Legal document
IMMONA Game Privacy Policy – Website and MVP/Beta App
Effective as of September 30, 2026
This English version is provided for convenience. The Polish version is the primary version. In the event of an interpretative discrepancy, the Polish version shall prevail to the extent permitted by mandatory applicable law.
IMMONA GAME PRIVACY POLICY – WEBSITE AND MVP/BETA APP
effective as of September 30, 2026
1. WHO IS THE DATA CONTROLLER?
The controller of your personal data is IMMONA GAME PROSTA SPÓŁKA AKCYJNA, with its registered office in Lublin, ul. Gospodarcza 26, 20-213 Lublin, Poland, KRS 0001255176, NIP 9462770286 (“IMMONA”, the “Controller”, “we”).
Privacy and personal data contact: office@immonagame.pl.
This Policy applies to:
- the IMMONA Game website, in particular https://www.immonagame.pl (the “Website”);
- forms, surveys, the waitlist and research activities relating to IMMONA Game;
- the IMMONA Game mobile application distributed in particular through Apple TestFlight, Google Play testing or another controlled channel (the “App”);
- the IMMONA Game MVP/beta testing version (the “MVP/Beta”).
The MVP/Beta is intended for persons aged 18 or over.
2. KEY INFORMATION
-
We process Account data and data necessary for the App primarily in order to provide the MVP/Beta service.
-
You may sign in using a Google or Apple account. Authentication is technically handled using Supabase.
-
Supabase stores, among other things, Account data, digital character (“Twin”) data, quest and progression data, level and evolution history and notification tokens if notifications are enabled.
-
Where a quest uses steps, the App may – after the relevant system permission is granted – use step information from your device. Our backend stores quest progress rather than a complete device activity history. We do not use this information to diagnose or infer your health status.
-
Behavioural analytics on the Website and product analytics in the App are optional and are activated only after you consent to analytics, as described in section 5.
-
On the Website we may use Microsoft Clarity for heatmaps and session recordings and Firebase/Firestore for pseudonymous experiment events and micro-survey responses after the required consent has been obtained.
-
In the App we may use Firebase Analytics to measure product events and Firebase Crashlytics for crash diagnostics in accordance with your privacy settings.
-
Recruitment forms and some surveys may be provided through Tally.
-
We do not sell your personal data or disclose it to advertisers for their own marketing purposes.
-
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you.
3. WHAT DATA DO WE PROCESS AND WHY?
3.1. Website operation and technical security
We may process:
- IP address;
- date and time of a request;
- browser, operating system and device information;
- requested page and basic request information;
- error and security information;
- language settings;
- information about stored privacy/cookie preferences.
Purposes:
- displaying and operating the Website;
- security, abuse prevention and diagnostics;
- remembering privacy and language settings.
Legal basis:
- Article 6(1)(f) GDPR – our legitimate interest in ensuring the security, stability and proper operation of the Website;
- for technologies strictly necessary to provide a service requested by you – the applicable exemption under Article 399(3) of the Polish Electronic Communications Law.
Technical data is retained for the period necessary for security and diagnostics, generally no longer than 12 months unless longer retention is required to investigate an incident or defend legal claims.
3.2. Landing-page analytics and product experiments
If you consent to analytics, we may process pseudonymous Website usage information, including:
- a random visitor identifier (
visitor_id); - session identifier (
session_id); - assigned message or experiment variant, such as A/B;
- Website language;
- device category such as mobile/tablet/desktop;
- acquisition source, referrer and UTM campaign parameters;
- visited sections and screens;
- clicks, scrolling, interactions and events such as opening or submitting a sign-up form;
- research segment assigned based on answers, such as “gamer”, “wellbeing”, “mixed” or “unknown”;
- responses to micro-surveys;
- interest in selected product elements or Test Offers.
Purposes:
- measuring landing-page and beta funnel effectiveness;
- conducting A/B tests and comparing message variants;
- understanding the use of the product demonstration;
- validating hypotheses for the MVP experiment;
- improving the Website and product.
Legal basis:
- Article 6(1)(a) GDPR – your consent;
- for storing or accessing information on the device – your consent under Article 399 of the Polish Electronic Communications Law, unless the technology is strictly necessary to provide a service requested by you.
