Gold Digger · Privacy Policy
Privacy Policy — Gold Digger
App: Gold Digger
Package name: com.golddigger.classicminer
Data controller: LonkeroStudio, established in Finland (European
Union)
Contact for privacy questions: support@lonkerostudio.com
Last updated: 14 September 2026
This policy explains what happens to data when you play Gold Digger on Android. It is written against what the app actually ships, not against a template: the file list, the event list, the permission list and the SDK list below were read out of the built package and the source, not recalled.
LonkeroStudio is established in the EU, so the General Data Protection Regulation applies to everything in this policy — for every player, wherever you live, not only for players in Europe. Where a regime somewhere else gives you more, section 9 says so.
The short version
Gold Digger has no accounts, no login, no servers of its own, and no way for one player to reach another. Your progress lives in a file inside the app's own private storage on your device.
Two things can leave your device, and both go to Google:
- A small amount of progression data, sent to Google Analytics: five events saying which level you were on and how it went. They carry no name, no email, no account, no advertising ID and no free text. You control this with the CONSENT row in the settings screen on the title screen, and wherever consent is required it is off until you say yes.
- Advertising data, collected by the Google Mobile Ads SDK (AdMob) around a rewarded video ad you choose to watch — including your device's advertising ID, device and app identifiers, approximate location derived from your IP address, ad interactions and diagnostic data. Google uses it for advertising, measurement, fraud prevention and security.
Ads are optional: the game is complete without ever watching one.
Giving us any of this is entirely voluntary. It is not a statutory or a contractual requirement, you are under no obligation to provide it, and the only consequence of refusing is that we learn less about where the game is too hard. The game itself plays identically.
As this is written, no statistics are collected at all. A build sends nothing unless it has been given an Analytics measurement id, and no published build has ever carried one, so no event has ever been sent by anybody's copy of this game. The rest of this section describes what happens once a measurement id is configured; on the day one is, this paragraph is removed.
1. Gameplay statistics — Google Analytics
The five events, and this list is exhaustive
| event | what it carries |
|---|---|
level_start |
the level number and its act |
level_end |
the level, its act, whether it was won, and the seconds left |
boss_defeated |
which boss, and its act |
revive_watched |
the level a rewarded ad was watched on, and its act |
run_end |
the furthest level reached, its act, and whether it beat your record |
Every one of them additionally carries two measurements about the session it happened in, and nothing else:
| on every event | what it is |
|---|---|
engagement_time_msec |
how long you had been playing, in milliseconds, since the previous event. It counts only time with the game in front of you: it stops while the app is in the background, and no single event may report more than five minutes of it |
session_id |
a number marking one sitting, so that events from the same sitting can be counted together. It is held in memory only, never written to your device, and a new one begins after thirty minutes away |
They carry no name, no email, no account, no advertising ID and no free text.
Three things travel with them that are not in those tables, and you should know about all three:
- An install id. A random number, made on this device the first time statistics are permitted and kept in the app's private storage. It exists so that events from one play session can be counted together. It is not your advertising ID, it is never shared with the ad SDK, and it is not derived from anything about you — only from a random number and the device clock at the moment it was made.
- A country. Which country is read from your phone's language setting — the same setting that decides what language the system menus are in. It is not a location. A phone set to US English reports the United States wherever it actually is, and that is the point: it is deliberately too coarse to say anything about where you are. We send it so we can tell whether a level is too hard everywhere or only in some markets.
- Your IP address, because every internet request on the internet carries
one and Google receives it in the same way any website you visit does. We do
not ask Google Analytics to turn it into a location, and we do not send the
ip_overrideparameter that would let it. The country above is sent instead, precisely so that your IP does not have to be used for this.
Because the install id singles out one installation, this data is not anonymous; it is pseudonymous, and it is personal data under the GDPR. This policy treats it as such.
It exists to answer one question — which levels players stop on — so the difficulty can be fixed. It is not used for advertising, is never combined with ad data, and is never sold.
Your choice, and how the game decides
Where consent is required, the game asks you outright, once, before it stores anything. On the title screen — after the opening card, so that you have seen what the game is before being asked anything about it — a panel appears headed MAY WE COUNT YOUR RUNS?. It lists exactly what is above: the five events, the play time and the country, the random number that goes with them, and the fact that the data is not anonymous. It offers NO THANKS and YES, COUNT THEM, in that order, as the same size and in the same style as each other. Either answer is a final answer and the panel does not return.
