1. Introduction
Welcome to Taki FF ("we," "our," or "us"). We are committed to protecting your privacy and ensuring transparency about how we collect, use, and safeguard your information. This Privacy Policy applies to our website (takiff.online) and all services offered through it.
By using Taki FF, you acknowledge the practices described in this policy. This policy is intended to explain our data handling clearly; it is not a certification that every privacy law applies in the same way to every visitor.
2. Information We Collect
2.1 Personal Data
We do not require users to create an account to use our core tools (Sensi Generator and Stylish Name Maker). However, if you contact us via email, we may collect your name and email address to respond to your inquiry.
2.2 Automatically Collected Data
Device Information: To provide accurate sensitivity settings, we collect device-specific information such as device model and operating system when you use our generator.
Log Data: Like most websites, we collect information that your browser sends whenever you visit our site. This may include your IP address, browser type, pages visited, and time spent on those pages.
Security & Abuse Prevention: We may temporarily use IP addresses to enforce daily usage limits and prevent spam/abuse of our free AI tools. This data is used only for security/anti-abuse purposes and is not sold.
Necessary Cookies: Some tools use short-lived, security-focused cookies for session continuity, human verification, rate limiting, and abuse prevention. These cookies are separate from advertising or analytics cookies.
Local Browser Storage: Some features may store limited settings or history in your browser's local storage. Local storage remains within that browser profile until it expires, the feature clears it, your browser removes it, or you clear the site's data.
Sensi Ustaad AI Mascot Preferences: The occasional AI invitation stores only a last-shown timestamp, a dismissal-until timestamp, and a one-promotion-per-tab flag in local or session storage. These values contain no chat text, FF UID, name, email address, account identifier, or device details. Showing or dismissing the mascot does not send a mascot-specific analytics or API event. When the invitation is shown, its same-origin static image is requested like any other website image and may appear in routine web-server access logs; that image request is not used as a dedicated impression or dismissal tracker. Selecting its link is normal site navigation, and the destination page visit may still be measured by the site-wide analytics described below.
Analytics and Advertising Technologies: Analytics and advertising providers may use their own cookies or similar technologies as described in the Third-Party Services section below. You can control these through available consent controls and browser settings.
2.3 Web Push Notifications
We use web push notifications to keep you updated on Latest Blog Posts, FF Redeem Codes, Giveaways, and Pro Gaming News so you never miss out on important rewards and updates. To provide this service, we store an anonymous unique identifier (Token) provided by your browser. We do NOT use this token to identify you personally or track your activity outside of our content updates. You have total control: You can block or unsubscribe at any time through your browser's site settings or by clicking the notification icon.
2.4 Scratch Card Giveaway & Fraud Prevention
To participate in our free Google Play Redeem Code scratch giveaway, we require users to verify their humanity using Cloudflare Turnstile. Additionally, our server logs and processes your IP address and a unique browser-generated device fingerprint hash during the scratch event.
Why We Do This: This tracking is strictly necessary to prevent automated scraping scripts, bot attacks, and fraudulent claims from draining our limited code supply. It enforces our 24-hour reward cooldown limit (only 1 code win per user/device per 24 hours), ensuring a fair and transparent giveaway for real players.
Data Minimization & Safety: We do not require or collect your game username, password, email address, or any personal credentials. All security identifiers and IP blocks are processed temporarily in our secure database for validation. We never share, lease, or sell this security data to any third-party advertisers.
3. Sensi Ustaad AI — Chat Privacy and Processing
This section applies specifically to the Sensi Ustaad AI text assistant on the Taki FF website. It does not apply to the separate Taki Sensi mobile app, which has its own app privacy policy.
3.1 Information You Submit
- Chat Text: The assistant processes the questions you type and its generated replies. A question is limited to 800 characters.
- Optional Device Details: You may voluntarily mention information such as your phone model, RAM, refresh rate, current sensitivity, network type, or gameplay issue to receive a more relevant answer.
