Mini Games Design
Privacy Policy

Privacy Policy

This policy explains how Mini Games Design handles information for GridFlow: Logic Puzzle. Effective date: July 31, 2026.

1. Who we are

Mini Games Design publishes GridFlow: Logic Puzzle. You can contact us at muzil7734@gmail.com.

2. Information stored on your device

GridFlow does not require an account. The game stores progress and preferences locally on your device so the game can remember your choices and unlock state. Local data may include current level, highest unlocked level, tutorial guide state, sound and music settings, haptics settings, language choice, color accessibility settings, Daily challenge history, Daily promise and repair state, energy balance and refill timestamps, badge claim state, badge statistics, and per-level or Daily performance records such as completion time, par-time score bucket, hint use, reset count, undo count, and attempt count.

If you enable push notifications, the game may also create and store a random anonymous installation ID on your device. This ID is not your name, email address, phone number, or Google account.

GridFlow does not collect account credentials, your name, email address, payment information, address book or contacts, user-generated content, or precise location. The game does not request precise location permission.

3. Advertising and consent

The Android release may use Google AdMob and Google User Messaging Platform to show optional rewarded video ads and limited interstitial ads, request or manage consent, reduce fraud, measure ad delivery, and comply with platform requirements. AdMob and related Google services may process information such as advertising identifiers, device and app identifiers, IP address, approximate location inferred by service providers, app interaction data, ad interaction data, diagnostics, and consent signals.

Ads may be personalized, non-personalized, or limited depending on consent, applicable law, app settings, and Google policy.

Ad and analytics providers may process advertising ID, app instance IDs, installation IDs, IP-derived approximate region, device and app information, usage events, diagnostics, consent signals, and ad interaction data under their own policies.

Rewarded ads are optional and may be used for in-game help such as hints, energy refill, or Daily repair. A reward is granted only after the ad flow reports completion or reward. Interstitial ads are limited to level-transition moments and are not shown during the first tutorial levels. Remote configuration may adjust ad eligibility, spacing, and cooldown rules.

4. Analytics and diagnostics

GridFlow may use Firebase Analytics and PostHog to process gameplay and technical events such as level start, first draw, level completion, level abandonment, level navigation, hint use, ad request and reward state, settings changes, Daily challenge actions, D7 journey progress, badge unlock or claim state, energy spend and refill state, notification permission and open events, update prompts, app version, platform, and error or delivery diagnostics.

Analytics events may include gameplay context such as level ID, elapsed time, score bucket, completed challenge day key, feature state, or public ad placement alias. The current PostHog integration keeps autocapture, pageview capture, and pageleave capture disabled. Analytics code blocks sensitive fields such as raw ad unit IDs and notification tokens from being tracked. We do not use these events to collect your name, email address, precise location, contacts, photos, messages, or payment information.

Analytics events may be queued locally for retry, up to 200 events per provider, before they are delivered, overwritten by queue limits, cleared with app data, or removed by uninstalling the app.

In production releases where PostHog is enabled, PostHog Session Replay may record an approximately 3% sample of gameplay sessions to help diagnose usability and stability issues. A sampled replay may include the GridFlow interface, Pixi canvas frames, interface changes, and touch or click interactions within the app.

Session Replay masks all input controls, and app configuration disables request-header capture, request-body capture, console-log recording, and PostHog performance capture. It does not access the device camera, microphone, contacts, photos, messages, payment information, or content outside GridFlow. Because sampled replays can show on-screen gameplay state, they are processed as pseudonymous app-interaction analytics by PostHog.

The Android production release may use Firebase Crashlytics to collect native crashes, application-not-responding reports, limited JavaScript exception messages and stack frames, app build information, and related device or app diagnostic state. JavaScript exception text is length-limited and filtered for email-shaped and secret-like values before reporting. GridFlow does not set a Crashlytics user ID.

The Android production release may use Firebase Performance Monitoring to measure app startup, lifecycle, network request performance, and custom app boot or game initialization traces. Custom traces use low-cardinality ready or failed results and do not include puzzle paths, touch input sequences, level IDs, names, messages, contacts, or payment information.

