Worm Garden

YOUR PRIVACY

Privacy Policy

Effective 10 October 2026

Your game progress stays on your device. This policy explains purchases, support and this website, and distinguishes the public game from the newer TestFlight build.

Who is responsible

Alex Vaitsiakhovich, trading as Alex Cozy Games and based in Cyprus, provides Worm Garden and is responsible for personal information handled for our support service and website. Contact: support@alexcozygames.com. Studio enquiries: hello@alexcozygames.com.

Which version are you using?

As checked on 10 October 2026, the public App Store version is 1.0. It has local puzzle progress and an optional permanent Apple purchase, with no advertising or gameplay analytics SDK. Version 1.2 (build 2026101001) is in TestFlight and includes Google Mobile Ads, Google’s User Messaging Platform (UMP), Harvest progress and an additional consumable purchase. Advertising disclosures below apply to that build when its consent or advertising services are used; they do not describe version 1.0 as containing ads.

Neither public version 1.0 nor TestFlight build 2026101001 includes AppsFlyer. A subsequent 1.2 update is being prepared with optional AppsFlyer analytics, interstitial ads between completed Story beds, and Play On Pack. The additional disclosures below apply when you use a build containing those features. Firebase Analytics is not integrated. Firebase Hosting, used for this website, is a separate service from app analytics. We do not require a game account.

Information stored on your device

The game saves progress, ratings, active attempts, cosmetics, earned currency and supplies, tutorial progress, local activities, and sound and motion preferences. Version 1.2 also stores Harvest activities and local reward and purchase-delivery receipts. Device time is used for local activities. The game does not upload this saved profile to a developer-operated gameplay server.

The game does not request contacts, photos, camera, microphone or precise location. It does not request App Tracking Transparency permission or access to the IDFA advertising identifier. This does not mean that the advertising services in version 1.2 process no data.

Purchases through Apple

Apple processes payments. StoreKit verifies transactions and permanent entitlements, restores eligible permanent purchases and responds to refunds or revocations. We do not receive your payment card details or Apple Account password. Transaction identifiers are stored locally as needed to avoid duplicate delivery; they are not sent to a developer-operated server. In the subsequent update, if you enable optional analytics, verified production purchases also send the product, amount, currency and quantity to AppsFlyer. Payment card details and raw Apple receipts are not included in those analytics events.

Version 1.0 offers No Ads + Extras, a non-consumable purchase. Version 1.2 also includes the consumable Gardener’s Bundle. Neither is a subscription. Consumables do not restore a spent or deleted local balance. Apple maintains its own transaction records under the Apple Privacy Policy. See license and purchase information for version-specific benefits.

Optional advertising in version 1.2 TestFlight

The TestFlight build integrates Google Mobile Ads and UMP. When configured and available, rewarded video offers are optional. Build 2026101001 has no banner or interstitial ads. The subsequent update adds occasional interstitial ads only when continuing after a completed Story bed, with introductory protection and frequency limits. There are no banners. No Ads + Extras suppresses both ad formats. Story retries remain free; an unavailable ad does not block continuation. Declining an ad does not prevent playing Gardens. Verified No Ads + Extras ownership suppresses advertising offers.

Google’s services may process IP addresses and approximate location inferred from them, device or app identifiers, ad impressions and interactions, app interactions, consent choices, crash reports, performance and diagnostic data. The purposes include delivering and measuring advertising, handling privacy choices, preventing abuse and diagnosing service performance. Advertising measurement is separate from the optional gameplay analytics described below.

The current build requests non-personalized ads and disables publisher first-party ID and publisher privacy personalization. This does not make ads anonymous or eliminate data processing. UMP requests applicable privacy choices, and Advertising privacy in Settings lets you revisit them when that option is available. UMP is separate from Apple’s tracking permission. Availability depends on region, privacy choices, connectivity and service configuration.

Google receives information directly when these services are used. See Google’s Privacy Policy, Google’s use of information from partner apps, and Google’s iOS advertising data disclosure.

Optional AppsFlyer analytics in the subsequent update

Analytics is off until you agree in Settings. If you agree, AppsFlyer receives app sessions, tutorial completion, Story and Daily attempt events (such as bed, outcome, moves and consented active time), supply use, offer interactions, granted rewards, verified production purchase product/amount/currency/quantity, and advertising revenue and placement information. We use this information to understand gameplay and purchase and advertising performance. We do not send your saved profile, board routes, name, email address, payment card details or raw purchase receipt in these events.

