Kanzi

Privacy Policy

Effective 24 August 2026

1. About Kanzi

Kanzi is a jigsaw-puzzle application featuring generated editorial illustrations and stories about places, landscapes, crafts and cultural traditions across Africa. The app does not require an account and does not ask for a name, email address, contact list, precise location, photos, microphone or camera access.

This policy explains how Bencode Studio ("we", "us") handles information when you use Kanzi.

2. Information kept on your device

Kanzi stores puzzle progress, completed puzzles, elapsed play time, earned beads, ad-unlocked images, onboarding state, language and accessibility/game settings locally on your device. It also caches the last valid remote-content catalog and artwork you choose to download. We use this information to save and restore your experience and make downloaded puzzles available offline. It is not uploaded to a Kanzi gameplay account or cloud-sync service.

Settings → Reset app data clears gameplay progress, album records, beads, streaks and settings. The operating system manages cached downloaded artwork; it may remain until the system evicts it or you uninstall the app. Uninstalling removes Kanzi's app data from the device, subject to the platform's backup and restore behavior.

Kanzi does not use banner ads. Free players may see a full-screen interstitial advertisement at a natural board transition: when continuing after every third completed board in that session, or before resuming an unfinished board after at least 30 minutes away once another board has already started in the current session. The first board of every app session is ad-free. A failed or unavailable ad does not block gameplay. You may also choose to watch a rewarded advertisement to receive a clearly described in-app reward.

Google AdMob and its consent platform may process consent choices, IP address, device or advertising identifiers where available, general device information, ad requests, ad views/interactions and diagnostics to provide, limit, secure and measure advertisements. Kanzi may request personalized ads only where Google's consent platform reports that they are permitted by the applicable ad choices, or that consent is not required. Otherwise Kanzi requests contextual, non-personalized ads. Kanzi does not request any ad unless Google's consent system reports that ads may be requested. Puzzle preferences and optional diagnostics are not supplied to AdMob for ad selection.

For reward security, the app sends a random one-time challenge with the ad. Google sends a signed completion callback to our verification service. The service records the challenge/transaction result to prevent the same reward from being claimed twice. The challenge is not your name, email address or puzzle history.

Closing a rewarded ad early grants no reward. If Google's consent system does not permit an ad request, Kanzi continues without showing the ad. You can open Google's privacy-options form from Kanzi Settings when it is required for your region.

5. Notifications

If you enable the daily reminder, Kanzi asks the operating system for notification permission and schedules the reminder locally on your device. We do not operate a push-notification account or upload your puzzle activity for this reminder. You can disable it in Kanzi Settings or system settings.

6. Diagnostics and app analytics

Kanzi uses Google Firebase Crashlytics for crash reports and Google Analytics for Firebase for a minimal set of puzzle-quality events, solely to fix defects and improve puzzle selection, difficulty and assistance. Share diagnostics is off by default. Nothing is sent unless you turn it on in Kanzi Settings, and you can turn it off at any time. Advertising consent is separate and never authorizes diagnostics collection.

Kanzi does not use diagnostics for advertising, attribution, audience creation, cross-app tracking, profiling or marketing. Analytics advertising identifiers, ad storage, ad-user data, ad-personalization signals and automatic screen reporting are disabled in the app's native configuration. Turning diagnostics off disables both services, resets local Analytics state and deletes unsent Crashlytics reports from the device.

Kanzi also uses Firebase Remote Config to fetch operational flags such as the current store-update links and other operational safeguards. Remote Config is used for app functionality and may receive the limited app, device, network and installation information required by Firebase to deliver and secure the configuration. It does not receive Kanzi puzzle progress or the closed-list gameplay events described below, and its fetch is not controlled by the diagnostics switch.

The gameplay events are a fixed, closed list. Kanzi records only that one of the following happened, together with non-identifying details such as the piece count or the puzzle's identifier:

Each event has its own fixed field list. Details are limited to piece count, puzzle identifier, library/Daily source, resume state, elapsed seconds, completion percentage, session depth, fixed navigation choice or automatic-ad placement where relevant. Piece identity, piece coordinates, gesture paths, ad-unit identifiers, revenue and other monetization fields are not accepted by these event schemas. Kanzi does not attach free text, your album, your name or your contact details to these events, and it has no field in which to do so. Crash reports contain diagnostic information about the failure, the device and the app version, gathered by Crashlytics.

Google processes this information as our service provider, and may process device and app identifiers, general device and app information and approximate region to provide these services.

Kanzi still has no user accounts, no cloud gameplay sync, no social features and no leaderboard. If these practices change, we will update this policy and the store disclosures before enabling the change.

7. Service providers and disclosures

We disclose information only as needed to operate the features described above:

We do not sell personal information or use/share diagnostics for marketing. Kanzi configures Firebase Analytics data as unavailable for ad personalization. AdMob personalization, when permitted, relies on Google's ad-specific consent system and not Kanzi diagnostics or puzzle preferences. Advertising providers may still process the information described above to deliver, limit, secure and measure ads, subject to the choices and rights available in your region.

8. Retention

Local gameplay information remains until you reset the app or uninstall it. The cached remote catalog remains until app storage is cleared or the app is uninstalled. Downloaded artwork remains in operating-system-managed cache until it is evicted, app storage is cleared, or the app is uninstalled. Crash reports and analytics events are retained only for the shortest practical period configured for those Firebase products and are not exported to an ads, marketing or audience system. Turning off Share diagnostics stops further collection, resets local Analytics state and deletes unsent crash reports. The reward-verification service keeps its random challenge, signed transaction ID and verification time in a restricted Firestore database for 10 minutes to confirm the reward and prevent a duplicate claim across service restarts and concurrent instances. Expired records are rejected immediately when read, and Firestore's time-to-live policy deletes them asynchronously. This short-lived replay-protection store is not a reward ledger and has no Kanzi account or player-identity link. Its own operational logs contain reason categories and error types, not request values or identifiers. Automatic Cloud Run request logs are excluded from storage for this service. Other sanitized Cloud Logging entries use the project's configured retention, currently 30 days. See These limits are enforced by the reward-verification service's deletion and logging controls.

Apple, Google and other hosting providers retain information under their own policies and our agreements with them.

9. Security and international processing

We use reasonable technical and organizational safeguards appropriate to the information handled, including store-validated entitlements and signed, single-use reward verification. No method of storage or transmission is completely secure.

Our service providers may process information in countries other than your own, including the United States. Where required, we rely on contractual or other lawful transfer safeguards supplied by those providers.

10. Children

Kanzi is intended for a general audience and is not directed to children under 13 or the minimum digital-consent age in their country. We do not knowingly ask children for personal information. Contact us if you believe a child has provided personal information through a service associated with Kanzi.

Kanzi is offered as a general-audience app and is not enrolled in a child-directed or Made for Kids program.

11. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, withdraw consent, or receive information in a portable format. You may also complain to a local data-protection authority.

Because Kanzi has no account, include the device platform and approximate dates when contacting us. We may need to verify a request and may retain information where law permits or requires.

You can also:

12. Changes

We may update this policy when Kanzi's features, providers or legal obligations change. We will post the revised policy with a new effective date and provide additional notice where required.

13. Contact

Privacy requests: privacy@bencodestudio.com