Sugaku

Privacy Policy

Effective 11 August 2026 · Applies to the Sugaku mobile game on iOS and Android

The short version

1. Who is responsible

Sugaku is developed and published by Martin Pisacic, an individual developer established in the European Union, acting as the data controller for the limited personal data described here.

Questions, requests, and complaints: pisacic.martin2@gmail.com.

This policy covers the Sugaku mobile app. This web page itself is a static document: it sets no cookies, runs no analytics, and loads nothing from third-party servers.

2. Data kept only on your device

Most of what Sugaku remembers never leaves your phone. It is written to the app's private storage, which is removed when you uninstall the app. We cannot read it, and it is not backed up to any server of ours.

The random identifier is created on your device and is not derived from any hardware identifier, advertising identifier, or anything else that would let it be linked back to you or followed into another app.

3. The leaderboard

The leaderboard is optional. Until you create a profile and choose a display name, Sugaku sends nothing about you to our server and the game is fully playable offline.

Once you have a profile, the app contacts our leaderboard service when you claim or change a name, when it checks whether a name is already taken, when a competitive game ends, when the rankings screen is opened, and when you delete your profile. Our server stores exactly four values per player:

Stored value What it is
user_id The random identifier generated on your device. It is how your row is found and deleted.
name The display name you chose, up to 20 characters. Names are unique across all players.
score Your best competitive score. A submission can only raise it, never lower it.
updated_at When that row last changed, used to break ties on the board.

When a score is submitted, the app sends your identifier, your name, your score, and your locally held skill level; the server keeps only the four values above and discards the rest. No game history, no per-round detail, and no device information are sent.

The leaderboard is public. Any player who opens the rankings screen sees the display names and scores on it. Please pick a nickname rather than your real name, an email address, or anything else you would not want shown publicly. Because names must be unique, the name you type is also checked against the server as you type it.

The service runs on Cloudflare Workers with a Cloudflare D1 database. As with any internet request, Cloudflare processes connection data such as your IP address in order to deliver the request and protect the service from abuse. We do not store IP addresses in our database and cannot link one to a leaderboard entry.

Scores are calculated on your device and reported by the app. We do not profile you, rank you against other players beyond the public board, or make any automated decision that has a legal or similarly significant effect on you.

4. Usage statistics and crash reports

Sugaku uses two Google Firebase services: Analytics, to understand which parts of the game get used, and Crashlytics, to find out when and where the app crashes.

Both are disabled in the build itself and stay off until you accept this policy on the first screen. You can turn either one off, permanently and independently, under Settings → Send crash reports and Settings → Send usage statistics. Turning them off stops collection from that moment on.

Events the app records

When usage statistics are on, the app records these events, and nothing else:

Event Recorded when Details attached
casual_game_launch A casual game is started
competitive_game_launch A competitive game is started
game_completed A game finishes Game mode and final score
game_exited A game is left early
play_again_pressed Play again is tapped
tutorial_launch A tutorial is opened Which mode
scores_launch The rankings screen is opened
profile_launch The profile screen is opened
achievement_unlocked An achievement is earned Achievement id and tier
user_create / user_delete A profile is created or deleted

Your display name and your leaderboard identifier are never attached to these events. The app does not set a user id or any user property in Analytics, so the analytics data is not connected to your leaderboard entry.

What Google collects automatically

Firebase adds its own technical data to each event, which is standard for these SDKs and outside the app's control. It typically includes an app instance identifier generated by Firebase, device model and operating system version, app version, language, and an approximate country or region derived from the IP address. Crashlytics additionally collects crash stack traces, the state of the app at the moment of the crash, and a Crashlytics installation identifier. Firebase's own handling of this data is described in Firebase's privacy documentation and Google's privacy policy.

Analytics is configured so that Google's advertising features are not used: Sugaku collects no advertising identifier (no IDFA on iOS, no Google Advertising ID on Android), shows no ads, and does not track you across other companies' apps or websites. This is why the app never asks for App Tracking Transparency permission on iOS.

5. What we never collect

6. Device permissions

Sugaku requests only what it needs to run: network access, for the leaderboard and for the services above, and vibration, for the haptic feedback during play. It requests no runtime permission that would show you a system prompt.

Under the GDPR, we rely on the following legal bases:

8. Age requirements

Sugaku is not directed at children. On first launch the app asks for your region and age and will not continue unless you are at least 16 in the EU, or at least 13 in the United States and elsewhere.

We do not knowingly collect data from anyone below those ages. If you are a parent or guardian and believe a child has used the app and created a leaderboard entry, contact us at pisacic.martin2@gmail.com and we will delete it. Deleting the profile in the app, or uninstalling it, also removes the data.

9. Service providers and international transfers

Both providers may process data outside the European Economic Area, including in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. We use no other processors, and we do not disclose your data to anyone else except where the law requires it.

10. How long data is kept

11. Deleting your data

  1. Delete your leaderboard entry: open Profile in the app and delete your profile. This removes your row from our database — identifier, name, and score — and removes the profile from your device. It is immediate and cannot be undone.
  2. Stop analytics and crash reports: switch them off in Settings.
  3. Remove everything held locally: uninstall the app, which deletes its private storage including statistics and achievements.

If you have already uninstalled the app and want a leaderboard entry removed, email us the display name from pisacic.martin2@gmail.com and we will remove that row.

12. Your rights under the GDPR

If you are in the EEA, the UK, or Switzerland, you have the right to request access to your personal data, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent at any time.

In practice most of these are immediate and in your hands: your leaderboard entry is visible to you on the rankings screen, the display name can be changed in the app, the entry can be deleted in the app, and consent for analytics and crash reporting is a switch in Settings.

For anything else, write to pisacic.martin2@gmail.com. We will respond within one month. Because there are no accounts, please include the display name — and, if you still have the app installed, be aware that we may be unable to verify a request beyond what the app itself already lets you do.

You also have the right to lodge a complaint with your national data protection supervisory authority.

13. California residents

In the twelve months before the date of this policy, the categories of personal information Sugaku handles are: identifiers (a device-generated random identifier and a display name you choose) and internet or other electronic network activity information (the in-app events listed above, when you have usage statistics on). Both are used only to operate the leaderboard and to understand and improve the game.

We do not sell personal information and do not share it for cross-context behavioural advertising, including for anyone under 16. You have the right to know, delete, and correct your information, and not to be discriminated against for exercising those rights — use the in-app controls above or write to pisacic.martin2@gmail.com.

14. Security

All traffic between the app and our service uses HTTPS. The leaderboard holds no credentials, no passwords, and no contact details, so there is no login to compromise. Data on your device is kept in the app's private storage, which other apps cannot read. No system is perfectly secure, but the amount of personal data involved here is deliberately kept as small as the game allows.

15. Changes to this policy

If this policy changes, the revised version is published on this page with a new effective date. Material changes to what is collected will be reflected in the app before they take effect, and where the law requires it we will ask for your consent again.

16. Contact

Martin Pisacic
Sugaku
pisacic.martin2@gmail.com