2F Corp OÜ — Fortune & FUN
AboutProductsFortune & FUNContact
Partner With Us

2F Corp OÜ·Version 1.0.0·Effective September 1, 2026

PRIVACY POLICY

Document
privacy_notice
Scope
global
Version
1.0.0
Locale
en
Effective date
2026-09-01 (ISO-8601)

Last Updated: September 1, 2026

Effective Date: September 1, 2026

This Privacy Policy describes how 2F Corp OÜ ("Company", "we", "us", or "our") collects, uses, discloses, and protects your personal data when you use our mobile applications, casual games, social puzzle products, websites, and related online services (collectively, the "Services" or "Apps").

Data Controller Information:

2F Corp OÜ

Registry Code: 17558284

Registered Address: Tartu mnt 67/1-13b, Tallinn 10115, Republic of Estonia

Contact Email: general@2fcorp.com

1. SCOPE AND APPLICABILITY

This Privacy Policy applies to all users of our mobile applications across iOS and Android platforms globally, with specific disclosures for residents of the European Economic Area (EEA), the United Kingdom (UK), and the United States (including California under the CCPA/CPRA).

2. INFORMATION WE COLLECT

We collect personal information in three ways: directly from you, automatically through your device, and from third-party platform partners.

A. Information You Provide Directly

  • Account & Profile Data: Display name, avatar selection, player ID, and user profile preferences.
  • User-Generated Game Content: Text clues, game guesses, and associations entered by players to participate in our asynchronous card and storytelling games. These inputs are processed exclusively on our internal servers for gameplay and matchmaking purposes. They are never transmitted to any third-party artificial-intelligence provider or external inference API (see Section 4).
  • Support & Correspondence: Email address, correspondence history, and details provided when contacting our support team at general@2fcorp.com.

B. Information Collected Automatically

  • Device & Technical Data: IP address, device model, operating system version, screen resolution, language settings, unique device identifiers (e.g., IDFV for iOS, Android Advertising ID). For users in the EEA/UK, collection of non-essential device identifiers via SDKs (including analytics) occurs only after consent is obtained through our in-app consent management tool, in accordance with applicable ePrivacy/electronic communications law; essential/security identifiers are exempt from this consent requirement.
  • Gameplay & Analytics Data: In-app session duration, gameplay milestones, card decks unlocked, matchmaking interaction timestamps, and crash logs collected via Google Firebase Analytics.
  • Subscription & Transaction Data: In-app purchase history, active subscription statuses, entitlement states, and renewal timestamps processed via RevenueCat Inc. (Note: We do not collect or process raw credit card numbers).

C. Information From Third Parties

  • Platform Accounts: If you sign in via Apple Sign-In or Google Sign-In, we receive an authenticated token and your registered display name/email as authorized by your privacy settings.

3. HOW WE USE YOUR INFORMATION AND LEGAL BASES (GDPR)

Under the EU General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:

Purpose of ProcessingCategories of DataGDPR Legal Basis
Delivering Gameplay & MatchmakingAccount Data, Gameplay Data, User CluesContract Performance (Art. 6(1)(b))
Managing Subscriptions via RevenueCatSubscription Status, User ID, In-App ReceiptsContract Performance (Art. 6(1)(b))
Analytics & App Performance OptimizationDevice Identifiers, Usage Data, Crash LogsLegitimate Interest (Art. 6(1)(f)) for essential diagnostics; Consent (Art. 6(1)(a)) for non-essential analytics identifiers where required by applicable ePrivacy/cookie law
Personalized Advertising & AttributionIDFA / Advertising ID, Marketing InteractionsConsent (Art. 6(1)(a))
Legal & Regulatory ComplianceTransaction Records, Regulatory CorrespondenceLegal Obligation (Art. 6(1)(c))

4. ARTIFICIAL INTELLIGENCE (AI) AND ARTWORK DISCLOSURE

Our Apps feature rich visual artwork and surreal card illustrations designed to enhance social gameplay.

  • Pre-Generated Collection: The artwork featured in our Apps includes images created in advance by the Company using generative artificial intelligence tools. These images were generated using generic, non-personal creative prompts unrelated to, and created independently of, any individual user's account, gameplay data, or UGC.
  • No Live API Processing: We do not transmit user text inputs, clues, guesses, or personal data to third-party AI providers or external APIs. There is no real-time or on-demand AI generation pipeline in the Apps; all AI-assisted visual assets are fixed, pre-hosted content curated before publication (see Terms of Service Section 3.2). All card artwork and visual assets are pre-hosted directly within the App or on our secure content delivery networks (CDNs).
  • No Training on User Data: Your in-game text inputs and gameplay history are never used to train public or commercial AI models.

