Now on the App Store Download
Legal

Privacy Policy

This Privacy Policy explains how Sfumato Studios LLC collects, uses, stores, and shares information when you visit cadrelle.art or use the Cadrelle mobile application.

We collect as little personal information as reasonably possible. We do not sell personal information, and we do not build advertising profiles from your activity in Cadrelle. We do advertise Cadrelle on other platforms, and with your permission we share a small, fixed set of campaign milestones so we can tell which ads worked. Section 3 sets out exactly what that means and how to decline.

For privacy questions or requests, contact hello@cadrelle.art.

Last updated: 14 August 2026

1Who we are

Cadrelle is operated by Sfumato Studios LLC.

When this policy says “Cadrelle,” “Sfumato Studios,” “we,” “us,” or “our,” it means Sfumato Studios LLC.

2Information collected on the website

When you visit cadrelle.art, we use a small number of services to operate the website and understand aggregate traffic.

Launch list

Before Cadrelle launched, cadrelle.art offered a “Notify me” form that asked for one thing: your email address. That form has since been removed, but this section still governs any email addresses collected through it.

Email addresses submitted through that form were transmitted to Formspark, our form processor, which processed the submission on our behalf. Formspark may also have received ordinary technical data needed to process the form submission, such as IP address, browser type, device information, timestamp, and referring page.

We use any email address collected this way only to send Cadrelle launch-related communication unless you separately choose to receive more from us.

After the launch announcement or launch-related communication is complete, we intend to delete launch-list emails from our active systems unless you have separately opted in to future communication.

Website analytics

We use Vercel Web Analytics and PostHog to understand site traffic in aggregate.

Vercel Web Analytics helps us see information such as page views, top pages, referring sites, countries, and general usage patterns. We do not use it to create advertising profiles, identify individual visitors, or follow visitors across unrelated websites.

Vercel Web Analytics is designed without third-party cookies and provides privacy-preserving aggregate analytics. Like most web infrastructure services, Vercel may process technical request data needed to deliver and secure the website.

PostHog measures two things on this website: aggregate page views, and which App Store link was clicked. When you click a “Download on the App Store” link, we record that a click happened and the placement of the link that was clicked — for example the hero badge, the download section, the sticky bar, a page header, or the studio page. We record the placement, not you.

We run PostHog in cookieless mode. In this mode PostHog does not set cookies and does not store anything in your browser’s local storage or session storage, so nothing about this measurement persists on your device. Instead, PostHog processes ordinary technical request data — including your IP address, your browser information, and the site being visited — transiently on its servers to compute a privacy-preserving hash. Your IP address is not retained with the events we receive, and the hash cannot be reversed to identify you.

It is worth being precise about what that hash can and cannot do. It lets us count page views and App Store clicks coming from the same browser and network as one visitor for that day. It is built with a secret value that changes every day, so the same browser produces a different hash tomorrow and we cannot reliably recognize a returning visitor from one day to the next. It is also deliberately imprecise: people who share an IP address and the same browser — a household, an office network, or a mobile carrier — collapse into a single count, and one person who switches networks during the day can be counted more than once.

We use this only to understand roughly how many visitors reach the App Store link each day and from where. We do not use it for advertising, to identify individual visitors, or to follow visitors across unrelated websites, and it is not linked to anything you do inside the Cadrelle app.

Fonts and site assets

Cadrelle may load fonts, images, scripts, and other site assets needed to display the website. Where practical, we prefer to self-host assets to reduce unnecessary third-party requests.

If we use externally hosted fonts or assets, the provider may receive ordinary technical request data, such as your IP address, browser information, and the page requesting the asset.

What we do not use on the website

3Information collected in the app

Cadrelle is designed to be offline-first and privacy-forward.

Most gameplay and preferences — including paintings restored, notes read, quizzes completed, distinctions earned, and progress through the collection — stay on your device. We also collect a limited amount of anonymous product analytics, and we process subscription-management data through service providers. Both are described below.

This means:

We do not use your app activity to build advertising profiles, and the analytics described below are not linked to your real-world identity. Because no account is required, the anonymous product analytics we collect are tied only to a randomly generated identifier, not to you personally. Campaign measurement is a separate thing, described below, and it is off unless you turn it on.

