Aquarium: Fish Business Empire · Privacy Policy
Privacy Policy — Aquarium: Fish Business Empire
App: Aquarium: Fish Business Empire
Package name: com.lonkerostudio.aquariumfishbusinessempire
Data controller: LonkeroStudio, an independent developer based in Finland (European Union)
Contact for privacy questions: support@lonkerostudio.com
Last updated: 3 October 2026
This policy explains what happens to data when you play Aquarium: Fish Business Empire on Android. It describes what the app actually ships. The file list, the network list and the permission list below were read out of the source code and the built package.
LonkeroStudio is based in the EU, so the General Data Protection Regulation applies to everything in this policy, for every player wherever you live, not only for players in Europe.
The short version
Aquarium: Fish Business Empire has no accounts, no login, no servers of its own, no analytics and no way for one player to reach another. Your tanks, fish and progress live in files inside the app's own private storage on your device.
One thing can leave your device: advertising data, collected by the Google Mobile Ads SDK (AdMob) when the game loads or shows a rewarded video ad. That includes your device's advertising ID, device and app identifiers, approximate location derived from your IP address, ad interactions and diagnostic data. Google uses it for advertising, measurement, fraud prevention and security.
Ads are optional. Each one is behind a button you choose to tap, and the game is complete without ever watching one.
The game does not run an AI model on your phone and does not send anything about your fish to a server. The "thoughts" your fish have are written by the game's own code on your device.
1. Advertising — Google AdMob
The game shows rewarded video ads only. There are no banners and no interstitials. An ad is shown only when you tap a "watch an ad" button, and watching one to the end gives a small in-game reward: a Keeper's Pass, a free refill of the auto-feeder hopper, or a rescue for a tank that has run empty. If you never tap one, nothing about the game changes.
So that the ad is ready when you tap, the game may ask Google for an ad shortly before you are likely to want one, for example when a rescue becomes available. Asking for an ad is when the SDK collects the data listed below, even if the ad is never shown.
Ads are served by Google AdMob using the Google Mobile Ads SDK, which is built into the app. When an ad is requested or shown, that SDK may collect and share with Google and its advertising partners:
- Device or other identifiers: the Android advertising ID (resettable and under your control), and other device and app identifiers.
- Approximate location, derived from your IP address. The app requests no location permission and has no access to GPS or precise location.
- App interactions: ad requests, impressions, clicks and rewards.
- Diagnostics: SDK errors and performance data.
- Device information: model, OS version, language, screen and network characteristics, sent with an ad request.
Purposes: serving and measuring advertising, limiting how often you see an ad, fraud prevention, security and compliance, and analytics on the advertising itself.
Consent. Where the law requires consent for personalised advertising (the EEA, the United Kingdom and Switzerland), the game asks for it in-app through Google's User Messaging Platform (UMP) before it requests personalised ads, and you can change your answer later from the game's settings. If you decline, or the consent form cannot be shown, only non-personalised ads are requested.
As this is written, the game is in testing and shows only Google's test ads. Test ads go through the same SDK, so the collection described above still applies to them, but no advertiser pays for them and they are not personalised. The consent form described above is switched on in the same update that switches on real ads, and this note is removed on that day.
Google sets the purposes and means for most of this collection itself, as a data controller in its own right for those purposes. Its handling of the data is described in:
- Google Privacy Policy — https://policies.google.com/privacy
- How Google uses information from sites or apps that use its services — https://policies.google.com/technologies/partner-sites
- Google Advertising, including the list of ad partners — https://policies.google.com/technologies/ads
The data collected by the ad SDK is sent over HTTPS.
2. What the game stores on your device
The game writes these files into the app's private internal storage, a directory Android gives every app and that no other app can read:
| File | What is in it |
|---|---|
aquarium_profile.json |
what is shared across all your tanks: coins, gems, your level and experience, which maps you have unlocked, the Aquapedia, daily tasks and streaks, goals, your settings (sound, music, thoughts), and which tips and tour steps you have already seen |
aquarium_<map>.json (one per tank: desk, living, sun, ocean) |
that tank: its fish (species, name, gender, age, family, rarity), eggs and babies, decorations, food, water, equipment, and the market history it has seen |
the same names ending .tmp or .bak |
short-lived and backup copies written while saving, so that losing power mid-save cannot cost you your tanks |
Each save carries a signature computed on your device, so that a save edited outside the game can be recognised. It is made from the save itself and a key inside the app; it contains nothing about you and never leaves the device.
No permission is needed for any of this and no dialog is shown, because private app storage is not shared storage. None of these files contains a name, an email address, a phone number, an account, a contact, a photo or a location. The only things you type are search words and amounts, and they are not saved.
The files are never uploaded, and uninstalling the app deletes all of them.
Android Auto Backup is switched off for this app (allowBackup="false" in
the package). Your save is not copied to your Google account, which also means it
does not follow you to a new phone.
3. Time checks
The game keeps a game calendar (fish age, the market and daily tasks follow real time), and it can confirm the time with a single HTTPS request that carries no data about you or your game: only the date in the reply is read. The server that answers would see your IP address, as every server you connect to does.
In the current version no time server is configured, and the released app makes no such request. If one is added, this section will name it before the update that uses it ships.
4. What the game does NOT do
- No user accounts, sign-in or profiles.
- No analytics SDK, no crash-reporting SDK, and no statistics of any kind sent by the game's own code.
- No server operated by the developer. The only network traffic is the ad SDK's, described in section 1.
