M44 Wallet SG Mobile Designs

Privacy policy

What the app knows about you

M44 Wallet is a companion app for the board game Memoir ’44. Most of it — the dice, the scenario reference, the hex grid, the battle tracker — never sends anything anywhere. The part that does is Connect, where players find each other and talk. This page lists every field that leaves your device and says plainly who can see it.

Effective 19 August 2026 · Version 1.0

At a glance

Who we are

M44 Wallet is published by SG Mobile Designs, a one-person independent studio (Sean Gambles). We are the data controller for the information described here. You can reach us at sean.gambles@gmail.com — it goes to a real person and it is the same address used for support and deletion requests.

M44 Wallet is an unofficial fan-made companion. It is not published by, endorsed by, or affiliated with Days of Wonder or Asmodee, and we share nothing with them.

You do not have an account

This is the most important thing to understand, because it shapes everything else. When you first open the app it signs in anonymously to Firebase and receives a random identifier — a string like UdT3k…. That identifier is the only thing linking your data together. We never ask for an email address or a phone number, and there is no password to lose.

The trade-offs are real and worth stating. Because there is no account, your data lives with that one installation: if you delete the app, reinstall it, or switch phones, you get a fresh identifier and cannot recover your old profile, match history, or conversations. It also means that if you email us asking to see or delete your data, we usually have no way to prove which anonymous ID is yours — so the in-app controls are the reliable route, not email.

The display name you choose is recorded in a public name registry so two players cannot claim the same one. That registry maps your chosen name to your anonymous ID and is readable by anyone signed in, which is how mentions and invitations work.

The ledger

Rather than describe categories in the abstract, here is the actual list. Every row is a field the app can store off your device. The right-hand column is the one to read.

Your public profile

Stored only once you fill in a profile and turn it on. Skip the profile and none of this exists.
FieldWhat it isVisible to
Display name The name you pick. Most players use a handle rather than their real name, and we recommend that. Every player
Approximate location Coordinates rounded to two decimal places — about a kilometre of imprecision — plus a town, region and country label. This is what places your pin on the map. Every player
Availability note Free text about when you like to play, e.g. “weeknights after 8”. Every player
Open to messages A yes/no switch controlling whether other players can start a conversation with you. Every player
Points, streak, rank, badges Totals recorded from how you use the app. They appear on leaderboards. Every player
Last seen and lobby status A timestamp so others can tell whether you are around before inviting you to a game. Every player
Contact detail An optional email address or Discord handle. This is stored in a private area of your profile that our security rules make readable only by you. It is not shown on the map. Only you
Private notes A free-text scratchpad attached to your profile. Only you
The place name you typed The text you entered to set your location, before rounding. Kept privately so the field can be shown back to you when you edit your profile. Only you
Profile photo There is no avatar upload anywhere in the app. Player markers are drawn from your initials. Not collected
Real name, age, gender Never requested and never stored. Not collected

Messages and posts

Everything you write to another player. Read the retention section before you post.
FieldWhat it isVisible to
Direct messages One-to-one conversations: the text, who sent it, who received it, and when. Visible to you and the person you are talking to, and to us as the operator. Not visible to other players. Two of you
Global Frequency chat The app-wide room. Your message, your display name, and any emoji reactions you add are readable by everyone using the app. Every player
Battle Tips comments Community strategy notes, published openly — these can be read by anyone, without signing in or installing the app. Your display name is attached to each one, and so is a record of which comments you upvoted. You can delete your own comments. Anyone
Game night and tournament listings Title, description, date, recurrence, and the venue’s exact coordinates. Event locations are not blurred, because people need to find the venue. Do not list your home address unless you are content for every player to see it. Every player
Event RSVPs Whether you marked yourself going or interested, so organisers can plan numbers. Every player
Game invitations Sender and recipient names and IDs, an optional message, the scenario, and a room code. Two of you
Remote game rooms While playing at a distance: your hand, the cards played, turn numbers, and in-room chat. Shared with your opponent. Two of you

