Ir al contenido principal
Paper Chase

Política de privacidad

Última actualización: 2026-03-10

Este documento está actualmente disponible solo en inglés.

1. Data Controller

The controller of your personal data is:

Cyber Beaver Studio Kamil Dutka ul. Dolnych Młynów 3/1, 31-124 Kraków Poland

Contact Email: contact@paperchase.app Data Protection Contact Point: gdpr@paperchase.app

Note: The data protection contact point is not a formally appointed Data Protection Officer (DPO) under GDPR Article 37. As a micro enterprise, we are not required to appoint a DPO. The contact point above is available for all data protection inquiries.

We process your personal data in accordance with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR” / “RODO”)
  • Polish Act on Protection of Personal Data (Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych)
  • Polish Act on Provision of Electronic Services (Ustawa z dnia 18 lipca 2002 r. o swiadczeniu uslug droga elektroniczna)

2. Data We Collect

2.1 Data You Provide Directly

Required data:

  • Email address – Account creation, authentication, communication
  • Username – Public identification within the Platform
  • Language preference – App localization (auto-detected, changeable)
  • Country – Regional content and leaderboards (auto-detected, changeable)

Optional data:

  • Display name – Public profile display
  • Profile photo / avatar – Public profile personalization (stored in Supabase Storage)
  • Gender – Profile personalization
  • Bio – Public profile description

2.2 Data from Third-Party Authentication

If you sign in using a third-party provider, we receive:

  • Google – Google ID token, email address, profile name
  • Apple – Apple ID token, email address (may be hidden via Apple relay), name
  • Facebook – Facebook ID token, profile information

We do not receive or store your third-party account passwords.

2.3 Data Collected Automatically

  • GPS coordinates – Core gameplay: Badge collection, location verification
  • Device information – Model, operating system version (for compatibility and debugging)
  • App version – Feature availability, debugging
  • Timezone – Time-based features, display formatting
  • IP address – Network communication, security, abuse prevention

2.4 Data Generated Through Use

  • Badge completions and timestamps – Gameplay progress tracking
  • Game progress – Challenge completion tracking
  • Achievement unlocks – Milestone and reward tracking
  • Activity feed entries – Social features (completions with optional photos)
  • Comments and reactions – Social interaction
  • Ratings – Badge quality feedback
  • Following / follower relationships – Social connections
  • Blocking / muting relationships – User safety preferences
  • Content reports submitted – Reports of content you have flagged for review
  • Notification history – Communication records
  • Points and leaderboard rankings – Gamification features

The following data is only collected if you explicitly opt in during onboarding or in settings:

  • Analytics events – Service improvement, feature usage analysis. Opt-in via onboarding consent screen + Analytics settings.
  • Crash reports – Bug identification and fixing. Opt-in via onboarding consent screen + Analytics settings.
  • Push notification token – Delivering push notifications. Opt-in via onboarding notification screen + Notification settings.

Analytics data is anonymous. We use PostHog with anonymized user identifiers. No personally identifiable information (PII) is sent to our analytics service.

Crash reports contain no PII. Sentry receives only technical exception data and stack traces, with no personal information attached.


We process your personal data based on the following legal bases under GDPR Article 6(1):

  • Contract performance (Art. 6(1)(b)) – Account data, gameplay data, location verification – necessary to provide the Service as described in our Terms of Service.
  • Consent (Art. 6(1)(a)) – Analytics, crash reporting, push notifications, marketing communications – you can withdraw consent at any time.
  • Legitimate interests (Art. 6(1)(f)) – Security measures (HMAC signing, rate limiting), fraud prevention (anti-cheating detection), service improvement based on aggregated usage patterns.
  • Legal obligation (Art. 6(1)(c)) – Data retention required by Polish law, responding to legal requests.

