Skip to content
Funkl-Go Join the waitlist

Privacy Policy

Funkl-Go — app, website and waitlist
Last updated: September 27, 2026

This policy explains what personal data we process when you use the Funkl-Go iPhone app, visit funklgo.app or join the waitlist, why we do it, how long we keep it and what rights you have. We have tried to keep it short and in plain language. Where something is not collected, we say so.

In short: Funkl-Go has no ads, no in-app purchases, no tracking and no third-party SDKs. You play under a random player ID, not under your real name. We only store location rounded to about 1 km, and only when you report a code. Collecting your walking trail is off unless you switch it on. You can export or delete everything in the app at any time.


1. Who is responsible

The controller under the EU General Data Protection Regulation (GDPR) is:

Peter Holzhauser
Dinkelsbühlerstr. 38
70374 Stuttgart
Germany
Email: [email protected] (general contact: [email protected])

Funkl-Go is run by a single independent developer. We are not legally required to appoint a data protection officer and have not done so. For all privacy questions, write to [email protected].

2. What Funkl-Go is (and why it needs some data)

Funkl-Go is a collecting game. Lamps ("beacons") in shops and other places send short codes by flickering very quickly. Your iPhone's camera reads the flicker. The first player to report a code gets a virtual creature called a "Funkl". There are 100 kinds of Funkl. The server decides at random how rare a Funkl is, and each Funkl gets a unique serial number. You can swap Funkls with another phone using the flashlight.

To run the game, the server has to know which player reported which code, when and roughly where. That is the core of the data described below.

3. Data processed in the app

3.1 Data that stays on your iPhone

  • Camera. The app uses the camera only while you scan. It does not take, store or upload photos or videos. It analyzes only brightness values from the image in real time to decode the flicker. The camera images are discarded right away.
  • Motion sensors. Used on the device to steady the scan and to spot when the phone is being moved. Raw sensor data is not sent to our server.
  • Your collection, settings and your age confirmation are stored locally on your iPhone.
  • Player ID and device key. When you first open the app, it creates a random player ID (a UUID) and a random secret device key. Both are stored in the iOS Keychain on this device only. They let the server know that later requests come from the same player. They are not linked to your Apple ID, name, phone number or advertising ID.

3.2 Data sent to our server when you play

DataWhenPurposeLegal basis
Player ID (random UUID) and a hash of your device key (we never see the key itself)With every game requestAssign catches, collection and trades to you; stop others from acting in your nameArt. 6(1)(b) GDPR (providing the game)
Player name (a name you choose; by default a random name such as "Hunter-1234")When you report a codeShow whose catch it is in the gameArt. 6(1)(b) GDPR
Confirmation that you are 16 or older (yes/no flag)With your first catchEnforce the minimum ageArt. 6(1)(b) and (c) GDPR
Catch data: the code you read, the time, the signal strength, and your location rounded to 2 decimal places (about 1 km)When you report a codeDecide who reported a code first, check that the report is plausible (you were near the beacon), give out the Funkl, prevent cheatingArt. 6(1)(b) GDPR; for cheating checks Art. 6(1)(f) GDPR
Your collection (which Funkls you own, serial numbers)OngoingKeep your collection and let you restore itArt. 6(1)(b) GDPR
Trade records (trade ticket, which Funkl, which player IDs, time, whether it was redeemed)When you tradeCarry out trades and prevent a Funkl from being traded twiceArt. 6(1)(b) GDPR
Technical request data (see section 3.5)With every requestDeliver the service, protect it against abuseArt. 6(1)(f) GDPR

Your player name is not shown to other players in the app. Only we, as the operator, can see it in our internal overview of recent catches, for running the game and preventing abuse. Please still do not use your real name or anything that identifies you as your player name.

Location permission. The app only asks for location access "While Using the App". It never uses location in the background. The app rounds your position before sending it, and the server rounds it again when saving. Your exact GPS position never leaves your iPhone.

3.3 Optional: walking trail for heatmaps (only with your consent)

In Settings you can choose to share your walking trail while the app is open. This is off by default. If you switch it on, the app sends positions rounded to about 1 km together with a time stamp and your player ID.

We use this data only to create anonymous, aggregated heatmaps (for example: "how many players passed this area per hour"). We may share these heatmaps with beacon operators and advertising partners so they can see how busy an area is. We never give them your trail, your player ID or any data about individual players.

  • Legal basis: your consent, Art. 6(1)(a) GDPR.
  • You can withdraw your consent at any time by switching the setting off. Withdrawal does not affect processing done before.
  • Trail data is deleted after 30 days at the latest.

