Privacy Policy for Life Reboots

Effective Date: August 26, 2026

Welcome to Life Reboots!

Fairyland Technology Co., LIMITED ("we," "us," or "Fairyland") understands the importance of your personal information and values your trust. We comply with applicable laws and regulations and take appropriate security measures to protect your personal information. This Privacy Policy (the "Policy") explains how we collect, use, share, store, and protect your personal information when you use this product, and how you may manage that information.

Please read and understand this Policy carefully before using the product, particularly the provisions shown in bold. If you have any questions, please contact us using the details at the end of this Policy.

This Policy covers:

I. Scope of Application

1.1 Applicable Products

This Policy applies to the Life Reboots app, mini programs, H5 pages, and new forms of products and services that may emerge as technology develops (collectively, the "Product" or "Services").

1.2 Third-Party Services

This Policy does not apply to services independently provided by third parties. For example, when you visit a third-party website through an in-game link, view advertisements supplied by a third-party advertising platform, or use a third-party login or payment channel, that third party's handling of information is governed by its own privacy policy or similar notice. We reasonably review our partners, but cannot control processing independently performed by third parties. We recommend reviewing their privacy policies before using their services.

II. How We Collect and Use Personal Information

We may collect and use personal information in the circumstances described below. We follow the principles of lawfulness, fairness, transparency, and necessity, and process only the information needed for the relevant functions. Where processing relies on consent, you may withdraw consent; withdrawal does not affect the lawfulness of processing performed before withdrawal.

(A) Categories of Personal Information We Collect

1. Identifiers and account information. Data collected may include user ID, character ID, device ID, UUID, session ID, third-party account-linking status, and linked platform. We use this information for account identification, login and account linking, associating game progress, account security, and user lifecycle analysis.

2. Device and technical data. Data collected may include device model, mobile-device brand, operating system and version, app version, platform type, language, time zone, network type, IP address, and system country or region. We use this information for device compatibility, troubleshooting, performance monitoring, security, anti-cheat measures, and regional adaptation.

3. Internet and application activity. Data collected may include game launches, page visits, button clicks, story and event choices, feature usage, game progress, task completion, changes in virtual resources, and other activity logs. We use this information to provide and improve game functions and to analyze usage, game balance, retention, and product experience.

4. Character and gameplay data. Data collected may include a character's age, gender, region, attributes, occupation, virtual assets, NPC interactions, story progress, and other gameplay data. We use this information to save progress, provide story and gameplay functions, analyze game balance, and improve content. This is virtual-character data and does not represent your real-life circumstances.

5. In-app communications information. Data collected may include message ID, conversation ID, NPC ID, interaction entry point, and related information generated through AI/NPC interactions. We use this information to maintain conversation context, provide AI/NPC interaction functions, and analyze and improve the conversational experience.

6. Payment and platform transaction information. Data collected may include order ID, product information, platform product ID, platform transaction number, payment method, price, currency, payment status, subscription information, and refund records. We use this information for order processing, payment verification, delivery of products and membership benefits, purchase restoration, subscription management, refunds, and transaction security. We do not directly collect or store complete bank-card numbers or similar payment credentials.

(B) Processing Necessary to Perform the Core Game Services Contract

1. Account Registration and Login

2. Core Game Services

3. Stability, Security, and Anti-Cheat Measures

4. In-App Purchases and Subscriptions

When you purchase diamonds, items, game benefits, or a VIP subscription, Apple App Store, Google Play, or another approved payment provider processes your payment. We generally do not receive your complete bank-card details. We receive and process order number, product or subscription identifier, price and currency, purchase time, payment status, receipt or transaction token, refund status, and information linking the transaction to your game account. We use this information to verify orders, deliver digital content, restore purchases, manage subscription benefits, prevent fraud, and provide customer support. Each platform's handling of payment information is governed by its own privacy policy.

(C) Legitimate Interests—Additional Functions and Services

1. Customer Service and Support

2. Product Improvement and Notifications

3. System Permissions

We may request the following permissions for specific functions. Refusal generally does not affect core functionality, but the relevant optional feature may be unavailable:

(D) Circumstances Not Requiring Separate Authorization

To the extent permitted by applicable law, we may process information to perform a contract, comply with legal obligations, protect the life or property of you or others, maintain service security and stability, process lawfully public information, cooperate with competent authorities, or pursue other legitimate interests recognized by applicable law. Where regional rules differ, mandatory local law prevails.

