Privacy Policy
Draft. Not in force. Not legal advice.
This policy explains what personal data Klooz collects, why, how long we keep it, and what you can do about it.
The part that matters most: Klooz is a location-based product. To decide whether you reached a checkpoint, the app reads your position while a session is running and sends it to us. Section 4 sets out exactly what we keep, for how long, and how to get rid of it. If you read one section, read that one.
1. Who is responsible for your data
The data controller is:
[FULL NAME], egyéni vállalkozó (registered sole trader) Registration number: [EV NYILVÁNTARTÁSI SZÁM] Registered address: [ADDRESS] Privacy contact: [PRIVACY EMAIL]
We have not appointed a Data Protection Officer. We are not required to: we do not carry out large-scale systematic monitoring or large-scale processing of special-category data as our core activity.
Drafting note. Revisit if scale grows. "Regular and systematic monitoring of data subjects on a large scale" (GDPR Art. 37(1)(b)) is a live question for a product that records position during sessions; the argument that it is not large-scale rests on user numbers, and user numbers change. Also revisit whether a Data Protection Impact Assessment is required under Art. 35: location tracking of individuals is on the Hungarian supervisory authority's DPIA list in some configurations, and one should be carried out before launch regardless.
Creators are separately responsible for personal data they collect through their own experiences beyond what the platform handles. Where that happens we are independent controllers, each for our own purposes.
2. What we collect and why
2.1 Account and profile
| Data | Where it comes from | Why | Lawful basis |
|---|---|---|---|
| Email address, password | You, at sign-up. Held in our identity service | Authentication, account recovery, service messages | Contract (Art. 6(1)(b)) |
| Email verification status | Identity service | Confirming the account is real | Contract |
| Display name | You | Shown to teammates and next to your reviews | Contract |
| Avatar reference | You, optional | Profile display | Contract |
| Preferred language and time zone | You, or your device | Showing content in your language and times that make sense | Contract |
| Profile type (player / creator) and which is active | You | Determines what the product shows you | Contract |
| Creator bio | You, creators only | Public creator profile | Contract |
| Consent records, which policy version you accepted, which permissions you agreed to, and when | You | Proving we asked, and honouring your choices | Legal obligation (Art. 6(1)(c)) and consent (Art. 6(1)(a)) |
Your password is never visible to us, the identity service stores a hash, not the password.
2.2 Gameplay
| Data | Why | Lawful basis |
|---|---|---|
| Sessions you take part in, and your role in them | Running the session, letting you rejoin, showing your history | Contract |
| Your position while a session is running | Deciding whether you reached a location; showing teammates roughly where you are | Contract (see §4) |
| Task answers, attempts and outcomes | Scoring, and resolving disputes about whether something was completed | Contract |
| Progress, scores and session timeline | The product | Contract |
| Offline event journal, what your device recorded while you had no signal, uploaded on reconnect | Awarding progress earned offline; validating it server-side; reconstructing what happened when a player says the app lost their work | Contract |
| Chat messages within a session | Team coordination | Contract |
| Device identifier for your installation | Attributing offline play to the right device; recovering a session | Contract |
| Join codes and team membership | Getting people into the same session | Contract |
2.3 Purchases (applies once paid tickets go live)
| Data | Why | Lawful basis |
|---|---|---|
| Orders, tickets held, validity and replay count | Delivering what you bought, and proving you are entitled to play | Contract |
| Payment status, provider reference, amount, currency | Fulfilment, refunds, accounting | Contract; legal obligation for accounting records |
| Invoice and tax details | Tax and accounting law | Legal obligation |
| Subscription plan and billing state (creators) | Running your plan | Contract |
We never receive or store your card number. Payment card data goes directly to Stripe. We see that a payment succeeded, its reference, and the amount.
2.4 Content you create
Experiences, listings, media you upload, reviews you write, and reports you submit. Processed to publish and distribute them, moderate them, and enforce our rules. Basis: contract for publication, legitimate interests for moderation, legal obligation where a law requires us to act on illegal content.
