This policy covers the Android version of Bori distributed on Google Play. The iOS version is a separate build with a separate policy — see the Bori Privacy Policy for iOS.
Summary
Bori has no account. It never asks for your name, email address, phone number, or address, and there is nothing to sign in to. Your progress through the cases stays on your device. Only two things leave it, both described below — an anonymous leaderboard entry, and pseudonymous usage analytics.
What Is Stored on Your Device
- Your case progress — your streak, which cases you have solved, your accuracy, your best scores, and your total time played
- Your subscription entitlement
- An anonymous leaderboard identifier (a random string the device generates when you install the app. It is not linked to your Google account, an advertising identifier, your email address, or your phone number.)
- Settings — language, sound effects, haptics, whether onboarding is finished, and whether case reminders are on
All of it lives in Bori's own private storage, where no other app can read it. Uninstalling the app or clearing its data deletes it along with everything else.
Leaderboard
Bori has a leaderboard that puts your score next to other players'. When a score is submitted, this is everything the app sends to the server:
- The anonymous identifier described above
- The case (chapter) number, the score, and how long the run took
No name, email address, device identifier, location, or advertising identifier is sent. Because this is an internet request, the server receives the IP address you connect from, exactly as any other web request does — that is what makes the connection work. The leaderboard runs on a server Pentarab operates.
Each leaderboard entry shows a flag beside it. That country code is not a value the app sends — the server works it out from your network location at the moment of the request, at country level only. It does not look at precise location such as a city or coordinates, and it does not use your device's location permission. If no country can be determined, the entry appears without a flag.
Analytics
To understand how the app is used and to improve it, Bori sends usage events to an analytics service that Pentarab runs itself. It is not Google Analytics, and the data is not passed on to any third party. The events record which screens you open, which features you use — a case started, a case completed, onboarding finished — and the steps of the purchase flow. This is a separate transmission from the leaderboard above: different contents, different destination. This is the complete list of what that service receives:
- The app identifier, the platform, and the app version and build number.
- An install identifier — a random value the app generates on first launch. It is not derived from your device, your Google account, or any advertising identifier, and reinstalling the app produces a new one.
- A session identifier, so one run of the app can be told apart from the next.
- Screen names, and how long each screen was open. The duration is measured from a matching open and close, not guessed from the gap between events.
- The UTC time of each event, plus your time-zone offset so local time can be reconstructed.
- Device information: the operating system and its version, the screen size, and the locale. The device model is not sent.
- A country. This is worked out by the receiving server from the connection itself — the app never sends it, and it is country-level only.
The service does not store your IP address. It is read only to derive the country and is then discarded. It collects no advertising identifier, no precise location, and no personal identifier such as a name, email address, or phone number. Nothing you create or enter in Bori is part of an analytics event.
The values recorded are screen names and feature names only. Bori has no account, so nothing in this data identifies you.
Bori does not collect the Android Advertising ID. Both advertising-ID permissions (com.google.android.gms.permission.AD_ID and android.permission.ACCESS_ADSERVICES_AD_ID) are explicitly removed from the app's manifest and are absent from the build published on Google Play. There are no ads, and Bori uses no crash reporter and no performance monitoring.
Purchases
The subscription that opens the locked cases is handled by Google Play Billing. Pentarab never receives or stores your card details, your Google account details, or your billing address. There is no server of ours that validates receipts — Google Play confirms your entitlement and it is applied on the device.
Permissions
- Internet — needed for the leaderboard and for analytics. It is an ordinary permission and shows no prompt.
- Notifications — so the app can post case reminders. It is requested only after onboarding is finished, and the app works normally if you decline.
- Run at startup — so a reminder you scheduled survives a reboot. This is an ordinary permission.
- Vibration — for haptic feedback. You can turn it off in Settings.
- Billing — used by the Google Play Billing library.
There is no camera, microphone, photo, storage, location, contacts, or calendar permission. Bori does not read your gallery and does not record sound.
Notifications
Case reminders are local notifications, scheduled entirely on the device. There is no push server, and no personal information is transmitted because of a notification. You can turn them on or off under Case reminders in Settings, or from Android Settings > Apps > Bori > Notifications.
Your Data Control
- Your progress is only on your device, so uninstalling the app — or clearing its data from Android Settings > Apps > Bori > Storage — removes it completely.
- To have a leaderboard entry deleted, email us. Your own entry is shown on the leaderboard only as “You”, so you cannot read the identifier off the screen; tell us the case name and the record (the score and the time) and we will find it by those values and delete it. If several entries share the same record, we may not be able to tell which one is yours.
- Analytics data is tied to an identifier that is generated at random for each install and is never displayed anywhere in the app. There is therefore no way to find one user’s records and delete them, and we do not offer a deletion request path. Uninstalling the app stops the collection, and reinstalling it creates a new identifier that is not connected to the old one.
Children's Privacy
Bori is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided information through the app, please contact us so we can address it.
Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated revision date.
Contact Us
Questions about this policy? Email us:
Email: info@pentarab.com