III. Consent-Based Advertising Services, Advertising Identifiers, and Attribution

3.1 In-Game Advertising

The Product may display banner, interstitial, native, or rewarded-video advertisements. You may voluntarily watch rewarded advertisements for in-game rewards; unless an event page expressly states otherwise, rewards have no cash value. We reasonably distinguish advertisements from game content and seek to avoid misleading, disruptive, or age-inappropriate advertising.

For personalized advertising and performance measurement, we use only resettable advertising identifiers such as IDFA and AAID. If you decline tracking or reset or disable the advertising identifier, we will not use persistent device identifiers such as IMEI, MAC address, Android ID, or OAID for ad delivery, personalized advertising, cross-context behavioral advertising, or attribution. We may still use limited device identifiers strictly for security, fraud prevention, and service functionality, but not for advertising or in combination with advertising data.

3.2 Information Processed by Advertising and Third-Party SDKs

To request, display, frequency-cap, measure, and prevent fraud in advertising, we and our advertising partners may process:

This information may be used for contextual or personalized advertising, frequency control, revenue and performance measurement, attribution of installs or purchases, and detection of invalid traffic and ad fraud. Where required by law, we obtain consent before using non-essential advertising technologies or personalized advertising.

We share personal information—including advertising identifiers, IP address, device information, and in-app events—with advertising partners to deliver and measure personalized advertisements. In some jurisdictions, this may constitute "sharing" or "targeted advertising."

You may opt out of personalized and cross-context behavioral advertising at any time through Settings > About > Advertising Preferences in the app.

Where applicable, we also honor legally recognized opt-out preference signals sent by your browser or device. After you opt out, we stop disclosing or using your personal information for personalized or targeted advertising, although you may still receive contextual, non-personalized advertisements.

These controls are independent of device settings, which may provide additional choices. We do not condition access to core Services on consent to personalized advertising.

3.3 IDFA and Google Advertising ID

3.4 Analytics and Advertising Attribution

We may use analytics and attribution services to measure active users, retention, feature use, crashes, ad performance, installation source, and purchase conversions. Based on ad clicks or impressions, install and first-open time, device or advertising identifiers, and limited in-app events, attribution services may determine the promotional channel from which an installation or conversion likely originated. We seek to use aggregated, de-identified, or privacy-preserving solutions and require partners to process information only for agreed purposes.

3.5 Advertising and Analytics Choices

You may manage choices through in-game Privacy Settings or Advertising Settings, where available; device permission settings; iOS tracking settings; or Android advertising privacy settings. Where personalized advertising or SDK processing relies on consent, withdrawal stops future processing but does not affect prior lawful processing.

IV. Cookies and Similar Technologies

To operate the Product and provide a convenient experience, we may use cookies, local storage, SDK identifiers, and similar technologies on mobile devices or web pages. These technologies may save preferences such as volume and language, maintain sessions, remember login status, support security, and enable the analytics and advertising functions described in this Policy.

We do not use strictly necessary cookies for purposes not described in this Policy. Where required by law, we obtain consent for non-essential analytics or advertising cookies. You may manage or delete related data through browser, device, or in-game settings; clearing it may remove local settings or guest progress.

4.1 EEA/UK Cookie and SDK Consent

If you are in the European Economic Area (EEA) or United Kingdom, we obtain your explicit consent before placing non-essential tracking technologies on your device.

4.1.1 Categories and Providers

Strictly necessary (always enabled): Required for account login, core functionality, and security.

Analytics (consent required): Tools such as Google Analytics and Mixpanel may access device identifiers and usage metadata to measure performance, with a maximum retention period of two years.

Advertising (consent required): SDKs such as Meta and Google Ads collect advertising identifiers and conversion data to provide personalized advertising, with a maximum retention period of two years.

4.1.2 Obtaining and Managing Consent

Non-essential cookies and SDKs remain fully blocked until you consent. Our consent banner gives equal prominence to Accept All and Reject All and provides granular category controls. You may update or withdraw consent at any time through the persistent Cookie Settings link in our website footer or through in-app account preferences.

