Privacy Policy and Legal Notice
Your photos never leave your device unless you share them. Here's what happens when you do, your rights, and how you can verify it.
What happens to your photos?
In the app's own folder
A copy of the photo you pick is written to a private folder only this app can reach. Delete the puzzle and the copy goes with it.
We don't even ask for photo access
Apple's own photo picker handles the choosing and hands us only the single photo you picked. The app never sees the rest of your library.
The puzzle is cut on your device
The pieces are cut on your phone's own processor. Playing never uploads a photo anywhere.
When you share a puzzle as a link
End-to-end encrypted
The photo is encrypted on your device; only the encrypted version reaches our server. The key to open it lives in the part of the link after the # and is never sent to us. We, our hosting provider and Cloudflare can't see the picture.
No location or photo tags
The shared picture is redrawn, so details like location, capture date and device model are not carried along.
30 days at most
The encrypted data is deleted from the server automatically after 30 days. You can delete it sooner in Settings → Sharing.
Where is it kept?
On a server run by Amazon Web Services in Ireland (EU); the connection passes through Cloudflare. Your IP address is held briefly in memory only to limit abuse and is never written anywhere.
Who can open it?
Anyone who has the link. The recipient sees the whole picture only after finishing the puzzle.
Reporting and blocking
You can report a puzzle you received and the link closes at once. If you allow it we see the picture to review it; if not, we never see it. You can block the sender on your device.
You can turn it off entirely
You can switch the feature off in Settings → Sharing. While it's off, the app never connects to the internet.
What we don't collect
No account
No sign-up, no login, no email, no password.
No analytics
Which screen you look at and how long you play are never recorded.
No ads
No ads are ever shown, and there's no ad network software inside.
No third-party software
The app uses only Apple's own frameworks — not a single outside library has been added.
No background connections
The app doesn't connect to the internet at launch, in the background or while you play; only during the sharing actions above, and only to our own server.
Things we should be upfront about
iCloud backup
Your puzzles are included in your own iCloud or computer backup — so they survive a device change. That backup belongs to your Apple Account, not to us. If you'd rather not, you can turn it off in Settings.
Purchases
If you buy Plus, Apple handles the payment from start to finish. Your card details never reach us, and no purchase data is kept on our side.
How can you be sure?
These claims are checked automatically on every release: networking code may exist only in the sharing file and may only reach our own server's address, and the code is scanned for tracking APIs and outside libraries. If one turns up, the release never ships.
On our App Store page, shared photos are declared under "App Privacy" as "Photos or Videos — not linked to you". No other data is collected.
Legal notice (Turkish KVKK Art. 10, EU GDPR Art. 13)
- Data controller
- Muhammed Taha İkiz (developer of the Sharepiece app, Türkiye). Contact: taha@ikiz.dev
- What data we process
- While you only play, we process no personal data at all; everything stays on your device.
- When you share a puzzle as a link: the end-to-end encrypted puzzle package (the photo, the piece count and a random sender number are inside the encrypted part; we don't have the key), the package size, its creation and expiry times, an irreversible hash of the deletion token, and the share's status (active, deleted, expired, removed).
- When you report a puzzle: the reason you picked, the time of the report and — only if you allow it — the puzzle key so we can review it.
- With every request: your IP address is held in server memory for at most one hour to limit request rates and is never written to any record. Cloudflare, in front of our server, processes your IP address and request details to deliver the service and protect it from attacks.
- We collect no account, name, email, phone number, location, device identifier, advertising identifier or usage analytics. The version of the terms you accepted is kept only on your device.
- Purposes
- Delivering the puzzle you share to the person who has the link, and letting you delete it whenever you want.
- Preventing abuse, spam and attacks, and keeping the system secure.
- Reviewing reported content, removing content that breaks the rules and meeting legal obligations.
- Legal bases
- GDPR Art. 6(1)(b) and KVKK Art. 5(2)(c): providing the sharing service you asked for.
