Revised Full English Privacy Protection Guidelines (Added Independent GDPR Section + Independent LGPD Section)

Company: Chengdu Time Engine Technology Co., Ltd.

URL: https://www.tegame.com.cn/en/privacy_policy.html

Last Updated: August 7, 2026

Effective Date: August 7, 2026

Summary

Welcome to Chengdu Time Engine Technology Co., Ltd. In addition to the Game License and Service Agreement, this Game Privacy Policy (hereinafter referred to as the "Guidelines") further specifies details regarding the collection, use, storage and sharing of your personal information when you use our games, as well as your relevant rights. This Guidelines forms an integral part of the Game Privacy Policy. Key highlights are set forth below:

You may read the full version of the Game Privacy Protection Guidelines to access detailed personal information processing rules, including the correspondence between types of personal information and their intended purposes.

Table of Contents

1. Information We Collect

When you use our game services, the game will collect information you actively provide or data generated from your use of services in the following ways, for the purpose of service provision, service optimization and account security protection:

1.1 Account & Display Information

When you register for or use our game services, we collect your online identity identifiers and commonly used device information to identify you as a game user. If you log in to the game, we collect your unique identifier, avatar and nickname to store your login credentials for cross‑device access. To deliver better gaming services and enhance your experience, we may use your account nickname, avatar, in‑game operation records and game data (collectively the "Relevant Information", including but not limited to login status, match records, achievement data, etc.). Such Relevant Information may be displayed to yourself, other players or your in‑game friends. Subject to specific game settings, we may provide options for you to control whether such information is publicly visible.

1.2 Real‑name Identity Information

To comply with applicable laws, regulations and competent authority requirements, real‑name authentication is mandatory for full access to game services. We will collect your real‑name identity information only with your consent or upon your voluntary submission. Refusal to provide real‑name information may result in login failures or functional restrictions during gameplay.

1.3 Device & Network Information

We collect your device ID, advertising ID (AAID/IDFA), device name, device model and version, operating system version, IP address, MAC address, application ID, network type and other data to guarantee normal service operation, stabilize core game functions, optimize product performance, improve user experience and secure your account. For users under GDPR/LGPD, advertising identifiers will only be processed for personalized advertising if you provide explicit, separate opt‑in consent.

1.4 Game Log Data

We collect game logs such as login records, item transaction logs and match history when you use the game. This allows you to view your in‑game history within the client, and supports operational statistics, customer complaint handling and game security analysis.

1.5 Transaction & Consumption Records

When you use in‑game payment functions, we collect your recharge and consumption records to enable transaction history inquiries and fully secure your virtual assets. Collection of such data is indispensable for completing in‑game transactions.

1.6 Anti‑cheating & System Crash Data

To secure your game account and maintain a fair, healthy gaming environment, we collect your game identifiers, hardware and operating system data, process logs and game crash records to detect acts that undermine game fairness or disrupt service operation, including pirated client identification, cheat detection and anti‑hacking measures.

1.7 Player Interaction Content

When you communicate with other players via text, images, voice, video or other forms within the game, we may collect and store the content you send to filter inappropriate content such as pornography, violence, politically sensitive material, abusive language and malicious advertising, so as to purify the gaming environment.

1.8 Microphone & Camera Access

If you wish to use voice chat, video interaction or live streaming with other players, the game may access your microphone and camera only after you grant explicit authorization to enable such functions.

1.9 Geolocation Information

If you want to interact with nearby players, we may collect your geolocation data upon your authorization to match and team up with local users. Geolocation data qualifies as sensitive personal information. Denying location authorization will only disable nearby‑player matching and will not affect other core game functions; you may revoke location permission at any time.

1.10 Wearable Device Health Data

We implement moderate gaming reminder functions. If you use a wearable device, we may collect your real‑time heart rate data during gameplay with your consent to send system alerts when you play excessively.

1.11 Circumstances Where We May Collect and Use Your Information Without Your Consent

Pursuant to applicable laws, regulations and national standards, we may collect and use your personal information without prior authorization under the following circumstances:

  1. Matters directly related to national security, national defense security and major public interests such as public safety and public health;
  2. Matters directly related to criminal investigation, prosecution, trial and judgment enforcement;
  3. Circumstances where it is difficult to obtain your consent but necessary to protect your or other individuals’ vital legal rights including personal safety, property and reputation;
  4. Personal information you voluntarily disclose to the public;
  5. Personal information collected from legally disclosed public sources such as authorized news reports and government public disclosures;
  6. Necessary for concluding and performing a contract at your request;
  7. Necessary to maintain the safe and stable operation of our products or services, such as troubleshooting product malfunctions;
  8. Necessary for legitimate news reporting;
  9. Necessary for statistics or academic research conducted for public interest purposes, provided that all personal identifiers are de‑identified before research results are published or shared;
  10. Other circumstances stipulated by applicable laws and regulations.

