Overview
Little Jigsaws is a jigsaw puzzle game for iOS and Android, made by SteelByteLabs Pty Ltd (“SteelByteLabs,” “we,” “us,” or “our”). This policy explains what data the app collects, how it is used, and the choices you have. The short version: we don't ask for your name, email, or account; gameplay is stored on your device; and the app is supported by ads with a one-time purchase to remove them permanently. The app is intended for a general audience and is not designed or marketed to appeal to children.
This policy has been prepared having regard to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) for users in Australia, the Privacy Act 2020 for users in New Zealand, and the Personal Information Protection and Electronic Documents Act (PIPEDA) — together with Quebec's Act respecting the protection of personal information in the private sector (Law 25) for Quebec residents — for users in Canada.
For users located outside Australia, New Zealand, and Canada (and outside the regions listed below as not yet offered), this policy describes our actual data practices in good faith. We have not conducted a jurisdiction-by-jurisdiction legal review for every country, but the same protections described throughout this policy apply to you regardless of location: we collect the minimum data needed to operate the app, we do not sell your personal information, and you can request access to or deletion of any data tied to your anonymous ID at any time by contacting [email protected].
Little Jigsaws is not currently offered to users in the European Economic Area (EEA), the United Kingdom, mainland China, or Vietnam. This policy does not address the EU General Data Protection Regulation (GDPR), UK GDPR, China's Personal Information Protection Law (PIPL), or Vietnam's Personal Data Protection Decree as a result. It does address United States, Brazilian, and Indian privacy law in their own dedicated sections below, since the app is offered in those countries.
Data We Collect
Collected automatically:
- Anonymous user ID — created via Firebase Authentication so the app can load the puzzle catalog securely. It is a random identifier and is not linked to your personal identity.
- Usage analytics — via Google Analytics for Firebase: events such as puzzles started/completed, difficulty chosen, features used, and screen views, together with general device information (model, OS version, app version, country-level region).
- Crash and performance data — via Firebase Crashlytics: crash logs and device state at the time of a crash, used solely to find and fix bugs.
- Advertising data — via Google AdMob (see “Advertising” below): a device advertising identifier — on iOS, your IDFA, collected only with your permission via Apple's App Tracking Transparency prompt; on Android, your Google Advertising ID (AAID), which you can reset or opt out of ad personalization for at any time via your device's Settings → Google → Ads, a setting that applies across all your apps, not just this one — plus IP-derived coarse location (i.e. an approximate region inferred from your network connection, not your device's GPS), and ad interaction data (views, taps).
- Push notification token — only if you opt in to reminders (see “Notifications” below).
- Purchase state — whether the “Remove Ads” purchase has been made (a yes/no flag). Payment itself is handled entirely by Apple or Google Play, depending on your device.
Requested only if you choose to share a completed puzzle:
- Photo library (add-only) access — if you tap “Save Image” from the native share sheet after completing a puzzle: on iOS, this asks your permission to add that image to your photo library (Apple's own share sheet feature). On Android, saving is instead handled entirely by whichever app you choose from the system share sheet (e.g. Google Photos, Files) — our app does not request or hold any photo/media permission itself there. In both cases, we do not read, browse, or access your existing photos, and no image data is sent to us or to any third party as part of this.
Stored on your device:
- Game progress, in-progress puzzles, stars, badges, streaks, and settings (sound, effects, notification preference, image overlay opacity). On iOS, if you have iCloud Backup enabled on your device (or use Quick Start when setting up a new device, or a Finder/iTunes backup), this data is included in that backup and is restored automatically when you set up a new device from it. On Android, the equivalent is Google's own “Back up to Google Drive” device setting, which similarly restores this data automatically to a new device signed into the same Google account, if enabled. In both cases downloaded puzzle images (below) are excluded from the backup. If you set up a new device as “new” instead of restoring from a backup, or switch to a different platform, this data does not carry over.
- Downloaded puzzle images (cached for faster loading) — not included in device backups.
We do NOT collect: your name, email address, contacts, camera or microphone data, or payment card details. We do not request or access your device's precise location (GPS) — the app has no location-tracking feature, and no such permission prompt will appear.
