Privacy Policy
Last Updated: September 22, 2026
Charmeji lets people create, collect, and play with screen buddies. This policy explains what data Charmeji handles and why.
Data We Collect
Charmeji may process anonymous Firebase authentication and installation identifiers, App Check signals, device push tokens, app settings, active buddy state, purchases, ad reward events, generated assets, uploaded reference images, import records, moderation records, support/admin records, and consent-gated analytics and attribution events.
Creating an account is optional. If you choose to create one, Firebase Authentication processes your email address for account creation, sign-in, password reset, security, and account management. You can continue using Charmeji anonymously without providing an email address.
Charmeji does not receive or store your password. Password credentials are handled by Firebase Authentication and protected in transit.
How We Use Data
We use this data to manage your optional account, sync your buddies across devices, protect backend routes, deliver generated assets, process purchases and restores through RevenueCat, grant rewarded-ad currency through Google AdMob server-side verification, measure app use and campaigns, prevent abuse, improve reliability, and provide support. Password-reset requests are processed by Firebase Authentication. Charmeji displays a neutral result and does not reveal whether an email address is registered.
Analytics, Attribution, and Advertising Revenue
After you grant consent, Firebase Analytics and PostHog receive privacy-safe app events, while AppsFlyer receives selected acquisition and conversion events. RevenueCat may share the AppsFlyer attribution identifier for server-to-server purchase attribution. AppsFlyer also receives impression-level AdMob revenue, including currency, ad format, placement, ad unit, and mediation source. Charmeji does not send prompts, imported text, raw links, provider error messages, or duplicate client-side purchase revenue to these services.
Until consent allows collection, these analytics providers do not collect app events, AppsFlyer is not started, RevenueCat attribution sharing is blocked, and impression revenue is not reported. Direct app links can still open locally. If consent is withdrawn, collection and attribution sharing are disabled again.
AI Creations and Uploaded Images
AI creations are private by default. Reference images and generated assets are stored so the app can show your buddies and complete hatch jobs. Upload only images you have rights to use.
Purchases, Ads, and Analytics
Purchases are processed by app stores and RevenueCat. Rewarded ads are provided by Google AdMob. Analytics, when enabled, avoids raw prompts and pasted import text.
Retention and Deletion
We keep data while needed to provide the app, meet purchase/accounting obligations, prevent fraud, and maintain service integrity. If you create an account, its email address and account identifier are retained while the account exists. They are deleted through Charmeji's account-deletion flow, subject to any narrowly applicable legal retention requirement.
To request deletion or access, use the in-app account-deletion controls, the developer contact email listed on Charmeji's Google Play listing, or the account deletion page.
Terms
Charmeji's terms are available in the Terms of Use.
Children
Charmeji is not intended for children under 13. Do not use Charmeji if you are under 13.
Changes
We may update this policy when Charmeji changes. The effective date above shows the latest version.