IQ Mogged — Privacy Policy
Last updated: 2026-07-19
App: IQ Mogged (iOS / Android)
1. Who is responsible (Controller)
The controller for your data under the GDPR is:
- The Lucas Agency GmbH
- Am Kabellager 11, 51063 Köln, Germany
- Represented by: Maxim David Dambietz
- Register: Amtsgericht Köln, HRB 127141
- Contact: privacy@socialix.ai
If you have questions about this policy or your data, contact us at privacy@socialix.ai.
2. Summary
IQ Mogged is a daily logic-puzzle game. You can play offline without giving us any personal details. If you use the online features (daily leaderboards, friends), we store a minimal profile and your daily solve times so you can compete with friends. The game is free to play; an optional one-time in-app purchase (no subscription) unlocks all level packs. We never ask for your real name or email address to play — they are only involved if you choose to use Sign in with Apple to secure your progress (§3(g)). We do not show ads, and we do not sell your data.
3. What we collect and why
a) Account / identity data
When you first open the app we create an anonymous account (a random user ID) via our backend provider (Supabase). To use the social features you choose:
- a username (a unique handle, e.g.
@lucas), - optionally a display name (shown to friends),
- a system-generated friend code.
We store these plus the account creation date. Playing does not require an email address, a phone number, or your real name, and we never ask for them here (please don't type sensitive information into your display name either). If you choose to secure your account with Sign in with Apple, an email address and optionally your Apple name are involved — see §3(g).
Purpose: to give you an identity others can add and compete with. Legal basis (GDPR Art. 6(1)(b)): performance of the service you requested.
b) Social / friends data
If you add friends: your friendship connections and pending friend requests (who sent/received, status, timestamps).
Purpose: to run the friends and request features. Legal basis: Art. 6(1)(b) (service), and for others adding you, our legitimate interest in providing a social game (Art. 6(1)(f)).
c) Gameplay data (online)
Two kinds of solve time are stored on our servers, each linked to your account:
- Daily puzzles: your solve time for that day and game, which powers the per-game daily leaderboard shown to you and your friends.
- Level packs: when you first solve a level, we store which game and level number it was and how long you took, so you and your friends can compare times on the same level. Only the first solve of a level is recorded; it is not updated afterwards.
Purpose: leaderboards and streaks. Legal basis (GDPR Art. 6(1)(b)): performance of the service you requested.
d) Data stored only on your device
Your in-progress puzzle state, streaks, app settings, and which levels you have unlocked are stored locally on your device and are not sent to us. (Your solve times are uploaded — see (c).) Your login session token is stored securely on your device (iOS Keychain / Android Keystore). Uninstalling the app removes this local data.
e) Technical data
Our backend provider processes technical data needed to deliver the service (e.g. IP address at the moment of a request, for security and rate-limiting). We do not build advertising or tracking profiles from it.
f) Purchase data
If you buy the one-time premium unlock (removes the level limit — a single non-consumable purchase, not a subscription), the payment itself is handled by Apple; we never see your card details. Our purchases provider (RevenueCat) records that a purchase was made and your resulting entitlement (premium: yes/no), linked to a random purchase ID — not to your username, display name, or email. On your device we store only a local flag that you own premium; we do not keep a purchase record on our own servers.
Purpose: to unlock the paid content and restore your purchase after a reinstall. Legal basis (GDPR Art. 6(1)(b)): performance of the purchase contract.
g) Sign in with Apple (optional)
Your account is anonymous by default, which means it lives on that one device: reinstall the app or switch phones and your streaks and friends are gone. To prevent that you can link it to your Apple ID ("Save progress"), and later use the same Apple ID to restore it. This is entirely optional — everything in the app works without it.
When you do, Apple sends us:
- a stable user identifier for your Apple ID (specific to this app),
- your email address — if you choose Hide My Email, this is an Apple relay address (
…@privaterelay.appleid.com) and we never see your real one, - optionally your name, which we use as your display name unless you change it. Apple only provides this on the very first sign-in.
We store the identifier and email with your account at our backend provider (Supabase) purely so we can recognise you again. We do not use your email address for marketing and we never send you email.
