Privacy

Privacy Policy

How Pocket Puzzle Lab uses local progress, optional accounts, advertising services and opt-in product analytics.

Pre-release draft: the legal operator name, monitored privacy email, mail provider, Google OAuth configuration and final advertising configuration must be confirmed before this page is used for a store submission.

Effective date: pending operator approval
Service: Pocket Puzzle Lab
Website: www.game.hao235.com

1. Information used by the app

Pocket Puzzle Lab can be played offline as a guest. The app stores a random local profile identifier, level progress, stars, best scores, Spark, Hint Tickets, Play Credits, daily counters, reward ledger records, language and settings on the device.

If a player chooses email or Google sign-in, the service processes an email address, optional display name, internal user ID, sign-in provider, account timestamps and expiring session credentials. Email passwords are stored only as scrypt hashes. Google passwords are never received. Signed-in players may upload a progress snapshot to restore progress on another device.

If a player voluntarily sends feedback, the service stores the selected category, report text, optional reply email, app version, build number, platform, language and any selected game or level. A signed-in report may be linked to the internal account ID. Guest and signed-in reports use an HMAC-SHA256 form of the random installation identifier to group duplicate reports; the raw identifier is not stored.

2. Optional analytics

First-party usage analytics is off until the player explicitly enables Anonymous usage statistics in Settings. When enabled, the app can send app starts, game starts, level completions, share-sheet openings, supported reward grants, sign-in provider and cloud-sync outcomes. The server stores an HMAC-SHA256 form of the random installation identifier, not the raw identifier. Events exclude names, email addresses, passwords, tokens, shared text and puzzle answers. Production events are retained for 90 days.

3. Advertising and Google services

A future release may use Google Mobile Ads for App Open and voluntary Rewarded ads, together with Google's User Messaging Platform where required. Google may process device identifiers, IP-derived approximate location, ad requests, impressions, interactions and diagnostics under its own policies. Advertising remains disabled until valid production identifiers and consent configuration are supplied.

4. Purpose

5. Retention and deletion

Local app data remains until the player clears it, clears operating-system app storage, or uninstalls. A signed-in player can delete the account in the app or use the public account deletion page. Account deletion removes the account, sessions, pending email codes and cloud progress from the live database. Existing feedback is detached from the deleted account so it can still be investigated. Resolved or closed feedback is automatically removed from the live database after 365 days. Minimal pseudonymous deletion evidence is retained for security and audit purposes. On-host backups are retained for 14 days.

6. Children

The app is not directed primarily to children. The operator will complete target-audience, content-rating, advertising and privacy disclosures using the final release configuration.

7. Security

Production traffic uses HTTPS. Account data is stored in an isolated transactional database with unique constraints, expiring and rotating session tokens, rate limits and administrative audit records. No system can guarantee absolute security.

8. Contact and changes

A monitored privacy and support email will be published here before the public store release. This policy will be updated when features, processors or legal requirements change.

9. Third-party policies

How Google uses information from sites or apps
Google Privacy Policy