Consent is voluntary. Refusal should not prevent access to core Website content or applying for testing.
You may change your decision at any time in the Website cookie/privacy settings.
3.3. Microsoft Clarity – heatmaps and session recordings
After analytics consent is given, we may use Microsoft Clarity to understand how the Website is used.
Clarity may process, among other things:
- pseudonymous browser/device and session identifiers;
- device and browser information and approximate location derived from the network connection;
- page views;
- clicks, pointer movement, scrolling and other interactions;
- information used to generate heatmaps;
- information used for session playback;
- experiment tags provided by us, such as message variant, segment, language, surface and selected campaign parameters.
We do not use Clarity for the purpose of identifying you by name or email. We do not send Tally form response content to Clarity as analytics data.
Legal basis: Article 6(1)(a) GDPR and the consent required for non-essential device technologies.
Under Clarity's current retention rules, session playback data is generally retained for 30 days, while heatmap/click data may be retained for up to 9 months, subject to changes in configuration or provider rules.
3.4. Website micro-surveys and Firebase/Firestore
After analytics consent is given, responses to short surveys embedded in the Website may be written to Google Firebase / Cloud Firestore together with experiment context.
This may include:
visitor_idandsession_id;- question identifier;
- answer;
- research segment;
- message variant;
- language;
- survey surface/screen;
- timestamp;
- attribution information and Website usage events.
The data is used to analyse experiment results and develop the product.
Legal basis: Article 6(1)(a) GDPR.
Individual experiment data is generally retained for up to 12 months from collection and then deleted or aggregated/anonymised, unless longer retention is required to document incubation programme results or defend legal claims.
3.5. Tally surveys and forms
Some forms and surveys may be provided by Tally BV.
We may process:
- survey responses;
- selected answers and profiling questions;
- an email address or other contact details provided voluntarily;
- information about interest in testing, community or an interview;
- technical information relating to form submission;
- where you have consented to analytics – pseudonymous
visitor_id, segment, message variant and selected campaign parameters passed as hidden form fields.
Purposes:
- research and product validation;
- recruitment to the MVP/Beta;
- contacting you about your request;
- analysis of research results.
Legal basis:
- Article 6(1)(f) GDPR – research and product validation where the survey is not part of entering into or performing an agreement;
- Article 6(1)(b) GDPR – where processing is necessary to take steps at your request in connection with participation in the MVP/Beta;
- Article 6(1)(a) GDPR – experiment data passed to a form only after analytics consent;
- separate consent for marketing where required.
Please do not enter health data or other special-category data in open fields unless we expressly request it and provide appropriate information about the processing.
Survey responses are generally retained for up to 24 months and then deleted or anonymised. Data of persons waiting for an invitation is generally retained for up to 12 months after the last contact or until the relevant recruitment programme ends, whichever occurs first, unless another legal basis justifies further processing.
3.6. Waitlist and MVP/Beta recruitment
If you apply to participate in testing, we may process:
- email address;
- qualification responses from the form;
- preferred language;
- invitation and testing status;
- organisational information relating to sending or activating an invitation;
- test-related communication history.
Purposes:
- receiving your application;
- selecting and inviting Testers;
- organising access through TestFlight, Google Play or another testing environment;
- sending operational communications relating to the test.
Legal basis: Article 6(1)(b) GDPR – taking steps at your request before entering into and for performing an agreement concerning participation in the MVP/Beta; where appropriate, also Article 6(1)(f) GDPR – organisation and documentation of the testing programme.
A message such as “your beta access is ready” does not constitute consent to unrelated marketing.
3.7. Account and sign-in
You may create or access an Account using, among other options, Google Sign-In or Sign in with Apple.
Depending on the selected provider, we may receive:
- a technical account/user identifier;
- email address, including an Apple private relay address if you choose that option;
- name or profile name if shared by the identity provider;
- avatar URL if shared;
- information required to create and maintain an authentication session.
Authentication and Account sessions are handled using Supabase Auth. Session information may be securely stored on the device using system Secure Store functionality.
Purposes:
- creating and managing the Account;
- authenticating the User;
- maintaining the session and Account security;
- providing access to data assigned to the User.
Legal basis: Article 6(1)(b) GDPR.
We do not receive or store the password to your Google or Apple account.
