Privacy Policy for SkimmIQ

Effective Date: September 2, 2026

1. Scope and Controller

This Privacy Policy explains how personal data is processed in connection with the SkimmIQ mobile application (the “App”) and the skimmiq.com website (the “Website”). The App and Website are described separately below so you can quickly find the information relevant to the service you use.

The data controller is Pawel Faber, operator of SkimmIQ, based in Warsaw, Poland. You can contact the controller at pawel@skimmiq.com. No Data Protection Officer has been appointed; privacy requests may be sent directly to that address.

2. SkimmIQ Mobile App

Data processed by the App

The core puzzle does not require your real name, email address, phone number, or precise GPS location. Optional public, account, analytics, advertising, purchase, and support features may process the following information:

We use this information to provide the requested App features, maintain purchases and Premium status, publish optional Leaderboard results, apply age-appropriate safeguards, measure and improve reliability, prevent abuse and fraud, display and measure advertising where permitted, and answer support reports.

Depending on the feature, processing is based on performance of the service you request, compliance with legal obligations, your consent where it is requested, and our legitimate interests in operating, securing, supporting, and improving SkimmIQ. Optional consent can be changed through the available privacy or platform settings.

If you choose a public nickname, use an alias that does not contain your real name, contact details, or other identifying information.

3. SkimmIQ Website

Website cookies and analytics

The Website's Privacy settings separate services into three categories. Necessary services, including session security, CSRF protection, secure form handling, and the cookie that remembers your privacy choices for up to 180 days, are always active because they are required to operate and protect the Website. Analytics and External services are optional and can be allowed or rejected independently.

Google Analytics storage and full analytics measurement remain disabled until you allow Analytics in Privacy settings. Before that choice, the Google tag may load in consent mode with storage denied and send limited cookieless consent or status signals, but it does not set analytics cookies. When Analytics is enabled, Google Analytics may process online identifiers, browser and device information, page interactions, an approximate region inferred from an IP address, and related diagnostic data to help us understand Website usage and reliability.

Google reCAPTCHA and optional embedded content such as YouTube remain blocked until you allow External services. Without that optional choice, the contact form cannot be submitted and external embeds are not loaded, but the rest of the Website, including its public content and browser tools, remains available. You can change either optional choice at any time through Privacy settings.

Website contact form and email correspondence

If you contact us through the Website form or directly by email, we process the name or nickname, email address, subject, message, and any other information you include. For form security and delivery diagnostics, we also process the IP address, user agent, referrer, submission time, and delivery status. The form is protected by Google reCAPTCHA, which receives the verification token and IP address needed to assess abuse.

We use this information only to receive, secure, document, and respond to your message, prevent spam or abuse, and establish, exercise, or defend legal claims where necessary. The normal legal basis is our legitimate interest in communicating with users and protecting the Website. If your request concerns entering into or performing a contract, processing may also be necessary to take steps at your request or perform that contract.

Providing contact-form data is voluntary, but the required fields are necessary to send the form and allow us to respond. Contact details submitted for support are not used for newsletters or unrelated marketing without a separate legal basis.

A contact-form record is stored in our protected Website database and email system. An owner-only notification containing selected contact details and a shortened message excerpt is also generated through a private internal notification system so the developer can respond promptly. Categories of service providers involved may include Website, database and email hosting, Google reCAPTCHA, and notification-delivery infrastructure. They process data only to provide and secure these services.

Routine contact correspondence and its operational copies are reviewed for deletion 12 months after the last substantive contact. They may be retained longer when reasonably necessary to comply with law or establish, exercise, or defend legal claims. Daily Website maintenance clears IP address, user-agent, and referrer fields once a database record is more than 90 days old and deletes contact-form records once they are more than 12 months old. Short-lived rate-limit identifiers expire after 24 hours and are physically removed during the next daily maintenance pass.

There is no automated decision-making or profiling based on contact-form submissions. A failed anti-spam check only prevents that submission from being delivered through the form; you may still contact us by email.

4. Third-Party Services and Recipients

We use Google User Messaging Platform (UMP) to manage applicable advertising consent choices and Google AdMob to display ads. For a restricted/underage user, the App sends derived protection signals so that age-restricted, child-directed, and non-personalized treatment can be applied. AdMob may process device identifiers, an approximate region inferred from an IP address, app and ad interactions, advertising data, and performance or diagnostic information for advertising, measurement, and fraud prevention. Because the App's AdMob and Firebase/Google Analytics services are linked, app analytics data may also be made available to AdMob to improve monetization and ad personalization, subject to applicable consent, age safeguards, and platform privacy choices.

We use Firebase services, including Anonymous Authentication, Firestore, Cloud Functions, Remote Config, and Google Analytics for Firebase, to support premium-point state and related App functionality. Google Analytics for Firebase may process app-instance or device identifiers, app interactions, an approximate region inferred from an IP address, diagnostic information, and purchase or subscription events.

On supported iOS versions, Apple Declared Age Range may provide age-range bounds selected or shared through Apple's system service. Apple does not provide the App with a date of birth, and the App does not retain the received bounds after converting them to the local adult or restricted/underage setting.

On the Website, Google Analytics is used only when the relevant optional consent has been granted. Google reCAPTCHA is loaded only when External services have been allowed and protects the contact form against spam and abuse. Starting April 2, 2026, reCAPTCHA data is processed by Google as a processor under Google Cloud contractual terms, including the Cloud Data Processing Addendum and Service Specific Terms for reCAPTCHA.

For in-app purchases, we use Apple App Store (StoreKit) and Google Play Billing. Purchase processing is handled by Apple or Google; we use purchase status data to unlock Premium features.

More information about Google's processing is available in Google's Privacy Policy, and information about Apple's processing is available in Apple's Privacy Policy.

5. Children's Privacy

SkimmIQ is a general-audience puzzle game and is not directed to children under 13, although its content may be suitable for a broad range of ages. The core puzzle and most Website content can be used without submitting identifying information. Leaderboard submission, public replay sharing, issue reporting, and the Website contact form are optional. Users under 13 should use public or support features only with the involvement of a parent or guardian. If you are a parent or guardian and believe a child has provided personal information, contact us and we will review and delete it where appropriate.

6. Security

We use reasonable technical and organizational measures, including access controls, server-side validation, anti-abuse controls, and protected transport and storage, to safeguard the data we process. No method of transmission or storage is completely secure.

7. Your Choices and Rights

To exercise these rights, email pawel@skimmiq.com. We may need enough information to verify that the request concerns your data.

8. Retention

9. International Transfers

Some service providers may process data outside the European Economic Area. Where required, such transfers rely on an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism and appropriate safeguards provided by the relevant service provider.

10. Changes to This Privacy Policy

We may update this Policy when the App, Website, service providers, or legal requirements change. We will publish the revised Policy and update the Effective Date. Where required, we will provide an additional notice or request consent before materially different processing begins.

11. Contact

For questions, privacy requests, or Leaderboard removal requests, contact:

Pawel Faber, operator of SkimmIQ
Warsaw, Poland
Email: pawel@skimmiq.com
Website: skimmiq.com