Jottly
JotBot waving hello

Privacy Policy

Effective September 27, 2026

Hi! JotBot here. Here's the short version: we built Jottly to be played and shared, not to harvest your data.

Jottly is a word and letter-deduction game platform made by Drew Sullivan at Iced Matcha Labs ("we," "us"). This policy explains what information the app does, and does not, involve.

Our promise

Information we don't collect

Jottly does not request access to your contacts or location and does not use an advertising identifier or track you across apps or websites. No email address or account is required to play. Information you choose to put in a display name, custom game, or support report can identify you; those uses are described below. We do not use that information for advertising or cross-app tracking.

Your optional sharing choices

Both optional sharing settings start off. You choose each independently: Share anonymous usage and Contribute favorite custom games. Neither is required to play. You can enable or disable either in Settings. Dismissing a privacy choice prompt preserves your existing choices; it does not enable sharing.

Anonymous product analytics

To learn what makes Jottly easier and more enjoyable, the app can send us small, first-party aggregate counters. These can include which game mode was selected, whether a game was started or completed, broad turn and duration ranges, which kind of share sheet was used, app version, and broad performance or sync outcomes. Events are combined on your device by calendar day before upload.

These aggregates contain no name, email, player ID, device ID, game ID, opponent ID, word, exact timestamp, advertising identifier, or precise location. We do not use them to identify an individual, follow someone across apps or websites, advertise, or build a profile. This collection happens only when Share anonymous usage is enabled. Turning it off deletes unsent usage aggregates stored by the app.

Favorite custom-game contributions

If you enable Contribute favorite custom games, repeated Solo play of an eligible game you created can send its complete reusable game package to us for private review for the community catalog. The package includes its title, description, icon choice, rules, creator attribution, package identifiers, compatibility information, and revision metadata. Text you authored and creator attribution can contain personal information. This submission does not include the match's secret words, guesses, or game history.

Contributing a package does not automatically publish it. Contributions are stored in our first-party Cloudflare infrastructure for review. This choice is separate from anonymous usage sharing. Turning it off stops future contributions and clears the app's locally stored contribution data; it does not retract a package already submitted.

Information used to play

To support multiplayer games, continuity, and portable game rules, information is created on your device and synced through Apple's iCloud / CloudKit:

Gameplay data lives on your device and in Apple's iCloud infrastructure under Apple's privacy policy. We do not use this content for advertising, profiling, or tracking. Anonymous product aggregates are sent to our first-party website infrastructure hosted by Cloudflare and stored separately from gameplay content.

Community games

Jottly may download a public catalog of reviewed game packages. Catalog entries contain the rules and presentation needed to play a game, not match records, secret words, guesses, opponent information, or player identifiers from a match. Privacy-preserving aggregate activity can help determine which reviewed games are useful to feature.

Purchases

Jottly is completely free. There are no in-app purchases, subscriptions, or ads, so there is nothing to buy and no payment information is ever collected or processed.

Support and diagnostic reports

When you submit an in-app report, we receive the name or notes you enter, the report type, app version and build, and recent diagnostic logs attached by the app. Draft reports remain on your device until submission. Reports are sent to our private developer inbox hosted on Cloudflare so we can investigate problems and improve Jottly. Avoid including information you do not want us to receive.

With Share anonymous usage enabled, updated Jottly releases automatically send limited reliability reports for errors, unusually slow or stuck actions, and unreadable or failed saves. Reports contain a generated description, app/build and broad device/software details, timing, typed error categories, and a small filtered technical excerpt. They exclude names, identity, game or player identifiers, words, game history, custom-game text, URLs, screenshots and raw diagnostic logs.

Turning usage sharing off stops automatic reliability reports and clears their unsent data; it cannot retract data already transmitted. Reports are grouped to limit repeated submissions. Unsent automatic reports expire after seven days, and automatic diagnostic excerpts and incident details are removed from our service after 30 days. Content-free issue summaries and counts may remain. Manual reports you choose to send are separate and are not removed by the usage switch.

Earlier app releases could automatically send a sanitized error report with recent diagnostics for a displayed error, separate from the two optional sharing settings. Update Jottly to use the unified usage-sharing control described above. Network providers necessarily process connection metadata; our developer reports do not include an IP address or a stable installation identifier.

If you choose to dictate a report, the app requests Microphone and Speech Recognition permission and uses Apple's speech frameworks. Apple may process audio using its speech-recognition services; recognition is not guaranteed to stay on your device. Jottly sends the resulting report text and diagnostics to our inbox when you submit, not an audio recording. You can type instead and can manage these permissions in iOS Settings.

If you email us feedback, we receive your email address and whatever you write and use it to read and respond. We do not add you to a mailing list.

Children

No name or email address is required to play. A parent or guardian can contact us about information a child may have included in a custom game or report. We do not use that information for advertising.

Protecting public submission services

To limit automated abuse, our server uses the network address supplied by Cloudflare to produce a keyed, temporary rate-limit token. The admission ledger stores no raw network address, permanent device identifier, or report text. Tokens change each minute; entries expire after two minute buckets and are removed on the next submission or daily maintenance. People sharing a network address may share a temporary limit. A rejected submission can be retried; an acknowledged duplicate does not create another record. This abuse control is separate from optional product analytics.

Data retention and deletion

Turn off sharing and clear pending data in Settings disables both optional sharing choices and clears improvement data stored on this device. It does not delete data already received by our service, including usage aggregates or submitted custom-game packages, and it does not delete support reports. Unsent anonymous usage aggregates expire locally after 35 days; that limit does not describe server retention or the separate custom-game contribution queue.

Removing a game or deleting the app affects local data and the shared-game actions that the app can complete. It does not delete another player's copy or all CloudKit records. Apple manages iCloud storage under its own policies. Already shared or contributed packages may remain with their recipients.

Received aggregates, contributions, and manual reports do not currently have a fixed automatic expiration period. We use them for product improvement and support. When a developer report is marked fixed, its attached diagnostic text is cleared while the report description and resolution remain. Contact us about information you submitted that we may be able to locate; anonymous usage aggregates do not identify a player.

Changes

If this policy changes, we'll update the date above and post the revised version at this URL.

Contact

Questions? Email support@icedmatchalabs.com.