Gulp
There is no Gulp account, and no server of ours. Every board — the journey's, the day's daily and endless — is generated or read on your device, and your progress is written to a database on it. Nothing you solve is sent anywhere, and there is nothing in this game you type.
Two things do leave the device, both about the game rather than about you, and both switchable: crash reports, and usage events. Both switches are in Settings › Data, both are read before anything is collected, and in the EEA, the United Kingdom and Switzerland both start switched off. Section 3 is the whole of it.
Gulp shows ads to players who have not bought Gulp Unlocked. They are served by AppLovin, which is a company separate from us, and serving them involves an advertising identifier that leaves the device — the one thing in this policy that is shared with a third party for their own purposes. Section 4 says exactly what, when and to whom. On a device that has bought the unlock the ad code is never started at all, so nothing in section 4 happens on it.
1. What the game stores on your device
All of it lives in app-private storage — a local database and a settings file — readable by Gulp and not by other apps. Uninstalling takes every bit of it with you.
- Your progress: which levels are open and solved, the stars on each, your best tap count, and the chapter you are in
- Your position in a level, stored as the taps you have made rather than as a board, so reopening the app replays them and lands you exactly where you stopped
- Your statistics: levels solved, taps, snakes eaten, your longest snake, and your daily streak with any freezes it has earned
- The daily boards you have opened, kept once built so that a change to the generator never rewrites a day you have already seen, and a list of the endless boards you have played, held as board fingerprints so a new one is not a repeat
- Your hint and skip banks, and the moment each last refilled
- Your settings: theme, snake skin, sound, music, haptics, animation speed, the stuck chip, colour-blind cues, reduce motion, large targets, left-handed buttons, the language, and the two diagnostics switches
- The screen you were last on, so a cold start opens where you left off
- Whether the unlock has been bought, as last reported by the store. It is kept device-local.
None of it identifies you, because none of it is asked for. There is no name, no email, no
profile and no sign-in anywhere in this game, and no free-text field a player can type into.
There is no backup or export file: Reset progress in Settings says so in as many
words before it deletes anything.
Your device's own backup
On Android, the game allows the platform's own backup, so if you have Android backup switched on, your device may copy the app's files into your Google account backup along with everything else on the phone. That is Android's backup of your device, made with your own account and governed by Google's terms — we neither see it nor hold a key to it. On iOS the same is true of an iCloud or an encrypted local device backup. Turning device backup off, or excluding the app from it, stops that copy being made.
2. Permissions, and exactly what each one is for
| Permission | What Gulp does with it |
|---|---|
| Vibrate | The tick under a tap. Granted at install, never asked for, and idle while the haptics setting is off. |
| Internet Network state |
No board needs a connection: every one is generated on the device or bundled with the game, including the daily. It is here for the store — the purchase, the restore, the update check and the rating sheet — for the crash and usage reporting in §3, which the two switches in Settings › Data turn off, and for the ads in §4. |
| Advertising ID Android only |
Read by the ad SDK to serve and measure the ads in §4, and used for nothing else. It was removed from the shipped manifest while the game carried no ads; it is declared now because the game does. Google's own analytics collection of it stays switched off in the build, so this identifier is the ad SDK's and no one else's. A device that has bought Gulp Unlocked never starts that SDK, so nothing reads it there. |
That is the whole list. There is no Privacy Sandbox advertising permission, because nothing in the game calls those APIs; no notification permission, because there is no reminder and the game never pushes anything at you; no storage permission, because there is no file to write; and no permission for location, contacts, the camera, the microphone, the phone, all-files access, or for listing the other apps you have installed.
3. Crash reports, and usage events
Two separate switches, both in Settings › Data. Either can be turned off at any time, permanently, from that screen. They are honoured before anything is collected rather than after: all three collectors ship disabled in the app's own manifest and property list, and are switched on only after the stored preference has been read. A player who turns one off is off from that moment, and stays off across launches.
Both switches start off in the EEA, the United Kingdom and Switzerland, and on elsewhere. A device that names no country at all takes the cautious side and starts off too. Either way the switches are yours, in both directions, from the first launch.
Settings › Data › Send crash reports
When the game crashes or hits an error it handled, a stack trace, the device model, the operating system version, the app build and the game's own breadcrumbs go to Firebase Crashlytics so the fault can be fixed. The switch's own subtitle is the promise: stack traces only, and off means nothing is sent at all.
Settings › Data › Send usage events
This one switch covers Firebase Analytics and Firebase Performance together. Its whole vocabulary is written out in the code as the only names an event may carry:
- Which screen is open — one of map, play, daily, endless, stats, settings or paywall
- What happened on a board: a level started, won, skipped or abandoned; a stuck chip shown; an undo back to a solvable position; a hint used; an ouroboros; a daily solved; an endless solved; the tap budget spent; a hint or skip bank run empty; the paywall opened; a setting changed; a purchase; and a store receipt that failed to verify
- The parameters those carry, and no others: a level id, a mode, a tier, a band, a tap count, a par, a star count, a hint count, a restart count, a duration in milliseconds, a source and which surface opened the paywall
- Four timings: how long a hint search, a dead-end check, a daily board and an endless board take to compute, plus the platform's own app-start and frame measurements
- The Firebase app-instance ID, which is what makes two events from one install countable as one session. It is the SDK's own identifier: it names an installation rather than a person, it is reset when the game is reinstalled or its data cleared, and there is no account in this game to join it to.
