Filigree · Aviro Studio · Effective August 27, 2026
The short version. You do not create an account, and we never ask for your real name, email address, phone number, or location. What we do record is the game itself: the words you found in a round, what they scored, a random identifier the app generates, and a display name if you choose one. We keep the words because the server rescores every round rather than trusting your phone — that is what stops invented scores reaching the leaderboard. We also receive a crash report when the app fails.
What we do not do is advertise, sell anything, use an advertising identifier, or profile you. Nothing here follows you into another app.
This policy explains what the Filigree mobile game collects, why, and what you can do about it. It applies to the Filigree Android app and to the game server the app communicates with.
In this policy, “we”, “us” and
“our” mean Aviro Studio, the developer of Filigree and the party
responsible for the data described here. “You” and
“your” mean the person using the app — anyone who installs or
plays Filigree, whether or not they have chosen a display name. “The
app” means the Filigree Android application, and “our
server” means the service it connects to at
api.filigreeapp.com.
Filigree has no sign-up. The first time the app contacts the server, it generates a random device key and stores it on your device. This key is a random value created by the app itself. It is not your Android ID, advertising ID, IMEI, phone number, or any hardware identifier, and it cannot be used to recognize you in any other app.
The app sends that key to our server, which stores only a hash of it — not the key itself — to recognize your device on future visits. Alongside it we store:
When you submit a round, we store the round identifier, your player ID and display name, your score, and how many words you found. This is what produces the leaderboard.
Your display name is public. It is shown to every other player on the leaderboard for rounds you take part in. Please do not use your real name, your email address, or anything else you would not want strangers to see. You can change it at any time in the app.
We use Firebase Crashlytics (a Google service) so we can find and fix crashes. When the app crashes it sends Google a crash report containing the technical stack trace, your device model, operating system version, app version, and a Crashlytics installation identifier. We use this only to diagnose faults. It is not linked to your leaderboard record.
We use Firebase App Check with Play Integrity to confirm that requests come from a genuine, unmodified copy of Filigree rather than a script. This sends Google a token about the app and device. It prevents fake scores; it does not identify you personally.
Our server briefly sees your IP address when your device connects, and uses it in memory to rate-limit abusive traffic. We do not store IP addresses in our database or link them to your player record. Our hosting provider may retain standard server logs for its own operational and security purposes.
Some things never leave your phone: your access token, your saved hints, daily-challenge progress and streaks, and your app settings. These are removed when you clear the app’s data or uninstall it.
Filigree requests no Android permission that grants access to personal data. There is no
location, camera, microphone, contacts, calendar, or storage access to grant, because the app
never asks for any. What it does declare is INTERNET and
ACCESS_NETWORK_STATE — the ability to reach our server, and to tell whether
the device is online — along with one internal permission Android generates for the app to
talk to itself.
| Data | Purpose |
|---|---|
| Hashed device key, player ID | Recognizing your device so your scores stay yours, without an account |
| Display name | Labeling your entry on the leaderboard |
| Scores and word counts | Running the game and ranking rounds |
| Crash reports | Finding and fixing bugs |
| Attestation tokens | Preventing cheating and fake submissions |
| IP address (in memory) | Rate-limiting abuse |
Where a legal basis is required, we rely on our legitimate interest in operating a functioning, fair game, and on performing the service you asked for when you chose to play.
Deletion runs automatically on a daily schedule. We may adjust these windows for operational reasons; this page will always describe the current practice.
We do not sell your data, and we do not share it for advertising. We use two service providers:
We may disclose information if legally required to do so.
Our game server and database are hosted in the United States. Google processes Firebase data in accordance with its own policies, which may involve servers in several countries. By using Filigree you understand that this data is processed outside your own country.
Because Filigree holds no name or email, the most direct control is in your hands:
Depending on where you live, you may also have rights to access, correct, delete, or object to our processing of your data, including under the EU/UK GDPR and India’s Digital Personal Data Protection Act, 2023. Write to us at the address below and we will help. Because we hold no contact details, we may need you to supply your in-app player ID so we can locate the right record.
Filigree is intended for a general audience and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information — most likely by putting it in a display name — contact us and we will remove it.
Traffic between the app and our server is encrypted in transit. Device keys are stored only as hashes. Scores are verified server-side rather than trusted from the device, and submissions are attested and rate-limited. No system is perfectly secure, but we keep the amount of data we hold deliberately small.
If we change what we collect, we will update this page and revise the effective date above. Significant changes will be noted in the app’s release notes.
Questions, requests, or anything about this policy:
[email protected]