1. Data controller and contact
Roland K. (MindSyntax)
Email:
r.kerner.developer@gmail.com
This privacy policy explains which personal data the app processes, why that data is required, and which options you have to manage and delete your data.
2. Data processed
2.1 Account and sign-in
The following data is processed for registration, sign-in, and account recovery:
- email address and the username you choose,
- the unique user identifier assigned by Firebase Authentication (Firebase UID),
- Firebase ID and refresh tokens used to maintain the signed-in session, and
- the password during registration, sign-in, or renewed authentication.
The password is transmitted to Firebase Authentication. It is not stored as readable text in the app profile or in Firebase Realtime Database. ID and refresh tokens are required locally on the device so protected requests can be associated with the signed-in account.
2.2 Device identifier, game progress, and settings
For synchronization, recovery, and gameplay, the app processes:
- a hashed device identifier. It is derived from an Android device identifier and the installation source. If no usable device identifier is available, the device model, device name, and processor type may be included when the hash is generated,
- game progress, total score, timestamps, remaining attempts, grid size, and the selected game mode,
- app settings such as sound status and other locally stored gameplay or display settings.
A hashed identifier is pseudonymized, but not necessarily anonymous. It is used in particular to recognize a device change and restore content that has already been unlocked.
2.3 Public leaderboard
When a score is submitted to the leaderboard, the username and score are visible to other users of the app. The email address, Firebase UID, and purchase data are not displayed on the public leaderboard. Please do not use a username that contains unnecessary personal information.
2.4 In-app purchases and image packs
The app uses Google Play Billing for optional image packs. In connection with a purchase, the app processes in particular:
- product ID and pack type,
- purchase token and, where supplied by Google Play, the order ID,
- purchase, verification, and status information, including timestamps,
- the verification status, such as pending, confirmed, consumed, cancelled, or refunded,
- the image names assigned to the purchase and information about images that have already been downloaded.
To associate a Google Play purchase with the signed-in account, a SHA-256 hash of the Firebase UID may also be sent to Google Play Billing as an obfuscated account identifier. The purchase token is verified with Google Play on the server. After a repeatable pack has been fully delivered, the purchase may be acknowledged as consumed through Google Play.
Google handles the payment itself and processes payment information such as card or bank account details. MindSyntax does not receive complete payment information.
2.5 Data stored locally on the device
The following data may be stored on the device:
- username, email address, Firebase UID, hashed device identifier, sign-in status, ID token, refresh token, and ID-token expiration time,
-
game progress, scores, attempts, settings, and purchase associations in app
preferences and local storage files, in particular
puzzle_score.save, - downloaded puzzle images and technically necessary local transaction markers.
This data is stored in the app's private storage on the device. The app asks Android not to include this storage in a cloud backup or direct device transfer. Different behavior by individual device manufacturers, which is beyond the app's control, cannot be ruled out completely.
2.6 Technical connection data
When online features are used, Google services receive technically necessary connection data, in particular the IP address, time, requested service, and information about whether the transmission succeeded. This data may be processed in the security and operational logs of the respective services.
3. Purposes and legal bases
The data described above is processed for the following purposes:
- providing and securing the user account, synchronizing game progress, and providing app features – Article 6(1)(b) GDPR,
- processing, verifying, confirming, and restoring in-app purchases – Article 6(1)(b) GDPR,
- operating the public leaderboard used by the user – Article 6(1)(b) GDPR,
- protecting against misuse, repeated unauthorized redemption, manipulation, and attacks, and securing technical operation – Article 6(1)(f) GDPR. The legitimate interest is the security and proper functioning of the app and its purchase processing,
- complying with legal documentation or retention obligations where these apply in an individual case – Article 6(1)(c) GDPR.
4. Services used
4.1 Firebase Authentication
Google's Firebase Authentication is used for registration, sign-in, password resets, and issuing session tokens.
