Skip to content
Adoracle by Crystal Sky
Download Family account Privacy Terms Impressum Support DE

Last updated: 23 July 2026

Privacy Policy

This policy is written for a privacy-light Adoracle soft launch: local-first photos, minimal location checks, no hidden tracking, and clear handling of optional AI verification and partner quests.

Before publishing: replace every yellow placeholder, remove sections for features you do not actually use, and obtain legal review before a paid launch, app-store launch, child-facing launch, public-gallery launch, or significant partner/advertising revenue.

1. Controller and contact

The controller responsible for Adoracle is:

Legal operatorJake Austin Hyvonen trading under/using the brand Crystal Sky and the project name Adoracle
Legal formAustrian sole proprietor / Einzelunternehmen [[REGISTERED_OR_NOT_IN_COMPANY_REGISTER]]
Address[[BUSINESS_ADDRESS_FOR_SERVICE_OF_PROCESS]]
Email[[SUPPORT_EMAIL]]
Phone or direct contact channel[[PHONE_OR_CONTACT_FORM_URL]]
Data protection contact[[PRIVACY_EMAIL_OR_SAME_AS_SUPPORT]]

No Data Protection Officer has been appointed unless required by law. If that changes, this policy will be updated.

2. Scope and current configuration

This privacy policy explains how Adoracle processes personal data through the Adoracle website, Android beta, related support channels, Owlzi NFC companion flows, photo quests, optional verification, and partner quests.

Current soft-launch configuration: the public site is available without an account. The optional family portal and family cloud sync use Google sign-in and Supabase authentication. There is no payment processing by Adoracle, public in-app photo feed, contact-book upload, background location tracking, ad SDK, or non-essential tracking on the public site.

The authenticated family portal stores family profiles, roles, invitations, Journal metadata, CertifiCute wording, and redemption requests in the Adoracle backend. Photo bytes remain on the capturing device; the portal receives only related dates, members, notes, event types, and other metadata. If paid features, public galleries, notifications, analytics, or advertising are added, this policy must be updated before or when they become active.

3. Privacy principles for Adoracle

  • Local-first: quest notes and photos should remain on the user's device unless the user explicitly chooses verification, export, backup, or sharing.
  • Minimum location: location should be checked only when needed to start, progress, or complete a quest. Adoracle is not intended to continuously track routes in the background.
  • No hidden social upload: sharing should be user-initiated through the device share sheet or a clear partner flow.
  • No training use by default: photos uploaded for verification should not be used to train AI models unless the user has separately and explicitly consented.
  • Short retention: raw verification photos should be deleted after verification unless a longer retention period is strictly necessary and disclosed.

4. Data categories processed

CategoryExamplesDefault handling
Website access dataIP address, date/time, requested URL, user agent, referrer, server logs.Processed by the web host for security, delivery, troubleshooting, and abuse prevention.
App installation/device dataApp version, platform, language, basic device/browser information, local app settings.Used to provide and debug the app. Device identifiers should be avoided unless necessary.
Quest dataQuest IDs, completion status, timestamps, points, streaks, chosen quest categories.Stored locally by default. If accounts/cloud sync are enabled, stored in Adoracle's backend.
Location dataApproximate or precise GPS position when checking whether a user is near a quest location.Used for location checks only. Background location and continuous route storage are not part of the intended MVP.
Photos and image metadataGoal photo, optional side-quest photos, date/time, possible EXIF/location metadata.Stored on the device by default. Uploaded only when the user chooses verification, backup, export, support, or sharing.
AI verification dataPhoto submitted for verification, quest rule, model response, pass/fail result, confidence/notes.Optional. Raw image should be deleted after verification; result may be stored for quest completion and anti-fraud purposes.
Account and family dataEmail address, display name, Google/Supabase login IDs, family roles, invitation targets, profiles, Journal metadata, CertifiCute wording, redemption dates, statuses, and notes.Stored in the authenticated Adoracle backend to provide family access, sync, audit history, and interpersonal redemption workflows.
Support communicationsEmail address, message contents, screenshots, attachments, bug descriptions.Processed to answer requests and maintain records.
Partner/affiliate reward dataPartner quest ID, reward code, redemption status, non-sensitive attribution data.Used to provide partner rewards and account for affiliate/sponsored arrangements. Avoid third-party tracking cookies where possible.
Marketing data, if enabledNewsletter email, consent timestamp, subscription status.Only with opt-in consent or another valid legal basis; unsubscribing must be easy.
Payment data, if enabledPurchase ID, product, app-store transaction reference, invoice-relevant information.Only if paid features are introduced. Card/payment details should be handled by payment/app-store providers, not Adoracle directly.

