Legal
Privacy Policy
Effective September 8, 2026
This policy explains what information Crystal Clues stores and sends when you play.
Summary
- No required personal loginCrystal Clues does not require a name, email address, password, or social login. Players may optionally choose a public leaderboard name.
- Global ScoresThe app creates an anonymous player identity and sends saved Campaign progress. Replay-verified play also sends bounded gameplay, restart, and app-integrity information.
- Optional paid creditsNew checkout can be enabled or disabled by a production service control; the installed app shows its current availability. Apple or Google handles payment details. Crystal Clues does not receive or store card or bank-account numbers.
- No precise locationCrystal Clues does not request location permission or precise location. When crash reporting is enabled, Sentry may derive coarse country or region from the network request even though storage of new raw IP addresses is disabled.
- No advertising or trackingCrystal Clues does not show ads, sell personal information, or use information for cross-app tracking.
Information Stored On Your Device
Crystal Clues may store saved campaign progress, current score and powerups, audio and motion settings, onboarding state, restart state, an anonymous authentication session, the current verified-run action history, pending Global Scores updates, RevenueCat purchase state, and the Letter Credit recovery key. Pending score updates remain in an on-device outbox until the service acknowledges the exact update, allowing a saved Campaign to synchronize after an interruption or temporary loss of connectivity. The recovery key is stored using operating-system secure storage.
Android cloud backup is disabled. On iOS, Keychain-backed secure values can persist after app removal and may be available again after reinstall; uninstalling is therefore not a reliable deletion method. Players should keep a private copy of the recovery key if they buy credits and use Delete All when they intend to delete the wallet link and local key.
Information Sent Off Your Device
For Global Scores and verified restart limits, Crystal Clues sends:
- A randomly generated anonymous user identifier and either a generated public alias or the optional leaderboard name entered by the player.
- For every saved Campaign: difficulty, a deterministic run identifier, current board, derived score, boards completed, run status, and a client update sequence. These values may be queued on the device and synchronized when connectivity returns.
- For replay-verified Campaigns: current attempt, bounded gameplay actions, powerups, board-completion state, and restart events used to derive and validate the score.
- Request nonces, idempotency identifiers, timestamps, and rate-limit events.
- Supabase session tokens and Firebase App Check tokens used to authenticate the anonymous player and verify app integrity.
The public leaderboard shows the chosen leaderboard name or generated alias, rank, score, Assisted status, difficulty, boards completed, run status, and update time. All Scores and the active-difficulty sections include both replay-verified Campaigns and device-synchronized Campaigns. A device-synchronized Campaign is always marked Assisted and is excluded from the Unassisted view; Assisted status appears as * beside the score. If the same Campaign later has replay-verified data, the service de-duplicates the two records. It uses a separate random public entry identifier and does not show the private authentication identifier.
Entered names are validated, checked for common unsafe or impersonating forms, length-limited, and rate-limited. Public names are governed by the overall Terms of Use without a separate in-app acceptance step. Players can report and hide public names; the service retains the report, name snapshot, reason, moderation status, and hide relationship while the anonymous accounts remain active.
Letter Credit Purchases And Recovery
For optional Letter Credit purchases and recovery, Crystal Clues sends or processes:
- A random wallet identifier used as the RevenueCat App User ID.
- App Store or Google Play/RevenueCat purchase transaction ID, product ID, purchase date, store, and test or sandbox status.
- Current credit balance, credit grants, credit spends, and whether a campaign used paid assistance.
- Purchase-event identifiers, event type, payload digest, reconciliation status, revocation reason, remaining credits attributed to each purchase, and whether a refunded purchase requires review.
- A recovery key sent over HTTPS when it is created or entered. The server retains only an HMAC digest of the key, not the readable key itself.
When checkout is available, paid Letter Credits can be purchased for Campaign play; existing balances, synchronization, and recovery can remain available while new checkout is disabled. Using one reveals one answer letter and permanently marks that campaign Assisted. Assisted campaigns remain ranked in Global Scores with * beside the score.
