1. Who is responsible for your data (Data Controller)
The app “Tilt Blocks” (Android package com.luxebyte.tiltblocks,
the “App”) is published by Luxebyte Labs (the
“Developer”, “we”, “us”).
For the limited processing described in this policy, the data controller is:
- Controller: Matteo Lamarque, trading as Luxebyte Labs
- Contact for privacy matters: luxebytecomp@gmail.com
“Luxebyte Labs” is a trading name of Matteo Lamarque, an independent developer based in Italy. This is a one-person publisher, and the email address above is the contact point for every privacy matter — it reaches the person who can actually act on it. If you need a postal address in order to exercise a right, write to luxebytecomp@gmail.com and it will be given to you.
Important to understand up front: the Developer operates no servers and runs no backend of its own. We do not receive, store, or have access to the advertising data described in Section 3(b). That data is collected and processed by Google (our advertising provider) and its partners. We are the controller only in the sense that we chose to integrate advertising into the App and we decide where and how an ad may appear. Google determines the means and purposes of its own processing of advertising data and acts as an independent (and, where applicable, joint) controller for it.
2. Scope of this policy
This policy applies only to the “Tilt Blocks” Android App distributed through the Google Play Store. It does not cover any other product, website, or third-party service except as expressly described here (in particular Google’s advertising services).
The App is distributed globally and its interface is localized into 16 languages. This English text is the primary version.
Updates to this policy
We may update this policy, for example if the App changes or if legal requirements change. When we make a material change we will update the “Last updated” date above and publish the new version at the same web address where you found this policy, before or at the time the change takes effect. Where the change concerns advertising consent, you may be asked again through the in-app consent mechanism (see Section 7). Your continued use of the App after an update takes effect means the updated policy applies to you; if you do not agree, you can stop using the App and uninstall it.
3. What data is processed
The App processes four clearly separate categories of data. We keep them separate on purpose, because they behave very differently: one never leaves your device, one is collected by Google and never reaches us, one is a single request that carries nothing about you but cannot help revealing where it came from, and one is a small, fixed set of usage statistics that you can switch off.
3(a). Data kept ONLY on your device — never transmitted to us or anyone
To make the App work, the App stores a small amount of information locally on your
device only, using Android’s standard SharedPreferences storage. This is
the complete list:
- your best score;
- your unfinished game, so a run can be resumed after you close the App (the board, the score, the turn count and the pieces in your hand);
- your settings: sound on or off, light or dark theme, and the language you have chosen;
- your board skin: which one is in use, and the moment each unlocked skin was unlocked, because an unlock lasts 24 hours and has to know when it started.
This on-device data:
- never leaves your device;
- is never transmitted to the Developer, who has no servers to receive it;
- is never sold or shared with anyone;
- contains nothing that identifies you — there is no account, no login, no name, no email address and no device identifier in it;
- is fully under your control — uninstalling the App, or clearing the App’s storage/data in Android Settings → Apps → Tilt Blocks → Storage, deletes it.
The App declares three permissions and no others:
- Vibration, to make blocks feel like objects in your hand;
- Internet access, used by the advertising and consent components described in 3(b), by the single request described in 3(c), by the usage statistics described in 3(d), and by nothing else;
- Advertising ID (
com.google.android.gms.permission.AD_ID), which is what allows Google to read the resettable advertising identifier described in 3(b). It is declared explicitly rather than inherited silently, so that what the App can reach is written down rather than guessed at.
It has no access to your camera, microphone, location, contacts, files, or phone state, and no permission that identifies you personally.
3(b). Advertising data — collected and shared by Google (AdMob)
The App offers one optional, opt-in advertisement: a rewarded video ad.
It appears in a single place — when a game ends, you may choose to watch a short video to clear space and continue that run. The ad is:
- opt-in — a dialog tells you a video is about to play and you must press Watch before anything happens;
- never auto-played, never shown during play, never shown on the board, and never shown in a notification;
- fully declinable — Play again is free, is the larger button, and sits above the offer;
- limited — at most two per game, a limit built into the game’s rules and not adjustable by us at runtime.
