Last updated: September 14, 2026
This Privacy Policy explains how we collect, use, and protect information when you use Arrow Solitaire: Crosswise ("the game", "the app"), published by DDInsights ("we", "our", "us") on Android and iOS. Android package: org.ddinsights.arrowclash. iOS bundle: org.ddinsights.arrowclash.ios.
The game is fully playable without an account: we ask for no sign-up and no personal details. Progress stays on your device. The game is also playable on the web — directly in a browser or as a Telegram Mini App — where analytics runs only with your consent, and never inside Telegram (see section 1.8). We collect limited app, device, usage and diagnostic data for analytics, crash fixing, campaign measurement and advertising. The Android app may show Google AdMob ads, some of them supplied by Unity Ads through AdMob mediation: a banner on the home screen or level result, an interstitial in the natural break after a successful level completion, and voluntary videos for a coin in the in-game shop or for skipping a Smart level. No other ad format is used. Google ads may be personalized where your consent and privacy choices permit it, including in Europe. Requests stay non-personalized when your region is unknown or the current privacy check fails. Unity Ads has separate restrictions described in section 1.4. The Android app also offers optional one-time in-app purchases — coin packs and a "No Ads" purchase — processed entirely by Google Play (see section 1.6). Advertising remains disabled in the iOS app, which does not use IDFA and does not track you across other companies' apps or websites.
Optional shared-level challenges: when you choose to share a completed level from the app, our server receives its starting layout and the Firebase Analytics app instance identifier. It encrypts and authenticates these in the challenge link. A recipient receives the playable layout, not your decrypted identifier. The isolated challenge page does not load Google tags or create a browser analytics identifier, and it does not modify ordinary web-game saves. On a successful challenge completion, our server sends shared_level_complete to Firebase Analytics under the original sender's app instance to measure the use of shared levels. This is the exception to the ordinary web-game analytics described in section 1.8. Re-sharing preserves the original attribution; no in-game reward is granted. DigitalOcean hosts this endpoint and processes the request data to provide this service.
Our service providers may create identifiers tied to this app installation rather than to your name:
On Android, we also send the AppsFlyer installation identifier to Firebase Analytics to associate records for the same app installation across our analytics reports. This does not require an account or your name, email address or phone number.
We do not request access to GPS or precise device location, and the app asks for no location permission. Analytics and attribution providers may derive an approximate location (country or region level) from your IP address so we can understand where the game is played and apply local rules. This coarse location is not used to track your movements.
On Android, before initializing Google Mobile Ads, the app asks Google's User Messaging Platform (UMP) for the current privacy requirements and presents a consent or privacy message where required. An ad request is made only when UMP reports that ads may be requested. If that check cannot be completed and no valid decision from an earlier session is available, advertising stays off. The iOS app exits the advertising path before UMP and does not initialize Google Mobile Ads.
Three ad formats are enabled on Android. An anchored adaptive banner may appear in a separate native area below the home screen or a sufficiently tall level-result screen. It does not cover the game or appear during active play. An ordinary interstitial may open automatically in a natural break after a successful level completion; it grants no reward. Levels 1 and 2 of each mode are always free of these full-screen breaks. A new app session requires 30 seconds of foreground time before an automatic break becomes eligible. With no previous fullscreen checkpoint, the chance starts at 60% after this warm-up and rises to 90% over the next 150 seconds. After a fullscreen ad, automatic breaks are blocked for 150 seconds; the chance then rises from 60% to 90% at 300 seconds. This checkpoint survives an app restart. After an automatic ad opens, the next otherwise eligible completed level is always kept free of an automatic full-screen ad, including after an app restart. A conservative checkpoint before native handoff protects against crashes and uncertain SDK callbacks. The preloaded interstitial is considered after a one-second result pause; if it is not ready or the player leaves the result, there is no delayed show or alternative ad. Voluntary videos also refresh the automatic cooldown. No app-open ads are used.
Rewarded ads are optional and play only after a tap. There are two voluntary rewarded offers: "+1 coin for a video" in the Exchange Shop, capped at five a day, and "Skip with a video" on the Smart failure screen, available from the third attempt at that level when an ad is ready. The skip offer does not grant a coin and is not subject to the shop's daily limit. Closing a video without earning its reward grants neither the coin nor the level skip. The "No Ads" purchase removes the automatic interstitial and banner, while leaving both voluntary offers available.
