Last updated: October 5, 2026
The German version is the authoritative one. This translation is provided for convenience. In case of any discrepancy, the German privacy policy prevails.
The controller within the meaning of the GDPR is:
RegSus Consulting GmbH
Cosimastr. 121, 81925 München, Germany
Email: webmaster@regsus.de
A data protection officer is not legally required given the company's size (§ 38 BDSG).
When you visit this website, the hosting provider automatically processes information your browser transmits (server log files): page requested and time of access, data volume transferred and status, browser type and version, operating system, referrer URL, and IP address.
The legal basis is Art. 6(1)(f) GDPR, the legitimate interest in operating the website securely and without errors. This data is not merged with other data sources.
Hosting provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (server location Helsinki, EU). Cloudflare, Inc. sits in front as a content-delivery and DDoS-protection service, routing requests before they reach our server. We have a data processing agreement under Art. 28 GDPR with both, based on each provider's standard terms.
This website loads all fonts from our own server. There is no connection to Google Fonts or any other external provider, and no IP address is transmitted to third parties.
When you choose a language on the start page, we store that choice locally in your browser (localStorage, key od-lang) so that your next visit lands in your language directly. This information never leaves your device and is not transmitted to us. You can delete it at any time via your browser settings.
No cookies are set and no profiles are built. How we count visits is explained below under “Analytics”.
The pre-registration buttons link to the Google Play Store. Clicking takes you to Google; from that point, Google's privacy policy applies. We do not transmit personal data to Google ourselves. The connection is created by your click.
If you pre-register on Google Play, Google is the controller for that processing: policies.google.com/privacy
To see how many people visit this website and which pages they come from, we use Cloudflare Web Analytics (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). When you open a page, your browser loads a script from static.cloudflareinsights.com. It sends Cloudflare the page you opened, the referring page (referrer), your browser and operating system type, and the page's loading times. Cloudflare derives your approximate country from your IP address.
No cookies are set, nothing is stored in your browser, and no profiles are built. Cloudflare does not follow you across websites. We only see aggregated figures, never individual visits. Cloudflare acts as our processor (Art. 28 GDPR) under the agreement mentioned above under hosting.
The legal basis is our legitimate interest in privacy-friendly audience measurement (Art. 6(1)(f) GDPR). For transfers to the US, see section 6. If you do not want to be counted, block the script with a content blocker; the website works exactly the same.
(The app measures its usage separately via Firebase Analytics, see section 3.)
Your progress is stored locally on your device. No registration with an email or password is required to play. As long as you do not switch on the cloud backup described below, your save data never leaves your device.
The cloud features are off by default. Only once you switch them on in the game's settings under “Cloud Backup” does the app connect to Firebase (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Until then, save data, leaderboard and the rival system stay entirely on your device; the leaderboard then shows computer-controlled families only.
Once switched on, the following is processed:
eur3. Access rules ensure only your device can read or write that record.Legal basis is your consent (Art. 6(1)(a) GDPR), given by actively switching on that toggle. You can withdraw it at any time with future effect by switching it back off; no data is transmitted from that moment on. Data already uploaded is not affected; use “Delete cloud data” (below) to remove it.
The settings contain a “Delete cloud data” entry, available whether or not the cloud backup is currently switched on. In one step it removes your cloud save, your leaderboard entry, the rival records and the time-check record, then closes the anonymous account including any linked Google account connection. Your local save on the device is left untouched.
You do not need to contact us for this. You can of course still exercise your right to erasure under Art. 17 GDPR (section 7) with us at any time.
With the cloud backup switched on, the settings additionally offer “Link with Google”, connecting your anonymous identifier to your Google account. This is voluntary and not required to play. Its only purpose is to let you restore your save after switching devices or reinstalling. Without it, the anonymous identifier is lost with the install.
When you start the flow, Google opens your device's account picker. After you confirm, the app receives the chosen account's standard profile details via Google Sign-In and passes them to Firebase Authentication: Google account identifier, email address, display name and, if present, the profile picture. These are stored with your account at Firebase Authentication. They are not written into your save data, not shown on the leaderboard, and not passed on to other players. We use them solely to recognise your account.
Legal basis is your consent (Art. 6(1)(a) GDPR); you start the flow yourself and can cancel it in the account picker at any time. The link can be undone via “Delete cloud data”, which deletes the account along with the profile details named above.
The app uses three further Firebase services, also from Google Ireland Limited. Unlike the cloud backup above, these are active from first launch:
All three work with a Google-assigned install identifier, not with your name or email address.
Legal basis is our legitimate interest in a working, stable game (Art. 6(1)(f) GDPR).
The app can remind you about the game. Two technically different paths are involved:
engagement_reminders) on Firebase Cloud Messaging. Google assigns an install-level identifier (registration token) for this and records which topic channels that device subscribes to. Messages go to all subscribers of the channel; we receive no recipient list from Google and cannot draw conclusions about individuals from it.On Android 13 and later, the operating system asks your permission before notifications may be shown. You can revoke it at any time in the Android settings for the app; nothing is then displayed. The technical topic subscription happens independently of that permission and ends with uninstalling the app at the latest.
