TINY ESCAPE

Tiny Escape · Your player data

Privacy Policy

Local play keeps your game progress on your device. Optional online features are available only to players aged 18 or above.

Effective September 15, 2026 · Covers the Tiny Escape website, Android game, and their connected game services.

About Tiny Escape

Tiny Escape is developed and operated by Guy Lahav. For privacy questions, contact glahav2@gmail.com.

Tiny Escape offers local arcade getaways, earned cosmetic trails, and a discoverable crown. Adults can also enable Daily Heist, friend challenges, Snack Clubs, and shared result cards. There are no ads, in-app purchases, or email/password/social sign-in in this version.

Online features use a guest identity remembered by your browser or app installation. That identity is pseudonymous: the service can associate game records with the same guest without knowing your real name.

Play first; online setup when you choose it

You can start a local getaway without registration, an age question, or a Terms acceptance screen. Until online play is enabled, runs, best scores, snacks, cosmetic unlocks, and crown remain on your device.

If you choose an online action such as Challenge Friends, Daily Heist, Clubs, or Share, the game asks for an age range before connecting. You can also open PLAY SETTINGS. No date of birth is requested. Closing the setup or choosing to keep playing locally without selecting an age leaves your age unknown, and you may open setup again later. Players who choose an under-18 range or prefer not to give an age use local play; those choices cannot be switched directly to an adult age in the game.

Local play does not create an online guest or send game records to the game service. Daily Heist, online rankings, profiles, friend challenges, clubs, uploads, public result sharing, and crown synchronization do not run while online play is disabled. Invitations do not connect automatically, and the game blocks external links and the device share interface in local mode.

Players who select 18 or above may read the linked Terms of Play and this Privacy Policy, then choose AGREE & ENABLE ONLINE. This action accepts the Terms and acknowledges the Privacy Policy before enabling online features; no separate signature or registration is requested. Your choice is remembered on this device, and an existing adult guest can be reused. Online requests include confirmation that adult online access has been enabled; they do not send the selected age range or a date of birth. This is an adult access choice, not a parental-consent service for children.

The Android app bundles local game assets and does not intentionally call the game API during local play. Visiting the website still involves requests to its hosting provider, which processes network metadata as described below. Choosing RETURN TO LOCAL PLAY does not erase online records from an earlier adult session; use the deletion controls or contact support to request removal.

What stays on your device

The Android app bundles game code, images, fonts, and legal pages so local getaways can work offline. The browser game uses local storage; the Android app uses native preferences and local game storage. These hold your age-range choice, online-feature choice, best score, earned snacks, cosmetic choices, crown, and sound setting. Adult online play can also keep pending submissions locally.

After an adult enables online features, a locally stored guest token authorizes connected actions. The app installation and browser can have separate guests; progress does not automatically follow you across devices. Keep the token private. Local mode does not send a previously stored token or retry pending online submissions.

Clearing storage or uninstalling can remove local progress and guest access. It does not, by itself, delete records already saved by the online service.

What adult online features send and save

  • Guest identity: a random player ID, generated name or optional nickname, creation time, and a stored hash of the token used to authenticate your guest.
  • Gameplay records: daily and friend attempt IDs, routes and game versions, start/finish times, scores, hops, and relevant snack and clean-crossing summaries.
  • Friend records: challenge participation, results, rematch relationships, and records used to show rivalry history.
  • Club records: club names, ownership, invitation codes, memberships, and join/leave times used for scoreboards.
  • Cosmetics: crown discovery and equip state when synchronized.
  • Shared results: a snapshot of the name, run details, and associated result or challenge when a public card is created.
  • Safety controls: the reporting guest, reported player or club, selected report reason and time, name-protection flags, and player or club blocking choices. In-app reports use predefined reasons, without a free-text message field.
  • Deletion credentials: the hash and expiration of a deletion code when you request one.

These records make selected online features work, protect guest access, validate runs, enforce attempt limits, display results, and operate reporting and blocking. After an adult enables online features, opening connected screens can create or refresh a guest; an existing profile and crown state can synchronize automatically.

Finishing an ordinary getaway or opening its results does not by itself publish a result card. An adult must choose Share to create the associated online result or challenge. Daily and friend modes send their scored results as part of those online activities.

Scored runs, shared ordinary runs, and crown verification send move recordings to the server. The game replays them in memory and stores resulting summaries. Its application code does not deliberately save raw move recordings to the game database. Pending recordings may remain on the device while awaiting synchronization in adult online mode.

What other adult online players can see

Daily rankings show player names and scores. Challenge participants see relevant results and rivalry history. Club members see names and scores on their club boards. Club invitations identify the club before someone joins.

Anyone who accesses an enabled public result link can see its captured player name and run details. A card is a snapshot: an ordinary nickname change does not rewrite an older card. Moderation protections may change the name displayed. Full player deletion removes associated cards from the service.

Reporting a player or club name replaces its displayed name with a generated game name and restricts further name edits. Blocking a player filters that player from your boards and prevents challenges between you. Blocking a club leaves it and prevents rejoining while the block remains. These controls do not recall copies already saved outside the service.

