← Back

Elementex · Legal

Privacy Policy

Last updated: 1 June 2026

Elementex (“the game”) is a mobile tower-defence game operated by Tassilo Posegga, an individual developer based in Germany. Full contact and legal-notice details are in the Impressum. This policy explains what data the game collects, why, how long it is kept, and the rights you have over it under the EU General Data Protection Regulation (GDPR).

For any privacy question or to exercise a right described below, email tassilo@posegga.eu.

1. The short version

  • We do not sell or share your personal data for advertising.
  • No loot boxes, no paid randomness, no hidden pricing.
  • By default you play under an anonymous ID — no name, email, or sign-up required.
  • We collect only what is needed to run your game, sync your gems and runes, show the global leaderboard, and keep the game fair.
  • You can request a copy of your data or its deletion at any time; deletion is completed within 30 days.

2. Who is responsible (controller)

The data controller is Tassilo Posegga, Dürrbergstr. 16, 82335 Berg, Germany — see the Impressum. Contact: tassilo@posegga.eu.

3. What we collect, why, and the legal basis

3.1 Anonymous game session (default — no sign-in)

The first time you launch the game it creates an anonymous account (a random identifier). We process:

  • Anonymous player ID — to persist your gems, runes, settings, and personal best across launches. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Gameplay data (wave reached, runs completed, runes kept, gems earned/spent, leaderboard score and the display name you choose) — to run the leaderboard, balance the game, and detect cheating/abuse. Legal basis: legitimate interests (Art. 6(1)(f)) in operating a fair, working game.
  • Device locale & OS version — to localise the UI and diagnose issues. Legal basis: legitimate interests (Art. 6(1)(f)).
  • In-app purchase receipts — to validate gem purchases server-side and credit your account. Legal basis: performance of a contract (Art. 6(1)(b)).
  • Crash diagnostics (via Google Firebase Crashlytics) — crash stack traces plus basic device model and OS version, so we can fix what breaks. No game content or identity is attached. Legal basis: legitimate interests (Art. 6(1)(f)) in a stable game.
  • Usage analytics (via Google Firebase Analytics) — anonymous, aggregated events about how the game is used (e.g. which screens are opened, runs started). This is optional: you can turn it off at any time under Settings → Data & privacy → Share usage analytics, which stops collection on your device. Legal basis: your consent (Art. 6(1)(a)), withdrawable any time.

The anonymous ID is not linked to your real identity unless you choose to link a platform account (see 3.2).

3.2 Optional linked account

If you choose to link an account (so your progress survives a phone swap), we receive a sign-in token from your platform:

  • Google Play Games (Android) — your Play Games player ID and display name. We do not request or receive your Google account email.
  • Sign in with Apple (iOS) — an Apple identifier (and, if you allow it, a private relay email). We never receive your real Apple ID email.

Linking is entirely optional — you can keep playing anonymously forever. Legal basis: your consent (Art. 6(1)(a)), withdrawable by unlinking or deleting your account.

3.3 What we do not collect

  • Real name, postal address, or phone number.
  • Contacts, calendar, photos, microphone, camera, or precise location.
  • Advertising identifiers (no ad SDK is active in the game today). If rewarded ads are ever enabled, this policy will be updated first and you will be asked for any consent the platform requires.

4. Where your data is stored

Player accounts, the gem wallet, rune inventory, and leaderboard data are stored with Supabase (managed PostgreSQL and edge functions) in the European Union (West EU, Ireland). Purchase validation is handled by Google Play Billing (Android) and the App Store (iOS), governed by Google’s and Apple’s own privacy terms.

Crash diagnostics and (if you opt in) usage analytics are processed by Google (Firebase Crashlytics and Firebase Analytics) on Google’s global infrastructure, which includes servers outside the EU/EEA, such as the United States. These transfers rely on the European Commission’s Standard Contractual Clauses and the EU–US Data Privacy Framework. Opting out of usage analytics (Settings → Data & privacy) stops that collection entirely.

5. Service providers (processors)

ProviderPurposeData involved
Supabase (EU) Database, anonymous auth, server-side economy logic Anonymous ID, gameplay data, receipts
Google Firebase Remote Config Remotely enabling/disabling game features A random installation ID and IP address (technical only)
Google Firebase Crashlytics Crash reporting & stability Crash stack traces, device model, OS version
Google Firebase Analytics (optional) Aggregated usage analytics — off when you opt out Anonymous in-app events, app instance ID
Google Play Billing Processing Android purchases Purchase token, product ID
Google Play Games (optional) Cross-device account sync (Android) Play Games player ID, display name
Apple App Store / Sign in with Apple (optional) iOS purchases & account sync Transaction receipt, Apple identifier

We do not use attribution or advertising SDKs. (Rewarded ads are planned for a future update; this policy will be updated and any platform-required consent requested before they are enabled.) If our use of processors changes, this policy will be updated and you will see an in-app notice.

6. How long we keep it

DataRetention
Player record (anonymous or linked)Until you request deletion
Gameplay & leaderboard dataUp to 24 months
Purchase receiptsAs required by tax/accounting law (up to 10 years), then deleted

When you request deletion, personal data is purged from production within 30 days; receipts are kept only as long as the law requires and are de-identified.

7. Your rights (GDPR)

You have the right to:

  • Access a copy of your data.
  • Rectify inaccurate data.
  • Erase your data (“right to be forgotten”).
  • Restrict or object to processing based on legitimate interests.
  • Data portability — receive your data in a machine-readable format.
  • Withdraw consent at any time (e.g. by unlinking an account).
  • Complain to a supervisory authority — for Germany, the data-protection authority of your federal state (for Bavaria, the BayLDA).

To exercise any right, email tassilo@posegga.eu. We respond within 30 days, free of charge.

8. Children

Elementex is not directed to children under 13, and the Terms require players to be at least 13. We do not knowingly collect data from children under 13. Where a higher age of digital consent applies (16 in Germany for consent-based processing), the optional account-linking feature should only be used with a parent’s or guardian’s consent. If you believe a child has provided us data, contact tassilo@posegga.eu and we will delete it.

9. Security

We use TLS in transit, encrypted-at-rest databases, server-side authority for every economy operation (gem balance, purchase validation), and short-lived authentication tokens. No system is perfectly secure; if a breach affects your personal data we will notify the competent authority within 72 hours as the GDPR requires, and you where legally required.

10. Changes

We may update this policy. The “Last updated” date above shows the most recent change; material changes will be surfaced via an in-app notice on the next launch.

11. Contact

Tassilo Posegga · tassilo@posegga.eu · Impressum · Terms of Service

© 2026 Tassilo Posegga · posegga.eu · Impressum · Datenschutz