Privacy Policy for Stryked
Last Updated: August 2, 2026 (Policy version 2.13 — ban-appeal response wording; partner k-anonymity, leaderboard fields, auth/IAP clarity, no ad brokers, visit vs redeem)
Aligned with in-app privacy choices: required service processing (location, account security) vs optional behavioral analytics consent
Your Privacy Matters: Stryked ("we", "our", or "the app") is committed to protecting your privacy. This policy explains what data we collect, why we collect it, and how you can control your information. For how we use platform technology (location, maps, and interactions), see our Technology & Platform Use page. Your use of the App is also governed by our Terms of Service.
0. Who Is Responsible for Your Personal Data
The controller of your personal data is Stijn Thomaes, trading under the Stryked / getstryked.com brand.
- Privacy and support email: support@getstryked.com
- In-App: Profile > About > Contact Support
- Trade register (KvK), VAT (BTW), and registered address: Will be published here before commercial launch in the EU
We have not designated a Data Protection Officer. For all privacy and data-protection requests, use the contact details above (see also Section 10). You may lodge a complaint with your supervisory authority (in the Netherlands: the Autoriteit Persoonsgegevens).
1. Information We Collect
Where data comes from:
- You: Profile fields, Snapventures, demographic answers, friend actions, privacy choices, support messages
- Your device / OS: Location and motion signals (Section 1.1), device integrity signals, local notification permission state
- Third parties you choose / account sign-in: Apple or Google when you Sign in (e-mail/name/tokens as they provide); or e-mail and password via Firebase Authentication; Apple for purchase/subscription status
- We generate: Trust scores, validation outcomes, aggregated partner statistics
1.1 Location Data
Stryked is a location-based game. Precise location is required to discover trophies, validate that you physically visit locations, and help prevent location spoofing.
What location data we process:
- Coordinates and related signals provided by Apple Core Location (which may use GPS and, as determined by the operating system, other positioning technologies such as Wi-Fi or cellular), including latitude, longitude, altitude, accuracy, speed, course, and timestamps
- Device motion data (accelerometer, gyroscope, magnetometer) for anti-spoofing
- Derived validation outcomes (for example trust-score logs and visit confirmations). Continuous GPS streams stay on your device for anti-spoofing. When you confirm a trophy visit, the App sends that single visit coordinate pair to our servers to check you are inside the trophy’s visit radius; we do not store those coordinates as a location history (see Section 3.2)
When we process location data:
- While the App is in use (foreground)
- If you grant Background Location permission in iOS: the App may receive location updates while it is not on screen (how often is determined by iOS / Core Location, not a fixed interval), to detect nearby trophies and support visit validation
- When you are near a trophy location (the relevant distance depends on the trophy and feature)
- When you visit a trophy: your device must be inside that trophy’s configured visit radius (which depends on the trophy type, often from about 100 m up to several kilometres) and meet GPS accuracy checks (first visits typically require accuracy of about 50 meters or better)
Why we process location data (legal bases — see also Section 11):
- Core gameplay (contract / Article 6(1)(b)): Detect nearby trophies and validate physical visits while the App is in use (While Using / foreground). Background Location (Always) is never required to perform the core contract: denying or revoking Always only stops periodic background visit detection; core gameplay continues with While Using. If you enable Background Location, those updates are part of providing that optional visit-detection feature under the same contract basis — not marketing consent
- Anti-fraud (legitimate interest / Article 6(1)(f), and where applicable Article 6(1)(b)): Prevent location spoofing and maintain fair gameplay
- Analytics (optional consent / Article 6(1)(a)): Approximate (city-level) location via Firebase Analytics only if you grant Behavioral Analysis consent — not precise GPS
Your controls: Change or revoke Location / Background Location in iPhone Settings > Stryked > Location. Without location permission (Never), trophy discovery and visit validation will not work. Denying or revoking Background Location (Always) does not block the core game: only periodic background visit detection stops; discovery and validation still work while the App is open (While Using). We do not use background location for advertising or cross-app tracking.
1.2 Photos and Media
We collect photos you upload as part of the Snapventure feature.
- Photos you capture or select for Snapventures
- We do not intentionally collect embedded photo metadata (EXIF). Images are processed and re-encoded during upload.
