Privacy Policy
This is a translation for convenience. The legally binding version is the German one: Datenschutzerklärung (deutsch)
Privacy Policy — Scrap Wars
Last updated: 1 October 2026
This privacy policy covers the website scrapwars.allbitsequal.com and the Android application
Scrap Wars (package name com.allbitsequal.scrapwars), including its servers at
api.beta.scrapwars.allbitsequal.com.
This is a translation for convenience. The controller is established in Germany and the German-language version of this policy is the legally binding one. In case of any discrepancy, the German version prevails.
Scrap Wars is in a closed testing phase (closed alpha). The app is distributed only to a small, personally invited group of testers through Google Play's closed testing track. Section 6 describes processing that applies only to that phase.
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
Konrad Abe c/o GAM
Pappelallee 64
10437 Berlin
Germany
Email: info@allbitsequal.com
No data protection officer has been appointed; the conditions of § 38 BDSG (German Federal Data Protection Act) are not met.
2. Principles
Scrap Wars is built to generate as little personal data as possible:
- There is no registration. No name, no email address, no password, no social sign-in.
- No analytics, tracking or advertising SDK is embedded. The app contains no advertising, no usage tracking, no advertising identifiers and no third-party crash-reporting SDK.
- No profiling and no automated decision-making within the meaning of Art. 22 GDPR takes place.
- There are no in-app purchases and no payment processing during the testing phase.
- There is no chat and no user-generated content. Players see each other's game objects only — never freely entered text.
- Data is never sold and never shared for advertising purposes.
3. Your rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
An informal message to info@allbitsequal.com is sufficient.
How to identify yourself as a data subject. Because Scrap Wars works without registration, your game data is stored solely under a randomly generated identifier (your player ID). I cannot locate your data from your name or email address. Under Art. 11(2) GDPR I can therefore only fulfil your rights under Art. 15–20 GDPR if you provide additional information enabling identification. Please quote your player ID, which you can find in the app on the title screen, bottom right (tap to copy).
Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority for me is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin, Germany
Website: https://www.datenschutz-berlin.de
You may also contact the authority where you habitually reside or work.
4. Using the website
4.1 Accessing the website
When you access the website, your browser necessarily transmits information to the server that delivers the page — in particular your IP address, the date and time of the request, the page or file requested, and your browser type and operating system. The page cannot be delivered without it.
Purpose: delivering the website and ensuring its technical security. Legal basis: Art. 6(1)(f) GDPR — my legitimate interest in the secure and reliable operation of the website. Logging: I keep no visitor or access logs of my own for this static website. Render provides no runtime logs for static sites in the customer dashboard. Technical request data is processed by Render and its delivery and security infrastructure to deliver and protect the website. I do not combine this data with other data sources.
4.2 Hosting
The website is hosted by the following processor:
Render Services, Inc.
525 Brannan St, Suite 300
San Francisco, CA 94107
USA
A data processing agreement under Art. 28 GDPR is in place. The website is delivered through a worldwide content delivery network, so your request may be answered by servers outside the European Union. For the legal basis of this transfer, see section 7.
Render's privacy notice additionally applies to technical usage and security data that Render processes as an independent controller: https://render.com/privacy.
4.3 Encryption
The website is served exclusively over a TLS-encrypted connection (HTTPS).
4.4 Cookies, consent and embedded content
The website sets no cookies, uses no analytics or audience measurement, and embeds no third-party content. Fonts, images, scripts and stylesheets are all delivered by the website's hosting provider (section 4.2). The fonts are part of the website itself; no request is made to Google or any other font service, neither when the website is built nor when you visit it. No access to information stored on your device within the meaning of § 25 TDDDG takes place, so no consent is required and no consent banner is displayed.
4.5 Contacting me by email
If you email me — for example at info@allbitsequal.com or another address named on this website — I process your email address, your name if given, and the content of your message.
Purpose: handling and answering your enquiry. Legal basis: Art. 6(1)(b) GDPR where your enquiry concerns a contract or steps towards one (for example, responding to a call for artists), otherwise Art. 6(1)(f) GDPR — my legitimate interest in answering enquiries. Retention: until your enquiry has been fully dealt with, then deleted unless a statutory retention obligation applies. Processor: the mailboxes are hosted by ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany, under a data processing agreement pursuant to Art. 28 GDPR.
5. Using the Scrap Wars app
5.1 Guest account and player ID
The first time you launch the app, a guest account is created automatically. Two random
identifiers are generated — an account identifier and a player ID — and the session, including
access and refresh tokens, is stored securely on your device (Android Keystore via
expo-secure-store). These identifiers contain no
information about you, are not derived from device characteristics, and are not advertising IDs.
