Privacy policy
What the app knows about you
M44 Wallet is a companion app for the board game Memoir ’44. Most of it — the dice, the scenario reference, the hex grid, the battle tracker — never sends anything anywhere. The part that does is Connect, where players find each other and talk. This page lists every field that leaves your device and says plainly who can see it.
Effective 19 August 2026 · Version 1.0
At a glance
- There is no sign-up. No email address, no password, no name. The app creates an anonymous ID on first launch and that is your whole identity.
- Your location on the player map is deliberately blurred to roughly a kilometre, and to a town or region label. Your street address is never published.
- Anything you type into your public profile, a game night listing, the global chat, or Battle Tips is visible to other players. Treat those as public.
- We show no ads, use no advertising identifiers, and do not track you across other apps or websites.
- You can delete your profile and data. The deletion page explains how, and is honest about the parts that cannot be pulled back.
Who we are
M44 Wallet is published by SG Mobile Designs, a one-person independent studio (Sean Gambles). We are the data controller for the information described here. You can reach us at sean.gambles@gmail.com — it goes to a real person and it is the same address used for support and deletion requests.
M44 Wallet is an unofficial fan-made companion. It is not published by, endorsed by, or affiliated with Days of Wonder or Asmodee, and we share nothing with them.
You do not have an account
This is the most important thing to understand, because it shapes everything else. When you first open the app it signs in anonymously to Firebase and receives a random identifier — a string like UdT3k…. That identifier is the only thing linking your data together. We never ask for an email address or a phone number, and there is no password to lose.
The trade-offs are real and worth stating. Because there is no account, your data lives with that one installation: if you delete the app, reinstall it, or switch phones, you get a fresh identifier and cannot recover your old profile, match history, or conversations. It also means that if you email us asking to see or delete your data, we usually have no way to prove which anonymous ID is yours — so the in-app controls are the reliable route, not email.
The display name you choose is recorded in a public name registry so two players cannot claim the same one. That registry maps your chosen name to your anonymous ID and is readable by anyone signed in, which is how mentions and invitations work.
The ledger
Rather than describe categories in the abstract, here is the actual list. Every row is a field the app can store off your device. The right-hand column is the one to read.
- Every player — anyone using the app can see it
- Only you — plus us, as the operator
- Not collected
Your public profile
| Field | What it is | Visible to |
|---|---|---|
| Display name | The name you pick. Most players use a handle rather than their real name, and we recommend that. | Every player |
| Approximate location | Coordinates rounded to two decimal places — about a kilometre of imprecision — plus a town, region and country label. This is what places your pin on the map. | Every player |
| Availability note | Free text about when you like to play, e.g. “weeknights after 8”. | Every player |
| Open to messages | A yes/no switch controlling whether other players can start a conversation with you. | Every player |
| Points, streak, rank, badges | Totals recorded from how you use the app. They appear on leaderboards. | Every player |
| Last seen and lobby status | A timestamp so others can tell whether you are around before inviting you to a game. | Every player |
| Contact detail | An optional email address or Discord handle. This is stored in a private area of your profile that our security rules make readable only by you. It is not shown on the map. | Only you |
| Private notes | A free-text scratchpad attached to your profile. | Only you |
| The place name you typed | The text you entered to set your location, before rounding. Kept privately so the field can be shown back to you when you edit your profile. | Only you |
| Profile photo | There is no avatar upload anywhere in the app. Player markers are drawn from your initials. | Not collected |
| Real name, age, gender | Never requested and never stored. | Not collected |
Messages and posts
| Field | What it is | Visible to |
|---|---|---|
| Direct messages | One-to-one conversations: the text, who sent it, who received it, and when. Visible to you and the person you are talking to, and to us as the operator. Not visible to other players. | Two of you |
| Global Frequency chat | The app-wide room. Your message, your display name, and any emoji reactions you add are readable by everyone using the app. | Every player |
| Battle Tips comments | Community strategy notes, published openly — these can be read by anyone, without signing in or installing the app. Your display name is attached to each one, and so is a record of which comments you upvoted. You can delete your own comments. | Anyone |
| Game night and tournament listings | Title, description, date, recurrence, and the venue’s exact coordinates. Event locations are not blurred, because people need to find the venue. Do not list your home address unless you are content for every player to see it. | Every player |
| Event RSVPs | Whether you marked yourself going or interested, so organisers can plan numbers. | Every player |
| Game invitations | Sender and recipient names and IDs, an optional message, the scenario, and a room code. | Two of you |
| Remote game rooms | While playing at a distance: your hand, the cards played, turn numbers, and in-room chat. Shared with your opponent. | Two of you |
On your device and in your own records
| Field | What it is | Visible to |
|---|---|---|
| Match log | Your recorded games: scenario, side, result, medals, rating change, notes, and the opponent’s name as you typed it. Private to you. | Only you |
| Notification settings | Whether nearby alerts are on, your chosen radius (1–100 km), and the push token that lets Apple deliver a notification to your device. | Only you |
| Subscription expiry | When your subscription access expires. This billing record is owner-only; the premium status flag on your commander profile can be visible when that profile is public. | Only you |
| Precise GPS coordinates | Your device’s exact fix is used on the device to work out the blurred value and to check what is near you. The unrounded position is not published to other players. | Only you |
| Calendar | Adding a game night to your calendar needs calendar permission, and the app writes that one event to your device. It never reads your existing events, and no calendar data is sent to us or to anyone else. | Not collected |
| Camera, microphone, photos, contacts | The app does not request or use any of these. | Not collected |
| Advertising identifiers | No ads, no attribution SDKs, no cross-app tracking, no IDFA prompt. | Not collected |
| Payment card details | Purchases are handled entirely by Apple or Google. We never see your card number, billing address, or full name. | Not collected |
Location, in detail
Location is the part of this app most worth explaining carefully, because the whole point of the player map is to be findable while staying safe.
