Privacy Policy for Scrabbdict
Last updated: October 1, 2026
Controller and contact
This privacy policy applies to the Scrabbdict mobile application ("Application"). The controller of the personal data described below is Piotr Sochalewski ("Developer"). For privacy questions or requests, contact: psdevsupport@icloud.com.
Summary
- The Application does not require an account and does not ask for your name, email address, contacts, precise location, or similar information.
- Usage analytics (Google Analytics for Firebase) is optional. It is turned off until you choose "Allow" on the consent screen shown at first launch. You can change your choice at any time in the Application's Settings.
- Crash reports (Firebase Crashlytics) are always on. They are used only to find and fix crashes and errors. You can object to this processing as described below.
- The words, letters, and patterns you type are never sent to analytics or crash reporting. The Application does not show ads, does not use the advertising identifier (IDFA), does not sell personal data, and does not track you across other companies' apps or websites.
Your analytics choice
At first launch, you are asked whether to allow usage analytics. Allowing and declining are equally easy, and the Application works the same either way. Until you decide, and if you choose "Don't allow", Google Analytics for Firebase does not collect or send analytics data. Your choice is stored on your device.
You can give or withdraw consent at any time in Settings under "Privacy" using the "Share usage statistics" switch. Withdrawing consent stops analytics collection immediately, deletes analytics data not yet sent from your device, and resets the analytics identifier stored on it. Data already sent to Google Analytics stays linked only to the previous random identifier and is deleted automatically at the end of the retention period described below.
Information processed in the Application
- Usage analytics (only with your consent). If you allow analytics, the Application sends the following events to Google Analytics for Firebase:
- that a word was checked and whether it exists in the dictionary,
- that a tiles (rack) search or a pattern search was performed,
- changes of the selected dictionary or search mode.
Events include the selected dictionary and search mode, but never the searched word, letters, or pattern. Google Analytics for Firebase also automatically processes technical data such as an app instance identifier, the identifier for vendor (IDFV), automatically collected events (for example first open, session start, and app or operating system updates), app version, operating system version, device model, language, timestamps, and approximate location (country, region, or city) derived from your IP address. According to Google, IP addresses are not logged or stored in Google Analytics. Advertising-related consent signals (ad storage, ad user data, and ad personalization) are always set to denied.
- Crash and diagnostics data. If the Application crashes or encounters an error (for example, a dictionary fails to load), Firebase Crashlytics processes crash traces, error details, the selected dictionary, app version, operating system version, device model and state at the time of the crash, installation identifiers, and timestamps needed to understand and fix the problem. If you allowed analytics, a crash report may also include the most recent analytics events listed above. Crash reports do not contain the words, letters, or patterns you type.
- Local app data. The Application stores settings on your device, such as the selected dictionary, search mode, and your analytics choice. This data is not sent to the developer.
- Support communications. If you contact support by email, your email address and message are processed to respond to your request.
Purposes and legal bases
- Providing app functionality. Local settings are processed on your device to provide the dictionary features you use and to remember your choices. Storing this information on your device is strictly necessary for the service you request.
- Usage analytics and product improvement. Analytics data is processed to understand which features are used and to improve the Application. The legal basis is your consent (Article 6(1)(a) GDPR), which also covers storing and reading analytics identifiers on your device as required by the ePrivacy rules (in Poland, Article 399 of the Electronic Communications Law). Giving consent is voluntary. If you do not consent, you can use all features of the Application.
- Crash diagnostics and reliability. Crash data is processed to find and fix crashes and errors and keep the Application stable and secure. The legal basis is the developer's legitimate interest in providing a working, reliable application (Article 6(1)(f) GDPR). Crash reporting is limited to technical data, does not include your searches, and is not used for analytics or advertising.
- Support. Support communications are processed to respond to your request. The legal basis is the developer's legitimate interest in answering your inquiry (Article 6(1)(f) GDPR). Providing your email address is necessary to receive a reply.
- Legal compliance. Data may be processed when necessary to comply with applicable legal obligations (Article 6(1)(c) GDPR).
The developer does not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects for you.
Service providers
International transfers
Google may process data outside the European Economic Area, including in the United States. Transfers to Google LLC in the United States rely on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, under which Google LLC is certified. Other transfers rely on the European Commission's standard contractual clauses included in Google's data processing terms. You can request more information about these safeguards using the contact details above.
Retention and deletion
- Local settings remain on your device until you uninstall the Application, which deletes them.
- Analytics data (only if you consented) is kept in Google Analytics for no longer than 14 months and is then deleted automatically. Aggregated reports that no longer relate to an identifier may be kept longer.
- Crash reports and associated identifiers are kept by Firebase Crashlytics for 90 days, after which deletion begins.
- Support emails are kept only as long as needed to handle your request and any related follow-up.
To stop further analytics collection, withdraw consent in Settings. To request earlier deletion of other data or of support emails, email psdevsupport@icloud.com.
Your rights
Under the GDPR (and, where applicable, the UK GDPR), you have the right to:
- request access to your personal data, and its rectification or erasure,
- request restriction of processing,
- receive data you provided on the basis of consent in a portable format,
- withdraw your analytics consent at any time in the Application's Settings, without affecting the lawfulness of processing before withdrawal.
Right to object: you have the right to object at any time, on grounds relating to your particular situation, to processing based on legitimate interests, including crash reporting. To do so, contact psdevsupport@icloud.com.
Analytics and crash data are linked only to random identifiers that the Application does not show, not to your name or email, and the analytics identifier is reset when you withdraw consent. As a result, the developer may be unable to identify data relating to you without additional information, and will explain what is possible when responding (Article 11 GDPR). Requests are answered within one month, which may be extended by two further months where necessary.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country of your habitual residence, place of work, or place of the alleged infringement, or, in the UK, with the Information Commissioner's Office. The authority in Poland, where the developer is established, is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl).
Children
The Application is not directed to children and does not knowingly collect personal data from children. If you are below the age at which you can consent to online services in your country (16 in Poland), do not allow analytics unless a parent or guardian agrees.
Security
Data collection is limited to what is needed for the purposes described above, and the service providers used encrypt data in transit.
Changes
This policy may be updated from time to time. The "Last updated" date above shows when the current version was published. If a change affects the scope of processing based on your consent, the Application will ask for your consent again where required.