We use AppsFlyer Strict without IDFA, disable its IDFV collection and Apple Ads attribution, and block sharing with advertising partners in this integration. AppsFlyer still processes an installation identifier, IP/network information and SDK/device information needed to operate its service. IP masking is enabled in our AppsFlyer settings; this does not mean no IP address is processed. Data can be associated with an app installation even though we do not ask you to create an account. See AppsFlyer’s Services Privacy Policy.

Optional analytics relies on your consent. Declining does not affect gameplay, purchases or rewards. You can turn it off in Settings at any time: the app stops new measurement and clears its own unsent event queue. This does not delete records already received by AppsFlyer or promise removal of data already handed to the SDK. If you later opt in again, measurement resumes. Advertising privacy choices remain separate and are handled by UMP.

For access or deletion requests, contact support@alexcozygames.com. In builds with this feature, Settings → Privacy request ID shows the installation identifier after analytics has been used; include it with your request before deleting the app. This ID is retained locally after withdrawal so that we can locate the relevant analytics records. We handle supported requests through AppsFlyer’s data-subject request process and confirm the outcome. Turning analytics off is immediate in the app; server-side deletion is a separate process. Analytics records are retained under our service arrangements with AppsFlyer until applicable retention limits or a completed deletion request; backups and records required by law may follow separate retention rules. We do not promise that uninstalling the app removes provider records.

Support correspondence

If you email support, we receive your email address, message, attachments and ordinary email metadata. Device or app details are supplied by you, not automatically sent by the game. We use this information to reply, investigate problems, help with purchases and handle privacy requests. It is not used for advertising or mailing lists.

Support and studio mail use Google Workspace/Gmail. Incoming messages are also copied to the developer’s private Gmail inbox, while originals remain in the work mailbox. Both are used to handle your enquiry. The private mailbox address is not a public contact address.

Our older support pages remain accessible on Google Sites. If you choose to use their existing Google Form, Google Forms stores your reply email, message and submission timestamp privately in the developer’s account, and notifications go to Gmail. Form responses are not published. The new studio website contains no embedded form.

This website and service providers

This static website is hosted on Google Firebase Hosting. Your browser sends ordinary request information, including IP address, URL, browser information and request time, to the hosting provider to deliver and protect the site. We add no analytics, advertising scripts, tracking pixels or cookies. Images and fonts are served from this site. Email links open your email app; they do not send a message automatically.

Legacy Google Sites and Forms pages may use Google cookies or other technologies. Apple operates its own App Store and TestFlight services. Google and Apple may process information outside your country; their privacy disclosures describe their safeguards and international transfer mechanisms. Information may also be disclosed where legally required or necessary for legal claims.

Why we process information

Where the GDPR or similar laws apply, we process support enquiries as necessary to provide requested assistance or perform our contract with you. We rely on legitimate interests for proportionate troubleshooting, service security and related records, subject to your rights, and on applicable legal obligations when required. Consent or opt-out choices for advertising are presented where required; Google explains the basis for its own processing in its disclosures and applicable messages. We do not make automated decisions about you with legal or similarly significant effects.

Retention and deletion

Local progress remains until app data is deleted. To remove it, use iOS Settings → General → iPhone Storage → Worm Garden → Delete App. Offload App retains data. Deletion does not erase Apple’s purchase records. Backups may retain app data and a restored backup may restore it. We cannot remotely access or delete your local progress.

We retain support correspondence only as long as reasonably needed to resolve the request, investigate related issues, meet legal obligations or handle disputes, then delete it or remove identifying information. Deletion requests cover both the work mailbox and the support copies under our control, subject to required retention. Provider logs and backups follow provider retention practices.

Your rights

Depending on your location, you may have rights to access, correct or delete personal information, restrict or object to processing, and receive certain information in a portable format. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Contact support@alexcozygames.com. We may request only information reasonably needed to verify and fulfil the request and will respond within applicable time limits. You may complain to your local data-protection authority. There is no player account to delete.

Children and families

The game does not ask for a name, birth date or email to play, and has no chat or user-posting feature. Parents or guardians should handle support correspondence and purchases for children. If you believe a child sent us personal information through support, contact us so we can review and delete it where appropriate.

Security and changes

We use reasonable safeguards, including restricted access to support correspondence and protected provider accounts. No system guarantees absolute security. We will revise this policy when actual data practices change and provide any required notices or choices. Future analytics integrations are not covered as if they were already active.