Product analytics

We use PostHog, an analytics service, to understand how Cadrelle is used in aggregate and to improve the app. These product analytics are anonymous: events are tied to a randomly generated identifier, not to your name, email, or any account.

Examples of what we may collect include general app interactions, feature usage, puzzle and quiz activity, your chosen language, broad engagement metrics, and subscription status.

App install and campaign measurement

We advertise Cadrelle on other platforms, including Meta. Measuring whether those ads work happens in two separate ways. The first applies to everyone. The second happens only if you allow it.

Apple’s privacy-preserving attribution, for everyone. On launch, Cadrelle tells Apple’s attribution system that an install happened, using a single fixed value that carries no information about you. On newer versions of iOS it registers with both of Apple’s attribution frameworks, SKAdNetwork and AdAttributionKit; on older versions, with SKAdNetwork alone. That fixed value is the only thing the app supplies on this path: no record of your activity, no advertising identifier, and no user or device identifier of its own. Nothing you do after the install is measured this way, and the measurement window closes immediately, so no further value can be sent.

What happens next is Apple’s decision, not ours. If Apple can match the install to an ad, Apple sends a report, called a postback, to the platform that showed the ad, and Apple decides what that report contains. Meta may receive such a report for an install that came from a Meta campaign. Apple applies its own timing delays and privacy protections, including thresholds that reduce or withhold detail, and designs the system so that a report does not identify you to the advertising platform. This path asks for no permission because there is nothing in it that identifies you.

Meta app events, only if you allow tracking. Cadrelle includes Meta’s official iOS SDK. It does nothing at all unless two things are true at the same time:

Until you have allowed both, the SDK is never started, your device’s advertising identifier is not collected, and nothing reaches Meta from the app.

If you allow both and later change your mind, switching either one off disables Meta collection again: your advertising identifier is no longer collected, Meta’s automatic events stop, and none of the milestones below are sent. Both controls are re-checked when you change the setting in Cadrelle, every time you return to the app, and again before anything would be sent, so a change made in iOS Settings applies from that point onward. In a session where the SDK has already loaded, it is switched off rather than unloaded, and nothing further is sent from it.

If both are on, Meta receives a small, fixed set of campaign milestones:

That is the whole list. Meta is not sent your name, email address, phone number, or any account with us, because there is none. It is not sent which paintings you restore, what you read, how you answer quizzes, how long you take, or which language you use.

If you decline. If you decline the tracking prompt, or never answer it, only Apple’s path applies and nothing above reaches Meta. You can change your answer at any time in iOS Settings, under Privacy and Security, then Tracking. You can also switch Share Usage Data off in Cadrelle’s Settings, which stops the Meta events and the product analytics together. Either control stops further collection. Neither deletes what Meta already received, which is governed by Meta’s own policies.

What we get back. Aggregate campaign reporting: how many installs and how many milestones a campaign produced. There is no per-person record for us to export, and we do not attempt to join that reporting to the product analytics described above.

Content delivery

Cadrelle loads some editorial content, such as featured works and exhibitions, from a hosted content service (Supabase). The app only reads this content. No Cadrelle account or personal profile is involved, though the provider may process ordinary technical request data needed to deliver the content.

Device storage

Cadrelle may store app progress, preferences, completed puzzles, distinctions, and similar app data locally on your device.

If you delete the app, change devices, erase your device, or lose your device, locally stored app data may be lost unless your operating system or device backup settings preserve it.

Platform diagnostics

Apple, Google, and your operating system may provide crash reports, diagnostics, install information, device information, or similar platform-level data under their own privacy policies and device settings.

Those platform channels are separate from Cadrelle. We may receive aggregated or developer-facing diagnostic information from Apple or Google, but we do not use it to track your behavior across apps or websites.

4Purchases and memberships

Cadrelle memberships and in-app purchases are handled through the Apple App Store or Google Play, depending on where you purchase.

To manage memberships and entitlements, we use RevenueCat, a subscription-management service. Apple and Google handle all payment processing; RevenueCat helps us verify purchases, manage access to paid features, and restore purchases across your devices. To do this, RevenueCat may process information such as your subscription and entitlement status and app- or device-level identifiers needed for subscription management. It does not receive your payment card or bank details.

We do not receive your full card number, payment credentials, billing address, or bank information.

