Word Catch Privacy Policy
Effective 4 September 2026. Version 1.0.
Word Catch collects no personal data and transmits none.
It has no network access, no accounts, no advertising, no analytics and no in-app purchases. Everything the game saves stays on your device and is deleted along with the app.
The only way we ever learn anything about you is if you write to us yourself.
Who is responsible for your data
Word Catch is published by Rebusarium, a small team of mobile game developers. In this policy, "we" means Rebusarium.
For anything concerning this policy or your data, including exercising your rights: hello@rebusarium.com. It is a working address, real people read it, and you get an answer within one business day.
This policy covers the Word Catch app and this website only. Our other apps have their own policies, listed on the home page.
What the app stores on your device
The game saves a handful of values using iOS storage (UserDefaults), inside the app's sandbox, where neither we nor other apps can reach them. The complete list, with nothing left out:
| What is stored | Why |
|---|---|
| Current level number | so the game opens where you left off |
| Words found on each level | so your progress is not lost |
| Hints already revealed | so you are not charged twice for the same hint |
| Coin count | an in-game counter; it cannot be bought with real money |
| Whether the game has been completed | so the final screen appears once |
| Chosen background | an appearance setting |
| Sound, music, haptics | your settings |
| Launch count and first launch date | so the system "rate this app" prompt does not appear in your first minute |
| Date the rating prompt was last shown | so we do not ask again too soon |
None of these values leaves your device: the app contains no networking code that could send them. We cannot see them and cannot obtain them.
None of it is personal data — it cannot identify anyone. We list it in full anyway, so you do not have to guess what "progress" stands for.
How to delete it
Deleting the app deletes everything listed above. There is no button for it, and no need to ask us — we do not hold this data. For the same reason we cannot restore it: no backup exists. That is the trade-off for a game that needs no account.
What the app never does
- does not request or store your name, email address, phone number, date of birth, gender, or any other detail about you;
- does not determine your location — not precisely, not approximately, not by IP;
- does not access contacts, photos, camera, microphone, calendar, health data or files;
- shows no advertising and contains no advertising libraries;
- contains no analytics or usage tracking, neither our own nor third-party;
- uses no cookies, no advertising identifier (IDFA), and never presents an App Tracking Transparency prompt;
- builds no user profile and makes no automated decisions;
- contains no in-app purchases or subscriptions;
- makes no network requests at all — not at launch, not in the background, not to check for updates.
The game is fully playable in airplane mode. That is a simple way to verify the above for yourself.
If you write to us
The only situation in which we receive your data is when you email hello@rebusarium.com yourself, from the app or by any other means.
We then receive: your email address, the text of your message, and anything you choose to attach.
What the "Contact us" button fills in
The game's settings include a "Contact us" button. It opens your mail app with a pre-filled message so we do not have to ask for technical details separately. Exactly three things are filled in:
- the app name and version;
- the device type — the word
iPhoneoriPad, with no model and no serial number; - the iOS version.
The message is never sent automatically. You see all of it before sending and may add to, change or delete any part, including that footer. There are no hidden identifiers in it.
What we do with it
We read it and reply. We do not use your address for newsletters, do not add it to any list, do not pass it to third parties and do not sell it.
What Apple processes, not us
The app is distributed through the App Store, and Apple as the platform processes some data. We do not control this, and we would rather be explicit about it:
- Buying the app. Apple is the seller. Apple processes payment details; we never see or store them.
- Aggregate statistics. App Store Connect shows us summary figures: download counts, countries, iOS versions. These are aggregated, cannot identify an individual, and we cannot connect them to you.
- Crash reports. If you have allowed sharing analytics with developers in your iPhone settings, Apple may send us an anonymised crash report. You control this: Settings → Privacy & Security → Analytics & Improvements.
How Apple handles data is described in Apple's own privacy policy.
Legal bases for processing
For users in the European Economic Area and the United Kingdom (GDPR / UK GDPR):
- Support correspondence — legitimate interest (Art. 6(1)(f) GDPR): answering someone who contacted us. You get in touch on your own initiative and decide yourself how much to tell us.
