Privacy Policy - The Scholar's Grid

Last Updated: 2026-07-17
Document Version: 1.2

The Scholar's Grid ("the app", "we") is a mobile board-game app published by the project owner. This policy describes what data the app collects, why, and your choices.

Summary

Data Purpose Required for
Federated sign-in (Apple / Google via Cognito) Online play, Standings, cloud cosmetic and Scholar's Marks sync Online features only
Match and ELO records Async online matches and global Standings Rated online play
Push notification token (Android FCM) Notify you when it is your turn Online play (optional fallback: polling)
App analytics events (Android / iOS) Measure early engagement (tutorial, first match/win, retention) and improve acquisition quality App install / store builds with Firebase configured
Local game settings and AI skill progress Offline play and Adaptive AI Local play
Personalization progress Board/piece skins and local-first Scholar's Marks with signed-in recovery Personalization

Local play (vs AI or Pass and Play) does not require an account.


Information we collect

Account and authentication

When you use online features (Find Online Match, Standings, or cloud Personalization sync), the app opens Amazon Cognito Hosted UI with federated sign-in:

We receive a Cognito user identifier (sub) and session tokens. We do not operate a separate email/password login. Identity providers may share profile fields allowed by your IdP settings; we use the Cognito sub as your player ID on our backend.

Session tokens are stored locally on your device (for example cloud_session.json) so you do not need to sign in every launch.

Online play and Standings

When you play rated async matches online, our AWS backend stores:

Standings show display names and ELO as returned by the API. Adaptive Skill Level (local AI difficulty) stays on your device and is not uploaded to Standings.

Push notifications (Android)

If you grant notification permission and play online on Android, the app registers an FCM device token with our backend so we can alert you when it is your turn. You can disable notifications in system settings; the app still works via periodic polling.

App analytics (Android / iOS)

On Android and iOS builds that include Firebase configuration, the app logs a small set of non-personal engagement events to Google Firebase Analytics (for example: tutorial complete, first match started, first win, Adaptive skill milestone, and day-3 return). It may also log a sparse performance sample after a match (approximate frame rate, graphics quality setting, GPU adapter name, and 2D/3D view) so we can improve smoothness on mid-range devices. Events do not include display names, account IDs, room codes, or match chat. On Android, Firebase may process device and advertising identifiers according to Google's privacy policy so we can measure install quality and, when linked, optimize ad campaigns for engaged players rather than raw installs. On iOS the Analytics SDK is linked without advertising-identifier support (no App Tracking Transparency prompt for analytics). The app does not show ads or include a third-party ad network SDK.

On the same Firebase-configured builds, crash reports (Firebase Crashlytics) may include custom diagnostic keys such as GPU adapter name, graphics quality tier, and render backend to help diagnose device-specific rendering issues.

Personalization and Scholar's Marks

The Personalization panel offers cosmetic-only items (board skins and piece sets). Gameplay is never locked behind payment.

The app does not include ads or a third-party ad network SDK. Analytics events above are for engagement measurement and acquisition quality only.

Local data on your device

The app may store locally:

This data stays on your device unless you sign in and use cloud sync. Owned cosmetic IDs and cumulative Scholar's Marks earned/spent totals then sync to your Player record; daily reward counters stay local.


How we use information

We do not sell personal data. We do not use LLM or third-party ad network SDKs that serve ads in the app.



Account and data deletion

If you signed in for online play, you may request deletion of your cloud account and associated data. Local-only play does not create a cloud account.

What we delete

When we process a verified request, we delete or anonymize:

Queued or in-progress online matches are recorded as a loss when the account is deleted. Completed match history may be retained in anonymized form where needed for Standings integrity, or deleted where applicable law requires.

What stays on your device

Local files (settings, Adaptive AI skill profiles, session cache) are not removed by us automatically. Your Scholar's Library purchase remains on the device and can be restored through the store. Sign out in the app, or clear app storage in Android Settings, to remove local data on your device.

How to request deletion

In the app: open Settings > Account > Delete my account, review the confirmation, then select Delete my account.

If you cannot sign in, email us from the address tied to your sign-in provider (Google or Apple), if possible. Include:

Request by email: papersignalstudios@gmail.com

We aim to complete verified requests within 30 days.


Third-party services

Provider Role
Amazon Web Services (Cognito, API Gateway, Lambda, DynamoDB, SNS) Auth, game API, storage, notifications
Apple / Google (federated IdP) Sign-in when you choose Hosted UI
Google Firebase Cloud Messaging Android push delivery
Google Firebase Analytics Android / iOS engagement events (early-action conversions for install quality)
Google Firebase Crashlytics Android / iOS crash reporting (when configured)

Each provider has its own privacy policy governing identity, analytics, crash, and notification flows.


Children

The app is intended for a general audience. We do not knowingly collect personal information from children under 13 (or under 16 in the EEA) without appropriate consent. Contact us if you believe a child has provided data through online sign-in.


Security

We use HTTPS for API calls and Cognito-issued JWTs for authenticated requests. No system is perfectly secure; report concerns to the contact below.


Your choices


Changes

We may update this policy. The "Last Updated" date will change. Material changes may be noted in release notes or the store listing.


Contact

Email: papersignalgames@gmail.com

Developer / Data controller: Paper Signal Games