Munch Loop Privacy Policy
Effective date: 2026-09-27
Last updated: 2026-10-10
This policy explains what data the game Munch Loop (the "game") processes, who processes it, why, and the choices you have. It applies to both versions of the game:
- the iPhone app from the Apple App Store (bundle ID com.sparetimevc.munchloop), and
- the Android app from Google Play (package name com.sparetimevc.munchloop).
Where the two differ, this policy says so.
In short:
- There is no account, no login, no chat and nothing you type in. Your progress, coins, outfits and settings are stored only on your device (and in your own device backup, if you use one, and on iPhone in your own iCloud). We do not run servers that receive them.
- The game is free because it shows ads. Ads come from Unity (Unity LevelPlay mediation, formerly ironSource, and the Unity Ads network). Unity receives device and usage data to show, measure and protect ads.
- You can buy optional items in the game (Remove ads, a Starter pack, coin packs). Google Play or Apple handle the payment: we never see your card or other payment details. Purchases are checked and remembered through RevenueCat, which works for us and uses a random ID, not your name.
- We use Google Firebase Analytics to see how the game is played and Firebase Crashlytics to fix crashes. Where your privacy choices allow personalized ads, or where the game asks for no privacy choices (outside the EEA, the UK, Switzerland and the United States), and on iPhone only if you also allow tracking, Google may also use this analytics data, including your device's advertising ID, to measure and improve our own ads for the game on Google (section 3.6).
- Nothing is asked when you first open the game. After you finish the first (tutorial) level, the game asks for your privacy choices where the law requires it, and on iPhone iOS may then ask whether the game can track you. You can change your answers later (see "Your choices").
1. Who we are
The game is published by Spare Time Ventures LLC, 30 North Gould Street, STE R, Sheridan, WY 82801, USA ("we", "us"). We are the controller of the personal data described here, for the purposes of the EU and UK General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection, and the "business" under US state privacy laws such as the California Consumer Privacy Act as amended by the CPRA (CCPA).
Contact: [email protected]
2. Data that stays on your device
The game saves your level, coins, boosters, album, outfits, daily-gift streak, event progress, sound, music and language settings, your privacy answer, and the list of store purchases it has already credited (so that a purchase pays out exactly once), in the app's local storage on your iPhone or Android device. This data is not sent to us or to anyone else. Deleting the app deletes it from the device.
If you use your device's own backup (iCloud on iPhone, Android backup to your Google account), the backup may include this save and, on Android, RevenueCat's anonymous app user ID, so that your progress and purchases come back on a new device. These backups belong to your Apple or Google account; we cannot access them. On iPhone, the game also keeps a copy of the save in your own iCloud (iCloud key-value storage of your Apple Account), so that your progress comes back when you reinstall the game and follows you to your other Apple devices; it stays there when you delete the app, and we cannot access it.
3. Data processed by our partners
We do not receive your name, email address, phone number, contacts, photos, precise location or payment details: the game never asks for them. The partners below receive data directly from the software (SDK) they provide inside the game.
3.1 Ads: Unity LevelPlay and Unity Ads (Unity Technologies)
When ads are running, the Unity LevelPlay SDK (mediation) and the Unity Ads SDK (the ad network) collect and process:
- Device identifiers:
- On iPhone: the Identifier for Advertisers (IDFA), only if you allow tracking in the iOS prompt; otherwise identifiers that are not the IDFA, such as the Identifier for Vendors (IDFV).
- On Android: the Android advertising ID (also called the Google advertising ID), unless you deleted it in your Android settings (section 4), and the App Set ID, an identifier shared only by apps of the same developer on your device.
- On both: identifiers Unity generates for the app installation.
- Device and network data: device model and type, operating system and version, language, time zone, screen size, volume and battery state, network type, carrier, and your IP address, from which an approximate location (country, region or city) is derived.
- Ad and usage data: which ads were requested and shown, whether you watched, closed or tapped an ad, which reward placement it was for, and session information such as when the app was opened.
- Diagnostics: SDK errors and performance data about ad loading and display.
Unity uses this data to choose and show ads, cap how often you see the same ad, measure and report ad performance and revenue, attribute installs to ad campaigns, and detect and prevent fraud and invalid traffic. With your consent (where it is required) or unless you opted out of the sale or sharing of your personal information, and, for the IDFA, only if you allowed tracking, Unity may also use the data to show you personalized ads based on your activity in other apps and websites.
Unity Technologies and its affiliates act as an independent controller of the data they collect through their SDKs: Unity decides how it uses the data for its own advertising services, as described in Unity's Game Player and App User Privacy Policy (section 12). You can exercise your rights with Unity directly: through the privacy ("i" / data privacy) icon shown in Unity ads, through Unity's "Do Not Sell or Share" page, or by writing to [email protected].
