Kazakhstan Users

Please note: If you are accessing the Service as a resident of, or from within, the Republic of Kazakhstan, your use of the Service is not governed by this document. Instead, your access is subject to a separate Privacy policy governed by the laws of the Republic of Kazakhstan, which can be accessed here.

Privacy Policy for the Portals Application

Version 1.0
Effective date August 2026

1. INTRODUCTION AND DATA CONTROLLERS

Your privacy is of the utmost importance to us and the foundation of our service. We are committed to safeguarding your personal data through strict data firewall protocols, industry-standard encryption methodologies, and non-AI design mechanics. This Privacy Policy explains how APS pay LLP, a limited liability partnership registered under the laws of the Republic of Kazakhstan and an official resident of the Astana Hub International Park of IT Startup (operating globally or through its localized regional affiliates) (together, "Portals", "Company", "we" or "us") collects, uses, and discloses your information when you access or use our websites, mobile applications, interactive self-regulation tools, community features and other online products and services (collectively, the “Services”), and when you contact our customer service team, engage with us on social media, or otherwise interact with us.

Global Data Controller: For all users accessing the Platform globally—specifically excluding residents of the Republic of Kazakhstan, whose data access is subject to a localized policy—the primary Data Controller is APS pay LLP.

Depending on how you interact with our Platform, the following may also apply to you:

Please read the following carefully to understand our practices regarding your personal information. We also strongly encourage you to review our comprehensive Terms of Use [Insert Link to Terms of Use], which outlines the specific governing laws and dispute venues strictly applicable to your residency, including distinct legal stipulations for UK, UAE, and US residents.

2. JURISDICTION, TERRITORIAL SCOPE, AND DATA PORTABILITY

We apply strict, privacy-by-design standards that adapt dynamically to your physical location and residency:

3. DATA SOVEREIGNTY AND FOREIGN ACCESS PROTECTION

Your personal data is protected under the privacy and data-protection laws applicable to the relevant processing and under the security controls described in this Policy. Your selected Home Jurisdiction does not exclude the application of mandatory laws that otherwise apply.

We do not voluntarily provide user data to governmental authorities except where disclosure is legally required or otherwise permitted by applicable law. We assess governmental requests for validity, necessity, proportionality and applicable jurisdiction and disclose only the minimum information legally required.

For our non-Kazakhstan infrastructure hosted on AWS, we use regional and, where implemented, sovereign-cloud controls, including jurisdiction-appropriate cryptographic and access-management safeguards.

4. DATA CLASSIFICATION AND MINIMAL DATA PROCESSING

To align with our privacy-by-design principles, Portals practices strict data minimization. We process only information necessary to operate the app, manage your progression, facilitate multiplayer and community features, provide user-selected content, maintain security, and support the optional features described in this Policy.

5. INFORMATION WE COLLECT AND COLLECTION METHODS

A. Information Provided Directly by You

We practice strict data minimization, collecting only the information required to provide you with a personalized, interactive self-regulation experience. We do not collect clinical questionnaires or psychological assessments. We may collect information when you register for an account, participate in multiplayer features, fill out a form, make a purchase, or communicate with our support team. The information you provide includes:

B. Special Category & Health Integrations:

Certain iteration names or optional health-integration data may reveal or relate to aspects of emotional or physical wellbeing and may be classified as sensitive, special-category, or consumer health data under applicable law. Where applicable law requires explicit consent for sensitive or health-related data, Portals relies on the consent or affirmative action required for the relevant feature and provides the corresponding controls.

How this may arise:

Our Legal Basis & Your Control:
Portals processes user-selected iterations only as needed to provide the practice and operate the Service. We do not use iteration selections to create a clinical or psychological profile.

C. Other Information You May Provide:

password or authentication credentials, language settings, country of residence, content you choose to save, and text you voluntarily add to saved or shared content.

