Privacy policy
Last updated 4 October 2026
This policy explains what data Tessera collects, why, and what you can do about it. Plain language, no surprises.
Who we are
Tessera Puzzle is run by Cooper Banfield Ltd, a company registered in England and Wales (company number 17281235), registered office C/O Aardvark Accounting, 1 Cedar Office Park, Cobham Road, Wimborne, BH21 7SB, United Kingdom. Cooper Banfield Ltd is the data controller. For anything to do with your data, email support@tesserapuzzle.com.
What we collect
If you just play the puzzle
- A streak counter stored in your browser's localStorage. Never leaves your device.
- Anonymous play stats by default, used in aggregate (how many people played today, how far they got). No persistent ID, no IP address stored.
If you create an account
- Your email address. If you sign in with Apple or Google, the account ID they give us and the email they share (with Apple this can be a private relay address), and any name they pass on. Our sign-in provider stores that name with your account; the game never shows it. Other players only ever see your handle.
- The handle you choose. It is public: it appears on leaderboards and to members of any league you join. League names you create are shown to their members.
- Your puzzle results (moves, time, whether you revealed the answer) and the country your connection came from. We store a two-letter country code, looked up by our host from your IP address, not the address itself. It is used for country leaderboards.
- Your Chain progress: the levels you have played, the boards you were dealt, your moves and your stars.
- Your coins: the balance and a record of every coin earned and spent, plus hints and lucky boards held, and the themes you own, have tried and have switched on.
- Settings that follow you between devices, such as colour-blind mode.
- If you allow notifications on the mobile app, a device token so we can send them.
- Any score you report as suspicious, or name you report as offensive.
If you buy something (mobile app)
- Purchases are made through the App Store or Google Play. We never see your card or payment details.
- RevenueCat, our purchase provider, receives the purchase record from the store, linked to your account ID, and tells our server so we can add the coins or unlock the themes you bought. We keep a record of each purchase event: what was bought, when, and the store's transaction ID.
If you watch an ad for coins (mobile app)
- Ads only play when you choose to watch one. Google AdMob serves them.
- In the UK and EEA, Google's consent form asks you first. On iPhone, ads are only personalised if you allow tracking when asked; otherwise AdMob is told to show non-personalised ads.
- AdMob collects device and usage information to serve the ad, under Google's own policy. When you finish an ad, Google tells our server your account ID and a transaction ID so we can add the coins.
Where you found the app (mobile app)
- On iPhone, when the app opens it passes Apple's ad attribution token to RevenueCat, which asks Apple whether the install came from one of our Apple Search Ads campaigns. Apple provides this without tracking you across other apps, and it does not need your permission. It creates a RevenueCat record for this install, linked to your account ID if you are signed in. We use it only to see which of our ads work.
- On Android, Google Play tells the app the campaign details of the link or ad that led to the install, such as a Google ad or a link on our website. The app keeps them on your device and sends them with its analytics only if you opt in to full analytics. If the install came from a Google ad we note that, but never keep the ad click's ID.
If you opt in to full analytics
- A persistent anonymous identifier so we can see retention (did the same player return tomorrow?) and multi-day funnels.
- Your IP address, used to derive approximate country and then discarded by our analytics provider.
If you opt in to crash reports (mobile app)
- A report when the app crashes: the error and its technical trace, your device model, operating system version, app version, language and time zone.
- A random ID for your installation, so we can tell how many people a crash affects, and a note when a session starts and ends, so we can work out how many sessions end in a crash.
- We set the app not to send your IP address, your name, your email or any account details with a report.
If you play on the website
- The website gives each browser one free game; after that, Tessera is played in the app. To keep to that, your browser stores a note of which puzzle you played (in localStorage and a first-party cookie). It contains nothing about you. If you're signed in, your account records the date you used your web game, so the same applies on your other browsers.
- When you tap a button to get the app, our server counts the tap by day, store and campaign, so we know which of our links and ads work. We store no identifier with that count.
If you opt in to marketing
- Event signals shared with Meta (Facebook and Instagram), TikTok and X so we can measure whether ads on those platforms brought you here and to the app, such as visiting the site, finishing a puzzle, or tapping a store button. For Meta we also send these from our server (the Conversions API) with your IP address and browser details, only if you accepted marketing cookies.