Legal basis for displaying notifications is your consent via the operating system's permission prompt (Art. 6(1)(a) GDPR); for the technical topic subscription, our legitimate interest in being able to inform players about news and running events (Art. 6(1)(f) GDPR).
The app shows ads via Google AdMob (Google Ireland Limited). This may process a device-level advertising ID to serve ads and measure their performance.
On first launch, a consent form (Google User Messaging Platform, UMP) asks whether personalised or only non-personalised ads may be shown. Without your consent, only non-personalised ads are shown. You can withdraw or change your choice at any time via “Manage ad consent” in the game’s settings.
Details on Google's processing, including a possible transfer to the US, are in Google's privacy policy: policies.google.com/privacy and the ad partner list: support.google.com/admob/answer/9012903.
Legal basis for non-personalised ads is our legitimate interest in funding the free game (Art. 6(1)(f) GDPR); for personalised ads, your consent (Art. 6(1)(a) GDPR).
An optional in-app purchase removes the ad break on city transitions (see Capo). Purchases are handled entirely through Google Play Billing: Google processes payment data (e.g. payment method), not us. We only receive confirmation from Google that a purchase succeeded, and unlock the content in response.
A rating around 12+ is targeted (no blood, no realism, abstracted game systems). The final rating only results from the IARC questionnaire at store submission. If that means the app (also) targets children, additional requirements apply (Google Play Families Policy, Art. 8 GDPR on children's consent).
SURGE is a puzzle game with no account, no cloud and no servers of our own. The app processes personal data only in connection with advertising, and only with your consent.
SURGE stores your progress, settings, your answer to the consent question and the ledger that discloses what each ad you watched earned only locally on your device. None of it is transmitted to us or to third parties. Uninstalling the app deletes this data.
The daily route uses the same seed for every player worldwide. It is derived from the calendar date, not fetched from a server.
On first launch, before anything else happens, SURGE asks whether you agree to advertising. If you decline, the ad SDK is never loaded: there is no connection to Google AdMob, and the game remains fully playable. You only forgo the optional rewarded ads.
If you agree, the app shows rewarded ads through Google AdMob (Google Ireland Limited) when you ask for one. This may involve processing the device's advertising ID, the IP address, approximate location derived from the IP address, and technical device and app information, in order to serve ads, measure their performance and prevent fraud. In the EU, the EEA and the United Kingdom, a consent form (Google User Messaging Platform) adds the choice between personalised and non-personalised ads. Until the game has its own setting for this, you withdraw consent by clearing the app's data in Android's settings; SURGE then asks again on the next launch.
The ad revenue Google reports for an ad is shown to you in the app's ledger. That amount is stored on your device and not shared.
For details on Google's processing see Google's privacy policy: policies.google.com/privacy and the list of ad partners: support.google.com/admob/answer/9012903.
The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw it at any time with effect for the future.
SURGE uses no usage analytics, no crash reporting, no push notifications, no sign-in and no in-app purchases.
SURGE is aimed at players aged 13 and over. The age rating results from the IARC questionnaire at store submission.
We store personal data only for as long as the respective purpose requires. In detail:
We obtain all Google services named in sections 3 and 4 from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) as our contracting party in the EU. Google does, however, process data across its global data centre network, so transfers to the US and other third countries can occur.
eur3. Cloud save, leaderboard entry, rival records and time check therefore reside on servers inside the EU. A transfer to a third country can still occur in the course of support and maintenance access by Google.For transfers to the US we rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework of 10 July 2023 (Art. 45 GDPR), where the recipient is certified under it, which applies to Google LLC and Cloudflare, Inc. In addition, and for transfers to other third countries, the European Commission's standard contractual clauses apply (Art. 46(2)(c) GDPR) as part of the respective terms. The current certification list is at dataprivacyframework.gov.
Despite these safeguards, access to transferred data by US authorities cannot be entirely ruled out.
For Firebase Authentication, Cloud Firestore, Firebase Analytics, Firebase Crashlytics, Firebase Cloud Messaging and Firebase Remote Config, Google acts as our processor under Art. 28 GDPR, on the basis of the data processing terms that form part of the Firebase terms of service: firebase.google.com/terms/data-processing-terms.
For Google AdMob and Google Play Billing, Google also processes data for its own purposes and is a controller in its own right in that respect. Google's controller terms apply to ad delivery: business.safety.google/adscontrollerterms. You can therefore also exercise your data subject rights for these services directly against Google.
For Google Sign-In, both apply: we are responsible for linking the account to your save data; Google remains responsible for your Google account itself (policies.google.com/privacy).
You have the right at any time to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), object to processing based on legitimate interests (Art. 21), and withdraw consent with future effect (Art. 7(3) GDPR).
To exercise these, contact webmaster@regsus.de. For your cloud data from the game there is a shortcut: “Delete cloud data” in the app’s settings removes it immediately and completely (see section 3).
You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR). Usually this is the authority of your place of residence or the authority responsible for the controller; for us (based in Munich, Bavaria) that is:
Bayerisches Landesamt für Datenschutzaufsicht (Bavarian Data Protection Authority)
Promenade 27, 91522 Ansbach, Germany
www.lda.bayern.de
We will update this policy whenever the processing changes, in particular at the store launch, once the final age rating and the consent flow are confirmed against the real build. The current version is always on this page.