They nonetheless constitute pseudonymous personal data under Art. 4(5) GDPR, because your game activity is permanently associated with them.
Purpose: associating your saved game, authenticating your requests to the game server, protecting against manipulation. Legal basis: Art. 6(1)(b) GDPR — performance of the contract to provide the game. Retention: see section 9.
The guest account is bound to your device. If you uninstall the app, clear its data, or switch devices, you lose access to your saved game permanently and irrecoverably. There is no recovery, because I hold no information that would let me match you to an existing save.
5.2 Saved game and gameplay
Scrap Wars is an online game with server-authoritative logic: game state is held on the server, not on your device. The data processed is what your saved game consists of — story progress, resources and inventory, units and their configuration, positions and orders in the game world, and the timing of game events.
Some of this is visible to other players in the same zone (for example convoys on the map). Only game objects and the pseudonymous identifier are visible; no real names, contact details or freely entered text are transmitted.
Purpose: providing the game. Legal basis: Art. 6(1)(b) GDPR.
5.3 Game API server logs
Every request the app makes to the game server is logged: IP address, timestamp, endpoint, HTTP status code and — after successful authentication — your player ID.
Purpose: operational security, troubleshooting and abuse detection. During the testing phase these logs are the only means of reproducing a reported fault. Legal basis: Art. 6(1)(f) GDPR, and Art. 6(1)(b) GDPR where logging serves performance of the contract. Logging and retention: the game API runtime logs I use remain available in the Render dashboard for 7 days. I do not export these logs or keep additional copies outside Render. This is separate from technical usage and security data that Render processes as an independent controller (section 4.2).
5.4 Processors
| Service | Provider | Purpose | Place of processing | Transfer basis |
|---|---|---|---|---|
| Database & authentication | Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 | Storing the saved game, issuing and verifying access tokens | EU (eu-central-1, Frankfurt am Main) | Standard Contractual Clauses |
| Application server | Render Services, Inc., 525 Brannan St, Suite 300, San Francisco, CA 94107, USA | Running the game API, server logs | EU (Frankfurt am Main) | Standard Contractual Clauses, additionally EU-U.S. Data Privacy Framework |
| App updates | 650 Industries, Inc. (Expo), 624 University Ave FL1, Palo Alto, CA 94301, USA | Delivering app updates (section 5.6) | USA | Standard Contractual Clauses, additionally EU-U.S. Data Privacy Framework |
Data processing agreements under Art. 28 GDPR are in place with all of the above. Game data is stored on servers within the European Union; on third-country access, see section 7.
5.5 Distribution via Google Play and Android
The app is distributed through Google Play. On installation, update and use, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland processes personal data from your Google account and device as its own controller. I have no influence over this; Google's privacy policy applies: https://policies.google.com/privacy.
Google provides me with aggregated, non-individual reporting (including crash and error rates via Android Vitals, and install counts). I embed no SDK for this; the data originates at the Android platform level.
5.6 App updates (expo-updates)
The app includes the expo-updates component, which lets me deliver fixes during the testing phase
without a full store update. On launch the app checks with Expo (650 Industries, Inc., USA)
whether a newer build is available. This transmits your IP address, the platform (Android), the
runtime version of the installed app, and a randomly generated identifier for this installation of
the app. That identifier is not derived from device or account data and is not linked to your
player ID; it is nonetheless pseudonymous data.
Purpose: delivering fixes within the testing phase. Legal basis: Art. 6(1)(f) GDPR — my legitimate interest in fixing faults promptly during an ongoing test.
5.7 Permissions and device access
The app requests no sensitive Android permissions. It does not access location, camera, microphone, contacts, phone, calendar, photos, or storage outside its own app directory.
The session, including access and refresh tokens, is stored securely on your device through
expo-secure-store. The access token is transmitted to the game services to authenticate requests;
the refresh token is transmitted to Supabase's authentication service to renew the session. These
transmissions are TLS-encrypted.
The app also uses local game-state caches, app settings and technical status values. The
authoritative saved game is held on the server (section 5.2). The update component also uses local
update files and an installation identifier (section 5.6). Uninstalling the Android app removes
local app data, including the session stored by expo-secure-store. Removing local app data does
not delete the server-side guest account or saved game; their retention is described in section 9.
6. Processing during the closed testing phase
This section applies only to people invited as testers.
6.1 Tester roster
To run the closed test I maintain a list of participants containing: name, the email address linked to the Google account (technically required, because Google Play binds test access to an account), the date participation was confirmed, device model and Android version, and a status note.
