Amberia
Support Privacy Terms

Amberia Privacy Policy

Last updated: September 15, 2026 Effective date: September 15, 2026

This Policy covers Amberia for Android and iOS and this official support website. The account, advertising, analytics and attribution disclosures apply across the Service where the described features are enabled. Platform-specific sections identify Apple and Google services and controls; a feature available on one platform is not necessarily available on the other.

Amberia is a fiction-reading application for Android and iOS. This Privacy Policy explains how Crazy Finger Studio Limited ("Amberia," "we," "us," or "our") collects, uses, discloses, retains, and protects information when you use the Amberia application and its related services (collectively, the "Service").

1. Who Is Responsible for Your Information

The operator and data controller for the Service is:

  • Legal entity: Crazy Finger Studio Limited
  • Business Registration Number: 78648496
  • Registered address: Room D01, 3/F, Wong King Industrial Building, 2 Tai Yau Street, San Po Kong, Kowloon, Hong Kong
  • Privacy contact: [email protected]

2. Information We Collect

Amberia provides a guest reader account without requiring an email address, phone number or password to start reading. You can choose a supported third-party sign-in option, such as Google, Apple or Facebook, when offered in your version.

2.1 Account, sign-in and service identifiers

We process your reader account ID, guest status, installation and service identifiers, access and refresh credentials, and the profile information associated with your account. Profile information can include a display name, email address, avatar and email-verification status. Purchase-account identifiers and purchase credentials associate transactions with the correct reader account.

When you choose a supported third-party sign-in provider, the provider and Firebase Authentication process authorization credentials and identity information. Amberia receives and processes provider identifiers, a Firebase user identifier and ID token, and the email address, name and avatar made available by the provider. We send the relevant information to our servers to authenticate you, create or access your reader account, maintain your profile and support account recovery. Signing in can change the active reader account; it is not merely a temporary identity check. We do not receive your provider password.

We may associate an AppsFlyer installation identifier with guest registration or sign-in and use an Amberia account identifier in analytics and attribution as described in Section 5. A guest account and its identifiers are not necessarily anonymous personal data merely because no email address is required.

2.2 Reading and library activity

We process information needed to provide the reading experience, including:

  • stories added to or removed from your Library;
  • reading position, reading history, and recently read stories;
  • chapter access and unlock status;
  • reading preferences such as appearance, text size, and reader controls; and
  • genre preferences and reading activity used for personalized recommendations when that option is enabled.

Search terms are used to return search results. Amberia does not keep a permanent on-device search history. Search requests may appear in short-term operational logs for up to 90 days, but full search terms are not included in the privacy-filtered on-device diagnostic log.

2.3 Purchases, subscriptions, Coins, and chapter unlocks

On iOS, purchases are processed by Apple through the App Store and StoreKit. On Android, Google Play purchases are processed by Google through Google Play Billing. We do not receive your full payment-card number or Apple/Google account password.

To verify a purchase, deliver Coins, prevent duplicate delivery, maintain your balance, and resolve purchase issues, we may process:

  • the App Store or Google Play product identifier;
  • Apple transaction identifiers, signed transaction information and storefront information; Google Play order identifiers, purchase tokens and purchase/acknowledgment status; and purchase dates and transaction status supplied by the applicable store;
  • the number of Coins purchased or used;
  • your Coin balance and Coin activity; and
  • the story, chapter, Coin price, and time associated with a chapter unlock.

In app versions and store regions that offer subscriptions, we may also process original and renewal transaction identifiers, subscription product and period, renewal and expiration information, offer eligibility or use, refund/revocation and billing status, and the subscription entitlement associated with your reader account, as made available by Apple or Google Play. We use this information to verify, provide and restore subscription access, reconcile renewals and refunds, prevent duplicate delivery or fraud, and handle support requests. This conditional disclosure does not mean subscriptions are available in every version or region; versions without subscriptions do not create subscription records merely because this Policy describes them. Relevant subscription transaction records follow the purchase-record retention rules in Section 9.

2.4 Notifications

If you allow notifications, we process the device push token and delivery information: an Apple Push Notification service (APNs) token on iOS, or a Firebase Cloud Messaging (FCM) registration token on Android. Tokens identify an app installation for message delivery. You can change notification permission in the notification settings for Amberia on your device. We may measure notification delivery or interaction to maintain and improve messaging.

2.5 Feedback and diagnostic information

If you submit feedback, we process the message, the support category, and any context you choose to provide. Do not include payment-card details, passwords, or other unnecessary sensitive information in feedback.

On iOS, Amberia may keep a small, privacy-filtered diagnostic log on your device. It can include app startup status, request method and path, response status, service error code, network error type, and request duration. It does not intentionally include authentication tokens, full chapter text, StoreKit signed transaction data, full search terms, or the text of your feedback. Diagnostic logs are not automatically uploaded, and the production app does not provide a diagnostic-log export control.