On your device and in your own records

Data tied to your installation, plus the permissions the app asks for.
FieldWhat it isVisible to
Match log Your recorded games: scenario, side, result, medals, rating change, notes, and the opponent’s name as you typed it. Private to you. Only you
Notification settings Whether nearby alerts are on, your chosen radius (1–100 km), and the push token that lets Apple deliver a notification to your device. Only you
Subscription expiry When your subscription access expires. This billing record is owner-only; the premium status flag on your commander profile can be visible when that profile is public. Only you
Precise GPS coordinates Your device’s exact fix is used on the device to work out the blurred value and to check what is near you. The unrounded position is not published to other players. Only you
Calendar Adding a game night to your calendar needs calendar permission, and the app writes that one event to your device. It never reads your existing events, and no calendar data is sent to us or to anyone else. Not collected
Camera, microphone, photos, contacts The app does not request or use any of these. Not collected
Advertising identifiers No ads, no attribution SDKs, no cross-app tracking, no IDFA prompt. Not collected
Payment card details Purchases are handled entirely by Apple or Google. We never see your card number, billing address, or full name. Not collected

Location, in detail

Location is the part of this app most worth explaining carefully, because the whole point of the player map is to be findable while staying safe.

Nothing about location happens unless you choose it. If you never build a profile, no location is stored. When you do, you type a place name rather than dropping a pin on your house; the app turns that text into coordinates, then rounds them to two decimal places before saving. Two decimal places is roughly a kilometre in each direction, so your marker lands somewhere in your suburb rather than on your street. The public label is only ever the locality, region and country. On iPhone and iPad the map additionally draws your marker with a small random offset, so that a pin cannot be read as more precise than it is.

On Android the app asks only for approximate location permission — the operating system does not even give it a precise fix. On iOS it requests location while in use and works to a hundred-metre accuracy, which it uses on the device to derive the blurred value.

If you turn on nearby alerts, our server compares blurred positions to find players within your chosen radius and sends you a notification. That notification deliberately carries no coordinates — just the fact that someone checked in and roughly how far away. We never send your position to another player’s device.

One caveat about the address box on iOS: as you type a place name, the suggestions come from Apple’s search service, which means the fragments you type are sent to Apple under Apple’s privacy policy. On Android the equivalent lookup goes to Google.

Messages, and what you cannot take back

We want to be direct about this rather than bury it. Direct messages and in-game room chat cannot be edited or deleted once sent — not by you, and not through the app by us. It is a deliberate design choice that stops people rewriting arguments after the fact, but it means you should write as though those messages are permanent, because they are.

Two things work differently. Global chat messages are automatically deleted after seven days. Battle Tips comments you can delete yourself, from the comment itself.

We do not read your direct messages as a matter of course and there is no automated scanning of their content. We can technically access them as the database operator, and we would only do so to investigate a specific report of abuse, to fix a fault, or where the law requires it.

Notifications

Push notifications are optional and off until you allow them. If you do, we store a device push token so messages can be delivered. Notification previews include up to about a hundred characters of the message text, which means a snippet may appear on your lock screen — worth knowing if you share a device. You can revoke notifications at any time in your operating system settings, or turn nearby alerts off in the app.

Purchases

M44 Wallet supports yearly subscriptions and existing one-off lifetime unlocks. The purchase screen shows the available option, price and renewal terms before you pay. The transaction itself is handled by the App Store or Google Play, and we never receive your payment details. We use RevenueCat to check whether a purchase is valid; it receives a generated app-user identifier, your purchase and transaction history, and basic technical diagnostics. The app database records whether premium access is active and keeps subscription expiry in a separate owner-only billing record, so paid features stop when access expires. Existing lifetime unlocks do not expire. Deleting your profile does not cancel a subscription; manage subscriptions through your store account.

Refunds are handled by Apple and Google under their own policies, not by us — though do email us first if something has gone wrong, because we can often just fix it.