To serve this ad we use the Google Mobile Ads SDK (Google AdMob). When an ad is requested and shown, Google and its advertising partners collect and process the following categories of data for the purposes of serving ads, measuring ad performance, and preventing fraud and abuse:
- the Android Advertising ID (AAID) — a resettable advertising identifier;
- the app-set ID — an identifier scoped to apps from the same developer;
- your IP address;
- device and diagnostic information (such as device model, operating-system version, language/region, and similar technical data);
- your interactions with ads (such as whether an ad was shown, viewed, or clicked).
This advertising data is collected by and shared with Google and Google’s advertising partners. The Developer does not receive it. Because Google’s advertising infrastructure is global, this data may be processed on servers located outside the European Union / European Economic Area, including in the United States (see Section 6).
No score, no game progress and no setting is ever sent with an ad request. Your best score and your saved game stay on your device.
3(c). One request to a static file, so ads can be switched off without an update
When the App starts it fetches a single small text file from a fixed address:
https://matteomark.github.io/ads-flag.txt
The whole content of that file is a line saying whether advertising is switched on. It exists so that ads can be turned off without publishing a new version of the App.
The App sends nothing with this request: no identifier, no advertising ID, no score, no setting, nothing about you or your game. But as with any request to any web server, the server that answers it necessarily sees the IP address the request came from, together with ordinary connection information such as the time, the file requested and the type of client. That server is GitHub Pages, operated by GitHub, Inc., which hosts the file as a plain static document. We run no server, and we never see a log of these requests.
A successful response is stored on your device for 24 hours, so a returning player usually makes no request at all.
Separately from this file, the App asks Google’s consent component at every start whether a consent message is required for you (Section 7). It does so whether advertising is switched on or off, because the answer also governs the usage statistics in Section 3(d). Outside the EEA, the UK and Switzerland that check shows nothing and asks you nothing.
3(d). Usage statistics (Google Analytics for Firebase)
Why this exists, plainly. Tilt Blocks is made by one person, and the only thing that person can otherwise see is a star rating. This Section describes the small, fixed set of facts the App can send so that we can learn whether people find the tutorial, how far their games get, whether the two optional video offers are understood, and which board colours are used. Nothing here changes the game: the pieces you are dealt, the difficulty ramp and the offers you see are decided by rules that cannot read any of this data, and that separation is enforced by automated tests in the App’s source.
We describe this data as pseudonymous, and deliberately not as “anonymous”. Each installation is identified by a random identifier generated by Google’s SDK, and Google sees the IP address the data arrives from. That is enough for the data to count as personal data, so it is treated as personal data throughout this policy.
Where this is active, and where nothing is sent at all
In the EEA, the UK and Switzerland, nothing is sent unless you say yes. The consent message described in Section 7 includes a purpose for these statistics. If you consent to that purpose, the App collects what this Section describes; if you decline it, or do not answer, nothing is sent at all — not a reduced set, nothing. You can change your answer at any time from Main menu → Settings → Ad and privacy settings; a withdrawal takes effect immediately and discards the identifier described above. Whether a consent message is required for you at all is decided by Google’s consent system, from the message we publish for those regions — the same mechanism that already decides whether the advertising in Section 3(b) is personalised there. The App does not work out your location itself, and does not try to.
Everywhere else, it is on unless you turn it off. The switch at Main menu → Settings → Share usage statistics starts in the on position. Turning it off stops the collection immediately and completely, and also discards the identifier described above, so that switching it back on later starts a new one rather than resuming the old. Section 4 sets out the legal basis, which outside those regions is our legitimate interest in understanding how the game is played, with that opt-out always available.
What is collected, where it is active — every fact, in plain words
Every item below is one of a fixed list of words chosen in advance by the App, or a band. Nothing is free text, nothing is a precise time, nothing is recorded per move, and your score is never sent.
Your games
- that a game started, and through which of three doors: the main menu, the “Play again” button after a game, or the end of the tutorial;
- that a game ended, with: roughly how many turns it lasted, as one of six bands (under 20, 20–49, 50–99, 100–199, 200–399, 400 or more); the rank band the game showed you at that moment (one of twelve fixed values such as “top 30%” — an estimate from simulated games, not your score); which of the App’s named difficulty rungs you had reached; how many extra lives you had taken in that game (0, 1 or 2); and whether the game had given you its one “second chance”;
- that a second chance was used, and roughly how many turns into the game, in the same bands;
- that you reached a new difficulty rung, and which one — once per rung per game;
- that you set a new personal best, with the rank band at that moment — once per game, and never the score itself.