2.6 Network and technical information

When the app communicates with our servers, the servers may process technical information such as IP address, request time, app version, operating-system version, device and network characteristics, requested endpoint, response status, and security events. We use this information only as needed to operate, secure, troubleshoot, and protect the Service. Routine operational logs are retained for up to 90 days. Records isolated for a confirmed security, fraud, or abuse investigation may be retained for up to 24 months, or longer when required by law or an active dispute.

3. How We Use Information

We use the information described above to:

  1. create, authenticate, recover, and protect your guest or signed-in reader account, and complete a supported third-party sign-in when you request it;
  2. provide Discover, Library, search, reading, chapter access, and reading-history features;
  3. synchronize reading progress, Library state, unlock entitlements, Coin balance, and purchase records;
  4. verify App Store or Google Play transactions and deliver purchased Coins only once;
  5. provide recommendations and, when enabled, personalize story discovery;
  6. send notifications you have allowed;
  7. answer feedback and troubleshoot technical or purchase problems;
  8. detect abuse, fraud, unauthorized access, duplicate transactions, and violations of our Terms of Service;
  9. measure app use, reading and purchase interactions, advertising performance and campaign attribution as described in Section 5;
  10. maintain the reliability and security of the Service; and
  11. comply with legal, accounting, tax, consumer-protection, and regulatory obligations.

Where applicable law requires a legal basis, we rely on performance of our agreement with you, compliance with legal obligations, our legitimate interests in operating and securing the Service, and your consent where consent is required. You may withdraw consent for optional processing at any time, without affecting processing that occurred before withdrawal.

4. Personalized Recommendations

Personalized recommendations are optional. You can change this setting in Amberia under Settings > Account & Privacy > Privacy Choices.

When personalized recommendations are disabled, Amberia should provide general or editorial recommendations instead of using your account activity to personalize story ordering. Disabling personalization does not remove your Library, reading progress, purchased Coins, purchase history, or unlocked chapters.

Amberia does not use this setting as consent for advertising or cross-app tracking.

5. Advertising, Analytics, and Tracking

5.1 Google Analytics for Firebase and app-event measurement

Amberia uses Google Analytics for Firebase and our service-side event measurement to understand use of the app, maintain reliability and improve reading, purchases and advertising. Information can include app-instance and installation identifiers, an Amberia user ID, device and app characteristics, session information, user properties, and automatic and custom events. Custom events can describe sign-in outcomes, screen and search interactions, story and chapter interactions, reading progress and duration, Library actions, purchase flows, advertising requests, impressions, clicks and revenue, and operational errors. Event details can include content/product identifiers, transaction status, amounts, currency, timestamps and technical context relevant to the event.

We may set an Amberia user ID and user properties in Firebase Analytics. Measurement data can therefore be linked to an account and must not be treated as anonymous statistics. Event routing and available events depend on the enabled features; not every event is sent to every provider. See Google's privacy policy and Firebase privacy information.

5.2 AppsFlyer attribution and campaign links

We use AppsFlyer to measure installations, sessions, acquisition campaigns and relevant in-app events, and to open content from campaign links. AppsFlyer may process its installation identifier, an Amberia customer user ID, IP address, device and operating-system information, campaign/referrer and deep-link information, and custom event details such as interactions, conversions, purchases or revenue where those events are configured. Attribution information can be associated with account and event information to evaluate acquisition and campaign performance.

Platform identifiers may include the Android advertising ID (AAID/GAID) on Android and IDFV on iOS. IDFA on iOS is available only with the required Apple tracking authorization. Advertising identifiers are subject to device privacy controls and applicable consent requirements. See AppsFlyer's Services Privacy Policy and customer-data processing information.

5.3 Advertising and mediation partners

Amberia displays third-party advertising in enabled placements, which can include banners, native ads, interstitials and rewarded ads. We use advertising and mediation services including Google AdMob, AppLovin MAX and TopOn. Depending on the active mediation configuration, participating networks can include AppLovin, Liftoff Monetize (Vungle), Digital Turbine (Fyber), Meta Audience Network, Unity Ads, Mintegral and InMobi. Availability varies by version, region and advertising configuration.

These services may process advertising and app-installation identifiers, IP address and approximate location derived from it, device and app information, consent choices, ad requests, impressions, clicks, rewards and revenue information. We use this information to deliver and measure ads, award eligible rewards, limit repeat ads, prevent fraud and, where permitted and with any required consent, personalize advertising. Identifiers used by an advertising or mediation service may include a service-specific user or installation identifier. Advertising partners receive data necessary for these purposes; data use is subject to applicable law and your available privacy choices.

For provider details, see Google advertising information, AppLovin's privacy policy and TopOn's privacy policy. The applicable advertising consent message identifies participating vendors and choices where required.