Analytics and diagnostics

Analytics here is minimal and, we think, unusually boring. On iOS we record two events: that a profile was updated, and that a profile was viewed. We do not use Crashlytics, and there is no third-party analytics, heatmapping, or session recording. Automatic screen tracking is switched off. The Android build has no analytics at all.

Firebase does collect standard technical information in order to work, such as your IP address, device model, operating system version, and app version, along with a Firebase installation identifier that distinguishes your copy of the app from anyone else’s. That identifier is not your advertising ID and is not shared for advertising. IP addresses are used to route your requests and to resist abuse; we do not use them to build a profile of you or to infer a precise location.

Who else handles your data

We are a very small operation and rely on established providers rather than running our own servers. Each one is a processor acting on our instructions:

We do not sell your personal information, and we do not share it for advertising, behavioural profiling, or cross-context targeting. Under laws such as the California Consumer Privacy Act, we do not “sell” or “share” personal information as those terms are defined. Beyond the processors above, we would only disclose data if legally compelled, to protect someone’s safety, or as part of transferring the app to a new owner — in which case this policy would travel with it and we would post notice here.

Why we are allowed to process this

If you are in the UK or the EU, the GDPR requires us to name a lawful basis for each purpose. Ours are:

Where consent is the basis, withdrawing it stops the processing going forward. We have no UK or EU establishment and, as a small independent developer processing minimal data on an occasional basis, we have not appointed an Article 27 representative; you can raise anything directly with us at the address below.

Where your data is held

Data is stored in Google Cloud infrastructure, which may be in a country other than yours, including the United States. Google maintains standard contractual clauses and similar safeguards for transfers out of the UK, EU, and other regions. The developer is based in Australia.

How long it is kept

Your choices and your rights

The most effective privacy control in this app is simply not filling in the optional parts. The dice roller, scenario library, hex reference, battle tracker and match log all work with no profile, no location, and no network account at all. Connect is opt-in.

Beyond that, you can edit or clear your display name, location, availability, contact detail and notes at any time from the profile screen, switch your public profile off to remove your pin from the map, turn messaging off so nobody can start a conversation with you, and revoke location or notification permission in your device settings.

Depending on where you live you may have rights to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to complain to your data protection authority — the ICO in the UK, your national authority in the EU, or the OAIC in Australia. We honour these requests regardless of where you live, and we will not treat you differently for making one.

The honest limitation

Because the app has no accounts, we usually cannot verify that a particular anonymous ID belongs to the person emailing us. Handing over data on the strength of an unverified email would itself be a privacy failure. So for access and deletion, the in-app controls are the real mechanism — see the deletion page. If you have lost access to the installation, email us and we will do what we can, but we may have to say no.

Children

M44 Wallet is not directed at children under 13, and we do not knowingly collect their personal information. Because the app has an open chat room and a public map, we would rather younger players did not use the Connect features at all. If you believe a child has provided personal information through the app, email us and we will remove it.

We are committed to follow the Google Play Families policy.

Security

All traffic between the app and our services is encrypted in transit. Access to the database is governed by server-side security rules with an automated test suite covering them, so private fields such as your contact detail and notes are readable only by your own installation. The Android build additionally uses Play Integrity to make it harder to reach our backend from outside the real app.

No system is perfect, and it would be dishonest to promise otherwise. If we discover a breach affecting your personal data, we will notify affected users and the relevant regulator as required by law. If you have found a security issue in the app or backend, please report it to sean.gambles@gmail.com — reports made in good faith are welcome and we will not pursue researchers who act responsibly and avoid touching other players’ data.

Changes to this policy

If we change how the app handles your data, we will update this page and move the effective date at the top. Material changes will be flagged in the app as well. Older versions are available on request.

Contact

Privacy questions, deletion requests, and complaints all go to the same place: sean.gambles@gmail.com. It is one developer answering, so please allow a few days.