Privacy Policy
Last Updated: November 23, 2025
Effective Date: November 23, 2025
Version: 1.1
1. Introduction
Welcome to Sisyfuzz ("we," "our," or "us"). We are committed to protecting your personal data and respecting your privacy rights. This Privacy Policy explains how we collect, use, store, and protect your information when you use our mobile application and services (collectively, the "Service").
This policy is designed to comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Data Controller:
Company: Sisyfuzz
Email: sisyfuzz.app@gmail.com
For any questions about this Privacy Policy or our data practices, please contact us at the above address.
3. Legal Basis for Processing
We process your personal data under the following legal bases (GDPR Article 6):
- Consent (Article 6(1)(a)): For analytics, marketing communications, and optional features
- Contract Performance (Article 6(1)(b)): To provide our services and manage your account
- Legal Obligation (Article 6(1)(c)): To comply with legal requirements (e.g., tax, accounting)
- Legitimate Interests (Article 6(1)(f)): For security, fraud prevention, and service improvement
4. Personal Data We Collect
- Account Information: Email address, username, display name, date of birth
- Profile Data: User preferences, settings, language selection
- User-Generated Content: Tasks (deeds), templates, scenes, notes, and other content you create
- Subscription Information: Payment details (processed by third-party payment providers), subscription plan, purchase history
- Communications: Feedback, support requests, survey responses
- Device Information: Device type, operating system, unique device identifiers
- Usage Data: App interactions, feature usage, session duration, navigation patterns
- Performance Data: Crash reports, error logs, app performance metrics
- Authentication Data: Login timestamps, authentication tokens (encrypted)
- Google Sign-In: If you authenticate via Google, we receive your Google account email and basic profile information
- Email/Password Authentication: If you create an account with email and password, we store your email address (encrypted) for authentication, account recovery, and essential service notifications
- Payment Providers: Transaction confirmations and subscription status (no payment card details are stored by us)
5. How We Use Your Personal Data
5.1 Essential Purposes (Always Active)
- Provide and maintain the Service
- Create and manage your account
- Process transactions and subscriptions
- Authenticate your identity and prevent fraud
- Provide customer support
- Send essential service notifications (e.g., account changes, security alerts)
- Comply with legal obligations
- Analyze usage patterns and improve user experience
- Monitor app performance and fix technical issues
- Understand feature adoption and user engagement
- Generate aggregated, anonymized statistics
5.3 Marketing (Requires Your Consent)
- Send promotional communications about new features
- Provide personalized offers and recommendations
- Conduct surveys and research
You can withdraw consent for analytics and marketing at any time through Settings > Privacy & Data.
6. Data Sharing and Disclosure
We do not sell your personal data. We share your information only in the following circumstances:
6.1 Service Providers
We use trusted third-party service providers who process data on our behalf:
- Supabase/Google Cloud Platform: Hosting, authentication, database, analytics
- Payment Processors: Subscription and payment processing (Google Play, Apple App Store)
- Email Services: Transactional and notification emails
All service providers are contractually bound to protect your data and use it only for specified purposes.
6.2 Legal Requirements
We may disclose your information if required by law, court order, or government regulation, or to:
- Protect our legal rights
- Prevent fraud or security threats
- Protect user safety
6.3 Business Transfers
If we undergo a merger, acquisition, or sale of assets, your data may be transferred to the new entity, subject to this Privacy Policy.
6.4 Team and Friend Data Sharing
When you use our team collaboration and friend connection features, certain data is shared with other users based on your privacy settings:
Friend Connections:
- Friends are connected through a special team system using invite codes
- You control what friends can see through 4 privacy levels:
- Level 1 (Hidden): Friends cannot see any of your stats or activity
- Level 2 (Aggregated - Default): Friends see only total XP, deed count, and level
- Level 3 (Shared Content): Friends see stats for scenes and templates with matching blueprints/presets, plus aggregated totals
- Level 4 (Full): Friends see all your activity details and progress
- You can change privacy levels for each friend at any time through Settings > Friends > Privacy Settings
Team Collaboration:
- When you join a team, team members can see:
- Your username and display name
- Team deeds assigned to you or completed by you
- Your contributions to shared team goals
- Basic stats related to team activities
- Team owners can manage member visibility and permissions
- You can leave a team at any time, which stops all data sharing with that team
Managing Your Sharing Preferences:
- Settings > Friends > Privacy Settings (for friend connections)
- Settings > Teams > Manage Teams (for team memberships)
- You can remove friends or leave teams at any time to stop data sharing
7. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States (where Supabase/Google Cloud servers are located). We ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs): EU-approved data transfer mechanisms
- Adequacy Decisions: Transfers to countries deemed adequate by the EU Commission
- Your Consent: Where required by law
8. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy:
| Data Category |
Retention Period |
| Active account data |
While your account is active |
| Deleted account data |
Immediately deleted; backup copies retained 90 days for disaster recovery |
| Inactive accounts |
Notified after 2 years, deleted after 3 years if no response |
| Analytics data (raw) |
Aggregated after 6 months, deleted after 2 years |
| Audit logs |
3 years (legal requirement) |
| Backup data |
90 days, then permanently deleted |
9. Your Rights Under GDPR
You have the following rights regarding your personal data:
9.1 Right of Access (Article 15)
Request a copy of all personal data we hold about you.