You can also close the panel without answering — with its close button, by tapping outside it, or with your phone's back button. Closing it is not a yes. Nothing is recorded, nothing is sent and nothing is stored; the panel does not come back for the rest of that session, and it asks again the next time you start the game.
It is a separate question from the advertising one, and deliberately so. The consent form Google shows for ads is about advertising companies; it says nothing about our own statistics, and answering it — either way — is not treated here as an answer about them. Refusing everything in the ad form and saying yes here is a perfectly coherent position, and the game will do exactly that.
Nothing is stored for statistics before you answer. The random install id described above is not written to your device until the moment statistics are actually permitted, so if you say no, one is never created at all.
There is also a CONSENT row in the settings screen behind the gear on the title screen, for everyone. It opens the same panel, with a line at the top saying whether statistics are on or off right now, and the same two answers — so you can change your mind, in either direction, at any time. Your answer is recorded the moment you tap it.
Until you have answered one way or the other, the game does not guess in its own favour:
- Wherever Google's consent framework reports that consent is required — the EEA, the UK, and anywhere else it says so — nothing is sent unless you switch it ON. This is an opt-in, and switching it on is the consent we rely on.
- Everywhere else it starts on and you can switch it off, which stops it for good.
Switching it OFF stops all further events immediately. Nothing about the game changes; there is no feature behind it and no reward for leaving it on.
Two further facts, because both are true of the code and neither is obvious:
- A build that has not been given an Analytics measurement id sends nothing at all, whatever the switch says.
- In a build that has been given one, the install id file is created on first run even when statistics are switched off. Nothing is sent in that case — the file sits in the app's private storage, is never transmitted, and is deleted with the app. We would rather tell you about that than let you find it.
Storing things on your device — the ePrivacy rule
Separately from the GDPR, Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive, as amended by Directive 2009/136/EC), implemented in Finland by the Act on Electronic Communications Services (917/2014), governs storing information on — or reading information from — your device at all. It allows it without consent only where it is "strictly necessary in order to provide an information society service explicitly requested by the subscriber or user", or purely to carry a communication.
An analytics identifier is not strictly necessary to play a gold-mining game, and neither is an advertising identifier. So both are consent matters, and that is why the app is built the way it is:
| What is stored or read | How it is dealt with |
|---|---|
| Your save, your codex, your local ad count | Strictly necessary to provide the game you asked for — it is the game. No consent needed. |
| The statistics install id | Consent, where consent is required: statistics start off there and nothing is sent until you answer yes. |
| The advertising identifier and the ad SDK's own storage | Consent, collected in-app through Google's User Messaging Platform before the ad SDK starts. See section 2. |
This is an independent requirement from the GDPR lawful basis in section 8, not a restatement of it. Both have to be satisfied and both are addressed here.
Our role, and Google's
For these five events LonkeroStudio is the data controller and Google Analytics is our processor: the events land in an Analytics property we control, keyed only to that random install id. This is the one place where we — not Google — decide the purposes, set the retention period, and answer for your rights. See section 7.
2. Advertising — Google AdMob
Gold Digger shows rewarded video ads only. There are no interstitials and no banners. A rewarded ad is never forced: it is offered on the screen you see after losing a level, and watching one gives you extra seconds to retry. If you ignore it, nothing changes and the game plays exactly the same.
Ads are served by Google AdMob using the Google Mobile Ads SDK, which is embedded in the app. Where consent is required the app asks for it in-app through Google's User Messaging Platform (UMP) before it makes its first ad request — before it even starts the ad SDK. See section 8.
If the consent form cannot be shown — no network, or you close it without answering — the game may still request an ad, but it asks for a non-personalised one, which is the same kind of ad served to somebody who declines inside the form. This is a deliberate decision: the only ad in the game is one you asked for, and a player whose connection dropped should not lose the retry. It is written down here because it is a decision about your data.
When an ad is requested or shown, that SDK may collect and share with Google and its advertising partners:
- Device or other identifiers — the Android advertising ID (resettable and under your control), and other device and app identifiers.