3.8. Gameplay, Twin and progression data
In connection with the MVP/Beta we process information needed for IMMONA Game mechanics, including:
- Supabase user identifier;
- Twin/Character name chosen by the User;
- character type/appearance to the extent stored by the App;
- experience points, level and development stage;
- Body, Mind and Spirit stats;
- evolution category;
- assigned quests;
- quest effort level, target and reward;
- current progress;
- completion status and date;
- level-up and evolution history;
- basic creation/update timestamps.
Purposes:
- providing game functionality;
- saving progress;
- displaying Character history and development;
- synchronising data between sessions;
- proper operation of the MVP/Beta.
Legal basis: Article 6(1)(b) GDPR.
Gameplay data is retained while the Account exists. Following Account deletion, User-linked data should be deleted or anonymised from active systems without undue delay, subject to backups and data that must be retained by law or for legal claims.
3.9. Steps and physical activity information
Some quests may use your device step counter.
After you grant the relevant system permission, the App may:
- read the number of steps required for the current quest;
- calculate progress increments;
- store quest progress in Supabase.
As a rule, we do not store your complete device step history in our backend. The backend receives the progress value needed for the relevant task.
We do not use step count or quest progress to diagnose health or create a medical profile.
Purposes:
- performing a step-based quest selected by you;
- displaying progress and granting an in-game reward.
Legal basis:
- Article 6(1)(b) GDPR – providing an App function requested by the User;
- the relevant device system permission;
- to the extent Article 399 of the Polish Electronic Communications Law applies – consent or the exemption for information necessary to provide the requested function.
If you do not grant motion/activity permission, a quest requiring automatic step counting may not work, but this should not restrict functions that do not require such access.
3.10. Push notifications and Firebase Cloud Messaging
If you allow notifications, we may process:
- FCM token / installation identifier required to deliver a notification;
- Account identifier linked to the token;
- operating system and technical information required to deliver the notification;
- whether notifications are enabled;
- notification-open information where analytics is active.
Purposes:
- delivering App-related communications;
- reminders relating to activities and testing;
- analysing the usefulness of notifications where analytics consent has been given.
Legal basis:
- Article 6(1)(b) GDPR – providing notification functionality enabled by the User;
- Article 6(1)(a) GDPR – optional interaction analytics;
- separate consent under the Polish Electronic Communications Law where a notification constitutes direct marketing or commercial communication requiring such consent.
The FCM token is detached from the Account on sign-out, and tokens no longer associated with a user are periodically deleted from our database. The current configuration removes orphaned tokens older than 30 days.
3.11. Firebase Analytics in the App
If you consent to App analytics, we may use Google Analytics for Firebase.
We may record, among other things:
- a user identifier linked to the Account;
- App language;
- operating system, App version and basic device parameters;
- screens viewed;
- sign-in start and result;
- quest start and completion;
- Twin creation;
- Character level-up and evolution;
- permission decisions;
- notification opens;
- use of selected App functions;
- display of or interaction with a Test Offer if such events are implemented.
We do not use Firebase Analytics for personalised advertising. MVP/Beta data is not intended for advertising personalisation.
Purpose: measuring MVP/Beta performance and validating product hypotheses.
Legal basis: Article 6(1)(a) GDPR and, for access to information on a device, consent required under the Polish Electronic Communications Law.
You may withdraw consent in App privacy settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
We configure user-data retention in Google Analytics for no more than 14 months unless a shorter period follows from service settings.
3.12. Firebase Crashlytics – crash diagnostics
If you consent to optional diagnostics/analytics, we may use Firebase Crashlytics.
Crashlytics may process, among other things:
- Crashlytics/Firebase installation identifiers;
- a User identifier set by the App;
- App version;
- device model and operating system version;
- crash information, stack traces, logs and error context;
- time of the crash;
- technical information needed to reproduce and resolve the issue.
Purpose: detecting and resolving errors and improving App stability and security.
Legal basis: Article 6(1)(a) GDPR under our consent-based model for optional diagnostics/analytics.
Google currently states that core Crashlytics crash data and associated identifiers are generally retained for 90 days before removal from live and backup systems begins.
