Privacy Policy

Last Updated: November 23, 2025 | Version: 1.1

Table of Contents

  • Privacy Policy
  • 1. Introduction
  • 2. Data Controller Information
  • 3. Legal Basis for Processing
  • 4. Personal Data We Collect
  • 4.1 Information You Provide Directly
  • 4.2 Information Collected Automatically
  • 4.3 Information from Third Parties
  • 5. How We Use Your Personal Data
  • 5.1 Essential Purposes (Always Active)
  • 5.2 Analytics & Performance (Requires Your Consent)
  • 5.3 Marketing (Requires Your Consent)
  • 6. Data Sharing and Disclosure
  • 6.1 Service Providers
  • 6.2 Legal Requirements
  • 6.3 Business Transfers
  • 6.4 Team and Friend Data Sharing
  • 7. International Data Transfers
  • 8. Data Retention
  • 9. Your Rights Under GDPR
  • 9.1 Right of Access (Article 15)
  • 9.2 Right to Rectification (Article 16)
  • 9.3 Right to Erasure / "Right to be Forgotten" (Article 17)
  • 9.4 Right to Data Portability (Article 20)
  • 9.5 Right to Restriction of Processing (Article 18)
  • 9.6 Right to Object (Article 21)
  • 9.7 Right to Withdraw Consent (Article 7(3))
  • 9.8 Right to Lodge a Complaint
  • 10. How to Exercise Your Rights
  • Export Your Data
  • Delete Your Account
  • Manage Consent Preferences
  • Update Profile Information
  • 11. Age Restriction
  • 12. Data Security
  • 13. Cookies and Tracking Technologies
  • 14. Third-Party Links
  • 15. Automated Decision-Making
  • 16. Data Breach Notification
  • 17. Changes to This Privacy Policy
  • 18. Contact Us
  • 19. Supervisory Authority
  • 20. Additional Information for Specific Regions
  • For EU/EEA Users
  • For California Users (CCPA)
  • For UK Users

Privacy Policy

Last Updated: November 23, 2025
Effective Date: November 23, 2025 Version: 1.1

1. Introduction

Welcome to Sisyfuzz ("we," "our," or "us"). We are committed to protecting your personal data and respecting your privacy rights. This Privacy Policy explains how we collect, use, store, and protect your information when you use our mobile application and services (collectively, the "Service").

This policy is designed to comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Data Controller Information

Data Controller:
Company: Sisyfuzz Email: sisyfuzz.app@gmail.com

For any questions about this Privacy Policy or our data practices, please contact us at the above address.

3. Legal Basis for Processing

We process your personal data under the following legal bases (GDPR Article 6):

  • Consent (Article 6(1)(a)): For analytics, marketing communications, and optional features
  • Contract Performance (Article 6(1)(b)): To provide our services and manage your account
  • Legal Obligation (Article 6(1)(c)): To comply with legal requirements (e.g., tax, accounting)
  • Legitimate Interests (Article 6(1)(f)): For security, fraud prevention, and service improvement

4. Personal Data We Collect

4.1 Information You Provide Directly

  • Account Information: Email address, username, display name, date of birth
  • Profile Data: User preferences, settings, language selection
  • User-Generated Content: Tasks (deeds), templates, scenes, notes, and other content you create
  • Subscription Information: Payment details (processed by third-party payment providers), subscription plan, purchase history
  • Communications: Feedback, support requests, survey responses

4.2 Information Collected Automatically

  • Device Information: Device type, operating system, unique device identifiers
  • Usage Data: App interactions, feature usage, session duration, navigation patterns
  • Performance Data: Crash reports, error logs, app performance metrics
  • Authentication Data: Login timestamps, authentication tokens (encrypted)

4.3 Information from Third Parties

  • Google Sign-In: If you authenticate via Google, we receive your Google account email and basic profile information
  • Email/Password Authentication: If you create an account with email and password, we store your email address (encrypted) for authentication, account recovery, and essential service notifications
  • Payment Providers: Transaction confirmations and subscription status (no payment card details are stored by us)

