Privacy Policy — The Puzzle Vault
Last updated: 6 September 2026
This policy explains what personal data The Puzzle Vault collects, why, where it is stored, and what you can do about it. It is written in plain language on purpose — if anything is unclear, write to us and we will explain it.
1. Who we are
The Puzzle Vault ("the app") is published by byhim.nl, a personal, non-commercial project of Mark Keulen, a private individual living in the Netherlands. There is no company behind the app and no Chamber of Commerce (KvK) registration.
For the purposes of the General Data Protection Regulation (GDPR) we are the data controller for the data described below.
Contact for anything privacy-related, including the requests in section 8: puzzlevault@byhim.nl
2. What we collect
We only collect what the app needs to work. There is no advertising SDK, no analytics SDK, no tracking pixel, no advertising identifier (IDFA), and no location tracking of any kind.
Account data
- Your e-mail address.
- If you sign up with e-mail and password: a password hash held by our authentication provider. We never see or store your plaintext password.
- If you sign in with Apple or Google: the identity token those services return, and the e-mail address they release to us. (With Sign in with Apple you may choose Apple's private relay address; we work fine with that.)
- Your username and, optionally, a display name, bio, location text, "solving since" year, puzzle-focus tags and a profile picture (if you have set one). Everything except the username is optional and is whatever you type — we do not verify or enrich it.
Content you create in the app
- Your collection (which puzzles you own, want or are willing to trade) and its notes.
- Solve sessions: start/end times, durations and any notes you attach.
- Ratings and reviews of puzzles, and reviews of people you have traded with.
- Catalog contributions: puzzle submissions, edit proposals and votes on other people's submissions and proposals.
- Marketplace activity: listings you create, bids you place, and whether a listing sold.
- Messages you send to other users through in-app chat.
- Photos you upload for puzzles and listings, whether you took them with the camera or picked them from your photo library. Every photo added to the catalog goes into the catalog's image bank; when a puzzle's cover photo is replaced by a better one, the earlier photo is retained in that bank rather than deleted.
- Photos you scan. If you use "Scan a puzzle", the photo you choose is sent to an AI service (Anthropic — see section 4) to identify the puzzle, together with a handful of catalog photos it is compared against, and we keep a record of each scan: when it happened, which model answered, how long it took, the model's description and candidate names, which catalog photos were compared, and which catalog entry (if any) it matched. When our image-similarity search is enabled (see Voyage AI in section 4), we also compute and store a numeric "fingerprint" of the scan photo (an embedding) so that it can be compared with catalog photos; the fingerprint is not a copy of the photo and cannot be displayed as one, and it is deleted together with the photo. We store the scan photo for 30 days and then delete it, unless you add it to the catalog (as a new puzzle submission or as a better photo for an existing one) — from that moment it is a catalog photo like any other upload and stays in the image bank. Your scan count per calendar month is kept to enforce the monthly scan allowance.
- Reports you file about other users or content, and the accounts you block.
Device data
- A push notification token, but only after you turn push notifications on in Settings → Notifications. We store the token, the platform (iOS/Android) and the device name so we can address a notification to the right device.
- Crash and error reports, if crash reporting is enabled for the build you are running (see section 4). A report contains the error and its stack trace, the app version, the device model and the OS version. It also carries your account's internal user id, so that a crash can be matched to the account that hit it. It does not carry your e-mail address, your messages or your content.
Device permissions we ask for
The app asks for three permissions, each only at the moment you first need it. Access to your photo library, so you can pick an existing image for a puzzle or a listing. Access to your camera, so you can take a photo of a puzzle — asked for only when you choose "Take photo" in the add-a-photo chooser, never on launch, and never if you always pick from your library. Permission to send you notifications, if you turn them on. A photo you take or pick stays on your device until you confirm the submission; nothing is uploaded before that. The one exception is "Scan a puzzle", where choosing the photo is the confirmation: the screen says so before you pick, and the photo is uploaded and analysed at that moment. We never record audio or video, and we do not ask for microphone, contacts, calendar or location access.
Public auction results from other sites
To show what a puzzle has sold for, the app also displays closed-auction results that we collect daily from two public collector marketplaces, Puzzle Paradise and the Cubicdissection Marketplace. For each closed auction we store only the listing title, the final price and currency, the closing date, the designer, maker and category as printed on the listing, and a link to it. We do not collect or store seller names, bidder names, feedback scores, descriptions or photos from those sites, and none of this data is about you or linked to your account.
