Cosmic Merge
Privacy Policy
Effective and last updated: September 15, 2026
This policy explains what information is handled when you play Cosmic Merge, why it is used, which service providers receive it, and the choices available to you.
This policy is a privacy notice, not a request for agreement or consent. Where consent is required for advertising or tracking, the game asks separately through Google's User Messaging Platform or Apple's App Tracking Transparency prompt.
1. Scope and summary
This policy applies to the Cosmic Merge iOS and Android apps and the related accountless services used for advertising, attribution, purchases, progression, analytics, diagnostics, and support. Cosmic Merge does not require a Puccini Labs account and does not ask you to provide a name, email address, phone number, contacts, photos, microphone recordings, or precise GPS location to play.
Most detailed gameplay state stays on your device. Limited gameplay, technical, advertising, purchase, and support information is processed by the providers described below.
2. Information handled
On-device game information
The app stores game progress and state locally, including scores, current and recent match state, settings, progression, achievements, powerup inventory, cached purchase entitlements, daily-reward state, and counters used to enforce the advertising cadence. This supports normal gameplay, recovery after interruption, fraud-resistant inventory use, and your preferences.
Product analytics and diagnostics
Cosmic Merge sends bounded events to PostHog to understand app reliability and feature use. These may include app launches, gameplay milestones, scores and tier progression, match duration and merge counts, settings and store actions, purchase and restore outcomes, ad lifecycle outcomes, app version, build, operating-system version, device class, and sanitized error or crash diagnostics.
Some match events contain a random match identifier. After the app verifies its accountless commerce profile, an app-generated random Support/Operations identifier is used as the PostHog analytics identity and as the RevenueCat customer identifier. It is not your Apple Account identifier, advertising identifier, name, or email. Cosmic Merge disables PostHog session replay, automatic screen capture, automatic element capture, and automatic screen-view capture. Its event sanitizer rejects names, email addresses, IDFA, IDFV, purchase transaction identifiers, raw device identifiers, and Support/Operations identifiers as event properties.
Advertising and consent information
The free version uses Google AdMob for fullscreen interstitial ads and narrowly bounded interrupted-ad recovery. Cosmic Merge does not use banner ads or rewarded ads. Google and the ad technology providers disclosed in the Google consent form may process IP address, general location inferred from IP, device and app characteristics, language, advertising interactions, fraud and security signals, and an advertising identifier when legally permitted.
On iOS, IDFA is available to advertising providers only if you allow tracking through Apple's App Tracking Transparency prompt. Where required, Google's User Messaging Platform presents regional consent choices before ads are requested. Consent state is stored and refreshed by Google's SDK. Declining personalized advertising does not necessarily remove ads; eligible contextual, non-personalized, or limited ads may still use information such as IP address to deliver, secure, and measure an ad. The iOS app disables Google's publisher first-party identifier, mediation initialization, and Google Mobile Ads SDK crash reporting.
An active Remove Ads entitlement suppresses third-party ad requests. RevenueCat receives bounded ad-impression revenue and placement information through its AdMob integration so purchases and ad revenue can be measured together. If you authorize tracking through Apple's prompt, Cosmic Merge also asks RevenueCat to collect IDFA, IDFV, IP address, and device version as reserved customer attributes for advertising attribution and measurement. These identifiers do not enter gameplay, support diagnostics, PostHog event properties, or app logs. Cosmic Merge does not send its Support/Operations identifier to Google Mobile Ads.
Cosmic Merge uses AppsFlyer to measure paid campaign installs, sessions, first-run activation, first match, Store and checkout actions. When the RevenueCat integration is enabled, RevenueCat—not the app—also reports purchase product, revenue, and refund events to AppsFlyer. RevenueCat includes its random App User ID, which is Cosmic Merge's accountless Support/Operations identifier, so AppsFlyer can join purchase value to the attributed install. AppsFlyer may also process an AppsFlyer install identifier, IP address, IDFV, and limited app, device, operating-system, advertising, and attribution information needed to measure and prevent fraud. IDFA is available to AppsFlyer only after ATT authorization. IDFV and IP address remain available for privacy-preserving Google iOS attribution when ATT is denied.