3.4 Optional: Sign in with Apple

Signing in is optional. You can play without it. Its only use is to restore your collection on a new iPhone.

We do not request your name or email address from Apple. The app sends only a one-way hash of the anonymous user identifier Apple gives to Funkl-Go. We cannot turn it back into your Apple ID. Legal basis: Art. 6(1)(b) GDPR. Apple processes the sign-in itself under its own privacy policy (see section 6).

3.5 Technical data, security and logs

When your app contacts our server, your IP address and basic request data (time, endpoint, app version) are necessarily transmitted. We do not write IP addresses to logs or to the database. For rate limiting (protection against flooding and brute force), IP addresses may be held briefly in the server's memory. They are not stored permanently. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is to keep the game secure and working.

3.6 Scan quality measurements (not linked to you)

To improve code detection across different iPhones, the app may send measurement data: device model and camera values (such as exposure and brightness statistics). This data is sent without your player ID and is not linked to you. It is deleted after 180 days. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is to make scanning work reliably on all devices.

3.7 The public register of Funkls

Every Funkl that is minted gets a signed entry in a public, append-only register. This lets anyone check that a serial number is genuine and unique. It is a tamper-evident log on our own server, not a blockchain.

A register entry contains the serial number, the kind of Funkl, the time and a location rounded to about 1 km. It does not contain your player ID in readable form. Instead it contains a salted hash. Only our server can match that hash to you, using a secret "salt" stored separately. When you delete your account, we destroy the salt. From then on, the entry can no longer be connected to you, but the register stays valid. Legal basis: Art. 6(1)(b) GDPR (proof of authenticity is part of the game) and Art. 6(1)(f) GDPR (integrity of the register).

3.8 Maps

The in-app map uses Apple MapKit to show where beacons are. Map data is loaded from Apple. When you tap "walk there", Apple Maps opens and Apple handles routing. We do not receive any data from Apple about this. Apple processes it under its own privacy policy.

3.9 What the app does not do

  • No advertising and no advertising ID (IDFA)
  • No tracking across apps or websites and no data brokers
  • No analytics or crash-reporting SDKs from third parties
  • No in-app purchases and no payment data
  • No access to contacts, photos, microphone or your Apple account name or email

4. Website funklgo.app

  • No cookies, no tracking. The website sets no cookies. It uses no analytics, no tracking pixels, no social media plugins and no external fonts or content delivery networks. Everything is loaded from funklgo.app. For this reason there is no cookie banner.
  • Server access. To show the page, your browser sends your IP address and standard request data. We do not store access logs with IP addresses. Our delivery partner Cloudflare (section 6) processes this data to deliver the page and protect it against attacks. Legal basis: Art. 6(1)(f) GDPR.

5. Waitlist

If you join the waitlist on funklgo.app:

  • What we store: your email address, optionally your country and platform (e.g., iPhone), your confirmation that you are 16 or older, the wording of the consent you gave, the time you signed up, and the time you confirmed. We do not store your IP address. It may be held briefly in memory to limit repeated sign-ups (spam protection), as described in section 3.5.
  • Double opt-in: After signing up you get an email with a confirmation link. You are only added to the list after you click it. That way nobody can sign up someone else's address.
  • Purpose: to email you when Funkl-Go launches or opens up in your country, and to send a few related project updates.
  • Legal basis: your consent, Art. 6(1)(a) GDPR. We keep the record of your consent (time of sign-up and confirmation) to be able to prove it, Art. 6(1)(c) and (f) GDPR.
  • Unsubscribe: Every email contains an unsubscribe link. You can also write to [email protected]. Unsubscribing withdraws your consent for the future.
  • Email tracking: We do not use open or click tracking in waitlist emails.
  • Sending: Emails are sent through Brevo (section 6).
  • Storage period: until 12 months after the launch email for your country, or until you unsubscribe, whichever comes first. Sign-ups that are never confirmed are deleted after 30 days. After you unsubscribe, we may keep your address with a note "unsubscribed" only if this is needed to prove your earlier consent, and never use it to contact you.

