Privacy Policy — Driftile
Effective date: 2026-08-12
Last updated: 2026-08-12
Published at: https://bakerly-apps.github.io/driftile-privacy/
Applies to: the Android application com.bakerly.driftile distributed on Google Play, and the web version of the same game.
This policy is written by Omar Diar Bakerly (trading as Bakerly Apps) ("we", "us"), Herwarthstraße 63, 47137 Duisburg, Germany.
Feature status
Some sections of this policy describe features that may not be switched on in the version of the app you have installed. Each section below is marked. A section marked NOT ACTIVE describes nothing that is happening today.
| Feature | Status in this version | Section |
|---|---|---|
| On-device saved progress | ACTIVE | 2 |
| Sharing your daily result | ACTIVE (only when you tap Share) | 3.1 |
| Android system backup | ACTIVE (controlled by your Google account settings) | 3.2 |
| Analytics | NOT ACTIVE — no analytics endpoint is configured and no analytics SDK is installed | 5 |
| Crash reporting | NOT ACTIVE — no crash reporter is installed | 6 |
| Advertising (Google AdMob, rewarded video) | NOT ACTIVE — no advertising SDK is installed | 7 |
| In-app purchases (Google Play Billing) | NOT ACTIVE — no billing SDK is installed | 8 |
| Daily reminder notification | NOT ACTIVE — no notification plugin is installed, and the app declares no notifications permission | 4 |
Maintenance note: re-publish this document at the same URL on the same day any conditional feature ships. A privacy policy that lags the build is itself a Google Play policy violation. The four conditional sections are written in advance precisely so that switching one on is an edit to one table row rather than a rewrite.
1. The short version
The game runs entirely on your device. It does not have accounts, does not ask who you are, and — in the version described by the ACTIVE rows above — does not send anything about you to us or to anyone else. Your progress is a small file on your phone. Deleting the app deletes it.
We do not sell personal data. We have never sold personal data.
2. What the app stores on your device
All of the following is written to your device's local storage by the app and stays there. It is not transmitted to us.
| What | Contains | Storage key |
|---|---|---|
| Campaign progress | Which levels you have completed, your best move count per level, stars earned, how many times you played each level, whether you solved it without undo, whether you solved it without a hint, whether you skipped it, the highest level unlocked, the level you last played | group:progress |
| Lifetime statistics | Totals only: moves made, undos, restarts, hints used, levels skipped, dead ends reached, time spent playing, and your average moves over the optimum | group:progress |
| Awards | Which of the 14 in-game awards you have earned | group:progress |
| Free daily hints | Today's date and how many of the day's three free hints you have used | group:progress |
| Appearance | Which board theme is applied, and which themes you own | group:progress |
| Levels you build or import | The levels themselves — board size, piece positions, walls, the name you gave them, and whether each is a draft or published | group:customLevels |
| Leaderboard name (conditional) | The name you chose to appear under, if you ever posted a score | group:progress |
| Daily puzzle results | For each date you have played: the date, your move count, the puzzle's optimal move count, plus your current and longest streak | group:progress |
| Unfinished level | If you close the app mid-puzzle: the level, where the pieces are, your move count, and your recent undo steps — so reopening puts you back where you were | group:progress |
| Hint balance | How many hints you have left | group:progress |
| Settings | Sound on/off, haptics on/off, motion preference, colour-shapes accessibility mode, chosen language, and whether you have opted in to sharing anonymous gameplay statistics — which is off unless you turn it on | group:settings |
| Purchases (conditional) | Which non-consumable products you own, so the game works offline | group:entitlements |
| Reminder (conditional) | The hour you chose for the daily reminder | group:notifications:dailyHour |
None of this identifies you. There is no username, no email address, no device identifier, no account, and no ID we assign to you. Two people with identical progress produce identical stored data.
The game also holds the last 50 gameplay events (for example "level started") in memory to power an internal debug view. This is never written to storage and is discarded when the app closes.
3. What leaves your device
In the version described by the ACTIVE rows above, the app makes no network requests of its own. It contains no analytics SDK, no advertising SDK, no crash reporter, and no server of ours to talk to. The whole game — every level, the solver, the daily puzzle generator — is contained in the app and runs offline.
The app requests the Android INTERNET permission. It is a standard part of the framework the app is built on and is reserved for the features in sections 5–8. Nothing in the current game uses it.
There are three exceptions where data can leave your device, and all three are initiated by you or by Google rather than by us.
