İçeriğe geç
Cat & Seek

Privacy Policy

What Cat & Seek collects, why, who else sees it, and how to make it stop.

Son güncelleme:

Bu sayfa yalnızca İngilizce olarak sunulmaktadır.

Everything below describes Cat & Seek as it works today — each statement was checked against the code, not written from intent. Some features are finished but switched off; those are marked not active yet and are listed again in Not switched on yet. This page changes whenever the app does, and before anything new is switched on, not after.

Two versions of the app are in use. Version 1.0 shows no ads, asks for no tracking permission and sends nothing to Google’s ad or analytics services or to Tenjin. Version 1.1 adds ads and ad measurement. Where the two differ, this page says “from version 1.1”. You can see your version in the app’s Settings.

The short version

  • Cat & Seek is a single-player puzzle. There is no chat, no comments, no leaderboard and no way for another player to find you.
  • You can play without an account. Tap Explore as guest and no email, no name and no photo is ever asked for.
  • From version 1.1, the app shows ads from Google AdMob. A banner, a full-screen ad now and then between levels, and an ad you can choose to watch for XP.
  • Two companies measure the app and its ads: Google Analytics for Firebase and Tenjin. Where the law asks for your consent, they follow your answer.
  • Your advertising identifier is read only if you allow it. Apple’s tracking prompt appears after you solve your first level, never when the app opens.
  • Your move-by-move play record stays on our own server. Google Analytics gets four events about your play — a level started, a level finished, a streak extended, a share — and not your moves.
  • We use your data to run the game — save your progress, keep your streak, send the notifications you allow, fix crashes, and pay for the game with ads.
  • You can change your ad and tracking choices at any time — see Changing your mind. You can delete your account and what is attached to it — see Deleting your account.

Who we are

Cat & Seek is published by Uttapal Sangwan, trading as vickydarlinn, at Badhra, Haryana, India. That entity is the data controller for everything on this page. The iOS app’s bundle identifier is {BUNDLE_ID}.

Questions, requests, complaints: vickydarlinn@gmail.com.

What we collect

Your account

You can play as a guest, which needs no identity at all. If you choose to sign in, we use a social provider and never a password — there is no password field in the app, no password stored, and nothing to reset.

What Why we hold it
Email address, and whether the provider says it is verified To identify your account and keep it unique. We do not send you email — the server has no mail transport of any kind.
Your account identifier at Google or Apple This is the actual login key: we find or create your account by it. It is the only thing that proves who you are.
Display name Shown to you in your own profile. It comes from Google’s verified name, or from the name Apple hands over the one time you sign in.
Username (@handle) Optional. Empty until you choose one, and you can skip that step.
Profile photo address Only if you sign in with Google. Google hands over the web address of your Google profile picture along with your name and email, and we store that address with your sign-in record without asking — that happens on the first sign-in and again on every one after it. We never receive the Google image file itself, only the address it lives at. Apple sends no picture at all, and the app does not let you upload a photo of your own.
Guest identifier and a guest secret The whole credential for a guest account. The identifier is a random value the app makes up on first run — not a device identifier from your phone. The secret is stored only as a one-way hash.
A token from Apple that can revoke your sign-in Only if you sign in with Apple. Apple hands us a token that does exactly one thing: tell Apple to withdraw this app’s access to your Apple ID. We hold it so that deleting your account also removes this app from Settings → Apple ID → Sign in with Apple on your devices — Apple requires that of us, and without this token we could not do it. It is the only thing we store that can act on an account rather than merely name one, so it is the only thing we encrypt before storing it. It is never sent to your phone or to anyone but Apple, and it is spent and destroyed when your account is deleted.

If you sign in with Apple and use Hide My Email, the app recognises the relay address and will not use it to match you to any other account.

Sign-in with Apple and sign-in with Google are both live on iOS. Neither is required: the guest route sits beside them on the same screen, and every level is playable without ever making an account.

The app does not let you upload a photo of your own: there is no photo picker in it. The only picture address we hold is the one Google hands over when you sign in with Google.

