Summary
Puzzlesight is a Sudoku app for iPhone, iPad, and Android. This policy explains, in plain language, what the app does and doesn't collect and which third-party services it uses. In short:
- Scanning happens on your device. Camera frames and photos are never uploaded to us.
- No named account is required. Online social features use a random anonymous profile; a recovery email is optional.
- We don't sell your personal information, and we don't run trackers to build an advertising profile of you.
- The free version shows ads and a rewarded-ad option; a one-time Pro purchase removes ads.
Puzzlesight is operated by Appverse LLC ("we", "us"). If you're in the EU/UK, we act as the "controller" for the limited data described below.
Your camera and photos (on-device)
Scanning uses your camera to find and read a Sudoku grid. That recognition runs entirely on your device. Camera frames are analysed in memory to detect the grid and read the digits, and are not uploaded, stored on our servers, or shared with anyone. When you import a board, only the resulting puzzle — the grid of digits — is saved locally on your device so you can return to it later.
The app asks for camera permission the first time you scan, and for photo access only if you choose to import from an existing picture. You can revoke either permission at any time in your device settings; the relevant feature simply stops working until you grant it again.
Your profile (anonymous by default)
When you first use a server-backed feature such as friends, leaderboards, cross-device profile recovery, or a verified rewarded ad, the app creates an anonymous profile on our server. It is identified by a random ID and device credential and does not require — or by default include — your name, email address, or phone number.
You may optionally add a recovery email. We use it for one purpose: to let you restore your profile and progress if you get a new phone or reinstall the app. You can add or remove it at any time. We don't use it for marketing.
When you request a recovery code, we send the recovery email and that one-time message through Resend, our transactional email provider. Resend receives the destination email address and delivery metadata needed to deliver and protect that message; we do not use Resend for marketing email.
To understand which countries use the app, our servers derive a country from your IP address when your device talks to our backend. We don't store your IP address itself. We store only the country on your anonymous profile. If you later add a display name or recovery email, that country is technically associated with the same profile; we use it only for operating the service and aggregate country-level usage reporting.
Requests to our backend also identify the app version and build, operating system and version, device model, and locale. We store those technical fields, the device's last-active time, and interactions needed to provide server features (for example reward verification, sync, friends, and leaderboard activity) with the anonymous device/profile record. We use them for app functionality, compatibility, abuse prevention, support, and aggregate product diagnostics. They can become associated with a display name or recovery email only if you choose to add one to that profile.
Friends and leaderboards
Leaderboards are opt-in. If you use them, the app stores and shows a display name you choose and your solve times and daily-challenge results, so you and the friends you've connected with can compare scores. Friend connections are made through an invite link you share; we don't read your contacts or address book. You can change your display name, leave a leaderboard, or delete your profile at any time.
Purchases (RevenueCat)
The optional one-time Pro upgrade is sold through the App Store or Google Play. We use RevenueCat to retrieve the offer and localized price, process and validate purchases, restore purchases, and remember the Pro entitlement. Apple or Google process the actual payment — we never see your card or full billing details. RevenueCat initially uses its own anonymous customer ID. If a Puzzlesight server profile exists, we link its random profile UUID to RevenueCat so a transferred or recovered profile can recover its entitlement where the relevant store account and store rules permit. We do not send RevenueCat your display name or recovery email. Deleting the Puzzlesight profile removes our profile and the local link, but it does not cancel or refund a store purchase; Apple, Google, and RevenueCat may retain transaction and entitlement records needed to validate and restore that purchase.
Ads and the gem reward (Google AdMob)
The free version shows ads to support the app, delivered by Google AdMob. AdMob may use a mobile advertising identifier to show and measure ads under Google's privacy policy. You can reset or limit that identifier in your device settings. We keep our ad stack deliberately narrow — AdMob is the only ad network we integrate directly, rather than a long list of third-party exchanges; any certified ad-technology partners Google itself works with to select and measure ads are disclosed through the in-app consent form (EU/UK/Switzerland) or at Google's user consent policy.
On iPhone and iPad, we ask for your permission before any tracking-related identifier is used, through Apple's App Tracking Transparency system prompt, shown once on first launch. You can change your answer at any time in Settings → Privacy & Security → Tracking. On Android, you can reset or turn off your advertising ID in Settings → Privacy → Ads.
If you're in the EU, UK, or Switzerland, you'll also see Google's consent form asking about ad storage, measurement, and personalization. The app checks Google's resulting can request ads signal before it starts AdMob or requests any ad. Depending on the choices and local rules, this can mean personalized ads, limited/non-personalized ads, or no ad request. You can revisit the choice at any time via Privacy options in the app's Settings; future requests are blocked when permission is no longer available.
You can also choose to watch a rewarded ad to earn in-app gems, which you spend on helpers like extra hints. Watching is always your choice; gems are a convenience, never a requirement. Before an ad is shown, the app supplies Google with your random profile UUID and a one-use nonce. Google returns those values to our server in a signed server-side-verification callback. Our server credits only callbacks for Puzzlesight's configured ad units and reward amount; it stores the nonce to prevent duplicate rewards. Taking the one-time Pro upgrade removes ads — including the rewarded ones — entirely.
