TEZZVO / Privacy

Privacy Policy

Applies to: Topper10 (Android). Publisher: TEZZVO.
Effective date: [set on first submission] · Last updated: 3 September 2026

Draft. This policy is written and kept in sync with the app, but it has not had a legal review yet. TEZZVO will have a lawyer check it before the Google Play listing goes live.

The short version

1. Who we are

Topper10 is published by TEZZVO ([legal entity name and registered address]), the data controller. Privacy contact: privacy@tezzvo.com [confirm this is a monitored mailbox].

EU/EEA representative (GDPR Art. 27): [name/address, or “not applicable”]. Data Protection Officer: [contact, or “not appointed”].

2. What we collect, why, and the lawful basis

Data Purpose Lawful basis (GDPR Art. 6) Leaves device?
Anonymous analytics events — screen names, “daily completed”, hits count, hints used, streak length, share-card opened, session timing, app version, coarse device model / OS version, country derived from IP at ingest (IP not stored) Understand retention and which features are used; find broken funnels 6(1)(f) legitimate interests — running a free game with no PII; always-available opt-out Yes — to PostHog
Crash & error reports — stack trace, screen, app/OS version, device model, non-PII breadcrumbs Detect and fix crashes 6(1)(f) legitimate interests — app stability Yes — to Sentry
Anonymous installation id — a random 128-bit value generated on the device; not a hardware or ad ID; reset on data-clear or reinstall Deduplicate analytics/crash data so counts are meaningful 6(1)(f) legitimate interests Yes — attached to the above
Advertising ID (only if ads are enabled — off at launch) — Android Advertising ID (GAID) Serve and cap ads, measure performance, fraud prevention — handled by Google AdMob 6(1)(a) consent where required (EEA/UK, via a Google consent prompt before the first ad) Yes — to Google
On-device only — display name, emoji avatar, your answers/guesses, streak, coins, achievements, settings Play the game and keep progress between sessions 6(1)(b) performance of the service you asked for (local only) No

We do not collect your real name, email, phone, contacts, photos, precise location, calendar, microphone or camera input, health data, files, or the text of your answers.

Notifications. If you turn on the daily reminder, the app schedules a local notification on your device. No push tokens are sent to us and no server is involved.

Cloud backup (planned, not yet active). A future version may offer optional cloud save of your progress via Google Firebase, using anonymous authentication. This section will be updated with the specifics before that feature ships. [revisit when ADR 0018 backend goes live]

3. Children

The app is not directed to children under 13 (or the applicable age of digital consent in your country, up to 16 in parts of the EEA). We do not knowingly collect data from children. Target content rating: [“Everyone” — confirm via the Play questionnaire]. If you believe a child has provided us data, contact us and we will delete it.

4. Who we share data with

We do not sell personal data. We share it only with the processors below, each under a data-processing agreement (Google AdMob acts as an independent controller for ad serving).

RecipientRoleDataPolicy
PostHog Product analytics processor Anonymous events + installation id posthog.com/privacy
Sentry Crash / error reporting processor Crash reports + installation id sentry.io/privacy
Google AdMob (only if ads enabled) Ad serving Advertising ID, coarse location, ad-interaction data policies.google.com/technologies/ads
Google Play App distribution Install/uninstall metrics; optional OS-level crash data policies.google.com/privacy

Processor regions: [PostHog EU Cloud and Sentry EU region are the intended defaults — confirm on account setup]. Where a processor operates outside the UK/EEA, transfers rely on the EU Standard Contractual Clauses (and the UK Addendum) or an adequacy decision. We may also disclose data if required by law.

5. Retention

6. Your rights

Under the GDPR/UK GDPR (and comparable laws such as CCPA/CPRA and LGPD) you can request access, rectification, erasure, restriction, objection, and portability, and withdraw consent at any time.

Because analytics data is not linked to your identity, we may be unable to single out your records without the installation id (GDPR Art. 11).

7. Security

Data in transit to PostHog, Sentry and Google is encrypted with HTTPS/TLS. On-device data uses the platform’s app-private storage. No system is perfectly secure, but we keep third parties to a minimum and collect no PII.

8. Current status of data collection

As of the “last updated” date, the analytics and crash components are built but not yet activated in production — the SDKs are not in the build and no keys are set, so the app currently collects nothing off-device. This policy is written for the state after activation so it does not need to change at that moment. Ads are off.

9. Changes

We’ll update this page and the “last updated” date for material changes, and surface an in-app notice for significant ones.

10. Contact

privacy@tezzvo.com · [postal address]