Back to projects

Privacy Policy

Spheriz is a mobile puzzle game for iOS and Android. This page explains what data the app and associated backend services process and how it is handled.

Who is responsible for your data

Spheriz is developed and operated by me, Jakub Hýl, Business ID 23097736, registered at Gen. Hrušky 1215/25, 709 00 Ostrava – Mariánské Hory, Czech Republic.

You can reach me at support@jakubhyl.com (support) or info@jakubhyl.com (general enquiries), phone +420 604 757 173.

For the processing described below, I am the data controller under the EU General Data Protection Regulation (GDPR). A Data Protection Officer is not required and has not been appointed.

Accounts and authentication

Spheriz supports Guest play without requiring a secured account. Authentication is processed via a trusted Cloudflare Worker layer sitting in front of Microsoft PlayFab.

Users may secure their account using email and password, Google (Sign in with Google), or Apple (Sign in with Apple). A Guest player can later secure and link their existing player identity rather than creating separate progress.

Authentication may involve processing: an opaque PlayFab player/account identifier, a device-specific custom identifier (stored securely on the device), display name, email address (when using email authentication), linked Google or Apple account identifiers, and authentication/session credentials.

Passwords and provider tokens are not stored by the Studio website. The app's PlayFab session ticket is intentionally kept only in memory on the client during an active session.

Gameplay and account data

Spheriz processes and stores gameplay data tied to your player account to provide game features, leaderboards, and progress sync. This data is not purely local and includes, as applicable:

Display name, player ID, friend code, account link information, game scores, high scores, leaderboard entries, games played, campaign progression, completed levels, best level scores, gameplay statistics, achievements, daily challenge state/rewards, Orb virtual-currency balance, owned/unlocked cosmetics, purchase entitlement state, and social/friend relationships and pending requests.

Cloud save and synchronization

Spheriz features authenticated cross-device cloud synchronization for secured accounts. The current sync covers non-economy player state such as campaign level progress, campaign best scores, and detailed 2D and 3D gameplay statistics.

Guest accounts are intentionally excluded from cross-device progress synchronization because they do not have a secured cross-device identity.

Some local state is still stored on the device for performance, settings, pending synchronization operations, and offline/resilient operation.

Public and social information

Certain information is deliberately public to other Spheriz players where social or leaderboard features are used. This includes limited public profile information such as display name, friend code, leaderboard score/ranking, and relevant public gameplay statistics.

Friend requests and friend relationships are processed by the backend. Email addresses, authentication provider identifiers, device Custom IDs, session tickets, and credentials are never public.

Backend infrastructure and Cloudflare

Spheriz uses a Cloudflare Worker as its trusted backend/API layer between the app and services such as PlayFab and RevenueCat for authenticated operations.

The Cloudflare infrastructure may process ordinary network and technical request information required to serve and secure API traffic. Backend secrets and private credentials are not shipped inside the mobile app.

Microsoft PlayFab

The primary game backend, account, and economy platform is Microsoft PlayFab.

Microsoft PlayFab is used for functionality including player identity/accounts, display names, game statistics, leaderboards, progression data, virtual currency/economy, cosmetics inventory, and social features.

In-app purchases and RevenueCat

Spheriz uses RevenueCat together with Apple App Store and Google Play billing.

Purchases include a one-time Premium unlock and consumable Orb currency packs. RevenueCat is used for purchase and entitlement verification, processing transaction identifiers, product identifiers, receipt data, entitlement status, and an application-specific customer identifier.

Payment card details are handled directly by Apple or Google and are never received by the developer. Consumable Orb purchases cannot be restored through a standard Restore Purchases flow.

Advertising and privacy consent

Spheriz integrates Google Mobile Ads / AdMob. The game may display banner advertising, interstitial advertising, and optional rewarded advertising that grants an in-game reward upon verified completion.

Spheriz uses Google User Messaging Platform (UMP) before requesting ads where consent handling is required. Google and its advertising partners may process advertising/device/network information according to your consent choices and applicable law.

The app provides an in-app option to manage privacy choices when Google UMP reports that options are required. Purchasing the Premium upgrade removes normal forced advertising.

Analytics and diagnostics

Spheriz does not integrate dedicated first-party analytics SDKs (such as Firebase Analytics, Google Analytics, Sentry, or Mixpanel).

Backend and cloud service providers may process necessary operational, security, and service telemetry as part of delivering their services.

Local device storage

Some data is stored locally on the device, including settings and preferences, cached progress state, authentication/device identity information (stored in SecureStore/AsyncStorage), local game state, and pending synchronization state.

Account deletion

Spheriz includes an in-app account deletion flow. Deletion is designed to remove the player's PlayFab account and associated Spheriz server-side account data.

The backend also attempts cleanup of the associated RevenueCat customer record. If Apple is linked, Apple account-access revocation is handled as part of deletion. A minimal non-PII deletion receipt may be retained to confirm deletion occurred.

Deleting your Spheriz account does not automatically erase data that independent providers (Apple, Google, RevenueCat) are legally required or permitted to retain under their own policies. If deletion fails, support can be contacted.

Data sharing, retention, and your rights

Personal data is not sold by the developer. Data is shared and processed only as needed by service providers used to operate Spheriz (Microsoft PlayFab, Cloudflare, RevenueCat, Apple, Google, Google Mobile Ads).

As a data subject in the EU, you have the right to access, rectify, erase, restrict processing of, object to processing, and request portability of your data. You also have the right to lodge a complaint with the Czech Data Protection Office (ÚOOÚ). For inquiries, contact support@jakubhyl.com.

Support

Need help, want to report a bug, or have an issue with the app? You'll find everything on the support page:

Go to support

Last updated: August 2026