Winklo
Privacy Policy
Last updated: 8 October 2026
Winklo is a set of quick daily solo puzzles — Zip, Path Words, and Sudoku. You sign in with Google to play, use the live leaderboard, keep a cloud profile, and sync progress. This policy explains what stays on your device and what is processed in the cloud.
Information stored on your device
Local preferences may include tutorial flags, sound settings, notification schedules, unfinished puzzle runs, game progress, and cached puzzle data. Uninstalling Winklo or clearing app storage removes local data. Your cloud profile and leaderboard scores are separate (see below).
When you sign in again, your streaks and your daily results for the current and previous day are restored from synced progress; older daily results stay with your account. If a different Google account signs in on the same device, the previous account’s local progress is removed from view. Any of it that had not synced yet is kept aside on the device and restored when that account signs in there again.
Account and profile
When you sign in with Google, Firebase Authentication creates an
account tied to your Google identity. We store a Firebase user id
(uid), display name, optional profile photo URL, and optional preset
avatar id on users/{uid}. Your display name and
photo/avatar may appear on Zip, Path Words, and Sudoku leaderboards
visible to other players in the app.
You may choose a gallery photo. The app uses the system photo picker
(no broad photo-library permission). The image is uploaded as JPEG to
our Cloudflare Worker and stored on Cloudflare R2 at a public URL (for
example on r2.dev). Preset avatars are bundled in the app
and do not upload a photo.
An FCM device token may be stored on your user document so we can send topic messages (for example announcements and app updates). The app may also schedule local notifications on the device.
Gameplay scores
Personal-best times for Zip, Path Words, and Sudoku sync to Firestore leaderboards (daily and all-time). Each leaderboard entry stores your uid, display name, avatar/photo, best time, whether you used hints or made mistakes on that run, your current streak, and when it was updated. Other players can see these on those boards.
Synced game progress
So streaks and current daily progress survive a reinstall or a new device, Winklo stores your game progress in Firestore under your account: for each daily puzzle you play, your best time and points, whether you used hints or made mistakes, how many hints you used that day, and when you cleared it; and for each game, your current and longest streak, the day you last cleared it, and whether a streak freeze is available. This progress is private to your account — only you (signed in) can read or change it, and it is not shown to other players. The app also uses it to re-send a cleared puzzle’s time to the leaderboard if an earlier submit failed.
Other network processing
- Cloud Firestore — puzzle catalogs; the user, leaderboard, and synced progress data described above; a daily app-open record (uid, first/last open time, platform); issue reports you submit (with your uid, display name, avatar, and app version); and app error reports.
- Firebase Analytics — product events (screens, games started/completed, hints, tutorials, and similar). Events may include gameplay metadata and device/installation identifiers from Google’s SDKs.
- Firebase Crashlytics — crash logs from release builds (stack traces, device/OS info). Not enabled for typical debug builds.
- Firebase Remote Config — operator settings such as minimum app version / build for update prompts.
- Path Words noun pool — the app may fetch a shared daily word list from our Cloudflare Worker.
Google may process technical data such as IP address and Firebase installation identifiers. See Firebase’s privacy information and Google’s privacy policy. Cloudflare’s processing for Workers/R2 is described in Cloudflare’s privacy policy.
The app may load the Lexend font from Google Fonts; Google may see your IP address for that request.
What we do not collect
- No advertising identifiers used for ads (the app has no ads)
- No precise location, contacts, or microphone
- No payment or health information
- No sale of personal information
Children
Winklo is not directed at children under 13. We do not knowingly collect personal information from children.
Your choices and account deletion
You can sign out in Profile. You can stop using network features by staying signed out (Zip, Path Words, and Sudoku require sign-in). Analytics and Crashlytics collection is required for the app’s current design (no in-app opt-out toggle).
There is no in-app “delete account” button yet. To request deletion of your account and associated cloud data (profile, leaderboard entries, synced game progress, daily app-open records, issue reports, and custom R2 avatar if any), open a GitHub issue and include the Google account email you used to sign in and your Firebase uid if you know it. We will delete that data within 30 days of a verified request.
Contact
Questions about this policy: open an issue on GitHub.