Overdraft Games played past the limit
DE EN

Privacy policy

Last updated: October 5, 2026

The German version is the authoritative one. This translation is provided for convenience. In case of any discrepancy, the German privacy policy prevails.

1. Controller

The controller within the meaning of the GDPR is:

RegSus Consulting GmbH
Cosimastr. 121, 81925 München, Germany
Email: webmaster@regsus.de

A data protection officer is not legally required given the company's size (§ 38 BDSG).

2. This website

Server log files

When you visit this website, the hosting provider automatically processes information your browser transmits (server log files): page requested and time of access, data volume transferred and status, browser type and version, operating system, referrer URL, and IP address.

The legal basis is Art. 6(1)(f) GDPR, the legitimate interest in operating the website securely and without errors. This data is not merged with other data sources.

Hosting provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (server location Helsinki, EU). Cloudflare, Inc. sits in front as a content-delivery and DDoS-protection service, routing requests before they reach our server. We have a data processing agreement under Art. 28 GDPR with both, based on each provider's standard terms.

Fonts

This website loads all fonts from our own server. There is no connection to Google Fonts or any other external provider, and no IP address is transmitted to third parties.

Language preference (local storage)

When you choose a language on the start page, we store that choice locally in your browser (localStorage, key od-lang) so that your next visit lands in your language directly. This information never leaves your device and is not transmitted to us. You can delete it at any time via your browser settings.

No cookies are set and no profiles are built. How we count visits is explained below under “Analytics”.

Links to Google Play

The pre-registration buttons link to the Google Play Store. Clicking takes you to Google; from that point, Google's privacy policy applies. We do not transmit personal data to Google ourselves. The connection is created by your click.

If you pre-register on Google Play, Google is the controller for that processing: policies.google.com/privacy

Analytics

To see how many people visit this website and which pages they come from, we use Cloudflare Web Analytics (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). When you open a page, your browser loads a script from static.cloudflareinsights.com. It sends Cloudflare the page you opened, the referring page (referrer), your browser and operating system type, and the page's loading times. Cloudflare derives your approximate country from your IP address.

No cookies are set, nothing is stored in your browser, and no profiles are built. Cloudflare does not follow you across websites. We only see aggregated figures, never individual visits. Cloudflare acts as our processor (Art. 28 GDPR) under the agreement mentioned above under hosting.

The legal basis is our legitimate interest in privacy-friendly audience measurement (Art. 6(1)(f) GDPR). For transfers to the US, see section 6. If you do not want to be counted, block the script with a content blocker; the website works exactly the same.

(The app measures its usage separately via Firebase Analytics, see section 3.)

3. The app (Capo: Idle Crime Tycoon)

Save data

Your progress is stored locally on your device. No registration with an email or password is required to play. As long as you do not switch on the cloud backup described below, your save data never leaves your device.

Cloud backup, leaderboard and rivals (optional)

The cloud features are off by default. Only once you switch them on in the game's settings under “Cloud Backup” does the app connect to Firebase (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Until then, save data, leaderboard and the rival system stay entirely on your device; the leaderboard then shows computer-controlled families only.

Once switched on, the following is processed:

  • Firebase Authentication (anonymous): Google generates a random, anonymous identifier for your install. It is not linked to your name, email address, or a Google account; it only identifies the install.
  • Cloud Firestore (save data): under that identifier, your save data (progress, resources, settings) is stored in the EU region eur3. Access rules ensure only your device can read or write that record.
  • Cloud Firestore (leaderboard): your leaderboard entry consists of exactly three values: score, time of last submission, and the game archetype you chose, stored under the same anonymous identifier. No name is transmitted, not even a self-chosen one. Other players see your entry as an archetype label plus the last four characters of your identifier (e.g. “Strategist #7b2c”). The leaderboard is readable by all installs that have enabled the cloud features.
  • Cloud Firestore (rival system): so the same rival attack is only resolved once across several devices, the app writes technical records (attack identifier and timestamp) below your own save record. Rivals are computer-controlled; these records contain no data about other people.
  • Cloud Firestore (time check): to guard against a device clock being moved forward, the app fetches and stores a server timestamp under the same identifier.

