Privacy Policy
Last updated: 3 August 2026
At Lamma, we respect your privacy and are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (DSGVO / GDPR) and the German Federal Data Protection Act (BDSG). This policy explains what we collect, why, and how you can exercise your rights.
1. Data Controller (Verantwortlicher)
Mohammad Areesheh
Connollystr. 3
80809 München, Deutschland
Email: lamma@areesheh.com
2. Data We Collect and Legal Basis
A. Email Sign-in Data (Clerk)
When you choose to link Premium to your email address on the web or mobile, we use the Clerk service (Clerk Inc., 548 Market St PMB 75011, San Francisco, CA 94104, USA) to process sign-in via a one-time code (OTP). Clerk retains your email address and an associated user ID for as long as your account is active.
- Purpose: Link your Premium subscription to a unified account that works across all your devices and platforms.
- Legal basis: Performance of a contract (Art. 6(1)(b) GDPR).
- Clerk Privacy Policy: clerk.com/privacy
B. Subscription and Purchase Data (RevenueCat)
Premium subscriptions and purchases are managed via the RevenueCat service (RevenueCat Inc., 633 Tasman Drive, Sunnyvale, CA 94089, USA). The app sends RevenueCat your device identifier or the user ID linked to your Clerk account, along with transaction information received from the store.
- Purpose: Verify Premium status, manage subscriptions and passes, and restore purchases.
- Legal basis: Performance of a contract (Art. 6(1)(b) GDPR).
- RevenueCat Privacy Policy: revenuecat.com/privacy
C. Web Payment Processing (Paddle)
When you purchase via the website, the payment is processed by Paddle (Paddle.com Market Limited, Core B, Block 71, The Plaza, Park West, Dublin 12, Ireland). Paddle acts as the Merchant of Record and handles the collection and processing of payment data (credit cards and others) and the remittance of applicable taxes. We neither receive nor store any payment data directly.
- Purpose: Complete purchases, issue invoices, and remit VAT.
- Legal basis: Performance of a contract (Art. 6(1)(b) GDPR).
- Paddle Privacy Policy: paddle.com/legal/privacy
D. Payment Processing via Apple App Store and Google Play
When you purchase from the App Store on iOS or Android, Apple or Google handles the payment in accordance with their terms. We do not receive your card details or banking information.
- Apple Privacy Policy: apple.com/legal/privacy
- Google Privacy Policy: policies.google.com/privacy
E. Game Content and Usage Data (Supabase)
We use Supabase (Supabase Inc., 970 16th Street, San Francisco, CA 94107, USA) as our backend infrastructure to manage game content and collect anonymous, aggregated data about how the app is used (such as the categories played and the number of sessions) in order to improve the user experience and develop new content.
- Purpose: To deliver game content and analyze usage patterns to improve the app.
- Legal basis: Legitimate interest (Art. 6(1)(f) GDPR).
- Supabase Privacy Policy: supabase.com/privacy
We also store in Supabase a record of your active passes (pass type, purchase and expiry time, transaction ID, platform, and store) linked to your RevenueCat/Clerk account identifier. The purpose is to grant your timed access across your devices and even offline, and to restore your passes when you sign in.
- Purpose: Activate time-limited passes, unify access across devices, and work offline.
- Legal basis: Performance of a contract (Art. 6(1)(b) GDPR).
F. New Category Notifications (Expo Push Notifications)
If you enable new-category notifications on iOS or Android, we store your device's Expo Push Token in Supabase together with platform, locale, app version, enabled status, and last-seen timestamp. We use this token only to notify you when new categories are published. This feature is not available on the web.
- Purpose: To send optional notifications when new categories are available.
- Legal basis: Your consent (Art. 6(1)(a) GDPR). You can turn notifications off in your system settings at any time.
- Expo Privacy Policy: expo.dev/privacy
G. Team Devices via QR Code (Companion Mode)
Companion mode lets each player use their own phone as a controller by scanning a QR code from the game screen. This opens playlamma.com/c in their phone's browser — nothing is installed. When you join, we process:
- Display name and avatar: What you type in yourself before entering (up to 16 characters) so your team can recognise you on screen. Pick anything you like — it does not have to be your real name.
- Room code, team number, and player id: To connect your device to the correct room and to restore your seat if the connection drops.
- An anonymous realtime account: A technical, anonymous Supabase account is created per participant to secure the room's channel. It is not linked to your email or to any other account of yours.
Team chat: Your team's messages travel through Supabase realtime servers to your teammates' screens only. They are not stored in our database or our logs: the host device keeps them in memory for the duration of the match and they are gone entirely once it ends. The opposing team never sees them.
- Purpose: To run the group play session you requested and to let a team coordinate.
- Legal basis: Performance of a contract (Art. 6(1)(b) GDPR).
- Duration: Room and player data is deleted automatically when the room expires; see Section 4.