3.1 The Share button
If you tap Share on a daily puzzle result, the app hands a short block of text to your device's system share sheet or clipboard:
Driftile #223
🟥🟥⬜🟦
🟥⬛⬜🟦
⬜⬜🟨🟦
6 moves — optimal
That is the entire contents. Where it goes next is decided by you — whichever app you pick receives it, and that app's own privacy policy applies from that point. We never see it and we do not log that you shared.
3.2 Android backup
Android may include the app's saved data in the automatic backup it makes to your own Google Drive, under your own Google account. This is a Google operating-system feature, not something we operate. We have no access to those backups and cannot read them.
You control this under Settings → Google → Backup on your device. Turning Android backup off stops it.
3.3 Level share codes
A level you build can be turned into a short code (42 characters for the largest board) that describes the puzzle itself — board size, where the pieces start, where the walls are. It contains nothing about you: not your name, not your device, not when you made it. The code is handed to your device's share sheet or clipboard only when you tap Share code, and where it goes next is your decision. We never see it.
3.4 Google Play itself
When you install or update from Google Play, Google records that installation against your Google account and may collect crash and performance data through the Play Store and Android itself. That is Google's processing under Google's Privacy Policy, not ours, and it happens for every app on the store. We receive only aggregated, anonymous statistics from Google Play Console — installation counts, country totals, crash-rate summaries and similar — which cannot be traced back to an individual by us.
4. Permissions
| Permission | Why | Can you refuse? |
|---|---|---|
INTERNET |
Required by the app framework; reserved for the features in sections 5–8 | Not a runtime prompt — Android grants it at install |
| Vibration | The gentle tick when a piece slides. Uses the standard web Vibration API and asks for nothing about you | Turn haptics off in Settings |
The app does not request location, camera, microphone, contacts, calendar, photos, files, storage, phone state, nearby devices, or notifications. It has no code that could use them.
5. Analytics — conditional
Status: NOT ACTIVE — no analytics endpoint is configured and no analytics SDK is installed. This section applies only when an analytics provider is switched on. At launch, the app ships with analytics disabled and no analytics SDK bundled.
If and when analytics is enabled, we would collect gameplay telemetry only, to find out which levels are too hard and where players stop playing.
What would be sent: the name of the event (for example level_completed), and, where relevant: the level identifier, the chapter, your move count, the puzzle's optimal move count, stars earned, how long the level took, how many times you restarted or undid, and — for settings changes — which setting you changed and its new value.
What would never be sent: your name, email, phone number, contacts, location, IP-derived precise location, the contents of any message, or any free text you type.
No identifier is attached — not even a random one. Analytics events carry no installation identifier, no device identifier, no advertising ID, no session identifier and no account. The only things sent alongside an event are the app version number and a timestamp. Two people who solve the same level in the same number of moves produce byte-for-byte identical events.
This is enforced in the code rather than promised in this document. The app maintains a fixed list of the properties an event may carry — level identifier, chapter, move count, optimal move count, stars, elapsed time, restart count, undo count, hint count, product identifier, ad placement, a short error code, and a settings name and value. Anything not on that list is discarded before transmission, and text values must match a short pattern of letters, digits and punctuation, so free text cannot be sent even by accident.
The practical consequence is that we cannot tell one player from another, cannot count how many distinct people play, and cannot link two events to the same person or device. That is deliberate, and section 10 explains what it means for deletion requests.
Your device's IP address is necessarily visible to the receiving server as a property of any internet connection, as it is for every website you visit. Nothing in the data we send is derived from it, and we do not store it against your events or use it to infer your location.
Provider: no analytics provider is used, acting as our processor. Legal basis (EEA/UK): consent, requested through the consent prompt described in section 7.4 before any analytics event is sent. Where consent is refused or withdrawn, no analytics events are sent. Retention: not applicable — no analytics data is collected.
6. Crash and error reporting — conditional
Status: NOT ACTIVE — no crash reporter is installed. This section applies only when a crash reporter is switched on. At launch, none is bundled.
If enabled, a crash report would contain: the error and its stack trace, the app version, the Android version, the device model, and a short context object naming the screen or operation that failed. Like analytics events, a crash report carries no identifier we assign to you — the app configures the reporter with personally-identifying data collection switched off, and with performance tracing and session replay disabled.
Crash reports are used to fix bugs and for nothing else. They are never used for advertising or profiling.
Provider: no crash reporting provider is used, acting as our processor. Legal basis (EEA/UK): our legitimate interest in keeping the app working (Art. 6(1)(f) GDPR), or consent where the provider's implementation requires it. Retention: not applicable — no crash data is collected.
