Sortia

Last updated: September 28, 2026

Privacy Policy

Sortia is an iOS card-sorting game from OzTech. This policy explains local gameplay, purchases, optional rewarded advertising, sign-in, and the world leaderboard. For privacy questions or requests, contact support@oztechapps.net.

1. Game data on your device

Sortia stores settings, language, tutorial and level progress, saved boards and move histories, lives and refill times, coin balances, cosmetic ownership, reward records, and purchase transaction identifiers on your device. These records support continued play, purchase delivery, and prevention of duplicate rewards.

Local records can also include a generated player name, a name draft, your guest or sign-in choice, a technical account identifier, a private provider-name suggestion, sharing preferences, and a queue of results awaiting delivery. During account deletion, an account identifier, authorization token, and recovery information can be kept in the device Keychain until cleanup is acknowledged.

Local play does not require Apple or Google sign-in or leaderboard participation. Sortia does not request contacts, photos, microphone access, or precise location for gameplay. The app does not integrate Firebase Analytics or Crashlytics; functional and security processing by its online services is described below.

2. Purchases

Apple processes in-app purchases through StoreKit. Sortia reads product information, verified transactions, and purchase entitlements, and keeps local transaction records to prevent duplicate delivery. On startup it checks entitlements and unfinished transactions, listens for transaction updates, and loads product information. This is separate from joining a leaderboard or watching an ad. OzTech does not receive your payment-card details through this purchase flow. See the Apple Privacy Policy and our purchase terms.

3. Optional advertising

Sortia uses Google AdMob for optional rewarded video and Google's User Messaging Platform (UMP) for privacy choices. Initializing the ad coordinator can contact UMP to refresh privacy requirements before you tap an ad offer, including during startup. That background check does not itself show a privacy form or load or display an ad. The game has no banner, automatic interstitial, or app-open ad placement.

Choosing an available video offer refreshes UMP information, shows a privacy message when required, and requests an ad only when UMP permits it. An eligible earned reward grants five extra moves, at most once per hand. Declining a video does not prevent local play; it leaves that video reward unearned.

Sortia requests non-personalized ads and disables Google's publisher first-party ID and publisher privacy personalization. Non-personalized does not mean no data is processed. Google's advertising SDK may process IP addresses and IP-derived approximate location, device or other identifiers, ad and product interactions, and crash or performance information for advertising, measurement, diagnostics, and fraud prevention. See Google's advertising SDK disclosure and Google's Privacy Policy.

When UMP requires a privacy-options entry, you can reopen the available choices using the game's ad privacy control. A verified No Ads owner can claim the same eligible five extra moves without watching a video, under the same one-per-hand limit. No Ads ownership does not by itself disable the UMP privacy-information refresh described above.

4. Optional sign-in and world leaderboard

Accounts and sign-in

You can play as a guest or sign in with Apple or Google using Firebase Authentication. Choosing guest play is a local choice; it does not by itself create a Firebase account. Joining the leaderboard separately uses your existing Firebase identity or creates an anonymous Firebase identity if none exists. Anonymous authentication still has a persistent technical account identifier and is not unidentifiable activity.

Apple, Google, and Firebase process the credentials and account information needed for sign-in. Apple sign-in requests your name when available and passes it with the identity credential to Firebase. Google sign-in can return basic profile information, including a name, email address, and profile-image URL. Firebase can process email and other profile information returned by a provider even if the game does not display it. Sortia can keep a provider name as a private name suggestion.

Signing in does not automatically join the leaderboard or publish your provider name. Linking an existing anonymous Firebase identity to Apple or Google requires a separate confirmation. A saved provider sign-in can initialize Firebase again during launch or foreground restoration without a new sign-in tap.

Results and public names

The leaderboard is world-only for the relevant game-book version. Sortia does not assign country or city membership, request GPS coordinates, or use IP location to choose a ranking region. After you join, eligible Classic results can be queued and submitted automatically, with retries when the app returns to the foreground. Requests include the game-book version, level identifier, deal and content seeds, and move history so the server can replay the game and verify the result.

Authentication tokens identify the account. Firebase App Check with Apple App Attest supplies app/device integrity evidence and tokens to protect the service. Authentication and network providers can also process connection information such as IP addresses. See Firebase's privacy information and Firebase's Apple-platform data disclosure.

