Last updated: 23 July 2026
Privacy Policy
This policy is written for a privacy-light Adoracle soft launch: local-first photos, minimal location checks, no hidden tracking, and clear handling of optional AI verification and partner quests.
1. Controller and contact
The controller responsible for Adoracle is:
| Legal operator | Jake Austin Hyvonen trading under/using the brand Crystal Sky and the project name Adoracle |
|---|---|
| Legal form | Austrian sole proprietor / Einzelunternehmen [[REGISTERED_OR_NOT_IN_COMPANY_REGISTER]] |
| Address | [[BUSINESS_ADDRESS_FOR_SERVICE_OF_PROCESS]] |
| [[SUPPORT_EMAIL]] | |
| Phone or direct contact channel | [[PHONE_OR_CONTACT_FORM_URL]] |
| Data protection contact | [[PRIVACY_EMAIL_OR_SAME_AS_SUPPORT]] |
No Data Protection Officer has been appointed unless required by law. If that changes, this policy will be updated.
2. Scope and current configuration
This privacy policy explains how Adoracle processes personal data through the Adoracle website, Android beta, related support channels, Owlzi NFC companion flows, photo quests, optional verification, and partner quests.
The authenticated family portal stores family profiles, roles, invitations, Journal metadata, CertifiCute wording, and redemption requests in the Adoracle backend. Photo bytes remain on the capturing device; the portal receives only related dates, members, notes, event types, and other metadata. If paid features, public galleries, notifications, analytics, or advertising are added, this policy must be updated before or when they become active.
3. Privacy principles for Adoracle
- Local-first: quest notes and photos should remain on the user's device unless the user explicitly chooses verification, export, backup, or sharing.
- Minimum location: location should be checked only when needed to start, progress, or complete a quest. Adoracle is not intended to continuously track routes in the background.
- No hidden social upload: sharing should be user-initiated through the device share sheet or a clear partner flow.
- No training use by default: photos uploaded for verification should not be used to train AI models unless the user has separately and explicitly consented.
- Short retention: raw verification photos should be deleted after verification unless a longer retention period is strictly necessary and disclosed.
4. Data categories processed
| Category | Examples | Default handling |
|---|---|---|
| Website access data | IP address, date/time, requested URL, user agent, referrer, server logs. | Processed by the web host for security, delivery, troubleshooting, and abuse prevention. |
| App installation/device data | App version, platform, language, basic device/browser information, local app settings. | Used to provide and debug the app. Device identifiers should be avoided unless necessary. |
| Quest data | Quest IDs, completion status, timestamps, points, streaks, chosen quest categories. | Stored locally by default. If accounts/cloud sync are enabled, stored in Adoracle's backend. |
| Location data | Approximate or precise GPS position when checking whether a user is near a quest location. | Used for location checks only. Background location and continuous route storage are not part of the intended MVP. |
| Photos and image metadata | Goal photo, optional side-quest photos, date/time, possible EXIF/location metadata. | Stored on the device by default. Uploaded only when the user chooses verification, backup, export, support, or sharing. |
| AI verification data | Photo submitted for verification, quest rule, model response, pass/fail result, confidence/notes. | Optional. Raw image should be deleted after verification; result may be stored for quest completion and anti-fraud purposes. |
| Account and family data | Email address, display name, Google/Supabase login IDs, family roles, invitation targets, profiles, Journal metadata, CertifiCute wording, redemption dates, statuses, and notes. | Stored in the authenticated Adoracle backend to provide family access, sync, audit history, and interpersonal redemption workflows. |
| Support communications | Email address, message contents, screenshots, attachments, bug descriptions. | Processed to answer requests and maintain records. |
| Partner/affiliate reward data | Partner quest ID, reward code, redemption status, non-sensitive attribution data. | Used to provide partner rewards and account for affiliate/sponsored arrangements. Avoid third-party tracking cookies where possible. |
| Marketing data, if enabled | Newsletter email, consent timestamp, subscription status. | Only with opt-in consent or another valid legal basis; unsubscribing must be easy. |
| Payment data, if enabled | Purchase ID, product, app-store transaction reference, invoice-relevant information. | Only if paid features are introduced. Card/payment details should be handled by payment/app-store providers, not Adoracle directly. |
5. Purposes and legal bases
| Purpose | Legal basis under GDPR |
|---|---|
| Deliver the website/app, store local app settings, provide quests, complete requested functions. | Contract or pre-contractual steps; legitimate interests in providing a functioning service. |
