Headshift: 2048 Snake Puzzle
Privacy Policy
This policy explains how Headshift handles your data. It describes the app's actual current behavior, not a future plan.
Developer / data controller
Goethe47 is the developer of Headshift and the controller responsible for selecting and configuring the advertising services used by the app. Unity Technologies processes advertising data under its own privacy terms and may act as a separate controller or service provider depending on the specific processing activity and applicable law. Contact: burteloffluther@gmail.com. Package: com.goethe47.headshift.
Product model
Headshift: 2048 Snake Puzzle ("Headshift") is a free, single-player puzzle game. It has no in-app purchases and no subscriptions. It is ad-supported, described below.
Account model
Headshift does not require an account, login, or account creation. There is no server-side player profile of any kind. Because there is no Headshift account, there is no account deletion URL — see "Deletion and local storage" below for what deletion actually means for this app.
Core gameplay and internet use
Core gameplay and local progress work without a game server. Headshift does not require an internet connection to be played. Internet access is used by Unity LevelPlay and Unity Ads to request, deliver, measure and secure advertisements (see below).
Data stored locally on your device
The following is stored in the app's own local storage on your device. Goethe47 does not operate a game server, so this local copy is not sent to us. If you switch on gameplay statistics (see the section below), a separate summary of finished runs is sent to Unity Analytics on our behalf — that summary is described there, and this local data is not uploaded as such:
- Best score and lifetime play statistics (games played, moves, merges, highest tile, longest snake), kept separately for each board size.
- Which achievements you've earned, and your board size, language, sound, vibration and tutorial preferences.
- The run you're in the middle of — the board, your score and move count — saved when you leave the app so it can be restored when you come back, and discarded once the run ends.
- Age privacy category: only whether you are under 18 or 18 and older. Headshift does not request or store a date of birth. The exact age you enter on the neutral local age slider exists only in temporary UI state, is cleared once your category is calculated, and is never saved, logged or sent. Every recheck starts with no age selected.
- Adult advertising privacy choice (personalized or non-personalized) and explicit US-state sale/share choice.
- A pending-change marker, set when your privacy choice changes while ads are already running, so the app knows to apply it the next time you open it.
- Ad-frequency bookkeeping, used only to avoid showing ads too often.
Advertising services actually included
Headshift shows ads through exactly two components, both confirmed present in the app's build: Unity LevelPlay (Unity's mediation SDK) running the Unity Ads network via its Unity Ads adapter. No other ad network's SDK or adapter is included in the app. Ads appear in three forms: a banner during play, an occasional full-screen ad between runs, and a rewarded video you choose to watch — offered once per run after a loss, in exchange for continuing that run. The rewarded one is never started on its own: it plays only if you tap the button offering it, and the continue is granted only if the ad is actually watched through. Declining costs nothing and the run simply ends as it otherwise would. Unity's dashboard lets specific ad placements/instances change without an app update, but that is not the same as adding a new network — a genuinely new advertising network requires adding its adapter to the build, which would mean a new app version and an update to this policy and to Play Console's Data safety section before it goes out.
Gameplay statistics (optional, off by default)
Separately from advertising, Headshift can send statistics about how the game is played, using Unity Analytics, part of Unity Gaming Services. These are not called anonymous here on purpose: each event carries an installation identifier generated on your device, which makes the data pseudonymous rather than anonymous, and it stays personal data under laws such as the GDPR. Unity processes this on Goethe47’s behalf as a service provider; it is not used to choose which ads you see, and it is not combined with advertising data.
It is switched off unless you switch it on. The control is “Send gameplay statistics to help improve the game”. It is offered once on the second screen of the first launch, and is available afterwards at any time in Settings → Ads & Privacy. It is not offered at all to users in the under-18 category: for them the switch is not shown and no gameplay statistics are collected under any circumstances.
While it is on, a finished run may send: an installation identifier and a random run identifier, both generated on your device, the board size, how long the run lasted, the number of moves, the score, the highest tile reached, how the run ended (which losing condition, or that it was restarted before finishing), whether a rewarded ad was used to continue it, and how many runs have been started on this device. It also records which ad format was shown, and whether it failed to load or to display.
Once per installation it additionally records which steps of the tutorial you reached, and whether you made a first move, a first merge and a first head separation. This is used to find where new players stop, and it is sent at most once each — reopening the tutorial from Settings does not send it again.
Every one of these events also carries, automatically and without Headshift choosing it: the app version, the platform (Android), a two-letter country code determined by Unity, and the installation identifier mentioned above. Sessions and first installs are recorded by the Unity SDK on its own, without Headshift sending anything.
