Effective date: August 24, 2026 (revised)
ZipFlow ("the App", "we", "us") is a single-line number path puzzle game. This policy explains what data the App collects and why. We take a simple position: the App never collects anything that could identify you personally.
ZipFlow has no account system, no sign-in, and no user profile. We do not collect, and the App has no capability to collect:
Your name, email address, or any contact information
Location data (beyond the coarse, non-precise region our ad and analytics providers infer from your IP address — see below)
Photos, contacts, microphone, or camera access
Any data that identifies you personally
The App uses Firebase Analytics (a Google service) to understand, in aggregate, how the game is played — for example, which board a session started and finished, how long it took, and whether Undo/Hint were used. This helps us balance difficulty and fix problems. These events are not tied to your name, email, or any personal identifier, and are governed by the Google Privacy Policy for how Google processes and retains this data on our behalf.
The same analytics also record when an ad was shown and what it earned — which ad network filled the slot, which ad unit and format it was, and the revenue our mediation partner attributes to that impression. This is how we know whether the ads pay for the App without having to make it cost anything. These records describe the ad slot, not you: they carry no advertising identifier and nothing that links them back to your device.
The App uses Firebase Crashlytics (a Google service) to find out when and why the App crashes or misbehaves, so we can fix it. When the App crashes, Crashlytics collects a crash report containing:
The crash stack trace (which lines of our own code failed)
Device model, manufacturer, OS version, orientation, and free storage/memory at the time of the crash
App version, and how long the App had been running
A randomly generated Crashlytics installation UUID, used only to count how many separate devices a given crash affects. It is not your advertising ID, it is not linked to any account, and it is reset when you reinstall the App.
Crash reports do not contain your name, email, contacts, location, puzzle content, or any personal identifier. Crashlytics is disabled entirely in our internal development builds, and is governed by the Firebase Crashlytics data collection terms and the Google Privacy Policy. Crash reports are retained by Google for a limited period (currently 90 days for individual reports) and then deleted.
The App shows ads, managed by Unity LevelPlay (Unity Technologies) — banner ads on the Home and Game screens, an occasional interstitial ad between Classic boards (never mid-puzzle), and optional rewarded video ads you choose to watch for an extra Hint. LevelPlay is a mediation service: it runs an auction between the ad networks below and hands the slot to whichever one bids highest. To do this, LevelPlay uses your device's advertising identifier and standard technical signals (device model, OS version, approximate IP-based region, ad interaction data). This is governed by Unity's Privacy Policy and Game Player and App User Privacy Policy — we do not receive or store this data ourselves.
The ad networks that compete to fill these slots are:
Unity Ads (Unity Technologies) — Banner, Interstitial, and Rewarded slots. Governed by Unity's Privacy Policy.
Liftoff Monetize (Liftoff Mobile, Inc., formerly Vungle) — Banner, Interstitial, and Rewarded slots. Governed by Liftoff's Privacy Policy.
InMobi (InMobi Pte Ltd.) — Banner, Interstitial, and Rewarded slots. Governed by InMobi's Privacy Policy.
Yandex Ads (Yandex) — Banner, Interstitial, and Rewarded slots. Governed by Yandex's Privacy Policy. The Yandex Ads SDK bundles Yandex's own AppMetrica component, which starts with the App and runs in AppMetrica's anonymous mode — it reports only to Yandex's own diagnostic keys about the SDK itself, and does not collect an advertising ID or build a profile of you. Unlike every other component listed here, it starts before the consent question below is answered, because it loads itself as part of Android's app startup rather than waiting to be called.
When one of these networks is chosen to serve an ad, it independently collects your device's advertising identifier, approximate IP-based location, and technical/diagnostic signals to select and measure that ad. We do not receive or store this data ourselves.
In regions where consent is required (the EEA, the UK, and Switzerland), the App asks you directly — in its own dialog, on first launch — before any ad SDK is started at all. Answering "No thanks" is free: you keep the entire game and simply see less relevant ads. Your answer is stored on your device and passed to LevelPlay, which forwards it to the ad networks above, and to Tenjin, which switches itself off completely if you decline.
