KOBASICSMALL WORLDS. MADE WITH CARE. Get a testing invitation

Kobasic · LUMA Bloom

Privacy Policy

LUMA Bloom Privacy Policy

Updated September 14, 2026 · com.kobasic.lumabloom

Last updated: September 14, 2026. This policy covers LUMA Bloom for Android, package com.kobasic.lumabloom, including its Internal testing builds.

1. Who is responsible

Andrija Rotter Kobasić, an independent developer based in Croatia and operating as Kobasic, is responsible for the game and the personal information handled by us. For privacy questions or requests, email kobasic@gmail.com.

2. Local game saves

LUMA Bloom has no player account, social sign-in, online leaderboard or developer-operated cloud save. Your playable save stays on your device. From version 1.1.2, optional analytics can send information about level attempts and results as described in section 5; this is not a cloud backup. The game saves the following on your device:

  • Level progress, restored flowers, star ratings and tutorial progress
  • Scores, Daily challenge state, nectar and unlocked cosmetics
  • Audio, music, haptic and visual preferences
  • Cosmetic ownership and purchase verification state
  • From version 1.1.1: selected age group and ad frequency counters

The app does not request access to your contacts, microphone, camera or precise device location. Version 1.1.2 also stores your separate analytics and crash-reporting choices locally. Versions through 1.1.1 do not include Firebase Analytics or Crashlytics.

3. Advertising and privacy choices

You can choose to watch a rewarded ad for an in-game benefit, such as continuing a round. From version 1.1.1, the game also supports occasional full-screen ads when you continue after successfully completing campaign levels. These are offered only after every seventh first-time campaign completion, with a minimum time interval; failures, repeated completions and Daily Garden do not trigger them. An unavailable ad is skipped. Ads are provided by Google AdMob. The game uses Google's User Messaging Platform (UMP) to check the privacy choices required for your region and to display the relevant messages. UMP contacts Google to check whether a privacy message is needed. Once ad requests are permitted, the game may load an ad before you choose to watch it.

Google's Mobile Ads SDK can collect and share the device's IP address, approximate location inferred from that address, app and ad interactions, diagnostic or performance information, and device or account identifiers such as the Android advertising ID. Google uses this information for ad delivery, measurement, fraud prevention and, where permitted by your choices and applicable requirements, personalisation. See Google's Mobile Ads data disclosure and Google's Privacy Policy.

Open Settings → Privacy choices in the game to review or change choices when Google makes that option available in your region. Withdrawing consent applies to future processing and does not undo earlier lawful processing. Declining personalised advertising does not necessarily prevent all data processing needed for permitted ads, consent management or fraud prevention. Core puzzle play is available without personalised advertising or in-app purchases.

Some testing builds request Google's sample ads. The selected build and registered test-device settings determine whether sample or commercial ads are requested. Test ads do not generate advertising revenue, but testing can still involve network requests and SDK data processing. This policy covers both rewarded and between-level ads when commercial ad serving is enabled. LUMA Bloom does not include Unity Ads or a third-party ad mediation adapter.

4. Purchases through Google Play

The game offers an optional, one-time cosmetic purchase. Google Play handles checkout, your payment method and its purchase records. We do not receive or store your payment card details.

The game uses Unity In-App Purchasing to communicate with Google Play. Product identifiers, purchase tokens, order information and signed receipts are processed to check payment status, verify the purchase on your device, grant the cosmetic entitlement and restore eligible purchases. The game saves ownership and verification state locally. We do not operate a receipt-validation server.

This integration uses Unity IAP 5.3.1 with native Google Play Billing. Unity's privacy information for IAP versions earlier than 5.4 describes that SDK's data handling. We do not enable Unity Analytics, Unity Authentication, a Unity webshop or direct-to-consumer payments. Google's handling of store and payment information is covered by its own privacy policy.

5. Optional analytics and crash reports

From version 1.1.2, LUMA Bloom includes Google Analytics for Firebase to help us balance puzzles and Firebase Crashlytics to help us find and fix errors. Both choices start off. Players who have selected an age group of 16 or over can enable either one independently, or continue with both off. They are unavailable while your age group is unknown or set to under 16. These choices are separate from advertising consent and do not affect access to levels, purchases or rewards.

Open Settings → Analytics & Crashes at any time to review your choices. Analytics can record screens visited, level starts and results, tutorial steps, rewarded continues and cosmetic unlocks, together with app and device information. Google's SDK also records sessions and can record in-app purchase metadata such as the product identifier, price and currency when analytics is enabled. It uses an app-instance identifier and can derive approximate location from a masked IP address. We do not attach a player name, email address, account ID, date of birth or age group to these events. Firebase advertising-ID collection and its advertising consent settings are disabled in this integration.

