Privacy
What we hold, and what we chose not to.
Updated August 30, 2026 · In effect from August 30, 2026
The short version
There is no email address or password on a Cantle account. We hold an anonymous ID, the display name you pick, your results, and your purchases. There is no advertising in the game and no third-party analytics in it either. Nothing we collect is used to track you across other apps or websites.
If you want it all deleted, the fastest way is Settings → Delete account & data, at the bottom of Settings in the app. If you cannot reach it, write to privacy@cantle.app with your friend code.
Who is responsible
- Controller
- ФОП Галас Юрій Володимирович (Halas Yurii Volodymyrovych, sole proprietor)
- Registered address
- Ukraine. The full registered address is published on the App Store and Google Play listings, which show it for every trader, and we will send it on request to privacy@cantle.app.
- Contact
- privacy@cantle.app
What we collect
| What | Specifically | Why | Kept |
|---|---|---|---|
| Account | An anonymous ID generated on your device, a friend code, the display name you choose, and a sign-in token | So your progress and purchases survive reinstalling the app | While the account exists. Deleted within 30 days of a deletion request |
| Avatar | The color, symbol and wallpaper you pick for yourself (a set of choices, not a picture you upload) | So other players see the mark you chose next to your name | While the account exists |
| Recovery code | A one-time code, issued only when you ask for one, that moves your account to another phone | Getting your account onto a new device | Until it is used, or a new one replaces it |
| Results | Which puzzle you played, how long you took, how many taps, and when you submitted | Leaderboards and your own history | While the account exists |
| Friends | Who you have added, and challenges between you | The friends feature | Until you remove the friend or delete your account |
| Purchases | What you are entitled to, and the store receipt that proves it | To give you what you paid for on every device | Three years, the minimum Ukrainian tax law sets for records of a sale |
| Device check | A one-way hash of a device identifier, sent only when a result goes to a leaderboard. On Android that identifier is the one the operating system gives the app; on iPhone it is a random value the app makes for itself. The server salts and hashes it on arrival and never keeps the original | So one person cannot take several places on the same board | 48 hours, then it is deleted whether or not you ask |
| Network address | The IP address your device connects from, which every server on the internet sees | Rate limiting, so the service cannot be flooded | Not stored: used for the request and dropped |
| Notifications | A push token and whether the device is iOS or Android, only if you turn notifications on | To send the notifications you asked for | Until you turn them off |
| Crash reports | The error, the stack trace, your platform and app version, and your anonymous ID | So a crash affecting many players is visible to us at all | 90 days |
| Reports | Display names other players report as abusive | Moderating the leaderboard | 12 months after the report is dealt with |
| Messages to us | Your address and whatever you wrote | To answer you | 12 months |
Your display name and your avatar are shown to other players on the daily leaderboard, and to anyone holding your friend code. Nothing else in that table is.
What we do not collect
This list is as much a part of the policy as the one above.
- No email address and no password: there is no such field on an account.
- No real name, phone number, postal address or date of birth.
- No location.
- No access to your contacts, photos or files.
- No advertising identifier. There is no advertising in the game.
- No third-party analytics, and no attribution or marketing SDK. None is built into the app.
Crash reports go to our own server rather than to a crash-reporting vendor, so that data stays on infrastructure you have already trusted with your scores.
Nothing we collect is used for tracking, in the sense Apple’s App Tracking Transparency framework defines it. We never link it to data from other companies for advertising, and we never sell it.
Legal basis
Where the GDPR applies:
- Contract: running your account, your results and your purchases.
- Legitimate interests: keeping the service up, fixing crashes, and stopping cheating and abuse.
- Legal obligation: tax and accounting records for purchases.
- Consent: push notifications, which you turn on yourself and can turn off at any time.
