Last updated: 14 April 2026 Effective date: 14 April 2026 Version: 1.0
This Privacy Policy explains how Veggies Labs SA (“Veggies Labs”, “we”, “us”, “our”) collects, uses, and protects information when you use the mobile application Escape Saylor (the “App”). It applies to all users worldwide and is designed to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the Swiss Federal Act on Data Protection (nFADP), and the privacy requirements of the Apple App Store and Google Play Store.
Veggies Labs SA Esplanade de Surville 1 1213 Petit-Lancy Switzerland Commercial register: CHE-467.379.309 (Veggies Labs SA, Moneyhouse ID 20574158681)
Privacy contact: [email protected]
For users in the EU/EEA, Veggies Labs SA acts as the data controller. Because Switzerland provides an adequate level of data protection recognised by the European Commission, no separate EU representative is appointed under Article 27 GDPR unless otherwise required.
Escape Saylor is strictly reserved for users aged 18 or older. The App distributes Bitcoin (BTC/WBTC) rewards on a public blockchain; we do not knowingly collect, process, or store personal data of persons under 18. If we become aware that a minor has used the App, we will terminate the associated account and delete the related data where legally possible (see Section 10 for on-chain limitations).
We collect only what is strictly necessary to operate the App, secure it against fraud, and comply with our legal obligations. We do not collect your name, email address, postal address, phone number, government ID, precise location, photos, or contacts.
| Data | Purpose |
|---|---|
| StarkNet wallet address | Your pseudonymous account identifier; required to receive in-game rewards on-chain |
| Username | Public display name you choose |
Language preference (lang) |
To display the App in your language |
| Referral code / referrer link | To operate the referral programme |
We do not use email/password, OAuth, or third-party social logins. The wallet address is a public pseudonymous identifier but, when combined with on-chain activity, may qualify as personal data under GDPR.
| Data | Purpose |
|---|---|
Device ID (x-device-id header) |
Abuse prevention, rate limiting, multi-account detection |
| iOS App Attest public key & sign count | Verifying that requests come from a genuine, unmodified build of the App |
| Android Play Integrity verdict (JWS from Google) | Same as above, on Android |
IP address (from x-forwarded-for, logged transiently) |
Security, debugging, abuse investigation |
| Platform / app version / game version | Compatibility, bug triage |
| Data | Purpose |
|---|---|
| Runs: mode, seed, keys used, scores (client + server-recomputed), distance, duration, coins collected, checkpoint timestamps, binary input trace | Running the game, verifying fairness, computing rewards |
| In-game balances: coins, keys, VIP status | Operating the game economy |
| Anti-cheat signals: suspicion flags, shadow-ban level, device-emulator detection, abnormal timing patterns | Preventing fraud, bots, and multi-accounting |
| Data | Purpose |
|---|---|
| Apple IAP: transaction ID, original transaction ID, product ID, bundle ID, JWS-signed transaction info | Processing in-app purchases via the Apple App Store |
| Google Play IAP: purchase token, product ID, package name, purchase state | Processing in-app purchases via Google Play |
| Crypto purchases (Layerswap): swap ID, reference ID, amount paid (USD), destination address | Processing crypto purchases |
| BTC/WBTC reward payouts: amount, BTC price at drop, on-chain transaction hash, payout status | Distributing rewards and maintaining financial records |
| Payout blacklist entries: device ID, reason (refund deficit, device inheritance, manual), metadata | Enforcing fair-play and anti-abuse policies |
We never see, store, or process your credit card number, bank account, or payment credentials. Apple and Google handle all payment data directly.