| Location check for a quest. | Contract where the user requests the quest function; consent/permission through the operating system where required; legitimate interest in fraud prevention for completion checks. |
| Camera/photo use for quest completion. | Contract where the user uses photo-quest features; consent/permission through the operating system for camera access; legitimate interests in verifying completion where proportionate. |
| AI image verification. | Contract where verification is needed for the requested quest; consent where the upload is optional; legitimate interests in preventing abuse and awarding points fairly. |
| Support, bug reports, and safety reports. | Contract/pre-contractual communication; legitimate interests in responding and improving safety; legal obligation where required. |
| Security logging, abuse prevention, anti-cheat, and fraud prevention. | Legitimate interests in protecting users, the app, and partners; legal obligation where applicable. |
| Accounting, tax, and legal record keeping for paid/partner activities. | Legal obligation; legitimate interests in documenting claims and business records. |
| Newsletter or promotional push notifications. | Consent unless another legal basis clearly applies; users can withdraw consent. |
| Non-essential cookies, analytics, ad pixels, profiling. | Consent before use. The current static website is intended not to use these. |
6. Location data
Adoracle may use location data to determine whether a user is near a quest, landmark, partner location, or route point. The intended MVP does not collect background location and does not store continuous route history.
Users can deny or revoke location permission in their browser or device settings. Some quests may not work without location access. Where possible, Adoracle should use coarse location or on-device checks instead of sending precise coordinates to a server.
Adoracle should not ask users to visit unsafe, restricted, private, or inaccessible locations. Users must still judge their surroundings and comply with local laws, traffic rules, property rights, park rules, museum rules, photography rules, and safety instructions.
7. Photos, camera, and metadata
Adoracle uses the camera or photo picker only when the user chooses a photo-related feature. Photos can reveal personal data, location, habits, bystanders, homes, vehicles, health information, religious/political places, or other sensitive context. Users should avoid photographing strangers, children, private interiors, license plates, documents, screens, or sensitive locations unless they have a lawful reason and consent where required.
Before uploading any photo, users should review whether it contains identifiable persons or sensitive information. Adoracle may remove or reject photos that are illegal, unsafe, abusive, privacy-invasive, fraudulent, or unrelated to the quest.
EXIF metadata may include timestamp, device information, and location coordinates. The privacy-friendly implementation should strip unnecessary metadata before upload or sharing where technically feasible.
8. AI verification
Adoracle may offer optional AI verification to check whether a quest photo appears to satisfy a quest condition, for example whether a requested object, color, landmark, or scene appears in the image.
The intended AI verification design is:
- the user actively chooses to verify or submit a goal photo;
- the image and quest rule are sent to [[AI_VERIFICATION_PROVIDER_OR_NONE]];
- the AI returns a verification result, short explanation, and/or confidence signal;
- the raw image is deleted by Adoracle after verification unless the user asks for support review or a legal/security retention reason applies;
- Adoracle stores only the minimum result needed for quest completion, points, abuse prevention, and troubleshooting;
- uploaded images are not used to train Adoracle or provider models unless the user gives separate explicit consent.
AI verification is probabilistic and can be wrong. A failed verification does not determine legal rights, creditworthiness, employment, access to essential services, or similarly significant matters. Users can retry or contact support for review.
Adoracle must not use AI verification for face recognition, biometric identification, emotion recognition, sensitive-trait inference, or surveillance.
9. Special category data and sensitive places
Adoracle does not intentionally ask for special category data such as health data, biometric identification data, political opinions, religious beliefs, trade-union membership, sexual orientation, or ethnicity. Because location and photos can accidentally reveal sensitive information, users should avoid uploading photos from sensitive places such as hospitals, clinics, schools, shelters, places of worship, protests, private homes, or locations where people may have a strong expectation of privacy.
If Adoracle receives sensitive data unexpectedly, it may delete or restrict the data unless retention is required to handle a safety, abuse, legal, or support issue.
10. Age and minors
Adoracle is intended for users aged 16 or older unless a separate child-safety and parental-consent flow is implemented. Users under 16 should not use the app or create an account without parental/guardian involvement where required by law.