Purpose: account recovery after a reinstall or device change. Legal basis (GDPR Art. 6(1)(b)): performance of the service you requested. Withdrawal: you can stop the linkage at any time in your Apple ID settings, and you can delete the account entirely in the app (Profile → Delete account).
h) Reports and blocks
If you block another player, we store who blocked whom. If you report someone, we store the reported account, the reason you selected, and the time — plus a copy of the username and display name as they were at that moment, so the report still makes sense if the account is later renamed or deleted. Only we can read this; it is never shown to other players.
Purpose: to keep blocks working and to act on abuse (Apple requires both for apps with user-generated content). Legal basis: Art. 6(1)(b) (service) and Art. 6(1)(f) (our legitimate interest in a safe service and in documenting abuse reports).
4. What we do NOT do
- No advertising and no ad-tracking / IDFA.
- No third-party analytics or behavioural tracking (as of this version — see §9).
- No sale or sharing of personal data for others' marketing.
- No collection of special-category data.
5. Who we share data with (processors)
We use trusted service providers who process data on our behalf under data-processing agreements:
- Supabase — backend hosting, database, and authentication. Region: EU (Ireland), AWS
eu-west-1. See Supabase's privacy terms. - Apple / Google — app distribution and payment processing for in-app purchases. Your payment details go to the store, never to us. If you use Sign in with Apple, Apple also acts as the identity provider and passes us the data listed in §3(g).
- RevenueCat — manages in-app purchases and your premium entitlement. It processes a random, app-generated purchase ID, your purchase/receipt data, and basic device/technical data needed to validate and restore purchases. It does not receive your username, display name, or friends data. US-based; safeguarded by Standard Contractual Clauses and a data-processing agreement.
We disclose data only if required by law.
6. International transfers
Your account, social, and gameplay data is stored inside the EEA, in the EU (Ireland) region. Purchase and entitlement data handled by RevenueCat and Apple is processed on US infrastructure. Some of our providers are US-based companies whose staff may access data from outside the EEA for support or maintenance; such access is safeguarded by Standard Contractual Clauses and the providers' data-processing agreements.
7. How long we keep it
- Account, social, and gameplay data: for as long as your account exists.
- When you delete your account in the app (Profile → Delete account), your account and all associated rows (profile, username, friendships, friend requests, daily results and level results) are permanently deleted from our database. This cannot be undone.
- Local device data is removed when you uninstall the app.
8. Your rights (GDPR)
You have the right to access, rectify, erase, restrict, and port your data, and to object to processing. Specifically:
- Access / portability: request a copy of your data at privacy@socialix.ai.
- Rectification: change your username and display name in the app at any time.
- Erasure: delete your account in-app (Profile → Delete account), or ask us at privacy@socialix.ai.
- Complaint: you may lodge a complaint with your data protection authority (in Germany, your state's Datenschutzbehörde).
9. Not yet active (update this section when they launch)
The following are not used in this version and this policy must be updated before they go live:
- Crash reporting (Sentry): would process crash and diagnostic data.
- Analytics: none currently.
(In-app purchases and Sign in with Apple are both live — see §3(f), §3(g) and §5. There are no subscriptions.)
10. Children
IQ Mogged is not directed at children under 16. We do not knowingly collect data from children under that age. If you believe a child has provided us with data, contact us at privacy@socialix.ai and we will delete it.
(16 is the GDPR "digital consent" age unless a member state lowers it; Germany does not. Keep the age rating you set in App Store Connect and Play Console consistent with this.)
11. Security
Access to your data is restricted by database Row-Level Security so only you and your confirmed friends can see the relevant rows; session tokens are stored in the device's secure enclave; leaderboard submissions are validated server-side. No system is perfectly secure, but we take reasonable measures to protect your data.
12. Changes to this policy
We may update this policy; the "Last updated" date reflects the latest version. Material changes will be surfaced in the app or on the store listing.
13. Contact
The Lucas Agency GmbH — privacy@socialix.ai — Am Kabellager 11, 51063 Köln, Germany
Eine deutschsprachige Fassung dieser Erklärung finden Sie unter Datenschutzerklärung.