5.4 Platform permissions and privacy choices

iOS: Apple's App Tracking Transparency permission controls tracking that requires that authorization, including access to IDFA. You can change it in iOS Settings. Refusing permission does not prevent core reading or purchasing, and does not by itself disable all analytics, contextual advertising or attribution processing that does not require that permission.

Android: Android does not use Apple's ATT prompt or IDFA. You can manage the advertising ID and available advertising privacy controls in your device's Google or privacy settings; available controls vary by Android version. Removing or restricting an advertising ID does not itself delete account data or stop all analytics and contextual advertising.

Where required, we request advertising consent through an in-app consent message. Use the privacy choices made available in your app or contact our privacy address to request withdrawal, objection or deletion. Personalized story recommendations are a separate choice and do not control all analytics, attribution or advertising. Accepting these Terms or this Policy is not a substitute for platform permission or other legally required consent.

5.5 The official website

Our static website pages do not embed Firebase, AppsFlyer, cookies, analytics scripts, advertising pixels, external fonts, or third-party scripts. Website hosting and content-delivery providers may process IP addresses, request times and browser/network information to deliver and secure the pages. Opening an external provider, refund or support link takes you to a separate service governed by its own policies. Sending us email shares the information you choose to include through your email provider.

6. When We Disclose Information

We do not sell your personal information for money. We disclose information to analytics, attribution and advertising partners for the purposes described in Section 5. Where applicable privacy law treats a disclosure for personalized advertising as sharing or a sale, we provide the choices required by that law; contact our privacy address to exercise applicable rights.

We may disclose information only in the following circumstances:

  • Service providers. To hosting, infrastructure, security, customer-support, or other processors that need the information to provide services to us and are subject to appropriate confidentiality and data-protection obligations.
  • Google and Firebase. For Firebase Analytics, supported sign-in and Firebase Authentication, Android push delivery through FCM, Google Play purchases, and Google advertising services as described above.
  • AppsFlyer and advertising partners. For attribution, campaign links, event measurement and advertising as described in Section 5.
  • Other sign-in providers. To the provider you choose, such as Facebook, for authorization and account identity. See Meta's privacy policy.
  • Apple services. To Apple as necessary for Sign in with Apple when you choose it, App Store distribution, StoreKit purchases and refunds, push notifications, and optional iCloud Keychain synchronization. Apple's handling of information is governed by its own terms and privacy policy.
  • Legal and safety reasons. When reasonably necessary to comply with law, regulation, legal process, or a valid government request; to enforce our agreements; or to protect the rights, safety, and security of users, the public, Amberia, or others.
  • Business transfers. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to applicable law and appropriate notice or safeguards.
  • At your direction. When you ask us to disclose information, such as the feedback text you submit to support.

We review service providers before granting access and limit their processing to the services they provide to us. Material changes to the categories of recipients will be reflected in this Policy.

7. On-Device Storage and Platform Recovery

On iOS, Amberia stores some information on your device using iOS Keychain, Core Data, UserDefaults, and the app's cache directories.

On iOS, authentication credentials, the installation identifier, and anonymous-account recovery information may use a synchronizable Keychain item. If you use the same Apple Account on another device, enable iCloud Keychain, and Apple completes synchronization, these items may become available on that device. The APNs token is device-specific and is not included in the synchronizable credential record.

Cached story data and chapter text are used only to provide reading functionality. The operating system or Amberia may remove cached content when it is no longer needed.

On Android, Amberia stores account/session information, settings, reading data and cached content in app-local storage. Android storage and backup rules apply; iCloud Keychain does not apply to Android. Reinstallation and cross-device recovery depend on the available account, service and platform features and are not guaranteed by local storage alone.

8. International Data Transfers

Amberia is operated from Hong Kong. Our infrastructure and service providers may process information in Hong Kong and in other countries or regions where they operate. Those locations may have data-protection laws different from those where you live. Where required, we use contractual, organizational, or other legally recognized safeguards for international transfers.

9. Retention

We retain information only for as long as necessary for the purposes described in this Policy, including to provide the Service, maintain security and transaction integrity, resolve disputes, and comply with law. Our standard retention periods are:

