1. Scope and controller
This policy applies to CRYA — Crystal Aether Network, including www.crya.pt, My CRYA, CRYA Bot, the CRYA Bot Owner App, Grow Game, CRYA Home, CRYA Worker, CyberK Modules, Livingstone Toolkit, CRYA Play, and CRYA support journeys where CRYA determines why and how personal data is handled.
CRYA — Crystal Aether Network is the controller for the processing described here. We do not invent a registered entity name or postal address that has not been verified. The current controller contact is the working CRYA contact and support route linked below. Telegram, Google, Google Play, device manufacturers, Home Assistant, and other connected platforms act under their own terms and privacy notices for the processing they control.
2. Information CRYA may handle
The exact information depends on the product and features you use. CRYA does not need every category for every person.
- Account and identity: display name, email address, provider identifiers, linked sign-in methods, account state, and security/session records.
- Telegram community context: Telegram user and chat identifiers, names or usernames, group membership and administrator status, commands, replies, configured group rules, reports, moderation actions, federation observations, and audit references.
- Grow Game: group-specific size and progression state, XP, coins, reputation, titles, achievements, collections, missions, battles, events, cooldowns, and anti-duplicate receipts.
- Android product and device context: app/package version, device compatibility signals, settings you save, push token where enabled, diagnostics you choose to send, and product-specific records such as field, home, package, or tool data.
- CRYA Play viewing context: selected Anime, Drama, or Chinese mode; catalogue and search interactions; title and episode references; progress and completion; library state; comments, reactions, reports, or blocked-comment-author state; enabled notification choices; auto-skip preference; TV or Google Cast connection attempts; and clearly labelled Sponsored Premiere delivery or interaction events. A separately identified private/sideload build can offer a locally PIN-gated adult section and offline media download state; the Google Play release excludes those features. Account-linked synchronisation applies only when you sign in.
- Premium and purchase evidence: product identifier, entitlement state, trial state, platform order or purchase reference, verification result, and renewal/cancellation state. CRYA does not receive your full payment-card details from Google Play.
- Support and contact: name, email, product, topic, subject, message, case reference, account link when signed in, status, and correspondence needed to handle the request.
- Website and security: essential cookies, request time, network/security metadata, route, response code, abuse signals, and maintenance-bypass audit when an authorised owner uses it. With consent, CRYA first-party analytics stores only the page path without query data, day, broad device class, language category, and broad referral category; it does not store an account, IP address, raw user agent, or visitor identifier in the analytics row.
3. Where information comes from
Information may come directly from you, from a group owner or administrator configuring a feature, from Telegram updates delivered to CRYA Bot, from Google or Telegram when you choose that sign-in method, from Google Play when a purchase is verified, from an Android product you use, or from a connected service you deliberately configure.
Federation information may include observations imported from an external federation source. CRYA labels external sources and keeps owner-controlled enforcement separate from visibility. A public source does not remove the need to handle the resulting personal data responsibly.
4. Purposes and legal bases
CRYA processes information only when a legal basis applies. The basis can differ by feature and country.
- Contract or steps requested by you: creating and securing an account, delivering a selected product, saving settings, verifying entitlement, running a game action, or opening a support case.
- Legitimate interests: protecting services and communities, preventing duplicate or abusive actions, maintaining reliable audit records, debugging failures, improving usability, and allowing owners to manage their communities, balanced against individual rights.
- Consent: optional communications, optional analytics or device permissions, certain linked-service uses, and processing that law requires to depend on consent. Consent can be withdrawn for future processing.
- Legal obligation: tax, accounting, consumer, lawful-request, security, and data-protection duties where they apply.
- Vital interests or public-interest grounds only in exceptional situations permitted by law, such as an immediate serious safety risk.
5. Telegram communities, moderation, and federation data
Group owners and administrators decide which CRYA Bot features to enable within the controls available to them. Moderation remains available by default where configured, while federation auto-enforcement is not treated as a silent universal default. A group may use read-only federation visibility without automatic bans.
Commands, reports, warnings, restrictions, bans, unbans, filters, greetings, federation observations, and administrator actions may be recorded so the group can operate, disputes can be understood, and duplicate or unauthorised actions can be prevented. Group members should also review Telegram’s privacy information and the group’s own rules.
A group administrator is responsible for choosing features lawfully, informing members when required, reviewing automated suggestions, and using permissions proportionately. Contact the group’s administrators first for a group decision; contact CRYA for a product, data, or security issue.
6. Automated tools and human review
Filters, anti-spam rules, deleted-account scanning, cooldowns, duplicate detection, federation matching, and other configured tools may produce or assist an action automatically. Group owners decide whether applicable enforcement features are active. CRYA does not claim that an automated signal is infallible.
If an action materially affects you, ask the group administrators for review and provide the visible reason or reference. You may also contact CRYA Support when the concern is about CRYA’s processing or the tool’s behaviour. CRYA does not use website browsing to make solely automated decisions with legal or similarly significant effects.
8. International processing
Some connected platforms or service providers may process information outside Portugal or the European Economic Area. Where CRYA is responsible for such a transfer, it uses an applicable legal mechanism and supplementary safeguards as required. Platforms acting independently describe their own transfer mechanisms in their notices.
9. Retention and security
CRYA keeps personal data only for as long as needed for the purpose collected, an active account or group feature, security and dispute handling, backup rotation, or a legal obligation. Retention is determined by the type of record, whether the feature remains active, whether a dispute or abuse investigation is open, and whether deletion would undermine another person’s rights or a required audit record.
Deletion may remove or anonymise active personal data before an encrypted backup expires through its normal rotation. Some group moderation or transaction records may be retained in restricted form where needed to protect communities, prevent repeated abuse, prove a purchase, or meet legal duties. CRYA explains exceptions in the response to a deletion request.
CRYA uses access controls, encrypted transport, protected server-side sessions, secret separation, least-privilege service access, request validation, rate limits, audit records, and backups. No security measure can guarantee zero risk; report a suspected incident through Support without posting secrets publicly.
10. Your rights
Depending on the processing and applicable law, you may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent. You may also ask for information about recipients, transfer safeguards, retention criteria, and meaningful review of an applicable automated decision.
CRYA may need to verify your identity and authority over the account, group, or data before acting. Rights are not absolute; the response will explain a lawful limitation. You may complain to the Portuguese Comissão Nacional de Proteção de Dados (CNPD) or another competent supervisory authority.
11. Children and age suitability
CRYA’s account and community-management products are not directed to children under 13. Where consent is the legal basis and Portuguese law applies, a child under 13 requires consent from a holder of parental responsibility; another country may set a different threshold. Telegram, Google, Google Play, and device platforms also set their own age rules.
Some community content and Grow Game humour may be unsuitable for younger users even where account use is legally permitted. Group owners should choose age-appropriate settings and rules. CRYA does not use profiling-based advertising aimed at children.
12. Changes and contact
CRYA may update this policy when products, law, or processing change. The page shows its version and date. Material changes will be communicated through an appropriate product, account, or website notice before they take effect where required.
For a privacy request, choose “Privacy or data” in the contact or signed-in Support form. Include the affected product and account or Telegram context, but never send a password, recovery code, bot token, private key, or full payment detail.

