Privacy policy
This policy explains what Magnitudle — the mobile game and this website, magnitudle.fit — collects about you, why, who else receives it and how long it is kept. It covers the game, the website and the servers behind them. It is written to be read, not to be survived, so it says plainly what happens rather than reserving every right we could imagine.
The short version. Magnitudle shows no advertising and contains no advertising, analytics, attribution or crash-reporting software from any other company. It does not read your advertising identifier and does not track you across other apps or websites. What we hold is the account you create, how you played, and a small set of technical facts needed to run the game. You can delete all of it, in the app, on this website or by writing to us. The website sets no cookies and counts visits with a cookieless tool we run ourselves. Like every web server, ours records the technical data each request carries, such as your IP address, in access logs kept for 14 days; beyond that, the only personal data the website receives is what you send through one of its forms.
1. Who is responsible
The controller of your personal data is:
FREEDOM LLP (formerly ARTADIAN GAMING LLP), a limited liability partnership registered in England and Wales under company number OC407608, registered office 101 King's Cross Road, London WC1X 9LP, United Kingdom.
For anything in this policy, including requests about your data, write to office@freedomgaming.co.
2. What the game collects
Your account
You can play as a guest without giving us anything that identifies you. A guest account holds only a nickname and your game progress.
If you create a full account, we hold, depending on how you sign in:
- your nickname, which other players can see in multiplayer matches and on leaderboards;
- your email address, if you save your account with email, or if Google or Apple provides one when you link it;
- your password, stored only as a cryptographic hash — we never hold the password itself;
- an identifier from Game Center if you sign in with it, or from Google or Apple if you link one of them to your account. This is the account identifier those services give us, not your password with them.
How you played
Your experience points, game statistics, skill rating, level progress, achievements, the rounds you played and their results, multiplayer match records, friend connections and invite codes you created.
If you block another player, we keep the list of players you have blocked, so that you are kept apart in multiplayer and their nickname stays hidden from you. If you report another player’s nickname, we keep the report — who reported whom, the nickname at that moment, the reason you chose and where you saw it — so that a moderator can review it.
Technical facts about your app
The platform you play on (iOS, Android or web), the app version and runtime version, and when you were last seen. If you turn on notifications, we also hold your push token and the language you chose, so a reminder arrives in the right language.
Product analytics
The app reports a fixed list of twenty named events — things like “a level was started” or “a match ended”. In our game database each event is stored with your account identifier, the event name, when it happened, the platform, the app version and a small set of properties defined in advance for that event. There is no free-text field.
Those stored events contain no IP address, no user agent, no device identifier, no email address and no nickname. The session identifier the app generates is never stored as sent: it is replaced by a salted hash so that sessions can be counted without being traced back.
The app also sends a copy of the same events to our own analytics service (appanalytics.ai, operated by FREEDOM LLP), which we use to compare our games with each other. There the events are keyed not by your account but by a random identifier the app creates on your device, and they additionally record when the app was installed or updated, when it was opened and closed, the platform, the app and operating-system version and, on Android, the device model name. The service works out a country from the IP address each request comes from and keeps the country, not the address. It is not an advertising identifier and it is not shared with anyone.
Feedback you send from the app
Now and then the app asks whether you are enjoying the game. If you answer that it could be better and write us a message, we receive your message together with your nickname, your account identifier, your email address if your account has one, your experience points, the number of levels you have completed, your platform and app version, and where in the game you were asked (a level, the daily challenge, multiplayer or settings). It is delivered to a channel our team reads in Discord.
Security records
When something significant happens to an account — a deletion is requested, cancelled or carried out — we record the event with a hashed form of the IP address it came from, and the browser or app user-agent string. The hash lets us recognise repeated abuse without storing the address itself.
Server logs
Our web servers — for the game and for this website — record ordinary access logs, which do contain plaintext IP addresses. These logs are rotated daily and kept for 14 days, then deleted.
3. What this website collects
You can read this website without telling us who you are. It has no accounts and no log-in, and the pages are the same for every visitor. Every request to it passes through Cloudflare, the network that delivers our pages (section 6).
Visitor statistics
We count visits with a statistics tool that we run ourselves, on our own server. It sets no cookies and stores nothing on your device. For each page view it records the page address, the page you came from, your browser, operating system, device type, screen size and language, and your country. The country is worked out from your IP address, which the statistics tool then discards and never stores (the server's own access logs are described under Server logs in section 2).
