Privacy Policy for the app "MOLE: Infiltration", the web app (mole-infiltration.app) and the website (mole-infiltration.com)
Last updated: 14 July 2026
Please note: The German version of this Privacy Policy is the legally binding one. This English translation is provided for information purposes only.
1. Controller
Sebastian Daubc/o pro Service GmbHMaximilianstr. 3397980 Bad Mergentheim, GermanyEmail: sd.creations.shop@gmail.com2. Data protection officer
Given the nature and scope of the processing, there is no legal obligation to appoint a data protection officer. For any data protection matter, you can reach the controller at the email address above.
3. Principles
We process personal data only to the extent necessary to provide the App. The legal bases are in particular Art. 6(1)(b) GDPR (performance of the user agreement), Art. 6(1)(f) GDPR (legitimate interest in a functioning and safe game), and Art. 6(1)(c) GDPR (compliance with legal obligations, such as those arising from the Digital Services Act).
4. Hosting and storage location
The App uses Google Firebase (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for authentication, database, file storage and server-side functions. The database and the server-side functions are located in "europe-west3" (Frankfurt am Main, Germany). A data processing agreement is in place with Google on the basis of the Firebase Data Processing Terms. Where data is transferred to countries outside the EU/EEA in individual cases, this takes place on the basis of the EU Standard Contractual Clauses.
5. Sign-in
5.1 Google sign-in: We receive a unique user identifier from Google and, to the extent you have released it, your name and profile picture.
5.2 Sign in with Apple: We receive a unique user identifier from Apple. Apple transmits your name only on your very first sign-in. Apple lets you choose whether your email address is shared or replaced by an anonymised relay address.
5.3 Guest access: Only a randomly generated identifier is created, which does not allow any conclusions to be drawn about your identity.
The legal basis in each case is Art. 6(1)(b) GDPR.
6. Data processed within the App
- Agent name (freely chosen; a pseudonym is permitted)
- Automatically generated agent identifier
- Profile photo (optional, uploaded voluntarily)
- Game statistics (wins, losses, tasks solved, eliminations)
- Friends list (identifier, display name and, where applicable, profile photo of the people you have connected with)
- Saved room configurations
- Data of the current game round (role, status, task progress); visible only during the round and only to fellow players
7. Review of profile photos
Profile photos you upload are automatically checked for prohibited content (in particular pornographic or violent depictions) using the Google Cloud Vision API before they are published. The check is carried out exclusively for this purpose; Google does not use the images for its own purposes. Only the result of the check is stored, never the rejected image itself. The legal basis is our legitimate interest in a safe platform, in particular in protecting minors (Art. 6(1)(f) GDPR).
8. Reports and moderation
If you report content or conduct of other users, we store your identifier, the identifier of the reported person, the category and your optional description. This data is used solely to process the report. Your identity is not disclosed to the reported person. The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 16 of Regulation (EU) 2022/2065, and Art. 6(1)(f) GDPR.
9. Device permissions
9.1 Camera: used only when you actively take a profile photo or scan a QR code. No processing takes place without your action.
9.2 NFC: used to read physical keycards during the game. The identifier read is used only within the current round.
9.3 Vibration: a purely local device function; no data is transmitted.
10. Analytics, tracking and advertising
The App does not include any third-party analytics, tracking or advertising services. There is no tracking for marketing purposes and no data is passed to third parties for advertising. Should this change in the future, this Privacy Policy will be updated and, where required, your consent obtained.
11. Notes on the website and the web app
The website (mole-infiltration.com) and the web app (mole-infiltration.app) are provided via Google Firebase Hosting. When they are accessed, the hosting service processes technical access data (including IP address, time of access, page accessed, browser type) in server log files. This is necessary in order to deliver the pages and to ensure the security of our systems (Art. 6(1)(f) GDPR).
The website sets no cookies of its own and includes no analytics or advertising services. The web app stores only strictly necessary data locally on your device (e.g. your sign-in and language preference) so that you remain signed in on your next visit; no consent is required for this.
12. Minors
The App is directed at persons aged 12 and over. For users between the ages of 12 and 15, we require the consent of a parent or legal guardian (Art. 8 GDPR). Parents or guardians who become aware of a registration made without their consent may contact us at any time at the email address above; we will then delete the data concerned without delay.
13. Retention periods
13.1 Account and profile data is stored for as long as your account exists.
13.2 After you delete your account, your personal data is deleted unless statutory retention obligations apply.
13.3 Data from individual game rounds is deleted after the round ends or transferred into aggregated statistics in anonymised form.
13.4 Data relating to reports and moderation decisions is retained for as long as necessary to process them and to document them towards supervisory authorities.
14. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and objection to processing (Art. 21 GDPR). You may withdraw any consent you have given at any time with effect for the future. To do so, contact sd.creations.shop@gmail.com.
You can also delete your account yourself at any time in the App settings.
You have the right to lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Germany.
15. Data security
Transmission between the App and the server is encrypted (TLS). Access to stored data is restricted to authorised persons by server-side security rules.
16. Changes to this Privacy Policy
We will amend this Policy if our processing changes. The current version is always available on this page.