Privacy Policy
Last updated: September 14, 2026
Pixzle Apps LLC ("Pixzle," "we," "us") builds Pixzle, a photo puzzle game for iPhone and iPad, and the web player at play.pixzle.net. This policy explains what we collect, what we do with it, and what you can ask us to do about it.
1. The short version
- Pixzle has no accounts. You never create a username, password, or profile.
- We do not ask for your name, email address, phone number, or date of birth.
- We collect usage analytics and crash reports so we can fix things and improve the game. They are tied to a per-device identifier, not to you by name.
- We show ads, and they are non-personalized. Pixzle never asks for permission to track you.
- If you share a puzzle made from your own photo, that photo is uploaded to our servers and deleted after 24 hours.
- The web player at play.pixzle.net sets one first-party cookie, for analytics. The iOS app sets no cookies.
2. What we do not collect
- No account, login, or password.
- No name, email address, phone number, postal address, or date of birth.
- No contacts, calendar, microphone, or precise location. We never ask for your location, and Pixzle cannot read it.
- No advertising identifier. Pixzle never presents Apple's "Allow tracking" prompt, so the advertising identifier (IDFA) is never available to us or to our ad provider.
- No profile of you built from your activity across other apps or websites.
One clarification, because "location" is easy to misread: we do not collect location from your device. But every internet request carries an IP address, and our analytics and advertising providers use it to estimate roughly where you are — country level for analytics, about city level for ads. Section 3 says exactly who does that.
3. What we do collect, and why
Usage analytics
We use Amplitude to understand how the game is used — which screens are opened, when a puzzle is started, paused, solved, or abandoned, which puzzle type was played, and how long things take. The iOS app also reports when it is installed, updated, opened, and sent to the background.
Each event carries a device identifier, and the identifier is not the same on iPhone and on the web. They are different mechanisms and we describe them separately, because summarising them as one thing would be inaccurate.
On both iPhone and the web, events also include the identifier of the shared puzzle you opened, which for a puzzle someone made from a photo is a reference to that photo while it exists on our servers. The photo itself is never sent to Amplitude.
On iPhone and iPad
The identifier is your device's identifier for vendor (IDFV). This is an ID that Apple generates and gives to apps from the same developer. We do not create it, cannot choose it, and do not change it.
- It is not your Apple ID, your name, your serial number, or the advertising identifier.
- It is not shared with other developers' apps, and it does not follow you around the internet.
- It does not reset when you delete and reinstall Pixzle, so long as you still have another app by Pixzle Apps installed. Apple issues a new one only after the last app from us is removed from the device.
Alongside the identifier, Amplitude records: your device model and manufacturer, operating system name and version, app version, platform, preferred language, mobile carrier name, and your IP address, from which it derives your approximate country.
On the web player
The identifier is a random value generated in your browser the first time you visit. It is not derived from your device, and it is stored in a cookie — see "Cookies and browser storage" below. Clearing that cookie discards it and a new one is generated.
Alongside it, Amplitude records your IP address, browser language, and platform.
What we use it for
To answer questions like "did the new library make people play more" and "where do people give up." We do not use it to identify you, and we do not combine it with data from anywhere else.
How long we keep it: analytics and crash data are held by Amplitude and Sentry under the retention settings on our accounts with them. Photos and shared content are deleted on the schedule in Section 4.
Crash reporting and performance
We use Sentry to capture crashes and errors. A report includes:
- An installation identifier — a random value Sentry generates the first time the app runs and stores on the device. This one genuinely is random, is not issued by Apple, and is discarded when you delete the app.
- A one-way hash derived from your device's identifier for vendor together with its hardware model and the app's identifier. It cannot be reversed into any of those, but it does stay the same for as long as the identifier for vendor does.
- Device model, operating system version, app version, language, time zone, screen size, total and free memory, free storage, and battery level.
- A technical stack trace, and a short trail of the actions leading up to the failure.
- The address of network requests the app makes — including, while a shared puzzle exists, the address of its image on our servers. Not the image itself.
Sentry also measures performance, and this is more than crash reporting, so we say it plainly. In the iOS app we currently sample every session — recording how long operations take, and periodically sampling which part of the code is running — so that we can find what is slow. On the web player we sample about one session in five and do not do the code sampling.
Sentry does not record your IP address, screenshots, or the contents of your screen.
