Privacy Policy — HMA Credits
Last updated: 2026-07-15 Effective date: 2026-07-15 Policy version: 1.0
Introduction
This privacy policy (“Policy”) describes how HMA Credits (the “App”) handles your information. The App is published by Nguyen Duong Duc (Android package com.wowsoftware.hmacredits) and is the companion wallet for the HMA service.
This Policy applies to the App distributed via the Google Play Store and to the App’s use of the HMA backend at app.hidemyandroid.com. It does not apply to third-party services governed by their own policies — in particular Google Play, which processes all payments.
By creating an account, signing in, or otherwise using the App, you acknowledge that you have read and understood this Policy.
Summary in plain language
HMA Credits is an account-based wallet. To work, it needs to know who you are (your account) and to keep track of your credit balance. It collects the minimum needed to do that:
- Your email and password to sign you in.
- Your balance and transaction history, held in your HMA account.
Payments are handled entirely by Google Play — the App never receives your card or bank details. The App shows no ads, contains no third-party analytics or tracking SDKs, and does not sell or share your data for advertising. You can request deletion of your account and data at any time by email.
Information we collect and process
Account data
- Email address — used as your login identifier and for support correspondence.
- Password — transmitted over HTTPS to the HMA backend to authenticate you. The App does not store your password on the device; it is verified server-side, where it is stored in hashed form.
- Display name — if associated with your HMA account.
- Account balance and transaction history — your HMA Credits balance and the record of your top-ups, held in your account on the HMA backend.
Authentication data
- Session token (JWT) — issued by the backend on sign-in and stored encrypted on your device (Android EncryptedSharedPreferences). It is sent with requests to prove you are signed in and is cleared when you log out.
Purchase data
- Google Play purchase token and product identifier — when you top up, Google Play returns a purchase token. The App sends this token and the product id to the HMA backend to verify the purchase and credit your account.
- The App never receives or stores your card number, bank details, or any full payment-instrument data. Google Play collects and processes all payment information under Google’s own privacy policy.
Technical data
- Network connectivity state — read on the device to show accurate error states. This signal is not transmitted off the device.
How we use your data
- Authenticate you and keep you signed in.
- Display and maintain your HMA Credits balance.
- Process top-ups and credit the correct net amount to your account.
- Prevent fraud and avoid double-crediting a purchase.
- Respond to your support requests.
We do not use your data for advertising, profiling, or any purpose beyond operating the wallet.
Where your data is stored
Your account data, balance, and transaction history are stored on the HMA backend (app.hidemyandroid.com) and transmitted over HTTPS. On your device, only the encrypted session token is retained.
Permissions requested
The Android permissions requested by the App, the data they gate, and their purpose are listed in the Permissions table on this page (rendered automatically from the App’s published metadata). In brief: INTERNET and ACCESS_NETWORK_STATE for talking to the backend and detecting connectivity, and com.android.vending.BILLING for Google Play top-ups. The App requests no location, contacts, camera, microphone, storage, or phone permissions.
Third-party services
The third-party services the App relies on are listed in the Third-party SDKs section on this page. For reference:
| Service | Purpose | Data involved |
|---|---|---|
| Google Play Billing | Collect payment and process top-ups | Payment details, collected and handled entirely by Google Play |
HMA backend (app.hidemyandroid.com) | Authenticate you; store balance and transactions | Account data, balance, transaction history |
The App contains no advertising SDK and no third-party analytics SDK.
Data sharing and sale
We do not sell your data and do not share it with third parties for advertising or analytics. Your data is shared only:
- with Google Play, as the payment processor for top-ups; and
- with the HMA backend, as the operator of the service that holds your account.
Account and data deletion
You can request deletion of your account and associated data at any time.
- How: email wowareofficial@gmail.com from (or citing) the email address on your account, with the subject “HMA Credits — delete my account”.
- What is deleted: your account record, your email and display name, your balance record, and your transaction history.
- Timeframe: we aim to process deletion requests within 30 days. We may retain limited transaction records where retention is required by law (for example, tax or accounting obligations); such records are not used for any other purpose.
This section, together with the Support page, is the deletion channel referenced in the Google Play data-safety disclosure.
Data retention
Your account data is retained while your account is active. It is deleted after a verified deletion request, subject to any legally required retention of transaction records described above.
Children
The App is a financial app and is not directed to children. The Play Store listing targets the audience 18+. We do not knowingly collect personal information from children.
Regional rights — GDPR / CCPA / others
If you reside in the EU, UK, California, Brazil, or another jurisdiction with data-protection legislation, you may request to access, correct, or delete your personal data, or object to its processing, by emailing the address below. We will respond within the timeframe required by your jurisdiction.
Security
- All communication with the backend uses HTTPS.
- Passwords are transmitted over HTTPS and stored hashed server-side; the App does not persist your password.
- The session token is stored encrypted on the device.
- The App targets a recent Android SDK (API 36) and does not embed remote-config or code-loading SDKs.
Changes to this Policy
We may update this Policy as the App evolves. Material changes are reflected in the “Last updated” and “Policy version” fields above. Continued use after an update constitutes acceptance of the revised Policy.
Governing law
This Policy is governed by the laws of the Socialist Republic of Vietnam. To the extent local consumer- or data-protection laws of your jurisdiction provide stronger rights, those apply to the extent required by law.
Contact
For questions about this Policy or the App’s data handling, email
wowareofficial@gmail.com. Please include the Policy version (currently 1.0) and, for technical questions, your Android version and device model.
The permissions table, third-party SDK list, and data-leaving-device summary below this introduction are rendered automatically from the App’s published metadata and are part of this Policy.
Permissions requested
| Permission | Purpose |
|---|---|
| INTERNET | Communicate with the HMA backend to sign in, load your balance, and verify top-ups |
| ACCESS_NETWORK_STATE | Detect connectivity so the app can show accurate network-error states |
| com.android.vending.BILLING | Process credit top-ups through Google Play Billing |
Third-party SDKs and services
Google Play Billing Library
Collect payment and process credit top-ups; all payment details are handled by Google Play
HMA backend API (app.hidemyandroid.com)
Authenticate the user and store the account balance and transaction history
Data leaving your device
The following data items are transmitted off-device:
- Email and password — sent over HTTPS to the HMA backend to sign you in
- Session token (JWT) — issued by the backend and stored encrypted on your device
- Account balance and transaction history — read from and written to the HMA backend
- Google Play purchase token — sent to the HMA backend to verify a purchase and credit your account
Sale and sharing of data
- Sold to third parties: No
- Shared with third parties: No
Contact
Questions about this privacy policy? Email wowareofficial@gmail.com.