Data protection
This privacy policy explains what personal data MindMochi processes, why, and the rights you have under the General Data Protection Regulation (GDPR).
1. Controller
SparkLabs UG (haftungsbeschränkt)
Lessingstraße 4
23564 Lübeck
Germany
Represented by the Managing Director Phillip Bamberger
Email: [email protected]
2. Overview
MindMochi is a brain-training web app. You can play most games without an account. If you create an account, we store your progress so it syncs across your devices. We do not use advertising, and we do not use any third-party analytics or tracking tools. We never sell your data.
3. Hosting
The app is delivered by Cloudflare Pages (Cloudflare, Inc.), which acts as our hosting and content-delivery provider. When you load the site, your browser necessarily transmits technical data such as your IP address, the requested files, and your browser and device type to the delivering server so the page can be served to you. Legal basis: Art. 6 (1)(f) GDPR (our legitimate interest in delivering a secure, functioning website).
4. Account and authentication
Sign-up and login are handled by Firebase Authentication (Google). If you register with email and password, we process your email address and an encrypted authentication token. If you choose “Sign in with Google”, Google shares your name, email address and profile picture with the app. This processing is necessary to provide the account you request. Legal basis: Art. 6 (1)(b) GDPR (performance of a contract / provision of the service).
5. Game progress and usage data
When you are logged in, your training data — such as levels reached, best scores, games played, streaks, gems, quest progress and your reminder settings — is stored in Cloud Firestore (Google) linked to your account, so it is available across your devices. This data is processed to provide the core functionality of the app. Legal basis: Art. 6 (1)(b) GDPR. As a guest (not logged in), this progress is stored only locally on your device (see section 9) and is not transmitted to us.
6. Community board (Backlog)
If you post a suggestion or comment on the community feature board, the text you submit, an optional image you attach, and your account identity are stored in Cloud Firestore and shown to other users. Please do not include personal data you do not want to be visible. Legal basis: Art. 6 (1)(b) and (f) GDPR (operating the community feature you chose to use).
7. Payments and subscriptions
Paid plans (Pro) bought on the web are sold through our reseller Paddle.com Market Ltd (United Kingdom), which acts as the Merchant of Record. You enter your payment details directly with Paddle — we never receive or store your card or bank details. Paddle processes your name, email address, billing country, payment details and transaction data for the payment, invoicing and its tax obligations, under its own privacy policy.
Paddle passes back to us only what is needed to unlock your subscription: your account identifier, which plan you hold, its status and renewal date, and a customer and subscription reference. We store that in Cloud Firestore against your account. Legal basis: Art. 6 (1)(b) GDPR (performance of the subscription contract) and Art. 6 (1)(c) GDPR (retention obligations under tax and commercial law). Purchases made inside the iOS or Android app are processed by Apple or Google instead, under their own privacy policies; there too we receive only subscription status, never payment details. To match such a purchase to your account we use RevenueCat, Inc. (USA), which receives your account identifier and what you bought — see section 8.
8. Third-party services
We rely on the following processors and services, and only the data necessary for each function is transmitted:
• Google (Firebase Authentication & Cloud Firestore), Google Ireland Ltd. / Google LLC — account and data storage. Data may be processed on servers in the USA; transfers are covered by the EU Standard Contractual Clauses and the EU–US Data Privacy Framework.
• Google (Firebase Crashlytics), Google Ireland Ltd. / Google LLC — crash and error reporting in the mobile app only; it is not used on the website. If the app crashes or hits an error, a report is sent containing the error message and stack trace, your device model and operating system version, the app version, and a Crashlytics installation identifier. If you are signed in, your MindMochi user ID is attached so that repeated reports can be recognised as coming from one account. No game content, message text, email address or name is transmitted. Data may be processed on servers in the USA; transfers are covered by the EU Standard Contractual Clauses and the EU–US Data Privacy Framework. Legal basis: Art. 6 (1)(f) GDPR (our legitimate interest in finding and fixing faults that make the app unusable).
• Cloudflare, Inc. — website hosting and content delivery.
• Google Fonts — the “Nunito” font is loaded from Google servers (fonts.gstatic.com); this transmits your IP address to Google. Legal basis: Art. 6 (1)(f) GDPR (consistent presentation of the site).
• Datamuse (api.datamuse.com) — in the word games, a word you enter that is not in the dictionary shipped with the app is checked against this word API; only that single word and your IP address are transmitted, and only in that case. Legal basis: Art. 6 (1)(f) GDPR (accepting valid words the built-in list does not contain).
• Paddle.com Market Ltd (United Kingdom) — payment processing and merchant of record for web subscriptions (see section 7). Transfers to the United Kingdom take place on the basis of the European Commission’s adequacy decision for the UK or, where applicable, the EU Standard Contractual Clauses.
• RevenueCat, Inc. (USA) — subscription management for purchases made inside the mobile app. It receives your account identifier, which product you bought and its status, so that a purchase made in the App Store or Google Play unlocks the right account. It never receives your payment details — those stay with Apple or Google. Transfers to the USA are covered by the EU Standard Contractual Clauses.
9. Local storage on your device
The app stores data in your browser’s local storage (a “localStorage” mechanism, not advertising cookies) to remember your game progress, preferences and dismissed prompts. This data stays on your device, is essential to how the app works, and is not used for tracking. You can clear it at any time via your browser settings.
10. Notifications
If you enable daily reminders, the app asks your browser or device for permission to show notifications and stores your reminder preferences with your account. You can withdraw this permission at any time in your browser or system settings. Legal basis: Art. 6 (1)(a) GDPR (your consent).
iPhone app waiting list. If you leave your email address on our “coming soon” page for the iPhone app, we store that address and the time you submitted it in Cloud Firestore (Google), and use it for one purpose only: to send you a single email when the app is available on the App Store. That email is sent through our email service provider Resend, Inc. (USA); transfers to the USA are covered by the EU Standard Contractual Clauses. We delete the list once that email has been sent. You can withdraw at any time by writing to us at the email address in section 1, and we will remove your address. Legal basis: Art. 6 (1)(a) GDPR (your consent).
11. Data retention
We keep account and progress data for as long as your account exists. When you delete your account (see section 12), the associated personal data is deleted. Locally stored data remains on your device until you clear it. Invoices and transaction records for paid subscriptions are kept by our reseller and by us for as long as tax and commercial law requires (in Germany, generally up to ten years), independently of account deletion.
12. Deleting your account and data
You can delete your account at any time from your profile within the app, which removes your personal data. Alternatively, you can contact us at the email address above and we will delete it for you.
13. Your rights
Under the GDPR you have the right to access your data (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20), and to object to processing (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future. To exercise any of these rights, contact us at [email protected].
14. Right to complain
You have the right to lodge a complaint with a data protection supervisory authority. In our case the competent authority is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany.
15. Age limit
You must be at least 16 years old to create an account, in line with the age of consent for data processing under Art. 8 GDPR as implemented in Germany (§ 3 (2) BDSG). Younger children may use the app under an account held and supervised by a parent or guardian. We do not knowingly create accounts for children under 16; if we learn that we have, we will delete the account and its data.
Last updated: October 2026