Turnlight · iOS
Privacy Policy
1. Scope and controller
This Privacy Policy applies to the Turnlight mobile application for iOS (the “App”) and this legal and support website (together, the “Services”).
The data controller responsible for the Services is Maksim Vinnik, operating under the name Dante, Poland.
2. Information processed
The categories below describe the first public version of Turnlight. The exact information available to a provider can depend on your device, region, consent choice, App settings, and the provider’s current SDK version.
Local gameplay and settings
Turnlight stores game progress, the current puzzle state, sound and vibration preferences, ad cadence information, and the local state needed to recognize a Remove Ads entitlement. This information is stored on your device and is not uploaded to a Dante-operated server.
Advertising — Google AdMob
When advertising is allowed by the applicable privacy choice, Google Mobile Ads may process IP address and general location derived from it, app or developer-bounded device identifiers, advertising data such as ads shown, ad interactions, app interaction data, performance information, and diagnostic data. Turnlight is configured for contextual or non-personalized ads.
Turnlight does not request Apple’s App Tracking Transparency permission, does not access IDFA, and does not use information to track you across apps or websites owned by other companies.
Analytics — Google Analytics for Firebase
When analytics collection is allowed, Firebase may process an app-instance or installation identifier, app version, device and operating-system information, language and general region, session information, and a limited set of gameplay events.
Turnlight’s gameplay events can include app and level starts, level number and stable level ID, authored or procedural source, difficulty and topology categories, active component count, rotations and move count, active duration, restarts, zoom actions, puzzle completion, ad request outcomes, and the outcome of Remove Ads purchase or restore actions. These events do not include your name, email address, free-form text, precise location, payment-card details, StoreKit receipts, or a developer-created account ID.
Diagnostics — Firebase Crashlytics
When crash reporting is allowed, Crashlytics may process a Crashlytics installation UUID, Firebase installation ID, session identifier, crash time, crash traces, app bundle identifier and version, device model, operating-system version, processor and memory information, disk information, and an indication of whether the device is jailbroken. Turnlight does not intentionally place names, email addresses, StoreKit receipts, or puzzle source filenames in crash reports.
App configuration — Firebase Remote Config
Remote Config uses a Firebase installation ID and technical app information to return configuration values to the App. It is used to tune declared functionality safely, not to create user accounts, deliver cloud saves, or silently add undisclosed data collection.
Privacy choices — Google User Messaging Platform
Google UMP requests current consent information and presents privacy messages where required. It processes and stores consent status and related request information so the App can determine whether advertising and related collection may start. Turnlight does not store the legal consent decision in the gameplay save.
Purchases — Apple StoreKit
Apple processes payments for the non-consumable Remove Ads purchase. The App receives product, transaction, purchase-result, and entitlement information needed to complete or restore the purchase. Dante does not receive your full payment-card details.
Support communications
If you email support, we receive your email address, message, and any information or attachments you choose to provide. Please do not send payment-card details, passwords, government identifiers, or full purchase receipts.
3. This website
This is a static website. It has no account system, contact form, advertising, cookies set by Dante, or first-party analytics. It is hosted on Cloudflare Pages. Cloudflare may process IP addresses and request metadata to deliver and secure the site under its own privacy terms. Clicking the email link opens your chosen email service; no message is sent until you choose to send it.
4. Why information is used
Information is processed only as needed to:
- save local progress and provide App functionality;
- deliver, limit, measure, and secure contextual advertising;
- understand aggregate gameplay performance and improve levels and controls;
- detect, diagnose, and fix crashes and technical failures;
- deliver safe configuration values to supported App versions;
- record and apply privacy choices;
- complete and restore the Remove Ads purchase;
- reply to support and privacy requests; and
- comply with legal obligations and protect the Services from abuse.
5. Legal bases
Where the GDPR, UK GDPR, or similar laws apply, processing is based on one or more of the following grounds:
- Consent for advertising, analytics, advertising measurement, and crash reporting where consent is required. You may withdraw consent at any time.
- Performance of a contract for core App functions and StoreKit purchase or restore actions you request.
- Legitimate interests in securing the Services, responding to support, diagnosing essential failures, and maintaining compatible app configuration, where those interests are not overridden by your rights.
- Legal obligation where processing is required by law.