5. How We Use Your Personal Data

5.1 Essential Purposes (Always Active)

  • Provide and maintain the Service
  • Create and manage your account
  • Process transactions and subscriptions
  • Authenticate your identity and prevent fraud
  • Provide customer support
  • Send essential service notifications (e.g., account changes, security alerts)
  • Comply with legal obligations

5.2 Analytics & Performance (Requires Your Consent)

  • Analyze usage patterns and improve user experience
  • Monitor app performance and fix technical issues
  • Understand feature adoption and user engagement
  • Generate aggregated, anonymized statistics

5.3 Marketing (Requires Your Consent)

  • Send promotional communications about new features
  • Provide personalized offers and recommendations
  • Conduct surveys and research

You can withdraw consent for analytics and marketing at any time through Settings > Privacy & Data.

6. Data Sharing and Disclosure

We do not sell your personal data. We share your information only in the following circumstances:

6.1 Service Providers

We use trusted third-party service providers who process data on our behalf:

  • Supabase/Google Cloud Platform: Hosting, authentication, database, analytics
  • Payment Processors: Subscription and payment processing (Google Play, Apple App Store)
  • Email Services: Transactional and notification emails

All service providers are contractually bound to protect your data and use it only for specified purposes.

6.2 Legal Requirements

We may disclose your information if required by law, court order, or government regulation, or to:

  • Protect our legal rights
  • Prevent fraud or security threats
  • Protect user safety

6.3 Business Transfers

If we undergo a merger, acquisition, or sale of assets, your data may be transferred to the new entity, subject to this Privacy Policy.

6.4 Team and Friend Data Sharing

When you use our team collaboration and friend connection features, certain data is shared with other users based on your privacy settings:

Friend Connections:

  • Friends are connected through a special team system using invite codes
  • You control what friends can see through 4 privacy levels:
    • Level 1 (Hidden): Friends cannot see any of your stats or activity
    • Level 2 (Aggregated - Default): Friends see only total XP, deed count, and level
    • Level 3 (Shared Content): Friends see stats for scenes and templates with matching blueprints/presets, plus aggregated totals
    • Level 4 (Full): Friends see all your activity details and progress
  • You can change privacy levels for each friend at any time through Settings > Friends > Privacy Settings

Team Collaboration:

  • When you join a team, team members can see:
    • Your username and display name
    • Team deeds assigned to you or completed by you
    • Your contributions to shared team goals
    • Basic stats related to team activities
  • Team owners can manage member visibility and permissions
  • You can leave a team at any time, which stops all data sharing with that team

Managing Your Sharing Preferences:

  • Settings > Friends > Privacy Settings (for friend connections)
  • Settings > Teams > Manage Teams (for team memberships)
  • You can remove friends or leave teams at any time to stop data sharing

7. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States (where Supabase/Google Cloud servers are located). We ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): EU-approved data transfer mechanisms
  • Adequacy Decisions: Transfers to countries deemed adequate by the EU Commission
  • Your Consent: Where required by law

8. Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this policy:

Data Category Retention Period
Active account data While your account is active
Deleted account data Immediately deleted; backup copies retained 90 days for disaster recovery
Inactive accounts Notified after 2 years, deleted after 3 years if no response
Analytics data (raw) Aggregated after 6 months, deleted after 2 years
Audit logs 3 years (legal requirement)
Backup data 90 days, then permanently deleted

9. Your Rights Under GDPR

You have the following rights regarding your personal data:

9.1 Right of Access (Article 15)

Request a copy of all personal data we hold about you.

9.2 Right to Rectification (Article 16)

Correct inaccurate or incomplete personal data.

9.3 Right to Erasure / "Right to be Forgotten" (Article 17)

Request deletion of your personal data (subject to legal obligations).

