1. Scope and controller
This policy covers the Patches iPhone app by youcloud GmbH, Waaghausgasse 3, 3011 Bern, Switzerland (UID CHE-427.270.675). Privacy and support contact: info@youcloud.ch. Apple’s own privacy terms also apply to the App Store and iCloud.
2. Data on your device
Patches stores puzzle progress, completed and archived attempts, times, hints, unlocked levels, coins and ledger entries locally, together with language and appearance preferences. This enables progress, statistics and offline play.
3. iCloud sync
When iCloud is available, the app syncs progress and coin entries through Apple’s private CloudKit database. With leaderboard participation enabled, profile credentials and access tokens are also stored there so your devices can use the same profile. This is not a public iCloud database. Apple processes account and connection data under its terms. Manage iCloud in your device settings.
4. Optional leaderboard
We ask for consent before participation. We then upload all retained past and future completed attempts: random player and attempt IDs, level and version, completion time, hints used, completion date and app version. We also store an optional player name, creation and submission timestamps and technical credentials. Unfinished puzzles and your coin balance are not sent to the leaderboard API. Player ID, name or “Anonymous”, derived avatar, best times and ranks are public. Do not use confidential information as your name. The global leaderboard also publicly shows completed level count, total hints used and total time.
5. Player-name reports
When you report a player name, we store the reporting and reported profile IDs, the reported name, your optional comment, the timestamp, review status and, where applicable, an internal review note. This information is used to review inappropriate names and is not public. Please do not include sensitive information in comments. Reports are removed from the active database when either associated profile is deleted; the backup retention rules below apply.
6. Purchases and offer codes
Apple processes In-App Purchases and offer codes. Patches verifies StoreKit transactions and stores product and transaction identifiers and corresponding coin entries to process credits and refunds without duplication. We do not receive card or bank details.
7. Operation, recipients and international processing
The leaderboard API and Aurora database run on Amazon Web Services in Frankfurt, Germany (eu-central-1). Requests involve technical connection data such as IP address, time and HTTP request data for operation, troubleshooting and abuse prevention. AWS provides hosting; Apple provides iCloud and StoreKit. Apple services may process data outside Switzerland and Germany; see Apple’s privacy policy. We do not sell personal data or use advertising or analytics SDKs in the app.
8. Retention, withdrawal and deletion
Local progress remains until you delete the app or its data; manage iCloud data separately in iCloud settings. Leaderboard data remains until profile deletion. “Delete player profile” stops participation and removes the profile, tokens and associated results from the active leaderboard database. Progress and coins remain. An iCloud deletion marker prevents automatic recreation. Data uploaded before consent was introduced remains until deletion; further uploads await consent. AWS operational logs are normally deleted after one day; remaining logs and database backups, including manual snapshots, are deleted within seven days. Deleted profile data may remain in backups until then. If a backup is restored, previous profile deletions are reapplied.
9. Purposes, rights and contact
Processing supports gameplay, requested sync, purchases and the leaderboard with revocable consent. Where GDPR applies, necessary service delivery relies on Article 6(1)(b), leaderboard participation on (a), and technical security on (f). Depending on applicable law, you may request access, correction, deletion, restriction, portability or object to processing. Withdrawal applies to future processing. Contact info@youcloud.ch; we may need your player ID to identify your data, never your access token. You may complain to the Swiss FDPIC or your competent authority.
10. Children and changes
We do not require real names, dates of birth, contacts or location. Do not enter other people’s personal details. We update this policy when features or data processing change and seek new consent where required.
11. Visiting these information pages
These app and privacy pages load no advertising or analytics scripts. When you select a language, a necessary cookie remembers that choice for up to one year. Visiting the pages produces ordinary technical web-server connection data.