MorphMove for iOS
Privacy
Last updated 24 September 2026
Analytics
Starting with iOS 1.17, first-party usage analytics is on by default to help us understand and improve MorphMove. The app sends product events that can cover app sessions, pages and instructions viewed, game starts and results, moves and blocked attempts, ratings and difficulty, AI reliability and latency ranges, restarts, review actions, settings, sharing, multiplayer interactions, and notification choices. You can turn sharing off in the app’s Privacy screen and keep playing.
Events use random identifiers for this app installation, each session, game, and event. They can include bounded details such as move method, move count, outcome, duration, rating, difficulty tier, runtime, and selected setting. A coarse country, device category, operating-system family, and browser family may be derived when events arrive at the server. Country may reflect a VPN, Private Relay, or where offline events are later uploaded. Names, email addresses, room access tokens, full user-agent strings, full referring URLs, and free-form text are not saved in this event stream. We do not use these events for advertising or tracking across other companies’ apps.
While sharing is on, compact lifetime totals and up to 300 pending events can be stored on this device, including while offline. The iOS app does not keep a detailed analytics archive. Turning sharing off stops new collection and queued uploads and clears the local identifiers, totals, and pending events. A request already in progress may finish; previously uploaded events remain subject to the retention period below; you can request their deletion by emailing us.
Multiplayer rooms
Multiplayer games use an eight-character room code, random participant credentials, game state, scores, presence timestamps, and anonymous room and match identifiers so the game can synchronize between players. Participant credentials are sent only to the relevant player; server-side credentials are stored in hashed form. Rooms are temporary and expire after about 24 hours unless renewed by activity.
Notifications
If you enable notifications from either Daily or multiplayer, the app receives an Apple device push token. MorphMove uses it for recurring 18:00 local-time Daily reminders when that day’s puzzle has not been played and, when you host a room, to tell you when the other player joins. The Daily registration also stores an anonymous management token, your current IANA time zone, the next reminder time, the latest Daily date played or reminded on this installation, and your selected language so alerts can use that language; room alerts are separately linked to an anonymous room-owner token. Room registrations expire after 30 days without refresh. Registrations are removed when Apple reports that they are no longer valid. You can stop all alerts at any time in iOS Settings; this stops delivery on that device but does not necessarily delete the Daily reminder registration from MorphMove’s server.
Daily Puzzle progress
Detailed Daily Puzzle attempts, moves, solved dates, and streaks are stored on this device. They are not linked to your rating or synchronized across devices. Removing the app removes that progress.
Physical-edition email
If you voluntarily register interest in a tabletop edition, MorphMove stores the email address you provide, a normalized copy used to avoid duplicates, the signup source, and the consent version. The address is used only for meaningful news about a physical MorphMove edition and administration of that list. It is not used for advertising profiles. You can ask for removal at any time.
Security and abuse prevention
MorphMove applies rate limits and other request protections to reduce spam and abuse. Hosting and infrastructure providers may process short-lived technical identifiers derived from connection data for those purposes and for ordinary service security.
Purpose, retention, and providers
Data is used to operate and secure MorphMove, provide multiplayer and notifications, improve the app while usage analytics is on, and manage the optional physical-edition mailing list. It is not sold and is not used to create advertising profiles. Analytics maintenance removes live events older than 360 days; provider recovery systems may retain deleted records for up to 30 additional days. Temporary multiplayer rooms and join-notification registrations expire as described above. Daily reminder registrations have a rolling ten-year expiry, renewed when the registration is refreshed or a reminder is successfully sent; invalid registrations are removed sooner. You can request deletion at admin@morphmove.com. Email signup records are kept while the physical-edition list remains relevant or until deletion is requested. Hosting, database, email, Apple push notification, and other infrastructure providers may process the minimum data needed to provide their respective services.
Your choices and rights
You can turn analytics sharing off at any time in this iOS privacy screen, decline notification permission, and avoid the optional physical-edition signup. For access, correction, deletion, objection, or other privacy questions, email admin@morphmove.com. You may need to provide your random installation identifier when asking about specific analytics history. You may also lodge a complaint with your applicable data-protection authority, including Portugal’s CNPD.
Back to MorphMove