2048SUPER

Privacy Policy

Effective date: 15 September 2026

2048 Super ("the game") is operated by Chan Hon Ming Vincent, 〒630-2306 奈良市月ヶ瀬桃香野3534-1, Japan ("we", "us"). This policy explains what information the game collects, who receives it, and what you can do about it. It applies to the website 2048super.com and to the iOS and Android apps of the game.

The short version: the game shows advertising supplied by Google and by Unity/ironSource. If you post a score it is published on a public leaderboard that anyone on the internet can read. We do not sell your data. You can delete your account and its records from inside the app, and section 9 says exactly what that removes and what it does not.

1. What this policy covers

Three things behave differently, so this policy names which is which throughout:

The apps are offered in English, Japanese, Korean, Traditional Chinese and Simplified Chinese. Your language choice is a setting stored on your device (section 7) and is not sent to us. This policy and the Terms are written in English; the app shows them in English whatever language you play in, and the English text is the one that applies.

2. What we collect, and why

Each item below says what the data is, how it reaches us, what it is used for, and who can see it. This list is complete: apart from the items below, and the sign-in tokens your device exchanges with our authentication provider to keep you signed in (section 7), the game sends us nothing about you.

The game asks for no permissions that read your data — no contacts, photos, camera, microphone, precise location, calendar or health access — and it contains no code that could use them. Tracking is a separate question, and section 4 answers it in full. On Android the app declares no permission that reaches your personal content. Its manifest asks only for technical permissions, including vibration for the haptic taps, internet access and network state, wake lock, the background-service and ad-services permissions the ad SDKs bring with them, and Google's advertising-identifier permission (com.google.android.gms.permission.AD_ID), which is what lets the ad SDKs read the advertising ID. Android does not prompt you for any of them.

We run no analytics, crash-reporting, attribution or telemetry service of our own in the apps. No crash reports and no performance data are sent to us.

3. Advertising

The apps show full-screen ads between runs and also during play. One is due when a run ends, and also after a set number of swipes (currently 350) and after a set number of powers used (currently 5) — so on an ordinary run the swipe rule alone comes round more than once, and you are interrupted mid-game, not only between games. Those numbers are settings on our server and can change without a new version of the app. The apps also show optional rewarded video ads you choose to watch in exchange for something in the game. The ads are supplied by third-party networks whose software is built into the app:

Both Google's and ironSource's software starts up when the app launches, whichever of them ends up filling a given ad slot. Which networks are used can change without a new app version: the app reads the list from our server at launch. As of this effective date that list is Google first, then Unity/ironSource. If we add a network we will name it here.

The game also shows our own in-house promotion screens. Those are drawn entirely from files inside the app and send nothing to anyone.

What the ad networks receive. When an ad is requested or shown, the networks receive, directly from your device: your IP address (from which an approximate location such as a city or region can be inferred), device and app identifiers, including the advertising identifier where it is available and identifiers scoped to this app on this device, the device model and operating system version, and which ads were shown to you and whether you interacted with them. Google's own published disclosure for its Mobile Ads SDK lists device identifiers, advertising data, coarse location, product interaction, crash data and performance data. This is how ad delivery, frequency capping, fraud prevention and payment measurement work. We do not receive any of it.

Install measurement. On iOS the app carries Apple's SKAdNetwork identifiers for 93 ad networks. SKAdNetwork lets Apple tell a network that an ad it showed led to an install, without identifying you to that network.

We do not join your game account to your ad identity. The app deliberately passes no user identifier to the ad mediator, so your nickname, email and account UUID are never sent to any ad network.

Google requires us to tell you that third parties may store and read data on your device and may use your IP address to collect information as a result of serving ads. How Google uses the information it collects from apps that use its services is described at policies.google.com/technologies/partner-sites. Unity's and ironSource's practices are described at unity.com/legal/game-player-and-app-user-privacy-policy. We require every company whose code we include to protect your data to the same standard this policy sets out.