- GDPR Art. 6(1)(f) and KVKK Art. 5(2)(f): our legitimate interest in security and abuse prevention (brief in-memory use of IP addresses, reviewing reports).
- GDPR Art. 6(1)(c) and KVKK Art. 5(2)(ç): our legal obligations regarding illegal content.
- GDPR Art. 6(1)(a) and 9(2)(a), KVKK Arts. 5(1) and 6: because photos can show what people look like and may in some cases count as special-category data, we also ask for your explicit consent before sharing. You can withdraw it at any time in Settings → Sharing; withdrawal does not affect processing that already took place.
- How data is collected
- Electronically and automatically, when you share a puzzle, open a link, delete a share or report a puzzle in the app.
- Who receives it
- Amazon Web Services (AWS): hosts our server and database in its data center in Ireland (EU) and sends our report alert emails via Amazon SES.
- Cloudflare, Inc. (USA): carries and protects the connection between the app and our server; it can see the encrypted package and your IP address, but not the key.
- Competent public authorities: only where the law requires it (for example, reporting illegal content).
- Data is never shared with anyone, or sold, for advertising, marketing or profiling.
- International transfers
- Our server is outside Türkiye (Ireland, EU) and connections pass through Cloudflare's global network, so sharing data is transferred abroad. The transfer relies on the explicit consent you give when sharing and takes place under our providers' data processing agreements. For users in the EU, transfers to Cloudflare rely on the EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
- The shared photo stays end-to-end encrypted in transit and for as long as it is stored.
- How long we keep it
- Encrypted puzzle package: 30 days at most; immediately if you delete it sooner. The one exception: if a share has been reported, its package is kept for review until its original expiry (still 30 days at most) even if the sender deletes it; the link opens for nobody during that time.
- The share's record (size, times, status): up to 30 more days after the package is deleted, so someone opening the link late can see that it expired. Then it is deleted completely.
- Reports: 90 days at most. The review key is deleted the moment the encrypted package is deleted.
- IP address: at most one hour in server memory; never written to a record, log file or backup.
- Server backups never contain encrypted packages; backups holding record details are kept for at most 30 days.
- Security
- The photo is encrypted on your device with AES-256-GCM (Apple CryptoKit). The key lives only in the part of the link after the # and is never sent to any server.
- The connection between the app and our network is encrypted with TLS, and because the shared photo is also end-to-end encrypted, it is never in readable form anywhere along the way. Server access logs are turned off for this service.
- Anyone who has the link can open the puzzle, so send it only to people you trust.
- Children
- Sharepiece is a general-audience app and is not directed to children under 13. The sharing feature is for adults 18 and over only. We do not knowingly collect personal data from children.
- If you notice that a child has shared something, or that a child's photo or data has been shared, write to taha@ikiz.dev and we will remove the share.
- Automated decisions and profiling
- We do no automated decision-making, profiling or tracking. Checking for inappropriate content (Apple's Sensitive Content Analysis) runs entirely on your device, and the result is never sent to us.
- Your rights
- Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent, and the right to lodge a complaint with the data protection authority in your country.
- Under KVKK Art. 11 you may learn whether your data is processed and request information about it, learn the purpose and whether it is used accordingly, know the third parties it is transferred to in Türkiye or abroad, request correction or deletion, request that third parties be notified, object to adverse outcomes of solely automated analysis and claim compensation for unlawful processing. You may also complain to the Turkish Personal Data Protection Board.
- How to make a request
- Write to taha@ikiz.dev. We answer free of charge within 30 days at the latest.
- Because we have no accounts, we can't link a share on the server to you by ourselves. You can delete your shares yourself in the app (Settings → Sharing); if your request is about a particular share, include its link and we'll find it.
- Changes
- When we change this notice we update the date below. For a significant change to sharing, the app asks for your consent again the next time you share.
For privacy questions, contact: taha@ikiz.dev
Last updated: 13 September 2026