Where you are, roughly

What Why we hold it
Your device’s time zone Sent each time you sign in, so a reminder arrives at a sensible hour where you are.
Country A two-letter country code, worked out from the time zone and nothing else.

Our server does not use your IP address to work out where you are, and the app collects no location of any kind — not precise, not approximate. Your phone’s region setting is received and then discarded. From version 1.1, Google does estimate a rough location from your IP address — see Who else receives data.

Signing in

What Why we hold it
IP address and browser/app user agent Written to the session record and to our server log at sign-in only, so a stolen session can be recognised.

This is the only place our server captures either value. There is no column for your IP address in our database and nothing logs your ordinary requests. The session record disappears on its own when the session expires.

Notifications

What Why we hold it
Push token The address Apple and Google use to deliver a notification to your phone.
Device name, device model, OS version, app version To send the right message to the right build, and to debug delivery. The device name is the name you typed on your phone, where the OS still gives it to apps — it is the most personal field in this record.
The messages themselves, and what happened to them The text sent to you, when it was pushed, whether your phone confirmed it, and whether it was shown, opened or dismissed.
Your notification settings Which categories you turned off, and any pause you set.
Which message led to a game If you open a notification and play within half an hour, that game is credited to that message, so we can tell whether a message was worth sending.

Read as a series, the notification log is the most revealing thing we hold. It is deleted in full when you delete your account.

Push is built but not active yet on iOS: the push library is not in the app, so no push token has ever been issued and no device record has ever been written.

Your play

What Why we hold it
Every cat you place and every wrong tap, per attempt The server, not the app, decides whether a level is solved and how many lives you have left. That is what stops a cleared level being faked — and it means we hold a move-by-move record of how you played.
Which levels you cleared, your best lives-used, hints used Progress, and unlocking the next level.
A calendar of the days you played, and how many games each day Your daily streak. Read as a series it is a day-by-day record of when you opened the app.
Your XP, and every change to it XP is earned by clearing levels and, from version 1.1, by watching an ad you chose to watch. It is spent on hints, so the balance has to be auditable. An ad reward is stored with a random claim number, so one ad cannot pay out twice.

The × marks you place while thinking are yours alone. They stay on your phone and are never sent to us.

Rewarded ads

From version 1.1, when you choose to watch an ad for XP:

What Why we hold it
Google’s confirmation that the ad was watched After the ad finishes, Google calls our server directly. We keep what it sends: Google’s transaction number, the ad unit, the reward, the time, the claim number and your account identifier. We use it to check that XP claims match ads that were really shown.

This record comes from Google’s servers, not from your phone, and it carries no IP address, device detail or advertising identifier.

Diagnostics

What Why we hold it
Screen size, pixel density, aspect ratio and safe-area insets Once per session, plus once per puzzle screen, to find out which screen shapes actually exist so the board fits them.
A fixed list of product events Seventeen named events — the app opening, a tutorial step, a settings change, an ad loading or being shown, a paywall being seen, a purchase being started. The app can only send events from that list; anything else is dropped. Each is stamped with your account, the app version and whether it was a test build.
Crash reports When the app crashes: the stack trace, device model, OS version, app version, the last few actions leading up to it, and your account identifier.

Crash reports are deliberately stripped before they leave your phone. They do not contain your IP address, email address, username, the device name you chose, any screenshot or picture of the screen, or any performance timing. A crash before you sign in, or after you sign out, carries no account identifier at all.

Two other identifiers can travel with a crash report, and neither is your account identifier or an advertising identifier:

  • A one-way hash on iPhone. Sentry’s library works it out from Apple’s vendor identifier for this app and your phone’s model, so that reports from the same phone can be grouped together. The vendor identifier itself is not sent.
  • A random installation identifier, only when the crash happens in the app’s native code, rather than in the game itself, before you sign in or after you sign out. Sentry’s library makes it up when the app is installed, and it disappears when you delete the app.