4. Tracking and the advertising identifier

The order you meet these screens. No ad network is asked for anything until you have been through them. First you accept these documents and the Terms. Then, where Google's consent framework says one is required, Google's own consent form appears. On iOS the app then shows a short card titled About the ads, which explains what the next screen is and has one button, Continue — it offers you nothing in exchange for allowing — and Apple's tracking prompt follows it. Only after all of that does the advertising software start and the first ad request go out.

Where Google says one is required — which includes the EEA — the app shows a consent form supplied by Google's User Messaging Platform. It lists the advertising partners that may receive your data and lets you accept or refuse, and no ad network is asked for anything while it is on screen. If you refuse, the ads you see are not personalised. You can reopen that form and change or withdraw your choices at any time: open Settings, go to the Account tab, and choose Privacy Options in the Legal group. That row is shown only to players Google's framework says are entitled to a withdrawal route, so if it is not there, the form does not apply where you are.

On iOS the app then asks you, with Apple's standard prompt, whether you allow it to track you across other companies' apps and websites. Your answer decides what happens:

You can change your mind about the tracking prompt at any time in iOS Settings, under Privacy & Security, then Tracking, where you can turn this app's permission on or off. That system setting is the only route for this particular answer: the in-app Privacy Options row described above reopens Google's consent form and does not touch Apple's tracking permission.

On Android there is no equivalent prompt, because Android has none. Outside the regions where Google's consent form applies, the ad networks receive your Android advertising ID and the ads are personalised. That identifier is controlled by the device, not by this app: you can reset it or delete it in the device's own settings.

We do not sell your data, and we do not share it with data brokers.

5. Public leaderboards

Leaderboards are public, and they are more public than the leaderboard screen makes them look. Anyone can read the whole table, not just the top entries the game displays.

The database that holds scores and profiles is readable by anyone, by design, because that is how every player's app draws the leaderboard. The read key is published inside the app. In practice this means:

Email addresses are never published, and are not readable this way.

Posting is automatic after the first time. The first time a run qualifies, the game asks you for a name and waits for you to save it. After that, every run that beats your best on that device is posted without asking again. On iOS, your score is also reported to Apple Game Center, which is governed by Apple's privacy policy, not this one. The Android app reports to no equivalent service.

The leaderboard screen shows two boards: Global (signed-in players) and Guests.

Choose a nickname and a guest name you are comfortable showing publicly, and treat anything you post as permanently public.

6. Where your data is stored and who else handles it

All data is transmitted over encrypted connections. If you would like the details of how any of these companies protects data transferred outside Japan, write to us at the address in section 17 and we will provide them.

7. Data that stays on your device

The game stores the following on the device itself, and none of it is sent to us: your game progress and saved run, your sound, music, language, haptics, accessibility and performance settings, your avatar choice, your tutorial and quest progress, the power tokens on your power bar and the items waiting in your backpack, your ad-free period, the counters that decide when an ad is shown, and the record that you accepted these documents. Uninstalling the app removes it. The two purchases that Apple or Google can restore — the permanent no-ads pack and the 30-day pass — are the exception: their record is held by the store you bought them from, and section 8 explains what comes back after a reinstall.

Three things are kept on your device but do not stay there, and it would be misleading to list them above. Your nickname or guest name is sent with every score you post, and is published (sections 2 and 5). Your best score on this device is the score the game posts to the leaderboard as soon as it beats what you have already posted, so that number is published too. Your sign-in session token is sent back to our authentication provider, which issued it in the first place, each time your session is renewed and again when you sign out, so that the old session can be invalidated.

8. In-app purchases

The apps sell three kinds of optional purchase: power packs (consumable), a 30-day no-ads pass (a non-renewing subscription: it does not renew and charges you once) and the Ultimate 99 Pack (a non-consumable that removes forced ads permanently). Every payment is handled entirely by Apple or by Google. We never see or store your payment details — no card numbers, billing addresses or payment credentials ever reach us — and nothing about a purchase is sent to our backend at all. What you bought is not part of your game account and is not visible to us.

