Draft status: 5 August 2026

Privacy Policy

This policy covers the InfiniteGame landing page and the InfiniteGame mobile application. It reflects the inspected source code and configuration; open regional details are identified instead of being invented.

1. Controller and privacy contact

Controller: Xinix UG (haftungsbeschränkt), Hirschstr. 40/1, 74078 Heilbronn, Germany. Telephone: +49 176 83417498. Email and privacy requests: xinix.ug@gmail.com. Data protection officer: Franz Graaf, Xinix UG (haftungsbeschränkt), using the address and contact details stated above.

2. Landing page delivery

The static website is intended to be delivered through Firebase Hosting. To deliver and secure requests, the hosting/CDN provider may process IP address, request time, requested URL or file, HTTP status, referrer, user-agent/browser information and security or operational log data. The purpose is reliable delivery, abuse prevention and troubleshooting; the intended legal basis is the controller’s legitimate interest under Art. 6(1)(f) GDPR.

  • Recipient/service provider: Google/Firebase and its infrastructure providers; the exact contracting entity and applicable data-processing terms must be verified in the project account.
  • Processing regions and log retention depend on the provider configuration. No exact retention period was verified and the operator must document the active setting.
  • International access or transfers cannot be excluded. The operator must verify the applicable adequacy basis or safeguards, including contractual safeguards where required.

3. Landing page storage, links and contact

The landing page adds no analytics, advertising, heatmaps, embedded third-party media, cookies, localStorage or similar non-essential storage. Language is selected through /de/ and /en/ URLs and is not persisted in the browser. External links transfer data only after you follow them. An email link opens your own mail application; the email and its metadata are then processed to answer the request under Art. 6(1)(b) or (f) GDPR and retained as long as needed for the request and legal obligations.

4. Accounts and sign-in

The app uses Firebase Authentication for email/password accounts and offers Google and Apple sign-in. Processed data can include Firebase user ID, email address, sign-in provider, provider profile data made available during sign-in, authentication tokens, account state and authentication timestamps/logs. This is required to create and protect the account and provide the game (Art. 6(1)(b) GDPR); provider sign-in is optional compared with email sign-in.

  • Recipients include Firebase Authentication and, when selected, Google or Apple as the sign-in provider.
  • Authentication credentials and logs follow provider and account retention settings; exact periods were not verified.
  • The app implements sign-out, password reset and email/password changes, but no account-deletion flow was found. Firestore rules deny client deletion of user documents. Until this is fixed, deletion and correction requests must be sent to the privacy contact.

5. Profile, gameplay and progression

Cloud Firestore stores the player ID, chosen username, creation timestamp, score, avatar-part IDs, visibility and movement radii, base level and location, inventory capacity, inventory entries and quantities, one-off items, crafting slots, crafting start/duration/result data, upgrades, marketplace limits and offers, marketplace transaction timestamps and related game-state timestamps. These data are required to save and synchronise gameplay and progression (Art. 6(1)(b) GDPR).

  • Inventory data can include item identifiers, titles, image URLs, value, rarity-related configuration and upgrade effects.
  • Crafting uses known recipes, ingredients, durations and calculated/randomised game results. These decisions affect game rewards only and are not legal or similarly significant automated decisions.
  • Retention is tied to the account and game state; no automatic deletion schedule was found.

6. Precise location

The app requests precise and approximate location permission and reads location while the game screen is active. iOS is configured not to allow background updates, and the Android code contains no background-location permission or service. The stream is configured for best navigation accuracy, a 3 metre movement filter and, on Android, a 2 second interval. The current position is uploaded at startup and then when at least 30 seconds have passed or movement of at least 15 metres is detected.

  • Exact current coordinates are stored as latPlayer/lngPlayer and overwritten rather than appended as a user location history. Exact base coordinates persist as latBase/lngBase.
  • Location is used for the visible map, nearby points of interest, random finds, map-area requests, the base, nearby scoreboards and local marketplace distance.
  • If permission or location services are unavailable, the app displays an availability gate and cannot provide the location-based game screen normally.
  • The intended legal basis for core location gameplay is Art. 6(1)(b) GDPR after the user grants operating-system permission. The operator must confirm whether consent under Art. 6(1)(a) is additionally relied upon and document withdrawal handling.