Install attribution (Tenjin)
To understand which ads or channels led people to download Puzzlesight — so we know where to spend a small marketing budget — we use Tenjin. When you first install and open the app, Tenjin may receive device and network signals (such as a device/advertising identifier, IP address, and device model) to match your install to a campaign. This is used for aggregate measurement, not to build a Puzzlesight identity profile. Tenjin receives Google's stored consent choice before it connects; when that choice requires Tenjin to opt out, the SDK sends no Tenjin events. On iOS, Apple's tracking choice separately controls access to the advertising identifier. Apple Ads (formerly Search Ads) can still provide privacy-limited attribution without that identifier; granting tracking permission enables the more detailed IDFA-based attribution path.
Crash and performance reports (Firebase Crashlytics)
After you accept the app's legal terms, when a production build crashes or misbehaves, Firebase Crashlytics sends us a diagnostic report — a stack trace plus technical context like your device model, operating-system version, and app version — so we can find and fix the bug. These reports are about the software, not about you, and aren't tied to your name or email. The app does not include Firebase Analytics.
Notifications (Firebase Cloud Messaging)
If you allow notifications, we use Firebase Cloud Messaging to deliver daily reminders and social/leaderboard updates you enable. This requires a device-specific messaging token, which we store linked to your anonymous profile so we know where to send the message. Firebase token generation and remote-notification registration remain off until notification permission is granted. Declining or revoking permission stops delivery.
Puzzles you save and print
Scanned and generated boards, and your in-progress solves, are stored locally on your device (your streak and daily results also sync to your anonymous profile). Files you export from Print are handed to your operating system's share sheet — where they go next (email, Files, a printer) is up to you and governed by those services' own terms.
On iPhone/iPad, your saved puzzles and progress may also sync via your iCloud account using Apple's CloudKit, subject to Apple's own iCloud terms. On Android, the same sync uses your Google Play Games account. We don't have access to your iCloud or Google account beyond this app-specific data.
What we don't do
- We don't sell or rent your personal information.
- We don't require your name, email, contacts, or precise location.
- We don't upload your camera frames or photos.
- We don't build cross-app advertising profiles ourselves.
How long we keep data
Your anonymous profile, streak, and leaderboard entries are kept while your profile exists. They remain until you delete the profile or ask us to delete it; we do not currently promise an automatic inactivity deadline. Crash reports and attribution data are retained only as long as they're useful for fixing bugs and measuring campaigns, per those providers' standard retention. Recovery-email delivery data is kept only as needed to deliver and secure those one-time messages, subject to Resend's retention practices. After profile deletion, we retain only a one-way hash of the former device sign-in token as an active receipt for 30 days so a lost network response can be retried safely; it cannot restore or identify the deleted profile. After expiry it is no longer used, and expired hashes are purged during subsequent deletion maintenance. Deleting the app removes its ordinary app-container data, but a secure Keychain identity credential on iOS and app data in your private iCloud or Play Games storage may survive reinstall until you clear the online profile through the app and manage platform cloud data through the relevant iCloud or Play Games account settings.
Your rights and choices
Depending on where you live (for example under the EU/UK GDPR or California's CCPA/CPRA), you may have the right to access, correct, or delete the data tied to your profile, and to opt out of the "sale" or "sharing" of personal information — which we don't do. Because most data is either on your device or held under an anonymous ID, you can exercise the core of these rights yourself:
- Delete your Puzzlesight server profile: use the in-app option, or email us and we'll remove the profile and its social, leaderboard, recovery, device, and reward data. Store transaction records are handled separately as described under Purchases.
- Limit ads/attribution: reset or turn off your advertising identifier in your device settings (iOS: Tracking; Android: Ads), or change your ad-personalization consent anytime via Privacy options in the app's Settings.
- Remove app data: use the in-app option for the online profile, manage private iCloud or Play Games data in the relevant platform account settings, then delete the app to remove its remaining local app-container data.
To make a request or ask a question, email [email protected]. We may need to verify the request against your profile ID before acting on it.
Children
Puzzlesight is intended for a general audience and is not directed at children under 13 (or the equivalent age in your region). Sudoku naturally appeals to a wide range of ages, but we don't market the app to children, don't knowingly collect personal information from anyone under 13, and configure our ads and advertising partner for a general audience rather than a child-directed one. If you believe a child under 13 has provided us with personal information, contact us and we'll remove it.
Where data is processed
Our servers and the third-party services above may process data in countries other than yours, including the United States. Where required, we rely on appropriate safeguards for those transfers. Downloading through the App Store or Google Play is also subject to Apple's and Google's own privacy practices.
Changes to this policy
If we change how the app handles data, we'll update this page and revise the date above. Material changes will also be noted in the app's release notes.
Contact
Questions or requests about privacy? Email [email protected].