Paketname: de.infinityakhi.mapscanner · Stand: 18. September 2026
Inoffizielle Fan-App. GTA 6 Map Scanner steht in keiner Verbindung zu Rockstar Games oder Take-Two Interactive und wird von diesen weder unterstützt noch autorisiert. Rockstar Games und Take-Two erhalten über die App keine Daten von dir.
InfinityAkhi, Yusuf Fuat Sarac
Kontakt: yusuf.fuat.sarac@gmail.com
Die vollständige Anbieterkennzeichnung findest du im
Impressum.
Ein Datenschutzbeauftragter ist nicht bestellt, da die gesetzlichen Voraussetzungen dafür nicht vorliegen.
Folgende Daten speichert die App ausschließlich im app-privaten Speicher deines Geräts:
Die App fragt keinen Standort (GPS) ab und liest keine Kontakte, Dateien oder anderen Apps aus.
Android-Sicherung: Die App erlaubt die Android-Sicherung. Datenbank und Einstellungen (einschließlich der Geräte-ID) können daher von deinem Gerät in deine eigene Google-Sicherung aufgenommen oder beim Gerätewechsel übertragen werden, sofern du das in den Android-Einstellungen aktiviert hast. Diese Sicherung steuert Android bzw. Google, nicht der Entwickler; der Entwickler hat darauf keinen Zugriff.
Speicherdauer: bis du die Daten in der App änderst, die App-Daten löschst oder die App deinstallierst.
Für den Scan der Pausenkarte kannst du die Kamera verwenden (Berechtigung wird erst beim Scannen abgefragt), ein Bild aus der Galerie wählen oder einen Screenshot aus einer anderen App an die App teilen. Die Bildauswertung (Positionsbestimmung) erfolgt vollständig auf deinem Gerät. Kamerabilder und Screenshots werden dabei nicht gespeichert und nicht übertragen.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO (Bereitstellung der von dir genutzten Funktion).
Was: Wenn du einen Fundort anlegst, überträgt die App: eine zufällig erzeugte Fundort-ID, die Kategorie, die Kartenkoordinaten (Position auf der Spielkarte, kein realer Standort), den von dir eingegebenen Titel (max. 60 Zeichen) und eine zufällige Geräte-ID. Wenn du einen fremden Fundort bestätigst, werden die Fundort-ID und deine Geräte-ID übertragen. Der Server speichert zusätzlich den Zeitpunkt.
Die Geräte-ID ist eine beim ersten Bedarf zufällig erzeugte Kennung (UUID). Sie wird nicht aus Hardware-Merkmalen, der Werbe-ID oder deinem Google-Konto abgeleitet. Sie dient dazu, dass jedes Gerät einen Fundort nur einmal bestätigen kann und eigene Fundorte nicht selbst bestätigt werden. Die Geräte-ID wird nicht öffentlich angezeigt; andere Nutzer sehen nur Kategorie, Position, Titel und Zahl der Bestätigungen.
Bitte gib im Titel keine persönlichen Angaben ein.
Abruf: Beim App-Start und beim Synchronisieren lädt die App öffentliche Fundorte herunter. Dabei wird keine Geräte-ID gesendet.
Zweck: gemeinsame Fundort-Karte der Community und Schutz vor Mehrfachbestätigungen.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO (Bereitstellung der Community-Funktion,
die du durch Anlegen oder Bestätigen aktiv nutzt); für die technische Verarbeitung der IP-Adresse
beim Verbindungsaufbau Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an einem sicheren,
funktionierenden Betrieb).
Empfänger / Auftragsverarbeiter: Supabase, Inc., USA (Datenbank-Hosting), auf Grundlage
eines Auftragsverarbeitungsvertrags (DPA). Serverregion: EU (Frankfurt, Deutschland — AWS
eu-central-1).
Speicherdauer: Unbestätigte Fundorte werden nach 90 Tagen automatisch gelöscht. Bestätigte Fundorte und Bestätigungen bleiben gespeichert, solange die Community-Karte betrieben wird, oder bis du sie löschst: Einstellungen → „Meine Community-Daten löschen“ entfernt deine Fundorte, Bestätigungen und Meldungen sofort vom Server.
