Privacy policy
Puzzeroo is used by children, so it is built to collect as close to nothing as a working app can. No accounts, no adverts, no third-party trackers, no personal data — and nothing at all is sent to us unless a grown-up switches it on. This page explains exactly what that means and what the few exceptions are.
Last updated: 27 July 2026. This policy covers the Puzzeroo iOS app and the puzzeroo.app website.
The short version. The app works entirely offline and stores your child's progress on their device. Out of the box it sends us nothing: anonymous usage data is switched off until a grown-up turns it on in Settings, and can be switched back off in one tap. If you buy the full unlock, Apple takes the payment and RevenueCat verifies the receipt. The app also keeps a short list of error messages on the device, so that you can email us a problem report if it misbehaves, and that list never leaves the device unless you choose to send it. That is the whole of it.
Who we are
Puzzeroo is an independent iOS app and this website, run by a single developer. For data protection purposes we are the data controller for the very limited information described below. You can reach us at any time at support@puzzeroo.app — a real address, read by a person.
Children's privacy
Puzzeroo is designed for children aged roughly five to twelve, and is built to satisfy the United States Children's Online Privacy Protection Act (COPPA), the UK Privacy and Electronic Communications Regulations (PECR) and the UK Information Commissioner's Age Appropriate Design Code. The design decisions that follow from that are not preferences; they are the reason the app is shaped the way it is.
- We do not knowingly collect personal information from anyone, of any age. There is no mechanism in the app by which a child could give us their name, email address, photograph, voice, location or contacts, because none of those fields, permissions or capabilities exist in the app.
- Nothing non-essential is on by default. Usage data collection starts switched off, as Standard 12 of the Children's Code requires, and only a grown-up who has passed the parental gate can switch it on. Nothing about it is nudged, pre-ticked or buried.
- There is no advertising. No ad SDK is present in the build. Nothing about a child is used for advertising, profiling, audience segmentation, retargeting or any other behavioural purpose, by us or by anyone else.
- There is no social element. No chat, no comments, no user-generated content, no friend lists, no leaderboards, no sharing to other services, no links out of the app to anywhere except this privacy policy and our support address.
- There are no nudges or dark patterns. No streaks, no daily-login rewards, no countdown timers, no push notifications, no "your friends are playing" prompts. Nothing in the app is designed to make a child feel they must come back.
- The purchase is behind a parental gate and behind Apple's own purchase confirmation, and there is exactly one thing to buy — a single permanent unlock, not a currency, not a subscription, not a loot box.
Because we collect no personal information from children, COPPA's verifiable parental consent requirement is not triggered, and the anonymous usage data described below would in any case fall within COPPA's carve-out for information used solely to support the internal operations of the service. UK law asks a different question, and we answer it separately: PECR regulation 6 governs storing information on the device at all, so the install identifier needs consent regardless of how anonymous it is. Hence the switch, and hence its being off to begin with.
What stays on the device
Everything that makes the app work is stored locally on the iPhone or iPad and never sent anywhere:
- Which levels have been completed, and progress within a level in progress.
- Settings such as the sound on/off preference, the helper mode, and whether usage data sharing is on.
- Whether the full unlock has been purchased.
- A short, self-overwriting list of error messages — see problem reports below.
None of this is backed up to a server by us. It travels with the device (and with your own iCloud device backup, if you have that switched on, which is between you and Apple). Deleting the app deletes it.
The anonymous usage data — off unless you switch it on
The app can send a small stream of anonymous events to a server we run ourselves, so that we can tell which puzzle types children actually play, where they give up, and whether the app is crashing. It is the only thing the app ever transmits to us, and it is switched off when you install it.
Off by default, and off means nothing exists. Until a grown-up turns the switch on, the app does not generate an install identifier, does not create a queue, writes no analytics data to the device and makes no request to our server. This is not a setting that suppresses sending — there is nothing to send. Turning the switch back off shuts the collection down and erases the identifier and anything queued, so opting in again later starts from scratch rather than resurrecting an old identifier.
How the switch works
- Where. Settings, under Privacy: Share anonymous usage data. The screen says what it collects, next to the switch rather than instead of it.
- Turning it on asks a grown-up question — a times-table sum a young child will not pass — because it is a decision about a child's data and should be made by an adult.
- Turning it off asks nothing at all and takes effect immediately. Withdrawing consent must be as easy as giving it, and a child who switches it off has, at worst, opted out of analytics.
- It is remembered on the device, and only on the device. We are never told what you chose, because if you chose "off" there is nothing that could tell us.
