This privacy policy was reviewed and updated on June 1, 2026, within the past year.
Application ID: kiss.gattouz.joychat. Platform: Google Play. App version: 1.0.0.
🛡️
Gattouz0 Privacy Policy
📆 Effective Date: June 1, 2026
📝 Last Updated: June 1, 2026
🔍 Last Reviewed: June 1, 2026
📜 Previous Updates: June 1, 2026
Effective Date: June 1, 2026
Last Updated: June 1, 2026
Last Reviewed: June 1, 2026
Data Controller: Nv Y | Gattouz0 Development Company
Data Protection Officer (DPO): Nv Y (Privacy & Compliance Lead) — Email: ynv20610@gmail.com
App Title: Gattouz0 – Trendy Social Hub
Package ID: kiss.gattouz.joychat
Policy Review Mechanism: Periodic review (at minimum annually) and ad-hoc updates in response to changes in law, technology, or our practices.
Effective Date: June 1, 2026 | Last Updated: June 1, 2026 | Last Reviewed: June 1, 2026.
This Privacy Policy for Gattouz0 explains how Gattouz0 Development Company (referred to as "Gattouz0", "our", "we", or "us") collects, uses, stores, discloses, and safeguards your personal data when you access our mobile application, website, and any associated services (collectively, the "Services"). By using Gattouz0, you consent to the practices described in this Policy, which is intended to comply with applicable international privacy laws including GDPR, CCPA / CPRA, VCDPA, and other relevant data protection regulations. This Policy is reviewed periodically — and at minimum annually — and updated as needed; the latest update was made on June 1, 2026.
🔍 Data Controller & Data Protection Officer Details
Data Controller: Nv Y (Gattouz0 Development Company)
Legal Business Name: Gattouz0 Development Company
Developer: Nv Y
App Package Identifier: kiss.gattouz.joychat
Registered Address: 412 Joy Lane, Los Angeles, CA 90028, United States
Data Protection Officer (DPO)
Name: Nv Y
Title: Data Protection Officer & Privacy Compliance Lead, Gattouz0 Development Company
Email:ynv20610@gmail.com
Postal Address: Attn: Data Protection Officer, Gattouz0 Development Company, 412 Joy Lane, Los Angeles, CA 90028, United States
Responsibilities: The DPO is responsible for monitoring our compliance with applicable privacy laws (including GDPR, CCPA / CPRA, and VCDPA), handling user privacy requests, coordinating with regulators, and overseeing the quarterly review and annual audit of this Privacy Policy.
Main Contact Email:ynv20610@gmail.com
Privacy Support Email:ynv20610@gmail.com
Reply Timeframe: All privacy-related questions will receive a reply within 48 working hours
You are welcome to reach out to our Data Controller or Data Protection Officer at any time if you have questions, worries, or requests related to your personal information and our privacy policies.
📜 Key Privacy Guidelines
Openness: We clearly explain what data we collect, how we use it, and who we share it with
Data Minimization: We only collect information that is essential to deliver our Services
Protection: We use strong security methods to keep your personal data safe
User Control: You have full rights to access, edit, delete, or opt out of data processing
Responsibility: We take accountability for protecting the data we process
Continuous Compliance: We review this Policy periodically and update it as needed to remain aligned with applicable law
📥 1. Data We Gather
1.1 Information You Voluntarily Provide
Account details: Your name, email, birth date, display name, and profile picture
Contact details: Phone number (only if you provide it for verification)
Payment details: Billing information (handled by trusted third-party payment services)
User interactions: Messages, chat records, and other content you send via our Services
Content you create: Images, videos, live broadcasts, and other materials you share
1.2 Information Collected Automatically
Device information and Device ID: We collect a limited set of device-level identifiers, namely the Device ID (the Android ID and the resettable Android Advertising ID / GAID on Android; the resettable Apple IDFV on iOS; and, only if you grant the system App Tracking Transparency permission, the Apple IDFA), together with the device model, operating system and version, app version, screen resolution, time zone, and language / region settings. We do not collect IMEI, MAC address, SIM serial number, ICCID, or any other persistent hardware identifier that would require privileged or restricted system permissions. Device ID data is used for account security, anti-fraud and anti-abuse risk control, crash diagnostics, basic analytics, and — only if you have not opted out — ad attribution and ad personalization.
