Last updated: 3 August 2026.
This privacy policy explains how SCHMUT/WEISS GmbH ("we", "us") processes personal data in connection with luminarypartygame.com and the Luminary mobile application (together, the "Service"). The mobile application includes the iOS app with bundle identifier com.weiss.luminary and the Android app with package name com.schmutweiss.luminary.
SCHMUT/WEISS GmbH
Sieveringer Straße 9/13, 1190 Vienna, Austria
Email: luminary.partygame@gmail.com
SCHMUT/WEISS GmbH is the controller for the processing described in this policy. "Personal data" means information relating to an identified or identifiable natural person. Although Luminary does not require an account and the identifiers described below do not directly reveal your identity to us, persistent identifiers and related activity may still be personal data under applicable law.
When you access the website, your browser automatically sends connection and request data to our hosting provider. Server logs may include the requested page, date and time, IP address, amount of data transferred, browser or user-agent information, and technical status information.
Purpose and legal basis: providing a secure, stable website and preventing abuse, based on Art. 6(1)(f) GDPR and our legitimate interests in operating the website securely. Server logs are retained for up to 14 days and then deleted or anonymised, unless a security incident requires longer storage.
We use a first-party analytics endpoint to understand which pages are useful, which language is viewed, which identifiable referral hostnames lead to the website, how often visitors select a Storefront link, and how often our own campaign or QR-code links are opened. Each event is immediately added to a daily aggregate counter in Supabase. The counter contains the event type, page path, language, referring hostname without the full referring URL, sanitised campaign values, broad device class, date, and total event count.
This website analytics system does not use cookies, local storage, advertising identifiers, persistent visitor or session IDs, fingerprinting, or cross-site tracking. We do not store IP addresses or full user-agent strings in the analytics database. Hosting providers may still process connection data in server logs as described above.
Purpose and legal basis: measuring and improving the website and our own communications, based on Art. 6(1)(f) GDPR and our legitimate interests. The aggregate counters are stored in an EU-region Supabase project, reviewed at least annually, and deleted when no longer needed for those purposes.
If you contact us by email, we process the information you provide, such as your name, email address, and message, to respond to your request. The legal basis is Art. 6(1)(b) GDPR when the request concerns a contract or pre-contractual measures, and otherwise Art. 6(1)(f) GDPR and our legitimate interest in responding to enquiries. We retain correspondence only as long as needed to handle the request and meet applicable legal obligations.
Luminary does not require a user account. The App nevertheless processes the following categories of data for functionality, anonymous analytics, purchases, and entitlement management.
On first launch, the App generates a random UUID and stores it on the device as a persistent app installation or device identifier ("device ID"). The device ID is not an Apple advertising identifier, Google advertising identifier, hardware serial number, Apple ID, Google account ID, name, email address, or phone number. We use the same device ID as the pseudonymous key for Supabase records and as RevenueCat's anonymous app-user ID.
The device ID lets the App associate activity, purchase status, and entitlements with an installation without requiring an account. It may allow events from the same installation to be distinguished over time, so it is declared as a device or other identifier even though it does not directly identify you by name.
Purpose and legal basis: App operation, entitlement delivery, abuse prevention, and product improvement. Contract-related functionality is based on Art. 6(1)(b) GDPR. Product analytics and service integrity are based on Art. 6(1)(f) GDPR and our legitimate interests in understanding and improving the Service.
The App sends a device profile to Supabase. It includes the device ID, platform, app version, build number, App locale, country code where supplied as part of the device locale, timezone, debug-build status, and timestamps such as the last time the profile was seen. The country code is locale information and is not GPS or precise location. Where available, the profile may also include an install cohort and campaign-level acquisition information.
Purpose and legal basis: compatibility, troubleshooting, release measurement, purchase and entitlement support, and aggregate product analysis, based on Art. 6(1)(b) GDPR for contract-related functionality and Art. 6(1)(f) GDPR for our legitimate interests in operating and improving the Service.
The App sends app activity and analytics events linked to the device ID to Supabase. Depending on how the App is used, this may include app and session lifecycle events, onboarding steps, deck and feature interactions, game starts and completions, selected deck identifiers, task formats, group-size counts, paywall and purchase-flow events, review or share interactions, and sponsored-deck task impressions. Event properties may include a random app-session or game-session identifier, App locale, product identifier, storefront, locally displayed currency or price information, entitlement context, and event timestamps. The App does not send player names or task answer content as analytics properties.
These records are anonymous in the sense that they are not linked to an account, name, or contact information, but they are persistent device-level analytics and are treated as personal data where applicable.
Purpose and legal basis: understanding feature use, improving the App, measuring purchase flows, maintaining reliability, and producing aggregate reporting for partner or sponsored decks. The legal basis is Art. 6(1)(f) GDPR and our legitimate interests in improving the Service and measuring agreed partner-deck performance. Purchase-related events may also be processed under Art. 6(1)(b) GDPR.