- Data on your device — no processing in the GDPR sense takes place: the values never leave your device and are not accessible to us.
For users in Russia (Federal Law 152-FZ): personal data is processed only to the extent you send it in your message, and only to answer you.
Who your data is shared with
We do not sell personal data and do not share it for advertising. Not ever, with anyone.
The contents of your email technically pass through one service provider:
| Who | What they receive | Why |
|---|---|---|
VK / Mail.ru — mail hosting for the rebusarium.com domain |
the message content and the sender's address | mail delivery and storage |
There are no other recipients. The website you are reading loads no third-party services whatsoever: no fonts, no counters, no widgets — not one external resource on any page. You can confirm this in your browser's developer tools.
We may disclose data if the law requires it. No such request has ever been made.
International transfers
Mail hosting for the domain is provided by VK / Mail.ru, whose servers are located in Russia. If you write to us from the European Economic Area, your message reaches servers outside the EEA. There is no European Commission adequacy decision covering Russia.
We state this plainly so you can decide with your eyes open. If such a transfer is unacceptable to you, write from a mailbox in a jurisdiction you prefer, or say so in your first message and we will arrange another way to talk.
How long we keep data
| What | How long |
|---|---|
| Data on your device | as long as the app is installed; deleted with it |
| Support correspondence | up to 12 months after the last message, then deleted |
| Correspondence you ask us to delete sooner | deleted within 30 days of your request |
We keep correspondence for a limited time for one reason only: so that if you write again, you do not have to explain everything from scratch.
Your rights and how to use them
Because the app collects nothing, the rights below concern your correspondence with us.
If you are in the EEA or the UK (GDPR)
- Access — find out what data of yours we hold and get a copy;
- Rectification — have inaccurate data corrected;
- Erasure — have the correspondence deleted;
- Restriction — have processing paused;
- Portability — receive the data in a machine-readable form;
- Objection — object to processing based on legitimate interest;
- Complaint — lodge a complaint with the data protection authority in your country. That right does not depend on contacting us first.
If you are in California (CCPA / CPRA)
- we do not sell and do not share personal information as CCPA defines those terms, and have not done so in the preceding 12 months;
- you may ask what categories of data we hold and request deletion;
- we do not discriminate against you for exercising these rights — there is nothing in the app that could be withheld.
If you are in Russia (152-FZ)
- you may obtain information about the processing of your data, demand correction, blocking or destruction, and withdraw consent;
- you may complain to Roskomnadzor.
How to exercise them
Email hello@rebusarium.com from the address you wrote to us from and say what you want, in your own words — no legal phrasing needed. We answer within 30 days, usually sooner. We charge nothing for this.
If a request arrives from an address that appears nowhere in our correspondence, we will ask for details — not out of bureaucracy, but so we do not hand someone else's messages to a person who did not write them.
Children
The app collects no data from anyone, children included, and never asks for an age. It contains no advertising, no in-app purchases, no chat, no user-generated content and no outbound links — that is, no mechanism through which a child could disclose anything or spend money.
We knowingly collect no data from children under 13 (COPPA) or under 16 (GDPR). If you are a parent and believe your child emailed us personal details, write to us and we will delete them.
Security
Game data needs no protection from us: it sits in the app's sandbox on your device, protected by iOS itself, including device encryption.
Correspondence is kept in a mailbox only we can open, secured with two-factor authentication. This site is served over HTTPS only.
Absolute security does not exist, and promising it would be dishonest. We reduce the risk in the most reliable way available: data that was never collected cannot be lost. That is why the app is built without data collection — not because we have not got round to adding analytics.
Changes to this policy
If the app changes in a way that changes how data is handled, we will update this page before that version ships, not after.
For material changes we will raise the policy version and describe what changed — the previous text will not be quietly replaced. The effective date is shown at the top of this page.
| Version | Date | What changed |
|---|---|---|
| 1.0 | 4 September 2026 | first edition |
Contact
Questions about this policy, exercising your rights, anything else:
We reply within one business day. Data requests: no later than 30 days.