Privacy Policy

Last updated: 5 October 2026

Table of Contents

  1. Introduction and scope
  2. Data controller identity and contact
  3. Summary of data practices
  4. Information we collect
  5. How we use your information
  6. Legal bases for processing under GDPR
  7. Third-party service providers
  8. International data transfers
  9. Data retention
  10. Your rights under GDPR (EU/UK)
  11. Your rights under CCPA/CPRA (California)
  12. Your rights under LGPD (Brazil)
  13. Other regional rights
  14. Children's privacy
  15. Security measures
  16. Apple App Privacy Nutrition Label disclosures
  17. Cookies and similar technologies
  18. Changes to this policy
  19. How to contact us and exercise your rights

1. Introduction and scope

This Privacy Policy explains what data Gossipy collects, why it is collected, and the rights you have. The solo game works without an online account. An anonymous account is created only when you use multiplayer, leaderboards, or another online feature.

This Privacy Policy (the "Policy") describes how personal data is handled in connection with the mobile application Gossipy (the "App"), an iOS narrative investigation game. The App is published and operated by KOFY, a French société par actions simplifiée unipersonnelle (SASU) (the "Developer", "we", "us", or "our").

The practices described here cover version 2.3.0 and later. Data flows can differ on earlier installed versions.

This Policy applies exclusively to the App and to the limited data flows triggered by your use of the App. It does not apply to the Apple App Store itself, to your iOS device, or to any third-party website or service that is not operated by the Developer, even when accessed from a link inside the App. Apple's processing of your data as the App Store operator is governed by Apple's Privacy Policy.

This Policy explains our data practices. Reading it or continuing to use the App does not constitute consent to processing for which your consent is required.

2. Data controller identity and contact

KOFY is the data controller for the personal data processed through Gossipy.

The data controller for any personal data processed in connection with the App is:

Throughout this Policy, references to "the Developer", "we", "us", and "our" refer to KOFY. The Developer has not appointed a Data Protection Officer because the processing carried out does not require one under Article 37 of the General Data Protection Regulation (GDPR).

3. Summary of data practices

The solo game does not require a login. Online play uses a pseudonymous account and generated public alias. We also process limited data to deliver the App, manage subscriptions, understand App use, and measure advertising.

TopicPosition
Name and loginThe first name or pseudonym entered for conversations stays on your device. No email or password is requested. Online features use an automatically generated account identifier and public alias.
Multiplayer and leaderboardsSupabase stores the generated alias, selected avatar and style, game statistics, leaderboard entries, duel membership, progress and results.
Subscription processingApple and RevenueCat manage purchases and access. Subscription events also support product analytics and advertising measurement.
Product analyticsPostHog receives selected usage events and technical metadata. Session replay and automatic screen capture are disabled.
Advertising measurementSingular measures installations, sessions, purchases and selected events. Configured events can be shared with TikTok for campaign measurement and optimisation.
iOS advertising identifier (IDFA)Available only if you grant Apple's App Tracking Transparency permission. Refusing does not stop all analytics or privacy-preserving attribution.
Account deletionIf an online account exists, you can delete it and its associated player data directly in Profile > Account. App Store subscriptions must be cancelled separately with Apple.
ChildrenThe App is intended for users aged 17 or older and is not directed at children.
Advertising data sharingWe share limited identifiers, technical data, purchase information and events with TikTok through Singular for advertising measurement and campaign optimisation.

Creator-programme exception. A person who voluntarily applies to the paid creator programme provides the professional identity, address, tax and bank details described in Section 4.1. Ordinary game use still requires no email, password or legal identity.

4. Information we collect

4.1 Information you provide

The first name or pseudonym used to personalise conversations remains on your device. Online surfaces show a server-generated alias instead.

The App has no email-and-password signup or login screen. The first name or pseudonym entered during onboarding does not need to be real and is not sent to Supabase, opponents, or leaderboards. If you choose an online feature, the App creates a pseudonymous guest account without asking for an email, password, phone number, or photo. Other players can see only a generated alias such as “Detective-AB12CD”, your selected avatar and style, and game or duel results. You may also enter a creator code in Settings; it identifies a referral campaign, not your real-world identity.

