Politique de confidentialité

Effective date: 2026-09-22

This privacy policy applies to the MotsDeMinuit application (French) also published as Woorden van middernacht (Dutch) for mobile devices, together with any related services operated by Kris Laermans (collectively, the “Application”). Kris Laermans is hereinafter referred to as the “Service Provider”.

Data Controller Information

Gixita (Kris Laermans) acts as the Data Controller responsible for the processing of your personal data.

For data protection inquiries and to exercise your GDPR rights, please contact the Data Controller using the contact information above.

What information does the Application obtain and how is it used?

MotsDeMinuit is a daily word game: every day, every player gets the same board of sixteen letters and three challenge cards, and composes one word from the tiles. It does not require you to create an account and does not collect your name, email address, phone number, or any other directly identifying personal information. The Service Provider does not send marketing communications.

The words you play and submit are generated and checked entirely on your device. All of your game data — your day records (the word you played, its score), your played-word history (historique), your week statistics (parcours, stats, streak), and your preferences (sound on/off, game language) — is stored solely on your device and is never transmitted by the Application itself. The Application never sends the words you play to the Service Provider or to any third party.

The Application optionally opens dictionary definition sources (the Wiktionnaire and the WikiWoordenboek) in your system’s web browser when you tap the link to a full entry. That browsing takes place outside the Application and is governed by the browser’s and the visited website’s own policies.

Two editions, one privacy posture

The Application ships in two builds of the same source code:

  • The FOSS build (Google-free, distributed on F-Droid and as a direct APK) contains no analytics, no crash reporting, no trackers of any kind: nothing ever leaves your device. This is enforced in the source code by a dedicated test.
  • The Google Play build additionally integrates Google Firebase (Analytics and Crashlytics), as described below. It integrates no advertising SDK and does not collect the mobile advertising ID — the corresponding Android permissions are explicitly removed from the Application.

Where the GDPR applies, the Service Provider relies on the following lawful bases for its processing (Google Play build only):

  • Contract performance: processing necessary to provide the Application and its core game functionality (all on-device processing).
  • Consent: your usage statistics (screen views and the SDK’s automatic events) are sent on the Google Play build only if you have opted in, through the “Usage statistics” switch on the Application’s Configuration page — the switch is off by default, and you may withdraw your consent at any time by switching it off, without affecting processing that occurred before withdrawal.
  • Legitimate interests: processing of crash reports to maintain reliability and ensure information security, provided those interests are not overridden by your data protection rights.
  • Legal obligation: to comply with laws or government requests, and — in particular for any future personalised advertising (see the section on third parties below) — your explicit consent, which you may withdraw at any time without affecting processing that occurred before withdrawal.

Cookies and similar technologies

The Application is a mobile app and does not use browser cookies. The Google Play build and its third-party SDKs (Google Firebase) may use SDK identifiers and similar technologies to support analytics and service delivery. Usage statistics are governed by your opt-in choice (the “Usage statistics” switch on the Configuration page, off by default): the Service Provider obtains your consent through that switch before enabling analytics collection, and honours your withdrawal immediately.

Automated decision-making and profiling

The Application does not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.

What information does the Application collect automatically?

The FOSS build collects nothing: no data leaves your device.

On the Google Play build, the Application itself stores your game data and preferences only on your device and does not collect any directly identifying device identifiers. Usage analytics are opt-in: they are sent only if you enable the “Usage statistics” switch on the Application’s Configuration page (off by default — a fresh installation sends nothing). When collection is enabled, the Application relies on Google Firebase (Analytics) as a data processor, which may process technical identifiers and usage data, including:

  • a Firebase app-instance identifier,
  • device model and operating system,
  • app version, country and language,
  • usage events such as screen_view (which of the game’s screens you open) and the SDK’s automatic first_open / session_start events — carrying only non-identifying parameters; never the words you play,
  • crash reports (crash logs, stack traces) from Firebase Crashlytics — sent regardless of the switch, as described under “Legal basis” above,
  • your IP address, to the extent Google processes it to derive your country.

Disabling the switch (or leaving it off) stops usage analytics at once; crash reports, governed by the Service Provider’s legitimate interests and disclosed here, continue. You may also disable crash reporting entirely by uninstalling the Application.

