Skip to main content

Freemium game developer reveals the dirty truths behind in-app purchases

apple and supercell partner for charity microtransactions clash of clans
Much has been made in recent years about the rise of the so-called “freemium” model sweeping games on mobile platforms, luring users in with free initial downloads and making boatloads of profit through countless, in-app micro-transactions. Despite several high-profile lawsuits forcing Apple and Google to temper the more exploitative elements of the practice, the model is thriving, with apps like Game of WarClash of Clans, and Candy Crush dominating the top-grossing charts. The vast majority of writing on the subject focuses on the consumer perspective, and how the distorted value proposition of these supposedly free games has eroded trust between players and developer.

Less attention has been given to the developers’ side of the equation. A revealing piece on Touch Arcade, written by an anonymous producer of major, free to play games, has pulled back the curtain on the machinery behind these massively profitable games, and the truth is even ickier than most of us have probably realized. Note that while the anonymous authorship of the piece means that its revelations could be taken with a grain of salt, Touch Arcade is a reputable and well-connected news source for the mobile gaming field, giving this story the weight of credibility.

The writer describes him or herself as “a senior producer at a free-to-play games company” that has worked for several major companies. You have almost certainly played or are playing a game that this person produced or worked on in some significant capacity. Originally a console game producer, they joined mobile games in the early days of the iPhone and witnessed the whole evolution that brought us to where we are today.

The most troubling revelation of the story is how much personal data developers skim about their players, and then use to target them for in-app purchases:

“This is about how we can target you, because we (and our partners) know everything about you. We know where you live, we know your income level, we know your relationships, your favorite sports teams, your political preferences. We know when you go to work, and where you work. We can target an event to start for you when we know you have a long weekend coming up. We own you.”

As is so often the case, the road to this dystopian present started innocently enough. In order to balance their games to be as enjoyable and accessible as possible, developers started to track player behavior. At first this just allowed them to do things like adjust the difficulty of particular levels and “balance the game in the wild.” Trouble started when the engineers started to look at not just the in-game data, but also the metadata about when people were playing.

“We know where you live, we know your income level, we know your relationships, your favorite sports teams, your political preferences … We own you.”

“During a meeting about the game, the guy who ran our website brought up some interesting information. He started watching the Web logs and seeing all the connections to the JSON file [which tracked in-game behavior]. Unbeknownst to him (or our team) he was getting us a DAU [daily active users]. For the engineering and production teams, this was just a neat thing to know, a feel good ‘look how many people love our game’ statistic. The CEO saw something else.”

Like sharks to the smell of blood, upper management developed an insatiable hunger for data about when, where, and how users were playing their games. They realized the potential this information held for getting players to buy more things, or convince their friends to play as well. Particular focus was given to the best way to find “whales” — the minority, high-spending users that account for the most profit in freemium games.

“Time passed, Free to Play became a thing. I went from company to company. Each time, every new project became less and less about how we can do cool things, and more about how we can track and target users to get the most whales possible, boost chart position and retain users to shove as many ads on them as possible.”

The widespread adoption of Facebook was the turning point. Like marketers of all kinds, developers mine Facebook’s rich stores of data to build creepily intimate portraits of how you play their games, so you can be targeted with personalized push notifications and store specials optimized to maximize the likelihood that you will spend money. Even if you do not actively use Facebook, your connections reveal a lot about you. As Edward Snowden’s NSA revelations demonstrated, a dangerously complete portrait of a person can be developed just from the metadata of their connections and communications, even without any actual content.

If you are a whale, the stalking goes to an even creepier level. “You spend enough money, we will friend you. Not officially, but with a fake account. Maybe it’s a hot girl who shows too much cleavage? That’s us. We learned as much before friending you, but once you let us in, we have the keys to the kingdom. We will use everything to figure out how to sell to you.” The writer then goes on to describe a particular whale who lived in Saudi Arabia, but loved American football, and how they created virtual items based on his favorite teams to sell just to him.

The same data that was once used to maximize fun is now being used to maximize profitability, with developers going so far as to manipulate gameplay itself. “We will flat out adjust a game to make it behave just like it did last time the person bought IAP. Was a level too hard? Well now they are all that same difficulty.”

If this makes you uncomfortable, then your only recourse is to opt out. Like lunch, there ain’t no such thing as a free game. Vote with your wallet and buy games with an up-front cost, or else publishers will continue to focus on manipulative tactics as the only way to extract profit from games.

Will Fulton
Former Digital Trends Contributor
Will Fulton is a New York-based writer and theater-maker. In 2011 he co-founded mythic theater company AntiMatter Collective…
What is the Temu app? Here’s everything you need to know
Temu logo on an iPhone.

Following an increased marketing push starting in 2023, the Temu app has started to pick up some solid momentum that's driven many shoppers to want to check it out. As new marketplaces start to make their way into the mainstream, however, there's usually a healthy amount of skepticism toward them.

Although it's always a good impulse to be cautious about putting sensitive information into any app, here's everything you need to know about Temu — and if you truly need to be careful.
What is Temu?

Read more
Our 5 favorite iPhone and Android apps by Black developers
An iPhone with apps from Black developers downloaded on it.

As we wrap up the celebration of 2023's Black History Month, it remains important to recognize and appreciate the contributions that Black people have made in various fields, including technology and the smartphone apps we use every day. From social media platforms to productivity tools, Black developers and other people of color have worked hard to create innovative, useful, and just plain fun apps.

Here, we're focusing on five helpful apps developed by Black people that you should check out. These iPhone and Android apps range from ones that help you discover and support Black-owned businesses to ones that provide legal assistance in case of an emergency to ones that curate and highlight sources of news and entertainment by Black creators.
We Read Too

Read more
SMS 2FA is insecure and bad — use these 5 great authenticator apps instead
Twilio Authy 2FA app running on an iPhone.

You probably have what seems like a million accounts across the internet these days, right? At least, that’s what it feels like for me — with all these social media, email, and banking accounts, plus digital storefronts, and more. Regardless of where I access these from, whether it’s my iPhone 14 Pro or my Samsung Galaxy S23 Plus, or even my Mac, the first step is to make sure that I have a strong and secure (preferably randomly generated) password. But for extra peace of mind, everyone needs to look into two-factor authentication (2FA) to really keep people out.

Recently, Twitter has made the news yet again because it’s forcing everyone who uses SMS 2FA to either remove it from their account or subscribe to Twitter Blue to keep it. SMS 2FA is when you get a code sent as an SMS to your phone, and while it's convenient, this is the least secure 2FA method available. SMS 2FA is susceptible to numerous vulnerabilities, including SIM swapping (where someone takes over a mobile phone number by convincing a carrier to link that number with the SIM card), SIM duplication attacks, and more.

Read more