Privacy - Touch Grass

What this site collects, why, and what you can do about it. Nothing here has changed since 24 August 2026.

Who is responsible

Maffin e.U., Brochweg 12, 6100 Mösern, Austria.
Email: admin@dasmaffin.com. Full details on the imprint.

We are not required to appoint a data protection officer and have not appointed one. Write to the address above and you reach the person who runs this.

The site itself

This part applies wherever you are on the site. Last changed 13 August 2026.

Signing in with Steam

What is kept
Your SteamID, which is the public number identifying your Steam account, the moment you first signed in, the moment you last signed in, and which permissions on this site have been granted to you. Signing in happens at Steam: you type your password on Valve's pages, never on ours, and we never see it. Steam tells us the SteamID and nothing else.
What for
To know who you are between pages, and to decide what you are allowed to see.
On what basis
Article 6(1)(b) GDPR - it is what you asked for by signing in. There is nothing on this site you have to sign in to read unless it is somebody's private data.
For how long
Until you ask for it to be removed. Ask and it is removed.
Who can see it
You, and the accounts holding the permission to manage permissions.

Signing in with an email address

What is kept
Your email address, a hash of your password, when the account was made and when it was last used, and a name if you chose to give one. The password itself is never stored and cannot be recovered from what is: it is put through a one-way function with a random salt, and even we cannot read it back.
What for
So that somebody without a Steam account can have one here. The address is used for two letters and nothing else: one asking you to confirm it is yours, and one carrying a link to choose a new password, sent only when somebody asks for it. There is no newsletter, no announcement, and no way to opt in to one.
On what basis
Article 6(1)(b) GDPR - it is what you asked for by making an account.
For how long
Until you ask for it to be removed. Ask and it is removed.
Who can see it
You, and the company that carries the letters, which is the mail provider for this domain. They are handed the address and the letter in order to deliver it and for nothing else. Nobody else is sent it and nothing is shown it.

Two factor authentication, if you turn it on

What is kept
A random secret shared with your authenticator app, when the code was last used, and the one-way hashes of ten recovery codes. The secret is not a hash and cannot be one - working out the same six digits your phone shows means knowing the same number it does. Nothing about your phone is collected: no device name, no push token, and no contact with the app you chose, which never speaks to this site at all.
What for
So that knowing your password is not enough to sign in as you.
On what basis
Article 6(1)(b) GDPR - it is what you asked for by turning it on.
For how long
Until you turn it off, which deletes the secret and every remaining recovery code, or until the account is removed.
Who can see it
Nobody. It is never shown again after the setup screen and is not sent anywhere.

Staying signed in

What is kept
One cookie holding a session identifier. No advertising cookie, no analytics, no tracking pixel, and nothing loaded from another company's servers - every stylesheet, script and font on this site is served from this site.
What for
So that following a link does not sign you out.
On what basis
Strictly necessary for a service you asked for, so no consent banner and nothing to opt out of.
For how long
Until the session ends or you sign out.
Who can see it
Nobody. It is an identifier, not information about you.

Web server logs

What is kept
The ordinary record a web server keeps of each request: the IP address it came from, the time, the address requested, and the browser's own description of itself.
What for
Keeping the site up, and working out what happened when something breaks or somebody attacks it.
On what basis
Article 6(1)(f) GDPR - our interest in a site that works and is not abused.
For how long
By the hosting provider, under their retention. Nothing on this site reads them as a matter of course.
Who can see it
The site's operator and the hosting provider.

Touch Grass

This part applies to the Touch Grass pages and to anything that sends data to them. Last changed 24 August 2026.

Your player, and your progress

What is kept
An anonymous player id, made by Unity Gaming Services the first time you play, and the progress filed under it - score, upgrades, garden, currencies and settings. Signing in with Google Play Games links that progress to your Google Play account as well. Playing needs no real name and no email address.
What for
So a game can be saved, and picked up again on another day or another device.
On what basis
Article 6(1)(b) GDPR - saving a game is the thing you installed it for.
For how long
Until you ask for it to be deleted. Uninstalling clears what is on the phone; the cloud copy goes on request, which is what the address on this page is for.
Who can see it
You. Unity holds it as the service that stores it, and the game's own server holds the parts that belong to a guild.

The name and face you chose

What is kept
A display name you type, and an avatar picked from the set built into the game. No photographs - there is nothing to upload.
What for
So there is something to show beside your score, and in your guild.
On what basis
Article 6(1)(b) GDPR - a leaderboard with nobody's name on it is not one.
For how long
Until you change them, or your progress is deleted.
Who can see it
Everybody. These two are public by design: they appear on leaderboards and inside guilds, so do not use your own name unless you mean to.