Activity data: How you use the app, which features you use, and session length
Location information: Approximate (IP-based, city-level) location at most. Precise GPS location is not collected unless you explicitly enable a feature that requires it (such as nearby discovery) and grant the system location permission.
Log information: IP address, access timestamps, and pages you view
Analytical data: Combined, aggregated usage statistics to help us improve the Services
Disclosure of "Device ID" collection: We expressly disclose that the Gattouz0 application collects and transmits a Device ID. The Device ID is treated as personal information under applicable privacy laws (including CCPA / CPRA and VCDPA) and is processed in accordance with this Privacy Policy. You can opt out of advertising-related uses of your Device ID at any time using the methods described in Section 5. Note that the Device ID is also used for essential, non-advertising purposes (account security, anti-fraud, and crash diagnostics) that cannot be disabled without preventing normal use of the Services — see Section 5.4.
1.3 Sensitive Personal Information (CCPA / CPRA § 1798.140(ae))
Under the California Privacy Rights Act, certain categories of personal information are classified as "Sensitive Personal Information" (SPI). The only categories of SPI that may be processed through the Services are:
Contents of user communications (messages, chat records, voice / video chat content) — only to the extent strictly necessary to deliver the messages to the intended recipient(s), to operate moderation and anti-abuse systems, to provide customer support that you initiate, and to comply with legal obligations. We do not use the contents of your communications to infer characteristics about you for advertising or other secondary purposes.
Account credentials (such as passwords and authentication tokens) — used only for authentication and account security.
Precise geolocation — only if you explicitly enable a feature that requires it and grant the system location permission. You can revoke this at any time in your device settings.
We do not collect or process the following categories of SPI: government-issued identifiers (driver's license, state ID, passport, or social security number), racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, biometric information for the purpose of uniquely identifying you, health data, or data concerning your sex life or sexual orientation. Consistent with CCPA / CPRA § 1798.121, you have the right to limit the use of any SPI we do process to purposes that are necessary to provide the requested service — see Section 6.2.
1.4 System Permissions We May Request
The Gattouz0 app may request the following device permissions through the operating system's standard permission prompts. Each permission is requested only when needed for the corresponding feature, and you may grant or revoke each permission at any time in your device settings:
Camera — to take or upload a profile photo, capture content for posts, and (optionally) make video calls or live broadcasts.
Microphone — to record voice messages, make voice / video calls, and (optionally) live-broadcast audio.
Photos / Media / Storage — to select images or videos for your profile, posts, or chats; to save received media to your device.
Notifications — to deliver push notifications about chats, social activity, and important account or security updates.
Approximate / Precise Location — only requested when you opt in to a feature that requires location (such as nearby discovery). Not requested at install.
Network State — to detect whether you are online and to choose an appropriate quality level for media (system-level, no personal data attached).
We do not request access to your contacts, SMS messages, call logs, calendar, body sensors, accessibility services, or device admin privileges.
⚙️ 2. Purposes of Data Usage
Create, maintain, and protect your Gattouz0 user account
Enable communication and interaction between you and other users
Handle payments for virtual goods and premium subscription features
Offer customer service and answer your questions and requests
Confirm your identity and prevent fraud and unauthorized activities
Customize your experience and enhance the quality of our Services
Maintain platform safety, enforce our terms, and meet legal obligations
🤝 3. Your Right to Know About Data Sharing
You have the right to know whether your personal data is shared, with whom it is shared, why it is shared, and what categories of data are involved. Under global privacy regulations including the California Consumer Privacy Act (CCPA / CPRA), the EU General Data Protection Regulation (GDPR), and the Virginia Consumer Data Protection Act (VCDPA), every user has the full right to know if, how, and with whom their personal data is shared. We provide complete transparency for all data sharing practices below, and you can request a personalized data-sharing report at any time (see Section 3.3).
