Skip to content
GRIDS & ACES
HomeSupportCommunity

Your information

Privacy Policy

Version: v2026-09-27-privacy-04 Effective: September 27, 2026

Daygull Studios LLC ("Daygull Studios," "we," "us") operates Grids & Aces. This policy explains how information is handled when you use the app, its community features, and related services.

Information we handle

Account and profile

We use Firebase Authentication for guest and protected sign-in. Depending on how you use the service, we may store a Firebase user identifier, sign-in provider, display name, player code, selected preset avatar, profile preferences, account state, and identifiers used to connect guest and protected account activity. For protected accounts, we also retain records showing the version and fingerprint of legal terms accepted, the accepting account, server-recorded acceptance time, and app build. Apple, Google, or another sign-in provider handles the credentials it collects under its own policy; we do not receive your Apple or Google password. For a preconfigured email-sign-in account, the app sends the email address and password securely to Firebase Authentication for verification. The app does not save or log that password, and our gameplay database does not store it. Firebase manages password credentials and requested password-reset emails.

Gameplay, social, and community activity

We store puzzle access and unlock records, progress and answers, completion and result data, favorites, Parties and multiplayer sessions, presence, invitations, join requests, social connections and follows, activity items, reports, and other information needed to provide, secure, and restore play. Public profile information and activity you choose to publish may be visible to other users. Blocking, reporting, moderation, and copyright-complaint records may include the people, content, communications, reasons, evidence, and actions needed to investigate and enforce our rules.

Creator content and moderation

If you create or publish puzzles, themes, grids, clues, descriptions, or other material, we store the submission, drafts and versions, creator attribution, publication state, engagement totals, review results, moderation findings, reports, and staff actions. Published material and attribution are intended to be public. Creator Content that you submit, share, or publish, together with selected attribution, may also appear in commercial digital or physical publications, merchandise, and related marketing as described in the Creator Terms.

Assets, notifications, and service operations

Firebase Storage delivers app-managed assets such as the preset avatar catalog; the current profile experience does not offer general user photo or file uploads. Firebase Cloud Messaging uses an installation identifier, push token, platform, and app version to deliver notifications you allow. Firebase Functions and our service providers process requests and may generate security, diagnostic, rate-limit, and operational logs, including IP address and request metadata.

Security, crash, and performance diagnostics

Firebase App Check processes app and device attestation information and installation identifiers to help distinguish authentic app requests and deter abuse. In production builds, Firebase Crashlytics processes crash and nonfatal error reports, which may include installation identifiers, timestamps, app version, device and operating-system information, relevant application state, and stack traces. Firebase Performance Monitoring processes installation identifiers, IP-derived country, app-start and screen-rendering timing, and HTTP/S request performance such as destination, duration, response code, and payload size. We use this information to secure the Service, find failures, and improve reliability. We do not attach names, email addresses, free-text user IDs, or message or puzzle content to Crashlytics or Performance Monitoring.

Purchases and entitlements

Apple processes App Store purchases and Google processes Google Play purchases. Where Web billing is available, Stripe processes payments through its hosted checkout and billing pages. The payment provider handles the payment information you submit under its own privacy policy. We do not receive or store your full card number.

We receive and store transaction or receipt information, purchase tokens, provider customer and subscription identifiers, and entitlement details needed to validate, restore, reconcile, and prevent misuse of Grids & Aces+. These records include product, transaction or invoice, ownership, payment and renewal status, expiration, cancellation, refund or revocation, and identifiers linking the purchase to your account. Availability of a payment method depends on the platform and release; describing Web billing here does not mean it is available to every player.

Usage analytics

We maintain custom product-usage and creator-performance records such as puzzle impressions, opens, starts, completions, unlocks, multiplayer activity, theme use, and content engagement. These records can include content, account, profile, session, or device-related identifiers and timestamps before they are summarized. Custom events are sent through our Firebase Functions and stored in Firestore; Firebase Analytics collection is disabled in the current production configuration.

Advertising and consent

Eligible free players may see Google Mobile Ads. Before requesting ads, the app uses Google's User Messaging Platform (UMP) to collect or update privacy choices where required and requests ads only when UMP reports that ads may be requested. The current app configures Google's Limited Ads mode before the ads SDK starts, disables Google's publisher first-party identifier, and sends an explicit non-personalized request. It does not request Apple's App Tracking Transparency permission or Android's advertising-ID permission. Google and its advertising partners may still receive IP address, app and device information, ad impressions and interactions, fraud-prevention signals, diagnostics, and approximate location such as a general area inferred from IP address to deliver and protect contextual ads. We do not request precise GPS location for advertising. Ad software and creatives may be cached on your device. With programmatic Limited Ads enabled, Google also uses cookies and local storage solely for invalid-traffic detection and fraud prevention on eligible limited-ad requests, including when you decline consent for personalized advertising. Limited Ads therefore does not mean that no information is processed or stored. A privacy-options entry point is available when required.

