Deen Words

Privacy Policy for Deen Words

Last updated: 29 September 2026

This policy covers the Deen Words app on iPhone and Android, and the web version at deen-words.vercel.app. It is written for players, not lawyers. Where a technical term cannot be avoided, it is explained on the spot.

The short version

There are five points where data leaves your device:

  1. Ads. Google receives device identifiers (on Android the advertising ID and the app set ID), your IP address, from which your approximate location can be told, how you interact with the ads, and technical performance data from the app. Google uses this for advertising, statistics and fraud prevention. It starts once you are past the welcome screen and happens at every start after that, even if you decline personalised ads.
  2. Purchases. At every start the app asks the billing service RevenueCat whether purchases belong to your installation, even if you never buy anything. RevenueCat receives an anonymous user ID, your device type and your purchase history. Payment itself runs through the App Store or Google Play.
  3. Your email to me. Tapping "Contact us" opens your own mail app with a few details already filled in. You see them before sending and can change or delete them.
  4. Web version. Loading deen-words.vercel.app creates server logs at the host, Vercel, including your IP address.
  5. Crashes and usage numbers. Crash reports (Firebase Crashlytics) and usage numbers (Firebase Analytics) are only sent in the European Economic Area, the UK and Switzerland if you agreed in the consent dialog. Outside these countries there is no dialog: there a crash sends a report to Google, and usage numbers are never sent. There is a section of its own on this below.

In the European Economic Area, the UK and Switzerland, Google asks you in a dialog whether ads may be personalised. If you decline, ads still appear, just not personalised ones, and Google still receives your IP address and technical data. You can change your answer at any time under Settings, "Privacy settings". Outside those countries no dialog appears.

I never see your payment details; they stay with Apple and Google. These services are based in the USA, and so is the company responsible. What that means and what you can do about it is in the section "Does data go to the USA?".

Everything else stays on your device. Your progress is never uploaded anywhere. There is no account, no server of mine and no cloud. I do not sell data. The ad software does send data to Google, which Google also uses for its own purposes; Google Play counts that as sharing with third parties, which is why the store listing says so. More on that in the advertising section.

Who is responsible?

NOMAD AGENCY FOR MARKETING & CONSULTING LLC

2880 W Oakland Park Blvd, Ste 225C

Oakland Park, FL 33311, USA

represented by Mustafa Ali (Authorized Member)

Email: support@na4mc.de

Representative in the Union: [OPEN: the company is based in the USA and has no establishment in the EU. Article 27 GDPR therefore requires a representative in the Union, whose name and address belong here under Article 13(1)(a) GDPR. To be clarified with a lawyer and filled in before publication.]

Deen Words is published by this company. The law calls the body that decides about your data the "controller" — here that is the company, and it is who you can turn to. There are no employees: one person works on the app, Mustafa Ali. Where this policy says "I", he is meant, running the app for the company. There is no data protection officer. Questions about privacy go to the address above.

What happens with the ads?

The app shows ads from Google AdMob. That is what pays for the game.

This is exactly what happens: once you are past the welcome screen, and at every start after that, the app first asks Google's consent service. It is called UMP, short for User Messaging Platform. That request already goes to Google: Google sees your IP address and technical details about the app and device, and uses them to decide whether consent is needed in your region. Then:

What Google receives:

What for: to deliver and select ads, with your consent also matched to your interests; to count and bill which ads were shown and tapped; for statistics at Google and for me, where I only see aggregated figures in AdMob and no individual people; and to detect fraud and abuse, such as fake clicks.

Sharing, plainly: Google processes this data not only for me but also for its own purposes, and is responsible for that itself. Google Play treats this as sharing with third parties, and that is what the data safety section of the store listing says. I do not sell data, neither to Google nor to anyone else.

Legal basis: for personalised ads, your consent, Article 6(1)(a) GDPR. For storing and reading information on your device for that purpose, additionally section 25(1) of the German TDDDG. For the request to the consent service and for ads without personalisation, Article 6(1)(f) GDPR: the controller's legitimate interest in financing the free game with ads, in obtaining the consent this requires, and in fending off ad fraud.

Recipients: Google Ireland Limited (Ireland) and Google LLC (USA). Google also processes this data for its own purposes and is responsible for that itself. Details: policies.google.com/privacy

Other ad partners: Google's ad auction also lets other advertising companies bid for the ad spaces in the app. In the European Economic Area, the UK and Switzerland the Google dialog lists these partners by name ("List of partners", or "Manage options"). If you agree, they may also receive the data listed above and use it for the purposes you allowed there. Some partners rely on legitimate interest instead of consent for certain purposes, such as measuring ads; you can object to that in the same place, partner by partner and purpose by purpose. Each partner is responsible for its own processing; its privacy policy is linked in the list.

