Legal document · mobile game
Privacy Policy — Kvant Puzzle
This document covers the Android mobile game, not the kvantcode.pl website.
Package com.kvantcode.kvantpuzzle
Version of 21 September 2026
1. Who is responsible
The data controller is Adrian Kopciński Soft-Craft, os. Kościuszkowskie 6/264, 31-858 Kraków, Poland.
adrian.kopcinski.softcraft@gmail.com
2. In short
- We create no accounts and never ask for your name, e-mail or phone number. We do not require you to sign in to Play Games — the game works fully without it. If you already have a Play Games account on your phone, however, sign-in happens automatically at start-up; section 5 explains this.
- Rewarded ads only — shown when you ask for a reward yourself. No in-app purchases.
- We do not sell your data. To serve ads we share your advertising ID with Google, based on your consent, which you can withdraw at any time in the game settings.
- Your game progress stays on your device. If you sign in to Play Games, your scores are additionally sent to a leaderboard run by Google — see section 5.
- We use Google tools that collect technical data about how the game runs.
3. Stored only on your device
This never leaves your phone and is removed when you uninstall the game:
- campaign progress and best level times,
- lives and undo credits,
- collected crystals,
- settings: sound, music, language, in-game prompt choices,
- a local player label (e.g. Player123), randomly generated on the device and not linked to any account,
- a local measurement file telemetry.csv which is never uploaded.
Leaderboards shown without signing in contain generated opponents. They are not real players and there is no server behind them.
The world leaderboard is the exception: once you sign in to Play Games, your scores are no longer local only and are sent to Google. Section 5 describes this.
4. What goes to Google
The game has no server of its own and sends nothing directly to us. It does include Google tools that send data to Google.
4.1. Firebase Analytics — how playable the game is
| What | Why |
|---|---|
| Gameplay events: level number, mode, completion time, moves, merges, chains, highest tier and backpack usage | To learn which levels are too hard and where players stop |
| App instance identifier (random, created at install) | To tell sessions of the same device apart |
| Device model, Android version, language, country (derived from IP address) | Device compatibility and which languages to add |
| Google Play install referrer | Where you came to the game from |
| Opening and closing the game | Session length — whether the game holds you past a single level |
| Your answer to the notification prompt (granted or declined) | How many players want notifications at all — otherwise we cannot tell whether asking makes sense |
Apart from the notification answer, events contain only data describing gameplay: numbers, the level number and the mode name (classic, time_attack, pro). They never include your player label or anything you type.
4.2. Firebase Crashlytics — crashes
When the game crashes, a report is sent: the stack trace, device model, OS version, memory state and a random installation identifier. It is used solely to fix bugs.
4.3. Google Play services
- In-app review — the rating dialog is shown by the Google Play Store itself. The game cannot see whether or how you rated it.
- TrustedTime — the game reads a trustworthy clock so that life regeneration cannot be cheated by changing the device time. No personal data is sent for this.
4.4. Google AdMob — rewarded ads
Ads are served by Google AdMob (Google Ireland Ltd) and are rewarded ads only: they appear when you ask for a reward yourself — an extra undo or an extra life. The game shows no interstitials and no banners.
| What | Why |
|---|---|
| Advertising ID (Android Advertising ID) | Ad selection and frequency capping |
| Device technical data and approximate location derived from the IP address | Matching ads to country and language, and counting impressions |
| Whether you watched the ad to the end | Granting the in-game reward and settlement with Google |
🔴 This is the only data we share rather than merely collect: Google uses the advertising ID on its own behalf, not solely on our instructions. The other tools in section 4 process data on our instructions and nothing from them is shared.
Choosing which ad you see is profiling within the meaning of the GDPR: Google makes that choice from the advertising ID and the technical data listed above. We make no automated decisions producing legal effects about you — the profiling decides only which ad is shown, and affects neither the game nor your rights.
The game also declares Android Privacy Sandbox permissions: ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION and ACCESS_ADSERVICES_TOPICS. The last of these gives Google's SDK access to the Topics API — broad interest categories computed by Android itself from the apps you use. The game neither sees nor stores those categories; they serve to select ads without the advertising ID. You can review and clear the list in your Android settings, under Privacy Sandbox.
Consent is collected in a dialog provided by Google (User Messaging Platform) — the first time you open a screen where an ad can earn you a reward, not at launch. No ad request is sent before it is given.
⚠️ Before that dialog can appear at all, Google's library (User Messaging Platform) asks Google's servers whether consent is required where you are and whether you have already given it. This happens every time the game starts, including before you consent. It is not an ad request — it only establishes whether, and what, we have to ask you.