Advertising
Little Jigsaws is free to play and may show ads (banner, interstitial, and optional rewarded ads) served by Google AdMob. We do not use any other ad network or mediation partner.
- App Tracking Transparency (iOS): on first launch you will be asked whether to allow tracking. If you decline, ads still appear but are not personalized using your advertising identifier. You can change this anytime in iOS Settings → Privacy & Security → Tracking.
- Ad personalization (Android): Android has no equivalent per-app prompt. Instead, you can reset your advertising ID or opt out of personalized ads at any time via your device's Settings → Google → Ads — a systemwide setting that applies across all your apps, not just this one.
- Remove Ads: a one-time in-app purchase removes all ads — banner, interstitial, and rewarded ad prompts — permanently. It is tied to your Apple ID (iOS) or Google Play account (Android) and can be restored on any device signed into that same account via “Restore Purchase.”
Google's use of advertising data is described at policies.google.com/technologies/ads.
In-App Purchases
The “Remove Ads” purchase is a one-time, non-consumable purchase processed entirely by Apple (through your Apple ID) or Google Play (through your Google Play account), depending on which platform you're using. We never see or store your payment information. Purchases can be restored at any time from Settings → Remove Ads → Restore Purchase.
Notifications
Notifications are strictly opt-in:
- Daily puzzle reminder — a local notification scheduled on your device (no data leaves your device for this).
- Occasional tips and nudges — sent a few times per week via Firebase Cloud Messaging to an anonymous device token subscribed to a broadcast topic.
You can turn notifications off at any time in the app (Info → Daily Reminders) or in your device's Settings (iOS or Android), which cancels reminders and unsubscribes the device.
Data Usage & Third Parties
Data is used to operate the app (load puzzles, save progress), improve stability (crash reports), understand aggregate usage (analytics), and fund development (ads). We do not sell your personal data. The app's service providers are:
- Google Firebase (authentication, puzzle catalog and images, analytics, crash reporting, remote configuration, push messaging) — firebase.google.com/support/privacy
- Cloudflare (content delivery network) — delivers puzzle images faster by serving them from a location closer to you. As with any content delivery network, Cloudflare processes your IP address as part of standard web request routing; it does not receive your anonymous user ID, purchase state, or any other information described in this policy. — cloudflare.com/privacypolicy
- Google AdMob (advertising) — support.google.com/admob/answer/6128543
- Apple (in-app purchases, App Store, and — if you have iCloud Backup enabled — standard iOS device backup of your local app data; this is Apple's own system-level backup feature, not a service we integrate with directly) — apple.com/legal/privacy
- Google Play (in-app purchases and Play Store, for Android users; and — if “Back up to Google Drive” is enabled on the device — standard Android device backup of your local app data, again a system-level feature of the device, not a service we integrate with directly) — policies.google.com/privacy
Some of these providers store and process data on servers located outside Australia, including in the United States. See “International Data Transfers” below for how this applies if you are in New Zealand or Canada.
International Data Transfers
Australia: We handle personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Where required, we take reasonable steps to ensure our providers handle data consistently with the APPs even where it is processed overseas.
New Zealand: If you are located in New Zealand, your information may be collected, stored, and processed outside New Zealand — including in Australia and the United States — by our service providers (Google Firebase, Google AdMob, Google Play, Cloudflare, Apple). We take steps to ensure these providers offer a comparable level of protection to that required under the Privacy Act 2020, consistent with Information Privacy Principle 12.
Canada: If you are located in Canada, your information may be collected, stored, and processed outside Canada — including in Australia and the United States — by our service providers. We handle your information in accordance with PIPEDA and, for users in Quebec, Law 25.
Privacy Officer (Quebec): SteelByteLabs Pty Ltd, contactable at [email protected], is responsible for ensuring compliance with applicable privacy laws and handling privacy-related complaints or requests from Quebec residents. Quebec residents may request a French-language version of this Privacy Policy by contacting [email protected].