Tips (optional). You can support the app with a one-off tip bought through Apple's App Store or Google Play. The payment itself is handled by Apple or Google; we never see your card or bank details. Our purchase processor, RevenueCat, tells us that a tip was made: your account id, the product (the tip size), the store, the transaction id, the price and currency, and the time. We store that record and the date of your first tip (shown as a "Supporter" badge on your profile).
We do not collect your contacts, your calendar, your precise or coarse location or your health data. Marketplace payments between users never happen inside the app (see the Terms of Service).
3. Why we use it (legal bases)
| Purpose | Legal basis |
|---|---|
| Creating and running your account; showing your collection, listings, messages and reviews | Performance of a contract (Art. 6(1)(b) GDPR) |
| Identifying a puzzle from a photo you choose to scan, and counting your scans against the monthly allowance | Performance of a contract (Art. 6(1)(b)) — you start each scan yourself, and nothing is analysed unless you do |
| Keeping the community safe: moderation, reports, blocking, preventing abuse and fraud | Legitimate interests (Art. 6(1)(f)) |
| Fixing crashes and errors so the app keeps working | Legitimate interests (Art. 6(1)(f)) |
| Sending you push notifications | Your consent (Art. 6(1)(a)) — you grant it by enabling notifications, and can withdraw it at any time in iOS/Android settings or by turning notifications off |
| Meeting legal obligations (for example responding to a lawful request) | Legal obligation (Art. 6(1)(c)) |
4. Where your data is stored, and who processes it
We use a small number of processors. Each acts on our instructions under a data processing agreement.
- Supabase — our database, authentication, file storage and realtime backend. Our project runs in the EU (eu-west-1, Ireland) region. Nearly all data described in section 2 lives here.
- Expo (Expo Push Service) — delivers push notifications. When we send you a notification, the push token and the notification's title and body pass through Expo, and then through Apple's APNs or Google's FCM to reach your device. This only happens if you enabled notifications.
- Sentry — crash and error reporting. This is only active when the build you are running has a Sentry DSN configured; when no DSN is configured, the reporting code does nothing and no report ever leaves your device. Alongside crashes, Sentry receives a sample of performance traces (how long a screen or a request took), and it records the IP address your device connects from by default. Sentry is not currently configured for The Puzzle Vault, so no data is sent to Sentry.
- Anthropic — puzzle recognition, only when you use "Scan a puzzle". The photo you choose is sent to Anthropic's API (from our own server-side function, never directly from your device) together with a short list of candidate catalog entries — their names and, for up to twelve of them, their catalog photos — so that the model can say which puzzle it is by comparing your photo with those. Nothing that identifies you goes with it: no account id, no e-mail address, no other content. Under Anthropic's commercial API terms, inputs sent this way are not used to train their models; Anthropic may retain API inputs and outputs for a limited period for abuse detection under those terms, after which they are deleted. Anthropic is established in the United States, so the transfer paragraph below applies.
- Voyage AI — image-similarity search for "Scan a puzzle", only when we have enabled it (it is optional on our side; when it is off, nothing is sent to Voyage AI). When enabled, the photo you scan and the catalog photos are sent to Voyage AI's API, again from our own server-side function and without anything that identifies you, to compute an image fingerprint (an embedding) that lets us find the catalog photos that look most like yours before the comparison above. Under Voyage AI's API terms, inputs sent this way are not used to train their models. Voyage AI is established in the United States, so the transfer paragraph below applies.
- RevenueCat — processes in-app tips on our behalf: it validates the App Store / Google Play receipt and sends us the purchase record described in section 2, keyed by your account id. It does not receive your name, e-mail address or any other profile data. RevenueCat is established in the United States, so the transfer paragraph below applies.
- Apple and Google — only if you choose to sign in with them, and for in-app tips (the purchase runs through your App Store / Google Play account under their own privacy policies). We receive an identity token and an e-mail address from them; we do not send them anything about your use of the app.
- Expo (EAS Update) — delivers over-the-air updates to the app's JavaScript. To check for and download an update, the app sends the platform and the app's runtime version to Expo's update service, along with an Expo-generated device/installation identifier. This is infrastructure for delivering app updates, not analytics, and no data from it reaches our own database.
Where a processor stores data outside the European Economic Area, that transfer relies on the European Commission's Standard Contractual Clauses.
