Privacy policy

Puzzeroo is used by children, so it is built to collect as close to nothing as a working app can. No accounts, no adverts, no third-party trackers, no personal data — and nothing at all is sent to us unless a grown-up switches it on. This page explains exactly what that means and what the few exceptions are.

Last updated: 27 July 2026. This policy covers the Puzzeroo iOS app and the puzzeroo.app website.

The short version. The app works entirely offline and stores your child's progress on their device. Out of the box it sends us nothing: anonymous usage data is switched off until a grown-up turns it on in Settings, and can be switched back off in one tap. If you buy the full unlock, Apple takes the payment and RevenueCat verifies the receipt. The app also keeps a short list of error messages on the device, so that you can email us a problem report if it misbehaves, and that list never leaves the device unless you choose to send it. That is the whole of it.

Who we are

Puzzeroo is an independent iOS app and this website, run by a single developer. For data protection purposes we are the data controller for the very limited information described below. You can reach us at any time at support@puzzeroo.app — a real address, read by a person.

Children's privacy

Puzzeroo is designed for children aged roughly five to twelve, and is built to satisfy the United States Children's Online Privacy Protection Act (COPPA), the UK Privacy and Electronic Communications Regulations (PECR) and the UK Information Commissioner's Age Appropriate Design Code. The design decisions that follow from that are not preferences; they are the reason the app is shaped the way it is.

Because we collect no personal information from children, COPPA's verifiable parental consent requirement is not triggered, and the anonymous usage data described below would in any case fall within COPPA's carve-out for information used solely to support the internal operations of the service. UK law asks a different question, and we answer it separately: PECR regulation 6 governs storing information on the device at all, so the install identifier needs consent regardless of how anonymous it is. Hence the switch, and hence its being off to begin with.

What stays on the device

Everything that makes the app work is stored locally on the iPhone or iPad and never sent anywhere:

None of this is backed up to a server by us. It travels with the device (and with your own iCloud device backup, if you have that switched on, which is between you and Apple). Deleting the app deletes it.

The anonymous usage data — off unless you switch it on

The app can send a small stream of anonymous events to a server we run ourselves, so that we can tell which puzzle types children actually play, where they give up, and whether the app is crashing. It is the only thing the app ever transmits to us, and it is switched off when you install it.

Off by default, and off means nothing exists. Until a grown-up turns the switch on, the app does not generate an install identifier, does not create a queue, writes no analytics data to the device and makes no request to our server. This is not a setting that suppresses sending — there is nothing to send. Turning the switch back off shuts the collection down and erases the identifier and anything queued, so opting in again later starts from scratch rather than resurrecting an old identifier.

How the switch works

Exactly what is sent, once it is on

FieldExampleWhy
Install identifierA random UUID generated on the device on first launchSo that fifty events from one iPad are not counted as fifty iPads. It is generated locally, is not derived from any device or account identifier, cannot be linked to a person, and is regenerated if the app is deleted and reinstalled.
App version1.4.2To tell whether a problem is fixed in a newer release.
PlatformiosConstant today; present so the schema survives a future platform.
OS version18.2To know which iOS versions still need supporting.
Event namepuzzle_complete, hint_used, js_errorWhat happened. The complete list is ten names long and is published by the server at /v1/config.
Event timestampA millisecond clock valueTo order events within a session and measure how long things take.
Event propertiespuzzle type, difficulty, level id, duration in ms, hints used, completed/skipped; for errors, a message and stack traceSmall scalar values only. There is no free-text field a child could type into anywhere in the app.

What is never collected

As defence in depth, any free-text value that could conceivably reach the server — an error message, for instance — has email-shaped text and long digit runs redacted before it is stored, even though nothing in the app should be producing such text in the first place.

Who receives it, how long it is kept

The data goes to a server we operate, on hosting we rent in the United Kingdom, and to nowhere else. There is no third-party analytics provider, no data warehouse, no tag manager and no advertising platform involved at any point. Events are deleted automatically once they are 180 days old — the deletion runs when the server starts and once every day thereafter.

If the server is unreachable, or was never configured, gameplay is completely unaffected: the app is fire-and-forget and never waits for us.

Our lawful basis (UK and EU visitors)

Consent, given by a grown-up through the switch described above, and withdrawable at any moment through the same switch. We rely on it for both things it covers: storing the install identifier on the device (UK PECR regulation 6) and processing the events that identifier ties together, to the extent that any of it constitutes personal data under the UK or EU GDPR — which we do not believe it does, since the identifier is random, device-local and unlinkable to a person.

We deliberately do not rely on legitimate interests here. We could have argued it, and the argument would have been reasonably strong given how little the data contains, but PECR does not offer that route for storing an identifier on someone's device, and the ICO's Children's Code is plain that non-essential processing should not be switched on for a child by default. A consent switch that starts off is the answer to both.

Problem reports: what stays on the device until you send it

Analytics being off by default leaves a gap: when an app misbehaves on a child's iPad, a parent quite reasonably cannot describe what went wrong in technical terms, and we have nothing to look at. So the app keeps its own local record of errors — and only that.

