AN Andre Neubert
Apps About Contact Privacy Impressum

Memoria Land

Privacy Policy

Information about the processing of personal data in the Memoria Land mobile matching game, in online play and for in-app purchases.

Deutsch English

Last updated: August 5, 2026

1. In Short

Memoria Land shows no ads, operates no analytics services of its own, performs no cross-app tracking and does not sell personal data. One exception we disclose: if you use the optional Google sign-in, Google’s sign-in SDK also collects data for analytics purposes as an independent controller — see Section 4.2. The game processes the data needed for your account, local and cloud save, public player profile, online and tournament features, safety and purchase verification. The game server is hosted in the European Union. Google or Apple are involved when you use their optional sign-in or store services and may also provide operating-system backups according to your device settings. You can permanently delete your game account from within the app.

This policy covers the Memoria Land app on Android and iOS, its game server, and the technical delivery of the Memoria Land legal pages on andreneubert.com, including this policy, the terms and the account-deletion page.

2. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Andre Neubert
Mainz, Germany
Email: contact@andreneubert.com

Further provider details are available in the Impressum. Please send privacy enquiries to the email address above.

3. Who the App Is For

Memoria Land is intended for players aged 13 and over. It is not directed at children under 13 and does not participate in the Google Play Families programme. If it becomes known that a child under 13 is using an account, the circumstances will be reviewed and the account deleted where required. You can report such cases to contact@andreneubert.com.

4. What Data Is Processed

4.1 Data Stored on Your Device

The app stores device-specific settings and account-related data locally. This includes language, sound and music settings, onboarding status, a local copy of game progress, sign-in state, the identifier and cryptographic checksum (document hash) of the Terms revision you accepted, the identifier and document hash of the Privacy Policy revision presented with it, the language displayed, the locally stored acceptance time, game events that have not yet been synchronised with the server, and a random guest identifier. The locally stored Privacy Policy revision does not mean that it is accepted as a contract; it records which information was provided together with the Terms. The guest identifier is created when you choose to continue as a guest. It is neither a hardware identifier nor an advertising ID and is sent to the game server to create or access your pseudonymous guest account.

Local data normally remains until it is cleared in the app or operating-system settings, or until the app is uninstalled. Depending on your operating-system and backup settings, it may also be included in a device backup and restored after a reinstall or on another device. After successful account deletion, the app resets the active sign-in state and guest identifier on that device. Device-specific settings and individual local progress copies may remain; you can remove all local app data through the operating-system settings or by uninstalling the app.

4.2 Account and Optional Provider Sign-In

  • Guest account: The random guest identifier is used to create or access a pseudonymous game account on the server without separate registration.
  • Google Sign-In (optional): The app receives an authentication token containing your Google account identifier and, depending on the data supplied by Google, profile information such as your name and email address. The token is sent to the game server for validation and linking. Your first name may be used as a one-time suggestion for your display name.
  • Sign in with Apple (optional, iOS only): The app requests your Apple account identifier, email address and name. Apple may supply your real email address or a private relay address if you choose “Hide My Email”. The identity token is sent to the game server for validation and linking. Your first name may be used as a one-time suggestion for your display name.

Provider sign-in is voluntary for normal play but required before a store purchase. The game server stores the provider account identifier needed for the link; authentication tokens are processed for sign-in and validation. Linking makes the game account recoverable after a reinstall or on another device. Google and Apple process data under their own privacy terms when you use their sign-in service.

The game server also stores account-bound evidence of Terms acceptance: the identifier of the Terms revision you accepted, the identifier of the Privacy Policy revision presented with it, cryptographic checksums (document hashes) of both revisions, the language displayed, and the acceptance time set by the server. The Privacy Policy is not “accepted” as a contract; its identifier records which information was provided together with the Terms. This record is used to perform the contract and to establish, exercise or defend legal claims.

What the Google sign-in SDK collects itself

Google sign-in relies on a sign-in SDK supplied by Google and bundled with the app. It collects more than what subsequently reaches our game server, and it does so as an independent controller. The following list is taken from the privacy manifest that Google ships with that SDK and that is delivered inside the app:

  • For app functionality: name, email address, phone number, coarse location and further items Google labels as “other data types”.
  • For analytics: device identifier, user identifier, other usage data and the same “other data types”.

