Last updated: 14 April 2026 Effective date: 14 April 2026 Version: 1.0

This Privacy Policy explains how Veggies Labs SA (“Veggies Labs”, “we”, “us”, “our”) collects, uses, and protects information when you use the mobile application Escape Saylor (the “App”). It applies to all users worldwide and is designed to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the Swiss Federal Act on Data Protection (nFADP), and the privacy requirements of the Apple App Store and Google Play Store.

1. Who we are (Data Controller)

Veggies Labs SA Esplanade de Surville 1 1213 Petit-Lancy Switzerland Commercial register: CHE-467.379.309 (Veggies Labs SA, Moneyhouse ID 20574158681)

Privacy contact: [email protected]

For users in the EU/EEA, Veggies Labs SA acts as the data controller. Because Switzerland provides an adequate level of data protection recognised by the European Commission, no separate EU representative is appointed under Article 27 GDPR unless otherwise required.

2. Age restriction (18+)

Escape Saylor is strictly reserved for users aged 18 or older. The App distributes Bitcoin (BTC/WBTC) rewards on a public blockchain; we do not knowingly collect, process, or store personal data of persons under 18. If we become aware that a minor has used the App, we will terminate the associated account and delete the related data where legally possible (see Section 10 for on-chain limitations).

3. What data we collect

We collect only what is strictly necessary to operate the App, secure it against fraud, and comply with our legal obligations. We do not collect your name, email address, postal address, phone number, government ID, precise location, photos, or contacts.

3.1 Account & identity data

Data Purpose
StarkNet wallet address Your pseudonymous account identifier; required to receive in-game rewards on-chain
Username Public display name you choose
Language preference (lang) To display the App in your language
Referral code / referrer link To operate the referral programme

We do not use email/password, OAuth, or third-party social logins. The wallet address is a public pseudonymous identifier but, when combined with on-chain activity, may qualify as personal data under GDPR.

3.2 Device & integrity data

Data Purpose
Device ID (x-device-id header) Abuse prevention, rate limiting, multi-account detection
iOS App Attest public key & sign count Verifying that requests come from a genuine, unmodified build of the App
Android Play Integrity verdict (JWS from Google) Same as above, on Android
IP address (from x-forwarded-for, logged transiently) Security, debugging, abuse investigation
Platform / app version / game version Compatibility, bug triage

3.3 Gameplay data

Data Purpose
Runs: mode, seed, keys used, scores (client + server-recomputed), distance, duration, coins collected, checkpoint timestamps, binary input trace Running the game, verifying fairness, computing rewards
In-game balances: coins, keys, VIP status Operating the game economy
Anti-cheat signals: suspicion flags, shadow-ban level, device-emulator detection, abnormal timing patterns Preventing fraud, bots, and multi-accounting

3.4 Payment & financial data

Data Purpose
Apple IAP: transaction ID, original transaction ID, product ID, bundle ID, JWS-signed transaction info Processing in-app purchases via the Apple App Store
Google Play IAP: purchase token, product ID, package name, purchase state Processing in-app purchases via Google Play
Crypto purchases (Layerswap): swap ID, reference ID, amount paid (USD), destination address Processing crypto purchases
BTC/WBTC reward payouts: amount, BTC price at drop, on-chain transaction hash, payout status Distributing rewards and maintaining financial records
Payout blacklist entries: device ID, reason (refund deficit, device inheritance, manual), metadata Enforcing fair-play and anti-abuse policies

We never see, store, or process your credit card number, bank account, or payment credentials. Apple and Google handle all payment data directly.