TOKENTO / PRIVACY

PRIVACY

Last updated 24 September 2026

1. Scope and data controller

This Privacy Policy explains how personal data is processed in connection with the closed beta test of Tokento and the beta waitlist on our website, tokentoapp.com. It describes the current version of the game, the website waitlist and the testing arrangements described below.

ABHI G STUDIOS PVT LTD, a private limited company registered in England and Wales with company number 17197255, is the controller of the personal data we process for the purposes described in this policy. Our registered office is 4th Floor Office, 205 Regent Street, London, England, W1B 4HB. References to “we”, “us” and “our” mean that company.

You can contact us at support@tokentoapp.com. Apple also processes personal data in connection with TestFlight for its own purposes, as explained in section 6.

Tokento is intended for users aged 13 and over. Our current arrangements for children and age verification are explained in section 13.

2. Local game data

Tokento does not require a Tokento account or sign-in. Your game progress, including your home, tokens and level, is stored on your device. Deleting the app deletes this local save, and we cannot restore it. The shared home used by the Friends feature is not a backup of your game.

An Apple Account is required to use TestFlight. That account is separate from Tokento and is subject to Apple's terms and privacy information.

3. Optional usage data

3.1 Consent and purpose

Tokento asks whether you wish to share usage data when you first play. Collection begins only if you give your consent. Declining does not restrict access to the game's features. You may change this choice at any time in Menu.

We use this information to understand gameplay and assess the game's performance during development. Our lawful basis for processing this usage data is your consent.

The usage-data setting applies only to Tokento's optional analytics. It does not control the separate processing associated with Friends, voluntary problem reports, email correspondence or Apple's TestFlight service.

3.2 Information collected

Where you consent, the following information is recorded:

Usage records are associated with a random installation identifier generated on your device when the game is first opened. This is not your name, email address or a device advertising identifier. It links activity from the same installation across sessions, so the records are pseudonymous rather than anonymous.

The analytics system excludes text you enter, your friend code, your Friends display name and your home layout. The server rejects these fields in analytics submissions. Information provided through Friends or a problem report is processed separately under sections 4 and 5.

Tokento does not request access to your location, contacts or address book, photo library, microphone, camera or advertising identifier. The game contains no advertising. These statements concern information accessed by the app; a report, email or attachment may contain personal information that you choose to provide.

3.3 Withdrawal of consent

Turning off usage sharing in Menu stops further collection, deletes usage data queued on your device and sends a request to erase the usage data already held on our server for that installation.

This does not delete your game save, shared home, friend code or problem reports. Those are processed separately. You do not need to delete your game to withdraw consent to analytics.

If your device is offline, collection stops immediately and the erasure request is retained and retried. If the request cannot be completed, the app displays a notice and provides a contact route for assistance. If you subsequently enable usage sharing, collection resumes for new activity; earlier queued activity is not submitted.

Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal. Our erasure arrangements are as described above, independently of that legal principle.

3.4 Identification of closed-test participants

During the closed test, we maintain a manually created record linking some installation identifiers to the names of participants who have agreed to test the game. We use this record to distinguish those participants' activity during testing. The association is entered by us, rather than inferred from device information.

For those participants, usage records can therefore be linked to an identified individual. The association is deleted when the closed test ends or when that participant's installation data is deleted, whichever occurs first. Optional usage collection remains subject to the consent setting described above.

4. Friends and shared homes

Opening Friends generates a friend code and uploads a copy of your home layout, chosen Friends display name and friend code to our server. We process this information to provide the Friends service you have requested: storing the shared home and displaying it to visitors who present the code.

Anyone who obtains the code can view the shared home, including someone to whom another person has forwarded it. We do not verify a visitor's identity or whether you authorised that person to receive the code. Share it only with people to whom you intend to give access.

The Friends feature does not upload your home unless you open it. The shared copy is used only to operate Friends and is not a backup of your game. You can remove the shared home and disable its code using Menu → Delete my data, or by contacting us. Our lawful basis is performance of the service you request through Friends.

5. Problem reports and correspondence

5.1 Reports submitted through the game

You may submit a report through Menu → Report a problem. A report includes your message, app version, device model, operating-system version, current game area, screen size, session duration and recent game events.

A report is submitted only when you choose to send it. Reporting is separate from optional analytics and remains available when usage sharing is disabled. We process reports on the basis of our legitimate interest in investigating and correcting faults and responding to users.

