Privacy policy
Privacy policy
Last updated 2026-08-28
Sudoku Junior (each store listing carries a longer localized title, such as "Sudoku Junior: Sudoku for Kids") is operated by TLM Software Design, Inc., a Michigan corporation with offices at 27280 Haggerty Road, Ste C-6, Farmington Hills, MI 48331, USA ("we", "us", "our"). The app is designed for children ages 4–12, and this policy is written to meet the standards that come with that: COPPA in the United States, GDPR-K in the EU/UK, and Google Play's Families policy. It describes what the app collects, why, where it goes, and the choices parents have.
Summary for parents
- No ads, ever. The app contains no advertising SDKs of any kind.
- No personal information. No accounts, no sign-in, no names, no photos, no location, no ad identifiers, no messages. We never ask for — and cannot receive — anything that identifies your child.
- Gameplay is fully offline. Every puzzle ships inside the app; all progress lives only on your device and is deleted with the app.
- The only network traffic is RevenueCat (verifying the one-time unlock purchase) and Google Firebase (crash reports and anonymous usage counts, configured for children's-privacy compliance).
- Parents can turn analytics off entirely from the Parents Hub, which sits behind a parental gate — as do purchases and every external link.
What the app stores on your device
The following values are written to local storage on the device. None of it is transmitted to us or to any third party, and none of it identifies your child.
- Puzzle progress — which levels are completed, current mid-puzzle board state, and hints used, so a kid never loses their place.
- Children on this device — if a grown-up adds more than one child, a name they typed and a colour for each, so each child keeps their own progress. A child’s name is stored only on the device: it is never transmitted, never included in analytics, and never reaches us.
- Learning record — per level, how long a child actively worked on it, how many wrong digits they placed, how many hints they used, and which Sudoku School lessons they finished. This is what the report in the Parents Hub is computed from. It is derived and displayed on the device and is never transmitted.
- Settings — sound and music toggles, whether numbers are shown as digits or countable dots, and the error-highlight preference parents choose in the Parents Hub.
- Unlock entitlement cache — a local record (maintained by RevenueCat) of whether the one-time purchase is active, so the app can unlock levels without a network round-trip.
There is no account, no cloud sync, no backup target. Deleting the app deletes all of it.
Network behavior
All gameplay — puzzles, tutorials, hints, progress, celebrations — runs locally and works in airplane mode. Only two external services ever receive traffic:
- RevenueCat — only when a parent initiates or restores the one-time unlock purchase (both behind the parental gate).
- Google Firebase — Crashlytics uploads a report if the app crashes; Analytics records a small set of anonymous usage events (e.g. "a hint was used"); Remote Config fetches one flag — the switch that lets us turn analytics off remotely.
If the device is offline, the game runs normally: purchases retry when connectivity returns, and crash reports queue locally.
How analytics is configured for children
We use Firebase Analytics and Crashlytics in a deliberately restricted, kids-app configuration:
- No user IDs are ever set, and no advertising identifiers (IDFA / Android Advertising ID) are collected or requested. On iOS the app never shows the App Tracking Transparency prompt because it never tracks.
- Events are a small fixed set with no free-text fields: the parental gate being opened, passed or cancelled; a hint being used; a settings toggle being changed; and three steps of the rate-this-app prompt (it was shown, a parent chose to rate, a parent chose to write to us). Every parameter is a fixed value or a small number, so nothing a child types or does can end up as personal data — there is nowhere to type anything.
- Alongside those, the Firebase SDK records its own standard signals: first open, session start, and app or OS updates, together with device model, OS version, app version and the country inferred from the network address. On Android it also reads the Play install referrer, which tells us which store listing or campaign an install came from — never who installed it. Automatic screen-view reporting is switched off.
- Crash reports contain stack traces, device model, OS version, and app version — enough to fix bugs, nothing about the person holding the device.
- Parents can switch all of it off in the Parents Hub (behind the parental gate). We can also disable analytics remotely for every install if a compliance concern ever arises.
