JewelTap Privacy Policy
Version 1.2 · Last updated:
You can play JewelTap without signing in. Your progress is then saved on your device. Signing in with Google lets you save it in the cloud. Advertising and purchases are additional features.
This policy covers the JewelTap Android app, including World Journey, Challenge, cloud saves and related server services. It also addresses parents and guardians. See “Children and parents” for information about use by children.
Controller and contact
The controller is Digital-e UG (haftungsbeschränkt), represented by managing director Kurt Laabs, Norderstraße 47, 25436 Tornesch, Germany. Privacy enquiries: anfrage@digital-e.org. Product support: kurt.laabs@digital-e.org.
We determine the purposes and means of our processing described below. Google also processes certain data for its own purposes, for example in connection with your Google account, Google Play and advertising.
Gameplay and local storage
The app stores saves and settings in a local database on your device. These include level and map progress, stars, experience, diamonds, energy and regeneration times, items, selected and unlocked characters, tutorial status, language, music, volume, and reward and synchronisation timestamps. Random game and change identifiers distinguish saves and updates. Position and camera values refer only to the game world, not your physical location.
World Journey and Challenge are calculated on the device. Challenge rewards become part of the save. There is no public leaderboard, chat or publication of your profile. Images, fonts and audio are bundled with the app.
Without sign-in, no guest save is uploaded to our cloud. Online services may still process technical data, particularly for advertising and store access. Local storage provides the game you request (Article 6(1)(b) GDPR, where personal data is involved). Strictly necessary device storage is based on section 25(2)(2) of Germany’s TDDDG.
Optional Google sign-in
We use Google Sign-In and Firebase Authentication when you sign in. Google provides a Google user identifier, email address, display name and, where available, a profile image URL. Firebase manages its own user identifier, sign-in status, sign-in timestamps and authentication tokens. IP addresses, device/browser information and security data are also processed. We do not receive your Google password.
Your display name appears in settings. The user identifier connects your account to its save and purchase entitlements. Sign-in information is kept on the device to maintain the session. On first sign-in, existing guest progress may be transferred to the signed-in profile. If local and cloud saves differ, the app lets you choose which to use.
The legal bases are Article 6(1)(b) GDPR for the account feature you choose and Article 6(1)(f) for secure authentication and preventing abuse. Without this information, you can play as a guest but cannot use cloud synchronisation or account-linked purchases.
For store review access that we authorise, there is an additional sign-in using a predefined test account name and password. The server checks the password against a stored salted verification value and issues a Firebase sign-in token. We store the test account name, associated user identifier and access status. These accounts are solely for app review, not general registration; several authorised reviewers may use the same test profile. Please do not add personal content to it. Credentials and account associations are retained until the review access is changed or removed; after account deletion, the next authorised test sign-in may create a new test profile. The legal basis is our legitimate interest in reviewing and publishing the app (Article 6(1)(f) GDPR).
Cloud saves and server operations
After sign-in, the gameplay and settings data described above are stored under your Firebase user identifier in Firebase Realtime Database and synchronised when changed. This also includes revision counters, change identifiers and a purchase ledger. The app checks purchase entitlements at startup, after relevant events and regularly during use.
The database and Cloud Functions are configured in europe-west1 (Belgium). We also use Google Cloud Run, Pub/Sub, Eventarc, Cloud Scheduler and Cloud Logging for purchase verification, refund notifications, deletion and operations. Requests generate IP addresses, timestamps, the requested service, response status and technical error/connection data. Account-related request counters and temporary processing locks protect against excessive or conflicting requests.
The legal bases are Article 6(1)(b) GDPR for storage, synchronisation and purchase delivery, and Article 6(1)(f) for security, troubleshooting and preventing duplicate credits. The European region does not mean that every Google service processes data exclusively in Europe.
Rewarded advertising and consent
Where enabled in the build you use, JewelTap offers optional rewarded videos through Google AdMob / Google Mobile Ads. Completing a video credits the game reward. Ads may be loaded before you tap the advertising button. When a “Remove ads” purchase is active, the app does not load new rewarded ads; this does not disable every Google service.
The advertising SDK may process your IP address and an approximate region inferred from it, advertising ID, app set ID and other device/account identifiers, app and device information, ad impressions, interactions, video views and diagnostics. Purposes include ad delivery, personalisation where applicable, measurement and fraud prevention. The Android manifest enables access to the advertising ID. The app does not expressly include your cloud save or Google email address in its ad request.