Legal basis is your consent (Art. 6(1)(a) GDPR), given by actively switching on that toggle. You can withdraw it at any time with future effect by switching it back off; no data is transmitted from that moment on. Data already uploaded is not affected; use “Delete cloud data” (below) to remove it.

Deleting cloud data

The settings contain a “Delete cloud data” entry, available whether or not the cloud backup is currently switched on. In one step it removes your cloud save, your leaderboard entry, the rival records and the time-check record, then closes the anonymous account including any linked Google account connection. Your local save on the device is left untouched.

You do not need to contact us for this. You can of course still exercise your right to erasure under Art. 17 GDPR (section 7) with us at any time.

Linking a Google account (optional)

With the cloud backup switched on, the settings additionally offer “Link with Google”, connecting your anonymous identifier to your Google account. This is voluntary and not required to play. Its only purpose is to let you restore your save after switching devices or reinstalling. Without it, the anonymous identifier is lost with the install.

When you start the flow, Google opens your device's account picker. After you confirm, the app receives the chosen account's standard profile details via Google Sign-In and passes them to Firebase Authentication: Google account identifier, email address, display name and, if present, the profile picture. These are stored with your account at Firebase Authentication. They are not written into your save data, not shown on the leaderboard, and not passed on to other players. We use them solely to recognise your account.

Legal basis is your consent (Art. 6(1)(a) GDPR); you start the flow yourself and can cancel it in the account picker at any time. The link can be undone via “Delete cloud data”, which deletes the account along with the profile details named above.

Usage statistics, crash reports and remote configuration

The app uses three further Firebase services, also from Google Ireland Limited. Unlike the cloud backup above, these are active from first launch:

  • Firebase Analytics: collects anonymised usage events (e.g. which parts of the game are reached) to understand how the game is played and to improve it.
  • Firebase Crashlytics: automatically transmits a technical report on a crash (device model, OS version, code location, anonymous install identifier) so bugs can be fixed.
  • Firebase Remote Config: fetches game balance configuration values from the server at launch. The device transmits a Google-assigned install identifier and technical details (e.g. app and OS version, language). No save data is transmitted.

All three work with a Google-assigned install identifier, not with your name or email address.

Legal basis is our legitimate interest in a working, stable game (Art. 6(1)(f) GDPR).

Notifications

The app can remind you about the game. Two technically different paths are involved:

  • Local reminders: notices such as “Training complete” are scheduled by the game directly on your device. No data is transmitted to us or to Google.
  • Push messages (Firebase Cloud Messaging): for general reminders we send to all players, the app subscribes your device to a topic channel (engagement_reminders) on Firebase Cloud Messaging. Google assigns an install-level identifier (registration token) for this and records which topic channels that device subscribes to. Messages go to all subscribers of the channel; we receive no recipient list from Google and cannot draw conclusions about individuals from it.

On Android 13 and later, the operating system asks your permission before notifications may be shown. You can revoke it at any time in the Android settings for the app; nothing is then displayed. The technical topic subscription happens independently of that permission and ends with uninstalling the app at the latest.

Legal basis for displaying notifications is your consent via the operating system's permission prompt (Art. 6(1)(a) GDPR); for the technical topic subscription, our legitimate interest in being able to inform players about news and running events (Art. 6(1)(f) GDPR).

Advertising

The app shows ads via Google AdMob (Google Ireland Limited). This may process a device-level advertising ID to serve ads and measure their performance.

On first launch, a consent form (Google User Messaging Platform, UMP) asks whether personalised or only non-personalised ads may be shown. Without your consent, only non-personalised ads are shown. You can withdraw or change your choice at any time via “Manage ad consent” in the game’s settings.

