Zenary Sudoku

Privacy Policy — Zenary Sudoku

Last updated: 14 September 2026
Version: 1.1


1. Who we are — Data Controller

The mobile application Zenary Sudoku (the "App") is developed and distributed by:

Cosmo Srls
Registered office: Via Fiume Giallo 362, 00144 Roma (RM), Italia
VAT / Tax number: IT14795571000
Privacy contact e-mail: comida.giampaolo@gmail.com
Website: https://zenary.cosmocomunicazione.it

Cosmo Srls acts as the Data Controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the "GDPR") for the processing described in this Policy.

We have not appointed a Data Protection Officer, as the conditions of Article 37 GDPR are not met. For any matter concerning personal data, write to us directly at comida.giampaolo@gmail.com.


2. The short version

Before the detail — because you are entitled to understand this in thirty seconds:

device receives an anonymous identifier and a token from our server: no name, no e-mail, no phone number.

your profile again on another phone. It is optional, and if you skip it nothing is withheld.

and in matches. There is no photograph and no way to upload an image.

community statistics and an anti-cheating check can exist. The contents of your grid and your games in progress stay on the phone.

matches and battles. During a shared match your progress is visible to your opponents.

game**. We ask for your explicit, revocable consent for it.

advertising, and we use no third-party usage-analytics or crash-reporting service.

disappears from the leaderboards and from other players' view.


3. What we process, why, and on what legal basis

3.1 Data that stays on your device only

The App stores the following in your phone's local storage, using the operating system's standard storage mechanisms:

What Examples Where it goes
Game progresscurrent grid, entered digits, pencil marks, elapsed time, undo historyDevice only
Game statisticsgames completed, best times, daily streaks, preferred difficultyDevice only
Game creditshow many of your 3 games are left, when the recharge wait expires, how many videos you watched todayDevice only
Preferenceslanguage, light/dark theme, sound, haptics, highlighting and grid-reading aidsDevice only
Local remindersthe alerts the App schedules on the phone and their settingsDevice only
Session tokenthe signed string that proves to the server it is you, without saying who you areOn the device; sent to our server with every request
Advertising consent statethe choice you made on the consent screenDevice only (handled by Google's SDK)

The contents of your grids are never transmitted to us. From a game we receive the outcome, not the moves: what you wrote in which cell and when stays on the phone.

Legal basis. Storing information on your terminal equipment is governed by Article 5(3) of Directive 2002/58/EC ("ePrivacy"), implemented in Italy by Article 122 of Legislative Decree 196/2003: because that storage is strictly necessary to provide the service you expressly requested — to play, to keep your game in progress, and to know how many games you have left — your consent is not required. Without this data the App could not function. The one exception is the advertising consent state, which is the record of a choice you made and is dealt with in § 4.

Deletion. You can erase all of it at any time, in two ways:

already been sent to the server. For that you need the option above.

3.2 Anonymous identity and optional account

The anonymous identity. On first launch the App registers with our server and receives two things: a user identifier we generate, and a signed device token valid for one year, which the App renews. It is not an account: there is no password, no address, and if you lose the phone that identity cannot be recovered — unless you have added an e-mail address.

An account, if you want one. You can attach an e-mail address and a password to your profile. It does one thing: it lets you find the same profile — results, leaderboard places, friends — on another device. It is optional, and skipping it costs you no feature of the game.

What Why Legal basis
User identifier and device tokenRecognising your profile without asking who you are: leaderboards, friends, challengesArticle 6(1)(b) GDPR — performance of the service you asked us for
E-mail address (and an address awaiting verification)Verifying the address, letting you back into your profile from another phone, resetting your passwordArticle 6(1)(b) GDPR
PasswordProtecting access to the profileArticle 6(1)(b) GDPR
Verification date, last sign-in date, last password-change dateAccount security, handling abuse reportsArticle 6(1)(f) GDPR — our legitimate interest in a secure service
Temporary attempt counters per e-mail address and per IP addressStopping anyone from trying thousands of passwordsArticle 6(1)(f) GDPR

Passwords are not stored. Of a password we keep only a cryptographic hash computed with argon2id, the algorithm recommended for this purpose. The password cannot be derived from the hash: not by us, and not by anyone who got hold of the database.

Password reset. If you forget it, we e-mail you an expiring link that works once only. We do not keep the link in the database, only a hash of it, for the same reason we do not keep passwords.