6. Service providers and sharing
Information may be processed by the following providers:
- Google LLC and its affiliates — AdMob, Google Analytics for Firebase, Firebase Crashlytics, Firebase Remote Config, Google UMP, and Gmail support communications. See Google’s Privacy Policy and Privacy and Security in Firebase.
- Apple Inc. and its affiliates — App Store distribution, StoreKit purchases, refunds, and entitlement services. See Apple’s Privacy Policy.
- Cloudflare, Inc. and its affiliates — hosting, delivery, and security of this website. See Cloudflare’s Privacy Policy.
Providers are selected and contractually required to protect data in accordance with applicable law and the protections described in this Policy. Depending on the service and legal context, a provider may act as a processor/service provider or as an independent controller. Information may also be disclosed when required by law, to protect legal rights or safety, or in connection with a business transfer subject to appropriate notice and safeguards.
Dante does not sell personal information and does not knowingly share it for cross-context behavioral advertising. The first release is not configured for personalized advertising or IDFA access.
7. Retention and deletion
- Local data remains on the device until it is overwritten, reset by an available App control, or removed by deleting the App. StoreKit purchase records may remain with Apple so purchases can be restored.
- Google Analytics for Firebase user-level and event-level data is configured for a two-month retention period, with retention not reset by new activity. Standard aggregated reports may remain available for longer under Google’s service operation.
- Firebase Crashlytics retains crash stack traces and associated installation identifiers for 90 days before removal from live and backup systems begins.
- Firebase installation IDs used by Remote Config are retained until deletion is requested through the applicable Firebase interface. Google states that removal from live and backup systems occurs within 180 days after the deletion call.
- AdMob, UMP, StoreKit, and website delivery data are retained by the applicable provider according to its service terms, legal obligations, fraud-prevention requirements, and privacy policy.
- Support emails are normally retained for up to 24 months after the last interaction, then deleted unless a longer period is required for security, dispute resolution, or law.
When information is no longer necessary, it is deleted or anonymized, subject to backup cycles and legal retention requirements.
8. Your choices and rights
Depending on your location, you may have rights to:
- access, correct, delete, restrict, or receive a copy of personal data;
- object to processing based on legitimate interests;
- withdraw consent without affecting processing that occurred before withdrawal;
- appeal or complain to your local data-protection authority; and
- receive information about the categories of data and parties involved.
Where required, use Settings → Privacy Choices in the App to review or withdraw the applicable consent. Withdrawal stops future gated collection; provider retention periods still apply to information already processed. You can remove local gameplay data by deleting the App. A Remove Ads entitlement remains in your Apple account so it can be restored.
You may also email playturnlight@gmail.com. Because the first release has no account and Dante does not receive a direct identity tied to analytics events, we may be unable to identify a particular analytics record as yours. We will still explain and use the available provider tools to honor a valid request where reasonably possible. We may request limited information to verify and locate the request, but will not ask for your password or full payment receipt.
9. International processing and security
Turnlight is offered worldwide. Google, Apple, and Cloudflare operate internationally, so information may be processed outside Poland or your country. Where required, transfers rely on recognized safeguards such as adequacy decisions, standard contractual clauses, or the provider’s applicable certified transfer mechanism.
We use reasonable technical and organizational safeguards, minimize the information sent by the App, require encrypted network transport, restrict analytics event fields, and avoid direct account identifiers. No method of storage or transmission can be guaranteed completely secure.
10. Children
Turnlight is a general-audience puzzle game and is not directed specifically to children. The first release does not ask for a name, birth date, email address, or account. If you are below the age at which you can make privacy choices in your country, use the App only with the involvement of a parent or guardian. If you believe a child’s personal information was processed without the required authorization, contact us so we can investigate and take appropriate action.
11. Features not present in the first release
The first release does not provide user accounts, a Dante-operated server, cloud saves, or push notifications. If any of these features, personalized advertising, new SDKs, or additional data uses are added, this Policy will be updated before the change is released and consent will be requested where required.
12. Changes to this Policy
This Policy may be updated to reflect changes in the App, providers, or law. The effective date at the top will be revised. If a change materially affects your choices or how personal information is used, notice and renewed consent will be provided where required.
13. Contact
Maksim Vinnik (Dante), Poland
Email: playturnlight@gmail.com