V. How We Share, Transfer, and Publicly Disclose Personal Information

5.1 Sharing

As a rule, we do not share your personal information with third parties, except:

We strictly govern external partners according to their legal role:

5.2 Third-Party SDKs and Services

We currently integrate the following third-party services. For each, we identify the provider, purpose, categories of personal information processed, and the provider's privacy-policy information. We update this table before adding or replacing a partner:

| Category | Provider | Primary Purpose | Information Categories | |-|-|-|-| | Login | Apple, Google, Facebook | Authentication and account linking | Third-party user identifier, name, email address, profile image, and authorization information | | Payment | Apple App Store, Google Play | IAP, subscriptions, receipt verification, and refund status | Order number, product/subscription identifier, receipt, currency, and payment status | | Analytics and stability | Firebase (Google), etc. | Crash analytics, performance monitoring, event statistics, and push notifications | Installation identifier, device information, crash logs, and in-app events | | Advertising | AppLovin MAX | Ad requests, display, measurement, frequency control, and anti-fraud | Advertising identifier, IP address, device information, ad interactions, and conversion events | | Attribution | AppsFlyer | Attribution of install and purchase sources and campaign-effectiveness analysis | Advertising/installation identifiers, click or impression information, installation, and limited conversion events |

We share personal information with these partners only for the listed purposes. If we materially change a partner, purpose, or data category, we provide advance notice in the app and obtain consent where required.

5.3 Transfer

We do not transfer your personal information except in a merger, acquisition, asset transfer, restructuring, bankruptcy liquidation, or similar event. We require the recipient to remain bound by this Policy. If the recipient changes the purpose or method of processing, it must provide renewed notice and obtain consent where required by law.

5.4 Public Disclosure

We publicly disclose personal information only when you choose to make it public, we have obtained your explicit consent, or disclosure is required by law or by an administrative enforcement or judicial authority. We apply security measures proportionate to the risk.

VI. How You May Exercise Your Rights

6.1 Access, Correction, and Supplementation

You may access or change information such as nickname and profile image through Settings > Account Center in the game. For information that cannot be changed directly in the client, such as a linked email address, contact customer support.

6.2 Deletion, Restriction, Objection, and Data Portability

Subject to applicable law, you may ask us to delete or correct personal information, restrict or stop processing, object to processing based on legitimate interests or direct marketing, withdraw consent, or provide a copy in a structured, commonly used, machine-readable format. We may need to verify your identity. If law permits us to deny or limit a request, we explain the reason and available appeal options.

6.3 Account Deletion

You may initiate deletion through Settings > Account Management > Delete Account, or a similarly named in-game option, or email [email protected]. After verification, we process the request promptly, ordinarily within 15 business days, or provide a status update; a shorter mandatory local deadline prevails.

Account deletion is irreversible. After deletion, we stop providing Services and delete or anonymize personal information associated with the account, except information that must be retained for legal, tax, accounting, transaction-dispute, security, or anti-fraud purposes. Game progress, virtual currency, items, VIP benefits, friend relationships, and other account data are permanently erased and generally cannot be restored.

Deleting the game account does not automatically cancel subscriptions managed by Apple App Store or Google Play. To prevent future charges, separately cancel through the relevant platform's subscription-management page. Where law requires retention of order or security records after deletion, we segregate them, restrict their use, and delete or anonymize them when the retention period expires.

If you use Sign in with Apple, we revoke the authorization token associated with the account when processing deletion, where applicable and as required by Apple.

6.4 Withdrawal of Authorization

You may disable notification, photo/storage, tracking, or other permissions in device settings, or withdraw consent through in-game privacy settings. We then stop processing based on that consent, without affecting prior lawful processing. Some features may become unavailable.

6.5 Submitting a Privacy Rights Request

You may exercise privacy rights through https://unfn.world/ or by emailing [email protected].

To protect your data, we verify all requests before acting. Verification ordinarily requires logging in or providing two or three data points matching our internal records. Information supplied for verification is used only to confirm identity.

We respond to verifiable consumer requests within 45 days. If additional time is needed, up to a further 45 days, we notify you in writing of the reason and duration of the extension.

If an authorized agent submits a request for you, we require signed authorization and may verify your identity directly before processing it.

We may deny portions of a request where permitted or required by law and provide written notice of any applicable exception.

6.6 Appeals and Complaints

If you believe we have not properly handled a request, you may appeal through the email address at the end of this Policy. You may also complain to a competent data-protection, consumer-protection, or other regulatory authority in your location.

If we deny your privacy-rights request, you may appeal within 60 days by emailing [email protected] with the subject line "Privacy Decision Appeal." Include the original request reference number, account information, and grounds for appeal. We may verify your identity again before review.

We provide a written decision with reasons within 45 days after receiving the appeal. If denied, you may complain to the appropriate regulator in your region.

VII. How We Protect and Store Personal Information

7.1 Security Measures

We use industry-standard safeguards, including encryption in transit, appropriate encryption at rest or de-identification, access controls, least privilege, access logs, security audits, vulnerability management, employee training, and incident response, to protect personal data from unauthorized access or disclosure.