None of what these two switches send is shared with anybody. Nothing here profiles anyone, and nothing is joined to data from any other company or app. The ads in §4 are the one place data does go to a third party, and they carry none of the events above. Everything sent goes over HTTPS. Google acts as our processor for these reports, and their handling of them is covered by Google's own privacy terms.
Neither switch can carry a board, a position, a solution or anything you chose to name, because nothing in this game is typed by a player and every analytics parameter comes from the fixed list above.
4. Advertising
Gulp shows ads only to players who have not bought Gulp Unlocked. They are served by AppLovin, using its MAX SDK, and there are exactly two places they appear: a banner strip along the bottom of the board while you are playing a level in portrait, and a full-screen ad between levels, after every fifteenth board you clear. There is no ad on the map, the daily calendar, the endless screen, the statistics or the settings, there is no ad when the game opens, and no ad ever interrupts a board you are in the middle of.
Nothing in this game is earned by watching an ad. There is no rewarded ad, so no hint, no skip and no level is ever behind one — the meters in the game are bought with time or with the unlock, never with attention.
Ads also wait until you have played a while: the banner does not appear until you have finished the first chapter, and the full-screen ad until you have finished three. Until then the ad SDK requests nothing.
What is shared, and with whom
To choose and measure an ad, AppLovin receives an advertising identifier along with the ordinary technical facts of a request — device model, operating system version, language, coarse region, and the fact that this app asked for an ad. On Android that identifier is the Google advertising ID, which you can reset or delete in the system settings. On iOS it is the vendor identifier, which is reset when you delete the app.
Gulp does not ask for App Tracking Transparency permission on iOS. The prompt is never shown, so the IDFA — the identifier that would let advertising follow you across other companies' apps — is never available to the SDK, and attribution is left to Apple's own SKAdNetwork, which reports installs without identifying a person. In Apple's terms the app does not track you, which is why its privacy manifest declares no tracking.
In the EEA, the United Kingdom and Switzerland the app tells the SDK it has no consent for personalised advertising, and on top of that sets the do-not-sell signal. Ads there are non-personalised: they are chosen from the request itself rather than from any profile of you. That is the same posture the two switches in §3 take in those regions, and it is set by the app rather than left to a consent form.
AppLovin handles what it receives as its own controller, under its own privacy policy, not as our processor. We receive no advertising data back beyond aggregate counts of ads shown and revenue earned, which name nobody. Ads are never shown a board, a position, a solution, your progress, or anything from §1 or §3 — the ad request carries none of it.
Turning them off
Buying Gulp Unlocked removes them, permanently and on every future version. This is not a setting that hides an ad after it loads: on a device that owns the unlock the ad SDK object is never constructed, so it is never started, never asked for an ad, and never reads an identifier. That is a property of the purchase rather than of this release.
You can also limit what the identifier is worth without buying anything: Android's Settings › Privacy › Ads lets you delete the advertising ID outright, and iOS's Settings › Privacy & Security › Tracking is already moot here because Gulp never asks. Ads still appear either way; they simply have less to go on.
5. Buying Gulp Unlocked
The unlock is one purchase, once — a non-consumable — made through Google Play Billing on Android or StoreKit on iOS. Both run in the store's own process, not in ours: the game never sees or stores a card, a billing address or a store account name. There is no server of ours in the path. On Android the signed purchase token is checked against the app's licensing key on your own device, and nothing about that check leaves the phone; the entitlement is then cached locally, which is also why a purchase keeps working with no connection.
The unlock also removes every ad in §4, which is the one thing it takes away rather than adds. Restoring on a new device asks the store, not us. What the store collects in the course of a purchase is governed by Google's or Apple's privacy policy, not by this one. No level is behind the purchase, so nothing you have played becomes unplayable if a store ever fails to answer.
6. What you can do with your data
- Turn either switch off in Settings › Data. Collection stops from that moment, and Firebase resets the app-instance ID rather than carrying it forward, so what is sent afterwards is not joinable to what was sent before.
- Reset progress in Settings › Data, which deletes every star, best and statistic on the device. It asks twice, and it warns you that there is no backup.
- Delete or reset the advertising ID in Android's Settings › Privacy › Ads, which is a system control and applies to every app. On iOS there is nothing to reset, because Gulp never asks for tracking permission and so never has the IDFA.
- Buy Gulp Unlocked if you would rather the ad SDK never ran at all — see §4.
- Uninstall. That removes everything the game kept on the device. Because we never held a copy, there is no server-side record to ask for the deletion of, and no deletion URL to send you to. Crash reports already sent can be deleted on request — write to the address in §9.
7. Children
Gulp is a puzzle game for a general audience and is not directed at children under 13. It has no social features, no messaging, no user profiles and no accounts, and it asks no one for a name, an email address or any other personal detail, at any age. Because it is not a child-directed app it is not in Google Play's Designed for Families programme, and the ads in §4 are ordinary advertising rather than the child-safe kind that programme requires. If you are setting the game up for a child, buying Gulp Unlocked removes the ad SDK entirely.
8. Changes to this policy
If what the game stores or sends changes, this page changes with it and the date at the top is updated. Anything that would move an answer here — an identifier of any kind, a cloud copy of your progress, a push service, or a third-party framework this page does not name — is a change to the product's own promises, not merely to its wording, and it is announced here before it is relied on. The advertising in §4 is the one time that has happened: the game shipped with no ad SDK at all, and this page said so until 8 September 2026.
9. Contact
Questions about this policy, or about anything Gulp stores: support@crackoncloud.com