Intentionally Creative — Analytics and Advertising Partners
Last updated: September 5, 2026 · rev 6
This page names every third-party service that receives any data from our apps, what each one receives, and how to stop it. It is referenced by, and forms part of, our Privacy Policy.
There are four, and only four. We do not use a social-login SDK, a push-notification service, a crash reporter, a customer-messaging SDK, a tag manager or an ad-network SDK other than the one named below.
Our own server is not on this list, because it is not a third party. Each app stores some of your data on our own server infrastructure, which we operate ourselves — see Section 2.4 of the Privacy Policy. None of it is sent to any of the four services below, and none of them can reach it.
Milestone can schedule reminders, and that is not a fifth partner: those are local notifications the phone gives itself, with no push service, no push token and no server involved — the build strips the push entitlement it does not use. There is nobody to name because nobody receives anything.
The split that matters: games vs. utility apps
| Parcel Yard<br>game | Pack Perfect<br>game | Before I Unpack<br>utility | Milestone<br>utility | |
|---|---|---|---|---|
| PostHog — product analytics | Yes, on by default | Yes, on by default | Yes, OFF by default | Yes, on by default |
| AppsFlyer — install attribution | Yes, with the advertising ID after ATT on an Apple device, or the Google Advertising ID on Android | Yes, same | Yes, advertising IDs disabled, only after you opt in | Yes, advertising IDs disabled |
| AppLovin MAX — advertising | Yes — rewarded + capped interstitial | Yes — rewarded only | No SDK at all | No SDK at all |
| RevenueCat — purchases | Yes | Yes | Yes | Yes |
| Apple ATT prompt (Apple devices only) | Yes, once, at the first ad | Yes, once, at the rewarded hint | Never | Never |
| Google UMP consent form (Android, and the EEA/UK/CH mechanism) | Yes, before the first ad | Yes, before the first ad | Never — no ad SDK | Never — no ad SDK |
| Advertising ID on Android | Used | Used | The permission is removed from the app | The permission is removed from the app |
In our games — Parcel Yard and Pack Perfect
1. AppLovin MAX — advertising and mediation
- Company: AppLovin Corporation
- Privacy policy: https://www.applovin.com/privacy/
- Opt out: https://www.applovin.com/optout/
- GDPR information: https://www.applovin.com/gdpr/
What it is. AppLovin MAX is an advertising mediation layer. When one of our games has an ad to show, MAX runs an auction and hands the placement to whichever advertising network bids highest.
What it receives:
- Device identifiers — on an Apple device the vendor identifier (IDFV) always, and the advertising identifier (IDFA) only if you allowed tracking when the app asked; on Android the Google Advertising ID (GAID), unless you have deleted it in Android Settings → Google → Ads
- Device and system information — model, operating system and version, language, country/region, time zone
- IP address, from which a coarse country or region is derived
- App information — app version and bundle identifier
- Ad events — requests, impressions, clicks, and the revenue an impression produced
- Consent and privacy signals — your tracking answer and your consent-form answer, so that networks can honor them
The mediated networks. This is the part of the page most companies get vague about, so here is our position stated exactly:
When MAX fills a placement, it passes the ad request to the advertising networks we have enabled in the MAX dashboard, and each of those networks is an independent controller of the data it receives for its own advertising purposes. As of the date at the top of this page we have enabled no mediated networks, because our games have not launched. Before any mediated network serves a single ad in our games, this page will list it by name, with the data it receives and a link to its own privacy policy — the same table shape used above. AppLovin publishes its own list of MAX mediation partners at https://www.applovin.com/max-partners/.
How to stop it:
- Buy "Remove ads" in Parcel Yard — it permanently removes interstitial advertising. (Rewarded videos remain available if you choose to watch one.) Parcel Yard's interstitials are capped at four a day, never appear on your first day or in your first session, never appear before board 15, and never appear within a minute of a rewarded video. Neither game shows banner, MREC or app-open ads at all.
- Settings → Ad & data choices in the game reopens the consent form and shows your tracking status.
- On an Apple device: iOS Settings → Privacy & Security → Tracking — turn tracking off for the app. The advertising identifier becomes unavailable and the ads you see are non-personalized.
- On an Android device: Settings → Google → Ads → Delete advertising ID (older versions call it Opt out of Ads personalisation). Android has no per-app tracking prompt; this is the system's own control and it applies to every app on the phone at once. Our games then receive a string of zeros and the ads you see are non-personalized.
- AppLovin's own opt-out, at the link above.
- Simply never tap a rewarded video. In Pack Perfect that is the only ad there is.
