Anonymous usage measurement
So that we can see where an investigation breaks down, Indizio sends a few aggregate milestones to our own server: that the walkthrough was started, finished or abandoned, that the first, second or third case file was opened or solved, that the staged help was used, that the daily case was opened for the first, second or third time, that the case note confirmed three findings for the first time, that all three free case files are complete, and the outcome of the review prompt. For the three free case files we also count, per file, whether it was started, solved or left and whether its solution was viewed, with how many accusations and which highest help level it ended, in which rough time span (under 2, 2 to 5, 5 to 10 or over 10 minutes) it was solved in the last session, how far a left file had come and at which step the walkthrough was abandoned; a file is named only by a fixed number 1 to 3 with the version of its content, never by name. We also report the app's start time in coarse bands and from which fixed place (home screen, locked file, settings, after a case) the purchase page was opened and “Buy” was tapped. Purchase and restore events are sent as well. Only these fixed event names with fixed stage and reason codes are transmitted, together with the platform, the app version and the selected language. Each event additionally carries the coarse origin of the installation (store, test or developer installation) so that test traffic is counted separately; the origin is determined on the device without any device or installation identifier. If an event comes from the networks Google publishes for its automated pre-launch tests (Google Test Lab), AppCore also counts it as test traffic; the IP address is only compared for this and not stored. No account, device or advertising identifier, no case name, no saved progress and no text you typed is transmitted; we therefore cannot relate any of it to you. Individual events are deleted after 7 days. Daily totals of game and review events are deleted after at most 120 days; aggregate daily counters of purchase steps and purchase errors are kept without a fixed deletion date. The legal basis is our legitimate interest in an app that works and is understandable (Art. 6(1)(f) GDPR).
Updated: 7 October 2026
1. Controller
Christian Hermann & Martina Hermann GbR, An Rainen 3, 72525 Münsingen, Germany; email: apps@bitbeans.de.
2. Data processed
Game progress, completed cases, language and appearance settings are stored locally on the device.
For purchase verification, restoration, reinstallation and refund status, we process a random anonymous installation identifier, product ID, store platform and technical receipt data. There is no app account or visible sign-in.
Voluntary in-app feedback contains your message, an optional contact email address, app version, platform, the screen it was sent from and, if one already exists, the random guest identifier. Limited purchase diagnostics contain a fixed funnel stage, platform, app version and fixed failure reason; account, device, order and transaction identifiers are not transmitted.
Open case files and grid marks remain local. After a solved case, a guest identifier, event time, case or weekly challenge ID, culprit, evidence, optional liar, unlocked actions, hints and accusation attempts may be sent to AppCore for result verification. Unsent results enter a limited local retry queue. Narration usage is not recorded; there are no ads or advertising trackers.
Apple Game Center or Google Play Games may synchronize achievements and leaderboard scores with the service's player ID. Sign-in and visibility follow its device and account settings.
3. Purposes and legal bases
We process data to provide the app, verify purchases, deliver online features you actively use, maintain security, resolve errors and answer voluntary requests. Depending on the operation, the legal bases are Article 6(1)(b), (f) or, where expressly requested, (a) GDPR.
4. Recipients and service providers
We use Cloudflare for AppCore, secure purchase verification, refund status, voluntary feedback and internal email delivery; Apple and Google are used for store and payment services.
5. International transfers
Some providers may process data outside the EU or EEA. Where no adequacy decision applies, transfers rely on appropriate safeguards, in particular EU Standard Contractual Clauses, or on applicable statutory exceptions.
6. Advertising and tracking
The app contains no third-party advertising. We do not create advertising profiles, sell personal data or use advertising tracking.
7. Retention and security
Local data remains on the device until it is removed in the app or through system settings. Server data is retained only for as long as required for the respective function, security and statutory evidence. Transfers are encrypted.
8. Delete data and account
Local data can be removed in the app or through the device’s system settings. Where an account or cloud data exists, deletion can be requested in the app or by emailing apps@bitbeans.de. Store purchases are managed separately by Apple or Google.
9. Your rights
Subject to the statutory requirements, you have rights of access, rectification, erasure, restriction, portability and objection. Consent can be withdrawn for the future. You may also lodge a complaint with a data-protection authority; the LfDI Baden-Württemberg is the authority responsible for our registered office.
