Novemade
Pivumo

Privacy Policy

What the Pivumo app does with information, what the studio does with Google and YouTube data, and how to remove either.

Last updated

The short version. Pivumo works without an account. If nobody signs in, nothing your child does leaves the device. There is no advertising in Pivumo, no third-party analytics, and no advertising identifier is collected. We never ask a child for an email address, a birthday, a photograph, contacts or location. We do not sell personal information, and we never sell or share Google user data.

This policy explains what NOVEMADE (“we”) does with information in the Pivumo mobile app, and separately what we do with Google and YouTube data in the tools we use to publish Pivumo’s own marketing videos. It describes how things actually behave rather than what a template would say.

NOVEMADE is the data controller for the processing described here. The studio’s legal entity is being established, and no registered company details are published on this page until that completes — an invented registration number in a document like this one would be worse than none. This notice will be updated with the registered identity as soon as it exists.

1. Playing without an account

Pivumo is designed to be played as a guest. A parent can open the app and hand it to a child immediately; we do not require registration before gameplay, and guest play needs no network connection.

In guest mode the app stores on the device: the child’s chosen nickname, an avatar colour, an approximate age band between two and six, and play progress such as which activities were finished. This stays in the app’s private storage on that device. It is not transmitted to us and we cannot see it.

2. What we collect when a parent creates an account

An account is optional. Its only purpose is to keep progress safe across a reinstall or a second device, and to carry a subscription between devices. If a parent chooses to sign in, the following is collected.

DataWhyWhere it goes
Parent’s email addressSign-in, verification, password resetSupabase
Account identifierIdentifies which family save belongs to the accountSupabase, RevenueCat
Child profile: nickname, avatar colour, age bandSo a restored device shows the right profilesSupabase
Play progress and recent practice historyRestoring progress, and the parent insights screenSupabase
Subscription statusUnlocking premium content on the family’s devicesRevenueCat, Apple

A nickname is whatever the parent types. It does not need to be a real name, and we suggest it is not. Practice history is bounded rather than unlimited: the app keeps recent sessions and lifetime totals, not a permanent record of every minute played.

3. Signing in with Google, inside the app

This section covers the Google Sign-In button a parent can use in the Pivumo app. It is one of three ways to make an account — the others are Sign in with Apple and an ordinary email address and password — and it is entirely optional. A child never sees it: account creation sits behind an adult gate.

Which Google data we access, and why

  • Your Google account identifier — so we know which family save belongs to you when you sign in again on another device. This is the only thing that can claim an existing family save.
  • Your email address — so we can reach the account holder about the account, and so account recovery works.
  • Basic profile information returned with the sign-in, such as your name — used only to show you which account you are signed in as.

That is the whole of it. Pivumo requests only the default sign-in scopes. It does not ask for, and cannot read, your Gmail, Drive, Calendar, Contacts, Photos or location. We never receive your Google password.

How the tokens are stored

Sign-in tokens are held in the operating system’s own secure storage — the iOS Keychain, or the Android Keystore — through FlutterSecureStorage. They are never written into the app’s save file, never included in a data export, and never sent anywhere except to the identity provider and to our authentication backend to establish the session. Signing out clears the session on the device and leaves local progress in place.

How to remove this access

Two separate things, and doing one does not do the other. To revoke Pivumo’s access to your Google Account, open your Google Account’s “Third-party apps & services” page and remove Pivumo. To delete the data we hold, delete your account from the parent area in the app, which removes the sign-in identity and the stored family save.

4. Google and YouTube data used by the studio

This section describes something different from everything above, and the distinction matters: it is about a tool we run inside the studio, not about the app on your device. No Pivumo player’s data is involved in it, and nothing here is affected by whether you use the app or have an account.

NOVEMADE publishes Pivumo’s trailers and short marketing videos to Pivumo’s own YouTube channel from an internal publishing tool. That tool uses YouTube API Services, and it is authorised by our own Google Account — the account that owns the channel. It is never authorised by a member of the public, and there is no way for an app user to grant it anything.

Which scopes are requested, and why each one

ScopeWhy it is requested
https://www.googleapis.com/auth/youtube.uploadTo upload our own Pivumo videos to our own channel, with their title, description and thumbnail. This is the tool’s only write capability.
https://www.googleapis.com/auth/youtube.readonlyTo read back the identity of the authorised channel and the status of the videos we uploaded, so a video can never be published to the wrong channel and a failed upload is not reported as a success.