- No real-money purchases. Coins, gems and the Keeper's Pass are earned and spent inside the game. If purchases are ever added they will go through Google Play's billing, we will never see your payment details, and this policy will say so first.
- No downloads after install: the art and music are inside the app.
- No on-device AI model and no AI service. Fish thoughts are written by the game's code.
- No social features, chat, user-generated content or sharing.
- No access to contacts, photos, files, the camera, the microphone, the calendar, SMS, call logs, health data or precise location.
- No automated decision-making and no profiling by us in the sense of GDPR Art. 22. (Google's advertising systems do profile for ad selection; that is section 1 and Google's own terms.)
- Nothing is sold for money. On "sharing" as California defines it, see section 8.
The game is fully playable offline and with no ad ever watched.
5. Permissions in the package, and why each is there
Read from the built package. INTERNET and ACCESS_NETWORK_STATE are requested
by the game itself for ad requests. Every other one comes with the ad SDK or one
of its own libraries. None is requested at runtime and none opens a permission
dialog.
| Permission | Why |
|---|---|
INTERNET, ACCESS_NETWORK_STATE |
fetching a rewarded ad, and knowing whether the network is available |
AD_ID, com.google.android.gms.permission.AD_ID |
the advertising ID, used by AdMob |
ACCESS_ADSERVICES_TOPICS, ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION |
Android Privacy Sandbox interfaces used by the ad SDK |
READ_BASIC_PHONE_STATE |
declared by Google Play services; the game never reads phone state |
FOREGROUND_SERVICE, WAKE_LOCK |
declared by a background-work library that comes with the ad SDK; the game schedules no background work and starts no foreground service |
There is no storage, location, camera, microphone, contacts or notification permission in the package.
6. Your choices
- Simply do not watch the ads. Every ad is behind a button you choose to tap.
- Play offline. With no network the game runs normally and no ad is requested.
- Change your ad consent (EEA, UK, Switzerland) from the game's settings once the consent form is live (see the note in section 1).
- Reset or delete your advertising ID: Android Settings → Privacy → Ads (the path varies by manufacturer). Deleting it stops apps from receiving it.
- Opt out of ad personalisation in the same settings screen, and at https://adssettings.google.com.
- Read this policy in the game: SETUP → Privacy opens this page (and Terms the terms of use).
- Erase your progress: SETUP → Erase data wipes every tank, fish and coin on this device after you confirm.
- Delete everything by uninstalling the app. There is no other copy.
7. How long data is kept, and your rights
We hold no personal data about you. Nothing the game stores reaches us, and we run no server it could reach. Your save stays on your device until you uninstall the app.
For the data the ad SDK collects, Google decides the purposes and keeps the data under its own policies and retention periods (links in section 1). We never receive it and cannot delete it for you. Section 6 has the controls that limit and reset it.
Under the GDPR you have the right to access, correct and erase your personal data, to restrict or object to its use, to data portability, and, where we rely on consent, to withdraw it at any time. Because we hold nothing that identifies you, there is nothing for us to look up; for ad data, Google's tools above are the way to exercise these rights. You can still write to us at any time and we will answer within one month.
You may complain to a supervisory authority. Ours is the Finnish Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), https://tietosuoja.fi/en/. In another EU or EEA country you may use your own national authority (list: https://edpb.europa.eu/about-edpb/about-edpb/members_en); in the United Kingdom, the Information Commissioner's Office, https://ico.org.uk/make-a-complaint/.
Where the data goes. The ad SDK sends data to Google, which processes it in the United States and other countries outside the EEA under its own transfer safeguards (the European Commission's standard contractual clauses and, where applicable, the EU-US Data Privacy Framework), described at https://business.safety.google/privacy/.
Legal bases. Personalised ads: your consent (Art. 6(1)(a)) given through the UMP form. Non-personalised ads: your request for the ad when you tap the button, with Google relying on its own legitimate interests for fraud prevention and security. Keeping your save on your device: necessary to provide the game you asked for, and none of it reaches us.
8. Region-specific notes
United Kingdom
The UK GDPR and the Privacy and Electronic Communications Regulations apply in the same way as the European rules above.
California
Through the Google Mobile Ads SDK the app collects and discloses identifiers (the advertising ID and app or device identifiers), internet or other network activity (ad requests, impressions, clicks, rewards and SDK diagnostics) and approximate location derived from an IP address, for advertising, measurement, fraud prevention, security and compliance. No sensitive personal information is collected. We do not sell personal information for money. When personalised ads are on, the SDK's disclosure of your advertising ID to Google for interest-based advertising counts as "sharing" under California law; opt out of ad personalisation, reset or delete your advertising ID, or never watch an ad to stop it. LonkeroStudio does not meet the CCPA's thresholds (https://oag.ca.gov/privacy/ccpa) as at the date above; if that changes, this section will add a "Do Not Sell or Share" control.
9. Children
Aquarium: Fish Business Empire is not directed at children. Its target audience declared in Google Play Console is ages 13 and over; no age group under 13 is selected, and the app is not in Google Play's Designed for Families programme. We do not knowingly collect personal information from children under 13. If you believe a child has provided information through the ad SDK, use the controls in section 6 and contact us.
10. Changes
If this policy changes, the "Last updated" date changes with it, and the current version always lives at https://lonkerostudio.com/aquarium/privacy/, the URL registered in Google Play Console. Where a change affects what happens to data, we will say so in the update notes and, where consent is needed, ask again.
11. Contact
LonkeroStudio, Finland — support@lonkerostudio.com