Security Policy

Last updated: September 18, 2026

1. Our Commitment

Stack Cards Sort is published by Guse LTDA. Most security policies describe how a company guards the data it has collected. This one mostly describes data we chose never to collect — which is the strongest protection we can offer — and then how we protect the little that does exist.

2. Security by Architecture

The game has no accounts, no login, no password and no server of ours. There is no players database, so there is nothing to breach, no credentials to steal, and no reset link to intercept. The app contains no analytics SDK, no advertising SDK and no third-party network code of any kind.

The only network feature in the game is Apple's Game Center, and it is optional.

3. On Your Device

Progress, settings and the in-progress level are written to your iPhone's own app storage and stay there. They are not credentials, so they are stored as ordinary app data rather than in the Keychain; iOS keeps them inside the app's sandbox, where other apps cannot read them, and removing the app removes them.

If you use iCloud or encrypted device backups, these values may be included in your own backup, protected by Apple's backup encryption.

4. What Apple Handles

Two things are deliberately delegated to Apple rather than built by us:

  • Payment. The one-time Pro unlock is processed entirely by the App Store. We never receive card numbers or billing details. The app verifies the purchase with StoreKit on the device.
  • Game Center. If you are signed in, your leaderboard score, two achievements and a saved copy of your progress are held by Apple under Apple's own security and privacy practices.

5. This Website

The website runs on Cloudflare Workers. Every request is served over HTTPS/TLS and passes through Cloudflare's network. The contact form is protected by Cloudflare Turnstile and its input is validated before anything is sent. Credentials used by the site are held as environment secrets and never appear in the client-side code or in this repository.

6. Incident Response

If a security incident occurs, we will: contain it; investigate its scope, cause and what was affected; notify affected people and the relevant authorities within 72 hours where the law requires it; remediate the cause; and publish what we changed.

7. Responsible Disclosure

If you find a vulnerability in the app or on this website, please report it to contact@guseapp.com with the subject "Security Vulnerability". Include the steps to reproduce it, give us reasonable time to fix it before disclosing it publicly, and do not go further into a system than is needed to demonstrate the problem. We aim to acknowledge reports within 24 hours and we credit researchers who want to be credited.

8. Contact

  • Security reports: contact@guseapp.com (subject: "Security")
  • Acknowledgement target: within 24 hours