Nothing about location happens unless you choose it. If you never build a profile, no location is stored. When you do, you type a place name rather than dropping a pin on your house; the app turns that text into coordinates, then rounds them to two decimal places before saving. Two decimal places is roughly a kilometre in each direction, so your marker lands somewhere in your suburb rather than on your street. The public label is only ever the locality, region and country. On iPhone and iPad the map additionally draws your marker with a small random offset, so that a pin cannot be read as more precise than it is.
On Android the app asks only for approximate location permission — the operating system does not even give it a precise fix. On iOS it requests location while in use and works to a hundred-metre accuracy, which it uses on the device to derive the blurred value.
If you turn on nearby alerts, our server compares blurred positions to find players within your chosen radius and sends you a notification. That notification deliberately carries no coordinates — just the fact that someone checked in and roughly how far away. We never send your position to another player’s device.
One caveat about the address box on iOS: as you type a place name, the suggestions come from Apple’s search service, which means the fragments you type are sent to Apple under Apple’s privacy policy. On Android the equivalent lookup goes to Google.
Messages, and what you cannot take back
We want to be direct about this rather than bury it. Direct messages and in-game room chat cannot be edited or deleted once sent — not by you, and not through the app by us. It is a deliberate design choice that stops people rewriting arguments after the fact, but it means you should write as though those messages are permanent, because they are.
Two things work differently. Global chat messages are automatically deleted after seven days. Battle Tips comments you can delete yourself, from the comment itself.
We do not read your direct messages as a matter of course and there is no automated scanning of their content. We can technically access them as the database operator, and we would only do so to investigate a specific report of abuse, to fix a fault, or where the law requires it.
Notifications
Push notifications are optional and off until you allow them. If you do, we store a device push token so messages can be delivered. Notification previews include up to about a hundred characters of the message text, which means a snippet may appear on your lock screen — worth knowing if you share a device. You can revoke notifications at any time in your operating system settings, or turn nearby alerts off in the app.
Purchases
M44 Wallet supports yearly subscriptions and existing one-off lifetime unlocks. The purchase screen shows the available option, price and renewal terms before you pay. The transaction itself is handled by the App Store or Google Play, and we never receive your payment details. We use RevenueCat to check whether a purchase is valid; it receives a generated app-user identifier, your purchase and transaction history, and basic technical diagnostics. The app database records whether premium access is active and keeps subscription expiry in a separate owner-only billing record, so paid features stop when access expires. Existing lifetime unlocks do not expire. Deleting your profile does not cancel a subscription; manage subscriptions through your store account.
Refunds are handled by Apple and Google under their own policies, not by us — though do email us first if something has gone wrong, because we can often just fix it.
Analytics and diagnostics
Analytics here is minimal and, we think, unusually boring. On iOS we record two events: that a profile was updated, and that a profile was viewed. We do not use Crashlytics, and there is no third-party analytics, heatmapping, or session recording. Automatic screen tracking is switched off. The Android build has no analytics at all.
Firebase does collect standard technical information in order to work, such as your IP address, device model, operating system version, and app version, along with a Firebase installation identifier that distinguishes your copy of the app from anyone else’s. That identifier is not your advertising ID and is not shared for advertising. IP addresses are used to route your requests and to resist abuse; we do not use them to build a profile of you or to infer a precise location.