H. Online Play and Voice Chat (when enabled)
When remote play is enabled, the same processing described in (G) applies to online rooms. If you join a voice chat inside a room, your audio is carried by Agora (Agora Lab, Inc., 2804 Mission College Blvd, Santa Clara, CA 95054, USA) to broadcast it to the other players in that room.
- We do not record audio: It is transmitted live only — we do not record, store, analyse, or use it for any other purpose.
- Microphone permission: Requested the first time you use it. You may decline or revoke it in your system settings and keep playing without voice.
- Purpose: To enable voice chat during remote play.
- Legal basis: Performance of a contract (Art. 6(1)(b) GDPR), with microphone access based on your consent (Art. 6(1)(a) GDPR).
- Agora Privacy Policy: agora.io/en/privacy-policy
I. Creator Codes and Referral Links
If you enter a Creator Code during website checkout where available, we process that code to attribute the sale to the respective creator for commission purposes. Creator Codes do not unlock Premium in the iOS app and cannot be redeemed for App Store access.
Additionally, if you click on a referral or creator link to visit our website, we collect basic technical data, including your device's browser information (user agent) and a cryptographically hashed version of your IP address (which cannot be easily traced back to you). The same technical processing applies to room join links (/j/) and team device links (/c/), except that those are used to connect you to the right room rather than to attribute a commission.
- Purpose: To manage affiliate attribution and prevent referral fraud.
- Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) and Legitimate interest (Art. 6(1)(f) GDPR) — managing our affiliate program and fraud prevention.
J. Product Analytics (PostHog) — only with your consent
To improve the game, we may use the PostHog product-analytics service to measure how app features are used (such as match starts, categories, and checkout steps). This analytics is disabled by default and only runs after your explicit consent, and you can withdraw your consent at any time in the app settings.
When enabled, your data is hosted on PostHog servers within the European Union, and we configure the service for data minimisation: IP-based geolocation disabled, session replay disabled, surveys disabled, and no automatic capture of taps or screens. We do not send PostHog any names, email addresses, question/answer text, or room codes. Events are tied to an anonymous per-install identifier and, once you sign in, to your account identifier (not your email).
The team device page (/c/): This page measures only its own technical performance — join success, dropped connections, and send failures — so we know whether controllers are working. Because a player arrives here by scanning a QR code and has no settings screen to configure, this page writes no persistent identifier to your device: a random identifier is created in memory and disappears when the page closes. Names, avatars, chat messages, and the room code are never included in these measurements.
- Purpose: Understand feature usage and improve the product.
- Legal basis: Your consent (Art. 6(1)(a) GDPR and Section 25 TDDDG). You can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- PostHog Privacy Policy: posthog.com/privacy
3. Transfer of Data Outside the European Union
The servers of Clerk, RevenueCat, Expo, Supabase, and Agora are located in the United States. This transfer is based on the European Commission's Standard Contractual Clauses pursuant to Art. 46 GDPR. You can find details of the safeguards in each service's privacy policy. PostHog analytics data, by contrast, is hosted within the European Union; however, PostHog is a US company and any onward access is governed by the same Standard Contractual Clauses.
4. Data Retention Period
- Clerk data: Retained for as long as your account is active. You can request deletion at any time.
- RevenueCat data: Retained in accordance with RevenueCat's policy for tax and legal compliance purposes.
- Paddle data: Retained in accordance with applicable EU tax and accounting requirements (typically seven years).
- Supabase data: Game analytics and creator code usage are retained as long as necessary for the stated purposes, usually in an aggregated or anonymized format where possible.
- Pass records: Pass records (including expired ones) are retained as part of transaction records for accounting and legal compliance.
- Push notification tokens: Retained while notifications are enabled; invalid tokens are disabled when detected.
- Game rooms and team devices: Every room has a set expiry time. The room's data, the associated player records (display name and avatar), and the anonymous accounts used for the realtime connection are deleted after it expires. Chat messages are never stored in the first place, so no retention period applies to them.
- PostHog data: Analytics events (when enabled with your consent) are retained in accordance with PostHog's policy; withdrawing consent stops future collection.
- Local game data: Stored only on your device and deleted when the app is uninstalled.
5. No Sale of Data
We never sell your personal data, nor do we share it with third parties for advertising purposes.
6. Data Security
In accordance with Art. 32 GDPR we take appropriate technical and organisational measures to protect your data, including: end-to-end TLS/HTTPS encryption of all traffic, private per-room realtime channels that only that room's participants can reach, row-level security rules in the database, and administrative access limited to the narrowest necessary scope. We never receive or store payment card data at any point.
That said, no transmission over the internet can be guaranteed absolutely secure. If a breach occurs that is likely to result in a high risk to your rights, we will notify the competent authority and inform you in accordance with Art. 33 and 34 GDPR.
7. No Automated Decision-Making
We do not subject you to any decision based solely on automated processing that produces legal effects or similarly significantly affects you, and we do not carry out profiling within the meaning of Art. 22 GDPR.
8. Your Rights Under GDPR
You have the right, at any time, to:
- Right of access (Art. 15 GDPR): Know what data we hold about you.
