Privacy Policy
This Privacy Policy explains how Wizzo Pty Ltd ("Zaparoo", "we", "us") collects, uses, shares, and protects personal information when you use zaparoo.com, Zaparoo Online, our apps, hosted APIs, cloud features, and related services (collectively, the "Service").
Wizzo Pty Ltd, based in Western Australia, Australia, is responsible for the personal information covered by this policy. Some third parties, such as payment processors and app stores, also act under their own privacy policies for information they collect directly from you.
This policy is effective as of February 25, 2026.
Last updated: July 30, 2026
Privacy at a Glance
- We do not sell personal information.
- We do not use targeted advertising or third-party advertising pixels.
- We use account and device data to provide Zaparoo features, not to build advertising profiles.
- Cloud backups are private and encrypted in transit and at rest, but they are not end-to-end encrypted. The detailed access explanation is below.
- We use service providers for hosting, authentication, payments, support, analytics, email, error reporting, and optional features.
- You can request access, correction, export, or deletion of your personal information.
Information We Collect
The information we collect depends on the features you use.
Account and Profile Information
- Account identifiers, username, display name, email address, and the sign-in provider you choose.
- Confirmation that you meet the minimum age requirement and records of your acceptance of our Terms and this policy.
- Account roles and status, security settings, multifactor-authentication status, and account-deletion requests.
Cards, Decks, Content, and Activity
- Cards, decks, scripts, mappings, redeemed codes, licenses, collection metadata, images, descriptions, and other content you create or manage.
- Play history you choose to sync, such as game or media names, systems, start and end times, and play duration.
- Developer submissions, published content, copyright notices, content reports, and moderation correspondence.
Devices and Cloud Features
- Linked-device identifiers and names, platform, operating system, architecture, Core version, capabilities, link time, last-seen time, and backup or remote-session status.
- Cloud-backup contents and metadata, described in detail under Cloud Backup Data below.
- Short-lived connection and signaling information needed to connect devices through optional remote features. We do not use remote-session traffic for advertising or profiling.
Purchases and Integrations
- Product, subscription, entitlement, store, renewal, expiration, and transaction-reference information received from payment providers. We do not receive or store full payment-card details.
- Information from an integration you choose to connect, such as a Patreon account identifier, membership status, name, or email address.
- API-key name, display prefix, scopes, creation time, and last-used time. Secret API keys are stored as one-way hashes and cannot be shown again after creation.
Communications, Diagnostics, and Usage
- Messages and contact details you provide when seeking support, submitting a form, reporting content, or communicating with us.
- IP address, browser or app type, device type, operating system, request time, pages or endpoints used, referral information, and security or rate-limit events.
- Crash and error details, including the operation that failed and relevant device, account, request, or service identifiers. We try to avoid sending unnecessary content or credentials in diagnostic data.
- Limited, cookieless website analytics, including page views, referrer, browser, device type, and approximate country or region derived from an IP address.
How We Collect Information
We collect information:
- directly from you when you register, configure, buy, publish, or contact us;
- from Zaparoo software and linked devices when you enable online features;
- from providers you use with the Service, such as Firebase, Paddle, RevenueCat, an app store, an identity provider, Patreon, or Shopify;
- automatically through server logs, security controls, diagnostics, and limited analytics; and
- from public sources such as game-catalog providers where needed to identify or describe media.
You can use public parts of our website without an account. Some information is required to create and secure an account or deliver a requested feature. If you do not provide it, that feature may not work.
Why We Use Information
We use personal information to:
- create, authenticate, secure, and support accounts;
- link devices and provide cards, decks, play history, backups, restores, remote connections, APIs, subscriptions, and other requested features;
- process purchases, entitlements, cancellations, and refunds;
- send transactional messages and important Service notices;
- respond to questions, support requests, and privacy requests;
- detect fraud, abuse, security incidents, copyright infringement, and violations of our Terms;
- diagnose problems and maintain, measure, and improve the Service;
- meet legal, accounting, reporting, and regulatory obligations; and
- establish, exercise, or defend legal claims and protect people or property.