Details on Google's processing, including a possible transfer to the US, are in Google's privacy policy: policies.google.com/privacy and the ad partner list: support.google.com/admob/answer/9012903.

Legal basis for non-personalised ads is our legitimate interest in funding the free game (Art. 6(1)(f) GDPR); for personalised ads, your consent (Art. 6(1)(a) GDPR).

Purchases

An optional in-app purchase removes the ad break on city transitions (see Capo). Purchases are handled entirely through Google Play Billing: Google processes payment data (e.g. payment method), not us. We only receive confirmation from Google that a purchase succeeded, and unlock the content in response.

Age

A rating around 12+ is targeted (no blood, no realism, abstracted game systems). The final rating only results from the IARC questionnaire at store submission. If that means the app (also) targets children, additional requirements apply (Google Play Families Policy, Art. 8 GDPR on children's consent).

4. The app SURGE

SURGE is a puzzle game with no account, no cloud and no servers of our own. The app processes personal data only in connection with advertising, and only with your consent.

Game progress and ledger

SURGE stores your progress, settings, your answer to the consent question and the ledger that discloses what each ad you watched earned only locally on your device. None of it is transmitted to us or to third parties. Uninstalling the app deletes this data.

The daily route uses the same seed for every player worldwide. It is derived from the calendar date, not fetched from a server.

Advertising

On first launch, before anything else happens, SURGE asks whether you agree to advertising. If you decline, the ad SDK is never loaded: there is no connection to Google AdMob, and the game remains fully playable. You only forgo the optional rewarded ads.

If you agree, the app shows rewarded ads through Google AdMob (Google Ireland Limited) when you ask for one. This may involve processing the device's advertising ID, the IP address, approximate location derived from the IP address, and technical device and app information, in order to serve ads, measure their performance and prevent fraud. In the EU, the EEA and the United Kingdom, a consent form (Google User Messaging Platform) adds the choice between personalised and non-personalised ads. Until the game has its own setting for this, you withdraw consent by clearing the app's data in Android's settings; SURGE then asks again on the next launch.

The ad revenue Google reports for an ad is shown to you in the app's ledger. That amount is stored on your device and not shared.

For details on Google's processing see Google's privacy policy: policies.google.com/privacy and the list of ad partners: support.google.com/admob/answer/9012903.

The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw it at any time with effect for the future.

No other services

SURGE uses no usage analytics, no crash reporting, no push notifications, no sign-in and no in-app purchases.

Age

SURGE is aimed at players aged 13 and over. The age rating results from the IARC questionnaire at store submission.

5. Retention

We store personal data only for as long as the respective purpose requires. In detail:

  • Server log files of this website: we run the server ourselves and cap the logs with size-based rotation (50 MB total, split across 5 files of 10 MB each); at typical traffic that works out to roughly 18 days; the actual duration varies with visitor volume. They are not evaluated beyond technical operation and attack mitigation.
  • Language preference in the browser: kept until you delete it. It never leaves your device.
  • Analytics (Cloudflare Web Analytics): we only receive aggregated figures. Cloudflare does not store IP addresses for individual visits and deletes the measurement data automatically under its own retention periods.
  • Cloud save, leaderboard entry, rival records and time check (Cloud Firestore): kept until you delete them (via “Delete cloud data” in the game or on request to us). There is no automatic deletion after a fixed period, because the purpose, keeping your progress restorable indefinitely, is by nature open-ended.
  • Anonymous identifier and any linked Google account connection (Firebase Authentication): kept until the account is deleted (via “Delete cloud data” in the game or on request to us).
  • Usage events (Firebase Analytics): our Firebase project is configured to the shortest available periods: event data is deleted after 2 months, user-level data after 14 months. The 14-month period is rolling: it restarts on each new activity of the install in question and therefore ends 14 months after the last activity. Aggregated reports that can no longer be attributed to an individual install are kept beyond that.
  • Crash reports (Firebase Crashlytics): deleted automatically by Google according to its own retention periods.
  • Install identifier (Firebase Remote Config): exists while the app is installed and expires on uninstall.
  • Registration token and topic subscription (Firebase Cloud Messaging): exist while the app is installed; they expire on uninstall or once Google treats the token as stale.
  • Progress, ledger and consent in SURGE: stay on your device and are deleted when you uninstall the app or clear its data in Android's settings.
  • Advertising ID and consent status (Google AdMob / UMP): retention at Google follows Google's own rules. You can reset or delete the advertising ID itself at any time in the Android settings.
  • Purchase data (Google Play Billing): Google stores payment and purchase history according to its own rules and statutory retention obligations. We store no payment data ourselves; we only receive confirmation that a purchase succeeded.
  • Email enquiries: we keep your message for as long as handling it requires, and beyond that only where statutory retention obligations apply.