This information does not directly identify you and is not used to identify you or to serve you personalised content.

Does the Application collect precise real time location information of the device?

This Application does not gather precise information about the location of your mobile device.

Does the Application use Artificial Intelligence (AI) technologies?

The Application does not use Artificial Intelligence (AI) technologies to process your data or provide features.

Do third parties see and/or have access to information obtained by the Application?

Usage analytics (only when you have opted in) and crash reports are transmitted to Google Firebase (Analytics and Crashlytics) to help the Service Provider improve the Application and ensure its reliability. These transmissions contain non-personally-identifiable usage events and technical device information, and are not aggregated or anonymized data in the sense of being combined before transmission.

The Service Provider may share your information with third parties only in the ways described in this privacy statement.

Future advertising (AdMob)

The Application does not currently display advertisements and no advertising SDK is integrated at this time. If the Service Provider later adds advertising, it may integrate Google AdMob, which may collect the mobile advertising ID and impression data, and may display personalised ads. Before any personalised advertising is served to users in the EEA or the UK, the Service Provider will obtain your explicit consent (via a Google-certified consent management tool), and you may withdraw that consent at any time. No advertising data is collected until such a feature is enabled.

International Data Transfers

The Service Provider or its third-party service providers may transfer personal data outside the European Economic Area (EEA). Where such transfers occur, the Service Provider will use an appropriate transfer mechanism required by GDPR Chapter V:

  • Adequacy decisions by the European Commission
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Other safeguards or derogations recognized under GDPR Chapter V, including consent where legally permitted

Countries outside the EEA may not provide the same level of data protection as the EEA. Where required by law, the Service Provider will apply appropriate safeguards and obtain any consent required for the transfer.

Please note that the Application utilizes third-party services that have their own privacy policies about handling data. Below are the links to the privacy policies of the third-party service providers used by the Application:

The Service Provider may disclose User Provided and Automatically Collected Information:

  • as required by law, such as to comply with a subpoena, or similar legal process;
  • when they believe in good faith that disclosure is necessary to protect their rights, protect your safety or the safety of others, investigate fraud, or respond to a government request;
  • with their trusted service providers who work on their behalf, do not have an independent use of the information the Service Provider discloses to them, and have agreed to adhere to the rules set forth in this privacy statement.

Where the GDPR applies, the Service Provider enters into Data Processing Agreements (DPAs) with third-party service providers that process personal data on its behalf, as required by Article 28 of the GDPR. These DPAs impose the same data protection obligations on those service providers as described in this Privacy Policy.

What are my opt-out rights?

Because the Application collects no identifying information, the Service Provider cannot link any user to the data transmitted to Google Firebase and therefore cannot identify or delete the data of a specific individual upon request. To withdraw your analytics consent, switch off the “Usage statistics” toggle on the Configuration page — collection stops at once. To delete all of your data and stop all collection (including crash reports), uninstall the Application. Uninstalling deletes all game data stored on your device and stops the Application from collecting further data from your device, although it does not remove data that has already been transmitted to third parties.

To withdraw consent or exercise any of your other rights, contact the Service Provider using the contact details provided above.

What is the data retention policy and how can you manage your information?

  • Game data (day records, history, statistics, preferences) is stored only on your device and is deleted when you uninstall the Application. The Service Provider does not retain it and never receives it.
  • Analytics data is retained by Google Firebase in line with the Firebase Analytics retention setting configured by the Service Provider (currently 14 months), unless a longer retention is required by law.
  • Crash reports are retained in line with Firebase Crashlytics' retention policy.
  • Aggregated and anonymized data that no longer identifies you may be retained indefinitely.
  • Data required for legal compliance is retained as long as required by applicable law.

Because all of your game data remains on your device and the Service Provider cannot link Firebase data to an individual, deletion of your data is performed by uninstalling the Application (see “Opt-out rights” above). For any other request, contact the Service Provider using the contact details provided above.

How does the Application address children’s privacy?

The Application is not intended for children under 16 years of age, or where a higher age of digital consent is established under applicable law. The Service Provider does not knowingly solicit data from children or market the Application to them.

