CubeScan Privacy Policy
Effective date: July 21, 2026
This Privacy Policy applies to CubeScan for Android, package
com.localrubik.solver, and CubeScan Solver for iOS, bundle
identifier com.jppjff.cubescan.
Summary
CubeScan solves a physical 3x3 cube primarily on your device. Camera frames and generated solution moves are processed locally and are not uploaded to CubeScan or Firebase. A cube state is uploaded only when an Android user deliberately creates or accepts an optional Rescue this cube challenge, as described below; camera images are never part of that upload.
The Android app uses Google Firebase Remote Config to deliver bounded scanner and interface settings. Android users may also choose to share anonymous usage events and crash diagnostics through Firebase Analytics and Firebase Crashlytics. Those optional diagnostics are off until the user allows them in the app. Android builds that include advertising use Google Mobile Ads and Google's User Messaging Platform (UMP) to request consent or privacy choices where required and to show app-open or interstitial ads. Android users may make a one-time Google Play purchase for Pro mode, which removes those ads. Android also offers user-initiated success-card and solve-video sharing, Google Play Install Referrer attribution, and—when the feature is securely enabled—Rescue challenge links backed by Firebase Authentication and Cloud Firestore.
CubeScan Solver for iOS 1.0 does not include Firebase, analytics, crash reporting, advertising, accounts, or another network service. Its scan, cube state, and solution remain on the device.
CubeScan does not sell personal data, require a named account, or upload cube content for advertising. Rescue challenges use a pseudonymous Firebase Anonymous Authentication user ID, but CubeScan does not set a Firebase Analytics user ID and does not ask for a name, email address, or password. CubeScan Solver for iOS 1.0 does not show ads or use an advertising identifier. On Android, Google Mobile Ads may process advertising or device identifiers when available and permitted by the device, consent choices, and applicable law.
Camera and Cube Data
CubeScan requests camera permission when you choose live scanning. While the scanner is visible, on-device computer vision finds the cube face and samples nine regions in memory to identify sticker colors.
- Camera frames are not intentionally saved, added to your photo library, or uploaded.
- Detected colors, manual corrections, the cube state, and solution moves remain in local app storage unless you deliberately create or accept a Rescue challenge. Rescue uploads only the compact facelet state described below, never camera frames or solution notation.
- Camera processing stops when you leave the live scanner.
- You can decline or revoke camera permission and use manual entry instead.
You can clear cube data with Reset, clear CubeScan storage through the operating system where available, or uninstall the app.
On first run, Android asks you to choose one intended-use category, accept the current Terms of Use, and make a separate optional diagnostics choice. The intended-use category, Terms version, acceptance time, onboarding stage, and diagnostics choice are stored locally on the device. The intended-use category and Terms-acceptance metadata are not sent to Firebase Analytics, Crashlytics, Google Mobile Ads, or a CubeScan server.
Solve Cards, Sharing, and Referral Attribution on Android
After a solve, CubeScan creates a success-card image locally. It contains a solved 3D cube graphic, the number of generated moves, a statement that solving occurred privately on the device, the CubeScan logo, a QR code, and a Google Play link. It does not include the scanned cube state, solution notation, camera content, a person’s name, contact information, or an estimated solve time. The on-screen preview stays in memory. When you choose to share, CubeScan writes a private temporary PNG to its app cache so Android can grant the selected app read access.
You may instead generate a 7.2-second vertical MP4 replay. CubeScan reconstructs the scanned cube and generated moves locally, renders the animation on the device, and writes the result to a private cache directory. The video visually shows the cube state changing from its scanned state to solved, so anyone you share it with can see those colors and moves. It does not contain camera frames, a name, contacts, or measured solving time. CubeScan limits the video cache by file count and total size.
Share PNG and MP4 files older than 24 hours are removed during a later CubeScan startup, video export, or share cleanup. Removal is therefore not guaranteed at the exact 24-hour mark if CubeScan is not opened again. Android may clear these cache files sooner.
When you tap Share my solve, CubeScan lets you choose the success-card image, solve video, or an available Rescue link, then gives only the selected content and link to Android Sharesheet. Cached media is shared using a temporary read-only content URI. The external app you select processes that content under its own terms and privacy policy. Android may return the selected destination to CubeScan; if optional diagnostics is enabled, CubeScan reduces it to a fixed category such as WhatsApp, Instagram, TikTok, WeChat, Messages, email, or other. CubeScan does not receive the selected recipient, Direct Share contact, delivery status, message contents, or proof that the content was sent or opened.