If a security incident affects your personal information, we notify you through direct channels such as email, in-app message, or postal mail. The notice describes the basic circumstances, specific data types affected, recommended protective steps, and how to obtain assistance. We provide notices without undue delay and within the timeframe required by the law of your jurisdiction.

7.2 Storage Location and Cross-Border Transfers

As a rule, personal information collected in China is stored in China. Where genuinely necessary to provide global servers, cloud services, customer support, analytics, advertising, and attribution, information may be processed outside your country or region. For information collected in China, we comply with applicable separate-consent, security-assessment, standard-contract, or other cross-border requirements. For data from the EEA, United Kingdom, Indonesia, the Taiwan region, and other regions, we use applicable contracts, assessments, consent, or other lawful mechanisms and supplementary safeguards.

7.3 Retention

We retain information only as long as necessary for the purposes in this Policy, considering the account lifecycle, service needs, limitation periods, tax and accounting obligations, dispute resolution, security, and anti-fraud requirements. Subject to applicable law, you may have rights to notice, access, correction, deletion, and a copy of your data. Necessary game data is retained while an account remains active. After deletion, we delete or anonymize personal information except information legally required or needed for dispute resolution. Transaction information may be retained for at least the statutory period.

Unless a shorter period is sufficient for the stated purpose or law requires a longer period, we apply the following schedule:

  1. Account details, including email and identifiers: retained while the account exists and deleted or de-identified within 30 days after account deletion, except for anti-fraud or security purposes.
  2. Logs: retained for up to 24 months.
  3. Advertising identifiers and advertising logs: retained for up to 13 months, or a shorter required period.
  4. Analytics events, de-identified or aggregated: retained for up to 24 months.
  5. Customer-support records: retained for up to 24 months after ticket closure.
  6. Transaction records: retained for seven years for tax and accounting requirements.

We may collect and use personal information in the described circumstances while you use the Product. We update this schedule and notify you of material changes.

VIII. Special Provisions Concerning Minors

The Product is primarily intended for adults and does not primarily target minors under the age of 16. If you are a minor under the laws of your location, we recommend that a parent or guardian read this Policy and that you use the Services and provide personal information with their consent and supervision.

We generally do not require all users to provide their full date of birth solely to determine their age. If we have actual knowledge that a user is under 16, we will apply additional safeguards to their personal information based on their age and the laws applicable in their location.

Children Under 13

If we have actual knowledge that a user is under 13, we will restrict non-essential collection and processing of personal information, as well as activities such as targeted advertising, cross-app tracking, advertising profiling, and the sale or sharing of personal information.

Where applicable law requires parental or guardian consent for continued collection or processing of the relevant personal information, we will carry out such processing only after obtaining verifiable consent from a parent or guardian. If the necessary consent cannot be obtained, we may restrict the relevant features or delete the relevant personal information already collected.

Users Aged 13 to 15

If we have actual knowledge that a user is aged 13 to 15, we will not use their personal information for targeted advertising, or sell or share their personal information as those terms are defined by applicable law, without the valid consent required by applicable law.

Where the relevant laws allow users to make their own choices, we may provide appropriate privacy choice mechanisms. Users may withdraw their choices through the privacy settings provided in the app or through other available methods.

The specific safeguards may vary depending on the user's location and applicable law.

Technical Safeguards for Minors' Data

For users identified as being under 16, we will restrict relevant data processing capabilities based on their age, location, and applicable law.

These measures may include:

If a parent or guardian believes that their minor child has provided personal information to us, or wishes to access, correct, or delete their child's relevant information, they may contact us at [email protected].

IX. Updates to This Policy

We may revise this Policy from time to time. For updates that do not materially affect your fundamental rights, we update the text on our website or in the game. If there is a material change to processing purposes, methods, scope, or your rights, we notify you through a pop-up, announcement, email, or other prominent means and obtain renewed consent where required. The effective date at the top identifies the latest version.

X. How to Contact Us

If you have questions, comments, requests, or become aware of a possible information leak, contact us:

We ordinarily respond within 15 business days after receiving a request and completing necessary identity verification, unless applicable law requires otherwise.

XI. Supplemental Terms for Users in Specific Regions

11.1 European Economic Area and United Kingdom

11.1.1 For EEA/UK users, Fairyland Technology Co., LIMITED is the data controller for processing described in this Policy.

EU Representative: Ji Wei, [email protected].

