Ziko — Privacy Policy
Last updated: July 30, 2026
Ziko ("the app", "we", "us") is a crossword game that generates puzzles about TV shows. This policy explains what the app does and does not collect, and who processes the limited data it sends off your device. We've written it to match what the app actually does — no boilerplate claims about data we don't touch.
Short version: Ziko has no accounts and asks for no name, email, or payment. What leaves your device is tied only to an anonymous sign-in token: the show name you search for (to look up the show and write the puzzle), a record of the puzzles you've solved and your streak (stored on our backend so your library and streak survive a reinstall, and used to suggest shows like the ones you've played), optional anonymous usage statistics and crash diagnostics you can turn off, and — once you allow notifications — an anonymous device push token so we can alert you about fresh puzzles. Your in-progress puzzles stay on your device, and a single switch turns notifications off.
Information stored only on your device
The following never leaves your phone — it lives in the app's local storage and is deleted when you uninstall the app:
- Your in-progress (partially solved) puzzles and the full puzzle grids/clues
- Your settings (theme, haptics, analytics preference) and whether you've seen the tutorial
We cannot see any of this, and it is never uploaded.
(A record of the puzzles you've completed and your streak is also saved on our backend so your library and streak survive a reinstall — see "Information sent off your device" below. Your in-progress puzzles, clue text, and answers are never uploaded.)
Information sent off your device
To generate a puzzle, the app sends a small amount of data to the services listed below. It is not linked to your real-world identity.
- Anonymous sign-in token. The app signs you in anonymously (no email or password) and uses the resulting token to limit how many puzzles can be generated per day. This token is a random identifier; it is not tied to your name, email, device contacts, or any personal account.
- The show you search for. When you search for a TV show or generate a puzzle, the show name (and chosen season) is sent to look up the show's details and to write the crossword's clues. We do not send your puzzle answers, your in-progress grids, or any personal information.
- A record of the puzzles you've completed, and your streak. When you finish a puzzle, the app saves a small record on our backend — the puzzle's id, the show name/id and season, the difficulty, when you finished, and how long it took — plus your streak count. This lets your solved-puzzle library and streak survive reinstalling or changing phones, and lets us suggest shows similar to the ones you've played (see notifications, below). It is tied only to the same anonymous sign-in token, is readable only by you, contains no clue or answer text, and is not linked to your name, email, or any personal account. You can erase it any time via Settings → Delete my server-side data.
- Optional usage analytics. If left enabled, the app sends anonymous, metadata-only events — for example puzzle difficulty, grid size, how long a solve took, whether a hint was used, coarse error categories, and basic app lifecycle events (app opened, installed, sent to the background). These events never include a clue, an answer, the show title you typed, or any personal information. They are tied to a random analytics identifier (not to your real-world identity). You can turn this off any time in Settings → Share usage analytics; when off, no usage events are sent.
- Optional crash and diagnostic reports. If a crash or unexpected error occurs and reporting is left enabled, the app sends a diagnostic report to help us find and fix the bug. A report contains the error and its stack trace and basic device/OS information (device model, operating-system version, app version) — technical diagnostics only. It is not linked to your real-world identity, and it never includes a clue, an answer, the show title you typed, or any personal information. Crash reporting is governed by the same "Share usage analytics" setting: when that is off, no analytics and no crash reports are sent.
- Push notifications. Notifications require your permission: your phone shows the standard system prompt, and nothing is sent unless you allow it there. Once you allow notifications, they are on by default — there is no separate in-app opt-in to hunt for. Reminders about your daily puzzle and streak are scheduled entirely on your device — nothing about your habits leaves the phone for those. For alerts about new and recommended puzzles, the app stores an anonymous device push token on our backend so the notification can reach your phone, and picks what to tell you about from the record of shows you've solved (above) — for example a new season of a show you played, or a fresh puzzle for a similar show. The token is device-routing data tied only to the same anonymous sign-in token — not to your name, email, or any personal account — and we do not build an advertising profile or sell any of this. A single switch, Settings → Notifications → New puzzle alerts, turns all of it back off (which removes the stored token); deleting your server-side record (below) also removes it. We cap these to at most one such alert a day, and keep a small record of what we've alerted you about so we don't repeat or over-notify.
- A clue report, if you choose to send one. If you long-press a clue and report it, the app sends which puzzle and clue you're reporting and the reason — so we can review and fix bad clues. It does not include your answer, and is tied only to the same anonymous sign-in token.
Service providers
The app relies on these processors to function. They handle only the limited data described above, under their own privacy terms:
- Supabase — backend and anonymous authentication (the sign-in token and rate-limit counters), and storage of your completed-puzzle library, streak, and device push token, each readable only by you. As our hosting provider, Supabase (and its Cloudflare network edge) also processes your device's IP address and approximate location transiently to route and secure each request, as described above.
- The Movie Database (TMDB) — TV show search and details. The app also loads show poster images directly from TMDB's image servers, which (like loading any image on the internet) exposes your device's IP address to TMDB to serve the image. This product uses the TMDB API but is not endorsed or certified by TMDB.
- Anthropic — generates the crossword clues from the show and season.
- PostHog (US region) — anonymous usage analytics (only if you leave analytics enabled).
- Sentry — anonymous crash and diagnostic reports (only if you leave the "Share usage analytics" setting enabled).
- Expo (Expo Application Services) — delivers push notifications via Apple's Push Notification service (APNs) when you have notifications enabled (processing the anonymous device push token to route the notification), and serves the app's over-the-air updates (the app downloads updated code from Expo's servers on launch).
What we do not collect
We do not collect your name, email address, phone number, contacts, photos, precise (GPS) location, advertising identifiers, or payment information. The app contains no third-party advertising and no session/screen recording.
A note on IP address and approximate location. As with any app that talks to a server, connecting to our backend transmits your device's IP address to our hosting provider (Supabase, via its Cloudflare network edge). The provider may use that IP to derive an approximate location — for example a city or region — and to route and secure the request. We do not store it, use it for analytics, or link it to you; it is processed transiently by the provider as a normal part of serving your request. In our own analytics and diagnostics we go a step further and disable IP-based location enrichment at the source, so the show searches and usage events we receive are not tagged with your location.
Children's privacy
Ziko is intended for a general audience and is not directed to children under 13 (or equivalent minimum age in your region). We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will address it.
Your choices and rights
- Analytics & crash reports: turn off "Share usage analytics" in Settings at any time — this single switch disables both usage analytics and crash reporting.
- Push notifications: turn off Settings → Notifications → New puzzle alerts to stop all push notifications and remove the stored device push token. (You can also revoke notification permission entirely in your phone's system Settings.)
- Deletion: uninstalling the app removes all locally stored data. The anonymous token, rate-limit counters, and any push token are not linked to you and expire or roll off on their own; the in-app Settings → Delete my server-side data removes your server-side anonymous record — including your completed-puzzle library, streak, and any push token — immediately, and you can also contact us to request the same.
Data retention
On-device data persists until you uninstall (history is also capped to the most recent puzzles automatically). Anonymous rate-limit records are short-lived and roll off on their own.
Changes to this policy
If this policy changes, we'll update the "Last updated" date above and post the new version at the same URL.
Contact
Questions about this policy or your data: [email protected]
(A note on scope: Ziko is currently free with no purchases. If subscriptions are added later, this policy will be updated to describe store-handled payment processing before that feature ships.)