3.13. Feedback, interviews and qualitative research
If you participate in an additional interview, conversation or research session, we may process:
- contact data;
- answers, opinions and suggestions;
- product experience information;
- interview notes;
- audio or video recording only where you have been informed in advance and an appropriate legal basis exists.
Purposes:
- evaluating the MVP/Beta;
- product development;
- qualitative analysis of experiment results.
Legal basis:
- Article 6(1)(f) GDPR – our legitimate interest in researching and developing the product;
- Article 6(1)(a) GDPR where we ask for consent for a particular form of research, in particular recording.
Qualitative research data is generally retained for up to 24 months and then deleted or anonymised.
3.14. Future-offer interest tests (“fake door”)
The MVP/Beta may display experimental prices, plans or features to test interest in a future offer.
We may process:
- display of a Test Offer variant;
- selected variant or clicked button;
- expressed interest;
- related pseudonymous analytics identifier where analytics consent has been given.
A fake-door test does not charge you and clicking does not enter you into a paid agreement.
Legal basis:
- operation of the MVP/Beta function – Article 6(1)(b) GDPR;
- behavioural analytics and linking the reaction to an analytics profile – Article 6(1)(a) GDPR.
3.15. Contacting us
If you contact us by email or another communication channel, we may process:
- email address;
- your name if provided;
- message content;
- other data included in your correspondence.
Purposes: responding, handling the matter and retaining a record of arrangements.
Legal basis:
- Article 6(1)(f) GDPR – legitimate interest in handling correspondence and enquiries;
- Article 6(1)(b) GDPR where the communication concerns entering into or performing an agreement.
Correspondence is retained for as long as required to handle the matter and subsequently for a period justified by legal claims or documentation needs.
3.16. Newsletter and marketing
If you separately subscribe to a newsletter or consent to marketing, we may use your email address or another selected channel to provide information about IMMONA Game, testing, community, product development or future offers.
Legal basis:
- Article 6(1)(a) GDPR – consent;
- the appropriate consent for the use of electronic communications where required by Article 398 of the Polish Electronic Communications Law.
You may withdraw consent at any time. We retain the data until consent is withdrawn or the communication channel is discontinued. Evidence of consent and withdrawal may be retained for the period necessary to demonstrate compliance and defend claims.
Acceptance of the MVP/Beta Terms is not consent to marketing.
3.17. Legal claims, compliance and security
We may retain information required to:
- establish, exercise or defend legal claims;
- demonstrate legal compliance;
- handle security incidents;
- prevent abuse.
Legal basis: Article 6(1)(f) GDPR and, where a legal obligation applies, Article 6(1)(c) GDPR.
Data is retained for the relevant limitation period or for the period required by law.
4. DO WE PROCESS HEALTH DATA?
IMMONA Game is not a medical product and at the MVP/Beta stage is not designed to diagnose health.
Information such as step count, completion of a movement task or selected effort level may relate to a User's activity, but we do not use it to establish a diagnosis, health status or medical profile.
Please do not provide information about diseases, diagnoses, treatment, disabilities or other special-category data in open survey or feedback fields unless we expressly request such information and provide additional processing information.
If we inadvertently receive special-category data without requesting it, we will limit processing to what is necessary to handle the matter and, where no legal basis for further processing exists, delete it.
5. COOKIES AND SIMILAR TECHNOLOGIES
5.1. What are cookies and similar technologies?
Cookies are small pieces of information stored by a browser and sent during subsequent connections to the relevant domain. Similar technologies include localStorage (browser storage without automatic expiry), sessionStorage (storage associated with a tab session), IndexedDB, session or installation identifiers and other mechanisms that store information on a device or access it. Identifiers may link visits or events without identifying you by name.
Device-access rules arise from Article 399 of the Polish Electronic Communications Law and also apply to technologies other than cookies. Where the information constitutes personal data, the rules described in the other parts of this Policy also apply.
5.2. Categories of technologies
-
Strictly necessary technologies support privacy choices, authentication or a function you request. They may operate without consent only within the exemption in Article 399(3) of the Polish Electronic Communications Law: where necessary to transmit a communication or provide a requested service. Merely calling a technology necessary does not cover its additional analytics uses.
-
Analytics technologies measure Website use, A/B variants and traffic sources. They are optional and we activate them only after your analytics consent.
