Wombatistan

Wombatistan · Legal

Privacy Policy

Last updated: October 2026

1. Controller

SynthScript Inh. Christoph Kretschmer
Hornisgrindestraße 9, 77855 Achern, Germany
Email: info@synthscript.de · Privacy: privacy@synthscript.de
Abuse reports: abuse@synthscript.de

2. What this is about

This policy describes which data the app "Wombatistan" (city-building game for iOS and Android, package ID de.synthscript.wombatistan) processes, for what purpose and for how long. The game is intended for people aged 13 and over.

If you are under 16, you may only give consent for ad videos (section 9a) and usage statistics (section 10) with the permission of your parents or other legal guardians (Art. 8 GDPR). Without this permission, please choose "No" and do not watch ad videos; the game still works fully without them.

3. Playing without signing in

On first launch, the app signs you in anonymously and assigns a random user ID (UID). No name, email address or phone number is required for this. Your game progress is stored under this UID (section 6).
Legal basis: Art. 6(1)(b) GDPR.

4. Sign-in (Firebase Authentication)

Sign-in and account management are handled by Firebase Authentication (Google Ireland Limited). In the process, Google processes technical data such as your IP address and the time of sign-in.

Only if you trigger it yourself in the settings do you link your account in order to restore your game progress on other devices:

Legal basis: Art. 6(1)(b) GDPR.

5. Name, profile and leaderboard

You can choose a player name or put one together from suggestions. Along with the name you receive a tag (#Tag) so that names remain unique.

Your public profile shows your name, epithets, a short text, points, your heroes with their equipment and your collection. You decide who may see it in the settings under "Privacy": all players, only signed-in players (default), only your alliance, or nobody.

The leaderboard shows the name, tag and points of signed-in players and is visible to all signed-in players.

Legal basis: Art. 6(1)(b) GDPR.

6. Game progress (Cloud Firestore)

Your game progress is stored in Cloud Firestore (Google): buildings, resources, heroes and the hero names you have given them, research, orders, in-game settings and timestamps. In addition, a random device identifier, so that the same game progress does not run on two devices at the same time, and review flags in case a save has been changed implausibly. A copy of your game progress is also kept on your device.
Database location: EU (Frankfurt, europe-west3).
Legal basis: Art. 6(1)(b) GDPR.

7. Friends, alliances and chat

Legal basis: Art. 6(1)(b) GDPR.

8. Text screening, reports and sanctions

Automated screening. Freely chosen names (player, alliance, hero names you assign yourself) and the alliance notice board are automatically checked for offensive or prohibited content before they are saved. For this, we send only the text, without a user ID or any other identifier, to OpenRouter (OpenRouter, Inc., USA). The text first goes to "Jev", a decision model from TypeSafe that is accessed via OpenRouter. Only if Jev does not respond does it go to one of the free language models from a third-party provider via OpenRouter. We store the result for up to 30 days under a hash of the text so that the same text does not have to be checked again. Chat messages are not sent to any model; they are only checked against fixed rules (e.g. no contact details, no links).

Which model responds varies. OpenRouter is configured so that the text is only passed on to providers that neither store inputs nor use them for training. In addition, only the text is sent out, never an identifier. Do not choose a name or notice that contains information about yourself or others.

Reports. You can report names, notices and individual chat messages. We then store a copy of the reported text, its author (UID) and who reported it. We delete the list of reporters as soon as a decision on the report has been made. Reports can only be seen by administrators designated by us.

Sanctions. In the event of violations, we may mute an account for a limited time, block chat for a limited time, or revoke a name. The person affected receives a notification in the app stating the reason and duration.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in safe interaction and in fulfilling the app stores' requirements regarding user-generated content) and Art. 6(1)(b) GDPR.

Once a decision on a report has been made, we delete the copy of the text together with its author after 6 months — even if the account has already been deleted. As long as no decision has been made on a report, it remains stored.

9. In-app purchases (RevenueCat)

Purchases are processed via the App Store or Google Play and managed with RevenueCat (RevenueCat, Inc., USA). In the process, RevenueCat processes your user ID (UID), the purchased product and the transaction identifier in order to verify and credit purchases. We do not receive payment data such as card numbers; these are processed exclusively by Apple or Google.
Legal basis: Art. 6(1)(b) GDPR.

9a. Ad videos (Google AdMob)

In the Bazaar you can voluntarily watch a short ad video and receive Favors in return (no more than a few videos per day). The app shows no other advertising. The videos are delivered by Google AdMob (Google Ireland Limited / Google LLC).

If you never watch a video, AdMob is not loaded and you are not asked anything. Without your consent, the app shows no videos — not even the "limited ads" that Google would otherwise deliver without consent.
Legal basis: Art. 6(1)(a) GDPR, Section 25(1) TDDDG (consent) for storing and reading information on the device; Art. 6(1)(b) GDPR for crediting the reward.

