Privacy Policy

AOT-PRIV-2026-01 · Version 1.0 · Effective 12 August 2026 · Applies to Age of Towers 1.0.0 (com.ageoftowers.ios) and ageoftowers.com

In short: the Age of Towers app makes no network requests of any kind. It has no analytics, no advertising, no tracking, no accounts and no third-party SDKs. Everything you do in the game is stored on your device and never transmitted to us. We operate no servers for the app and receive no data from it.

The only processing described below that involves us at all concerns this website — and the purchase, which is handled entirely by Apple.

1. Controller

The controller within the meaning of Art. 4(7) GDPR for this website and for the Age of Towers app is:

Nuancebit GmbH
Brahmsstraße 4
37085 Göttingen, Germany
Managing Director: Cornelius Brosche
Email: info@nuancebit.com
Phone: +49 551 40135400 Amtsgericht Göttingen · HRB 207939 · VAT DE458081235

No Data Protection Officer has been appointed, as the thresholds of § 38 BDSG are not met.

2. Scope

This policy covers two separate things, and the difference between them matters:

Part A — The Age of Towers app

3. Nothing leaves your device

The app contains no networking code. It makes no HTTP requests, opens no sockets, and contacts no server operated by us or by anyone else. There is no analytics SDK, no crash-reporting SDK, no advertising SDK and no third-party framework of any kind in the app.

4. What is stored on your device

The game keeps its state locally, using Apple's standard on-device storage (UserDefaults and Core Data). This includes your campaign progress and completed levels, your three-star ratings, unlocked ages, research-tree state, resource balances, audio, haptics and accessibility settings, and whether the campaign unlock has been purchased.

This information stays in the app's private container on your device. It is not personal data processed by us, because we never receive it. It is included in your device backup only if you have enabled iPhone or iCloud backups yourself — that is a function of iOS, not of this app.

5. Required-reason API declarations

Apple requires apps to declare certain platform APIs and the reason for using them. For completeness, Age of Towers declares exactly three, all used purely on-device:

6. No permissions are ever requested

The app declares no usage-description keys, which means iOS never shows you a permission prompt for it. It has no access to your location, camera, microphone, photos, contacts, calendars, health data or motion data. There is no App Tracking Transparency prompt because there is nothing to track: no advertising identifier (IDFA) is read, and no tracking of any kind takes place.

7. No cloud sync

This version of Age of Towers does not synchronise anything to iCloud or any other cloud service. Your progress exists on the device you played on. If you delete the app, that progress is deleted with it.

8. Deletion

Deleting the app removes all game data from your device. There is nothing for us to delete on our side, because we never held it. If you have written to us by email, see section 12.

9. Children

The app collects no data from anyone, of any age. There is no advertising, no user-generated content, no chat, no social features and no external links inside gameplay. The only purchase is a single one-time unlock, which can be prevented entirely using iOS Screen Time or Ask to Buy.

Part B — Purchases and this website

10. The in-app purchase

Age of Towers offers one non-consumable in-app purchase (com.ageoftowers.unlock.lifetime). The entire transaction is conducted by Apple. We never see your name, address, payment details or Apple Account identifier. We receive only aggregated, anonymised sales and payout reports through App Store Connect, from which no individual buyer can be identified.

Restoring a purchase queries Apple, not us. For EU and EEA users the relevant Apple entity is Apple Distribution International Ltd., Ireland. Apple's own privacy policy governs that processing: apple.com/legal/privacy.

11. Hosting and server logs

This website is hosted on Cloudflare Pages (Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA; in the EU represented by Cloudflare Germany GmbH). When you load a page, the hosting provider processes technical data in server logs — your IP address, the time of the request, the page requested, the referrer and your browser's user agent.

The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in delivering this site securely and reliably and in preventing abuse. Logs are retained for a maximum of 14 days. A data processing agreement under Art. 28 GDPR is in place with Cloudflare. Transfers to the United States are covered by EU Standard Contractual Clauses under Art. 46(2)(c) GDPR and by Cloudflare's certification under the EU–U.S. Data Privacy Framework.

12. No cookies, no analytics, no consent banner

This site sets no cookies and uses no local storage. It runs no analytics, no tracking pixels, no social plugins and no embedded third-party content. It loads no external scripts and no external fonts — the single typeface used here is served from this domain, so no request is ever made to a font CDN.

Because nothing beyond what is technically necessary to deliver the page takes place, no consent is required under § 25 TDDDG and no cookie banner is shown. That is not an oversight.

13. Contacting us by email

If you write to us, we process your email address and whatever you put in your message in order to answer it. The legal basis is Art. 6(1)(b) GDPR where your request concerns a contract, and otherwise Art. 6(1)(f) GDPR. We delete such correspondence once the matter is closed, unless a statutory retention period (§ 147 AO, § 257 HGB) requires us to keep it.

14. Your rights

You have the right to:

In practice, because we hold no data from the app, a request for access will normally confirm that we hold nothing about you beyond any correspondence you started yourself. To exercise any of these rights, write to info@nuancebit.com.

15. Automated decision-making

We carry out no automated decision-making and no profiling within the meaning of Art. 22 GDPR.

16. Right to complain

You may lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:

Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover, Germany

You may also complain to the supervisory authority where you live or work.

17. Changes

If this policy changes materially, we will update it here and raise the version and effective date shown at the top of this page.