport Layer Security) encryption
- Secure Authentication: Token-based authentication with verified OAuth providers
(Google, Apple)
- Secure Storage: User media files are stored in encrypted AWS S3 buckets with restricted
access
- Access Controls: Limited access to personal data within our organization
Secure Data Transfer
All communications between the Penguin app and our servers use HTTPS with TLS encryption. This ensures that
your personal information, messages, scribbles, and activity data cannot be intercepted or read by
unauthorized parties.
Data Retention
We retain personal information only as long as necessary to:
- Provide you with our services
- Comply with legal obligations
- Resolve disputes
- Enforce our agreements
When you delete your account, we will delete or anonymize your personal data within 30 days, except where
retention is required by law.
4. Sharing Your Information
With Your Partner
The core function of Penguin involves sharing information with your connected partner:
- Messages, scribbles, and media you send
- Your mood status
- Game moves and challenges
- Question answers (shared in the chat context)
- Online/activity status
Third-Party Service Providers
We may share information with trusted third-party services that help us operate the app:
| Service Provider |
Purpose |
Data Shared |
| Google (Firebase) |
Authentication, Push Notifications |
Email, FCM tokens |
| Apple |
Authentication (iOS) |
Apple User ID, email |
| Amazon Web Services (AWS) |
Media Storage |
Uploaded photos, videos, voice messages |
| MongoDB Atlas |
Database Hosting |
All user data (encrypted) |
These providers are contractually obligated to protect your information and use it only for the specified
purposes.
Legal Requirements
We may disclose your information if required by law, such as:
- Complying with a subpoena, court order, or legal process
- Protecting our rights, property, or safety
- Protecting the safety of our users or the public
- Responding to lawful requests from public authorities
5. Your Rights & Choices
Access & Update
You have the right to:
- Access your personal information through your account settings
- Update your profile information (name, nickname, avatar, age, gender)
- View and manage your partner connection
Data Deletion
You can request deletion of your personal data by:
- Contacting us via email at [support email]
- We will process deletion requests within 7 business days
- We will confirm deletion via email
Note: Some data may be retained if required by law or for legitimate business purposes
(e.g., fraud prevention, legal compliance).
Push Notifications
You can control push notifications through:
- Your device settings (iOS/Android)
- The app's notification preferences
Account Deletion
To delete your entire account and all associated data, use the "Delete Account" option in the app settings.
Upon deletion:
- Your profile and personal information will be removed
- Shared content (messages, photos) may remain visible to your partner
- Game history and challenge responses will be deleted
6. Third-Party Authentication
Google Sign-In
If you sign in with Google, we may collect:
- Your Google email address
- Your display name
- Other information you've made publicly available on Google
We use this information solely for authentication and account creation. We adhere to Google's Limited Use
requirements and will not share your Google data with unauthorized third parties.
Apple Sign-In
If you sign in with Apple, we may collect:
- Your Apple User ID
- Your email address (or Apple's private relay email)
- Your display name (if provided)
Apple Sign-In may provide a private relay email address, which we respect and use for account communications.
7. Children's Privacy
Penguin is not intended for children under 13 years of age. We do not knowingly collect personal information
from children under 13. If you are a parent or guardian and believe your child has provided us with personal
information, please contact us immediately, and we will take steps to delete such information.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence,
including India and the United States, where our servers and service providers are located. We ensure
appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect:
- Changes in our practices
- New features or services
- Legal or regulatory requirements
We will notify you of significant changes by:
- Posting the updated policy in the app
- Updating the "Effective Date" at the top of this policy
- Sending a notification through the app (for material changes)
Your continued use of Penguin after any changes indicates your acceptance of the updated Privacy Policy.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please
contact us:
Email: admin@thethousandways.com
Address: Patna, Bihar, India
11. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act
(CCPA):
- Right to Know: Request information about the categories and specific pieces of personal
information we collect
- Right to Delete: Request deletion of your personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your
CCPA rights
To exercise these rights, contact us at the email address above.
12. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), you have additional rights under GDPR:
- Right of Access: Obtain confirmation and access to your personal data
- Right to Rectification: Correct inaccurate personal data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Request limitation of processing
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
Legal Basis for Processing:
| Purpose |
Legal Basis |
| Account creation & services |
Contract performance |
| Push notifications |
Legitimate interest |
| Analytics & improvements |
Legitimate interest |
| Legal compliance |
Legal obligation |
To exercise your GDPR rights, contact us at the email address above.