You may withdraw consent at any time:

  • Analytics & crash reporting: In-app via Settings → Privacy
  • Push notifications: In-app via Settings → Notifications, or via your device’s system settings
  • Marketing: Via unsubscribe links in communications

Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.


4. How We Use Your Data

We use your personal data for the following purposes:

  1. Providing the Service – Account management, Badge collection, Game participation, social features, leaderboards, achievements.
  2. Location Verification – Confirming your physical presence at Badge locations to prevent cheating and ensure gameplay integrity.
  3. Communication – Sending account-related notifications, responding to support requests, and (with consent) marketing communications.
  4. Security and Fraud Prevention – Detecting and preventing unauthorized access, cheating (including GPS spoofing), and abuse of the Service. This includes HMAC request signing validation and rate limiting.
  5. Content Moderation – Automated filtering of user-submitted content before publication and manual review of reported content to enforce community guidelines and legal requirements. See Section 5 for details on automated processing.
  6. Service Improvement – Analyzing anonymized usage patterns and crash reports (with consent) to improve the Service.
  7. Legal Compliance – Fulfilling legal obligations, responding to legal processes, and protecting our rights.

5. Automated Processing

In accordance with GDPR Article 13(2)(f), we inform you about the following automated processing systems used in the Service.

5.1 Automated Content Filtering

Existence and purpose: We use an automated, rule-based keyword filter that checks user-submitted text content (comments, ratings, usernames, and display names) before publication.

Logic involved: The system uses predefined keyword lists to detect prohibited content. The filter operates across multiple languages and applies two strictness tiers: a standard tier for general user-generated content (comments, ratings) and a stricter tier for usernames and display names. The system uses pattern matching with normalization (including common character substitution detection) – it does not use machine learning or artificial intelligence.

Significance and consequences: Content that matches the filter is rejected at the time of submission and is not published. The User is informed that their submission was rejected. Individual rejections do not result in any account-level consequences (no warnings, suspensions, or bans). The User may revise their content and resubmit.

5.2 Anti-Cheat Detection

Existence and purpose: We use an automated, rule-based system to verify the integrity of Badge collections by checking the physical plausibility of a User’s location claims.

Logic involved: The system compares GPS distance between consecutive Badge collections against the elapsed time to detect physically impossible travel. This is a deterministic, rule-based calculation – it does not use machine learning or artificial intelligence.

Significance and consequences: Suspicious activity detected by this system is flagged for human review. The system does not automatically impose any penalties. A human moderator evaluates flagged cases before any enforcement action is taken.

5.3 Not Solely Automated Decision-Making

Neither of the above systems constitutes solely automated decision-making with legal or similarly significant effects under GDPR Article 22. The content filter is a pre-submission blocker that does not affect the User’s account status. The anti-cheat system only flags activity for human review – enforcement decisions are made by human moderators.

Legal basis: Contract performance (Art. 6(1)(b)) for both systems – they are necessary to provide the Service as described in our Terms of Service.


6. Location Data

6.1 Why We Need Location Data

Location data is fundamental to Paper Chase. The Service is designed around visiting real-world locations to collect digital Badges. Without location access, the core functionality of the Service cannot operate.

6.2 How Location Data Is Used

  • Real-time verification: Your GPS coordinates are compared to Badge locations to verify physical presence at the time of collection.
  • Proximity detection: Determining whether you are within the required distance of a Badge.
  • Map display: Showing your position relative to nearby Badges (processed locally on your device).

6.3 Location Data Precision

We use precise GPS coordinates (as provided by your device’s location services) for Badge collection verification. GPS accuracy varies by device, environment, and conditions.

6.4 Foreground Location Only

Location access is used exclusively while the app is in the foreground and you are actively using it. We do not request or use background location access.

6.5 Location Data Storage

  • Location data used for real-time Badge verification is processed at the time of collection.
  • Badge completion records include a timestamp but do not store the precise GPS coordinates of your verification.
  • We do not build location history profiles or track your movements over time.
  • We do not sell, rent, or share your location data with third parties for advertising or marketing purposes.

