Pathfinder Memory needs no account, no email address and no password. You only pick a display name for the leaderboards. We never learn who you are.
The app shows ads through Google AdMob and is funded by them. Ads can be removed permanently with a one-time in-app purchase.
For personalised ads we ask first — through Google’s consent dialog and, on iOS, Apple’s tracking prompt. Decline and you still see ads, just not personalised ones. Everything else works unchanged.
We run no tracking of our own and use no third-party analytics service — no Firebase, no Google Analytics.
Pascal Dohmeier
Gustav-Müller-Straße 20A
10829 Berlin, Germany
Email: pathfindermemory.support@gmail.com
Phone: +49 160 95861111
No data protection officer has been appointed; the thresholds of Art. 37 GDPR and § 38 BDSG are not met. Reach me directly with any privacy matter using the details above.
Progress, statistics, streaks, a paused run, your settings (language, appearance, sound, haptics, reminder) and your list of blocked players. All of it is stored locally in the app’s settings. This data is never transmitted and disappears when you delete the app.
Keeping the block list local is deliberate: blocking is a personal “I don’t want to see this”, not a verdict on anyone — so it works offline and cannot hide a player from everybody else.
So that leaderboards, the friends list and moderation can work at all, the following is transmitted and stored:
| Data | Purpose | Legal basis |
|---|---|---|
| Random installation identifier (UUID), generated on first launch | Ties your results to your installation. No device name, no advertising ID, no hardware identifier — it is randomly generated and linked to nothing outside this app | Art. 6(1)(b) GDPR |
| Display name you choose | Shown in the public leaderboards | Art. 6(1)(b) GDPR |
| Results (date, levels cleared, streak) | Leaderboards and streak display | Art. 6(1)(b) GDPR |
| Friendships (identifiers only) | Friends leaderboard | Art. 6(1)(b) GDPR |
| Reports about display names | Moderating offensive names — the App Store requires reporting and filtering for public name lists | Art. 6(1)(f) GDPR |
| Product events (round started, level cleared or failed, tutorial finished) with your identifier | Solely to find out where the app is too hard or unclear | Art. 6(1)(f) GDPR |
| IP address, for the duration of the request | Technically unavoidable for any server access; processed to operate the service and prevent abuse, and not stored against your profile | Art. 6(1)(f) GDPR |
Processor: Supabase Pte. Ltd, 65 Chulia Street #38-02/03,
OCBC Centre, Singapore 049513. The database runs in region
eu-central-1 — Frankfurt am Main, Germany. A data
processing agreement under Art. 28 GDPR forms part of Supabase’s terms of service
and is therefore in place; it incorporates the EU Standard Contractual Clauses
(see section 9).
No third-party analytics. The product events sit on our own server and are shared with nobody.
Provider for the European Economic Area: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
To serve, measure and protect ads against fraud, Google processes among other things:
Google may also use this across apps to build profiles. That is exactly why we ask first.
Your consent can be withdrawn at any time and without giving reasons, through the privacy options in Google’s consent dialog. Apple’s tracking permission is changed under iOS Settings → Privacy & Security → Tracking. Withdrawal takes effect going forward; processing carried out beforehand remains lawful.
Turning ads off entirely: the one-time in-app purchase “Remove ads”. After that the ad SDK is no longer loaded and no advertising data is collected.
More information: Google’s Privacy Policy, “How Google uses information from sites or apps that use our services” and Google’s data transfer frameworks.
The “Remove ads” purchase is handled by Apple (Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland). We receive no payment details and no personal data about you — the app only asks Apple whether a purchase exists for this Apple Account. What Apple itself processes is described in Apple’s privacy policy.
The app requests only two permissions, each at the moment it is needed, and each one can be declined:
| Permission | What for | If you decline |
|---|---|---|
| Notifications | An optional daily reminder at 10:00 for the daily puzzle | Everything keeps working, just without the reminder. The reminder is scheduled locally on the device — nothing is sent to any server for it, not even to Apple |
| Tracking (Apple’s advertising-ID prompt) | Personalised ads | You still see ads, just not personalised ones. The advertising ID is then not accessed |
Camera, microphone, photos, contacts, location and health data are never requested and cannot be accessed by the app.
If you email the address above, we process your message and sender address in order to answer it (Art. 6(1)(f) GDPR, or (b) for contractual matters). Such messages are deleted once the matter is settled and no retention obligation applies. Mail is handled by Google (Gmail) as our email provider.
This site is static — no cookies, no login, no analytics, no ads, no embedded third-party fonts or scripts. It is hosted on GitHub Pages (GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA). For technical reasons GitHub logs a visitor’s IP address for security and operational purposes; we have no influence over this and no access to it. Legal basis for running the site: Art. 6(1)(f) GDPR (legitimate interest in a reachable information page, which § 5 DDG obliges us to provide anyway). Details in GitHub’s privacy statement.
| Recipient | Country | Safeguard |
|---|---|---|
| Google (advertising) | USA | European Commission adequacy decision for the EU-US Data Privacy Framework, in which Google participates, and additionally EU Standard Contractual Clauses under Art. 46(2)(c) GDPR |
| Supabase (database) | Singapore (contracting entity); storage in Frankfurt am Main, Germany | EU Standard Contractual Clauses under Art. 46(2)(c) GDPR, part of the data processing agreement |
| GitHub (hosting of this website) | USA | EU-US Data Privacy Framework and EU Standard Contractual Clauses |
| Apple (in-app purchase) | Ireland, EU | No third-country transfer by us |
We deliberately name both safeguards for the USA. The adequacy decision for the Data Privacy Framework is in force but is the subject of pending proceedings before the European courts; the Standard Contractual Clauses carry the transfer even if it were to fall away.
| Data | Kept for |
|---|---|
| Profile, display name, results, streaks, friendships | Until you delete your profile (section 13). Without deletion: for as long as the app is operated |
| Product events | 12 months at the most; on profile deletion the link to you is removed immediately |
| Reports about display names | Until the case is handled, at most 12 months |
| IP address at the server | Only for the duration of the request, or in short-lived operational logs |
| Data on your device | Until you delete the app |
| Advertising data at Google | According to Google’s own retention periods — see Google’s privacy policy |
You are not obliged to provide any data, and there is no legal or contractual requirement to do so. The game itself works entirely without a server connection. Providing nothing simply means doing without the leaderboards and the friends list — both of which, by their nature, require a result to reach our server. For advertising: without consent you see non-personalised ads, and without ads there is the “Remove ads” purchase.
Delete your profile — right in the app, without asking us: Settings → “Delete profile”. Your display name, all leaderboard entries, streaks and friendships are removed from the server and the name becomes available again. You continue playing as a new, anonymous player.
Beyond that you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21), as well as to withdraw consent you have given (Art. 7(3)).
One practical note: we know you only by the random installation identifier. For an access or erasure request we therefore need your display name — otherwise we cannot locate your profile, and we will not try to guess it from other traits.
You may also lodge a complaint with a supervisory authority at any time (Art. 77 GDPR). The competent authority is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin, Germany
Phone: +49 30 13889-0 · Email:
mailbox@datenschutz-berlin.de
The app is not directed at children and is not classified as a kids’ app in the App Store sense. It asks for no age and collects no data from which an age could be inferred. Display names are filtered automatically and can be reported by anyone; blocked players no longer appear in any leaderboard.
We update this policy when the processing changes — for instance because a service is added or dropped. The date above shows the current version. Material changes are announced in the app.