Privacy Policy
KROPKI is an outdoor game: you look for dots on the map and complete quests on the spot. This policy explains what data we collect, why, who we entrust it to, how long we keep it and what rights you have. It applies to the Android and iOS apps and to the web version.
1. Data controller
The controller of your personal data is Spaceit Jakub Moskwa, ul. Głowackiego 17a, 22-400 Zamość, Poland, NIP (tax ID): 9223061813, REGON: 383202965. Contact for personal data matters: hello@grakropki.pl.
2. What data we collect and why
- Account. You can play as a guest. We then create an anonymous identifier, with no email address or name. If you sign in with Google, we receive your name, email address, profile picture and the tokens needed to sign you in. If you sign in with Apple, we receive your Apple account identifier, your email address (a relay address if you choose to hide yours) and your name if you choose to share it. If you sign in with an email link, we store your email address.
- Game profile. Nickname and game mode (solo, duo, squad, family).
- Progress. Quests started and completed, points, items in your collection and the dates you earned them.
- Quest submissions. Depending on the quest: a proof photo, a text answer, a typed or scanned QR code, and GPS coordinates at the moment of submission. They are used to check that the quest was completed. Photos and open answers may be reviewed by a moderator (only when you ask for a manual review).
- Automatic photo and answer check. A proof photo (or, for quests with an open answer, your answer) is assessed by Google's Gemini model. It receives only the photo or answer and the quest description and answers a single question: does the submission meet the quest's requirements. If it does, the quest is completed immediately. If not, the submission is rejected, you see a short reason, and you can try again or send the submission to a moderator with one tap; a person then reviews it and their decision is final. A moderator never sees a submission unless you ask. The photo is sent once, directly from our server to Google with no intermediaries; Google does not use it to train models or for advertising. Google may keep, for a limited time, a request that its automated abuse filters flag as a possible violation, solely to review it.
- Session and security. Session token, IP address and information about your browser or device, to keep you signed in and to protect accounts from abuse. The server also keeps short-lived technical logs.
We don’t show your data to other players, we don’t sell it and we don’t use it for advertising or profiling. The app contains no third-party analytics or advertising tools.
3. Location, camera and photos
- Location: only while the app is open, never in the background. On your device it shows your position on the map. We send coordinates to the server only when you submit a quest, to check that you are at the dot.
- Camera: for proof photos and scanning QR codes. The code is read on your device and we send only its content.
- Photo library: only when you pick a proof photo yourself; we send only that one photo.
You can revoke these permissions at any time in your system settings. Without them, some quests won’t work.
4. Legal basis
- Providing the game service you ask for: Art. 6(1)(b) GDPR (account, profile, progress, submissions, location and photos for quests).
- The controller’s legitimate interest: Art. 6(1)(f) GDPR (security, abuse prevention, technical logs, handling inquiries).
5. Who we entrust data to
- Cloudflare, Inc.: server, database, photo storage, technical logs and sending sign-in link emails.
- Google (Gemini API, Gemini model): assessment of proof photos and open answers. The photo or answer and the quest description go to Google only for the duration of the assessment and are not used to train models. Google may keep requests flagged by its automated abuse filters for a limited time in order to review them.
- Google: Sign in with Google (if you choose it) and the map in the Android app. Google processes data under its own privacy policy.
- Apple: Sign in with Apple (if you choose it) and the map in the iOS app. Apple processes data under its own privacy policy.
- OpenStreetMap: map tiles in the web version; its servers see the IP address the map is loaded from.
Some of these companies may process data outside the European Economic Area, on the basis of a European Commission adequacy decision (EU-US Data Privacy Framework) or standard contractual clauses.
6. How long we keep data
- Account, profile, progress, submissions, photos and coordinates: until you delete your account.
- Email sign-in link: valid for 5 minutes. The record with your address is deleted once it is used or shortly after it expires, and always together with your account.
- Sign-in sessions: until you sign out or the session expires, at the latest until your account is deleted.
- Server technical logs: up to 7 days.
- Database backup (used to restore the database after a failure): deleted data disappears from it within 30 days at the latest.
7. Your rights
You have the right to access your data, to have it rectified, erased or its processing restricted, to data portability, and to object to processing based on legitimate interest. Write to hello@grakropki.pl. We will reply within one month at the latest. You can also lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl).
8. Deleting your account
You can delete your account and all your data yourself in the app: Settings (Ustawienia) → Delete account (Usuń konto). How to do it without the app and exactly what we delete: Account deletion (in Polish).
9. Changes
If we change these rules, we will update this page and the date at the top.