None of it contains a name, email address, contact, photo, file, message, or a location more precise than that country code, and there is no Headshift account for any of it to be attached to.
Switching it off stops collection immediately and also asks Unity to delete what that device already sent. Uninstalling the app stops collection but does not by itself delete what was already sent — use the switch first, or contact us at the address above.
Crash and diagnostic data
Headshift is built with Unity, and Unity’s own engine-level diagnostics are enabled for this build. Separately from anything described above, Unity may receive crash reports, error logs and technical information about the app and the device it is running on — for example the app version, the operating system version and the device model — used to find and fix faults.
This is not covered by the gameplay-statistics switch. That switch controls what Headshift itself sends about how you play. Engine diagnostics belong to the engine, are collected regardless of it, and cannot be turned off from inside the game. They contain no name, email, contact, photo, file, message or location data, and are not used to select advertising.
Whether any given build actually transmits this data is determined by Unity’s own implementation rather than by Headshift. It is disclosed here on the assumption that it does, because understating what leaves your device would be the worse error.
Google Play Data Safety declaration
These categories come from Unity's currently published Data Safety guidance for the Unity Ads SDK, plus the optional gameplay statistics described above. Headshift's Play Console declaration is maintained to match the SDK versions and dashboard configuration included in the current release:
- Approximate location — purposes: Advertising or marketing; Analytics; App functionality; Fraud prevention, security, and compliance.
- Personal identifiers / User IDs — purpose: App functionality. These are Unity SDK identifiers, not a Headshift account or login.
- Purchase history — purposes: Advertising or marketing; Analytics. Declared Yes because Unity's official Unity Ads disclosure says Yes; Headshift having no purchases does not override the embedded SDK's declaration, and no written or technical Unity confirmation for this exact build establishes otherwise.
- App interactions — from the ad SDK, page views and taps during the ad experience. In addition, only while you have gameplay statistics switched on, how runs are played, as itemised in “Gameplay statistics” above. Purposes: Advertising or marketing; Analytics; Fraud prevention, security, and compliance.
- App diagnostics — from the ad SDK, and from Unity’s engine-level diagnostics as described in “Crash and diagnostic data” above. Purposes: App functionality; Analytics.
- Device or other identifiers — purposes: Advertising or marketing; Analytics; App functionality; Fraud prevention, security, and compliance.
Other app activity requires a Unity dashboard check: Unity says app usage time is collected only when Acquire Optimization is enabled in the Monetization dashboard. Its final Yes/No value must match that live dashboard setting before the Play Console declaration is submitted. If enabled, it is collected, shared, not ephemeral, required, for Advertising or marketing; Analytics; Fraud prevention, security, and compliance.
Headshift's build also declares Android Privacy Sandbox Topics and Attribution permissions. Not applicable to Headshift according to Unity Ads' table: precise location, contacts, messages, photos, files, and calendar. Unity's published table covers only the Unity Ads SDK; Goethe47 is responsible for any other SDK included in a future build and for the final Play Console declaration as a whole.
Purposes of processing
Ad delivery and measurement; ad personalization (only if you choose personalized ads); frequency capping (so interstitial ads aren't shown too often); fraud prevention and security for the advertising system. Separately, and only while you have switched it on, understanding how the game is played so it can be improved — which runs end how, and how long they last.
Legal bases (where applicable)
Where consent is legally required, Headshift relies on your consent, given through the age and advertising-choice screens described below, before enabling personalized advertising. Limited processing needed for non-personalized ad delivery, measurement, security and fraud prevention may be based on legitimate interests or another lawful basis available to Unity, subject to applicable law — this is not a claim that legitimate interests alone satisfies every requirement of the EU/UK ePrivacy rules on accessing information on a device. In jurisdictions where consent is required for that processing or for that device access, consent is obtained before it occurs. This policy does not claim final legal compliance for every jurisdiction; jurisdiction-specific legal review and current Unity dashboard/SDK configuration remain necessary.
Advertising and privacy choices
Before Headshift starts the advertising SDK or requests an advertisement, a neutral local age slider lets you select your current age and assigns you to one of two product privacy categories. No value is selected in advance. The exact age you enter exists only until the category is calculated and is not saved, logged or sent. If you are under 18, you receive limited non-personalized advertising: your advertising ID is not used, only ads suitable for a younger audience are requested, Unity Ads is instructed not to build a behavioral profile for you, and the sale/share restriction is turned on automatically. This is a product setting, not a claim that every user under 18 is legally a child under COPPA.
If you confirm you are 18 or older, you choose equally between personalized and non-personalized ads. Adult non-personalized ads are not selected from your interests, but limited device and ad-interaction data may still be used for delivery, measurement, frequency limits, analytics, security and fraud prevention. Adults also have an independent sale/share control. Choices and the age group can be reviewed in Settings → Ads & Privacy; each age recheck begins with an empty selection.
