Privacy Policy for Stryked

Last Updated: August 2, 2026 (Policy version 2.13 — ban-appeal response wording; partner k-anonymity, leaderboard fields, auth/IAP clarity, no ad brokers, visit vs redeem)

Aligned with in-app privacy choices: required service processing (location, account security) vs optional behavioral analytics consent

Your Privacy Matters: Stryked ("we", "our", or "the app") is committed to protecting your privacy. This policy explains what data we collect, why we collect it, and how you can control your information. For how we use platform technology (location, maps, and interactions), see our Technology & Platform Use page. Your use of the App is also governed by our Terms of Service.

0. Who Is Responsible for Your Personal Data

The controller of your personal data is Stijn Thomaes, trading under the Stryked / getstryked.com brand.

We have not designated a Data Protection Officer. For all privacy and data-protection requests, use the contact details above (see also Section 10). You may lodge a complaint with your supervisory authority (in the Netherlands: the Autoriteit Persoonsgegevens).

1. Information We Collect

Where data comes from:

1.1 Location Data

Stryked is a location-based game. Precise location is required to discover trophies, validate that you physically visit locations, and help prevent location spoofing.

What location data we process:

When we process location data:

Why we process location data (legal bases — see also Section 11):

Your controls: Change or revoke Location / Background Location in iPhone Settings > Stryked > Location. Without location permission (Never), trophy discovery and visit validation will not work. Denying or revoking Background Location (Always) does not block the core game: only periodic background visit detection stops; discovery and validation still work while the App is open (While Using). We do not use background location for advertising or cross-app tracking.

1.2 Photos and Media

We collect photos you upload as part of the Snapventure feature.

Important — location and public Snapventures: We do not store your personal GPS coordinates or EXIF location metadata with Snapventures (images are re-encoded and location metadata is stripped before upload). However, each Snapventure is linked to the trophy you selected. Trophies have fixed locations that are already public game data. When a Snapventure is public, other signed-in users can see your photo together with that trophy and the upload time. Together, this can show that you were in the vicinity of that trophy location around that time. Multiple public Snapventures over time may allow others to reconstruct a pattern of places you have visited. To limit this, set individual Snapventures to private (visible only to you) or change your default in Profile > Account Management > Snapventure Privacy.

What we store with each Snapventure:

What we do not store: Your personal GPS coordinates, EXIF location tags, or a separate location history tied to Snapventures.

You control visibility per Snapventure and your default for new uploads: public (visible to all signed-in users in the Snapventure feed) or private (visible only to you). You can change either setting at any time after upload.

1.3 User Profile Data

1.3.1 Demographic Profile

When you activate free trophy categories, we ask you to complete a short demographic profile:

This information is stored in your user profile and linked to your account. We use it to unlock free trophy categories and for internal product understanding of our community in aggregate. We do not use it to power an automated trophy recommendation engine. Your individual demographic answers are not currently written into the partner analytics event pipeline; partners do not receive your individual answers.

Why we collect this: Required to unlock free trophy categories (contract performance). Separate optional partner visit/audio analytics (Section 1.5) run only with Behavioral Analysis consent — they do not currently include these demographic fields. We do not sell this data or use it for advertising.

Your choices: The form is required for free categories in production. Completing it does not enable Behavioral Analysis — that remains optional and off by default until you turn it on in Profile > Account Management > Privacy & Consent. You can update your demographic answers when editing your profile. Deleting your account removes this demographic data (see Section 5.5).

1.4 Purchase Information

1.5 Device and Usage Data

We collect device and usage information for security, performance, and analytics purposes:

Security Verification: We use Firebase App Check (Apple App Attest) to verify that requests come from legitimate, unmodified app installations. This helps prevent abuse and protects your data.

Note: Most device and usage data collection requires your consent for behavioral analytics. You can control this in Profile > Account Management > Privacy & Consent.

1.6 Crash and Error Data

When you opt in to Behavioral Analysis, we collect crash reports and error information via Firebase Crashlytics to improve app stability and fix bugs.

Why we collect this: To identify and fix bugs, improve app stability, and ensure a better user experience.

