Privacy - Touch Grass
What this site collects, why, and what you can do about it. Nothing here has changed since 24 August 2026.
Who is responsible
Maffin e.U., Brochweg 12, 6100 Mösern, Austria.
Email: admin@dasmaffin.com.
Full details on the imprint.
We are not required to appoint a data protection officer and have not appointed one. Write to the address above and you reach the person who runs this.
The site itself
This part applies wherever you are on the site. Last changed 13 August 2026.
Signing in with Steam
- What is kept
- Your SteamID, which is the public number identifying your Steam account, the moment you first signed in, the moment you last signed in, and which permissions on this site have been granted to you. Signing in happens at Steam: you type your password on Valve's pages, never on ours, and we never see it. Steam tells us the SteamID and nothing else.
- What for
- To know who you are between pages, and to decide what you are allowed to see.
- On what basis
- Article 6(1)(b) GDPR - it is what you asked for by signing in. There is nothing on this site you have to sign in to read unless it is somebody's private data.
- For how long
- Until you ask for it to be removed. Ask and it is removed.
- Who can see it
- You, and the accounts holding the permission to manage permissions.
Signing in with an email address
- What is kept
- Your email address, a hash of your password, when the account was made and when it was last used, and a name if you chose to give one. The password itself is never stored and cannot be recovered from what is: it is put through a one-way function with a random salt, and even we cannot read it back.
- What for
- So that somebody without a Steam account can have one here. The address is used for two letters and nothing else: one asking you to confirm it is yours, and one carrying a link to choose a new password, sent only when somebody asks for it. There is no newsletter, no announcement, and no way to opt in to one.
- On what basis
- Article 6(1)(b) GDPR - it is what you asked for by making an account.
- For how long
- Until you ask for it to be removed. Ask and it is removed.
- Who can see it
- You, and the company that carries the letters, which is the mail provider for this domain. They are handed the address and the letter in order to deliver it and for nothing else. Nobody else is sent it and nothing is shown it.
Two factor authentication, if you turn it on
- What is kept
- A random secret shared with your authenticator app, when the code was last used, and the one-way hashes of ten recovery codes. The secret is not a hash and cannot be one - working out the same six digits your phone shows means knowing the same number it does. Nothing about your phone is collected: no device name, no push token, and no contact with the app you chose, which never speaks to this site at all.
- What for
- So that knowing your password is not enough to sign in as you.
- On what basis
- Article 6(1)(b) GDPR - it is what you asked for by turning it on.
- For how long
- Until you turn it off, which deletes the secret and every remaining recovery code, or until the account is removed.
- Who can see it
- Nobody. It is never shown again after the setup screen and is not sent anywhere.
Staying signed in
- What is kept
- One cookie holding a session identifier. No advertising cookie, no analytics, no tracking pixel, and nothing loaded from another company's servers - every stylesheet, script and font on this site is served from this site.
- What for
- So that following a link does not sign you out.
- On what basis
- Strictly necessary for a service you asked for, so no consent banner and nothing to opt out of.
- For how long
- Until the session ends or you sign out.
- Who can see it
- Nobody. It is an identifier, not information about you.
Web server logs
- What is kept
- The ordinary record a web server keeps of each request: the IP address it came from, the time, the address requested, and the browser's own description of itself.
- What for
- Keeping the site up, and working out what happened when something breaks or somebody attacks it.
- On what basis
- Article 6(1)(f) GDPR - our interest in a site that works and is not abused.
- For how long
- By the hosting provider, under their retention. Nothing on this site reads them as a matter of course.
- Who can see it
- The site's operator and the hosting provider.
Touch Grass
This part applies to the Touch Grass pages and to anything that sends data to them. Last changed 24 August 2026.
Your player, and your progress
- What is kept
- An anonymous player id, made by Unity Gaming Services the first time you play, and the progress filed under it - score, upgrades, garden, currencies and settings. Signing in with Google Play Games links that progress to your Google Play account as well. Playing needs no real name and no email address.
- What for
- So a game can be saved, and picked up again on another day or another device.
- On what basis
- Article 6(1)(b) GDPR - saving a game is the thing you installed it for.
- For how long
- Until you ask for it to be deleted. Uninstalling clears what is on the phone; the cloud copy goes on request, which is what the address on this page is for.
- Who can see it
- You. Unity holds it as the service that stores it, and the game's own server holds the parts that belong to a guild.
The name and face you chose
- What is kept
- A display name you type, and an avatar picked from the set built into the game. No photographs - there is nothing to upload.
- What for
- So there is something to show beside your score, and in your guild.
- On what basis
- Article 6(1)(b) GDPR - a leaderboard with nobody's name on it is not one.
- For how long
- Until you change them, or your progress is deleted.
- Who can see it
- Everybody. These two are public by design: they appear on leaderboards and inside guilds, so do not use your own name unless you mean to.
Guilds, and what is said in them
- What is kept
- Which guild you are in, its name, description and banner, what you have contributed to it, and the chat messages you send.
- What for
- To run the social half of the game. Messages pass an automatic profanity filter on the way through.
- On what basis
- Article 6(1)(b) GDPR for the guild itself, and 6(1)(f) - a legitimate interest in a chat that is not abusive - for the filtering and the moderation.
- For how long
- While the guild exists, or until your data is deleted on request.