1.12 New Functional Data Collection

Please note that our functions and services are continuously updated and upgraded. If any newly launched function collects your personal information not covered above, we will separately notify you of the type, scope and purpose of data collection via in‑page prompts, interactive pop‑ups or official website announcements to obtain your consent. At present, we only obtain user data from third‑party research institutions for game research to optimize products and deliver personalized services; we will not actively acquire your personal information from third parties outside our corporate group. If we need to obtain your personal information from external third parties for business development in the future, we will clearly inform you of the source, type and scope of use of such information prior to collection. If processing exceeds the scope of consent you originally granted to the third party, we will obtain your explicit consent before processing such data. We will also strictly comply with relevant laws and require such third parties to guarantee the legality of the information they provide.

2. Information Storage

2.1 Storage Methods and Retention Period

We store your information via secure means including local client cache, databases and server logs.

Generally speaking, we will only retain your personal information for the minimum period necessary to fulfill service purposes or as required by applicable laws and regulations. For GDPR and LGPD users, retention periods are clearly limited to the shortest term matching each specific processing purpose; once the purpose is fulfilled, all associated personal data will be anonymized or permanently deleted.

2.2 Storage Location

In accordance with legal requirements, all personal information collected within mainland China will be stored within the territory of the People’s Republic of China. For users located in the EU/EEA, UK or Brazil, cross‑border data transfers to third countries (including China and the United States) will comply with the mandatory cross‑border safeguards defined in Sections 11 and 12 below.

2.3 Notification Upon Service Termination

If our products or services cease operation, we will issue public announcements in compliance with laws and fully safeguard your legitimate rights and interests, including fulfilling all data deletion requests submitted by GDPR and LGPD users.

3. Information Security

3.1 Security Protection Measures

We strive to secure your personal information against leakage, loss, improper use, unauthorized access and disclosure via comprehensive multi‑layer protection covering technical tools, management systems and security frameworks. Our game systems have completed filing and evaluation for Class III Cybersecurity Protection Grade Assessment as required by national standards.

We adopt industry‑leading technical safeguards including firewalls, SSL encryption, de‑identification/anonymization and access control. We continuously upgrade security capabilities on your local device: partial data encryption is completed locally to strengthen transmission security; we monitor installed applications and running processes on your device to defend against viruses, Trojans and other malicious programs.

We have established dedicated management systems, workflows and teams for personal information security. We strictly limit personnel access to user data and enforce confidentiality obligations with regular audits; staff violating confidentiality rules will face disciplinary penalties. We regularly review internal security systems to prevent unauthorized access, use or disclosure of user data.

We recommend you exercise caution to protect your personal information while using our services, and we provide multiple security tools to assist you. All third‑party advertising, attribution and analytics SDK partners (including AppLovin MAX, Meta Audience Network, AppsFlyer, Google AdMob) are contractually required to implement equivalent data security standards and sign formal Data Processing Agreements (DPAs).

3.2 Security Incident Response

In the event of personal information leakage or other security incidents, we will activate emergency response protocols to contain the incident. After the incident, we will notify you of basic incident details, remedial actions taken or to be implemented, and recommended precautions via official announcements, app push notifications or emails. If individual notification is unfeasible, we will issue public warning announcements. For users protected by GDPR or LGPD, we will also notify the relevant local data protection authority within the legal mandatory timeline.

4. How We Use Your Information

We use collected information strictly in compliance with laws, regulations and contractual agreements set forth in these Guidelines, the Game License and Service Agreement and the Privacy Policy to deliver premium services.

4.1 Rules for Information Usage

  1. We utilize collected data to provide all core and supplementary functions including basic gameplay, player interaction, live streaming and in‑game purchases;
  2. Based on your game level, preferences, activity habits and consumption records, we build indirect user profiles to recommend relevant in‑game events, competitions and promotional offers as personalized services. For GDPR/LGPD users, such profiling for personalized advertising is only performed with separate, explicit opt‑in consent; you may withdraw consent at any time without penalty to core gameplay access.
  3. We analyze product operation data including usage frequency, fault logs and performance metrics to ensure service stability, optimize products and upgrade service quality. We will not combine analytical data with your personally identifiable information without your separate consent.

