Skip to main content

Zaparoo Software Privacy Policy

Last updated: August 12, 2026

This policy explains how Wizzo Pty Ltd ("Zaparoo", "we", "us") handles information through Zaparoo App, Zaparoo Core, other Zaparoo software that links to this policy, and zaparoo.org.

Wizzo Pty Ltd, located in Western Australia, Australia, is responsible for the personal information covered by this policy.

Privacy at a glance

  • Zaparoo App and Zaparoo Core can be used without a Zaparoo Online account.
  • We do not sell personal information or use it for targeted advertising.
  • Ordinary local traffic between Zaparoo App and your Core device is not sent to Wizzo.
  • Cloud and provider connections use encrypted HTTPS or TLS transport.
  • Compatible Core versions support authenticated application-layer encryption, but legacy local Core connections may use plaintext WebSocket traffic.
  • Camera images, NFC scans, accelerometer readings, local media libraries, mappings, and configuration remain local unless you use a feature that explicitly sends resulting data elsewhere.

Scope and relationship to Zaparoo Online

This policy covers software distributed through the Zaparoo open-source ecosystem and the zaparoo.org website. It covers information stored locally by the software, information exchanged with a Zaparoo Core device, and information sent to providers used directly by the software.

Zaparoo Online is an optional hosted account and cloud service with a separate Zaparoo Online Privacy Policy. When you enable an Online feature, information sent to or stored by the hosted service is also handled under that policy. The Online policy does not apply to information that remains solely on your device or traffic exchanged only between Zaparoo App and a locally operated Zaparoo Core device.

Zaparoo App

Information stored on your device

Zaparoo App stores settings and operational data needed to provide its features. This may include:

  • the address and connection history of Core devices you configure or discover;
  • display, accessibility, haptic, NFC, reader, search, and other preferences;
  • recent searches and queued Core commands;
  • local purchase or entitlement state; and
  • pairing credentials stored through secure operating-system storage.

This information remains on your device unless another section below explains a transfer. You can remove local app data through your device settings or by uninstalling the app, subject to operating-system behavior and backups you control.

Camera, NFC, accelerometer, and nearby devices

The app may request access to the camera to scan barcodes, NFC hardware to read or write tags, and the accelerometer for shake-to-launch features. Camera images and raw sensor readings are processed on the device. A scanned barcode or NFC value may be sent to your selected Core device when you choose to launch, map, or write that value.

The app uses local-network discovery to find compatible Core devices. It does not collect your geographic location, contacts, installed-app inventory, phone number, or advertising identifier for these features.

Barcode recognition uses Google ML Kit. Barcode images and decoded barcode content are processed on the device and are not sent to Google. ML Kit automatically sends limited metrics such as device and app information, a per-installation identifier, performance measurements, API configuration, feature events, and error codes to Google for diagnostics and usage analytics.

Communication with Zaparoo Core

When connected to Core, the app sends commands and receives responses needed to operate the software. Depending on the feature you use, this traffic may include:

  • library searches and browse requests;
  • game or media names, paths, launch scripts, and launch history;
  • keyboard, gamepad, media-control, and reader actions;
  • NFC values and tag-write content;
  • mappings, settings, device status, screenshots, and diagnostic logs; and
  • short-lived, single-purpose claims used when you choose to link Core to Zaparoo Online.

Ordinary local Core traffic goes directly between your mobile device and the Core device you selected. Wizzo does not receive or store that traffic.

Compatible Core versions can protect the connection with authenticated application-layer encryption. Legacy Core versions and configurations may use plaintext WebSocket traffic on the local network, including for deliberately short-lived device-linking bootstrap claims. Use trusted local networks and enable encrypted pairing where supported.

Optional Zaparoo Online account

You can use the app without signing in. If you create or use a Zaparoo Online account through the app, the app and its authentication providers may process:

  • your name or display name, when supplied by Google or Apple sign-in;
  • your email address;
  • a Firebase account identifier and authentication provider;
  • confirmation that you meet the minimum age requirement;
  • acceptance of applicable terms and privacy notices;
  • multifactor-authentication and account-security status; and
  • linked-device, subscription, entitlement, and account-deletion status.