- The campaign that brought you (for example "an ad on X"), kept in a first-party cookie for 30 days so a later visit is still credited to it. Also kept if you accepted analytics cookies.
If you sign up for the email list
- Your email address, until you unsubscribe.
- Your locale (English or Spanish) so we can send the right version of the email.
- Where on the site you signed up from. Used to understand which entry points work and to prove you opted in.
- The date and time you subscribed, recorded by our email provider.
Why we collect it
| Data | Why | Legal basis |
|---|---|---|
| Account, results, Chain progress, coins and themes | Run the game you signed up for, keep it in sync across devices | Contract |
| Public handle, leaderboards and leagues | Show rankings to other players | Contract |
| Country code on results | Country leaderboards | Legitimate interest |
| Purchase records | Deliver what you bought, handle refunds | Contract |
| Ads for coins | Pay you coins for an ad you chose to watch | Consent where required (Google's consent form) |
| IP address, briefly, for rate limits | Stop abuse and automated requests | Legitimate interest |
| Anonymous play stats | Understand how the game is used | Legitimate interest |
| Full analytics (opt-in) | Retention, cohort analysis | Consent |
| Crash reports (opt-in, mobile app) | Find and fix crashes | Consent |
| Marketing pixels (opt-in) | Measure ad effectiveness | Consent |
| Email signups | Send updates you asked for | Consent |
Who else sees it
- Vercel, our hosting provider. They process visit metadata as part of serving the site. Vercel privacy policy.
- Supabase, our database and sign-in provider. It stores your account and everything linked to it. Supabase privacy policy.
- Apple and Google, if you sign in with them, and as the App Store and Google Play for purchases.
- RevenueCat, our purchase provider. It handles purchases, and on iPhone it also checks whether you installed from one of our Apple Search Ads. RevenueCat is based in the United States. RevenueCat privacy policy.
- Google AdMob, used only if you choose to watch an ad for coins. Google privacy policy.
- Upstash, which holds the daily reminder mailing list and web notification sign-ups, and short-lived counters used for rate limits.
- PostHog (EU), our analytics provider. Data stays in the EU. PostHog privacy policy.
- Sentry (EU), our crash reporting provider. Used only if you opted in to crash reports in the mobile app. Reports are stored in the EU. Our server also reports its own errors to Sentry, which can include your account ID when an error concerns your account. Sentry privacy policy.
- Loops, our email provider. Used only if you signed up for the daily reminder list. Loops is based in the United States; your email is transferred there under standard contractual clauses. Loops privacy policy.
- Meta (Facebook and Instagram), TikTok and X, only if you accepted marketing cookies. These transfers go to the United States under standard contractual clauses.
How long we keep it
- Your account and everything linked to it (results, Chain progress, coins, themes, purchase records, league memberships): until you delete your account. Deleting is in the app's Settings. It takes effect after 48 hours, so a mistake can be undone, and then it is all removed from our database.
- Rate-limit counters: minutes to a day, then they expire.
- Anonymous analytics: 12 months rolling.
- Crash reports: 30 days, then deleted automatically.
- Email signups: until you unsubscribe.
- Marketing pixel data: handled by Meta (Facebook and Instagram), TikTok and X under their own retention policies.
Your rights
Under UK and EU data protection law, you can:
- Ask what data we hold about you.
- Ask us to correct or delete it.
- Object to processing, or withdraw consent at any time.
- Ask for your data in a portable format.
- Complain to a regulator (ICO in the UK; your local DPA in the EU).
To exercise any of these, email support@tesserapuzzle.com. We'll respond within 30 days.
Cookies and tracking
Full detail in our cookie policy. Change your choices any time via the "Cookie preferences" link in the footer.
Children
Tessera isn't aimed at under-13s and we don't knowingly collect data from them. If you believe a child has provided us data, email us and we'll delete it.
Changes
We'll update the date at the top when this changes. If the change is material, we'll surface a notice in-app and re-prompt your cookie choices.
Complaints
If we've got something wrong, please tell us first at support@tesserapuzzle.com. You can also complain to the UK Information Commissioner's Office at ico.org.uk.