MazeTrap privacy policy

Effective date: September 13, 2026 (UTC)

This policy covers MazeTrap for Android, the browser game, and our game and share-link pages. No internet connection is needed for Android gameplay, progression, local leaderboards, sound, or How to Play. The browser game can work offline once its files have been cached; browser storage can be cleared or evicted.

Data on your device

MazeTrap stores settings, progression, local scores and display names, and resumable Android game state on your device. Online features also use locally generated identifiers and credentials, pending upload queues, and cached leaderboards. The browser uses local storage and an offline asset cache. Result sharing creates a temporary game image locally.

Usage analytics

The setting currently labelled "Anonymous analytics" is enabled by default in Android and the browser and can be turned off in Settings. We use analytics to understand game difficulty, reliability, usage, and layout problems.

Analytics can include random installation, session, event, and attempt identifiers; event timestamps; platform and screen dimensions, density, and layout class; screens viewed; and session and level summaries such as duration, level, outcome, moves, retries, and pauses. These identifiers allow events from the same installation or session to be associated. They are not a guarantee of completely anonymous data.

The current How to Play screen records ordinary screen views, not tutorial steps. Older client versions may still send legacy tutorial or input-summary events. Analytics do not include display names, email addresses, contacts, advertising identifiers, precise location, or move-by-move recordings.

Global leaderboards

Global leaderboard participation is enabled by default on Android and is off by default in the browser. You can change it in Settings without affecting local play or local scores.

The initial Android display name can use the permission-free device-name setting or device model. The browser suggests a device/browser label. The global name initially follows the local name but can be edited independently. A device name may contain personal information: review your global display name and use a nickname if you do not want that information published.

Submissions include a random player identifier, display name, run identifier, level, time, moves, game and rules versions, and a hash identifying the starting game scenario. That scenario hash is not a hardware fingerprint. A separate private player credential authorizes profile and score changes; the backend stores its hash. Supported builds may also send a Google Play Integrity token for app, device, and licensing checks to prevent abuse.

Global display names, scores, ranks, completion dates, and random player identifiers are available through the public leaderboard service. Private player credentials and analytics installation identifiers are not included in public leaderboard responses. Analytics and leaderboard identifiers are separate in MazeTrap's data model.

Sharing a result

When you choose Share, MazeTrap generates an image of the finished game board, outcome, level, time, moves, and game link. It does not record other apps or your device's screen generally. The image and result text are passed to the sharing app you choose; MazeTrap does not upload these result images to its backend. MazeTrap does not add a player identifier to the shared game link.

Browsers may instead offer an image download or copy the result text and link to your clipboard. Saved images and copies sent to friends or social networks remain outside MazeTrap's control and follow the receiving service's privacy and retention practices. Clearing MazeTrap data does not remove those copies.

Network addresses, countries, and providers

MazeTrap does not infer or store countries for analytics or leaderboards and does not display country flags with scores. The game does not access GPS, Wi-Fi positioning, or precise location.

Network addresses are processed to deliver requests and prevent abuse. The backend stores IP-derived hashed rate-limit keys and counters, rather than plain network addresses in its rate-limit table. This is distinct from hosting-provider request and security logs.

Website visits, file downloads, integrity requests, and apps you choose for sharing can involve network processing beyond MazeTrap's analytics and leaderboard API. Production game-service transfers use HTTPS. Providers may process data outside your region. Their operational logs and backups are subject to their service arrangements and applicable retention practices. MazeTrap does not sell game data or use it for advertising.

Retention

The application database's configured retention periods are 90 days for raw analytics and 24 months for daily aggregate analytics. These limits are applied by database maintenance, not by changing a setting on your device. Daily aggregates contain counts rather than individual event records.

Leaderboard profiles, submitted scores, and related fraud-prevention records may be retained while the global service operates or until removed through moderation or a deletion request. Expiring a daily, weekly, or monthly ranking does not necessarily delete the underlying score. Rate-limit records have expiry times and are removed by database maintenance.

Local data remains until removed by the app, your device/browser, or you. Shared-image cache files are temporary; downloaded or externally shared copies have their own retention. Provider logs and backups are separate from the application database periods above. Privacy correspondence may also be retained to handle and document requests.

Your choices and deletion requests

Turning analytics off stops new analytics recording, deletes locally queued analytics, and resets the local analytics identifier. Turning global participation off stops online leaderboard participation while it is off. Neither action automatically deletes information already received by the server or information already shared with others.

You can edit display names and clear local app or browser data. Clearing local storage removes its saved identifiers and queues but does not delete server records. Device backup and restore settings may also affect local app data. Names or scores may be rejected, removed, or blocked to protect leaderboards.

For access, correction, or deletion requests, contact info.relit.studio@gmail.com. Include the platform, global display name, and player identifier if available. We may need further information to locate records and verify a request. Do not send passwords or private player credentials. Contacting us by email provides your email address and message, which we use to handle your request.

Android permissions

The app uses network and background-work permissions, including:

MazeTrap does not request location, contacts, camera, microphone, or broad storage permissions. Sharing grants the chosen app temporary read access to the generated result image, not to your other private game files.

Children and policy changes

A real name, email address, or date of birth is not required to play. Parents or guardians can contact us about privacy or deletion. Online features still process the data described above when enabled; random identifiers do not mean that no data is processed.

We will update this policy and its effective date when these practices change.