Image generation
If you create an image with Apple's Image Playground to make a puzzle from, what you type and any photo you start from are handled by Apple, under Apple's privacy policy. Nothing about that reaches us — we receive only the finished image, and only if you then choose to share the puzzle.
Advertising
We use Google AdMob to show ads. Ads in Pixzle are requested as non-personalized only, which means they are selected based on general context rather than a profile of your interests or browsing history.
Non-personalized does not mean nothing is collected, and we would rather be specific than reassuring. AdMob still receives:
- Your IP address, which Google uses to estimate your general location — roughly city level — and to select contextually relevant ads.
- A device-scoped identifier, used for capping how often you see the same ad, aggregated reporting, and detecting fraudulent clicks. Because Pixzle never presents Apple's tracking prompt, this is not the advertising identifier.
- Which ads were shown to you and whether you interacted with them.
- Google's own crash and performance data for its advertising code.
Google's handling of that data is governed by its own policies: https://policies.google.com/technologies/partner-sites
Separately, if you installed Pixzle after seeing an ad for it, Apple's SKAdNetwork may send an install confirmation to the advertising network that showed you that ad. Apple performs that entirely, we do not see it, and it contains nothing about you.
You can remove ads entirely with the one-time "Remove Ads" purchase.
Game Center
If you use leaderboards or achievements, Pixzle submits your scores and achievement unlocks to Apple's Game Center. Your Game Center identity is managed entirely by Apple, under Apple's privacy policy.
Nothing comes back to us. We do not receive your Game Center nickname, your player identifier, or your Apple ID, and we store nothing from Game Center on our servers.
Unsplash
The iPhone app includes an image search provided by Unsplash. When you open it you are using Unsplash's own interface, not ours — the search field, the results, and the request to their servers all live inside a component Unsplash provides. What you type goes directly to Unsplash and is handled under their privacy policy, not ours.
When you tap a photo, the app fetches it from Unsplash's image servers so it can be used in your puzzle. That fetch reaches Unsplash from your device and, like any web request, carries your IP address and your app's user agent. We do not receive either.
Unsplash also supplies the Daily Puzzle image. That image is served to you from our own content delivery network rather than fetched from Unsplash on demand, so opening the Daily does not send a request to them. The photographer is credited on the puzzle screen.
Cookies and browser storage
The iOS app sets no cookies.
The web player at play.pixzle.net sets one cookie, named AMP_6cc8fd6c7f. It holds the random analytics identifier described above along with your current session, it is set on .pixzle.net, and it lasts 365 days. It is a first-party cookie and it is not used for advertising. Clearing cookies for pixzle.net removes it.
The web player also keeps your last chosen grid size in your browser's local storage, and holds analytics events there briefly before sending them. Neither is used to identify you, and the grid size never leaves your browser.
Shared puzzle images
Covered in full in Section 4.
4. Photos you upload
There are two ways a picture of yours reaches our servers. Both are described here.
4a. A puzzle you made from your own photo
If you create a puzzle from your own photo and share it, that photo is uploaded to our servers so the person you send it to can open it.
What we store:
| Item | How long |
|---|---|
| Your uploaded photo | Expires after 24 hours, deleted shortly thereafter |
| Blurred preview thumbnail | Expires after 24 hours, deleted shortly thereafter |
| Puzzle settings (its size, how the pieces were scrambled, when it expires) and a link to the image | Expires after 10 days |
| The share link page | Expires after 10 days |
The metadata outlives the photo on purpose. It is what allows someone opening an old link to see a clear "this puzzle expired" message instead of a broken page. The metadata contains no image data and nothing about you.
4b. A picture of a puzzle you solved
When you share a picture of a puzzle you have finished, a small image of that solved puzzle — which is your photo, if the puzzle was made from one — is uploaded along with a link page, so that whoever opens the link can see it.
| Item | How long |
|---|---|
| The image of your solved puzzle | Expires after 24 hours, deleted shortly thereafter |
| The share link page | Expires after 24 hours, deleted shortly thereafter |
Both kinds
Who can see it: anyone with the link, until it expires. Share links are long random identifiers — they are not listed anywhere, and there is no way to find one from inside Pixzle or on our website. But they are not secret: treat a share link the way you would treat any link you send someone.
What we do with it: nothing. We do not use uploaded photos for training, analysis, advertising, or any purpose other than delivering the puzzle to the person you sent it to.
