Privacy Policy
Last updated: September 29, 2025
1. Introduction
EmojiHouse ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our developer platform and API services.
By using our services, you agree to the collection and use of information in accordance with this policy. We comply with GDPR, CCPA, and other applicable privacy regulations.
2. Information We Collect
OAuth Authentication Data
- Email address from your OAuth provider
- Display name and profile picture
- Unique OAuth provider ID
- OAuth provider type (Google, GitHub, Apple)
API Usage Data
- API endpoints accessed
- Request timestamps and frequency
- Response times and status codes
- IP addresses (processed for security and geolocation, limited retention)
- User agent information
Behavioral Data (For Attribution & Fraud Prevention)
ℹ️ Complete Disclosure of Behavioral Tracking
We collect detailed behavioral signals to enable accurate attribution and prevent fraud. This data is used ONLY for these purposes, not for cross-site tracking or building advertising profiles.
- Emoji engagement patterns (selection, timing, frequency)
- Session duration and interaction timing
- Mouse/touch movement patterns (bot detection)
- Scroll depth and velocity (engagement verification)
- Click patterns and interaction analysis
- Page visibility and tab switching behavior
- Device orientation changes (mobile verification)
- Form interaction patterns
- Network timing and latency (fraud detection)
- Device fingerprints (see Section 7 for details)
Technical Data
- Browser type and version
- Operating system
- Device information
- Cookies and similar technologies
3. How We Use Your Information
- Authentication & Security: Verify your identity and secure your account
- API Services: Provide access to our development tools and APIs
- Usage Analytics: Monitor and improve our service performance
- Communication: Send important service updates and notifications
- Legal Compliance: Meet our legal obligations and prevent abuse
- Service Improvement: Enhance user experience and develop new features
4. Cookie Policy
We use cookies and similar technologies to enhance your experience. You can manage your cookie preferences through our consent management system.
Cookie Categories:
- Necessary: Essential for authentication and security (always enabled)
- Analytics: Help us understand usage patterns (optional)
- OAuth: Enable third-party authentication providers (optional)
5. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share information in these limited circumstances:
- OAuth Providers: Only during authentication flow
- Service Providers: Trusted partners who help operate our services
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In case of merger or acquisition
6. Your Privacy Rights
Under GDPR, CCPA, and other privacy laws, you have the following rights:
Access & Portability
Request a copy of your personal data in a portable format
Rectification
Correct inaccurate or incomplete information
Erasure
Delete your personal data ("right to be forgotten")
Objection
Object to processing based on legitimate interests
Exercise Your Rights:
7. Device Fingerprinting
Transparency: We Use Limited Device Fingerprinting
To protect our platform and advertisers from fraud, we generate device fingerprints using technical metadata. This is done exclusively for security and fraud prevention, not for advertising or cross-site tracking.
What We Collect for Fingerprinting:
- Device type (desktop, mobile, tablet)
- User agent string (browser and OS version)
- Screen resolution and color depth
- Timezone and language settings
- Platform information
How We Use Device Fingerprints:
- Fraud Detection: Identify suspicious patterns and protect advertisers
- Bot Prevention: Distinguish real users from automated scripts
- Attribution Accuracy: Improve confidence scoring
- Security: Detect and prevent unauthorized access
Privacy Protections:
- Fingerprints stored for 90 days maximum, then anonymized
- Used ONLY for fraud prevention, not ad tracking
- Never shared with third parties or advertisers
- You can request deletion via our data export/deletion tools
Legal Basis (GDPR): Legitimate interest (fraud prevention and service security). You may object to processing, but this may affect service availability.
8. Data Security
We implement industry-standard security measures to protect your information:
- End-to-end encryption for data transmission
- Secure OAuth 2.0 authentication flows
- Regular security audits and monitoring
- Access controls and principle of least privilege
- Data backup and recovery procedures
9. Data Retention
We retain your information only as long as necessary:
- Account Data: Until you delete your account
- API Logs: 12 months for security and debugging
- Analytics Data: 24 months in aggregated, anonymized form
- Legal Hold: Extended retention if required by law
10. International Data Transfers
Our services are hosted in secure data centers. For international transfers, we ensure adequate protection through standard contractual clauses and other approved mechanisms under applicable privacy laws.
11. Updates to This Policy
We may update this Privacy Policy to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes via email or through our platform.
12. Contact Us
If you have questions about this Privacy Policy or want to exercise your privacy rights:
Email: privacy@emojihouse.ai
Address: EmojiHouse Privacy Team
[Your Business Address]
Data Protection Officer: dpo@emojihouse.ai
EU Residents: You have the right to lodge a complaint with your local data protection authority if you believe we have not addressed your concerns adequately.