1. Introduction & Scope
- Welcome. This Privacy Policy ("Policy") describes how Yash Rayjada, operating as YBR Digital ("we", "us", "our"), the developer and operator of Crack The Code: Brain Puzzle ("Crack The Code", "the App", "the Service"), collects, uses, stores, shares, and protects information obtained from users ("you", "your", "Player") of the App on the Android (Google Play Store) and iOS (Apple App Store) platforms.
- Acceptance. By downloading, installing, accessing, or using Crack The Code, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with any provision of this Policy, you must immediately cease all use of the App and uninstall it from your device.
- Data Controller. For the purposes of the EU General Data Protection Regulation (GDPR), the data controller is:
Yash Rayjada (operating as YBR Digital)
Website: www.ybrdigital.in
Email: info@ybridigital.in - Scope. This Policy applies to all information collected through the App, including but not limited to: gameplay data, device telemetry, virtual economy transaction records, advertising interaction data, and subscription management information. The App operates in a fully offline mode — all gameplay data is stored exclusively on your device and is permanently deleted when the App is uninstalled.
"Personal Data" means any information relating to an identified or identifiable natural person, as defined under the GDPR, CCPA/CPRA, and other applicable privacy legislation.
"Processing" means any operation performed on Personal Data, whether automated or manual, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, or erasure.
2. Information We Collect
2.1 Information Automatically Collected
When you install and use Crack The Code, we and our integrated third-party service providers may automatically collect the following categories of data:
| Data Category | Examples | Purpose |
|---|---|---|
| Device Identifiers | Google Advertising ID (GAID), Apple Identifier for Advertisers (IDFA), Android ID | Ad personalization, analytics attribution, fraud prevention |
| Network & Connection | IP address (truncated where required), connection type (Wi-Fi/cellular), carrier information | Content delivery, approximate geolocation for compliance, analytics |
| Device Technical Data | Operating system & version, device manufacturer & model, screen resolution, system language, time zone | App compatibility, bug diagnosis, performance optimization |
| Diagnostic & Crash Data | Crash logs, ANR (Application Not Responding) reports, stack traces, performance metrics | Stability monitoring, bug fixes (via Firebase Crashlytics) |
| Session & Engagement | Session start/end timestamps, session duration, app foreground/background events | Usage analytics, feature engagement analysis |
| Gameplay Progression Telemetry | Level completion status, solve times, accuracy rates, hint usage frequency, current progression stage across 1000+ levels | Game balancing, difficulty calibration, player experience optimization |
2.2 Virtual Economy & Transaction Records
Crack The Code features an in-game virtual economy comprising Coins/Credits, hint consumables, and lifeline tools. We collect and process the following transaction-related data:
- Purchase Tokens & Order IDs: Platform-issued purchase verification tokens from Google Play Billing or Apple StoreKit to validate and fulfill in-app purchases.
- Subscription Status: Active/inactive subscription state, subscription tier (Weekly, Monthly, Annual, Lifetime VIP Gold), renewal dates, and cancellation status.
- Coin Balances & Transaction Logs: Current coin wallet balance, coin earning events (rewarded ads, daily bonuses), and coin consumption records (hint purchases, lifeline activations). All coin and transaction data is stored locally on your device only.
We do not collect, store, or process raw credit card numbers, bank account details, or any direct payment instrument data. All financial transactions are processed exclusively and securely through Google Play Billing or Apple App Store In-App Purchase infrastructure. Please refer to Google's Privacy Policy and Apple's Privacy Policy for details on how these platforms handle your payment information.
2.3 Feature-Specific Data
The following data is collected in connection with specific features of the App. All feature-specific data is stored exclusively on your device and is permanently deleted when you uninstall the App:
| Feature | Data Collected | Storage |
|---|---|---|
| Daily Puzzles & Streaks | Daily challenge completion timestamps, current streak count, longest streak record, streak freeze usage, streak recovery events | Local only (SQLite / SharedPreferences) |
| Player Statistics & Performance Analytics | Cumulative solve rates, average solve times, accuracy metrics, milestone achievement records, performance graph data points | Local only (SQLite / SharedPreferences) |
| Smart Hints & Lifeline Usage | Number of hints consumed (position reveal, eliminator, solution unlock), frequency of lifeline activation per session | Local only (SQLite / SharedPreferences) |
| Virtual Economy | Coin wallet balance, coin earning history, coin spending history | Local only (SQLite / SharedPreferences) |
Crack The Code is a fully offline application. All gameplay data, progress, statistics, coin balances, and streak records are stored exclusively on your device using local storage (SQLite / SharedPreferences). We do not operate cloud servers for user data synchronization. Uninstalling the App will permanently and irreversibly delete all locally stored data.