5. Purposes and legal bases

PurposeLegal basis under GDPR
Deliver the website/app, store local app settings, provide quests, complete requested functions.Contract or pre-contractual steps; legitimate interests in providing a functioning service.
Location check for a quest.Contract where the user requests the quest function; consent/permission through the operating system where required; legitimate interest in fraud prevention for completion checks.
Camera/photo use for quest completion.Contract where the user uses photo-quest features; consent/permission through the operating system for camera access; legitimate interests in verifying completion where proportionate.
AI image verification.Contract where verification is needed for the requested quest; consent where the upload is optional; legitimate interests in preventing abuse and awarding points fairly.
Support, bug reports, and safety reports.Contract/pre-contractual communication; legitimate interests in responding and improving safety; legal obligation where required.
Security logging, abuse prevention, anti-cheat, and fraud prevention.Legitimate interests in protecting users, the app, and partners; legal obligation where applicable.
Accounting, tax, and legal record keeping for paid/partner activities.Legal obligation; legitimate interests in documenting claims and business records.
Newsletter or promotional push notifications.Consent unless another legal basis clearly applies; users can withdraw consent.
Non-essential cookies, analytics, ad pixels, profiling.Consent before use. The current static website is intended not to use these.

6. Location data

Adoracle may use location data to determine whether a user is near a quest, landmark, partner location, or route point. The intended MVP does not collect background location and does not store continuous route history.

Users can deny or revoke location permission in their browser or device settings. Some quests may not work without location access. Where possible, Adoracle should use coarse location or on-device checks instead of sending precise coordinates to a server.

Adoracle should not ask users to visit unsafe, restricted, private, or inaccessible locations. Users must still judge their surroundings and comply with local laws, traffic rules, property rights, park rules, museum rules, photography rules, and safety instructions.

7. Photos, camera, and metadata

Adoracle uses the camera or photo picker only when the user chooses a photo-related feature. Photos can reveal personal data, location, habits, bystanders, homes, vehicles, health information, religious/political places, or other sensitive context. Users should avoid photographing strangers, children, private interiors, license plates, documents, screens, or sensitive locations unless they have a lawful reason and consent where required.

Before uploading any photo, users should review whether it contains identifiable persons or sensitive information. Adoracle may remove or reject photos that are illegal, unsafe, abusive, privacy-invasive, fraudulent, or unrelated to the quest.

EXIF metadata may include timestamp, device information, and location coordinates. The privacy-friendly implementation should strip unnecessary metadata before upload or sharing where technically feasible.

8. AI verification

Adoracle may offer optional AI verification to check whether a quest photo appears to satisfy a quest condition, for example whether a requested object, color, landmark, or scene appears in the image.

The intended AI verification design is:

  • the user actively chooses to verify or submit a goal photo;
  • the image and quest rule are sent to [[AI_VERIFICATION_PROVIDER_OR_NONE]];
  • the AI returns a verification result, short explanation, and/or confidence signal;
  • the raw image is deleted by Adoracle after verification unless the user asks for support review or a legal/security retention reason applies;
  • Adoracle stores only the minimum result needed for quest completion, points, abuse prevention, and troubleshooting;
  • uploaded images are not used to train Adoracle or provider models unless the user gives separate explicit consent.

AI verification is probabilistic and can be wrong. A failed verification does not determine legal rights, creditworthiness, employment, access to essential services, or similarly significant matters. Users can retry or contact support for review.

Adoracle must not use AI verification for face recognition, biometric identification, emotion recognition, sensitive-trait inference, or surveillance.

9. Special category data and sensitive places

Adoracle does not intentionally ask for special category data such as health data, biometric identification data, political opinions, religious beliefs, trade-union membership, sexual orientation, or ethnicity. Because location and photos can accidentally reveal sensitive information, users should avoid uploading photos from sensitive places such as hospitals, clinics, schools, shelters, places of worship, protests, private homes, or locations where people may have a strong expectation of privacy.

If Adoracle receives sensitive data unexpectedly, it may delete or restrict the data unless retention is required to handle a safety, abuse, legal, or support issue.

10. Age and minors

Adoracle is intended for users aged 16 or older unless a separate child-safety and parental-consent flow is implemented. Users under 16 should not use the app or create an account without parental/guardian involvement where required by law.

Adoracle is not directed at children and should not be marketed as a toy, children's game, or child-directed social app. Owlzi physical objects are art/ritual companions, not toys, unless separately assessed and marketed under toy-safety rules.

11. Social sharing and partner rewards

Adoracle may allow users to share quest photos or completion messages to third-party services such as social networks or messaging apps. Sharing should be user-initiated. Third-party services process shared content under their own terms and privacy policies.

Partner quests, sponsored quests, affiliate links, reward codes, and paid placements must be clearly labeled. If Adoracle receives commission, payment, free products, free services, or another economic benefit, this will be disclosed near the relevant quest or link.

Adoracle should not upload a user's contacts or scrape social accounts for proof of sharing unless a separate, clear consent and privacy assessment is completed.

12. Cookies and local storage

The static Adoracle landing site is intended not to use analytics cookies, ad pixels, retargeting pixels, or external tracking scripts. The optional account portal uses necessary browser storage for the Supabase session, OAuth PKCE state, a stable browser installation ID, and a pending invitation token. The Android app may use local storage, IndexedDB, Room, and device app storage for settings, synced metadata, and device-local photos.

