Last updated: August 8, 2026

Anthony Daigle, operating under the DayGull Studio Labs name (“DayGull,” “we,” “us”), operates Grids & Aces. This policy explains how information is handled when you use the app, its community features, and related services.

Information we handle

Account and profile

We use Firebase Authentication for guest and protected sign-in. Depending on how you use the service, we may store a Firebase user identifier, sign-in provider, display name, player code, selected preset avatar, profile preferences, account state, and identifiers used to connect guest and protected account activity. Apple, Google, or another sign-in provider handles the credentials it collects under its own policy; we do not receive your provider password.

Gameplay, social, and community activity

We store puzzle access and unlock records, progress and answers, completion and result data, favorites, parties and multiplayer sessions, presence, invitations, join requests, social connections and follows, activity items, reports, and other information needed to provide, secure, and restore play. Public profile information and activity you choose to publish may be visible to other users.

Creator content and moderation

If you create or publish puzzles, themes, grids, clues, descriptions, or other material, we store the submission, drafts and versions, creator attribution, publication state, engagement totals, review results, moderation findings, reports, and staff actions. Published material and attribution are intended to be public.

Assets, notifications, and service operations

Firebase Storage delivers app-managed assets such as the preset avatar catalog; the current profile experience does not offer general user photo or file uploads. Firebase Cloud Messaging uses an installation identifier, push token, platform, and app version to deliver notifications you allow. Firebase Functions and our service providers process requests and may generate security, diagnostic, rate-limit, and operational logs, including IP address and request metadata.

Purchases and entitlements

Apple processes App Store purchases. We receive and store signed transaction or receipt information and entitlement details needed to validate, restore, reconcile, and prevent misuse of Grids & Aces+, such as product, transaction, ownership, renewal, expiration, revocation, and account-linking status. We do not receive or store your full card number.

Usage analytics

We maintain custom product-usage and creator-performance records such as puzzle impressions, opens, starts, completions, unlocks, multiplayer activity, theme use, and content engagement. These records can include content, account, profile, session, or device-related identifiers and timestamps before they are summarized. Custom events are sent through our Firebase Functions and stored in Firestore; Firebase Analytics collection is disabled in the current production configuration.

Advertising and consent

Eligible free players may see Google Mobile Ads. Before requesting ads, the app uses Google’s User Messaging Platform (UMP) to collect or update privacy choices where required and requests ads only when UMP reports that ads may be requested. The current app configures Google’s Limited Ads mode before the ads SDK starts, disables Google’s publisher first-party identifier, and sends an explicit non-personalized request. It does not request Apple’s App Tracking Transparency permission or Android’s advertising-ID permission. Google and its advertising partners may still receive IP address, app and device information, ad impressions and interactions, fraud-prevention signals, diagnostics, and approximate location such as a general area inferred from IP address to deliver and protect contextual ads. We do not request precise GPS location for advertising. A privacy-options entry point is available when required.

How we use information

Service providers and sharing

We share information as needed with providers that run the service, including Google Firebase services (Authentication, Firestore, Storage, Functions, and Cloud Messaging), Google Mobile Ads and UMP, Apple for App Store purchases and Sign in with Apple, Google for Google sign-in, and infrastructure or support providers. These companies process information under their own terms and privacy policies.

We may also disclose information when required by law, to protect rights or safety, during a business transaction, or with your direction. Community content and public profile information are shared with other users by design.

We do not sell personal information for money. Advertising-related disclosures may nevertheless be considered “sale,” “sharing,” or targeted advertising under some privacy laws. Where required, we provide consent or opt-out choices through the app and Google’s privacy tools.

Retention

We keep account, entitlement, active-game, social, and creator records while needed to provide the service. Published content may remain available until it is removed or anonymized. Detailed live game-session data is normally removed after 30 days, empty disbanded party data after seven days, and quick-chat messages after 30 days; active resumable games are not automatically removed on that schedule. Invitations, join requests, and similar coordination records expire according to their functional window.

After deletion or unpublishing, limited copies may remain temporarily in backups, transaction reconciliation, fraud-prevention, security, moderation, or legal records. Aggregated or de-identified statistics may be retained when they no longer reasonably identify you.

Your choices and requests

A short-lived hashed completion receipt and minimized purchase, fraud-prevention, moderation, security, or legal records may remain where required. We may ask for information needed to verify your identity and authority for support requests.

Security and international processing

We use technical and organizational safeguards intended to protect information, but no online service can guarantee absolute security. Our providers may process information in the United States and other countries where they operate, subject to the protections required by applicable law.

Children

The service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information contrary to this policy, contact us so we can investigate and take appropriate action.

Changes and contact

We may update this policy as the service changes. We will post the revised date here and provide additional notice when required.

Email privacy questions or requests to support@gridsandaces.com.