Last updated: 27 July 2026
This Privacy Policy explains how Ninelume handles data when providing the game and the optional sync and verification services. It should be read together with the Terms of Use.
In this policy, "Ninelume", "we", and "our" refer to the Ninelume product and the organisation responsible for its distribution — Earthquake Games, a brand of Earthquake Digital Serviços de Audiovisual LTDA, CNPJ 35.367.701/0001-48. "You" refers to the person using the game. This policy covers the Ninelume apps and the services directly required for the catalogue, progress sync, and game verification; it does not cover third-party services subject to their own policies, such as the App Store and Google Play.
Ninelume does not require your name, email, phone number, contacts, location, camera, microphone, or advertising identifier. When you use sync, the product processes only the data needed to make it work:
UUIDs may be normalised to lowercase before persistence. This normalisation does not create new personal data. The IP address used for rate limiting is not part of the game journal and is removed from the service's memory after inactivity, in line with its operational routine.
We process the data described above to provide and protect the features you request: keeping a local game, syncing devices when you use that feature, validating results, preventing abuse, and meeting applicable legal obligations. Where the law requires a specific legal basis, processing is carried out to the extent necessary for the performance of the service, the security of the product, compliance with legal obligations, or another basis provided by applicable law.
Ninelume contains no ads, no advertising SDKs, no cross-app tracking, no advertising profiling, no sale of personal data, and no paid hints. We do not use your game data for behavioural advertising. The app's privacy declaration for mobile platforms classifies game content, pseudonymous identifiers, and product interaction as data used exclusively for app functionality, never for tracking.
Any future addition of telemetry, advertising, or a new use of data will require a prior update of this policy and of the stores' privacy declarations, together with the corresponding technical review.
Games are stored on your device so the game works offline. If you use sync, the logical journal and pseudonymous identifiers are sent to the Ninelume service and stored on its infrastructure for that purpose. An internal verification service may re-read the puzzle and journal of a completed session to confirm the result; it does not receive a copy of your calendar, contacts, or any content outside the game.
We do not sell or rent personal data. We may share data only with providers who host or operate the infrastructure on our behalf, under instructions compatible with this policy and applicable legal obligations, or when a competent authority validly requires it. If processing involves an international transfer, we will adopt the safeguards required by applicable law.
On the device, you control local data by deleting a game or removing the app, subject to any copies still held by the operating system's own features. On the sync services, we keep guest identifiers and the journal for as long as they are needed to provide sync, recovery, and verification, or for the period required by law. After that, the data is securely deleted or anonymised.
You can request export or deletion of the data associated with your authenticated guest account through the support channel listed on the store page where you obtained Ninelume. To protect the account, we may ask for technical proof consistent with the guest identifier before fulfilling the request. Deletion may prevent the recovery or syncing of your progress.
Under applicable law, you may request confirmation of processing, access, correction, anonymisation, blocking, deletion, portability, information about sharing, and review of automated decisions, where applicable. You may also withdraw consent used as a legal basis. These rights may be subject to legal exceptions and requirements; we will explain if a request cannot be fulfilled.
If you are in Brazil, the rights provided by the Lei Geral de Proteção de Dados Pessoais (LGPD, Lei n.º 13.709/2018) apply to the extent applicable. You may also contact the competent data protection authority if you believe your request was not handled adequately.
We use technical and organisational controls proportional to the data we process, including guest credentials with a random secret, hashed credentials on the server, short-lived access tokens, rotating renewal, secure on-device storage, and event validation before persistence. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Ninelume is not directed at children and does not knowingly collect personal data from children. If local law requires a guardian's consent for minors to use the service, that consent must be obtained before use. If you become aware that personal data was submitted in breach of this rule, contact us through the support channel so we can assess and act in accordance with applicable law.
We may update this policy to reflect changes in the product, the services, or the law. We will publish the updated version on this page and revise the "Last updated" date. When a change is significant, we will provide the additional notice required by applicable law before it takes effect.
For questions, privacy requests, export, or deletion, use the support channel listed on the App Store or Google Play page where you obtained Ninelume, or write to suporte@earthquakedigital.com.br. Keep your guest identifier available so we can securely locate the data associated with your account.