Legal basis: Consent (GDPR Article 6(1)(a)) via Behavioral Analysis. Crashlytics is off by default until you enable it in Profile > Account Management > Privacy & Consent. You can withdraw consent at any time.

Service Provider: Firebase Crashlytics (Google LLC). Data may be processed outside the EER under Firebase DPA and Standard Contractual Clauses.

1.7 Partner Rewards

When you participate in optional partner reward offers (vouchers, codes, or similar benefits at participating locations), we process:

What partners receive: Partners fulfil rewards themselves. When a partner scans your QR code, they receive only the information needed to verify redemption through our systems. We do not sell your profile or share your email with partners for marketing through the redemption flow unless you contact them separately.

Legal basis: Contract performance (Article 6(1)(b)) — processing necessary to operate the reward unlock and redemption feature you use. See also our Terms of Service (Section 8) for your contractual rights and limitations regarding partner fulfilment, expiry, and third-party liability.

1.8 Friends and Social Features

You can search for other players, send or accept friend invitations, and see friends on leaderboards.

Legal basis: Contract (Article 6(1)(b)).

1.9 Device Notifications

With your iOS permission, the App may show local notifications on your device (for example friend invites, nearby trophy / visit alerts, or partner-reward alerts). These are created on the device. Deny or limit them in iPhone Settings > Notifications > Stryked; core gameplay still works.

Legal basis: Contract (Article 6(1)(b)) for feature alerts you use.

2. How We Use Your Information

2.1 Core Game Functionality

2.2 Anti-Spoofing and Security

We use behavioral analysis and automated systems to maintain game integrity:

2.3 Service Improvement

Usage and Product Insight (only with Behavioral Analysis):

If you have enabled Behavioral Analysis, when you use the app—for example, when you activate a challenge or redeem a trophy—we may log these actions to Firebase Analytics for product and usage insight. We use a technical user ID to link events to a session. We do not store name, email, or phone number in these analytics events and do not use them for advertising. If Behavioral Analysis is off, these analytics events are not sent.

Automatically collected data (Firebase Analytics, only with Behavioral Analysis):

Note: Enable or withdraw Behavioral Analysis in Profile > Account Management > Privacy & Consent.

3. Data Storage and Security

3.1 Where We Store Your Data

Data Storage Location: Core app data (profiles, trophy progress, Snapventures, trust-score validation logs, and similar account data) is stored on servers in the European Union (Belgium, europe-west1 region) using Google Cloud Platform’s EU data centers for our Firebase services. Optional Behavioral Analysis data (Firebase Analytics and Crashlytics, only when you opt in) may be processed by Google outside the EU. Where such transfers occur, we rely on appropriate safeguards (for example Standard Contractual Clauses) as set out in Google Cloud / Firebase terms and privacy documentation — see Section 9.1.

3.2 How Long We Retain Your Data

3.3 Security Measures

4. Data Sharing and Disclosure

4.1 With Other Users

4.2 With Service Providers and Partners

4.3 Legal Requirements

We may disclose your information if required by law or to:

4.4 Business Transfers

If we are involved in a merger, acquisition, asset sale, reorganization, or similar transaction — or if our assets are transferred in connection with insolvency — personal data we hold may be disclosed or transferred to the counterparty as part of that transaction, subject to appropriate confidentiality and data-protection safeguards. We will continue to require that personal data remain protected in a manner consistent with this policy, and we will notify you of any material change of controller where required by law.

4.5 We Do NOT:

No advertising stack: Stryked does not integrate advertising networks, does not use Apple’s App Tracking Transparency (ATT) or the Identifier for Advertisers (IDFA), does not request ATT permission, and does not sell personal data to data brokers. We do not track you across apps or websites for advertising or profiling. Optional Behavioral Analysis (if enabled) is first-party product analytics inside our App only, as described in this policy.

5. Your Rights and Choices

5.1 Location Services

5.2 Account Management

5.3 Privacy Choices in the App

Your privacy choices are stored on your device (not per account). If someone else signs in on the same iPhone, they inherit the device's analytics preference until they change it in Profile > Account Management > Privacy & Consent. After switching accounts on a shared device, review Privacy & Consent so the preference matches the signed-in user.

