Splits · Speedcubing Timer
Privacy Policy.
Last updated 12 September 2026 · iOS, Android, and splitscubetimer.com
The short version
Your solves never leave your device. Splits has no accounts, no sign-in, no ads and no advertising identifiers. It does not sell or share your information, and there is no Splits server holding your times.
The app does send two things, and neither is your solve history. It asks a configuration service which features to switch on, and it reports crash and performance diagnostics — errors, screen timings, which controls were tapped, and the device model and OS version they happened on — so that a bug can be found and fixed. Both are described in full below, along with what they cannot see.
What stays on your device
Everything you create in Splits is written to your device's own storage and stays there:
- Every solve — its time to the millisecond, its scramble, its puzzle, any +2 or DNF penalty, and when you did it
- The puzzle you last selected and the scramble currently on screen
- Your timer preferences — inspection on or off, hold duration, scramble preview
- Challenge links you have opened or sent
On iOS and Android this is the app's own private storage, which no other app can read. On the website it is your browser's local storage for splitscubetimer.com, which no other site can read. None of it is transmitted anywhere. There is nowhere for it to be transmitted to.
Erase all data in Settings deletes every solve on the device immediately and irreversibly. Deleting the app does the same thing, as does clearing the site's data in your browser.
Splits has no sign-in, so nothing you do in it is attached to a name, an email address, or an account. There is no account to attach it to, and nothing we receive — the configuration request and the diagnostics below — could identify you, because none of it says who you are.
Configuration
Splits uses a feature-flag service, Quonfig, to decide at runtime which features to show — whether the Pro upgrade screen appears, what price copy sits under it, whether a store's download button is live yet. This lets a feature be switched off without shipping a new build.
To answer, the service is told two things: your platform, as the string ios, android, or web, and an install identifier — a random value generated on your device the first time you open the app. It exists so that a feature can be switched on for one tester, or rolled out to a stable slice of installs rather than landing all-or-nothing on an entire platform.
That identifier is not a hardware identifier and not an advertising identifier. It is random, it is scoped to this one installation of this one app, and it is gone when you delete the app — so it cannot follow you to another app, to a website, or to a reinstall. It carries no name, no email address and no reference to your solves or your scrambles. The request is made when the app starts and repeats about every five minutes while it is open.
In the iOS and Android apps, the same identifier is also attached to the diagnostics described below, so that when a feature is switched on for one tester, the install it is switched on for can be found. The website does not send it with diagnostics.
As with any network request, the service necessarily sees the IP address the request arrives from, and processes it on our behalf as a service provider in order to answer. We do not use it to identify or profile anyone.
If the request fails or times out, the app carries on with its built-in defaults. Splits is fully usable offline, and every feature except this one works with no network at all.
Crash and performance diagnostics
Splits reports diagnostics to Datadog, which processes them on our behalf as a service provider. This is how a crash gets fixed: without it, an app that closes itself on one model of phone is something we simply never find out about.
It is diagnostics, not advertising. What is sent is:
- Crashes and errors — the message and the stack trace, including native crashes on iOS and Android
- Which screen you are on, by its name in the app —
/timer,/solves,/settings— and how long it took to draw - Which controls were tapped, by their on-screen or accessibility label, and signals that a tap did not work — a button pressed repeatedly, or one that produced an error
- How a Pro purchase went — that one was started, and whether it went through, was cancelled, or was declined, along with which plan it was for. Not the price, and never anything about how you paid
- The network requests the app itself makes — the configuration request above, and cloud backup if you have turned it on — as addresses and timings. Not their contents.
- Technical context — device model, operating system version, app version, language and region, a randomly generated session identifier, in the iOS and Android apps the install identifier described above, and the IP address the report arrives from
And what is not:
- No account or identity. The app never tells Datadog who you are, because it does not know. No name, no email address, no account, no advertising identifier. In the iOS and Android apps, reports carry the random install identifier described under “Configuration”, so reports from one installation can be recognised as coming from the same installation — it names an installation, not a person, and it does not follow you to another app, to a website, or to a reinstall. On the website there is not even that: the session identifier is random and expires, and nothing links one visit to the next.