4.2 Personalized Push Notifications

We deliver customized promotional content such as in‑game skin recommendations based on your gaming characteristics. Subject to game settings, you may adjust the relevance of recommended content or opt out of personalized push services entirely. GDPR and LGPD users have dedicated one‑click opt‑out controls within the game settings menu.

4.3 Consent for Expanded Usage Purposes

We will only use your personal information for the purposes stated in these Guidelines. If we intend to use your information beyond the original stated purposes or reasonably associated scopes, we will notify you in advance and obtain your explicit consent before processing.

5. External Disclosure and Sharing

Unless otherwise stipulated in these Guidelines, the Game License and Service Agreement and the Privacy Policy, we will not actively share, transfer or disclose your personal information to third parties outside our corporate group. Any such external sharing, transfer or disclosure will only proceed after we confirm the third party has obtained your explicit consent.

Notwithstanding the above, if a game is developed by an overseas entity, we may provide your in‑game records and logs (including login logs and item transaction records) to the overseas developer for operational statistics, customer support and game security analysis, to help them optimize game services and user experience. In addition, we may contact guardians and share relevant consumption records to remind, verify and resolve suspected minor unauthorized purchases.

We will not publicly disclose your collected personal information unless required by law. If public disclosure is mandatory, we will inform you of the disclosure purpose, categories of information and sensitive data involved, and obtain your explicit consent in advance.

In the event of corporate merger, acquisition or asset transfer due to business development, we will notify you of the transaction and ensure the new controller protects your personal information in compliance with laws and at no lower standard than specified in these Guidelines.

Pursuant to applicable laws and national standards, we may share, transfer or publicly disclose personal information without prior consent under the following circumstances:

  1. Matters directly related to national security and national defense security;
  2. Matters directly related to public safety, public health and major public interests;
  3. Matters directly related to criminal investigation, prosecution, trial and judgment enforcement;
  4. Circumstances where it is difficult to obtain your consent but necessary to protect your or other individuals’ vital legal rights including personal safety and property;
  5. Personal information voluntarily disclosed to the public by the information subject;
  6. Personal information collected from legally disclosed public sources such as authorized news reports and government public disclosures.

Third‑Party SDK Disclosure (Advertising & Attribution Partners)

We integrate the following third‑party service providers for advertising monetization, user attribution and game performance analytics: AppLovin MAX, Meta Audience Network (Facebook Ads), AppsFlyer, Google AdMob, Firebase. These parties process your advertising ID, IP address, install and gameplay event data to deliver targeted ads and measure marketing performance.

You may withdraw consent for third‑party personalized advertising tracking at any time via in‑game privacy settings, and we will immediately stop sharing your advertising identifiers with all ad partners upon withdrawal.

6. Your Rights (Global General Provisions)

During your use of game services, subject to specific game settings, we provide in‑app controls for you to query, delete, correct or revoke authorizations related to your personal information. Please refer to the dedicated instructions within each game for operational steps. We also maintain official complaint and feedback channels to respond to your inquiries promptly.

Additional enhanced statutory rights for regional users are fully defined in Section 11 (GDPR) and Section 12 (LGPD). All data rights requests may be submitted to custom_service@tegame.com.cn. We will verify your user identity before processing your application.

7. Amendments to the Guidelines

We may revise these Guidelines periodically. Upon any material revision, we will notify you of the updated terms via appropriate channels when the new version is released. Please read the revised Guidelines carefully. Your continued use of the game constitutes your acceptance of our updated rules for personal information collection and processing. Material updates impacting GDPR or LGPD compliance will be highlighted with dedicated regional notification pop‑ups for affected users upon game launch.

8. Minor Protection

We attach great importance to the protection of minors’ personal information and continuously develop new protective mechanisms.

We fully implement national anti‑addiction policies through dedicated anti‑addiction systems to safeguard minors’ legal rights. We verify account real‑name data to identify minor users and place their accounts under anti‑addiction supervision. We collect login timestamps and cumulative playtime to automatically restrict gaming duration and enforce forced logouts at the system level, guiding rational gaming behavior. For suspected minor unauthorized purchases, we will attempt to contact guardians for reminders, verification and dispute resolution to support healthy internet use for minors. To further protect minors’ physical and mental health, we may implement stricter anti‑addiction rules than national mandatory standards and continuously test new minor protection technologies. For example, facial recognition verification may be activated for certain games or selected users to strengthen real‑name authentication accuracy and prevent identity fraud by minors.