The tutorial and the rules
- that the “New here?” offer was shown, and how it was answered: play, skip, or closed;
- that the tutorial was opened, and from where: that offer, “How to play” on the main menu, or “How to play” inside a game;
- that the tutorial ended, and how: finished or skipped;
- that “How to play” was opened, from the menu or from inside a game.
The two optional video offers
- that an offer was put on the screen — the extra life after a game, or a board colour unlock;
- that you accepted an offer by pressing the button that names the video;
- that the feature was handed over, and why: the video played through; the video could not be shown and the feature was given anyway; or no video was available and the feature was given anyway. For a board colour unlock, which of the five colours it was;
- that you were offered an extra life and chose “Play again” instead, and how many extra lives you had already taken in that game.
Your settings
- that you changed a setting, which of three it was, and the new value: sound on or off; light or dark theme; or the language you chose from the App’s own list (or “follow the phone”);
- which board colour you selected from the gallery — one of six names.
Where your installation came from
- which link brought you to the App’s store page, once per installation, as three words from a fixed list: whether the link was in our torch app, Shake to Enable Torch, or was Google Play itself; the name of our one promotion; and, for the torch app, which of its four buttons. Any other link is recorded only as “other”, and a missing one as “none”. The link’s own text is never sent. Google Play supplies this to the App once, after installation; the App keeps the three words on your device until the statistics are permitted to be sent, sends them once, and never again. Google’s SDK records the same fact by itself (see below); this is the App’s own copy of it.
Two facts about the current state of your installation are kept alongside these events rather than sent with each one: the board colour in use, and whether the theme is light or dark.
Collected automatically by Google. Once the switch above is on, Google’s SDK also records, on its own: the first opening after installation; each opening; the start of a session and roughly how long it lasted; an App update; an operating-system update; a screen view each time the App’s single screen comes to the front; where Google Play tells the SDK that your installation came from a campaign link, that campaign’s name, source and medium; that an advert was shown, where Google’s advertising SDK reports that to the same system; and an approximate country or region derived by Google from the IP address. Google also records the device model, operating-system version, App version and language with each event.
What is deliberately not collected. No advertising identifier is used for this purpose — the App switches that off explicitly, and the advertising identifier described in Section 3(b) is used by the advertising SDK alone. No free text of any kind. No precise timestamps as data fields. No record of individual moves, placements or tilts. No score, no saved game, no best score. No setting other than the four named above. No contacts, no location from the device, no account.
The identifier. Google’s app-instance identifier is random, scoped to this App on this device, and resettable: turning the switch off discards it, and clearing the App’s data or uninstalling removes it. It is not the Android advertising ID, and no advertising identifier is collected for this purpose; the link between our AdMob account and this analytics property, described in Section 5, carries advertising revenue totals into our reports and does not make these statistics available for personalising advertising.
One exception to “discards it”, stated for accuracy: if you switch the statistics off in a session where nothing had yet been sent, the analytics component was never started, so there is nothing for the App to reset — the identifier stays dormant on your device, unused for as long as the switch is off, and could be resumed if you switch the statistics back on; clearing the App’s data or uninstalling removes it in every case.
The provider. Google Analytics for Firebase (GA4), supplied by Google. The data is encrypted in transit by Google’s own TLS. Retention is described in Section 8, and the countries it may reach in Section 6.
3(e). What the App does NOT do
For the avoidance of doubt, the App contains no crash-reporting SDK, no attribution or install-tracking SDK, no social login and no in-app purchases. Apart from the Google advertising and consent components named in 3(b), the analytics component named in 3(d), and the single static-file request described in 3(c), the App makes no network requests of any kind.
