Privacy Policy
Jnana · Effective and last updated 8 October 2026
Jnana is a word game for iOS and Android published by The Pancake Stack ("we", "us"). This policy explains what the app collects, how, why, who helps us process it, how long we keep it, and what you can do about it. It covers the Jnana app and this website. It is written to be read, not to be survived.
The short version. Jnana is free, with no ads and no in-app purchases. We do not sell your personal information and we do not share it for advertising. You can play the single-player modes without signing in. If you sign in, we keep a backup of your scores, a display name, and your friends list. Usage analytics and crash reports help us fix and improve the game, and you can turn analytics off in Settings. You can delete your account and its data from inside the app at any time — see Deleting your account.
1. Who we are
Jnana is made by The Pancake Stack, the studio name of William Caldwell, who is the developer of Jnana and the controller of the personal information described here. You can reach us about anything in this policy at support@thepancakestack.dev.
2. What we collect
When you first open the app
- An anonymous account identifier. Firebase Authentication creates a random identifier the first time the app starts, so your multiplayer matches have somewhere to live. It is not tied to your name or email.
- A display name. Until you choose one, the app generates a name such as "Player 4821". While you are not signed in, your display name is stored on your device and is only sent to our servers if you join or create a multiplayer match (see below).
If you sign in (optional)
Signing in is optional; the single-player modes work without it. Signing in is needed for friends, invites, cloud backup, notifications, and submitting a board for the Daily.
- Sign in with Google. Google shares your Google account identifier, name, email address, and profile picture link with us through Firebase Authentication, which stores them with your account. We use your name only to suggest your first display name; we do not use your email address for anything except your sign-in, and we never show your email or picture to other players.
- Sign in with Apple (iPhone and iPad). We ask Apple for your name only — never your email address. Apple shares an Apple account identifier and, the first time only, the name on your Apple Account, which we use to suggest your first display name and which Firebase Authentication stores with your account. When you delete an account created with Apple, we also ask Apple to revoke Jnana's access to your Apple Account.
- Your display name, which you can change at any time in Settings → Account, is stored in your profile.
- A friend code, so other players can add you by link or code.
- Older versions of the app also kept a copy of your Daily streak (its length and the date you last solved the Daily) in your profile. Current versions no longer write it; an existing copy is removed when you delete your account. The Daily streak reminder never used it: it is scheduled on your device (see Notifications below).
Friends and invites
- Your friends list and blocked list. Each entry stores the other player's internal identifier and display name, and a friend entry also stores when the friendship began.
- The stats your friends see — your Gauntlet best scores and your Daily streak — are copied into your friends' lists (see What other players can see).
- Match invites you send or receive: who sent it, their display name, the match type, its Join code, and when it was sent.
Gameplay
- Cloud backup (signed-in players): your Gauntlet best scores and your Daily results, kept separately for each word list ("Lexicon") you play, so a new device or a reinstall restores them.
- Multiplayer match data for Rally and Duel matches you create or join: the Join code, the name the host gives the match, the display names and internal identifiers of the players, the boards players author, the letters dealt, the moves and scores played, timings, and the match status and results.
- Daily submissions (signed-in players), if you send in a board you built for consideration as a Daily: the board, the word list it was built for, your account identifier, your display name as it stood when you submitted (the default credit), when you submitted it, and its status (pending, published, or not selected) and, if published, the date it runs.
Notifications
- If you are signed in and allow notifications, we store a push notification token for each of your devices, with the device platform (Android or iOS) and when it was last refreshed. It lets Firebase Cloud Messaging deliver notifications to that device. Anonymous players get no token stored and no notifications.
- We send notifications only about your own games: a friend invited you to a match (the notification shows their display name), a Duel needs your move or has finished, or a Rally is ending soon or has results. We do not send marketing notifications.
- The Daily streak reminder works differently: if you turn it on, the app schedules it on your device itself, before the Daily ends. It uses no data from our servers and stores no push token, so it is available whether or not you are signed in, and turning it off in Settings → Daily reminder cancels it.