Ad personalization depends on your region and privacy choices. In the European Economic Area (EEA), United Kingdom and Switzerland, Google may show personalized ads when you consent to personalized advertising and the required use of data by the relevant providers. Google's SDK reads the choices saved by the UMP privacy message and uses them to determine which ads it may serve. The app does not block personalization solely because you are in Europe. If your region is unknown or cannot be refreshed — for example, when that check fails and only a decision from an earlier session is available — requests stay non-personalized. When your choices or this regional signal change, ads that were already loaded are discarded and requested again. Where UMP requires an ongoing privacy-options entry point, the Android home screen shows Ad privacy at the bottom so you can reopen and change those choices. In US states with consumer privacy laws, Google's privacy message and Ad privacy let you opt out of the sale or sharing of your personal information for targeted advertising where Google offers these choices, and Google's ads respect them. Depending on your location and choices, ads may be personalized, non-personalized or limited, or no ad may be shown.
Some of these ads may come from Unity Ads (Unity Technologies), which bids for the app's ad requests through Google AdMob mediation and is initialized only after the UMP check permits ad requests. Before any ad starts, the app tells Unity Ads that it has no consent to personalized advertising in the EEA, United Kingdom and Switzerland and under the consumer privacy laws covered by Unity's privacy settings, including US state laws, Brazil's LGPD and Quebec's Law 25. Unity Ads therefore serves non-personalized ads in those places, whatever you choose in Google's messages, and may personalize ads elsewhere. Unity may show its own data privacy icon during its ads, where Unity's privacy controls are available.
Earlier app versions may remain installed. Versions up to and including 1.18.0 also offered a video for an extra life on defeat. That offer and the earlier banner were removed in 1.19.0. Some versions before 1.28.0 used a rewarded interstitial with an explicit Watch/Skip introduction and a coin reward, instead of the current ordinary interstitial. The banner returns in 1.28.0 on Home and level results only. These format changes do not introduce new categories of advertising data. Versions before 1.29.0 requested every ad as non-personalized and did not use Unity Ads.
The full game state is stored locally on your device and is not uploaded by the app to a cloud-save service. Deleting the app removes it from that device; Android's system backup or device-transfer feature may restore non-sensitive local game state.
The Android app offers optional one-time in-app purchases: coin packs for the in-game Exchange Shop and a single "No Ads" purchase that permanently removes the automatic interstitial and banner. Both voluntary rewarded offers remain available to "No Ads" owners (section 1.4): a video for a shop coin or a Smart-level skip. Neither rewarded video plays without a tap. All payments are processed by Google Play under Google's own terms and privacy policy; we never receive your payment card, bank or billing details. After a successful payment the app receives a purchase confirmation from Google Play — the product identifier, purchase state, Play order identifier and a purchase token — which it uses to credit the item exactly once and, for "No Ads", to restore the purchase when you reinstall the app or switch devices under the same Google account. The purchase token stays in the app's local storage for delivery deduplication, is excluded from Android cloud backup and device transfer, and is never sent as a custom analytics parameter. Firebase Analytics may automatically record the Google Play purchase, and the app sends AppsFlyer a standard purchase event containing the product identifier, localized amount and currency, quantity and Play order identifier. Those purchase-history fields are used for purchase analytics and campaign measurement; they contain no payment method or billing details. Purchase state (coins, boosters, the "No Ads" flag) is stored locally on your device. Purchases are optional and the whole game can be played without paying. The iOS app and the web version currently offer no in-app purchases.
Arrow Solitaire: Crosswise can also be played at crosswisearrows.com/play in a regular browser or inside Telegram, where our bot opens the same page as a Mini App. The web version keeps progress (levels, coins, settings) on your device only: in the browser's local storage, and inside Telegram — in Telegram's per-bot device storage (DeviceStorage), so progress survives Telegram restarts. It is not uploaded to us.