According to the manifest Google links this information to your identity, but declares no tracking for any of it, so it is not used for cross-app or cross-provider tracking. We receive neither the analytics data nor your phone number or location — only the authentication token described above reaches the game server. Google’s processing is governed by the Google Privacy Policy.

You can avoid this entirely: without Google sign-in, this SDK is not used for signing in. A guest account is enough to play, and on iOS “Sign in with Apple” is available for a recoverable account.

4.3 Save Game, Public Profile and Online Features

  • Display name: freely chosen and checked for prohibited terms. It is visible to other players and can be used to find your profile.
  • Save game and inventory: campaign and event progress, character and profile settings, coins, XP, diamonds, unlocked or purchased items, cosmetics, achievements and trophies.
  • Public player profile: depending on your progress, other signed-in players can see information such as your display name, level, selected character and title, trophies, league, wins, tournament results, campaign progress, achievements and recent online-match history, including opponents, result, time and duration.
  • Social and online data: account identifier, friend code, friend requests, friends list, invitations, blocks, the online status needed for those functions, leaderboard records, matchmaking and online-match results.
  • Tournaments: registration, team or bracket assignment, match results, ranking, rewards and tournament status.
  • Quick chat: online matches offer predefined phrases only. There is no free-text chat. Optional free text can, however, be submitted in a player report as described below.

4.4 Player Reports, Moderation and Abuse Prevention

If you report another player, the server stores the account identifiers and display names of the reporter and reported player, the selected category, an optional free-text note of up to 300 characters, timestamps, processing status and the moderation outcome. Where action is taken, the reason and duration of a restriction or suspension may also be stored. Do not include unnecessary personal or sensitive information in the report note.

Reports are available only to authorised moderation staff. Report counts and previous outcomes are used to prevent misuse of the reporting system. Repeated rejected reports can automatically result in a temporary loss of the ability to submit further reports. Name filters, rate limits, duplicate-purchase checks and technical fraud or abuse indicators may also operate automatically. These checks do not constitute solely automated decisions with legal or similarly significant effects within the meaning of Art. 22 GDPR; player-account sanctions are reviewed by an authorised person.

4.5 Technical Data and Logs

When the app connects to the game server, the IP address, time, account or session identifier, server function requested, technical status and error information, and security events may be processed. This is necessary to establish the connection, operate and protect the service, diagnose faults and investigate abuse. Such data may appear in server or infrastructure logs. When you open these legal pages, the web server also receives technical connection data such as the IP address, time, requested address, browser identifier and, where supplied, the previously visited page. STRATO retains IP addresses in those server logs for no more than seven days; anonymised downloadable log data may be available for up to six weeks.

The Memoria Land legal pages store your language choice in the browser only for the duration of the browser session. They do not use an advertising or tracking cookie for this purpose.

If you contact us by email, we process the sender address, time, subject, message content and technical delivery information to handle your request and, where necessary, verify that you are authorised to act for a game account.

4.6 Notifications and Permissions

While the app has an active connection, the game server can inform it about game, friend, tournament or maintenance events. The app can display a notification directly on your device. Memoria Land does not register a remote-push token and does not use a separate push-notification provider. On operating systems that require it, the app asks for notification permission; you can withdraw it at any time in the device settings.

The app needs network access and uses the relevant app store's billing function for purchases. The operating system may also ask for permission to display notifications. Memoria Land does not request access to contacts, location, photos, camera or microphone. The operating system and integrated platform services may use further purely technical system permissions, for example for network status, vibration or secure purchase handling.

4.7 What Does Not Happen

The release build contains no advertising SDK, we operate no analytics services of our own, and there is no cross-app tracking. Personal data is not sold or used for advertising profiles. Memoria Land does not make solely automated decisions that produce legal or similarly significant effects within the meaning of Art. 22 GDPR. The limited automated safety and abuse-prevention checks are described in Section 4.4.

One limitation we disclose: if you use the optional Google sign-in, Google’s sign-in SDK is bundled in the app. According to the privacy manifest Google publishes for that SDK, it also collects a device identifier and other usage data for analytics purposes — as an independent controller, not for us and not on our behalf. We do not receive that analytics data. The SDK declares no tracking for any of these data types. The affected data types are listed in Section 4.2; Google’s processing is governed by the Google Privacy Policy. If you sign in with Apple instead, or play as a guest, the Google SDK is not used for signing in.