-
Functional technologies may support additional features, such as the embedded YouTube video player. Necessity is assessed against the particular function requested; other uses require prior consent. The current landing does not store a separate language preference in cookies or browser storage: the language version follows the page address. Saving the functional category choice in cookie settings does not mean that we use a separate mechanism to remember optional preferences.
5.3. Technologies used on the Website
Our first-party experiment mechanisms store pseudonymous visitor_id and session_id identifiers, the A/B message variant and the first visit source: UTM parameters, referrer, page language and capture time. The referrer stored by this mechanism excludes query parameters and the URL fragment.
| Technology | Provider | Purpose | Category | Retention |
|---|---|---|---|---|
localStorage: immona_cookie_consent_v1 | IMMONA Game | Remember acceptance or refusal of consent and category choices | Strictly necessary | No configured expiry; until the choice is overwritten or browser data is deleted |
Cookie immona_prototype_auth | IMMONA Game | Maintain access after successful sign-in to the protected prototype | Strictly necessary for requested access | 24 hours; deleted on sign-out |
localStorage: visitor identifier, A/B variant and first visit source | IMMONA Game | Link visits and measure the experiment | Analytics, after consent | No automatic expiry; removed by the main landing mechanism operating without consent or by the user |
sessionStorage: visitor and session identifiers, A/B variant and first visit source | IMMONA Game | Link events within the tab session | Analytics, after consent | Tab session; earlier removal by the landing mechanism or the user is possible |
Microsoft Clarity: cookies including _clck and _clsk, and SDK session storage | Microsoft | Website-use analysis, heatmaps and session recordings | Analytics, after consent | _clck: normally 365 days; _clsk: normally 1 day; SDK session storage: tab session. Service-data retention is described in section 5.6 |
| Firebase / Cloud Firestore: SDK cache and server-side event storage | Google / Firebase | Pseudonymous experiment events and micro-survey responses | Analytics, after consent | In-memory cache while the page is running; server-side data periods: sections 3.4 and 8 |
| Firebase App Check with reCAPTCHA Enterprise: tokens, IndexedDB and reCAPTCHA browser mechanisms | Google / Firebase | Protect experiment infrastructure access against abuse | Protection of the analytics integration; activated after analytics consent | Tokens have an expiry assigned by the service; the landing code sets no fixed period for tokens or all provider data |
| Embedded Tally form and form support script | Tally | Display and handle beta applications; transmit experiment context only after analytics consent | Requested form service; additional context: analytics | The landing code sets no retention period for data held by Tally; application data: sections 3.1 and 8 |
Embedded YouTube player on the youtube-nocookie.com domain | Google / YouTube | Display video content on the Mirror page | Functional; not part of our first-party experiment analytics | Any provider-side storage periods depend on player operation and Google rules; the landing code sets no fixed period |
The experiment keys in localStorage are immona_experiment_visitor_id_v1, immona_experiment_message_variant_v1 and immona_experiment_first_touch_v1. In sessionStorage they are immona_experiment_session_visitor_id_v1, immona_experiment_session_id_v1, immona_experiment_session_message_variant_v1 and immona_experiment_session_first_touch_v1.
This Firestore implementation does not enable persistent browser offline storage. The separate App Check mechanism may store tokens in IndexedDB. Google also states that reCAPTCHA uses the _GRECAPTCHA cookie for risk assessment when executed; we do not assign it a period not specified by the landing configuration or the referenced documentation.
The Clarity cookie list may also include Microsoft cookies described in the provider documentation; actual storage depends on consent, the browser and provider rules, among other things. We send an advertising-consent refusal to Clarity. The YouTube youtube-nocookie.com mode limits personalisation under the player rules, but does not guarantee the absence of device access or data processing by Google. Form rules are described in the Tally Privacy Policy.
5.4. Consent
Analytics is voluntary. Refusal does not block access to basic Website content or a beta application. Website analytics does not start before consent is given. Continued browsing or acceptance of the Terms is not treated as analytics consent.
Before consent, only storage or access strictly necessary to operate the consent mechanism or provide a requested service may operate within the statutory exemption. Other technologies that store or access device information require prior consent. The application form remains available after refusal; our identifiers and analytics context are added only after consent.