6. Service providers and other recipients

We do not sell your data and we do not share it for advertising. We use a small number of service providers:

RecipientRoleWhat they getLocation / safeguard
Own server operated by usHosting of game server, database, website and waitlistEverything described aboveGermany
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USANetwork tunnel, content delivery, protection against attacks, email forwarding for @funklgo.app addressesIP address, request data, content passing through (encrypted in transit); emails you send to usUSA. Cloudflare is certified under the EU-U.S. Data Privacy Framework (adequacy decision, Art. 45 GDPR). In addition, EU Standard Contractual Clauses apply under Cloudflare's data processing addendum. Processor under Art. 28 GDPR.
Brevo GmbH (formerly Sendinblue GmbH), Köpenicker Straße 126, 10179 Berlin, GermanySending waitlist emailsEmail address, sending dataEU. Processor under Art. 28 GDPR.
Apple (for users in the EU: Apple Distribution International Ltd., Ireland)Sign in with Apple, MapKit and Apple Maps, App Store distributionWhat you share with Apple when you use these functionsApple acts as an independent controller under its own privacy policy: https://www.apple.com/legal/privacy/
Google (Gmail)Mailbox to which emails sent to hello@ and [email protected] are forwardedThe contents of your emailGoogle Ireland Ltd. / Google LLC, USA (Data Privacy Framework)
Beacon operators and advertising partnersReceive heatmapsOnly anonymous, aggregated statistics, never personal data–

We may also disclose data where we are legally required to, for example to authorities on the basis of a court order.

7. How long we keep data

DataRetention
Catch location and player name stored with a catchRemoved after 90 days. What remains is an anonymous statistic (code, time) without location or name.
Walking trail (only with consent)Deleted after 30 days
Scan quality measurements (not linked to you)Deleted after 180 days
Player account, collection, trade recordsUntil you delete your account. Accounts with no activity for 24 months are deleted automatically.
Register entriesKept permanently, but no longer linkable to you after account deletion (section 3.7)
Database backupsRotated automatically, kept for at most 14 days
WaitlistUntil 12 months after the launch email or until you unsubscribe; unconfirmed sign-ups after 30 days
Emails to usAs long as needed to handle your request, then deleted, unless statutory retention obligations apply

8. Your rights

Under the GDPR you have the right to:

  • Access your data and receive a copy (Art. 15)
  • Rectification of incorrect data (Art. 16). You can change your player name in the app.
  • Erasure (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability, i.e. receive your data in a machine-readable format (Art. 20)
  • Object at any time to processing based on legitimate interests (Art. 6(1)(f)), on grounds relating to your particular situation (Art. 21)
  • Withdraw consent at any time with effect for the future (Art. 7(3)): for the walking trail by switching it off in Settings, for the waitlist via the unsubscribe link

Do it yourself in the app: Settings → Legal → Export my data gives you a JSON file of everything the server stores about your player ID. Settings → Legal → Delete account & all data deletes it. See https://funklgo.app/delete for details.

By email: Write to [email protected] and include your player ID (shown in Settings). Because we do not know who you are, the player ID is the only way to find your data. We may ask for proof that the player ID is yours, for example a request sent from the app.

Right to complain. You can complain to a data protection supervisory authority. The authority responsible for us is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)
Lautenschlagerstraße 20, 70173 Stuttgart, Germany
https://www.baden-wuerttemberg.datenschutz.de

You can also contact the authority in the EU country where you live or work.

9. No automated decisions with legal effect

We do not make decisions based solely on automated processing that have legal or similarly significant effects on you (Art. 22 GDPR). Two game mechanics are automatic, and we want to be clear about them. First, a code goes to the player whose report reaches the server first, which is a pure timing rule. Second, the server picks the rarity of a Funkl at random. Neither mechanic evaluates you as a person, and neither has any legal or financial effect.

10. Are you required to provide data?

You are not required by law to provide any data. However, the game cannot work without the player ID and catch data (section 3.2). Everything else is optional: the walking trail, Sign in with Apple and the waitlist.

11. Minimum age

Funkl-Go is intended for people aged 16 and older. The app asks you to confirm your age before you can play. We do not knowingly process data of people under 16. If you believe a child under 16 is using Funkl-Go, please contact us and we will delete the data.

12. Security

All connections between the app, the website and our server are encrypted (HTTPS/TLS). Your device key is stored only as a hash on the server. We store only the data we need, round locations, and delete data on the schedules above. No system is perfectly secure, but we regularly review our measures.

13. Changes to this policy

We will update this policy when the app or the law changes. The current version is always available at https://funklgo.app/privacy. If a change affects how we use data you have already given us, we will tell you in the app. If the change requires your consent, we will ask for it first.

Funkl-Go
ImprintPrivacyTermsSafetyDelete data[email protected]

© 2026 Peter Holzhauser · Funkl-Go · Made in Stuttgart. No cookies on this site.