The ordinary solve-card Play URL contains only fixed campaign fields; it does not contain an account, advertising identifier, cube data, or unique inviter token. An optional Rescue URL instead contains one random 32-character challenge code. The code is a lookup key and does not contain the cube colors, but a person who has a valid unexpired link can ask the authenticated app to retrieve that challenge. If CubeScan is not installed, the same opaque code may be carried in the Google Play Install Referrer so the app can offer the challenge after installation.
On first execution after a Play install, CubeScan asks Google Play Install Referrer for the install referrer, recognizes only CubeScan's supported solve-card or Rescue campaigns, stores the bounded campaign result and any valid Rescue code locally, and closes the connection. CubeScan does not send the raw referrer to Firebase Analytics. If optional diagnostics is enabled, Firebase Analytics may receive aggregate referral and sharing events, but never the challenge code or cube state. If diagnostics is declined, those analytics events are not sent. Rescue's necessary Authentication and Firestore processing is separate from optional diagnostics.
Rescue Challenges and Temporary Referral Rewards on Android
Rescue is available only when CubeScan's secure server-side release gate is enabled. Creating a challenge is a deliberate action. CubeScan signs the installation in to Firebase anonymously and uploads a 54-character facelet representation of that one cube, a random challenge code, the anonymous inviter ID, status fields, and creation/expiry timestamps to Cloud Firestore. The facelet string uses only the six cube-face letters; it is not a photo and does not contain solution notation.
When another installation explicitly accepts the link, CubeScan uses its own anonymous Firebase ID to retrieve and claim that state. Firestore records the inviter and recipient anonymous IDs, challenge code, claim status, and claim timestamp. If that recipient completes its first accepted guided Rescue solve, Firestore also records a completion timestamp and a bounded generated move count. CubeScan does not send a name, email address, phone number, contact, selected share recipient, raw Sharesheet target, camera frame, or solution notation with a challenge. A challenge can be claimed only once and cannot be claimed by its creator. One anonymous recipient identity can hold only one first-Rescue claim while its 90-day deduplication record is retained.
Challenge records are scheduled to expire after 7 days. Recipient claim/completion records are scheduled to expire after 90 days so CubeScan can deduplicate a first Rescue solve and verify the inviter's reward. Firestore time-to-live deletion is asynchronous, so a record may remain for a period after its expiry time; expired challenge records cannot be used through the app's security rules. Clearing app data or uninstalling removes the local anonymous credentials and pending link, but does not immediately delete an existing Firestore record. Cloud records instead follow these expiry schedules or an applicable legal/deletion request.
The inviter receives exactly 24 hours without CubeScan ads only after Firestore confirms the referred recipient's first completed Rescue solve. A click, link open, install, or claim does not earn a reward. The 24 hours run from the server-recorded completion time, do not accumulate into a permanent entitlement, and are separate from the one-time Google Play Pro purchase. CubeScan uses server-derived time and a bounded local verification cache to enforce the window; it does not send the reward or challenge content to Google Mobile Ads.
CubeScan uses Firebase App Check with Play Integrity in release builds, anonymous authentication, unguessable codes, denied list access, atomic claim/completion rules, and bounded move-count and timing checks to reduce automated abuse. These measures cannot prove that a person physically turned a cube. A user who clears app data may receive a new anonymous identity, and expiry of the 90-day claim record means lifetime “first ever” deduplication is not guaranteed. Anyone with the bearer link can attempt to claim it before it expires. Rescue should not be used to store sensitive or identifying information.
Firebase Remote Config on Android
CubeScan contacts Firebase Remote Config to receive operational settings such as detection stability, frame-analysis cadence, confidence thresholds, animation timing, whether video help is available, and whether new Rescue links may be created or accepted. The Rescue default is off. The app includes safe local defaults, restricts each setting to an expected type and range, and does not store secrets or user-entered content in Remote Config.
Firebase may process a Firebase installation identifier, IP address, and technical request metadata to provide this service. Remote Config does not receive camera frames, sticker colors, cube states, or solution moves.