- Who can see it
- The other members of your guild, and whoever moderates it. Nothing said in a guild is private, so keep personal details out of it.
Your device, and how the game runs on it
- What is kept
- Device model, operating system version, language, screen settings, and the advertising id the phone provides. In-game events such as taps, upgrades and sessions, performance figures, and crash reports. Your IP address, and the city or country worked out from it.
- What for
- To find out what is broken, to fix crashes, and to know whether a change made the game better or worse.
- On what basis
- Article 6(1)(f) GDPR - a legitimate interest in a game that works on the phones people actually own.
- For how long
- By Unity, for as long as their analytics service keeps it.
- Who can see it
- The people who work on the game, and Unity as the provider of the service.
Advertising
- What is kept
- Your advertising id and similar data, used by Unity LevelPlay (ironSource) and the networks it mediates, Google AdMob and AppLovin among them.
- What for
- To show ads, to cap how often one appears, and to hand over the reward when you watch one on purpose.
- On what basis
- Your consent, where consent is required. In the EEA, the UK and other regions under the same rule the game asks on first launch, and the answer can be changed at any time.
- For how long
- By each ad provider, under its own policy - they are the ones holding it.
- Who can see it
- The ad providers. Two ways to limit it: buy Remove Ads, which stops ads being shown at all, or reset or delete your advertising id under Settings, Privacy, Ads on Android. Remove Ads stops the ads and not the measurement described in the next note.
Where an install came from
- What is kept
- Your device and advertising identifiers, your IP address, and the ad you interacted with and what you did in the game afterwards. Singular, a measurement partner, does this part.
- What for
- To know which advertisement led to an install, and whether the money spent on a campaign was worth spending.
- On what basis
- Article 6(1)(f) GDPR - a legitimate interest in knowing where players came from - and your consent where consent is required, asked at the same prompt as the ads.
- For how long
- By Singular, under its own policy at singular.net/privacy-policy.
- Who can see it
- Singular, and whoever runs the campaigns. Buying Remove Ads does not switch this off - it stops ads being shown, which is a different thing from measuring where you arrived from. Resetting or deleting your advertising id does limit it.
Things you buy
- What is kept
- A record of the in-app purchases and subscriptions on your account, Remove Ads among them. Not your card: payment goes through Google Play and the card details reach neither the game nor this site.
- What for
- To give you the thing you paid for, and to check a purchase is real before it is granted.
- On what basis
- Article 6(1)(b) GDPR to deliver it, and 6(1)(c) for the records a sale has to leave behind.
- For how long
- As long as the account has it, and as long afterwards as the law requires.
- Who can see it
- Google, as the shop. Nobody else needs to know what you bought.
Who else is involved
- What is kept
- Nothing further - this is who processes the above, each under its own policy: Unity Technologies (authentication, cloud save, leaderboards, economy, analytics and LevelPlay), ironSource, Google (Play services, Play Games, AdMob and Play Billing), AppLovin, and Singular Labs.
- What for
- So that "a third party" is never a phrase this policy hides behind.
- On what basis
- Not a separate purpose - the same processing, named.
- For how long
- See each provider: unity.com/legal/privacy-policy, is.com/privacy-policy, policies.google.com/privacy, applovin.com/privacy, singular.net/privacy-policy.
- Who can see it
- Saved progress, guilds and chat live on a server run for the game and nowhere else. Opening the community Discord from inside the game puts you under Discord's policy; the game itself sees only how many people are online, which is a number rather than a person.
Nothing is sold
- What is kept
- No personal information is sold, and none is shared for anybody else's advertising beyond what is described above.
- What for
- Worth saying plainly rather than leaving to be inferred from a list.
- On what basis
- Not processing - a limit on it.
- For how long
- Not applicable.
- Who can see it
- Data reaches the providers named above so they can do their jobs, other players where you chose to be social, and anybody the law obliges. That is the whole list.
What you can ask for
Under the GDPR you may ask us to:
- Show you what we hold about you (Article 15). You do not have to write to anybody for this one: your profile has a button that gathers it from every part of the site and sends it to you as a file, once a week.
- Correct it if it is wrong (Article 16).
- Delete it (Article 17).
- Stop using it while a disagreement is sorted out (Article 18).
- Hand it over in a form you can take elsewhere (Article 20).
- Object to any use we base on our own legitimate interest (Article 21).
For the rest, write to admin@dasmaffin.com from an address we can tie to your account, or include your SteamID. There is no form and no fee, and we answer within a month. Deleting is done by hand today, so ask and it is done rather than pressed.
If you are not happy with the answer
You can complain to the Austrian data protection authority: Osterreichische Datenschutzbehorde, Barichgasse 40-42, 1030 Wien, dsb@dsb.gv.at, dsb.gv.at. If you live in another EU country you may complain to your own authority instead.
Where it is kept
On servers rented from a hosting provider, who processes it on our behalf and under contract and does nothing else with it. Signing in involves Valve Corporation, whose own handling of your Steam account is described in the Steam Privacy Policy. We send Valve nothing about you; you are sent to them, and they tell us the SteamID you signed in with.
Children
Nothing here is aimed at children, and we do not knowingly keep data about anybody under 14. Tell us and it goes.
Changes
When this changes, the date at the top changes with it. There is no mailing list to be dropped from, because there is no mailing list.