- No Account Required: The assistant does not require a Taki FF account and its chat history is not connected to an account profile.
- Text Only: The assistant does not accept image, audio, video, document, game-file, or account uploads.
3.2 Chat History Stored on Your Device
- Browser-Local Storage: Completed user-and-assistant message pairs are stored in local storage inside the browser profile used to access the assistant. Taki FF does not write this visible transcript to its own database, server file, or permanent server-side conversation log.
- Storage Limit: The browser keeps up to the 40 most recent messages, subject to a total local history limit of approximately 60,000 characters. When the limit is reached, the oldest complete message pairs are removed first.
- Local Expiry: Saved browser history expires after seven days without an update. A browser may remove local storage earlier because of private-browsing rules, storage cleanup, user settings, or device policies.
- No Sync or Backup: Chat history is not synchronized to another device, browser, or account. A different browser or device starts with separate history.
- Shared-Device Risk: Anyone who can use the same browser profile may be able to view the locally saved transcript. Browser local storage is not end-to-end encrypted and may also be exposed by a malicious browser extension, malware, or a same-origin website security compromise.
- Storage Unavailable: If local storage is blocked or unavailable, the assistant can continue in memory for the open page, but the visible transcript may disappear after a reload or navigation.
3.3 What Is Sent When You Ask a Question
- Current Question and Recent Context: When you send a question, your browser transmits that question and up to eight recent locally stored messages to help maintain conversational context. Older local messages are not included in that request.
- Temporary Application Processing: The Taki FF server receives the request, performs security and usage checks, sends the permitted text for AI inference, and returns the reply. Message content necessarily exists in working memory while the request is processed.
- No Taki FF Server Transcript: The assistant application does not retain chat text in a server conversation map after the request, or write prompts and replies to our database, file system, or application chat logs. Our application error logs are designed to record request identifiers and status information rather than message content.
- Encrypted Transport: In production, text is transmitted over HTTPS/TLS. Do not use the assistant over a connection that your browser identifies as insecure.
3.4 AI Service Provider Processing
We use Amazon Web Services (AWS) Amazon Bedrock to generate assistant replies. The current question and limited recent context are transmitted to Amazon Bedrock in our configured AWS Region, which may be located outside your country, including in the United States.
Our application does not use chat content to train its own model. AWS documents that Bedrock data handling and durable retention depend on the effective account, project, and model retention mode. We therefore do not promise zero provider retention or immediate deletion by AWS. AWS also explains the conditions under which inference data may be retained for abuse detection or, when explicitly configured and required, shared under a provider-data-sharing mode. See the official Amazon Bedrock Data Retention documentation and Amazon Bedrock Data Protection documentation.
3.5 Session Cookie, Turnstile, and Abuse Prevention
- Necessary Session Cookie: The assistant uses a cookie named
sensi_ustaad_ai_session. It contains a signed random session identifier and expiry time—not chat text. It is HttpOnly, SameSite=Strict, restricted to the assistant API path, marked Secure over HTTPS, and expires after approximately 30 minutes. - Cloudflare Turnstile: Initial verification uses Cloudflare Turnstile. A verification token and technical network information, which may include an IP address, are sent to Cloudflare for bot and abuse detection under Cloudflare's policies.
- Pseudonymous Security Records: For usage limits and abuse prevention, the server temporarily holds HMAC-hashed IP identifiers, random session identifiers, counters, and timestamps in volatile memory. These security records do not contain chat text and generally expire within approximately 25 hours.
- Limits Remain After New Chat: Starting a new chat clears browser conversation history but does not reset security, CAPTCHA, cooldown, or usage-limit records.
3.6 Retention, Deletion, and Your Controls
- New Chat: Selecting “New Chat” removes the saved Sensi Ustaad AI transcript from that browser and clears the visible conversation.
- Clear Site Data: You can also remove local history and the session cookie through your browser's cookies/site-data controls.
