Nimblins Privacy Policy
This policy describes how Berki Software handles information when you use Nimblins on Android or iOS.
1. Scope and controller
Berki Software provides Nimblins and is responsible for the product choices described in this policy. The policy covers the Nimblins mobile app and related support requests. It does not replace the privacy policies of Google, Firebase, AdMob, Apple, your app store, or your email provider.
Privacy contact: berkisoftware@gmail.com.
2. Information stored locally
Nimblins uses device app storage to keep the game useful between sessions. Depending on the features you use, this includes:
- onboarding completion and gameplay settings;
- Classic progress, stars, completion times, and puzzle state;
- Daily completion history, streak information, first-clear results, and pending leaderboard synchronization state;
- active and completed Endless run state, local personal bests, pending submission state, and claimed milestones;
- Coins, wallet transactions, unlocked and selected cosmetic Nimblins;
- verified Premium status, verification time, Google Play purchase token, and Premium Daily Gift state;
- Achievements, Missions, Mastery, and activity summaries;
- sound, haptic, animation, accessibility, notification, and rating-invitation preferences;
- a locally generated or chosen public leaderboard display name; and
- advertising pacing and reward-limit state, plus consent information managed by Google’s SDK.
This local game data is not automatically uploaded as a general cloud backup by Berki Software. Your operating system or device backup settings may separately back up app data under the platform provider’s rules.
3. Firebase, anonymous authentication, and server features
Nimblins uses Firebase services in the project operated for the app. When you open or submit to a leaderboard, or synchronize a supported public-name change, the app may sign you in with Firebase Anonymous Authentication. This creates a random Firebase user identifier without asking you for an email address or password.
Cloud Firestore stores supported leaderboard documents. Firebase Cloud Functions receives submissions, checks that a player is authenticated, validates results, applies server timestamps, and writes accepted records. Clients cannot directly create, change, or delete leaderboard documents.
If you turn on Nimblins notifications, Firebase Cloud Messaging creates and manages an app-installation push token and subscribes it to a language-specific Daily-notification topic. Nimblins does not store that raw token or your selected language in Cloud Firestore, and it does not link the topic subscription to the app’s anonymous leaderboard user identifier. Google and Apple process push-delivery identifiers under their own platform rules. Turning notifications off removes the topic subscription and cancels scheduled local reminders; uninstalling removes local preference data, while the platform provider controls final push-token retirement.
Google Analytics for Firebase
Nimblins uses Google Analytics for Firebase to understand aggregate product use and improve the app. The app sends bounded events such as screen views, sessions, onboarding steps, puzzle mode and difficulty, puzzle completion characteristics, Daily and Endless actions, notification opens and permission-funnel actions, rewarded-ad outcomes and placements, Mission progress and claims, Premium purchase or restore funnel steps, rating-invitation actions, settings changes, and cosmetic collection actions.
The Firebase Analytics SDK automatically assigns an app-instance identifier and can process app lifecycle events, device and app information, Android advertising identifiers where available, masked IP addresses used to derive coarse location, and automatically measured in-app purchase events such as product identifier, product name, and price. Data is used for analytics, product improvement, and understanding app reliability and feature performance. Google encrypts Analytics data in transit and applies its own controls and retention rules.
Nimblins does not set the Firebase Analytics User-ID to the anonymous leaderboard identifier. Custom Analytics events do not include a public display name, player name, email address, phone number, raw Firebase user identifier, purchase token, FCM token, leaderboard opponent identity, arbitrary user-entered text, report text, hidden-player data, or board state. Event parameters use small allowlisted values rather than puzzle IDs or other high-cardinality content.
Google Play Premium verification
On Android, buying or restoring Nimblins Premium sends the Google Play product identifier, app package name, and purchase token through an authenticated Firebase Cloud Function to the Google Play Developer API. The function checks ownership and purchase state before activating Premium and acknowledging an eligible purchase. The raw purchase token is not logged or stored in Firestore; Firestore stores a SHA-256 token hash, the anonymous Firebase user identifier linked to the entitlement, product and platform identifiers, verification timestamps, active status, and the most recent Premium Daily Gift UTC date. Google Play separately controls payment, transaction, tax, refund, and purchase-history information under Google’s policies.
Daily leaderboard data
A first-clear Daily submission can include the Daily puzzle date or ID, public display name, solve time, mistakes, Hint use, whether the result was perfect, the anonymous user identifier used as the document key, and a server submission time. Leaderboard readers can retrieve leading entries and their own entry after anonymous authentication.
Endless leaderboard data
An Endless personal-best submission can include the public display name, score, puzzles completed, active play time, mistakes, assisted Hints, flawless clears, best combo, run and rules-validation information, the anonymous user identifier used as the document key, and a server submission time. The server reconstructs the deterministic run and recomputes results before accepting a supported personal best.
Public-name reports
If you report a public leaderboard name, Nimblins stores the reporting and reported anonymous Firebase user identifiers, a server-derived display-name snapshot, leaderboard context, report category, app version, and server report time. Reports are private to the app’s backend and authorized moderation tooling; they are not readable from the app by other players.
4. Public display names and leaderboard visibility
Nimblins creates a friendly random display name locally when one is needed, and you can edit it within the app. A submitted display name and the result metrics shown by a leaderboard are public to other authenticated Nimblins leaderboard users. Do not use your legal name, email address, phone number, or other sensitive information as a display name.
