Privacy policy
Last updated: 23 September 2026
Who is responsible?
This privacy policy covers the Otodama website and the Otodama app for iOS. The controller is SCHMUT/WEISS GmbH, Sieveringer Straße 9/13, 1190 Vienna, Austria. For privacy questions and requests, contact office@schmutweiss.com.
Otodama is available for iOS. An Android version is coming soon.
Visiting this website
Your browser sends technical information needed to deliver the website, including your IP address, requested URL, access time, browser information and response status. Infrastructure providers process this information to deliver the site, maintain security and investigate technical problems. The legal basis is our legitimate interest in a reliable and secure website under Article 6(1)(f) GDPR. Technical records are retained only for the operational or security purpose for which they are needed, subject to the hosting configuration and any legal preservation duties.
Cookies, fonts and website analytics
Optional website analytics is currently disabled. This website uses no tracking cookies and no localStorage or stored visitor or session identifiers for analytics. The URL determines the language. Work Sans and illustrations are served locally. Apple and other external services are contacted when you follow their links; their own privacy notices then apply.
Prepared optional website analytics (disabled)
We have prepared first-party counts of page views, entry views, download navigation clicks, Apple link clicks and the first successful card reveal on German and English pages. Activation requires a documented privacy decision and approved, completed notices. Using no cookies does not automatically exempt processing from privacy or consent requirements.
The prepared consent controls would count only after your voluntary choice. You could turn analytics off at any time under “Website analytics” in the footer. Your choice and the first known referral context last only in this browser document’s memory, including internal navigation. Reloading loses them; there is no persistent event queue. Withdrawal stops new events and pending deliveries; it does not retrospectively remove counts already sent.
The planned fields are limited to approved page paths without query strings, language, coarse viewport size, first known entry path, a restricted referral category, registered campaigns, link placement and notice version. Arbitrary referral domains and unregistered campaigns are discarded or grouped as “other”. A random identifier for each event prevents double counting during short retries; it does not identify a person or session. Names, full URLs, IP addresses and raw browser identifiers are not stored as analytics data. Infrastructure may still keep operational logs.
The prepared delivery path runs through our own server to the Otodama backend at Supabase. The backend configuration provides for aggregate counters for 24 months and event receipts for eight days. Specific recipient, location, contract and transfer details and the legal assessment must be completed and reviewed before activation. Counters are not unique visitors; store clicks are not installs. Recognized assistant referrals represent only observed referrals, not total visibility in AI services.
This preparation does not change the released app or its collection. Changes to app privacy notices and store disclosures must be coordinated with an actual app release.
Playing Otodama
You do not need to create an Otodama account. Player names, your language choice and onboarding preferences are stored locally on your device so the app can remember them. We do not send those player names to an Otodama server. You can remove players in the app; clearing the app’s data removes local preferences, subject to your device’s backup settings. The legal basis for the processing necessary to provide these features is Article 6(1)(b) GDPR.
Game rounds work offline. The app can still contact the subscription service when launched with an internet connection, even if you have not made a purchase. There is no advertising SDK or separate gameplay analytics SDK in the current app.
Purchases and RevenueCat
Apple processes App Store purchases and payment details. We use RevenueCat, Inc. to check receipts, manage access to Unlimited, restore purchases and understand subscription activity. RevenueCat processes an automatically generated app user identifier, purchase and subscription records, entitlement status and technical connection information. We do not supply player names or a custom account identifier to RevenueCat. We do not receive your full payment-card details.
Subscription verification and fulfilment are based on Article 6(1)(b) GDPR. Preventing abuse and understanding subscription performance are based on our legitimate interests under Article 6(1)(f) GDPR. Transaction records subject to legal retention duties are processed under Article 6(1)(c) GDPR. Subscription records are retained as necessary to provide and restore access and meet applicable record-keeping duties. RevenueCat may process data in the United States. Applicable processor arrangements and transfer safeguards must cover this processing. See RevenueCat’s privacy information for its processing practices.
When you contact us
If you email us, we process your email address, the contents of your message and any information you choose to share. We use this information to answer your request and provide support. Contract-related requests are processed under Article 6(1)(b) GDPR; other correspondence is processed under Article 6(1)(f) GDPR, based on our interest in answering inquiries. We retain correspondence while needed to resolve the request and, where applicable, to meet legal obligations or establish or defend legal claims.
Recipients and international processing
Recipients may include website infrastructure and email service providers, RevenueCat for subscription processing, Apple in connection with App Store purchases, and professional advisers or authorities where legally necessary. Processors may act on our instructions; Apple also processes data as an independent controller. Where data is transferred outside the EEA, the transfer must be covered by an applicable adequacy decision or appropriate safeguards such as the EU Standard Contractual Clauses. Contact us for information about the safeguards applicable to your data.
Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction of processing and data portability. You may object to processing based on legitimate interests on grounds relating to your situation. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing. We do not use personal data to make automated decisions with legal or similarly significant effects.
Send requests to office@schmutweiss.com. To locate an app purchase, we may need relevant purchase information; we will not ask you for your Apple password or full payment-card details. You can also complain to your local supervisory authority or the Austrian Data Protection Authority at dsb.gv.at.
Changes
We update this policy when the app, website or relevant processing changes. The date at the top identifies the version you are reading.