If you attach an address and never verify it, after seven days the address and the password are removed from the profile. You lose nothing — profile, statistics and friends stay — and you can attach the address again whenever you like.

IP addresses. We use them to derive your country (§ 3.3) and for rate limiting, which is the ordinary defence against abuse. We do not write them to the database and we do not attach them to your profile.

3.3 Your public profile: nickname, avatar, country

What Who sees it Legal basis
NicknameAnyone: leaderboards, challenge screens, friend lists, the battle tableArticle 6(1)(b) GDPR
Built avatar (shape, colours and accessories you pick from a fixed set)Anyone, in the same placesArticle 6(1)(b) GDPR
Country code (two letters, ISO 3166-1)Anyone, next to your name on the leaderboardArticle 6(1)(b) GDPR
Friend codeOnly whoever you give it toArticle 6(1)(b) GDPR

⚠️ Your nickname is public: choose it accordingly. It is the only thing other players see of you, and we recommend not using your real name or anything else that identifies you. The App says so on the screen where you choose it.

No photographs, no image uploads. The avatar is assembled from graphic pieces we supply. The App asks for neither camera nor photo-library access, and there is no way to upload an image at all. That is deliberate: a user-uploaded image is content to be moderated, and content to be moderated in a game open to thirteen-year-olds is a risk we chose not to take.

Your country is not your location. The country code is derived from the IP address you connect from — or read from a header supplied by the network service in front of our server — and is used only for national leaderboards. It is not GPS location, not a city, not an address: it is two letters. The App does not request and does not hold the location permission on either platform. If the country cannot be derived it stays empty, and you appear only in the global leaderboards.

Nickname moderation. Nicknames pass an automatic filter that rejects the most common insults in Italian and English. It is an automatic check against a word list, not a judgement about you, and it produces no legal effect within the meaning of Article 22 GDPR: a rejection is resolved by picking another name. The legal basis is our legitimate interest (Article 6(1)(f)) in keeping the game usable by an audience that includes minors.

3.4 Game results and leaderboards

When you finish a game, the App sends our server:

What Example
Puzzle identifier and seedthe string from which the puzzle regenerates identically
Grid size and difficulty9×9, "hard"
Modefree play or daily challenge
Outcome, time taken, number of mistakes, hints usedcompleted, 7 minutes 12 seconds, 2 mistakes, 1 hint
Scorethe one the App computed, which the server recomputes independently
Local day of completion and App version2026-09-14, version 1.0.0

What it is for, and why it is not less.

best result**, not all of them.

They are aggregate: they do not say who.

score: an impossible result — a puzzle solved in less time than it takes to type the digits — does not enter the leaderboard. That is the only reason we genuinely need the seed and the time. A result that is suspicious but not impossible is recorded for a human to look at**, and stands in the meantime.

What other players see. Leaderboards show nickname, avatar, country, score and time. Nothing else.

Legal basis. Article 6(1)(b) GDPR for leaderboards and statistics, which are the service you asked for by using the App online. For anti-cheating verification alone, and for rate limits on submissions, Article 6(1)(f) GDPR: it is our legitimate interest — and every other player's — that a leaderboard should mean something.

3.5 Friends, online presence and multiplayer

Friends by code only. Every profile has a friend code. You become friends by exchanging that code and accepting the request. There is no search by nickname, and that is not an oversight: it is a choice made to make it impossible for an adult to scroll a list of players and pick out a younger one. If you give your code to nobody, nobody can reach you.

The App does not touch your contacts. It does not request the contacts permission, does not hold it, and does not know who you know.

Blocking. You can block any profile: a blocked person can no longer challenge you or send you requests. We keep the list of blocks because it is the only way to make blocking work (Article 6(1)(f) GDPR: legitimate interest in user safety).

Online presence — the green dot. While the App is open and connected, your friends can see that you are online. That information lives only in the server's memory: it is not written to the database, it produces no history, and it disappears when the service restarts. We do not record when you connect or how long you stay.

Shared matches. The App offers a challenge against a friend, a quick match against a stranger, and a battle of up to ten players. In all of them, on the same puzzle at the same time, the server transmits to your opponents, for the duration of the match:

We do not transmit the digits you enter, nor your pencil marks: opponents see how far along you are and how many mistakes you made, not your grid.

