Privacy Policy – Zero Zone

Last updated: June 11, 2026. Controller under GDPR:

Lukas Ulbrich / RCR Interactive
Kuhlweinstraße 6
28359 Bremen, Germany
rcrinteractive@gmail.com

1. Scope and Minimum Age

This policy applies to the Zero Zone app (iOS and Android). The app is intended for users aged 13 and older. Under GDPR Art. 8, users under 16 require parental or guardian consent for consent-based data processing (Analytics, Ads, Push Notifications).

2. Data We Process

a) Location Data (GPS)

The core function of the app is run tracking. We access device location in the foreground and — while an active run session is in progress — in the background. Raw GPS data is used solely to calculate distance, route, and pace. The leaderboard displays a city tag only, never exact coordinates. You are not required to place your in-game base at your home address. Legal basis: Art. 6(1)(b) GDPR (contract performance).

b) Account Data

Sign-in is provided via Google Sign-In or (on iOS) Sign in with Apple. Your name and email address are transmitted from Google or Apple to Firebase Authentication and stored in our database. Legal basis: Art. 6(1)(b) GDPR.

c) Game Progress and Profile Data

We store the following in Firebase Firestore: player profile (display name, avatar selection, city tag), base data (hex coordinates), claimed territory (hex indices), run history (distance, duration, route, timestamp), battle log, and leaderboard entries. Legal basis: Art. 6(1)(b) GDPR.

d) Usage and Crash Data

With your consent, we collect anonymized usage events (Firebase Analytics, e.g. screen views and in-game actions) and crash reports (Firebase Crashlytics). Both services can be disabled at any time under Settings → Privacy in the app. Legal basis: Art. 6(1)(a) GDPR.

e) Advertising (Google AdMob)

The app shows rewarded ads only. We have deliberately chosen non-personalized advertising: no advertising identifier (IDFA/AAID) is read, no ATT prompt is shown, and no cross-device tracking is performed. Ad consent is requested on first launch via the UMP Consent SDK and can be withdrawn at any time under Settings → Privacy Options. Legal basis: Art. 6(1)(a) GDPR.

f) Push Notifications (FCM)

If you allow push notifications, we store a device token (Firebase Cloud Messaging) in our database. It is used exclusively to deliver game-relevant notifications (e.g. attacks on your territory). You can disable notifications at any time in your device's system settings. Legal basis: Art. 6(1)(a) GDPR.

g) In-App Purchases

Purchases are processed entirely by the Apple App Store or Google Play. Payment and purchase data is handled exclusively by Apple or Google. We receive only an anonymized purchase receipt for server-side validation. Legal basis: Art. 6(1)(b) GDPR.

h) Map Data (Stadia Maps)

In-app maps are loaded via Stadia Maps. Your IP address is technically transmitted to Stadia Maps servers as part of this process. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing map functionality).

i) Local Device Storage

For offline functionality (GPS buffer during a run, settings, consent status) data is stored locally on your device. This data does not leave your device until the app syncs over an active connection.

j) Health / Step Data (Apple Health / Health Connect)

With your explicit consent, the app reads your step count from Apple Health (iOS) or Google Health Connect (Android) to convert your everyday movement outside tracked runs into in-game resources ("Health Sync"). We read steps only — no other health data — and write nothing back. Step values are processed only briefly to compute the reward on our server; we store only the resulting capped resource credit and limiting counters (e.g. the last collection time and a daily allowance), not your health history. The permission is optional and can be revoked at any time in your device's system or health settings. Legal basis: Art. 6(1)(a) GDPR (consent).

3. Data Retention

4. Third Parties

5. International Data Transfers

Firebase data (Firestore, Auth, Functions) is processed in EU region europe-west3 (Frankfurt). Other Google services (AdMob, Analytics) may involve transfers outside the EU; Google LLC is certified under the EU–US Data Privacy Framework. Apple services may similarly involve US-side processing under standard contractual clauses.

6. Your Rights

Under GDPR you have the following rights:

7. Withdrawing Consent

You may withdraw consent for Analytics, Crashlytics, and advertising at any time via Settings → Privacy Options in the app. This does not affect the lawfulness of processing carried out before withdrawal.

8. Changes

For material changes to this policy we will notify you via the app. The date at the top reflects the latest revision.

9. Contact

Privacy questions: rcrinteractive@gmail.com