5. HOW WE SHARE YOUR INFORMATION

We share personal data only with trusted third-party service providers who act as data processors under strict contractual obligations:

  • Platform & Billing Partners:
  • Apple Inc. (App Store) & Google LLC (Google Play): Primary app distribution and payment processing.
  • RevenueCat, Inc.: Subscription status management and paywall entitlement mapping.
  • Infrastructure & Analytics Partners:
  • Google Firebase / Google Cloud Platform / Amplitude: Serverless database hosting, real-time matchmaking, and crash analytics.
  • Legal Requirements: We may disclose data if required by law, subpoena, or government order, or to protect the safety, rights, or property of 2F Corp OÜ, our users, or the public.

6. INTERNATIONAL DATA TRANSFERS

As an Estonian company with a distributed administrative and technical team (in Austria and Ukraine) and cloud servers located in the US and EU:

  • Your data may be transferred to and processed in countries outside your country of residence.
  • For transfers outside the EEA, 2F Corp OÜ relies on the EU Commission's Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework to ensure your personal information receives an equivalent level of legal protection. Transfers to our Ukraine-based team are made on the basis of SCCs together with a supplementary transfer risk assessment, given Ukraine's non-adequacy status under Article 45 GDPR.

7. YOUR PRIVACY RIGHTS

A. European Economic Area (EEA) & UK Residents (GDPR)

You have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data and account history.
  • Right to Restrict or Object: Object to or restrict our processing of your data.
  • Right to Data Portability: Receive your personal data in a structured, machine-readable format.
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, contact us at general@2fcorp.com. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at www.aki.ee.

B. California & US Residents (CCPA / CPRA)

Under the California Consumer Privacy Act (CCPA/CPRA):

  • Right to Know & Delete: You have the right to request disclosure of the personal information we collect, use, and share, and the right to request deletion.
  • Opt-Out of "Sale" or "Sharing": We do not sell your personal information for monetary compensation. However, using third-party advertising identifiers may be classified as "sharing" under California law. You may opt-out of personalized advertising directly through your iOS/Android system settings (e.g., "Limit Ad Tracking" or "Ask App Not to Track"). We also recognize and honor the Global Privacy Control (GPC) signal as a valid opt-out-of-sharing request under the CCPA/CPRA where technically detectable.
  • Sensitive Personal Information: We do not collect or process "Sensitive Personal Information" as defined under the CPRA (e.g., precise geolocation, government ID numbers, health, or biometric data). Accordingly, no separate right-to-limit request is applicable at this time; if this changes, this Policy will be updated to include that right.
  • Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

8. DATA RETENTION AND SECURITY

  • Retention: We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy, maintain active subscriptions via RevenueCat, or comply with legal, tax, and accounting obligations under Estonian law. Account data is deleted or anonymized within 30 days of a valid erasure request. Absent an earlier deletion request: gameplay/analytics data and crash logs are retained for a maximum of 24 months from collection and then deleted or irreversibly anonymized; UGC (clues, guesses, chat messages) is retained for the life of the associated account plus 30 days, after which it is deleted or anonymized; and transaction/subscription records are retained for seven (7) years to satisfy Estonian accounting and tax law.
  • Security: We employ industry-standard technical measures, including SSL/TLS encryption in transit, AES-256 encryption at rest, restricted administrative access, and multi-factor authentication across all cloud infrastructure.

9. CHILDREN'S PRIVACY (COPPA / GDPR AGE RESTRICTIONS)

Our Apps and Services are not intended for children under the age of 13 in the United States or under 16 in the European Union. We do not knowingly collect personal information from children. We enforce this through a neutral age-gate at account creation as described in our Terms of Service, Section 1. If we learn that we have inadvertently collected data from a child under these ages without verifiable parental consent, we will delete that information immediately. If you believe a child has provided us with personal data, contact us at general@2fcorp.com.

10. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy periodically to reflect changes in our Apps, multi-app portfolio offerings, regulatory guidance, or legal requirements. We will notify you of material changes by updating the "Last Updated" date at the top of this policy and, where appropriate, displaying an in-app notification.

11. CONTACT US

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:

2F Corp OÜ

Attention: Privacy & Compliance Officer

Tartu mnt 67/1-13b, Tallinn 10115, Republic of Estonia

Email: general@2fcorp.com

Document information
Version
1.0.0
Revision
1
Locale
en
In force from
2026-09-03T16:00:00Z
Archived version
/legal/privacy/1.0.0/en/
Content SHA-256
fee8a04a70d2e3a7105c7f77944e694e6e35ed426b6a323f7cdb59f14e4c7005
2F Corp OÜ — Fortune & FUN
AboutProductsContactPrivacyTermsSupportDelete Account
© 2026 2F Corp OÜ · Registered in Estonia · Fortune & FUN