IQ Mogged

IQ Mogged — Privacy Policy

Last updated: 2026-08-29
App: IQ Mogged (iOS / Android)

1. Who is responsible (Controller)

The controller for your data under the GDPR is:

If you have questions about this policy or your data, contact us at privacy@socialix.ai.

2. Summary

IQ Mogged is a daily logic-puzzle game. You can play offline without giving us any personal details. If you use the online features (daily leaderboards, friends), we store a minimal profile and your daily solve times so you can compete with friends. The game is free to play; there are three optional one-time in-app purchases and never a subscription — one unlocks every level, one removes the ads, and one is both together. Only the last two remove the ads. We never ask for your real name or email address to play — they are only involved if you choose to use Sign in with Apple, either to create your account or to secure an existing one (§3(h)).

Since version 2.0 the free game is funded by advertising: a full-screen ad appears after every third level you finish. The daily puzzles stay ad-free. Separately from that, you can choose to watch a short ad in exchange for an extra life — that one only ever appears when you tap it, and it stays available even if you have paid to remove the ads. On iOS we ask, through Apple's tracking prompt, whether ads may be matched to your interests: if you decline, or before you answer, the ads are non-personalised and nothing else changes. Android has no such prompt — there the decision rests on Google's consent dialog and is applied by Google's advertising SDK. Details in §3(j). We do not sell your data, and your puzzle results, times and friends are never shared with advertisers.

3. What we collect and why

a) Account / identity data

When you first open the app we create an anonymous account (a random user ID) via our backend provider (Supabase). To use the social features you choose:

We store these plus the account creation date. Playing does not require an email address, a phone number, or your real name, and we never ask for them here (please don't type sensitive information into your display name either). If you choose to secure your account with Sign in with Apple, an email address and optionally your Apple name are involved — see §3(h).

Purpose: to give you an identity others can add and compete with. Legal basis (GDPR Art. 6(1)(b)): performance of the service you requested.

b) Social / friends data

If you add friends: your friendship connections and pending friend requests (who sent/received, status, timestamps).

Purpose: to run the friends and request features. Legal basis: Art. 6(1)(b) (service), and for others adding you, our legitimate interest in providing a social game (Art. 6(1)(f)).

c) Gameplay data (online)

Two kinds of solve time are stored on our servers, each linked to your account:

Public leaderboards (optional, off by default). By default the leaderboards above show only you and your confirmed friends. You can switch on public ranking in the app; while it is on, any signed-in player can see the following.

In the public leaderboards:

In your public profile, which any of those players can open by tapping your row:

Your username, your friend list, your e-mail address and your individual level times are not part of any of it. The setting is off until you turn it on, and switching it back off removes you from the public leaderboards and from the public profile again.

Purpose: leaderboards and streaks; with public ranking on, comparison beyond your friend circle. Legal basis (GDPR Art. 6(1)(b)): performance of the service you requested. For public ranking, your consent (Art. 6(1)(a)), which you can withdraw at any time via the same setting.

d) Data stored only on your device

Your in-progress puzzle state, streaks, app settings, and which levels you have unlocked are stored locally on your device and are not sent to us. (Your solve times are uploaded — see (c).) Your login session token is stored securely on your device (iOS Keychain / Android Keystore). Uninstalling the app removes this local data.

e) Notifications (from version 2.0)

Notifications are optional. We ask inside the app first, whether you would like to be reminded at all; the iOS system dialog only appears if you agree there. If you decline, nothing is stored and nothing is sent to us.

If you agree, three things are involved:

The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time by turning Profile → Reminders off. That deletes the scheduled reminder on the device and removes the stored push identifier from our server. It is also deleted when you delete your account. We never send advertising through this channel.

f) Technical data

Our backend provider processes technical data needed to deliver the service (e.g. IP address at the moment of a request, for security and rate-limiting). We do not build advertising or tracking profiles from it.

g) Purchase data

The app offers three one-time purchases: unlocking every level, removing the ads, and a bundle of both. All three are non-consumable and none is a subscription, and they are independent of one another — unlocking the levels does not remove the ads, and removing the ads does not unlock the levels. The payment itself is handled by Apple or Google; we never see your card details. Our purchases provider (RevenueCat) records that a purchase was made and the resulting entitlements (levels unlocked: yes/no; ad-free: yes/no), linked to your account's user ID so that a payment can be matched to an account if you contact us about it. RevenueCat does not receive your username, display name, email address, or friends data. On your device we store only a local flag for what you own; we do not keep a purchase record on our own servers.

Purpose: to unlock the paid content and restore your purchase after a reinstall. Legal basis (GDPR Art. 6(1)(b)): performance of the purchase contract.

h) Sign in with Apple or Google (optional)

Your account is anonymous by default, which means it lives on that one device: reinstall the app or switch phones and your streaks and friends are gone. Sign in with Apple prevents that, and you can use it in two ways:

Exactly one provider is offered per platform: Sign in with Apple on iOS, Sign in with Google on Android. You are never asked to choose between them.

This is entirely optional in both cases — the first screen also offers a plain form, and everything in the app works without ever signing in.

When you do, Apple sends us:

On Android, Google takes Apple's place and sends us the same three things: a stable user identifier for your Google account, your email address, and optionally your name. Google offers no relay-address equivalent, so the address is your real Google address. Unlike Apple, Google provides the name and email on every sign-in, not only the first.