5. Third-party services

GridFlow may use Google AdMob and Google User Messaging Platform for advertising and consent; Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring, Firebase Remote Config, Firebase A/B Testing, and Firebase Cloud Messaging for analytics, diagnostics, performance, configuration, experiments, app update policy, and notifications; PostHog for product analytics and sampled Session Replay; Cloudflare Workers and Cloudflare D1 for the developer website and push backend; and Google Play services for Android platform distribution and operation. These providers may process information under their own terms and privacy policies. Review Google's privacy policy at https://policies.google.com/privacy and PostHog's privacy notice at https://posthog.com/privacy.

6. Push notifications

Notifications are optional. The game first shows an in-game explanation before requesting Android notification permission. If you grant permission, the game may subscribe to broad and language-specific topics such as general GridFlow updates, Daily challenge reminders, D7 journey reminders, energy refill reminders, and update notices.

When notifications are enabled, GridFlow may send a Firebase Cloud Messaging token, anonymous installation ID, platform, language, topic aliases, and app build number to the GridFlow push backend hosted on Cloudflare. The backend stores token hashes and encrypted token data so we can send topic, language, or targeted notifications. Notification payloads may route you to the main screen, Daily challenge, Daily panel, or badge claims screen. We do not use push registration to collect your name, email address, phone number, contacts, or messages.

When notifications are enabled, the raw FCM token is stored encrypted by the GridFlow push backend and the installation ID is stored as a hash.

7. Remote configuration and updates

The Android release may use Firebase Remote Config to deliver non-secret gameplay, messaging, experiment, safety, and required update settings, including recommended or required app update policy, store URL, energy system values, and interstitial ad frequency. Remote Config helps us operate the game, tune pacing, disable or adjust features, and protect users from broken versions.

Firebase A/B Testing may use pseudonymous app installation assignment together with Remote Config variants and Firebase Analytics events to compare approved pacing or feature settings. Required-update thresholds, store URLs, and safety controls are excluded from experiments. Checked-in experiment drafts do not start an experiment by themselves; an experiment must be separately reviewed and published in Firebase Console.

Required update settings may prevent old app versions from continuing until the user updates from Google Play.

8. How information is used

  • To operate gameplay, save local progress, and remember settings.
  • To provide Daily challenges, D7 journey progress, badges, energy pacing, hints, and local performance records.
  • To provide optional rewarded ads and limited interstitial advertising.
  • To provide optional push notifications and route notification opens to the intended screen.
  • To understand level difficulty, improve stability, tune game balance, and fix defects.
  • To deliver app update prompts, remote configuration, security controls, and service reliability.
  • To comply with platform, security, fraud prevention, and legal obligations.

9. Sharing

We do not sell your personal information. Advertising, consent, analytics, hosting, and platform providers may receive information needed to provide their services. We may disclose information if required by law, to protect rights and safety, or to investigate abuse.

10. Children

GridFlow is a general logic puzzle game for teens and adults and is not directed to children under 13. If you believe a child has provided personal information to us, contact us and we will take appropriate action.

11. Data retention and deletion

Local progress, settings, Daily state, energy state, badge state, and local performance records remain on your device until you clear app data or uninstall the app. Push registration records may remain on the GridFlow push backend while the token appears active, until the token becomes invalid, or until we process a deletion request that we can verify. Analytics, advertising, consent, hosting, and platform providers may retain information under their own policies.

Because GridFlow does not require an account, we may not be able to identify all device-related records from your email address alone. If you send a privacy request, include the platform, approximate install or notification date, app version if available, and a description of the request so we can evaluate what records we can locate.

Pseudonymous analytics records may not be practically searchable without the relevant SDK identifier and remain subject to provider retention policies.

12. Security

We use reasonable technical and organizational measures for the services we control. For the push backend, notification tokens are stored as hashes and encrypted token ciphertext rather than plain text. No method of transmission or storage is perfectly secure.

13. Your choices

  • You can change sound, music, haptics, language, and accessibility settings in the game.
  • You can use the in-game privacy options entry where consent controls are available.
  • You can decline notification permission, turn off notifications in Android settings, or clear app data to remove local notification preferences and local installation state.
  • You can use Android or Google settings to manage advertising ID and ad personalization choices where available.
  • You can reset local data by clearing app data or uninstalling the app.
  • You can contact us at muzil7734@gmail.com for privacy questions or requests.

14. International processing

Service providers may process information in countries or regions where they operate. If you use the game outside those locations, information may be transferred or processed across borders as needed to provide the game and related services.

15. Changes

We may update this policy when the game, services, or legal requirements change. The updated version will be posted on this page with a new effective date.

Effective date: July 31, 2026