Analytics on crosswisearrows.com is opt-in sitewide. In a regular browser the site asks first — on the landing page and the game page alike — and until you choose "Allow analytics" no request is sent to Google. Inside Telegram analytics never loads at all — the Mini App runs without any Google tags, so your Telegram launch data stays out of reach of analytics scripts. If you agree in a browser, Google Tag Manager and Google Analytics collect aggregate site statistics — page views, clicks on outbound links (such as the store buttons) and similar interaction events, browser and device type, and IP-derived approximate location; the page address may also include campaign parameters of the link you followed (such as utm). To do this, Google Analytics sets first-party cookies on crosswisearrows.com (names starting with _ga, and _gcl for campaign linking) that hold a pseudonymous browser client ID. The web version sends no gameplay events to analytics. Your choice is stored in your browser's local storage on your device. The button below withdraws consent for future visits and also deletes these analytics cookies from your browser:
Inside Telegram the page loads Telegram's Web App SDK to integrate with the Telegram app. The game does not read, use or transmit your Telegram profile data: launch parameters (such as tgWebAppData) are kept opaquely in session storage of the current WebView session only — so that a reload keeps working — and are removed from the page address before any optional analytics could observe them. The bot receives the messages you send it, replies to them, and stores no profile data.
When the energy system is enabled on Android, the app makes a short HTTPS request to crosswisearrows.com/api/time after the game loads and whenever it returns to the foreground. The JSON body contains only the current server time and helps prevent large changes to the device clock from granting unlimited energy. Starting a level never waits for this request: if it fails or the device is offline, the game continues with its local-clock fallback.
The request sends no account or player identifier, Advertising ID, energy balance, progress, saved game or gameplay event. As with any HTTPS request, the infrastructure handling it receives ordinary network metadata such as the IP address, user agent, request time and technical routing information. DigitalOcean App Platform hosts the site and stateless endpoint and uses Cloudflare as a subprocessor for CDN, load-balancing and platform-security services. Through that infrastructure, Cloudflare may set the first-party, HttpOnly __cf_bm cookie used for bot protection; it expires after 30 minutes of inactivity, is specific to this site and is not an identifier from the game. This provider relationship is described in section 3.
We do not sell data for money. Some US state laws treat letting advertising partners use data for personalized ads as a "sale" or "sharing" of personal information; section 4 explains how to opt out. We share the data above with the service providers listed below, each acting under its own privacy policy:
| Provider | Purpose | Data involved | Policy |
|---|---|---|---|
| Google AdMob (Google Ireland Ltd. / Google LLC) | Banner, interstitial and rewarded advertising in the Android app, including AdMob mediation; personalized only where section 1.4 permits | On Android, after the UMP privacy check permits ad requests: IP-derived approximate location, app and device information, device or advertising identifiers where available, ad views and interactions, diagnostics and data used for delivery, measurement, frequency capping and fraud prevention, and for ad personalization where section 1.4 permits it. Mobile Ads measurement is delayed until this consent-gated initialization. The iOS app does not initialize Google Mobile Ads. Rewarded ads are requested on Android for the two optional offers described in section 1.4 — a shop coin or a Smart-level skip — and play only after you tap the offer; ordinary interstitials are requested for successful level-completion breaks without an ad reward, and anchored banners for Home and level-result screens. No app-open ads are requested on either platform, and no ad format is requested on iOS. | policies.google.com/privacy |
| Unity Ads (Unity Technologies) | Additional bidding for Android banner, interstitial and rewarded ads through Google AdMob mediation | On Android, only after the UMP privacy check permits ad requests: IP-derived approximate location, app information and performance diagnostics, device information, the resettable Advertising ID and identifiers Unity assigns to the installation, ad views and taps within its ads, purchase history as described in Unity's Google Play data disclosure, and data used for bidding, delivery, measurement, frequency capping and fraud prevention. The app tells Unity Ads that it has no consent to personalized advertising in the EEA, United Kingdom and Switzerland and under US state, Brazilian and Quebec privacy laws; elsewhere Unity Ads may personalize ads. No Unity ad is requested on iOS. | unity.com/legal/game-player-and-app-user-privacy-policy |
| Google Play Billing (Google LLC) | Processing optional in-app purchases in the Android app | Google Play processes the payment under your Google account and Google's own privacy policy. The app receives the product identifier, purchase state, localized amount and currency, Play order identifier and a purchase token. The token is kept locally to deliver the item once and restore the one-time "No Ads" purchase; it is excluded from Android cloud backup and device transfer and is not sent as a custom analytics parameter. We never see your payment method or billing details. | policies.google.com/privacy |
