Legal

Privacy Policy

He Fen Mahjong is built to put you in control of your game and your data. This policy explains what information we collect, how we use it, and the choices you have.

Last updated: August 2026

1. The short version

  • You can use the App without creating an account — no name, email, or password is required. Each install is given a random, anonymous identifier.

  • When you scan tiles, the photo is sent to our AI provider (Google Cloud Vertex AI / Gemini) to identify the tiles and score the hand. The same happens when you upload a rules sheet to add a custom ruleset.

  • By default we keep scanned images to improve tile recognition. You can turn this off any time in Settings → Data → "Keep my scans."

  • If you play online, other players at your table can see the nickname you choose and your game moves.

  • We use Google Firebase and Google Cloud to run the App, and Google AdMob to show ads. We don't use third-party analytics trackers, and we don't sell your data.

2. Who this applies to

This policy applies to everyone who uses the App. The App is a general-audience game and is not directed to children under [13 / 16, per your target markets]. We do not knowingly collect personal information from children under that age.

3. Information we collect

a. Information you provide

  • Photos of your tiles. When you use "Score a Hand" (or the camera enrolment feature), the image you capture or select is processed to detect and score the tiles.
  • Rule sheets you upload. If you add a custom ruleset, the document or photo of the rules you provide is sent for AI processing. Please avoid including personal information in these images.
  • Player nicknames. Names you type for players at a table (for local score-keeping and, in online games, shown to other players at that table).

b. Information collected automatically

  • Anonymous identifier. On first launch the App signs you in anonymously via Firebase Authentication and stores a random user ID (UID). It is not linked to your name, email, or a real-world identity by us.
  • Device push token (online play). If you enable notifications, we store your device's push token so we can alert you when it's your turn or a game starts. On Android this is a Firebase Cloud Messaging token; notifications require your permission.
  • Gameplay and technical data. For online games we process game state (moves, discards, scores, turn/presence "heartbeat", timestamps) needed to run the match. Standard technical data (e.g. app version) may be recorded with uploads.

c. Camera and photo access

The App requests camera and photo library permission so you can photograph or select images of your tiles. Images are used for tile detection and scoring as described here. We remove embedded EXIF metadata (including any GPS location) from images before we retain them for training.

d. What we do NOT collect

  • No account, email address, phone number, or password.
  • No contacts, and no location data (we strip location metadata from photos).
  • No audio recordings. The App does not record or use your microphone.
  • No third-party analytics trackers. (We do show ads via Google AdMob — see Section 8 — which uses an advertising identifier.)

4. How we use information

  • Detect and score your tiles — sending the photo to our AI provider to identify tiles, name patterns, and calculate the score under your chosen ruleset.

  • Compile custom rulesets — turning an uploaded rule sheet into a playable, scorable ruleset.

  • Run gameplay — keeping running scores at your table, and, for online games, synchronising the match between players through our server-authoritative referee.

  • Send game notifications — if you opt in (turn reminders, game start, wins).

  • Improve tile recognition — retaining confirmed scans (image + the corrected/confirmed tile labels) to train and evaluate our recognition models. You can opt out (see Section 6).

  • Show ads — we display ads through Google AdMob to keep the App free (see Section 8).

  • Maintain and secure the service — diagnosing errors and preventing abuse.

We do not sell your personal information.

5. Legal bases (EEA/UK users)

Where the GDPR/UK GDPR applies, we rely on:

  • Performance of a contract — to provide the scoring and gameplay you request.
  • Legitimate interests — to improve our tile recognition (Section 6), and to keep the service secure. You have the right to object to processing based on legitimate interests.
  • Consent — where required, e.g. for push notifications and, in the EU/UK, for personalised ads (Google's consent form).

6. Improving recognition — your choice

To make tile recognition more accurate for everyone, we retain confirmed scans — the image together with the final tile labels and your anonymous UID — in our Google Cloud storage. This is on by default, disclosed here and at first use, and based on our legitimate interest in improving our own product.

  • Tile images depict game tiles, not people; we strip EXIF/GPS metadata before retention.
  • You can turn retention off at any time in Settings → Data → "Keep my scans." When off, scans are not uploaded for training.
  • We do not condition use of the App on this retention.

7. AI processing

Tile detection, scoring, and ruleset compilation are performed by Google Cloud Vertex AI (Gemini). Your image or document is transmitted, via our secure server proxy, to Google Cloud for processing and a result is returned. Google Cloud acts as our processor for this activity; under Google Cloud's terms, data sent to Vertex AI is not used to train Google's foundation models. Our server proxy validates your anonymous Firebase token so that no Google credentials are ever stored in the App.

8. How information is shared

  • Service providers. We use Google Firebase and Google Cloud Platform (Authentication, Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, and Vertex AI) to operate the App. Google processes data on our behalf under its terms.
  • Advertising (Google AdMob). We use Google AdMob to show ads. To serve and measure ads, AdMob may process your device's advertising identifier and app-interaction data. In the EU/UK we ask for your consent through Google's consent form; on iOS, ads use tracking only if you allow it via Apple's App Tracking Transparency prompt. You can reset or limit your advertising ID in your device settings. See Google's ad policies.
  • Other players. In online games, the nickname you choose and your game moves are visible to other players in that match. Your hidden tiles are held server-side and are not revealed to opponents until the rules require it.
  • Legal reasons. We may disclose information if required by law or to protect our rights, users, or the public.
  • No sale of data. We do not sell your personal information. Sharing with AdMob to show ads is not a "sale," and you can limit ad tracking as described above.

9. Data retention

  • Anonymous account: kept while the App is installed and used.
  • Retained training scans: kept for as long as they are useful to develop and evaluate our recognition models, unless you opt out or request deletion.
  • Online match data: kept for the duration of a match and a reasonable period afterward for reliability, then cleaned up.
  • Push tokens: kept while notifications are enabled and refreshed by the device.

10. Security

We use industry-standard measures provided by Google Cloud, including encryption in transit, server-side access controls, and rules that keep each player's hidden game state readable only by that player. No method of transmission or storage is completely secure, but we work to protect your information.

11. International transfers

We are based in [COUNTRY], and Google's infrastructure that processes data for the App is located in the United States and other countries. Where we transfer personal data internationally, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses) as offered by our providers.

12. Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. Because the App is designed around an anonymous identifier, we may be unable to locate data about you unless you can provide your anonymous UID or the relevant details. To exercise your rights, contact us at [CONTACT EMAIL].

  • Turn off scan retention: Settings → Data → "Keep my scans."
  • Turn off notifications: your device's system settings.
  • California residents: we do not sell or "share" personal information as defined by the CCPA/CPRA; you may still contact us to exercise applicable rights.

We will not discriminate against you for exercising your rights.

13. Children's privacy

The App is not directed to children under [13 / 16], and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.

14. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date and, where appropriate, an in-app notice. Continued use of the App after changes take effect means you accept the revised policy.