Exactly what is sent, once it is on
| Field | Example | Why |
|---|---|---|
| Install identifier | A random UUID generated on the device on first launch | So that fifty events from one iPad are not counted as fifty iPads. It is generated locally, is not derived from any device or account identifier, cannot be linked to a person, and is regenerated if the app is deleted and reinstalled. |
| App version | 1.4.2 | To tell whether a problem is fixed in a newer release. |
| Platform | ios | Constant today; present so the schema survives a future platform. |
| OS version | 18.2 | To know which iOS versions still need supporting. |
| Event name | puzzle_complete, hint_used, js_error | What happened. The complete list is ten names long and is published by the server at /v1/config. |
| Event timestamp | A millisecond clock value | To order events within a session and measure how long things take. |
| Event properties | puzzle type, difficulty, level id, duration in ms, hints used, completed/skipped; for errors, a message and stack trace | Small scalar values only. There is no free-text field a child could type into anywhere in the app. |
What is never collected
- IP addresses. The server is explicitly configured not to read them: trust in proxy headers is disabled so the framework cannot derive an address, the access log records only method, path, status code and duration, and no database table has an address column. Rate limiting is keyed on the anonymous install identifier rather than on an address, precisely so that the usual reason a service wants an address does not apply.
- Names, email addresses, postal addresses, phone numbers or any other contact details.
- Precise or coarse location, including country-level location inferred from an address.
- Advertising identifiers (IDFA), device fingerprints, or any cross-app or cross-site identifier.
- Photos, camera, microphone, contacts, calendars, health data or the device's file system.
- User agent strings and referrer headers.
As defence in depth, any free-text value that could conceivably reach the server — an error message, for instance — has email-shaped text and long digit runs redacted before it is stored, even though nothing in the app should be producing such text in the first place.
Who receives it, how long it is kept
The data goes to a server we operate, on hosting we rent in the United Kingdom, and to nowhere else. There is no third-party analytics provider, no data warehouse, no tag manager and no advertising platform involved at any point. Events are deleted automatically once they are 180 days old — the deletion runs when the server starts and once every day thereafter.
If the server is unreachable, or was never configured, gameplay is completely unaffected: the app is fire-and-forget and never waits for us.
Our lawful basis (UK and EU visitors)
Consent, given by a grown-up through the switch described above, and withdrawable at any moment through the same switch. We rely on it for both things it covers: storing the install identifier on the device (UK PECR regulation 6) and processing the events that identifier ties together, to the extent that any of it constitutes personal data under the UK or EU GDPR — which we do not believe it does, since the identifier is random, device-local and unlinkable to a person.
We deliberately do not rely on legitimate interests here. We could have argued it, and the argument would have been reasonably strong given how little the data contains, but PECR does not offer that route for storing an identifier on someone's device, and the ICO's Children's Code is plain that non-essential processing should not be switched on for a child by default. A consent switch that starts off is the answer to both.
Problem reports: what stays on the device until you send it
Analytics being off by default leaves a gap: when an app misbehaves on a child's iPad, a parent quite reasonably cannot describe what went wrong in technical terms, and we have nothing to look at. So the app keeps its own local record of errors — and only that.
- What is in it. A timestamp, the app version, the error message and a shortened stack trace, plus the names of a couple of ordinary events (a puzzle being opened, a puzzle being finished). Nothing else.
- What is not in it. No install identifier — none exists unless you switched analytics on, and it is not put in the report even then. No name, no email address, no location, no device identifier, nothing about which puzzle was open, nothing your child typed or solved. As a belt-and-braces measure, any email-shaped text or long run of digits that somehow reached an error message is blanked out before it is stored.
- How big it gets. It is a fixed-size ring: roughly the last hundred and fifty entries, capped at 64KB, oldest overwritten first. It cannot grow.
- Where it goes. Nowhere, on its own. It is not sent to us, not backed up to a server by us, and not copied into the device backup we mirror progress into. It sits in the app's own storage until it is overwritten, cleared, or the app is deleted.
If something does go wrong, Settings → For grown-ups → Email a problem report (behind the parental gate) turns that record into plain text you can read in full, and hands it to the iOS share sheet or to your email app. You choose whether to send it, to whom, and whether to delete anything first. Clear report data, next to it, empties the record immediately and needs no gate — throwing away a list of error messages cannot cost anybody anything.
We keep any report you do send for as long as it takes to fix the problem and no longer, and we will delete it sooner if you ask.
Purchases
Puzzeroo has one optional in-app purchase: a permanent unlock of the later levels. It is not a subscription and nothing renews.
- Apple takes the payment. We never see your card details, your billing address, or your Apple Account email. Apple's handling of the transaction is governed by Apple's own privacy policy.
- RevenueCat is the service we use to verify the App Store receipt and to remember that the unlock belongs to your Apple Account so it restores on your other devices. RevenueCat receives an anonymous app user identifier, the receipt data from Apple, and standard technical information about the request such as the platform, app version and the IP address the request came from — an ordinary consequence of making a network request, and something RevenueCat rather than we control. We do not send RevenueCat a name, an email address or any information about the child. RevenueCat's own policy is at revenuecat.com/privacy.
Purchases are also unlockable offline with a gift code, which involves no network request and no third party at all.