If you voluntarily apply to the paid creator programme, Gossipy collects your public TikTok or Instagram username, follower count and temporary bio-verification code; legal name; professional address; tax residence and registration country; business form and registration number; VAT status and optional VAT number; signed collaboration agreement; bank-account holder name, IBAN and optional BIC; submitted video links; public view counts; calculated earnings; and payment status. Bank details are encrypted before storage. This information is used only to assess eligibility, administer the collaboration, track submitted content and make or document manual bank transfers.

If you choose to contact the Developer by email at the address listed in Section 2 or Section 19, the email content you send will be received and read by the Developer and may be retained as needed to respond to your request and to comply with applicable record-keeping obligations.

4.2 Information collected automatically

Technical data and selected events are collected for content delivery, referrals, product analytics, and advertising measurement. Your game save and the text you enter are separate from this telemetry.

The following categories of data may be collected automatically when you use the App:

4.3 Information from third parties

Apple and RevenueCat provide purchase and subscription information. Our measurement providers also report App usage and campaign attribution.

When you purchase or restore an in-app subscription, the following information is transmitted to RevenueCat, which acts as a data processor on behalf of the Developer:

The Developer accesses this data through RevenueCat to manage subscription access, restore purchases, and analyse subscriptions. The App supplies RevenueCat with its PostHog installation identifier and Singular device identifier, together with App/device metadata and ATT status. RevenueCat sends subscription lifecycle events to PostHog, where they can be connected to App usage through the installation identifier. Singular also receives the pseudonymous RevenueCat app user identifier to connect measurement for the same App user. These links do not require an account or your real name. RevenueCat's privacy practices are described at revenuecat.com/privacy.

PostHog and Singular provide event reports and derived information such as usage patterns and acquisition source. Singular and TikTok provide advertising-performance and attribution information, including whether an installation or action is associated with a campaign.

Apple may also independently collect aggregated, non-identifying analytics about the App through App Store Connect (App Analytics), in accordance with Apple's Privacy Policy. The Developer can view aggregated charts in App Store Connect but does not receive raw personal data from this source.

5. How we use your information

We use the data described above to operate Gossipy, understand its use, and measure and improve our advertising.

The Developer processes the data categories listed in Section 4 for the following purposes:

Paid creator collaborations. Creator-programme data is used to verify eligibility and account ownership, form and retain the collaboration agreement, track public videos and view counts, calculate remuneration, make manual bank transfers, document payments, prevent fraud, and grant the promised creator Premium benefit.

The Developer does not carry out automated decision-making that produces legal or similarly significant effects on you.

Data protection law and rules on access to information on your device apply separately. Pseudonymous identifiers remain personal data when they can distinguish a user or device.

PurposeData categoryLegal basis (GDPR Art. 6)
Online gameplay, multiplayer and rankingsPseudonymous account ID, generated alias, avatar, style, stats, progress and resultsArt. 6(1)(b), performance of the service requested by the player
Delivering and securing the AppIP address, request and technical metadataArt. 6(1)(b) for delivery; Art. 6(1)(f) for security and fraud prevention
Managing subscriptionsPseudonymous user ID, receipt, subscription and purchase metadataArt. 6(1)(b), performance of the subscription contract
Creator referralsInstallation ID, creator code, referral events and timestampsArt. 6(1)(f), campaign administration and fraud prevention
Product analyticsPseudonymous identifiers, usage, purchase and technical eventsConsent under Art. 6(1)(a) where required; otherwise Art. 6(1)(f), App improvement
Advertising measurementIdentifiers, purchases, selected events, device and network metadataConsent under Art. 6(1)(a) where required
Support and legal complianceCorrespondence and legally required recordsArt. 6(1)(b) and Art. 6(1)(c)

The optional creator programme processes professional identity, social-profile and public-video data, the agreement, tax and bank details, earnings and payment records under Art. 6(1)(b) to take steps at the creator's request and perform the collaboration agreement; Art. 6(1)(c) for applicable tax and accounting duties; and Art. 6(1)(f) for fraud prevention and programme security.

You may object to processing based on legitimate interests by contacting us. Where processing relies on consent, you may withdraw it without affecting processing lawfully carried out before withdrawal.

ATT controls iOS tracking permission and access to IDFA. It does not by itself provide a separate consent choice for every analytics or data-sharing purpose. The current App does not offer a separate general analytics or advertising-sharing switch. Sections 4.2 and 7.4 describe the flows that can continue without IDFA; Section 10 explains the available controls and how to contact us about them.