AppsFlyer does not receive the Game ID, name, email address, phone number, date of birth, support report, final-board image, gameplay-report content, receipt or transaction identifier, or ordinary detailed gameplay analytics from Cosmic Merge. The random Support/Operations identifier is used only as the RevenueCat purchase-attribution join described above. Organic gameplay analytics remain in PostHog. Privacy- preserving SKAdNetwork and AdAttributionKit postbacks may be copied to AppsFlyer for aggregate attribution.
Purchases and accountless commerce
On iOS, Apple processes App Store purchases and payment information. Cosmic Merge uses RevenueCat to verify products, purchases, entitlements, restores, and virtual powerup balances. RevenueCat may receive the app-generated Support/Operations identifier, device and app information, Apple receipt or transaction information, product identifiers, purchase status, entitlement state, virtual-currency activity, and related diagnostics. When paid measurement is enabled, RevenueCat may also receive the AppsFlyer install identifier so its purchase events can be matched to an attributed install. We do not receive your payment card details or Apple Account password.
For iOS, our accountless commerce service verifies Apple-signed app and transaction evidence and maintains the accountless commerce profile. It stores the random Support/Operations identifier, StoreKit environment, entitlement and inventory reconciliation state, idempotency records, bounded fraud or conflict evidence, and daily progression information. Daily-reward requests include your current IANA time-zone identifier so the service can calculate the correct local calendar day; the service stores the last successful claim timestamp, local date, and time zone. It does not request GPS access or store an Apple Account identifier.
Game Center
If Game Center is available and authenticated, Cosmic Merge uses Apple's GameKit services to load and report achievements and leaderboard scores. Apple handles the associated Game Center player account and service data under Apple's policies. Local achievement and progression state also remains on your device.
Android services
On Android, Google Play processes purchases and payment details. RevenueCat and our accountless commerce service process purchase tokens, product identifiers, purchase status, entitlement and powerup balances, and the app-generated Support/Operations identifier to deliver purchases, handle restores, and prevent duplicate grants. We do not receive your payment card details or Google password. Daily rewards use your IANA time zone and claim history as described above. The accountless identifier is not your Google Account ID.
Google Play Integrity checks app and device authenticity when the app establishes or recovers its commerce identity. Google processes the verification request; our service receives the integrity proof and verification results used to protect inventory and purchases. Local recovery credentials are encrypted using Android Keystore. The app also uses Google Block Store for recovery; it requests cloud backup only when end-to-end encryption is available. Recovery may therefore retain an accountless commerce identity after reinstall, depending on your device and Google backup settings.
Google Play Games sign-in is optional. When signed in, Google handles your Play Games profile, leaderboard scores, and achievements. The app uses the player identifier to keep local synchronization state separate for each player. You can manage Play Games profile and sign-in settings through Google Play Games. Core puzzle gameplay does not require a separate Puccini Labs account.
Android uses AdMob and Google's User Messaging Platform for ads and regional privacy choices. AdMob may collect IP-derived approximate location, app interactions, diagnostics, and device or other identifiers for advertising, analytics, and fraud prevention. Android advertising-identifier controls are available in your device's Google privacy settings. Apple's ATT, IDFA, IDFV, SKAdNetwork, and AdAttributionKit descriptions apply only to iOS.
Android AppsFlyer measurement starts only after regional consent status is resolved. It receives the limited acquisition events described above and may process an install identifier, IP address, app/device details, and consent signals. The Android app disables AppsFlyer's advertising-identifier collection and links its install identifier with RevenueCat for configured purchase attribution. Android PostHog events use the bounded gameplay and diagnostic vocabulary described above; session replay and automatic screen capture are disabled.