- Photo thumbnails for display purposes
Important — location and public Snapventures: We do not store your personal GPS coordinates or EXIF location metadata with Snapventures (images are re-encoded and location metadata is stripped before upload). However, each Snapventure is linked to the trophy you selected. Trophies have fixed locations that are already public game data. When a Snapventure is public, other signed-in users can see your photo together with that trophy and the upload time. Together, this can show that you were in the vicinity of that trophy location around that time. Multiple public Snapventures over time may allow others to reconstruct a pattern of places you have visited. To limit this, set individual Snapventures to private (visible only to you) or change your default in Profile > Account Management > Snapventure Privacy.
What we store with each Snapventure:
- Your photo (full image and thumbnail)
- The trophy you linked it to (trophy ID — the trophy's location is public game data)
- Upload timestamp
- Optional caption
- Visibility setting (public or private; default is public unless you change it)
What we do not store: Your personal GPS coordinates, EXIF location tags, or a separate location history tied to Snapventures.
You control visibility per Snapventure and your default for new uploads: public (visible to all signed-in users in the Snapventure feed) or private (visible only to you). You can change either setting at any time after upload.
1.3 User Profile Data
- User ID (automatically generated by Firebase)
- Username and display name you choose
- Email address (when provided during sign-in)
- Country / country of origin (optional profile field, when you provide it)
- Profile picture (optional)
- Game statistics (points, trophies visited, achievements)
1.3.1 Demographic Profile
When you activate free trophy categories, we ask you to complete a short demographic profile:
- Age range (e.g. 18–24, 25–34)
- Gender (self-reported options you select in the app)
- Family situation (e.g. lives alone, with partner, with family/roommates)
This information is stored in your user profile and linked to your account. We use it to unlock free trophy categories and for internal product understanding of our community in aggregate. We do not use it to power an automated trophy recommendation engine. Your individual demographic answers are not currently written into the partner analytics event pipeline; partners do not receive your individual answers.
Why we collect this: Required to unlock free trophy categories (contract performance). Separate optional partner visit/audio analytics (Section 1.5) run only with Behavioral Analysis consent — they do not currently include these demographic fields. We do not sell this data or use it for advertising.
Your choices: The form is required for free categories in production. Completing it does not enable Behavioral Analysis — that remains optional and off by default until you turn it on in Profile > Account Management > Privacy & Consent. You can update your demographic answers when editing your profile. Deleting your account removes this demographic data (see Section 5.5).
1.4 Purchase Information
- In-app purchase history (subscription status, unlocked tiers)
- Purchase dates and renewal status
- Payment information is processed by Apple and is not accessible to us. We only process purchase-related data (product ID, subscription status, dates) to provide the service; we never receive or store payment card or other payment details. Apple retains App Store purchase records under Apple’s policies. Our own purchase documents in Firebase are deleted when you delete your account (see Section 3.2 and Section 5.5).
1.5 Device and Usage Data
We collect device and usage information for security, performance, and analytics purposes:
- Biometric authentication: The App Store build does not use Face ID or Touch ID for our own sign-in. Any biometric prompt you see when using Sign in with Apple or Sign in with Google is handled by the operating system or that provider; we receive only authentication tokens, never biometric templates. We do not store biometric data on our servers.
- Device information: Device type, model, iOS version, screen resolution (automatically collected by Firebase Analytics when behavioral analytics consent is granted)
- App information: App version and build number (automatically collected by Firebase Analytics)
- Security data: Device integrity status (to detect jailbroken devices for security), device attestation tokens (via Apple App Attest) for security verification
- Usage patterns: App usage patterns and interaction data (only when behavioral analytics consent is granted; logged for product insight, aggregated for reporting)
- Partner visit and audio analytics: We do not store visit-confirm durations on your user profile. If you grant Behavioral Analysis consent and you interact with a partner trophy, we may write short-lived raw partner analytics events (exact visit-confirm seconds and/or audio-listen seconds, a pseudonymous subject hash derived from partner name + user ID — not your raw user ID in the event document, and a timestamp). Those raw events are retained for about 32 days, then deleted. Partners only see aggregated counts — for visit speed, broad time buckets per partner/trophy/day (for example 0–3 minutes, 3–8 minutes, 8–15 minutes, 15–30 minutes, 30+ minutes), without your user ID or exact timestamps. Aggregated daily partner stats are retained about 36 months (see Section 3.2)
- Approximate location: City-level geolocation (automatically collected by Firebase Analytics, not precise GPS coordinates)
- IP address: May be processed by Firebase (e.g., for security, fraud prevention, and city-level geolocation). We do not use IP addresses for tracking, profiling, or advertising.
Security Verification: We use Firebase App Check (Apple App Attest) to verify that requests come from legitimate, unmodified app installations. This helps prevent abuse and protects your data.
