Privacy Policy
Last updated: July 9, 2026
This Privacy Policy describes how Loldol ("we", "us", or "our") collects, uses, and shares information when you use the Loldol mobile application (the "App") and the associated services at lolodol.com (together, the "Service"). By using the Service you agree to the practices described below.
1. Data controller
Loldol is operated by J-19 Group. If you have any question about this policy or want to exercise any of the rights described below, contact us at j19group.dev@gmail.com.
2. Data we collect
2.1 Data you give us
- Account information — email address, phone number, username, display name, avatar image, referral code, and (if you sign in with Google, Apple, or Facebook) the profile identifiers those providers give us.
- Payment information — when you purchase coin packs or a subscription, the transaction is processed by Apple or Google. We do not receive or store your card number, CVV, or full card details. We do receive a transaction identifier, the product identifier, the amount, and the receipt/purchase token needed to grant entitlements.
- User-generated content — likes, favorites, watch lists, and profile edits.
2.2 Data we collect automatically
- Usage data — episodes and series you open, watch position and duration, quality preference, taps on rewarded / interstitial ads, daily check-in and lucky-spin events, and Loldol coin balance and transactions.
- Device and technical data — device model, operating system version, app version, language, network type (Wi-Fi / mobile), a randomly generated device identifier, IP address (used only for security and rate-limiting, not stored beyond 30 days in server logs), and push-notification tokens (Firebase Cloud Messaging on Android, APNs on iOS).
- Diagnostic data — crash reports and non-fatal error stack traces, collected via Firebase Crashlytics for the sole purpose of debugging.
2.3 Third-party SDKs we integrate
| SDK | Purpose | Data shared |
| Firebase Authentication | Sign-in, session refresh | Email or phone, provider ID token |
| Firebase Analytics | Aggregate usage statistics | Screen views, custom events, pseudonymous device ID |
| Firebase Crashlytics | Crash reporting | Stack traces, device model, OS version, app version |
| Firebase Cloud Messaging / APNs | Push notifications | Push token |
| Google Mobile Ads (AdMob) | Rewarded and interstitial advertising | Advertising ID, device model, coarse location. See Google Ads policy. |
| Apple App Store / Google Play Billing | In-app purchases | Purchase receipt, product ID, transaction ID |
3. How we use the data
- Authenticate you and keep you signed in across sessions and devices.
- Deliver the video catalog personalised to your language and viewing history.
- Track playback position so you can resume episodes on any device.
- Grant Loldol coins for check-ins, ads, purchases, and referrals; debit them when you unlock premium episodes.
- Send notifications about new episodes, coin rewards, and account activity — only when you have not opted out.
- Detect and prevent fraud, abuse, and violations of our Terms of Service.
- Improve the Service by analysing aggregate, de-identified usage patterns.
4. Legal bases (EU / UK users)
If you are in the European Union, the United Kingdom, or another region that requires a legal basis for processing, we rely on:
- Contract — to provide the Service you signed up for.
- Legitimate interest — for security, fraud prevention, and aggregate analytics.
- Consent — for push notifications and personalised advertising, which you can withdraw at any time in the app settings or your device settings.
- Legal obligation — where we are required to retain records (e.g. tax law for purchases).
5. Who we share data with
- Service providers — Google Firebase, Google AdMob, Apple, and infrastructure providers (Kubernetes hosting, S3-compatible object storage). Each provider processes the minimum data needed for the service they perform and is contractually required to protect it.
- Legal or safety — when required by valid legal process, or to protect the rights, safety, or property of users, the public, or Loldol.
- Business transfers — if Loldol is acquired, merged, or restructured, your data may be transferred to the new entity, which will be bound by this Privacy Policy or a policy at least as protective.
We do not sell your personal information.
6. Data retention
- Account data — kept for the life of your account. Deleting your account (see Section 8) removes it within 30 days.
- Watch history and interactions — kept until you delete individual items or your account.
- Purchase records — kept for 7 years as required by tax and accounting law.
- Server logs (IP, request path) — 30 days.
- Crash reports — 90 days.
7. Data security
All connections between the App and our servers use TLS 1.2 or higher. Passwords are hashed with bcrypt. Firebase Auth ID tokens and app session tokens have short lifetimes and are refreshed on rotation. Payment tokens never touch our servers unhashed. We restrict internal access to production data to a small operations team.
No system is perfectly secure. If we discover a breach that affects your data we will notify affected users promptly and comply with any applicable notification laws.
8. Your rights
Regardless of where you live, you have the right to:
- Access a copy of the data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and associated data — through Profile → Settings → Delete account in the App, or by writing to j19group.dev@gmail.com.
- Export your data in a portable format.
- Object to processing that relies on legitimate interest.
- Withdraw consent for push notifications or personalised ads at any time.
Residents of the EU, UK, or Switzerland may also lodge a complaint with a supervisory authority. Residents of California have the additional right to opt out of the "sale" or "sharing" of personal information — we do not sell or share personal information for cross-context behavioural advertising, so no opt-out is needed.
9. Children
The Service is not intended for children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children in that age range. If we learn that we have collected such information, we will delete it.
10. International transfers
Loldol operates from Kazakhstan; our production infrastructure is hosted in Kazakhstan and the European Union. If you access the Service from outside these regions, your data will be transferred to our infrastructure using the safeguards required by applicable law (Standard Contractual Clauses where necessary).
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will notify you via the App or by email. The date at the top of this document is always the last effective date.
12. Contact
Questions, requests to exercise your rights, or complaints: j19group.dev@gmail.com.