Privacy Policy
This policy explains how Ultra Murdle uses account, gameplay, purchase, support, remote-content, and optional local-reminder data.
Data We Use
The public website records only daily aggregate App Store button impressions and clicks by an allowlisted campaign and page language. It does not set an analytics cookie, create a browser identifier, or store an account, IP address, user agent, referrer, free-text route, or arbitrary URL. The aggregate table contains only date, campaign, locale, impression count, click count, and update time.
The 90-second Quick Start case runs locally without an account or network connection and makes no Firebase, GA4, wallet, leaderboard, or purchase calls. An account with a display name is required only after Quick Start to save progress and open the archive; username and gender are optional. Ultra Murdle then uses account email, authentication identifiers, the selected private profile, gameplay progress, badges, completed cases and focused timing, optional recommendation activity, Firebase-synced Hint Token wallet records and paid reveal history, opt-in public leaderboard summaries, and remote puzzle pack status.
For core account and progress operations, the server derives a private activation fact containing account time, provider, locale, display-name readiness, server-observed coarse first-case milestones, and authoritative solve counts. It never stores puzzle notes, clue or story text, choices, drafts, solutions, purchase identifiers, advertising identifiers, or raw analytics events. Daily summaries contain aggregate funnel counts only and suppress provider or language cells with fewer than five accounts.
Optional investigation reminders are local and off by default. Their preferences, system-permission state, schedule timestamps, and validated case target remain on the device. Ultra Murdle does not request or collect a remote push token for these reminders. At most one reminder is pending, and its generic copy contains no clue, solution, account detail, purchase, or Hint Token balance.
If you separately consent to usage analytics, Ultra Murdle links your Firebase account identifier to screen and allowlisted action identifiers, case and volume identifiers, difficulty, locale, foreground engagement time, assistance counts, purchase and wallet outcomes, reminder type and outcome events, and allowlisted reliability codes. The app owner or an authorized, role-restricted administrator can view this activity with the current email and username from your account profile. Analytics never contains notification titles, bodies, routes, push tokens, private notes, clue or story text, solutions, deduction-grid content, accusation selections, passwords, authentication tokens, receipts, transaction identifiers, support text, raw error messages, or tap coordinates.
If you contact support, your message may include the support category, your written comment, optional screenshots you choose to attach, app version, platform, locale, text-size setting, active case identifier, account email, and account user ID if signed in.
Authorized administrators may review exact account, progress, badge, wallet, purchase-delivery, leaderboard, recommendation, support-metadata, and consented analytics records when needed for support or operations. Access is role-restricted and audited. Broad account views exclude private puzzle state, receipts, transaction identifiers, support comments, screenshot files, and storage paths.
Services
Firebase provides authentication, Firestore database storage, remote content delivery, Analytics, and a private role-restricted administration service. Google Analytics 4 and BigQuery process consented usage events. The public website host stores the unlinked daily campaign totals described above. RevenueCat manages purchase validation and restore state for Apple and Google in-app purchases. Apple App Store and Google Play process mobile purchases and refunds according to their own systems.
Usage analytics is not used for advertising or cross-app tracking. Ultra Murdle does not collect IDFA for analytics and does not use heatmaps, session replay, or raw tap capture. Advertising consent remains denied even when usage analytics is enabled.
Personalized recommendation activity is optional and is sent only after the signed-in player enables it in Settings. Events contain compact identifiers, difficulty, locale, timing, completion, failed-submission, and assistance metadata. They do not contain private notes, clue or story text, solutions, deduction grids, manual marks, accusation content, email, or purchase identifiers.
Hint Token balances, paid clue unlocks, and full-answer reveal history are synchronized to the signed-in account and may be cached temporarily on the device. The platform purchase service validates store purchases. The leaderboard is viewable without joining, is off for publishing by default, and publishes only after explicit confirmation on the leaderboard screen. A public entry contains the detective name chosen for the account, solved cases, badge totals, streaks, collection points, focused solve times, and ranking metadata. It never contains an account identifier, email, selected profile, private notes, or case content.
Deletion And Retention
Per-account operational activation facts are deleted immediately with the account. Daily activation summaries contain aggregate counts only and expire after 13 months.
Raw account-linked usage events are retained for no more than 90 days. Turning “Share usage analytics” off stops future collection; previously collected events remain until they expire within that period. Anonymous, irreversible daily aggregates that do not contain a user identifier, including public-site campaign totals, may be retained for up to 24 months.
Account deletion can be started inside the app from Settings. It revokes Sign in with Apple when applicable and deletes the RevenueCat subscriber, Firebase Auth account, progress, badges, wallet, paid clue and full-answer history, support attachments, public ranking, remote sync data, and linked analytics identity. BigQuery analytics deletion is processed within 24 hours. Unused Hint Tokens are permanently forfeited and cannot be restored.
A non-reversible HMAC deletion tombstone is retained for 90 days only to prevent delayed or retried purchase webhooks from recreating a deleted wallet. Store processors may retain transaction, refund, tax, dispute, fraud, or security records when legally or operationally required.
Contact
For privacy questions or data requests, contact support@ultramurdle.com.
ملخص عربي
يمكن إكمال قضية البدء السريع محليًا دون حساب أو اتصال بالشبكة. يلزم حساب واسم عرض فقط بعد نجاحها لحفظ التقدم وفتح الأرشيف، بينما يبقى اسم المستخدم والجنس اختياريين. تشرح هذه السياسة كيف يستخدم ألترا مردل بيانات الحساب والملف الخاص واللعب والمشتريات والدعم والمحتوى عن بعد والتذكيرات المحلية الاختيارية.