- Approximate location — derived from your IP address. The app requests no location permission and has no access to GPS or precise location.
- App interactions — ad requests, impressions, clicks and rewards.
- Diagnostics — SDK errors and performance data.
- Device information — model, OS version, language, screen and network characteristics, sent with an ad request.
Purposes: serving and measuring advertising, capping how often you see an ad, fraud prevention, security and compliance, and analytics on the advertising itself.
Google sets the purposes and means for most of this collection itself, acting as a data controller in its own right for those purposes and as a processor for others; Google's own terms decide which is which. Its handling of the data is described in:
- Google Privacy Policy — https://policies.google.com/privacy
- How Google uses information from sites or apps that use its services — https://policies.google.com/technologies/partner-sites
- Google Advertising, including the list of ad partners — https://policies.google.com/technologies/ads
The data collected by the ad SDK is transmitted over HTTPS.
3. What the game stores on your device
The game writes these files into the app's private internal storage, a directory Android gives every app at install and enforces owner-only access to at the filesystem level:
| File | What is in it |
|---|---|
golddigger.save |
your run in progress, best scores, which bosses you have caught, your sound settings and your answer to the statistics question |
golddigger.save.tmp, golddigger.save.bak |
short-lived copies written while saving, so that losing power mid-save cannot cost you your run |
golddigger_ads.json |
a local count of rewarded ads you have watched, used only to pace the offer |
golddigger_codex.json |
which first-encounter cards you have already been shown |
golddigger_tel.json |
the random install id described in section 1 |
No permission is requested for any of this and no dialog is ever shown, because private app storage is not shared storage. None of these files contains a name, an email address, a phone number, an account, a contact, a photo, or a location.
The files themselves are never uploaded. The only thing inside any of them
that ever leaves the device is the install id in golddigger_tel.json, which is
sent with each statistics event as described in section 1 — and only when
statistics are switched on.
Uninstalling the app deletes all of them from the device. If Auto Backup has copied them to your Google account, see below.
Android Auto Backup
The app allows Android's standard Auto Backup. If Auto Backup is switched on in your device settings, Android — not the game — copies the app's private files into your own Google Drive backup, so that your progress follows you to a new phone. There are no backup exclusion rules in this app, so this covers every file in the table above, including the install id. A phone set up from that backup therefore keeps the same install id, and so does a reinstall restored from it.
This is a Google platform feature. The copy sits in your own Google account, the developer has no access to it, and you can switch Auto Backup off — and delete an existing backup — in your device's backup settings.
4. What the game does NOT do
- No user accounts, sign-in, or profiles.
- No crash-reporting SDK, and no analytics SDK: the five progression events are sent as plain HTTPS requests from the game's own code, not by an embedded analytics library.
- No server operated by the developer. The game talks to exactly two network endpoints, both of them Google's: Google Analytics, for the five events in section 1, and the Google Mobile Ads servers, for the ad.
- No in-app purchases, no billing, no payment details.
- No social features, chat, user-generated content or sharing.
- No access to contacts, photos, files, the camera, the microphone, the calendar, SMS, call logs, health data or precise location.
- No automated decision-making and no profiling in the sense of GDPR Art. 22: nothing about you is scored, ranked or decided by us. (Google's advertising systems do profile for ad selection; that is described in section 2 and governed by Google's own terms.)
- Nothing is sold for money. On "sharing" as California defines it, see section 9.
The game is fully playable offline and with the ad never watched.
5. Permissions in the package, and why each is there
Read from the built package, not from memory. INTERNET and
ACCESS_NETWORK_STATE are requested by the game itself — for the ad requests and
for the statistics requests. Every other one arrives with the ad SDK or one of
its own dependencies. None is requested at runtime and none opens a permission
dialog.
| Permission | Why |
|---|---|
INTERNET, ACCESS_NETWORK_STATE |
fetching a rewarded ad, sending the statistics events, and knowing whether the network is available |
AD_ID, com.google.android.gms.permission.AD_ID |
the advertising ID, used by AdMob |
ACCESS_ADSERVICES_TOPICS, ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION |
Android Privacy Sandbox interfaces used by the ad SDK |
READ_BASIC_PHONE_STATE |
declared by Google Play services; the app itself never reads phone state |
FOREGROUND_SERVICE, WAKE_LOCK |
declared by androidx.work, a library that arrives under the ad SDK. The game schedules no background work and starts no foreground service, and neither permission is used by any of its code |
There is no storage permission, no location permission, and no camera, microphone or contacts permission in the package.