Advertising and Consent on Android
Android builds that include AdMob may show a closeable app-open ad during an eligible startup opportunity, a closeable interstitial at an eligible transition after a valid Solve request, and an eligible Finish interstitial only after the user leaves the success card by choosing Solve another cube. No ad is shown immediately when the final move completes. Missing consent, unavailable inventory, timeouts, load failures, or dismissal do not prevent access to the scanner or solver.
CubeScan asks Google's UMP service to update consent information on launch and displays a consent form when required. Advertising requests begin only when UMP reports that ads may be requested. When Google requires a privacy-options entry point, it is available from CubeScan's privacy settings. The ads shown and the information used may depend on your region, device settings, age-related settings, consent choices, and Google's serving rules.
To request, deliver, measure, limit fraud, and diagnose ads, Google Mobile Ads and UMP may process information such as:
- Advertising or other device/app identifiers when available and allowed.
- IP address and network-derived approximate location.
- App name/version, device model, operating system, language, network, and technical request information.
- Ad requests, impressions, interactions, presentation errors, and diagnostics.
- Consent and privacy-choice status needed to apply advertising rules.
CubeScan does not add camera frames, sampled colors, sticker arrays, cube facelets, solution notation, user-entered text, contact details, or a developer-set user ID to ad requests. Public debug builds use Google's sample identifiers and contain no advertising test panel. An unshipped internal-QA build may use real CubeScan identifiers only after the SDK verifies that the current phone matches the registered test-device list; otherwise the app blocks every ad request. That developer-only QA surface is excluded from public debug and release builds. Test-device identifiers are not published, and testers are instructed to verify test mode and never click live ads.
If Pro mode or a verified temporary Rescue reward is active, CubeScan does not initialize Google Mobile Ads in a new app process or make ad requests, retries, refreshes, or presentations. If the SDK was initialized before the entitlement became active in the same running process, CubeScan clears its ad inventory and performs no further ad work. When an installation that may have earned a Rescue reward cannot obtain an authoritative status and has no still-valid verified cache, CubeScan withholds ads rather than risk showing one during an earned window.
Pro Purchase on Android
CubeScan Pro is an optional one-time, non-consumable purchase provided by Google Play. The app asks Google Play for localized product information, opens Google Play's purchase screen when you choose to buy, and queries your currently owned one-time products on launch and foreground so an existing purchase can be restored on another Android device using the same eligible Google Play account.
Google Play processes the purchase, payment method, receipt, purchase status, and fraud/security signals under Google's terms and privacy policy. CubeScan receives purchase metadata from the Play Billing service, including the product identifier, purchase state, acknowledgement state, purchase token, and order-related metadata supplied by the service. CubeScan uses this only to grant or restore Pro, acknowledge delivery, handle pending purchases, and remove ads. It does not send a purchase token to Firebase Analytics, Crashlytics, Remote Config, Mobile Ads, or a CubeScan server. The current app has no Pro purchase-verification backend and does not associate Pro purchase metadata with a Rescue anonymous ID.
CubeScan stores a local yes/no Pro entitlement after Google Play confirms a completed purchase so ads remain blocked before the next ownership check. Clearing app data removes that local cache; Google Play can restore the entitlement when the app reconnects. Pending or canceled purchases do not activate Pro. Refunds and revoked ownership are reflected after a successful Google Play ownership refresh. A 24-hour Rescue reward never creates, restores, replaces, or extends this permanent Pro entitlement.
Optional Analytics on Android
If you select Allow or enable diagnostics from the lock icon, Firebase Analytics may collect:
- Coarse product interactions, such as opening a fixed app screen, confirming a face, viewing rotation guidance, requesting a solution, advancing a move, completing a solve, resetting, or opening video help.
- Fixed technical categories, such as automatic versus fixed-guide detection and a low, medium, or high confidence bucket.
- Coarse counts and timing, such as completed-face count, move count, and solver duration.
- Success-card views, selected share formats, local solve-video creation, native-share taps, a bounded selected-destination category, matched campaign installs, Rescue challenge funnel steps, a referred user's first guided solve, and activation of a temporary referral reward.
- App, device, operating-system, language, and general network-derived location information that Firebase automatically processes for analytics.
- A Firebase-generated app-instance or installation identifier.
Analytics events never include camera images, RGB samples, sticker-color arrays, cube facelets, solution notation, challenge codes, anonymous Firebase Authentication IDs, user-entered text, contact details or Direct Share recipients, raw receiving activity names, raw Install Referrer strings, full ad-unit identifiers, advertising auction/response payloads, an advertising identifier, or a developer-set Analytics user ID.