Crash reporting only runs in a build that was given a reporting key. In every other build it is completely silent. Version 1.0 of the app was not given one, so no crash report has ever left a phone running it. App Store builds are given one from version 1.1.

Purchases

If purchases are switched on, we record what the store tells us: the product bought, the change of state (started, renewed, cancelled, expired), when the current period ends, any XP granted, the amount charged and its currency, and the country of the store that charged it, and the store’s own receipt reference.

The amount is on the record because a price is set separately for each country’s store, so an amount without its currency and its territory would mean nothing at all. Three things it is not. It is not how you paid: we never see or store a card number, a bank detail or a billing address — payment happens inside the App Store and we are told only the outcome. It is not your device’s location; the store’s country is the territory that priced the sale, and we collect no location of any kind (see What we do not collect). And it is not a price we publish anywhere — there is no single price, so the app shows you the store’s own figure, in your own currency, before you confirm.

No purchase is possible in Cat & Seek today — the purchase system is built but has no store credentials, so nothing can be bought, restored or subscribed to and no purchase record has ever been written.

What we do not collect

Stated plainly, because “we may collect” language hides more than it says. Where a line has an exception, the exception is written next to it:

  • No advertising identifier unless you allow it. Apple’s advertising identifier (IDFA) is read only after you tap Allow on Apple’s tracking prompt, and only by Google’s ads and analytics libraries and Tenjin. Our own server never receives it. Android’s advertising ID is never read: there is no Android app.
  • No tracking prompt at launch. From version 1.1 the prompt appears once, after your first solved level. Version 1.0 has no prompt at all.
  • Apple’s vendor identifier (IDFV) is read by the crash reporter, which sends only a one-way hash of it (see Diagnostics). From version 1.1, Tenjin and Google’s libraries can read it too.
  • No location from your phone. The app never asks for location permission. Your country on our server comes from your time zone.
  • No access to your photos. The app has no photo picker, never asks for permission to your photo library, and never receives an image from your phone.
  • No password, anywhere.
  • No card, bank or payment details.
  • No contacts, calendar, health data, microphone, camera, motion or Bluetooth.
  • No free text from you beyond a display name and a username. There is no chat, no comments, no leaderboard and no search box.
  • No session recording, no screenshots, and no picture of your screen in crash reports.
  • No account identifier sent to Tenjin. Tenjin’s records are about a phone, not a Cat & Seek account.

Ads and measurement

This section describes version 1.1 and later. Version 1.0 shows no ads and sends nothing to the companies named here.

The ads

All ads come from Google AdMob. There are three kinds:

  • a banner at the bottom of the screen;
  • now and then, a full-screen ad when you leave a finished level. The app spaces these out, and a new account does not see one straight away;
  • an ad you choose to watch, which adds XP to your balance. Nothing makes you watch it.

We ask Google for ads rated suitable for a general audience.

When you first open the app, Google’s consent form may appear. Whether it does depends on where you are and on the privacy laws there. In the UK, the EEA and Switzerland it asks, among other things, whether information may be stored on and read from your phone, whether ads may be personalised, and whether ads may be measured.

The app applies your answers to all three companies:

  • If you refuse storing information on your phone, or measuring ads, Tenjin is switched off for you and receives nothing, and Google Analytics is told you do not consent to analytics. Ad storage follows the storing-information answer on its own: refuse that, and Google Analytics is told no to ad storage as well.
  • If you refuse personalised ads, Google shows ads that are not personalised to you, and Google Analytics is told not to use your data to personalise ads.
  • Until you have answered, Tenjin waits and sends nothing. Google Analytics waits briefly for your answer, then starts with analytics and ad storage treated as refused until you answer.

Where no consent form applies to you, Google Analytics and Tenjin run without asking. You can still switch tracking off, as described below.

If you live in the United States

Some US states give you the right to opt out of the “sale” or “sharing” of personal information, and of “targeted advertising”. Showing personalised ads and measuring ad campaigns can count as both.

