Privacy Policy
Last updated: 22 April 2026
At Lamma, we respect your privacy and are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (DSGVO / GDPR) and the German Federal Data Protection Act (BDSG). This policy explains what we collect, why, and how you can exercise your rights.
1. Data Controller (Verantwortlicher)
Mohammad Areesheh
Connollystr. 3
80809 München, Deutschland
Email: lamma@areesheh.com
2. Data We Collect and Legal Basis
A. Email Sign-in Data (Clerk)
When you choose to link Premium to your email address on the web or mobile, we use the Clerk service (Clerk Inc., 548 Market St PMB 75011, San Francisco, CA 94104, USA) to process sign-in via a one-time code (OTP). Clerk retains your email address and an associated user ID for as long as your account is active.
- Purpose: Link your Premium subscription to a unified account that works across all your devices and platforms.
- Legal basis: Performance of a contract (Art. 6(1)(b) GDPR).
- Clerk Privacy Policy: clerk.com/privacy
B. Subscription and Purchase Data (RevenueCat)
Premium subscriptions and purchases are managed via the RevenueCat service (RevenueCat Inc., 633 Tasman Drive, Sunnyvale, CA 94089, USA). The app sends RevenueCat your device identifier or the user ID linked to your Clerk account, along with transaction information received from the store.
- Purpose: Verify Premium status, manage subscriptions, and restore purchases.
- Legal basis: Performance of a contract (Art. 6(1)(b) GDPR).
- RevenueCat Privacy Policy: revenuecat.com/privacy
C. Web Payment Processing (Paddle)
When you purchase via the website, the payment is processed by Paddle (Paddle.com Market Limited, Core B, Block 71, The Plaza, Park West, Dublin 12, Ireland). Paddle acts as the Merchant of Record and handles the collection and processing of payment data (credit cards and others) and the remittance of applicable taxes. We neither receive nor store any payment data directly.
- Purpose: Complete purchases, issue invoices, and remit VAT.
- Legal basis: Performance of a contract (Art. 6(1)(b) GDPR).
- Paddle Privacy Policy: paddle.com/legal/privacy
D. Payment Processing via Apple App Store and Google Play
When you purchase from the App Store on iOS or Android, Apple or Google handles the payment in accordance with their terms. We do not receive your card details or banking information.
- Apple Privacy Policy: apple.com/legal/privacy
- Google Privacy Policy: policies.google.com/privacy
E. Usage Data
We may collect anonymous, aggregated data about how the app is used (such as the categories used and the number of sessions) in order to improve the user experience and develop content.
- Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) — improving the app.
3. Transfer of Data Outside the European Union
The servers of Clerk and RevenueCat are located in the United States. This transfer is based on the European Commission's Standard Contractual Clauses pursuant to Art. 46 GDPR. You can find details of the safeguards in each service's privacy policy.
4. Data Retention Period
- Clerk data: Retained for as long as your account is active. You can request deletion at any time.
- RevenueCat data: Retained in accordance with RevenueCat's policy for tax and legal compliance purposes.
- Paddle data: Retained in accordance with applicable EU tax and accounting requirements (typically seven years).
- Local game data: Stored only on your device and deleted when the app is uninstalled.
5. No Sale of Data
We never sell your personal data, nor do we share it with third parties for advertising purposes.
6. Your Rights Under GDPR
You have the right, at any time, to:
- Right of access (Art. 15 GDPR): Know what data we hold about you.
- Right to rectification (Art. 16 GDPR): Correct inaccurate data.
- Right to erasure (Art. 17 GDPR): Request deletion of your data ("right to be forgotten").
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR).
- Right to object (Art. 21 GDPR): Object to processing based on legitimate interest.
- Cancel subscription: You can cancel your monthly subscription at any time via the store settings (App Store or Google Play) or the web dashboard.
To exercise any of these rights, contact us at: lamma@areesheh.com
You also have the right to lodge a complaint with the competent data protection authority. In Germany: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.
7. Children's Privacy
Lamma is a family-friendly game suitable for all ages. We do not knowingly collect personal data from children under the age of 16 without parental consent. If you become aware that a child's data has been collected without consent, please contact us immediately so we can delete it.
8. Storage on Your Device (Cookies and Similar Technologies)
Under Section 25 of the German Telecommunications-Telemedia Data Protection Act (TTDSG) and Article 5(3) of the ePrivacy Directive, any access to information stored on your device (cookies, LocalStorage, IndexedDB/OPFS) requires your consent — unless the storage is strictly necessary to provide the service you have explicitly requested.
We only use strictly necessary storage mechanisms. We do not use any third-party analytics, advertising, or tracking. For that reason we do not ask for cookie consent, but you are entitled to know exactly what we store:
a. Local Game Storage (necessary)
- LocalStorage — game settings: audio, language, and display preferences. Legal basis: necessary to provide the service.
- LocalStorage — database lock (lamma:web-db-lock): prevents the game from being opened in two browser tabs at once, which would corrupt your saved data. Legal basis: necessary to provide the service.
- OPFS / IndexedDB — question database: stores the category catalog, questions, and your play progress locally so the game works offline. Legal basis: necessary to provide the service.
All of this data stays on your device and is never sent to our servers. You can delete it at any time through your browser settings.
b. Clerk Sign-In (only when you request it)
When you click "Link Premium" or "Sign In", we load the Clerk library, which may set cookies and LocalStorage items needed to authenticate you and manage your session. This load happens only when you explicitly request sign-in, and is necessary to perform the contract for the service you requested.
c. Paddle Checkout (only when you request it)
When you click "Subscribe", the Paddle checkout iframe opens. Paddle may set cookies strictly necessary to complete the payment and prevent fraud. This only happens when you start a purchase.
What we do NOT use: no Google Analytics, no Meta Pixel, no behavioral analytics of any kind, no ads, and we do not share your browsing data with third parties for marketing purposes.
9. Amendments to This Policy
We may update this policy when adding new services or changing our practices. The last update date will be shown at the top of the page. In the event of any material change affecting your interests, we will notify you via the app or email where available.
10. Contact Us
For any inquiry or request related to privacy:
lamma@areesheh.com