Permission and Data Safety Disclosures

Effective Date: July 18, 2026

Contact Privacy Team

This page explains Android permissions and data categories associated with Risus. The Google Play Data Safety form must accurately reflect the actual app, SDKs, backend processing, and public privacy policy for package com.buzeegroup.risus.

01

Android Permissions and User-Facing Purpose

Risus requests sensitive permissions only when they are needed for a user-facing feature, and only in the context where the feature is used.

Permission or data accessRisus purposeDisclosure or action
CAMERATaking photos and videos, scanning codes, profile or post media.Requested only in context and disclosed in the Privacy Policy and Data Safety form.
RECORD_AUDIORecording audio in videos or voice/media features where enabled.High sensitivity. Removed if no live audio feature exists; requested only in context.
READ_MEDIA_IMAGES / READ_MEDIA_VIDEOAccess to photos or videos for upload, sharing, or media features.Uses selected media access or the system Photo Picker where broad access is not core functionality.
READ_MEDIA_VISUAL_USER_SELECTED / system Photo PickerUser-selected photo or video access for upload and sharing.Preferred for selected-media flows where supported; broad library access is avoided when unnecessary.
ACCESS_MEDIA_LOCATIONReading location metadata embedded in media.Removed unless metadata is essential and clearly disclosed.
READ_EXTERNAL_STORAGE / WRITE_EXTERNAL_STORAGELegacy media and file access on older Android versions.Limited or removed where modern scoped storage and pickers are sufficient.
SYSTEM_ALERT_WINDOWDrawing over other apps.Removed unless a core, user-facing, policy-compliant overlay feature requires it and is clearly disclosed.
INTERNET / network statusApp connectivity, API access, diagnostics, messaging, and notifications.Common permission; data transmission and diagnostics are disclosed where applicable.
VIBRATEHaptic feedback and notifications.Low sensitivity; no special user data disclosure normally required.
ACCESS_COARSE_LOCATION / ACCESS_FINE_LOCATIONNo current core Risus purpose unless a live location feature is introduced.Not requested unless necessary. Approximate and precise location are distinguished, and the in-app disclosure, Privacy Policy, and Data Safety form are updated before any use.
READ_SMS / READ_CALL_LOGNot required for Risus account verification.Not requested for verification. Risus uses a user-entered OTP, the SMS Retriever API, the Digital Credentials API, or another policy-compliant method.
POST_NOTIFICATIONSPush notifications for messages, reactions, safety, security, and account updates.Requested at runtime with an explanation of the user-facing purpose; users can decline or disable notifications.

Permissions that are not necessary for a current user-facing feature are removed from the app. You can review and change app permissions at any time in your device settings.

02

Google Play Data Safety Categories

Based on Risus features, the following categories are relevant. Every final Play Console answer is confirmed against the live app, backend, third-party SDKs, AI-provider configuration, and all versions currently distributed on Google Play.

CategoryData collectedPurpose
Personal infoName, email address, username, profile photo, user ID, account credentials and authentication status.Account management, app functionality, security, and communication.
User-generated contentPosts, pings, captions, reposts, messages, chat room content, images, videos, audio, comments, reactions, reports.Social sharing, messaging, moderation, and safety.
Photos and videosSelected or uploaded media, and possibly embedded metadata.Profile photos, posts, chat, media viewing, and AI media features.
AudioAudio captured in videos or voice/media features where enabled.User-created content and messaging features.
AI and moderation dataPrompts, captions, editing instructions, images, videos, reported content, lyrics, music preferences, generated outputs, feedback, and safety signals.App functionality, content generation, moderation, fraud and abuse prevention, security, and reliability. Processed by the AI providers identified in the Privacy Policy.
App activityPosts viewed, interactions, likes, bookmarks, profile visits, messages, notification activity, search and explore usage.Functionality, analytics, personalization, safety, and debugging.
App info and performanceCrash logs, diagnostics, performance data, app version, device and OS information.Analytics, debugging, fraud prevention, reliability, and security.
Device or other IDsPush notification tokens, authentication and session identifiers, installation or diagnostic identifiers.Account security, notifications, fraud prevention, analytics, and app functionality.
Approximate / precise locationAn IP address may reveal approximate country or region where Risus derives or stores that information. Media metadata may separately contain location information.Security, fraud prevention, analytics, and localization. Device GPS and other precise location are not collected unless a live feature requires it and the permission, in-app disclosure, Privacy Policy, and Data Safety form all reflect it.
03

Sharing and Processing Disclosures

Risus may share or process data with:

  • hosting and storage providers;
  • authentication providers, including Google sign-in and Google Play services;
  • analytics and crash-reporting providers;
  • push-notification providers;
  • moderation and security tools;
  • email and SMS providers;
  • support systems;
  • AI providers including Google Gemini, Google Imagen, Google Cloud Vision, Sightengine, and ElevenLabs.

The Data Safety form does not state that no data is shared or processed, because information is transmitted to third-party processors and is intentionally made visible to other users through social features.

04

Prominent Disclosure and Consent

When access, collection, use, or sharing of personal or sensitive user data would not be reasonably expected, Risus displays a disclosure inside the app during normal use, before the data is accessed or transmitted. The disclosure identifies the data, explains how it is used or shared, and remains separate from unrelated notices.

Consent requires clear affirmative action. Risus does not use a preselected option and does not interpret navigating away as consent. Consent is obtained before collection or processing begins.

A policy page is not a substitute for in-app disclosure

A Privacy Policy or Terms page alone does not replace a required prominent in-app disclosure.

05

Security and Deletion Disclosures

  • Data is transmitted using modern cryptography, such as HTTPS/TLS.
  • Data deletion requests are supported through in-app deletion (Settings > Account > Delete Account) and a public web deletion page.
  • The Privacy Policy, Data Safety form, account deletion answers, and actual app behavior must match at all times.

Request deletion

You can request account and data deletion from the public web page at https://risus.io/delete-request, in the app under Settings > Account > Delete Account, or by emailing privacy@risus.io.

06

Android Platform and Play Requirements

Risus tracks the following Google Play and Android platform requirements for package com.buzeegroup.risus:

  • Android Developer Verification registration confirmed by September 30, 2026.
  • Target Android 16 (API level 36) for app updates submitted from August 31, 2026.
  • Content rating kept current in Play Console.
  • The Privacy Policy is linked in the Google Play store listing and inside the app, and remains available at an active public URL without requiring sign-in.
  • READ_CALL_LOG and READ_SMS are not requested for account verification.
  • The Data Safety form matches actual app behavior, SDKs, permissions, and backend processing.

Questions About Permissions or Data?

Contact our privacy team for questions about Android permissions, the Google Play Data Safety declaration, or how Risus processes your data.

privacy@risus.io

© 2026 Risus. All rights reserved.

Permissions are requested only when needed, and only in context.

https://risus.io/permission-and-data-safety-disclosures