How we use information

We use information to:

  • provide authentication, profiles, games, multiplayer, social features, creator tools, notifications, and support;
  • validate unlocks, purchases, subscriptions, restoration, and access rights;
  • rank and recommend community content, calculate creator and gameplay statistics, and improve reliability and design;
  • review content, enforce rules, investigate reports, prevent fraud and abuse, and protect users and the service; and
  • comply with legal obligations and establish, exercise, or defend legal claims.

Service providers and sharing

We share information as needed with providers that run the service, including Google Firebase services (Authentication, App Check, Firestore, Storage, Functions, Cloud Messaging, Crashlytics, and Performance Monitoring), Google Mobile Ads and UMP, Apple for App Store purchases and Sign in with Apple, Google for Google Play purchases and Google sign-in, Stripe for Web payment processing and subscription management where available, and infrastructure or support providers. When authorized by the Creator Terms, we may also provide selected Creator Content and attribution to publishers, editors, printers, manufacturers, distributors, retailers, licensees, and marketing partners. These companies process information under their own terms and privacy policies.

We may also disclose information when required by law, to protect rights or safety, or with your direction. If we consider or complete a financing, merger, acquisition, reorganization, change of control, or sale of Grids & Aces or related service assets, information may be reviewed or transferred as part of that transaction, subject to appropriate safeguards and applicable law. A successor's handling of personal information remains subject to this policy unless and until it provides notice of a lawful change. Community content and public profile information are shared with other users by design.

We do not sell personal information for money. Advertising-related disclosures may nevertheless be considered "sale," "sharing," or targeted advertising under some privacy laws. Where required, we provide consent or opt-out choices through the app and Google's privacy tools.

Retention

We keep account, entitlement, active-game, social, and creator records while needed to provide the service. Published content may remain available until it is removed or anonymized. Detailed live game-session data is normally removed after 30 days, empty disbanded party data after seven days, and quick-chat messages after 30 days; active resumable games are not automatically removed on that schedule. Invitations, join requests, and similar coordination records expire according to their functional window.

After deletion or unpublishing, limited copies may remain temporarily in backups, transaction reconciliation, fraud-prevention, security, moderation, or legal records. Aggregated or de-identified statistics may be retained when they no longer reasonably identify you.

Your choices and privacy requests

  • Change available profile, notification, and advertising privacy settings in the app or device settings.
  • Guest and protected accounts can choose **Settings → Account deletion → Delete account permanently**. The app requires the exact confirmation DELETE. Protected accounts must verify again with a linked provider. An Apple-linked account must verify with Apple so the app can revoke its Apple authorization before backend deletion. Guest accounts use their current anonymous session as deletion authority.
  • Deletion removes the Firebase authentication account and identity-scoped profile, progress, unlock, social, creator, and uploaded data. Shared multiplayer records may remain only after the active identity is removed or replaced with a pseudonymous deleted-player label that is no longer connected to an active profile. Cleanup is retry-safe: authentication is removed last so interrupted cleanup can be retried. A short-lived hashed completion receipt and minimized purchase, fraud-prevention, moderation, security, or legal records may remain where required.
  • Manage or cancel a subscription through the provider used for that purchase: Apple subscription settings for App Store purchases, Google Play subscription settings for Google Play purchases, or the Stripe-hosted billing portal reached through Web subscription management where available. Account deletion and subscription cancellation are separate actions; deleting or signing out of a Grids & Aces account does not cancel a subscription or stop provider billing.
  • Contact us for access, correction, a narrower deletion request, or help with creator content.

We may ask for information needed to verify your identity and authority. Requests are handled subject to applicable law and legitimate retention requirements. Depending on where you live and whether the relevant law applies to Daygull Studios, you may have rights to know, access, correct, delete, or obtain a copy of certain personal information; opt out of certain sale, sharing, targeted advertising, or profiling; restrict or object to certain processing; withdraw consent; or appeal a denied request. We will not unlawfully discriminate against you for exercising a privacy right.

An authorized agent may submit a request where applicable law permits. We may require evidence of the agent's authority and may ask you to verify the request directly. If we deny an appealable request, our response will explain how to appeal. Submit privacy requests or appeals to legal@daygullstudios.com with "Privacy Request" in the subject. Do not send passwords, government identity numbers, or payment-card information.

Security and international processing

We use technical and organizational safeguards intended to protect information, but no online service can guarantee absolute security. Our providers may process information in the United States and other countries where they operate, subject to the protections required by applicable law. Where required for an international transfer, we rely on an available lawful transfer mechanism or another legally recognized basis.

Children

The service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information contrary to this policy, contact us so we can investigate and take appropriate action.

Changes and contact

We may update this policy as the Service, providers, and law change. We will post the current version and effective date and provide additional notice when required. Material changes to the Terms of Service may require separate affirmative acceptance; this Privacy Policy is a notice describing our practices.

Email privacy questions, requests, or appeals to legal@daygullstudios.com. General product support remains available at support@gridsandaces.com.

GRIDS & ACES
SupportPrivacyTermsCommunityCopyrightSubscriptionsCreators
Grids & Aces is operated by Daygull Studios LLC. Product availability varies during storefront rollout. Contact support@gridsandaces.com.