Simulated opponents. If a battle does not gather enough players within a few seconds, the table may be filled with computer-generated opponents. They are always declared as such in the interface, with a label next to the name: we do not pass them off as people.

When a battle ends we keep the outcome (position, time survived, percentage completed, mistakes, reason for elimination, points) to show you the summary and your statistics.

Legal basis. Article 6(1)(b) GDPR throughout § 3.5: these features only run if you use them, and sharing your progress is the game — a challenge in which you cannot see how your opponent is doing would not be a challenge. If you do not want to share anything live, do not start multiplayer matches: solo play and the daily challenge transmit nothing to other players while you play.

3.6 Notifications

Push notifications (Firebase Cloud Messaging — Google). If you turn them on, the phone generates a notification token: a string identifying that installation of the App on that device. The token is sent to our server and stored there, together with the platform (iOS or Android) and the device language, because that is the only way to deliver a notification to you. We also store your preferences: which kinds of alert you want (challenge invitation, friend request, friend request accepted, opponent finished, battle starting) and the quiet hours you set.

To deliver a notification, our server passes the token and the message text to Firebase Cloud Messaging, a Google service: see § 5.

You can switch them off at any time, from the App's settings or from the operating system's. If you switch them off in the App, the token is deleted from our server: we do not leave an identifier of your phone sitting on a service you no longer use.

Local reminders. These are alerts the App schedules directly on the phone (for example: the daily challenge is available). They do not pass through us, do not pass through Google, and never leave the device.

Legal basis. For push notifications: your consent, under Article 6(1)(a) GDPR, given by enabling notifications in the App and allowing them at operating-system level, and withdrawable at any time as just described. Local reminders involve no processing by us at all.

3.7 Data processed for advertising (Google AdMob)

The App is free and is funded by advertising. The mechanic is this: you have 3 games; when you run out you can wait two hours and get them back for free, or choose to watch a short video advertisement to get them back immediately (a "rewarded ad"). The daily challenge is always free and costs no games.

Watching advertising is never compulsory: waiting is the alternative, and it is free. There is no advertising inside the game screen, and no ad ever interrupts a game.

Advertising is provided by Google through the Google AdMob platform and the Google Mobile Ads SDK embedded in the App.

What data Google processes. According to Google's published documentation, the Google Mobile Ads SDK collects and shares with Google the following categories of data:

Category Detail Purposes stated by Google
IP addressyour device's IP address, which may be used to estimate your approximate location (typically city or region level — not precise GPS location)Advertising, analytics, fraud prevention
Advertising identifierson Android: the Advertising ID (GAID) and the App Set ID; on iOS: the Identifier for Advertisers (IDFA), only if you expressly authorise it, and the Identifier for Vendors (IDFV)Advertising, analytics, fraud prevention
Product interactionsApp launches, ad impressions, video completions, taps on adsAdvertising, analytics, fraud prevention
Advertising datawhich ads were shown to you and how oftenAdvertising, measurement, frequency capping
Diagnostic informationtechnical and performance data (device model, OS, launch time, SDK errors)Diagnosing and improving the SDK, fraud prevention

The App does not transmit your nickname, your user identifier, your e-mail address, your results, your friends or your games to Google or to any advertiser. The advertising stack and our server are two separate worlds, and there is no code joining them.

Legal bases. Two distinct situations, because they really are different:

(a) Personalised advertising (profiling). If you consent, the ads you see may be selected on the basis of an interest profile, including activity across other apps and websites. The legal basis is your consent under Article 6(1)(a) GDPR and, for the reading and storing of identifiers on your device, Article 122 of the Italian Privacy Code and Article 5(3) ePrivacy Directive. Consent is requested before any advertising component is initialised, through a dedicated screen, and is freely given, specific, informed and revocable.

(b) Non-personalised advertising. If you refuse profiling, you may still receive non-personalised ads, selected on the basis of the App's content and your approximate geographic area, without an interest profile being built. Even then, Google uses device identifiers for technical purposes such as frequency capping, ad fraud prevention and measurement: access to those identifiers is therefore also subject to your consent, requested through the same screen, in accordance with Article 122 of the Privacy Code.

(c) Fraud prevention and security. For the sole purposes of securing the advertising ecosystem and combating fraudulent traffic, Google also processes data on the basis of its legitimate interests under Article 6(1)(f) GDPR.

