Privacy policy
This policy explains what personal data we process when you visit this website and when you play Scaleborn on iPhone, iPad or Android, why we do it, and what rights you have. The German version is equally valid.
In short:
- No tracking on the website. It sets no cookies, has no analytics and loads nothing from other companies. The app contains no analytics SDKs.
- Ads, personalised only if you say yes. The free game shows ads from Google AdMob. Before any ad, the app asks whether Google may personalise them, and on iPhone and iPad whether it may track you. You can say no and still play.
- The game needs a server. Your progress, gold, eggs and dragons are kept on our server, so the app creates an anonymous guest account when you first start it.
- Leaderboards are public. Your display name and scores can be seen by anyone.
- You stay in control. In the game, under Settings → Account, you can download all your data and delete your account at any time.
1. Who is responsible
The controller under the General Data Protection Regulation (GDPR) is:
DeViLink Software GmbH
Adolf-Kolping-Straße 33
88433 Schemmerhofen, Germany
Email: support@devilink.ai
Phone: +49 175 2688305
For any privacy question or request, write to support@devilink.ai.
2. This website
Server logs
When you open this website, your browser sends technical data to our web server. It is stored briefly in the server's logs:
- IP address, date and time of the request,
- the page requested, the HTTP status and the amount of data transferred,
- the referring page, browser type and operating system (user agent).
We need this data to deliver the website and to keep it secure, for example to detect and fend off attacks. The legal basis is our legitimate interest in a secure, working website (Art. 6(1)(f) GDPR). The logs are deleted after 30 days.
No cookies, no tracking, no third parties
This website sets no cookies and uses no comparable technologies. It contains no analytics or tracking tools, no social media plugins and no embedded content from other companies. Fonts and images are served from our own server, so your browser does not contact third parties. The store buttons are plain links: Apple or Google only receive data from you if you click one of them and go to their store.
3. The game
3.1 Guest account and device identifier
The game's economy is managed on our server, meaning your gold, eggs, dragons and progress. That's what stops cheating and lets you keep your progress. So when you first start the game, the app automatically creates a guest account without asking for your name or email address. To recognise your device again, the app sends us an identifier:
- iPhone/iPad: the vendor identifier Apple provides to apps from the same developer (identifierForVendor), or a random number if it isn't available,
- Android: a random number that the app creates once when it is installed. It is not a hardware or advertising identifier.
We store that identifier with a random account ID and a default display name.
Legal basis: performance of the contract on the use of the game (Art. 6(1)(b) GDPR).
3.2 Account with email, Apple or Google
If you create an account, we process:
- Email sign-in: your email address, a password stored only as a secure hash (Argon2), and whether and when you confirmed your address,
- Sign in with Apple / Google: a unique user ID that Apple or Google gives us for this game, and, with Google or if you share it with Apple, your name, which we use as your initial display name. We do not receive or store your Apple or Google password, and we do not store the email address of these accounts,
- your display name, which you choose and which is shown publicly (see 3.6).
For Apple or Google sign-in, the app passes a sign-in token to our server, which checks it with Apple or Google. Their processing is governed by their own privacy policies.
Legal basis: Art. 6(1)(b) GDPR.
3.3 Login sessions and security
To keep you signed in and protect your account, we store the following for each login session (each device on which you are signed in):
- the time of creation, expiry and revocation,
- the IP address and user agent (app and system version) from which the session was started.
Sessions run for up to 30 days and are renewed while you play. We delete IP address and user agent at the latest 7 days after a session has ended, expired or been renewed, and the session record itself at the latest 7 days after its expiry. We keep a small number of old, renewed session records without IP address for a short time to detect stolen login tokens.
To prevent attacks on accounts (such as password guessing) and to prevent overload, our server keeps short-lived counters linked to your IP address or email address. These are deleted automatically after 1 minute (rate limits) and at the latest after 24 hours (failed login attempts, protection against duplicate transactions).
Legal basis: our legitimate interest in the security of our service and your account (Art. 6(1)(f) GDPR).
3.4 Emails
If you have an account with an email address, we send you emails that are necessary for it: confirming your address, resetting your password, confirming a change of email address, and security notices when your password or email address changes. We do not send newsletters or marketing emails.
The links in these emails are valid for 1 to 24 hours. The tokens behind them are deleted as soon as they are used or expire. When you change your email address, the new address is stored with that token until you confirm it.
We send emails through Brevo (Sendinblue SAS, France) as our processor.
Legal basis: Art. 6(1)(b) GDPR.
3.5 Game data and cloud save
To run the game, we store on our server what you do in it and what you own:
- your progress and cloud save, unlocked spells and upgrades, achievements, quests and daily streak,
- your gold, eggs and other virtual items with a history of changes (where they came from and what you spent them on), and the dragons you have hatched,
- the results of your flights (runs), scores and statistics.
