← Home

Privacy Notice

Last updated: June 2026

1. Who we are

Circulet is operated by rumon lai. rumon lai is the data controller for personal data processed through the Service and is responsible for how that data is handled.

2. Data we collect

  • Account data: email address, username, password (hashed), avatar color.
  • Game data: token balance, inventory, gameplay activity, leaderboard standing.
  • Support communications: messages you send us.
  • Technical data: IP address, device/browser identifiers, log data, basic usage telemetry.
  • Payment data: handled directly by Paddle (our Merchant of Record); we receive only the transaction confirmation, not your card details.

3. Why we use it (purposes & legal basis)

  • To create and operate your account and provide the game — performance of a contract.
  • To process purchases and fulfil token packs — performance of a contract.
  • To prevent fraud, abuse, and secure the Service — legitimate interests.
  • To respond to support requests — legitimate interests / contract.
  • To improve the Service and fix bugs — legitimate interests.
  • To comply with legal obligations — legal obligation.

4. Who we share data with

  • Paddle.com Market Ltd — Merchant of Record. Handles payments, subscription management, tax compliance, invoicing, and refund requests.
  • Lovable Cloud (managed hosting, database, and authentication subprocessor).
  • Professional advisers (legal, accounting) where necessary.
  • Authorities when required by law.

5. Data retention

We keep account and game data for as long as your account is active. If you delete your account, we delete or anonymise associated personal data within 90 days, except where we are required to retain certain records (e.g. transaction records kept for up to 7 years for tax/accounting). Support correspondence is retained for up to 2 years.

6. Your rights

Subject to your local law, you have the right to: access your data, correct inaccurate data, request erasure, request restriction, request portability, object to processing, and withdraw consent. Where GDPR applies, you may also lodge a complaint with your supervisory authority. We aim to respond within one month.

7. International transfers

Our subprocessors may process data outside your country. Where required, transfers are protected by appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.

8. Security

We use appropriate technical and organisational measures including encryption in transit (HTTPS), encryption at rest provided by our hosting platform, and database row-level access controls.

9. Cookies

We use essential cookies and local storage to keep you signed in and to operate the Service. We do not use third-party advertising cookies.

10. Contact for privacy matters

To exercise any of the rights above or ask a question about this notice, contact rumon lai through the in-app support channel. We will route your request to the appropriate person.