Google's role. For this processing Google acts as an independent data controller, not as our processor: it determines the purposes and means of processing the data it collects through AdMob. Accordingly, to exercise your rights over that data you must also address Google directly:

The Google entities involved are Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) for users in the European Economic Area, the United Kingdom and Switzerland, and Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) for other users.

3.8 Data we never process, and things we do not do

For the avoidance of doubt, and so that you do not have to work it out by elimination, we expressly state that the App does not collect and does not request:

free);

We also state, with the same precision:

Firebase Analytics, no Sentry, no Mixpanel, nothing of the sort. The App's code does contain components prepared to collect usage events and errors, but today they write only into the device's memory and send nothing to anyone, neither to us nor to third parties. Should we ever connect them to a service, this Policy will be updated first, and we will tell you in the App as described in § 14.

We build no interest profiles, we infer no personal characteristics from the way you play, and we use your results for nothing beyond a leaderboard or an aggregate statistic.

that others can read are your nickname.

significantly affecting you within the meaning of Article 22 GDPR. The anti-cheating check (§ 3.4) can keep an impossible result out of a leaderboard: that is a rule of the game, not a decision about you as a person, and it has no consequence outside the game.


4. Advertising consent: how it works and how to change your mind

4.1 How we ask

If you are in the European Economic Area, the United Kingdom or Switzerland, on first launch — and before any advertising component is initialised — you are shown a consent screen served through Google's User Messaging Platform (UMP), a Google-certified consent management platform ("CMP") integrated with the IAB Europe Transparency and Consent Framework (TCF).

On that screen you can:

/ "More options" button.

The complete, up-to-date list of third-party advertising vendors that may receive data if you consent is available inside that same consent screen, under the advertising partners section.

4.2 iOS: the tracking prompt (ATT)

On Apple devices running iOS 14.5 and later, in addition to the consent screen above, the operating system displays a separate prompt required by the App Tracking Transparency framework, asking whether you allow the App to track your activity across other companies' apps and websites.

works exactly the same way**: games, the timed recharge, rewarded videos, leaderboards, friends and multiplayer all remain identical. We do not penalise you in any way for that choice.

4.3 Withdrawing consent, at any time

Consent can always be withdrawn, and withdrawing it is as easy as giving it, as Article 7(3) GDPR requires.

lets you change any choice.

all apps.

For push notifications, withdrawal is described in § 3.6: Settings → Remote notifications in the App, or your phone's system settings.

Withdrawal does not affect the lawfulness of processing carried out before it.


5. Recipients of data

We do not sell, rent or otherwise transfer personal data to third parties. The recipients are only these:

Recipient What it receives In what capacity
Other playersNickname, avatar, country, score and time on leaderboards; during a shared match, also your progress and your mistakesDisclosure inherent in the service you chose to use
Google Ireland Limited / Google LLC — Firebase Cloud MessagingYour device's notification token and the content of the notification to deliverProcessor acting on our behalf under Article 28 GDPR, under the Google Cloud Data Processing Terms
Google Ireland Limited / Google LLC — AdMobThe advertising data listed in § 3.7Independent controller
Aruba S.p.A. (or another server infrastructure provider)Hosts the machine running our server and database, in ItalyProcessor under Article 28 GDPR

The e-mails we send you (address verification, password reset) are sent from our own mail server: your address is not handed to any third-party sending platform.

Data may also be disclosed to public authorities, courts or law enforcement where required by law or necessary to establish, exercise or defend a legal claim.


6. Where the data lives, and transfers outside the European Union

Our data is in Italy. The Zenary Sudoku server and its PostgreSQL database run on a machine hosted in Italy. The database is not reachable from the internet: it listens only on the machine itself, and is accessed only through an encrypted administrative channel.

Only two flows leave the European Union, both to Google:

Such transfers take place on the basis of the safeguards set out in Chapter V GDPR, and in particular:

which the European Commission adopted an adequacy decision on 10 July 2023 pursuant to Article 45 GDPR. Certification status is publicly verifiable at https://www.dataprivacyframework.gov/.

decision, Google relies on the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, pursuant to Article 46(2)(c) GDPR, together with supplementary measures.

You may request information about the safeguards in place by writing to comida.giampaolo@gmail.com, or consult the terms published by Google at https://business.safety.google/.