Note: Most device and usage data collection requires your consent for behavioral analytics. You can control this in Profile > Account Management > Privacy & Consent.
1.6 Crash and Error Data
When you opt in to Behavioral Analysis, we collect crash reports and error information via Firebase Crashlytics to improve app stability and fix bugs.
- Crash reports and stack traces when the app encounters errors
- Device information associated with crashes (model, OS version)
- Custom context data to help diagnose issues
- Error logs and diagnostic information
Why we collect this: To identify and fix bugs, improve app stability, and ensure a better user experience.
Legal basis: Consent (GDPR Article 6(1)(a)) via Behavioral Analysis. Crashlytics is off by default until you enable it in Profile > Account Management > Privacy & Consent. You can withdraw consent at any time.
Service Provider: Firebase Crashlytics (Google LLC). Data may be processed outside the EER under Firebase DPA and Standard Contractual Clauses.
1.7 Partner Rewards
When you participate in optional partner reward offers (vouchers, codes, or similar benefits at participating locations), we process:
- Offer metadata: Gift title, description, partner name, unlock rules, and whether an offer is active (stored in our database; basic offer listings may be visible before sign-in)
- Unlock and redemption status: Whether you have unlocked or redeemed a specific offer, timestamps, and your user ID in server-side records used to prevent duplicate redemption and fraud
- QR redemption payloads: Short-lived, cryptographically signed codes generated when you choose to redeem; validated when scanned by an authorised partner
- Gameplay linkage: We use your existing trophy visit history (already stored for core gameplay) to determine eligibility. We do not collect additional precise GPS coordinates solely for Partner Rewards beyond what is already processed for trophy validation
What partners receive: Partners fulfil rewards themselves. When a partner scans your QR code, they receive only the information needed to verify redemption through our systems. We do not sell your profile or share your email with partners for marketing through the redemption flow unless you contact them separately.
Legal basis: Contract performance (Article 6(1)(b)) — processing necessary to operate the reward unlock and redemption feature you use. See also our Terms of Service (Section 8) for your contractual rights and limitations regarding partner fulfilment, expiry, and third-party liability.
1.8 Friends and Social Features
You can search for other players, send or accept friend invitations, and see friends on leaderboards.
- What we store: Friendship records (user IDs, invitation status, timestamps). Invite metadata may include the other user’s public display name, points, and country code as shown at invite time
- What others see: Your public display name, profile picture if shown, public stats (e.g. points), and friend status. Not your e-mail or precise GPS via friends
- Hide Identity: In Profile > Account Management > Edit Public Profile you can show a public alias instead of your sign-in name (and optionally still show your avatar). Details in Section 4.1
Legal basis: Contract (Article 6(1)(b)).
1.9 Device Notifications
With your iOS permission, the App may show local notifications on your device (for example friend invites, nearby trophy / visit alerts, or partner-reward alerts). These are created on the device. Deny or limit them in iPhone Settings > Notifications > Stryked; core gameplay still works.
Legal basis: Contract (Article 6(1)(b)) for feature alerts you use.
2. How We Use Your Information
2.1 Core Game Functionality
- Detect nearby trophies based on your location
- Validate trophy visits to award points and achievements
- Display your progress and statistics
- Enable Snapventure social features
- Enable friends, search, and related social features (see Section 1.8)
- Determine eligibility for and validate redemption of optional Partner Rewards (see Section 1.7)
2.2 Anti-Spoofing and Security
We use behavioral analysis and automated systems to maintain game integrity:
- Movement Pattern Analysis: We analyze your movement patterns, travel speed, and on-device location samples (recent GPS and related signals on your device—not a server-side personal GPS history) to detect location spoofing and ensure fair gameplay for all users. This includes analyzing GPS coordinates, speed, direction, and device motion sensor data (accelerometer, gyroscope, magnetometer). In some cases we also compare the distance and time between your last trophies using static trophy locations and visit timestamps (not your personal GPS history) to detect clearly impossible “teleport” movements.
- Device Integrity Verification: We verify device integrity to detect jailbroken or rooted devices and prevent cheating. This includes checking device attestation tokens via Apple App Attest / Firebase App Check. Where technically used, we may also process signals indicating modified clients, emulators, or software that interferes with location or sensor data. We do not use these signals for advertising.
- Automated Security Measures: Our system may automatically apply temporary bans (24 hours) when suspicious activity is detected. These automated decisions are based on analysis of movement patterns, trust scores, and violation history.