The history of changes and the run results help us find errors and cheating.
Legal basis: Art. 6(1)(b) GDPR. For cheat detection, also Art. 6(1)(f) GDPR (our and all players' interest in a fair game).
3.6 Leaderboards (public)
When you take part in a mode with a leaderboard, your display name, your account ID (a random number), your rank and score and, for dragon rankings, your dragon's colour, level and similar game data are shown in the game. They can also be retrieved from our server without signing in. That means anyone can see them, not just other players. At the end of a season we archive its leaderboard with your rank.
Choose a display name that doesn't reveal your real name if you don't want to be identifiable.
Legal basis: Art. 6(1)(b) GDPR, because leaderboards are part of the game.
3.7 Reports of display names
Players can report display names they find inappropriate. We store the reported account, the reporting account, the reason given, and the time. Reports are deleted 90 days after we have dealt with them. If the reporting account is deleted, the report remains without it.
Legal basis: Art. 6(1)(f) GDPR (a respectful game for everyone).
3.8 Support requests
If you write to us, we process your email address, your message and any details you send us (such as screenshots) to answer you. We delete the correspondence when your request has been dealt with, unless we have to keep it for legal reasons.
Legal basis: Art. 6(1)(b) GDPR if your request concerns the game or your account. Otherwise Art. 6(1)(f) GDPR.
3.9 Error and performance monitoring
To detect errors and slow responses on our server, we use New Relic (New Relic, Inc., USA) as our processor. Our server sends New Relic the requests' timing data, error messages and log lines. These contain the request method and address (with codes and tokens masked), status code and duration, but no IP addresses, no request headers and no device information. The data is stored in New Relic's EU data centre and deleted after 30 days.
Legal basis: Art. 6(1)(f) GDPR (a reliable and secure service).
3.10 On your device
The app stores your login tokens on your device (on iPhone and iPad in the Keychain, on Android in the app's private storage), along with your settings and a local copy of your game state. Besides internet access, the app only asks for what advertising needs: on Android access to the advertising ID, on iPhone and iPad the tracking permission (see 3.12), which you can refuse. It does not access your contacts, photos, camera, microphone or precise location.
3.11 In-app purchases
You can buy gold, eggs and other virtual items in the game. Payment is handled entirely by Apple (App Store) or Google (Google Play) under their own responsibility and privacy policies. We never see your payment details.
To credit your purchase to the right account and to check that it is genuine, we use RevenueCat (RevenueCat, Inc., USA) as our processor. The app tells RevenueCat your account ID (the random number described in 3.1), and RevenueCat receives the store's purchase receipt together with technical data needed for this: the product, price and currency, the time of purchase, the store country, transaction IDs, the app and system version, and the IP address of the request. RevenueCat then informs our server about the purchase, its renewal or a refund. We store the platform, product, store transaction ID and the type of event in your account.
Legal basis: performance of the purchase contract (Art. 6(1)(b) GDPR). We keep purchase records until you delete your account.
3.12 Advertising (Google AdMob)
The game is free and is financed by advertising. Ads are delivered by Google AdMob, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google decides itself how it uses the data for ad delivery and is responsible for this as a separate controller (Google's privacy policy, how Google uses data from apps).
What Google receives when the app requests or shows an ad: your IP address (from which Google derives an approximate location), device information (model, operating system, language), information about the app, the ad shown and your interactions with it (views, clicks), and, depending on your choices, the advertising ID of your device (on iPhone/iPad the IDFA, on Android the Advertising ID).
Your choices:
- Consent dialog. Before any ad is shown, the app displays Google's consent dialog (Google User Messaging Platform, based on the IAB Transparency & Consent Framework). There you decide whether Google and its ad partners may store and read information on your device and use your data for personalised advertising, which means ads based on your interests. You can change your decision at any time under Settings in the game.
- App tracking (iPhone/iPad). iOS additionally asks whether the app may track you across apps and websites. Only if you allow this does Google receive the IDFA.
- If you say no, you will see non-personalised ads, which are based only on the context (for example the game itself) and your approximate location. If you also refuse storing and reading information on your device, Google only shows limited ads that work without it. Google still uses the data needed to deliver an ad, to limit how often you see it, to prevent fraud and for aggregated reporting.
- On Android you can also reset or delete your advertising ID in the system settings (Settings → Privacy → Ads).
Rewarded ads. Some rewards in the game are optional: you can choose to watch an ad to receive gold or another bonus. When you have watched the ad in full, Google sends our server a signed confirmation with a transaction ID, the reward and your account ID, so that we can credit the reward exactly once. We store these confirmations in your account.
Legal basis: For storing and reading information on your device and for personalised advertising: your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG). You can withdraw it at any time with effect for the future. For showing non-personalised and limited ads to finance the free game: our legitimate interest (Art. 6(1)(f) GDPR). For crediting rewarded ads: Art. 6(1)(b) GDPR.
