Privacy
last updated 2026-08-08
The short version: LADDER has no accounts, your saves stay on your device, and nothing here is sold or used for advertising. The details below are the long version of that sentence, including the parts that are less tidy: the AI companion sends what you type to a third-party model provider, and the app checks in with our server whether or not you ever talk to it.
The game
- No account, no login. There is nothing to sign up for. Your runs, your deck, and your settings are stored locally on your device and are deleted when you delete the app.
- Anonymous product analytics, on by default. The game records anonymous gameplay events (for example "a run ended at L4") via PostHog, hosted in the EU, to help us balance and improve it. It is on unless you turn it off. Settings has two switches for it, both under Privacy: "Gameplay analytics" is the master switch, and "Share analytics with the developer" controls whether those events leave your device at all. Turn the second one off and events stay local. None of this is sold, and none of it is used for advertising. The game plays identically with both off.
- What rides along on every event. The app version, the platform, and the device model. Ordinary app-lifecycle events (opened, updated, backgrounded) are captured automatically on the same switch.
- Linked to an install, not to a person. We do not ask for a name, an email address, or an advertising identifier, and we do not have one. We are not being coy, though: events from one install are deliberately linked to each other under an install id, so we can tell one player's fifty runs from fifty players' one run. Our App Store privacy declaration says the same thing, and marks the data we collect as linked to that identifier.
- Crash and error reports. When the game throws an error, the same pipeline records it so we can fix it: what broke, where, and the app version and device model it broke on. It rides the same switches, so turning analytics off turns this off too.
- Roughly where you are. Our analytics provider turns the connecting IP address into a coarse location - country and region, never a street or a building - so we can see which regions play the game. Same switches again.
- Device-integrity checks, which the switches do not cover. Before our server will talk to the app, it checks the app is genuinely our app and not a script. That check involves Apple and Google, it happens whether or not you ever open the companion, and it is not covered by the analytics switches. It cannot be: it is the anti-abuse gate on the Cognit ledger, and a gate you can switch off is not a gate. No personal data is involved. We would rather write that down than let you discover it.
- Purchases. In-app purchases go through the App Store or Google Play, with RevenueCat as the receipt-validation layer between them and us. We receive confirmation that a purchase happened; we never see your payment details.
What lives on our server
One thing, essentially: the Cognit ledger. Your Cognit balance and the record of how it got that way cannot live on your device, because then a reinstall would wipe what you paid for. It is kept against a random install identifier, together with the minimum needed to run it: what you have claimed, any promo code you redeemed, and confirmation that a purchase happened. If you use the report button on one of Bit's replies, that exchange is kept so we can review it.
There is no name, no email, and no advertising identifier in any of it. The install identifier means nothing anywhere except our own records, and it is the support code shown in Settings, which is how you can point us at your record without telling us who you are. Records are backed up, and the backups expire on their own.
The AI companion
- It is never required. The whole game is playable and winnable without ever opening it, and it costs nothing to ignore. To be precise about what you can and cannot switch off today: there is no single master off switch for the companion in Settings. What there is: the rumor mill has its own off position (Settings → Companion → Rumor mill → off), and if you never open the chat, no chat message is ever sent.
- Where your messages go. When you send a message, it passes through our own relay to Groq, Inc., which runs the model that writes the reply. Groq is our sub-processor for this and nothing else.
- What travels with it. Not just the sentence you typed: also the recent conversation and a summary of where you are in the game, so the reply makes sense. It is all game state. None of it is contact data, because we do not have any.
- Some calls are not prompted by you. The rumor mill collects office gossip during a run and writes it with the same model, without you asking. Set it to "off" in Settings → Companion and it stops collecting and stops calling.
- Your chat content is never used for analytics. We record that a companion reply happened (and what it cost) and never what was said. The only exception is a reply you explicitly report, described above.
- We do not train any model on your messages, and we do not sell them.
Push notifications
- Opt-in, not on by default. Nothing described in this section happens until you say yes to the notification permission prompt. Say no, or dismiss it, and none of this applies to you.
- What we register the moment you say yes. The push token your device hands us, a random install identifier minted by our server (the same kind used for the Cognit wallet - linked to an install, not to a person), your timezone and language, and the app build you are running. A last-activity timestamp rides along and updates automatically while the app is open, so we know whether a message is still worth sending.
- What it is for. At most one notification a day. If you are actively playing, that is a daily message from Bit. If you go quiet, it is one of a small, finite set of win-back nudges - at 3, 7, 14, and 30 days of inactivity - and then nothing further. We do not send more than one a day, and we do not send more once the schedule runs out.
- Who delivers it. Apple and Google. Our server hands their delivery networks a token and a message; getting it onto your device from there is what those platforms do for every app, not something specific to us.
- How long we keep the registration. It is deleted automatically after 45 days without a check-in, and immediately the moment you opt out.
- Turning it off. One switch, in Settings. Flip it and the registration - token, install id, timezone, locale, and last-activity timestamp - is deleted from our server right away, not just silenced. Your OS-level notification settings are honored independently of that switch, either way.
This website
- laddergame.ai uses cookieless, anonymous analytics (PostHog, EU-hosted): page views and clicks, aggregated. No cookies are set, which is why there is no cookie banner to click away.
- We never identify visitors, and there is nothing to log into.
Your data, and deleting it
- Stopping collection. Settings → Privacy has two switches: "Gameplay analytics" and "Share analytics with the developer". Turn them off and the game stops sending analytics, crash reports, and coarse location. Nothing about how the game plays changes. The device-integrity check described above is not on these switches.
- Stopping notifications. A separate switch in Settings deletes your push registration from our server immediately, described above under "Push notifications".
- Deleting the local copy. Deleting the app deletes your runs, your deck, and your settings. That part is entirely in your hands.
- Deleting the server copy. Write to ladder@yazfab.com and include the support code from Settings, which is the only reliable way for us to find your record. On request we will delete your analytics profile and your wallet record: balance, ledger, and claim history, and tell you when it is done.
- What we cannot delete today, stated plainly. We would rather narrow this promise than make one the software cannot keep. Records tied to purchases, promo codes, and replies you reported have no deletion path yet, and backups expire on their own schedule. Building deletion for the rest is on our list, and until it exists we are not going to claim it. Ask us anyway if it matters to you and we will tell you where it stands.
- What is not ours to delete. Apple and Google keep their own record of a purchase and we cannot reach into it. Aggregate counts that no longer point at any single install stay in our totals.
How long we keep things
- On your device: until you delete the app.
- Analytics: under our analytics provider's standard retention, and deleted sooner on request.
- The ledger: for as long as the install keeps checking in, because it is what a reinstall restores.
- Push notification registration: 45 days after your last check-in, or immediately if you turn the notifications switch off.
- Reported replies: until reviewed.
- Backups: a limited period, then deleted automatically.
Who we are, and your rights
LADDER is published by Yazfab, established in the Netherlands, which is the controller for the data described on this page, reachable at ladder@yazfab.com.
If you are in the EU, the UK, or somewhere with comparable law, you have the right to ask what we hold about your install, to get a copy of it, to have it corrected, to have it deleted (within the limits set out above), to restrict or object to how we use it, and to complain to your data protection authority. Ours is the Dutch one, the Autoriteit Persoonsgegevens, but you can go to the authority where you live. We rely on your consent for analytics and for push notifications, which is why both have a switch, and on our legitimate interest in running a working, un-abusable game for the wallet, integrity, and purchase records, which is why those do not. Ask us using the address above and include your support code.
Questions
Write to ladder@yazfab.com. A human reads it.