We store the identifier and email with your account at our backend provider (Supabase) purely so we can recognise you again. We do not use your email address for marketing and we never send you email. This is the same data either way — only the provider differs.

Purpose: creating your account, and recovering it after a reinstall or device change. Legal basis (GDPR Art. 6(1)(b)): performance of the service you requested. Withdrawal: you can stop the linkage at any time — in your Apple ID settings, or under Third-party apps with account access in your Google account — and you can delete the account entirely in the app (Profile → Delete account), or via our account deletion page.

i) Reports and blocks

If you block another player, we store who blocked whom. If you report someone, we store the reported account, the reason you selected, and the time — plus a copy of the username and display name as they were at that moment, so the report still makes sense if the account is later renamed or deleted. Only we can read this; it is never shown to other players.

Purpose: to keep blocks working and to act on abuse (Apple requires both for apps with user-generated content). Legal basis: Art. 6(1)(b) (service) and Art. 6(1)(f) (our legitimate interest in a safe service and in documenting abuse reports).

j) Advertising (from version 2.0)

There are two ad formats, and the difference matters for your data.

Full-screen ads, shown to you. If you have not bought "remove ads" or the bundle, the app shows a full-screen ad after every third level you finish. Buying "unlock every level" on its own does not stop these. The daily puzzles are always ad-free, and no ad ever interrupts a puzzle you are solving. If you own ad-freedom, none of these is ever requested or shown, and nothing to do with advertising is started for you unprompted — no ad request leaves your device unless you ask for one, as described next.

Rewarded ads, only when you ask for one. Where the app offers you an extra life, you may tap to watch a short ad in exchange for it. It is never shown on its own, it never interrupts anything, and nothing is credited unless the ad was watched through to the end. It is available to every player, including those who bought "remove ads" or the bundle: paying removes the ads we would put in front of you, not the ones you choose to watch. If you do tap it, the advertising SDK is started at that moment and the consent dialog described below is shown first — this is the one case in which an ad request leaves the device of a paying player. If you never tap it, nothing is started.

The ads are delivered through Google AdMob. To deliver them, Google's SDK processes a device identifier and technical data about your device and about the ad itself (which ad was shown, whether you tapped or dismissed it, error and performance data). It uses this to deliver ads, to limit how often you see the same one, and to detect invalid traffic and fraud.

AdMob is the mediation platform, not the only source of ads. For each ad slot it collects bids from other ad networks and lets the highest one serve. Besides Google, one further network is currently integrated: Unity Ads (Unity Technologies). When Unity wins a bid, its SDK also processes a device identifier and technical data about your device and the ad in order to deliver it, for the same purposes. If another network is added, it will be named here before the app version carrying it is released.

The limits below apply to every one of these sources alike, whichever network ends up serving a given ad: how a request is marked follows the rules set out next, and if you own ad-freedom no advertising SDK starts at all unless you tap a rewarded ad yourself — not Google's and none of the mediated ones.

The limits we set in the app:

Your choice (EEA/UK): before the first ad request we show you Google's consent dialog (Google User Messaging Platform). If you decline, or if the dialog cannot be shown, the app requests no ads at all. You can change your decision later via the privacy options in the dialog where offered. You can also remove the full-screen ads permanently with the one-time "remove ads" purchase or the bundle; the voluntary rewarded ad stays available to you afterwards if you want it.

Purpose: to fund the free version of the game. Legal basis: your consent (GDPR Art. 6(1)(a)) where consent is collected via the dialog above; storage on your device is based on your consent under §25(1) TTDSG.

4. What we do NOT do

5. Who we share data with (processors)

We use trusted service providers who process data on our behalf under data-processing agreements:

We disclose data only if required by law.

6. International transfers

Your account, social, and gameplay data is stored inside the EEA, in the EU (Ireland) region. Purchase and entitlement data handled by RevenueCat and Apple is processed on US infrastructure. Some of our providers are US-based companies whose staff may access data from outside the EEA for support or maintenance; such access is safeguarded by Standard Contractual Clauses and the providers' data-processing agreements.

7. How long we keep it

8. Your rights (GDPR)

You have the right to access, rectify, erase, restrict, and port your data, and to object to processing. Specifically:

9. Not yet active (update this section when they launch)

The following are not used in this version and this policy must be updated before they go live:

(In-app purchases and Sign in with Apple are both live — see §3(g), §3(h) and §5. There are no subscriptions.)

10. Children

IQ Mogged is not directed at children under 16. We do not knowingly collect data from children under that age. If you believe a child has provided us with data, contact us at privacy@socialix.ai and we will delete it.

(16 is the GDPR "digital consent" age unless a member state lowers it; Germany does not. Keep the age rating you set in App Store Connect and Play Console consistent with this.)

11. Security

Access to your data is restricted by database Row-Level Security so only you and your confirmed friends can see the relevant rows — except for the data you deliberately publish by switching on public ranking (section 3c), which is then visible to any signed-in player; session tokens are stored in the device's secure enclave; leaderboard submissions are validated server-side. No system is perfectly secure, but we take reasonable measures to protect your data.

12. Changes to this policy

We may update this policy; the "Last updated" date reflects the latest version. Material changes will be surfaced in the app or on the store listing.

13. Contact

The Lucas Agency GmbH — privacy@socialix.ai — Am Kabellager 11, 51063 Köln, Germany

Eine deutschsprachige Fassung dieser Erklärung finden Sie unter Datenschutzerklärung.