You can change your answer at any time under Settings → Personalised ads inside the App. You can also reset or opt out of personalized advertising at any time in your device's own settings (Android: Settings → Google → Ads).
To remember your progress between sessions, the App also saves a small amount of data locally on your device, using Android's standard app storage (DataStore). This data never leaves your device and is never sent to us or to any third party:
Which Classic board you're currently on, and your lifetime Classic win count
Your Daily Challenge streak and completion history
Your light/dark theme preference
Whether you've completed the tutorial/first-time setup
Your remaining free-hint balance
The date you were last asked to rate the App (so we don't ask too often)
The last time an interstitial ad was shown (so we don't show them too often)
Your answer to the advertising-consent question, where it is asked (so we only ask once)
Uninstalling the App permanently deletes all of this data.
The App requests:
Vibration (VIBRATE) — used to provide haptic feedback (a short buzz) when you complete a move or hit a wall. Not classified as sensitive by Android.
Internet / network state — required by Firebase Analytics, Firebase Crashlytics, Unity LevelPlay and Tenjin to send the events and crash reports described above and to load ads.
Advertising ID — used by Unity LevelPlay and whichever network it selects (Unity Ads, Liftoff Monetize, InMobi, or Yandex Ads) to serve and measure ads, and by Tenjin to attribute installs (see "Advertising" and "Third-party services"). Reset or disable it any time in your device's own settings.
Firebase Analytics (Google) — see "Gameplay analytics" above.
Firebase Crashlytics (Google) — see "Crash and stability reporting" above.
Unity LevelPlay (Unity Technologies), including the Unity Ads (Unity Technologies), Liftoff Monetize (Liftoff Mobile, Inc.), InMobi (InMobi Pte Ltd.), and Yandex Ads (Yandex) networks it mediates — see "Advertising" above.
Tenjin (Tenjin Inc.) — measures which advertising campaign an install came from, and the ad revenue that install goes on to generate, so we know whether promoting the App is worth the cost. Tenjin receives your device's advertising identifier, the Google Play install referrer, and the ad impression data described under "Advertising" above. It never receives your gameplay, and it is switched off entirely for players who decline the advertising question. Governed by Tenjin's Privacy Policy.
Google Play In-App Review API — occasionally asks if you'd like to rate the App, using Google's own native review dialog. We never see whether you submitted a review or what you wrote — that interaction happens entirely between you and Google Play.
The Google-operated services above are governed by the Google Privacy Policy; Unity Ads is governed by Unity's own Privacy Policy; Liftoff Monetize is governed by Liftoff's own Privacy Policy; InMobi is governed by InMobi's own Privacy Policy; Yandex Ads and its bundled AppMetrica component are governed by Yandex's own Privacy Policy; Tenjin is governed by Tenjin's own Privacy Policy. Aside from these, the App does not integrate with any other third-party advertising or social platform.
The App is a general-audience puzzle game and is not directed at children, and shows standard (not child-directed) ads. If the App is ever submitted to Google Play's Designed for Families program, this policy — and its advertising configuration — will be revisited to meet that program's specific requirements first.
Your locally stored data is protected by your device's own operating system security. Data sent to Firebase Analytics and Firebase Crashlytics is transmitted (encrypted in transit) and stored under Google's own security practices — see the Google Privacy Policy linked above. Data sent to Unity LevelPlay, Unity Ads, Liftoff Monetize, InMobi, Yandex Ads, or Tenjin is transmitted and stored under that provider's own security practices — see the Unity, Liftoff, InMobi, Yandex and Tenjin privacy policies linked above.
If this policy changes — for example, if we add an account system or a new third-party service in the future — we will update this page and revise the effective date above before the change ships in an App update.
If you have questions about this policy, contact us at: carrotcreationsupport@gmail.com