2.4 Information We Do Not Collect
We do not knowingly collect: real names (unless voluntarily provided), email addresses (unless provided for support), photos, contacts, precise GPS geolocation, microphone or camera data, health data, or financial account credentials.
3. Advertising & Analytics Disclosures (Third-Party Services)
Crack The Code integrates the following third-party services, each of which may independently collect and process data pursuant to their own privacy policies. These third-party SDKs may transmit data when your device has an active internet connection:
| Service Provider | Purpose | Data Collected | Privacy Policy |
|---|---|---|---|
| Google AdMob | Advertising delivery (banner, interstitial, rewarded video ads) | Advertising ID, IP address, device info, ad interaction data | Google Ads Policy |
| Unity Ads | Supplementary ad network (rewarded video) | Device identifiers, session data, ad interaction metrics | Unity Privacy Policy |
| Google Play Services | Authentication, licensing, Play Integrity | Device identifiers, account tokens | Google Privacy Policy |
| Firebase Analytics | Usage analytics, event tracking, audience segmentation | App instance ID, session data, custom event parameters | Firebase Privacy |
| Firebase Crashlytics | Crash reporting, stability monitoring | Crash stack traces, device state, Crashlytics installation UUID | Firebase Privacy |
3.1 Personalized vs. Non-Personalized Advertising
- Personalized Ads. Where you have provided consent (or where consent is not required by applicable law), our advertising partners may use your Advertising ID and behavioral data to serve ads tailored to your inferred interests.
- Non-Personalized Ads. If you have not provided consent or have opted out of ad personalization, contextual (non-personalized) ads will be served based solely on general factors such as the content of the App, your general geographic region derived from IP address, and device type.
- Consent Management. We implement the IAB Transparency and Consent Framework (TCF) and Google's User Messaging Platform (UMP) SDK to manage your consent preferences for personalized advertising in jurisdictions requiring affirmative opt-in consent (e.g., EEA/UK under GDPR).
3.2 Opt-Out Procedures
You can limit ad personalization through the following operating system settings:
- Android: Navigate to
Settings → Privacy → Ads(orSettings → Google → Ads) and enable "Opt out of Ads Personalization" or delete your Advertising ID. - iOS: Navigate to
Settings → Privacy & Security → Trackingand disable "Allow Apps to Request to Track", or navigate toSettings → Privacy & Security → Apple Advertisingand disable "Personalized Ads".
Opting out of personalized advertising does not eliminate advertisements from the App. You will continue to receive contextual, non-personalized advertisements. VIP Gold subscribers enjoy a fully ad-free experience during the active subscription period.
4. How We Use Your Information
We process the information described in Section 2 for the following purposes:
- Core Service Delivery: To operate, maintain, and improve the App's 1000+ logic/deduction levels, numeric code-breaking engine, daily puzzle distribution, and overall gameplay experience.
- Virtual Economy Management: To track and validate coin wallet balances, process rewarded ad coin credits, deduct coins for hint and lifeline consumption, and fulfill in-app purchase transactions. All virtual economy data is managed locally on your device.
- Streak & Level Validation: To verify daily puzzle completion, maintain streak counters and streak recovery mechanics. All streak and level data is stored locally on your device.
- Subscription Fulfillment: To verify VIP Gold subscription status, provision premium features (ad-free experience, bonus hints, exclusive themes, streak freeze), and manage subscription lifecycle events.
- Player Statistics & Analytics: To calculate and display solve rates, time tracking, accuracy metrics, performance graphs, and milestone achievements within the App's statistics dashboard. All statistics are computed and stored locally.
- Advertising Delivery: To serve banner, interstitial, and rewarded video advertisements through integrated ad networks (Google AdMob, Unity Ads), including management of rewarded ad coin credits.
- Analytics & Optimization: To understand feature usage patterns, identify popular levels, optimize difficulty calibration, measure feature engagement, and inform product development decisions (via Firebase Analytics).
- Anti-Cheat & Fraud Prevention: To detect and prevent manipulation of game state, including clock tampering to exploit daily puzzle mechanics or streak systems, memory editing, automated scripting, and fraudulent purchase transactions.
- Stability & Diagnostics: To monitor application performance, identify and resolve crashes and bugs, and ensure reliable operation across diverse device configurations (via Firebase Crashlytics).
- Legal Compliance: To comply with applicable laws, regulations, legal processes, and enforceable governmental requests.
