Privacy policy

Puzzeroo is used by children, so it is built to collect as close to nothing as a working app can. No accounts, no adverts, no third-party trackers, no personal data. Nothing at all is sent to us unless a grown-up switches it on. This page explains exactly what that means and what the few exceptions are.

Last updated: 22 August 2026. This policy covers the Puzzeroo app on iOS and Android, and the puzzeroo.app website.

The short version. The app works entirely offline and stores your child's progress on their device. Out of the box it sends us nothing: anonymous usage data is switched off until a grown-up turns it on in Settings, and can be switched back off in one tap. If you buy the full unlock, Apple or Google takes the payment (whichever store you bought it from) and RevenueCat verifies the receipt. The app also keeps a short list of error messages on the device, so that you can email us a problem report if it misbehaves, and that list never leaves the device unless you choose to send it. That is the whole of it.

Who we are

Puzzeroo is an independent app for iPhone, iPad and Android, plus this website, run by a single developer. For data protection purposes we are the data controller for the very limited information described below. You can reach us at any time at support@puzzeroo.app. It is a real address, read by a person.

Children's privacy

Puzzeroo is designed for children aged roughly five to twelve, and is built to satisfy the United States Children's Online Privacy Protection Act (COPPA), the UK Privacy and Electronic Communications Regulations (PECR) and the UK Information Commissioner's Age Appropriate Design Code. The design decisions that follow from that are not preferences; they are the reason the app is shaped the way it is.

Because we collect no personal information from children, COPPA's verifiable parental consent requirement is not triggered, and the anonymous usage data described below would in any case fall within COPPA's carve-out for information used solely to support the internal operations of the service. UK law asks a different question, and we answer it separately: PECR regulation 6 governs storing information on the device at all, so the install identifier needs consent regardless of how anonymous it is. Hence the switch, and hence its being off to begin with.

What stays on the device

Everything that makes the app work is stored locally on the phone or tablet and never sent anywhere:

None of this is backed up to a server by us. It travels with the device (and with your own iCloud or Google device backup, if you have that switched on, which is between you and Apple or Google). Deleting the app deletes it.

Anonymous usage data, off unless you switch it on

The app can send a small stream of anonymous events to a server we run ourselves, so that we can tell which puzzle types children actually play, where they give up, and whether the app is crashing. It is the only thing the app ever transmits to us, and it is switched off when you install it.

Off by default, and off means nothing exists. Until a grown-up turns the switch on, the app does not generate an install identifier, does not create a queue, writes no analytics data to the device and makes no request to our server. This is not a setting that suppresses sending. There is nothing to send. Turning the switch back off shuts the collection down and erases the identifier and anything queued, so opting in again later starts from scratch rather than resurrecting an old identifier.

How the switch works

Exactly what is sent, once it is on

FieldExampleWhy
Install identifierA random UUID generated on the device on first launchSo that fifty events from one tablet are not counted as fifty tablets. It is generated locally, is not derived from any device or account identifier, cannot be linked to a person, and is regenerated if the app is deleted and reinstalled.
App version1.4.2To tell whether a problem is fixed in a newer release.
Platformios or androidWhich build sent it.
OS versioniOS 18.2, Android 14To know which iOS and Android versions still need supporting.
Event namepuzzle_complete, hint_used, js_errorWhat happened. The complete list is ten names long and is published by the server at /v1/config.
Event timestampA millisecond clock valueTo order events within a session and measure how long things take.
Event propertiespuzzle type, difficulty, level id, duration in ms, hints used, completed/skipped; for errors, a message and stack traceSmall scalar values only. There is no free-text field a child could type into anywhere in the app.

What is never collected

As defence in depth, any free-text value that could reach the server, an error message for instance, has email-shaped text and long digit runs redacted before it is stored. Nothing in the app should be producing such text in the first place.

Who receives it, how long it is kept

The data goes to a server we operate, on hosting we rent in the United Kingdom, and to nowhere else. There is no third-party analytics provider, no data warehouse, no tag manager and no advertising platform involved at any point. Events are deleted automatically once they are 180 days old. The deletion runs when the server starts, and once every day after that.

If the server is unreachable, or was never configured, gameplay is completely unaffected: the app is fire-and-forget and never waits for us.

Our lawful basis (UK and EU visitors)

Consent, given by a grown-up through the switch described above, and withdrawable at any moment through the same switch. We rely on it for both things it covers: storing the install identifier on the device (UK PECR regulation 6) and processing the events that identifier ties together, to the extent that any of it constitutes personal data under the UK or EU GDPR. We do not believe it does, since the identifier is random, device-local and unlinkable to a person.

We deliberately do not rely on legitimate interests here. We could have argued it, and the argument would have been reasonably strong given how little the data contains, but PECR does not offer that route for storing an identifier on someone's device, and the ICO's Children's Code is plain that non-essential processing should not be switched on for a child by default. A consent switch that starts off is the answer to both.

Problem reports: what stays on the device until you send it

Analytics being off by default leaves a gap: when an app misbehaves on a child's tablet, a parent quite reasonably cannot describe what went wrong in technical terms, and we have nothing to look at. So the app keeps its own local record of errors, and nothing more.