The aforesaid facial recognition verification only compares your real facial data with the official public security authority database. A matching result means successful authentication, and your daily playable time limit will be assigned based on your actual age group. If the comparison fails or you refuse verification, you will be treated as a minor aged 12 or under and subject to corresponding anti‑addiction restrictions. Encrypted facial verification data will only be used for comparison with the public security authority platform and will not be retained by us.

If you are the legal guardian of a minor, please confirm whether the minor has obtained your authorization before they use our game services or submit personal information. If you have questions regarding your ward’s personal information, please contact us via the channels specified in Section 10.

Regional Minor Supplementary Rules

9. Miscellaneous Provisions

The general Privacy Policy sets out universal privacy clauses including user rights and information security safeguards, which shall equally apply to all game users. Where provisions of Section 11 (GDPR) or Section 12 (LGPD) conflict with general clauses in this document, the regional supplementary sections shall prevail for users residing in the corresponding jurisdictions.

10. Contact Us

If you have complaints, suggestions or inquiries regarding minors’ personal information, GDPR data subject requests, LGPD data rights requests or privacy compliance issues, please send your questions to our official email: custom_service@tegame.com.cn

Chengdu Time Engine Technology Co., Ltd. will review your submission and reply within thirty (30) working days after verifying your user identity, except for mandatory shorter response deadlines set by GDPR (1 calendar month) and LGPD (15 calendar days).

11. Supplementary Provisions for Users in EU/EEA/United Kingdom (GDPR Compliance)

This section applies exclusively to natural persons residing within the European Economic Area or the United Kingdom, governed by Regulation (EU) 2016/679 (GDPR). Chengdu Time Engine Technology Co., Ltd. acts as the Data Controller for all personal data collected from you.

11.1 Lawful Bases for Processing (GDPR Article 6)

We only process your personal data under one or more of the following legally recognized grounds:

  1. Consent: Separate, freely‑given, specific, informed opt‑in consent for personalized advertising, cross‑device tracking and marketing profiling. You may withdraw consent at any time, with no negative impact on core game functionality; withdrawal is as simple as granting consent. Pre‑ticked consent boxes are never used within our game pop‑ups.
  2. Performance of a Contract: Processing necessary to deliver core gameplay, account saving and in‑game purchase services you requested.
  3. Legitimate Interest: Limited processing for anti‑cheating, crash troubleshooting and product optimization. We complete a balancing test before relying on this basis for all marketing‑related processing.
  4. Legal Obligation: Processing required to comply with Chinese or international legal and regulatory requirements.

11.2 Full GDPR Data Subject Rights

You hold the following enforceable legal rights:

  1. Right of Access: Request a full copy of all personal data we store about you, including records of data shared with third‑party ad/attribution SDKs.
  2. Right to Rectification: Demand correction of any inaccurate or incomplete personal data held by us.
  3. Right to Erasure ("Right to be Forgotten"): Request full permanent deletion of all your personal data when: consent is withdrawn; data is no longer needed for original collection purposes; you object to processing; or data was processed unlawfully.
  4. Right to Restriction of Processing: Request we suspend all data processing while we verify data accuracy, investigate unlawful processing, or evaluate your objection request.
  5. Right to Data Portability: Receive your account, gameplay and transaction data in a machine‑readable structured format, or request direct transfer to another data controller where technically feasible.
  6. Right to Object: Object to all processing based on legitimate interests at any time; you have an absolute right to opt out of all direct marketing and personalized advertising profiling with immediate effect.
  7. Right to Withdraw Consent: Revoke any prior consent for tracking or advertising at any time, without affecting lawful processing completed before withdrawal.
  8. Right to Human Review: Challenge fully automated profiling decisions that create legal or similarly significant impacts on you.
  9. Right to Lodge a Complaint: Submit a formal complaint to your local national data protection supervisory authority if you believe our processing violates GDPR.

11.3 Cross‑Border Data Transfers

Your personal data may be transmitted to servers located in the People’s Republic of China, the United States, and other non‑adequacy third countries outside the EU/EEA/UK. To comply with GDPR mandatory safeguards:

11.4 Response Timeline for GDPR Requests

All GDPR data rights applications submitted via custom_service@tegame.com.cn will receive a formal response within one (1) calendar month of identity verification. Complex or multiple requests may extend this deadline by a maximum of two additional months, and we will notify you of any extension within the original one‑month window.