It also records a fixed list of events: a click on the App Store or Google Play button, or a QR code for either being shown, an answer in a sample round, a comparison you make in a comparison tool, a change of language or an answer to the language suggestion, a click on a source link, the topic (never the content) of a contact form message, a visit to an invite or shared-result page, and measurements of how fast pages load. None of these contain your name, your email address or anything else you typed.
The contact form
When you write to us through the contact form, we receive your email address, the topic you chose, your message, the size you are reporting if it is a correction, and the language of the page you sent it from. It reaches our support mailbox as an email, with your address set as the one we reply to. To prevent abuse, our server also uses your IP address and your email address to limit how many messages can be sent in 15 minutes; for that purpose they are held only in memory, briefly, and are not stored with your message.
Reports of a wrong size
If you choose “A correction to a size”, we also keep a record of your report in our database: the item, your message and your email address, and later whether we changed the size and a short note. Resolved reports are listed in the public correction log with the item, the outcome, the date and our note only — never your email address or your message.
The account deletion form
The form on Delete your account sends the email address you enter, and then the code and the password you enter, straight to our game server to confirm the deletion. What happens next is the same as deleting in the app (section 7), and it is recorded as described under Security records in section 2.
What your browser remembers
If you close the suggestion to read a page in another language, your browser remembers that choice in its own local storage so the suggestion doesn't come back. It stays on your device and is never sent to us. Nothing else is stored on your device.
4. What we do not do
- No advertising. The game shows no ads and contains no advertising software. Neither does this website.
- No third-party tracking. There is no Firebase, no AdMob, no AppLovin, no Meta or TikTok SDK, no attribution or crash-reporting service. Analytics is entirely our own: it goes to our game server, to FREEDOM LLP's own analytics service and, for this website, to the statistics tool we run ourselves — never to another company.
- No cookies on this website. It sets no cookies, has no tracking pixels and loads nothing from other companies' servers.
- No advertising identifier. The app does not read the IDFA or any advertising ID, and does not present the App Tracking Transparency prompt, because it has nothing to ask for.
- No cross-app or cross-site tracking, and no profiling that produces legal effects for you.
- We do not sell your personal data, and we do not share it for anyone else's advertising.
5. Why we use it, and on what legal basis
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Creating and running your account, saving progress, matching you with opponents, leaderboards | Performance of a contract (Art. 6(1)(b)) |
| Sending the emails the game needs to work: password reset codes, account deletion codes, and the notice that an account has been anonymised | Performance of a contract (Art. 6(1)(b)) |
| Keeping accounts secure, preventing abuse and cheating, rate limiting, reviewing reported nicknames and applying blocks between players | Legitimate interests (Art. 6(1)(f)) — running a fair game |
| Understanding how the game is used, so it can be improved | Legitimate interests (Art. 6(1)(f)) — balanced against you by keeping the events to a fixed list, with no free text and no advertising identifier |
| Reading feedback you choose to send from the app | Legitimate interests (Art. 6(1)(f)) — acting on what players tell us |
| Counting visits to this website and seeing which pages and buttons are used | Legitimate interests (Art. 6(1)(f)) — improving the website, with no cookies and no profile of you |
| Answering messages you send through the contact form | Legitimate interests (Art. 6(1)(f)) — replying to you; where your message is about your account, performance of a contract (Art. 6(1)(b)) |
| Checking reports of a wrong size and publishing the correction log | Legitimate interests (Art. 6(1)(f)) — keeping our sizes accurate and being open about corrections |
| Push notifications | Consent (Art. 6(1)(a)) — you grant it in the operating system and can withdraw it at any time |
| Keeping records we are required to keep, or responding to a lawful request | Legal obligation (Art. 6(1)(c)) |
6. Who else receives it
We use a small number of service providers. Each receives only what its job requires.