Für Kartenregionen, für die noch keine Scan-Daten vorliegen, kannst du freiwillig ein Foto der Pausenkarte beitragen. Vor dem Senden erscheint ein Hinweis, den du mit „Zustimmen und senden“ bestätigen musst.
Was: das Foto, auf höchstens 1600 Pixel Kantenlänge und höchstens 150 KB verkleinert und neu als JPEG kodiert (dabei werden keine Kamera-Metadaten wie Aufnahmeort übernommen), abgelegt auf dem Server unter deiner zufälligen Geräte-ID. Name oder Konto werden nicht übertragen. Ist gerade keine Übertragung möglich, bleibt das Foto im app-privaten Speicher, bis es gesendet werden kann (höchstens 20 Fotos, höchstens 5 pro Tag).
Bitte nimm keine Personen oder persönlichen Informationen mit auf das Foto.
Zweck: Aufbau der Scan-Referenzdaten für neue Kartenregionen.
Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO (Einwilligung). Die Einwilligung kannst
du jederzeit per E-Mail mit Wirkung für die Zukunft widerrufen.
Empfänger: Supabase (Speicher-Bucket), siehe Abschnitt 4.
Speicherdauer: Fotos werden spätestens nach 180 Tagen automatisch gelöscht, auf Wunsch sofort über Einstellungen → „Meine Community-Daten löschen“.
Die App lädt Kartenaktualisierungen (höchstens einmal täglich beim Start geprüft) und das
Scan-Datenpaket (beim Öffnen des Scanners) aus dem Internet. Dabei werden keine Daten über dich
gesendet; technisch bedingt erhält der jeweilige Server deine IP-Adresse und übliche
Verbindungsdaten.
Anbieter: GitHub (GitHub, Inc., USA, Tochter der Microsoft Corporation) — sowohl für
das Scan-Datenpaket als auch für Kartenaktualisierungen werden die Dateien über GitHub Releases
ausgeliefert.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b und f DSGVO.
Speicherdauer: nach den Richtlinien des jeweiligen Anbieters; der Entwickler erhält
diese Verbindungsdaten nicht.
Die Sprachsteuerung startet nur, wenn du auf das Mikrofon tippst; die Mikrofon-Berechtigung wird
erst dann abgefragt. Die App nimmt selbst keine Audiodaten auf und speichert keine. Die Erkennung
übernimmt der Spracherkennungsdienst deines Geräts (auf den meisten Geräten der
Google-Spracherkennungsdienst). Je nach Gerät und Einstellung verarbeitet dieser Dienst die Sprache
auf dem Gerät oder überträgt sie an die Server des Anbieters (bei Google: Google LLC, USA). Dafür gelten
die Datenschutzbestimmungen des jeweiligen Anbieters. Die App erhält nur den erkannten Text und
wertet ihn lokal als Befehl aus. Antworten werden über die Sprachausgabe (Text-to-Speech) deines
Geräts gesprochen.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO.
Die kostenlose Version zeigt ein Werbebanner auf dem Kartenbildschirm. Anbieter ist Google (für Nutzer im EWR und in der Schweiz: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland). Die Pro-Version zeigt keine Werbung, und für Pro-Nutzer wird Google AdMob nicht gestartet.
Einwilligung: Nach der Einführung zeigt die App über die Google User Messaging Platform (UMP) – wo gesetzlich erforderlich – eine Einwilligungsabfrage. Erst wenn diese abgeschlossen ist und Werbung angefragt werden darf, wird Google AdMob gestartet; vorher wird keine Werbung angefragt. Lehnst du personalisierte Werbung ab, kann Google nicht personalisierte Werbung ausliefern.
Was: Google AdMob verarbeitet je nach deiner Wahl u. a. die Werbe-ID deines Geräts,
IP-Adresse, Geräte- und App-Informationen sowie Interaktionen mit Anzeigen. Die App fordert dazu die
Berechtigungen „Werbe-ID“ (AD_ID) und die Android-Werbedienste (Privacy Sandbox: Werbe-ID,
Attribution, Themen) an, die Google Mobile Ads mitbringt.
Zweck: Auslieferung und Messung von Werbung, ggf. personalisiert; Betrugsvermeidung.
Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO und § 25 Abs. 1 TDDDG (Einwilligung),
soweit personalisierte Werbung oder Zugriff auf Gerätekennungen erfolgt; im Übrigen Art. 6 Abs. 1
lit. f DSGVO (Finanzierung der kostenlosen Version).