Depending on the platform, purchase flow, and technical implementation, we may receive or process purchase-related records needed to provide access, restore purchases, prevent fraud, comply with law, or support your membership. These records may include:

If you need to manage, cancel, or request a refund for a subscription purchased through Apple or Google, you must do so through the applicable platform.

5Children

Cadrelle is intended for a general audience interested in art, visual culture, and educational play. It is not directed to children under 13.

We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us at hello@cadrelle.art and we will take appropriate steps to delete it.

If a future version of Cadrelle is directed to children or includes child-specific features, we will update this policy and our platform disclosures before launch.

6How we use information

We use the limited information we collect for the following purposes:

We do not build advertising profiles from your activity in Cadrelle. Where you allow tracking, the campaign milestones described in Section 3 are shared with Meta for advertising measurement and campaign optimization, and Meta’s own use of them is governed by Meta’s policies.

7Processors and service providers

We may use service providers to operate Cadrelle. These providers process information on our behalf or provide platform services.

Current or expected providers may include:

We may replace, remove, or add providers as Cadrelle evolves. If we add a provider that materially changes how personal information is collected or used, we will update this policy.

8How long we keep information

We keep information only as long as reasonably necessary for the purpose for which it was collected.

Launch-list emails are intended to be kept only for launch-related communication unless you separately opt in to future communication.

Purchase and subscription records may be kept as long as needed to provide access, restore purchases, maintain business records, resolve disputes, prevent fraud, comply with platform rules, or meet legal obligations.

Support, legal, or privacy-request emails may be kept as long as reasonably necessary to respond, maintain records of the request, and comply with law.

Aggregate analytics may be kept in non-identifying form.

Campaign measurement data that Meta receives is kept under Meta’s own retention policies, not ours. What we hold is aggregate campaign reporting, which is not tied to a person and which we cannot use to identify you.

9Your privacy rights

Depending on where you live, you may have rights under privacy laws such as the GDPR, UK GDPR, California privacy law, and other applicable laws.

These rights may include the right to:

Because Cadrelle is designed to collect very little personal information, there may be limited information for us to provide or delete.

For advertising measurement specifically, the fastest way to withdraw permission is on your device rather than through a request to us: iOS Settings, then Privacy and Security, then Tracking, and the Share Usage Data setting under Settings in the app. Either takes effect immediately.

To make a privacy request, write to:

hello@cadrelle.art Subject line: Privacy request

We will respond within 30 days unless applicable law allows or requires a different period.

10California privacy notice

We do not sell personal information.

If you allow tracking, the campaign milestones and advertising identifier described in Section 3 are shared with Meta for advertising measurement and campaign optimization. Under California privacy law that may be treated as sharing for cross-context behavioral advertising. It happens only with your permission, and you can stop it at any time by declining or withdrawing tracking permission in iOS Settings, or by switching Share Usage Data off in Cadrelle’s Settings. Those two controls are our opt-out mechanism and we honor them immediately.

If you decline, no such sharing occurs, and only Apple’s privacy-preserving install measurement applies.

We do not knowingly sell or share the personal information of children under 16.

We do not use sensitive personal information to infer characteristics about you.

If California privacy law applies to your request, you may have the right to know, access, correct, delete, and limit certain uses of personal information, and the right not to be discriminated against for exercising privacy rights.

11International visitors

Cadrelle is operated from the United States.

If you access Cadrelle from outside the United States, your information may be processed in the United States or in other countries where our service providers operate. These countries may have privacy laws that differ from those in your country.

Where required, we rely on appropriate legal bases for processing personal information, including consent, contract necessity, legitimate interests, legal obligations, and the operation of requested services.

12Security

We use reasonable administrative, technical, and organizational measures to protect the limited information we process.

No website, app, platform, or transmission method is completely secure. We cannot guarantee absolute security, but we design Cadrelle to reduce risk by collecting as little personal information as reasonably possible.

13Changes to this policy

We may update this Privacy Policy from time to time.

If we make a material change, such as adding a new category of personal information collected by Cadrelle or introducing behavioral analytics, cloud accounts, or advertising tracking, we will update this page and, where appropriate, provide additional notice.

The “Last updated” date shows when this policy was last revised.

14Contact

For privacy questions or requests:

hello@cadrelle.art Subject line: Privacy request