Retention: decided by Google. I have no access to it and no influence over it.

Changing your answer: open Settings and tap "Privacy settings". The same Google dialog opens again, at any time. Withdrawal applies going forward and does not make the earlier processing unlawful retroactively. Outside the countries where Google shows the dialog, and in the web version, there is no such dialog, and the app tells you so.

How many ads you see: The first five solved puzzles are ad free. After that a banner appears below the board, and roughly every two to three puzzles a full-screen ad follows. Videos for coins only start when you tap them. The one-time purchase "Remove ads" switches the banner and the ads between puzzles off for good; voluntary videos stay available. That is why the app keeps starting the advertising software after this purchase and keeps loading ads in the background; the only ones it shows you are the videos you start yourself. Google keeps receiving the data listed above.

SKAdNetwork on iPhone: the iOS build lists 54 SKAdNetwork identifiers. SKAdNetwork is Apple's method for letting ad networks measure whether an ad led to an install. How Apple designs that measurement is documented by Apple.

What happens when you buy something?

There is a one time purchase, "Remove ads", and there are coin packs. The purchase runs through the App Store or Google Play. I never see your payment details. Card number, address and invoice sit with Apple and Google, who are responsible for them.

To manage purchases I use the service RevenueCat. Once you are past the welcome screen, and at every start after that, the app checks in with RevenueCat, even if you never buy anything. RevenueCat receives:

What for: to verify your purchase with the store and match it to your installation; to unlock "Remove ads", credit coins you bought, even if the app closes right after payment, and restore purchases after a reinstall; and for purchase and revenue statistics that RevenueCat compiles for me from this data, such as how often a pack was bought. I do not see names or email addresses there.

Legal basis: Article 6(1)(b) GDPR, performance of the purchase contract, for verifying, unlocking, crediting and restoring. For the check at start when you have not bought anything, and for the statistics, Article 6(1)(f) GDPR, the controller's legitimate interest in recognising purchases reliably and knowing which offers are used.

Recipients: RevenueCat, Inc. (USA) as my service provider, and Apple and Google as the store operators. See revenuecat.com/privacy, apple.com/legal/privacy and policies.google.com/privacy

Retention: as long as your purchase has to stay valid and restorable, or until you ask for deletion; how that works is described under "How do you delete your data?" below. Apple and Google set their own periods. Tax and bookkeeping obligations for the payment itself fall on the stores, not on me.

What happens when you write to me?

The support number. Your device creates it once, the first time it is needed, from the current time down to the microsecond; the last eight characters become your number. It is not derived from any device identifier and cannot be traced to a device or a person. It has one job: if you write twice, I can connect both emails to the same case.

It only leaves your device if you send an email yourself. Tapping "Contact us" opens your own mail app with a prepared text containing your support number, your purchase ID (the anonymous user ID at RevenueCat, see above; it is left out if RevenueCat does not answer at that moment), your current level, your coin balance, and your operating system and its version. That saves me from asking, and lets me find your purchases at RevenueCat when your message is about a purchase or a deletion. You see this text before sending and can edit or delete it. The app never sends anything on its own. If no mail app can be opened, the app simply copies the support address to your clipboard.

Once you send the mail, I also learn your sender address and whatever you write in it.

Legal basis: Article 6(1)(b) GDPR where your message concerns a purchase or the app itself, otherwise Article 6(1)(f) GDPR, the controller's legitimate interest in answering you and fixing bugs.

Recipients: your own mail provider when sending, and SiteGround Spain S.L., Calle de Prim 19, 28004 Madrid, Spain. SiteGround receives the message, filters spam and puts it in my mailbox. There is a data processing agreement with SiteGround under Article 28 GDPR; it forms part of their terms of service and includes the standard contractual clauses for the case that data reaches a third country.

Retention: until your issue is settled and no follow-up questions are expected, and no more than six months after that. If your message concerns a purchase, a refund or a complaint, I keep it until the end of the third calendar year after the matter is closed: claims arising from it can be brought during that period, and I need to be able to defend against them (Article 17(3)(e) GDPR). After that I delete it, attachments included. You can ask me at any time to delete it sooner; if nothing prevents it, I will.

What about the web version?

At deen-words.vercel.app there are no ads and no purchases. Neither service is available in the browser and neither is loaded. Your progress sits in your browser's localStorage, a small store your browser keeps for one site on your own computer.

Loading the page produces technically necessary server logs: IP address, time of the request and the file requested. Without them a website cannot be delivered.

Legal basis: Article 6(1)(f) GDPR, the controller's legitimate interest in running the site securely and reliably.