Crash reports can include error messages and stack traces, relevant device and app state, installation identifiers, and the game version, mode and level number. For managed C# exceptions, the game reports the exception type and a sanitized stack trace, omitting the exception message and full file paths. When analytics is also enabled, recent gameplay events can appear as breadcrumbs that help explain what happened before an error. These reports do not contain a cloud copy of your saved game, and we do not set a personal user ID.

The crash SDK may keep diagnostic records locally while the game runs. Automatic crash-report uploads are disabled. The game checks pending reports on a later launch and sends them only when crash reporting was allowed for the entire originating session and is still allowed; otherwise, pending reports are deleted. Enabling reporting partway through a session applies to eligible reports from the next launch, so a report may arrive later. Turning reporting off prevents new submission attempts under these checks. A report submission that has already started may finish after you turn reporting off; reports already sent are not recalled.

Google provides these services to process reports for us. See Google Analytics' app data disclosure, Firebase's Crashlytics data disclosure and Firebase privacy and security information. Advertising data processing described in section 3 remains separate.

6. If you contact us

If you email support or send feedback, we receive your email address and whatever you include, such as a device model, problem description or screenshot. We use that information to respond, investigate the issue and keep the related support correspondence. Please do not send passwords, payment card details or unnecessary sensitive information.

7. Why information is processed

We process information needed to provide requested game features, purchases or support, and to meet applicable legal obligations. Where relevant, we rely on our legitimate interests in resolving problems, protecting purchases and preventing abuse. We rely on your consent to send optional gameplay analytics and crash reports. We also rely on consent where required for advertising identifiers, storage or personalised advertising; the advertising consent message describes the choices available. Google processes information for its services under the purposes and legal bases explained in its notices.

8. Sharing, retention and deletion

Advertising and purchase information is handled by Google as described above. When you enable optional reporting, Google also handles the analytics or crash information for us. We may need to disclose support or business records where required by law or to protect legal rights. We do not publish your support messages or sell local game saves.

Local progress, settings and purchase-verification state remain until they are replaced, cleared through Android's app storage settings or removed with the app. Android or Google backup behaviour may depend on your device settings. Clearing local data does not cancel a purchase or remove Google's store records; eligible cosmetics can be restored using the purchasing Google Play account.

Support correspondence is retained as needed to resolve the request and related disputes or legal obligations. Google's retention periods and deletion controls apply to data it holds. The game's Privacy choices control changes ad choices; it does not erase Google's purchase history. We cannot directly identify or retrieve a local save on your device.

Firebase documents a 90-day retention period for crash traces and associated identifiers before removal from live and backup systems begins. Analytics retention follows the settings of our Google Analytics property and Google's applicable retention rules. Disabling analytics stops future event collection and resets the app's local analytics data when it was previously enabled; this does not automatically erase information already received by Google. Contact kobasic@gmail.com for a request concerning previously sent information. Because we do not associate reporting identifiers with your name or email, we may need additional information to locate a relevant record.

9. International processing and security

Google and its service providers may process data outside your country, including outside the European Economic Area. Its data transfer information explains the safeguards it uses where applicable. Google documents encryption in transit for data collected by its Mobile Ads, Analytics and Firebase services. Local saves depend on your device's access controls; no method of storage or transmission is completely secure.

10. Your rights

Depending on applicable law, you may request access to, correction or deletion of information we hold about you, restriction of processing, portability, or object to processing based on legitimate interests. You may withdraw consent where processing relies on it. Email kobasic@gmail.com with the game name and a description of your request. We respond within 30 days or any shorter period required by applicable law, subject to any legally permitted extension, and may need information to verify the request.

You may complain to the Croatian Personal Data Protection Agency (AZOP) or your local data protection authority. To manage data held by Google, use the controls and contact routes in Google's privacy policy. Your statutory rights are not limited by this policy.

11. Children and family privacy

LUMA Bloom is intended for players aged 13 and above. Starting with version 1.1.1, the game asks for a broad age group before requesting ads: under 16, 16–17, or 18 and over. It does not ask for a date of birth. The selected group is stored on your device and is used to configure age-appropriate advertising and consent treatment with Google; we do not receive it on a developer server. For the under-16 group, the app requests Google's child age treatment and marks the user as under the age of consent. For ages 16–17, it requests teen age treatment. These settings limit advertising practices; they do not mean that no SDK data is processed.

From version 1.1.2, the same local age choice also determines whether optional analytics and crash-report sending can be enabled. They remain off for the under-16 group. Changing your age group to under 16 disables those optional features. We do not send the selected age group as an analytics event or crash-report field.

If you are a parent or guardian and believe a child has sent personal information to us, contact kobasic@gmail.com so we can investigate and address it. Age ratings and availability are shown in the game's store listing when published. This privacy notice does not grant permission for purchases or replace any parental consent required by law.

12. Changes and contact

We update this page when the game's data practices change and revise the date above. Where a change requires a new notice or consent, we will provide it as applicable. For questions about LUMA Bloom, email kobasic@gmail.com.