If something does go wrong, Settings → For grown-ups → Email a problem report (behind the parental gate) turns that record into plain text you can read in full, and hands it to the iOS share sheet or to your email app. You choose whether to send it, to whom, and whether to delete anything first. Clear report data, next to it, empties the record immediately and needs no gate — throwing away a list of error messages cannot cost anybody anything.

We keep any report you do send for as long as it takes to fix the problem and no longer, and we will delete it sooner if you ask.

Purchases

Puzzeroo has one optional in-app purchase: a permanent unlock of the later levels. It is not a subscription and nothing renews.

Purchases are also unlockable offline with a gift code, which involves no network request and no third party at all.

This website

puzzeroo.app sets no cookies, runs no analytics of any kind, and contains no JavaScript. Every font, image, stylesheet and PDF is served from this domain — nothing is loaded from a CDN, an advertising network, a font service or a social platform, so no other company learns that you visited. Downloading a worksheet requires no email address and creates no record beyond the ordinary web server log kept by our host for operational purposes.

The only links leaving this site are to Apple's App Store and to RevenueCat's privacy policy, both clearly labelled. Following them takes you to companies with their own privacy practices.

Security

All traffic to this site and to the analytics endpoint is encrypted in transit with HTTPS. The analytics service accepts only a strictly validated JSON payload, rejects anything oversized or malformed, and rate-limits per install identifier. The admin dashboard is password protected and fails closed if credentials are not configured. The honest summary of our security posture, though, is that the strongest control is the one at the top of this page: we do not hold data about anyone, so there is very little for anybody to steal.

Your rights

Under the UK GDPR, the EU GDPR and similar laws you have rights to access, correct, delete, restrict and object to the processing of your personal data, and to complain to a supervisory authority (in the UK, the Information Commissioner's Office).

There is an unavoidable honesty problem in exercising them here: because the usage data contains nothing that identifies you, we genuinely cannot find "your" records in order to show or delete them, and we will not ask you for identifying information in order to try — collecting personal data in the name of a privacy request would make things worse rather than better. Under Article 11 of the UK GDPR we are not required to acquire additional information solely to identify a data subject.

One right needs no request at all, because it is a switch rather than a letter: withdrawing consent. Settings, then Share anonymous usage data, off. It takes effect immediately, erases the identifier from the device, and nothing further is collected. That is the right most people actually want, and it should not require writing to anybody.

What we can do, and will do promptly on request:

Write to support@puzzeroo.app. We reply to everything, usually within two working days.

Changes to this policy

If this policy changes we will update the date at the top of the page. If a change ever meant the app started collecting something it does not collect today, we would say so plainly at the top of this page rather than quietly editing a paragraph in the middle.

Questions parents and schools ask

Does Puzzeroo collect personal information from children?

No. The app has no accounts, no sign-in, no name field, no email field, no birthday, no contacts access, no camera access, no microphone access, no location access and no advertising identifier. Nothing that leaves the device identifies a person, a household or a device.

Does Puzzeroo show adverts?

No, and there is no advertising SDK in the app at all. Nothing about a child is used for advertising, profiling, audience building or any form of behavioural targeting, by us or by anybody else.

Is anything collected by default?

No. Anonymous usage data is switched off when you install the app and stays off until a grown-up turns it on in Settings, behind a parental gate. Until then the app generates no identifier of any kind, writes nothing to send, and makes no network request to us at all. It is not a switch that stops the sending: with it off, nothing is created in the first place.

What does the anonymous usage data contain, if I do switch it on?

A random install identifier generated on the device, the app version, the platform ("ios"), the OS version string, and a list of events. Each event is a name such as puzzle_complete, a timestamp, and a small bag of scalar values such as puzzle type, difficulty, level id, duration in milliseconds and hint count. That is the complete list.

Is my IP address recorded?

No. The analytics server is configured never to read or store one: proxy header trust is switched off so the framework cannot derive an address, the access log records only method, path, status and duration, and no database table has an address column. Even the rate limiter is keyed on the anonymous install identifier rather than on an address.

How do I turn the usage data off again?

One tap. Settings, then the "Share anonymous usage data" switch. Turning it on asks a grown-up question first; turning it off does not, because withdrawing consent has to be at least as easy as giving it. Switching it off also erases the install identifier and anything still queued on the device, so nothing is left behind waiting to be sent.

What is the problem report, and what is in it?

The app keeps a short list of error messages on the device — timestamps, the app version, error text and stack traces, and the names of a couple of events such as puzzle_start. It is capped, it overwrites itself, and it never leaves the phone or tablet on its own. If something goes wrong you can use Settings, then "Email a problem report", to send it to us; the app builds the report as plain text you can read in full before sending. It contains no identifiers, no names, no email addresses and nothing about what your child typed or solved. "Clear report data", next to it, throws the list away.

Do you sell or share data with anybody?

No. Nothing is sold, rented, brokered or shared for anyone else's purposes. The only third parties involved at all are Apple, which processes the purchase, and RevenueCat, which verifies the receipt on our behalf.

Does this website track me?

No. puzzeroo.app sets no cookies, runs no analytics, loads no fonts, scripts, images or stylesheets from any other server, and has no social buttons or embeds. There is no JavaScript on these pages at all.

Still unsure about something? support@puzzeroo.app. If you are a school or nursery that needs this on headed paper for a records-of-processing file, say so and we will send it.