Where parental or guardian consent is required under applicable law, the Application is not intended for use without that consent. The Service Provider does not knowingly collect personally identifiable information from children under 16 years of age, or where a higher age of digital consent is established by applicable law, in violation of applicable law. In the event the Service Provider discovers that a child has provided personal information, the Service Provider will immediately delete it from their servers. If you are a parent or guardian and you are aware that your child has provided the Service Provider with personal information, please contact the Service Provider using the contact details provided above so that they will be able to take the necessary actions.

How is your information kept secure?

The Service Provider is committed to safeguarding the confidentiality of your information. The Service Provider implements physical, electronic, and procedural safeguards to protect information it processes and maintains. For example, access is limited to authorized personnel who need to know that information to operate, develop, or improve the Application. However, no security system can prevent all potential security breaches.

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, the Service Provider will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by applicable law. Where the breach is likely to result in a high risk to your rights and freedoms, the Service Provider will also notify you without undue delay, providing information about the nature of the breach, the categories of data affected, and the measures taken or proposed to address the breach.

How will you be informed of changes to this Privacy Policy?

The Service Provider may update this Privacy Policy from time to time. The Service Provider will notify you of material changes by posting the updated Privacy Policy with an effective date. Where required by law, the Service Provider will seek your consent to material changes before they take effect.

Previous versions of this Privacy Policy will be maintained and made available upon request by contacting the Service Provider using the contact details provided above.

This privacy policy is effective as of 2026-09-22.

What are your GDPR data protection rights?

Under the GDPR, you have the following rights:

  • Right of Access: You can request access to your personal data.
  • Right to Rectification: You can request correction of inaccurate data.
  • Right to Erasure: You can request deletion of your personal data (the “right to be forgotten”).
  • Right to Restrict Processing: You can request that the Data Controller limits how they use your data.
  • Right to Data Portability: You can request a copy of your data in a structured, commonly used, machine-readable format.
  • Right to Object: You can object to processing based on legitimate interests. You have an absolute right to object to processing for direct marketing purposes at any time.
  • Right to Withdraw Consent: Where processing is based on your consent, you can withdraw it at any time without affecting processing carried out before withdrawal.
  • Rights Regarding Automated Decision-Making: You have rights related to automated decisions that affect you.

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority. Contact details for each country’s Data Protection Authority can be found at: https://edpb.europa.eu/about-edpb/members_en

If you are located in the United Kingdom, you may contact the Information Commissioner’s Office at https://ico.org.uk

What are your California privacy rights (CCPA/CPRA)?

If you are a resident of California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information:

  • Right to Know: You can request disclosure of the categories and specific pieces of personal information the Service Provider has collected about you.
  • Right to Delete: You can request deletion of personal information the Service Provider has collected from you, subject to certain exceptions.
  • Right to Correct: You can request correction of inaccurate personal information.
  • Right to Opt-Out: You can opt out of the sale or sharing of your personal information for cross-context behavioral advertising. The Service Provider does not sell your personal information.
  • Right to Limit Use of Sensitive Personal Information: You can limit the use of your sensitive personal information to essential purposes.
  • Right to Non-Discrimination: The Service Provider will not discriminate against you for exercising any of your CCPA/CPRA rights.

To exercise any of these rights, please contact the Service Provider using the contact details provided above. The Service Provider will verify your request using the information you provide and respond within the timeframes required by law. You may designate an authorized agent to make a request on your behalf.

Usage statistics on the Google Play build are opt-in: you give your consent by enabling the “Usage statistics” switch on the Application’s Configuration page — the switch is off by default, so a fresh installation sends nothing. You may withdraw that consent at any time by switching it off, without affecting processing carried out before withdrawal. Crash reports are processed on the basis of the Service Provider’s legitimate interests, as disclosed above. Any future personalised advertising would rely on a Google-certified consent management tool, as described above. Processing based on other lawful bases, including contract performance, is carried out as described above.

How can you contact the Data Controller?

If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider using the contact details provided above.

To request deletion of your personal data or to exercise any of your rights, contact the Service Provider using the details provided above. The Service Provider will respond within one month of receiving your request, extendable by up to two months where necessary due to the complexity or volume of requests, as permitted by applicable law.