Automatic Firebase screen reporting, Firebase Analytics Advertising ID collection, and Analytics ad-personalization signals are disabled. This does not describe the separate data processing performed by Google Mobile Ads as disclosed above. CubeScan's custom events and screen names use a fixed allowlist. After you opt in, Firebase Analytics may also record its standard app-lifecycle events, such as first open, app update, session start, and user engagement.
Optional Crash Diagnostics on Android
If diagnostics are enabled, Firebase Crashlytics may receive crash and non-fatal diagnostic information, including stack traces, app and device state, operating-system details, app version, timestamps, Firebase installation identifiers, and fixed technical context such as the active app screen, scan phase, selected face name, completed-face count, camera pipeline, and configuration schema version.
CubeScan sanitizes handled camera and solver exceptions before reporting them and does not attach camera frames, sticker data, cube states, solution contents, arbitrary user text, or Firebase user IDs.
Your Choices
On Android, CubeScan asks whether you want to share optional usage and crash diagnostics. The app remains fully usable if you choose Not now. That choice controls Firebase Analytics and Crashlytics, not UMP advertising consent. CubeScan Solver for iOS 1.0 does not present a diagnostics choice because it does not include those services.
Rescue Authentication and Firestore requests are needed only when you create, accept, complete, or receive a reward from a Rescue challenge. They are functional processing, not optional Analytics, and are not enabled by the diagnostics choice. You can avoid this processing by not creating or accepting Rescue links and can cancel before an imported challenge replaces the current scan.
You can change the setting at any time using the lock icon in CubeScan. Turning diagnostics off immediately disables Analytics and Crashlytics collection, resets Analytics data held by the app on the device, and deletes unsent Crashlytics reports. Data already received by Google or the developer may remain according to Firebase project settings, legal requirements, backups, and Google's retention processes.
On Android, Remote Config remains active because it supplies operational app settings. When UMP requires a privacy-options entry point, you can reopen Google's choices from CubeScan's privacy settings. Device-level advertising controls may also be available in Android settings. Changing a choice may affect personalization or eligibility but does not necessarily remove all advertising where another permitted serving mode applies. Purchasing Pro removes CubeScan's ads; choosing Not now leaves the app fully usable in its regular ad-supported mode.
You can stop network access by denying it at the operating-system level, clearing app data, or uninstalling CubeScan; the scanner and ordinary solver retain compiled defaults and remain local when network services are unavailable. Rescue link creation, retrieval, completion verification, and reward refresh require network access. Clearing app data does not itself delete already-created Firestore records; those follow the stated 7-day and 90-day expiry schedules.
Service Provider and Disclosure
Google provides Google Play Billing and Install Referrer, Firebase Remote Config, Anonymous Authentication, Cloud Firestore, App Check with Play Integrity, Analytics, Crashlytics, UMP, and Google Mobile Ads. Data may be processed on Google's infrastructure under the Google Privacy Policy, Google Play Terms of Service, How Google uses information from sites or apps that use its services, Firebase privacy and security terms, and Google's advertising/privacy controls.
CubeScan does not sell personal data or provide camera/cube content to advertisers or data brokers. Google processes advertising information as described above to provide the advertising service. Information may also be disclosed when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.
External Video Help
If you tap a video-help action, CubeScan opens an allowlisted YouTube search URL in your browser or YouTube app. The external service may collect data under its own policy. CubeScan does not receive your YouTube activity back from the browser or YouTube app.
Security
CubeScan limits app-defined telemetry to fixed fields, processes ordinary cube content locally, uses HTTPS network services, limits Rescue data to pseudonymous fixed-schema records, and separates Firebase diagnostics consent from advertising consent. Rescue uses anonymous identities rather than a named user-account profile. No transmission or storage system can be guaranteed completely secure.
Children's Privacy
CubeScan is a general puzzle utility and is not directed to children under 13. It does not knowingly request names, email addresses, or other direct identifiers from children. Optional diagnostics can be left off. A parent or guardian may contact the developer about a privacy concern.
Changes
This policy may be updated when CubeScan's features, providers, or data practices change. A revised policy will show a new effective date.
Contact
For privacy questions or deletion requests, contact the developer
using the contact email shown on CubeScan's Google Play or App Store
listing. Include CubeScan privacy in the subject and do not
include camera images or cube data unless specifically requested.