3.13 Age confirmation and your choices on record
Before ads are shown, the app asks you to confirm that you are 16 or older. We do not ask for or store your date of birth. We only store when you confirmed it. Together with it, we store your region, the consent string from Google's dialog, your app-tracking choice on iPhone/iPad, and whether you get non-personalised ads. That way your choices apply on every device you sign in on, and we can prove the consent you gave.
Legal basis: Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR (proof of consent) and Art. 6(1)(f) GDPR (protection of minors). We keep this record until you delete your account; when you change a choice, we replace the old one.
4. Recipients and processors
We do not sell your data. We share it only with service providers who process it on our behalf and under our instructions (Art. 28 GDPR), or where this policy says so:
| Recipient | Purpose | Location |
|---|---|---|
| OVH SAS | Hosting of this website and the game server, database | EU (Germany: Frankfurt; France) |
| Brevo (Sendinblue SAS) | Sending account emails | EU (France) |
| New Relic, Inc. | Error and performance monitoring | EU data centre; US company |
| RevenueCat, Inc. | Checking and recording in-app purchases | USA |
| Apple, Google | Checking your sign-in, only if you use Sign in with Apple or Google | see their privacy policies |
We have concluded data processing agreements with OVH, Brevo, New Relic and RevenueCat.
Separate controllers. When you download the game or buy something in it, Apple (App Store) or Google (Google Play) process your data under their own responsibility and privacy policies. The same applies to Google for ad delivery through AdMob (section 3.12).
5. Transfers outside the EU
We store and process your data in the EU, in OVH data centres in Frankfurt and France. Should we add locations outside the EU, we will update this policy beforehand. Some service providers are based in the USA or belong to US groups:
- RevenueCat processes purchase data in the USA,
- New Relic stores our data in its EU data centre, but access from the USA can't be ruled out,
- Google may process advertising data in the USA.
These transfers are based on the EU–US Data Privacy Framework, where the recipient is certified under it (adequacy decision of the European Commission, Art. 45 GDPR), and otherwise on the EU standard contractual clauses (Art. 46(2)(c) GDPR).
6. How long we keep data
| Data | Deleted |
|---|---|
| Website server logs | after 30 days |
| Account, display name, email address, game data, leaderboard entries, purchase records, rewarded-ad confirmations, consent record | when you delete your account |
| IP address and user agent of a login session | at the latest 7 days after the session ended, expired or was renewed |
| Login session records | at the latest 7 days after expiry |
| Email links (confirmation, password reset, email change) | when used or expired (1–24 hours) |
| Security counters (IP/email) | after 1 minute to at most 24 hours |
| Name reports | 90 days after they are dealt with |
| Monitoring data at New Relic | after 30 days |
| Support emails | when your request has been dealt with, unless we must keep them by law |
| Database backups | overwritten after 30 days |
We do not delete accounts for inactivity. A guest account you no longer use stays until you delete it in the app or ask us to delete it.
7. Minimum age
Scaleborn is intended for players aged 16 and over and is not directed at children. If we learn that a child under 16 has given us personal data, we delete it. If you believe this is the case, please write to us.
8. Your rights
You have the right to:
- access the data we hold about you and receive a copy (Art. 15 GDPR),
- have incorrect data corrected (Art. 16 GDPR),
- have your data deleted (Art. 17 GDPR),
- have processing restricted (Art. 18 GDPR),
- receive your data in a machine-readable format, data portability (Art. 20 GDPR),
- object to processing (Art. 21 GDPR, see below),
- withdraw consent you have given at any time, with effect for the future (Art. 7(3) GDPR).
You can exercise the most important rights directly in the game, under Settings → Account (as a guest, under Your data):
- Export my data gives you a file (JSON) with all the data about your account stored on our server.
- Delete account permanently deletes your account and all its data. See Deleting your account.
For anything else, write to support@devilink.ai.
Right to object: Where we process your data based on our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation. We will then stop processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims.
9. Right to lodge a complaint
You can complain to a data protection supervisory authority, in particular in the EU country where you live or work. The authority responsible for us is:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI)
Lautenschlagerstraße 20, 70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de
10. Are you required to provide data?
You don't have to provide any data by law. Without the guest account and the related data (section 3.1), however, the game's online features, such as saving progress, gold, eggs and leaderboards, can't work. An email address is only needed if you want to create an account with email sign-in.
We do not use automated decision-making within the meaning of Art. 22 GDPR. If you consent to personalised advertising, Google creates interest profiles for this purpose (section 3.12). We ourselves do not create profiles.
11. Changes to this policy
We will update this policy when the game or the law changes, in particular before we add new services. The current version is always on this page, and the date at the top shows when it last changed.