5.2 Email correspondence

Email sent to support@tokentoapp.com is received through Cloudflare Email Routing and forwarded to our Google Workspace mailbox. We process the sender's email address, message and attachments to deal with the correspondence, on the basis of our legitimate interest in providing support and responding to enquiries.

Correspondence is retained while the matter remains active. Completed conversations are reviewed every three months, and those whose most recent message is more than twelve months old are deleted. This quarterly schedule means completed correspondence may be retained for approximately fifteen months after the last message. You may request deletion earlier, and we will delete it on request.

Replies may come from our Google Workspace address rather than support@tokentoapp.com. Both are operated by ABHI G STUDIOS PVT LTD.

6. TestFlight

6.1 Processing by Apple

The beta is distributed through Apple's TestFlight service. Apple automatically collects testing information separately from Tokento's optional analytics. Tokento's usage-data setting does not control that collection, and we cannot disable it on your behalf.

Apple describes its collection of crash logs, usage information, device and operating-system information, and feedback. Feedback may also include screenshots, comments and device information such as carrier, time zone, battery level and available storage. Apple uses information for its own purposes, including improving TestFlight and preventing fraud.

Apple's processing is governed by its TestFlight privacy notice and privacy policy. Menu → Delete my data does not delete information held by Apple. Requests concerning Apple's processing must be made through Apple's privacy channels.

6.2 Information available to us

App Store Connect makes the following information available to us:

Our closed test uses email invitations rather than a public invitation link. This information can therefore be associated with an identified participant.

6.3 Our purposes, storage and lawful basis

We use this information to administer the closed test and identify and resolve faults. Our lawful basis is our legitimate interest in testing and improving the game before release. You may object to this processing by contacting us; we will remove you from the test.

Under our current working arrangements, we review TestFlight information within App Store Connect and do not download, export or retain separate copies. This describes our practice, rather than a technical restriction imposed by Apple. If we change that practice to retain a crash log for a particular fault, this policy will be updated to describe the change, and the copy will be retained only until that fault has been resolved. The manually maintained installation-to-tester record described in section 3.4 is a separate record created by us.

Apple restricts disclosure of TestFlight information to third parties. We do not disclose that information to third parties.

6.4 Ending participation and retention

On request, we will remove you from the test and cease using your existing TestFlight information. This is a commitment concerning our processing; it does not mean that Apple technically prevents further access to historical records.

We do not currently retain separate copies of TestFlight information. If our practice changes and we hold such copies, we will delete them on request.

Apple states that it may retain crash logs and usage data until bugs are resolved and retains beta feedback for one year. We do not control Apple's retention or delete Apple's records on your behalf. We have not verified whether removing a participant also removes our access to that participant's earlier feedback or crash reports in App Store Connect; this policy does not represent that it does.

Requests concerning our use of TestFlight information can be sent to support@tokentoapp.com. A separate request to Apple may also be necessary.

7. Service providers and IP addresses

Cloudflare provides our server and database infrastructure and forwards support email on our behalf. Google Workspace hosts the mailbox in which we receive and handle that correspondence. Apple provides TestFlight and also processes information for its own purposes, as described in section 6.

We do not sell personal data or use it for advertising. Tokento does not use third-party advertising or analytics services.

Requests to our server include an IP address. Our application server uses it only for rate limiting, to protect the service against excessive requests, and does not write it to our database. This statement does not cover Cloudflare's own operational and security records, which are maintained as part of its infrastructure services under its applicable terms.

8. Processing locations and international transfers

Our Cloudflare database currently runs in Western Europe. It stores usage events, problem reports, shared homes and waitlist entries. Requests are handled through Cloudflare's worldwide network; Cloudflare determines the processing location for individual requests. Google Workspace and Apple TestFlight also operate through international infrastructure. Personal data may therefore be processed outside the United Kingdom and the European Economic Area.

The following arrangements apply to the services described in this policy:

You may consult these documents directly or contact us for the relevant parts of the safeguards applicable to our processing.

9. Retention and backups

9.1 Retention periods

We apply the following retention arrangements:

9.2 Backups and restoration

Cloudflare provides database restore points covering seven days under our current plan. We cannot delete individual records within those restore points; they expire through the provider's retention process.

Manual database exports made before changes are stored on a company computer. An export becomes due for deletion after 30 days and is removed at the next cleanup run while that computer is available. Cleanup runs daily and when the computer starts, and due copies are also removed when the next backup is taken. If the computer is unavailable, deletion takes place on the next run after it becomes available.

