Khelio Privacy Policy
Khelio is operated by Tryonixs (“Khelio”, “we”, or “us”) in Pakistan. This policy explains how the Khelio mobile app handles information for entertainment, decision games, social features, and nearby discovery.
1. Information we collect
- Account and profile: email address, display name, profile image or avatar URL, Firebase user ID, linked Supabase user ID, and authentication/session information. Khelio does not store your plain-text password.
- Gameplay and app activity: spins, game results, custom wheels, saved places, virtual coins, wallet balance and ledger entries, live-room participation, selected entry fees/stakes, round outcomes, payouts or refunds, streaks, reactions, and related timestamps.
- Community and social data: public profile, Explore posts and images, comments, likes, game invites, message requests, blocks, and reports.
- Chats and snaps: direct messages, voice notes, conversation membership, read/open status, deletion mode, snap photos or videos, filters, duration, view count, screenshot-event messages where supported, and delivery/expiry metadata.
- Location and searches (optional): a city or address you type, or the approximate or precise coordinates supplied by the operating system when you tap current location, plus place category, budget, and distance inputs. Khelio does not request background location.
- Device and notifications (optional): Expo push token, an app-generated installation ID, platform, device name, notification preferences, and delivery receipts when you enable notifications.
- Support and safety: support emails and reports, including reason, optional details, reported account/content identifiers, reporter account details, and review status.
- Technical data: service providers may process IP address, request timestamps, network information, and diagnostics needed to secure and operate their services. Khelio does not currently include a dedicated third-party crash-reporting SDK.
We do not claim collection of your contacts address book, purchase receipts, or background location. Khelio requests non-personalized ads and does not use the advertising ID for ads personalization.
2. How we use information
- Authenticate accounts and provide profiles, games, saved results, live rooms, Explore, chats, snaps, and nearby recommendations.
- Lock, refund, or settle virtual-coin entry fees for live rooms and Ludo matches on the server so stakes cannot be spent twice.
- Deliver messages and optional notifications, maintain view/expiry state, prevent duplicate actions, and remove expired media.
- Protect users, process blocks/reports, investigate abuse, enforce community rules, and prevent fraud or spam.
- Respond to support and improve reliability. Locally queued gameplay analytics currently remain on the device and are not sent to a cloud analytics provider.
3. Service providers and other recipients
We do not claim to sell personal information. Information is processed by providers needed for the features you use:
- Google Firebase / Google Cloud: authentication, profiles, app data, chat metadata, reports, Cloud Functions, and related workflows.
- Supabase: linked multiplayer identity, live rooms and related game data, Explore media storage, and private chat snaps (with signed URLs for viewing).
- Cloudinary: optional or alternate authenticated snap/media storage and delivery when that upload path is enabled.
- Expo: push-token issuance and notification delivery.
- OpenStreetMap Nominatim: typed place searches and reverse geocoding; queries or coordinates and the network IP address are sent when used.
- Google Gemini through Khelio’s backend: nearby recommendation inputs, including coordinates/city, category, budget, and distance. AI suggestions may be inaccurate and should be verified.
- Google Maps or installed map applications: origin/destination coordinates when you choose maps or directions.
- Google AdMob / Google Mobile Ads: banner advertisements and rewarded video advertisements. Google may process device and usage information needed to deliver and measure ads, in accordance with Google’s advertising policies.
Public profiles, Explore content, comments, likes, and public-room activity are visible to other signed-in users. Chat and snap content is intended only for conversation members. We may disclose information when legally required or necessary to protect users and the service.
4. Virtual coins and live-game stakes
Khelio coins are a virtual entertainment balance. They have no cash value, cannot be withdrawn, and are not a real-money gambling product. Solo games do not charge an entry fee. Live multiplayer rooms may lock a selected entry fee (500, 1,000, 10,000, or 1,000,000 coins) when you join or when a round starts. Ludo winners receive the other seated players’ stakes. Other live rooms credit twice the entry fee when your pick matches the server result. Leaving before a Ludo match or live countdown starts refunds a pending stake. Wallet changes are recorded in a server ledger for fairness and abuse prevention.
5. Advertising
Khelio uses Google AdMob (Google Mobile Ads) to display:
- Banner advertisements in a dedicated layout area below app content, not over buttons, game boards, or navigation.
- Rewarded advertisements that unlock certain in-app features. Watching a rewarded ad to completion may unlock a coin spin, or may appear after a mini-game is finished before the result continues.
A rewarded ad counts toward unlocking a feature only after Google reports that the reward was earned. Closing an ad early, failing to load an ad, or tapping an ad does not grant the unlock. If a rewarded ad cannot be shown, the related unlock is not granted; other parts of the app remain usable.
Khelio requests non-personalized ads. The app does not use the device advertising ID for ads personalization. Google’s own technologies may still collect technical data required to serve ads. Google’s advertising policies apply to those ads.
6. Permissions
- Camera: requested when you open the snap camera to capture a photo or video. Deny → you cannot capture snaps.
- Microphone: requested when you record a voice message or a video snap with sound. Deny → you cannot record voice notes or video with audio.
- Photos and videos: used when you choose media to share (profile photo, Explore posts, chat media, chat backgrounds). On modern Android, Khelio uses the system photo picker without broad storage/library access; iOS may request photo-library access. Deny → you cannot pick gallery media.
- Location (foreground): requested only after you tap the current-location action for nearby places. Deny → manual city/address search still works. No background location.
- Notifications: optional; requested when you enable them in Profile / first-run prompt. The app remains usable without them.
7. Chats, disappearing snaps, and screenshots
Private chat snaps may be stored in Supabase private object storage and/or Cloudinary authenticated storage, depending on the active upload path. Explore images are stored in Supabase media storage and are visible to signed-in users. Temporary access URLs may be issued for viewing. Expired or deleted media is removed on a best-effort schedule; backups, reports, and caches may delay full erasure.
Conversation members select a deletion mode (after viewing, 24 hours after viewing, or keep in chat). Snaps are designed for limited views (typically an initial view plus one replay). Cleanup can be delayed by outages or retries. Recipients can still photograph, screenshot, screen-record, or capture content with another device. Khelio does not provide end-to-end encryption for chat or snaps.
8. Storage, security, and international processing
Data is transmitted over HTTPS/TLS for app-controlled calls and stored using access controls provided by Firebase, Supabase, and Cloudinary. Provider-managed encryption at rest may apply. No system is completely secure, and we do not guarantee absolute security. These providers may process data in countries outside yours under their own infrastructure and contractual terms.
9. Retention
Account, profile, saved, community, multiplayer, wallet, and non-expiring chat data is generally kept while the account or content remains active. Expiring messages follow their selected mode; scheduled deletion can be delayed by outages or retries. Push tokens remain until disabled, replaced, or the account is deleted. Anonymized safety reports are retained for 24 months. Provider backups may persist for up to 30 days. Public Explore images can be cached by recipients or content-delivery networks after deletion.
10. Your choices and deletion
- Update profile and notification preferences in the app.
- Use block/report controls, leave rooms, delete your own posts where offered, sign out, and deny or revoke OS permissions.
- Delete your account in-app at Profile → Settings → Delete account. See the Account Deletion page for what is removed and what may be retained.
- Request deletion without the app through the public deletion page. Ownership verification is required.
11. Children and audience
Khelio includes user-to-user chat, media sharing, location tools, public content, and virtual-coin live games. It is not intended for children under 13. Contact us if you believe an ineligible child supplied personal data.
12. Policy changes
We may update this policy as Khelio changes. We will update the date above and provide additional notice where required.
13. Contact
Questions about privacy: contact@tryonixs.com