4.2 Firebase Realtime Database
Firebase Realtime Database stores account-related app data such as username, email address, Firebase UID, hashed device identifiers, game progress, attempts, settings, high score, and purchase and image associations managed on the server.
4.3 Firebase Storage
Firebase Storage hosts the puzzle images offered by the app. Protected images are delivered only after the account-related authorization has been checked.
4.4 Firebase / Google Cloud Functions
Server-side functions process account requests, purchase tokens, image
permissions, downloads, account deletions, and leaderboard requests, among
other operations. The Cloud Functions currently used run in the
us-central1 region.
4.5 Google Play Billing
Google Play Billing provides the products and purchase dialogs, processes the payment, and supplies the purchase status. Google processes this data under the terms and privacy information that apply to the Google account and Google Play.
5. Recipients and processing outside the EEA
The recipient of the data required for the respective features is, in particular, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, including affiliated companies and appointed subcontractors for Firebase, Google Cloud, and Google Play.
Google services may also process data outside the European Union or the European Economic Area. Google's data-protection and data-transfer mechanisms for the respective service apply. Further information is available in the Google Privacy Policy and Privacy and Security in Firebase.
Personal data is not sold. It is transferred to other parties only when this is required for the services named above, required by law, or necessary to respond to specific security incidents.
6. Retention periods
There is no single retention period for every type of data. The retention period depends on the respective purpose:
- Account, profile, game-progress, and purchase-association data is generally retained while the account exists and the data is needed for synchronization, purchase verification, or content restoration.
- A leaderboard entry remains stored until it is updated or the associated account is deleted.
- Local session, game-progress, and image files generally remain until sign-out, account deletion, deletion of the app data, or uninstallation. Device backups may exist independently of this.
- Purchase and verification records may be retained beyond active use where this is necessary to handle refunds, prevent misuse, or comply with legal obligations.
- Technical logs and data processed independently by Google are subject to the retention rules and settings of the respective Google service.
Data is deleted or anonymized when its purpose no longer applies and there are no legal or security-related reasons for further retention.
7. Account and data deletion
7.1 Deletion directly in the app
- Open the menu in the app and then open the “Setup” section.
- Select “Delete Account” or “Konto löschen”.
- Confirm the prompts displayed.
- For the security check, enter the username and password of the signed-in account and confirm the deletion.
The app then requests deletion of the Firebase sign-in account, the associated app profile, the public high score, and the internal purchase-token associations. After a successful server response, the local session, app settings, game-progress files, and downloaded content managed by the app are removed. An internet connection is required for deletion.
Deleting an account in Puzzle-Paradies does not automatically delete data that Google Play processes independently for payments, order history, or legal records. You manage this data through your Google account or Google Play Support.
7.2 Deletion request outside the app
If you can no longer use the app, send your deletion request to r.kerner.developer@gmail.com. Include the username and, where possible, write from the email address associated with the account. To protect against unauthorized deletion requests, reasonable verification of account ownership may be required. Never send your password, ID or refresh token, or a complete purchase token by email.
8. Your rights
Where the applicable legal requirements are met, you have in particular the right to:
- obtain information about your personal data being processed,
- correct inaccurate data,
- request deletion or restriction of processing,
- data portability,
- object to processing based on legitimate interests.
To exercise your rights, contact r.kerner.developer@gmail.com. You also have the right to lodge a complaint with a competent data-protection authority.
9. Data security
The app uses encrypted HTTPS connections, Firebase session tokens, and server-side authorization checks. However, no technical measure can guarantee absolute protection. You should therefore also protect your device and Google account against unauthorized access.
10. Children
The app does not collect a date of birth. If a parent or guardian believes that a child has created an account without the required consent, they may contact us using the email address above. The account will be handled in accordance with the applicable legal requirements.
11. Changes to this privacy policy
This policy is updated when features, data flows, or legal requirements change. The version published at this address is the applicable version.