One value the app sends to the store, not to us. So that the app can tell a purchase made on this install from one made on another device, it generates a random install token on the device and passes it to Apple with each purchase. The token is random, it is not derived from your account, your email, your device identifier or your advertising identifier, it is never sent to our servers, and a reinstall creates a new one. Apple returns it with the purchase record, and the app uses it only to decide whether the one-time tokens that come with a pass or the Ultimate pack should be granted here.

What survives a reinstall. Power tokens and items in your backpack are held only in the app's own storage on that handset, so a reinstall or a second device does not carry them over and nothing can restore them. The Ultimate pack's permanent ad-free state and the current 30-day pass window are different: Apple and Google keep the purchase record, and the app reads it back at launch or when you tap Restore Purchases, on any device signed in to the same Apple or Google account. What comes back is the ad-free state only; the one-time tokens are not sent again.

9. Deleting your account and your data

You can delete your account from inside the app, without contacting us: open Settings, go to the Account tab, choose Delete account, and confirm. It is permanent and it acts only on the account you are signed in to.

What it removes, immediately and permanently:

What it does not remove, and why:

If you cannot use the in-app route — for example you played only as a guest, or you can no longer sign in — write to us at the address in section 17 and we will do what we can, though for guest scores that is limited by the paragraph above.

10. How long we keep data

Your account record, profile and posted scores are kept until you delete your account, or until we shut the service down.

How long we keep things. Scores — including guest scores, which have no account attached and so cannot be deleted on request — are kept for as long as the game is running, and are deleted when we shut the service down. Everything tied to an account goes immediately when you delete the account, and there is no backup copy for it to survive in: our database plan takes no automatic backups, so a deletion is final the moment it happens. Server request logs at Supabase are kept for one day; Cloudflare retains no HTTP request logs at all. Launch-notification addresses are deleted within 30 days of the launch email going out; feedback messages are deleted after 12 months (section 11).

11. The website 2048super.com

Since 15 September 2026 2048super.com is an information site about the game: how to play, questions and answers, this policy, the Terms and the support page. The browser version of the game has been retired. The site offers no sign-in of any kind, loads no analytics, sets no cookies, and carries no advertising. Cloudflare, which serves it, sees your IP address as with any website (section 6) and retains no request logs.

The launch notification. If you leave your email address in a “Notify me” box, we keep that address, the page you were on, the time, the language your browser reports and its user-agent string. We use them for one thing: to send you one email when the game is released on the App Store and Google Play. It is not a newsletter and we send nothing else. The legal basis is your consent, given by submitting the address; you can withdraw it at any time by writing to us (section 17), and the launch email carries a link that removes you. We delete the list within 30 days of sending that email.

The feedback form. It sends us what you type: the topic, your message, the language you play in and, only if you fill them in, your device and an email address, together with the page, the time and your browser's user-agent string. We use them only to read and answer your message; an email address, if you give one, is used only to reply. The legal basis is our legitimate interest in answering you. Messages are deleted after 12 months, or sooner if you ask.

Both are stored with Cloudflare (section 6). Neither is shared with anyone, used for advertising, or connected to a game account unless you ask us to look at yours. A hidden field on each form catches automated submissions, which are thrown away.

Before that date the site ran the game itself and, only with your consent, Google Analytics 4 (property G-B1Q9HDPE65). That tag is gone. Any cookie it set in your browser is now inert; you can delete it from your browser's site data. Google keeps the event-level data it already received for 2 months and visitor-level data for 14 months from the last visit, under its own policy.

Accounts created on the old website are the same accounts the app uses. If yours was made with Google or Apple, sign in to the app and it is there. If it was made with an email address and a password, the app cannot sign you in; write to us (section 17) and we will delete it, or the support page explains what else can be done.