4. Why we process data, and the legal basis for each purpose (GDPR)
Where the EU/UK GDPR applies to you:
| Purpose | Data | Legal basis |
|---|---|---|
| Running the game (score, saved run, settings) | Section 3(a), on-device only | Not personal data processing by us — the data never reaches us. To the extent it is processing, it is necessary to perform the service you asked for (Art. 6(1)(b)). |
| Showing personalized ads | Section 3(b) | Your consent (Art. 6(1)(a)), collected through the in-app consent message described in Section 7. Where the IAB Transparency and Consent Framework permits it, some of Google's advertising partners rely on their own legitimate interests (Art. 6(1)(f)) for parts of this processing instead of consent. The consent message names which partners do so, and lets you object to each of them individually. |
| Checking whether ads are switched on | Section 3(c): the IP address the request comes from, seen by the file host | Legitimate interests (Art. 6(1)(f)) in being able to switch advertising off without shipping a release. No identifier is sent, and we receive nothing. |
| Showing non-personalized ads where you refuse personalization | Section 3(b), limited | Your consent where required for storing/accessing information on your device, and Google’s legitimate interests in fraud prevention and basic ad delivery (Art. 6(1)(f)). |
| Fraud and abuse prevention in advertising | Section 3(b) | Legitimate interests (Art. 6(1)(f)) of Google and advertisers in preventing invalid traffic. |
| Usage statistics (Section 3(d)) | The pseudonymous events listed in Section 3(d), the app-instance identifier and the IP address Google sees | In the EEA, the UK and Switzerland: your consent (Art. 6(1)(a) GDPR, and Art. 5(3) of the ePrivacy Directive for the identifier stored on your device), taken through the consent message described in Section 7; nothing is collected until it is given, and a withdrawal stops it immediately. Everywhere else: our legitimate interest (Art. 6(1)(f)) in understanding how the game is played, with the in-app opt-out available at any time and effective the moment it is used. |
If you refuse consent, the App keeps working in full. You are not shown fewer features, and the extra life offered at the end of a game is granted for free when no ad can be shown.
5. Who receives data (third parties / recipients)
- Google Ireland Limited / Google LLC — as the provider of Google AdMob and the Google User Messaging Platform (the consent tool). Google’s own privacy policy: https://policies.google.com/privacy. How Google uses data from apps that use its services: https://policies.google.com/technologies/partner-sites.
- Google Ireland Limited / Google LLC again, in a separate role — the same two companies, operating Google Analytics for Firebase, which receives the usage statistics described in Section 3(d) where they are switched on. We decide what is collected there and why; Google acts as our analytics provider, and processes the data additionally for its own purposes as described in the policies linked above. Our AdMob account and this analytics property are linked, which is what lets the advertising revenue totals Google already holds appear in our analytics reports — as a total earned from a coarse group of players, never from any one of them. That link runs in one direction only: the usage statistics are not used to personalise advertising — the setting that would allow it is switched off for every region, and Google signals, the feature that would associate this data with a signed-in Google account, is off — and the analytics component collects no advertising identifier, so the identifier described in Section 3(b) remains the advertising SDK’s alone. The consent rules in Section 7 are unchanged by the link: nothing is sent for this purpose in the EEA, the UK or Switzerland, and everywhere else the switch described in Section 3(d) decides.
- Google’s advertising partners, where you consent to personalized ads. The current list of partners is presented to you inside the consent message and can be reviewed there at any time.
- GitHub, Inc. — only as the host of the one static text file described in Section 3(c). It receives the IP address that request is made from, and nothing else. GitHub's privacy statement: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement.
The Developer discloses your data to no one else. We do not sell data, and we have nothing to sell — see Section 9.
6. International data transfers
The Developer neither receives nor stores any of this data, and so transfers none of it. That is not the same as saying nothing leaves your device: the App is designed to cause requests to the recipients named in Section 5, and those recipients may process what they receive outside the EEA and the UK.
The static file described in Section 3(c) is served by GitHub, Inc., a company based in the United States, so the IP address that request is made from is received there.
The usage statistics described in Section 3(d) are sent to Google Analytics for Firebase, and Google may process and store them outside the EEA and the UK, including in the United States, under the same safeguards Google states below. In the EEA, the UK and Switzerland this happens only where you have consented under Section 3(d); otherwise nothing is sent for that purpose, so there is nothing to transfer.
Google, as an independent controller for advertising data, may transfer that data outside the EEA/UK, including to the United States. Google states that it relies on the European Commission’s Standard Contractual Clauses and, for transfers to the US, on the EU–US Data Privacy Framework where applicable. Details are in Google’s own privacy documentation linked in Section 5.
7. Consent and how to change or withdraw it
In the EEA, the UK, and Switzerland
Before the App requests any ad, it shows a consent message provided through the Google User Messaging Platform. No ad is requested until you have answered it.