Guilds, and what is said in them

What is kept
Which guild you are in, its name, description and banner, what you have contributed to it, and the chat messages you send.
What for
To run the social half of the game. Messages pass an automatic profanity filter on the way through.
On what basis
Article 6(1)(b) GDPR for the guild itself, and 6(1)(f) - a legitimate interest in a chat that is not abusive - for the filtering and the moderation.
For how long
While the guild exists, or until your data is deleted on request.
Who can see it
The other members of your guild, and whoever moderates it. Nothing said in a guild is private, so keep personal details out of it.

Your device, and how the game runs on it

What is kept
Device model, operating system version, language, screen settings, and the advertising id the phone provides. In-game events such as taps, upgrades and sessions, performance figures, and crash reports. Your IP address, and the city or country worked out from it.
What for
To find out what is broken, to fix crashes, and to know whether a change made the game better or worse.
On what basis
Article 6(1)(f) GDPR - a legitimate interest in a game that works on the phones people actually own.
For how long
By Unity, for as long as their analytics service keeps it.
Who can see it
The people who work on the game, and Unity as the provider of the service.

Advertising

What is kept
Your advertising id and similar data, used by Unity LevelPlay (ironSource) and the networks it mediates, Google AdMob and AppLovin among them.
What for
To show ads, to cap how often one appears, and to hand over the reward when you watch one on purpose.
On what basis
Your consent, where consent is required. In the EEA, the UK and other regions under the same rule the game asks on first launch, and the answer can be changed at any time.
For how long
By each ad provider, under its own policy - they are the ones holding it.
Who can see it
The ad providers. Two ways to limit it: buy Remove Ads, which stops ads being shown at all, or reset or delete your advertising id under Settings, Privacy, Ads on Android. Remove Ads stops the ads and not the measurement described in the next note.

Where an install came from

What is kept
Your device and advertising identifiers, your IP address, and the ad you interacted with and what you did in the game afterwards. Singular, a measurement partner, does this part.
What for
To know which advertisement led to an install, and whether the money spent on a campaign was worth spending.
On what basis
Article 6(1)(f) GDPR - a legitimate interest in knowing where players came from - and your consent where consent is required, asked at the same prompt as the ads.
For how long
By Singular, under its own policy at singular.net/privacy-policy.
Who can see it
Singular, and whoever runs the campaigns. Buying Remove Ads does not switch this off - it stops ads being shown, which is a different thing from measuring where you arrived from. Resetting or deleting your advertising id does limit it.

Things you buy

What is kept
A record of the in-app purchases and subscriptions on your account, Remove Ads among them. Not your card: payment goes through Google Play and the card details reach neither the game nor this site.
What for
To give you the thing you paid for, and to check a purchase is real before it is granted.
On what basis
Article 6(1)(b) GDPR to deliver it, and 6(1)(c) for the records a sale has to leave behind.
For how long
As long as the account has it, and as long afterwards as the law requires.
Who can see it
Google, as the shop. Nobody else needs to know what you bought.

Who else is involved

What is kept
Nothing further - this is who processes the above, each under its own policy: Unity Technologies (authentication, cloud save, leaderboards, economy, analytics and LevelPlay), ironSource, Google (Play services, Play Games, AdMob and Play Billing), AppLovin, and Singular Labs.
What for
So that "a third party" is never a phrase this policy hides behind.
On what basis
Not a separate purpose - the same processing, named.
For how long
See each provider: unity.com/legal/privacy-policy, is.com/privacy-policy, policies.google.com/privacy, applovin.com/privacy, singular.net/privacy-policy.
Who can see it
Saved progress, guilds and chat live on a server run for the game and nowhere else. Opening the community Discord from inside the game puts you under Discord's policy; the game itself sees only how many people are online, which is a number rather than a person.

Nothing is sold

What is kept
No personal information is sold, and none is shared for anybody else's advertising beyond what is described above.
What for
Worth saying plainly rather than leaving to be inferred from a list.
On what basis
Not processing - a limit on it.
For how long
Not applicable.
Who can see it
Data reaches the providers named above so they can do their jobs, other players where you chose to be social, and anybody the law obliges. That is the whole list.
Other parts of this site keep their own things:

What you can ask for

Under the GDPR you may ask us to:

For the rest, write to admin@dasmaffin.com from an address we can tie to your account, or include your SteamID. There is no form and no fee, and we answer within a month. Deleting is done by hand today, so ask and it is done rather than pressed.

If you are not happy with the answer

You can complain to the Austrian data protection authority: Osterreichische Datenschutzbehorde, Barichgasse 40-42, 1030 Wien, dsb@dsb.gv.at, dsb.gv.at. If you live in another EU country you may complain to your own authority instead.

Where it is kept

On servers rented from a hosting provider, who processes it on our behalf and under contract and does nothing else with it. Signing in involves Valve Corporation, whose own handling of your Steam account is described in the Steam Privacy Policy. We send Valve nothing about you; you are sent to them, and they tell us the SteamID you signed in with.

Children

Nothing here is aimed at children, and we do not knowingly keep data about anybody under 14. Tell us and it goes.

Changes

When this changes, the date at the top changes with it. There is no mailing list to be dropped from, because there is no mailing list.