- Trust Score Calculation: While you play, the App maintains an in-session trust score on your device based on validation results from location checks. Related validation outcomes may also be written to short-lived server logs (~49-hour TTL; see Section 3.2). This is not a permanent score field stored on your user profile.
- Grey-market and Terms enforcement: Account, visit, and device-integrity signals may also be used to detect and enforce against prohibited grey-market activity (such as selling or transferring accounts or progress), as described in our Terms of Service (Sections 3.4 and 9).
- Fair Gameplay: All security measures are designed to maintain fair gameplay and prevent cheating that would negatively impact other users' experience. Details of automated restrictions and your right to human review are in Section 6.
2.3 Service Improvement
- Analyze usage patterns to improve app features
- Optimize performance and fix bugs
- Develop new features based on user behavior
Usage and Product Insight (only with Behavioral Analysis):
If you have enabled Behavioral Analysis, when you use the app—for example, when you activate a challenge or redeem a trophy—we may log these actions to Firebase Analytics for product and usage insight. We use a technical user ID to link events to a session. We do not store name, email, or phone number in these analytics events and do not use them for advertising. If Behavioral Analysis is off, these analytics events are not sent.
Automatically collected data (Firebase Analytics, only with Behavioral Analysis):
- Device information (device type, model, iOS version)
- App version and build number
- Approximate geolocation (city-level, not precise GPS coordinates)
- Screen resolution and device capabilities
Note: Enable or withdraw Behavioral Analysis in Profile > Account Management > Privacy & Consent.
3. Data Storage and Security
3.1 Where We Store Your Data
- Firebase/Google Cloud: User profiles, trophy visit history, trust score validation logs, photos, and game data
- On Your Device: Temporary location data for gameplay, app preferences, and cached content. For account-security checks we may also store your last sign-in approximate coordinates (and related timestamp) in the device Keychain, to help detect unusual sign-in location changes. This is not a GPS visit history and is not the same as trophy-visit coordinate checks (Section 1.1)
- Apple Servers: Purchase and subscription information (managed by Apple)
Data Storage Location: Core app data (profiles, trophy progress, Snapventures, trust-score validation logs, and similar account data) is stored on servers in the European Union (Belgium, europe-west1 region) using Google Cloud Platform’s EU data centers for our Firebase services. Optional Behavioral Analysis data (Firebase Analytics and Crashlytics, only when you opt in) may be processed by Google outside the EU. Where such transfers occur, we rely on appropriate safeguards (for example Standard Contractual Clauses) as set out in Google Cloud / Firebase terms and privacy documentation — see Section 9.1.
3.2 How Long We Retain Your Data
- Location data: Continuous GPS and motion checks run on your device for trophy detection and anti-spoofing. When you confirm a visit, the App transmits that visit’s latitude and longitude to our Cloud Functions so we can verify you are inside the trophy’s visit radius; those coordinates are used for the check and are not written to your profile as a GPS history (we store visit timestamps and related outcomes only). We also store validation outcomes (e.g., trust score logs with 49-hour TTL) and, for teleport detection, derived metrics based on static trophy locations and visit timestamps. Snapventures do not store your personal GPS (see Section 1.2). When you later redeem a trophy, the App sends account and trophy identifiers (and related game outcomes) to our servers — not a new GPS coordinate pair. Precise location is used for visit confirmation, not for the redemption write itself.
- Trust score and teleport validation logs: Retained for about 49 hours (TTL), then automatically deleted. These logs contain validation results and ban decisions (not raw GPS coordinates) for anti-spoofing purposes. They are not actively purged as part of the account-deletion cascade; any remaining documents expire via that TTL
- Trophy visit history: Retained for the lifetime of your account
- User profile: Until you delete your account
- Snapventure photos: Until you delete them or your account. You can also hide individual snapventures at any time, which will make them private and invisible to other users, but they will remain stored until you delete them or your account.
- Purchase history: Our Firebase purchase documents (product/subscription status we store) are deleted when you delete your account. Apple retains App Store purchase and subscription records under Apple’s own policies; we do not keep a separate multi-year tax archive of those Apple records
- Partner reward records: Unlock and redemption records (including user ID, partner name, gift ID, and timestamps) are retained while your account is active and as needed for fraud prevention, partner reporting, and dispute resolution. They are deleted when you delete your account, except where retention is required by law. With Behavioral Analysis consent, raw partner analytics events are retained about 32 days; aggregated daily partner stats (visit / visit-speed / audio-listen) about 36 months, then deleted by our retention jobs
- Analytics data: Event data retained for 2 months in Google Analytics 4 (when you have opted in to Behavioral Analysis). Older events are automatically deleted.