Usage analytics
Released versions of the app use Google Analytics for Firebase to count how the game is used. We do not attach your account identifier, name, or email to analytics. Analytics receives:
- Google's standard automatic events, such as first open, app open, session start, engagement time, app and OS updates, and notification receipt and opens;
- an app-instance identifier generated by Analytics, your device model, operating system and version, app version, language, and an approximate location (country or city) that Google derives from your IP address;
- these named events of our own, none of which contains your name, account identifier, Join codes, or friend codes:
| Event | Recorded when | Details sent |
|---|---|---|
mode_opened | You open a game mode | Which mode; for Gauntlet, the difficulty |
sign_in_started, sign_in_completed | You start, and finish, signing in | Google or Apple |
friend_add_completed | A friendship is confirmed | Nothing else |
match_started, match_completed | You start, and finish, a Rally or Duel | Rally or Duel; the word list |
push_permission_result | You answer the notification permission prompt | Granted or denied |
daily_solved | You solve the current day's Daily | Streak length as a range (1, 2–3, 4–7, 8–30, 31+); the word list |
lexicon_selected | You choose a word list | The word list |
board_timing | A board you waited for becomes playable | Mode, grid size, word list, and how long it took as a range |
dictionary_load_timing | The app loads a word list | Loading stage, word list, and how long it took as a range |
Analytics also records a screen view when you arrive from an invite link, friend link, or notification — reported as the kind of link, never the code in it. Debug and test builds send no analytics.
If your device is set to a region in the European Economic Area, the United Kingdom, or Switzerland (or to no region at all), analytics is off until you agree to it. The first time you open the app, it asks once whether you want to share usage stats; nothing is sent before you answer, and nothing at all if you say no. If you close the app without answering, analytics stays off and the question comes back next time. Everywhere else, analytics is on unless you turn it off.
Wherever you are, you can change your answer at any time with Settings → Share usage stats; it takes effect straight away and stays that way on that device. Analytics is never used for advertising.
Crash and error reports
Released versions of the app send crash and error reports to Sentry. A report contains the error and stack trace, a short trail of recent app events leading up to it (such as the app moving to the background, and app log messages), device details such as model and manufacturer, operating system and version, app version and build, screen size, language, time zone, and memory and storage state, and a random installation identifier created by the Sentry library. We do not attach your account identifier, name, or email, we do not capture screenshots, and we have not enabled Sentry's options for sending personal information. An error message can occasionally include a technical identifier such as a database path; we do not use reports to identify anyone.
Security and configuration
- Firebase App Check asks Google Play Integrity (on Android) or Apple's App Attest and DeviceCheck (on iPhone and iPad) to confirm requests come from a genuine copy of the app on a genuine device, which protects our servers and other players from abuse.
- Firebase Remote Config is checked once at startup to learn whether your app version still works with our servers. Like other Firebase services, it sends a Firebase installation identifier and basic device details (app version, operating system, language, country and time zone).
- Our servers and our providers' servers receive your IP address as part of every network connection, and use it to deliver the service and protect it from abuse.
Stored only on your device
Much of the game never leaves your phone or tablet. Your in-progress Gauntlet run, today's Daily attempt, your Hook Quiz bests and attempts, custom quizzes, boards you author (until you send one to an opponent or submit it), the list of matches you have joined, Duel drafts, your settings (music, word list, difficulty, notification preferences), and while you are not signed in your display name, are stored on your device only. We cannot see them, they are not backed up, and they are lost if you uninstall the app. Matches you joined can be rejoined with their Join code.
This website
This website, including invite links that open in a browser, has no cookies, analytics, or tracking. Google's hosting service processes your IP address and browser details to deliver the pages. The app also downloads a small file of published Daily boards from this website.
3. What we do not collect
- No precise location, and no access to your device's location services.
- No access to your device's contacts, photos, camera, microphone, files, or calendar.
- No payment or financial information — there is nothing to buy.
- No ads and no ad networks, and no advertising identifiers: we have turned off Analytics' collection of the Android advertising ID, and on iPhone and iPad the app never asks for permission to track you.
- No chat or private messaging — the only text other players see from you is your display name, a match name you give as host, and a credit on a board we publish.
- No health, fitness, biometric, or other sensitive information, and no browsing or search history.
4. How we use it, and our legal bases
We use personal information only to run and improve Jnana. We do not sell it, we do not use it for advertising or to build advertising profiles, and we do not make automated decisions about you that have legal or similarly significant effects. If you are in the European Economic Area or the United Kingdom, these are the legal bases we rely on:
| Purpose | Information used | Legal basis |
|---|---|---|
| Running your account, sign-in, cloud backup, friends, invites, and multiplayer matches | Account identifiers, sign-in details, display name, friend code, friends and blocked lists, invites, gameplay and match data | Performing our agreement with you (the Terms of Service) |
| Sending the notifications you allowed | Push tokens, match and invite data | Performing our agreement with you; you can turn notifications off at any time |
| Reviewing and publishing a board you submit for the Daily | The submission and its credit | Performing our agreement with you, at your request |
| Fixing crashes and errors | Crash and error reports | Our legitimate interest in a working, reliable game |
| Understanding which features are used and how fast the game runs | Usage analytics | In the EEA, the UK and Switzerland: your consent, asked once when you first open the app, which you can withdraw at any time in Settings → Share usage stats. Elsewhere: our legitimate interest in improving the game; you can turn it off in the same setting (see Your choices) |
| Protecting the service, preventing abuse and cheating, enforcing our terms | App Check results, IP addresses, account and match data | Our legitimate interest in keeping the service secure and fair |
| Answering your emails and requests | Whatever you send us | Our legitimate interest in supporting players, and our legal obligations |
| Meeting legal obligations | Any of the above, only as required | Compliance with law |
5. What other players can see
- Your display name is visible to your friends, to anyone who opens your friend link or enters your friend code, to players in any match you create or join, and in the notification a friend receives when you invite them to a match.