| Google Firebase (Analytics, Crashlytics) | Usage analytics and crash reporting | Firebase and Crashlytics installation identifiers, device info, event and crash data, IP-derived approximate location. On Android, this also includes the AppsFlyer installation identifier for linking analytics records. Firebase Analytics may automatically record Google Play purchase history including the product identifier, localized amount and currency, quantity and subscription-related fields where applicable. iOS Analytics is built without advertising-ID support. | firebase.google.com/support/privacy |
| Google Tag Manager and Google Analytics (Google Ireland Ltd. / Google LLC) | Aggregate web statistics on crosswisearrows.com, including the browser version of the game | Web only, and only after your explicit consent on the site; nothing loads until you agree. Never loaded inside Telegram. Page views, clicks on outbound links, UTM campaign parameters, browser and device info, IP-derived approximate location; first-party _ga/_gcl cookies with a pseudonymous browser client ID. No gameplay events are sent from the web version. | policies.google.com/privacy |
| AppsFlyer Ltd. | Install attribution and campaign measurement | Installation, app, campaign and product-interaction data, device info and IP-derived approximate location. On Android, a completed Google Play purchase sends the product identifier, localized amount and currency, quantity and Play order identifier for purchase analytics and campaign measurement. Restoring an already acknowledged "No Ads" entitlement does not create a revenue event; an unfinished coin-pack or "No Ads" transaction recovered after an app interruption may send its original purchase event. Android may provide its resettable Advertising ID. iOS uses AppsFlyer Strict: no IDFA and no cross-app tracking. | appsflyer.com/legal/services-privacy-policy |
| DigitalOcean, LLC — App Platform (using Cloudflare as a subprocessor) | Hosting crosswisearrows.com and the stateless Android trusted-time endpoint; CDN, load-balancing and platform-security services are supplied through DigitalOcean App Platform's Cloudflare infrastructure | Ordinary request and infrastructure metadata such as IP address, user agent, request time, routing and security diagnostics. Cloudflare may set the first-party __cf_bm cookie used for bot protection, as described in section 1.9; it expires after 30 minutes of inactivity and does not contain a game account or player identifier. The endpoint receives no game state or app identifier, and its JSON body contains only the current server time. |
DigitalOcean privacy policy; DigitalOcean subprocessor list; Cloudflare privacy policy |
These providers may store and process data outside your country, including in the United States, under the safeguards described in their own policies.
After the UMP privacy flow described in section 1.4, Android may display AdMob banners on Home or level results and preloaded interstitials at successful level-completion breaks under the timing rule there, including ads supplied by Unity Ads through AdMob mediation. Whether they may be personalized follows the regional rules in that section. Neither format appears during a move. If an interstitial is unavailable, the result remains usable without waiting for a later show. The "No Ads" purchase removes both formats. Rewarded videos remain optional for all players, including "No Ads" owners: they play only when you tap "+1 coin for a video" in the Exchange Shop or "Skip with a video" on the Smart failure screen. The shop offer is limited to five rewards a day; the skip offer is available from the third attempt at that level, as described in section 1.4. No app-open format is enabled. Advertising remains disabled on iOS. Campaign attribution remains active on both platforms so we can measure which promotion led to an install.
The game is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has used the app and you would like the associated data removed, write to us at the address below and we will pass the request to the providers listed in section 3.
Analytics, crash, attribution, advertising and infrastructure data are retained by our providers for their standard or configured retention periods (Firebase Analytics: up to 14 months for event data; Crashlytics: up to 90 days for crash reports; AppsFlyer, Google AdMob, Unity Ads and DigitalOcean App Platform, including its Cloudflare subprocessor: as set out in their policies or our service configuration; Google Analytics data from the website: retained according to our configured Google Analytics data-retention setting and Google's policy). The Cloudflare __cf_bm cookie expires after 30 minutes of inactivity. Data stored on your device stays there until you delete the app.
Depending on where you live, you may have the right to access, correct, delete or export data associated with your app installation, to object to processing, and to withdraw consent. Contact us to exercise these rights. If possible, include the platform and an installation identifier available to you; without an identifier, we or a provider may be unable to locate an anonymous installation. Deleting the app removes locally stored progress from either platform.
We rely on the transport encryption and access controls of the providers above. The app operates no game account, cloud save or gameplay server and stores no third-party credentials; its only app-owned network utility is the stateless trusted-time endpoint described in section 1.9, which receives no game state and returns only the current time. No method of transmission over the internet is entirely secure.
We may update this Privacy Policy. Changes are published on this page with a new "Last updated" date; material changes will also be noted in the app's release notes on Google Play or the Apple App Store.
Email: support [at] ddinsights.org
DDInsights — publisher of Arrow Solitaire: Crosswise on Google Play and the Apple App Store.