A supported name change updates the current Endless entry and the current day’s Daily entry when those records exist. It does not promise that every historical Daily entry is renamed.
5. Google AdMob, advertising data, and privacy choices
Nimblins uses the Google Mobile Ads SDK and Google AdMob to show banner, interstitial, and optional rewarded ads. Google and authorized advertising partners may process information needed to request, deliver, measure, limit, protect, and report ads. Depending on your platform, region, settings, and consent, this can include IP address, device and app information, advertising or device identifiers, approximate location derived from network information, ad interactions, consent signals, and diagnostics.
Ads may be personalized only where legally and technically permitted and where your choices allow it. Otherwise, Google may serve non-personalized or restricted ads using contextual and limited information. Nimblins does not force personalized advertising as a condition of playing.
Nimblins integrates Google’s User Messaging Platform (UMP). At app startup, it requests current consent information, shows a required message when applicable, and asks the SDK whether ads can be requested. For users in the European Economic Area, United Kingdom, or Switzerland, Google’s message can request choices about storage, personal data, and personalized advertising. Applicable US-state options can provide an opt-out path. When Google indicates that a privacy options entry point is required, Nimblins displays Privacy Choices in Settings so you can reopen the current form.
Consent choices and their availability depend on the region and Google’s current configuration. Ad failure or the inability to request ads does not block puzzle gameplay.
6. Apple platforms, ATT, and IDFA
On iOS or iPadOS, a Google privacy message may explain why the app wants permission under Apple’s App Tracking Transparency (ATT) framework. Apple controls the system prompt. If you deny permission, Nimblins does not receive access to the Identifier for Advertisers (IDFA) through that permission; ads can still be requested without IDFA when the consent state and platform permit. You can review Apple tracking permissions in device Settings.
7. Why information is processed
- save progress, preferences, rewards, goals, and active game state on your device;
- authenticate server access without requiring a named account;
- measure aggregate app usage, screens, feature engagement, purchase funnels, notification opens, and product reliability;
- verify Google Play Premium ownership, restore eligible benefits, prevent duplicate Daily Gifts, and respond to ineligible purchase states;
- validate, store, rank, and display Daily and Endless results;
- support public display-name changes for currently supported records;
- receive and review public-name reports for safety and abuse prevention;
- request, display, measure, protect, and limit ads and grant confirmed rewarded-ad benefits;
- present and respect applicable privacy choices; and
- diagnose support, reliability, abuse, and security issues.
8. Retention
Local information remains in app storage until the app changes or removes it, you clear app data, or you uninstall the app, subject to platform backup behavior. Push-topic subscriptions remain active only while the app preference is enabled and the platform token remains valid. Berki Software does not currently publish a fixed automatic deletion schedule for accepted Daily leaderboard entries, weekly Endless entries, Premium entitlement records, hashed purchase-token records, or anonymous Firebase identities. They may remain until deleted through an applicable request, replaced by supported product behavior, or removed for operational, fraud-prevention, accounting, safety, or legal reasons.
Google Analytics for Firebase, other Firebase services, AdMob, Apple, and app stores apply their own retention rules to information they control.
9. Security
Berki Software uses platform and Firebase controls intended to protect server features, including authenticated reads, server-only leaderboard writes, and server validation. No internet or storage system can be guaranteed completely secure. Please avoid placing sensitive information in a public display name or support message.
10. Your choices and requests
- Change the public display name in the app.
- Turn Nimblins notifications on or off independently in Settings and manage operating-system notification permission in device Settings.
- Purchase, restore, or refresh Premium from Settings on Android.
- Use Privacy Choices in Settings when the entry is required.
- Change Apple tracking permission in device Settings.
- Clear local data or uninstall the app, subject to platform backups.
- Choose whether to watch an optional rewarded ad.
- Contact Berki Software about access, correction, objection, restriction, or deletion.
The current server-data request process is explained at Data Requests & Deletion. Because Nimblins uses anonymous authentication, locating a server record from a public name alone may not always be possible.
11. Audience and children
Nimblins is a logic puzzle game and does not ask users to create an account with a name, email address, birth date, or school information. A public leaderboard display name should never contain personal information. At the effective date of this policy, formal store target-audience declarations for Nimblins still require final review before public release. The AdMob maximum ad content rating is PG; that setting does not by itself define the app’s legal target audience.
If you believe a child submitted personal information through a display name or support email, contact berkisoftware@gmail.com with enough non-sensitive detail to evaluate the request.
12. Third-party services
These official resources explain relevant third-party practices:
- Google Privacy Policy
- Firebase privacy and security information
- Google Analytics for Firebase data collection information
- How Google uses information from apps that use its services
- Apple App Tracking Transparency information
- Apple Privacy Policy
13. Policy changes
Berki Software may update this policy when Nimblins features, data flows, service providers, or legal requirements change. The effective date at the top will be updated. Material changes may also be communicated through an appropriate app or store surface.
14. Contact
For privacy questions or requests, email berkisoftware@gmail.com. Include “Nimblins privacy” in the subject and do not send passwords, authentication tokens, advertising identifiers, or purchase records unless Berki Software specifically explains why a limited item is necessary.