Recipient: Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA, as the host. There is no European Vercel entity. See vercel.com/legal/privacy-policy

Retention: Vercel states a fixed period only for the logs available in its own dashboard, between one hour and three days depending on the plan. That is how long they can be queried, not a promise that Vercel deletes them afterwards: no deletion period is given in Vercel's documentation, its privacy notice or its data processing addendum. I do not retrieve or analyse these logs.

What happens when the app crashes?

Since version 1.1.1 the app uses Firebase by Google, for two things and only these.

Crash reports (Firebase Crashlytics). If the app crashes, a technical report goes to Google: the place in the program where it happened, your device model, the version of your operating system and of the app, the memory state and a random installation ID. No name, no progress, no word you found, no advertising ID. Without that report I learn about a crash only from a review in the store — and then I do not know what caused it.

Usage numbers (Firebase Analytics). How often the app is started, how long a session lasts, which language and device model are in use, and roughly which country the request comes from. It shows me where the game becomes too hard — not who stopped there.

Both stay off until you agree, in the European Economic Area, the UK and Switzerland. They follow the same answer you give Google's consent dialog: the app only switches Firebase on if you allowed storage on your device, measurement and Google as a vendor there. If you decline, the app sends neither crash reports nor usage numbers. You can change this at any time under Settings, "Privacy settings". Withdrawal takes effect at once: the app switches Firebase off, deletes the usage numbers' ID on your device and discards crash reports that were not sent yet.

Outside these countries there is no consent dialog. There a crash sends a report to Google; usage numbers are never sent there, because there is nowhere you could agree to them.

Offline stays offline. With no internet connection nothing leaves the device, and every puzzle still works.

Recipients: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC.

Legal basis: for both, Article 6(1)(a) GDPR, your consent, and for storing the installation ID on your device Section 25(1) of the German TDDDG. You can withdraw it at any time; withdrawal applies going forward. Outside the European Economic Area, the UK and Switzerland the crash reports rest on my legitimate interest in the app not crashing on your device (Article 6(1)(f) GDPR).

Retention: crash reports 90 days, usage numbers 2 months. Google deletes them after that.

Where is your progress stored?

On your device, and nowhere else. On iPhone and Android in the storage the operating system gives every app, in the web version in your browser's localStorage. I never see it.

This is the complete list of what the app stores, all 48 entries:

On top of that, the billing service RevenueCat keeps a cache with your anonymous user ID and the last known state of your purchases. It also stays on your device and is deleted with the app. Google's ad software likewise keeps its own entries on your device, including your answer in the consent dialog, so that it still applies at the next start. They are also deleted with the app.

Ratings: After you complete a world, the app may open the rating dialog of Google Play or the App Store. What you enter there goes straight to Google or Apple, under their privacy terms. The app never learns whether you rated, or how.

The name is the only thing you type in yourself. It is optional, the app never asks for it, and without it the greeting simply says "traveller". It stays on your device like everything else: there is no account, nobody but you ever sees it, and it is not uploaded.

That is all. There is no database, no further files with user data, and no server anything is copied to.

Legal basis: Article 6(1)(b) GDPR, because without stored progress there is no game to install. For the storage on your device, additionally section 25(2) no. 2 TDDDG, since it is strictly necessary for the service you asked for.

Recipients: none.

Retention: until you reset, delete the app, or clear your browser data in the web version.

What about the reminders?

If you switch them on, your device schedules at most three notifications for itself: one in the evening when your streak is running and today's puzzle is still open, one after three quiet days, and one with a word to take away.

There is no messaging service — no Firebase Cloud Messaging either — no device token and no server that learns about it. The text of the notification sits inside the app; your device works out the time. Nothing is uploaded, not even whether you opened a notification.

You can switch them off at any time, in the app's settings or in your device's. The app then deletes the scheduled notifications.

Legal basis: Article 6(1)(a) GDPR, the consent you give with the switch and can withdraw at any time.

Recipients: none.

Does data go to the USA?

Yes, in two ways. First, Google — including Firebase — RevenueCat, Apple and Vercel are US companies or belong to one; whatever reaches them may also be processed in the USA. Second, the controller itself is a company based in Florida. Whatever you send to the support mailbox therefore also ends up in the USA.

The European Commission has adopted an adequacy decision for the USA under the EU-US Data Privacy Framework. It only covers companies that have certified under it. As of 9 September 2026, Google LLC and Vercel Inc. appear on the official list with an active certification. Apple Inc. and RevenueCat, Inc. do not; for those, the transfer relies on standard contractual clauses under Article 46(2)(c) GDPR. You can obtain a copy of those clauses from the provider concerned, or write to me and I will point you to it. You can check the current status yourself at dataprivacyframework.gov/list.

About the entities behind this: within the European Economic Area, Google's services are provided by Google Ireland Limited in Dublin, and your App Store purchase runs through Apple Distribution International Ltd. in Cork. Both are based in the EU. Certification and standard contractual clauses only concern the onward transfer from there to Google LLC and Apple Inc. in the USA.

