Privacy Policy

Effective September 12, 2026 · Last updated September 9, 2026

This policy explains what Nibbit ("the app", "we") collects, why, and your choices. Nibbit is a daily coding-practice game. It is built to collect as little as possible.

The short version

What we collect

For every player, from first launch:

DataWhyWhere
An anonymous account identifierTo save your progress without a loginFirebase Authentication
A display name ("handle") Nibbit assignsTo show you on leaderboards and to friendsFirestore
Gameplay data — daily answers, correctness, score, streak, level, XPTo run the game, grade fairly, and rank dropsFirestore and Cloud Functions
Friend connections you createTo show a friends leaderboardFirestore
Your difficulty preference and whether reminders are onTo set your level and schedule your reminderOn your device and in Firestore
Your device's time zone nameTo decide which calendar day a completed drop belongs to and to fire the reminder at the right local timeFirestore
Crash reports, if the app crashesTo find and fix the crashFirebase Crashlytics — not linked to your account
Usage events — opens, drops started and finished, screens used, failuresTo tell whether the app works and where people get stuckOur own server and database; no analytics SDK, no third party

If you choose to add a sign-in (all optional): with email we collect the address you provide; with Apple or Google we receive the email address and name the provider returns. Apple's "Hide My Email" is honored. Adding a sign-in lets your progress follow you to a new phone.

If you set a profile photo, the image is stored in Firebase Storage and is readable by anyone who has its URL, so it can be shown to friends and on leaderboards. Deleting your account deletes it.

If you report another player or write to support, we store what you sent us. "Reporting another player" and "Contacting support" below say exactly what that is.

We do not collect: your location, contacts, camera or microphone, health or financial data, advertising identifiers, or your web-browsing history. Nibbit requests no such permissions. Choosing a photo uses your device's picker, and only the image you pick is uploaded.

How your handle and scores are shared

Your handle, score, and photo (if set) are visible to other players on the Global and Friends leaderboards and to people you add as friends. Handles are assigned by Nibbit and contain no personal information.

Moderation

Your handle is shown to other players, so it is checked before it exists: when you claim one or change it, our server screens it against a list of names we refuse to publish. That check runs on the server, not in the app, so a name the app lets you type can still be turned down.

Behind that there is an admin panel, used by a short list of people we have approved by hand. Looking up a single account there shows the handle and display name, the progression numbers, when the account was created, whether it is suspended, the email address on it if a sign-in was added, and the account's recent attempts — which questions were answered, whether each was right, how long each took, and whether our server flagged the timing as odd. The attempts are there so a suspicion can be looked at before anyone is banned.

A moderator can also change your stored progress. That covers your current and longest streak, total XP, level, perfect days, completed drops, correct and total answers, your last completed day, the completed-day journal the Profile calendar is drawn from, your time zone, and your display name and experience band. Two figures cannot be set by hand and are always recalculated instead: your progress toward the next level, and your accuracy. Your handle cannot be edited there at all — a rename goes through the same path you use, so the name stays unique and still gets screened.

Every one of those actions is written to a log naming the moderator who did it, what they changed, and when. The log is not reachable from the app; it exists so nothing done to an account is done without a record.

An account can be suspended or deleted for breaking the rules. A suspension switches off its sign-in, so it cannot be used again until the suspension is lifted. A deletion runs exactly the same removal as deleting your own account from Settings, and cannot be undone.

Reporting another player

If a handle or something a player did is a problem, you can report them from a leaderboard row or from your friends list. A report records who you are, the account you reported, the reason you picked, the note you typed if you added one, and the handle that account had at the time — so a rename cannot shake off a report.

Reports go to a queue in the admin panel and are read only by moderators. The person you report is not told who reported them. A report is not anonymous to us, though: your account id is on it, because a queue nobody can be held to is a way to harass people rather than a way to stop it. You can have a few reports open at once, and reporting the same person twice does not file a second one.

Contacting support

Settings → Contact support sends us a message. We store what you wrote, the handle you had at the time, your app version, your platform and OS version, and — only if you type one — an email address so a reply can reach you. That field is optional, and it is there for players without a sign-in: signing out gives you a new anonymous account, and a reply sitting in the old one would never be read.

A person reads it. A moderator sees your message, and the email address if you gave one, and writes one reply back that appears in the app. We do not use the address for anything else and it is not added to any mailing list. Your support messages, and any address attached to one, are deleted along with your account.

Notifications

If you allow it, Nibbit schedules a local daily reminder on your device. You can turn it off in the app or in your system settings.

Crash reporting

If Nibbit crashes, we receive a crash report: the technical stack trace, your device model, your OS version and the app version. We use Firebase Crashlytics for this, and it is how we find out something is broken without you having to tell us.

Crash reports are not linked to your account. We deliberately do not attach your account id to them, so a crash report cannot be traced back to you. They contain no handle, no email, and nothing you typed in the app.

How we measure the app

We record what happens in the app so we can tell whether it works: when it is opened, when a drop is started, finished or abandoned, which kind of question was answered and whether it was correct, which screens are used, and when something fails.

This is ours, not a third party's. There is no analytics SDK in Nibbit. These events go to our own server and our own database, and are not shared with an advertising network, a measurement company, or anyone else.

Our website keeps the same promise. Pages like this one count their visits and button taps with our own code, sent to our own database. The counters use no cookies and no identifiers of any kind — we count visits, not visitors, so nothing connects one page view to another after you close the tab.

What we deliberately do not record: the answers you give, the text of any question, your handle, your email, or free-form text of any kind. How long you spent on a question is recorded as a range ("under 5 seconds"), never an exact figure. These events are tied to your account id, because questions like "do people come back a week later" cannot be answered otherwise.

Advertising and tracking

None. Nibbit contains no advertising SDKs and no tracking. We never combine your data with data from other companies' apps or websites, and we do not ask for permission to track you across them, because we do not.

Service providers

We use Google Firebase (Authentication, Cloud Firestore, Cloud Functions, Storage, and Crashlytics for crash reports) to store data and run the game's server logic. Google processes this data on our behalf under Google's terms. If you sign in with Apple or Google, that provider handles the sign-in and shares the basic profile described above.

How long we keep data

We keep your gameplay data while your account exists so your streak and history persist. When you delete your account, everything tied to it is deleted.

That includes your support messages and any email address you attached to one, and any report filed about your account. Moderation log entries are kept, because a record of what was done to an account is the point of having one; they name the moderator, the account acted on, which values were changed, and when — never the contents of anything you wrote.

Your choices and rights

Children's privacy

Nibbit is intended for a general audience and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us and we will delete it.

International users

Data is processed on Google's infrastructure, which may be located outside your country. By using Nibbit you consent to that processing.

Changes to this policy

If we change what we collect, we will update this page and its "Last updated" date.

Contact

Questions or requests: shotacurtisruo@gmail.com.

Nibbit · a daily coding-fluency game · Nibbit on LinkedIn