This Privacy Policy explains what information is handled when you play Chesshape ("the App"), a chess-move painting puzzle game published by its independent developer ("we", "us"). The short version: we do not ask for your name, e-mail or an account, and we do not run a server that stores your game or purchase records. Game and purchase- delivery records are handled locally; Google processes advertising data; and Apple App Store or Google Play processes payments, as described below.
The App keeps the following records in its private local storage:
The App does not store a full store receipt, payment-card details or store credentials. These local records are not visible to us. Depending on your OS, account and device settings, Apple or Google backup/device-transfer features may copy or restore them. Uninstalling normally removes the device copy, but does not guarantee deletion of a platform backup that may later restore it. The App does not read contacts, photos, files, precise location or other personal content.
If a Premium purchase remains unresolved or is interrupted, the App also keeps a local purchase-intent marker containing the product identifier, an app-generated attempt identifier and the purchase start time. It is used only to resume or reconcile that attempt with the store and is removed after a terminal result or when the 30-day reconciliation window expires.
The free version of the App shows ads served by Google AdMob. To serve and measure ads, Google may collect and process data on your device, including your device's Advertising ID and general device information (model, OS version, language), approximate (IP-based) location, and ad interaction data (impressions, clicks).
We do not receive or store any of this data ourselves; it is processed by Google under its own policies. Learn more at Google's Privacy Policy and How Google uses information from apps.
On iOS, Google UMP may show a consent message and, when applicable, Apple's App Tracking Transparency (ATT) request. Ad personalization follows your consent and device settings; IDFA is used only with ATT permission. You can keep playing if you decline. Google's publisher first-party identifier remains disabled. Available privacy choices can be reopened in Settings. On both platforms, Firebase Analytics access to the iOS vendor identifier or Android advertising ID, and Analytics ad-personalization signals, are disabled.
In-app purchases are processed by Apple App Store on iOS and Google Play on Android under their own terms and privacy policies. We do not receive your payment-card details or billing credentials. To deliver a product and restore Premium, the native billing SDK temporarily provides the App with a store receipt or purchase token, product identifier, purchase status, transaction date and reference. These values are not sent to a developer-operated server; the App retains only the compact one-way delivery fingerprint described in Section 1. Refund and revocation requests are handled by the store. This client-only release has no authoritative server-side reconciliation: the App may learn of a change only if the store later reports it and may not detect or revoke local Premium/content promptly or at all. Consumed hints cannot be reliably clawed back. The App stores only the local entitlement/balance and compact delivery marker described in Section 1.
Apple and Google process their store and payment data under their own privacy policies: Apple Privacy Policy and Google Privacy Policy.
For a new Android purchase, the app sends Google Play a one-way hash of a random value created for that checkout. This links the store response to the local pending purchase; it is not an account, advertising or installation identifier. Signed purchase information is checked on the device. No custom purchase verification server is operated.
In production releases, the App enables Firebase Analytics and Firebase Crashlytics after startup. Analytics processes gameplay and feature interactions such as level, puzzle, piece and product identifiers; moves, hints, undo/restart, ad and purchase/restore outcomes; counters and durations. Firebase may attach app-install or session identifiers and technical app/device context. Crashlytics processes crash reports, stack traces, app/OS/device diagnostics and may include recent Analytics events as troubleshooting breadcrumbs. This data is used for analytics and App functionality/reliability, not tracking or ad personalization. Collection remains off in debug builds. Events contain no account, name, e-mail or player-entered content, and there is no developer-operated user database.
The App is a general-audience puzzle game. We do not knowingly collect personal information from children. Where consent frameworks apply, ads are requested through Google's certified tools. If you believe a child has provided personal information through the App, contact us and we will help address it.
Depending on where you live (including the EU/EEA under GDPR, the UK, California under CCPA/CPRA, and Türkiye under KVKK), you may have rights to access, correct or delete personal data. Because we do not hold personal data ourselves, such requests usually concern data processed by Google — see Google My Ad Center and the links in Section 2. You can always contact us with any privacy question and we will do our best to help.
Local game and purchase-delivery records are protected by the operating system's application sandbox. They normally remain while the App is installed and may also be included in an OS backup or device transfer controlled by you and the platform. Removing the App usually removes its local copy; a platform backup may restore it later. We retain no copy on a developer-operated server.
If the App's data practices change (for example, if new data categories, accounts or online features are added), this page and its effective date will be updated before the change ships. Significant changes will also be noted in the App's store listing.