Who else sees it
We do not sell personal data and we do not share it for advertising. These are the companies that process some of it on our behalf:
| Who | For what | Where |
|---|---|---|
| Apple | Distributing the app, taking payment, validating receipts | US and worldwide |
| Distributing the app, taking payment, validating receipts | US and worldwide | |
| RevenueCat | Checking purchases with the stores and keeping entitlements in step | US |
| DigitalOcean | The server the game talks to | Frankfurt, Germany |
| Cloudflare | Traffic in front of that server, encrypted backups, and mail sent to the addresses on this site | EU and worldwide |
Where it lives
The game server and its database are in Frankfurt, Germany. Backups are encrypted and stored with Cloudflare.
Apple, Google and RevenueCat are in the United States, so purchase data reaches them there. Each relies on the safeguards set out in its own data protection terms: the EU–US Data Privacy Framework where the provider is certified under it, and the European Commission’s Standard Contractual Clauses otherwise or in addition. We do not restate those terms here, because a provider can change which mechanism it relies on without telling us; the version each publishes is the one that applies.
How long we keep it
Retention is given per category in the table above. When you ask us to delete your account we remove your ID, display name, avatar, friend code, any recovery code, results, friendships and notification token. The device-check hashes are not in that list because they are not attached to an account: nothing in them says whose device it was, and they are deleted 48 hours after they are written.
Records of a purchase stay. Tax law does not let a record of a sale be destroyed at the buyer’s request. They are kept for three years and are no longer attached to an account: there is no display name in them, no friend code, no results. Reports that have already been dealt with stay in the same stripped form. Otherwise deleting an account would erase the record of what it did, and the next one could start clean.
Security
Traffic between the app and the server is encrypted in transit. The server is firewalled to the ports it needs, access is restricted to keys we hold, and backups are encrypted.
We hold no payment details at any point: card numbers go to Apple and Google and never reach us.
Children
Cantle is not intended for anyone under 13. Where the law you live under sets a higher age for consenting to the processing of personal data, that higher age applies instead. We do not knowingly collect anything from a child below it. If we learn that an account belongs to one, we delete the account and everything tied to it. If you think a child in your care has an account, the quickest route is Settings → Delete account & data on their phone; otherwise write to privacy@cantle.app and we will remove it.
Your rights
Wherever you live, write to privacy@cantle.app to get a copy of your data, correct it, or have it deleted. Deletion is also a button in the app (Settings → Delete account & data, at the bottom), and that is the fastest route. Include your friend code, or we cannot tell which account is yours. That code says which account you mean; it does not prove the account is yours, because friend codes are made to be shared. Before deleting anything we may ask for something only the account holder would know, and if we cannot establish that, we will say no rather than destroy someone else’s account. We reply within one month, which is the period the GDPR allows. If a request turns out to be complicated we may need longer, and we will say so inside that month.
European Union, EEA and United Kingdom
The GDPR gives you rights of access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests. Where we rely on consent you can withdraw it at any time, which does not affect what was done beforehand.
You can also complain to your national supervisory authority. We have not appointed a representative in the Union under Article 27 of the GDPR. Send any request from the EU to privacy@cantle.app, and it is answered in the same time as any other.
The trader details required by the Digital Services Act appear on our App Store and Google Play listings.
United States
California. Under the CCPA as amended by the CPRA you may ask what we collect, ask us to delete it, ask us to correct it, and you will not be treated differently for asking. We do not sell or share personal information as the CCPA defines those words. There is no advertising in the game and no third-party analytics in it.
Other states. Virginia, Colorado, Connecticut, Utah and a growing list of others give comparable rights. We handle every such request the same way, whichever state you write from.
Children. Cantle is not directed to children under 13, and we do not knowingly collect personal information from them. If we find that we have, we delete it.
Ukraine
Personal data is processed in accordance with the Law of Ukraine “On Personal Data Protection”. You have the right to know who holds your data and why, to see it, to have inaccurate data corrected, and to have it deleted, and you may apply to the Ukrainian Parliament Commissioner for Human Rights.
Changes
If this policy changes we update the date at the top. For anything material we will say so in the app or by email before it takes effect.