- Anyone who has a match's Join code can see that match's name, its players' display names, and its boards, moves, and results. Share a Join code only with people you want to play with.
Your Gauntlet best scores and your Daily streak are visible to your confirmed friends, and there is currently no setting to turn this off. If you do not want someone to see them, do not accept them as a friend, or remove them as a friend. We may add a visibility control in a future version.
Friendship is mutual and only forms when you accept — nobody can add you silently. Blocking someone is never revealed to them. There is no public profile, no player search or directory, no leaderboard, and no online status.
Daily submissions are the one way something of yours can reach every player. A board you submit is seen only by you and by us — we review every submission by hand, and other players cannot see, browse, or review submissions. If we publish your board, it runs as that day's Daily for every player, stays in the Daily Archive, and is included in the public file of Daily boards on this website, with a credit. The credit defaults to the display name you submitted under, but we set the final text and may edit it or leave it off. It is a fixed piece of text, not a link to your account: renaming yourself later does not change it, and nothing on a published board leads back to your profile or friend code.
6. Who else processes it
We do not sell or rent personal information, and we do not share it with advertisers or data brokers. We use these service providers, which process data on our behalf, under contracts that require them to protect it at least as well as this policy does and to use it only to provide their services to us:
- Google LLC (Firebase) — Authentication, Cloud Firestore (our database), Cloud Functions, Cloud Messaging (push notifications), App Check, Remote Config, Hosting (this website), and Google Analytics for Firebase.
- Functional Software, Inc. (Sentry) — crash and error reporting.
When you choose to sign in, Google or Apple handles the sign-in itself under its own privacy policy, and sends us only what is described in What we collect. App Check also relies on Google Play Integrity and Apple App Attest / DeviceCheck, which are part of your device's operating system.
We may also disclose information if the law requires it, to protect the rights, safety, or property of players, us, or others, or as part of a merger, acquisition, or transfer of the app, in which case this policy (or one at least as protective) will continue to apply.
7. Where it is stored
We are based in the United States, and our database, server functions, and crash reporting run on servers in the United States. If you use Jnana from elsewhere, including the EEA or UK, your information is transferred to the United States. Google and Sentry protect those transfers with the safeguards in their data processing terms, such as the European Commission's Standard Contractual Clauses and, where they are certified, the EU–U.S. Data Privacy Framework and its UK extension. You can ask us for details of these safeguards.
8. How long we keep it
| Information | Kept until |
|---|---|
| Account, profile, display name, friend code, friends and blocked lists, cloud backup, Daily streak | You delete your account |
| Push tokens | You sign out on that device, delete your account, or the token stops working; a token not refreshed for 270 days is removed the next time we try to use it |
| Rally match data | Automatically deleted 7 days after the Rally closes |
| Duel match data | Automatically deleted 7 days after the Duel ends; a Duel nobody touches for 30 days is closed and deleted soon after |
| Match invites | The recipient accepts or declines it, a Rally invite's match closes, the recipient's inbox overflows (the oldest of 50 is removed), or the recipient deletes their account |
| Daily submissions | You withdraw it or delete your account. A submission we do not select is marked "Not selected" in the app. It is deleted once you have seen that and 7 days have passed (the next time you open your submissions), and in any case 90 days after we declined it. A published board stays in the game and the Daily Archive |
| Notification delivery records (which reminder was sent, to prevent duplicates) | 30 days |
| Usage analytics | Event-level data no longer than 14 months; Google keeps aggregated reports |
| Crash and error reports | Up to 30 days |
| Anonymous account identifiers | Deleted automatically once the app has not been used with them for 6 months, together with anything still stored under them on our servers |
| Emails you send us | As long as needed to deal with your message, and any record we need to show we handled a request |
| Information stored only on your device | You clear it, sign out, delete your account, or uninstall the app |
Automatic deletions normally complete within a few days of the stated time. Deleted data can persist in our providers' encrypted backups for a limited period before it is overwritten.
