Cornered has no accounts, no advertising, and no third-party tracking. It does not know who you are and has no way to find out.
The short version. Everything you play is stored on your own device. The app sends one small anonymous record when you finish a board, and a fault report if it breaks. Neither contains anything that identifies you.
If you would rather send nothing at all, there is nothing to switch off, because there is nothing personal in it. You can still reset the anonymous identifier at any time in Settings, which starts the count over from scratch.
Your progress lives on your phone and nowhere else. That includes which puzzles you have played and what you found in them, your settings, your marks, whether you have seen the tutorial, and which awards you have earned.
None of it is sent anywhere, and none of it is readable by us. It rides along in your device's own backup if you use one, because it is ordinary app storage. Deleting the app deletes all of it. There is no copy on a server to ask us for.
Three things, all anonymous. They go to a server we run on Cloudflare, and to nobody else.
When you finish a board:
| Field | What it is |
|---|---|
install | A random identifier the app generates the first time it opens. Not your device id, not an advertising id, not linked to anything. Resettable in Settings. |
event_id | A random identifier for this one record, so a retry does not count twice. |
day, weekday | Which puzzle it was. |
found, total | How many answers you charted, out of how many there were. |
hints | How many hints you used. |
seconds | How long the board took. |
finished | Whether you completed it. |
source | Whether it was today's board or one from the archive. |
build | Which version of the app you are running. |
env | Whether this came from a released copy of the app, a test build, or a developer's own machine. It describes the BUILD rather than you, and it is there so our own testing can be kept out of the figures. |
If the app hits an error:
| Field | What it is |
|---|---|
install, event_id | As above. |
build, platform | Which version, and iOS or Android. |
env | Whether this came from a released copy of the app, a test build, or a developer's own machine. It describes the BUILD rather than you, and it is there so our own testing can be kept out of the figures. |
fatal | Whether it took the screen down. |
message, stack, component | The error's own description of itself and where it happened in the code. |
When a share card is opened:
A finished board can be shared as a link. When somebody opens that link, or when a messaging app draws the card's preview, we add one to a counter. This is the only thing on this page that can be triggered by somebody who has never installed the app, and it is deliberately the smallest record we keep.
| Field | What it is |
|---|---|
kind | Either preview, meaning a messaging app drew the card, or open, meaning a person opened the link. |
env | As above. It describes the build, not you. |
There is no record of who opened a share card, or of which one. We do not store an identifier, an address, a device, or even which puzzle the card was for. What is kept is a date, one of those two words, and a number - so a row counts events and could not describe a person even if we wanted it to. The result inside the link itself is never stored: the page redraws the card from the link every time it is opened, and keeps nothing.
Our server adds two things of its own:
| Field | What it is |
|---|---|
received | The date the record arrived, according to our server rather than your phone. |
country | A two-letter country code that Cloudflare works out at its edge. |
Your IP address is never stored, and never reaches our code. The country comes from a header Cloudflare fills in before the request gets to us, which is why we can say where players are in aggregate without holding anything about where you are.
Cornered can update parts of itself without a full download from the store, so a fix reaches you in hours rather than after a review. To do that, the app asks Expo's update service whether a newer version exists. This is the only request the app makes to anyone other than us.
That request carries no information about you and nothing from your device's
storage. It says which platform you are on, which version of the app you are
running, and the id of the version you already have, so the service can answer
whether there is a newer one. It does not include your install id,
your progress, your settings, or anything you have played. Like any request over
the internet it reaches Expo from your IP address, which we neither receive nor
store.
The app never waits on this. It opens from the copy already on your device and checks in the background, so Cornered works with no connection at all.
The records above are deleted after thirteen months, automatically, every night. Everything in those tables — the anonymous identifier, which puzzles were played, the error reports — goes with them.
What we keep after that is counts: how many people played on a given day, how many came back a week later, what proportion of Saturdays get finished. Those are totals with nothing attached to them. There is no identifier in them, nothing about any one person, and no way to work backwards from a number to a player. We keep them indefinitely, because “is this game growing” is a question with no expiry date and answering it does not require remembering anybody.
If you buy anything, the payment is handled entirely by Apple or Google. We never see your card, your billing address or your name. To know whether a purchase should be restored on a new phone, we use RevenueCat, which receives the store's receipt and the anonymous identifier above.
Optional, off unless you ask for them, and scheduled by your own phone. There is no push server, so switching them on tells us nothing.
Cornered is suitable for all ages and collects nothing personal from anybody, regardless of age. There is no chat, no user content and no way for players to contact each other.
Because the records we hold are anonymous, we genuinely cannot find yours to delete on request - there is nothing connecting them to you. That is a consequence of collecting so little, and resetting the identifier is the equivalent control.
If this policy changes, the date below changes with it. Material changes will be described in the app's release notes rather than made quietly.
Peach Tree Productions LLC — [email protected]