This policy explains what information the Crossly iOS app collects, why, and what choices you have. It's written to be read, not just posted in an App Store field — if anything is unclear, email us and we'll fix the wording.
Crossly is developed and operated by Prateek Gaur, an individual developer ("we", "us"). For the purposes of the EU/UK General Data Protection Regulation (GDPR) and similar laws, we are the data controller for the information described below.
Contact for any privacy question or request: [email protected]
Crossly is a general-audience crossword puzzle game and is listed on the App Store as such. It is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
When you share the app or challenge a friend, Crossly builds a link that encodes your display name, a puzzle identifier, and your time — entirely on your device. That link is never sent to or stored on any server we operate; it is decoded directly on the recipient's device when opened. We have no record of who you challenged or who accepted.
| Service | Purpose | What it may collect |
|---|---|---|
| Google Firebase Analytics | Understand feature usage and app performance (screen views, puzzle completions, settings changes, ad and purchase-funnel interactions) | Pseudonymous analytics/app-instance identifiers, device model, OS version, coarse (region-level) location, app version, event data listed above |
| Google Firebase Crashlytics | Detect and diagnose crashes | Crash logs, stack traces, device model, OS version, app version |
| Google Firebase Remote Config | Deliver configuration values (feature toggles, ad settings) without a new app release | A pseudonymous app-instance identifier used to resolve the config; no content you type is sent |
| Google AdMob | Serve advertising that funds free access to Crossly | Your Advertising Identifier (IDFA) only if you grant tracking permission via Apple's App Tracking Transparency prompt; otherwise, device information and context used for non-personalized ads only |
| Apple StoreKit (only if/when a paid "remove ads" option is offered) | Process in-app purchases | Purchase and entitlement status; full payment details are handled by Apple and never reach us |
Each provider is bound by its own privacy policy for how it independently processes data: Firebase Privacy & Security, AdMob & user data, and Google's overall Privacy Policy.
On iOS 14.5 and later, Apple requires apps to ask your permission before accessing your device's Advertising Identifier (IDFA) for tracking. Crossly shows Apple's standard ATT prompt before any such access. If you decline, AdMob serves only non-personalized ads and does not access your IDFA. You can change this choice at any time in Settings → Privacy & Security → Tracking on your device.
Beyond the ATT control in §4, you can also:
Data stored locally on your device (progress, settings, install identifier) persists until you clear or reinstall the app. Analytics, crash, and advertising data are retained by Google per their own retention schedules, which we do not control.
We do not sell personal information. We share data only with the service providers listed in §3.4, to the extent necessary for them to provide analytics, crash reporting, and advertising services, or where required by law, to protect our legal rights, or to investigate fraud or abuse of the service. This is also reflected in the app's Apple App Store "Privacy Nutrition Label."
Our third-party providers (Google, Apple) operate global infrastructure, which means data may be processed in countries other than your own, including the United States. These providers maintain their own safeguards (including EU Standard Contractual Clauses where applicable) for such transfers.
You have the right to access, correct, delete, restrict, or port your personal data, and to object to its processing. Because Crossly stores gameplay data locally and keeps almost no data on our own servers, most of these rights are exercised simply by deleting the app's data or uninstalling it. For anything held by our analytics/advertising/crash providers, contact us and we will help route the request, and you may also lodge a complaint with your local data protection authority.
You have the right to know what personal information is collected, to request deletion, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. We do not sell personal information for money. To the extent ad personalization is considered "sharing" under CPRA, you can opt out using the tools in §4 and §6.
Regardless of where you live, you can always email us at [email protected] to ask what we hold about you or to request deletion, and we will respond within a reasonable time.
We rely on the security practices of the third-party providers listed above for data they process, and standard transport security (HTTPS/TLS) for data in transit. No method of transmission or storage is 100% secure, but we do not operate a server-side database of user records that could itself be breached.
We may update this policy as the app changes. We'll update the effective date above; material changes will be reflected here before they take effect, and this policy is also linked from the app's Settings screen so it's always one tap away.
Questions, requests, or concerns about this policy or your data: [email protected]