Where GDPR or UK GDPR applies, our legal bases are performance of our contract with you, compliance with legal obligations, your consent where requested, and our legitimate interests in operating, securing, supporting, and improving the Service. We balance those interests against your rights and do not rely on them where your rights override them.
We do not use backup contents, private account content, or support communications for advertising, data-brokerage, or training our own AI models. We may use aggregated or de-identified statistics that no longer identify a person to understand and improve the Service.
Cloud Backup Data
When you enable cloud backup, compatible Zaparoo Core software selects supported, allowlisted device files for backup. Depending on platform, these may include Zaparoo data and mappings, game saves, save states, input mappings, settings, and application configuration files. We also store file paths, categories, hashes, sizes, timestamps, device and platform details, backup dates, and restore status.
Backups are not published or shared with other users. You can access them through your signed-in account and compatible linked devices. Any person or application holding an API key you created with backup-read permission can also access backup metadata and file contents until you revoke that key. Only grant that scope to software you trust.
Backup data is encrypted in transit and stored in private, access-controlled object storage using provider-managed encryption at rest. We mirror a copy to a second storage provider for disaster recovery. This is server-side encryption, not end-to-end or zero-knowledge encryption. Zaparoo systems hold credentials needed to process, download, and restore backups, and authorized requests to the storage providers can decrypt the stored data.
A limited number of authorized Wizzo personnel with infrastructure responsibilities may technically access backup contents. Personnel may access them only when reasonably necessary to provide support you ask for, maintain Service security or integrity, investigate suspected abuse, respond to a valid legal request, enforce our Terms, or protect users, the public, or Wizzo Pty Ltd. We do not routinely inspect backup contents. Storage and hosting providers may also process the data to provide their contracted services.
Backup history is kept according to the limits and retention rules for the feature. Unlinking a device does not necessarily delete its existing backups. When a backup is logically deleted, it becomes unavailable for normal restore. Because files may be deduplicated and packed across snapshots, underlying bytes shared with a retained snapshot remain until no retained snapshot needs them. Unreferenced data then passes through a limited recovery and deletion period before removal from primary and disaster-recovery storage.
AI Features
If you use an AI-assisted feature or our AI API proxy, request content, images, tool definitions, and tool results may be sent to Google Gemini for processing. We store account-level usage information such as date, request count, token count, and model so we can enforce quotas and operate the feature. Do not submit secrets or sensitive personal information that the feature does not need. Google processes requests under its applicable service and privacy terms.
When We Share Information
We may disclose relevant information to:
- providers that host, secure, monitor, support, or deliver the Service;
- identity, payment, subscription, app-store, and integration providers you choose to use;
- professional advisers, insurers, auditors, and contractors subject to appropriate duties of confidence;
- courts, regulators, law enforcement, rights holders, or other parties when required by law or reasonably necessary to protect rights, safety, and the Service; and
- a buyer or successor involved in a merger, financing, reorganization, or sale of all or part of our business, subject to applicable law and continued protection of the information.
Providers currently used for relevant parts of the Service include:
- Firebase and identity providers selected by users for authentication;
- DigitalOcean, Backblaze, BunnyCDN, Cloudflare, and Twilio for infrastructure, storage, content delivery, or optional network relay;
- Paddle, RevenueCat, Apple, Google, and Shopify for purchases, subscriptions, entitlements, and shop services;
- Resend and Web3Forms for email and contact forms;
- Rollbar and Umami for error reporting and limited analytics;
- Google Gemini for AI features;
- Patreon for optional membership linking; and
- IGDB/Twitch for game-catalog information.
Providers receive only the information reasonably needed for their role and may independently collect information from you under their own privacy policies. We do not sell or rent personal information or share it for cross-context behavioral advertising.
International Processing
We operate from Australia and use providers that process information in the United States, Australia, United Kingdom, European Economic Area, and other countries where they maintain facilities. These countries may have privacy laws different from those where you live.
Where applicable law requires safeguards for an international transfer, we use an available lawful mechanism, which may include contractual protections, adequacy decisions, or another recognized safeguard. You may contact us for more information about a transfer relevant to you.
Security
We use measures appropriate to the nature of the information and the size of the Service. These include encrypted transport, access controls, private storage, encryption at rest where described, credential hashing or encryption where appropriate, multifactor authentication for privileged product administration, backups, monitoring, and procedures for responding to incidents.
