Legal & privacy

Privacy Policy

Effective 13 August 2026

This policy describes how the Trio mobile application handles data. Trio is developed by Baltzer Technologies. Privacy questions can be sent to trio@baltzer.eu.

Scope

This policy applies to the Trio mobile application. Trio is intended for adults aged 18 and over and is not designed or marketed for children.

Data stored on the device

Trio stores game settings, local gameplay statistics, and a cached indication of whether the current store account owns the Remove Ads purchase. If a player chooses to join the online ladder, Trio also stores the sharing choice, random player ID, generated handle, authentication secret, and any completed result waiting to upload. The authentication secret is kept in platform secure storage. This information is not sent to Trio's server unless the player explicitly enables ladder sharing.

Players can reset gameplay statistics from inside Trio. Removing the application through the operating system removes its device-local application data. A Remove Ads purchase remains associated with the relevant Google Play or Apple store account and can be restored according to that store's rules.

Advertising and consent

When ads are enabled, Trio uses Google AdMob to request and display banner and interstitial advertisements. Trio uses Google's User Messaging Platform (UMP) to request and manage advertising consent where required. A privacy-choices entry is available in Trio's settings whenever UMP reports that it is required.

According to Google's disclosure for the Google Mobile Ads SDK, the SDK may automatically collect and share the following data for advertising, analytics, and fraud-prevention purposes:

  • IP address, which may be used to estimate general location;
  • interactions with the application and advertisements, such as launches, taps, and video views;
  • diagnostic and application-performance information; and
  • device or account identifiers, including the Android advertising ID and app set ID when available.

Google states that this data is encrypted in transit. Advertising behaviour, including whether personalised advertising is permitted, depends on applicable law, the consent choices presented by Google, device settings, and Google's own policies. Trio limits requested advertisements to Google's G maximum ad content rating.

Players who purchase Remove Ads do not receive banner or interstitial ad requests after Trio confirms the entitlement. Consent and advertising SDK data already processed before that entitlement is confirmed remains subject to Google's retention and deletion practices.

More information is available in the Google Privacy Policy and Google's Mobile Ads data disclosure.

Purchases

Trio uses the platform store to offer the one-time Remove Ads product. On Android, Google Play processes the transaction. Trio queries Google Play for product and ownership information and sends the purchase token to Google Play when acknowledging a completed purchase. Trio does not operate a purchase server, receive payment-card details, or retain the purchase token in its own local storage.

Google Play's handling of purchase and account information is governed by the Google Privacy Policy.

Optional online ladder

The online ladder is disabled by default. A player who enables it receives a random player ID, a generated public handle, and a high-entropy authentication secret. Trio does not ask for a name, email address, password, social login, or store-account identity. The server stores only a cryptographic hash of the secret.

A player can use the same anonymous identity on another device by creating a temporary one-time export code and importing it within ten minutes. The code does not contain the permanent authentication secret. The server stores only a hash of the temporary code and deletes expired codes automatically. Each linked device receives or retains a separate authentication credential for the same player ID. If an imported device already has a player identity, its verified results are combined with the exported identity and the exported player ID and generated handle are kept.

For an eligible completed run, Trio sends the authenticated random player ID, generated handle, game mode and rules board, random deal seed, result metrics, app version, platform, and an ordered transcript containing evaluated board positions and relative event times. The server uses this data to replay and verify the result, prevent duplicate or abusive submissions, calculate rankings, and operate the service. Hosting and network systems also process IP address and bounded request metadata for security, rate limiting, and troubleshooting. Transport uses HTTPS.

Public rankings show only the generated handle, rank, board, and verified game metrics. Player IDs, authentication secrets, IP addresses, and transcripts are not public. Ladder data is not used for advertising and is not combined with advertising or purchase identifiers.

Sharing can be paused at any time without deleting existing rankings. Local play and local statistics continue normally whether sharing is enabled, paused, unavailable, or never activated.

Data Trio does not request

Trio does not create a conventional named account and does not request a player's name, email address, contacts, precise location, photos, camera, microphone, or health information. The optional ladder identity is anonymous but functions as an app account because its secret authenticates one unique player. Trio does not include a Trio-operated analytics, crash-reporting, or general telemetry service.

Retention and deletion

Device-local settings, statistics, and the cached Remove Ads entitlement remain until they are reset by an available in-app action, removed with the application's local data through the operating system, or replaced by a newer value. Data processed by Google is retained and deleted according to Google's policies and the controls available through the player's Google account, advertising settings, consent choices, and applicable law.

The in-app Delete ladder data action immediately removes the generated handle, submitted results, transcripts, and public rankings and revokes every linked device credential. The deletion applies to every device using that player ID. A non-public random-ID and revoked-credential tombstone is retained for no more than 30 days so deletion retries can be handled safely and abusive credential reuse can be rejected. Security audit events are retained for no more than 90 days; after the first 30 days they are no longer linked to the random player ID. Cleanup runs automatically. Pending results and ladder credentials are also removed from the device after a successful deletion.

Account and data deletion instructions are available without opening the app. Privacy or deletion questions can be sent to trio@baltzer.eu.

Changes to this policy

This policy will be updated when Trio's data practices, included SDKs, advertising behaviour, purchases, or legal obligations change. The effective date at the top of this page identifies the current version.

← Back to Trio