Where Google’s form offers that choice to you, it is under Settings → Ad privacy in the app. When you opt out:

  • Google’s ads stop using your data to personalise ads;
  • Tenjin is switched off for you and receives nothing;
  • Google Analytics is told not to use your data for advertising. It still measures how the app itself is used.

Apple’s tracking prompt

After you solve your first level, iOS asks whether Cat & Seek may track you across other companies’ apps and websites. It is never asked when the app opens, and never in the middle of a level.

  • If you tap Allow, Google’s ads, Google Analytics and Tenjin can read your advertising identifier from then on.
  • If you tap Ask App Not to Track, none of them can read it. Ads still appear; they are less tailored to you.

Ad networks also use Apple’s SKAdNetwork. It tells an ad network that one of its ads led to an install, without naming you or your phone. Apple sends a copy of that message to Tenjin.

The tracking prompt and the consent form are separate. Your answer to one does not change the other.

Changing your mind

  • Settings → Ad privacy in the app reopens Google’s consent form. The row only appears where the form applies to you. A new answer takes effect for Tenjin and Google Analytics straight away.
  • iPhone Settings → Privacy & Security → Tracking turns tracking off for Cat & Seek, or for every app.

Changing your mind stops what happens next. It does not recall data already sent. To ask for that, see Deleting your account.

Who else receives data

We keep the list of companies short on purpose, and this is the whole list. It includes the two a page like this usually leaves off: the company whose machines our server runs on, and the crash reporter — which sits on the server as well as on your phone.

Company What reaches them Status
Our infrastructure host — Amazon Web Services, US East (N. Virginia) — us-east-1 Everything on this page that our server holds. Our server, our database and our cache run on their machines, so whatever we store is physically stored there. They are our processor and act on our instructions. Active
Google LLC If you sign in with Google, Google tells us your account identifier, email address, name and profile picture address. Active
Apple Inc. If you sign in with Apple, Apple tells us your account identifier and, once, your email and name. And when you delete your account, we send Apple’s own token back to it, to revoke your Sign in with Apple grant. Active
Google AdMob and its consent form (Google LLC) To choose and show ads: information about your phone and the app, including performance and crash data from the ads library; the IP address your phone connects from, and a rough location Google works out from it; how you interact with ads; and your consent choices. Your advertising identifier only if you tapped Allow. SKAdNetwork install messages. For an ad you choose to watch for XP, your account identifier and a random claim number, which Google sends back to our server to confirm the ad was watched. From version 1.1
Google Analytics for Firebase (Google LLC) Four events about your play — a level started and a level finished (with the level number), a streak extended (with its length), and the share button tapped — plus which screens you open, your account identifier, and whether the build is a test build. Google’s library also records on its own: the app being opened, sessions, the app version, device model, system version, language, a rough location from your IP address, and an app-instance identifier. Your advertising identifier only if you tapped Allow. Once Google’s ads are linked to it, the ads you were shown and what they earned. It follows your consent choices as described above. From version 1.1
Tenjin (Tenjin, Inc.) To work out which ad campaign brought you to the app: your phone’s vendor identifier for our app (IDFV), your advertising identifier only if you tapped Allow, basic device information, the IP address your phone connects from, and when the app is opened. Also what each ad shown to you earned: the ad unit, the amount, the currency and Google’s response number. Apple sends it a copy of each SKAdNetwork install message. Tenjin never receives your account identifier. From version 1.1, only in App Store builds, and only if your consent choices allow it
Google (Firebase Cloud Messaging) Your push token, and the text of each notification on its way to your phone. Built, not active yet on iOS
Cloudflare Nothing. Our server has code to store profile pictures in a Cloudflare bucket, but no bucket is configured and the app has no way to upload a picture. Not used
Sentry (Functional Software, Inc.) Two streams, not one. From your phone: crash reports, stripped as described above. From our server: the errors it runs into — the failure itself, the route it happened on, and the server’s own environment. We have not switched on the Sentry setting that would attach your IP address, your headers or the contents of your request. In the app, only in a build given a reporting key; on the server, only in production and only when a key is set

The database and the cache are ours; they run on the infrastructure named in the first row and nowhere else. Your move-by-move play record, your XP ledger and your progress stay there. Google Analytics receives only the four play events named in its row.

