Flow Puzzle

Privacy policy

Last updated: 11 August 2026

In short

Flow Puzzle is an offline game. It needs no account, asks for no name, email or phone number, does not touch your contacts, photos, microphone or device location, and shows no ads.

Your progress stays on the device. Only two things can leave the phone, and they are separate: usage statistics, off until you turn them on, and crash reports, on by default and switchable off at any moment. Both are anonymous.

Data kept on the device

Completed levels, stars, records, daily streak and preferences (theme, language, audio, accessibility) are stored in the app's local storage. They are sent nowhere, and they are erased by deleting the app or from Settings → Reset all progress.

Anonymous usage statistics (optional)

The app asks whether you want to contribute anonymous usage data on the second launch — not the first, where there would be nothing but the tutorial and a permission prompt on top of it. The default is off: do nothing and nothing is collected. You can change your mind at any time in Settings → Analytics.

If you turn it on, what is collected is product interaction: which modes get opened, which levels get finished or abandoned, how many moves it takes, when a hint is asked for, and which country the game is played from. It is there to show where the game is unfair rather than hard, and which language to translate it into next.

Crashes are not part of this setting: they are a separate channel, explained below.

Crash reports

When the app breaks, a technical report is sent: the kind of error, where in the code it happened, the app version and the device model. Nothing else — not what you were playing, not when, not who you are.

They are on by default, and they are the only thing on this page that starts without you switching it on. The reason is that a crash is only visible from the phone it happens on: asking permission from someone the app is closing on means never fixing it. You can turn them off whenever you like in Settings → Crash reports, and they stay off.

They are deliberately separate from usage statistics: declining statistics does not switch off crashes, and switching off crashes does not switch off statistics. Two different questions, two switches.

How both are handled

Events on both channels are attached to a random identifier generated on the device, not to you: there is no account, and we never call the functions that would tie that identifier to a person. We do not collect identity, do not join this data with any other source, and do not use it to track you across other apps or sites.

If you turn statistics on, the country is derived from the connection's IP address — the country and nothing else: never the city, and never the IP address itself, which is resolved and immediately discarded. It is there to show where the game is actually played, and therefore which language to translate it into next. Crash reports stay out of this too: they run by default, so they come from people who declined statistics, and deriving their country would be collecting sideways something that was not granted. Every crash is marked at source so that address is never resolved.

None of this is device location: the app does not ask for that permission and will not use it, and a country derived from an IP address is approximate by construction.

If you turn statistics on, the events on that channel are grouped by identifier. That is what makes it possible to ask questions a single event cannot answer — do people who finish the tutorial come back? at which level do they stop? — which without the grouping stay out of reach. It remains a random identifier: we do not know whose it is, and have no way of finding out. If you withdraw consent, the identifier is thrown away and the device generates a new one: turning statistics back on later does not stitch the two periods together.

Crash reports stay out of that grouping, deliberately: they are on by default, so they are sent even by people who declined statistics, and using them to build the same profile would be a sideways route to exactly what was refused. Every crash is marked at source so that it contributes to no profile.

The service used is PostHog, with data hosted in the European Union. PostHog acts as a data processor on our behalf.

Usage statistics rest on your consent, which you can withdraw at any time. Crash reports rest on the legitimate interest in keeping the app working and safe, which is why they start switched on; the toggle in Settings is the direct way to object.

Backing up your progress

In every case below, your progress stays between you and the maker of your operating system: it passes through no server of ours, we do not see it and we cannot reach it. The copy on the device is always the good one, and the game works identically with no backup at all.

On iPhone and iPad, iCloud (optional). If you switch syncing on in Settings, your game progress (completed levels, stars, records, daily history) is stored in the iCloud key-value store of your Apple account, so you find it again on your other devices. That processing is governed by Apple's privacy policy. It is off until you turn it on, and switching it off leaves your progress on the device.

On Android, Play Games saved games (optional). The same row in Settings stores your progress in Google Play Games Services saved games, tied to your Google account. That processing is governed by Google's privacy policy. It is off until you turn it on.

On Android, also the system's automatic backup. Independently of that row, Android includes the app's data in your Google account backup, which is what brings your progress across when you change phone. It is not a feature of the app and has no switch inside it: it is governed from Android Settings → System → Backup, and Google's policy applies there too.

Leaderboards and achievements

The game uses the game service of the platform it runs on, and the same thing is true on both: if the service is active, scores and achievements are sent to its operator to populate leaderboards and achievements, and that processing is governed by that operator's policy, not this one. Nothing comes back the other way: name, identifier and leaderboard position never return to our systems, for the simple reason that we have no systems.

On iPhone and iPad the service is Game Center (Apple's policy), which you can disable in the iOS settings. On Android it is Google Play Games Services (Google's policy), which you can disable from the Play Games app. Either way, with the service off the game is the same and leaderboards simply do not appear.

Notifications

The daily and weekly puzzle reminders are local notifications: they are scheduled on the device and pass through no server. They are off until you turn them on, and they go off again from Settings → Reminders or from your phone's system settings.

Children

Flow Puzzle is not directed at children under 13 and does not knowingly collect data about them.

Your rights

If you want the events sent from your phone — statistics or crash reports — deleted, write to us: all we need is roughly when you played, because the identifier attached to the events is random and we have no way at all of getting from you to it. To stop them right now, the two switches in Settings are enough — and switching statistics off throws the identifier away regardless. For everything else, the data is already only yours and already only on your phone.

Data controller: Flow Puzzle, independent developer, Italy. daveappsandgames@icloud.com

Changes

If this policy changes, the date at the top changes with it. Material changes will also be called out in the release notes on the App Store and on Google Play.

This policy is written in Italian. The other languages are translations provided for convenience: in case of any discrepancy, the Italian version prevails.