- Crash reports: Retained for 90 days, then automatically deleted
- Device information: Retained while your account is active, deleted upon account deletion
- Backups: After your account and data are deleted, backup copies held by our service providers (e.g. Google/Firebase) are purged within 30 days, in line with our agreements with them.
- Inactive accounts: If you do not sign in or otherwise use your account for 24 months, we will send two email reminders (at approximately 22 and 23 months of inactivity) to the address linked to your account. If you do not sign in after those reminders, our scheduled retention job is configured to permanently delete your account and associated personal data (profile, trophy progress, Snapventures, friendships, and similar account-linked data). Until we enable live deletion in production, that job may run in dry-run mode (warnings can still be prepared/sent; accounts are not deleted yet). Signing in before deletion keeps your account. You can also delete your account yourself at any time (Section 5.5). Apple may still hold App Store purchase records separately as described under Purchase history above.
- Ban records:
- Temporary bans: 24 hours after ban expires
- Permanent bans: Kept while needed for security and abuse prevention for that account. Ban records for a user are removed when the account is deleted (including inactive-account deletion), except where we must keep limited records to meet a legal obligation
- Appeal status (in-app): Stored with your ban record and removed when the underlying ban record is deleted (temporary bans) or when the ban record is removed as part of account deletion.
- Appeal communications (email): We may retain appeal emails and related support communications as needed to respond to your request and for compliance/security record-keeping.
- Support and report messages: Kept as needed to handle your request, meet legal duties, and defend claims; then deleted or anonymised when no longer needed
3.3 Security Measures
- Data encryption in transit (HTTPS/TLS)
- Encryption at rest as provided by Google Cloud / Firebase for hosted data
- Firebase authentication and security rules
- Regular security audits
- Access controls and monitoring
4. Data Sharing and Disclosure
4.1 With Other Users
- Your public display name, profile picture (if shown), and public statistics are visible to other users. With Hide Identity on (Profile > Account Management > Edit Public Profile), others see your public alias instead of your sign-in name; your account name stays stored for the account but is not shown as the public name. Avatar while aliased only if you allow it. Change or turn off anytime
- Friends: Friends and invitees see the limited public fields above (respecting Hide Identity)
- Snapventure photos and captions you choose to make public are visible to all signed-in users, together with the linked trophy (and thus its location) and upload time — see Section 1.2 for how this can reveal where you were. Private Snapventures are visible only to you. You can change visibility per post or set a default in Profile > Account Management > Snapventure Privacy.
- Leaderboards: Other signed-in users may see a limited public profile: your public display name (or alias if Hide Identity is on), points, country/city completion counts, country of origin (if set), and optional avatar. Leaderboards do not expose your full trophy visit list or any personal GPS history. Combined with publicly known trophy locations, rankings may still allow others to infer that you play in certain regions
- We do not publish a live map of your real-time GPS position to other users. Public Snapventures remain the primary way your presence near a trophy at a given time can become visible to others (see Section 1.2)
- Reporting content: You can report Snapventures or other user content you believe is illegal, inappropriate, or infringes rights via the in-app report option or by emailing support@getstryked.com. See our Terms of Service (Section 6.4) for how we handle reports under the EU Digital Services Act.
4.2 With Service Providers and Partners
- Firebase / Google Cloud: Authentication, Firestore, Storage, Hosting, Cloud Functions, App Check, Remote Config (feature flags), and optional Analytics/Crashlytics if you opt in
- Brevo: Sends transactional e-mails we initiate (e.g. inactive-account warnings). Processor on our instructions —
Brevo privacy policy
- Apple: In-app purchases, App Store, Sign in with Apple, MapKit
- Google: Sign in with Google (if you choose it)
- Participating partners (Partner Rewards): When you redeem an offer, the partner receives only the verification data needed to honour the reward through our redemption systems. Partners do not receive ongoing access to your full profile, e-mail, or personal GPS history through this feature
- City / venue partners (dashboard insights): Where we provide a partner dashboard, partners see only aggregated statistics (e.g. visit counts, broad time buckets, engagement ratios). We apply privacy safeguards such as k-anonymity / small-bucket suppression (groups that are too small are not shown). Partners do not receive individual player marketing lists through this dashboard. Optional visit/audio analytics that feed those aggregates require Behavioral Analysis consent (Sections 1.5 and 11)
4.3 Legal Requirements
We may disclose your information if required by law or to:
- Comply with legal processes or government requests
- Enforce our Terms of Service (including anti-cheat and grey-market rules)
- Protect the rights, property, or safety of our users or others
- Prevent fraud or security issues
4.4 Business Transfers
If we are involved in a merger, acquisition, asset sale, reorganization, or similar transaction — or if our assets are transferred in connection with insolvency — personal data we hold may be disclosed or transferred to the counterparty as part of that transaction, subject to appropriate confidentiality and data-protection safeguards. We will continue to require that personal data remain protected in a manner consistent with this policy, and we will notify you of any material change of controller where required by law.