7. Location disclosure and marketplace

A significant current limitation is that Firestore rules allow every signed-in player to read all user documents, including exact current and base coordinates. The scoreboard UI shows usernames, scores, rank and calculated distance, but another authenticated client can technically retrieve the underlying coordinates. This can reveal a home, workplace, routine or current position.

  • Creating a marketplace offer copies the seller’s exact current latitude and longitude, username, user ID, item details, quantity, price and creation time into a marketplace document.
  • All signed-in players can read marketplace documents and therefore their exact coordinates. The UI presents local distance and global/local listings.
  • Sold and cancelled offers keep status, timestamps and, for sold offers, buyer ID. Rules deny client deletion and no expiry or server cleanup was found.
  • The operator should round/geohash or server-filter coordinates, return only coarse distance/area, expire coordinates when an offer ends, reduce rules exposure and define a deletion schedule before public launch.

8. Maps, map requests and item images

Native release builds on Android and iOS enable the Google Maps SDK. Map tile or SDK requests can disclose IP address, device/app information and the requested map area to Google; depending on SDK behaviour this can relate to precise location. Separately, if no internal map chunk covers an area, the app writes an exact-coordinate REQUESTMAP record with Firebase user ID, timestamp and completion status to Firestore. All signed-in players can currently read these records.

  • Map chunks and points of interest are loaded from Firestore.
  • Item, point-of-interest and base graphics can be loaded from URLs configured in Firestore. The actual image hosts were not identifiable from source code and must be inventoried by the operator.
  • No runtime OpenStreetMap, routing, Places or geocoding integration was found.

9. Marketplace, social visibility and transactions

Player-visible information includes the chosen username, score, rank and distance in scoreboards, plus marketplace username, item name/image, quantity, price, distance and listing status. Email addresses and authentication-provider details are not intentionally displayed in these screens. Marketplace purchase functions in europe-west1 update buyer and seller score, inventory, offer history, buyer ID and rolling transaction timestamps. No free-form chat, user posts or uploaded profile images were found.

10. Local device data and diagnostics

Shared preferences store music playback preference and locally generated random-point state. These remain on the device unless removed with app data and are not designed to identify the player to others. Firebase and network services inevitably receive IP address and standard connection/security data. Firebase installation identifiers or SDK security telemetry may be generated by core SDK operation, but no dedicated Analytics, Crashlytics, Performance Monitoring, App Check, device-info, root detection, anti-cheat or fraud SDK was initialised in the inspected code.

11. Notifications, advertising, purchases and AI

No Firebase Cloud Messaging, push token handling, notification SDK, advertising SDK, advertising identifier, consent-management SDK, in-app purchase/billing integration or runtime AI service was found. The app does not receive payment-card data in the inspected build. These statements must be reviewed when functionality changes.

12. Firebase regions, transfers and retention

Verified services are Firebase Authentication, Cloud Firestore and callable Cloud Functions. A Firebase Storage bucket is configured, but its rules deny all access and no client Storage path is used. Functions are configured for europe-west1. The Firestore database location, Authentication processing location, hosting log region and Google contracting entity were not verifiable from the repository. It would therefore be inaccurate to claim that all data remains in Germany or the EU.

  • Retention generally follows account/game necessity, provider logs and legal duties; concrete schedules are still required.
  • Possible third-country transfers and safeguards must be confirmed from the active Firebase/Google account agreements and data-location configuration.

13. Your rights

Subject to the legal requirements, you may request access, rectification, erasure, restriction, data portability and object to processing based on legitimate interests. You may withdraw consent for the future where processing relies on consent. You may also lodge a complaint with a competent data-protection supervisory authority. Contact: xinix.ug@gmail.com. Identity verification may be necessary to protect the account.

14. Children, automated decisions and changes

The intended minimum age, store age rating, target audience and any parental-consent process were not found and must be decided before launch. The app does not collect an age in the inspected code. No personalised advertising or legally significant profiling was found. This policy will be updated when services, data flows, retention rules or legal details change; the current version date is shown above.