7. Data Sharing and Third Parties

We share your data only with the following categories of service providers, strictly for the purposes of operating and improving the Service:

7.1 Service Providers

Supabase (EU) – Authentication, data storage, file storage. Data shared: email, user data, avatars. Legal basis: Contract.

PostHog (EU Cloud) – Anonymous usage analytics. Data shared: anonymous event data (no PII). Legal basis: Consent.

Sentry (EU) – Crash reporting and debugging. Data shared: exception data, stack traces (no PII). Legal basis: Consent.

OneSignal (Global) – Delivering push notifications. Data shared: user ID, notification content. Legal basis: Consent.

Google OAuth (US) – Social login. Data shared: ID token, email, profile name. Legal basis: Contract.

Apple Sign In (US) – Social login. Data shared: ID token, email (optional), name. Legal basis: Contract.

Facebook OAuth (US) – Social login. Data shared: ID token, profile information. Legal basis: Contract.

Cloudflare Turnstile (Global) – Bot protection (CAPTCHA). Data shared: CAPTCHA verification token. Legal basis: Legitimate Interest.

Mapy.com (EU) – Map tile rendering. Data shared: IP address (tile requests). Legal basis: Legitimate Interest.

Mailjet (EU) – Transactional and marketing email delivery. Data shared: email address, notification content. Legal basis: Contract (transactional emails) / Consent (marketing emails).

Cloudflare Pages (Global/EU) – Web hosting for legal pages and account deletion page. Data shared: IP address (web requests). Legal basis: Legitimate Interest.

7.2 When We May Share Data

Beyond the service providers above, we may share your data:

  • Legal requirements: When required by law, regulation, legal process, or governmental request.
  • Protection of rights: To enforce our Terms of Service, protect the safety of Users, or protect the Operator’s rights and property.
  • Business transfers: In connection with a merger, acquisition, or sale of assets (you would be notified).
  • With your consent: When you explicitly authorize a specific sharing.

7.3 We Do Not Sell Your Data

We do not sell, rent, or trade your personal data to third parties for their own marketing or commercial purposes.


8. International Data Transfers

8.1 Primary Hosting

Our primary infrastructure (Supabase, PostHog) is hosted within the European Union, ensuring that the majority of your data remains within the EU/EEA.

8.2 Transfers Outside the EU/EEA

Some of our service providers (Google, Apple, Facebook, OneSignal, Cloudflare) are based in the United States or operate globally. When your data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs) adopted by the European Commission.
  • Adequacy decisions where applicable.
  • Provider-specific data protection agreements and certifications.

8.3 Your Right to Object

You have the right to object to international data transfers. However, please note that certain third-party authentication providers (Google, Apple, Facebook) necessarily involve data transfer to US-based servers. If you wish to avoid these transfers, you may register using email authentication instead.


9. Your Rights Under GDPR

As a data subject under GDPR/RODO, you have the following rights:

9.1 Right of Access (Art. 15)

You have the right to request a copy of the personal data we hold about you. You can access most of your data directly through your profile in the application.

9.2 Right to Rectification (Art. 16)

You have the right to correct inaccurate personal data. You can update your profile information directly in the application (username, display name, bio, avatar, gender, language, country).

9.3 Right to Erasure / “Right to Be Forgotten” (Art. 17)

You have the right to request deletion of your personal data. You can exercise this right by deleting your account through the application’s Settings → Account → Delete Account, or via our web deletion page. This performs a complete data erasure.

9.4 Right to Restriction of Processing (Art. 18)

You have the right to request that we restrict the processing of your personal data in certain circumstances (e.g., while we verify the accuracy of contested data).