If something does go wrong, Settings → For grown-ups → Email a problem report (behind the parental gate) turns that record into plain text you can read in full, and hands it to the device's share sheet or to your email app. You choose whether to send it, to whom, and whether to delete anything first. Clear report data, next to it, empties the record immediately and needs no gate. Throwing away a list of error messages cannot cost anybody anything.

We keep any report you do send for as long as it takes to fix the problem and no longer, and we will delete it sooner if you ask.

Purchases

Puzzeroo has one optional in-app purchase: a permanent unlock of the later levels. It is not a subscription and nothing renews.

This website

puzzeroo.app sets no cookies, runs no analytics of any kind, and contains no JavaScript. Every font, image, stylesheet and PDF is served from this domain. Nothing is loaded from a CDN, an advertising network, a font service or a social platform, so no other company learns that you visited. Downloading a worksheet requires no email address and creates no record beyond the ordinary web server log kept by our host for operational purposes.

The only links leaving this site are to RevenueCat's privacy policy, to the developer's own website, and — once the app is listed — to the App Store and Google Play, all clearly labelled. Following them takes you to companies with their own privacy practices.

Security

All traffic to this site and to the analytics endpoint is encrypted in transit with HTTPS. The analytics service accepts only a strictly validated JSON payload, rejects anything oversized or malformed, and rate-limits per install identifier. The admin dashboard is password protected and fails closed if credentials are not configured. The honest summary of our security posture, though, is that the strongest control is the one at the top of this page: we do not hold data about anyone, so there is very little for anybody to steal.

Your rights

Under the UK GDPR, the EU GDPR and similar laws you have rights to access, correct, delete, restrict and object to the processing of your personal data, and to complain to a supervisory authority (in the UK, the Information Commissioner's Office).

There is an unavoidable honesty problem in exercising them here: because the usage data contains nothing that identifies you, we cannot find "your" records in order to show or delete them, and we will not ask you for identifying information in order to try. Collecting personal data in the name of a privacy request would make things worse rather than better. Under Article 11 of the UK GDPR we are not required to acquire additional information solely to identify a data subject.

One right needs no request at all, because it is a switch rather than a letter: withdrawing consent. Settings, then Share anonymous usage data, off. It takes effect immediately, erases the identifier from the device, and nothing further is collected. That is the right most people actually want, and it should not require writing to anybody.

What we can do, and will do promptly on request:

Write to support@puzzeroo.app. We reply to everything, usually within two working days.

Changes to this policy

If this policy changes we will update the date at the top of the page. If a change ever meant the app started collecting something it does not collect today, we would say so plainly at the top of this page rather than quietly editing a paragraph in the middle.

Questions parents and schools ask

Does Puzzeroo collect personal information from children?

No. The app has no accounts, no sign-in, no name field, no email field, no birthday, no contacts access, no camera access, no microphone access, no location access and no advertising identifier. Nothing that leaves the device identifies a person, a household or a device.

Does Puzzeroo show adverts?

No, and there is no advertising SDK in the app at all. Nothing about a child is used for advertising, profiling, audience building or any form of behavioural targeting, by us or by anybody else.

Is anything collected by default?

No. Anonymous usage data is switched off when you install the app and stays off until a grown-up turns it on in Settings, behind a parental gate. Until then the app generates no identifier of any kind, writes nothing to send, and makes no network request to us at all. It is not a switch that stops the sending: with it off, nothing is created in the first place.

What does the anonymous usage data contain, if I do switch it on?

A random install identifier generated on the device, the app version, the platform ("ios" or "android"), the OS version string, and a list of events. Each event is a name such as puzzle_complete, a timestamp, and a small bag of scalar values such as puzzle type, difficulty, level id, duration in milliseconds and hint count. That is the complete list.

Is my IP address recorded?

No. The analytics server is configured never to read or store one: proxy header trust is switched off so the framework cannot derive an address, the access log records only method, path, status and duration, and no database table has an address column. Even the rate limiter is keyed on the anonymous install identifier, not on an address.

How do I turn the usage data off again?

One tap. Settings, then the "Share anonymous usage data" switch. Turning it on asks a grown-up question first; turning it off does not, because withdrawing consent has to be at least as easy as giving it. Switching it off also erases the install identifier and anything still queued on the device, so nothing is left behind waiting to be sent.

What is the problem report, and what is in it?

The app keeps a short list of error messages on the device: timestamps, the app version, error text and stack traces, and the names of a couple of events such as puzzle_start. It is capped, it overwrites itself, and it never leaves the phone or tablet on its own. If something goes wrong you can use Settings, then "Email a problem report", to send it to us; the app builds the report as plain text you can read in full before sending. It contains no identifiers, no names, no email addresses and nothing about what your child typed or solved. "Clear report data", next to it, throws the list away.

Do you sell or share data with anybody?

No. Nothing is sold, rented, brokered or shared for anyone else's purposes. The only third parties involved at all are Apple or Google, whichever store processes the purchase, and RevenueCat, which verifies the receipt on our behalf.

Does this website track me?

No. puzzeroo.app sets no cookies, runs no analytics, loads no fonts, scripts, images or stylesheets from any other server, and has no social buttons or embeds. There is no JavaScript on these pages at all.

Still unsure about something? support@puzzeroo.app. If you are a school or nursery that needs this on headed paper for a records-of-processing file, say so and we will send it.