Other regions: If you are located outside Australia, New Zealand, or Canada (and outside the regions listed in the Overview as not yet offered), your information may also be collected, stored, and processed outside your home country — including in Australia and the United States — by the same service providers listed above. We apply the same data-minimization and no-sale practices described throughout this policy regardless of where you are located.
United States
This section is written with California's Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), specifically in mind, and applies consistently to residents of other US states with comparable comprehensive consumer privacy laws (for example Virginia, Colorado, Connecticut, and Utah, among a growing list of others). As with “Other regions” above, we have not conducted a state-by-state legal review of every US jurisdiction; we apply the same data-minimization approach described throughout this policy regardless of which US state you are in.
If you are located in the United States, your information may be collected, stored, and processed outside the United States — including in Australia, where SteelByteLabs is based — by us and by our service providers.
“Sale” and “sharing” of personal information. We do not sell personal information for money. Our use of Google AdMob for personalized advertising does, however, involve sharing your advertising identifier with AdMob for cross-context behavioral advertising — which CPRA defines broadly enough to count as “sharing” even though no money changes hands. You can opt out of this at any time:
- On first launch, a detected California (or other applicable US state) resident is shown a consent message covering this specifically, before any personalized advertising occurs.
- You can change your choice at any time via Settings → Ad Privacy Choices in the app.
- Opting out does not stop ads from showing — you will still see ads, just not personalized ones.
We do not otherwise sell or share sensitive personal information, and the app does not collect sensitive personal information as CPRA defines it (e.g. no precise geolocation, no biometric data, no government ID numbers).
Your rights. If you are a California resident, or a resident of another US state with a comparable law, you have the right to:
- Know what personal information we collect, use, and disclose (see “Data We Collect” and “Data Usage & Third Parties” above).
- Delete personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of your personal information, and of targeted/personalized advertising (see above).
- Limit the use of sensitive personal information — not applicable here, since we do not collect any.
- Not be discriminated against for exercising any of these rights — we will not deny you access to the app, charge you a different price, or provide a different level of service because you exercised a privacy right.
Since we do not collect information that identifies you personally, most of these requests can be handled simply by uninstalling the app (which clears all local data) or contacting us for anything tied to your anonymous ID. To exercise these rights, email [email protected]. We will respond within the time required by applicable law (generally 45 days for California, extendable once by a further 45 days if reasonably necessary).
Authorized agents. You may designate an authorized agent to make a request on your behalf; we may require proof of the agent's authority and may still need to verify your identity directly for certain requests.
Brazil
This section addresses Brazil's Lei Geral de Proteção de Dados (LGPD).
Legal basis for processing. We rely on legitimate interests to operate the core app, load the puzzle catalog, and produce the aggregate usage and crash analytics needed to run and improve the app. We rely on your consent for personalized advertising (see “Advertising” above) and for push notifications (see “Notifications” above), both of which you can withdraw at any time without affecting the lawfulness of processing carried out before withdrawal.
Your rights. Under the LGPD, you have the right to: confirmation of whether we process your data; access to that data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data; data portability; deletion of data processed with your consent; information about the public and private entities with which we share data; information about the possibility of not giving consent and the consequences of doing so; and revocation of consent. Since we do not collect information that identifies you personally, most requests can be handled simply by uninstalling the app (which clears all local data) or contacting us for anything tied to your anonymous ID.
Encarregado (data protection contact). SteelByteLabs Pty Ltd, contactable at [email protected], serves as the contact point for LGPD-related requests and questions, consistent with LGPD Article 41.
International transfers. If you are located in Brazil, your information may be collected, stored, and processed outside Brazil — including in Australia and the United States — by us and by our service providers. We rely on your consent to the processing described in this policy, together with our service providers' own contractual data protection commitments, as the basis for these transfers.
To exercise your rights, email [email protected]. We aim to respond within 15 days, as required under the LGPD.
India
This section addresses India's Digital Personal Data Protection Act (DPDPA).
Legal basis. We rely on your consent for personalized advertising and push notifications (see “Advertising” and “Notifications” above), and on legitimate uses (to operate, maintain, and improve the app, and to prevent fraud or misuse) for the other processing described in this policy.