Required for the game (information only — no withdrawable toggle while you use the app):

Optional (you can withdraw anytime):

5.4 GDPR Rights (EU Users)

If you are in the European Union, you have additional rights:

5.5 Account Deletion

You can delete your account at any time. We also schedule inactive-account deletion after 24 months of inactivity and two email warnings; live deletion follows Section 3.2 (including dry-run until enabled in production).

Delete your account yourself:

  1. Go to Profile > Account Management in the app
  2. Select "Delete Account"
  3. Confirm your decision

Upon deletion:

6. Automated Decision-Making

6.1 Anti-Spoofing System

The app uses automated systems to detect location spoofing and cheating. This system:

6.2 Your Right to Appeal Automated Decisions (GDPR Article 22)

Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing, including automated bans. You have the right to request human review of any automated decision that affects you.

If you believe you were incorrectly banned:

How to Submit an Appeal

  1. In-App Appeal: Use the built-in ban appeal flow in the app. When you see a ban notification, tap "Appeal Ban" to submit your appeal directly within the app.

What Happens After You Submit an Appeal

Your Rights

In addition to the appeal process, you have the right to:

Note: Automated bans are temporary (24 hours) and are designed to prevent cheating and maintain fair gameplay. Most bans are automatically lifted after the specified duration, but you can appeal at any time if you believe the ban was incorrect.

7. Children's Privacy

Stryked is not intended for anyone under the age of 16. In the European Economic Area (EEA), including the Netherlands, the minimum age is 16, in line with the GDPR age of digital consent for processing personal data (such as location data). We do not knowingly collect personal data from anyone under 16, including location data. If you are under 16, please do not use the app or create an account. If we become aware that we have collected data from someone under 16, we will delete it promptly. This aligns with our Terms of Service.

How we enforce this: We ask you to confirm you are at least 16 (self-declaration on device). We do not collect date of birth for this check. If we learn someone is under 16, we delete their personal data promptly.

8. Changes to This Policy

We may update this privacy policy from time to time. When we do:

9. Third-Party Services

Our app uses the following third-party services:

This website (legal pages): These hosted legal pages are static content. We do not place advertising or analytics cookies on these pages for cross-site tracking. Firebase Hosting may process standard server logs (e.g. IP address, user agent) needed to deliver the page and protect the service. Linked services (Apple, Google, Brevo, partners) have their own privacy notices when they act as independent controllers.

9.1 Firebase (Google LLC)

9.2 Apple Sign-In

9.3 Google Sign-In

9.4 Apple Maps (MapKit)

9.5 E-mail and password (Firebase Authentication)

9.6 Apple In-App Purchase / App Store

10. Contact Us

If you have questions, concerns, or requests regarding this privacy policy or your personal data (including exercising your GDPR rights—access, rectification, erasure, restriction, portability, objection, or withdrawal of consent), please contact the controller:

Response Time: We aim to acknowledge privacy e-mails within 48 hours. For GDPR rights requests we respond within one month of receipt (Article 12(3); we will tell you if we need up to two more months for complex cases).

Identity verification: For e-mail requests (not in-app export/delete while signed in), we may ask you to prove control of the account before we disclose or delete data.

Data Protection Officer: We have not designated a Data Protection Officer. For all privacy and data protection requests, please use the contact details above.

Data breach notification: In the event of a personal data breach, we will notify the competent supervisory authority within 72 hours of becoming aware of it (GDPR Article 33) and will inform affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34). For questions about our incident process, contact support@getstryked.com.

For EU Users – Complaints:

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (in the Netherlands: the Autoriteit Persoonsgegevens).

11. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal bases under GDPR:

Sensitive location data (not GDPR Article 9 special category data): Precise location is not a special category under GDPR Article 9. It is nonetheless sensitive in practice. We process it for core gameplay under contract (Article 6(1)(b)) — on-device for discovery and anti-spoofing, and as a visit coordinate check on our servers when you confirm a trophy visit — and, where applicable, legitimate interest for fraud prevention (Article 6(1)(f)). Optional analytics that use only approximate (city-level) location require separate Behavioral Analysis consent (Article 6(1)(a)).


© 2026 Stryked. All rights reserved.
This privacy policy is effective as of August 2, 2026 (version 2.12).