D. Information We Collect When You Use the Services or Interact with Us / Information We Collect Automatically

When you interact with our Services, we collect certain information to ensure the app remains secure, functional, and personalized:

E. When you use the Services, we infer or generate the following information about you to personalise your experience:

F. Information We Collect from Other Sources

We may receive data about you from third parties to streamline your experience:

G. Information You Make Public (or We Collect Publicly):

We may obtain information about you that is publicly available to better understand our community or verify business accounts:

6. USE OF INFORMATION

We process your information only for the purposes described below and under the legal bases applicable to the relevant jurisdiction and processing activity:

7. DISCLOSURE OF INFORMATION

We do not sell your personal data or use your sensitive wellbeing information for cross-context behavioral advertising. We disclose information only as necessary to provide, secure and support the Services, at your direction, or as required or permitted by law.

8. PROTECTION AGAINST PROFILING

We do not sell or disclose your individual wellbeing content, saved mandalas/text, or usage history to:

9. ANALYTICS & ATTRIBUTION

To understand app performance and improve the Service, we use limited operational analytics, crash-diagnostic and attribution services. We do not use these services as a scientific research program.

10. DATA RETENTION & DELETION

We treat your data with a "shelf-life" mindset. We only keep what we need, for as long as it serves your self-regulation journey and the app mechanics you have chosen to engage with.

11. INTERNATIONAL DATA FLOWS & GLOBAL OPERATIONS

To provide our services and real-time multiplayer functionality, personal data may be processed on regional cloud infrastructure.

12. DATA SECURITY: THE CYBER-SHIELD FRAMEWORK

We treat your personal data with the highest level of rigor to protect your privacy and ensure a secure self-regulation journey. We implement a multi-layered security framework:

1. Encryption at Every Step

2. Data Isolation & Access Levels

We use logical separation and access controls within our database architecture to distinguish direct account identifiers from interaction/content data. These data may reside in separate tables within the same database rather than in physically separate databases.

3. Community Content & Public Visibility

13. YOUR PRIVACY RIGHTS AND CONTROLS

We believe you should have total clarity and control over your personal data. Regardless of whether you reside in the United Arab Emirates, the United Kingdom, the United States, or elsewhere globally, we provide these core privacy rights to all members, grounded in the UK GDPR, and applicable US state frameworks.

A. Core Privacy Rights

B. Consent Autonomy & Feature Controls

C. Automated Decisions & Tracking Controls

D. Exercising Your Rights

14. CHILDREN’S PRIVACY & DIGITAL SAFETY

We are committed to maintaining the highest standards of digital safety and high privacy by default for younger users. While Portals is designed primarily for adults, our cognitive self-regulation tools may benefit teenagers, our data practices are guided by the specific age of consent in your jurisdiction.

15. IDENTITY VERIFICATION & AUTHORIZED AGENTS

To protect your sensitive wellness data against unauthorized access or fraudulent privacy requests, we implement strict verification standards.

16. APPEALS AND COMPLAINTS

If we decline to take action on a privacy request, or if you have concerns about how your data is handled, you have the right to request a formal human review and escalate your request.

17. SUPPLEMENTAL NOTICES

Depending on your physical location and jurisdiction of residence, you have additional rights under local privacy laws. We provide this supplemental information to ensure compliance with those frameworks. Please note that APS Pay LLP is headquartered in Kazakhstan and utilizes secure, localized data infrastructure to process your information.

This section provides additional disclosures required by applicable regional privacy laws. Where a conflict exists between this Section 17 and the general terms of this Privacy Policy, this section shall supersede for residents of the respective jurisdiction.

A. INFORMATION FOR INDIVIDUALS IN THE UK, EEA, AND SWITZERLAND

This section applies specifically to users located within the United Kingdom, European Economic Area, and Switzerland.

B. UNITED STATES PRIVACY NOTICES

This Supplemental Privacy Notice applies solely to residents of the United States. It supplements the Portals Global Privacy Policy to comply with comprehensive U.S. state privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Washington My Health My Data Act (MHMDA), and applicable privacy frameworks in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Nevada, Delaware, and other states with active comprehensive privacy legislation.

1. California Privacy Notice (CCPA / CPRA)

Categories of Personal Information Collected (Past 12 Months)
Portals is not a data broker. We do not sell your personal information or share sensitive wellbeing data for cross-context behavioral advertising. The following table describes the categories of personal information processed by Portals for the current Service.