4.5 We Do NOT:
- Sell your personal data to third parties
- Share your data for advertising purposes
- Use advertising networks or ad SDKs, or sell/share personal data with data brokers
- Monetise the App through third-party behavioural advertising
- Use your data for cross-app tracking
- Use App Tracking Transparency (ATT) — we do not track you across apps or websites for advertising or other purposes
No advertising stack: Stryked does not integrate advertising networks, does not use Apple’s App Tracking Transparency (ATT) or the Identifier for Advertisers (IDFA), does not request ATT permission, and does not sell personal data to data brokers. We do not track you across apps or websites for advertising or profiling. Optional Behavioral Analysis (if enabled) is first-party product analytics inside our App only, as described in this policy.
5. Your Rights and Choices
5.1 Location Services
- Disable or limit location: Go to iPhone Settings > Stryked > Location (choose Never, While Using, or Always / Background as offered by iOS)
- Note: Choosing Never for location prevents trophy discovery and visit validation. Choosing While Using (without Always) keeps the core game playable; only background visit detection is unavailable. See Section 1.1
5.2 Account Management
- Update profile / Hide Identity: Edit your public profile, alias, and avatar in Profile > Account Management > Edit Public Profile (see Section 4.1)
- Control Snapventure visibility: Make individual Snapventures public or private at any time; set your default for new uploads under Account Management > Snapventure Privacy
- Understand location inference: Public Snapventures are linked to trophy locations — see Section 1.2 before choosing public visibility
- Delete or hide Snapventures: Remove your uploaded photos anytime, or hide a snapventure without deleting it
- Manage subscriptions: Go to iPhone Settings > Your Name > Subscriptions
5.3 Privacy Choices in the App
Your privacy choices are stored on your device (not per account). If someone else signs in on the same iPhone, they inherit the device's analytics preference until they change it in Profile > Account Management > Privacy & Consent. After switching accounts on a shared device, review Privacy & Consent so the preference matches the signed-in user.
Required for the game (information only — no withdrawable toggle while you use the app):
- Location: On-device processing to detect trophies and validate visits (contract / legitimate interest)
- Account Security & Fair Play: Automated anti-cheat may temporarily restrict accounts; you can appeal for human review (normally within 24 hours) (contract / fraud prevention, GDPR Article 22(2)(a))
Optional (you can withdraw anytime):
- Behavioral Analysis: Firebase Analytics and Crashlytics for usage insights and crash reports, plus partner visit/audio analytics (consent, Article 6(1)(a)). Off by default at first launch; enable or withdraw anytime in Privacy & Consent (not granted by completing the demographic form — Section 1.3.1)
5.4 GDPR Rights (EU Users)
If you are in the European Union, you have additional rights:
- Right to Access: Request a copy of your personal data. You can export a machine-readable file of available account data through the app in Profile > Account Management > Export Your Data, or contact us directly for assistance with anything the export does not include.
- Right to Rectification: Correct inaccurate personal data. You can update your profile information directly in the app (Profile > Account Management > Edit Public Profile) or contact us for assistance.
- Right to Erasure: Request deletion of your account and data. You can delete your account directly in the app (Profile > Account Management > Delete Account) or contact us for assistance.
- Right to Data Portability: Receive available account data in a machine-readable format (JSON). Use Profile > Account Management > Export Your Data, or contact us if you need help obtaining data not included in that export.
- Right to Object (Article 21): Appeal automated bans in-app (Section 6.2). To object to processing based on legitimate interests (Article 6(1)(f) — e.g. certain anti-fraud processing in Section 11), e-mail
support@getstryked.com with subject “Objection – legitimate interest”. We will assess and respond as required by law. Optional partner analytics are controlled by withdrawing Behavioral Analysis consent (Section 5.3), not by this objection route
- Right to Withdraw Consent: You may withdraw Behavioral Analysis consent at any time in Profile > Account Management > Privacy & Consent. Location and account security are required to play and are not controlled by a consent toggle.