- No Remote Recovery: Because the visible transcript is stored locally and is not linked to an account, Taki FF cannot recover, synchronize, or remotely delete that browser copy for you.
- Completed Requests: Clearing local history cannot reverse a request that has already been processed, erase automatically expiring security counters immediately, or control any data AWS retains under its effective retention mode.
3.7 Sensitive Information and AI Limitations
- Do not enter passwords, OTPs, access tokens, payment information, email addresses, phone numbers, private account credentials, or other confidential information.
- The assistant is an independent gaming guide. It does not access Garena accounts, game servers, private player records, payment systems, or live account data.
- AI-generated replies may be incomplete, inaccurate, or unsuitable for a specific device. Treat sensitivity and performance suggestions as starting points and test changes gradually.
- We may reject requests involving cheats, account intrusion, credential theft, modified apps, ban bypasses, or other unsafe activity.
4. GFX Tool & Image Privacy (Important)
We take your privacy seriously, especially when using our AI GFX Tool (Logo, Banner, and Thumbnail Maker).
- No Server Storage: Any image you upload to create a logo or banner is processed instantly in real-time. We do NOT save, store, or archive your personal photos on our servers or databases.
- Instant Deletion: Once the AI generates your design, your uploaded image data is immediately discarded from the processing memory (RAM). It is permanently deleted and cannot be recovered by us or anyone else.
- Your Data is Yours: The final designs generated by our tool are yours to download and use. We do not claim ownership of your creations or the images you upload.
5. FF Teammate Finder Tool — Privacy, Security & Disclaimer
Our FF Teammate Finder is a community-driven social matchmaking tool that enables FF players to discover and connect with active rank push partners in real time. This tool is strictly a social-matching utility. It does not interact with, connect to, access, modify, or query any Garena, FF, or third-party game server, database, API, or backend system in any capacity whatsoever.
5.1 No Game Server Interaction Disclaimer
Taki FF Teammate Finder operates entirely as an independent, self-contained social matching service hosted on our own infrastructure. It is important for users, game publishers, and regulatory bodies to understand:
- Zero Garena/Game Server Access: This tool does NOT access, query, scrape, or interface with any Garena, FF, or third-party game server, account database, matchmaking system, or player profile API. We have absolutely no connection to any game publisher's infrastructure.
- No Account Access or Credentials: We do NOT request, collect, or store game account passwords, login credentials, email addresses, or authentication tokens. The FF UID entered by users is treated as a self-declared public display identifier only — we do not verify, validate, or cross-reference it against any game database.
- Not a Hack, Mod, or Exploit Tool: This tool does not modify game files, inject code, provide unfair advantages, generate in-game currency, or bypass any game security system. It is a simple community chat room where two players can exchange their self-declared UIDs to add each other as friends in-game manually.
- Independent Operation: All matchmaking logic runs entirely on our own web server using temporary in-memory data structures. No external game APIs or databases are contacted at any point during the matchmaking or chat process.
5.2 Data Collection & Privacy
- Self-Declared Information Only: Users voluntarily provide a self-declared FF UID (numeric identifier), an in-game display name, and an optional short note (e.g., "CS Rank Grandmaster Push"). These are user-submitted text strings — we do not verify their accuracy or authenticity against any external system.
- 1-on-1 Private Rooms: Each matchmaking session is strictly limited to a maximum of 2 players per private room. A 3rd player attempting to join is automatically paired into a new, separate room to ensure complete conversation privacy.
- Zero Persistent Database Storage: We do NOT save, archive, log, or write chat messages, player names, FF UIDs, or room data to any permanent database, file system, or disk storage. All session data exists exclusively in volatile server memory (RAM).
- 10-Minute Automatic Memory Wipe: Every room session is governed by a strict 10-minute countdown timer. Upon expiration, all associated data — including room IDs, player tokens, chat message history, and typing status flags — is permanently and irreversibly destroyed from server memory. No residual data remains after cleanup.
