Last updated: August 29, 2026. Controller under GDPR:
Lukas Ulbrich / RCR Interactive
Kuhlweinstraße 6
28359 Bremen, Germany
rcrinteractive@gmail.com
This policy applies to the Zero Zone app (iOS and Android). The app is intended for users aged 13 and older. Under GDPR Art. 8, users under 16 require parental or guardian consent for consent-based data processing (Analytics, Ads, Push Notifications).
The core function of the app is run tracking. We access device location in the foreground and — while an active run session is in progress — in the background. GPS data is used to calculate distance, route, and pace, to validate the plausibility of a run on our server, and for location-based game actions you explicitly start. A live position is never shared with other players. The general leaderboard displays a city tag only, never exact coordinates. You are not required to place your in-game base at your home address. Legal basis: Art. 6(1)(b) GDPR (contract performance).
Sign-in is provided via Google Sign-In or (on iOS) Sign in with Apple. Your name and email address are transmitted from Google or Apple to Firebase Authentication and stored in our database. Legal basis: Art. 6(1)(b) GDPR.
We store the following in Firebase Firestore: player profile (display name, avatar selection, city tag), base data (hex coordinates), claimed territory (hex indices), run history (distance, duration, route, timestamp), battle log, community routes and related game actions, and leaderboard entries. Legal basis: Art. 6(1)(b) GDPR.
With your consent, we collect anonymized usage events (Firebase Analytics, e.g. screen views and in-game actions) and crash reports (Firebase Crashlytics). Both services can be disabled at any time under Settings → Privacy in the app. Legal basis: Art. 6(1)(a) GDPR.
The app shows rewarded ads only. We have deliberately chosen non-personalized advertising: no advertising identifier (IDFA/AAID) is read, no ATT prompt is shown, and no cross-device tracking is performed. Ad consent is requested on first launch via the UMP Consent SDK and can be withdrawn at any time under Settings → Privacy Options. Legal basis: Art. 6(1)(a) GDPR.
If you allow push notifications, we store a device token (Firebase Cloud Messaging) in our database. It is used exclusively to deliver game-relevant notifications (e.g. attacks on your territory). You can disable notifications at any time in your device's system settings. Legal basis: Art. 6(1)(a) GDPR.
Purchases are processed entirely by the Apple App Store or Google Play. Payment and purchase data is handled exclusively by Apple or Google. We receive only an anonymized purchase receipt for server-side validation. Legal basis: Art. 6(1)(b) GDPR.
In-app maps are loaded via Stadia Maps. Your IP address is technically transmitted to Stadia Maps servers as part of this process. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing map functionality).
For offline functionality (GPS buffer during a run, settings, consent status) data is stored locally on your device. This data does not leave your device until the app syncs over an active connection.
With your explicit consent, the app reads your step count from Apple Health (iOS) or Google Health Connect (Android) to convert your everyday movement outside tracked runs into in-game resources ("Health Sync"). We read steps only — no other health data — and write nothing back. Step values are processed only briefly to compute the reward on our server; we store only the resulting capped resource credit and limiting counters (e.g. the last collection time and a daily allowance), not your health history. The permission is optional and can be revoked at any time in your device's system or health settings. Legal basis: Art. 6(1)(a) GDPR (consent).
When you explicitly publish one of your own run routes, a technically simplified route geometry with its start and finish trimmed is made visible to signed-in players together with your chosen title, difficulty, fixed highlight categories, and aggregated usage values. The original run ID, timestamps, and exact start and finish points are not published. Published routes can be reported and archived by you.
If you voluntarily hide an in-game artifact along a route, the exact depot position, reservations, search proof, and transfer history are processed on our server. The exact position is not publicly visible; it is provided only to the owner and, as part of a personal time-limited search assignment, to the assigned player. No other player's live position is shown. Legal basis: Art. 6(1)(b) GDPR.
If you voluntarily create a field cache, we process the title you choose, your riddle text, the difficulty rating and the exact real-world position of the cache. Depending on the precision mode you select, other players see either a sector or the position itself; your display name is visible as the creator. When placing a cache you explicitly confirm that the location is publicly accessible, permitted and safe.
On a find we process the position of the finding device, the server-measured distance to the cache, the time, failed attempts and the verification of the entered code. The code itself is stored as a hash only. No live position is ever shared with other players.
For safety and moderation we also process reports (with a fixed set of reasons), review notes, moderation decisions, anomaly signals, your list of hidden creators and the version of the terms of use you accepted. Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest in safety, abuse prevention and moderation); for the terms acceptance additionally Art. 6(1)(c) GDPR.
Firebase data (Firestore, Auth, Functions) is processed in EU region europe-west3 (Frankfurt). Other Google services (AdMob, Analytics) may involve transfers outside the EU; Google LLC is certified under the EU–US Data Privacy Framework. Apple services may similarly involve US-side processing under standard contractual clauses.
Under GDPR you have the following rights:
You may withdraw consent for Analytics, Crashlytics, and advertising at any time via Settings → Privacy Options in the app. This does not affect the lawfulness of processing carried out before withdrawal.
For material changes to this policy we will notify you via the app. The date at the top reflects the latest revision.
Privacy questions: rcrinteractive@gmail.com