- Right to Restrict Processing (GDPR Article 18): You may ask us to restrict how we use your data (e.g. only store it and not use it) in certain cases—for example when you contest the accuracy of the data, when the processing is unlawful but you prefer restriction over erasure, or when you have objected and we are assessing whether our grounds override yours. Contact us using the details in Section 10; we will respond within one month and, where applicable, restrict processing as required by law.
- Right to Lodge a Complaint: If you are not satisfied with how we handle your data, you have the right to lodge a complaint with your local data protection authority.
5.5 Account Deletion
You can delete your account at any time. We also schedule inactive-account deletion after 24 months of inactivity and two email warnings; live deletion follows Section 3.2 (including dry-run until enabled in production).
Delete your account yourself:
- Go to Profile > Account Management in the app
- Select "Delete Account"
- Confirm your decision
Upon deletion:
- Your profile, trophy visit history, uploaded photos, and partner reward unlock/redemption records will be permanently deleted
- Trust score validation logs are not cascade-deleted with the account; any remaining logs expire automatically after about 49 hours (Section 3.2)
- Our Firebase purchase documents for your account are deleted; Apple may retain App Store records under Apple’s policies
- Your username will become available for others to use
- This action cannot be undone
6. Automated Decision-Making
6.1 Anti-Spoofing System
The app uses automated systems to detect location spoofing and cheating. This system:
- Movement Pattern Analysis: Analyzes your movement patterns, travel speed, acceleration, and on-device location samples (not a server-side personal GPS history) to identify impossible or suspicious travel patterns (e.g., teleporting between distant locations, traveling at impossible speeds).
- Device Sensor Data: Uses device motion sensors (accelerometer, gyroscope, magnetometer) to verify that location changes correspond to actual device movement, helping detect location spoofing apps.
- Trust Score System: Maintains an in-session trust score on your device based on validation results from location checks. Multiple failed validations or suspicious patterns lower that score. Related short-lived validation logs (~49-hour TTL) may be stored on our servers (Section 3.2).
- Automated Bans: May automatically apply temporary bans (24 hours) when the system detects violations such as location spoofing, impossible travel speeds, or repeated suspicious behavior patterns.
- Decision Logic: Automated ban decisions are based on objective criteria including:
- Impossible or unrealistic travel between trophies (server-side checks using static trophy locations and visit times)
- Continuous GPS samples on the device that imply impossible or unrealistically high short-distance speeds
- Impossible location changes (e.g., appearing in distant locations without plausible travel time)
- Repeated validation failures in trust score checks
- Device integrity violations (jailbroken devices used for spoofing)
- Transparency: When a ban is applied, you will see a plain-language explanation of the restriction, what it means for your account, and the duration. We do not show internal anti-cheat scores or detection logic in the app.
6.2 Your Right to Appeal Automated Decisions (GDPR Article 22)
Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing, including automated bans. You have the right to request human review of any automated decision that affects you.
If you believe you were incorrectly banned:
How to Submit an Appeal
- In-App Appeal: Use the built-in ban appeal flow in the app. When you see a ban notification, tap "Appeal Ban" to submit your appeal directly within the app.
What Happens After You Submit an Appeal
- Review Process: Our support team manually reviews your appeal by examining your account's trust score validation logs, trophy visit history, and the circumstances that led to the ban.
- Response Time: We normally review and respond to ban appeals within 24 hours of receipt. Complex cases may take longer; we will notify you if this happens.
- Possible Outcomes:
- Ban Overturned: If the ban was incorrect, your account will be immediately restored and you can continue playing.
- Ban Upheld: If the ban was correct, we will explain the reason and provide information about when the ban will expire.
- Additional Review: In complex cases, we may request additional information or extend the review period (we will notify you if this happens).
- Notification: Submitting an appeal emails our support inbox (it does not automatically send you a decision email). After human review, we respond by email with the decision and any relevant details. Where supported, you may also see the current appeal status in-app.
Your Rights
In addition to the appeal process, you have the right to:
- Request Human Review: You can request that any automated decision be reviewed by a human (GDPR Article 22(3))
- Express Your Point of View: You can provide additional context or explanations in your appeal
- Challenge the Decision: If you disagree with the appeal outcome, you can contact us again or lodge a complaint with your local data protection authority
Note: Automated bans are temporary (24 hours) and are designed to prevent cheating and maintain fair gameplay. Most bans are automatically lifted after the specified duration, but you can appeal at any time if you believe the ban was incorrect.
