Last updated 3 August 2026
Psolari is a daily puzzle game. It has no accounts, no advertising, nothing to buy and no tracking. This policy describes the little that is processed.
The German version is the authoritative one. This translation is provided for convenience.
While the “Share results” setting is switched off, no game data leaves your device. The app still downloads the day’s puzzle from our server, which necessarily transmits your IP address along with basic technical information about the request, such as which client software made it. See the IP addresses section below.
With the setting switched on, the outcome of each finished Daily is submitted. The app transmits no identifier by which we could link your results to each other or to you.
| What | Why |
|---|---|
| Whether you solved the puzzle, how many attempts you used, and the routes you drew | To see how hard each day’s puzzle really was, and to find puzzles that turn out to be unfair |
| How long the game took | Same |
| Which puzzle it was | To group results by day |
| Technical fields describing the puzzle: the attempt limit and the number of dots | So results can be interpreted correctly |
| App version, operating system and version, platform (iOS or Android), and the data-format version | To trace a bug to a specific release |
| A one-off identifier for that single submission | So a result resent after a poor connection is not counted twice. Generated fresh each time and never stored on your device |
No name. No email address. No account. No advertising identifier. No contacts. No photos. No device fingerprint. No cross-app identifier. No persistent identifier of any sort.
No location data: no GPS, no device location. Our infrastructure logs do derive the country of a request from its IP address as a technical by-product. We do not analyse it.
Nothing is passed to data brokers or advertising networks.
Settings, game progress and your history are stored only on your device and are not transmitted. They remain until you delete the app.
That storage is strictly necessary for the service you asked for, so under § 25(2) no. 2 TDDDG it requires no consent. Submitting a result, by contrast, happens only with your consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR.
This website sets no cookies for analytics, advertising or recognition, and contains no JavaScript. Our website provider Cloudflare may set strictly necessary cookies for security purposes, for example when a request is checked for being automated. They serve only to prevent abuse.
If you share your result through your operating system’s share menu, the shared content goes to whichever app you choose. That is outside our control.
The lawful basis for submitting and storing game results is your consent under Art. 6(1)(a) GDPR.
Sharing is off until you turn it on. The app asks once after your first finished Daily, and at most twice more after that. If you decline, nothing in the game is withheld, delayed or degraded.
You can withdraw your consent at any time under Settings, Data sharing, with effect for the future. Withdrawing is as easy as giving it. The lawfulness of processing carried out beforehand is unaffected. After withdrawal, no further results are sent, immediately and permanently.
Providing this data is neither a statutory nor a contractual requirement. You are under no obligation to provide it.
Results already submitted remain stored after a withdrawal. Because they carry no identifier, we could not pick them out afterwards even if asked.
Traffic between the app and the server travels only over an encrypted connection (HTTPS/TLS).
There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
Any request over the internet necessarily reveals your IP address to the server that receives it. Your IP address appears in our infrastructure logs. It is used to block abuse and to keep the service running, and it is deleted after 30 days at the latest. That covers the logs we configure ourselves at our providers; beyond those, the providers also process IP addresses for their own security purposes on their own retention schedules.
The lawful basis is Art. 6(1)(f) GDPR. Our legitimate interest is keeping the service available and working for everyone using it.
We do not link IP addresses to game results.
We use the following service providers as processors under Art. 28 GDPR:
Not processors but independent controllers: Apple and Google as the app store operators. They process their own data when the app is downloaded and distributed, which is outside our control and governed by their own privacy notices.
Nothing is passed to data brokers, advertising networks or any other third party for their own purposes.
Storage is in the AWS Frankfurt region (eu-central-1). The day’s puzzle is delivered through a worldwide content delivery network, so depending on where you are your request may be served from a location outside the European Economic Area.
Where processing takes place outside the EEA, whether through that network or in the course of support, it relies on the European Commission’s Standard Contractual Clauses under Art. 46(2)(c) GDPR and, where applicable, on the provider’s certification under the EU-US Data Privacy Framework under Art. 45 GDPR.
Game results are kept indefinitely, because community statistics only become meaningful over time. They carry no identifier.
Candidly: for the first 30 days it would in principle be technically possible to relate a result to an IP address through our infrastructure logs. We do not do so. After 30 days those logs are deleted and the relation is no longer technically possible either. Even then we could not identify you from it: getting from an IP address to a person runs through your access provider’s records, which we do not have and are not entitled to obtain.
Support messages are deleted no later than twelve months after the matter is closed.
You have the rights of access, rectification, erasure, restriction of processing and data portability under Art. 15 to 20 GDPR.
Submitted results deliberately carry no name, account, device or advertising identifier, and no persistent identifier of any sort. We are therefore not in a position to relate an individual result to a person. Under Art. 11(1) GDPR we are not obliged to collect additional data solely in order to satisfy these rights, and under Art. 11(2) GDPR Articles 15 to 20 do not apply in that case unless you provide additional information enabling your identification. If you do, we will give effect to those rights. This holds during the first 30 days too: that a result could in theory be related to an IP address in that window does not put us in a position to identify the person behind it.
Collecting nothing identifiable is a stronger protection than collecting it and promising to delete it on request.
Everything stored on your device is removed when you delete the app. For any request about your rights, write to [email protected].
You have the right to complain to a supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement, Art. 77 GDPR.
No data protection officer has been appointed. The conditions of Art. 37 GDPR and § 38 BDSG are not met.
We answer requests free of charge within one month.
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your IP address under Art. 21(1) GDPR. An email to [email protected] is enough.
Psolari is not directed at children. We do not knowingly collect personal data from children. Because the app collects no account, age, name or device identifier, younger players generate no data beyond what is described above.
Sharing results rests on consent. If you are under 16, please get a parent’s agreement first, Art. 8 GDPR; some Member States set a lower age. We collect no age and so cannot verify one; the results submitted carry no identifier and nothing that points to a person in any case.
If what we process ever changes, this page changes with it and the date at the top is updated. Anything that meaningfully broadened processing would be asked about in the app first.
The controller for the purposes of the GDPR is Louis Henry, reachable at [email protected]. A postal address is available on request by email.