Widerruf / Änderung: In der App unter Karte → Menü → Einstellungen →
Abschnitt „Info“ → „Datenschutzoptionen (Werbung)“. Dieser Eintrag erscheint, wenn die
Einwilligungsabfrage für deine Region vorgeschrieben ist. Außerdem kannst du die Werbe-ID in den
Android-Einstellungen (Google → Werbung) zurücksetzen oder löschen.
Speicherdauer / weitere Informationen: nach den Richtlinien von Google:
policies.google.com/privacy und
policies.google.com/technologies/partner-sites.
Die werbefreie Pro-Funktion ist ein Abonnement (monatlich oder jährlich), das sich automatisch verlängert, bis du es kündigst. Abschluss, Verlängerung, Bezahlung und Kündigung laufen vollständig über Google Play. Zahlungsdaten gibst du nur bei Google ein; der Entwickler erhält sie nicht. Die App fragt bei Google Play lediglich ab, ob ein gültiges Abo besteht, und speichert lokal einen Vermerk „Pro freigeschaltet“. Abo- und Zahlungsdaten werden nicht an einen Server des Entwicklers übertragen.
Kündigen kannst du jederzeit in der Google-Play-App unter Zahlungen & Abos → Abos; die Kündigung
wirkt zum Ende des laufenden Abrechnungszeitraums, danach zeigt die App wieder Werbung und begrenzt
Scans auf 3 pro Tag.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung).
Anbieter: Google (siehe
Datenschutzerklärung von Google). Für die
steuerlich vorgeschriebene Aufbewahrung von Transaktionsdaten ist Google zuständig.
Supabase, Google und GitHub sind Unternehmen mit Sitz bzw. Konzernmutter in den USA. Dabei kann es zu einer Übermittlung personenbezogener Daten (z. B. IP-Adresse, Geräte-ID, Werbe-ID) in die USA kommen. GitHub, Inc. ist nach Prüfung auf dataprivacyframework.gov aktiv unter dem EU-U.S. Data Privacy Framework zertifiziert; für die Übermittlung an GitHub gilt daher der Angemessenheitsbeschluss der EU-Kommission. Supabase, Inc. ist dort nicht gelistet; die Übermittlung an Supabase stützt sich auf Standardvertragsklauseln (Art. 46 Abs. 2 lit. c DSGVO), die Bestandteil des Auftragsverarbeitungsvertrags mit Supabase sind. Für Google gilt ergänzend zu etwaigen Zertifizierungen ebenfalls Art. 46 Abs. 2 lit. c DSGVO, soweit keine Zertifizierung vorliegt oder Google Ireland Limited als EWR-Gesellschaft auftritt.
Du hast das Recht auf Auskunft (Art. 15 DSGVO), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20) und Widerspruch gegen Verarbeitungen auf Grundlage berechtigter Interessen (Art. 21). Erteilte Einwilligungen kannst du jederzeit mit Wirkung für die Zukunft widerrufen (Art. 7 Abs. 3). Außerdem kannst du dich bei einer Datenschutz-Aufsichtsbehörde beschweren (Art. 77), z. B. in deinem Wohnsitz-Bundesland.
So stellst du einen Antrag: Schreib an yusuf.fuat.sarac@gmail.com. Da die App kein Konto kennt, können wir Server-Daten nur einem Gerät zuordnen, wenn du die betreffenden Einträge beschreibst (z. B. Titel, Kategorie und ungefähre Position deiner Fundorte oder Datum eines Fotobeitrags) oder deine Geräte-ID mitschickst. Du findest sie in der App unter Einstellungen → „Meine Geräte-ID“ (Tippen kopiert sie). Deine Community-Daten kannst du dort auch selbst sofort löschen.
Lokale Daten löschst du selbst, indem du in den Android-Einstellungen die App-Daten löschst oder die App deinstallierst.
Die App richtet sich nicht an Kinder, sondern an Erwachsene (18+) — wie das zugrundeliegende Spiel, das eine Altersfreigabe ab 18 Jahren (USK/PEGI) trägt. Wir erheben wissentlich keine Daten von Kindern.