2.5 Safety, moderation and support
Reports you make or that are made about you, moderation decisions, enforcement actions, appeals, support cases and the session evidence attached to them. Basis: legal obligation (Digital Services Act Art. 16), and legitimate interests in keeping the platform safe and defending claims.
2.6 Technical data
Server logs, IP address, request time, endpoint, response, correlation identifier, user agent; app and device type and version; crash and error diagnostics. Basis: legitimate interests in operating the service securely and diagnosing faults.
We use no analytics cookies, no advertising technology and no third-party tracking. See the Cookie Policy.
We do capture internal product events (sign-ups, purchases, session transitions, publishes) to understand whether the product works. These are tied to your account. Basis: legitimate interests in operating and improving the service. You may object under §7.
2.7 Marketing
Only if you opt in. You can withdraw at any time, in settings or from any message we send. Basis: consent.
2.8 What we do not collect
We do not collect special-category data, health, ethnicity, religion, political opinion, sexual orientation, biometrics. Do not put it into a chat message, a review or an experience. We do not profile you for advertising, and we do not sell personal data to anyone.
3. Where the data comes from
Almost all of it comes from you or from your use of the product. We also receive:
- payment status from Stripe;
- authentication events from our identity service;
- reports about you from other users;
- your position from your device's operating system, once you grant permission.
4. Location data: the specifics
Because this is the most sensitive processing we do, here is precisely what happens.
4.1 When we read your position
Only while a session is active, and only after you grant the operating system permission. Not when the app is closed, not between sessions, not when you are browsing the catalogue.
4.2 What we keep
We keep your latest known position per session, not a continuous trail. As you play, each new reading replaces the previous one on our servers. There is no table of everywhere you have been.
The exception is offline play. When you play without signal, your device records what happened in an event journal, including position readings, and uploads it when you reconnect. That journal contains a sequence of positions from that session. We replay it to award progress, and we keep it under §4.4, because it is the only record that can settle a dispute about work done in the field.
4.3 Why the legal basis is contract, not consent
We process position data because performing the contract requires it: an experience triggered by arriving at a place cannot work without knowing you arrived. We rely on Article 6(1)(b) GDPR.
We still ask for your permission on the device, and we still record your choice, because your operating system requires it and because you should know. But we are not pretending that permission is the legal basis; a "consent" you cannot refuse without losing the product is not freely given, and treating it as the basis would be weaker protection for you, not stronger.
What this means in practice: you cannot withdraw location processing and still play a location-triggered experience. You can withdraw the device permission at any time, and you can stop playing, close your account, and have the data erased (§7).
4.4 How long we keep it
Position data and offline journals are deleted 90 days after a session ends.
At that point the session record is stripped of the identifiers linking it to you and to any position. What remains is anonymous aggregate information (that a session was completed, how long it took, what score it reached) which creators see as statistics about their experience and which is no longer personal data.
90 days is the window that lets us answer a "your app lost my progress" complaint, a payment dispute, or a safety report about an experience. After that, holding it has no purpose.
4.5 Who sees it
- Your teammates, during an active session, see your approximate position and your progress. That is the point of a team session. Do not join one with people you would not share that with.
- We see it to run the session and, in support, to reconstruct what happened when someone asks us to.
- Creators do not see individual player positions. They see aggregate statistics about their experience.
- Nobody else, unless the law requires it (§6).