Google’s User Messaging Platform (UMP) checks consent status and displays required privacy dialogs. This processes technical connection data and your choices and stores consent information on the device. Ad initialisation follows UMP’s permission to request ads. This permission does not necessarily mean consent to personalised advertising. The specific purposes and vendors displayed depend on the advertising configuration.
Consent-required advertising processing is based on Article 6(1)(a) GDPR; corresponding device access is based on section 25(1) TDDDG. Non-personalised advertising is not automatically exempt from consent. Strictly necessary storage of your privacy choice falls under section 25(2)(2) TDDDG; managing that choice fulfils legal obligations (Article 6(1)(c) GDPR). “Privacy options” appears under “Privacy & help” when UMP requires this entry point. You can change your choices there and withdraw consent for the future. Earlier lawful processing remains unaffected. You can also reset or delete the advertising ID in Android settings.
In-app purchases and restoration
The built-in shop uses Google Play Billing for one-time purchases such as diamonds, items, energy and “Remove ads”. The built-in catalogue contains no subscriptions.
Purchases require Google sign-in in JewelTap. Google processes payment details. Our service receives a product identifier, purchase token, purchase/refund status and save revision. It verifies the purchase through the Google Play Developer API and associates it with a user identifier and a SHA-256 value derived from the Google user identifier. This account verification value is also sent to Google Play.
Stored information includes a hash of the purchase token, product identifier, account association, timestamps and entitlement/revocation status. The original purchase token is processed for verification but is not permanently stored in our backend database or intentionally logged. Hash values are not automatically anonymous. Full card or bank details are not stored in our game database.
Restoration, purchase acknowledgement and refund reconciliation use Google Play, server notifications and periodic requests. Legal bases: Article 6(1)(b) GDPR for purchases and delivery, Article 6(1)(f) for fraud prevention and preventing duplicate credits, and Article 6(1)(c) for applicable statutory record-keeping obligations.
Local error diagnostics
The app keeps up to 25 diagnostic events locally. Each contains a timestamp, error category and up to 35 shortened technical stack lines. Our diagnostic store does not record error-message text, account details or complete SDK responses. Exported diagnostics also include the build label.
“Copy diagnostics” writes this information to the clipboard at your request. We receive it only if you send it yourself. There are no app integrations of Firebase Analytics, Crashlytics or Sentry. This does not cover the separate telemetry of Google services and advertising described elsewhere.
Limited local diagnostics support stability and troubleshooting (Article 6(1)(f) GDPR); an export you request supports your enquiry (Article 6(1)(b)). Strictly necessary technical device storage is governed by section 25(2)(2) TDDDG.
Support, email and external pages
The support feature opens your email app. We receive only what you send, such as your email address, message, game identifier, proof of purchase or voluntarily attached diagnostics. Please do not send passwords or full payment details. Incoming email uses IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany; senders’ email providers also participate in transmission.
We process enquiries to handle your request (Article 6(1)(b) GDPR), other correspondence in our legitimate interest in responding (Article 6(1)(f)), and rights requests to fulfil legal obligations (Article 6(1)(c)). Privacy links open an external browser. This website’s privacy policy, including Firebase Hosting, also applies when you visit it.
Device features
JewelTap uses internet access, local app storage, the device language and a feature that keeps the screen awake while playing. Its gameplay features do not access contacts, photos, microphone recordings or precise GPS locations. A camera position in a save is not an image from your device’s camera.
The operating system and store may process their own backup, installation, purchase and diagnostic data. System backups may contain local app data. The relevant device and account settings are managed by the platform provider.
Children and parents
JewelTap is intended for all ages and can be played without an account. The app prepared for release asks neutrally for an age group before the first game launch. You can choose not to answer. The choice is stored on this device separately from the game save and is not included in the cloud profile. No date of birth is requested. You can change the age group under Privacy & help. This self-declaration is not verified age assurance or parental consent.
For users under 16 and users of unknown age, the app sets AdMob child treatment. For users aged 16 or 17, it sets teen treatment. Google describes these settings as disabling personalized advertising and remarketing. Child treatment also prevents transmission of the Android advertising ID and requests to additional advertising technology vendors. All age groups receive a maximum ad content rating of G. UMP receives the under-age flag for users under 16 and users of unknown age and does not show them a consent form. These treatment flags are sent to Google. The age-group selection itself remains local.
Where processing in an online service offered directly to a child relies on consent, consent or authorisation by a guardian is required in Germany for children under 16 (Article 8 GDPR). Other countries have different thresholds; in particular, US law provides protections for children under 13. A child’s selection in an advertising dialog does not replace required parental consent.
Parents should review optional online features together with their child. Google accounts and purchases are also subject to Google’s requirements and rules on representing minors. Guardians may contact us to request access, correction or deletion of their child’s data and an end to further processing requiring consent. We verify their authority using as little additional information as necessary.