3.1 Categories of Data That May Be Shared
Personal Identifiable Information: Shared only with your permission or when required by law
Device Identifiers: Shared with service partners for operation, security, and analytics (anonymized when possible)
Anonymous/Non-Identifiable Data: May be shared with analytics partners to improve services
Usage Information: May be shared with service providers to improve performance
Transaction Records: Shared with payment processors to complete purchases
Location Information: Shared only with your consent for specific service features
3.2 Categories of Third Parties We May Share Data With
We disclose data only by category of recipient, not by individual vendor, because our specific service providers may change over time. The categories below describe every type of third party that may receive any portion of your data:
Infrastructure and Hosting Providers: Reputable cloud hosting, storage, content-delivery, and database service providers that host the back-end of the Services. Data shared with this category is encrypted in transit and used solely for storage and delivery on our behalf.
Payment Processors: The in-app purchase / billing platform of the operating system on which you installed Gattouz0 (for Android, this is Google Play Billing; for iOS, this is Apple In-App Purchase). These processors handle the payment transaction directly — we do not receive your full credit-card or banking details.
Mobile Analytics and Crash-Reporting SDKs: Industry-standard mobile analytics and crash-reporting tools that receive only anonymized or pseudonymized event data (such as feature usage counts and crash stack traces). No message content or chat content is shared with analytics tools.
Attribution / Anti-Fraud Providers: Mobile measurement and anti-fraud SDKs that receive only device-level signals (such as the Device ID and install events) for the limited purposes of attributing installs, preventing fraudulent installs, and detecting abusive accounts.
Advertising SDKs (only if you have opted in to personalized ads): When personalized advertising is enabled, anonymized or pseudonymized device-level identifiers may be shared with ad networks strictly for ad delivery and measurement. You can opt out at any time via Section 5.
Customer Support and Communication Tools: Email and push-notification delivery services used to respond to your support requests and deliver notifications.
Legal Authorities and Successors: Government, regulatory, or judicial bodies when required by applicable law, court order, or valid legal request; and any successor entity in the event of a merger, acquisition, or sale of assets (in which case we will provide notice and continue to honor this Policy).
Business Partners: Only with your direct, opt-in approval and for purposes explicitly disclosed to you at the time of consent.
An up-to-date list of the specific vendors currently in use within each of the above categories is available upon written request to our DPO.
3.3 How to Request Data Sharing Details
You can ask for a full, personalized report that lists exactly what data of yours has been shared, who received it, why it was shared, and how long it was stored by:
Sending an email to ynv20610@gmail.com with the subject "Data Sharing Disclosure Request"
Submitting a request in the app via Settings > Privacy & Security > Data Sharing Report
We will respond to your verified request within 15 business days at no cost, as required by law.
🚫 4. Your Right to Refuse Data Sale
Under CCPA, GDPR, and other international privacy laws, you have the clear right to opt out of the sale of your personal data to third parties for financial or other valuable benefits.
4.1 Our Policy on Data Sale
Gattouz0 will NOT sell your personal data to any third party for money or other compensation. We do not participate in any data sale activities as defined by CCPA, VCDPA, or other privacy laws.
4.2 Scope of Your Opt-Out Right
What you can opt out of: You have the right, at any time and for any reason, to opt out of (a) the sale or sharing of personal data for cross-context behavioral advertising, (b) targeted / personalized advertising, and (c) profiling that produces legal or similarly significant effects concerning you. This right is guaranteed by CCPA § 1798.120, GDPR Article 21, and VCDPA § 59.1-577.
Even though we do not sell your personal data, you keep the full right to opt out of any potential future sale, as well as opt out of non-essential data sharing used for targeted advertising. Opt-out requests are processed within 7 business days, and we will provide written confirmation of completion.
What is outside the scope of this opt-out: The opt-out right described in this section does not, and cannot, extend to essential data processing that is strictly necessary to (i) provide the Services you have requested (such as account creation, authentication, messaging, content delivery, and payment fulfillment), (ii) maintain the security and integrity of the platform (such as anti-fraud, anti-abuse, anti-spam, account-recovery, and risk-control systems), or (iii) comply with our legal and regulatory obligations. These activities are necessary to operate Gattouz0 and remain in effect even after you opt out of advertising-related processing. The expected effects of opting out on personalized features (such as recommendations and ad relevance) are described in Section 5.4.