Google uses data from apps that show its ads under its own policies. Google explains how at policies.google.com/technologies/partner-sites.

The app also schedules local reminders using the operating system’s own notification scheduler. Those never leave your phone and no company receives anything from them.

Not switched on yet

Some things are worth naming because a reader who went looking would want to know where they stand. None of them receives any data:

  • GameAnalytics — removed from the app entirely. It is not in the build: no code, no library, nothing to start.
  • RevenueCat (purchases) — the library is linked, but it carries no credentials and is never started, so no purchase can happen and no webhook can fire. There is nothing to buy: the app is free.
  • Push notifications — as described in its section above.

If any of these is ever switched on, this policy changes before it happens, not after.

Children

Cat & Seek is not directed to children, and we do not knowingly collect personal data from anyone under 13. The app has no age screen and asks for no birthdate, so we have no way to identify a child by age.

From version 1.1 the ads are for a general audience: we ask Google for ads rated suitable for everyone, and we do not mark any player as a child. The app’s App Store age rating is 4+.

If you believe a child has created an account, write to vickydarlinn@gmail.com and we will delete it.

How long we keep things

We keep your account data for as long as your account exists. When you delete it, we delete it — the full list of what is removed, what is kept, and why, is on Deleting your account.

Two honest details that belong here rather than in the small print:

  • Sign-in session records expire on their own. They hold your IP address and user agent, they sit in a short-lived cache rather than the database, and they are cleared when you sign out or delete your account, and otherwise when the session runs out.
  • Purchase and subscription records are kept after deletion. They evidence money moving, they carry no name, email or other direct identifier, and we keep them where the law requires it or to prevent fraud and abuse.

Those two are not the whole story, and the deletion page names the rest rather than burying it. On our server, four things outlive a deletion: the purchase records above, a stub row that stops the account identifier ever being reissued, the session records in the paragraph before this one, and Google’s rewarded-ad confirmations with your account identifier removed. Outside our server, four companies keep what they received under their own retention rules: Sentry (crash reports), Google Analytics, Tenjin and Google AdMob. See Deleting your account.

Where your data is held

Our server, database and cache run at Amazon Web Services, US East (N. Virginia) — us-east-1. Crash reports go to Sentry. From version 1.1, ad and measurement data goes to Google and Tenjin. All three operate internationally. If you are in the UK, the EEA or Switzerland, this may mean your data is processed outside your country; where it is, we rely on the standard contractual clauses those providers offer.

Your rights

Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to another service. You can also complain to your data protection authority.

The quickest route to deletion is in the app, and Deleting your account walks through it. Your ad and tracking choices are in the app too — see Changing your mind. For anything else, write to vickydarlinn@gmail.com. We will not charge you for a request or make you sign in to something new to make one.

Where the law requires a legal basis:

  • we process your account, your progress and your session records to perform the contract of letting you play;
  • crash reports and the fixed event list rest on our legitimate interest in an app that works;
  • from version 1.1, showing ads that are not personalised, and checking that rewarded-ad claims are real, rest on our legitimate interest in paying for a free game and preventing fraud;
  • from version 1.1, storing and reading information on your phone for ads, personalised ads, and measurement by Google Analytics and Tenjin rest on your consent where the law requires it, given in Google’s consent form. Reading your advertising identifier also needs your permission in Apple’s tracking prompt;
  • notifications rest on your consent.

You can withdraw any consent at any time, in the app or in your phone’s settings.

Changes

If this policy changes in a way that affects you, we will change the date at the top of this page and, where the change is significant, tell you in the app. Continuing to play after a change means the updated policy applies.

Contact

vickydarlinn@gmail.com — the same address for support, privacy questions and deletion requests. It is one mailbox on purpose: three addresses would mean two nobody watches.