IQ Mogged — Privacy Policy
Last updated: 2026-08-29
App: IQ Mogged (iOS / Android)
1. Who is responsible (Controller)
The controller for your data under the GDPR is:
- The Lucas Agency GmbH
- Am Kabellager 11, 51063 Köln, Germany
- Represented by: Maxim David Dambietz
- Register: Amtsgericht Köln, HRB 127141
- Contact: privacy@socialix.ai
If you have questions about this policy or your data, contact us at privacy@socialix.ai.
2. Summary
IQ Mogged is a daily logic-puzzle game. You can play offline without giving us any personal details. If you use the online features (daily leaderboards, friends), we store a minimal profile and your daily solve times so you can compete with friends. The game is free to play; there are three optional one-time in-app purchases and never a subscription — one unlocks every level, one removes the ads, and one is both together. Only the last two remove the ads. We never ask for your real name or email address to play — they are only involved if you choose to use Sign in with Apple, either to create your account or to secure an existing one (§3(h)).
Since version 2.0 the free game is funded by advertising: a full-screen ad appears after every third level you finish. The daily puzzles stay ad-free. Separately from that, you can choose to watch a short ad in exchange for an extra life — that one only ever appears when you tap it, and it stays available even if you have paid to remove the ads. On iOS we ask, through Apple's tracking prompt, whether ads may be matched to your interests: if you decline, or before you answer, the ads are non-personalised and nothing else changes. Android has no such prompt — there the decision rests on Google's consent dialog and is applied by Google's advertising SDK. Details in §3(j). We do not sell your data, and your puzzle results, times and friends are never shared with advertisers.
3. What we collect and why
a) Account / identity data
When you first open the app we create an anonymous account (a random user ID) via our backend provider (Supabase). To use the social features you choose:
- a username (a unique handle, e.g.
@lucas), - optionally a display name (shown to friends),
- a system-generated friend code.
We store these plus the account creation date. Playing does not require an email address, a phone number, or your real name, and we never ask for them here (please don't type sensitive information into your display name either). If you choose to secure your account with Sign in with Apple, an email address and optionally your Apple name are involved — see §3(h).
Purpose: to give you an identity others can add and compete with. Legal basis (GDPR Art. 6(1)(b)): performance of the service you requested.
b) Social / friends data
If you add friends: your friendship connections and pending friend requests (who sent/received, status, timestamps).
Purpose: to run the friends and request features. Legal basis: Art. 6(1)(b) (service), and for others adding you, our legitimate interest in providing a social game (Art. 6(1)(f)).
c) Gameplay data (online)
Two kinds of solve time are stored on our servers, each linked to your account:
- Daily puzzles: your solve time for that day and game, which powers the per-game daily leaderboard shown to you and your friends.
- Level packs: when you solve a level, we store which game and level number it was and how long you took, so you and your friends can compare times on the same level. We keep one row per level and, in it, your best time: replaying a level updates that row if you were faster and changes nothing if you were not. We also store the major version of the app that uploaded the result (e.g.
2) — no more than that single number. When a level pack is rebuilt, a level number stops referring to the same puzzle, so this is what lets us keep results uploaded by outdated app versions out of the leaderboards instead of ranking them against times set on a different board.
Public leaderboards (optional, off by default). By default the leaderboards above show only you and your confirmed friends. You can switch on public ranking in the app; while it is on, any signed-in player can see the following.
In the public leaderboards:
- your display name,
- your solve time for a given daily puzzle,
- your number of solved levels per game, together with the moment you last solved one in that game,
- your total number of solved levels across all games, together with the number of games you have solved anything in.
In your public profile, which any of those players can open by tapping your row:
- your display name again,
- your number of solved levels per game,
- the days on which you solved a daily puzzle — one date-and-game entry per solve, for your whole history. The app turns that list into the streaks and the badges it shows on the profile; it contains no times.
Your username, your friend list, your e-mail address and your individual level times are not part of any of it. The setting is off until you turn it on, and switching it back off removes you from the public leaderboards and from the public profile again.
Purpose: leaderboards and streaks; with public ranking on, comparison beyond your friend circle. Legal basis (GDPR Art. 6(1)(b)): performance of the service you requested. For public ranking, your consent (Art. 6(1)(a)), which you can withdraw at any time via the same setting.
d) Data stored only on your device
Your in-progress puzzle state, streaks, app settings, and which levels you have unlocked are stored locally on your device and are not sent to us. (Your solve times are uploaded — see (c).) Your login session token is stored securely on your device (iOS Keychain / Android Keystore). Uninstalling the app removes this local data.
e) Notifications (from version 2.0)
Notifications are optional. We ask inside the app first, whether you would like to be reminded at all; the iOS system dialog only appears if you agree there. If you decline, nothing is stored and nothing is sent to us.