We restrict personnel and service-provider access to legitimate duties. Technical ability to access data does not authorize personal or casual use. No transmission or storage system is completely secure, however, and we cannot promise that an incident or data loss will never occur. Protect your account, devices, recovery methods, and API keys, and tell us promptly if you suspect compromise.
Retention and Deletion
We keep personal information only as long as reasonably needed for the purposes described above. Retention depends on the type of information, whether your account or feature remains active, security and dispute needs, and legal obligations.
- Active account and feature data is generally retained while your account exists or while needed to provide the feature.
- Account deletion has a 14-day grace period. After it takes effect, we delete or de-identify account data, subject to the exceptions below.
- Backup data follows the feature-specific lifecycle described in the Cloud Backup Data section.
- Payment, tax, corporate, and transaction records may be retained for the period required by law, commonly five to seven years.
- Security logs, abuse records, content reports, and legal records may be retained for a reasonable period needed to protect the Service, investigate an incident, resolve a dispute, or comply with law.
- Public content may remain where others reasonably rely on it, but we will remove its association with your account where reasonably possible after account deletion.
Deletion from active systems may be followed by a limited period in deletion queues, caches, system backups, or provider recovery systems. Information retained only for those purposes is not used for ordinary business activity and is removed or overwritten through normal cycles.
Your Choices and Rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal information; obtain a portable copy; withdraw consent; and complain to a privacy regulator. We make core access, correction, export, and deletion options available to users generally, not only where a particular privacy law requires it.
- Use available account tools to view or update account data, download an account export, manage API keys, and schedule account deletion.
- Account exports include backup records and authenticated download locations; backup file contents may need to be downloaded separately.
- Use the unsubscribe link in a marketing email to stop marketing. We may still send security, billing, account, and other essential Service notices.
- Contact privacy@zaparoo.com if a tool does not cover your request.
We may need to verify your identity before acting. A right may be limited where an exception applies, such as protecting another person's privacy, preserving security, or complying with law. If we cannot fulfill a request, we will explain why where the law allows. We will not discriminate against you for exercising a privacy right.
Automated Service Decisions
Our systems automatically apply subscription entitlements, feature quotas, rate limits, account requirements, and basic security or abuse controls using information such as subscription status, account status, usage totals, and request activity. This can allow, limit, or temporarily block access to a feature. We do not use personal information for solely automated decisions intended to produce legal or similarly significant effects. Contact support if you believe an automated control is wrong and want it reviewed.
Cookies, Browser Storage, and Analytics
Our public website uses Umami for limited, cookieless analytics and does not use advertising trackers. Account services use essential cookies, local storage, or session tokens for authentication, security, settings, and core functionality. Payment, shop, embedded, or linked third-party services may use their own storage under their policies.
Because we do not sell personal information or use cross-context behavioral advertising, browser "Do Not Track" or Global Privacy Control signals do not change those practices.
Children
Zaparoo accounts are not intended for children under 13, and users must confirm they are at least 13. If local law requires a higher age or parental authorization, that requirement also applies. If we learn that we collected personal information from a child who could not lawfully provide it, we will take reasonable steps to delete it. Contact us if you believe this has happened.
Public Content and External Services
Content you submit for publication can be seen, copied, or retained by others. Do not publish information you want to keep private. The Service also links to external sites and services that we do not operate. Their handling of information is governed by their own policies.
Changes to This Policy
We may update this policy when our practices, providers, or legal obligations change. We will post the updated policy here with a new date. If a change materially affects how we use personal information, we will give registered users reasonable advance notice by email or through the Service and obtain consent where required by law.
Privacy Questions and Complaints
Send privacy questions, rights requests, or complaints to:
Privacy Contact
Wizzo Pty Ltd
Western Australia, Australia
privacy@zaparoo.com
For a complaint, describe what happened and how you would like it resolved. We will investigate and aim to respond in writing within 30 days. If you remain dissatisfied and a privacy law applies, you may contact the Office of the Australian Information Commissioner, your local EU or UK supervisory authority, the Office of the Privacy Commissioner of Canada, a U.S. state privacy regulator, or another regulator available where you live.