Do not put private information into a player name, club name, or anything you share. See Terms of Play for the rules and appeal route.

Sharing and device permissions

When an adult in online mode chooses to share, the game sends the selected image, message, or link to the destination you choose in the platform share interface. That service handles the content under its own practices. Images prepared for sharing may be written to a temporary local file.

The game does not request your device address book, location, microphone, or camera. It stores in-game friend relationships, which are different from reading your device contacts. The current Android app does not include an advertising or remote analytics SDK.

Game statistics

The owner can view combined counts and averages from adult online game records, such as Daily Heist attempts, friend runs, new guests, and shared cards, to understand game use and improve the experience. These summaries use records already saved for those online features.

Adults who enable online play can separately choose Share optional usage statistics in PLAY SETTINGS. It is off by default and is not needed to play online. If enabled, visits, run starts, replays, completed or otherwise ended runs, scores, hops, playing time, game mode, and obstacle type are sent over HTTPS to the game service. The existing guest token authenticates these requests; they are not anonymous network requests. No new analytics identifier, advertising ID, location, contact information, raw move recording, or free text is included in these statistics.

The analytics table stores daily combined counts, sums and maximums by game mode, broad distance band, obstacle and destination. It does not store per-player or per-session event records. These aggregate rows become eligible for deletion after 90 days; cleanup runs when statistics are received or the owner opens the dashboard. Aggregate totals cannot be traced back and removed for one guest. Existing online records, hosting metadata, logs and backups remain subject to the separate retention rules below.

Turning optional statistics off stops future statistics requests and cancels pending requests on that device. Activity is never queued for later upload. Runs started before opt-in are not uploaded afterward. Children, unknown-age players and local players send no optional statistics. There is no third-party analytics SDK, advertising, cross-app tracking or sale of these statistics.

Hosting and security

The website is delivered through its hosted Sites service and Cloudflare infrastructure, with Cloudflare D1 used for online game records. Website requests and adult online requests can include IP addresses and ordinary request metadata. Hosting a website necessarily involves network requests even when its game is in local mode. The backend also logs unexpected service errors.

Game API requests use HTTPS. The game database stores hashes of guest tokens and deletion codes rather than the raw credentials. Your device keeps the token it needs to authorize requests.

Hosting providers may keep operational and security logs, and Cloudflare D1 provides database recovery history. These systems can retain information separately from the active game database under their own retention and deletion processes. Removing a player from the active database does not immediately erase provider logs or recovery copies.

How long records remain

Local progress remains until you reset or clear it, or uninstall the app. Adult online game records are kept to maintain rankings, friend history, clubs, and shared links until full player deletion. There is no general automatic age-based deletion schedule for those game records. Leaving a club can preserve its historical score record.

In-app content-report records are eligible for cleanup after 180 days. Cleanup runs when the service is used, so removal may occur after that period rather than at an exact deadline. Name-protection flags remain until associated deletion or a support action. Blocking records remain until unblocking, associated deletion, or a support action.

A deletion code expires after 24 hours and cannot be used afterward. Its database record may remain until a replacement code is created or the guest is deleted.

Full deletion removes associated records from the active game database. It does not create a functional archive of the deleted player. Provider logs and recovery copies are separate; immediate erasure from those systems is not promised.

Delete local progress or online game records

For local play, use the app’s local reset control or clear its storage. There is no online guest created by local play. A parent or guardian can contact Guy Lahav about privacy or data from an earlier online session without enabling online play for a child.

For an adult online guest, use Delete player data for the web deletion flow. In the Android app, open Privacy and player data, expand Delete player and progress, type DELETE, and confirm.

You can also generate a private deletion code in the app and use it on the website within 24 hours. It works once; a new code replaces the previous one. Save it before uninstalling if you intend to use it later. The deletion page can use an authenticated guest from the same browser without a code.

Full deletion removes your guest identity and token, nickname, daily attempts, crown state, memberships, owned clubs and their memberships, hosted or reserved rematch rounds and their associated results/cards, your other friend runs and reports, and deletion credentials. Related shared records can disappear from friends' histories; unrelated player identities remain.

Deletion through the Android app also clears its associated local progress and preferences. Deletion by an external code does not remotely clear a device: reset the app's local data separately. Copies of images or messages already saved or forwarded by other people cannot be recalled.

Already uninstalled or lost your code?

Use Contact Tiny Escape to request help without reinstalling. Ownership may need to be verified; a nickname alone may not identify the correct guest. Do not send another person's token or code.

When you contact support

If you email Guy Lahav about Tiny Escape, your email address, message, and any information you choose to attach are used to address your support, privacy, deletion, or content report. These messages are handled in the support email inbox. Include only information relevant to your request.

Correspondence may remain in that inbox and its email-provider systems as part of the request history. The game does not automatically delete support messages when you delete a guest. Contact glahav2@gmail.com to ask about information in a support conversation.

Changes and questions

This policy may be updated when the game or its data practices change. The effective date above identifies the current published version.

Use Contact Tiny Escape for game support, privacy questions, or deletion assistance. This policy describes this game's data practices; unrelated services and the destinations you choose for sharing have their own policies.