Local storage on the user's device is not the same as Adoracle receiving the data on its server, but it can still contain personal information. Users can delete local data in the app settings or through browser/device storage controls.

If Adoracle later uses non-essential cookies, web analytics, advertising pixels, or similar tracking technologies, it must request consent before using them and update the cookie information.

13. Processors and recipients

Personal data may be processed by carefully selected service providers where necessary. Replace the placeholders below with your real providers before launch.

Recipient / processorPurposeLocation / transfer note
[[WEB_HOSTING_PROVIDER]]Hosting, server logs, security.[[HOSTING_REGION_AND_TRANSFER_BASIS]]
SupabaseGoogle-linked authentication, session management, and hosted PostgreSQL family metadata.[[SUPABASE_PROJECT_REGION_AND_TRANSFER_BASIS]]
GoogleOAuth sign-in for the optional family portal and Android account.Google processes sign-in under its own privacy terms; document the configured transfer basis before launch.
[[AI_VERIFICATION_PROVIDER_OR_NONE]]Optional image verification.[[AI_REGION_RETENTION_AND_TRANSFER_BASIS]]
[[EMAIL_PROVIDER]]Support emails and notifications.[[EMAIL_REGION_AND_TRANSFER_BASIS]]
[[APP_DISTRIBUTION_PROVIDER_OR_NONE]]App distribution, beta testing, crash logs, purchase records if applicable.[[APP_DISTRIBUTION_REGION_AND_TRANSFER_BASIS]]
[[PAYMENT_PROVIDER_OR_NONE]]Payments, invoices, refunds if paid features are introduced.[[PAYMENT_REGION_AND_TRANSFER_BASIS]]

Where providers process personal data on Adoracle's behalf, Adoracle should conclude data processing agreements. Where personal data is transferred outside the EEA, Adoracle should rely on an adequacy decision, Standard Contractual Clauses, or another valid transfer mechanism, plus supplementary safeguards where needed.

14. Retention periods

DataRetention
Website server logsAs short as reasonably possible for security/troubleshooting; placeholder: [[SERVER_LOG_RETENTION_DAYS]] days.
Local quest history and local photosUntil the user deletes them from the app/device, uninstalls the app, or clears browser/app storage.
Uploaded verification photoDelete after verification; placeholder target: [[VERIFICATION_PHOTO_RETENTION_HOURS]] hours, unless support/legal/security retention is needed.
Verification resultAs long as needed for quest history, points, anti-cheat, and support; placeholder: [[VERIFICATION_RESULT_RETENTION_PERIOD]].
Account, family, Journal, and CertifiCute metadataUntil deletion request, family removal, configured inactivity deletion, or a legal/security retention need. Declined and cancelled redemption attempts remain part of the family audit history until deletion.
Support emailsAs long as needed to handle the issue and document claims; placeholder: [[SUPPORT_EMAIL_RETENTION_PERIOD]].
Accounting/payment recordsFor statutory Austrian tax/accounting retention periods where applicable.
Partner reward recordsAs long as needed for redemption, fraud prevention, accounting, and partner reporting.

Backups may persist for a limited time after deletion until overwritten under normal backup cycles.

15. User rights

Users have the right to request access, rectification, deletion, restriction, portability, objection, and withdrawal of consent where applicable. To exercise rights, contact [[PRIVACY_EMAIL_OR_SAME_AS_SUPPORT]].

Users also have the right to lodge a complaint with a data protection supervisory authority. In Austria, this is the Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna. Use the official authority website rather than links copied from this template.

When a request concerns local-only data stored solely on the user's device, Adoracle may not be able to access it. In that case, users can delete the data using the in-app deletion function or their browser/device storage settings.

16. Security

Adoracle should use HTTPS, access controls, least-privilege permissions, secure authentication where accounts exist, regular software updates, encrypted transport, secure storage for secrets, and deletion routines for temporary verification files. No internet service can be guaranteed completely secure.

If a personal data breach occurs and is likely to create a risk to users' rights and freedoms, Adoracle will assess notification duties and notify the competent authority and/or affected users where required.

17. Changes to this policy

Adoracle may update this policy when the app changes, providers change, legal requirements change, or new features are introduced. Material changes should be communicated in the app or on the website. The current version date is shown at the top of this page.

Contents
  1. Controller and contact
  2. Scope and current configuration
  3. Privacy principles for Adoracle
  4. Data categories processed
  5. Purposes and legal bases
  6. Location data
  7. Photos, camera, and metadata
  8. AI verification
  9. Special category data and sensitive places
  10. Age and minors
  11. Social sharing and partner rewards
  12. Cookies and local storage
  13. Processors and recipients
  14. Retention periods
  15. User rights
  16. Security
  17. Changes to this policy
Adoracle is a Crystal Sky project. Operator: Jake Austin Hyvonen, Vienna, Austria.
Impressum & legal notice Privacy policy Terms of Use Cookies & local storage Partner & ad disclosure Withdraw from contract Delete data Accessibility Support
© 2026 Jake Austin Hyvonen. This static template uses no tracking pixels or external fonts.