IconRush — Privacy Policy

Effective date: 9 August 2026 · Applies to: IconRush for iOS and Android, including TestFlight and all released versions beginning with 0.1.0

The effective date above is the date on which this text was finalised. It covers pre-release testing as well as public distribution.

1. Overview

IconRush is an offline quiz application. It collects no personal data. There is no account system, no sign-up, no advertising, no analytics, no crash-reporting service, and no tracking of any kind.

IconRush ships without the Android internet permission, has no backend, and the audited source contains no network path. All game data — questions answered, scores, streaks, and statistics — is stored on the user's device and is not transmitted.

The application requests one optional permission over its lifetime: notifications, and only if the user enables the Daily Challenge reminder. No permission is requested at installation or on first launch.

2. Information We Collect

None.

Because store disclosure forms ask the question in several different ways, the following table states the position for each category:

CategoryCollectedNotes
Personal identifiers (name, email address, telephone number, account ID)NoThere is no account system.
Builder handle or nicknameNo — stored on the device onlyEntered at first launch so that the application can display the handle on the user's own stat card. It is never transmitted.
Game statistics, scores, streaks, badgesNo — stored on the device onlyUsed solely to render the user's own screens. Never transmitted.
Location data of any precisionNoThe application never requests location access.
Contacts, calendar, photos, microphone, filesNoNever requested.
Images or media captured on the deviceNoThe application declares no camera permission and provides no image-capture feature.
Advertising identifiers (IDFA, GAID), device identifiersNoThe build contains no advertising SDK.
Usage analytics, telemetry, session dataNoThe build contains no analytics SDK.
Crash logs and diagnosticsNoNo crash-reporting service is integrated. Apple and Google may provide OS-level crash information to the user if the user has enabled sharing with those platforms; that is a platform process, and the developer receives no identified data from it.
PurchasesNoThe application is free and contains no purchases of any kind.

No data is sold, shared, or transferred to third parties, because no data leaves the device.

3. Data Storage and Retention

All data held by the application is a small local profile containing the user's chosen handle, preferences, dates, and numeric game statistics.

These two platform mechanisms are the only means by which statistics are restored, and both are operated by the operating system rather than by the developer. This version provides no additional restore path, and the resulting limitations are stated plainly:

The application provides no in-app export, no backup file, and no account. This is a consequence of operating without servers, and it is documented here rather than left for the user to discover.

Data is retained on the device for as long as the application remains installed, subject to the platform backup behaviour described above, or until the user deletes it.

4. Permissions

IconRush requests no permissions at installation or on first launch. Over the entire lifetime of the application, exactly one permission prompt can appear, and it is initiated by the user:

Notifications — requested only when the Daily Challenge reminder is enabled. The prompt appears at that setting and at no earlier point. The reminder is a single local notification scheduled by the device at a time the user chooses; it contains a fixed line of text and opens the Daily Challenge. It is not a push notification: there is no server, and nothing is delivered from a remote source. Disabling the reminder cancels any scheduled notification.

That is the complete list. The permission is optional, and declining it leaves the application fully playable. The application declares no camera permission: android.permission.CAMERA and the camera hardware feature are absent from the Android manifest, and the iOS Info.plist contains no NSCameraUsageDescription. Android's INTERNET permission is absent; iOS has no equivalent user-facing permission, and the application contains no network path. No further permission may be added without a published change to the application's specification, and the project's build gate fails if a camera or network declaration is introduced.

Technical note. Android declares the notification permission in its manifest, while iOS requests authorization through UNUserNotificationCenter and requires no notification usage string in Info.plist. On both platforms, no prompt is shown until the reminder is enabled. Android also declares RECEIVE_BOOT_COMPLETED so that a scheduled reminder survives a device restart; no exact-alarm permission is declared or requested.

5. Sharing

Share images are composed on the device as a PNG file and passed to the operating system's standard share sheet. Subsequent handling is governed by the application the user selects; the developer receives no callback, no link tracking, and no indication of whether a share took place. Share images contain no identifier, no referral code, and no tracking parameter.

The stat card is a screen within the application that displays the user's own figures: handle, headline statistics, badges, and streak. It is rendered on the device from data already stored on the device, and no part of it is uploaded.

6. Data Deletion

Settings → Delete my data erases everything the application stores. The deletion is complete: lifetime totals, every personal best, every badge, every theme unlock, the user's handle, and every preference. It removes both stored records from the platform store — the Keychain items on iOS and the statistics files on Android — and returns the application to first-run onboarding, so that a returning player is indistinguishable from a new installation.

The application requires two confirmations, the second requiring the user to type DELETE, because the action cannot be undone. There is no backup and no means of recovering the statistics in this version. Deletion also removes the records that the two platform restore paths described in section 3 would otherwise have restored, so a reinstallation finds nothing to recover. Data that has already left the application — an iCloud or Google backup taken before deletion, or an image already shared — is outside the application's control and cannot be affected by it.

Deletion is a means of removing data, not a means of resetting progress: the application provides no facility for returning a statistic to zero while continuing to play on the same profile.

7. Third-Party Services and SDKs

The application bundles no advertising, analytics, attribution, A/B testing, or crash-reporting service.

The open-source components it links against are the Flutter framework, an SVG renderer, an encoding library, and a local notification scheduler. All of these execute on the device, and none contacts a network on the developer's behalf.

A source-level no-network gate runs on every continuous-integration run and covers the Dart and tooling sources, the dependency list and lockfile, both platform manifests, and, as of this release, the native Swift and Kotlin sources. A full release-build runtime network audit has not been performed, and this document makes no claim that one has.

8. Children's Privacy

IconRush is a quiz concerning cloud infrastructure icons. It is not directed at children, and it is equally suitable if a child plays it. Because it collects no information from any user, it collects no information from children. There is no mechanism by which the developer could knowingly or unknowingly obtain a child's personal information through this application.

9. Your Rights

Rights of access, rectification, portability, erasure, and objection to processing presuppose that a party is processing the user's personal data. No such processing takes place. The developer holds no personal data about any user, so there is nothing to disclose, export, rectify, or erase, and no sale of data to opt out of; data has never been sold.

The complete copy of a user's data is the application on that user's device. It may be viewed on the Stats screen and erased permanently through Settings → Delete my data, which removes both stored records and returns the application to first-run state. This version provides no export format, so there is no data to port.

Where a legal basis under the GDPR would otherwise be required, none arises, because no processing of personal data takes place. Users who wish to raise a question may use the contact address in section 12.

10. International Users

The application processes no personal data and transfers no data across borders, because no data leaves the device on which the application is installed. There is no international transfer mechanism to describe, and no data-processing infrastructure in any jurisdiction.

11. Changes to This Policy

If the behaviour of the application changes — and any such change requires a published specification change first — this document is updated and its effective date is amended accordingly. Material changes, such as the addition of a permission, are also stated in the application's release notes. Previous versions of this document remain available in the project's public history.

12. Contact

Email: info@dev252.net (send mail)
Enquiries concerning privacy, this policy, or the verification of the statements made in it are welcome. The build is auditable: it declares no internet permission, links against no networking dependency, and bundles no analytics component.