5. How long we keep everything else
| Data | Retention |
|---|---|
| Account and profile | While the account exists, then deleted or anonymised within 30 days of closure |
| Consent records | 5 years after the consent ends, evidence that we asked and what you chose |
| Session records, positions, journals, chat, task answers | 90 days after the session ends, then anonymised (§4.4) |
| Orders, tickets, payment references | 8 years, as Hungarian accounting law requires |
| Invoices and tax records | 8 years, legal obligation |
| Reviews you published | Until you delete them or your account closes; then the text is removed and an anonymised record kept for the experience's rating |
| Reports, moderation cases, enforcement decisions, appeals | 3 years after the case closes, to handle repeat behaviour, appeals and legal claims |
| Support cases | 2 years after closure |
| Server logs | 90 days |
| Product event records | [24] months, then aggregated |
| Marketing consent and history | Until you withdraw, plus 1 year as proof of what you chose |
| Backups | Overwritten on a rolling [30]-day cycle. Data you delete disappears from backups within that period |
Where a legal claim, an investigation or a legal obligation requires it, we keep the relevant data until that is resolved, and no longer.
Drafting note. The 8-year figures follow the retention rule in Hungarian accounting law (Act C of 2000). Confirm the exact period and what it attaches to. Every other figure in this table is a proposal, not a legal requirement, and each one needs to be matched by an actual deletion job in code before this policy is published; see the README. A retention schedule nobody executes is worse than none: it is a documented promise you are visibly breaking.
6. Who we share data with
We do not sell personal data. We share it only as set out here.
6.1 Other users
Your display name, avatar and reviews are visible publicly. Within a session, teammates see your display name, progress and approximate position.
6.2 Creators
The creator of an experience you play sees aggregate statistics and your review if you write one. They do not get your email address, your position, or your identity beyond your display name.
6.3 Service providers
Each of these is a processor acting on our instructions under a data processing agreement.
| Provider | Role | Data | Location |
|---|---|---|---|
| [HOSTING PROVIDER] | Servers and database | Everything | [EU REGION] |
| Cloudflare | Media storage and delivery | Uploaded images and audio, offline map packs | EU storage region; company is US-based, transfers covered by Standard Contractual Clauses |
| Stripe Payments Europe, Ltd. | Payments | Payment data, email, order references | Ireland (EU) |
| [EMAIL PROVIDER] | Transactional email | Email address, message content | [REGION] |
| Expo (EAS) | Mobile app builds and updates | Crash diagnostics, app version, device model | US, Standard Contractual Clauses |
| Apple / Google | App distribution and push notification delivery | Push tokens, device identifiers | US, Standard Contractual Clauses |
Our identity service, our realtime service and our map data run on our own servers; they are our software, not third parties.
Drafting note. Every row needs a signed DPA before launch, and the blanks filled with the actual provider, its entity name, and the region. Stripe's DPA is accepted through the dashboard. The hosting and email rows cannot be completed until those decisions are made. Confirm whether Expo/EAS receives any personal data at all in the configuration you ship, if updates and crash reporting are off, that row shrinks or disappears.
6.4 Authorities
We disclose data where the law requires it (a court order, a criminal investigation, a regulator's request) or to establish or defend legal claims. Where we are permitted to tell you, we will.
Content that is child sexual abuse material is reported to the authorities without exception and without notice.
6.5 Business transfer
If the business is sold or transferred, your data may transfer with it. You will be told before it happens, and this policy continues to apply until you are given a new one.
7. Your rights
Under the GDPR you have the right to:
- know what we hold and why: this document, and a copy on request;
- access your data;
- correct anything wrong;
- delete your data ("right to be forgotten"), subject to what we must keep by law;
- restrict processing while a dispute about it is resolved;
- object to processing based on legitimate interests (including our product event records) on grounds relating to your situation;
- port your data to another service in a machine-readable format;
- withdraw consent at any time, for anything based on consent, without affecting what was lawful before;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
7.1 How to use them
In the app: settings let you edit your profile, change your consents, download your data, and delete your account.
By email: [PRIVACY EMAIL].
We respond within one month. If a request is complex we may extend by two further months and will tell you why. We do not charge, unless a request is manifestly unfounded or repetitive.
We may ask you to confirm your identity before acting, not to obstruct you, but because handing your data to someone impersonating you would be worse than the delay.
