Privacy Policy
Last updated: October 7, 2026
This privacy policy explains how personal data is processed on the website flasche-bitte.de and in the mobile app “Flasche, bitte!” (iOS & Android).
1. Controller
Joshua AckermannDunantstraße 7
79110 Freiburg im Breisgau, Germany
E-mail: support@flasche-bitte.de
2. Data processing on this website
2.1 No cookies, no tracking
This website is a static website. It sets no cookies, uses no analytics or tracking services and embeds no third-party content (fonts, scripts and images are served exclusively from this domain). For this reason no cookie banner is required.
2.2 Hosting and delivery (Cloudflare)
The website is delivered via Cloudflare Pages and the content delivery network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. When you visit the website, Cloudflare processes technically necessary connection data (in particular IP address, date and time of access, requested URL, user agent) in order to deliver the page and to defend against attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a secure and fast operation of the website). Transfers to the USA are based on the EU-US Data Privacy Framework and/or EU standard contractual clauses. More information: cloudflare.com/privacypolicy.
3. Data processing in the app
3.1 Account and sign-in
An account is required to use the app. The following is processed:
- E-mail address and password (when registering via e-mail) — for account creation, sign-in and important system messages (e.g. password reset). The password is only stored in encrypted (hashed) form.
- Sign in with Apple (iOS) or Google (Android) — we only receive your e-mail address; we do not request your name or profile picture. With Apple this can also be an anonymous relay address. The privacy policies of Apple and Google additionally apply.
- Game data (e.g. collected bottles, level, bottle caps, inventory, village, friend lists, gifts, market listings, battles) — assigned to a random user identifier. You choose your player name (“animal name”) from suggested animal names; no real name is required.
The legal basis is Art. 6(1)(b) GDPR (providing the game) and Art. 6(1)(f) GDPR (secure operation, abuse prevention).
3.2 What other players see
“Flasche, bitte!” is played with others. Visible to all players are your animal name and your player profile: level, power level, profile bottle, banner, badges, when you joined and game statistics (e.g. streak, defeated bosses, completed sets), as well as your positions in the leaderboards and your market listings. Nobody sees your e-mail address.
3.3 Server and database (Supabase)
Account and game data are stored and processed with Supabase (Supabase Pte. Ltd., Singapore) as a processor (database, authentication, server functions). The database is located in a data centre in Frankfurt am Main, Germany (Amazon Web Services, region eu-central-1). When you sign in, the authentication service logs the time and IP address; we delete this sign-in log after 90 days. Details: supabase.com/privacy.
3.4 E-mail delivery (Resend)
System e-mails (e.g. confirmations, password resets) are sent via Resend (Resend, Inc.). The recipient's e-mail address is processed for this purpose. Details: resend.com/legal/privacy-policy.
3.5 Push notifications
The app can send you push notifications (e.g. for gifts, friend requests, bottle posts or when your daily bottle is ready). For this we store a device token of the push service, the platform, the app language, your notification settings and a random installation identifier. Notifications are delivered via Firebase Cloud Messaging (Google Ireland Limited) and the Apple Push Notification service; their texts may contain another player's animal name. So that notifications do not arrive at inconvenient times, we also remember when you last opened the app and at which times of day you usually use it (counters per hour). Push notifications can be switched off at any time in the app and in your system settings. Device tokens of signed-out accounts are deleted automatically, the log of sent notifications after 60 days.
3.6 Protection against abuse and automation
To detect and prevent fraud, multiple accounts and automated play, we process the following data: a hash value derived from the device identifier (iOS: identifier for vendor, Android: Android ID; it cannot be traced back to the identifier) together with platform and app version, the time and result of the device check (attestation), the number of requests your account sends to our server per hour, events such as suspicious requests (with the technical identifier of the requesting app, the user agent), the IP addresses of your sign-ins (to detect many accounts on one connection) and, if an account is restricted, restriction records with reason and duration. The legal basis is our legitimate interest in a fair and functioning game (Art. 6(1)(f) GDPR).
For the device check we use Firebase App Check (Google Ireland Limited) with Play Integrity on Android (Google) and App Attest / DeviceCheck on iOS (Apple Inc.). Your device sends attestation data to Google or Apple; we only receive the result (valid / invalid). No data from your game account is transmitted to Google or Apple in this process.
Retention: individual requests until the hourly roll-up (at most about one hour), hourly activity totals 90 days, bookings of the in-game currency (log for fraud cases and support) 90 days, event logs 180 days, restriction records up to 1 year after they expire, device registration and attestation results until your account is deleted.
3.7 Bottle Post (Bluetooth, optional)
With Bottle Post you meet other players who pass you in real life. It is optional and off by default; you switch it on in the game and can switch it off at any time. While it is on:
- your phone sends a random identifier that changes every hour and is issued by our server via Bluetooth Low Energy, and reads the same kind of identifier from other players' phones nearby. Device names or other device data are not sent;
- your phone remembers seen identifiers (identifier, first and last sighting, signal strength) for at most 7 days on the device; only the identifier and the sighting times are sent to our server;
- no location is determined: Android asks for the “Nearby devices” permission without location, and our server stores no place;
- Android shows a persistent notification.