Information you choose to provide
If you contact support, we process the email address, name, message, and attachments you choose to send. If you choose to copy and send a diagnostic summary, it may contain the visible Support/Operations identifier, app and build version, purchase environment, entitlement state, inventory status, and bounded logical diagnostics. The app does not silently transmit that support summary.
After a match ends, you may also choose Share with Support and confirm a separate in-game report. That report contains the app-generated Support/Operations identifier, random match and report identifiers, app/build/device/operating-system details, final score and bounded match counters, the danger-line trigger summary, and a bounded list of final planet tiers and board positions. If shown in the confirmation, the report also contains one bounded image of the exact final game board. This is an in-app board image, not an operating-system or full-device screenshot, and cannot include notifications or another app. The report does not contain your name or email address, IDFA or IDFV, payment information, transaction or receipt data, ad content, creative URLs, or raw device logs. Nothing is sent by merely opening the confirmation, and a failed submission can be retried with the same report reference. Before sending, you also select which powerup you would prefer if the report qualifies for an optional thank-you.
You may separately choose Report a Bug in Customer Support. A submitted report contains the description you write, one screenshot you select through the platform's system picker, your preferred thank-you powerup, a random report identifier, the app-generated Support/Operations identifier, the current random Game ID when one is available, and app/build/device/operating-system details. The picker is limited to screenshots and shares only the item you select; Cosmic Merge does not request access to your photo library. You can preview and remove the screenshot before submitting it.
A selected screenshot can contain personal or sensitive information visible on that image, such as notifications, names, messages, or content from another app. Review the preview and do not submit an image you do not want support operators to see. The report does not automatically include your name, email address, advertising identifiers, payment information, receipt data, or other photos. Cosmic Merge redraws the selected image before upload to remove embedded metadata such as photo location.
3. How information is used
- Operate, save, restore, secure, and improve gameplay.
- Provide purchases, Remove Ads, powerups, and daily progression.
- Display and measure ads when the player is eligible.
- Respect consent, tracking, and privacy choices.
- Diagnose crashes, performance problems, failed operations, and abuse.
- Provide customer support and resolve purchase or inventory issues.
- Comply with App Store, accounting, security, and legal obligations.
4. Legal bases
Depending on your location and the specific processing, we rely on: your consent for personalized advertising, tracking, and other consent-based processing; performance of a contract to deliver the game, purchases, and requested services; legitimate interests in operating, securing, diagnosing, and improving the app where those interests are not overridden by your rights; and compliance with legal obligations. You may withdraw consent without affecting processing that was lawful before withdrawal.
5. Service providers and disclosure
We disclose information only as needed to operate the app, follow your choices, comply with law, protect players and services, or complete a transaction you request. The principal providers are:
- Google AdMob and User Messaging Platform
- Advertising, consent, ad delivery, measurement, and fraud prevention. See Google's Privacy Policy and how Google uses information from partner apps.
- Apple
- App distribution, StoreKit purchases and receipts, App Tracking Transparency, SKAdNetwork attribution, and Game Center. See Apple's Privacy Policy.
- Google Play services
- Android distribution and billing, Play Games profiles and game activity, Play Integrity verification, and Block Store recovery. See Google's Privacy Policy.
- RevenueCat
- Purchase validation, entitlements, virtual currency, restores, bounded AdMob revenue attribution, the AppsFlyer install identifier when paid measurement is enabled, and—only after ATT authorization—other device identifiers and related attribution information. See RevenueCat's Privacy Policy.
- AppsFlyer
- Paid campaign attribution, privacy-preserving install and session measurement, the limited acquisition funnel described above, and fraud prevention. See AppsFlyer's Privacy Policy.
- PostHog
- Product analytics, sanitized diagnostics, and error tracking. See PostHog's Privacy Policy.
