Privacy Policy – Amtsschimmel
Last updated: 08.2026
This privacy policy explains which personal data is processed when you use the app Amtsschimmel (the "App"), on which legal basis this happens, and which rights you have. It applies to the App itself and to its Google Play Store listing. This is an English translation provided for convenience; in case of doubt, the German version prevails.
1. Controller
The controller within the meaning of the EU General Data Protection Regulation (GDPR) is:
Jonathan Zbick
Willy-Brandt-Platz 2d
44532 Lünen
Deutschland
E-Mail: jonathan@jjzb.de
2. Summary
- The App requires no account and no registration. Your game progress is stored only locally on your device – we have no access to it.
- Personal data is processed only in connection with advertising (Google AdMob), usage analytics (Google Firebase Analytics), crash reporting (Firebase Crashlytics), and in-app purchases (Google Play Billing, RevenueCat).
- Personalized advertising and usage analytics only take place with your consent. On first launch, the App shows a consent dialog; you can change your choices at any time in the App settings under "Privacy".
- The in-app purchase "Remove Ads" (
no_ads) permanently disables all advertising in the App.
3. Legal bases
We process personal data on the basis of:
- Art. 6(1)(a) GDPR (consent) – for personalized advertising and usage analytics; in addition, storing and reading information on your device is governed by Section 25(1) of the German TDDDG, unless technically necessary (Section 25(2) TDDDG).
- Art. 6(1)(b) GDPR (performance of a contract) – for processing in-app purchases and providing purchased content.
- Art. 6(1)(f) GDPR (legitimate interest) – for showing non-personalized advertising to fund the App, and for crash reporting to ensure stability and security.
You may withdraw any consent at any time with effect for the future (Art. 7(3) GDPR) in the App under Settings → Privacy.
4. Data stored locally on your device
The App stores the following data exclusively on your device (using the App's system storage):
- Game progress (advancement, currencies, unlocked content), including a randomly generated device value ("salt") used solely to protect the save file against tampering. It is never transmitted to us or third parties and cannot identify you.
- Settings (e.g. sound, language) and your privacy consent status.
This local storage is technically necessary to operate the App (Section 25(2) no. 2 TDDDG). The data is deleted when you clear the App's data in your Android settings or uninstall the App. Nothing is transmitted to us.
5. Consent management (Google UMP)
On first launch (and at any time via Settings → Privacy), the App shows a consent dialog provided by Google's User Messaging Platform (UMP). There you decide whether advertising is personalized or non-personalized and whether usage analytics is active. As part of consent management, Google processes technically necessary information (e.g. your consent status); the status is stored locally on your device. The legal basis is Art. 6(1)(c) GDPR in conjunction with our obligation to obtain verifiable consent.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
6. Advertising (Google AdMob)
The App is funded by advertising and uses Google AdMob (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). There are two ad formats:
- Rewarded videos: these start only when you actively tap them (e.g. "Watch a video for a ×2 bonus").
- Interstitial ads: shown occasionally at natural breaks in gameplay (e.g. after an "administrative reform"), never directly at app launch.
When serving ads, Google processes, among other things: the device's advertising ID, IP address, approximate location (derived from the IP address), device information (model, operating system, language setting), app identifier, and interactions with ads (e.g. impressions, clicks, video completion).
- Personalized advertising is only served if you have consented in the consent dialog (Art. 6(1)(a) GDPR, Section 25(1) TDDDG).
- Without consent, non-personalized, contextual advertising is shown (Art. 6(1)(f) GDPR; our legitimate interest is funding the App).
You can reset or delete your advertising ID in your Android settings (Settings → Google → Ads). Purchasing "Remove Ads" (no_ads) disables all advertising in the App.
More information: Google Privacy Policy · How Google uses data from partner apps
7. Usage analytics (Google Firebase Analytics)
To improve the App (e.g. game balance, identifying drop-off points), we use Google Firebase Analytics (provider: Google Ireland Limited). Analytics is only active if you have consented (Art. 6(1)(a) GDPR, Section 25(1) TDDDG); without consent, data collection is technically disabled.
The following is processed: pseudonymous identifiers (app instance ID), usage events (e.g. session start, game progress milestones, aggregated interaction counters – individual inputs are not recorded), device information (model, OS version, language), approximate region, and the IP address (used only briefly to determine the region). No names, email addresses, or contact details are collected.
User-level analytics data is automatically deleted after at most 14 months.
8. Crash reporting (Firebase Crashlytics)
To detect and fix crashes and errors, we use Firebase Crashlytics (provider: Google Ireland Limited). In the event of a crash, the following is transmitted: crash log (stack trace), device type and model, OS version, app version, time of the crash, and a pseudonymous installation identifier. Crash reports contain no save-game or contact data.
The legal basis is our legitimate interest in the stability and security of the App (Art. 6(1)(f) GDPR). You can object to the transmission of crash reports at any time in the App under Settings → Privacy.
9. In-app purchases (Google Play Billing and RevenueCat)
The App offers in-app purchases (e.g. Remove Ads, paperclip packs).
Payment processing: purchases are handled entirely by Google Play (Google Ireland Limited). Google acts as the merchant of record for the digital content. We never receive your payment details (e.g. credit card number). The Google Privacy Policy additionally applies.
Purchase validation: to verify and manage purchases (e.g. so that Remove Ads can be restored after reinstalling), we use RevenueCat (RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA) as a processor under Art. 28 GDPR. RevenueCat processes: a randomly generated, pseudonymous user ID, transaction data (purchased product, time, Google Play purchase token, price and currency), and technical details (app version, platform, language setting, IP address). No link to your name or email address is created.
The legal basis is Art. 6(1)(b) GDPR (performance of the contract for the purchase of digital content).
More information: RevenueCat Privacy Policy
10. Transfers to third countries
The services provided by Google and RevenueCat may involve transfers of personal data to the USA:
- Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF); in addition, the EU Standard Contractual Clauses apply between us and Google Ireland Limited.
- RevenueCat, Inc. safeguards transfers via the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
11. Retention
We ourselves store no personal data about you. For the services used: user-level analytics data is deleted after at most 14 months (see Section 7); crash reports are retained by Crashlytics for 90 days; transaction data is retained as long as necessary to provide purchased content and to comply with statutory retention obligations. Locally stored data (Section 4) remains on your device until you delete it.
12. Your rights
You have the following rights vis-à-vis the controller:
- Access to processed data (Art. 15 GDPR),
- Rectification of inaccurate data (Art. 16 GDPR),
- Erasure (Art. 17 GDPR),
- Restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR),
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR).
To exercise your rights, simply email jonathan@jjzb.de. Note: since we cannot identify individual users of the App (we store no account or contact data), we may only be able to respond to requests requiring identification to a limited extent (Art. 11 GDPR).
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), e.g. the authority responsible for your place of residence or for our registered office.
13. No automated decision-making, no obligation to provide data
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. You are neither legally nor contractually obliged to provide personal data; however, without the local storage described in Section 4, the App cannot technically function.
14. Children
The App is intended for users aged 13 and over and is not directed at children under 13. We do not knowingly collect data from children. In Germany, personalized advertising requires valid consent, which minors under 16 can only give with the approval of a parent or guardian (Art. 8 GDPR).
15. Changes to this privacy policy
We will update this privacy policy when the App or the legal situation changes (e.g. new features or services). The current version is always available in the App under Settings → Privacy and at https://jjzb.de/privacy/.
Diese Erklärung ist auch auf Deutsch verfügbar: Datenschutzerklärung (Deutsch)