Privacy policy
Privacy policy
Last updated 2026-07-31
Match & Spot (full store name “Match & Spot: Kids Puzzles”) is operated by TLM Software Design, Inc., a Michigan corporation with offices at 27280 Haggerty Road, Ste C-6, Farmington Hills, MI 48331, USA (“we”, “us”, “our”). The app is made for children aged 4 to 10, and this policy is written to the standards that come with that: COPPA in the United States, GDPR-K in the EU and the UK, Apple's Kids Category rules and Google Play's Families policy. It describes what the app collects, why, where it goes and what choices parents have. The app is still in development and has not been released on either store yet; this policy describes how it is designed and built, and we will update it here before launch if anything changes.
Summary for parents
- No ads, ever. The app contains no advertising SDKs of any kind.
- No personal information. No accounts, no sign-in, no names, no photos, no location, no advertising identifiers, no messaging. We never ask for, and cannot receive, anything that identifies your child.
- Playing is fully offline. Every card set and every scene ships inside the app; progress lives only on your device and is deleted with the app.
- The only network traffic is RevenueCat (verifying the one-time unlock) and Google Firebase (crash reports and anonymous usage counts, configured for children's-privacy compliance).
- Parents can turn reporting off entirely in the Parents Hub, which sits behind a parental gate, as do purchases and every outbound link.
What the app stores on your device
The following values are written to local storage on the device. None of it is transmitted to us or to any third party, and none of it identifies your child.
- Progress in both modes: which levels are finished in each pack, which cards or differences are already found in a level in progress, and hints used, so a kid never loses their place.
- Settings: the sound and music switches, and the optional timer or move counter a parent can turn on for older kids.
- Unlock entitlement cache: a local record, maintained by RevenueCat, of whether the one-time purchase is active, so the app can open levels without a network round-trip.
Network behaviour
All play, in both modes, runs locally and works in airplane mode, including the very first launch. Only two external services ever receive traffic:
If the device is offline the game runs normally: purchases retry when connectivity returns, and crash reports queue locally.
- RevenueCat, only when a parent starts or restores the one-time unlock (both behind the parental gate).
- Google Firebase: Crashlytics uploads a report if the app crashes, and Analytics records a small set of anonymous usage events, for example that a level was finished.
How reporting is configured for children
We use Firebase Analytics and Crashlytics in a deliberately restricted, kids-app configuration:
Firebase data is processed by Google and governed by Google's privacy policy. Analytics retention is capped at Google's defaults (up to 14 months) and Crashlytics reports can be purged on demand from our console.
- No user IDs are ever set, and no advertising identifiers (IDFA or the Android Advertising ID) are collected or requested. On iOS the app never shows the App Tracking Transparency prompt, because it never tracks.
- Events are a small fixed set of counters (level started, level finished, hint used, which mode was played, and the like) with no free-text fields. Nothing a child types can end up as personal data, because there is nowhere in the app to type anything.
- Crash reports contain stack traces, device model, OS version and app version: enough to fix bugs, nothing about the person holding the device.
- Parents can switch all of it off in the Parents Hub, behind the parental gate. We can also disable reporting remotely for every install if a compliance concern ever arises.
The parental gate
Everything that leads out of the kid-safe play area sits behind a parental gate: the purchase and restore flow, the Parents Hub, settings that affect play, data deletion, and any link that leaves the app, including the links on this page. The gate is an adults-only arithmetic challenge that is generated fresh every time. There is no “remember me” and no way to switch it off.
In-app purchase and RevenueCat
The single Unlock everything non-consumable purchase is managed by RevenueCat. When a parent starts or restores the purchase, RevenueCat receives an anonymous, app-generated identifier and the store receipt in order to verify the entitlement. Payment itself is handled entirely by the Apple App Store or Google Play: neither we nor RevenueCat ever see your payment method or financial details. The purchase supports Family Sharing, so one purchase covers the household.
Android permissions
The app requests only network-access permissions (android.permission.INTERNET, android.permission.ACCESS_NETWORK_STATE), needed solely for purchase verification and crash reporting. No camera, microphone, location, contacts, storage, calendar or biometric permissions are requested, and no advertising-ID permission is present in the app.
Children's privacy (COPPA and GDPR-K)
Match & Spot is directed at children and will be listed in Apple's Kids Category and under Google Play's Families program. Because the app collects no personal information from anyone, child or adult, there is nothing for us to sell, share or profile. We do not knowingly collect personal data from children, and the app is architected so that we cannot: there are no accounts, no data-entry fields, no chat, no user-generated content and no push notifications. If you believe the app has somehow collected personal information from your child, write to privacy@swtlm.com and we will investigate and delete it.
Your rights and choices
To exercise any right or raise a privacy concern, email privacy@swtlm.com and we will respond within 30 days.
- Turn reporting off: Parents Hub, privacy switch, behind the parental gate.
- Delete all data: the Parents Hub offers on-device deletion, and uninstalling the app removes everything, since nothing is stored anywhere else.
- Access and portability: we hold no personal data on our servers, so there is nothing to export. The on-device progress is already yours.
- For Firebase data held by Google, see Google's privacy controls.
This website
These pages (apps.swtlm.com/kids-memory-game) are static and hosted on AWS S3 and CloudFront. The site is aimed at parents, not children. As of this writing no analytics tag is active: the site loads no third-party scripts and sets no cookies at all. If Google Analytics is ever switched on, it will load only after you explicitly accept via a cookie banner, this section will be updated to describe the consent-gated analytics cookies (_ga, _ga_*), and declining will remain a one-tap choice. The only data that flows today is standard CDN access logs (IP address, timestamp, requested URL) retained by AWS under their default logging policy, never joined to any in-app identifier.
Service providers
- RevenueCat: management and verification of the one-time unlock purchase.
- Google Firebase: Crashlytics and Analytics, in the restricted kids-app configuration described above.
- Amazon Web Services (S3 and CloudFront): hosts this parent-facing page and receives standard CDN access logs that are not joined to any in-app identifier.
Changes to this policy
We will post material changes here and update the “Last updated” date above. If a change ever expanded what the app collects from children, which we have no plans to do, we would seek verifiable parental consent as required by law before it took effect.
Contact
Privacy questions: privacy@swtlm.com. General support: info@swtlm.com.
27280 Haggerty Road, Ste C-6
Farmington Hills, MI 48331
USA