🔕 5. How to Opt Out of Data Sale & Targeted Ads
You can choose to opt out of data sharing or selling for targeted advertising at any time using the methods below. All opt-out requests are processed free of charge and will not affect your access to the core features of the app (account login, messaging, content delivery, video / voice chat, in-app purchases, and customer support). Before opting out, please review Section 5.4 to understand which personalized experiences (such as recommendations and ad relevance) will be affected, and which essential processing activities (security, fraud prevention, and legal compliance) remain outside the scope of opt-out.
5.1 In-App Opt-Out (Immediate Effect)
Launch the Gattouz0 app and log into your account
Navigate to Settings > Privacy & Security
Open Advertising Preferences
Turn off "Personalized Ads" to stop targeted advertising
Turn off "Share Usage Data for Ads" and "Share Device ID for Ads"
Save your settings – changes take effect right away
You can view your opt-out status at any time in the same menu
5.2 Device-Level Opt-Out
iOS: Go to Settings > Privacy & Security > Apple Advertising > Disable Personalized Ads
Android: Go to Settings > Google > Ads > Turn off Ad Personalization
5.3 Opt-Out via Email (Verified Request)
Send an email to ynv20610@gmail.com with the subject "Opt Out of Data Sale & Targeted Ads", including your registered email and user ID. To verify your identity, please include one additional piece of account information (e.g., date of account creation, last 4 digits of phone number if provided).
We will process your request within 7 business days and send a confirmation email to your registered address. If you do not receive confirmation, please follow up – we are required by law to resolve opt-out request issues within 10 business days.
5.4 What Opt-Out Covers — and What It Does Not
Your opt-out request will:
Not affect your access to core features (account, messaging, content delivery, video / voice chat, in-app purchases, customer support)
Not require you to provide any additional personal information beyond what is necessary to verify your identity
Not incur any fees or charges of any kind
Remain in effect until you explicitly choose to re-enable the affected options through the same channels
Personalized experiences that will change after you opt out: Because some personalized features rely on the same data signals used for advertising and behavioral profiling, you may notice the following after you opt out — this is the natural and expected consequence of reduced data input, not a penalty:
Advertisements will become generic rather than tailored to your interests; ads will not stop appearing
Personalized recommendations (such as suggested users, suggested rooms, suggested chats, or "for you" content) may become less relevant and will generally fall back to popularity-based, freshness-based, or randomly-sampled defaults
Promotional offers, in-app rewards, and content surfaces that rely on usage patterns may stop being personalized to you
Re-engagement notifications and tailored marketing emails will no longer be targeted
Essential processing that opt-out does not apply to: The following activities are necessary to provide a safe and functional service, and continue regardless of your opt-out choices:
Anti-fraud, anti-spam, anti-abuse, account-takeover protection, and other risk-control systems
Identity verification and KYC / AML / age-assurance checks where required by law
Payment processing, refund handling, and chargeback investigation
Compliance with applicable laws, court orders, regulatory requests, and enforcement of our Terms of Service
Aggregated, fully de-identified analytics used to maintain and improve the Services
Security logging, crash diagnostics, and incident-response activities
Your opt-out preferences are stored in your account settings and remain in effect until you explicitly choose to re-enable them through the same channels.
📋 6. Your Privacy Rights & Choices
Based on your location, you may have the following rights regarding your personal information, in line with GDPR, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), and the Virginia Consumer Data Protection Act (VCDPA):
6.1 General Privacy Rights (Available Under GDPR, CCPA / CPRA, VCDPA and Similar Laws)
Right to know / Right to be informed: Know what personal information we collect, the categories of sources, the business or commercial purposes for collecting it, and the categories of third parties with whom we share it
Right to access: Request a copy of the personal data we store about you
Right to correction: Ask us to fix incorrect or incomplete information
Right to erasure / deletion: Request deletion of your personal data (where legally allowed)
Right to data portability: Receive your data in a commonly used, machine-readable digital format
Right to object: Refuse certain types of data processing, including marketing
Right to revoke consent: Cancel your approval for specific data processing activities
Right to disclosure: Get full details about data sharing and sales
Right to opt out of sale / sharing: Refuse the sale or sharing of your personal data, including data sharing used for cross-context behavioral / targeted advertising
Right to limit use of sensitive personal information
Right to non-discrimination: Receive equal service quality and pricing even after exercising your privacy rights
Right to appeal: Appeal any denied request within 60 days of notification
6.2 California Privacy Rights (CCPA / CPRA)
If you are a resident of California, United States, you have specific rights under the California Consumer Privacy Act of 2018 (CCPA, Cal. Civ. Code § 1798.100 et seq.) as amended by the California Privacy Rights Act of 2020 (CPRA). These rights include:
Right to Know (Cal. Civ. Code § 1798.100, § 1798.110, § 1798.115): The right to know what categories and specific pieces of personal information we collect, use, disclose, sell, or share; the categories of sources from which the information was collected; the business or commercial purpose for collecting, selling, or sharing personal information; and the categories of third parties to whom we disclose personal information.