5. Data Storage, Security & Retention
5.1 Storage Architecture
- Local-Only Storage. Crack The Code is a fully offline application. All gameplay progress, player statistics, coin balances, streak data, hint/lifeline inventory, and user preferences are stored exclusively on your device using local SQLite databases and SharedPreferences (Android) / UserDefaults (iOS). No user gameplay data is transmitted to or stored on external servers operated by us.
- Third-Party SDK Data. Integrated third-party services (Google AdMob, Firebase Analytics, Firebase Crashlytics) may transmit diagnostic, analytics, and advertising data to their own servers when your device has internet connectivity. This data is governed by the respective third-party privacy policies listed in Section 3.
- Data Deletion on Uninstall. Because all gameplay data is stored locally on your device, uninstalling the App will permanently and irreversibly delete all stored data, including but not limited to: gameplay progress, level completions, coin balances, streak records, statistics, achievements, hint inventory, and user preferences. This action cannot be undone.
5.2 Security Measures
- Any data transmitted between the App and third-party services (ad networks, analytics, crash reporting) is encrypted in transit using industry-standard TLS 1.2+/HTTPS protocols.
- Local data stored on your device is protected by the operating system's built-in application sandboxing and storage encryption mechanisms (where enabled on the device).
- While we implement commercially reasonable security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
5.3 Data Retention
| Data Type | Retention Period | Notes |
|---|---|---|
| Local gameplay data (progress, coins, streaks, statistics) | Until app uninstall or manual data clear | Stored entirely on-device; permanently deleted on uninstall |
| Analytics & telemetry (Firebase) | 26 months (Firebase default) or shorter per configuration | Collected by Firebase; aggregated/anonymized data may be retained longer |
| Crash & diagnostic logs (Crashlytics) | 180 days | Automatically purged via Firebase Crashlytics retention policy |
| Purchase & subscription records | As required by applicable tax/financial regulations (typically 7 years) | Maintained by Google Play / Apple for audit, refund dispute, and compliance purposes |
| Advertising interaction data | Per ad network retention policies | Governed by Google AdMob / Unity Ads data policies |
6. User Rights & Data Deletion (GDPR & CCPA/CPRA)
6.1 Your Rights Under GDPR (EEA/UK Residents)
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation:
- Right of Access (Art. 15): You have the right to request confirmation as to whether your Personal Data is being processed, and to obtain a copy of such data.
- Right to Rectification (Art. 16): You have the right to request correction of inaccurate Personal Data and completion of incomplete Personal Data.
- Right to Erasure / "Right to be Forgotten" (Art. 17): You have the right to request deletion of your Personal Data where it is no longer necessary for the purposes for which it was collected, where you withdraw consent, or where processing is unlawful.
- Right to Restriction of Processing (Art. 18): You have the right to request restriction of processing of your Personal Data under certain circumstances.
- Right to Data Portability (Art. 20): You have the right to receive your Personal Data in a structured, commonly used, machine-readable format (e.g., JSON/CSV).
- Right to Object (Art. 21): You have the right to object to processing of your Personal Data based on legitimate interests, including for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
6.2 Your Rights Under CCPA/CPRA (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with the following rights:
- Right to Know: You have the right to request that we disclose the categories and specific pieces of Personal Information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom it is shared.
- Right to Delete: You have the right to request deletion of your Personal Information, subject to certain exceptions.
- Right to Correct: You have the right to request correction of inaccurate Personal Information.
- Right to Opt-Out of Sale/Sharing: You have the right to opt out of the "sale" or "sharing" of your Personal Information. We do not sell your Personal Information. Advertising-related data sharing with third-party ad networks may constitute "sharing" under CPRA; you may opt out via the ad personalization settings described in Section 3.2.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
We do not sell Personal Information in exchange for monetary consideration. To the extent that serving personalized advertisements constitutes "sharing" under the CPRA, you may exercise your right to opt out by adjusting your device's advertising settings as described in Section 3.2, or by contacting us at the email address below.
6.3 How to Exercise Your Rights
To submit a data access, deletion, portability, or other rights request, please follow these steps:
- Via Email: Send a written request to info@ybridigital.in with the subject line "Privacy Rights Request — Crack The Code". Include sufficient information to verify your identity (e.g., the device identifiers associated with your usage, approximate first-use date, platform used).