9.5 Right to Data Portability (Art. 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transfer it to another controller. You can exercise this right directly in the application via Settings → Account → Export My Data. Your data export is provided as a JSON file, downloadable via a signed URL that remains available for 7 days. The export covers 14 data categories including profile, preferences, badges, games, achievements, saved items, points history, legal consents, following relationships, activities, comments, ratings, inventory, and path progress. Exports are rate-limited to one request per 24 hours.

Note: moderation records related to your account are accessible upon request under the Right of Access (Art. 15) but are not included in the portable data export under Art. 20, as they are not data you have provided.

9.6 Right to Object (Art. 21)

You have the right to object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.

Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing. See Section 3 for how to withdraw consent and Section 5 for information about automated processing.

9.8 Right to Lodge a Complaint (Art. 77)

You have the right to lodge a complaint with a supervisory authority. The competent authority in Poland is:

Urząd Ochrony Danych Osobowych (UODO) ul. Stawki 2, 00-193 Warszawa, Poland Website: https://uodo.gov.pl Email: kancelaria@uodo.gov.pl

9.9 Exercising Your Rights

To exercise any of the above rights (except those available directly in the app), contact us at contact@paperchase.app. We will respond to your request within 30 days in accordance with GDPR Article 12(3). We may request proof of identity before processing your request.


10. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.

10.1 Retention Periods

  • Account data (email, username, profile) – Duration of account + 30 days after deletion. Basis: Contract / Erasure completion.
  • Gameplay data (badges, games, achievements) – Duration of account. Basis: Contract.
  • Social data (comments, reactions, followers) – Duration of account. Basis: Contract.
  • Location data (GPS coordinates for verification) – Processed in real-time, not stored after verification. Basis: Minimization.
  • Legal consent records – 6 years after consent action. Basis: Polish statute of limitations (Art. 118 Kodeks Cywilny).
  • Analytics data (anonymous) – Up to 24 months. Basis: Consent / Legitimate Interest.
  • Crash reports – Up to 12 months. Basis: Consent.
  • Push notification tokens – Until consent withdrawn or account deleted. Basis: Consent.
  • Security logs (IP addresses, request logs) – Up to 12 months. Basis: Legitimate Interest / Legal Obligation.
  • Soft-deleted moderated content (comments, ratings removed for policy violations) – 12 months from removal, then permanently hard-deleted. Content is inaccessible to all Users during this period. Basis: Legitimate Interest (moderation audit, appeal resolution, legal claims defence).
  • Moderation action records – 6 years. Basis: Polish statute of limitations (Art. 118 Kodeks Cywilny), legal claims defence.

10.2 After Account Deletion

You may request account deletion at any time through the application (Settings → Account → Delete Account) or via our web deletion page. The process works as follows:

Immediate Deactivation. Upon submitting a deletion request, your account is immediately deactivated. Your profile, content, and activity become invisible to other Users.

30-Day Grace Period. Your data is retained for 30 days from the deletion request. During this period, you may cancel the deletion by logging back into your account, which restores your profile and data from a snapshot taken at the time of the request.

What is permanently deleted: Personal data (profile information, email, preferences), gameplay data (badge completions, game progress, achievements, points), and social connections (following/follower relationships, blocking/muting preferences).

What is anonymized: User Content you submitted (such as comments and ratings) is disassociated from your identity but retained to preserve the integrity of community content.

What is retained after deletion:

  • Legal consent records – 6 years after consent action. Basis: Polish statute of limitations (Art. 118 Kodeks Cywilny).
  • Moderation action records – 6 years. Basis: Polish statute of limitations, legal claims defence.
  • Soft-deleted moderated content – 12 months from removal, then hard-deleted. Basis: Legitimate Interest (moderation audit, appeals, legal claims defence).

Backup purge: Backup copies are purged within 30 days of deletion completion.

Email confirmations: You will receive email confirmations at each stage: upon requesting deletion, reminder notifications at 7 days and 3 days before completion, upon completion of deletion, and upon cancellation (if applicable).


11. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

11.1 Technical Measures

  • Encryption in transit: All data transmitted between the app and our servers uses HTTPS/TLS encryption.
  • Request signing: All mobile API requests are validated using HMAC signature verification to prevent tampering.
  • Certificate pinning: The mobile app employs SPKI certificate pinning (in beta and production environments) to prevent man-in-the-middle attacks.
  • Secure token storage: Authentication tokens are stored using platform-native secure storage (Keychain on iOS, Keystore on Android).
  • Rate limiting: API endpoints are protected by per-user and per-endpoint rate limiting to prevent abuse.
  • Access control: Role-based access control (RBAC) with JWT authentication.

11.2 Organizational Measures

  • Access to personal data is restricted to authorized personnel on a need-to-know basis.
  • Service providers are bound by data processing agreements.
  • Regular security reviews and updates.

11.3 Incident Response

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the supervisory authority (UODO) within 72 hours of becoming aware of the breach (GDPR Art. 33).
  • Notify affected Users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Art. 34).

12. Children’s Privacy

12.1 Age Requirements

Paper Chase is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13.

Users aged 13 to 15 may use the Service only with verifiable parental or legal guardian consent, in accordance with Polish GDPR implementation which sets the age of digital consent at 16 years.

Users aged 16 and above may use the Service independently.

12.2 Parental Rights

If you are a parent or guardian and believe your child under 13 has provided personal data to us, please contact us at contact@paperchase.app. We will take steps to delete such data promptly.

If your child is aged 13-15 and you wish to review, modify, or delete their data, or withdraw consent for their use of the Service, please contact us at the same address.


13. Cookies and Tracking Technologies

13.1 Mobile Application

Paper Chase is a mobile application and does not use browser cookies. However, we use the following technologies:

  • PostHog SDK – Anonymous usage analytics (no PII). Opt-in required during onboarding.
  • Sentry SDK – Crash reporting (no PII, release builds only). Opt-in required during onboarding.
  • OneSignal SDK – Push notification delivery. Opt-in required during onboarding.

13.2 No Advertising Trackers

We do not use advertising SDKs, advertising identifiers (IDFA/GAID), or any third-party advertising trackers. We do not serve ads within the application.

13.3 Web Pages

Our static web pages (legal documents, account deletion page) are hosted by Cloudflare Pages. These pages may use server-level cookies that are necessary for the hosting service to operate. These cookies are not used for tracking, analytics, or advertising purposes.

13.4 Managing Tracking Preferences

You can manage your tracking preferences at any time:

  • Analytics & Crash Reporting: Settings → Privacy within the application.
  • Push Notifications: Settings → Notifications within the application, or via your device’s system settings.

14. Changes to This Policy

14.1 Updates

We may update this Privacy Policy from time to time. Changes will be communicated through the application, and you will be asked to review and accept the updated policy.

14.2 Notice

We will provide reasonable advance notice of material changes (at least 14 days before the new policy takes effect), unless changes are required by law or regulation.

14.3 Version History

All versions of this policy are identified by a version number and effective date. The current version information is listed at the bottom of this document.


15. Contact and Complaints

15.1 Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data:

15.2 Supervisory Authority

If you are not satisfied with our response to your data protection concern, you have the right to lodge a complaint with:

Urząd Ochrony Danych Osobowych (UODO) ul. Stawki 2, 00-193 Warszawa, Poland Website: https://uodo.gov.pl Phone: +48 22 531 03 00 Email: kancelaria@uodo.gov.pl

15.3 EU Residents

If you reside in another EU/EEA member state, you may also lodge a complaint with your local data protection authority. A list of all EU data protection authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.


Document Version: 1.0.0 Last Updated: March 10, 2026 Language: English

This document is available in English and Polish. The English version is the global reference version. For Users residing in Poland, the Polish-language version (Polityka Prywatności), available at paperchase.app/pl/privacy-policy, shall prevail in case of discrepancies between language versions.