If you agree, three things are involved:
- Your streak reminder — scheduled and shown by your device. The reminder itself never travels to us, and we do not learn whether you acted on it. One detail does reach us, together with the push identifier below: **which puzzle day a reminder is currently pending for**. We need it so we do not send you a server notification on a day your phone is already going to remind you — one reminder a day, not two through different channels. It is stored against your account id and overwritten as the reminder moves on.
- The device's push identifier — an identifier issued by the operating system and Expo (a push token), linked to your account id. Stored alongside it: the platform (iOS/Android), your device language, the pending reminder day described above, and when the entry was last updated. It is what allows a notification to reach your device at all — for example, the note that a friend has overtaken you on a daily. Delivery runs through Expo's push service and from there through Apple or Google.
- The notification queue — when a friend overtakes you on a daily, we write one entry recording who overtook whom, in which game, on which puzzle day, and what happened to the notification afterwards (sent, or skipped and why). It is what makes the cap of one such notification per day possible, and it is how we can tell a delivery problem from a silent one. Entries are deleted together with your account.
The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time by turning Profile → Reminders off. That deletes the scheduled reminder on the device and removes the stored push identifier from our server. It is also deleted when you delete your account. We never send advertising through this channel.
f) Technical data
Our backend provider processes technical data needed to deliver the service (e.g. IP address at the moment of a request, for security and rate-limiting). We do not build advertising or tracking profiles from it.
g) Purchase data
The app offers three one-time purchases: unlocking every level, removing the ads, and a bundle of both. All three are non-consumable and none is a subscription, and they are independent of one another — unlocking the levels does not remove the ads, and removing the ads does not unlock the levels. The payment itself is handled by Apple or Google; we never see your card details. Our purchases provider (RevenueCat) records that a purchase was made and the resulting entitlements (levels unlocked: yes/no; ad-free: yes/no), linked to your account's user ID so that a payment can be matched to an account if you contact us about it. RevenueCat does not receive your username, display name, email address, or friends data. On your device we store only a local flag for what you own; we do not keep a purchase record on our own servers.
Purpose: to unlock the paid content and restore your purchase after a reinstall. Legal basis (GDPR Art. 6(1)(b)): performance of the purchase contract.
h) Sign in with Apple or Google (optional)
Your account is anonymous by default, which means it lives on that one device: reinstall the app or switch phones and your streaks and friends are gone. Sign in with Apple prevents that, and you can use it in two ways:
- to create your account, offered as the first action on the very first screen, and
- to secure an account you already started ("Save progress"), or to restore it later on a new device with the same provider account.
Exactly one provider is offered per platform: Sign in with Apple on iOS, Sign in with Google on Android. You are never asked to choose between them.
This is entirely optional in both cases — the first screen also offers a plain form, and everything in the app works without ever signing in.
When you do, Apple sends us:
- a stable user identifier for your Apple ID (specific to this app),
- your email address — if you choose Hide My Email, this is an Apple relay address (
…@privaterelay.appleid.com) and we never see your real one, - optionally your name, which we use as your display name unless you change it. Apple only provides this on the very first sign-in.
On Android, Google takes Apple's place and sends us the same three things: a stable user identifier for your Google account, your email address, and optionally your name. Google offers no relay-address equivalent, so the address is your real Google address. Unlike Apple, Google provides the name and email on every sign-in, not only the first.
We store the identifier and email with your account at our backend provider (Supabase) purely so we can recognise you again. We do not use your email address for marketing and we never send you email. This is the same data either way — only the provider differs.
Purpose: creating your account, and recovering it after a reinstall or device change. Legal basis (GDPR Art. 6(1)(b)): performance of the service you requested. Withdrawal: you can stop the linkage at any time — in your Apple ID settings, or under Third-party apps with account access in your Google account — and you can delete the account entirely in the app (Profile → Delete account), or via our account deletion page.
i) Reports and blocks
If you block another player, we store who blocked whom. If you report someone, we store the reported account, the reason you selected, and the time — plus a copy of the username and display name as they were at that moment, so the report still makes sense if the account is later renamed or deleted. Only we can read this; it is never shown to other players.
