Apps / Jnana

Privacy Policy

Jnana · Effective and last updated 8 October 2026

Jnana is a word game for iOS and Android published by The Pancake Stack ("we", "us"). This policy explains what the app collects, how, why, who helps us process it, how long we keep it, and what you can do about it. It covers the Jnana app and this website. It is written to be read, not to be survived.

The short version. Jnana is free, with no ads and no in-app purchases. We do not sell your personal information and we do not share it for advertising. You can play the single-player modes without signing in. If you sign in, we keep a backup of your scores, a display name, and your friends list. Usage analytics and crash reports help us fix and improve the game, and you can turn analytics off in Settings. You can delete your account and its data from inside the app at any time — see Deleting your account.

1. Who we are

Jnana is made by The Pancake Stack, the studio name of William Caldwell, who is the developer of Jnana and the controller of the personal information described here. You can reach us about anything in this policy at support@thepancakestack.dev.

2. What we collect

When you first open the app

If you sign in (optional)

Signing in is optional; the single-player modes work without it. Signing in is needed for friends, invites, cloud backup, notifications, and submitting a board for the Daily.

Friends and invites

Gameplay

Notifications

Usage analytics

Released versions of the app use Google Analytics for Firebase to count how the game is used. We do not attach your account identifier, name, or email to analytics. Analytics receives:

Custom analytics events
EventRecorded whenDetails sent
mode_openedYou open a game modeWhich mode; for Gauntlet, the difficulty
sign_in_started, sign_in_completedYou start, and finish, signing inGoogle or Apple
friend_add_completedA friendship is confirmedNothing else
match_started, match_completedYou start, and finish, a Rally or DuelRally or Duel; the word list
push_permission_resultYou answer the notification permission promptGranted or denied
daily_solvedYou solve the current day's DailyStreak length as a range (1, 2–3, 4–7, 8–30, 31+); the word list
lexicon_selectedYou choose a word listThe word list
board_timingA board you waited for becomes playableMode, grid size, word list, and how long it took as a range
dictionary_load_timingThe app loads a word listLoading stage, word list, and how long it took as a range

Analytics also records a screen view when you arrive from an invite link, friend link, or notification — reported as the kind of link, never the code in it. Debug and test builds send no analytics.

If your device is set to a region in the European Economic Area, the United Kingdom, or Switzerland (or to no region at all), analytics is off until you agree to it. The first time you open the app, it asks once whether you want to share usage stats; nothing is sent before you answer, and nothing at all if you say no. If you close the app without answering, analytics stays off and the question comes back next time. Everywhere else, analytics is on unless you turn it off.

Wherever you are, you can change your answer at any time with Settings → Share usage stats; it takes effect straight away and stays that way on that device. Analytics is never used for advertising.

Crash and error reports

Released versions of the app send crash and error reports to Sentry. A report contains the error and stack trace, a short trail of recent app events leading up to it (such as the app moving to the background, and app log messages), device details such as model and manufacturer, operating system and version, app version and build, screen size, language, time zone, and memory and storage state, and a random installation identifier created by the Sentry library. We do not attach your account identifier, name, or email, we do not capture screenshots, and we have not enabled Sentry's options for sending personal information. An error message can occasionally include a technical identifier such as a database path; we do not use reports to identify anyone.

Security and configuration

Stored only on your device

Much of the game never leaves your phone or tablet. Your in-progress Gauntlet run, today's Daily attempt, your Hook Quiz bests and attempts, custom quizzes, boards you author (until you send one to an opponent or submit it), the list of matches you have joined, Duel drafts, your settings (music, word list, difficulty, notification preferences), and while you are not signed in your display name, are stored on your device only. We cannot see them, they are not backed up, and they are lost if you uninstall the app. Matches you joined can be rejoined with their Join code.

This website

This website, including invite links that open in a browser, has no cookies, analytics, or tracking. Google's hosting service processes your IP address and browser details to deliver the pages. The app also downloads a small file of published Daily boards from this website.

