Privacy
Privacy Policy
This policy explains how All In Pieces collects, uses, stores, shares, and protects personal information for the puzzle tracking app.
Last updated: July 10, 2026
What we collect
We collect account and profile details such as email address, public handle, display name, country, password-authentication records, email verification state, profile settings, and profile photos. We also collect puzzle records, attempt times, timer metadata, notes, uploaded photos, Want to Puzzle saves, friend connections, teams, participant snapshots, confirmations, notifications, public ranking settings, and optional Supporter subscription status. If affiliate links are enabled, we also collect aggregate affiliate click-intent counts by link, date, placement, and marketplace.
Contact and support records
If you use the contact form, we store the category, name, reply email, subject, message, optional page link, linked account if you are signed in, staff status, and staff notes needed to review and respond to the request. Do not send passwords, reset links, verification links, or private tokens through the form.
How we use information
We use information to run the app, manage accounts, verify email ownership, recover accounts, track puzzle progress, support friends and teams, show private history, display public or friends-only results according to your visibility choices, process support and privacy requests, protect the service, investigate abuse, and meet legal or operational obligations.
Public and private boundaries
Your account email is private account infrastructure, not public identity. Attempts start private unless you choose another visibility. Registered participants linked to a solve can open that attempt at any visibility. Accepted friends can open friends-only attempts, but other participant identities are shown to friends or the public only after those participants confirm and approve display. Public attempts, selected public evidence, public profile details, and leaderboard rows appear only where the app's visibility and consent rules allow them. Private notes, unselected photos, unpublished attempts, and contact submissions are not public.
Photos and uploads
Uploaded images are treated as untrusted input. The app validates image type and size, uses generated storage keys, and creates separate public derivatives where public display is supported. Public image versions are intended to be re-encoded without metadata such as EXIF/GPS data.
Sharing and service providers
We may share information with service providers that host, store, deliver, secure, or operate the app, including hosting, database, object storage, content delivery, transactional email, and payment processing providers. Public content you choose to publish is visible to other users and guests. We may also disclose information if required for safety, security, legal compliance, or to enforce the Terms of Use.
Supporter billing
If Supporter billing is enabled and you choose to subscribe, payment checkout and billing management are handled by Stripe. We store limited billing state such as Stripe customer and subscription identifiers, subscription status, plan interval, price identifier, renewal or cancellation metadata, and webhook processing markers. We do not store your card number.
Affiliate links
Some puzzle pages may include clearly labelled Amazon affiliate links. We count click intent only in aggregate, by link, date, placement, and marketplace. We do not store user ID, email address, IP address, or session ID in affiliate click-intent stats.
Clicking an Amazon link sends you to Amazon. Amazon handles its own prices, sellers, stock, checkout, shipping, returns, support, and data processing. Amazon API tools may be used by staff to help manage link candidates and review coverage.
Ads and consent
The site may include the Google AdSense loader and ads.txt for review or future advertising. If ads are enabled, Google and other advertising partners may use cookies or similar technologies to serve, measure, and improve ads, including ads based on prior visits where permitted.
Google CMP consent messaging is planned for regions where it is required before serving personalized ads, including the EEA, UK, and Switzerland. Where consent is required and not available, ads may be limited, non-personalized, or disabled.
Overseas disclosure
We may use cloud, infrastructure, email, payment, analytics, advertising, and security providers that process or store information in Australia, the United States, and other locations where those providers operate. By using the app, you understand that your information may be processed outside your country of residence where needed to provide, secure, support, and improve the service.
Access, correction, and deletion
You can update many profile and visibility settings in the app. Signed in members can request account deletion from Profile. You can also use the contact form to ask for access, correction, privacy help, account deletion, photo removal, or content review. Some records may need to be retained for security, audit, dispute, legal, backup, or data-integrity reasons.
Security and data breaches
We use privacy-by-default product rules, authentication, authorization, CSRF protections, upload validation, restricted operational access, and environment-based production configuration. No internet service can be guaranteed perfectly secure. If we identify a data breach that requires notification, we will assess it and notify affected people and regulators where required.
Children
All In Pieces is not directed to children under 13. Do not create an account or submit personal information if you are under 13. If you are under the age required in your location to consent to online services, use the app only with parent or guardian permission.
Contact
Use the contact form for privacy questions, data requests, complaints, account help, photo removal, public-content reports, security concerns, or other support requests.
Open contact form