Die Verbindungen zu den Servern (Supabase, GitHub) werden ausschließlich verschlüsselt (HTTPS)
aufgebaut. Das erzwingt die App selbst im Code: Eine hinterlegte Adresse, die nicht mit
https:// beginnt, wird gar nicht erst verwendet — die betroffene Funktion bleibt dann
inaktiv, statt unverschlüsselt zu senden. Lokale Daten liegen im app-privaten Speicher, auf den
andere Apps keinen Zugriff haben.
Wir passen diese Erklärung an, wenn sich die App oder die Rechtslage ändert. Es gilt die jeweils hier veröffentlichte Fassung.
Stand: 18. September 2026
Package name: de.infinityakhi.mapscanner · Last updated: 18 September 2026
In case of doubt, the German version above prevails.
Unofficial fan app. GTA 6 Map Scanner is not affiliated with, endorsed or authorized by Rockstar Games or Take-Two Interactive. Rockstar Games and Take-Two do not receive any of your data through the app.
InfinityAkhi, Yusuf Fuat Sarac
Contact: yusuf.fuat.sarac@gmail.com
Full provider details: Impressum (legal notice).
No data protection officer has been appointed, as the legal requirements for this are not met.
The app stores the following data only in its private storage on your device:
The app does not request your location (GPS) and does not read contacts, files or other apps.
Android backup: The app allows Android backup. Its database and settings (including the device ID) may therefore be included in your own Google backup or transferred to a new device, if you have enabled this in your Android settings. This backup is controlled by Android/Google, not by the developer; the developer has no access to it.
Retention: until you change the data in the app, clear the app data or uninstall the app.
To scan the pause map you can use the camera (permission is only requested when you scan), pick an image from your gallery, or share a screenshot from another app. Image analysis (position detection) runs entirely on your device. Camera images and screenshots are neither stored nor transmitted in the process.
Legal basis: Art. 6(1)(b) GDPR (providing the feature you use).
What: When you add a find, the app transmits a randomly generated find ID, the category, the map coordinates (a position on the game map, not a real-world location), the title you entered (max. 60 characters) and a random device ID. When you confirm someone else’s find, the find ID and your device ID are transmitted. The server also stores a timestamp.
The device ID is a random identifier (UUID) created when first needed. It is not derived from hardware properties, the advertising ID or your Google account. It ensures that each device can confirm a find only once and cannot confirm its own finds. The device ID is not shown publicly; other users only see category, position, title and number of confirmations.
Please do not enter personal information in the title.
Download: On app start and when syncing, the app downloads public finds. No device ID is sent for this.
Purpose: shared community map of finds and protection against multiple confirmations.
Legal basis: Art. 6(1)(b) GDPR (providing the community feature you actively use by
adding or confirming finds); for the technical processing of your IP address when connecting,
Art. 6(1)(f) GDPR (legitimate interest in secure and functioning operation).
Recipient / processor: Supabase, Inc., USA (database hosting), under a data processing
agreement (DPA). Server region: EU (Frankfurt, Germany — AWS eu-central-1).
Retention: Unconfirmed finds are deleted automatically after 90 days. Confirmed finds and confirmations are kept as long as the community map is operated, or until you delete them: Settings → “Delete my community data” removes your finds, confirmations and reports from the server immediately.
For map regions without scan data yet, you can voluntarily contribute a photo of the pause map. Before sending, a notice appears that you must confirm with “Agree and send”.
What: the photo, reduced to at most 1600 pixels on its longest side and at most 150 KB and re-encoded as JPEG (camera metadata such as capture location is not carried over), stored on the server under your random device ID. No name or account is transmitted. If sending is not possible at the moment, the photo stays in the app’s private storage until it can be sent (max. 20 photos, max. 5 per day).
Please do not capture people or personal information in the photo.
Purpose: building scan reference data for new map regions.
Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time
by e-mail with effect for the future.
Recipient: Supabase (storage bucket), see section 4.
Retention: Photos are deleted automatically after 180 days at the latest, or immediately via Settings → “Delete my community data”.
The app downloads map updates (checked at most once a day on start) and the scan data package (when
opening the scanner). No data about you is sent; for technical reasons the respective server receives
your IP address and usual connection data.
Providers: GitHub (GitHub, Inc., USA, a subsidiary of Microsoft Corporation) — both the
scan data package and map updates are delivered via GitHub Releases.