How Google processes this data is described in the Google Privacy Policy and in Firebase privacy information.
5. Play Games sign-in and the world leaderboard
We neither require nor ask for a Play Games sign-in. Without signing in, nothing in this section happens — the game is fully playable and your scores stay on the device.
⚠️ If your phone already has a Play Games account, sign-in happens automatically when the game starts. We do not ask separately, because Play Games provides no such prompt inside a game. You make that choice at the level of your Google account, not in our game — the end of this section explains how to control it.
Once you sign in, the following data is involved:
| What | Why |
|---|---|
| Your Play Games player identifier (Player ID) | To tell which score is yours |
| The display name from your Play Games profile | To show who holds which position on the leaderboard |
| Level scores and leaderboard positions | To run the world leaderboard |
The world leaderboard publishes data. Your Play Games display name, avatar and score are visible to other players — a separate purpose and a separate category of recipients from everything in section 4. If you do not want to be visible, do not sign in — and if you already are, change your profile visibility or sign out in the Google Play Games app. There is no way to do it inside the game itself.
Google acts in a different role here than in section 4. With Firebase, Google processes data on our instructions and according to our settings. With Play Games, Google is a separate controller: it runs the player profile and the leaderboards on its own behalf and on its own terms, described in the Google Privacy Policy. We do not entrust this data to Google — it comes into being on Google's side.
We do not use Play Games data for advertising. The player identifier, display name, avatar and scores never reach any advertising tool and are not used to select or target ads. The Play Games Services Terms forbid it, and we treat that as a boundary in the code, not merely a statement in a document.
How to stop — and what we cannot do for you
- Sign out in the Google Play Games app — from that moment we submit no new scores there. ⚠️ The game has no sign-out button of its own: Play Games offers no such option inside a game, so it is done in the Google Play Games app or in your Google account settings.
- 🔴 We will not delete your Play Games profile data. The profile, name, avatar and score history belong to your Google account, not to us — we have no way to erase them and will not promise otherwise.
- They are removed with Google's own tools: in the Google Play Games app → More → Settings (delete game data or the whole Play Games profile) and in your Google account.
6. Notifications
The game may send notifications (for example, that your lives are back). They are created and scheduled locally on the device — there is no server behind them and no data is sent. You can withdraw permission in Android settings or in the game's settings.
7. Data security
The game has no server of its own, so security comes down to four things here — and we prefer to name them plainly:
- Transmission is encrypted. Everything the game sends to Google's servers travels over an encrypted (TLS) connection. The game sends no data over an unencrypted connection.
- On-device data sits in the app's private directory, which other apps cannot read. It is gone when you uninstall the game or clear its data.
- We run no database of our own. There is no data set on our side that could leak — we only ever look at the data in Google's consoles, as aggregate reports.
- Access to the Google consoles (Firebase, Google Play Console, AdMob) is limited to the controller named in section 1, and that account is protected by two-step verification.
No safeguard is absolute. If we learn of a breach that may put players' rights at risk, we will report it to the Polish supervisory authority and, where the risk is high, tell players inside the game as well.
8. Legal basis and purposes
| Purpose | Basis (GDPR) |
|---|---|
| Detecting and fixing crashes | Legitimate interest — Article 6(1)(f) (keeping the game working) |
| Measuring how the game is used and improving it | Legitimate interest — Article 6(1)(f) (developing our own product) |
| Play Games sign-in, the world leaderboard and showing your score to other players | Consent — Article 6(1)(a). We do not require signing in, and signing out in the Play Games app withdraws the consent, see section 5 |
| Serving and selecting rewarded ads | Consent — Article 6(1)(a). You can withdraw it at any time, see section 4.4 |
Providing data is neither a statutory nor a contractual requirement. Uninstalling the game ends analytics collection, and everything based on consent is optional and can be turned off without losing access to the gameplay.
9. How long we keep data
In Google Analytics we keep data tied to identifiers for:
| Type of data | Period |
|---|---|
| Event data (gameplay) | 14 months |
| User data (installation identifier) | 14 months |
The period for user data is rolling: it counts from your last activity, so as long as you keep playing, your installation identifier is kept. It is deleted after 14 months without opening the game.
Play Games leaderboard scores are kept by Google, as a separate controller and on its own terms. We set no period for them and cannot delete them for you — see sections 5 and 11.
Aggregate reports are built from aggregated data and contain no information about individual devices. Data stored on the device is removed when you uninstall the game.