If your age group, personalization or sale/share setting changes after advertising has already started, Headshift stops showing ads under the old setting and clears what was already loaded. Advertising privacy changes are applied the next time you close and reopen the app, using your newly saved choice.
US-state privacy choices
Adult users can enable or disable the "Do not sell or share my personal data" checkbox in Settings → Ads & Privacy. A missing saved value is not treated as an automatic opt-in; false is sent only after you explicitly leave the checkbox unchecked. For users under 18, the restriction is enabled automatically and cannot be disabled. Headshift does not detect the user's country or state.
Data recipients and advertising partners
Unity Technologies, via the LevelPlay mediation platform and the Unity Ads network specifically (the only network integrated in this build), and — only if you switch gameplay statistics on — via Unity Analytics, acting there as a service provider processing on Goethe47's behalf rather than for its own purposes. See Unity's Player and App User Privacy Policy for how Unity itself handles this data. If you want to exercise a right (access, deletion, opt-out) over data Unity's systems hold, you can contact Unity directly using the details in their policy, or contact Goethe47 at the email below and we'll help route the request — Goethe47 chose and configured the advertising SDKs in this app and doesn't disclaim responsibility for that choice just because we don't run our own server.
International transfers
Unity's advertising infrastructure may process data outside your own country. See Unity's own privacy policy (linked above) for the safeguards Unity applies to such transfers; Goethe47 does not operate the infrastructure involved and cannot independently describe it beyond what Unity discloses.
Retention
Data processed by Unity/Unity Ads is retained per Unity's own policy, not a schedule Goethe47 sets. Data stored locally on your device (see above) is retained until you clear the app's storage, uninstall the app, or change the relevant setting yourself.
Deletion and local storage
Headshift disables Android backup with android:allowBackup="false" and explicit extraction rules. For Android 12 and later, android:dataExtractionRules excludes the root, files, databases, shared preferences, and external files from both cloud backup and device transfer. For Android 11 and earlier, android:fullBackupContent excludes the same domains. The explicit Android 12 rules matter because some device manufacturers can allow device-to-device transfer despite allowBackup="false". Uninstalling the app or clearing its storage removes its local data; because Headshift has no account or server, there is no separate account-deletion step. For data already processed by Unity/Unity Ads, use the contact/rights information above.
Android permissions
Headshift's own game code requests exactly one permission — vibration, used for the short buzz on merges and at the end of a run, which can be switched off in Settings. Vibration carries no data and reads nothing from the device. Beyond that the game's own code does not use camera, microphone, contacts, files, or device-location permissions. The app's advertising libraries add internet access, network-state, advertising-identifier, and Android Privacy Sandbox (Topics/Attribution) permissions to the final installed app, plus a small number of supporting Android system-service permissions (e.g. for scheduling background work) that these libraries need to function — these support the advertising SDK's own operation and are not, by themselves, evidence of an additional personal-data category beyond what's listed above.
Age audience and children's privacy
Headshift's selected Google Play audience is 13–15, 16–17 and 18+; groups under 13 and Designed for Families are not selected. Headshift uses a conservative age-18 threshold for advertising personalization. Users identified as under 18 receive the restricted plan described above and cannot enable personalized ads or disable the automatic sale/share restriction. Adults may choose either ad mode. A Recheck age group control is available. Every category change — including your first selection confirming you are an adult — clears any earlier or legacy adult personalization choice, so an adult must make a fresh selection. This architecture is not presented as a final legal solution for every country.
Your rights
Depending on your location, you may have rights to access, correct, delete, or object to processing of your data, and (in the US) to opt out of sale/sharing/targeted advertising or limit use of sensitive data. Where processing is based on your consent, you may withdraw that consent at any time through Settings → Ads & Privacy; withdrawal does not affect the lawfulness of processing that took place before withdrawal. Depending on your location, you may also have the right to restrict processing, obtain a copy of your data in a portable format, and lodge a complaint with your local data protection authority. For data Goethe47 holds directly, that's limited to what's on your own device (see above) — contact us and we'll help. For data Unity/Unity Ads processes, see the contact routing above.
Security
Locally stored data is protected by standard Android app sandboxing. No method of electronic storage or transmission is 100% secure, and this applies to our advertising partners' systems as well as anyone else's.
Changes to this policy
We may update this policy as the app or its advertising configuration changes — including before adding any new advertising network. Material changes will be reflected here with an updated "Last updated" date.
Contact
Questions about this policy or your data: burteloffluther@gmail.com