- Right to rectification (Art. 16 GDPR): Correct inaccurate data.
- Right to erasure (Art. 17 GDPR): Request deletion of your data ("right to be forgotten").
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR).
- Right to object (Art. 21 GDPR): Object to processing based on legitimate interest.
- Cancel subscription: You can cancel your monthly subscription at any time via the store settings (App Store or Google Play) or the web dashboard.
- Withdraw analytics consent: You can turn product analytics (PostHog) on or off at any time in the app settings.
To exercise any of these rights, contact us at: lamma@areesheh.com
You also have the right to lodge a complaint with the competent data protection authority. In Germany: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.
9. Users in Saudi Arabia and the Gulf
If you reside in the Kingdom of Saudi Arabia, your data is also processed in accordance with the Saudi Personal Data Protection Law (PDPL) and its implementing regulations. The PDPL gives you the right to be informed that your data is being collected, to access it, to request its correction or destruction, and to request a copy of it in a readable format. Because our servers and providers are located outside the Kingdom, your data is transferred for the purpose of delivering the service you requested and under contractual safeguards with each provider, as described in Section 3.
To exercise these rights, use the same address: lamma@areesheh.com. You also have the right to lodge a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA). The same principle applies to users elsewhere in the Gulf, subject to the data protection laws in force in their country of residence.
10. Children's Privacy
Lamma is a family-friendly game suitable for all ages. We do not knowingly collect personal data from children under the age of 16 without parental consent. If you become aware that a child's data has been collected without consent, please contact us immediately so we can delete it.
In companion mode and group play, we encourage parents to have children pick a display name that does not identify them — the name is entirely free, does not have to be real, and is visible to the other players in the room.
11. Storage on Your Device (Cookies and Similar Technologies)
Under Section 25 of the German Telecommunications and Digital Services Data Protection Act (TDDDG) and Article 5(3) of the ePrivacy Directive, any access to information stored on your device (cookies, LocalStorage, IndexedDB/OPFS) requires your consent — unless the storage is strictly necessary to provide the service you have explicitly requested.
We use strictly necessary storage mechanisms by default, and we do not show ads or track you for marketing. We do not collect product analytics (PostHog) unless you explicitly consent, and it remains disabled until you agree. For that reason we do not ask for cookie consent for strictly necessary storage, but you are entitled to know exactly what we store:
a. Local Game Storage (necessary)
- LocalStorage — game settings: audio, language, and display preferences. Legal basis: necessary to provide the service.
- LocalStorage — database lock (lamma:web-db-lock): prevents the game from being opened in two browser tabs at once, which would corrupt your saved data. Legal basis: necessary to provide the service.
- OPFS / IndexedDB — question database: stores the category catalog, questions, and your play progress locally so the game works offline. Legal basis: necessary to provide the service.
These items stay on your device and are never sent to our servers. You can delete them at any time through your browser settings.
b. Team Device Page Storage (necessary)
When you open the team device page (/c/) on your phone, these are the only items stored in your browser:
- lamma-ctrl-profile: the display name and avatar you chose, so you do not have to retype them for every match.
- Room session token (lamma-ctrl:<code>:<team>): lets you reclaim your seat if the connection drops or the tab is closed.
- lamma-ctrl-gate-bypass: remembers — for this session only — that you chose to continue despite the warning that you are inside an in-app browser.
All of these are strictly necessary to run the controller you asked for, and none is used for tracking. This page also writes no analytics identifier to your device: the identifier used for performance measurement stays in memory and disappears when the page closes.
c. Clerk Sign-In (only when you request it)
When you click "Link Premium" or "Sign In", we load the Clerk library, which may set cookies and LocalStorage items needed to authenticate you and manage your session. This load happens only when you explicitly request sign-in, and is necessary to perform the contract for the service you requested.
d. Paddle Checkout (only when you request it)
When you click "Subscribe", the Paddle checkout iframe opens. Paddle may set cookies strictly necessary to complete the payment and prevent fraud. This only happens when you start a purchase.
e. PostHog Analytics (only after your consent)
If you consent to product analytics, PostHog stores an anonymous identifier on your device to link events together. This happens only after your explicit consent, and you can turn it off at any time in the app settings. This does not apply to the team device page (/c/), which writes no persistent identifier at all, as described above.
What we do NOT use: no Google Analytics, no Meta Pixel, no ads, and we do not share your browsing data with third parties for marketing purposes. Product analytics (PostHog) runs only if you enable it yourself with your consent.
Fonts and external files: The fonts on our pages are served from our own servers, not from Google Fonts or any external delivery network. That means simply opening a page does not send your IP address to any third party.
12. Amendments to This Policy
We may update this policy when adding new services or changing our practices. The last update date will be shown at the top of the page. In the event of any material change affecting your interests, we will notify you via the app or email where available.
13. Contact Us
For any inquiry or request related to privacy:
lamma@areesheh.com