5.5. Changing and withdrawing consent
At any time, you can open “Cookie Settings” in the Website footer, change category choices and save the settings. To withdraw analytics consent, disable the analytics category and save your choice. Withdrawal must be as easy as giving consent and requires neither contacting us nor providing a reason.
You may also use browser settings to block cookies and delete cookies, localStorage, sessionStorage and other site data. Deleting the stored decision alone does not communicate a new choice to us: cookie settings may be shown again. Deleting data necessary for sign-in may end the prototype session.
Withdrawal means that you no longer consent to further optional processing within its scope. It does not affect the lawfulness of processing before withdrawal and does not automatically delete data previously transmitted to provider systems; sections 8 and 10 govern retention and the exercise of rights.
5.6. Retention periods
Device-storage periods differ from server-side personal-data retention. localStorage has no automatic expiry of its own, and the current implementation sets none for the consent decision or experiment data. sessionStorage is associated with a tab session, subject to browser session-restoration features. Browser deletion or restrictions may shorten the periods stated.
The main landing mechanism removes first-party experiment records from localStorage and sessionStorage when operating without analytics consent, including after a consent change on that page. This does not automatically remove all provider cookies or SDK data. You can delete them in browser settings.
Standard _clck and _clsk cookie periods follow the code published by Microsoft. Clarity session playback data is normally available for 30 days and heatmaps for up to 9 months. The provider also retains recordings marked as favourites and a randomly selected recording sample for up to 9 months, under the Clarity FAQ. This clarifies the standard periods stated in sections 3.3 and 8.
The landing code does not configure automatic deletion of Firestore records after a specific period. Firestore personal-data retention is described in sections 3.4 and 8; these periods are not cookie or local-identifier expiry periods. App Firebase Analytics, Crashlytics and FCM data periods are described in sections 3.11, 3.12, 3.10 and 8 respectively.
5.7. Mobile App
The App need not use browser cookies to store or access device information. It may use local device storage, including secure system Secure Store mechanisms, to store:
- Supabase session tokens;
- FCM token and installation identifiers needed for notifications;
- whether a particular permission request has already been shown;
- preferred language, privacy settings and other App settings;
- other information necessary to maintain the session and requested functionality.
Some mobile SDKs use installation identifiers and device information. Optional analytics and diagnostics SDKs, including Firebase Analytics and Crashlytics described in sections 3.11 and 3.12, collect data only after the relevant consent. You manage consent for these technologies in App privacy settings; a browser choice does not replace a separate App choice. Technologies necessary to maintain a session or provide a function you request may operate within the exemption in Article 399(3) of the Polish Electronic Communications Law. App-data periods remain defined in sections 3 and 8.
6. WHO MAY RECEIVE THE DATA?
Your data may be processed by service providers supporting our activities, including:
- Supabase – authentication, database, backend and storage for the MVP/Beta;
- Google / Firebase – Analytics, Crashlytics, Cloud Messaging and Firebase/Firestore infrastructure used for the landing experiment;
- Google – Google sign-in;
- Apple – Sign in with Apple, TestFlight and Apple platform services;
- Tally BV – forms and surveys;
- Microsoft – Microsoft Clarity;
- hosting, cloud infrastructure, email and development-tool providers;
- technical support and security providers;
- accountants, lawyers and other professional advisers where necessary;
- public authorities and courts where disclosure is required by law.
We disclose to each provider only the data reasonably required for the relevant purpose.
If you follow a link to an external service such as Discord or Buy Me a Coffee, further processing on that service is also governed by the provider's own privacy rules. Voluntary support through Buy Me a Coffee is not required to use the MVP/Beta.
7. TRANSFERS OUTSIDE THE EEA
Some infrastructure or technology providers may process data outside the European Economic Area, including in the United States.
Where data is transferred outside the EEA, we rely on a GDPR-compliant transfer mechanism depending on the recipient and transfer, including:
- an adequacy decision under Article 45 GDPR, including the EU-U.S. Data Privacy Framework where the relevant US recipient participates; or
- European Commission Standard Contractual Clauses under Article 46 GDPR, with supplementary safeguards where required.
You may contact us for more information about the transfer mechanism used for a particular provider.