- Via In-App Support: Navigate to
Settings → Help & Support → Privacy Requestwithin the App to initiate a data request directly. - Local Data Deletion. Since Crack The Code is a fully offline application with all data stored locally, you can delete all your data at any time by either:
- Clearing App Data: Navigate to your device settings (
Settings → Apps → Crack The Code → Storage → Clear Data) to erase all locally stored data without uninstalling the App. - Uninstalling the App: Uninstalling Crack The Code from your device will permanently and irreversibly delete all locally stored data, including gameplay progress, coin balances, streak records, statistics, and achievements.
- Clearing App Data: Navigate to your device settings (
- Third-Party Data. To request deletion of data collected by third-party SDKs (Firebase Analytics, Firebase Crashlytics, Google AdMob), you may contact us at info@ybridigital.in and we will initiate the appropriate deletion procedures with the respective third-party services. We will process verified requests within 30 days (or within the timeframe required by applicable law).
Clearing app data or uninstalling the App will result in permanent, irreversible loss of all gameplay progress, coin balances, streak records, statistics, and achievements. Since the App does not have cloud backup or synchronization functionality, this data cannot be recovered once deleted. Subscription billing is managed by Google Play / Apple and will not be affected by data deletion; you must separately cancel any active subscription through the platform store.
7. Children's Online Privacy Protection (COPPA & Age Limits)
- Age Requirement. Crack The Code is not directed to children under the age of 13 (or 16 in jurisdictions where the GDPR mandates a higher minimum age for digital consent, such as Germany, the Netherlands, and Ireland). We do not knowingly collect Personal Data from children under these age thresholds.
- COPPA Compliance. In accordance with the U.S. Children's Online Privacy Protection Act (COPPA), we do not knowingly collect, use, or disclose personal information from children under 13 without verifiable parental consent.
- Non-Targeted Data Collection. We do not serve behaviorally targeted advertisements to users identified as minors. Where age-gating mechanisms indicate a user may be under the applicable minimum age, only contextual (non-personalized) advertisements will be displayed, and analytics collection will be limited to aggregated, non-identifiable metrics.
- Parental Rights. If you are a parent or guardian and believe that your child under the applicable minimum age has provided Personal Data through the App, please contact us immediately at info@ybridigital.in. We will take prompt steps to investigate and delete such data.
- Google Play Families Policy. If the App is published in a Google Play Families program category, we additionally comply with Google Play's Families Policy requirements, including restrictions on advertising SDKs, data collection, and API usage for child-directed content.
8. International Data Transfers & Legal Basis for Processing
8.1 Legal Basis for Processing (GDPR)
We process your Personal Data on one or more of the following legal bases:
| Legal Basis | Applicable Processing Activities |
|---|---|
| Contractual Necessity (Art. 6(1)(b)) | Core gameplay delivery, virtual economy management, subscription fulfillment |
| Consent (Art. 6(1)(a)) | Personalized advertising, optional analytics, marketing communications |
| Legitimate Interests (Art. 6(1)(f)) | Anti-cheat & fraud detection, app stability & crash diagnostics, non-personalized analytics for product improvement, security monitoring |
| Legal Obligation (Art. 6(1)(c)) | Tax record retention for purchase transactions, compliance with law enforcement requests |
8.2 International Transfers
- While the App itself operates offline, data collected by integrated third-party SDKs (Firebase Analytics, Firebase Crashlytics, Google AdMob, Unity Ads) may be transferred to, stored in, and processed in countries outside your country of residence, including the United States, where these service providers maintain infrastructure.
- For transfers of Personal Data from the EEA/UK to countries not deemed to provide an adequate level of data protection by the European Commission, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms such as adequacy decisions or binding corporate rules.
- By using the App, you acknowledge and consent to the transfer of your data to jurisdictions that may have different data protection laws than your country of residence.
9. Updates to This Policy & Contact Information
- Policy Modifications. We reserve the right to update or modify this Privacy Policy at any time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this document.
- Provide at least 30 days' prior notice of material changes through an in-app notification, a prominent notice on the App's store listing, or by other reasonable means.
- Where required by applicable law (e.g., GDPR), obtain renewed consent for changes that affect the legal basis or scope of data processing.
- Continued Use. Your continued use of the App after the effective date of a revised Policy constitutes your acceptance of the updated terms. If you do not agree with the revised Policy, you must discontinue use of the App.
- Contact Us. If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Developer: Yash Rayjada
Powered By: YBR Digital
Website: www.ybrdigital.in
Email: info@ybridigital.in
Subject Line: "Privacy Inquiry — Crack The Code" - Supervisory Authority. If you are located in the EEA or UK and believe that our processing of your Personal Data violates applicable data protection law, you have the right to lodge a complaint with your local Data Protection Authority (DPA). A list of EU DPAs is available at edpb.europa.eu.