Firebase provides authentication. Google and Apple may provide federated sign-in under their own privacy policies. The Firebase account identifier is also used to associate purchases and subscription entitlements with the correct account.

Information received and retained by Zaparoo Online is described in the Zaparoo Online Privacy Policy.

Purchases and subscriptions

On supported mobile platforms, RevenueCat processes account identifiers, product and entitlement information, and purchase history to provide and analyze subscriptions and purchases. Apple or Google processes the payment transaction. Zaparoo App and Wizzo do not receive full payment-card details from the app stores.

Crash reports and diagnostics

Native production builds use Rollbar to receive uncaught errors, stack traces, app version and platform details, and limited diagnostic context. Diagnostic context may include route navigation, connectivity changes, and network request URLs, but not request bodies.

Rollbar is configured not to capture usernames, email addresses, IP addresses, form input, console logs, or DOM interaction. Known personal, authentication, device-address, and credential fields are scrubbed, and any person object or request body is removed before transmission. Error reporting is automatic in supported native production builds so we can diagnose failures and maintain the app.

Live updates

Native builds use Capawesome Live Update to check for compatible signed web-layer updates. The service receives a device-generated identifier scoped to the app installation, app and bundle information, platform details, and update status. Capawesome uses the identifier for update delivery and device management and to count monthly active users. It is not an advertising identifier and is not used by Wizzo for advertising profiles.

User-initiated log uploads

The app can retrieve diagnostic logs from your Core device. Logs stay between the app and Core unless you choose to upload them. When you select the upload action, the app sends the log content to logs.zaparoo.org and returns a shareable URL for support. Logs may contain paths, device or platform details, configuration values, launch activity, and error messages. Review them before sharing where possible and do not upload logs containing information you do not want support personnel to see.

Zaparoo Core

Zaparoo Core stores its configuration, media index, token history, mappings, profiles, play history, and related operational data on the device where you run it. Core can operate without an Online account, and Wizzo does not receive this local data merely because you use Core.

Optional error reporting

Core includes optional Sentry error reporting that is disabled by default. If you enable it, Core may send:

  • error messages and stack traces;
  • Core version, platform, operating-system, and architecture details; and
  • a randomly generated Core device identifier used to group reports from the same installation.

Core removes usernames from file paths, does not attach HTTP bodies or breadcrumbs, and is configured not to include your hostname or automatic user information. Reports are sent through errors.zaparoo.org to Sentry and used to identify and fix software faults. You can disable reporting through Core settings.

Optional hosted features

Core sends information to Zaparoo Online only when you link a device and use hosted features such as play-history sync, cloud backup, or other Online services. Those transfers and their retention are described in the Zaparoo Online Privacy Policy. Disabling or unlinking a feature stops the transfers described by that feature but may not delete information already stored online.

Other Zaparoo software

This policy also applies where another ZaparooProject software distribution links to it. Unless the software or its documentation says otherwise, these tools process files, configuration, media metadata, and user input locally. When a tool sends information to Zaparoo Online or another hosted service, the interface or documentation should identify that feature and the applicable hosted-service policy also applies.

Zaparoo.org website and documentation

You can browse public pages without creating an account. Our hosting and content-delivery providers may process standard request information such as IP address, user agent, requested page, request time, and security events to deliver and protect the site.

We use Umami for limited, cookieless website analytics. This may include page views, referring page, browser, operating system, device type, and approximate country or region. We use it to understand documentation usage and improve the site, not for advertising profiles.

Documentation search uses Algolia DocSearch. Search terms, documentation version and language, result counts, and technical request information are sent to Algolia to return results and measure search quality. Selecting a result may also send its identifier and position, the query identifier, event time, and a randomly generated anonymous token. Our search integration does not connect that token to a Zaparoo Online account or retain it in a cookie between visits.

If you contact us, report a documentation issue, or participate through a linked community service, we process the information you provide to respond. External services such as GitHub, Discord, Reddit, and social networks handle information under their own policies after you leave zaparoo.org.