8. HOW LONG DO WE RETAIN DATA?
We apply data-minimisation and storage-limitation principles. Indicative periods are:
- Account and gameplay data: while the Account exists; following deletion, deletion or anonymisation from active systems without undue delay, subject to backups and data required for legal claims;
- waitlist/recruitment: generally up to 12 months after the last contact or until the recruitment programme ends;
- surveys and qualitative research: generally up to 24 months, then deletion or anonymisation;
- landing experiment events in Firestore: generally up to 12 months, then deletion or aggregation/anonymisation;
- Microsoft Clarity: under the provider's current rules, session playback normally up to 30 days and click data/heatmaps normally up to 9 months;
- Firebase Analytics: no more than 14 months for user data under our configuration;
- Firebase Crashlytics: under Google's current rules, core crash data and associated identifiers are normally retained for 90 days before the deletion process begins;
- FCM: while needed for notifications; tokens detached from an Account are periodically removed from our database, currently after 30 days without an association;
- contact: until the matter is resolved and then for the period necessary to defend claims;
- marketing/privacy consents: while valid and subsequently for the period necessary to demonstrate the consent, its content or withdrawal.
Once information has been effectively anonymised so that it can no longer be linked to an individual, aggregated research results may be kept for longer.
9. SOURCES OF DATA
We generally obtain data:
- directly from you;
- from your device and the App when you use functions for which the required permissions have been granted;
- from Google or Apple in connection with your selected sign-in method;
- from technical providers in connection with operation of the Website and App;
- from campaign parameters or the referring page where analytics is active.
We do not purchase lists of individuals interested in the MVP/Beta.
10. YOUR RIGHTS
Depending on the legal basis and circumstances of processing, you have the right to:
- access your data and receive a copy – Article 15 GDPR;
- rectification – Article 16 GDPR;
- erasure – Article 17 GDPR;
- restriction of processing – Article 18 GDPR;
- data portability – Article 20 GDPR where applicable;
- object to processing based on Article 6(1)(f) GDPR – Article 21 GDPR;
- withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal;
- lodge a complaint with the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
To exercise your rights, contact office@immonagame.pl.
Where a request concerns Account-linked data, we may ask for information reasonably necessary to verify that you are entitled to submit the request.
11. ACCOUNT DELETION
You may request Account deletion:
- through an in-App function once available in the relevant version; or
- by contacting office@immonagame.pl.
Deleting the Account ends access to User-linked data. Account and gameplay information is deleted or anonymised in accordance with the retention rules above.
Some information may remain for a limited period in backups or may be retained where necessary to comply with law, protect against abuse or defend legal claims.
12. PROFILING AND AUTOMATED DECISION-MAKING
As part of experiments we may:
- assign a User to an A/B variant;
- group survey responses into a research segment such as gamer/wellbeing/mixed;
- compare behaviour between User groups;
- analyse interest in functions or variants of a future offer.
These activities are carried out for research and product development.
We do not use them to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
13. SECURITY
We use technical and organisational measures appropriate to the risks, including:
- User authentication;
- access control;
- Row Level Security mechanisms in the MVP/Beta database;
- encrypted transmission;
- secure system storage of session tokens on the device;
- limiting data disclosed to providers;
- error and incident monitoring;
- need-to-know access controls for team members and contractors.
No method of data transmission or storage can guarantee absolute security.
14. THIRD-PARTY PLATFORMS
The MVP/Beta may be distributed through Apple TestFlight and Google Play. Use of those platforms is also governed by their own privacy rules.
If you select Google Sign-In or Sign in with Apple, the identity provider independently processes information necessary to provide its service under its own rules.
If you leave our Website for an external service such as Discord or Buy Me a Coffee, information that you provide directly to that service is governed by the relevant operator's policies.
15. CHANGES TO THIS POLICY
We may update this Policy, in particular if:
- Website or App functionality changes;
- a technology provider is added or removed;
- the experiment scope changes;
- new payment or community features are launched;
- applicable law or supervisory guidance changes.
The current version will be published on the Website with its effective date.
Where a change materially affects the processing of data of Account holders, we will provide appropriate notice, for example in the App or by email.
16. CONTACT
For privacy and personal data matters:
IMMONA GAME PROSTA SPÓŁKA AKCYJNA
ul. Gospodarcza 26
20-213 Lublin
Poland
Email: office@immonagame.pl
KRS: 0001255176
NIP: 9462770286