3. What we do not collect

4. How we use it, and our legal bases

We use personal information only to run and improve Jnana. We do not sell it, we do not use it for advertising or to build advertising profiles, and we do not make automated decisions about you that have legal or similarly significant effects. If you are in the European Economic Area or the United Kingdom, these are the legal bases we rely on:

Purposes and legal bases
PurposeInformation usedLegal basis
Running your account, sign-in, cloud backup, friends, invites, and multiplayer matchesAccount identifiers, sign-in details, display name, friend code, friends and blocked lists, invites, gameplay and match dataPerforming our agreement with you (the Terms of Service)
Sending the notifications you allowedPush tokens, match and invite dataPerforming our agreement with you; you can turn notifications off at any time
Reviewing and publishing a board you submit for the DailyThe submission and its creditPerforming our agreement with you, at your request
Fixing crashes and errorsCrash and error reportsOur legitimate interest in a working, reliable game
Understanding which features are used and how fast the game runsUsage analyticsIn the EEA, the UK and Switzerland: your consent, asked once when you first open the app, which you can withdraw at any time in Settings → Share usage stats. Elsewhere: our legitimate interest in improving the game; you can turn it off in the same setting (see Your choices)
Protecting the service, preventing abuse and cheating, enforcing our termsApp Check results, IP addresses, account and match dataOur legitimate interest in keeping the service secure and fair
Answering your emails and requestsWhatever you send usOur legitimate interest in supporting players, and our legal obligations
Meeting legal obligationsAny of the above, only as requiredCompliance with law

5. What other players can see

Your Gauntlet best scores and your Daily streak are visible to your confirmed friends, and there is currently no setting to turn this off. If you do not want someone to see them, do not accept them as a friend, or remove them as a friend. We may add a visibility control in a future version.

Friendship is mutual and only forms when you accept — nobody can add you silently. Blocking someone is never revealed to them. There is no public profile, no player search or directory, no leaderboard, and no online status.

Daily submissions are the one way something of yours can reach every player. A board you submit is seen only by you and by us — we review every submission by hand, and other players cannot see, browse, or review submissions. If we publish your board, it runs as that day's Daily for every player, stays in the Daily Archive, and is included in the public file of Daily boards on this website, with a credit. The credit defaults to the display name you submitted under, but we set the final text and may edit it or leave it off. It is a fixed piece of text, not a link to your account: renaming yourself later does not change it, and nothing on a published board leads back to your profile or friend code.

6. Who else processes it

We do not sell or rent personal information, and we do not share it with advertisers or data brokers. We use these service providers, which process data on our behalf, under contracts that require them to protect it at least as well as this policy does and to use it only to provide their services to us:

When you choose to sign in, Google or Apple handles the sign-in itself under its own privacy policy, and sends us only what is described in What we collect. App Check also relies on Google Play Integrity and Apple App Attest / DeviceCheck, which are part of your device's operating system.

We may also disclose information if the law requires it, to protect the rights, safety, or property of players, us, or others, or as part of a merger, acquisition, or transfer of the app, in which case this policy (or one at least as protective) will continue to apply.

7. Where it is stored

We are based in the United States, and our database, server functions, and crash reporting run on servers in the United States. If you use Jnana from elsewhere, including the EEA or UK, your information is transferred to the United States. Google and Sentry protect those transfers with the safeguards in their data processing terms, such as the European Commission's Standard Contractual Clauses and, where they are certified, the EU–U.S. Data Privacy Framework and its UK extension. You can ask us for details of these safeguards.

8. How long we keep it

Retention
InformationKept until
Account, profile, display name, friend code, friends and blocked lists, cloud backup, Daily streakYou delete your account
Push tokensYou sign out on that device, delete your account, or the token stops working; a token not refreshed for 270 days is removed the next time we try to use it
Rally match dataAutomatically deleted 7 days after the Rally closes
Duel match dataAutomatically deleted 7 days after the Duel ends; a Duel nobody touches for 30 days is closed and deleted soon after
Match invitesThe recipient accepts or declines it, a Rally invite's match closes, the recipient's inbox overflows (the oldest of 50 is removed), or the recipient deletes their account
Daily submissionsYou withdraw it or delete your account. A submission we do not select is marked "Not selected" in the app. It is deleted once you have seen that and 7 days have passed (the next time you open your submissions), and in any case 90 days after we declined it. A published board stays in the game and the Daily Archive
Notification delivery records (which reminder was sent, to prevent duplicates)30 days
Usage analyticsEvent-level data no longer than 14 months; Google keeps aggregated reports
Crash and error reportsUp to 30 days
Anonymous account identifiersDeleted automatically once the app has not been used with them for 6 months, together with anything still stored under them on our servers
Emails you send usAs long as needed to deal with your message, and any record we need to show we handled a request
Information stored only on your deviceYou clear it, sign out, delete your account, or uninstall the app