Only our server can match identifiers to accounts. It stores sightings (which two accounts met when) for at most about 7 hours, sent bottle posts until 2 days after they were accepted, declined or expired, and stamps (which two accounts met on which day and which reward they got) until one of the two accounts is deleted. Other players see your animal name, level and profile bottle in Bottle Post — unless you use anonymous mode. Bottle Post notifications never contain names. If you switch Bottle Post off, the server deletes all future identifiers of your account. The legal basis is Art. 6(1)(b) GDPR (providing the game feature you switched on).
3.8 Seeker Stone (NFC, optional)
With the Seeker Stone you scan NFC seals that we hand out e.g. at events. The app only reads the code stored on the seal — not the chip's identifier — and sends it to our server to redeem it. The code, the reward and the time of redemption are stored until your account is deleted.
3.9 Bug reports
If you send us a bug report from the settings, we store your text together with your animal name, e-mail address, user identifier, app version, platform, operating system version and language, so that we can reply and reproduce the problem (Art. 6(1)(b) GDPR). If you delete your account, we remove the animal name, e-mail address and user identifier; the report itself remains without any personal reference.
3.10 App updates (Shorebird)
We deliver small bug fixes without a store update. For this the app asks the service Shorebird (Code Town, Inc., USA) at start-up whether a fix is available and downloads it if so. This transmits the app version, platform, processor type, the number of the installed fix and a random installation identifier that identifies neither you nor your device; for technical reasons Shorebird also processes the IP address. No game data is transmitted. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a bug-free app). Details: shorebird.dev/privacy.
3.11 Deluxe subscription (in-app purchases)
You purchase the optional Deluxe subscription through the App Store (Apple) or Google Play. Billing, renewal and cancellation are handled exclusively by the respective store; we never receive your payment details.
To link your subscription to your game account and check its status (active, cancelled, expired, refunded), we use RevenueCat (RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA) as a processor. This involves your player ID (a random identifier — no name, no e-mail address), the store's purchase data (product, purchase and expiry date, transaction identifiers, price, currency, store country), technical device data (operating system, app version, language setting) and your IP address. We additionally store the subscription status with Supabase (see 3.3). Details: revenuecat.com/privacy.
Legal basis: Art. 6(1)(b) GDPR (performance of the subscription contract). If you delete your account, we delete the subscription status and request deletion of your data at RevenueCat; the stores' own retention obligations remain unaffected.
3.12 No ads, no tracking
The app contains no advertising SDKs, no analytics or crash reporting services and no third-party trackers. We do not track you across other apps or websites.
4. Storage period
- Account and game data are stored for as long as the account exists.
- Shorter periods apply to some data — they are listed in the sections above (e.g. sign-in log 90 days, Bottle Post sightings about 7 hours, activity totals of the abuse protection 90 days).
- When the account is deleted, the associated personal data is deleted unless statutory retention obligations require otherwise (details in section 5).
- Website server logs are only stored for as long as necessary for operation and security.
5. Deleting your account
You can delete your account at any time directly in the app (Settings → Delete account). Deletion happens immediately and permanently. If you signed in with Apple, we also revoke the link to your Apple ID. Without the app you can ask by e-mail — instructions at flasche-bitte.de/en/delete-account.
All personal data of your account is deleted. Only the following deliberately remains:
- Your animal name is retired and never given out again. If it is listed in the thank-you credits for the first testers, it stays there.
- Gifts you sent stay with their recipients — without a sender.
- Market proceeds that another player has not collected from you yet are credited to them immediately.
- Bug reports remain without animal name, e-mail address and user identifier (see 3.9).
- The sign-in log (see 3.3) expires after its period of 90 days.
- You cancel a running Deluxe subscription in the store; the stores manage billing data according to their own rules.
6. Your rights
Under the GDPR you have in particular the right to:
- access to the data processed about you (Art. 15),
- rectification of inaccurate data (Art. 16),
- erasure (Art. 17) and restriction of processing (Art. 18),
- data portability (Art. 20),
- object to processing based on Art. 6(1)(f) (Art. 21),
- lodge a complaint with a data protection supervisory authority (Art. 77).
To exercise your rights, an informal e-mail to support@flasche-bitte.de is sufficient. Step-by-step instructions for deleting your account or only some of your data are at flasche-bitte.de/en/delete-account.
7. Recipients and transfers to third countries
We do not sell your data and do not pass it on for advertising. Recipients are only the service providers named above, working for the purposes described: Supabase (database, sign-in), Google (push, device check, Sign in with Google), Apple (push, device check, Sign in with Apple), RevenueCat (subscription), Resend (e-mail), Shorebird (app updates) and Cloudflare (website).
Where these service providers process data outside the EU/EEA, this is done on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR (EU-US Data Privacy Framework and/or EU standard contractual clauses). For RevenueCat (USA), these are the EU standard contractual clauses (Implementing Decision (EU) 2021/914) in RevenueCat's data processing agreement.
8. Changes
This privacy policy will be updated when the app or website changes. The current version is always available at flasche-bitte.de/en/privacy.