The Unity SDKs use device identifiers and similar technologies (not browser cookies) to recognize the app installation and, with your permission, the device across apps. Data collected by Unity may be processed as set out in Unity's Game Player and App User Privacy Policy. The opt-outs are described in section 4.
If you bought Remove ads or the Starter pack, the game no longer shows ads between levels; ads you choose to watch for a reward still come from Unity as described here.
We receive from Unity only aggregated reports and, for each ad shown, the network, ad format, placement, country and estimated revenue. We do not receive your advertising ID, IDFA or IP address.
3.2 Analytics: Google Analytics for Firebase (Google)
Depending on where you are and what you chose (section 4), the game sends Google:
- Game events: level started, won or lost (with the level number, its difficulty and whether it was an event level), continue used, tutorial completed, outfit bought, daily gift claimed, event level played, and each ad impression with its estimated revenue.
- Events Google collects automatically: first open, session start, engagement time, app and operating system updates, and in-app purchases (product, price and currency).
- Identifiers: an app instance ID created by Firebase, and on iPhone the IDFV. The Android advertising ID or, on iPhone, the IDFA only under the conditions of section 3.6 (Google ad measurement). Otherwise advertising storage is set to "denied" and Firebase Analytics does not use the IDFA or the Android advertising ID.
- Device data: device model, iOS or Android version, language, app version; an approximate location (country, region, city) derived from your IP address. Google Analytics does not log or store IP addresses.
In the EEA, the UK and Switzerland, the events wait in the game's memory until you answer and are dropped if you decline. In the United States they are sent from the first launch until you opt out; elsewhere they are sent from the first launch (section 4). We use this data to understand how the game is played (for example, which levels are too hard), to balance the game and to measure ad and purchase revenue. We do not link this data to any account, name or email address. For these analytics purposes Google processes the data on our behalf. Under the conditions of section 3.6, some of this data is also used for our own advertising on Google.
3.3 Crash reports: Firebase Crashlytics (Google)
Whenever analytics are on (see section 4), when the game crashes or hits an error it sends a crash report: the stack trace, the app and operating system version, device model, free memory and disk space, whether the device is jailbroken or rooted, the app state at the time, the last game events before the crash, and a random installation identifier. In the EEA, the UK and Switzerland, crash reports wait on the device until you answer; if you decline, they are deleted without being sent. We use them only to find and fix bugs. Google processes this data on our behalf.
3.4 In-app purchases: Google Play, Apple and RevenueCat
Payment. You buy with your Google Play or Apple account, through Google Play's billing system or the App Store. Google or Apple process the payment under their own terms and privacy policies (section 12); we never see or store your card number or other payment details. Google and Apple give us order records (order number, product, price, tax, country and date) that we need for accounting, taxes, refunds and fraud checks.
Checking and remembering purchases: RevenueCat. The game uses the RevenueCat SDK (RevenueCat, Inc., United States) to fetch the prices shown in the shop, confirm each purchase with Google Play or Apple, deliver it, and restore Remove ads and the Starter pack on a new install. RevenueCat processes:
- a random, anonymous app user ID that the RevenueCat SDK creates when the game first starts. We do not link it to your name, email address or store account;
- purchase and transaction data: the product, price and currency, the store's order or transaction number, the purchase token or receipt the store issues, the purchase date, the store country, and refunds;
- device and app data: device model, operating system and version, app version, SDK version, language and region settings;
- your IP address, which RevenueCat receives with each request and may use to estimate your country.
RevenueCat acts as our processor (a "service provider" under the CCPA): it processes this data only on our behalf and on our instructions, under a data processing agreement. The purchase data RevenueCat processes is not used for advertising and is not given to Unity or Google (the in-app purchase events Firebase records are covered by sections 3.2 and 3.6).
3.5 Apple and Google as app stores
Apple provides the App Store, iOS and the App Tracking Transparency prompt; Google provides Google Play, Google Play services and Android. If you have agreed to share usage and diagnostics data with app developers in your device settings, Apple or Google may give us aggregated, anonymous statistics about installs, crashes and app usage (on Google Play, the Play Console's statistics and Android vitals). Their processing is covered by their own privacy policies (section 12).
3.6 Measuring our own ads on Google (Google Ads)
We advertise Munch Loop with Google Ads (app campaigns that invite new players to install the game), and our Google Analytics property is linked to our Google Ads account for that. When this happens depends on where you are:
- In the EEA, the UK and Switzerland: only after you tapped Accept in the game's privacy dialog.