يسجل الموقع العام إجماليات يومية فقط لمرات ظهور أزرار App Store والنقر عليها حسب حملة مسموح بها ولغة الصفحة. لا ينشئ الموقع ملف تعريف ارتباط للتحليلات أو معرّف متصفح، ولا يخزن حسابًا أو عنوان IP أو وكيل المستخدم أو المُحيل أو مسارًا حرًا أو رابطًا عشوائيًا. يحتوي جدول الإجماليات على التاريخ والحملة واللغة وعدد مرات الظهور والنقر ووقت التحديث فقط.
تكون تذكيرات التحقيق المحلية متوقفة افتراضيًا. تبقى تفضيلاتها وحالة إذن النظام وأوقات الجدولة وهدف القضية المتحقق منه على الجهاز. لا يطلب ألترا مردل رمز دفع عن بُعد لهذه التذكيرات ولا يجمعه. يوجد تذكير واحد معلّق كحد أقصى، ونصه العام لا يحتوي على دليل أو حل أو بيانات حساب أو مشتريات أو رصيد رموز التلميح.
لأغراض تشغيل الحساب والتقدم، يشتق الخادم حقيقة تفعيل خاصة ومحدودة تشمل وقت الحساب ومزود الدخول واللغة وجاهزية اسم العرض والمراحل العامة الأولى للقضية وأعداد الحلول الموثوقة. لا تخزن ملاحظات الألغاز أو نصوص الأدلة أو الاختيارات أو المسودات أو الحلول أو معرفات الشراء أو الإعلانات. تحتوي الملخصات اليومية على أعداد إجمالية فقط وتخفي أي فئة تضم أقل من خمسة حسابات.
بعد موافقة مستقلة وصريحة، يربط التطبيق معرّف حساب Firebase بنشاط الشاشات والإجراءات المسموح بها والقضايا ووقت الاستخدام في الواجهة ونتائج الشراء والمحفظة ونوع التذكير ونتيجته ورموز الأعطال المسموح بها. يستطيع مالك التطبيق أو مسؤول مخوّل بصلاحية محددة عرض هذا النشاط مع البريد الإلكتروني واسم المستخدم الحالي. لا تشمل التحليلات عناوين التذكيرات أو نصوصها أو مساراتها أو رموز الدفع أو الملاحظات أو نصوص الأدلة والقصة أو الحلول أو شبكة الاستنتاج أو الاتهامات أو كلمات المرور أو رموز المصادقة أو الإيصالات أو معرفات المعاملات أو نصوص الدعم أو الأخطاء الخام أو إحداثيات الضغط.
قد يراجع المسؤولون المخوّلون بيانات الحساب والتقدم والشارات والمحفظة وتسليم المشتريات ولوحة الصدارة والتوصيات وبيانات الدعم الوصفية والتحليلات الموافق عليها عند الحاجة للدعم أو التشغيل. يخضع الوصول لصلاحيات محددة وسجل تدقيق، وتستبعد عروض الحساب العامة حالة الألغاز الخاصة والإيصالات ومعرفات المعاملات وتعليقات الدعم وملفات الصور ومسارات التخزين.
يستخدم التطبيق Firebase وGoogle Analytics 4 وBigQuery لمعالجة النشاط الموافق عليه، ويستخدم RevenueCat للتحقق من المشتريات والاستعادة. لا تستخدم التحليلات للإعلانات أو التتبع بين التطبيقات، ولا يستخدم التطبيق IDFA أو خرائط الحرارة أو تسجيل الجلسات أو الضغطات الخام. يبقى نشاط التوصيات الاختياري منفصلًا عن تحليلات الاستخدام.
تحذف حقيقة التفعيل الخاصة بالحساب عند حذفه، وتنتهي ملخصات التفعيل الإجمالية بعد 13 شهرًا.
يُحتفظ بالأحداث الخام المرتبطة بالحساب لمدة لا تتجاوز 90 يومًا. يؤدي إيقاف المشاركة إلى وقف الجمع الجديد مع بقاء الأحداث السابقة حتى انتهاء مدتها. قد تبقى إجماليات يومية مجهولة الهوية، ومنها إجماليات حملات الموقع العام، لمدة تصل إلى 24 شهرًا.
يمكن مشاهدة لوحة الترتيب دون الانضمام، ويكون النشر متوقفًا افتراضيًا ولا يبدأ إلا بعد تأكيد صريح من شاشة الترتيب. يظهر اسم المحقق المختار وإحصاءات الترتيب فقط، ولا يظهر البريد أو اختيار الملف أو معرف الحساب الخاص أو الملاحظات أو محتوى القضايا. يؤدي حذف الحساب إلى إلغاء تفويض Apple عند استخدامه وحذف سجل الشراء والحساب والتقدم والمحفظة والكشوف المدفوعة ومرفقات الدعم والترتيب وهوية التحليلات. تُفقد رموز التلميح غير المستخدمة نهائيًا. تبقى بصمة HMAC غير قابلة للعكس 90 يومًا فقط لمنع إعادة إنشاء المحفظة بسبب إشعارات الشراء المتأخرة.
لأسئلة الخصوصية: support@ultramurdle.com