CATEGORY COLLECTED ‘SOLD’/’SHARED’
A. Identifiers (email or Apple private relay email, username, User ID, technical/device identifiers where applicable) Yes No
B. Customer Records (Payment history processed via App Stores) Yes No
C. Internet / Network Activity (App engagement and feature usage) Yes No
D. Sensitive / Consumer Health Information (where applicable: user-selected wellbeing iteration and optional HealthKit/Health Connect data) Yes No

Automated Decision-Making Technology (ADMT)
Portals uses deterministic app mechanics and does not use AI or automated decision-making technology to make decisions about users that produce legal or similarly significant effects. We do not use automated processing to diagnose psychological or medical conditions.

Your California Privacy Rights:

C. WASHINGTON AND NEVADA CONSUMER HEALTH DATA NOTICE

If you are a resident of Washington State or Nevada, or an individual whose data is collected in those states, please refer to our dedicated Consumer Health Data Privacy Policy for specific disclosures required under the Washington My Health My Data Act (MHMDA) and Nevada SB 370. This standalone notice governs our handling of health-related self-regulation selections and can be accessed directly at any time via the link in our website footer or in-app Privacy Settings.

D. PRIVACY NOTICE FOR OTHER US STATES

This section applies to residents of US states with applicable comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, and Oregon and others.

E. ASIA-PACIFIC (AUSTRALIA, JAPAN, MALAYSIA AND SOUTH KOREA)

18. CONTACT US AND GLOBAL PRIVACY INQUIRIES

APS Pay LLP an Astana Hub resident entity incorporated in the Republic of Kazakhstan, serves as the primary Data Controller for users globally (excluding domestic residents of the Republic of Kazakhstan, who are governed by a separate localized Privacy Policy).
To streamline communication and provide a direct "single window" for all global privacy matters, all inquiries, rights requests, and communications regarding this Privacy Policy or our data practices are managed centrally by our primary Data Controller.

Privacy Policy for the Portals Application

Kazakhstan Users

Please note: If you are accessing the Service as a resident of, or from within, the Republic of Kazakhstan, your use of the Service is not governed by this document. Instead, your access is subject to a separate Privacy policy governed by the laws of the Republic of Kazakhstan, which can be accessed here.

Privacy Policy for the Portals Application

Version 1.0
Effective date August 2026

1. INTRODUCTION AND DATA CONTROLLERS

Your privacy is of the utmost importance to us and the foundation of our service. We are committed to safeguarding your personal data through strict data firewall protocols, industry-standard encryption methodologies, and non-AI design mechanics. This Privacy Policy explains how APS pay LLP, a limited liability partnership registered under the laws of the Republic of Kazakhstan and an official resident of the Astana Hub International Park of IT Startup (operating globally or through its localized regional affiliates) (together, "Portals", "Company", "we" or "us") collects, uses, and discloses your information when you access or use our websites, mobile applications, interactive self-regulation tools, community features and other online products and services (collectively, the “Services”), and when you contact our customer service team, engage with us on social media, or otherwise interact with us.

Global Data Controller: For all users accessing the Platform globally—specifically excluding residents of the Republic of Kazakhstan, whose data access is subject to a localized policy—the primary Data Controller is APS pay LLP.

Depending on how you interact with our Platform, the following may also apply to you:

Please read the following carefully to understand our practices regarding your personal information. We also strongly encourage you to review our comprehensive Terms of Use [Insert Link to Terms of Use], which outlines the specific governing laws and dispute venues strictly applicable to your residency, including distinct legal stipulations for UK, UAE, and US residents.

2. JURISDICTION, TERRITORIAL SCOPE, AND DATA PORTABILITY

We apply strict, privacy-by-design standards that adapt dynamically to your physical location and residency:

3. DATA SOVEREIGNTY AND FOREIGN ACCESS PROTECTION

Your personal data is protected under the privacy and data-protection laws applicable to the relevant processing and under the security controls described in this Policy. Your selected Home Jurisdiction does not exclude the application of mandatory laws that otherwise apply.