The backend stores account membership, technical identifiers, best per-level results, ranking totals, profiles, and request-rate records in Firestore. Other participants see a public player alias or approved display name, total stars, and completed-level count. Ranking responses also contain a public alias identifier and name-source status, but not your Firebase account identifier, provider email, private name candidate, or move history.

Submitting a public name requires separate confirmation. The candidate is stored privately for review; only an approved name is published. Pending or rejected candidates use a generated fallback name. A provider name or local draft is not automatically approved. Avoid submitting your real name, contact details, or sensitive information. Report inappropriate names to support@oztechapps.net.

Pause sharing or delete an account

Open the leaderboard and choose Pause sharing to stop future local sharing requests. Published results remain, and an upload already in progress may finish. Pausing does not delete the account or sign you out of your provider.

Choose Delete leaderboard account in the leaderboard and confirm to request deletion of the Sortia Firebase account and its leaderboard data. You may need to authenticate again with the same provider; Apple-linked deletion also requires Apple-token revocation. Successful deletion removes leaderboard membership, results, profile and name reservation, request-rate records, and the Firebase Authentication account. A minimal account-keyed deletion marker remains, including a hashed recovery value where used, to prevent late requests from recreating the account and to support retries. There is currently no automatic expiry for this marker.

Deletion requires a reachable service. If interrupted or unsuccessful, it stays pending with sharing paused; retry the in-app recovery action or contact support. Do not treat an unconfirmed request as completed deletion. The in-app deletion path leaves local game progress, lives, coins, and purchase rights unchanged. It does not delete your Apple or Google account, support correspondence, or provider-held logs and backups.

5. Support and this website

If you email support, your email address, message, and any attachments you choose to send are used to handle your request. Please do not send passwords, payment-card information, identity documents, or unrelated private content. Support correspondence and any separate moderation decision or audit records are not automatically removed by the in-app account-deletion action; contact support about those records.

This Sortia website section contains no advertising, analytics scripts, embedded social widgets, or external font requests. Hosting and network providers necessarily receive connection information, such as an IP address and requested URL, when serving the site. Sending an email opens your chosen email service and is not anonymous.

6. Retention, storage, and transfers

Local game records remain until replaced through normal use or removed with app data. Delivered results are removed from the local delivery queue; pausing sharing also clears that queue when local storage is writable. App files, preferences, SDK-managed sign-in state, and Keychain deletion records are separate stores. Removing the app is not a cloud-account deletion request and may leave credentials or device backups.

The leaderboard application does not apply an automatic age-based expiry to account, profile, best-result, or request-rate records. They are removed by successful account deletion as described above, except for the retained deletion marker. Support correspondence, moderation audit records, service logs, and backups have separate handling; this policy does not promise a fixed retention period or immediate erasure of every copy. Contact support to request access or deletion of records outside the in-app deletion path. Apple and Google's own processing and retention are described in their linked policies.

The leaderboard Firestore database is in Frankfurt, Germany (europe-west3). That database location does not confine all processing to Germany. Firebase states that its Authentication service processes data in the United States; Apple, Google advertising, integrity checks, hosting, and support services may also process information outside your country. See Firebase's data storage and processing locations.

7. Your choices and requests

You can play without provider sign-in or joining a leaderboard, decline rewarded-video offers, manage available ad privacy choices, pause sharing, request account deletion, and remove local app data using iOS. Deleting local data can also remove progress and unspent consumable coins, so contact support first if you are troubleshooting.

Depending on applicable law, you may have rights to access, correct, delete, obtain a copy of, restrict, or object to processing of your personal data, withdraw consent, and complain to a data-protection authority. Email support@oztechapps.net to make a request. We may need enough information to locate the relevant record and verify the request without requesting unnecessary sensitive documents.

8. Audience and family use

Sortia is intended for a general audience, not as a child-directed service. The app does not ask for a date of birth. A store age rating describes content and is not proof of parental consent to online data processing. A parent or guardian with a concern about a child's information should contact support@oztechapps.net.

9. Changes

This page will be revised when Sortia's data practices change. A change to this policy is not, by itself, consent to a new use of personal data. The date at the top identifies this version.