5. What other people can see
The Puzzle Vault is partly a public community, so some of what you create is visible to other signed-in users by design:
- Your profile: username, display name, profile picture, bio, location text, solving-since year, badges, trust score, and two aggregate counters — how many puzzles you own and how many you have solved. Those two numbers are the only aggregate figures other people learn about your collection.
- Your puzzle ratings and reviews, your marketplace listings, and reviews you leave for trading partners.
- Your catalog submissions, edit proposals and votes, which are shown to the community that votes on them.
- Activity entries generated by what you do — that you solved, rated or added a puzzle, or created a listing — which appear in the community feed with the puzzle's name.
Your collection is private. The individual entries in your collection — which specific puzzles you own or want, your personal notes, what you paid and when you acquired it, your own rating and your solve times — are readable only by you and by our moderators. Other users cannot read them. What they see is the aggregate counters above, the activity entries above, and whatever you deliberately publish: a review you write, or a puzzle you put up on the marketplace.
One deliberate exception is trade matching. Marking a puzzle as wanted or for trade is how you ask to be found: when another collector's flags mirror yours (they offer what you want, or want what you offer), each of you is shown the other's username and the puzzle in question, and each of you gets a notification, so you can start a conversation. Nothing else from your collection is revealed, and clearing the flag removes the match. Two users who have blocked each other are never matched.
Also private to you (and, where applicable, to the person you are talking to): your e-mail address, your chat messages, your reports and your blocks.
We do not sell your data, and we do not share it with advertisers or data brokers. We disclose data to third parties only when we are legally required to, or when it is strictly necessary to investigate abuse or protect someone's safety.
6. Blocking and moderation
You can report a profile, listing, review or message thread, and you can block another user. Blocking is symmetric in effect: once a block exists between two accounts, neither sees the other's listings, reviews, activity, messages or trade reviews. Reports are readable only by you and by our moderators, and are retained while the report is open and for a reasonable period afterwards so that repeat abuse can be recognised.
7. How long we keep it
We keep your data while your account exists. You can delete your account yourself, at any time, in the app under Settings → Danger Zone → Delete Account. There is no e-mail to send and nothing to wait for — the deletion runs immediately and cannot be undone.
Deleted outright when you delete your account: your login record and profile, your collection and solve sessions, your puzzle reviews and trade reviews, your marketplace listings and bids, all of your chat messages — both the ones you sent and the ones you received, your notifications, your push tokens, your follows, your achievements and badges, your trust-score history, your catalog submissions, edit proposals and votes, your status requests, your blocks, the reports you filed, your scan history and scan counts, and the image files you uploaded to our storage buckets. A scan photo you never added to the catalog is removed by the routine 30-day sweep at the latest (see section 2).
Also deleted outright: moderation-log entries recording actions you took as a moderator — those rows are removed with your account.
Kept, but permanently disconnected from you: catalog entries that were accepted into the public puzzle catalog keep existing as catalog data, with the "submitted by" attribution set to nothing; the same applies to designer/maker records linked to your profile, to moderation-log entries recording an action taken about you (the entry stays as an anonymous audit record, with the reference to you set to nothing), to the "resolved by" attribution on submissions, proposals, status requests and reports you resolved, and to the buyer/winner attribution on another user's sold listing. The same applies to photos that became part of the public catalog (a cover, a gallery image, or a scan you added to the catalog): they stay in the catalog's image bank with the uploader reference set to nothing. The catalog is a shared community resource — the entry stays, your name comes off it.
Backups roll off for a short rolling period on our provider's schedule (currently seven days), after which deleted data is gone from backups too.
8. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and get a copy of it.
- Rectify data that is wrong — most of it you can edit yourself in Settings.
- Erase your data ("right to be forgotten") — the in-app account deletion above does exactly this, and you can also ask us by e-mail.
- Data portability — ask us for your data in a structured, machine-readable format.
- Restrict or object to processing that we base on legitimate interests.
- Withdraw consent for push notifications at any time, without affecting anything that happened before.
Write to puzzlevault@byhim.nl and we will answer within one month. If you are not satisfied with our answer, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the supervisory authority in your own EU country.
9. Children
The Puzzle Vault is intended for people aged 16 and over, which is the age of consent for information-society services in the Netherlands. The app is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has created an account, write to us and we will remove it.
10. Changes to this policy
If we change this policy we will update the date at the top and publish the new version at https://byhim.nl/puzzlevault/privacy. If a change materially affects you, we will tell you in the app before it takes effect.
11. Contact
puzzlevault@byhim.nl byhim.nl — Mark Keulen, private individual, the Netherlands