2. Apple App Tracking Transparency (ATT)
- Whose it is: Apple Inc. — part of iOS, not an SDK we add
- Apple's explanation: https://support.apple.com/en-us/102420
- Apple's developer rules: https://developer.apple.com/app-store/user-privacy-and-data-use/
What it is. ATT is the iOS permission that decides whether an app may use your advertising identifier or otherwise link your activity to other companies' data. When you tap "Ask App Not to Track," the advertising identifier returns all zeros and our advertising and attribution partners cannot use it.
How our games ask. Once, at the first moment an ad is actually on offer — never at launch, never during onboarding, and never behind a "pre-permission" screen designed to pressure a yes. In Pack Perfect, that moment is your tap on "Watch a short video for one hint."
Saying no costs you nothing. The video still plays, the hint still arrives, the reward is the same, nothing is hidden, and the app does not ask again. Ads simply become non-personalized.
Our utility apps never show this prompt, because they contain nothing that would need it.
2a. Google's User Messaging Platform (UMP) consent form — Android
- Whose it is: Google LLC — presented for us by AppLovin MAX, which integrates it; we do not build our own consent screen
- Google's explanation: https://support.google.com/admob/answer/10113004
- AppLovin's description of the flow: https://support.applovin.com/en/max/android/overview/privacy
What it is, and why this section exists. Android has no App Tracking Transparency. There is no system prompt that asks, per app, whether you may be tracked. So on Android the consent form our games show you before the first ad is the whole mechanism: it is Google's UMP form, it is what asks for your consent to personalised advertising in the European Economic Area, the United Kingdom and Switzerland, and your answer is passed on as a standard consent signal to every advertising network in the chain.
How our games ask. The form is shown before an ad is served, in the regions where consent is required, and never as a wall in front of the game. You can reopen it at any time from Settings → Ad & data choices and change your answer.
Saying no costs you nothing. The video still plays, the hint still arrives, the reward is the same, and nothing is hidden. Ads simply become non-personalized.
The device-level control is separate and is yours regardless: Android Settings → Google → Ads → Delete advertising ID. It applies to every app on the phone, ours included, and it does not depend on any answer you gave us.
Our utility apps never show this form either, because they contain no ad SDK — and on Android they go further: the advertising-ID permission is removed from those apps entirely, so there is no advertising identifier on either platform, not one we choose not to read.
In all four apps
3. AppsFlyer — install attribution and measurement
- Company: AppsFlyer Ltd.
- Privacy policy for end users of apps using AppsFlyer: https://www.appsflyer.com/legal/services-privacy-policy/
- AppsFlyer's own privacy policy: https://www.appsflyer.com/legal/privacy-policy/
- Opt out: https://www.appsflyer.com/legal/opt-out/
What it is. A mobile measurement partner. It tells us, at the level of a marketing campaign, that installs came from a particular ad — so we do not spend money on advertising that does not work. It is required in order to run advertising campaigns on AppLovin at all.
What it receives — and this differs by app:
In our games (Parcel Yard, Pack Perfect):
- Device identifiers — the AppsFlyer ID always; on an Apple device the IDFV, and the IDFA only if you allowed tracking; on Android the Google Advertising ID, unless you have deleted it in Android Settings → Google → Ads
- Device and system information, IP address (coarse country), app information
- A short, named list of in-app events, and ad-revenue events
- The SDK starts only after the tracking prompt has been answered, either way
In Before I Unpack:
- No advertising identifier, ever, on either platform. The SDK is started with advertising identifier collection explicitly disabled, and device-name collection disabled with it — "Sam's phone" is a person's own words. On Android we go one step further than a setting: the advertising-ID permission is removed from the app, so this app cannot read the Google Advertising ID at all, even though the attribution component inside it would otherwise ask for it.
- **It does not start at all until you turn on Share anonymous usage, which is off by default.**
- The events it may receive are exactly:
activated,record_completed,pdf_exported,landlord_sent,compare_reviewed,purchase_completed. Nothing else, ever — the app's own code refuses anything outside that list. - Attribution runs through Apple's SKAdNetwork on Apple devices, and the Google Play Install Referrer on Android — the latter tells us which campaign a download came from and carries no identifier of you. Both return aggregated postbacks containing no user identifier by design.
In Milestone:
- No advertising identifier, ever, on either platform — the same explicit disabling, the same reason, and on Android the same removal of the advertising-ID permission from the app. A note on one thing that is not protection: this app sets AppsFlyer's "strict mode" flag, and that flag is implemented for Apple devices only. On Android what carries the promise is the removed permission and the event allowlist, not the flag.