5. In-App Purchases and Purchase Verification

Memoria Land offers consumable diamond packs and the one-time non-consumable purchase “The Insect Meadow”. The adventure can be restored on another device when you use the same linked game account and store account. There are no loot boxes, randomised purchase mechanics or gacha. Diamonds and coins are not legal tender, cannot be exchanged back into money, and are neither transferable nor tradable.

5.1 Payment and Verification

Google Play or the Apple App Store processes your payment. Andre Neubert does not receive your card number, bank details or billing address. For verification and crediting, however, the app and game server process the product identifier, store, purchase or transaction identifier, receipt or purchase token, purchase status and relevant timestamps. A pseudonymous game-account reference is also sent to the store so that the purchase can be assigned to the correct account. The receipt or token is checked with Google or Apple before an item is credited.

Raw receipts, purchase tokens and store responses are used for validation and are not kept as the permanent purchase record. Google and Apple process payment and store-account data under their own privacy terms.

5.2 Why Store Purchases Require a Linked Account

Store purchases require a game account linked to Google or Apple. A guest account depends on locally stored credentials and may become inaccessible if that local data is lost. Linking is therefore a purchase safeguard: it assigns the balance or entitlement to a recoverable account.

5.3 Pseudonymous Purchase Ledger

When in-app purchases are enabled, the game server keeps a pseudonymous purchase record to prevent duplicate redemption, process refunds or revocations and document the correct entitlement. It contains protected representations of the transaction and game-account identifiers and, where required, the store, product and product class, processing status, relevant purchase, credit and status timestamps, and technical markers for account deletion or permitted reassignment. It contains no card, bank or billing-address data and no permanently stored raw receipt.

The direct binding to an active game account is removed when that account is deleted. The remaining purchase record is pseudonymous rather than automatically anonymous and is retained only while it is necessary for duplicate-redemption prevention, refund or revocation handling, dispute resolution or applicable legal obligations.

The full evidentiary record and the technical protection against an impermissible first or repeated credit follow different retention rules. The exact periods for active, refunded and revoked transactions and the subsequent data minimisation are set out in Section 8.

6. Recipients and Service Providers

  • DigitalOcean, LLC: infrastructure and database hosting for the self-hosted game server. The active game data is hosted in an EU data centre.
  • Strato AG, Germany: hosting and technical delivery of this privacy policy and the account-deletion page, and email delivery for support and privacy enquiries sent to the contact address.
  • Google Ireland Ltd. and Google Commerce Ltd.: optional Google Sign-In and Google Play payment and purchase verification on Android.
  • Apple Distribution International Ltd.: optional Sign in with Apple and App Store payment and purchase verification on iOS.

Data may also be disclosed to the service providers' approved subprocessors, professional advisers or public authorities where this is necessary to provide the service, establish or defend legal claims, or comply with a legal obligation. Data is not disclosed to third parties for their advertising.

6.1 Processing Outside the EEA

DigitalOcean, Google and Apple are part of international groups. Depending on the service and support situation, data may be processed in or accessed from countries outside the European Economic Area, including the United States. An EU data-centre location does not by itself exclude such access. Where required, transfers are based on an adequacy decision such as the EU-US Data Privacy Framework for certified recipients, or on the European Commission's standard contractual clauses and supplementary safeguards. You can request further information about the safeguards using the contact details in Section 2.

7. Purposes and Legal Bases

  • Art. 6(1)(b) GDPR (performance of a contract or steps requested before entering into a contract): creating and authenticating your game account, optional account recovery through Google or Apple, local and cloud save, public profile, online play, social and tournament functions, account-bound documentation of the accepted Terms, and verifying, crediting once, restoring and contractually correcting in-app purchases.
  • Art. 6(1)(f) GDPR (legitimate interests): reliable and secure operation, technical logs, fault diagnosis, service and account security, name filtering, moderation, protection of players, rate limiting, documenting refunds and — where required for legal claims — acceptance of the Terms, and preventing cheating, abusive reports, fraud and duplicate purchase redemption. The interests are a fair and safe game, reliable operation and the establishment, exercise or defence of legal claims. For the purchase ledger, those interests are limited by using protected representations instead of plain identifiers, not retaining raw receipts, restricting access and applying the data-minimisation rules below.
  • Art. 6(1)(c) GDPR (legal obligation): processing required by a specifically applicable statutory retention, disclosure or cooperation duty or a binding request from a competent authority. Store statements and accounting documents are generally kept outside the operational purchase ledger; individual ledger data is retained for longer on this basis where it is itself subject to a legal obligation in the specific case.