Drafting note (launch blocker, narrowed): the API exists, the in-app entry points are pending. Export and deletion now exist as endpoints:
GET /api/me/exportreturns the Art. 15 bundle as JSON, andPOST/DELETE /api/me/deletionclose an account and cancel that closure inside the 30-day window (branchfeature/account-deletion-export). No screen in the mobile app or player web calls either one, so the sentence "In the app: settings let you … download your data, and delete your account" is still not true of the shipped product, and Apple's in-app-deletion requirement is not yet met. Two further gaps behind this section: nothing yet runs the day-30 erasure on a schedule (the endpoints close an account, but the erasure that follows is invoked by no job; README item 2, the retention spec'sAccountErasureJob) and [PRIVACY EMAIL] is still a placeholder here and in the configuration (Compliance:PrivacyContactis empty), so the by-email channel this section offers has no address. Do not publish this section until the client entry points exist. The README tracks the remainder as launch blocker 1, backend-complete / client-pending.
7.2 What deletion actually does
When you delete your account we remove your profile, display name, avatar, consents, sessions, positions, journals and chat messages, and detach your reviews from you.
We keep, for as long as the law requires: order and invoice records (accounting law), consent records (proof we asked), and records relating to a report, moderation decision or legal claim involving you. Those are minimised to what the obligation needs.
Anonymised statistics (that a session happened, that an experience has a rating) remain. They are no longer personal data and cannot be traced back to you.
Deletion propagates to backups within the backup cycle in §5.
7.3 Complaints
Tell us first ([PRIVACY EMAIL]) and we will try to fix it.
You may complain to the Hungarian supervisory authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) 1055 Budapest, Falk Miksa utca 9-11 Postal: 1363 Budapest, Pf. 9 ugyfelszolgalat@naih.hu · +36 1 391 1400 · naih.hu
You may also complain to the authority in the EU country where you live or work.
8. Automated decisions
The platform decides automatically whether you reached a location, whether an answer was correct, and what you scored. Those decisions follow rules the creator wrote, and you can ask support to review any of them (§7).
A person makes every decision that restricts your account or removes your content, or reviews it on appeal. We do not use automated tools to suspend accounts or remove content. Where that changes, we will say so here and in the statement of reasons you receive, as the Digital Services Act requires.
We do not profile you, and we do not make decisions producing legal or similarly significant effects by automated means alone.
9. Children
Klooz is not for children under 16. You must be 16 to hold an account, and under-18s must play accompanied by a responsible adult (Player Terms §4.1).
We do not knowingly collect data from anyone under 16. If we learn we have, we delete it. If you believe a child has given us data, tell us at [PRIVACY EMAIL].
10. Security
- Everything travels over encrypted connections (TLS).
- Passwords are hashed by our identity service; we never see them.
- We never receive payment card details.
- Access to production data is limited to those who need it, and is logged.
- Data is stored in the EU.
- Backups are encrypted and their restore is tested.
- Every action a support or moderation operator takes is recorded with who did it, why and when.
No system is perfectly secure. If a breach puts your rights at risk, we will notify the supervisory authority within 72 hours and tell you without undue delay, as the GDPR requires.
Found a vulnerability? [SECURITY EMAIL]. We will not pursue good-faith research reported responsibly.
Drafting note. Two of these claims currently overstate the code. Moderation and support records are held in memory and do not survive a restart, so the audit trail in the last bullet is not durable yet. And backup restore has not been rehearsed against a real environment. Fix both, or soften both, before publishing.
11. International transfers
Your data is stored in the EU. Where a provider in §6.3 is based outside the EEA, transfers are covered by the European Commission's Standard Contractual Clauses, together with technical measures: encryption in transit and at rest, and minimising what is sent. You can ask us for a copy of the safeguards at [PRIVACY EMAIL].
12. Changes
We will update this policy when what we do changes. Material changes are notified by email or in the app at least 30 days before they take effect, and each version has a policy_id we record against your acceptance.
Changes required by law may take effect sooner where the law requires.
Last reviewed against the codebase: 2026-07-31.