Your rights. As a Data Principal under the DPDPA, you have the right to: obtain a summary of the personal data we process about you and of the processing activities involved; correction, completion, updating, and erasure of your personal data; grievance redressal; and to nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. Since we do not collect information that identifies you personally, most requests can be handled simply by uninstalling the app (which clears all local data) or contacting us for anything tied to your anonymous ID.
Children. The DPDPA defines a “child” as anyone under 18 — a notably broader definition than elsewhere in this policy. See “Children” below for how we address this.
International transfers. If you are located in India, your information may be collected, stored, and processed outside India — including in Australia and the United States — by us and by our service providers.
To exercise your rights or raise a grievance, email [email protected]. If you are not satisfied with our response, you may approach the Data Protection Board of India.
Children
Little Jigsaws is intended for a general audience. It is suitable for all ages in terms of content, but it is not listed in any children's category on the App Store or Google Play (including Google Play's Families program), and is not directed at, marketed to, or designed to appeal to children — it does not use cartoon characters, mascots, or other imagery or content designed to attract children. We do not knowingly collect personal information from children under 13 (under 14 in Quebec, Canada; under 18 in India, per the Digital Personal Data Protection Act's broader definition of “child” — see “India” above). We do not collect any age, birthdate, or other information that would let us determine whether a user is a minor under any of these thresholds. If we become aware that we have processed a child's personal information without the consent required in their jurisdiction, we will delete it promptly. Parents or guardians who believe their child has provided us with information may contact us at [email protected] to request its removal. Ads are served through Google AdMob under its family-safe ad policies where applicable.
Data Retention & Deletion
- Local data (progress, settings, cached images) stays on your device and is removed when you uninstall the app. If you have iCloud Backup (iOS) or “Back up to Google Drive” (Android) enabled, a copy of your progress and settings (not cached images, which are excluded from both backup mechanisms) may also persist in your device backup until that backup is replaced or deleted — this is standard OS backup behavior and outside our control.
- Analytics and crash data are retained by Google Firebase per its standard retention periods (up to 14 months for user-level analytics data).
- You can request deletion of data associated with your anonymous ID by emailing [email protected].
Data Breach Notification
If a data breach occurs that is likely to result in serious harm or significant risk to affected individuals, we will notify affected users and the relevant regulator as required by applicable law, including the Privacy Act 1988 (Australia), the Privacy Act 2020 (New Zealand), and PIPEDA (Canada).
Your Rights
Under the Australian Privacy Principles (in particular APP 12 and APP 13), the New Zealand Privacy Act 2020, and PIPEDA — and depending on your location — you may have rights to access the personal information we hold about you and to request its correction or deletion. Wherever you are located, including outside Australia, New Zealand, and Canada, we extend the same rights to access, correct, or delete your data on request. Since we do not collect any information that identifies you personally, most requests can be handled simply by uninstalling the app (which clears all local data) or contacting us for anything tied to your anonymous ID. To exercise these rights, email [email protected]. We aim to respond within 30 days.
Complaints
If you believe we have mishandled your personal information, please contact us first at [email protected] with details of your concern. We will acknowledge your complaint and aim to resolve it within a reasonable time, typically within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the relevant regulator:
- Australia — Office of the Australian Information Commissioner (OAIC): oaic.gov.au/privacy/privacy-complaints, Phone: 1300 363 992, Mail: GPO Box 5288, Sydney NSW 2001, Australia
- New Zealand — Office of the Privacy Commissioner: privacy.org.nz
- Canada — Office of the Privacy Commissioner of Canada: priv.gc.ca
- Quebec — Commission d'accès à l'information du Québec: cai.gouv.qc.ca
- California (US) — California Privacy Protection Agency (CPPA): cppa.ca.gov
- Brazil — Autoridade Nacional de Proteção de Dados (ANPD): gov.br/anpd
- India — Data Protection Board of India (established November 2025; its complaint process is administered online per the DPDPA Rules — contact us first and we will direct you appropriately if we cannot resolve your concern directly)
Security & Updates
All communication between the app and our services uses HTTPS encryption. We may update this policy as the app evolves; material changes will be reflected on this page with a new effective date.
Contact
Questions about this policy or your data: [email protected]