Gridora
Privacy Policy
Gridora is a mobile logic puzzle in which players satisfy number constraints to complete an ON/OFF pattern. This policy explains what information the App handles, how the Daily world ranking and advertising services work, and the choices available to users.
iOS 1.0(6) is the public-distribution build using the restrictions above. The earlier TestFlight 1.0(5) uses Google's official test ads and may use European consent-flow test settings. Installing through TestFlight alone does not select test ads. Test ads still communicate with Google servers and do not mean that no data is collected.
1. Operator and scope
App operator and data controller: JeongSeok Lee
This policy applies to the Gridora iOS and Android apps, their Daily ranking features, and this privacy policy page.
2. Information we handle
Daily ranking and anonymous account
When online features are enabled and a connection is available, Gridora creates a Supabase anonymous account or restores its locally saved authentication session at app startup. No separate sign-up screen, real name, or email address is required. We process a randomly assigned user identifier, your optional public nickname, puzzle ID, date, generator version, difficulty and seed, completion and ranking times, hint, undo and reset counts, and record creation or update timestamps. The public Daily leaderboard displays your nickname and submitted game record.
Reports, blocks, and account protection
If you report or block a leaderboard player, we process the requesting and target user identifiers, associated record, nickname at the time of reporting, selected reason, processing timestamps, and moderation actions. We also retain server-verified Gridora account origin and registration timestamps to prevent deletion of the wrong account. Reports and block lists are not themselves displayed on the public leaderboard.
Information stored on your device
Personal bests, Daily participation and streaks, tutorial completion, language, sound and haptic preferences, and an unsent Daily best may be stored in the App's local container. Authentication session tokens are also stored locally so the anonymous account can be restored.
Service connection information
Network providers such as Supabase may process IP addresses, request times, technical device, browser or app information, and server logs to secure the service, diagnose errors, and prevent abuse.
Advertising information in AdMob-enabled versions
The Google Mobile Ads SDK may process approximate location inferred from an IP address, an advertising identifier or another app- or developer-bounded device identifier, ad impressions and interactions, product interactions such as app launches, taps and video views, crash logs, and diagnostic or performance information such as launch time, hang rate and energy use. Actual processing varies with SDK version, device settings, region, and consent choices.
Gridora does not require a real name, email address, phone number, precise location, contacts, photos, camera access, or microphone access to play. Do not use a nickname containing personal information you do not want to make public.
3. How we use information
- Maintain anonymous sign-in and recognize the same ranking player
- Validate that players are comparing results for the same Daily puzzle
- Store personal-best Daily results and calculate and display world rankings
- Preserve game preferences and local progress
- Secure the service, diagnose errors, and prevent abuse
- Review inappropriate-nickname reports, apply personal blocks or moderation restrictions, and safely delete accounts
- In AdMob-enabled versions, serve and frequency-limit ads, measure performance, provide analytics, and prevent advertising fraud
The operator does not intentionally send the Supabase user ID or ranking nickname to Google AdMob, use that ranking data for cross-app advertising tracking, or sell personal information. The app disables ads personalization and applies child-directed ad treatment. This does not mean the advertising SDK performs no data collection or measurement. Google's advertising data processing may vary with region, device settings, and the restricted ad configuration.
4. Service providers and international processing
Gridora uses the providers below. They may process information using infrastructure in multiple countries under their own privacy terms.
Supabase, Inc.
Provides anonymous authentication and hosts profiles, Daily rankings, reports, blocks, and account-protection data.
Supabase Privacy PolicyGoogle LLC · AdMob / UMP
Provides advertising, measurement, and regional privacy-choice management in advertising-enabled versions.
How Google uses data from partner appsGoogle Privacy Policy
Specific processing locations and retention periods can vary with the selected service region, provider infrastructure, and legal obligations. The operator uses reasonable contractual and technical safeguards and HTTPS transport.
5. Advertising consent and choices
Gridora checks privacy status through Google's User Messaging Platform before initializing the advertising SDK. The normal ad configuration applies under-age-of-consent treatment to every user, so a European regulations consent message may be suppressed. Separate verification builds may disable this treatment to test the consent flow. iOS 1.0(6) requests ads only when UMP permits ad requests and offers a Privacy Options entry in Settings when UMP requires it. Earlier versions and Android use consent status and form availability. Availability and choices depend on region, SDK responses, and build settings.
- Ads are currently requested only as non-personalized or limited ads.
- Gridora does not request iOS IDFA, so the current build does not show an App Tracking Transparency prompt.
- Android advertising-ID permission is also removed, but Google Mobile Ads may process other app/developer-bounded identifiers and diagnostics.
- You can also manage Google ad personalization in Google Ad Settings.
6. Retention and deletion
- Local records and settings may remain until you clear the App's data or uninstall the App.
- Profile and Daily ranking records may be retained while needed to operate the service and rankings or until an eligible deletion request is completed.
- Report, block, and account-protection information supports those features and safe deletion checks, and is handled with account deletion as described below.
- Uninstalling the App clears its local container but does not automatically delete server ranking records stored by Supabase.
- Provider security logs, backups, and advertising data may be retained according to each provider's policy and legal obligations.
In the latest app, start deletion from Settings → Delete Anonymous Account. The server checks that the currently authenticated account was issued exclusively for Gridora and is not linked to or used by another service. When the checks pass, it deletes that anonymous authentication account and its Gridora profile, Daily records, and related report/block data. It does not delete another app's accounts or records.
After the server confirms success, the app displays completion and clears the local online credentials and queued uploads. Local game data such as personal bests, streaks, and preferences remains. The app does not automatically create a replacement account until you choose to reconnect online.
Accounts from earlier test versions whose origin cannot be verified, or accounts linked to another service, are not automatically deleted. The app reports that deletion did not complete and preserves the existing credentials. If a network problem leaves completion uncertain, the app does not report success and allows a retry. You may contact support below for help with an earlier account or lost access. Uninstalling the app alone does not delete the server account.
7. Your rights
Depending on applicable law, you may request access to, correction or deletion of, restriction of, or an objection to the processing of your personal information, or withdraw consent. We may request proportionate verification to protect your rights and other users' data.
Privacy, support, and deletion requests
Email: elvo27@gmail.com
Please include “Gridora” and a description of your request. Never send a password or authentication token by email.
8. Security
Gridora uses HTTPS for network requests and restricts record access using Supabase authentication and database row-level security. The operator does not provide ranking authentication tokens to advertising services. No storage or transmission method, however, can be guaranteed to be completely secure.
9. Children's privacy
Gridora is a logic puzzle suitable for a broad, all-ages audience. The operator does not intentionally ask children for their real name or contact information. Until a separately reviewed neutral age screen exists, every ad request is treated for children or users of unknown age. Guardians should advise children not to use an identifying nickname.
10. Changes to this policy
We will update this policy when the App's features, advertising SDK, service providers, legal requirements, or operating practices change. The latest revision date will appear at the top, and material changes may also be communicated through an app or store update where appropriate.