We do not voluntarily provide user data to governmental authorities except where disclosure is legally required or otherwise permitted by applicable law. We assess governmental requests for validity, necessity, proportionality and applicable jurisdiction and disclose only the minimum information legally required.

For our non-Kazakhstan infrastructure hosted on AWS, we use regional and, where implemented, sovereign-cloud controls, including jurisdiction-appropriate cryptographic and access-management safeguards.

4. DATA CLASSIFICATION AND MINIMAL DATA PROCESSING

To align with our privacy-by-design principles, Portals practices strict data minimization. We process only information necessary to operate the app, manage your progression, facilitate multiplayer and community features, provide user-selected content, maintain security, and support the optional features described in this Policy.

5. INFORMATION WE COLLECT AND COLLECTION METHODS

A. Information Provided Directly by You

We practice strict data minimization, collecting only the information required to provide you with a personalized, interactive self-regulation experience. We do not collect clinical questionnaires or psychological assessments. We may collect information when you register for an account, participate in multiplayer features, fill out a form, make a purchase, or communicate with our support team. The information you provide includes:

B. Special Category & Health Integrations:

Certain iteration names or optional health-integration data may reveal or relate to aspects of emotional or physical wellbeing and may be classified as sensitive, special-category, or consumer health data under applicable law. Where applicable law requires explicit consent for sensitive or health-related data, Portals relies on the consent or affirmative action required for the relevant feature and provides the corresponding controls.

How this may arise:

Our Legal Basis & Your Control:
Portals processes user-selected iterations only as needed to provide the practice and operate the Service. We do not use iteration selections to create a clinical or psychological profile.

C. Other Information You May Provide:

password or authentication credentials, language settings, country of residence, content you choose to save, and text you voluntarily add to saved or shared content.

D. Information We Collect When You Use the Services or Interact with Us / Information We Collect Automatically

When you interact with our Services, we collect certain information to ensure the app remains secure, functional, and personalized:

E. When you use the Services, we infer or generate the following information about you to personalise your experience:

F. Information We Collect from Other Sources

We may receive data about you from third parties to streamline your experience:

G. Information You Make Public (or We Collect Publicly):

We may obtain information about you that is publicly available to better understand our community or verify business accounts:

6. USE OF INFORMATION

We process your information only for the purposes described below and under the legal bases applicable to the relevant jurisdiction and processing activity:

7. DISCLOSURE OF INFORMATION

We do not sell your personal data or use your sensitive wellbeing information for cross-context behavioral advertising. We disclose information only as necessary to provide, secure and support the Services, at your direction, or as required or permitted by law.

8. PROTECTION AGAINST PROFILING

We do not sell or disclose your individual wellbeing content, saved mandalas/text, or usage history to:

9. ANALYTICS & ATTRIBUTION

To understand app performance and improve the Service, we use limited operational analytics, crash-diagnostic and attribution services. We do not use these services as a scientific research program.

10. DATA RETENTION & DELETION

We treat your data with a "shelf-life" mindset. We only keep what we need, for as long as it serves your self-regulation journey and the app mechanics you have chosen to engage with.

11. INTERNATIONAL DATA FLOWS & GLOBAL OPERATIONS

To provide our services and real-time multiplayer functionality, personal data may be processed on regional cloud infrastructure.

12. DATA SECURITY: THE CYBER-SHIELD FRAMEWORK

We treat your personal data with the highest level of rigor to protect your privacy and ensure a secure self-regulation journey. We implement a multi-layered security framework:

1. Encryption at Every Step

2. Data Isolation & Access Levels

We use logical separation and access controls within our database architecture to distinguish direct account identifiers from interaction/content data. These data may reside in separate tables within the same database rather than in physically separate databases.

3. Community Content & Public Visibility

13. YOUR PRIVACY RIGHTS AND CONTROLS

We believe you should have total clarity and control over your personal data. Regardless of whether you reside in the United Arab Emirates, the United Kingdom, the United States, or elsewhere globally, we provide these core privacy rights to all members, grounded in the UK GDPR, and applicable US state frameworks.

