Effective date: pending operator approval
Service: Pocket Puzzle Lab
Website: www.game.hao235.com
1. Information used by the app
Pocket Puzzle Lab can be played offline as a guest. The app stores a random local profile identifier, level progress, stars, best scores, Spark, Hint Tickets, Play Credits, daily counters, reward ledger records, language and settings on the device.
If a player chooses email or Google sign-in, the service processes an email address, optional display name, internal user ID, sign-in provider, account timestamps and expiring session credentials. Email passwords are stored only as scrypt hashes. Google passwords are never received. Signed-in players may upload a progress snapshot to restore progress on another device.
2. Optional analytics
First-party usage analytics is off until the player explicitly enables Anonymous usage statistics in Settings. When enabled, the app can send app starts, game starts, level completions, share-sheet openings, supported reward grants, sign-in provider and cloud-sync outcomes. The server stores an HMAC-SHA256 form of the random installation identifier, not the raw identifier. Events exclude names, email addresses, passwords, tokens, shared text and puzzle answers. Production events are retained for 90 days.
3. Advertising and Google services
A future release may use Google Mobile Ads for App Open and voluntary Rewarded ads, together with Google's User Messaging Platform where required. Google may process device identifiers, IP-derived approximate location, ad requests, impressions, interactions and diagnostics under its own policies. Advertising remains disabled until valid production identifiers and consent configuration are supplied.
4. Purpose
- Provide local game progress and settings.
- Create optional accounts and restore progress.
- Prevent duplicated rewards and protect account sessions.
- Measure product use only after the player opts in.
- Apply advertising choices and frequency limits when advertising is enabled.
5. Retention and deletion
Local app data remains until the player clears it, clears operating-system app storage, or uninstalls. A signed-in player can delete the account in the app or use the public account deletion page. Account deletion removes the account, sessions, pending email codes and cloud progress from the live database. Minimal pseudonymous deletion evidence is retained for security and audit purposes. Backup retention terms must be confirmed before public release.
6. Children
The app is not directed primarily to children. The operator will complete target-audience, content-rating, advertising and privacy disclosures using the final release configuration.
7. Security
Production traffic uses HTTPS. Account data is stored in an isolated transactional database with unique constraints, expiring and rotating session tokens, rate limits and administrative audit records. No system can guarantee absolute security.
8. Contact and changes
A monitored privacy and support email will be published here before the public store release. This policy will be updated when features, processors or legal requirements change.
9. Third-party policies
How Google uses information from sites or apps
Google Privacy Policy