Automatic deletions normally complete within a few days of the stated time. Deleted data can persist in our providers' encrypted backups for a limited period before it is overwritten.

9. Deleting your account

In the app: open Settings → Account → Delete account and confirm. You will be asked to sign in again with Google or Apple to prove it is you. Deletion is immediate and cannot be undone. It removes:

For an account created with Sign in with Apple, we also revoke Jnana's access to your Apple Account. Settings → Account → What's stored, what's deleted lists the same things in the app.

What deletion does not remove:

Without the app: if you no longer have the app, or would rather we did it, email support@thepancakestack.dev with the subject "Delete my Jnana account". To help us find the right account, include your display name and friend code, or the email address of the Google account you signed in with. We may ask you to confirm the request before deleting anything, and we will confirm when it is done. Uninstalling the app on its own deletes only what is stored on your device.

If you never signed in, there is no account to delete in the app: your progress is on your device, your matches expire on the schedule above, and uninstalling removes the rest. Email us if you want us to remove anything sooner.

Signing out is different from deleting: it removes that device's push token and clears signed-in progress from the device, but keeps your account so you can sign back in.

10. Your choices and rights

Choices in the app and on your device

Your rights

Depending on where you live, you may have the right to: know what personal information we hold about you and get a copy of it; correct it; delete it; restrict or object to how we use it (including the analytics we run on legitimate interests); receive it in a portable format; and withdraw any consent you have given. To use any of these rights, email support@thepancakestack.dev. We will respond within one month (or within the time your local law sets), may need to verify that the request comes from you, and will not charge you for it. Because analytics and crash reports are not linked to your account, we generally cannot single out those records for a particular person.

If you are in the EEA or UK and are unhappy with how we have handled your information, you can complain to your local data protection authority (in the UK, the Information Commissioner's Office). We would appreciate the chance to put it right first.

United States residents

Some US state laws, including California's, give residents rights over their personal information. In the last 12 months we have collected the categories described in section 2: identifiers (account identifiers, display name, email address if you sign in with Google, device and app identifiers, and IP address); internet or other electronic network activity (gameplay, match and usage data, crash reports); and approximate location derived from IP address. We do not draw inferences about you to build a profile. We collect them from you, your device, and Google or Apple when you sign in, for the purposes in section 4, and disclose them only to the service providers in section 6. We do not sell personal information, and we do not "share" it for cross-context behavioral advertising, and we have not done so in the last 12 months. We do not use or disclose sensitive personal information. You may ask to know, access, correct, or delete your information, or appoint an authorized agent to do so, by emailing us; we will verify the request and will not discriminate against you for exercising any of these rights.

11. Security

Everything the app sends or receives over the network is encrypted in transit (HTTPS/TLS), and our providers encrypt stored data at rest. Our database is protected by access rules that let each player read and change only their own data, plus the shared match data described above; App Check helps keep fake clients out. Server-side clean-up and push delivery run in Google's cloud under restricted service accounts. No system is perfectly secure, but we will tell you, and the authorities where required, if a breach affects your information.

12. Children

Jnana is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (or the higher minimum age that applies where you live). If you believe a child has given us personal information, email us and we will delete it.

13. Changes to this policy

If we change what we collect or how we use it, we will update this page and the date at the top before the change takes effect. If a change is material, we will also tell you in the app before it applies to you, and ask for your consent where the law requires it. Earlier versions are available on request.

14. Contact

Questions, requests, corrections, or complaints: support@thepancakestack.dev