7.1 Required and Optional Data

Account, save-game and connection data is required to provide the relevant online functions. Without it, those functions cannot be used or can be used only to a limited extent. Linking to Google or Apple is optional for normal play, but is required for account recovery across devices and before a store purchase. Friend, tournament, reporting and notification functions are optional. The free-text note in a player report is always optional.

8. Retention and Deletion

The periods below apply and are binding. Core account, save and profile data is kept while your game account exists. Other data follows these periods and criteria:

  • an unlinked guest account is marked for clean-up after 180 days without use recorded in the game profile and deleted within the following 30 days. A successful sign-in by the app to the game server restarts the period. The same applies to server-backed play that reads or saves the game state; offline-only use without a server connection and technical maintenance do not count. This applies only to a device-only level-1 guest account with no trophies, diamonds, store purchase recorded on the account, redeemed store transaction, purchased shop item, DLC or purchased character and no link to a recoverable external sign-in provider. The conditions are checked again immediately before deletion. A non-empty save without a reliable activity timestamp is not deleted. Deletion removes all remaining progress, including coins and XP. Because such an account has no contact address, an individual reminder will normally not be possible. Linking the account to Google or Apple removes it from this inactivity rule;
  • evidence of Terms acceptance: the identifiers of the accepted Terms and associated Privacy Policy revisions, document hashes, language and server-set acceptance time are kept for the life of the game account and deleted with it. The game server does not retain this account-bound record as a legal hold after account deletion. If, independently of that record, a statutory duty or the establishment, exercise or defence of legal claims requires documentation outside the operational game server in a specific case, that separate processing follows the general restriction and deletion rule at the end of this section;
  • game-server and infrastructure logs are rotated automatically and deleted after no more than 30 days. Where a necessary extract is assigned to a documented security incident, only that extract is retained until the incident is finally resolved and for a further 12 months; it is then deleted within 30 days. Website-hosting logs follow the periods stated in Section 4.5;
  • your own match and leaderboard data while the account exists. Public match history is limited to the latest 50 entries. Entries containing your name and account identifier may also remain in an opponent's limited history until they are replaced by newer matches or deleted with that opponent's account;
  • tournament records while needed to run and settle the tournament and handle objections. A tournament record may remain after account deletion until the tournament has ended. Seven days after the end it becomes eligible for deletion and is removed during the next technical tournament-maintenance pass;
  • reports and moderation records while a case is under review and for 12 months after the final moderation decision. Evidence required for an active restriction is retained for the duration of that restriction and for a further 12 months. Individual timestamps used for the rolling 30-day assessment of abusive reporting are removed on the next access after the window ends and no later than the monthly deletion run;
  • pseudonymous purchase records: the separation and deletion described below is implemented on the production server.
    • for a credited consumable or permanent item, the full pseudonymous record is kept until the end of the third calendar year following the first credit. A later restore of a permanent item does not restart this period;
    • following a refund, refund reversal, revocation or withdrawal, the full pseudonymous record is kept until the end of the third calendar year following the store's last final status decision.
    The account association, product, event timestamps and other evidence fields are deleted within 30 days after the applicable period ends. A separate small replay-control record prevents an impermissible first or repeated credit of a consumable purchase, in particular after a final refund, withdrawal or revocation. It is retained no later than the end of the tenth calendar year following the purchase date confirmed by the store and is then deleted within 30 days. A later store decision or legal dispute can extend the required evidence record, but not this ten-year period. After that date, the server rejects a credit solely because of the verified purchase age. For an active permanent item, only the entitlement core needed for restoration or permitted reassignment remains; it is reviewed annually and deleted within 30 days after both options have permanently ended. For a finally refunded, withdrawn or revoked permanent item, only a non-account-linked denial core remains while the same store transaction can technically be presented again and could create an entitlement without that core; it is also reviewed annually and deleted within 30 days after a renewed entitlement has become technically and permanently impossible; and
  • support and privacy requests: general support correspondence is deleted 12 months after the request is closed. The minimum record needed to document a privacy or account-deletion request is retained until the end of the third calendar year following closure of the request. Additional identity-verification material is deleted within 30 days after verification is complete.