A. Core Privacy Rights

B. Consent Autonomy & Feature Controls

C. Automated Decisions & Tracking Controls

D. Exercising Your Rights

14. CHILDREN’S PRIVACY & DIGITAL SAFETY

We are committed to maintaining the highest standards of digital safety and high privacy by default for younger users. While Portals is designed primarily for adults, our cognitive self-regulation tools may benefit teenagers, our data practices are guided by the specific age of consent in your jurisdiction.

15. IDENTITY VERIFICATION & AUTHORIZED AGENTS

To protect your sensitive wellness data against unauthorized access or fraudulent privacy requests, we implement strict verification standards.

16. APPEALS AND COMPLAINTS

If we decline to take action on a privacy request, or if you have concerns about how your data is handled, you have the right to request a formal human review and escalate your request.

17. SUPPLEMENTAL NOTICES

Depending on your physical location and jurisdiction of residence, you have additional rights under local privacy laws. We provide this supplemental information to ensure compliance with those frameworks. Please note that APS Pay LLP is headquartered in Kazakhstan and utilizes secure, localized data infrastructure to process your information.

This section provides additional disclosures required by applicable regional privacy laws. Where a conflict exists between this Section 17 and the general terms of this Privacy Policy, this section shall supersede for residents of the respective jurisdiction.

A. INFORMATION FOR INDIVIDUALS IN THE UK, EEA, AND SWITZERLAND

This section applies specifically to users located within the United Kingdom, European Economic Area, and Switzerland.

B. UNITED STATES PRIVACY NOTICES

This Supplemental Privacy Notice applies solely to residents of the United States. It supplements the Portals Global Privacy Policy to comply with comprehensive U.S. state privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Washington My Health My Data Act (MHMDA), and applicable privacy frameworks in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Nevada, Delaware, and other states with active comprehensive privacy legislation.

1. California Privacy Notice (CCPA / CPRA)

Categories of Personal Information Collected (Past 12 Months)
Portals is not a data broker. We do not sell your personal information or share sensitive wellbeing data for cross-context behavioral advertising. The following table describes the categories of personal information processed by Portals for the current Service.

CATEGORY COLLECTED ‘SOLD’/’SHARED’
A. Identifiers (email or Apple private relay email, username, User ID, technical/device identifiers where applicable) Yes No
B. Customer Records (Payment history processed via App Stores) Yes No
C. Internet / Network Activity (App engagement and feature usage) Yes No
D. Sensitive / Consumer Health Information (where applicable: user-selected wellbeing iteration and optional HealthKit/Health Connect data) Yes No

Automated Decision-Making Technology (ADMT)
Portals uses deterministic app mechanics and does not use AI or automated decision-making technology to make decisions about users that produce legal or similarly significant effects. We do not use automated processing to diagnose psychological or medical conditions.

Your California Privacy Rights:

C. WASHINGTON AND NEVADA CONSUMER HEALTH DATA NOTICE

If you are a resident of Washington State or Nevada, or an individual whose data is collected in those states, please refer to our dedicated Consumer Health Data Privacy Policy for specific disclosures required under the Washington My Health My Data Act (MHMDA) and Nevada SB 370. This standalone notice governs our handling of health-related self-regulation selections and can be accessed directly at any time via the link in our website footer or in-app Privacy Settings.

D. PRIVACY NOTICE FOR OTHER US STATES

This section applies to residents of US states with applicable comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, and Oregon and others.

E. ASIA-PACIFIC (AUSTRALIA, JAPAN, MALAYSIA AND SOUTH KOREA)

18. CONTACT US AND GLOBAL PRIVACY INQUIRIES

APS Pay LLP an Astana Hub resident entity incorporated in the Republic of Kazakhstan, serves as the primary Data Controller for users globally (excluding domestic residents of the Republic of Kazakhstan, who are governed by a separate localized Privacy Policy).
To streamline communication and provide a direct "single window" for all global privacy matters, all inquiries, rights requests, and communications regarding this Privacy Policy or our data practices are managed centrally by our primary Data Controller.