Legal basis: Art. 6(1)(b) and (f) GDPR.
Retention: according to the respective provider’s policies; the developer does not
receive this connection data.
Voice control only starts when you tap the microphone; the microphone permission is only requested
then. The app itself does not record or store audio. Recognition is performed by your
device’s speech recognition service (on most devices the Google speech recognition
service). Depending on device and settings, this service processes speech on the device or sends it
to the provider’s servers (for Google: Google LLC, USA); the provider’s privacy policy applies. The app
only receives the recognized text and interprets it locally as a command. Answers are spoken by your
device’s text-to-speech engine.
Legal basis: Art. 6(1)(b) GDPR.
The free version shows an ad banner on the map screen. The provider is Google (for users in the EEA and Switzerland: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The Pro version shows no ads, and Google AdMob is not started for Pro users.
Consent: After onboarding, the app shows a consent request via the Google User Messaging Platform (UMP) where legally required. Google AdMob is only started once this is completed and ads may be requested; no ads are requested before that. If you decline personalized ads, Google may serve non-personalized ads.
What: Depending on your choice, Google AdMob processes, among other things, your
device’s advertising ID, IP address, device and app information and interactions with ads. For this,
the app declares the “advertising ID” permission (AD_ID) and the Android ad services permissions
(Privacy Sandbox: ad ID, attribution, topics) that come with Google Mobile Ads.
Purpose: serving and measuring ads, personalized where consented; fraud prevention.
Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent) where personalized ads or
access to device identifiers are involved; otherwise Art. 6(1)(f) GDPR (funding the free version).
Withdraw / change: In the app under Map → menu → Settings → “About” section →
“Privacy options (ads)”. This entry appears when the consent request is required for your
region. You can also reset or delete your advertising ID in Android settings (Google → Ads).
Retention / more information: according to Google’s policies:
policies.google.com/privacy and
policies.google.com/technologies/partner-sites.
The ad-free Pro feature is a subscription (monthly or yearly) that renews automatically until you cancel it. Purchase, renewal, payment and cancellation are handled entirely by Google Play. You enter payment details only with Google; the developer does not receive them. The app only asks Google Play whether a valid subscription exists and stores a local “Pro unlocked” flag. Subscription and payment data is not sent to any server of the developer.
You can cancel at any time in the Google Play app under Payments & subscriptions →
Subscriptions; cancellation takes effect at the end of the current billing period, after which the app
shows ads again and limits scans to 3 per day.
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
Provider: Google (see Google Privacy Policy).
Supabase, Google and GitHub are companies based in, or with parent companies in, the USA. Personal data (e.g. IP address, device ID, advertising ID) may therefore be transferred to the USA. GitHub, Inc. is, as verified on dataprivacyframework.gov, an active participant in the EU-U.S. Data Privacy Framework; transfers to GitHub therefore rely on the European Commission’s adequacy decision. Supabase, Inc. is not listed there; transfers to Supabase rely on Standard Contractual Clauses (Art. 46(2)(c) GDPR), which are part of the data processing agreement with Supabase. For Google, Art. 46(2)(c) GDPR applies in addition to any certification, to the extent no certification applies or Google Ireland Limited acts as the EEA-based entity.
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw any consent at any time with effect for the future (Art. 7(3)). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77).
How to make a request: Write to yusuf.fuat.sarac@gmail.com. Since the app has no accounts, we can only match server data to a device if you describe the entries concerned (e.g. title, category and approximate position of your finds, or the date of a photo contribution) or include your device ID. You find it in the app under Settings → “My device ID” (tap to copy). You can also delete your community data there yourself.
You can delete local data yourself by clearing the app data in Android settings or uninstalling the app.
The app is not directed at children, but at adults (18+) — like the underlying game, which carries an age rating of 18 and up (USK/PEGI). We do not knowingly collect data from children.
Connections to the servers (Supabase, GitHub) are always encrypted (HTTPS). The app enforces this
itself in code: a configured address that does not start with https:// is never used —
the affected feature simply stays inactive instead of sending data unencrypted. Local data is kept in
the app’s private storage, which other apps cannot access.
We update this policy when the app or the legal situation changes. The version published here applies.
Last updated: 18 September 2026