9. Deleting your account
In the app: open Settings → Account → Delete account and confirm. You will be asked to sign in again with Google or Apple to prove it is you. Deletion is immediate and cannot be undone. It removes:
- your sign-in account, profile, display name, friend code, and Daily streak;
- your cloud backup, for every word list;
- your friends, from their lists as well as yours, and your blocked list;
- match invites waiting for you;
- your Daily submissions, at every status;
- your push notification tokens;
- your seat in any match lobby you have joined; and
- the game progress stored on your device.
For an account created with Sign in with Apple, we also revoke Jnana's access to your Apple Account. Settings → Account → What's stored, what's deleted lists the same things in the app.
What deletion does not remove:
- Matches you have already played with others remain visible to the other players, including your display name as it appeared in them, until they are deleted automatically (see How long we keep it).
- Invites you sent that are still waiting in a friend's inbox stay there until the friend opens them or they expire.
- A board of yours we have already published as a Daily stays in the game, the Daily Archive, and the public file of Daily boards, with the credit that ran with it, because it is part of the published game rather than your account. Email us and we will change or remove the credit.
- Analytics and crash reports are not linked to your account, so they are not deleted with it; they expire on the schedule above.
Without the app: if you no longer have the app, or would rather we did it, email support@thepancakestack.dev with the subject "Delete my Jnana account". To help us find the right account, include your display name and friend code, or the email address of the Google account you signed in with. We may ask you to confirm the request before deleting anything, and we will confirm when it is done. Uninstalling the app on its own deletes only what is stored on your device.
If you never signed in, there is no account to delete in the app: your progress is on your device, your matches expire on the schedule above, and uninstalling removes the rest. Email us if you want us to remove anything sooner.
Signing out is different from deleting: it removes that device's push token and clears signed-in progress from the device, but keeps your account so you can sign back in.
10. Your choices and rights
Choices in the app and on your device
- Play without signing in, and nothing is linked to a Google or Apple account.
- Change your display name in Settings → Account.
- Turn notifications off in Jnana's Settings or your device settings.
- Turn usage analytics on or off with Settings → Share usage stats. In the EEA, the UK and Switzerland it stays off unless you agree, and turning it off withdraws that consent. Crash reports are separate and are not affected.
- Remove or block friends, decline invites, and withdraw a pending Daily submission.
- Delete your account, as described above.
Your rights
Depending on where you live, you may have the right to: know what personal information we hold about you and get a copy of it; correct it; delete it; restrict or object to how we use it (including the analytics we run on legitimate interests); receive it in a portable format; and withdraw any consent you have given. To use any of these rights, email support@thepancakestack.dev. We will respond within one month (or within the time your local law sets), may need to verify that the request comes from you, and will not charge you for it. Because analytics and crash reports are not linked to your account, we generally cannot single out those records for a particular person.
If you are in the EEA or UK and are unhappy with how we have handled your information, you can complain to your local data protection authority (in the UK, the Information Commissioner's Office). We would appreciate the chance to put it right first.
United States residents
Some US state laws, including California's, give residents rights over their personal information. In the last 12 months we have collected the categories described in section 2: identifiers (account identifiers, display name, email address if you sign in with Google, device and app identifiers, and IP address); internet or other electronic network activity (gameplay, match and usage data, crash reports); and approximate location derived from IP address. We do not draw inferences about you to build a profile. We collect them from you, your device, and Google or Apple when you sign in, for the purposes in section 4, and disclose them only to the service providers in section 6. We do not sell personal information, and we do not "share" it for cross-context behavioral advertising, and we have not done so in the last 12 months. We do not use or disclose sensitive personal information. You may ask to know, access, correct, or delete your information, or appoint an authorized agent to do so, by emailing us; we will verify the request and will not discriminate against you for exercising any of these rights.
11. Security
Everything the app sends or receives over the network is encrypted in transit (HTTPS/TLS), and our providers encrypt stored data at rest. Our database is protected by access rules that let each player read and change only their own data, plus the shared match data described above; App Check helps keep fake clients out. Server-side clean-up and push delivery run in Google's cloud under restricted service accounts. No system is perfectly secure, but we will tell you, and the authorities where required, if a breach affects your information.
12. Children
Jnana is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (or the higher minimum age that applies where you live). If you believe a child has given us personal information, email us and we will delete it.
13. Changes to this policy
If we change what we collect or how we use it, we will update this page and the date at the top before the change takes effect. If a change is material, we will also tell you in the app before it applies to you, and ask for your consent where the law requires it. Earlier versions are available on request.
14. Contact
Questions, requests, corrections, or complaints: support@thepancakestack.dev