Adytum · legal
Privacy Policy
Privacy Policy
Counsel review required before publication. This policy is a structured starting point and must be reviewed by qualified privacy counsel against GDPR, CCPA/CPRA, the Australian Privacy Principles, and the App Store / Play Store data-disclosure requirements in their current form before it is relied upon.
Diegetic note. Adytum, like its parent product The Fold, normally speaks to participants in a specific in-world voice. This document deliberately does not. Privacy law requires plain English, and you are entitled to plain English. Nothing about your legal rights is hidden behind a tone, a metaphor, or a name. If anything in this policy is unclear, write to us at the address at the bottom and we will explain it in plainer English still.
Last updated: [DATE-LOCKED-AT-LAUNCH]
1. Who we are
Adytum ("we", "us", "our") operates the Adytum mobile application and associated services (the "Service"). Adytum is operated by [legal entity — to be inserted], registered in Australia. Our contact for privacy matters is [privacy email — to be inserted].
2. Who can use the Service
The Service is for adults aged 18 or older. We do not knowingly collect data from anyone under 18. At signup we ask your date of birth and refuse accounts where the calculated age is under 18. If we discover that an account holder is under 18, we will delete the account and all associated personal data within 30 days.
2.1 Children (COPPA)
The Service is not directed to children and is not intended for anyone under 13. We do not knowingly collect, use, or disclose personal information from children under 13. Independently of the under-13 prohibition, the Service requires all users to be 18 or older (see §2). If you believe a child under 13 has provided us personal information, contact us at [privacy email] and we will delete it.
3. What we collect
3.1 Data you give us at signup
- Phone number. Collected and verified through Twilio. Used only to send and check a one-time passcode (OTP) for login. We do not use your phone number for marketing.
- Email address. Used for account recovery and transactional email (account, security, and notifications you opted into). Not used for marketing.
- Date of birth (DOB). Used for the 18+ age gate. We store it to confirm eligibility; it is not used for marketing or profiling.
- A player-chosen name. This name is visible to other players in accordance with the game's "learn-by-confide" rules, which govern when and to whom your name is revealed during play. It may or may not be your real name — we do not check.
3.2 Data we collect as you use the Service
- In-app activity ("telemetry"). We log events describing what you do in the app: session start/stop, screen views, ritual completions, social interactions (e.g. someone joins your group), in-app purchases, and errors and crashes.
- Approximate device information. Device model, operating-system version, app version, locale.
- Push-notification token. A device-specific identifier issued by Apple Push Notification Service or Firebase Cloud Messaging (via Expo) so we can deliver notifications you have opted into — including omens, witching-hour events, and trial events.
3.3 Location
Certain features (proximity and territory mechanics) use your device location. We ask for your explicit consent the first time such a feature is used, and you can withdraw consent at any time in the app settings or your device settings.
- By default, location is collected at
areaprecision — coarse enough to support proximity and territory features without pinpointing you. - Finer (precise) location is collected only after you give a separate, explicit opt-in.
- We never share precise location with other players.
3.4 Device sensors and permissions
These permissions are requested only for the features described, and only when you use them:
- Bluetooth. Used for proximity detection between nearby players. We use Bluetooth to estimate closeness; we do not use it to build a contact graph or to track you when the relevant feature is not in use.
- Microphone. Used solely for the ggwave acoustic handshake during the Resonance ritual — a short data-over-sound exchange between devices that are physically together. We do not record, store, or transmit conversations or ambient audio. The microphone is used only to decode the acoustic handshake tones in the moment.
- Camera. Used solely for a QR-code handshake when the Resonance (acoustic) handshake is unavailable. We do not store photographs and we do not access your camera roll or photo library.
3.5 Sigil generation (AI)
When you generate a sigil, we send a prompt to Google Gemini. That prompt contains anonymised player state only — your level, your path, your war count, and your loyalty value. It contains no personally identifying information: no name, phone number, email, date of birth, or location.
3.6 Error reporting
We use Sentry to capture crashes and errors. Sentry receives stack traces and technical diagnostic data so we can fix bugs. It does not receive your user content (e.g. messages, names you have given other players, or location data).
3.7 What we do NOT collect
- We do not record your conversations or ambient audio (the microphone is used only for the acoustic handshake described in §3.4).
- We do not access your contacts.
- We do not access your camera roll or photo library.