10. Usage statistics (Google Analytics for Firebase)

We record which game features are used (e.g. building constructed, order completed, purchase in the in-game shop) in order to improve and balance the game. For this, Google Analytics for Firebase uses an app instance identifier that is stored on your device. No user ID or name is transmitted in the process. The data is not used for advertising purposes and is not linked with data from other apps.

The statistics run only if you agree. The app asks you on first launch; Yes and No are presented as equal options. If you are under 16, you may only agree with your parents' permission (section 2). You can change your choice at any time in the settings under "Privacy". If you withdraw it, we switch off collection and delete the identifier on your device.
Legal basis: Art. 6(1)(a) GDPR, Section 25(1) TDDDG (consent).
Google stores the usage data for 14 months and deletes it afterwards.

11. Crash reports (Firebase Crashlytics)

If the app crashes or an error occurs, it sends a report to Firebase Crashlytics (Google): error message and code location, device type, operating system, app and save version, current term (season) and game content version, your user ID (UID) and the random device identifier. We need the UID to be able to attribute errors to a game save and fix them. Crashlytics stores reports for 90 days.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an error-free app). Storing the identifier required for this on your device is based on Section 25(2) no. 2 TDDDG: it is strictly necessary for us to keep the game you are using functional and to fix errors affecting your game progress. Crashlytics is not used for advertising or analytics purposes and is not linked with other data. You can object to this processing at any time (Art. 21 GDPR), e.g. by email to privacy@synthscript.de.

11a. Protection against abuse (Firebase App Check)

When the app calls our servers, it proves that it is a genuine, unmodified installation on a real device. For this, Firebase App Check (Google) uses the Play Integrity API (Google) on Android and DeviceCheck (Apple) on iOS. Technical information about the device and the app installation is processed in the process. We ourselves only receive the result of the check, no device data.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting the game and our servers against abuse and manipulated apps). Access to the information on your device required for this is based on Section 25(2) no. 2 TDDDG. You can object to this processing at any time (Art. 21 GDPR).

12. Notifications

Reminders (e.g. "Production ready to collect") are scheduled by the app on your device; no data is sent to us for this. The app asks for permission beforehand, which you can revoke at any time in your device settings.

For events that your device cannot know about by itself, our server sends notifications via Firebase Cloud Messaging (Google): a reward in your inbox, being accepted into an alliance, a new message in the friends chat (with the sender's name, without the message text) and news in the alliance chat. For this, we store one Firebase Cloud Messaging device token per device and the app language under your account.

If you turn off notifications in the settings, we delete this device's token. If you delete your account, we delete all tokens.
Legal basis: Art. 6(1)(b) GDPR; for the token on your device, Section 25(2) no. 2 TDDDG.

13. Recipients and processors

We do not sell data. Advertising exists only in the form of voluntary videos (section 9a).

14. Transfers to third countries

The database is located in the EU (Frankfurt). Our server functions run in Google data centers in the USA (us-central1); game progress, chat messages and names are processed there but not stored permanently. Sign-in, Analytics, Crashlytics, Cloud Messaging and AdMob are global Google services. RevenueCat and OpenRouter process data in the USA. Transfers to Google are based on the EU-U.S. Data Privacy Framework (Google LLC is certified). RevenueCat and OpenRouter are not certified; transfers to them are based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), which form part of their data processing agreements.

15. Retention and deletion

DataRetention period
Game progress, profile, name, friends, allianceuntil you delete your account
Chat messages30 days, even after the account is deleted
Sign-in code (email)10 minutes
Sign-in link usage record24 hours
Result of text screening (without identifier)30 days
Crash reports90 days
Usage statistics (only with consent)14 months
Counter of ad videos watched (day, number)until you delete your account
Invite code, who invited you, counter of rewarded invitationsuntil you delete your account
Device token for notificationsuntil you turn off notifications or delete your account
Reportsuntil a decision is made, then 6 months

Delete account: In the app under Settings → Account → "Delete account". This immediately and permanently deletes: game progress, profile, name and tag, leaderboard entry, friendships and requests, your alliance membership (if you are the leader, leadership passes to another member; if you are the last member, the alliance is dissolved), your notifications and your sign-in account. Your invite code and your invitation status are deleted along with it. For "Sign in with Apple", we additionally revoke the link with Apple.

Not deleted immediately:

If you can no longer open the app, write to privacy@synthscript.de stating your player name and tag; we will then delete the account for you.

16. Permissions

17. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21 GDPR), in particular to processing based on legitimate interest. You can withdraw any consent you have given at any time with effect for the future (Art. 7(3) GDPR).
Contact: privacy@synthscript.de

18. Right to lodge a complaint

You can lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg).

19. Changes

If what the app processes changes, we will update this policy. We will announce material changes in the app.