7. Third-party service providers

We use service providers for content, subscriptions, analytics, and advertising measurement. Apple and advertising partners also process data under their own applicable terms and privacy notices.

7.1 RevenueCat

RevenueCat, Inc., a Delaware corporation headquartered in the United States, provides the subscription management infrastructure that validates Apple receipts and exposes your subscription status to the App. RevenueCat acts as a data processor on behalf of the Developer. Categories of data processed are listed in Section 4.3. RevenueCat publishes data-processing terms, including provisions for international transfers. RevenueCat's privacy practices are described at revenuecat.com/privacy.

7.2 Cloudflare

Cloudflare is operated by Cloudflare, Inc., a company headquartered in the United States, with edge servers distributed worldwide. Cloudflare stores the App's static assets in its R2 object storage and delivers them over its content delivery network, processing the standard access logs described in Section 4.2. Cloudflare acts as a data processor on behalf of the Developer. Because of the global edge architecture, your requests are typically served by the geographically closest edge node, which may be located outside the European Union, see Section 8. Cloudflare's privacy practices are described at cloudflare.com/privacypolicy.

7.3 Apple

Apple Inc. and its affiliates (collectively, "Apple") operate the App Store, the in-app-purchase infrastructure, and push notification delivery. Apple acts as an independent data controller with respect to its own processing of your data as an App Store customer. The Developer has no access to your Apple ID, your Apple payment information, or your Apple account. Apple may also collect aggregated App Analytics (anonymous funnel and crash metrics) which the Developer can view in App Store Connect. Apple's practices are governed by Apple's Privacy Policy and the App Store & Privacy notice.

7.4 Advertising and attribution partners

Singular is our mobile measurement provider. It processes the identifiers, technical information, sessions, and selected events described in Section 4.2 on our behalf and provides campaign-attribution reports. Its service privacy notice describes its role as a processor for data supplied by its business customers: Singular Privacy Policy.

TikTok receives configured measurement data through Singular to measure and optimise Gossipy campaigns. Our integration is configured for all users, rather than only installations attributed to TikTok. It includes installation or re-engagement measurement, App sessions, investigation and paywall views, checkout starts, and confirmed purchases. Depending on the event, fields include App and device identifiers (such as IDFV, and IDFA when authorised), the pseudonymous RevenueCat user identifier, device and operating-system details, tracking-permission status, IP address, approximate country/region/city, event type and time, product or offer context, and campaign context. Events can be shared when an installation was not attributed to TikTok and when IDFA is unavailable. This is separate from Apple's SKAdNetwork postbacks.

TikTok's processing is governed by the applicable advertising terms and its privacy notices. Information is available through TikTok's privacy resources. Section 11.4 describes advertising-sharing choices for California residents.

7.5 PostHog

PostHog provides product analytics, processing pseudonymous usage events and subscription events from RevenueCat on our behalf. Gossipy uses PostHog's EU ingestion endpoint. Session replay, automatic screen capture, and IP-based geolocation enrichment are disabled in the App configuration. The data remains linkable through installation identifiers. See the PostHog Data Processing Agreement and PostHog Privacy Policy.

7.6 Online and creator infrastructure

Supabase provides anonymous authentication, multiplayer, leaderboard and database hosting. It processes the online player and creator-programme data described above on the Developer's behalf. Vercel hosts first-party APIs and the private creator dashboard. TikHub is queried only for public TikTok or Instagram profile and video information needed to verify a submitted creator account and public view counts; legal, tax and bank details are not sent to TikHub. RevenueCat processes the pseudonymous identifier needed to grant a creator Premium benefit.

8. International data transfers

The Developer is based in France. Some providers are based in the United States or use infrastructure and support teams in other countries.

Supabase, Vercel and TikHub may process the online-player, creator-programme and public social-media data described in Sections 4 and 7 in the locations covered by their applicable service terms and data-processing arrangements.

Transfers subject to EU or UK data protection law require an applicable transfer mechanism, such as an adequacy decision or Standard Contractual Clauses with any necessary supplementary safeguards. The mechanism depends on the recipient, destination, and applicable contractual arrangements; the location of a provider's headquarters alone does not establish it.