10. Your rights
You have the right to access, rectify, erase and restrict processing of your data, and to object to processing based on legitimate interest. Where the basis is consent, you also have the right to data portability and to withdraw consent at any time — without affecting the lawfulness of processing carried out before. Write to the address in section 1 — we reply within one month.
You may also lodge a complaint with the Polish supervisory authority (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa).
The fastest way to stop all collection is to uninstall the game. Section 11. Data deletion on request describes the steps, and exactly what is deleted and what is kept.
11. Data deletion on request
Here is how to request deletion of the data collected by Kvant Puzzle (com.kvantcode.kvantpuzzle).
Step 1 — stop collection and erase on-device data
Uninstall the game. Everything described in section 3 — progress, settings and the local telemetry file — is removed from your device and nothing further is sent. This takes effect immediately and needs no contact with us.
If you want to keep playing but cut new data off from the old, go to Android Settings → Apps → Kvant Puzzle → Storage → Clear data. The game then receives a new random installation identifier, and events recorded from that point on are no longer linked to the earlier ones.
Step 2 — ask us to delete data from Google Analytics
Send an email:
Subject: Data deletion — Kvant Puzzle
In the message include: your device model, the approximate date you first opened the game and — if you have it — the installation identifier.
We reply within 30 days and tell you plainly what we were able to delete.
Step 3 — Play Games profile data (only if you signed in)
Sign out in the Google Play Games app (there is no such option inside the game itself) to stop new scores from being submitted. The Play Games profile itself — name, avatar and score history — is run by Google, so it is removed with Google's tools: in the Google Play Games app → More → Settings, or in your Google account. A request sent to us will not do it — we have no access to that data.
What we cannot do — stated plainly
We keep no accounts. Data in Google Analytics is tied only to a random installation identifier, which cannot be derived from a device model or an email address. Without that identifier we most likely cannot locate your installation — and we will tell you so rather than promise a deletion we will not perform. The outcome is then the one in the table below: the data expires on its own.
What is deleted, what is kept, and for how long
| Data | What happens to it |
|---|---|
| Progress, settings and the telemetry file on your device | Deleted immediately when you uninstall the game or clear its app data. We have no access to it — it never leaves the device. |
| Google Analytics events (gameplay) | Deleted within 30 days if you provide the installation identifier. Without it, they expire on their own after the period given in section 9. |
| Installation identifier (Analytics and Crashlytics) | As above. Uninstalling stops it from being renewed, so the full 14 months then count down to deletion. |
| Crash reports (Crashlytics) | Deleted together with the installation identifier, on the same terms. |
| Play Games profile: player identifier, name, avatar and leaderboard scores | Not deleted by us — this data belongs to your Google account. Remove it in the Google Play Games app (More → Settings) or in your Google account, as described in step 3. |
| Advertising data in Google AdMob | You can reset or switch off the advertising ID in Android settings (Settings → Google → Ads) — this works immediately and independently of us. Google's own retention periods are described in the Google Privacy Policy. |
| Aggregate reports and statistics | Kept indefinitely. They are built from aggregated data, contain no information about individual devices, and your data cannot be reconstructed from them. |
| Our correspondence with you about the request | Kept for 12 months as a record that the request was handled, then deleted. |
12. Children
The game is not directed at children. On Google Play we declare it for players aged 13 and over, and we do not knowingly collect data from anyone younger. If you believe a child has provided us with data, contact us and we will delete it.
⚠️ In Poland and some other European countries, you can only give consent to online data processing on your own from the age of 16. If you are between 13 and 15, consent to personalised ads — the one in the dialog we show at your first reward — should be given by your parent or guardian. Refusing blocks nothing: the game works in full, and ads are then non-personalised or absent altogether.
13. Transfers outside the EEA
Google also processes data on servers outside the European Economic Area, primarily in the United States.
Google LLC is certified under the EU-US Data Privacy Framework. By its decision of 10 July 2023 the European Commission found that this framework ensures a level of data protection equivalent to the European one, so a transfer to a certified recipient needs no further authorisation.
Where that framework does not reach — for example transfers to countries other than the United States — the basis is the European Commission's standard contractual clauses.
We provide a copy of these safeguards on request — write to the address in section 1.
14. Changes
Changes are published on this page with a new date at the top.
We will actively notify you of significant changes — a new purpose, a new category of recipients or a new legal basis — with a message inside the game the first time you open it after the update. We do not consider a changed date on this page, or asking you to check back regularly, to be enough.
Minor changes — wording fixes and clarifications that do not alter the scope or purpose of processing — are announced by publishing the new version alone.