Back to NABORYN

Privacy Policy

Your information across our websites, AI products, and games

Last updated

How Naboryn Technologies Private Limited handles personal information, including advertising and analytics in our mobile games.

1. Who we are and what this policy covers

Naboryn Technologies Private Limited ("NABORYN", "we", "us") operates NABORYN websites, Mazor2 website builder, Agent OS, publishing services, and the mobile applications and games that we publish or operate and that link to this policy (together, the "Services"). This policy explains the personal information we handle, why we handle it, who receives it, and your choices.

We determine how information is used for our own accounts, billing, support, security, and game operations. When a customer uses our hosting or agent tools to process information about their visitors, we may process that information on the customer's instructions. The customer's privacy notice also applies to its website, forms, and agents.

Not every App offers the same features. References to accounts, cloud saves, purchases, advertising, or connected services apply where the relevant App or Service offers them. An App-specific notice may provide more detail. This policy is not a request for consent and does not replace a separate permission or consent where one is required.

2. Information you provide

  • Account information: your email address, name, profile image if supplied, account identifiers, and organization details. Password-based accounts use a password hash, not a stored plain-text password.
  • Project and agent content: prompts, chat messages, uploaded documents, website content, source files, agent instructions, configuration, and connected-service details. We also store generated output, project versions, task activity, and related errors.
  • Credentials you connect: API keys and integration credentials that you deliberately provide so we can call an authorized service on your behalf. Do not put credentials in public content or ordinary chat messages.
  • Support communications: your contact details, questions, feedback, screenshots, and transaction or device information you send when asking for help. Please avoid unnecessary sensitive information, passwords, API secrets, or full payment-card details.

3. Technical information and other sources

Our servers and infrastructure process request information such as IP addresses, requested URLs, browser or client details, timestamps, response status, and error information. Product records include sessions, model and tool use, task status, and usage measurements needed to operate, secure, and bill the Services.

If you sign in with Google, we receive the authorized basic profile, email address, and Google account identifier. This sign-in does not itself grant access to your Gmail messages or Google Drive files. Payment providers supply billing and subscription information described below.

Information can also come from a customer who uploads it, a visitor who uses a customer agent, or an integration the customer enables. Browser storage and game SDK collection are explained in their own sections below.

4. Mobile games and app information

Our games use Google AdMob for advertising and Google Analytics for Firebase (Firebase Analytics) for app-usage measurement. The information processed depends on the game, platform, SDK configuration, and your permissions and choices. These providers and the available controls are described in the next three sections.

Where a game supports them, game-related information can include progress, scores, preferences, reward events, purchase entitlements, and support identifiers. A save stored only on your device is different from information synchronized with an online service. Do not assume that every game has a NABORYN account, cloud saves, or the same data collection.

Apple and Google process information when you download an App, use a store account, or make a store purchase under their own policies. We may receive purchase references or entitlement information to validate or restore supported purchases. Their receipt and account systems are separate from a NABORYN web account.

5. Google AdMob advertising

AdMob's Google Mobile Ads SDK processes information to deliver and measure ads, maintain reliability, and detect invalid traffic. This can include your IP address and approximate location derived from it, app and ad interactions, diagnostic information, and device or advertising identifiers such as the Android advertising ID or Apple's IDFA when available and permitted.

Ad requests and interactions are shared with Google through the SDK. Whether an ad uses personalization depends on the App's configuration, applicable requirements, and your choices. Non-personalized or limited ads can still involve information needed to deliver an ad, measure it, or prevent fraud; they do not necessarily mean no data processing.

Read Google's Privacy Policy and Google's Mobile Ads data disclosure. See Advertising and analytics choices for controls and requests.

6. Firebase Analytics

Firebase Analytics helps us understand how people use our games and which experiences need improvement. It processes an app-instance identifier, app and device information, session and engagement events, and approximate geographic information. Depending on the integration, events can include app opens, screen activity, gameplay milestones, ad interactions, or purchases.