- No solves. Your times, scrambles, penalties and history are not sent. Diagnostics describe the app's behaviour, not your results.
- No screen recording. Session Replay — Datadog's feature for recording what a screen looked like — is switched off, and we do not intend to turn it on. If that ever changes, this page will say so before it does.
- No advertising. No ad networks, no advertising identifiers, no attribution SDKs, and none of this is used to track you across other apps or websites or shared with anyone who would.
A challenge link's contents never reach Datadog. The website reports the page you are on as /c with the query string removed, so the puzzle, the time and the scramble in the link stay out of the diagnostics — see “Challenge links” below.
Retention. Datadog holds these reports for a limited period — thirty days for session and error data on our current plan — after which they are deleted automatically. We do not copy them anywhere else, and there is no long-term archive.
If you would rather not send them. There is no account to look you up by, and nothing in the diagnostics says who you are, so we cannot single out and delete an individual's reports on request; they are deleted automatically at the end of the retention period above. A content blocker, a network-level blocker, or simply using the app offline will stop the reports leaving your device; Splits works normally either way.
Challenge links
A challenge link lets you send someone a solve to race. Everything the challenge needs is written into the link itself — the puzzle, your time in milliseconds, and the scramble — as ordinary URL parameters. There is no account behind it, no invitation record, and no server that pairs the two of you.
Two things follow from that, and they are worth being plain about:
- Anyone holding the link can read it. The time and scramble are visible in the URL to anyone the link is forwarded to, and to any system it passes through.
- The link travels through whatever you send it with. Messages, mail, a chat app — that service handles it under its own privacy policy, exactly as it would any other link you send. Some of them fetch a link to build a preview.
Opening a challenge link on the website requests a page from our CDN, which serves the same static app to everyone, and a small function that renders the link's preview card. We do not enable access logging on either, so the request — and the scramble and time in its URL — is not recorded on our side.
The diagnostics described above are the other place a URL could have ended up, so the website strips the query string before reporting the page: Datadog is told /c and never the payload. The link is a message between you and the person you sent it to; we are not a party to it.
Splits Pro
Splits Pro is an optional subscription, sold and billed entirely through the App Store or Google Play. Your payment details never reach us — we do not see or store your card, your billing address, your Apple ID, or your Google account. Apple and Google handle the transaction and tell the app only whether a subscription is currently active.
The app keeps the store's last answer in its own local storage — whether Pro is active, which plan, and when it was last checked — so that it works offline and does not have to ask the store on every screen. That record never leaves your device, and it is not attached to a name or an account, because there isn't one.
What does leave the device is the outcome of a purchase made in the app — started, completed, cancelled or declined, and which plan — as part of the diagnostics above, so that a checkout that has stopped working gets noticed. Like the rest of the diagnostics, it says nothing about who made the purchase.
Apple and Google process your purchase under their own privacy policies, not this one.
Cloud backup
With Pro, Splits can back your solve history up to your own cloud account — iCloud Drive on iPhone and iPad, Google Drive on Android. It is off on the web.
Your solves do not pass through us. There is no Splits server in the middle, and we never receive, see, or store your history. The app writes a file straight into your own storage: on iOS, the app's private iCloud container, using whatever Apple ID the device is already signed in to — there is nothing to sign in to and nothing for us to see. On Android, the app's hidden folder in your Google Drive, which requires your permission once and is reachable only by Splits. Neither is visible alongside your documents and photos, and no other app can read either.
What is written is your solve history and nothing else: the times, the puzzle, the scramble, the penalty, and when each solve happened, plus a random identifier for the device that wrote the file so two devices can be merged. No name, no email, no account, no device fingerprint, no advertising identifier.