Apple processes purchases made through the Apple App Store, and Google processes purchases made through Google Play. Apple and Google handle the payment method and payment authorization under their own terms and privacy policies. We do not receive your complete payment card details.
We use RevenueCat to load product information and manage purchase status, purchase history, subscription infrastructure, and entitlements for Luminary Unlimited and optional one-time deck purchases. RevenueCat receives the anonymous app-user ID described above and transaction or customer-status information from the applicable Storefront, such as product identifiers, purchase and renewal events, expiration or refund status, active entitlements, and the Storefront used. RevenueCat does not process your payment card in Luminary's purchase flow.
We may store entitlement snapshots in Supabase, including device ID, entitlement and product identifiers, active status, expiry where applicable, RevenueCat customer ID, Storefront, and update time. This lets the App provide and support purchased access, including when network access is temporarily unavailable.
Purpose and legal basis: presenting products, completing requested purchases, restoring purchases, providing paid access, maintaining subscription state, and handling support, based on Art. 6(1)(b) GDPR. Legal or accounting records may also be processed under Art. 6(1)(c) GDPR.
Processor: RevenueCat, Inc., 600 California St, San Francisco, CA 94108, USA. Privacy policy: revenuecat.com/privacy.
On iOS, the App uses Apple's AdServices framework. On first launch, and again later if attribution is not yet available, the App can request an attribution token from Apple and send it to Apple's Attribution API. Apple returns campaign or cohort-level information where applicable. We store resulting source, campaign, network, and capture-time fields in the Supabase device profile to measure Apple Search Ads performance. We do not use a third-party mobile measurement provider for this flow.
Purpose and legal basis: measuring the effectiveness of our Apple Search Ads campaigns, based on Art. 6(1)(f) GDPR and our legitimate interest in evaluating our advertising. This processing is specific to iOS and does not use the iOS advertising identifier (IDFA).
We use these service providers and recipients where relevant:
Apple and Google act independently for their Storefront accounts, payment processing, refund handling, and related Storefront data. Requests concerning those independent records should be directed to the relevant Storefront. Our processing of purchase status and entitlements is separate from their processing of your account and payment method.
Some recipients, including RevenueCat and Vercel, are based in the United States, and service providers may use personnel or infrastructure outside the European Economic Area. Supabase App and website data are configured for an EU-region project, but service-provider access or supporting processing may still involve another country. Where personal data is transferred outside the European Economic Area, we use a transfer mechanism permitted by Chapter V GDPR, such as an adequacy decision or standard contractual clauses, as applicable, and take supplementary measures where required. You can contact us for more information about the applicable safeguards.
We retain each category only for as long as needed for the purposes described above and to meet legal obligations. App activity and device-profile data are retained while useful for operating, securing, analysing, and improving the Service, then deleted or anonymised. Purchase and entitlement records are retained while needed to provide or restore access, resolve support issues, prevent fraud, and satisfy legal or accounting duties. Email correspondence is retained as described above. Storefronts determine retention for the records they independently control.
We review retention needs periodically. We do not state a fixed App analytics or purchase-history period because the necessary period depends on the data category, the continued use of the Service, active entitlements, support needs, and applicable legal obligations.
Under the GDPR, where applicable, you have the right to access personal data, correct inaccurate data, request deletion, restrict processing, receive portable data, and object to processing based on legitimate interests. You may also have the right to lodge a complaint with a supervisory authority.
Because the App does not use an account, we may need the device ID shown or stored by the App, if available, to locate device-level records. Follow the steps on our data deletion page to submit a request. We will verify and handle the request as required by law. Deleting the App from a device does not by itself identify or delete the corresponding server records processed for us in Supabase or RevenueCat. For Storefront account or payment records controlled by Apple or Google, use the privacy tools of the applicable Storefront.
The competent supervisory authority in Austria is the Austrian Data Protection Authority: dsb.gv.at.
We use technical and organisational measures appropriate to the nature of the data, including access controls, restricted service credentials, encrypted network transmission, and separation of payment-card processing from our systems. No system is completely secure, so we cannot guarantee absolute security.
Luminary is a party game and is not directed at children. The App does not require an account or ask for a date of birth. Anonymous technical and activity data may still be generated if the App is used on a device. If you are a parent or guardian and believe that a child has used the Service in a way that requires review or deletion, contact us and provide the device ID if available. We will assess and handle the request under applicable law.
The website does not set analytics or marketing cookies, and the App does not display third-party advertising. Luminary does not collect IDFA for its analytics, does not use data for cross-app behavioural advertising or retargeting, and does not share data with data brokers.
For privacy questions or requests, contact luminary.partygame@gmail.com.