Scordle Games — Privacy Policy
Last updated: [date — set at publication]
Effective date: [date]
Scordle Games (“Scordle”, “the app”, “we”, “us”, “our”) is operated by Xerica Ltd, a company registered in England & Wales (company no. 05222460, registered office Woodlands Grange, Woodlands Lane, Bradley Stoke, Bristol, BS32 4JY). Xerica Ltd is the data controller for the personal data described below.
This policy explains what we collect, why, who we share it with, and the rights you have. Questions or requests: privacy@scordle.games.
1. The short version
- We don't use logins, emails or passwords. You pick a nickname; your device proves who it is with a key stored securely on the device.
- We collect the minimum needed to run the app: your nickname, your game scores, the reactions and comments you post, and who's in your clubs.
- We don't track you across other apps or websites, we don't run analytics, and we don't sell your data.
- Free users see ads. Our ads are non-personalised — they aren't based on profiling you. In the UK/EEA we ask your consent first.
- You can delete your account at any time, in the app or at scordle.games/delete. Deletion is immediate and permanent.
2. What we collect and why
| Data | Why we use it | Lawful basis |
|---|---|---|
| Nickname | Shown to other members of your clubs so they can recognise you | Performance of our contract with you |
| Device identifier & device key (a random ID and a cryptographic key generated on your device) | To sign you in securely without a password | Contract / our legitimate interest in account security |
| Account secret & recovery code (stored only as a hash) | To let you add devices and recover your account | Contract |
| Your game scores, results and streaks | The core purpose of the app — tracking your stats and sharing them with your clubs | Contract |
| Reactions and comments you post | To power the social feed within your clubs | Contract |
| Your club and competition memberships | To show you the right content and who you're sharing with | Contract |
| Push notification token | To send you the notifications you've allowed | Your consent (you can turn notifications off any time) |
| IP address (in short-lived server logs) | Security, abuse prevention and reliable delivery | Our legitimate interest in keeping the service safe |
| Advertising data (free tier only) | To show non-personalised ads via Google AdMob | Your consent (UK/EEA) / our legitimate interest elsewhere |
| Purchase confirmation (from Apple/Google) | To unlock features and verify subscriptions | Contract |
| Crash diagnostics (only when the app crashes) | To find and fix bugs | Our legitimate interest in a stable app |
We do not collect: your real name, email, phone number, address, contacts, photos, precise location, or browsing history. We do not run usage analytics.
3. How your information is shared
Your scores, reactions and comments are shared with the other members of clubs you belong to — that's the point of the app. They are never visible to people you don't share a club with.
We use a small number of trusted service providers (“processors”) who handle data on our behalf under contract:
| Provider | Role | Where |
|---|---|---|
| Cloudflare | Hosting, database and storage | Global edge; may process outside the UK/EEA |
| Google (Firebase Cloud Messaging) | Delivering push notifications | May process outside the UK/EEA |
| Google (AdMob + the Google UMP consent tool) | Serving non-personalised ads to free-tier users, and collecting your ad consent in the UK/EEA | May process outside the UK/EEA |
| Sentry (EU region) | Crash diagnostics | EU |
| Apple / Google | Processing in-app purchases and subscriptions (they are the merchant of record) | Per their own policies |
We do not sell your personal data, and we do not share it for cross-app advertising or tracking.
4. Advertising and consent
If you're on the free (ad-supported) plan, we show ads through Google AdMob. These ads are non-personalised — they are not based on a profile of you. If you're in the UK or EEA, we ask for your consent through Google's consent tool before any ads load, and you can change your choice at any time from Settings → Privacy options. Subscribers and lifetime-purchase users see no ads.
5. International transfers
Some of our providers (above) may process data outside the UK and EEA. Where they do, the transfer is protected by an appropriate safeguard — an adequacy decision, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses — so your data keeps an equivalent level of protection.
6. How long we keep it
We keep your personal data for as long as your account is active. When you delete your account (section 8):
- Your identifying and credential data (nickname, device keys, account secret, recovery code, push token, purchase records) is permanently deleted.
- Your comments are deleted.
- Your scores and reactions are kept but fully anonymised — they're relabelled to “Deleted Player” so your friends' competition history and statistics aren't broken. Once anonymised, they can no longer be linked to you and are no longer personal data.
Server access logs (including IP addresses) are short-lived. Crash diagnostics are retained only as long as needed to investigate bugs.
7. Your rights
Under UK/EU data protection law you have the right to: access your data; have it corrected; have it erased; restrict or object to processing; data portability; and withdraw consent at any time (for example, by turning off notifications or changing your ad-consent choice).
- Erase your account yourself at any time — in the app (Settings → Delete my account) or on the web at scordle.games/delete (you'll need your recovery code). Deletion is immediate and irreversible.
- For any other request, contact privacy@scordle.games.
You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority, though we'd appreciate the chance to help first.
8. Deleting your account
You can permanently erase your account at any time, with no need to contact us:
- In the app: Settings → Delete my account.
- On the web: scordle.games/delete (using your recovery code, if you no longer have the app).
Deletion happens straight away and cannot be undone. Please note: deleting your account does not cancel any paid subscription — you must cancel that separately in the App Store or Google Play to stop being billed. See what is kept (anonymised) versus deleted in section 6.
9. Security
Sign-in uses a cryptographic key generated and stored in your device's secure hardware (Android Keystore / iOS Secure Enclave) — there is no password to steal. Data in transit is encrypted (HTTPS). Keep your recovery code safe: it's the only way to recover your account on a new device, and anyone who has it could access or delete your account.
10. Children
Scordle Games is not directed to children. It's intended for users aged 13 or over (or older where your local law sets a higher age for consenting to online services). We don't knowingly collect data from children below that age; if you believe we have, contact privacy@scordle.games and we'll delete it.
11. Changes to this policy
We may update this policy from time to time. We'll change the “Last updated” date above and, for significant changes, tell you in the app. Continuing to use Scordle Games after a change means you accept the updated policy.
12. Contact
Privacy: privacy@scordle.games ·
Support: support@scordle.games
Data controller: Xerica Ltd, Woodlands Grange, Woodlands Lane, Bradley Stoke, Bristol, BS32 4JY, England & Wales
(company no. 05222460).