You can change or withdraw your choice at any time:
Main menu → Settings → Ad and privacy settings
That row appears in the App only where a standing consent entry point is required, which is exactly the region where you have the right to withdraw. Opening it reloads the same consent message so you can change any choice, including withdrawing consent entirely.
The same consent message governs the usage statistics in Section 3(d): it carries a purpose for them, nothing in Section 3(d) is collected in these regions until you consent to that purpose, and withdrawing it here stops the collection at once. Outside these regions, the control is the switch at Main menu → Settings → Share usage statistics, which appears only where no consent message is required. The App asks Google’s consent component whether a message is required at every start, including when advertising is switched off remotely (Section 3(c)); outside these regions that check shows nothing.
Everywhere — controlling your Advertising ID at the Android level
Independently of the App, Android lets you control the advertising identifier:
Settings → Google → Ads (wording varies by device and Android version)
There you can delete or reset your Advertising ID, and on Android 12 and later you can remove it entirely, after which apps receive a string of zeroes instead.
Children
See Section 10. The App is not directed to children.
8. Data retention — how long data is kept
- On-device data (Section 3(a)): kept until you delete it, by clearing the App’s storage or uninstalling the App. We have no copy and therefore no retention period of our own.
- Advertising data (Section 3(b)): retained by Google according to Google’s own retention schedules, which are described in Google’s privacy documentation. The Developer holds none of it and cannot delete it on your behalf; requests concerning it should be directed to Google, and we will help where we can.
- Usage statistics (Section 3(d)): event-level data is kept by Google for 2 months — the shortest period Google offers, and the value a new property carries by default. It is a setting in the Google Analytics console, applied to the whole property, and if we ever lengthen it this policy will say so before we do. The random app-instance identifier is discarded when you turn the switch off, when you clear the App’s data, or when you uninstall.
- The static-file request (Section 3(c)): whatever server log GitHub keeps is subject to GitHub's own retention schedule. We receive no such log and hold nothing from it.
9. Your privacy rights
If you are in the EEA, the UK, or Switzerland (GDPR / UK GDPR)
You have the right to access, rectify, erase, restrict, and object to processing of your personal data, the right to data portability, and the right to withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
Practically:
- For the on-device data, you can exercise all of these yourself, instantly, by clearing the App’s data or uninstalling it. We cannot access it, so we cannot act on it for you.
- For the advertising data, the controller in practice is Google. Requests should be addressed to Google using the contacts in Google’s privacy policy. Write to luxebytecomp@gmail.com as well and we will do what we can to assist and to point you to the right place.
You also have the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or place of the alleged infringement.
If you are in California (CCPA/CPRA) or another US state with a privacy law
We do not sell your personal information, and we receive none of it ourselves.
We do not claim that no “sharing” takes place. Showing a personalized ad means advertising data is made available to Google and its partners for cross-context behavioural advertising, and that is capable of being “sharing” as the CCPA and CPRA define it, whether or not the Developer ever holds the data. Rather than argue that point, the App gives you the opt-out:
- In the App: Main menu → Settings → Ad and privacy settings, which opens a US state privacy message where you can opt out of that use. As in the EEA, the row appears where such a message applies to you.
- On the device: the Android Advertising ID controls described in Section 7, which apply wherever you are.
You may also request access to, or deletion of, personal information we hold about you. We hold none, and we will tell you so.
10. Children’s privacy
The App is not directed to children and its Play Store target audience is declared accordingly. We do not knowingly collect personal data from children.
We are aware that a colourful puzzle game can attract younger players. If you believe a child has used the App in a way that resulted in personal data being processed, contact luxebytecomp@gmail.com and we will help you direct the request to Google, who holds the data.
If the App’s declared target audience ever changes to include children, the advertising configuration will change with it — child-directed treatment will be signalled to the ads SDK and the advertising identifier permission will be removed — and this policy will be updated before that release ships.
11. Security
The App stores its data using Android’s standard app-private storage, which the operating system isolates from other apps. We hold no servers, no databases and no accounts, which removes an entire category of risk: there is no place for us to be breached.
No method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security of data handled by third parties such as Google.
12. Changes to this policy and how you are notified
Material changes are published at the same address as this document, with an updated “Last updated” date, before or when they take effect. Where a change concerns advertising consent you may be asked again through the in-app consent message.
13. How to contact us about privacy
Write to us with any question, any request, or to tell us this policy is wrong about something. We would rather fix it than defend it.