7. Advertising — conditional
Status: NOT ACTIVE — no advertising SDK is installed. This section applies only when advertising is switched on. At launch, the app contains no advertising SDK and shows no ads.
7.1 What kind of ads
Only rewarded video, and only when you choose it — you tap a button offering a hint in exchange for watching a video. There are no interstitials, no banners, and no ad you did not ask for. Declining costs you nothing but the hint.
7.2 Who serves them
Google AdMob, and the advertising networks that bid through it. AdMob is operated by Google and its own handling of your data is governed by Google's Privacy Policy and How Google uses information from sites or apps that use our services. A list of the ad partners that may receive data is maintained by Google at https://support.google.com/admob/answer/9012903.
7.3 The advertising ID
To show an ad, the AdMob SDK reads your device's Android Advertising ID (AAID) — a resettable identifier that Android provides specifically for advertising. It may also collect your approximate location (derived from your IP address, at roughly city level), your device model and OS version, and information about how you interacted with the ad.
The advertising ID is not your name and is under your control:
- Reset it: Settings → Google → Ads → Reset advertising ID
- Delete it entirely: Settings → Google → Ads → Delete advertising ID. Android then returns a string of zeros to every app, and ads become non-personalised.
- Opt out of personalisation: Settings → Google → Ads → Opt out of Ads Personalisation
When advertising is enabled, the app declares the AD_ID permission, as Google requires of any app that reads this identifier.
7.4 Consent in the EEA, UK and Switzerland
If you are in the European Economic Area, the United Kingdom or Switzerland, the app shows a consent form the first time it launches, built with Google's User Messaging Platform (UMP) and operating under the IAB Transparency & Consent Framework. It asks separately about personalised advertising and about the other purposes your data may be used for.
- No ad request is made, and no analytics event is sent, before you answer.
- If you decline personalisation you still get ads, and they still pay out the hint; they are simply chosen without profiling you.
- You can change your answer at any time from Settings → Privacy options, which reopens the same form.
Outside those regions the app follows the applicable local rules — including, for residents of US states with such laws, the right to opt out of "sale" or "sharing" of personal information for cross-context behavioural advertising. Use the same Settings → Privacy options control, or contact us at support.bakerly.apps@gmail.com.
7.5 What we get
We do not receive your advertising ID. Our own view of advertising is the aggregate revenue and impression reporting Google gives us in the AdMob console.
8. Purchases — conditional
Status: NOT ACTIVE — no billing SDK is installed. This section applies only when in-app purchases are switched on. At launch there is nothing to buy.
Purchases are processed entirely by Google Play Billing. Payment happens inside Google's own interface.
We never see your payment details. We do not receive, store, or have any way to obtain your card number, bank details, billing address, or full name. Google is the merchant of record.
What the app receives from Google is a purchase token confirming that a specific product was bought and is still valid, so it can unlock what you paid for. The app stores the resulting entitlement (for example, "ads removed") on your device so it survives a restart.
Your purchase history, refunds and subscription controls live in your Google Play account: https://play.google.com/store/account. Refunds are handled under Google Play's refund policy.
Restore purchases re-queries Google Play for what your Google account already owns. It does not create any record with us.
9. Children
The game contains no violence, no chat, no user-generated content, no social features, and no external links other than those in this policy. It is suitable for all ages by content.
However, it is not directed to children within the meaning of COPPA, the GDPR's rules on children's data, or Google Play's Families policy, and it is not enrolled in Google Play's Designed for Families programme. We do not knowingly collect personal information from anyone under 13.
This matters for one practical reason: once advertising (section 7) is switched on, the app uses standard advertising infrastructure that is not permitted in apps aimed at children. If you are a parent and your child uses this app, consider deleting the device's advertising ID (section 7.3), which turns off ad personalisation across every app on the device.
If you believe a child has provided personal information to us, contact support.bakerly.apps@gmail.com and we will delete it.
10. Retention and deletion
| Data | Where it lives | How long | How to delete it |
|---|---|---|---|
| Progress and settings | Your device | Until you delete it | Uninstall the app, or Settings → Apps → Driftile → Storage → Clear data |
| Android backup copy | Your Google Drive | Per Google's backup retention (a backup is deleted after the device has been inactive for a period set by Google, and when you delete it manually) | Settings → Google → Backup, or Drive → Backups |
| Analytics events (conditional) | no analytics provider is used | not applicable — no analytics data is collected | Not individually deletable — see below. Stop future events by turning analytics off in Settings, or by withdrawing consent |
| Crash reports (conditional) | no crash reporting provider is used | not applicable — no crash data is collected | As above |
| Advertising data (conditional) | Google and its ad partners | Per Google's policies | Delete or reset your advertising ID (section 7.3) |
| Purchase records (conditional) | Per Google's policies and applicable tax law | Via your Google Play account |
There is no account to delete, because there is no account. Uninstalling the app removes everything held on your device.