Right to Delete (Cal. Civ. Code § 1798.105): The right to request deletion of personal information we have collected from you, subject to legal exceptions.
Right to Correct (Cal. Civ. Code § 1798.106): The right to request correction of inaccurate personal information we maintain about you.
Right to Opt-Out of Sale or Sharing (Cal. Civ. Code § 1798.120): The right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising. Gattouz0 does not sell your personal information, and you can opt out of any sharing for targeted advertising using the methods in Section 5.
Right to Limit Use and Disclosure of Sensitive Personal Information (Cal. Civ. Code § 1798.121): The right to limit the use of sensitive personal information to purposes necessary to provide the requested service.
Right to Non-Discrimination (Cal. Civ. Code § 1798.125): The right not to be discriminated against (in price, service quality, or access) for exercising any of your CCPA / CPRA rights.
Right to Data Portability: The right to receive your personal information in a portable, readily usable format.
Right to Designate an Authorized Agent: The right to use an authorized agent to submit requests on your behalf.
"Shine the Light" Law (Cal. Civ. Code § 1798.83): California residents may also request information about third-party direct-marketing disclosures by contacting our DPO.
How California residents can exercise these rights: Email our DPO at ynv20610@gmail.com with the subject line "California Privacy Rights Request" and specify the right you wish to exercise. We respond to verifiable requests within 45 days as required by CCPA, with a possible 45-day extension if needed. There is no fee for exercising your CCPA rights.
6.3 Virginia Privacy Rights (VCDPA)
If you are a resident of the Commonwealth of Virginia, United States, you have specific rights under the Virginia Consumer Data Protection Act (VCDPA, Va. Code Ann. § 59.1-575 et seq.), effective January 1, 2023. These rights include:
Right to Confirm and Access (Va. Code § 59.1-577(A)(1)): The right to confirm whether we are processing your personal data and to access that personal data.
Right to Correct (Va. Code § 59.1-577(A)(2)): The right to correct inaccuracies in your personal data, taking into account the nature of the data and the purposes of the processing.
Right to Delete (Va. Code § 59.1-577(A)(3)): The right to delete personal data we have collected from or about you.
Right to Data Portability (Va. Code § 59.1-577(A)(4)): The right to obtain a copy of your personal data in a portable and, to the extent technically feasible, readily usable format.
Right to Opt Out (Va. Code § 59.1-577(A)(5)): The right to opt out of (a) targeted advertising, (b) the sale of personal data, and (c) profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.
Right to Appeal (Va. Code § 59.1-578(C)): The right to appeal our refusal to take action on any request within a reasonable period.
Right to Non-Discrimination: The right not to receive discriminatory treatment for exercising any VCDPA rights.
How Virginia residents can exercise these rights: Email our DPO at ynv20610@gmail.com with the subject line "Virginia Privacy Rights Request (VCDPA)". We respond to verifiable requests within 45 days as required by VCDPA, with one 45-day extension where reasonably necessary. If we decline to act on your request, you may appeal that decision by replying to our response email within 60 days; you may also contact the Virginia Attorney General at oag.state.va.us to submit a complaint.
