One Question: Mystery Cards

Privacy Policy

Last updated: July 10, 2026

This Privacy Policy explains how One Question: Mystery Cards handles local answers, public Circle profile data, purchases, ads, analytics, crash reports, permissions, sharing, retention, and deletion.

Developer and privacy contact

One Question: Mystery Cards is provided by VIF through the developer account listed for the app on Google Play.

Privacy contact: eduard@vif-com.org Support contact: eduard@vif-com.org

Privacy, support, and deletion requests can also use the public deletion page when the request relates to a One Question public Circle profile.

Open the account/profile deletion request page

Public Play Console URL

For Google Play, this policy must be uploaded as a public HTTPS page on the final VIF domain. It must not be a local URL, PDF, geofenced page, editable document, or restricted page.

https://vif-com.org/legal/one-question/privacy-policy.html

What the app does

One Question: Mystery Cards is a reflection and conversation app. It offers solo mystery boxes, group questions, date-night questions, local written answers, optional local audio/video responses, avatar progress, question packs, reminders, referrals, rewarded ads, Premium subscription access, analytics, and crash reporting.

Data stored locally on the device

The app stores written answers, journal history, custom questions, local progress, avatar level, mystery box usage, settings, optional audio/video responses, local export files, and local consent choices on the device.

Sensitive local app data is excluded from Android cloud backup in the production Android build. If a user shares, exports, records, screenshots, or manually backs up data, the chosen destination may process that data under its own terms and privacy policy.

Public Circle profile data sent to One Question services

If the user creates or uses a public Circle profile, the app may send these profile and social-progress details to the Supabase-backed One Question service:

  • Public Circle display name.
  • Profile identifier.
  • Invite code.
  • Invite relationships and referral connections.
  • Public leaderboard profile and solo answer/progress count used for Circle leaderboards.

This data is used to reserve unique names, apply invite rewards, connect invited users, and show Circle leaderboard comparisons.

The app does not send written answer text, private journal entries, custom question text, audio recordings, or video recordings to the One Question profile registry in the current launch build.

Purchases and subscriptions

Premium subscription purchases are processed by Google Play Billing. Google Play handles payment methods, taxes, receipts, renewals, cancellations, refund flows, and payment security. The app receives purchase status and purchase tokens so Premium can be unlocked and verified. One Question may verify Google Play purchase tokens on a backend server before granting Premium. The app does not receive or store the user's full payment card details.

Rewarded ads

Free users may choose to watch rewarded ads to receive extra mystery box access or reroll certain social mystery card choices. Rewarded ads are optional and the reward is disclosed before the ad is shown.

Ads may be provided through Google AdMob and Google Mobile Ads SDK. Google and advertising partners may collect or receive ad-related data such as approximate device or app information, product interactions, diagnostic data, fraud-prevention signals, IP address, and advertising or device identifiers where available and permitted. Where required, Google-certified consent or privacy-choice screens may be shown before ads are requested.

Analytics and crash reports

If the user consents, the app may use Firebase Analytics and Firebase Crashlytics to understand app usage and diagnose problems. Analytics may include screen or mode selected, category selected, mystery box actions, saves, skips, Premium interest, settings choices, app version, and general app/device diagnostics. Crash reports may include crash and error details, WebView error context, operating system details, app version, device model, and stability diagnostics.

The app is designed not to send answer text, question text, custom question text, invite codes, or recorded media content through analytics or crash reporting. Users choose analytics and crash-report consent during onboarding and can withdraw consent in Settings.

Camera, microphone, and media

Camera and microphone access are used only when the user chooses to record a solo response. Audio and video responses are stored locally on the device in the current launch build. Users should only record themselves or people who clearly agree to be recorded.

If a user shares a recording, Android and the chosen destination app or platform may receive and process the file under their own terms and privacy policy.

Notifications

If enabled, One Question may send local notifications about available mystery boxes, questions, Premium moments, or app activity. Users can disable reminders in the app or through device settings.

Sharing to other apps

If the user chooses to share a question, answer, invite, screenshot, audio file, video file, or other content to another app, the receiving app or platform may process that content under its own terms and privacy policy. User-controlled sharing should be disclosed consistently in the Play Console Data safety form.

Data sharing and service providers

Data may be shared with service providers only as needed to operate app features:

  • Google Play Billing for purchases and subscriptions.
  • Firebase Analytics and Firebase Crashlytics if the user consents.
  • Google AdMob and Google Mobile Ads SDK for rewarded ads and ad consent/privacy choices.
  • Supabase for public Circle profile, invite, deletion request, and leaderboard data.
  • Social or messaging platforms selected by the user when sharing content.

One Question does not sell personal and sensitive user data.

Account/profile deletion and local data deletion

Users can request deletion of their One Question public Circle account/profile from inside the app or through the public web deletion page.

Account/profile deletion removes or starts the removal process for the public Circle data tied to the profile:

  • Public Circle display name.
  • Profile identifier.
  • Invite code.
  • Invite relationships and referral connections.
  • Leaderboard profile and public progress profile.

Separately, users can use Erase all local data in Settings to remove local answers, custom questions, progress, settings, consent choices, and local media metadata from that device.

Open the public account/profile deletion page

Data that may remain after deletion

Some data is not deleted automatically when a public Circle profile is deleted, especially data already processed by third-party platforms or retained for legitimate reasons. This may include:

  • Google Play Billing records, receipts, subscription records, tax records, refund records, and payment security records controlled by Google Play.
  • Firebase Analytics or Crashlytics records that were already processed before consent withdrawal or deletion, subject to Firebase retention settings.
  • Google AdMob and Google Mobile Ads SDK records used for ads, consent, fraud prevention, and platform operation.
  • Supabase logs, backups, abuse-prevention records, legal records, security records, or deletion request records where retention is required or justified.
  • Content the user already shared, exported, screenshotted, backed up, or sent to another app or person.

Data Safety alignment for Google Play

The Play Console Data safety form must match the final Android build, SDK list, permissions, app behavior, and this Privacy Policy. Based on the current launch plan, check the form against Firebase Analytics/Crashlytics, AdMob, Google Play Billing, Supabase public Circle data, camera, microphone, local media, notifications, and user-controlled sharing.

If the final app changes before submission, update this Privacy Policy and the Play Console Data safety answers together.

Children's privacy

One Question: Mystery Cards is not intended for children. The target audience should be configured in Google Play Console to match the final store listing, content rating, ad settings, and question content.

Security and changes

The app uses HTTPS for configured network services. Access to sensitive Android permissions uses runtime permission prompts where available. This policy may be updated when the app changes, when services change, when Play Console disclosures change, or when legal or store requirements change.