Crash Reporting
When crash reporting is enabled, Crystal Clues may send crash logs, stack traces, app version, operating system, device model, and runtime diagnostics to Sentry. Sentry may derive approximate country or region from the request; Crystal Clues does not request precise location or location permission, and Sentry storage of new raw IP addresses is disabled. Default personal-information collection, screenshots, and view-hierarchy capture are disabled. Known authorization, recovery-key, wallet, and purchase-identifier fields are redacted before upload.
How Information Is Used
Information is used to save and resume play, synchronize saved Campaigns, validate replay-verified scores, display and moderate Global Scores, process reports and player-specific hiding, deliver and recover paid Letter Credits, reconcile refunds, prevent duplicate purchase grants, mark assisted play, enforce restart rules with server time, prevent replay and automated abuse, diagnose failures, and improve reliability. Approximate region derived during crash processing is used only for diagnostics and service operation. Information is not used for targeted advertising.
Service Providers
- Supabase provides anonymous authentication, database storage, and Edge Function processing.
- Google Firebase provides App Check and platform app-integrity verification.
- Apple provides App Store purchase processing, StoreKit transaction status, App Attest, and DeviceCheck for iOS.
- Google Play processes Android purchases and payment details.
- RevenueCat processes in-app purchase status and transaction history.
- Sentry may provide crash reporting, diagnostics, and derived coarse-geography processing in production.
These providers process information to operate, secure, and support Crystal Clues. Their own legal terms and privacy practices also apply.
Retention
Most on-device data remains until Delete All, app deletion, or replacement by newer records. Pending Global Scores updates remain until acknowledged, superseded by a newer update for the same Campaign, or removed by Delete All. On iOS, the Keychain-backed Letter Credit recovery key may persist across uninstall/reinstall, so Delete All is the supported way to remove it together with the remote wallet link. Server gameplay, device-synchronized Campaign snapshots, report and hide, moderation, Letter Credit wallet records, and any legacy Global Scores acceptance record created by an older app release remain associated with the anonymous player until Delete All successfully deletes that player or the developer removes records for operational or legal reasons.
After deletion, Crystal Clues may retain a store transaction ID and basic transaction or revocation facts without a player or wallet link to prevent duplicate grants, reconcile refunds, prevent fraud, or meet legal obligations. Apple, Google Play, RevenueCat, and Sentry retain records according to their own policies and applicable requirements; these may include provider diagnostic or derived coarse-location records.
Deletion
Open Settings and choose Delete All. With an internet connection, Crystal Clues first deletes the anonymous server account and its leaderboard, run, restart, nonce, submission, rate-limit, legacy accepted-Terms, report and hide, moderation, Letter Credit balance, recovery digest, and player-linked purchase and spend records. It then deletes local campaign, score, restart, settings, onboarding, recovery key, and identity records.
Unused paid credits are permanently lost. Detached transaction facts may remain only for duplicate-grant prevention, refund or revocation processing, fraud prevention, or legal obligations. The app keeps a random internal deletion receipt so it can confirm deletion if the response was interrupted; it is not displayed to the player. After completion, the receipt retains no player identifier and expires through service cleanup.
If server deletion cannot be confirmed, the app keeps the local identity so the player can retry instead of orphaning remote data. Deleting the app cannot by itself request deletion of server records and, on iOS, may leave the Keychain-backed recovery key available to a later reinstall. Use Delete All for confirmed in-app/server deletion; a saved recovery key can recover unused credits on a new installation only while the wallet link still exists.
See Delete Crystal Clues Data or email crystalclues.support@gmail.com for help.
Children
Crystal Clues is a general-audience puzzle game. A player may optionally enter a public first name or nickname for Global Scores, but should not enter a full legal name or other private information. Crystal Clues does not provide profile biographies or chat. If you believe a leaderboard name or information relating to a child requires review or deletion, contact support.
Changes
If Crystal Clues changes its data practices, this policy and the store privacy disclosures will be updated.
Contact
Privacy questions can be sent to crystalclues.support@gmail.com.