In short
- Tsukiniwa doesn't ask for a name, email, or account — you're identified only by a random ID generated on your device.
- We store only what the leaderboards and player cards need, plus a private backup of your progress so reinstalling the app gets it back: your device ID, chosen board name, daily solves, the streak, badges and totals shown on your player card, and that backup.
- Ads run through Google AdMob: optional rewarded videos only, for an extra hint or a second chance at the mistake limit. There are no banner ads. In the EEA, the UK and Switzerland, Google's consent form asks for your choices before any ad is requested. Tsukiniwa doesn't run its own analytics or crash-tracking SDK; AdMob's SDK does some of that incidentally as part of serving ads, and on Android it reads your device's advertising ID — see Ads below.
- Daily reminders, if you turn them on, are scheduled entirely on your device — no server ever knows whether you've enabled them.
- If you buy Tsukiniwa Supporter, Apple or Google handles your payment directly — we only ever see whether the purchase succeeded.
What we collect
Tsukiniwa has no sign-up. The first time it runs, it generates a random device ID and stores it on your device. On iPhone a copy also goes in the Keychain, which keeps it when the app is deleted, so reinstalling brings back the same player. That ID — not you by name — is what the leaderboards are built on. Solves are sent only for the daily board, never for lessons or library boards.
| Data | What it is | Why we collect it |
|---|---|---|
| device_id | A random identifier generated on-device (not your Apple/Google advertising ID). It stays private: only your phone sends it, and no leaderboard or player card shows it | Ties your solves and leaderboard rows together across sessions, and proves a solve or a name change comes from your phone |
| public_id | A second random identifier, made by our server, that has nothing to do with your device ID | Lets the leaderboards and your player card point at you without revealing your device ID |
| display_name | An auto-assigned name like “Player4821,” editable by you, shown publicly on the leaderboards. A name you choose is yours alone: no other player can take it | So other players can tell rows apart |
| daily submissions | Your solved board (the picture, as its tile colours), the time you took, and your mistake and hint counts for that day’s daily — and a start time, stamped by our server when you first paint a daily | Checks that a solve is genuine, checks the time you claim against the time since you started, and ranks it on Today’s board |
| garden days | Which dates you’ve solved a daily on | Counts your days on the This month board |
| supporter status | Whether you’ve bought Tsukiniwa Supporter, set by our server when RevenueCat reports your purchase or a refund. Your phone can’t set it itself | Shows the moon by your name on both leaderboards |
| streak, badges and totals | Your current and longest streak, the last day your streak counts, the badges you’ve earned, how many dailies you’ve solved and how many with no hint or mistake, and the date of your first, as your phone works them out | Shown on your player card to anyone who taps your row |
| progress backup | The progress the app keeps on your phone: boards solved, your daily log, badges, lessons finished, and your clue style and appearance settings | Restores your progress if you delete and reinstall the app. Only your phone can read it; nothing public shows it |
What we don't collect
No account means there's a lot we simply never ask for:
Tsukiniwa itself doesn't run its own analytics or crash-tracking SDK, and never asks for your location. Google AdMob's SDK, as part of serving ads, does incidentally collect some coarse-location and performance/crash data on its own infrastructure — see Ads.
How it's used
Everything in the table above exists to run two features: the daily leaderboard (fastest time at each level) and the month leaderboard (days placed in the garden), and the player card that opens when someone taps your row on either one. Your progress — your garden, stats, lessons, and library boards — lives on your device, with a private copy on our server that's read only when a reinstalled app on your device asks for it. Your streak, badges and those totals are the exception: your phone also shares them for your player card. Nothing else about how you play — saved boards in progress, or your moves — leaves your device.
Purchases
Tsukiniwa Supporter is a one-time, optional purchase. It removes the rewarded ad, adds five more hints per board and a second chance on any board, and puts a small moon by your name. The puzzles, the garden, and the leaderboards are the same for everyone. Payment is handled entirely by the App Store or Play Store; Tsukiniwa never sees your card number, billing address, or any other payment detail. We only receive a yes/no signal that the purchase went through, via RevenueCat.
Ads
Tsukiniwa shows no banner ads. The only ads are optional rewarded videos through Google AdMob: you can choose to watch one for an extra hint, or for a second chance after a board stops at the mistake limit. Nothing makes you watch one; every board comes with three free hints that don't need an ad at all. Supporters never see the ad.
Every ad request is non-personalized only: ads aren't chosen from a profile of you, and Tsukiniwa does no cross-app tracking of its own. As part of delivering ads, AdMob's own SDK does incidentally collect some data on Google's infrastructure — device and coarse-location signals, and performance/crash diagnostics — independent of anything Tsukiniwa itself reads, stores, or sends.
On Android, the app includes Android's advertising ID permission (AD_ID), which AdMob's SDK uses to read your device's advertising ID. Even for non-personalized ads, Google uses it for things like frequency capping, fraud prevention and measuring ads. You can reset it, or delete it so apps see only zeros, in your phone's Settings (on most phones, Settings › Privacy › Ads, or Settings › Google › Ads).
On iPhone, Tsukiniwa never shows the App Tracking Transparency prompt, so AdMob can't read your advertising identifier (IDFA).
In the EEA, the UK and Switzerland, Google's consent form appears before the first ad is requested, and asks for your choices about how Google may use data for ads. Tsukiniwa requests ads only when that form allows it. You can change your choices at any time from Privacy choices in the app's Settings. Supporters never see ads, so they're never asked.
Notifications
If you turn on the daily reminder in Settings, Tsukiniwa asks your device for permission to send local notifications — the same kind of system prompt any app uses to ask before it can notify you. The reminder is scheduled entirely on your device using its own clock; nothing about whether you've turned it on, when it's scheduled, or whether you open one is ever sent to a server.
You can turn the reminder off at any time in Settings, or deny or revoke the notification permission at the OS level — either way, nothing else about the app changes.
Keeping & deleting data
Server-side data is kept tied to your device ID for as long as you use the app. Since there's no login, we can't look you up by name or email, and a display name alone could be anyone's, so a deletion request needs something only your phone shows you. To have your data deleted (your leaderboard rows, player card, and progress backup), email us your display name together with the player ID shown in the app's Settings; we'll check the two match before removing anything, and reply when it's done.
Deleting the app removes what it stores on your phone, but it doesn't delete anything on our server. On Android, it also deletes the device ID, so a fresh install starts as a new, unlinked player. On iPhone, the device ID and your chosen name are also kept in the iOS Keychain, which isn't cleared when the app is deleted, so reinstalling brings back the same player and, from the backup, your progress. The Keychain copy stays until the iPhone itself is erased.
Children
Tsukiniwa is a general-audience app, not directed at children under 13, and we don't knowingly collect data from them beyond what's described above.
Security
All traffic to our backend runs over HTTPS. The database key embedded in the app is scoped to a narrow set of server-side functions built for this purpose — it can't be used to read or modify anything outside the leaderboard tables.
Changes to this policy
If this policy changes in a way that affects what we collect or how it's used, the "Effective" date at the top will update. Meaningful changes will also be noted in the app's release notes.
Contact
Tsukiniwa is built and run by an independent developer. Questions, deletion requests, or anything else — reach out at contact@nathanle.info.