- Cloudflare
- Hosting, secure network delivery, and the accountless commerce and progression service. Player-confirmed game and bug reports are stored in that service. Bug-report screenshots are stored in a private R2 bucket. Report content and images are available only through the administrator-only Commerce Operations console. When a new report arrives, a notice containing only the report type, service environment, time, and a protected console link may be sent to the verified Puccini Labs operator email; the notice does not include the report text, screenshot, or player identifiers. See Cloudflare's Privacy Policy.
We do not sell personal information for money. Advertising-related disclosures may be treated as a “sale,” “sharing,” or targeted advertising under some privacy laws even when no money is exchanged for personal information. Use the controls below to manage those activities where applicable.
6. Retention
Local gameplay information remains until you reset the relevant feature or delete the app, subject to iOS backup and restore behavior. Some accountless purchase identity may remain in the iOS Keychain so that purchases and inventory can be restored safely after reinstall.
Commerce, entitlement, purchase, inventory, fraud-prevention, and support records are retained while needed to provide durable purchases and services, resolve disputes, prevent abuse, meet accounting or legal obligations, and support restore operations. Analytics and diagnostic records are retained according to our configured operational needs and the provider's applicable retention settings. Attribution and advertising records are retained according to our AppsFlyer configuration, applicable partner rules, and the providers' policies. App Store and Game Center records are retained by Apple under its policy.
Images attached to player-confirmed in-game support reports are automatically deleted no later than 30 days after submission. Their bounded match details, identifiers, selected powerup, and status history are automatically deleted after 90 days. This limit does not extend a separate support email, transaction record, or legal record that must be retained for its own documented purpose.
Screenshots attached through Report a Bug are automatically deleted no later than 30 days after submission. The report description, identifiers, selected powerup, technical details, and status history are automatically deleted after 90 days. Minimal grant and idempotency records may be retained longer when needed to preserve inventory integrity, prevent duplicate rewards, resolve a dispute, or meet legal obligations; they do not retain the screenshot.
A deletion request does not require deletion of information that must be retained for legal compliance, transaction records, security, fraud prevention, or the defense of legal claims. Where deletion is not possible, information may be restricted or de-identified when appropriate.
7. Your privacy choices
- Regional ad choices: when Google reports that a privacy-options form is required, open Cosmic Merge Settings → Privacy, Terms & Credits → Ad Privacy Choices.
- Tracking: change Apple's tracking permission in iOS Settings → Privacy & Security → Tracking.
- Remove Ads: purchase or restore the lifetime Remove Ads entitlement through the in-app Store to suppress third-party ads.
- Game Center: manage Game Center authentication and privacy through your Apple device settings.
- Android: manage your Google Play Games profile, advertising identifier, and backup preferences in the relevant Google and Android settings. Deleting the app removes ordinary local game data; Block Store recovery and server-side purchase records may remain as described above.
- Local data: deleting the app removes ordinary local gameplay data, subject to iOS backup, purchase restoration, and Keychain behavior described above.
- Requests: email hello@puccinilabs.com to request access, correction, deletion, restriction, objection, portability, or help withdrawing a choice, where applicable.
We may need information sufficient to verify and locate the relevant accountless profile, such as your Support/Operations identifier. You may also have the right to complain to your local data-protection authority.
8. Children
Cosmic Merge is a general-audience game and is not designed specifically for children or enrolled in Apple's Kids Category. We do not knowingly ask children to provide personal contact information. Parents or guardians who believe a child has provided personal information may contact us so we can review the request. Advertising and consent treatment may vary based on applicable law, platform settings, and the information available to Google.
9. International processing and security
Providers may process information in countries other than your own, including the United States. Where required, transfers rely on applicable contractual or legal safeguards. We use HTTPS, bounded identifiers, access controls, data minimization, and sanitization, but no system can guarantee absolute security.
10. Changes and contact
We may update this policy when the app, providers, or legal requirements change. The effective date above will be updated, and material changes will be communicated through an appropriate app or store notice when required.
Questions or privacy requests: hello@puccinilabs.com.