Two exceptions, stated plainly:
- If an uploaded image is reported to us and we determine it violates our Acceptable Use Policy, we review and delete it.
- If a shared image is reported to us, we may copy it — together with its thumbnail, link page and puzzle settings — into separate storage that only we can access, before we review the report, so that it is not deleted while we work out what the law requires. If we are legally required to preserve it — for example, after reporting it to the National Center for Missing & Exploited Children as US law requires — we keep that copy for as long as the law requires, notwithstanding the schedule above. Otherwise, we delete the copy once our review is complete.
5. Legal basis for processing (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your data on these bases:
| What | Basis |
|---|---|
| Usage analytics and crash reporting | Legitimate interests — understanding and improving the app |
| Delivering a shared puzzle you created | Performance of a service you requested |
| Non-personalized advertising | Legitimate interests — funding a free app |
| Content review and legal preservation | Legal obligation and legitimate interests — safety |
Our servers are in the United States. When you use Pixzle from outside the US, your data is transferred there. We rely on Standard Contractual Clauses where our service providers offer them.
6. Your rights
You can ask us to:
- Tell you what data we hold about you
- Delete data associated with your device
- Stop processing your data
Because Pixzle has no accounts, the only way we can find your data is by the per-device identifier described in Section 3. Email support@pixzleapps.com from any address and we will respond within 30 days.
On iPhone or iPad: the identifier is one Apple issues to your device, and it is not shown to you anywhere in the app today. Email us and we will walk you through finding it, or work out what we can do without it. We are adding it to a Settings screen in a future version.
On the web player: the identifier lives only in your browser's cookie, and we have no way to look it up from our side. You can remove it yourself at any time by clearing cookies for pixzle.net, which severs the association and causes a new identifier to be generated on your next visit.
If you are in the EEA or UK, you also have the right to lodge a complaint with your national data protection authority.
To stop collection: deleting the app stops all further collection from that device immediately, and clearing cookies for pixzle.net does the same for the web player. Two honest caveats. First, data already collected is not removed automatically — ask us and we will delete it. Second, on iPhone and iPad the identifier described in Section 3 is issued by Apple and is not reset by deleting Pixzle; it changes only once every app made by Pixzle Apps has been removed from the device.
7. Children
The Pixzle game — the daily puzzle, the curated image library, and playing a puzzle made from a photo already on your device — is rated 4+ and suitable for all ages.
One feature is not. Creating a shared puzzle from your own photo uploads that photo to our servers and produces a link that anyone holding it can open. Because of that, photo upload and sharing is intended for people aged 13 and older.
We do not knowingly collect personal information from children under 13 beyond the technical data described in Section 3, and we do not serve personalized ads to anyone. Every ad request Pixzle makes is tagged as non-personalized, so ads are selected from general context rather than from any profile of you or your child.
If you believe a child under 13 has uploaded a photo through Pixzle, email support@pixzleapps.com with the share link and we will delete it immediately.
Pixzle is not part of Apple's Kids Category.
8. Service providers
| Provider | Purpose | Their policy |
|---|---|---|
| Amazon Web Services | Image and metadata storage, content delivery | aws.amazon.com/privacy |
| Amplitude | Usage analytics | amplitude.com/privacy |
| Sentry | Crash reporting | sentry.io/privacy |
| Google AdMob | Non-personalized advertising | policies.google.com/privacy |
| Apple | App distribution, in-app purchases, Game Center, Image Playground | apple.com/legal/privacy |
| Unsplash | Daily Puzzle image, in-app image search, and image delivery | unsplash.com/privacy |
We do not sell your data. We have never sold your data. Apart from the install confirmations Apple's SKAdNetwork sends to advertising networks, described in Section 3, we do not share it with anyone beyond the providers above.
9. Security
Uploads are encrypted in transit, and stored images are encrypted at rest. Share links use long random identifiers — 122 bits of randomness — which cannot realistically be guessed.
No system is perfectly secure. If you find a vulnerability in Pixzle, please email support@pixzleapps.com — we would genuinely rather hear from you than not.
10. Changes
We will post any change here and update the date at the top. Every change we make to this policy is recorded on our Policy Changelog, including corrections.
11. Contact
Pixzle Apps LLC
Email: support@pixzleapps.com
Web: https://www.pixzleapps.com/support.html