Purpose: to keep blocks working and to act on abuse (Apple requires both for apps with user-generated content). Legal basis: Art. 6(1)(b) (service) and Art. 6(1)(f) (our legitimate interest in a safe service and in documenting abuse reports).
j) Advertising (from version 2.0)
There are two ad formats, and the difference matters for your data.
Full-screen ads, shown to you. If you have not bought "remove ads" or the bundle, the app shows a full-screen ad after every third level you finish. Buying "unlock every level" on its own does not stop these. The daily puzzles are always ad-free, and no ad ever interrupts a puzzle you are solving. If you own ad-freedom, none of these is ever requested or shown, and nothing to do with advertising is started for you unprompted — no ad request leaves your device unless you ask for one, as described next.
Rewarded ads, only when you ask for one. Where the app offers you an extra life, you may tap to watch a short ad in exchange for it. It is never shown on its own, it never interrupts anything, and nothing is credited unless the ad was watched through to the end. It is available to every player, including those who bought "remove ads" or the bundle: paying removes the ads we would put in front of you, not the ones you choose to watch. If you do tap it, the advertising SDK is started at that moment and the consent dialog described below is shown first — this is the one case in which an ad request leaves the device of a paying player. If you never tap it, nothing is started.
The ads are delivered through Google AdMob. To deliver them, Google's SDK processes a device identifier and technical data about your device and about the ad itself (which ad was shown, whether you tapped or dismissed it, error and performance data). It uses this to deliver ads, to limit how often you see the same one, and to detect invalid traffic and fraud.
AdMob is the mediation platform, not the only source of ads. For each ad slot it collects bids from other ad networks and lets the highest one serve. Besides Google, one further network is currently integrated: Unity Ads (Unity Technologies). When Unity wins a bid, its SDK also processes a device identifier and technical data about your device and the ad in order to deliver it, for the same purposes. If another network is added, it will be named here before the app version carrying it is released.
The limits below apply to every one of these sources alike, whichever network ends up serving a given ad: how a request is marked follows the rules set out next, and if you own ad-freedom no advertising SDK starts at all unless you tap a rewarded ad yourself — not Google's and none of the mediated ones.
The limits we set in the app:
- On iOS we ask before anything is personalised. The app shows Apple's App Tracking Transparency prompt. Only if you allow it may the advertising identifier (IDFA) be used, and only then are ads selected on the basis of your interests.
- On iOS, if you decline, the ads stay non-personalised. The request is then marked "non-personalised ads only", iOS withholds the advertising identifier from the SDK, and nothing about the game changes. The same applies before you have answered.
- **On Android there is no tracking prompt, and personalisation follows the consent dialog instead.** Android has no App Tracking Transparency, so the app marks the request neither way; whether an ad is personalised is decided by Google's advertising SDK itself, on the basis of the consent you gave or refused in Google's consent dialog described below. Refuse there and no ad is requested at all.
- Nothing depends on your answer. No feature, no content and no price changes either way, and we offer you nothing in return for allowing it.
- You can change your mind at any time in iOS Settings → Privacy & Security → Tracking.
Your choice (EEA/UK): before the first ad request we show you Google's consent dialog (Google User Messaging Platform). If you decline, or if the dialog cannot be shown, the app requests no ads at all. You can change your decision later via the privacy options in the dialog where offered. You can also remove the full-screen ads permanently with the one-time "remove ads" purchase or the bundle; the voluntary rewarded ad stays available to you afterwards if you want it.
Purpose: to fund the free version of the game. Legal basis: your consent (GDPR Art. 6(1)(a)) where consent is collected via the dialog above; storage on your device is based on your consent under §25(1) TTDSG.
4. What we do NOT do
- No personalised advertising unless you allowed it. On iOS the permission is Apple's App Tracking Transparency prompt: decline it, or leave it unanswered, and the ads are non-personalised. On Android there is no such prompt — the decision rests on Google's consent dialog and is applied by Google's advertising SDK. See §3(j).
- No selling of your data, and no sharing of your puzzle results, times or friends list with any advertiser. What the ad SDK receives is the advertising identifier and ad-interaction data, never your game content.
- No third-party analytics or crash-reporting SDK of our own (as of this version — see §9).
- No sale or sharing of personal data for others' marketing.
- No collection of special-category data.
5. Who we share data with (processors)
We use trusted service providers who process data on our behalf under data-processing agreements:
- Supabase — backend hosting, database, and authentication. Region: EU (Ireland), AWS
eu-west-1. See Supabase's privacy terms. - Apple / Google — app distribution and payment processing for in-app purchases. Your payment details go to the store, never to us. If you use Sign in with Apple, Apple also acts as the identity provider and passes us the data listed in §3(h).
