Privacy Policy
Last updated: May 5, 2026
MindMirror AI ("we", "our", or "us") develops and publishes mobile games including Magnet Mayhem: Scrap City and Merge Market: Sort & Serve. This Privacy Policy explains how we collect, use, store, and protect your information when you use any of our games, applications, or services (collectively, "Services").
By using our Services, you agree to the practices described in this policy. If you do not agree, please do not use our Services.
1. Information We Collect
1.1 Account Information
When you sign in with Google (via Google Sign-In / Credential Manager), we receive:
- Display name
- Email address
- Profile photo URL
- Unique Google account identifier (UID)
This information is used to create and manage your game account, enable cloud saves, and provide social features.
1.2 Game Data (Cloud Saves)
When signed in, your game progress is stored in Google Firebase Cloud Firestore, including:
- Level progress, scores, and achievements
- Virtual currency balances (Scrap Metal, Gems)
- City-building progress and unlocked items
- Win streaks and statistics
- Settings and preferences
- Friend codes and friend list
- Challenge data sent to/from friends
1.3 Device and Technical Information
We automatically collect:
- Device type, model, and manufacturer
- Operating system and version
- App version
- Advertising ID (Android AD_ID, with your consent)
- Firebase installation ID
- Crash reports and diagnostic data
1.4 Usage and Analytics Data
Through Firebase Analytics, we collect:
- Session duration and frequency
- Levels played, completed, and failed
- Features used (e.g., combo system, city builder)
- In-game events (purchases, ad views, achievements)
- App open/close events
1.5 Purchase Information
If you make in-app purchases (e.g., Gem packs, Remove Ads), transaction data is processed by Google Play Billing. We receive:
- Purchase token and order ID
- Product identifier and purchase state
- Transaction timestamp
We do not receive or store your payment card details, billing address, or other financial information. All payment processing is handled by Google.
1.6 Advertising Data
Our free-to-play games display advertisements via Google AdMob. The AdMob SDK may collect:
- Advertising ID (with consent)
- IP address (for geographic ad targeting)
- Device information for ad delivery
- Ad interaction data (impressions, clicks)
2. How We Use Your Information
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide and maintain gameplay | Account info, game data | Contract performance |
| Cloud save synchronization | Game data, account UID | Contract performance |
| Social features (friends, challenges) | Friend codes, challenge data | Consent / Legitimate interest |
| Serve advertisements | Advertising ID, device info | Consent (via UMP) |
| Analytics and game improvement | Usage data, device info | Legitimate interest |
| Process in-app purchases | Purchase tokens, product IDs | Contract performance |
| Crash reporting and stability | Diagnostic data, device info | Legitimate interest |
| Fraud and abuse prevention | Device identifiers, usage patterns | Legitimate interest |
3. Third-Party Services
Our games integrate the following third-party services. Each operates under its own privacy policy:
| Service | Provider | Purpose |
|---|---|---|
| Firebase Authentication | Google LLC | User sign-in and account management |
| Cloud Firestore | Google LLC | Cloud save storage, friend lists, challenges |
| Firebase Analytics | Google LLC | Usage analytics and event tracking |
| Google AdMob | Google LLC | Advertising (interstitial and rewarded ads) |
| Google Play Billing | Google LLC | In-app purchase processing |
| Google Sign-In | Google LLC | Authentication via Google account |
For more information, see Google's Privacy Policy.
4. Advertising and Consent (GDPR/EEA)
For users in the European Economic Area (EEA), United Kingdom, and other jurisdictions requiring consent for personalized advertising:
- We use Google's User Messaging Platform (UMP) to present a consent dialog before loading any advertisements
- You may choose to consent to personalized ads, accept only non-personalized ads, or decline ads entirely (where applicable)
- Your consent choice is stored locally and respected across sessions
- You can change your ad preferences at any time via Settings → Ad Preferences within the game
If you do not consent to personalized advertising, you will still see ads, but they will not be tailored to your interests.
5. Data Sharing
We do not sell your personal information. We may share data only in the following circumstances:
- Service providers: Third-party services listed above that help us operate our games
- Legal obligations: When required by law, regulation, or legal process
- Safety: To protect the rights, safety, or property of our users or the public
- Consent: With your explicit permission
6. Data Retention
- Game data: Retained for as long as your account is active
- Analytics data: Retained for up to 14 months (Firebase Analytics default)
- Advertising data: Managed by Google AdMob per their retention policies
- Purchase records: Retained for as long as required for support and legal compliance
You may request deletion of your account and all associated data at any time (see Section 8).
7. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS/SSL) for all data transfers
- Firebase Security Rules restricting database access to authorized users only
- No storage of payment credentials or sensitive financial data
- Regular security reviews of our codebase and infrastructure
However, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
8. Your Rights
Depending on your location (including GDPR, CCPA, and similar regulations), you may have the right to:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate data
- Deletion: Request deletion of your data ("right to be forgotten")
- Restriction: Request restriction of processing
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interest
- Withdraw consent: Withdraw consent at any time (e.g., for personalized ads)
To exercise these rights, email us at contact@mindmirrorapp.ai. We will respond within 30 days.
Account Deletion
To delete your account and all associated data, send an email to contact@mindmirrorapp.ai with the subject "Account Deletion Request" and include the email address linked to your game account. We will process your request within 30 days and confirm deletion via email.
9. Children's Privacy
Our games are not directed to children under 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. Our AdMob implementation uses content rating flags appropriate for general audiences.
If you believe a child has provided us with personal data, please contact us immediately and we will promptly delete it.
10. International Data Transfers
Your data may be processed and stored in countries outside your own (including the United States) through our use of Google's cloud infrastructure. Google maintains appropriate safeguards for international data transfers in compliance with applicable data protection laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Material changes will be communicated through the game or via email where possible. Continued use of our Services after changes constitutes acceptance of the revised policy.
12. Contact Us
If you have questions about this Privacy Policy, wish to exercise your data rights, or have concerns about our data practices, contact us at:
MindMirror AI
Email: contact@mindmirrorapp.ai
Website: mindmirrorapp.ai