- In the United States: only after you tapped Continue in the game's privacy dialog, and only until you opt out of the sale or sharing of your personal information.
- Elsewhere: the game shows no privacy dialog, so it applies from the first launch.
- On iPhone, in every region, it also needs your permission in the iOS tracking prompt.
Only then does the game tell Firebase that advertising storage, ad user data and ad personalization are allowed. In every other case (for example after Decline, after "Do Not Sell or Share My Personal Information", before you answer, or on iPhone without tracking permission) they stay "denied" and nothing in this section applies.
When it applies:
- Firebase Analytics also collects the Android advertising ID (on iPhone, the IDFA), in addition to the data in section 3.2.
- Google uses that identifier, the app instance ID and the game events of section 3.2 (for example the first open, levels played and won, in-app purchases with their price, and ad impressions with their estimated revenue), with device data and approximate location, to attribute installs and in-game actions to our ads (which of our ads led to an install and what the player did next), to measure and optimize our campaigns so that they reach people likely to enjoy the game, and to build advertising audiences and personalize ads on Google's services and its partners' (for example, to avoid showing our ads to people who already play).
- Google receives this data and uses it for its advertising services as an independent controller, under its own privacy policy. How Google uses information from apps that use its services: https://policies.google.com/technologies/partner-sites
- We see only aggregated campaign reports in Google Ads (installs, actions and revenue per campaign, country or ad); we do not receive your advertising ID or IDFA.
How to stop it:
- In the EEA, the UK, Switzerland and the United States: in the game, gear button > Settings > Privacy choices (Decline, or "Do Not Sell or Share My Personal Information"). Your choice applies from then on.
- On iPhone, in every region: do not allow tracking, or turn it off later in iOS Settings > Privacy & Security > Tracking. The iPhone app then sends no Google ad measurement data.
- Elsewhere on Android the game has no in-game setting for this. Deleting your advertising ID in the Android settings (section 4) removes the identifier, but game events may still reach Google Ads linked to the app instance ID. To stop all collection, delete the app; to have data already collected deleted, contact us (section 9, "How to make a request").
You can also manage the ads Google shows you in My Ad Center: https://myadcenter.google.com
4. When data collection starts, and your choices
- First launch and tutorial: no ads, no consent prompt, no tracking prompt. In the EEA, the UK and Switzerland, analytics and crash reporting stay off until you answer: game events and crash reports from that time wait on the device and are sent only if you agree. In the United States and everywhere else, analytics and crash reporting run from the first launch; in the United States you can turn them off (below). Outside the EEA, the UK, Switzerland and the United States, the Android app also allows the Google ad measurement of section 3.6 from the first launch; on iPhone it waits for the tracking prompt (step 3).
- After you win the first level, the game asks for your privacy choices, depending on where you are:
- In the EEA, the United Kingdom and Switzerland: "Ads keep Munch Loop free", with Accept and Decline, both equally visible. Accept allows personalized ads and analytics, including the measurement of our own Google ads (section 3.6); Decline means you still see ads, but not personalized, and no analytics, crash reports or Google ad measurement data are sent.
- In the United States: "Ads keep Munch Loop free", with Continue and Do Not Sell or Share My Personal Information. Continue allows personalized ads and Google ad measurement (section 3.6). Opting out turns off personalized ads, analytics, crash reports and Google ad measurement from then on, and deletes crash reports not sent yet.
- Elsewhere: no dialog, and no privacy setting in the game. Personalized ads, analytics, crash reports and Google ad measurement (section 3.6; on iPhone only with tracking permission) are on from the first launch. What you can do: on iPhone, the tracking prompt (step 3) and iOS Settings; on Android, the advertising ID settings (below); everywhere, deleting the app, which stops all collection, and asking us to delete data (section 9).
- On iPhone, iOS may then ask "Allow Munch Loop to track your activity across other companies' apps and websites?" This is shown only if you did not decline or opt out in step (section 3.6); if not, the IDFA is never available to the game or its partners, and the iPhone app sends no Google ad measurement data. Android has no such prompt: the Android advertising ID is controlled in the Android settings (below).
- If you allow it, Unity may use the IDFA for ads and Google may use it to measure our own ads
- Then the ad SDK starts.
The game plays the same whatever you choose. Nothing is locked behind a privacy answer. Purchases work the same whatever you choose: RevenueCat's processing (section 3.4) is needed to deliver what you buy and does not depend on the privacy dialog. It happens only when the shop is used or a purchase is checked.