7. How long we keep data

Type of data Retention period Who holds it
Games in progress, local statistics, preferences, game credits, local remindersUntil you erase them, or until you uninstall the AppYour device only
Profile: identifier, nickname, avatar, country, friend codeUntil you ask for deletion (Settings → Your data → Delete my data)Our server
E-mail address and password hashUntil you ask for deletion. If the address is never verified: 7 daysOur server
Verification and password-reset linksExpire within hours and work once only; the row is deleted one day after expiryOur server
Device (session) token1 year from issue, then it must be renewed. It lapses immediately on password change and on data deletionYour device, verified server-side
Game results and leaderboard entriesUntil you ask for deletionOur server
Battle outcomesUntil you ask for deletionOur server
Friendships, requests, blocksUntil you remove them or delete your data. Unanswered requests are cancelled when they expireOur server
Quick-match queue24 hours, then clearedOur server
Online presenceMemory only: no history, cleared when the service restartsOur server
Push tokens and notification preferencesFor as long as you keep notifications on. Deleted when you turn them off or delete your data. A token Firebase declares invalid is removed after 30 daysOur server
Aggregate per-puzzle statisticsPuzzles played by few people and idle for 30 days are deleted; the rest stay. They contain no user identifiersOur server
Database backupsOne nightly copy, kept on the same server; copies older than two weeks are deleted automaticallyOur server
Advertising consent stateUntil withdrawn or changed, and in any event no longer than 13 months, after which consent is requested againYour device
Advertising data (IP, identifiers, interactions)According to the retention periods set by Google in its own policies, over which we have no controlGoogle

⚠️ An honest word about backups. When you delete your data it disappears immediately from the live database, and therefore from the leaderboards and from anyone's view. It may however remain for a short while inside backups already taken — which nobody consults, and which are overwritten and finally deleted within two weeks. It would be misleading to tell you "erased everywhere, instantly": it is erased where it counts immediately, and gone entirely within two weeks.

Any e-mails you send to comida.giampaolo@gmail.com are kept for as long as needed to handle your request and in any event no longer than 24 months, unless longer retention is necessary to defend a legal claim.


8. Your rights (GDPR)

As a data subject you have the rights set out in Articles 15 to 22 GDPR:

Right Reference What it means here
AccessArt. 15Confirmation of whether processing is taking place and a copy of the data. Most of what concerns you is already visible in the App: profile, statistics, leaderboards, friends
RectificationArt. 16Correction of inaccurate data. Nickname and avatar you change yourself in Settings → Profile
Erasure ("right to be forgotten")Art. 17Deletion. **You can do it yourself, immediately, from *Settings → Your data → Delete my data*** (see below); for advertising data the right is exercised against Google
RestrictionArt. 18Restriction of processing in defined cases
PortabilityArt. 20Receiving your data in a structured, machine-readable format. Write to us and we will send you a file
ObjectionArt. 21Objection to processing based on legitimate interests. You have an unconditional right to object to processing for direct marketing purposes, at any time and without having to give reasons
Withdrawal of consentArt. 7(3)Withdraw advertising or notification consent at any time, as described in §§ 3.6 and 4.3
ComplaintArt. 77Lodge a complaint with a supervisory authority

8.1 The deletion you can perform yourself, in ten seconds

Settings → Your data → Delete my data, with a double confirmation. When you confirm:

matchmaking queue entry, push tokens and notification preferences, and any e-mail address with its password hash, are removed from our server**;

nobody can reach you, and anyone who had you as a friend no longer finds you;

What remains is a technical row with no informational content, marked as deleted, whose only job is to stop the identifier from being reassigned. The operation cannot be undone, and the App tells you so before performing it.

8.2 Exercising your rights by writing to us

Write to comida.giampaolo@gmail.com. We reply without undue delay and in any event within one month of receiving the request, extendable by two further months where the request is complex, in which case we will tell you. Exercising your rights is free of charge.

⚠️ One limitation you should know about, and which we state openly. If you have not attached an e-mail address to your profile, all we know about you is a random identifier and a nickname: on receiving a message from some e-mail address, we have no way of verifying that the profile is yours, and handing over — or erasing — someone else's profile at a stranger's request would be a worse breach than the one we are trying to avoid. This is the situation described in Article 11 GDPR: we are not required to keep extra data for the sole purpose of being able to identify you.

