Privacy Policy
The short version
- No accounts and no login. We never ask for your name, email, phone, or contacts.
- Any display name and avatar you set stay on your device.
- Your answers and guesses never leave your device.
- We collect anonymous analytics events and crash reports to keep the game working. They’re tied to a random id, not to you, and there’s a single opt-out in Settings.
- If in-app ads are enabled, Google AdMob may use a resettable advertising ID. Ads are off at launch.
- We do not sell personal data.
1. Who we are
Topper10 is published by TEZZVO ([legal entity name and registered address]), the data controller. Privacy contact: privacy@tezzvo.com [confirm this is a monitored mailbox].
EU/EEA representative (GDPR Art. 27): [name/address, or “not applicable”]. Data Protection Officer: [contact, or “not appointed”].
2. What we collect, why, and the lawful basis
| Data | Purpose | Lawful basis (GDPR Art. 6) | Leaves device? |
|---|---|---|---|
| Anonymous analytics events — screen names, “daily completed”, hits count, hints used, streak length, share-card opened, session timing, app version, coarse device model / OS version, country derived from IP at ingest (IP not stored) | Understand retention and which features are used; find broken funnels | 6(1)(f) legitimate interests — running a free game with no PII; always-available opt-out | Yes — to PostHog |
| Crash & error reports — stack trace, screen, app/OS version, device model, non-PII breadcrumbs | Detect and fix crashes | 6(1)(f) legitimate interests — app stability | Yes — to Sentry |
| Anonymous installation id — a random 128-bit value generated on the device; not a hardware or ad ID; reset on data-clear or reinstall | Deduplicate analytics/crash data so counts are meaningful | 6(1)(f) legitimate interests | Yes — attached to the above |
| Advertising ID (only if ads are enabled — off at launch) — Android Advertising ID (GAID) | Serve and cap ads, measure performance, fraud prevention — handled by Google AdMob | 6(1)(a) consent where required (EEA/UK, via a Google consent prompt before the first ad) | Yes — to Google |
| On-device only — display name, emoji avatar, your answers/guesses, streak, coins, achievements, settings | Play the game and keep progress between sessions | 6(1)(b) performance of the service you asked for (local only) | No |
We do not collect your real name, email, phone, contacts, photos, precise location, calendar, microphone or camera input, health data, files, or the text of your answers.
Notifications. If you turn on the daily reminder, the app schedules a local notification on your device. No push tokens are sent to us and no server is involved.
Cloud backup (planned, not yet active). A future version may offer optional cloud save of your progress via Google Firebase, using anonymous authentication. This section will be updated with the specifics before that feature ships. [revisit when ADR 0018 backend goes live]
3. Children
The app is not directed to children under 13 (or the applicable age of digital consent in your country, up to 16 in parts of the EEA). We do not knowingly collect data from children. Target content rating: [“Everyone” — confirm via the Play questionnaire]. If you believe a child has provided us data, contact us and we will delete it.
4. Who we share data with
We do not sell personal data. We share it only with the processors below, each under a data-processing agreement (Google AdMob acts as an independent controller for ad serving).
| Recipient | Role | Data | Policy |
|---|---|---|---|
| PostHog | Product analytics processor | Anonymous events + installation id | posthog.com/privacy |
| Sentry | Crash / error reporting processor | Crash reports + installation id | sentry.io/privacy |
| Google AdMob (only if ads enabled) | Ad serving | Advertising ID, coarse location, ad-interaction data | policies.google.com/technologies/ads |
| Google Play | App distribution | Install/uninstall metrics; optional OS-level crash data | policies.google.com/privacy |
Processor regions: [PostHog EU Cloud and Sentry EU region are the intended defaults — confirm on account setup]. Where a processor operates outside the UK/EEA, transfers rely on the EU Standard Contractual Clauses (and the UK Addendum) or an adequacy decision. We may also disclose data if required by law.
5. Retention
- Anonymous analytics events (PostHog): [rolling ~14 months, then deleted/aggregated].
- Crash reports (Sentry): [~90 days — confirm plan retention].
- Advertising data (AdMob): per Google’s retention policy.
- On-device data: until you clear app data or uninstall — under your control, not ours.
- Support emails: [up to ~24 months after the matter is closed].
6. Your rights
Under the GDPR/UK GDPR (and comparable laws such as CCPA/CPRA and LGPD) you can request access, rectification, erasure, restriction, objection, and portability, and withdraw consent at any time.
- Stop collection / withdraw consent: open Settings → Privacy in the app and turn off analytics & crash reporting. This immediately suppresses all events and crash reports. To reset the anonymous id, clear app data or reinstall.
- Access / erasure / portability: email privacy@tezzvo.com and include the anonymous installation id shown in Settings → Privacy [id display is a pending in-app task]. We respond within one month (extendable by two months for complex requests).
- Ads: reset or delete your Advertising ID in Android Settings → Privacy → Ads.
- Complaint: you may complain to your supervisory authority — in the UK the ICO (ico.org.uk); in the EU your national DPA. [name the lead authority once the controller establishment is fixed]
Because analytics data is not linked to your identity, we may be unable to single out your records without the installation id (GDPR Art. 11).
7. Security
Data in transit to PostHog, Sentry and Google is encrypted with HTTPS/TLS. On-device data uses the platform’s app-private storage. No system is perfectly secure, but we keep third parties to a minimum and collect no PII.
8. Current status of data collection
As of the “last updated” date, the analytics and crash components are built but not yet activated in production — the SDKs are not in the build and no keys are set, so the app currently collects nothing off-device. This policy is written for the state after activation so it does not need to change at that moment. Ads are off.
9. Changes
We’ll update this page and the “last updated” date for material changes, and surface an in-app notice for significant ones.
10. Contact
privacy@tezzvo.com · [postal address]