12. Children

The game is not directed at children. It is a puzzle game with no violent or adult content, and no account is ever required to play — anyone can play entirely as a guest, with no email and no sign-in. We do not ask your age.

It does show advertising supplied by third parties, and we do not choose the individual ads.

We declare this app as not directed at children with Google, and with ironSource in its publisher settings, and we tell Google that its players are not to be treated as below the age at which consent is required. We also cap the rating of the ads Google may serve, so that advertising rated for mature audiences is excluded.

Unity Ads reaches you through ironSource rather than directly from us, so we send it the same declaration ourselves rather than assuming it is passed along.

One limit on all of this, which we would rather state than let you assume. Ads suitable for teenagers can still appear. We are limiting a rating, not reviewing each ad ourselves, and we do not choose the individual ads.

We do not knowingly collect personal information from children below the age at which consent is required where they live. If you believe a child has created an account, write to us and we will delete it.

13. Your rights

You can ask us to confirm what personal information we hold about you, to correct it, to add to it, to delete it, to stop using it, or to stop providing it to a third party. Write to the address in section 17 and tell us the email address or nickname on the account. We will reply within 30 days of receiving your request.

The fastest route for deletion is the in-app button in section 9, which acts immediately and needs no request.

Our legal bases, if you are in the EEA or the UK. We rely on performance of a contract for creating and running your account, storing your nickname, and publishing the scores you choose to post — that is the service you asked us for. We rely on our legitimate interests in keeping the service working, paid for and free of abuse for the server request logs and IP addresses in sections 2 and 6, and for showing advertising that is not personalised. We rely on your consent, given through the consent form and the tracking prompt described in section 4, for personalised advertising and for any tracking across other companies' apps and websites. Where we rely on consent you can withdraw it at any time and the ads simply stop being personalised; where we rely on legitimate interests you can object, using the contact address in section 17.

These rights are offered to every player, wherever you live. We do not ask what country you are in before honouring them. You can also object to how we use your information, ask for a copy of it in a portable form, and complain to the data protection authority for your own country. If you are in Japan, complaints about our handling of personal information can be sent to the address in section 17, which is our complaints contact for the purposes of the Act on the Protection of Personal Information.

14. Security

Data travels over encrypted connections. Writing to the database is restricted by server-side rules: you can only write a score under your own account identifier, and you can only change your own profile. Deleting an account uses a server-side function that takes whose account to delete from your own signed session and never from the request, so nobody can delete anyone else's account. Your sign-in session is stored on your device; signing out asks the server to invalidate it as well as removing it locally. Administrative access to the backend is held only by the developer named at the top of this page. No system is perfectly secure, and anything you post to a leaderboard is public by design.

15. Changes to this policy

If we change this policy we will post the updated version on this page with a new effective date. When a change is material — we collect something new, or share it with someone new — the app asks you to read and accept the documents again the next time you open it. A revision that only describes the app more precisely, like this one, does not. The effective date at the top always tells you when the policy was last revised.

16. Summary for the App Store privacy labels

This section restates the sections above in the categories Apple uses on the App Store product page, so the two can be checked against each other line by line.

Data Used to Track You. These labels describe the iOS app. For players who allow tracking when iOS asks, the Device ID above is used for tracking as Apple defines it, and the advertising data and product interaction the ad networks collect may be used for advertising measurement across companies. For players who decline, iOS withholds the advertising identifier and the app marks every ad request as non-personalised, so nothing here is used to track you. The Android app is different, and this line is not a claim about it: Android has no tracking prompt, so outside the regions where Google's consent form applies the advertising ID is available to the ad networks and the ads are personalised. See section 4.

17. Contact

Questions, deletion requests, complaints, or a request for the cross-border transfer details in section 6:

Contact: [email protected]

Personal information manager and representative: Chan Hon Ming Vincent