UK Representative: Ji Wei, [email protected].

You may contact our EU/UK representatives regarding personal-data processing.

11.1.2 Depending on the circumstances, our lawful basis is performance of a contract, your consent, compliance with legal obligations, or our legitimate interests. Legitimate interests include service security, fraud prevention, product improvement, and service-performance measurement, but do not override your rights and freedoms. You have rights of access, correction, deletion, restriction, objection, portability, and withdrawal of consent, and may complain to your local supervisory authority.

11.1.3 Personal data collected in the EEA and UK may be transferred to and processed by third-party providers outside Europe, primarily in the United States and Singapore, including cloud hosting, IT support, payment, and analytics partners. Transfers rely on an adequacy decision, Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), or another valid mechanism.

We apply supplementary technical safeguards, including strict pseudonymization, data encryption, and restricted-access protocols, to further protect data in transit and at rest. To request a copy of transfer documents or details of their availability, email [email protected].

11.1.4 Our systems analyze technical signals such as IP reputation, device fingerprints, and transaction anomaly scores to detect potential fraud. The analysis may trigger additional authentication or block suspicious settlement activity. Where an automated security decision prevents a transaction or account access and may significantly affect you, you may request human intervention as provided by law by contacting [email protected].

11.1.5 We assess browser/app interaction data, approximate location, and usage history to create a preference profile. This helps limit advertising frequency and present tailored offers. The processing does not produce legal or similarly significant effects. You may object to profiling for direct marketing at any time through the in-app privacy control or by emailing [email protected].

11.1.6 You may object at any time to use of personal data for direct marketing, including related profiling, through the always-available in-app privacy/advertising settings or by emailing [email protected]. After objection, we stop processing for direct-marketing purposes.

11.2 United States

Depending on applicable state law, you may have rights to know, access, correct, delete, and obtain a copy of personal information, and to opt out of a "sale," "sharing" for cross-context behavioral advertising, or targeted advertising.

We do not discriminate against you for exercising privacy rights. We do not deny goods or services, charge a different price—including removing a discount or imposing a penalty—provide a lower quality of service, or suggest that you will receive different treatment.

We may occasionally offer permitted financial incentives, such as discounts, rewards, or loyalty programs, in exchange for collecting, retaining, or selling personal information. If offered, we provide advance notice of material terms. We enroll you only after affirmative, explicit consent, which you may withdraw at any time without penalty.

We support and automatically honor state-recognized universal opt-out preference signals, such as Global Privacy Control (GPC). When our platform receives a valid GPC signal from a browser or device, we immediately treat it as a request to opt out of targeted advertising and the sale or sharing of personal data. For signed-in users, the opt-out applies across the account; for visitors, it applies to the particular browser or device. We honor the signal without additional barriers, confirmations, or account requirements.

We do not knowingly sell minors' personal information. "Sale" and "sharing" have the meanings assigned by applicable state law. Disclosure of advertising identifiers or activity data to advertising partners may constitute "sharing" under some state laws even without monetary consideration.

We provide persistent access to privacy choices in the in-app menu under Settings > About > Privacy Preferences and in the website footer under Do Not Sell or Share My Personal Information / Opt Out of Targeted Advertising.

11.2.1 Technical Implementation and Persistence

When you opt out, our systems restrict data transmission to third-party SDKs and advertising-technology networks. For registered users, the setting is linked to the account and automatically applies across devices and future sessions. For visitors, it relies on local browser storage or a device ID; if you clear cookies or use a new browser/device, you must apply the preference again. We also honor a valid GPC opt-out signal sent by your browser.

11.2.2 Third-Party SDK Directory

In addition to our unified opt-out control, you may manage choices directly with advertising network and analytics SDK partners:

11.3 Indonesia

We process personal data lawfully, transparently, and consistently with stated purposes under applicable Indonesian personal data protection law. You may request access, correction, deletion or termination of processing, withdraw consent, object to decisions based solely on automated processing, obtain a portable copy, and complain about processing. We apply legally required safeguards to cross-border transfers. Where notification of a personal data protection incident is required, we notify you and the competent authority within the statutory period.

11.4 Taiwan Region

Under personal data protection requirements applicable in the Taiwan region, we provide notice of the collecting entity, purposes, data categories, period, area, recipients and methods of use, and your available rights. You may make inquiries or request access, request copies, request supplementation or correction, request cessation of collection, processing, or use, and request deletion. We apply reasonable safeguards to cross-border processing and comply with restrictions lawfully imposed by competent authorities.