- RevenueCat — manages the in-app purchases and your resulting entitlements (levels unlocked, ad-free). It processes your account's user ID (see §3(g)), your purchase/receipt data, and basic device/technical data needed to validate and restore purchases. It receives that user ID but not your username, display name, email address, or friends data. US-based; safeguarded by Standard Contractual Clauses and a data-processing agreement.
- Expo (Expo Push Service) — delivers notifications, if you have turned them on (§3(e)). It processes only your device's push identifier and the text of the notification itself, and passes both on to Apple or Google. Your username, display name and friends data are not sent — though a friend's display name may appear inside the text of a notification. US-based; transfers are safeguarded by Standard Contractual Clauses. If you have not turned notifications on, no data reaches Expo at all.
- Google (AdMob) — serves the ads described in §3(j) and receives the data listed there. Unlike the providers above, Google also uses that data for its own purposes (ad delivery across its network, fraud prevention, reporting), so it is not simply acting on our behalf. Google is US-based; transfers are safeguarded by Standard Contractual Clauses. If you own ad-freedom, no data reaches Google unless you tap a rewarded ad yourself: nothing to do with advertising is started for you unprompted (§3(j)).
- Unity Technologies (Unity Ads) — an ad network integrated through AdMob's mediation (§3(j)). It receives the data listed there only when it wins the bid for a given ad slot and its ad is actually shown. Like Google, Unity also uses that data for its own purposes (delivery across its network, fraud prevention, reporting), so it is not simply acting on our behalf. US-based; transfers are safeguarded by Standard Contractual Clauses. The same applies here: if you own ad-freedom, no data reaches Unity unless you tap a rewarded ad yourself.
We disclose data only if required by law.
6. International transfers
Your account, social, and gameplay data is stored inside the EEA, in the EU (Ireland) region. Purchase and entitlement data handled by RevenueCat and Apple is processed on US infrastructure. Some of our providers are US-based companies whose staff may access data from outside the EEA for support or maintenance; such access is safeguarded by Standard Contractual Clauses and the providers' data-processing agreements.
7. How long we keep it
- Account, social, and gameplay data: for as long as your account exists.
- When you delete your account in the app (Profile → Delete account), your account and all associated rows are permanently deleted from our database — among them your profile, username, friendships, friend requests, daily results, level results, any push identifiers, the notification-queue entries described in §3(e), and the blocks and reports described in §3(i). This cannot be undone.
- Local device data is removed when you uninstall the app.
- A step-by-step description, including what is kept and for how long, is on our account deletion page.
8. Your rights (GDPR)
You have the right to access, rectify, erase, restrict, and port your data, and to object to processing. Specifically:
- Access / portability: request a copy of your data at privacy@socialix.ai.
- Rectification: change your username and display name in the app at any time.
- Erasure: delete your account in-app (Profile → Delete account), or ask us at privacy@socialix.ai.
- Complaint: you may lodge a complaint with your data protection authority (in Germany, your state's Datenschutzbehörde).
9. Not yet active (update this section when they launch)
The following are not used in this version and this policy must be updated before they go live:
- Crash reporting (Sentry): would process crash and diagnostic data.
- Analytics: none currently.
(In-app purchases and Sign in with Apple are both live — see §3(g), §3(h) and §5. There are no subscriptions.)
10. Children
IQ Mogged is not directed at children under 16. We do not knowingly collect data from children under that age. If you believe a child has provided us with data, contact us at privacy@socialix.ai and we will delete it.
(16 is the GDPR "digital consent" age unless a member state lowers it; Germany does not. Keep the age rating you set in App Store Connect and Play Console consistent with this.)
11. Security
Access to your data is restricted by database Row-Level Security so only you and your confirmed friends can see the relevant rows — except for the data you deliberately publish by switching on public ranking (section 3c), which is then visible to any signed-in player; session tokens are stored in the device's secure enclave; leaderboard submissions are validated server-side. No system is perfectly secure, but we take reasonable measures to protect your data.
12. Changes to this policy
We may update this policy; the "Last updated" date reflects the latest version. Material changes will be surfaced in the app or on the store listing.
13. Contact
The Lucas Agency GmbH — privacy@socialix.ai — Am Kabellager 11, 51063 Köln, Germany
Eine deutschsprachige Fassung dieser Erklärung finden Sie unter Datenschutzerklärung.