Change your choice at any time (EEA, UK, Switzerland and United States, where the game shows the dialog): in the game, tap the gear button > Settings > Privacy choices. The same dialog opens and your new answer applies from then on (and is passed to Unity and to Firebase). Elsewhere the game has no dialog and no Privacy choices button; the device settings below still apply.
- iPhone: tracking permission is changed in iOS Settings > Privacy & Security > Tracking (or Settings > Munch Loop > Allow Tracking). You can also reset the IDFV-based analytics identity by deleting the app.
- Android: in the Android Settings > Privacy > Ads (on some older versions Settings > Google > Ads), Delete advertising ID removes the advertising ID: apps, including this game's ad SDKs and Firebase, then receive only zeros. Reset advertising ID replaces it with a new one. Deleting the app resets the game's other identifiers (Firebase, Unity and RevenueCat installation IDs).
Asked again after the update of 2026-10-10: the privacy dialog now also names Google as a recipient (section 3.6). If you are in the EEA, the UK or Switzerland and answered the dialog before this update, the game asks for your choices again after you update. Until you answer, analytics, crash reports, personalized ads and Google ad measurement stay off, as on a first launch. Answers given in the United States stay as they are; you can change them in the game at any time as described above.
5. Purposes and legal bases (EEA, UK, Switzerland)
| Purpose | Data | Legal basis |
|---|
| Showing ads (non-personalized), frequency capping, ad delivery | Device and network data, installation identifiers, ad interaction data | Our legitimate interest in funding a free game with ads (Art. 6(1)(f) GDPR). Unity's own processing: see Unity's policy. |
| Preventing ad fraud and invalid traffic, security | Same as above | Legitimate interest (Art. 6(1)(f)) of us and Unity in secure, honest advertising |
| Personalized ads, ad measurement across apps | IDFA (only with iOS tracking permission) or Android advertising ID, device and usage data | Your consent (Art. 6(1)(a)); access to the device identifier also under the ePrivacy rules that require consent |
| Measuring and optimizing our own ad campaigns on Google, advertising audiences (section 3.6) | Android advertising ID or IDFA (only with iOS tracking permission), app instance ID, game events (first open, levels played and won, in-app purchases, ad impressions and revenue), device data, approximate location | Your consent (Art. 6(1)(a)), given with Accept in the privacy dialog; access to the device identifier also under the ePrivacy rules that require consent. Google's own processing: see Google's policy. |
| Selling, delivering and restoring in-app purchases | RevenueCat's anonymous app user ID, purchase and transaction data, device and app data, IP address | Performing the contract you enter when you buy (Art. 6(1)(b)) |
| Accounting, taxes and refunds | Order records from Google Play and Apple | Our legal obligations (Art. 6(1)(c)) |
| Preventing purchase fraud | Purchase and transaction data | Legitimate interest (Art. 6(1)(f)) in not delivering fake or refunded purchases |
| Game analytics | Game events, app instance ID, IDFV (iPhone), device data, approximate location | Your consent (Art. 6(1)(a)) |
| Crash reports | Crash data, installation ID | Your consent (Art. 6(1)(a)) |
| Keeping your progress | Save data on your device | Not sent to us; performing the game you asked to play (Art. 6(1)(b)) |
You can withdraw consent at any time (section 4). Withdrawal does not affect processing that happened before.
6. How long data is kept
- On your device: until you delete the app.
- Firebase Analytics: user-level and event-level data are kept for 14 months, then deleted. Aggregated reports without identifiers may be kept longer.
- Firebase Crashlytics: crash reports and their identifiers for 90 days.
- Google Ads (section 3.6): Google keeps the data it uses for its advertising services as described in its privacy policy; what we see in our Google Ads account is aggregated.
- RevenueCat: purchase records are kept while the game sells in-app purchases, so that purchases can be restored and refunds handled, and are deleted when you ask us (section 9) or when we stop using RevenueCat. Your purchases themselves stay with your Google Play or Apple account.
- Order records from Google Play and Apple: as long as tax and accounting law requires us to keep them.
- Unity: Unity keeps personal data as long as needed for the purposes it was collected for. Its policy states that app interaction data associated with an installation ID is kept for up to 12 months and transaction records for up to 180 days.
7. International transfers
Unity, Google and RevenueCat process data in the United States and other countries where they or their service providers operate.
- Google (Firebase and Google Ads) is certified under the EU-US Data Privacy Framework, its UK extension and the Swiss-US Data Privacy Framework, and uses the European Commission's Standard Contractual Clauses where the Framework does not apply (Firebase Data Processing and Security Terms; Google Ads Controller-Controller Data Protection Terms).