Advertising identifiers may also be available to Analytics depending on platform permissions and configuration. Where advertising integrations or data-sharing settings are enabled, Analytics information may also support advertising measurement or personalization, subject to the applicable choices. An app-instance identifier is pseudonymous, not a guarantee that information is anonymous.

See Google Analytics data collection and Firebase privacy information. Using Firebase Analytics does not mean that every App uses other Firebase products. The game SDK disclosures here do not mean that AdMob or Firebase Analytics is installed on every NABORYN website.

7. Advertising and analytics choices

Use the privacy or consent choices offered within the relevant App where available. Platform controls are separate: Apple devices provide app tracking controls, and Android provides advertising-ID controls. See Apple's tracking-permission guidance and Google's advertising-ID guidance. Available controls differ by operating-system version.

Disabling an advertising identifier or refusing tracking does not necessarily disable all analytics, remove ads, or delete previously collected information. An ad-removal purchase is not, by itself, an analytics opt-out. For an access, deletion, consent-withdrawal, or advertising opt-out request, contact contact@naboryn.com and identify the App and platform. We may need an App identifier to locate information that is not linked to your email.

Where applicable law requires consent before optional storage, analytics, or personalized advertising, that consent must be obtained through the relevant mechanism; accepting our Terms is not a substitute. This policy does not itself enable a device control or change an SDK setting.

8. Why we use information

  • Deliver the Services: create and secure accounts, keep projects and conversations available, generate and publish websites, run agents and integrations, and provide supported game features.
  • Manage purchases: determine plan access, measure usage, process subscriptions, maintain invoices, and handle payment or entitlement issues.
  • Support and improve reliability: respond to requests, investigate failures, understand feature use, and improve our products.
  • Protect users and comply with law: investigate abuse, prevent fraud, enforce legitimate service restrictions, keep required records, and respond to lawful requests.
  • Operate game advertising and analytics: fund supported games, measure ads and app engagement, and improve game experiences, subject to applicable permissions and choices.

Where a law requires a legal basis, the basis depends on the purpose: performing our agreement for requested features and billing; legitimate interests in security, support, and proportionate service improvement where those interests are not overridden by your rights; legal obligations for required records and requests; and consent where required for optional analytics, advertising, or device access. You can withdraw consent without affecting processing that was lawful before withdrawal.

9. AI prompts, models, and integrations

AI requests can include your prompt, relevant chat history, project source code, agent instructions, retrieved document excerpts, and tool results. Knowledge documents may be split into searchable excerpts and embeddings. These are used to find context for answers; uploading a document can therefore make relevant excerpts available to the configured model.

Supported providers include DeepSeek, OpenAI, Google Gemini, Anthropic, and server-configured Ollama. Requests go to the provider used for the task, not automatically to every provider. Where a configured fallback is used after a provider failure, relevant request information can go to that fallback provider. In particular, an Ollama request can fall back to configured DeepSeek service. Choosing Ollama does not guarantee that processing stays on your device or never reaches a cloud provider.

When you supply an API key, our backend uses it to request the provider's service. Provider retention, security, and any use of content for model improvement depend on the applicable API agreement and settings. We do not promise that every provider offers zero retention or the same training restrictions.

Enabled tools can send task information to configured webhook or backend endpoints and return results to the model. Only connect services and submit information you are authorized to use. Avoid unnecessary sensitive personal data; AI conversations are not a confidential professional-advice channel.

10. Published sites and visitor conversations

Publishing a site makes its selected content accessible to visitors. Public information can be copied, indexed, or cached by others. Check generated content and connected resources before publishing. Unpublishing does not automatically remove project history or copies held by third parties.

When you interact with an Agent OS widget or a customer-operated agent, the conversation and related usage information can be stored by NABORYN and viewed by the agent's owner. A conversation is not private from that owner. The owner's instructions, enabled tools, and privacy notice determine how they use the information they receive.