Who else handles your data
We are a very small operation and rely on established providers rather than running our own servers. Each one is a processor acting on our instructions:
- Google (Firebase) — anonymous sign-in, the Firestore database, cloud functions, push delivery, and the small amount of analytics described above. Covered by the Firebase privacy documentation.
- Google Maps Platform — renders the map and resolves place names on Android.
- Apple — App Store purchases, push delivery, and MapKit map rendering and address suggestions on iOS.
- RevenueCat — validates purchases and tracks entitlement.
We do not sell your personal information, and we do not share it for advertising, behavioural profiling, or cross-context targeting. Under laws such as the California Consumer Privacy Act, we do not “sell” or “share” personal information as those terms are defined. Beyond the processors above, we would only disclose data if legally compelled, to protect someone’s safety, or as part of transferring the app to a new owner — in which case this policy would travel with it and we would post notice here.
Why we are allowed to process this
If you are in the UK or the EU, the GDPR requires us to name a lawful basis for each purpose. Ours are:
- Performance of a contract — running the parts of the app you asked for: creating your anonymous identity, storing your profile, delivering your messages, showing the player map, and validating your purchase.
- Consent — location and push notifications, both of which are off until you grant permission, and both of which you can withdraw at any time in your device settings without losing access to the rest of the app.
- Legitimate interests — keeping the service working and secure, resisting abuse and spam, and the minimal analytics described above. We have weighed these against your privacy and kept the data involved deliberately small.
- Legal obligation — retaining what we must, and responding to lawful requests.
Where consent is the basis, withdrawing it stops the processing going forward. We have no UK or EU establishment and, as a small independent developer processing minimal data on an occasional basis, we have not appointed an Article 27 representative; you can raise anything directly with us at the address below.
Where your data is held
Data is stored in Google Cloud infrastructure, which may be in a country other than yours, including the United States. Google maintains standard contractual clauses and similar safeguards for transfers out of the UK, EU, and other regions. The developer is based in Australia.
How long it is kept
- Global chat messages — automatically deleted after 7 days.
- Direct messages and in-game chat — kept indefinitely, and cannot be deleted through the app.
- Your profile, notes, contact detail and notification settings — kept until you delete your profile.
- Match log — kept until you delete the entries or your profile.
- Event listings — kept until you remove them, or until the event’s expiry date passes where one has been set. Delete an event yourself once it is over; the listing does not disappear on its own.
- Battle Tips comments — kept indefinitely as part of the shared reference material.
- Analytics — retained on Google’s default schedule for Firebase Analytics.
- Purchase records — retained by Apple, Google and RevenueCat for as long as their accounting obligations require, which is typically several years.
Your choices and your rights
The most effective privacy control in this app is simply not filling in the optional parts. The dice roller, scenario library, hex reference, battle tracker and match log all work with no profile, no location, and no network account at all. Connect is opt-in.
Beyond that, you can edit or clear your display name, location, availability, contact detail and notes at any time from the profile screen, switch your public profile off to remove your pin from the map, turn messaging off so nobody can start a conversation with you, and revoke location or notification permission in your device settings.
Depending on where you live you may have rights to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to complain to your data protection authority — the ICO in the UK, your national authority in the EU, or the OAIC in Australia. We honour these requests regardless of where you live, and we will not treat you differently for making one.
The honest limitation
Because the app has no accounts, we usually cannot verify that a particular anonymous ID belongs to the person emailing us. Handing over data on the strength of an unverified email would itself be a privacy failure. So for access and deletion, the in-app controls are the real mechanism — see the deletion page. If you have lost access to the installation, email us and we will do what we can, but we may have to say no.
Children
M44 Wallet is not directed at children under 13, and we do not knowingly collect their personal information. Because the app has an open chat room and a public map, we would rather younger players did not use the Connect features at all. If you believe a child has provided personal information through the app, email us and we will remove it.
We are committed to follow the Google Play Families policy.
Security
All traffic between the app and our services is encrypted in transit. Access to the database is governed by server-side security rules with an automated test suite covering them, so private fields such as your contact detail and notes are readable only by your own installation. The Android build additionally uses Play Integrity to make it harder to reach our backend from outside the real app.
No system is perfect, and it would be dishonest to promise otherwise. If we discover a breach affecting your personal data, we will notify affected users and the relevant regulator as required by law. If you have found a security issue in the app or backend, please report it to sean.gambles@gmail.com — reports made in good faith are welcome and we will not pursue researchers who act responsibly and avoid touching other players’ data.
Changes to this policy
If we change how the app handles your data, we will update this page and move the effective date at the top. Material changes will be flagged in the app as well. Older versions are available on request.
Contact
Privacy questions, deletion requests, and complaints all go to the same place: sean.gambles@gmail.com. It is one developer answering, so please allow a few days.