Recipients and service providers
Access is limited to authorised persons at Digital-e and providers needed for the chosen feature. Google Cloud and paid Firebase services generally involve Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland. Google accounts, Play and AdMob for European users involve in particular Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as well as Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Firebase/Cloud processing on our behalf is subject to the relevant Google data-processing terms. Google may act as a separate controller for its own account, store and advertising purposes. Additional advertising partners are identified through the vendor information and privacy options actually displayed. IONOS processes email data. Authorities, courts or legal advisers receive data only where legally required or necessary to establish or defend claims. Saves are not made accessible to other players.
Processing outside Europe
Even with a database in Belgium, Google services may process data outside the EU/EEA, particularly in the USA. This includes authentication, advertising, store transactions and support/security processes. We do not promise exclusively European processing of all data.
Transfers to appropriately certified US companies may rely on the EU-US Data Privacy Framework adequacy decision. Where that does not apply, safeguards include EU Standard Contractual Clauses and necessary supplementary measures under Article 46 GDPR. You can request information and a copy of the applicable safeguards through our privacy contact.
Retention periods
Retention depends on the feature. Simply signing out or uninstalling the app does not delete a cloud account. Where legal obligations or specific claims require longer retention, only the necessary data is retained and then deleted.
- Local profiles and settings: until app data is cleared or the app is uninstalled, subject to operating-system backups. Account profiles remain locally after sign-out; successful account deletion removes the affected local profile on the device used.
- Cloud saves and account associations: for the life of the account, until account deletion or a valid erasure request. Automatic deletion solely for inactivity is not currently configured.
- Firebase Authentication: Google states that logged IP addresses are kept for a few weeks; after user deletion is initiated, removal from live and backup systems can take up to 180 days. Realtime Database retains technical IP/user-agent data for a few days according to Google.
- Our function/operational logs in the regional Google Cloud log store: 30 days. Other Google service-specific security/administrative logs follow their respective retention periods.
- Local diagnostics: at most the last 25 events, without an additional time-based deletion schedule; removed by clearing app data. Account deletion alone does not clear this separate store.
- Deletion barrier containing the user identifier: at least two hours after successful server deletion, with cleanup running every six hours. Under normal operation it therefore disappears within about eight hours. Failed deletions are retried.
- Purchase ledger and account association: until account deletion unless further retention is justified. The purchase-token hash, product identifier and deletion/revocation markers remain to prevent further unauthorised credits. These verification records currently have no automatic expiry. Their continued necessity is reviewed on erasure requests; they are not treated as inherently anonymous.
- Support messages: until the request is resolved and for as long as required for specific follow-up questions, legal claims or statutory records. Google’s own account, payment and advertising data are also subject to Google’s retention rules.
Delete your account and data
Open the dedicated account deletion page
When signed in, you can select “Delete account” in settings. Confirmation requires signing in with Google again. The server removes the Firebase user account, cloud save and account links in the purchase register, and deletes request counters. The device used then removes the affected local account profile. The purchase verification records and temporary deletion barriers described under “Retention periods” remain initially. For authorised store review accounts, sign in again with the test credentials.
Without access to the app, you can request deletion by emailing anfrage@digital-e.org with the subject “JewelTap: delete account”. Include the Google email address you used or a game/user identifier known to you. We clarify account ownership where necessary without requesting your password. Guardians may also submit a request.
Deleting your JewelTap account does not delete your Google account, Google purchase records, local diagnostics or copies on other devices and in system backups. Clear app data on other devices if needed. Deletion does not automatically refund purchases; refunds use the applicable store procedures.
Your rights
Subject to the GDPR, you have rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18) and data portability (Article 20). You may withdraw consent at any time for the future. Contact our privacy address to exercise your rights; we limit any necessary identity checks to what is required.
Where processing relies on legitimate interests, you may object on grounds relating to your particular situation (Article 21 GDPR). You may object to direct marketing at any time without a specific reason, including related profiling.
You may complain to a data-protection authority, particularly where you live, work or believe an infringement occurred. Digital-e’s competent authority is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Germany. We do not make solely automated decisions producing legal or similarly significant effects under Article 22 GDPR. Game calculations and technical purchase checks serve gameplay and purchase fulfilment; Google’s advertising personalisation is described in the advertising section.
Changes to this policy
We update this policy when processing or legal requirements change. The published version carries a version number and date. Publishing a changed policy does not replace consent where new processing requires it. This policy is available in the eight app languages; statutory rights apply regardless of the language selected.