Customer websites may connect their own forms, analytics, payment services, or backend providers. Contact the website or agent operator about those activities. Where we process information only for that operator, we may refer your request to them and assist with the part we control.

11. Payments and billing information

Our web billing integration uses Stripe. Hosted checkout sends payment details to the payment processor. NABORYN keeps account references, customer and subscription identifiers, plan and payment status, amounts, currencies, billing dates, and invoice references or links, rather than storing the full card number through that checkout flow.

Apple and Google Play handle store-billed game purchases separately. Their privacy notices explain their payment processing. See Stripe's Privacy Policy, Apple's Privacy Policy, and Google's Privacy Policy.

Canceling a subscription, deleting an account, and requesting deletion of billing data are different actions. Required financial and transaction records may need to be retained after a cancellation or deletion request.

12. Cookies and browser storage

  • Sign-in cookies: web products use secure session mechanisms to authenticate you. Access cookies last about 15 minutes; refresh cookies can last up to 30 days and may be renewed during use. Temporary Google sign-in state and return-path cookies last about 10 minutes. Signing out revokes sessions and clears the relevant authentication cookies.
  • Preferences: browser local storage remembers your light or dark theme until it is changed or cleared.
  • Chat continuity: the Mazor2 studio stores recent project chat messages in browser local storage. Agent widgets use session storage for conversation continuity within a browser session. Server-side conversation and project records are separate.
  • Reliability: temporary session storage can record whether a recovery attempt has already been made after a deployment-related loading error.
  • Your controls: you can block or clear cookies and site storage through your browser. This can sign you out, reset preferences, or remove local chat continuity. Clearing browser storage does not delete server-side records. On a shared device, sign out and clear local project data before leaving it with someone else.

13. Who receives information

Information is shared for the purposes above with the parties involved in providing the feature you use:

  • Infrastructure and operational providers: hosting and related systems, including AWS, that support storage, delivery, and service operations.
  • Identity, payment, AI, advertising, and analytics providers: Google sign-in, Stripe, applicable app stores, the AI provider or configured fallback, AdMob, and Firebase Analytics as described in this policy.
  • People and services you involve: your authorized organization, the owner of an agent you contact, connected tool or backend providers, and visitors to content you publish.
  • Legal and business recipients: advisers or authorities when needed for legal obligations, rights, safety, or a genuine investigation; and parties involved in a merger, financing, or business transfer, subject to applicable confidentiality and data-protection requirements.

Pages may load fonts, images, or other content from external hosts, including Google Fonts. Loading such a resource sends the host technical request information such as your IP address. Independently operated sites, advertisements, and connected services have their own policies; linking to one does not put all of its processing under our control.

14. International processing

Our team, hosting infrastructure, and service providers may process information outside your country, including in India, the United States, and other countries where a provider operates. Location depends on the Service and provider. DeepSeek states that it processes and stores data in the People's Republic of China; see DeepSeek's Privacy Policy.

Different countries may provide different legal protections. Where transfer restrictions apply, an appropriate lawful transfer mechanism is required; using a service or accepting this policy is not a blanket waiver of those protections. Contact us for information about the transfer arrangements applicable to your use. We do not promise country-specific storage for all Services.

15. How long information is kept

Retention depends on the information and purpose, not a single period for every record. Account data supports your relationship with us; projects, versions, source artifacts, documents, and conversations support the features you use; operational records support reliability and security; billing records support accounting, disputes, and legal obligations.

We consider whether the information remains needed for those purposes, the nature and sensitivity of the data, your deletion request, legal requirements, and unresolved disputes or abuse investigations. Provider-side retention also depends on the applicable service and settings. Device-only information and cookies follow their own storage lifetimes described above.

Deleting a visible item, unpublishing a site, clearing chat in a browser, or uninstalling an App does not necessarily remove every server record, backup, or third-party copy. Following a verified deletion request, we delete information we are required to delete and explain relevant exceptions. Restricted backup copies may remain until replaced through the backup lifecycle; retained legal records are not treated as an active account.