You can contact the Developer using Section 19 to request information about the transfer safeguards applicable to your data. Provider data-processing terms and privacy notices are linked in Section 7.

9. Data retention

We keep data only as long as needed for the purposes listed above, with the longer periods driven by legal obligations (especially accounting).

Data categoryRetention period
Online account, profile, stats, multiplayer and leaderboard dataUntil you delete the online account in the App, or until the account is removed after an appropriate period of inactivity. Non-personal prize ledgers and accounting records may be retained where legally necessary.
RevenueCat subscription recordsFor the subscription duration and as required for accounting, tax, fraud prevention and dispute handling.
Cloudflare access logsA short rolling period under Cloudflare's policy, unless needed for a security incident.
Pseudonymous creator-referral eventsUp to thirteen (13) months, then deleted or irreversibly aggregated, unless needed for fraud or legal compliance.
PostHog and Singular recordsFor the period configured to analyse App use, conversion and campaign performance, subject to deletion or restriction requests.
Data disclosed to TikTokUnder the applicable advertising terms, TikTok retention practices and privacy requests.
Local game dataUntil you uninstall or reset the App.

Creator application, agreement, earnings and payment records are kept for the collaboration and then only for applicable limitation, tax and accounting periods. Encrypted bank details are kept while needed to pay outstanding earnings and then deleted or restricted unless a legal obligation or dispute requires longer retention.

When retention periods expire, the relevant data is deleted or irreversibly anonymised.

Deleting an online account in Profile > Account > Delete online account deletes the Supabase authentication record and associated player profile, statistics, multiplayer membership and leaderboard records. It does not cancel an Apple subscription, erase local progress, or automatically delete records held separately by Apple, RevenueCat, PostHog, Singular or TikTok. You can request deletion or restriction of those records through Section 19, subject to legal exceptions.

10. Your rights under GDPR (EU/UK)

If you are in the EU, EEA, or the United Kingdom, you have the rights listed below. You can exercise them by emailing us.

If you reside in the European Union, the European Economic Area, or the United Kingdom, you have the following rights under the GDPR (Regulation (EU) 2016/679) and the UK Data Protection Act 2018:

To exercise these rights, use the in-App deletion option for the online account or contact contact@gossipyapp.com for other records. The Developer may request proportionate information, such as the user code visible in the App, to locate and verify a request.

iOS control. You can change Gossipy's tracking permission in Settings > Privacy & Security > Tracking. Turning it off removes access to IDFA; it does not delete existing records or switch off all analytics and measurement described in this Policy. For access, deletion, objection, withdrawal of consent, or other data-sharing requests, email contact@gossipyapp.com. No Gossipy account is required. See Apple's instructions for tracking permissions.

The competent supervisory authority for France is:

Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
cnil.fr

If you reside in another EU or EEA Member State, or in the United Kingdom, you may alternatively lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available on the European Data Protection Board website at edpb.europa.eu. For the United Kingdom, the competent authority is the Information Commissioner's Office (ICO), ico.org.uk.

11. Your rights under CCPA/CPRA (California)

Where the CCPA/CPRA applies, California residents have the rights described below, including the right to opt out of sale or sharing. Our advertising data flows are described in Section 7.4.

This section describes our practices and the rights available where the California Consumer Privacy Act of 2018 applies, as amended by the California Privacy Rights Act of 2020 (collectively, the "CCPA/CPRA"), codified at California Civil Code §§ 1798.100 et seq.

11.1 Categories of personal information

The categories of personal information ("PI") covered by the App data flows described in this Policy, mapped to Cal. Civ. Code § 1798.140, are:

Statutory category (§ 1798.140)Collected?ExamplesRecipients, according to the flow in Sections 4 and 7
IdentifiersYesIP address; installation, device, and subscription identifiers; IDFA when authorisedCloudflare, RevenueCat, Apple, PostHog, Singular, TikTok, referral hosting provider
Customer records (Cal. Civ. Code § 1798.80(e))Only if provided in a support requestEmail address and correspondenceDeveloper and email service provider
Characteristics of protected classificationsNot requested——
Commercial informationYesPurchase and subscription records; offer views and checkout startsApple, RevenueCat and PostHog for subscription records; Singular and TikTok for the selected offer or checkout events described above
Biometric informationNo——
Internet or other electronic network activity informationYesContent requests, referral events, sessions, selected gameplay and purchase actionsCloudflare, referral hosting provider, PostHog, Singular, TikTok, according to the event
Geolocation dataApproximateNetwork-derived country, region, or city; country of purchase. The App does not request GPS location.Cloudflare, RevenueCat, PostHog for purchase country, Singular, TikTok
Sensory data (audio, electronic, visual)No recording through analyticsSession replay and screen capture are disabled—
Professional or employment-related informationNot requested——
Education informationNot requested——
Inferences drawn from PILimited analyticsAcquisition source, usage and subscription patternsPostHog, Singular, TikTok
Sensitive Personal InformationNot requested for these flowsNo precise GPS location, payment-card details, or account password is requested by Gossipy—

For optional creator applicants, the additional categories include customer records, professional or business information, financial information and payment records: legal name, professional address, business and tax identifiers, collaboration agreement, bank-account details, earnings and payment status. Gossipy discloses these only to the Developer and the creator-programme infrastructure providers described in Section 7.6.

11.2 Sources of personal information

The Developer collects personal information (a) from you when you contact us or enter a creator code; (b) from your device through the App, its SDKs, creator links, and content requests; and (c) from Apple, RevenueCat, PostHog, Singular, and advertising partners for subscriptions, analytics, and campaign attribution.

11.3 Purposes for collection

The purposes for which personal information is collected are described in Section 5 of this Policy.

11.4 Sale or sharing of personal information

The Developer does not exchange personal information for money. However, the advertising integration described in Section 7.4 discloses identifiers, technical data, approximate location, and selected activity to TikTok for advertising measurement and campaign optimisation. Advertising disclosures can constitute "sharing" for cross-context behavioural advertising, or a "sale" for other valuable consideration, under California law. The absence of a payment for data does not by itself exclude those definitions.

You can submit a Do Not Sell or Share My Personal Information request by email. No account is required. The iOS tracking control is also available as described in Section 10, but is not a general opt-out from every flow described here.

11.5 Sensitive Personal Information

The analytics and measurement flows described here do not request sensitive personal information such as precise GPS location, account passwords, or payment-card details. Please do not include unnecessary sensitive information in support messages. Apple handles payment information under its own privacy notice.

The optional creator programme separately collects the bank and tax information described in Section 4.1 solely to administer and pay the collaboration. It is not used to infer characteristics about a creator or for advertising.

11.6 Your CCPA/CPRA rights

Subject to applicable exceptions, you have the right to:

To exercise these rights, contact the Developer at contact@gossipyapp.com. You may also use an authorised agent to submit a request, in which case the Developer will verify the agent's authorisation. For requests to access, correct, or delete records, we may need proportionate information to locate the records and verify the request. An opt-out of sale or sharing does not require an account or verification of your identity; we may need enough information to identify the records to which it applies.

11.7 California "Shine the Light"

California Civil Code § 1798.83 ("Shine the Light") entitles California residents to request, once per calendar year, information regarding the disclosure of personal information to third parties for the third parties' direct marketing purposes. You may send this request to the email address in Section 19. Advertising disclosures are described in Section 7.4.

12. Your rights under LGPD (Brazil)

If you are in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD). You can exercise them by emailing us.

If you reside in Brazil, the processing of your personal data is subject to Federal Law No. 13.709 of 14 August 2018, as amended (the "Lei Geral de Proteção de Dados", or "LGPD"). The Developer is the controller (controlador) of your personal data within the meaning of Art. 5(VI) LGPD.

The legal bases relied upon under Art. 7 LGPD mirror those described in Section 6 of this Policy: performance of a contract to which you are a party (Art. 7(V)), compliance with a legal or regulatory obligation (Art. 7(II)), the legitimate interests of the controller (Art. 7(IX)) where permitted, and consent (Art. 7(I)) where required. The available controls and their limits are described in Sections 6 and 10.

You have the rights set out in Art. 18 LGPD, including:

To exercise these rights, contact the Developer at contact@gossipyapp.com. You may also lodge a complaint with the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados, ANPD), gov.br/anpd.

13. Other regional rights

Residents of Canada, South Africa, Japan, Australia, and other jurisdictions retain the privacy rights granted by their local laws. The Developer will honour those rights to the extent applicable.