6.4 How to Exercise Your Rights (All Jurisdictions)
Exercise Your Rights: To use any of these rights, contact our Data Protection Officer (Nv Y) at ynv20610@gmail.com with the subject line clearly indicating your request type (e.g., "Data Access Request", "Opt Out Request", "California Privacy Rights Request", or "Virginia Privacy Rights Request (VCDPA)"). We will verify your identity (in accordance with privacy laws) and reply to valid requests within 30 days (GDPR) or 45 days (CCPA / CPRA and VCDPA) as required by law. You have the right to appeal any denied requests within 60 days of notification.
To use these rights, contact our Data Protection Officer at ynv20610@gmail.com. We will reply to valid requests within the timeframes required by law.
🔒 7. Data Protection Measures
We apply reasonable, industry-standard administrative, technical, and organizational safeguards to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These measures include, where appropriate to the type and sensitivity of the data:
Encryption of data in transit between your device and our servers (HTTPS / TLS)
Encryption or hashing of sensitive credentials (such as authentication secrets and payment tokens) at rest, and use of managed cloud storage that applies disk-level encryption
Logical access controls limiting personal data access to authorized personnel on a need-to-know basis
Routine security reviews, dependency updates, and patching
An incident-response and breach-notification process consistent with applicable law
No method of internet transmission or electronic storage is 100% secure, and we cannot guarantee absolute security of your information.
⏳ 8. Data Storage Period
We keep your personal information only as long as needed to fulfill the purposes it was collected for, including:
The entire time your account remains active
To meet legal, tax, auditing, and record-keeping requirements
To settle disputes and enforce our terms and agreements
To prevent fraud, misuse, and security risks
When your data is no longer needed, we securely delete or anonymize it according to applicable laws.
👶 9. Protection of Minors
Our Services are not designed for or directed at people under the age of 18. We do not intentionally collect personal information from anyone under 18. If we learn we have collected data from a minor without parental consent, we will delete it immediately. Parents or guardians who believe their child has provided us with data may contact us at ynv20610@gmail.com.
🌐 10. Cross-Border Data Transfers
Your information may be transferred and processed in countries outside your region, including the United States. We ensure these transfers follow data protection laws using Standard Contractual Clauses approved by the European Commission and other legally recognized methods.
📝 11. Updates to This Policy
11.1 Review and Maintenance
We review this Privacy Policy periodically — and at minimum annually — and update it as needed to reflect changes in our practices, technology, or applicable law. Material legal or regulatory developments may trigger ad-hoc updates between scheduled reviews.
11.2 Update History
Effective Date: June 1, 2026
Last Updated: June 1, 2026 — refreshed publication date, standardized date formatting, narrowed Device ID disclosures, replaced specific third-party vendor names with category-based descriptions, and clarified the scope of opt-out rights.
Last Reviewed: June 1, 2026
Previous Updates:
June 1, 2026 — refined opt-out procedures and clarified user rights
June 1, 2026 — enhanced CCPA compliance language
June 1, 2026 — added GDPR data-portability and cross-border transfer language
June 1, 2026 — initial policy release
11.3 How We Notify You of Changes
If we make material changes to this Privacy Policy (defined as changes that affect your privacy rights or how we process your personal data), we will provide notice before the changes take effect through one or more of the following channels, as appropriate to the nature of the change:
An in-app notice on the relevant screens of the Services
An updated "Last Updated" date and effective date at the top of this Policy
For significant changes that meaningfully expand our processing, an email notification to the address associated with your account
Minor, clarifying, or non-material edits (such as typo fixes, formatting changes, or improvements in wording that do not change the substance) may be made without separate notice. We encourage you to review this Policy periodically to stay informed about how we protect your privacy. Your continued use of the Services after the effective date of changes constitutes acceptance of the revised Policy.
📞 12. Get in Touch With Us
If you have any questions, concerns, or requests related to this Privacy Policy or our privacy practices:
Data Controller: Nv Y (Gattouz0 Development Company)
Data Protection Officer:ynv20610@gmail.com
Privacy Support Team:ynv20610@gmail.com
Mailing Address: Gattouz0 Development Company, Attn: Privacy Team, 412 Joy Lane, Los Angeles, CA 90028, USA
Privacy Request Response Time: All privacy-related inquiries receive an initial response within 48 working hours, and complete resolution within 30 days (or 15 days for opt-out requests) as required by law.