12. Supplementary Provisions for Users Located in Brazil (LGPD Compliance)

This section applies exclusively to all natural persons located within Brazilian territory, governed by Lei Geral de Proteção de Dados Pessoais (LGPD, Lei nº 13.709/2018). Chengdu Time Engine Technology Co., Ltd. acts as the Data Controller, subject to extraterritorial jurisdiction of the Brazilian National Data Protection Authority (ANPD).

12.1 Core LGPD Processing Principles

All personal data processing of Brazilian users strictly complies with the 10 mandatory LGPD principles: Purpose Limitation, Adequacy, Necessity (Data Minimization), Free Access, Data Accuracy, Storage Limitation, Transparency, Security, Non‑Discrimination, and Accountability. We only collect device identifiers (AAID, IP) required for game operation and advertising measurement, and never collect sensitive personal data (race, religion, biometrics, health information) without explicit separate consent.

12.2 LGPD Legal Bases for Data Processing

We rely on the following valid legal grounds for processing your data under LGPD Article 7:

  1. Explicit, Free Consent (Consentimento): The primary basis for personalized advertising, attribution tracking and behavioral profiling. Consent cannot be bundled with game service access; refusal of ad tracking consent does not block core gameplay functions. Consent is revocable at any time via in‑game privacy settings, with revocation procedures identical to consent procedures. Pre‑checked consent options are prohibited.
  2. Contract Execution: Processing necessary to deliver game services you requested.
  3. Legitimate Interest (Interesse Legítimo): Only used for anti‑cheat and crash analysis after completing a formal LGPD balancing test; we do not rely on legitimate interest for any advertising or marketing processing targeting Brazilian users.
  4. Compliance with Legal Regulatory Obligations.

12.3 Nine Statutory LGPD Data Subject Rights

All Brazilian users hold the full set of rights defined under LGPD Article 18‑22:

  1. Confirmation of whether we hold your personal data;
  2. Full access to all categories and copies of stored personal data;
  3. Correction of incomplete or inaccurate personal information;
  4. Permanent erasure of all personal data upon valid request;
  5. Anonymization or blocking of data that is excessive or unlawfully processed;
  6. Data portability to another service provider;
  7. Right to object to processing for specific stated purposes (including all personalized advertising);
  8. Immediate full withdrawal of prior consent for tracking and marketing;
  9. Contest automated decision‑making based solely on data profiling.

12.4 Cross‑Border Data Transmission Rules for Brazil

Your personal data may be transferred overseas to servers and third‑party SDK providers (Meta, AppsFlyer, AppLovin MAX, Google) outside Brazilian territory. All cross‑border transfers comply with ANPD regulatory requirements via signed formal Data Processing Agreements (DPAs) incorporating ANPD‑recognized protective clauses to ensure equivalent data protection standards overseas.

12.5 Minor User Mandatory Rules (Digital ECA + LGPD)

All Brazilian users under 18 years of age are classified as minors under Brazilian law. By default, we automatically disable all personalized advertising, ad ID tracking and behavioral profiling for users identified as minors. We integrate region‑specific signals to notify all advertising SDKs to stop delivering targeted ads to minor Brazilian players.

12.6 Response Timeline for LGPD Requests

All LGPD data rights requests sent to custom_service@tegame.com.cn will be fully resolved and responded to within 15 calendar days after successful identity verification, in strict compliance with ANPD mandatory response deadlines.

12.7 ANPD Enforcement Notice

Failure to comply with LGPD obligations may result in administrative penalties imposed by ANPD, including fines up to 2% of the company’s total annual gross revenue generated within Brazilian territory, capped at 50 million Brazilian Reais (BRL), temporary suspension of all data processing activities, and mandatory public disclosure of non‑compliance violations.


Modification Instructions for Website Deployment

1. Directly replace the original full text of your /en/privacy_policy.html with this complete revised document;

2. The document adds two independent, standalone regional compliance chapters at the end (Section11 GDPR / Section12 LGPD), does not destroy your original Chinese domestic privacy clauses;

3. All third‑party ad/attribution SDKs (MAX, Meta, AppsFlyer) are clearly disclosed, matching your actual project integration;

4. Separately clarifies cross‑border data transfer safeguards (SCC for GDPR, DPA for LGPD), which can directly support Google Play Data Safety form filling and overseas store review;

5. Distinguishes regional minor protection rules (EU <16, Brazil <18), consistent with current 2026 overseas regulatory requirements;

6. Unified dedicated privacy email for all regional data rights requests, with legally specified response time limits for GDPR/LGPD.

If you need, I can further generate a Brazilian Portuguese pt‑BR LGPD independent appendix for your Brazilian store listing and game pop‑up compliance.