6. Your choices
- Turn the statistics off — CONSENT, in the settings screen behind the gear on the title screen, then NO THANKS. It takes effect immediately, and where consent is required nothing is sent until you say yes in the first place.
- Reopen the advertising consent form. Where the game asked for your advertising consent, a PRIVACY OPTIONS button appears inside that same CONSENT panel and on the pause menu. It reopens Google's form so you can change the answer you gave, at any time.
- Read this policy in the game. The PRIVACY POLICY row on the same settings screen opens this page in your browser.
- Reset or delete your advertising ID. Android Settings → Privacy → Ads (the exact path varies by manufacturer). Deleting the advertising ID stops apps from receiving it.
- Opt out of ad personalisation in the same settings screen, and at https://adssettings.google.com.
- Simply do not watch the ads. The rewarded ad is optional and the game is complete without it.
- Play offline. With no network connection the game runs normally; no ad is requested and no event is sent.
- Delete everything local by uninstalling the app. If Android Auto Backup has copied the app's files, delete that copy from your device's backup settings.
7. How long data is kept, and your rights over it
What we hold, and what Google holds
For the five progression events we are the controller and Google Analytics is our processor. The events sit in our Analytics property, keyed only to the random install id. We keep them for 14 months — the data-retention setting on our Analytics property — after which Google deletes the event- and user-level records automatically.
For the data the ad SDK collects, Google decides the purposes and holds the data under its own policies and retention periods; see the links in section 2. We never receive it and cannot delete it for you. Section 6 has the controls that limit and reset it.
Everything else — your save, your codex, your ad count, the install id — stays on your device except through your own Google backup, and uninstalling deletes it.
Your rights
Under the GDPR you have the right to ask us for a copy of your personal data, to have it corrected or erased, to restrict or object to how we use it, to data portability, and — where we rely on your consent — to withdraw that consent at any time, without affecting the lawfulness of what was done before you withdrew it.
You may lodge a complaint with a supervisory authority. Ours, as a controller established in Finland, is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), https://tietosuoja.fi/en/. If you live elsewhere in the EU or the EEA you may complain to your own national authority instead — the list is at https://edpb.europa.eu/about-edpb/about-edpb/members_en. In the United Kingdom it is the Information Commissioner's Office, https://ico.org.uk/make-a-complaint/.
You can also write to us first, at the address at the top of this policy. We would rather hear from you than from an authority, and we will answer within one month.
Exercising them when there is no account — please read this part
We deliberately hold nothing that identifies you. The only thing tying a statistics event to a device is the random install id, the app does not show it to you, and we have no way of working out which id is yours. Nobody can: it is not derived from you or your phone, and it is kept in storage only your device's own operating system can read.
Article 11(2) of the GDPR covers exactly this situation. Where a controller can show it is not in a position to identify a person, the access, correction, erasure, restriction and portability rights do not apply unless that person supplies the extra information that would make identification possible. For us that extra information is the install id, and today there is no way for you to obtain it. So we must tell you plainly: we cannot find, export or delete your statistics record on request, because we cannot tell which one it is.
What you can do instead, and what it achieves:
- Say NO THANKS under CONSENT. All further collection stops at once. This needs no identification, and it is the right to object and the right to withdraw consent, honoured in one tap.
- Uninstall the app. The install id is deleted with it, so no future install can ever be joined to the old events either. (If Auto Backup restores the app, it restores the id too — see section 3.)
- Wait out the retention period above, after which Google deletes the existing records automatically.
If you can identify your own record and want it erased, write to the address at the top of this policy with the install id and we will delete it through Google Analytics' user-deletion tooling.
There is no in-app "delete my data" button today. Uninstalling is not the same thing as a deletion request, and this policy does not pretend it is.
Where the data goes
Both Google Analytics and the Google Mobile Ads SDK send data to Google, which processes it in the United States and in other countries outside the EEA. Google relies on its own approved transfer safeguards — the European Commission's standard contractual clauses and, where applicable, the EU-US Data Privacy Framework — described at https://business.safety.google/privacy/ and https://policies.google.com/privacy. You can obtain a copy of those safeguards through the pages linked there, or by writing to us.