Following a restoration, we reapply the relevant deletion records to remove data that was deleted after the backup was created. This procedure covers shared homes as well as other deleted installation data. Residual copies in backups are not used for other purposes while awaiting expiry.

10. Deleting your data

10.1 In-game deletion

Menu → Delete my data requests deletion from our server before clearing the local game save. The local save is cleared only after server confirmation. If the device is offline or the request is interrupted, you can retry without the app first erasing that local save.

This process removes the installation's usage events, problem reports, installation-to-tester association and, where applicable, shared home. The friend code is disabled so it can no longer be used to visit the home.

The process does not delete email correspondence or information held by Apple. Contact us to request deletion of correspondence, and use Apple's privacy channels for Apple's records. You may also ask us to withdraw your TestFlight invitation.

10.2 Limited records retained after deletion

We retain the following deletion records indefinitely:

These records support our legal obligation to give effect to erasure and our legitimate interest in preventing deleted data from being reintroduced. A residual copy may remain in a backup until the backup expires, subject to section 9.2.

10.3 Starting over

Menu → Start over resets the local game to a new home. It does not delete information from our server and is separate from Delete my data.

11. Your data protection rights

Under applicable UK and EU data protection law, you may request access to your personal data and information about its processing, correction, erasure, restriction of processing, or object to processing. You may also request usage data in a portable form where it is processed on the basis of your consent.

You may withdraw consent to optional usage collection at any time through Menu, as explained in section 3.3. Requests can also be sent to support@tokentoapp.com. We respond within one month and do not charge for handling these requests.

You have the right to complain to a data protection supervisory authority without first contacting us. In the UK, you can contact the Information Commissioner's Office or call 0303 123 1113. In the EEA, you may contact the supervisory authority where you live.

12. Automated decision-making and profiling

We do not use the personal data described in this policy for automated decision-making about individuals or for profiling.

13. Children

Tokento is intended for people aged 13 and over and is not directed at children under 13. It is not listed in the App Store's Kids Category. We do not knowingly collect personal data from children under 13.

We do not currently verify players' ages. The game does not request an age or age confirmation, and we cannot inspect a player's age through the App Store rating or family device controls. A user's age may become known to us if they provide it in correspondence or a report.

If you believe a child under 13 has provided personal data, including a problem report or shared home, contact us and we will delete it. In-game deletion is also available under section 10, with the scope and exceptions described there.

14. The website waitlist

14.1 What we collect

If you join the waitlist on tokentoapp.com, we collect the email address you enter, the date and time you joined, the part of the website the form was on, and a reference to the wording of the consent statement you agreed to. We do not ask for your name or any other information through the form.

14.2 Why we use it, and our lawful basis

We use your email address to invite you to upcoming Tokento beta test groups and to send you occasional updates about the beta. Joining the waitlist does not guarantee a place.

We process this information on the basis of your consent, which you give by ticking the box on the form before joining. You can withdraw your consent at any time by emailing support@tokentoapp.com. Withdrawing consent does not affect processing that took place before you withdrew it.

We do not send automated emails. Any email about the beta is sent by us individually from our Google Workspace mailbox, and our correspondence with you is then handled as described in section 5.2.

14.3 Where it is stored

Waitlist entries are stored in our Cloudflare database, which currently runs in Western Europe, as described in sections 7 and 8.

14.4 How long we keep it

We keep a waitlist entry for 12 calendar months from the date and time you first joined. Joining again with the same email address does not create a second entry and does not extend this period. When the 12 months have passed, the entry is deleted by a scheduled process that runs daily, at its next successful run, normally within 24 hours.

14.5 Leaving the waitlist

To be removed earlier, email support@tokentoapp.com from any address and tell us the email address you want removed. We will remove it as soon as practicable and in any event within one month, and we will reply to confirm. We do not currently send emails with removal links.

Residual copies may remain in database backups for the periods described in section 9.2. If we restore the database from a backup, we remove again any waitlist entry that was removed, on request or because its 12 months had passed, after that backup was made.

15. Contact

Contact support@tokentoapp.com for enquiries about Tokento. The following optional subject lines help identify your request:

Use of a particular subject line is not a condition for handling your request.

© ABHI G STUDIOS PVT LTD. See also the Tokento Terms and Conditions.