6. Transfers to third countries and Google's role

We obtain all Google services named in sections 3 and 4 from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) as our contracting party in the EU. Google does, however, process data across its global data centre network, so transfers to the US and other third countries can occur.

Server locations

  • Cloud Firestore: the database is pinned to the European multi-region eur3. Cloud save, leaderboard entry, rival records and time check therefore reside on servers inside the EU. A transfer to a third country can still occur in the course of support and maintenance access by Google.
  • Firebase Authentication, Firebase Analytics, Firebase Crashlytics, Firebase Cloud Messaging, Firebase Remote Config, Google AdMob and Google Play Billing: no European region is configured for these services. Processing on servers in the US is possible and must be assumed.
  • Hosting of this website: the server is in Helsinki (EU). The Cloudflare, Inc. (US) CDN and DDoS protection in front of it routes requests via the nearest data centre, so processing outside the EU cannot be ruled out here either. The same applies to audience measurement with Cloudflare Web Analytics.

Legal basis for the transfer

For transfers to the US we rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework of 10 July 2023 (Art. 45 GDPR), where the recipient is certified under it, which applies to Google LLC and Cloudflare, Inc. In addition, and for transfers to other third countries, the European Commission's standard contractual clauses apply (Art. 46(2)(c) GDPR) as part of the respective terms. The current certification list is at dataprivacyframework.gov.

Despite these safeguards, access to transferred data by US authorities cannot be entirely ruled out.

Controllership

For Firebase Authentication, Cloud Firestore, Firebase Analytics, Firebase Crashlytics, Firebase Cloud Messaging and Firebase Remote Config, Google acts as our processor under Art. 28 GDPR, on the basis of the data processing terms that form part of the Firebase terms of service: firebase.google.com/terms/data-processing-terms.

For Google AdMob and Google Play Billing, Google also processes data for its own purposes and is a controller in its own right in that respect. Google's controller terms apply to ad delivery: business.safety.google/adscontrollerterms. You can therefore also exercise your data subject rights for these services directly against Google.

For Google Sign-In, both apply: we are responsible for linking the account to your save data; Google remains responsible for your Google account itself (policies.google.com/privacy).

7. Your rights

You have the right at any time to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), object to processing based on legitimate interests (Art. 21), and withdraw consent with future effect (Art. 7(3) GDPR).

To exercise these, contact webmaster@regsus.de. For your cloud data from the game there is a shortcut: “Delete cloud data” in the app’s settings removes it immediately and completely (see section 3).

8. Right to complain

You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR). Usually this is the authority of your place of residence or the authority responsible for the controller; for us (based in Munich, Bavaria) that is:

Bayerisches Landesamt für Datenschutzaufsicht (Bavarian Data Protection Authority)
Promenade 27, 91522 Ansbach, Germany
www.lda.bayern.de

9. Changes

We will update this policy whenever the processing changes, in particular at the store launch, once the final age rating and the consent flow are confirmed against the real build. The current version is always on this page.

Capo Studio Legal notice Privacy
Overdraft · Ink / Paper / Red