A regular deletion period is suspended only for the fields covered by a documented legal dispute, authority request or specifically applicable statutory retention duty. Those fields are restricted from operational use and deleted within 30 days after the reason ends.

Deleted game data may remain in access-restricted production database backups for up to seven days, after which the backup cycle overwrites it. Backups are used only to restore the service after a technical incident, not to restore a deleted account in normal operation. If a backup must be restored, deletion requirements are applied again.

8.1 Deleting Your Account in the App

You can delete your account yourself: Menu → Settings → “Delete account”, confirmed by two safety prompts. A connection to the game server is required. This works for guest accounts and for accounts linked with Google or Apple. After successful server deletion, the app resets the active sign-in state and guest identifier stored on that device.

8.2 Deletion Without the App

If you no longer have the app, email contact@andreneubert.com. If available, include your friend code or game-account identifier. A display name can help with the search but is not unique. To protect accounts from unauthorised deletion, additional proof that the account belongs to you may be requested. Requests are handled without undue delay and normally within one month. Details are available on the account-deletion page.

8.3 What Is Deleted

Deletion removes the active game account, save game, inventory and balances, display name and public profile, current friends and social data, leaderboard entry, the account-bound evidence of Terms acceptance, account-provider links and data that is no longer required for an overriding purpose. On the device used for deletion, the app resets the active sign-in state and guest identifier. Device-specific settings and individual local progress copies may remain; you can remove all local app data through the operating-system settings or by uninstalling the app. Deleting Memoria Land does not delete your Google or Apple account or the purchase history held independently by the app store.

8.4 What May Remain

Pseudonymous purchase records, required moderation or legal records, tournament records, entries in an opponent's limited match history, server and security logs and temporary backup copies may remain according to the purposes and criteria above. The account-bound evidence of Terms acceptance on the game server is not included; it is deleted with the account. Active account restrictions end when the account is deleted. The remaining records remain subject to access restrictions and your applicable GDPR rights.

8.5 Note on Purchases

Diamonds are deleted with the game account because they form part of its balance; statutory rights and the store's refund rules remain unaffected. The permanent purchase “The Insect Meadow” remains recorded in your store account and can normally be unlocked once for a new game account after account deletion via “Restore purchases”, provided that the store records and technical evidence allow it.

9. Your Rights

Subject to the relevant legal requirements and exceptions, you have the right to:

  • access personal data processed about you (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16),
  • erasure (Art. 17),
  • restriction of processing (Art. 18),
  • data portability (Art. 20), and
  • object to processing based on legitimate interests (Art. 21).

You may withdraw consent at any time with effect for the future. Processing carried out before withdrawal remains lawful. Where processing is based on legitimate interests, you may object on grounds relating to your particular situation.

To exercise your rights, email contact@andreneubert.com. A friend code or game-account identifier helps match the request to the correct account. Additional information may be requested only where necessary to verify your identity; never send a password, full purchase receipt or payment details by email. Requests are answered without undue delay and generally within one month. Where the GDPR permits an extension because a request is complex or numerous, you will be informed of that extension and the reasons within the first month.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz); you may also contact the supervisory authority where you live or work or where the alleged infringement occurred.

10. Data Security

Transmission between the app and the publicly accessible game service is protected by TLS. Access to production systems and personal data is restricted to authorised persons. Purchase receipts are validated with Google or Apple before an item is credited. No method of transmission or storage can provide absolute security.

11. Changes to This Policy

This privacy policy will be updated if Memoria Land, the services used or the legal requirements change. The current version is available at this address; the date above shows its status.

12. Related Documents

  • Terms of Use for Memoria Land
  • Delete your account
  • Impressum
AN Andre Neubert
Row Empire Fintraq Roulette Tactics Memoria Land Contact Privacy Impressum

© Andre Neubert, 2026. All rights reserved.