Why we use information

We process information described in this policy to:

  • provide software, device-control, authentication, purchase, update, and support features;
  • secure accounts, pairing, local connections, downloads, and hosted endpoints;
  • diagnose faults and maintain or improve software and documentation;
  • deliver requested support and respond to privacy requests;
  • prevent abuse and comply with legal obligations; and
  • establish, exercise, or defend legal rights.

Where GDPR or UK GDPR applies, our legal bases are performance of a contract or delivery of a requested feature, compliance with legal obligations, consent where requested, and our legitimate interests in operating, securing, supporting, and improving the software and site.

Service providers and disclosures

Providers used for relevant parts of the software and website include:

  • Firebase, Google, and Apple for authentication;
  • Google ML Kit for on-device barcode recognition and limited diagnostic and usage metrics;
  • RevenueCat, Apple, and Google for purchases and subscription entitlements;
  • Rollbar and Sentry for error reporting;
  • Capawesome for live updates;
  • Umami for limited website analytics;
  • Algolia for documentation search; and
  • hosting and content-delivery providers for websites, log uploads, error-report tunnels, and downloads.

Providers process information for their assigned role and may independently process information under their own policies where they interact directly with you. We may also disclose information when required by law, to protect users or the software, to investigate abuse, or as part of a business transfer subject to applicable law and continued protection of the information.

We do not sell or rent personal information or share it for cross-context behavioral advertising.

International processing

Wizzo operates from Australia and uses providers that may process information in Australia, the United States, the United Kingdom, the European Economic Area, and other countries where they maintain facilities. Where applicable law requires safeguards for an international transfer, we use an available lawful mechanism such as contractual protections, an adequacy decision, or another recognized safeguard.

Security

We use safeguards appropriate to the information and feature involved, including HTTPS or TLS for internet services, authenticated application-layer encryption for compatible Core connections, secure operating-system storage for pairing credentials, access controls, data minimization, and diagnostic scrubbing.

Not every local Core connection is encrypted. Legacy plaintext support exists for compatibility with older Core versions and local deployments. No transmission or storage system is completely secure. Protect your devices and accounts, use trusted local networks, install current software, and enable encrypted pairing where available.

Retention and deletion

Information kept only on your device remains until you delete it, clear the app or software data, uninstall the software, or remove it through a provided setting, subject to device backups you control.

We and our providers retain diagnostic reports, live-update device records, website measurements, support communications, and user-initiated log uploads only as long as reasonably needed for their stated purpose, security, dispute resolution, or legal obligations. Provider recovery systems and backups may take additional time to expire after deletion from active systems.

Zaparoo Online account data follows the retention and deletion terms in the Zaparoo Online Privacy Policy. Deleting local App or Core data does not delete an Online account, and deleting an Online account does not automatically erase data remaining on devices you control.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal information; obtain a portable copy; withdraw consent; and complain to a privacy regulator.

You can control many practices directly by choosing whether to sign in, enable Core error reporting, link a device, use Online features, upload logs, or grant camera, NFC, and accelerometer permissions. Withdrawing permission may prevent the related feature from working.

Contact us if you want to exercise a privacy right or request deletion of diagnostic, update, support, or other information that cannot be managed through the software. We may need to verify your identity before acting and may retain information where required by law or another valid exception.

Children's privacy

Zaparoo accounts are not intended for children under 13, and account creation requires confirmation that the user meets the minimum age requirement. If local law requires a higher age or parental authorization, that requirement also applies. Contact us if you believe a child has provided personal information without valid authorization.

Changes to this policy

We may update this policy when software behavior, providers, or legal obligations change. We will post the updated policy at this URL and revise the date above. If a change materially affects registered users or requires consent, we will provide additional notice as required by law.

Contact us

Send privacy questions, requests, or complaints to:

Privacy Contact

Wizzo Pty Ltd

Suite 60, Shop 1097

1382 Albany Highway

Cannington WA 6107

Australia

privacy@zaparoo.com