In practice, then:

device and does not require us to identify you;

act on any request;

in-app route. This is not a device for avoiding a reply: it is the direct consequence of having designed the App so that you can play without saying who you are.

How to exercise them with Google: use the tools Google provides at https://policies.google.com/privacy and https://adssettings.google.com/.

Supervisory authority. If you believe the processing infringes the GDPR you may lodge a complaint with the Italian Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy — www.garanteprivacy.it — protocollo@gpdp.it. You may also lodge a complaint with the supervisory authority of your own EU Member State of residence, place of work or place of the alleged infringement. Your right to an effective judicial remedy is unaffected.


9. Children

The App is not directed to children and is not intended for an audience of minors. We do not classify it as a children's app on the stores and we do not participate in the stores' families programmes.

The App is intended for an audience aged 13 or over (Google Play) and carries an appropriate age rating on the App Store.

Under Article 8 GDPR, the age at which a child can validly consent to information society services ranges from 13 to 16 years depending on the Member State; in Italy the threshold is 14 years (Article 2-quinquies of Legislative Decree 196/2003). Below that age, consent must be given or authorised by the holder of parental responsibility.

In the United States, the App is not directed to children under 13 within the meaning of the Children's Online Privacy Protection Act (COPPA), and we do not knowingly collect personal information from children under 13.

9.1 How the social side was designed with younger players in mind

These are not good intentions: they are technical choices, and we list them so they can be checked.

feature that lists players or searches them by nickname. If you do not hand out your code, you cannot be reached.

then having to keep it. The age band is declared in the store listings.

9.2 Parents and guardians

We do not knowingly collect data from children below the applicable threshold. If you are a parent or guardian and believe your child is using the App in a way you would not have authorised, you can:


10. Security

We apply technical and organisational measures appropriate under Article 32 GDPR:

over TLS-encrypted channels with a valid, automatically renewed certificate; the same holds for the advertising SDK's traffic;

within hours, and work once only;

reached solely through an encrypted administrative channel;

data deletion invalidate every open session immediately, on every device;

e-mail address, against automated attempts;

reading it, and benefits from device encryption where the user has set a passcode;

Firebase, the server) is protected by multi-factor authentication or by cryptographic key, and limited to strictly necessary personnel.

No system is absolutely secure. In the event of a personal data breach posing a risk to your rights and freedoms, we will act in accordance with Articles 33 and 34 GDPR: notification to the supervisory authority within 72 hours and, where the risk is high, communication to the data subjects.


11. Permissions requested by the App

The App requests the minimum possible set of system permissions:

Permission Platform Why
Internet accessAndroid, iOSLeaderboards, friends, multiplayer, notifications and advertisements. Solo play works offline and results are sent once the connection is back
Network stateAndroidTo know whether attempting a request or loading a video makes sense
NotificationsAndroid 13+, iOSRequired to show you push notifications and local reminders. If you deny it, the App still works and you simply see no alerts
com.google.android.gms.permission.AD_IDAndroidAllows the advertising SDK to access the device advertising identifier, within the limits of the consent you gave
Tracking request (ATT)iOSAllows us to ask your permission to use the IDFA. If you deny it, the App still works

The App requests no location, camera, microphone, contacts, calendar, external storage or phone permissions.


12. Notice for United States residents (CCPA / CPRA and comparable state laws)

This section supplements the Policy for residents of California under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and applies by analogy to residents of other U.S. states with a comprehensive consumer privacy law (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others), to the extent those laws apply.

12.1 Categories of personal information collected in the last 12 months

CCPA category Collected? Examples Source
IdentifiersYesInternal user identifier, nickname, friend code, device token, notification token; e-mail address only if you attach one; Advertising ID / IDFA / App Set ID and IP address via Google's SDKDirectly from the device and from you
Commercial informationNo
Internet or other electronic network activityYesGame results, use of the social features; ad interactions and ads viewedFrom the App and via Google's SDK
Geolocation dataYes, coarse onlyTwo-letter country code derived from the IP address; approximate area estimated by Google. We do not collect precise location and do not request the location permissionFrom the IP address
Inferences (preference profile)Yes, by GoogleInterest segments used for personalised advertising. We build noneGoogle
Sensitive personal informationNo
Protected classifications, biometric, professional, education, audio/visual, customer recordsNo

Purposes: running the connected game (profile, leaderboards, statistics, friends, challenges and battles), delivering the notifications you asked for, preventing cheating and abuse, serving advertising (personalised or non-personalised depending on your choices), measuring its performance, capping its frequency and preventing ad fraud.

