Privacy Policy
ONE PIXEL is made by RoBu Games, a trading name of Bhoopendrasingh Bhogun ("we", "us", "our") — not a separate company. This policy explains what happens when you play ONE PIXEL on iOS or Android, based directly on what the app's code actually does as of this date.
Short version
ONE PIXEL has no account, no login, and no in-app form asking for your name or email. Gameplay events — including your best score — are sent to an analytics provider, tied to a persistent identifier for your installation. Details below.
Information we do not collect directly
The app itself does not ask for or access your name, phone number, photos, contacts, precise (GPS) location, or your microphone/camera. There are no user accounts, no chat, and no user-generated content.
Your best score: stored locally, and also sent to analytics
Your personal best score is saved on your device (standard app storage) so the game itself works offline and instantly.
Also sent to analytics: when analytics is active (the case for our standard release configuration), several gameplay events sent to our analytics provider include your current best score as a numeric value — for example, when you finish a run or set a new best. The score lives on your device, and is also transmitted off-device as part of ordinary analytics.
Gameplay analytics (PostHog)
We use PostHog to understand how ONE PIXEL is played in aggregate. Analytics only run when the app is built with an analytics key configured; that is the case for our standard releases, but a given build could in principle ship without one, in which case none of this section applies to that build.
The events we send, and exactly what each one contains, are:
| Event | What it contains |
|---|---|
app_open | nothing beyond default technical metadata (below) |
game_start / retry / play_again | attempt number, whether this run is a challenge attempt, the challenge target (if any) |
challenge_received / challenge_accepted / challenge_beaten | the challenge target score |
score_reached / first_hit_success | the score just reached |
new_personal_best | the new score and new best score |
milestone_reached | the milestone and current score |
game_over | final score, best score, why the run ended, attempt number, challenge info, run duration |
game_complete | final score (200), best score, attempt number, challenge info, run duration |
share_tapped | the score you were sharing |
None of these include free text you typed, your name, or your email address. All are numbers, short fixed labels (like a failure reason), or booleans.
What "no account" does not mean: PostHog automatically assigns your installation a persistent random identifier, stored on your device and reused every time you play. That identifier is not your name or email, but it does let events be correlated to the same device over time — which is a form of data linkage, even without an account. Whether this counts as "personal data" and how it should be labelled (e.g. on an App Store privacy label) depends on the specific privacy framework and is not something the absence of a login screen settles by itself. We are not treating "no account" as proof that this data is anonymous or unlinked.
We do not use screen recording/session replay, autocapture, or console-log capture — only the named events above are ever sent. We also collect uncaught JavaScript errors and unhandled promise rejections (technical error messages and stack traces) to help fix bugs.
Where this data is processed is a release-configuration detail, not a fixed fact about the app. The analytics host is set by build-time configuration and can differ between development, preview, and production builds, or change without a code change to the app itself. As of this update, the configuration we use for production builds points to PostHog's EU region. We have not independently confirmed this from network traffic captured out of a shipped build — only from the build-time configuration itself — so treat "EU-hosted" as our current intended configuration, not an audited guarantee for every copy of the app in the wild. See PostHog's own privacy policy for how it processes and secures data: posthog.com/privacy.
Advertising (Google AdMob)
ONE PIXEL shows occasional interstitial (full-screen) ads between attempts, provided by Google AdMob. Before requesting any ad, the app uses Google's User Messaging Platform (UMP) to ask for your consent where required (for example, in the EEA/UK); ads are only requested if that consent allows it.
Two separate things are true here, and we want to be precise about both:
- The app does not use Apple's App Tracking Transparency permission and does not itself request or read your device's advertising identifier (IDFA) for cross-app tracking.
- Independently of that, Google's AdMob SDK can still process other technical data for ad delivery, measurement, and fraud prevention — including inferring your approximate location (for example, from your IP address), which is not the same as, and does not require, the precise GPS location the app never requests. This is Google's SDK behaviour, governed by Google's own privacy policy, not something we control line-by-line: policies.google.com/privacy. You can review Google's ad-related privacy choices at myadcenter.google.com.
Builds distributed for testing before public launch use Google's official test ad unit, which shows sample ads only and runs no real ad auction.
If you contact us for support
Emailing us (see Contact, below) is separate from, and not automatically connected to, the gameplay analytics described above. If you email us, we receive your email address and whatever you write, in an ordinary personal email inbox, retained the way any email is. We have no automated way to match that email to your in-game analytics identifier — the two systems aren't linked — unless you tell us details (like an exact time or score) that let us find the matching event ourselves.
Sharing your score
If you tap "Share Score", your device's normal share sheet opens with a short message containing your score and a link back to the app. You choose where that message goes (Messages, social apps, etc.). We do not see the message text, the recipient, or the destination app — only the share_tapped event above (the score value) is sent to analytics.
Children
ONE PIXEL is intended as a general-audience game and is not directed to, or knowingly marketed at, children under 13. We do not knowingly collect personal information from children.
Your choices and rights
We don't have a directory of players to look you up by name — nothing in our systems is indexed that way. That does not mean no data exists that relates to your device; see the sections above for exactly what's collected and how it's identified (a persistent per-installation ID, not a name). If you'd like to ask about, or request deletion of, data associated with your installation, or have any question about this policy, contact us below — we'll do what's practically possible given the identifiers actually available to us.
International transfers
Analytics data is processed according to whichever PostHog region our current build configuration points to (see above). Google/AdMob operates global infrastructure and may process data outside your country, under its own compliance safeguards.
Changes to this policy
If ONE PIXEL's data practices or release configuration change — for example, a real (non-test) ad unit going live, or analytics hosting changing — we'll update this page and the "Last updated" date above.