Adoracle is not directed at children and should not be marketed as a toy, children's game, or child-directed social app. Owlzi physical objects are art/ritual companions, not toys, unless separately assessed and marketed under toy-safety rules.
13. Processors and recipients
Personal data may be processed by carefully selected service providers where necessary. Replace the placeholders below with your real providers before launch.
| Recipient / processor | Purpose | Location / transfer note |
|---|---|---|
| [[WEB_HOSTING_PROVIDER]] | Hosting, server logs, security. | [[HOSTING_REGION_AND_TRANSFER_BASIS]] |
| Supabase | Google-linked authentication, session management, and hosted PostgreSQL family metadata. | [[SUPABASE_PROJECT_REGION_AND_TRANSFER_BASIS]] |
| OAuth sign-in for the optional family portal and Android account. | Google processes sign-in under its own privacy terms; document the configured transfer basis before launch. | |
| [[AI_VERIFICATION_PROVIDER_OR_NONE]] | Optional image verification. | [[AI_REGION_RETENTION_AND_TRANSFER_BASIS]] |
| [[EMAIL_PROVIDER]] | Support emails and notifications. | [[EMAIL_REGION_AND_TRANSFER_BASIS]] |
| [[APP_DISTRIBUTION_PROVIDER_OR_NONE]] | App distribution, beta testing, crash logs, purchase records if applicable. | [[APP_DISTRIBUTION_REGION_AND_TRANSFER_BASIS]] |
| [[PAYMENT_PROVIDER_OR_NONE]] | Payments, invoices, refunds if paid features are introduced. | [[PAYMENT_REGION_AND_TRANSFER_BASIS]] |
Where providers process personal data on Adoracle's behalf, Adoracle should conclude data processing agreements. Where personal data is transferred outside the EEA, Adoracle should rely on an adequacy decision, Standard Contractual Clauses, or another valid transfer mechanism, plus supplementary safeguards where needed.
14. Retention periods
| Data | Retention |
|---|---|
| Website server logs | As short as reasonably possible for security/troubleshooting; placeholder: [[SERVER_LOG_RETENTION_DAYS]] days. |
| Local quest history and local photos | Until the user deletes them from the app/device, uninstalls the app, or clears browser/app storage. |
| Uploaded verification photo | Delete after verification; placeholder target: [[VERIFICATION_PHOTO_RETENTION_HOURS]] hours, unless support/legal/security retention is needed. |
| Verification result | As long as needed for quest history, points, anti-cheat, and support; placeholder: [[VERIFICATION_RESULT_RETENTION_PERIOD]]. |
| Account, family, Journal, and CertifiCute metadata | Until deletion request, family removal, configured inactivity deletion, or a legal/security retention need. Declined and cancelled redemption attempts remain part of the family audit history until deletion. |
| Support emails | As long as needed to handle the issue and document claims; placeholder: [[SUPPORT_EMAIL_RETENTION_PERIOD]]. |
| Accounting/payment records | For statutory Austrian tax/accounting retention periods where applicable. |
| Partner reward records | As long as needed for redemption, fraud prevention, accounting, and partner reporting. |
Backups may persist for a limited time after deletion until overwritten under normal backup cycles.
15. User rights
Users have the right to request access, rectification, deletion, restriction, portability, objection, and withdrawal of consent where applicable. To exercise rights, contact [[PRIVACY_EMAIL_OR_SAME_AS_SUPPORT]].
Users also have the right to lodge a complaint with a data protection supervisory authority. In Austria, this is the Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna. Use the official authority website rather than links copied from this template.
When a request concerns local-only data stored solely on the user's device, Adoracle may not be able to access it. In that case, users can delete the data using the in-app deletion function or their browser/device storage settings.
16. Security
Adoracle should use HTTPS, access controls, least-privilege permissions, secure authentication where accounts exist, regular software updates, encrypted transport, secure storage for secrets, and deletion routines for temporary verification files. No internet service can be guaranteed completely secure.
If a personal data breach occurs and is likely to create a risk to users' rights and freedoms, Adoracle will assess notification duties and notify the competent authority and/or affected users where required.
17. Changes to this policy
Adoracle may update this policy when the app changes, providers change, legal requirements change, or new features are introduced. Material changes should be communicated in the app or on the website. The current version date is shown at the top of this page.