- Unity relies on adequacy decisions where they exist and on the European Commission's Standard Contractual Clauses for transfers to countries without one, such as the United States (Unity's privacy policy).
- RevenueCat stores data with Amazon Web Services in the United States. Transfers are covered by the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum and their Swiss adaptation (RevenueCat's Data Processing Addendum).
8. Children
Munch Loop is a general audience game. It is not directed at children under 13: it is not in the App Store Kids category or in Google Play's Families program, and its target audience on Google Play is 13 and over. We do not knowingly collect personal data from children under 13. The game has no chat, no user-generated content and no account. In-app purchases are made with the store account, where parents can require approval for purchases (Google Play parental controls and Family Link, Apple's Ask to Buy). The game is registered with Unity as "not directed to children" under the US Children's Online Privacy Protection Act (COPPA).
If you are under the age at which you can give consent yourself where you live (between 13 and 16 in the EEA and the UK), ask a parent before accepting personalized ads and analytics, or choose Decline / Do Not Sell or Share, and before buying anything. The game plays the same either way.
If you are a parent and believe your child under 13 has used the game and data was collected, contact us at [email protected]: we will ask Google, Unity and RevenueCat to delete the data we can identify. Deleting the app removes the local data and stops all collection. Refunds for purchases are requested from Google Play or Apple.
9. Your rights
EEA, UK and Switzerland
You have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing (including processing based on legitimate interests), to data portability, and to withdraw consent at any time. You can also lodge a complaint with your data protection authority.
United States (California and other states with consumer privacy laws)
- Categories collected in the last 12 months: identifiers (IDFA with permission, IDFV, Android advertising ID, app instance, installation and anonymous app user IDs, IP address); commercial information (in-app purchase records); internet or other electronic network activity (game events, ad interactions, device and app data); approximate geolocation derived from the IP address (not precise geolocation); diagnostics. No sensitive personal information.
- Sources: your device, through the SDKs described in section 3, and Google Play or Apple for order records.
- Notice at collection: analytics and crash reporting (section 3.2 and 3.3) start when you first open the game; personalized ads and Google ad measurement (section 3.6) only after the privacy choices shown once you win the first level; purchase data when you open the shop or buy (section 3.4). The purposes are in section 5 and how long data is kept in section 6.
- "Sale" and "sharing": making identifiers and ad interaction data available to Unity for personalized (cross-context behavioral) advertising, game analytics processed by Google, and making the advertising ID, game events, purchases and ad revenue available to Google to measure and target our own ads (section 3.6) may count as a "sale" or "sharing" under the CCPA and similar laws. Purchase data processed by RevenueCat is not sold or shared. We do not sell or share data for any other reason, and we do not knowingly sell or share the personal information of consumers under 16.
- Your rights: to know what we collect and disclose, to delete, to correct, to opt out of sale, sharing and targeted advertising, and not to be discriminated against for using these rights. We do not use sensitive personal information, so the right to limit its use does not apply.
- Do Not Sell or Share My Personal Information: in the game, gear button > Settings > Privacy choices > "Do Not Sell or Share My Personal Information". You can also email [email protected] with the subject "Do Not Sell or Share".
- An authorized agent may make a request for you with your signed permission.
How to make a request, including deletion
Email [email protected]. Because the game has no account, we do not know who you are: to find data about you we need the identifiers our partners use, which are not shown in the game.
- Purchases: include the order number from your receipt (Google Play: the number starting with "GPA." in the receipt email or in the Google Play app > Payments and subscriptions > Budget and history; Apple: the order ID in the receipt email or at reportaproblem.apple.com). With it we find and delete the RevenueCat record of your purchases. What you bought stays with your store account, so "Restore purchases" still gives Remove ads back.
- Ads and analytics: we explain what we can do and pass deletion and objection requests to Google and Unity. You can also go to Unity directly (section 12).
We answer within the time the law requires (one month under the GDPR, 45 days under the CCPA). Deleting the app erases all local data and stops all collection at once.
10. Security
Data sent by the SDKs is encrypted in transit (HTTPS). We do not store any player data on our own systems. Access to the Firebase, Google Analytics, Google Ads, Unity, RevenueCat, Google Play Console and App Store Connect dashboards is limited to the people who work on the game.
11. Changes to this policy
If this policy changes, we will update this page and the "Last updated" date. For significant changes affecting consent, the game will ask for your choices again. The update of 2026-10-10 (Google Ads measurement, section 3.6) is such a change: players in the EEA, the UK and Switzerland are asked again (section 4).
12. Our partners' privacy policies
13. Contact
Spare Time Ventures LLC, 30 North Gould Street, STE R, Sheridan, WY 82801, USA Email: [email protected]