16. Security

Our safeguards include HTTPS for public web traffic, hashed passwords and refresh tokens, product access checks, and encryption of saved Agent OS provider API keys. Access to information is limited according to the service functions and permissions involved.

No system is completely secure. These measures do not mean that every stored record is encrypted end to end, or that an AI provider cannot process content sent to it. Keep your account and connected credentials secure and report a suspected exposure to contact@naboryn.com.

17. Children and parental requests

Game audiences and permitted ages depend on the individual App and applicable law. Parents should review the App's description, age information, privacy disclosures, and online features. A store content rating or a parent's acceptance of our Terms is not, by itself, valid consent to collect a child's personal information.

Collection and advertising involving children require additional restrictions and, where applicable, verifiable parental consent. This general policy does not authorize personalized advertising to children or replace an App-specific child-privacy notice or required consent process.

If you believe a child has provided personal information in circumstances requiring parental consent without that consent, contact contact@naboryn.com. Identify the App and the concern without sending unnecessary information about the child. We will investigate and take appropriate steps, including deletion or restriction where required. A parent or guardian may also contact us to request access, correction, or deletion, subject to appropriate verification.

18. Your privacy rights

Depending on your location and the law that applies, you may have rights to know about or access your information; correct inaccurate information; request deletion; obtain a portable copy; restrict or object to certain processing; withdraw consent; or opt out of certain advertising-related uses. Some laws also provide rights concerning significant decisions based solely on automated processing.

Rights can have limits, including where information is needed for legal obligations, another person's rights, security, or a transaction you requested. We will explain the applicable reason if we cannot fulfill a request. You may ask us to reconsider or appeal where a right of appeal applies, and you may complain to the relevant data-protection authority or other competent regulator. You do not have to contact us first to exercise a right to complain.

19. Additional US privacy information

Where applicable US state privacy law covers our processing, the categories described above include identifiers, account and commercial information, internet or app activity, approximate location, and content or communications you provide. The sources, purposes, and recipient categories are described in this policy.

Advertising-related disclosures of identifiers and activity to providers such as AdMob may be treated as a "sale", "sharing", or processing for targeted advertising under some laws, even when no money is exchanged for the information. You may have an opt-out right even where we do not receive payment for a disclosure.

To submit a request to opt out of sale, sharing, or targeted advertising where applicable, email contact@naboryn.com with the App or Service name and your request, and use available App or device controls. We handle applicable rights and authorized-agent requests subject to proportionate verification. We will not unlawfully discriminate against you for exercising a privacy right.

20. Access, deletion, and other requests

For app-data or account deletion, visit our Account and data deletion page. You can submit a request without creating an account, signing in, or reinstalling an app.

Send requests to contact@naboryn.com. Include the Service or game name, platform, the action requested, and the account email or relevant identifier if you have one. For account requests, using the email associated with your account helps us verify control. For a game without an account, an email address alone may not identify SDK records.

We may request limited additional information to confirm identity, parental authority, or an authorized representative before disclosing or deleting data. Do not send passwords, full card numbers, API keys, or identity documents unless we specifically explain a necessary, secure verification process. We respond within the time required by applicable law and explain any permitted extension.

For data controlled by a customer's website or agent, contact that operator as well. We can assist with identifying the responsible operator and the information NABORYN processes. Account deletion does not automatically cancel an Apple, Google Play, or separately billed subscription; manage cancellation with the billing provider.

21. Policy changes and contact

We may update this policy when our Services or practices change. The date at the top identifies the latest revision. We will provide additional notice of material changes where required, using an appropriate website, account, in-App, or email notice. A new purpose that requires consent needs that consent separately; continued use alone does not supply every required permission.

For privacy questions, complaints, or requests, contact Naboryn Technologies Private Limited at contact@naboryn.com. App-specific developer-support details may also be available in the relevant Google Play or Apple App Store listing. Our Terms of Use describe the contractual rules for the Services.