- A short list of allowlisted events with allowlisted properties, and the app's locale. No name, amount, note, photograph, phone number, venue, date or row identifier can be in any of them.
How to stop it:
- The switch in the app's Settings — Share usage analytics / Share anonymous usage / Ayudar a mejorar la app. In Before I Unpack and Milestone this stops attribution as well as analytics, at the app, not just at the provider.
- On an Apple device: iOS Settings → Privacy & Security → Tracking (games).
- On an Android device: Settings → Google → Ads → Delete advertising ID (games; our utility apps cannot read it in any case).
- AppsFlyer's own opt-out, at the link above.
4. PostHog — product analytics
- Company: PostHog, Inc.
- Privacy policy: https://posthog.com/privacy
- Data processing agreement: https://posthog.com/dpa
- EU hosting: https://posthog.com/eu
What it is. First-party product analytics: it counts how many people finished a level, exported a document, or reached a screen. It is not an advertising product, joins nothing to another company's data, and reaches no data broker.
What it receives: a random, device-local identifier it generates itself; the event names on that app's declared list with their allowlisted properties; app version; device and OS information; and locale.
What is switched off in every one of our apps, deliberately:
| Off | Why |
|---|---|
| Session replay | It records the screen, and the screen contains your board, your home or your daughter's photographs |
| Autocapture | It reads the text of the views it touches, which in Milestone is a girl's name |
| Vendor lifecycle events | They are a second, differently shaped answer to a question our own events already answer, outside our declared list |
| Error/console autocapture (Before I Unpack) | Our own error strings name files on your phone |
| IP-based location lookup (Before I Unpack, Milestone) | Neither app has any use for a location |
Where it is hosted: PostHog EU Cloud for Parcel Yard, Pack Perfect and Before I Unpack. PostHog US Cloud for Milestone.
How to stop it: the switch in each app's Settings. Turning it off stops collection at the app and opts the provider out; it does not merely mute the sending. In Before I Unpack it is off until you turn it on.
5. RevenueCat — purchases and entitlements
- Company: RevenueCat, Inc.
- Privacy policy: https://www.revenuecat.com/privacy
- Data processing agreement: https://www.revenuecat.com/dpa/
What it is. The service that knows whether you bought the one-time unlock, and that makes Restore purchases work on a new device. It is not an advertising or analytics product.
What it receives: an anonymous app user ID it generates itself; the product identifier, transaction identifier and store receipt; and entitlement status. We never send it a name, an email address or any subscriber attribute, because we do not have one.
It is the one provider that runs before the analytics question in Before I Unpack, and that is deliberate: somebody who paid must get what they paid for on a fresh install, and holding an unlock hostage to an unrelated second "yes" would be the dark pattern, not the fix.
How to stop it: you cannot switch it off and still receive what you bought. If you have made no purchase, it holds nothing but an anonymous identifier.
Payment data
We never receive it. Apple or Google — the store you bought from — processes every payment, and we do not see and cannot store your card number, bank details or billing address. Refunds are handled by the store you bought from — Apple at https://reportaproblem.apple.com, Google at https://play.google.com/store/account.
Keeping this page true
If we add a provider, enable a mediated ad network, change where analytics is hosted, or change what any provider receives, this page changes in the same release and the "Last updated" date moves. A partners page that lags the binary is the failure this page exists to prevent.
Questions: support@get-creative.co
Change log
- September 3, 2026 · rev 5 — Revised with the suite, which carries one date across all four documents. No partner, no data category, no purpose and no opt-out route changed on this page. The change that prompted the revision is Parcel Yard's optional email / Apple ID sign-in (Privacy Policy §2.4), and an address attached that way is never sent to any partner named here.
- September 1, 2026 · rev 4 — Hosting move only. This page is now published at https://legal.alc.fyi/legal/partners.html, and every URL on it points at that host. No partner, no data flow and no opt-out route on this page changed, and the contact is still support@get-creative.co.
- September 1, 2026 · rev 3 — Publisher rename only. Intentionally Creative (get-creative.co), contact support@get-creative.co, page hosted under the studio's own domain (superseded at rev 4). No partner, no data flow and no opt-out route on this page changed.
- September 1, 2026 · rev 2 — Added one clarification only: our own server is not on this page because it is ours, not a third party's, and nothing it holds reaches any of the four services named here. No partner, no data flow and no opt-out route on this page changed.
- September 1, 2026 · rev 1 — First draft of the suite.