The Developer respects the privacy rights granted by your local law, including:

To exercise any of the rights above, contact the Developer at contact@gossipyapp.com.

14. Children's privacy

The App is intended for users aged 17 or older and is not for children. We do not knowingly collect data from children.

The App is intended for users aged 17 or older due to mature narrative content (investigations involving infidelity, suggestive themes, simulated communications). The App is not directed at children and is not intended for use by children. The Developer does not knowingly collect personal data from children under 17, and where applicable does not knowingly collect personal data from children under 13 within the meaning of the United States Children's Online Privacy Protection Act ("COPPA", 15 U.S.C. §§ 6501–6506) or from children under 16 within the meaning of Article 8 of the GDPR.

If you are a parent or guardian and believe a child has provided personal data to the Developer through the App, please contact contact@gossipyapp.com. The Developer will promptly investigate and delete the data unless retention is required by law.

15. Security measures

We minimise the data collected, rely on industry-standard processors for everything that leaves the device, and depend on Apple's platform security for the data on your device.

The Developer implements technical and organisational measures appropriate to the nature of the processing, the limited categories of data involved, and the risks they present:

Creator bank details are encrypted at rest with a server-only key, are never returned to the mobile App in full, and are exposed only through the authenticated private founder dashboard.

No system is perfectly secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, the Developer will notify the competent supervisory authority and, where required, affected users in accordance with Articles 33 and 34 of the GDPR.

16. Apple App Privacy Nutrition Label disclosures

Apple's privacy categories include information linked to a device or pseudonymous identifier, even when an app has no named account.

The App data flows described above include the following categories. The App Store's privacy label is a separate disclosure; this section does not mean that all transmitted data is anonymous.

16.1 Data Used to Track You

Identifiers and selected usage events are used for advertising attribution and shared with TikTok as described in Section 7.4. Apple's tracking definition concerns links between App or device data and data from other companies for advertising or advertising measurement. IDFA requires ATT authorisation. Apple's SKAdNetwork postbacks are a separate privacy-preserving measurement mechanism.

16.2 Data Linked to You

For optional creator applicants, linked data also includes contact information (legal name and professional address), financial information (bank-account details), identifiers (social username and Gossipy user ID), submitted video links, professional and tax information, public view counts, earnings and payment records.

These categories are used for App functionality, analytics, and, for the limited fields described in Section 7.4, the Developer's advertising or marketing.

16.3 Data Not Linked to You

Apple also provides aggregated App Analytics reports and privacy-preserving advertising reports. These are separate from the pseudonymous event records above. We do not describe all identifiers or purchase records as "not linked" merely because we do not ask for a name or email address.

If you notice an inconsistency with the App Store privacy label, contact contact@gossipyapp.com.

17. Cookies and similar technologies

The native App uses local storage and SDK identifiers. These technologies can support measurement even without browser cookies.

Game saves, preferences, referral state, SDK identifiers, and queued events use native application storage. The App does not use browser cookies for its native gameplay. The analytics, subscription, and advertising flows that transmit data are described in Sections 4 and 7.

When the App opens an external URL, your browser's cookie and storage behaviour applies. The relevant website's privacy and cookie notices govern those interactions.

18. Changes to this policy

The "Last updated" date identifies the revision of this Policy.

The Developer may update this Policy to reflect changes in the App, data flows, law, or provider practices. Additional notice or consent is required where applicable law requires it. Continued use of the App does not replace any required consent.

19. How to contact us and exercise your rights

Email the Developer at contact@gossipyapp.com. We will respond within the statutory timeframes.

For any question concerning this Policy or the data practices described in it, and to exercise any of the rights described in Sections 10 to 13, please contact:

When contacting the Developer, describe the request precisely. We may ask for the Gossipy user code, approximate dates, country or a store receipt to locate the relevant pseudonymous records and verify the request.

The Developer will acknowledge your request promptly and respond within the timeframes set by applicable law (one month under GDPR, extendable by two months for complex requests; forty-five days for CCPA/CPRA access, correction, or deletion requests, extendable by forty-five days, and as soon as feasible within fifteen business days for applicable sale or sharing opt-outs; fifteen days under the LGPD, extendable as provided by law).