  • Account and reading data: Reader identifiers, Library state, reading progress, reading history, recommendation preferences, Coin balance, and active chapter entitlements are kept while the account remains active. Following a completed account-deletion request, these records are deleted or de-identified from active systems within 30 days.
  • Purchase and financial records: App Store or Google Play transaction, Coin delivery, Coin activity, and paid chapter-unlock records needed for accounting, tax, charge, refund, and fraud review are retained for seven years from the relevant transaction, or longer if required by law or an active dispute.
  • Push notifications: An APNs or FCM token is kept until it becomes invalid, notification delivery is disabled for the device, or the account is deleted. Obsolete tokens are removed from active systems within 30 days after we identify them as obsolete.
  • Feedback and support: Feedback and its support context are kept for up to 24 months after the support matter is closed, unless a longer period is needed for a dispute, safety issue, or legal obligation.
  • Operational logs: Routine request and security logs are kept for up to 90 days. Records isolated for a confirmed security, fraud, or abuse investigation may be kept for up to 24 months or for the duration of a related proceeding.
  • Backups: Deleted information may remain in protected backups for up to 90 days before being overwritten, unless a longer period is required by law. Backup data is not restored to ordinary use after an account-deletion request.
  • On-device data: On iOS, diagnostic logs use a rolling limit of two files of up to 512 KB each. Cached content remains until removed by Amberia, the operating system, storage pressure, app deletion, or account deletion, as applicable.
  • Identity and measurement providers: Authentication, analytics, attribution and advertising records are retained according to the applicable processing purpose, configured retention and legal obligations. Account deletion includes requesting deletion of associated personal data processed on our behalf by service providers, subject to legitimate retention exceptions. Data that has been irreversibly anonymized is no longer associated with an identifiable account.

Hong Kong business and transaction records are retained for at least seven years where required. Other personal information is not kept longer than necessary for the purpose for which it was collected. At the end of the applicable period, information is deleted or de-identified unless continued retention is legally required.

10. Account Deletion

You can request account deletion through the account settings in Amberia or by emailing [email protected] with the subject "Amberia Account Deletion" and your Amberia ID, if available. See account deletion instructions for platform steps and identity verification. On Android, a deletion request is scheduled to take effect after 30 days, and you can sign in during that period to cancel it. On iOS, follow the confirmation shown in the app. Once deletion is completed, the account cannot be restored.

Completed deletion removes the reader account and the account data we are not legally required to retain. It also clears account-related local data, including locally cached reading progress, Library entries, chapter entitlements, and credentials. Deletion permanently gives up remaining Coins, unlocked-chapter access, reading history, and other account state. Deleted accounts cannot be restored.

If an App Store or Google Play transaction is still pending or has been verified on the device but not yet delivered to the account, Amberia may require that transaction to finish before account deletion; contact support if it remains pending. This protects against losing a paid transaction or delivering it to a different account.

Some transaction, security, fraud-prevention, tax, accounting, or legal records may be retained as described in Section 9. Account deletion does not itself submit a refund request. App Store refunds follow Apple's process; Google Play refunds follow Google Play's process and applicable law.

Deleting your Amberia account or uninstalling the app does not itself cancel an App Store or Google Play subscription. Cancel through the store that bills you: Apple subscriptions or Google Play subscriptions. Restoring an eligible paid entitlement does not restore deleted account data. See the subscription terms.

Deleting Amberia does not delete your underlying Apple, Google or other provider account. We handle deletion of associated personal data held by us and request deletion by providers processing it on our behalf, subject to the retention exceptions above. You may separately manage connected-app authorizations in your provider account settings. Contact our privacy address for assistance; do not send passwords or authentication tokens.

11. Your Privacy Rights

Depending on where you live, you may have rights to:

  • request access to personal information associated with your account;
  • request correction of inaccurate information;
  • request deletion of information;
  • object to or restrict certain processing;
  • withdraw consent for optional processing;
  • request a portable copy of eligible information;
  • appeal a decision regarding a privacy request; and
  • complain to a data-protection authority.

You may manage personalized recommendations in the app and may delete the account in the app. For other requests, contact [email protected] and include your Amberia ID so that we can locate your account. We may need to verify that you control the relevant account before completing a request.

We will not discriminate against you for exercising a privacy right. These rights may be limited where an exception under applicable law applies.

12. Security

We use administrative, technical, and organizational measures designed to protect information, including encrypted network transport, access controls, platform security features, and transaction verification. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If you believe your account or information has been accessed without authorization, contact [email protected].

13. Children

Amberia is not directed to children under 13, or a higher minimum age where required by local law. We do not knowingly collect personal information from a child below the applicable minimum age. If you believe a child has provided information to Amberia contrary to this section, contact [email protected] so that we can investigate and take appropriate action.

Users who have not reached the age of legal majority where they live must have permission from a parent or legal guardian to use paid features.

14. Changes to This Policy

We may update this Policy to reflect changes in the Service, law, or our data practices. We will update the date at the top and provide additional notice when required. If a change materially affects optional processing based on consent, we will request consent again where required.

15. Contact Us

For privacy questions or requests, contact:

Crazy Finger Studio Limited

Room D01, 3/F, Wong King Industrial Building, 2 Tai Yau Street, San Po Kong, Kowloon, Hong Kong [email protected]

General support: [email protected]

© 2026 Crazy Finger Studio Limited
Home Support Account deletion