9.2 Right to Rectification (Article 16)
Correct inaccurate or incomplete personal data.
9.3 Right to Erasure / "Right to be Forgotten" (Article 17)
Request deletion of your personal data (subject to legal obligations).
9.4 Right to Data Portability (Article 20)
Receive your data in a structured, machine-readable format (JSON) and transmit it to another service.
9.5 Right to Restriction of Processing (Article 18)
Request temporary suspension of data processing while maintaining your account.
9.6 Right to Object (Article 21)
Object to processing based on legitimate interests or for direct marketing purposes.
9.7 Right to Withdraw Consent (Article 7(3))
Withdraw consent for analytics or marketing at any time without affecting prior processing.
9.8 Right to Lodge a Complaint
File a complaint with your local data protection authority if you believe we've violated your rights.
To exercise these rights: Go to Settings > Privacy & Data in the app, or contact us at sisyfuzz.app@gmail.com.
10. How to Exercise Your Rights
Export Your Data
Settings > Privacy & Data > Export My Data (available in JSON and PDF formats)
Delete Your Account
Settings > Account > Delete Account (immediate permanent deletion; backup copies retained 90 days)
Manage Consent Preferences
Settings > Privacy & Data > Consent Management
Settings > Profile > Edit Profile
11. Age Restriction
Our Service is restricted to users who are 18 years of age or older. We implement age verification during signup:
- Users under 18 cannot create accounts
- Age verification is required during account creation
- We collect date of birth solely for age verification purposes
If we discover we've collected data from a user under 18, we will delete it immediately and terminate the account.
12. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in Transit: TLS/SSL encryption for all data transmission
- Encryption at Rest: Supabase encryption for stored data
- Authentication Security: Secure token-based authentication with Supabase Auth
- Access Controls: Role-based access and principle of least privilege
- Regular Audits: Security assessments and vulnerability testing
- Incident Response: Data breach notification procedures (within 72 hours as required by GDPR)
However, no system is 100% secure. We cannot guarantee absolute security but commit to promptly addressing any security incidents.
13. Cookies and Tracking Technologies
We use the following technologies:
- Essential Cookies: Required for authentication and core functionality (cannot be disabled)
- Analytics Cookies: Track usage patterns (requires your consent)
- Session Storage: Temporary data for app functionality
You can manage cookie preferences through Settings > Privacy & Data > Consent Management.
14. Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for their privacy practices. Please review their privacy policies before providing any personal data.
15. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or significantly affects you without human intervention.
16. Data Breach Notification
In the event of a data breach affecting your personal data, we will:
- Notify the relevant supervisory authority within 72 hours (GDPR Article 33)
- Notify affected users without undue delay (GDPR Article 34)
- Provide information about the breach, its likely consequences, and mitigation measures
- Take immediate steps to contain and remediate the breach
17. Changes to This Privacy Policy
We may update this Privacy Policy periodically. When we make material changes:
- We will update the "Last Updated" date
- We will notify you via in-app notification or email
- We may require you to re-consent to continue using certain features
- Previous versions will be archived and available upon request
Your continued use of the Service after changes constitutes acceptance of the updated policy.
For questions, concerns, or to exercise your rights:
Email: sisyfuzz.app@gmail.com
Location: Heidelberg, Germany
Data Protection Officer: Not applicable
Response Time: We aim to respond to all inquiries within 30 days as required by GDPR.
19. Supervisory Authority
If you are located in the EU/EEA, you have the right to lodge a complaint with your local data protection authority:
For EU/EEA Users
This policy complies with GDPR. Your data controller is Sisyfuzz, and you have all rights outlined in Section 9.
For California Users (CCPA)
California residents have additional rights under the California Consumer Privacy Act. Contact us for more information.
For UK Users
This policy complies with UK GDPR and the Data Protection Act 2018.
Acknowledgment: By using Sisyfuzz, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.