This website
puzzeroo.app sets no cookies, runs no analytics of any kind, and contains no JavaScript. Every font, image, stylesheet and PDF is served from this domain — nothing is loaded from a CDN, an advertising network, a font service or a social platform, so no other company learns that you visited. Downloading a worksheet requires no email address and creates no record beyond the ordinary web server log kept by our host for operational purposes.
The only links leaving this site are to Apple's App Store and to RevenueCat's privacy policy, both clearly labelled. Following them takes you to companies with their own privacy practices.
Security
All traffic to this site and to the analytics endpoint is encrypted in transit with HTTPS. The analytics service accepts only a strictly validated JSON payload, rejects anything oversized or malformed, and rate-limits per install identifier. The admin dashboard is password protected and fails closed if credentials are not configured. The honest summary of our security posture, though, is that the strongest control is the one at the top of this page: we do not hold data about anyone, so there is very little for anybody to steal.
Your rights
Under the UK GDPR, the EU GDPR and similar laws you have rights to access, correct, delete, restrict and object to the processing of your personal data, and to complain to a supervisory authority (in the UK, the Information Commissioner's Office).
There is an unavoidable honesty problem in exercising them here: because the usage data contains nothing that identifies you, we genuinely cannot find "your" records in order to show or delete them, and we will not ask you for identifying information in order to try — collecting personal data in the name of a privacy request would make things worse rather than better. Under Article 11 of the UK GDPR we are not required to acquire additional information solely to identify a data subject.
One right needs no request at all, because it is a switch rather than a letter: withdrawing consent. Settings, then Share anonymous usage data, off. It takes effect immediately, erases the identifier from the device, and nothing further is collected. That is the right most people actually want, and it should not require writing to anybody.
What we can do, and will do promptly on request:
- Answer any question about what the app sends, in as much detail as you want.
- Delete a specific install identifier's events if you send us that identifier.
- Delete a problem report you sent us, if you would rather we did not keep it.
- Confirm in writing what is and is not collected, for a school or a data protection officer who needs it on file.
Write to support@puzzeroo.app. We reply to everything, usually within two working days.
Changes to this policy
If this policy changes we will update the date at the top of the page. If a change ever meant the app started collecting something it does not collect today, we would say so plainly at the top of this page rather than quietly editing a paragraph in the middle.
Questions parents and schools ask
Does Puzzeroo collect personal information from children?
No. The app has no accounts, no sign-in, no name field, no email field, no birthday, no contacts access, no camera access, no microphone access, no location access and no advertising identifier. Nothing that leaves the device identifies a person, a household or a device.
Does Puzzeroo show adverts?
No, and there is no advertising SDK in the app at all. Nothing about a child is used for advertising, profiling, audience building or any form of behavioural targeting, by us or by anybody else.
Is anything collected by default?
No. Anonymous usage data is switched off when you install the app and stays off until a grown-up turns it on in Settings, behind a parental gate. Until then the app generates no identifier of any kind, writes nothing to send, and makes no network request to us at all. It is not a switch that stops the sending: with it off, nothing is created in the first place.
What does the anonymous usage data contain, if I do switch it on?
A random install identifier generated on the device, the app version, the platform ("ios"), the OS version string, and a list of events. Each event is a name such as puzzle_complete, a timestamp, and a small bag of scalar values such as puzzle type, difficulty, level id, duration in milliseconds and hint count. That is the complete list.
Is my IP address recorded?
No. The analytics server is configured never to read or store one: proxy header trust is switched off so the framework cannot derive an address, the access log records only method, path, status and duration, and no database table has an address column. Even the rate limiter is keyed on the anonymous install identifier rather than on an address.
How do I turn the usage data off again?
One tap. Settings, then the "Share anonymous usage data" switch. Turning it on asks a grown-up question first; turning it off does not, because withdrawing consent has to be at least as easy as giving it. Switching it off also erases the install identifier and anything still queued on the device, so nothing is left behind waiting to be sent.
What is the problem report, and what is in it?
The app keeps a short list of error messages on the device — timestamps, the app version, error text and stack traces, and the names of a couple of events such as puzzle_start. It is capped, it overwrites itself, and it never leaves the phone or tablet on its own. If something goes wrong you can use Settings, then "Email a problem report", to send it to us; the app builds the report as plain text you can read in full before sending. It contains no identifiers, no names, no email addresses and nothing about what your child typed or solved. "Clear report data", next to it, throws the list away.
Do you sell or share data with anybody?
No. Nothing is sold, rented, brokered or shared for anyone else's purposes. The only third parties involved at all are Apple, which processes the purchase, and RevenueCat, which verifies the receipt on our behalf.
Does this website track me?
No. puzzeroo.app sets no cookies, runs no analytics, loads no fonts, scripts, images or stylesheets from any other server, and has no social buttons or embeds. There is no JavaScript on these pages at all.
Still unsure about something? support@puzzeroo.app. If you are a school or nursery that needs this on headed paper for a records-of-processing file, say so and we will send it.