Firebase data is processed by Google and governed by Google's privacy policy; Analytics retention is capped at Google's defaults (up to 14 months) and Crashlytics reports can be purged on demand from our console.
The parental gate
Everything that leads out of the kid-safe play area — the purchase and restore flow, the Parents Hub, gameplay-affecting settings, data deletion, and any link that leaves the app (including the links on this page) — sits behind a parental gate: an adults-only arithmetic challenge that is freshly generated every time. There is no "remember me" and no way to switch it off.
In-app purchase — RevenueCat
The single Unlock everything non-consumable purchase is managed by RevenueCat. When a parent initiates or restores the purchase, RevenueCat receives an anonymous, app-generated identifier and the store receipt to verify the entitlement. Payment itself is handled entirely by Apple App Store or Google Play — we and RevenueCat never see your payment method or financial details. The purchase supports Family Sharing, so one purchase covers the household.
Android permissions
The app itself declares one permission,
android.permission.INTERNET, for purchase
verification, crash reporting and analytics. Four more are merged in by the Google Play
billing and Firebase libraries, alongside a signature-level one Android generates
for the app's own use: ACCESS_NETWORK_STATE,
com.android.vending.BILLING,
WAKE_LOCK, and the Play install-referrer
service binding, which Firebase Analytics uses for the install-source signal described
above. No camera, microphone, location, contacts, storage, calendar, or biometric
permissions are requested, and the advertising-ID permission is explicitly removed
from the app.
Children's privacy (COPPA / GDPR-K)
Sudoku Junior is directed at children, so Google Play's Families policies apply to it. It is not in Apple's Kids Category; the App Store submission is categorised under Games. Because the app collects no personal information from anyone — child or adult — there is nothing for us to sell, share, or profile. We do not knowingly collect personal data from children, and the app is architected so that we cannot: there are no accounts, no data-entry fields, no chat, no user-generated content, and no push notifications. If you believe the app has somehow collected personal information from your child, contact privacy@swtlm.com and we will investigate and delete it.
Your rights and choices
- Turn off analytics — Parents Hub › privacy toggle (behind the parental gate).
- Delete all data — the Parents Hub offers on-device data deletion, and uninstalling the app removes everything, since nothing is stored anywhere else.
- Access / portability — we hold no personal data on our servers, so there is nothing to export; the on-device progress is yours already.
- For Firebase data held by Google, see Google's privacy controls.
To exercise any rights or raise a privacy concern, email privacy@swtlm.com and we will respond within 30 days.
This website
These pages (apps.swtlm.com/kids-sudoku-game) are
static and hosted on AWS S3 + CloudFront. This site is
aimed at parents, not children. It uses Google Analytics to count visits — pages viewed,
session count, referral source. Analytics cookies
(_ga,
_ga_*) are set only after you accept via the
cookie banner, and declining is a one-tap choice that loads no script and sets no cookie.
You can withdraw consent at any time by clearing this site's local storage in your browser.
AWS also records standard CDN access logs (IP address, timestamp, requested URL) under their
default logging policy, never joined to any in-app identifier.
apps.swtlm.com is one website: this page and every app page on it share a single analytics property and a single consent choice, so accepting or declining once applies everywhere on the domain. That is the analytics only. This privacy policy covers Sudoku Junior and its pages, and nothing else — every other app on apps.swtlm.com has its own policy, because every app handles different data.
Service providers
- RevenueCat — one-time unlock purchase management and entitlement verification.
- Google Firebase — Crashlytics, Analytics and Remote Config, in the restricted kids-app configuration described above.
- Amazon Web Services (S3 + CloudFront) — hosts this parent-facing page; receives standard CDN access logs that are not joined to any in-app identifier.
Changes to this policy
We will post material changes here and update the "Last updated" date above. If a change ever expanded what the app collects from children (we have no plans for that), we would seek verifiable parental consent as required by law before it took effect.
Contact
Privacy questions: privacy@swtlm.com. General support: info@swtlm.com.
TLM Software Design, Inc.27280 Haggerty Road, Ste C-6
Farmington Hills, MI 48331
USA