- No Chat Logs or Message Archives: We maintain zero chat history. Messages exist only in real-time volatile memory during the active 10-minute session window. Once the session ends or a player disconnects, all messages are permanently erased.
5.3 Security & Anti-Abuse Measures
- Cloudflare Turnstile CAPTCHA Verification: Before joining any matchmaking room, users must pass a Cloudflare Turnstile human verification challenge. This prevents automated bots, spam scripts, and malicious crawlers from abusing the service.
- Server-Side Rate Limiting: A strict 1.5-second cooldown is enforced between consecutive chat messages at the server level. Any request sent within this cooldown window is automatically rejected (HTTP 429), preventing message flooding and spam attacks.
- Content Filtering: All chat messages and user-submitted notes are scanned in real time against a server-side blocklist that rejects URLs, links, phishing domains, and prohibited keywords (including hack, mod, injector, cheat, script, and similar terms). This prevents social engineering, scam distribution, and harmful content.
- Message Length Limits: Chat messages are capped at 80 characters, and in-memory history is limited to the most recent 30 messages per room. Older messages are automatically discarded.
- Encrypted Transport: All data transmitted between the user's browser and our server is protected by industry-standard HTTPS/TLS encryption.
6. Third-Party Services and Advertising
6.1 Google AdSense
We use Google AdSense to serve advertisements on our website. Google, as a third-party vendor, uses cookies (such as the DART cookie) to serve ads based on your visit to our site and other sites on the Internet.
Users may opt out of personalized advertising by visiting Google Ads Settings.
6.2 Google Analytics
We use Google Analytics to monitor and analyze web traffic. Google Analytics tracks website usage data which is used to improve our services.
6.3 Amazon Affiliate Disclosure
Taki FF is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to Amazon.in (and associated Amazon sites). As an Amazon Associate, we earn a small commission from qualifying purchases. This carries no extra cost to you as a buyer and helps support the maintenance and server hosting of our free tools.
6.4 Amazon Bedrock
Sensi Ustaad AI uses Amazon Bedrock for text inference. When you submit a question, the current question and limited recent context are processed through AWS as described in Section 3. Amazon Bedrock's own terms, data-retention configuration, and privacy documentation apply to that processing.
6.5 Cloudflare Turnstile
We use Cloudflare Turnstile on protected tools to verify that requests are made by people rather than automated abuse systems. Cloudflare may process verification tokens and technical browser or network information under its own privacy terms. Turnstile verification is validated by our server before protected requests are accepted.
7. How We Use Your Information
- To provide and maintain our tools (Sensitivity Generator, Stylish Name Maker, FF Teammate Finder).
- To generate Sensi Ustaad AI replies using the user's current question and limited recent context.
- To improve our website's user experience and performance.
- To show relevant advertisements through Google AdSense.
- To respond to user inquiries and support requests.
- To secure free tools, enforce usage limits, prevent automated abuse, and diagnose service failures without intentionally recording AI chat content in application logs.
8. Data Protection
We implement industry-standard security measures, including HTTPS/TLS encryption, to protect your data. We do not sell, trade, or rent your personal information to third parties.
No online service or browser storage system can be guaranteed 100% secure. Users should avoid submitting sensitive information and should clear local chat history when using a shared or public device.
9. GDPR and CCPA Rights
If you are a resident of the European Economic Area (EEA) or California, you have certain data protection rights. You can request to access, correct, or delete any personal data we hold about you by contacting us.
Sensi Ustaad AI's visible transcript is stored in your browser rather than an account-controlled server record. You can delete that local copy directly by selecting “New Chat” or clearing site data. We cannot retrieve a browser-local transcript that was never stored in our systems.
10. Children's Privacy
Our website is not intended for children under 13. We do not knowingly collect personal information from children under 13.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us at: contact@takiff.online