Nothing else is requested. The tool does not read viewer data, comments, subscriber lists, watch history or analytics for any other channel, and it has no access to any Google service beyond YouTube. It does not read, and cannot read, the Google account of anyone who uses the Pivumo app.

How the OAuth tokens are stored

  • The refresh token and the short-lived access token are stored on studio-controlled infrastructure, in a directory belonging to that one product, readable only by the operating-system account that runs the publishing tool.
  • They are never shipped inside the Pivumo app, never included in this website’s code, and never sent to any third party, service or subprocessor.
  • Each product has its own OAuth client and its own token. A token issued for one channel is never reused for another — that separation is enforced by the tool’s own storage layout, not by convention.
  • The refresh token is kept only while we are still publishing to that channel, and is destroyed when access is revoked or the channel is retired.

Limited Use, and what we never do with it

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell, rent, trade or transfer Google user data. We do not use it for advertising, we do not share it with data brokers, and we do not use it to train machine-learning or AI models. It is used only for the one purpose described above: publishing our own videos to our own channel.

How to remove this access

The channel owner can revoke the tool’s access at any time from the Google Account’s “Third-party apps & services” page, which invalidates the stored refresh token immediately. Revoking it stops all future uploads; it does not remove videos already published, which are managed in YouTube Studio like any other video on the channel.

Because this tool uses YouTube API Services, the YouTube Terms of Service and the Google Privacy Policy also apply to that use.

5. What we do not do

  • No advertising of any kind. No ad network SDK is present in the app.
  • No third-party analytics or attribution service. The app has no analytics transport; the counters behind the parent insights screen are calculated on the device.
  • No advertising identifier (IDFA or Android Advertising ID) is collected. Collection of it by our subscription provider is switched off.
  • No selling or sharing of personal information, and no use of a child’s information for marketing or profiling.
  • No selling, sharing or model-training use of Google or YouTube user data.
  • No location, contacts, microphone, camera or photo library access. The app does not request those permissions.

6. Children

Pivumo is made for children aged roughly 2 to 6 and is meant to be set up by a parent or guardian. Account creation, purchases, data export, deletion and every link that leaves the app sit behind a gate that asks for an adult action before continuing. That gate is an interaction guard; it is not a verified identity check.

The app does not ask a child for any personal information. There is no chat, no user-to-user messaging, no social feature, no user-generated content shared with anyone else, and no external link reachable from the child’s part of the app.

If you believe a child has provided us with personal information without a parent’s involvement, write to info@novemade.com and we will delete it.

7. Who processes data for us

  • Supabase — account authentication and the stored family save.
  • RevenueCat — subscription status and receipt validation.
  • Apple and Google — app distribution, payment processing, and the optional sign-in providers.

Payments are handled entirely by the app store. We never see or store card numbers or billing details.

8. Storage, retention and security

Cloud data is held only while the account exists, and is deleted when the account is deleted. Data in transit uses HTTPS. Access to a family’s stored save is restricted at the database level to that family’s own account; another signed-in account cannot read it. Sign-in tokens are kept in the operating system’s secure storage, never in the app’s save file or in an export.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your choices

  • Play without an account. Nothing is collected.
  • Export. A parent can export the family’s data as a JSON file from the parent area.
  • Erase on the device. A parent can erase the local family data from the parent area.
  • Delete the account. Deleting the account from the parent area removes the sign-in identity and the stored family save. This cannot be undone.
  • Revoke Google access separately, from your Google Account’s third-party apps page.
  • Subscriptions are separate. Deleting an account does not cancel a subscription — cancel that in the App Store.

To ask about the information associated with an account, write to info@novemade.com from that account’s email address.

10. International transfer

Our providers may process and store data in countries other than the one you live in, including the United States.

11. Changes

If this policy changes we will update the date at the top of this page. Material changes will also be noted in the app’s parent area.

12. Contact

NOVEMADE — info@novemade.com. Questions about this policy, requests for a copy of what we hold about you, and deletion requests all reach a person at that address.

PivumoTerms of ServiceThis website’s privacy policy