| Who | What reaches them | Where |
|---|---|---|
| DigitalOcean (hosting) | Everything the game and this website store, because our servers and database run on their machines | Frankfurt, Germany (EU) |
| Cloudflare (website delivery) | Every request to this website: your IP address, the address of the page and your browser's request headers, so that it can pass the request to our server and serve saved copies of our public pages | Worldwide, at the Cloudflare data centre nearest to you; Cloudflare, Inc. is in the United States |
| Resend (email delivery) | Your email address and the contents of the few emails we send, and the messages you send through the contact form | Sent from Ireland (EU); Resend states that account metadata and delivery logs are held in the United States |
| Expo (650 Industries): app updates and push relay | See below | United States |
| Apple | Game Center and Sign in with Apple, if you use them; notification delivery to iOS devices | United States and elsewhere |
| Only if you choose to link Google to your account. Google tells us your account identifier, email address and name; we tell Google nothing about you | United States and elsewhere | |
| Discord | Feedback you choose to send from the app, with the details listed in section 2 | United States |
What Expo receives, specifically
Two separate things, and we would rather spell them out than hide them under “service providers”:
- Update checks. On every launch, before you sign in and without any action from you, the app asks Expo whether a newer version of the game code is available. That request carries a random identifier created when the app was installed, the platform, the app's runtime version and the update channel. If the previous launch ended in a crash, a shortened copy of the error message is included. This identifier is tied to the installation, not to you, and is not an advertising identifier.
- Push notifications. If you allow notifications, the app exchanges the device token issued by Apple or Google for an Expo push token, and our reminders are delivered through Expo's push service, which passes them to Apple or Google. Expo therefore sees the device token and the contents of the notification.
International transfers
Our servers, database and backups are in Frankfurt, Germany, so the bulk of the processing stays inside the European Union. FREEDOM LLP is established in the United Kingdom, which the European Commission has recognised as providing an adequate level of protection. Where a provider above processes data in the United States, that transfer relies on the safeguards that provider offers, such as the EU–US Data Privacy Framework or standard contractual clauses.
7. How long we keep it
- Your account and game data — for as long as the account exists.
- After you ask us to delete it — the account is scheduled for deletion and held for a 14-day grace period, so that a request made in anger or by mistake can be cancelled. To cancel it during that time, write to us and we will restore the account.
- Then it is anonymised. Your email address, password hash and your Google, Apple and Game Center identifiers are removed from the account, and we send you a notice that this has happened. What remains cannot be linked back to you.
- An encrypted archive of the removed identity fields is kept for 90 days and then destroyed. It exists only so that a deletion carried out in error, or a serious abuse investigation, can be resolved within that window.
- Our analytics service — raw events for 90 days; per-device summaries (first and last seen, sessions, platform, versions, country) for as long as we run the service. They are tied to the random device identifier, not to your account. When you delete your account, the app replaces that identifier with a new one, so nothing afterwards is connected to it.
- Feedback sent from the app — in our team's Discord channel until we delete it. Ask us and we will delete yours.
- Contact form messages — in our support mailbox for as long as we need them to answer you and to deal with any follow-up.
- Reports of a wrong size — the full report, with your email address, while we deal with it and afterwards as the record of what changed, until you ask us to delete it. The public correction log never contains your email address or your message.
- Website visitor statistics — they contain no personal data, so we keep them for as long as they are useful.
- Blocks and reports — for as long as your account exists. When an account is deleted, the blocks it made and the reports it filed are deleted with it, and reports about it no longer carry its nickname.
- Server access logs — 14 days.
- Short-lived security records — password reset codes, deletion codes, sign-in tokens and invite codes all expire on their own and are removed automatically when they do.
8. Your rights
If the UK GDPR or the EU GDPR applies to you, you have the right to access the data we hold about you, to have it corrected, to have it erased, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on consent, you can withdraw it at any time without affecting what was done before.
The quickest route to erasure is in the app: open the Profile tab, scroll to Danger zone and tap Delete account. You can also delete your account on this website. Everything in section 7 then happens automatically. For anything else, write to office@freedomgaming.co and we will respond within one month.
If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to a data protection authority: in the United Kingdom that is the Information Commissioner's Office (ico.org.uk); in the EU or EEA it is the authority for the country where you live or work.
9. Children
Magnitudle is a general-audience game. It is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has created an account, write to office@freedomgaming.co and we will delete it.
10. Security
Traffic between the app and our servers is encrypted in transit, and this website is served only over encrypted connections. Passwords are stored only as hashes, never in a form we could read. Reset codes, deletion codes and invite codes are stored as hashes too, so a copy of our database would not reveal a working code. The archive described in section 7 is encrypted. Access to the production server is restricted to named administrators using SSH keys; password logins are disabled.
No system is perfectly secure. If a breach ever affects your rights, we will tell you and the relevant authority as the law requires.
11. Changes
If this policy changes in a way that affects you, we will update the effective date above and, where the change is significant, tell you in the app. Earlier versions are available on request.
Published by FREEDOM LLP · company no. OC407608 · office@freedomgaming.co