Purpose: granting test access on Google Play, emailing information about new test releases and test instructions, tracing reported faults. Regular status updates are posted only in Discord; information about new test releases and test instructions is also available there. Legal basis: Art. 6(1)(a) GDPR (your consent to take part) and Art. 6(1)(b) GDPR to carry out your participation. Recipients: the email address is transmitted to Google in order to grant test access. Retention: deleted within 90 days of the end of the testing phase, or without delay upon withdrawal of consent.
Participation is voluntary. You may withdraw your consent at any time, without giving reasons and without disadvantage; the lawfulness of processing before withdrawal is unaffected.
6.2 Feedback and fault reports
Feedback is collected through a private channel on Discord (Discord Netherlands BV, Amsterdam, Netherlands / Discord, Inc., USA). Discord's own privacy policy applies, and your Discord account and its use are your own responsibility. Using Discord is optional — feedback by email is equally acceptable.
Technical fault descriptions are recorded as issues in a private repository on GitHub (GitHub, Inc., USA / Microsoft). Before copying a report, I remove names, Discord identifiers, email addresses, player, account and installation identifiers, and other identifying information from the text and attachments such as screenshots. Only the sanitised technical fault description is copied. Personal feedback remains in the respective feedback channel and is not copied into GitHub as such.
Legal basis: Art. 6(1)(f) GDPR.
6.3 What is evaluated during the test
I evaluate only data the server already holds — essentially story progress, connection stability, and the punctuality of scheduled game events — in aggregate across all participants. No additional analytics tooling is used and no additional data is collected for this purpose.
7. Transfers to third countries
Game data is stored on servers in the European Union (Frankfurt am Main). Supabase Pte. Ltd. (Singapore) and Render Services, Inc. (USA) are nonetheless companies established outside the EU, and access from a third country — particularly for remote maintenance and support — cannot be ruled out. The website is delivered through Render's worldwide content delivery network (section 4.2). Expo (650 Industries, Inc.) processes the data described in section 5.6 in the United States. The use of Discord may also involve processing in the United States. Technical fault descriptions are copied into GitHub after identifying information has been removed as described in section 6.2.
Singapore has no adequacy decision from the European Commission; transfers to Supabase are therefore based solely on the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR.
Where personal data is transferred to, or accessible from, the United States, the transfer is based on:
- the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework of 10 July 2023, where the provider concerned is certified under that framework, and/or
- the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR, supplemented by additional safeguards — in particular encryption in transit and limiting the data set to pseudonymous identifiers.
Please note that the United States does not provide a level of data protection fully equivalent to that of the EU, and that access by US authorities cannot be ruled out with certainty.
You can request information about the safeguards applicable to a particular transfer and a copy of the relevant Standard Contractual Clauses by emailing info@allbitsequal.com. Public contractual information is also available from Supabase, Render and Expo.
8. Data security
Traffic between app and server is TLS-encrypted without exception. Access to game data requires a valid, cryptographically signed token; the association with a saved game is derived server-side from that token alone and is never taken from data supplied by the app. Database access is additionally protected by row-level security, so access to another player's save is technically prevented. Service credentials are held only in the environment of the respective server.
9. Retention and deletion
| Data | Retention |
|---|---|
| Website access | no visitor or access logs kept by me; for processing by the hosting provider, see sections 4.1 and 4.2 |
| Email enquiries | until the enquiry is dealt with, unless a statutory retention obligation applies |
| Game API server logs | available in the Render dashboard for 7 days; no additional copies kept by me (section 5.3) |
| Guest account, player ID, saved game | for the duration of the testing phase; deleted or anonymised within 90 days of its end |
| Saved games with no discernible use | deleted or anonymised within 90 days of last access |
| Tester roster | deleted within 90 days of the end of the testing phase; without delay on withdrawal |
| Fault reports and feedback | until resolved, at the latest the end of the testing phase |
Because this is expressly a test, your saved game may be reset during the testing phase — either individually, if you are stuck in a broken state, or for all participants. Any such reset is announced in advance. Your participation in the test and your access to the app are unaffected.
10. Age
The app is intended for people aged 13 and over and is not intended for children under 13. Regional content ratings on Google Play differ, including USK 12, PEGI 16 and ESRB Teen. The intended audience of “13+” is not a universal content rating; please observe the rating displayed in the store for your region. Processing is not based on consent within the meaning of Art. 8 GDPR but on performance of the contract; participation in the closed testing phase (section 6) requires that you are of full legal age.
11. No obligation to provide data
You are under no obligation to provide personal data. The data described in section 5, however, arises as a technical necessity of playing an online game; without it the game cannot be provided.
12. Changes to this policy
This policy will be updated whenever the processing described here changes — for example when the app leaves testing, when purchases are introduced, or when further services are integrated. The version published on this page applies. Material changes are additionally communicated to participants in the testing phase.