No sugar coating: a residual risk remains. Under certain conditions US authorities can access data processed there, and the legal remedies against that do not match the European level in every respect. Declining the advertising consent only prevents personalised ads, not every transfer to Google. The only way to avoid transfers entirely is to play without an internet connection: every puzzle works offline, and while your device is offline nothing goes to Google or RevenueCat. There are no videos for coins and no purchases then, though.

Does the app track you across other apps?

The app itself does not. I do not link data from this app with data from other apps or websites. The crash reports and usage numbers described in the Firebase section concern this app only; they are not merged with data from other apps or websites, and there is no tracking component of my own.

With the ads, it depends on Google and on your choice. On iPhone the app never asks for tracking permission through Apple's App Tracking Transparency, so Google does not get the advertising ID there. On Android, Google may use the advertising ID for personalised ads if you agreed, or if no consent dialog appears in your region. What Google draws on for that is described in Google's privacy policy. If you delete the advertising ID in the Android settings, Google no longer receives it. The rest of the data listed in the advertising section reaches Google either way.

What the app deliberately does not do

Android permissions: my own app file declares three permissions: internet, showing notifications (POST_NOTIFICATIONS), and rescheduling the reminders after the device restarts (RECEIVE_BOOT_COMPLETED). Android only asks you about showing notifications when you switch the reminders on. When the app is built, the permissions of the bundled libraries are added, which is normal on Android. The finished package therefore also contains:

Location, camera, microphone, contacts and photos are not among them.

How long is data kept?

DataWhereHow long
progress, settings, support numberon your device onlyuntil you reset, delete the app or clear browser data
your support emailmy mailboxsix months after the matter is settled; for a purchase, refund or complaint until the end of the third calendar year
advertising dataat Googleper Google's rules, no access on my side
purchase dataat RevenueCatas long as the purchase must stay valid and restorable; deleted within 30 days if you ask
purchase data and receiptsat Apple and Googleper their rules, including tax retention obligations
web version server logsat Vercelone hour to three days in the dashboard depending on the plan, no period stated beyond that; no access on my side

What rights do you have?

You can ask for access to the data processed about you (Article 15 GDPR), correction of wrong data (Article 16), erasure (Article 17), restriction of processing (Article 18) and a copy in a common format (Article 20). You can object to processing based on legitimate interests (Article 21), which here means the ads without personalisation and the request to the consent service, the check with RevenueCat, the web server logs and the handling of your email. You can withdraw consent at any time with effect for the future (Article 7(3)). What happened lawfully before that stays lawful.

Honestly, what this means in practice:

You can also complain to a data protection supervisory authority (Article 77 GDPR): the authority where you live, where you work, or where the alleged infringement took place. You do not have to contact me first.

How do you delete your data?

Children and young people

I do not ask for your age and do not know it. Nothing in the app puts children in touch with other people: no chat, no friend lists, no profiles.

The one point that matters is the advertising consent. In Germany, young people can only consent on their own from the age of 16, and in some other EU countries the limit is lower (Article 8 GDPR). Below that age, parents decide.

For parents, concretely: decline personalised ads in Google's consent dialog. Ads still appear, but they are not tailored to your child. You can reopen that dialog at any time under Settings and "Privacy settings" and change the answer. Where Google shows no dialog, you can delete the advertising ID in the device settings on Android. If you want the banner and the ads between puzzles gone entirely, buy "Remove ads".

The app is not a children's offering. It is not part of Google Play's Families programme and it is not in Apple's Kids Category. The age rating each store shows is on that store's page. If I learn that someone under 13 has sent me data, in a support email for example, I delete it without anyone having to ask.

Do you have to provide any data?

No. You need not provide anything to play, and you need not agree to personalised ads. If you decline, the game carries on as normal, ads included, only they are not personalised. Google still receives your IP address and technical data, as described in the advertising section, and RevenueCat still receives your anonymous user ID at start. The only way to send nothing at all is to play without an internet connection; every puzzle still works then. Without a purchase, "Remove ads" and the coin packs stay locked, and that is all that happens.

Are decisions made about you automatically?

No. I make no automated decisions in individual cases and no profiling within the meaning of Article 22 GDPR. What Google does to select ads is described in Google's own privacy policy.

Will this policy change?

Yes, whenever the app changes. If a service is added or dropped, I write it in here and put a new date at the top. If a new kind of processing needs your consent, I will ask you in the app first. The current version is always at deen-words.vercel.app/privacy.html, the German one at deen-words.vercel.app/datenschutz.html.

Contact

Write to support@na4mc.de. The easiest way is "Contact us" in the settings, which brings your support number and your purchase ID along.