Why we cannot delete individual analytics or crash records
Because those records carry no identifier of any kind (section 5), there is nothing in them that points back to you, and nothing we could match a deletion request against. We are not withholding a lookup — the lookup does not exist. If you emailed us asking us to delete your events, we would have no honest way to find them, and we will not ask you for extra personal information in order to try, because collecting identifying data to service a privacy request would make the situation worse rather than better.
What you can actually do, and what it achieves:
- Withdraw consent via Settings → Privacy options (section 7.4). No analytics event is sent while consent is refused or withdrawn, and anything already queued on your device is discarded rather than sent later.
- Uninstall the app. Everything on your device goes with it, and nothing further is ever sent.
- Records already received are deleted by our provider at the end of the retention period stated above, without any action from you.
Maintenance note (delete this block before publishing): the two controls referenced above — the in-app consent/analytics toggle in Settings → Privacy options (also promised in §7.4 and §11) — do not exist in the UI yet. The service layer supports them (
setAnalyticsEnabled,requestConsent), but nothing calls them. They must be wired into the Settings sheet before analytics or ads are switched to ACTIVE, or this policy describes a control the app does not have.
If a future version ever does attach an identifier — or introduce an account — this policy will be updated before that version ships, and both an in-app and a web deletion route will be provided, as Google Play requires.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict processing, to withdraw consent, and to complain to a data protection authority.
In the ACTIVE configuration these rights have little to bite on: we hold nothing about you.
Where sections 5–8 are active, the honest position is the one set out in section 10: analytics and crash records carry no identifier, so we hold no personal data about you to access, correct, export or delete, and no way to connect any record to you even if you asked us to. A subject access request will be answered truthfully — that we hold nothing identifiable — rather than with a file we cannot actually produce. The rights that do have practical effect are the right to withdraw consent (Settings → Privacy options, section 7.4) and, for advertising, the controls Google provides over your advertising ID (section 7.3).
For anything else, email support.bakerly.apps@gmail.com. We respond within 30 days. We will not ask you for identifying information in order to service a privacy request.
EEA/UK residents may complain to their national supervisory authority; a list is at https://edpb.europa.eu/about-edpb/about-edpb/members_en. We are established in Germany, within the EU, so no Article 27 representative is required. There is no statutory obligation to appoint a Data Protection Officer for processing of this scale.
12. International transfers
Data described in the ACTIVE sections does not leave your device, so no transfer occurs.
Where sections 5–8 are active, our providers may process data in the United States and other countries. Those transfers rely on the European Commission's standard contractual clauses or an applicable adequacy decision, as set out in each provider's terms.
13. Security
On-device data is stored in the app's private storage area, which Android isolates from other apps. Where the conditional sections are active, all traffic to our providers is encrypted in transit with TLS.
No system is perfectly secure. Given that the app holds no personal data, the realistic worst case is that someone with physical access to your unlocked phone learns which puzzle levels you have solved.
14. Changes to this policy
We will update this page when the app changes, and update the Last updated date. Material changes — in particular switching on any of sections 5 through 8 — will be announced in the app before they take effect, and where consent is required we will ask again rather than assume.
Previous versions are available on request.
15. Contact
Omar Diar Bakerly (trading as Bakerly Apps)
Herwarthstraße 63, 47137 Duisburg
Germany
Email: support.bakerly.apps@gmail.com
For anything privacy-related, email is the fastest route and reaches a person.
16. Provider identification / Anbieterkennzeichnung (Impressum)
Angaben gemäß § 5 DDG (Digitale-Dienste-Gesetz):
Omar Diar Bakerly (trading as Bakerly Apps)
Herwarthstraße 63, 47137 Duisburg
Germany
E-Mail: support.bakerly.apps@gmail.com
Verantwortlich für den Inhalt: Omar Diar Bakerly (trading as Bakerly Apps), Anschrift wie oben.
Responsible provider of this app and of this page: the person and address named above. This is the German statutory provider identification and repeats the contact details already given in section 15.
EU-Streitschlichtung: Die Europäische Kommission stellt eine Plattform zur Online-Streitbeilegung bereit: ec.europa.eu/consumers/odr. Wir sind nicht verpflichtet und nicht bereit, an Streitbeilegungsverfahren vor einer Verbraucherschlichtungsstelle teilzunehmen.