12.2 "Sale" and "sharing" of personal information

We do not sell personal information for money. However, the CPRA definitions of "sale" and especially "sharing" (disclosure for cross-context behavioural advertising) are broad: making advertising identifiers available to Google and its partners for the selection of personalised ads may qualify as "sharing" under the CPRA and as "targeted advertising" under other states' laws.

We therefore treat that activity as subject to a right to opt out.

Your public profile (nickname, avatar, country, score) is visible to other players because that is what a leaderboard is, but it is neither a sale nor a sharing for advertising purposes: it does not go to advertisers and it is not used to select ads.

We do not knowingly sell or share the personal information of consumers under 16 years of age.

12.3 Your rights and how to exercise them

You have the right to:

the notice at collection);

penalty**: a user who opts out of personalised advertising gets the same 3 games, the same free timed recharge, the same free daily challenge and the same features as anyone else.

Fastest way to opt out: open Settings → Privacy → Ad settings inside the App and turn off personalised advertising. That choice is transmitted to Google and its partners through the consent signals provided for the United States. Additionally, or alternatively, you can disable ad personalisation at system level:

Written requests: write to comida.giampaolo@gmail.com with the subject line "Privacy request — California" (or your state). We respond within 45 days, extendable by a further 45 days with notice. You may act through an authorised agent, who must demonstrate authorisation. The limitation described in § 8.2 applies here too: if you have not attached an e-mail address to your profile we cannot verify that it is yours, and we will point you to the in-app deletion.

12.4 Opt-out preference signals

The App is a mobile application, not a website: the Global Privacy Control (GPC) browser signal is not technically applicable in this context. The in-app opt-out mechanism described above serves the same function.


13. Third-party links and services

Advertisements may contain links to third-party websites or app store listings. If you tap an ad, you leave our App and arrive at a destination operated by someone else, governed by their privacy policy, over which we have no control and for which we are not responsible. We encourage you to read it.

The same applies if you share a result or a challenge invitation through your phone's sharing sheet: from that moment the content is in the hands of the app you picked (messaging, mail, social) and of its own privacy policy.


14. Changes to this Policy

We may update this Policy to reflect changes to the App, to the services it uses, or to applicable law. The current version is always available at https://zenary.cosmocomunicazione.it/privacy and shows the date of last update at the top.

Where changes are material — in particular where they introduce new processing purposes, new recipients or the use of new categories of data — we will notify you inside the App before the changes take effect, and where the change concerns consent-based processing we will ask for fresh consent. Continuing to use the App after a non-material update constitutes acknowledgement of the updated Policy.

Version history

Version Date Changes
1.013 September 2026First publication
1.114 September 2026Substantial rewrite. Version 1.0 described a purely local App, with no server and no social features: it no longer matched the product. Added: anonymous identity and optional e-mail-and-password account, public profile (nickname, avatar, country derived from IP), result submission and leaderboards, friends by code, online presence, challenges and battles with live progress sharing, push notifications through Firebase Cloud Messaging, the list of recipients and the location of the data in Italy, retention periods for each category, and in-app data deletion. Clarified that no third-party usage-analytics or crash-reporting service is in use. Updated the description of the game economy (3 games, then a free two-hour recharge or a rewarded video; the daily challenge is always free)

15. Contact

For any question about this Policy or about the processing of your data:

Cosmo Srls
Via Fiume Giallo 362, 00144 Roma (RM), Italia
VAT IT14795571000
comida.giampaolo@gmail.com


Updated on 14 September 2026. This text is drafted on the basis of the information supplied about how the App works and of a review of the source code of the application and the server carried out on the same date, together with the law and platform policies then in force. It does not constitute and does not replace signed legal advice. Before publication the company must verify that the text matches what the software actually does: a privacy policy describing processing other than that actually carried out is itself a violation. If in-app purchases, usage-analytics or crash-reporting connected to external services, a chat or any free-text exchange between users, image uploads, or further SDKs are introduced, this Policy must be updated before the feature reaches users.