Privacy Policy
Your privacy matters to us. This page explains what data we process and what rights you have.
This privacy policy explains which personal data we process when you use the TipsyTales app (Android app and web app at app.tipsytales.de) and the website tipsytales.de. It applies to all language versions of the app. This policy is also available in German: Datenschutzerklärung. In case of discrepancies, the German version prevails.
1. Controller
Britz & Weiland GbR, represented by Sebastian Britz and Joshua Weiland
Nachtigallenstraße 26, 56751 Polch, Germany
Email: Kontakt@TipsyTales.de
We have not appointed a data protection officer because we are not legally required to. Please send privacy requests to the email address above.
2. Age
The app is intended exclusively for people aged 18 and over. We do not knowingly process data of minors. If we learn that an account belongs to a minor, we delete it.
3. Using the app without an account
You can use TipsyTales without registering. In that case:
- Local storage on your device: language, theme, onboarding status, progress (coins, streaks, unlocks), your list of bookmarked packs, notification setting and a randomly generated installation ID. This stays on your device and – except for the push data described in section 6 – is not sent to us. Legal basis: Section 25(2) no. 2 TDDDG (strictly necessary) and Art. 6(1)(b) GDPR.
- Loading content: To display packs and check the app version, the app retrieves data from our database (Google Cloud Firestore, location: EU/eur3). Google technically receives your IP address in the process. Legal basis: Art. 6(1)(b) and (f) GDPR (providing the app).
- Anonymous usage statistics: We count, without any user or device ID, how often e.g. a round is finished, a pack is chosen or a card is rated (daily counters). These counters do not identify individuals. Legal basis: Art. 6(1)(f) GDPR (improving the app).
- Crash and error reports: On errors the app sends technical information via Firebase Crashlytics (Google), such as the error message, device model, OS version, time and a Firebase installation ID. Legal basis: Art. 6(1)(f) GDPR (stability and security).
4. Optional account (sign-in with Google or Apple)
For purchases and cross-device sync you can sign in with your Google or Apple account. Sign-in runs through Firebase Authentication (Google). We receive a user ID (UID), your email address and your name (for Apple possibly an anonymised relay address). We never receive your password.
In our database (Firestore, EU) we store for your account: email address, first and last name, premium and purchase status (unlocked packs), coins, unlocks and chosen avatars/cards. Purpose: providing the account, restoring purchases, syncing. Legal basis: Art. 6(1)(b) GDPR. Retention: until you delete your account.
You can delete your account at any time in the app under Settings → Delete account or by email. Your account and your record in our database are then deleted. Statutory retention duties for purchase records remain unaffected (section 5).
5. Purchases and subscriptions
Purchases (individual packs, bundle, premium subscription) are processed through Google Play in the Android app. We do not receive payment data (e.g. card numbers); the store operator processes it as an independent controller under its own privacy policy. In the web app, payment is made via RevenueCat Web Billing and the payment provider integrated there.
To manage purchases, subscriptions and entitlements we use RevenueCat, Inc. (USA) as a processor. RevenueCat receives purchase information, a user identifier (your UID or an anonymous ID) and – when you buy – your email address and name. Legal basis: Art. 6(1)(b) GDPR; for retention of accounting records Art. 6(1)(c) GDPR in conjunction with Sections 147 AO and 257 HGB (6 and 10 years). Buying content requires an account.
6. Push notifications
We only send notifications if you allow them in the system dialog. To send them we store (via Firebase Cloud Messaging and Firestore) your push token, the platform (Android/iOS), your premium status, your list of bookmarked packs, the time of your last activity, your notification setting and the random installation ID. This data is not linked to your account. We use it for reminders after longer inactivity and for notices about new packs and offers on packs you bookmarked.
Legal basis: your consent, Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw it at any time in the app settings or your device settings. Push tokens that become invalid are removed automatically. Sending runs through Google Cloud Functions; processing in the USA cannot be ruled out (see section 9).
7. Other features
- Text to speech: runs locally through your device’s speech synthesis; no text is sent to us.
- Sharing and inviting: you use your operating system’s share dialog; we do not learn who you share with.
- Rating prompt: provided by Google Play or Apple.
- Network status: the app checks locally whether an internet connection exists.
8. Website tipsytales.de
- Hosting and server log files: The website is hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany (data processing agreement in place). When you visit, data such as IP address, date and time, requested page, referrer and browser identifier are processed in log files and stored only as long as required for secure operation. Legal basis: Art. 6(1)(f) GDPR (secure and stable operation).
- No cookies, no tracking: The website sets no cookies and uses no analytics or advertising services; fonts and libraries are served locally. Hence there is no cookie banner.
- Contact form and email: Your details (name, email address, subject, message) are sent to us via STRATO’s mail server and stored to handle your request. Legal basis: Art. 6(1)(b) or (f) GDPR. We delete them once your request is completed unless retention duties apply (e.g. 6 years for business letters).
- External links: Links to Google Play and Instagram are plain links; data is only transferred to the respective provider when you click them.
- Instagram profile: We run a profile on Instagram (Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland). We are jointly responsible with Meta for processing related to page insights; otherwise Meta’s privacy policy applies. Legal basis: Art. 6(1)(f) GDPR.
9. Recipients and transfers to third countries
Recipients of your data are our service providers: Google (Firebase: Authentication, Firestore, Cloud Messaging, Cloud Functions, Crashlytics), RevenueCat, STRATO and the app store operators. Authorities only receive data where legally required.
Our database is located in the EU. For Google (Firebase Authentication, Cloud Functions, Crashlytics) processing in the USA may occur; the Google entity is certified under the EU-US Data Privacy Framework (adequacy decision of the European Commission, Art. 45 GDPR; listing), and standard contractual clauses additionally apply. With RevenueCat, Inc. (USA) we have concluded a data processing agreement based on the EU standard contractual clauses (Art. 46(2)(c) GDPR). You can request a copy.
10. Retention
We store data only as long as the purpose requires: local data until you uninstall the app; account data until you delete the account; push data until you withdraw consent or the token becomes invalid; purchase records according to statutory retention periods; enquiries until they are handled; anonymous statistics indefinitely (no personal reference).
11. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future (Art. 7(3)). Please contact Kontakt@TipsyTales.de.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the state of your habitual residence, place of work or place of the alleged infringement. Our competent authority is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz, Germany.
You are not obliged to provide data; without the data mentioned, however, some features (account, purchases, push) cannot be used. There is no automated decision-making, including profiling.
12. Notes for users outside the EU
- United Kingdom: Your rights under the UK GDPR apply; you may complain to the Information Commissioner’s Office (ico.org.uk).
- Switzerland: Your rights under the revised Federal Act on Data Protection apply; you may complain to the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
- USA: We do not sell personal data and do not share it for cross-context behavioural advertising. Please send requests under your state’s law (access, deletion, correction) to Kontakt@TipsyTales.de; we handle them without discrimination.
13. Security and changes
Data is transmitted encrypted (TLS). We update this policy when our processing or the law changes; the current version on this page applies.