8. Our legal bases
| What | Basis |
|---|---|
| Personalised rewarded ads | your consent, Art. 6(1)(a), given through the UMP form |
| Non-personalised rewarded ads | your consent to the ad request; Google relies on its own legitimate interests for fraud prevention and security |
| The five progression events, and creating the install id on your device | your consent, Art. 6(1)(a), given by answering YES, COUNT THEM — plus, separately, the ePrivacy consent described in section 1. Where Google's framework reports that consent is not required, the switch starts on and we rely on our legitimate interest in knowing where players stop so the game can be balanced (Art. 6(1)(f)); you can object at any time under CONSENT, and objecting ends it |
| Keeping your save, codex and local ad count on your device | necessary to provide the game you asked for; none of it reaches us |
We rely on no other basis, and we process none of this for any purpose beyond the one it is listed against here. For the ad data, Google's own legal bases, its partner list and its retention periods are in the links in section 2.
9. Region-specific notes
United Kingdom
The UK GDPR and the Privacy and Electronic Communications Regulations apply in the same shape as the European rules above. Your supervisory authority is the Information Commissioner's Office, https://ico.org.uk/make-a-complaint/.
California
Notice at collection. Through the Google Mobile Ads SDK, this app collects and discloses identifiers (the Android advertising ID and app or device identifiers), internet or other electronic network activity information (ad requests, impressions, clicks and rewards, and SDK diagnostics) and approximate geolocation derived from an IP address, for advertising, measurement, fraud prevention, security and compliance. With statistics switched on, the app also collects an identifier (the random install id) and internet or other electronic network activity information (the five progression events) for product analytics. Retention is as stated in section 7. No categories of sensitive personal information are collected.
Sale and sharing. We do not sell personal information for money. When you watch a rewarded ad and have not opted out of ad personalisation, the Google Mobile Ads SDK discloses your advertising ID and IP-derived signals to Google for interest-based advertising — which California law calls "sharing" for cross-context behavioral advertising, whether or not any money changes hands. We say that plainly rather than denying it.
How to stop it. Opt out of ad personalisation in your Android settings, reset or delete your advertising ID, or never watch an ad. Any of the three stops the sharing. The statistics events are never shared for advertising and are switched off under the CONSENT row.
Whether the CCPA applies to us. The California Attorney General states that the CCPA applies to for-profit businesses doing business in California that have gross annual revenue over $25 million, or buy, sell or share the personal information of 100,000 or more California residents or households, or derive 50% or more of their annual revenue from selling California residents' personal information (https://oag.ca.gov/privacy/ccpa). As at the "Last updated" date above, LonkeroStudio meets none of those three thresholds and the CCPA therefore does not apply to us. We have written this section anyway, and the controls above are available to everyone regardless of where they live. If we ever cross a threshold we will add a "Do Not Sell or Share My Personal Information" control and honour the Global Privacy Control signal, and this paragraph will change.
10. Children
Gold Digger is not directed at children. Its target audience declared in Google Play Console is ages 13 and over (the 13–15, 16–17 and 18+ age groups); no age group under 13 is selected. The app is not enrolled in Google Play's Designed for Families programme, and the developer does not knowingly collect personal information from children under 13.
Under Article 8 of the GDPR a child below the age set by the applicable national law cannot validly consent to an information society service on their own, and consent must be given or authorised by a parent or guardian. We do not knowingly rely on the consent of a child below that age.
If you believe a child has provided information through the ad SDK, use the ad-settings controls in section 6 and contact us at the address at the top of this policy; we will delete what we can identify. Parents in the United States can read about their rights under the Children's Online Privacy Protection Act at https://www.ftc.gov/business-guidance/privacy-security/childrens-privacy.
11. Changes
If this policy changes, the "Last updated" date at the top changes with it, and the current version always lives at the public URL registered in Google Play Console. Where a change affects what we do with data we have already collected, or introduces a purpose you have not agreed to, we will ask again rather than rely on this page having changed.
12. Contact
LonkeroStudio, Finland — support@lonkerostudio.com
Write to that address for anything in this policy, including the rights in section 7.