9.4 Right to Data Portability (Article 20)

Receive your data in a structured, machine-readable format (JSON) and transmit it to another service.

9.5 Right to Restriction of Processing (Article 18)

Request temporary suspension of data processing while maintaining your account.

9.6 Right to Object (Article 21)

Object to processing based on legitimate interests or for direct marketing purposes.

9.7 Right to Withdraw Consent (Article 7(3))

Withdraw consent for analytics or marketing at any time without affecting prior processing.

9.8 Right to Lodge a Complaint

File a complaint with your local data protection authority if you believe we've violated your rights.

To exercise these rights: Go to Settings > Privacy & Data in the app, or contact us at sisyfuzz.app@gmail.com.

10. How to Exercise Your Rights

Export Your Data

Settings > Privacy & Data > Export My Data (available in JSON and PDF formats)

Delete Your Account

Settings > Account > Delete Account (immediate permanent deletion; backup copies retained 90 days)

Manage Consent Preferences

Settings > Privacy & Data > Consent Management

Update Profile Information

Settings > Profile > Edit Profile

11. Age Restriction

Our Service is restricted to users who are 18 years of age or older. We implement age verification during signup:

  • Users under 18 cannot create accounts
  • Age verification is required during account creation
  • We collect date of birth solely for age verification purposes

If we discover we've collected data from a user under 18, we will delete it immediately and terminate the account.

12. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in Transit: TLS/SSL encryption for all data transmission
  • Encryption at Rest: Supabase encryption for stored data
  • Authentication Security: Secure token-based authentication with Supabase Auth
  • Access Controls: Role-based access and principle of least privilege
  • Regular Audits: Security assessments and vulnerability testing
  • Incident Response: Data breach notification procedures (within 72 hours as required by GDPR)

However, no system is 100% secure. We cannot guarantee absolute security but commit to promptly addressing any security incidents.

13. Cookies and Tracking Technologies

We use the following technologies:

  • Essential Cookies: Required for authentication and core functionality (cannot be disabled)
  • Analytics Cookies: Track usage patterns (requires your consent)
  • Session Storage: Temporary data for app functionality

You can manage cookie preferences through Settings > Privacy & Data > Consent Management.

14. Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for their privacy practices. Please review their privacy policies before providing any personal data.

15. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or significantly affects you without human intervention.

16. Data Breach Notification

In the event of a data breach affecting your personal data, we will:

  1. Notify the relevant supervisory authority within 72 hours (GDPR Article 33)
  2. Notify affected users without undue delay (GDPR Article 34)
  3. Provide information about the breach, its likely consequences, and mitigation measures
  4. Take immediate steps to contain and remediate the breach

17. Changes to This Privacy Policy

We may update this Privacy Policy periodically. When we make material changes:

  • We will update the "Last Updated" date
  • We will notify you via in-app notification or email
  • We may require you to re-consent to continue using certain features
  • Previous versions will be archived and available upon request

Your continued use of the Service after changes constitutes acceptance of the updated policy.

18. Contact Us

For questions, concerns, or to exercise your rights:

Email: sisyfuzz.app@gmail.com
Location: Heidelberg, Germany
Data Protection Officer: Not applicable

Response Time: We aim to respond to all inquiries within 30 days as required by GDPR.

19. Supervisory Authority

If you are located in the EU/EEA, you have the right to lodge a complaint with your local data protection authority:

  • EU Data Protection Authorities: https://edpb.europa.eu/about-edpb/board/members_en
  • UK Information Commissioner's Office (ICO): https://ico.org.uk/

20. Additional Information for Specific Regions

For EU/EEA Users

This policy complies with GDPR. Your data controller is Sisyfuzz, and you have all rights outlined in Section 9.

For California Users (CCPA)

California residents have additional rights under the California Consumer Privacy Act. Contact us for more information.

For UK Users

This policy complies with UK GDPR and the Data Protection Act 2018.


Acknowledgment: By using Sisyfuzz, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.