Winklo

Privacy Policy

Last updated: 8 October 2026

Winklo is a set of quick daily solo puzzles — Zip, Path Words, and Sudoku. You sign in with Google to play, use the live leaderboard, keep a cloud profile, and sync progress. This policy explains what stays on your device and what is processed in the cloud.

Short version: We do not run ads and we do not sell data. Google Sign-In is required for Zip, Path Words, Sudoku, the leaderboard, and profile. Your game progress syncs privately to your account. We use Google Firebase (Auth, Firestore, Analytics, Crashlytics, Remote Config, Cloud Messaging) and Cloudflare (avatar upload Worker + R2) to run those features.

Information stored on your device

Local preferences may include tutorial flags, sound settings, notification schedules, unfinished puzzle runs, game progress, and cached puzzle data. Uninstalling Winklo or clearing app storage removes local data. Your cloud profile and leaderboard scores are separate (see below).

When you sign in again, your streaks and your daily results for the current and previous day are restored from synced progress; older daily results stay with your account. If a different Google account signs in on the same device, the previous account’s local progress is removed from view. Any of it that had not synced yet is kept aside on the device and restored when that account signs in there again.

Account and profile

When you sign in with Google, Firebase Authentication creates an account tied to your Google identity. We store a Firebase user id (uid), display name, optional profile photo URL, and optional preset avatar id on users/{uid}. Your display name and photo/avatar may appear on Zip, Path Words, and Sudoku leaderboards visible to other players in the app.

You may choose a gallery photo. The app uses the system photo picker (no broad photo-library permission). The image is uploaded as JPEG to our Cloudflare Worker and stored on Cloudflare R2 at a public URL (for example on r2.dev). Preset avatars are bundled in the app and do not upload a photo.

An FCM device token may be stored on your user document so we can send topic messages (for example announcements and app updates). The app may also schedule local notifications on the device.

Gameplay scores

Personal-best times for Zip, Path Words, and Sudoku sync to Firestore leaderboards (daily and all-time). Each leaderboard entry stores your uid, display name, avatar/photo, best time, whether you used hints or made mistakes on that run, your current streak, and when it was updated. Other players can see these on those boards.

Synced game progress

So streaks and current daily progress survive a reinstall or a new device, Winklo stores your game progress in Firestore under your account: for each daily puzzle you play, your best time and points, whether you used hints or made mistakes, how many hints you used that day, and when you cleared it; and for each game, your current and longest streak, the day you last cleared it, and whether a streak freeze is available. This progress is private to your account — only you (signed in) can read or change it, and it is not shown to other players. The app also uses it to re-send a cleared puzzle’s time to the leaderboard if an earlier submit failed.

Other network processing

Google may process technical data such as IP address and Firebase installation identifiers. See Firebase’s privacy information and Google’s privacy policy. Cloudflare’s processing for Workers/R2 is described in Cloudflare’s privacy policy.

The app may load the Lexend font from Google Fonts; Google may see your IP address for that request.

What we do not collect

Children

Winklo is not directed at children under 13. We do not knowingly collect personal information from children.

Your choices and account deletion

You can sign out in Profile. You can stop using network features by staying signed out (Zip, Path Words, and Sudoku require sign-in). Analytics and Crashlytics collection is required for the app’s current design (no in-app opt-out toggle).

There is no in-app “delete account” button yet. To request deletion of your account and associated cloud data (profile, leaderboard entries, synced game progress, daily app-open records, issue reports, and custom R2 avatar if any), open a GitHub issue and include the Google account email you used to sign in and your Firebase uid if you know it. We will delete that data within 30 days of a verified request.

Contact

Questions about this policy: open an issue on GitHub.