Every device signed in to the same account shares that one hidden folder, which is what makes a solve on your phone show up on your tablet. It also means anyone using a device signed in to your Apple ID or your Google account can see the history Splits has backed up there, in the same way they could see anything else in that account.
Apple and Google hold that file under their own privacy policies and their own storage terms, and it counts against your iCloud or Drive quota. You can delete it the way you would delete anything else in your account — in iCloud settings, or from Drive's app-data controls — and turning sync off in Splits stops any further writing.
Sync is per ecosystem, not across them. A history backed up to iCloud does not appear on an Android phone, and the other way round, because the two copies live in two different accounts that we have no way to connect — and no wish to.
The website
splitscubetimer.com serves the same application as the apps, as static files from Amazon CloudFront and S3. It makes the same configuration request described above, and sends the same crash and performance diagnostics, and nothing else.
One cookie. The diagnostics set a cookie named _dd_s in your browser. It holds a randomly generated session identifier and nothing else — no name, no account, no profile — and it exists so that the three errors from one visit are recognisably one visit rather than three unrelated ones. It expires with the session. There are no advertising cookies, no third-party trackers and no session replays on this site.
Your solves on the website are held in your browser's local storage for splitscubetimer.com, which is not a cookie, is never transmitted, and is cleared when you clear the site's data.
Access logging is not enabled on the CloudFront distribution, so page requests are not logged to us. Amazon Web Services operates the delivery network as our service provider and handles traffic under its own operational practices.
Who processes what
Three companies handle anything on our behalf, and only what is described above:
- Amazon Web Services — serves the website and the challenge-link preview cards.
- Quonfig — answers the configuration request.
- Datadog — receives the crash and performance diagnostics.
Apple and Google are separate: they handle subscription payments and, if you turn cloud backup on, your own storage account. They act under their own privacy policies rather than as our processors, as described in “Splits Pro” and “Cloud backup” above.
What we never do
- No accounts, logins, or profiles — we never learn your name or email address
- No selling or sharing of personal information, ever, to anyone
- No advertising, ad networks, or advertising identifiers
- No tracking you across other apps or websites, and no data brokers
- No sending your solves, times, or scrambles anywhere you have not chosen to send them
- No screen or session recording, on any platform
- No location access of any kind — the app never asks, on any platform
- No access to your contacts, camera, microphone, photos, or health data
Retention
Your solves. They live on your device for as long as you keep them and are gone the moment you erase them. We never receive them, so there is no copy on our side to request, correct, or delete — and if you want your own copy, Settings › Data › Export solves writes the whole history to a file you keep, in a format that reads back in. It is free, and it needs no account, because there is not one.
Diagnostics. Crash and performance reports are held by Datadog for thirty days on our current plan and then deleted automatically. They contain no account and no name — in the apps, only the random install identifier described above, which names an installation rather than a person — which is what makes them diagnostics rather than a record of you, and is also why we cannot pick an individual's reports out to delete on request: nothing in them says whose they are. Blocking or going offline stops them being sent at all, as described above.
Configuration. The install identifier described above is stored on your device and destroyed when you delete the app. The copies of it in the apps' diagnostics are deleted with them, after thirty days.
Children
Splits is a general-audience tool for timing puzzle solves. It is not directed at children, and it collects no information that identifies anyone, of any age.
Your choices
- Your solves: erase them at any time from Settings, or by deleting the app or clearing the site's data.
- Challenge links: send them or don't. Nothing is shared unless you share it.
- The configuration request: a content blocker or an offline device will stop it. The app works normally either way, on its built-in defaults.
- Diagnostics: the same — a content blocker, a network-level blocker, or using the app offline stops the reports leaving your device, and nothing in the app depends on them.
- The install identifier: deleting the app destroys it. A fresh install mints a new random one with no connection to the old.
Changes
If this policy changes materially — in particular if Splits begins sending anything not described above — this page will be updated and the date at the top revised before the change takes effect.
Contact
Questions about this policy can be sent to privacy@madelabs.dev.
Splits is published by Forrest Grant. See also the Terms of Use and Support.