- We do not collect biometric data.
- We do not buy data about you from third parties.
- We do not use any of the data above for advertising or marketing targeting.
4. How we use what we collect
- To operate the Service and deliver features you request (login, proximity, territory, rituals, sigils).
- To keep your account secure (OTP authentication, fraud prevention).
- To send transactional messages and the push notifications you opted into (omens, witching-hour events, trial events).
- To improve the Service (analyse telemetry in aggregate and fix errors).
- To comply with legal obligations.
We do not sell your personal data. We do not use your personal data for advertising targeting on or off the Service.
5. Third parties who process data on our behalf ("sub-processors")
We use the following providers under data-processing agreements. Each receives only the data necessary for its function.
| Provider | Purpose | Data shared | | ----------------- | -------------------------------------- | ---------------------------------------------------------------------------- | | Supabase | Database, authentication, file storage | Account data, telemetry, location (at the precision in §3.3) | | Vercel | Web/API hosting | Request logs, IP addresses, request bodies as part of normal HTTP processing | | Resend | Transactional email | Email address, message content | | Twilio | OTP login (SMS) | Phone number, the one-time passcode message | | Google Gemini | Sigil generation | Anonymised player state only (level, path, war count, loyalty) — no PII | | Sentry | Error and crash reporting | Stack traces and technical diagnostics — not user content | | Expo / APNs / FCM | Push-notification delivery | Push token, notification payload |
If we add or change a sub-processor we will update this list and, where required, notify you.
6. International transfers
Some providers above are based outside Australia (notably in the United States and the European Union). We rely on the standard contractual clauses, equivalent transfer mechanisms, and the providers' own certifications (e.g. EU–US Data Privacy Framework) to ensure adequate protection.
7. Data retention
We keep personal data only as long as we need it for the purposes set out in this policy.
- While your account is active: we retain your account data (phone number, email, DOB, chosen name) for as long as your account exists, because this data is what makes the Service work.
- Telemetry: retained in identifiable form for up to 12 months, after which it is aggregated or deleted.
- Location data: retained only as long as needed to provide the relevant proximity or territory feature, and then deleted or de-identified.
- Sigil prompts: the anonymised state we send for sigil generation contains no PII (see §3.5) and is not retained in a form that identifies you.
- Error reports: stack traces in Sentry are retained according to our Sentry configuration and then purged; they contain no user content.
- After you request deletion: we delete personal data within 30 days (see §8.1), except where law requires us to retain a record (e.g. accounting records for tax purposes), in which case we retain only the minimum required and only for the minimum required period.
- Backups: deleted data persists in encrypted backups for up to 90 days and is then overwritten.
8. Your rights
You have rights over your personal data. The specific rights depend on where you live; we honour the most generous applicable set.
- All users: the right to access your data, correct inaccuracies, and request deletion.
- EU / UK (GDPR): in addition, the rights to restrict processing, port your data to another provider, object to processing, and lodge a complaint with your local supervisory authority.
- California (CCPA / CPRA): in addition, the right to know what categories of personal information we collect and the right to opt out of sale (we do not sell — but the right exists).
- Australia (Australian Privacy Principles): in addition, the rights set out in APP 12 (access) and APP 13 (correction), and the right to complain to the Office of the Australian Information Commissioner (OAIC).
To exercise any right, write to [privacy email]. We respond within 30 days.
8.1 Right to erasure (GDPR "right to be forgotten") and account deletion
You may request deletion of your account and personal data at any time, in-app or by writing to [privacy email]. On a valid request we delete your personal data within 30 days, subject to the legal-retention and backup exceptions in §7.
Because some data must be removed across multiple systems (database, authentication, file storage, sub-processors, and backups), we operate a documented verification procedure to confirm that erasure is complete. That procedure — including what is deleted, where, and how completion is confirmed — is set out in LEGAL/GDPR-DELETE-VERIFICATION.md.
9. Security
We use industry-standard measures: encryption in transit (TLS), encryption at rest for the database, role-based access controls, secret rotation, and audit logs. No system is perfectly secure; if a breach affecting your data occurs, we will notify you and the relevant regulator in accordance with the timelines required by law.
10. Changes to this policy
We may update this policy. If we make a material change, we will notify you in-app and by email at least 30 days before the change takes effect.
11. Contact
Privacy questions: [privacy email] Postal address: [legal entity address]