7. Children's Privacy
Stryked is not intended for anyone under the age of 16. In the European Economic Area (EEA), including the Netherlands, the minimum age is 16, in line with the GDPR age of digital consent for processing personal data (such as location data). We do not knowingly collect personal data from anyone under 16, including location data. If you are under 16, please do not use the app or create an account. If we become aware that we have collected data from someone under 16, we will delete it promptly. This aligns with our Terms of Service.
How we enforce this: We ask you to confirm you are at least 16 (self-declaration on device). We do not collect date of birth for this check. If we learn someone is under 16, we delete their personal data promptly.
8. Changes to This Policy
We may update this privacy policy from time to time. When we do:
- The "Last Updated" date and policy version at the top will be changed
- The updated policy will be published on this page (linked from the App under Profile > About)
- For material changes, we bump the in-app privacy policy version so you may be asked to review privacy choices again before continued use where required
- Where the law requires more than notice (for example a new consent or an active acceptance), we will ask for that before relying on the change
- We do not rely on “continued use alone” as acceptance of material changes where applicable law requires a stronger form of agreement
9. Third-Party Services
Our app uses the following third-party services:
This website (legal pages): These hosted legal pages are static content. We do not place advertising or analytics cookies on these pages for cross-site tracking. Firebase Hosting may process standard server logs (e.g. IP address, user agent) needed to deliver the page and protect the service. Linked services (Apple, Google, Brevo, partners) have their own privacy notices when they act as independent controllers.
9.1 Firebase (Google LLC)
- Purpose: Authentication, database, hosting, Cloud Functions, analytics, crash reporting, security verification, Remote Config
- Services Used:
- Firebase Authentication (user sign-in)
- Cloud Firestore (database)
- Firebase Storage (photo storage)
- Firebase Hosting (websites and legal pages)
- Cloud Functions (server-side game and account operations)
- Firebase Remote Config (feature flags)
- Firebase Analytics (usage analytics)
- Firebase Crashlytics (crash reporting)
- Firebase App Check (security verification)
- Data Collected: User data, location data, usage data, crash reports, device information, IP address (for security and approximate geolocation; not used for tracking or advertising)
- Data Location: Core Firebase app data (Firestore, Storage, Auth-related records we control) is configured for the EU region (europe-west1, Belgium)
- Data transfers: If you opt in to Behavioral Analysis, Firebase Analytics and Crashlytics data may be processed by Google outside the EU. Where such transfers occur, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) as set out in Google Cloud/Firebase terms and privacy documentation. Core gameplay data remains subject to Section 3.1
- Privacy Policy: firebase.google.com/support/privacy
- Data Processing Agreement: Automatically incorporated via Google Cloud Terms of Service (GDPR compliant)
9.2 Apple Sign-In
- Purpose: User authentication
- Data Collected: Email, name (if you choose to share)
- Hide My Email: If you use Apple’s Hide My Email / private relay, we receive Apple’s relay address instead of your personal e-mail and use it only for account and transactional communications related to the App
- Privacy Policy: apple.com/legal/privacy
9.3 Google Sign-In
- Purpose: User authentication (alternative to Apple Sign-In)
- Data Collected: Email address, name, profile picture (if you choose to share)
- Privacy Policy: policies.google.com/privacy
9.4 Apple Maps (MapKit)
- Purpose: Displaying maps, trophy locations, and location-based features in the App
- Data Collected: Map interactions may be processed by Apple according to their policies; we do not receive your Apple ID through MapKit for map display
- Terms: Apple Maps Terms of Service
- Privacy Policy: apple.com/legal/privacy
9.5 E-mail and password (Firebase Authentication)
- Purpose: Account creation and sign-in if you choose e-mail and password
- Data: E-mail address and authentication credentials handled by Firebase Auth (we do not store your password in plaintext)
- Privacy Policy: firebase.google.com/support/privacy
9.6 Apple In-App Purchase / App Store
- Purpose: Payments for unlocks, subscriptions, and consumables; deliver entitlements
- Data we receive: Product identifiers, purchase/subscription status and dates. We do not receive payment card details
- Privacy Policy: apple.com/legal/privacy
11. Legal Basis for Processing (GDPR)
We process your personal data based on the following legal bases under GDPR:
- Consent (Article 6(1)(a)):
- Behavioral Analysis only: Firebase Analytics and Crashlytics (usage insights and crash reports), and partner visit-duration / audio-listen analytics for partner trophies as described in Section 1.5
Behavioral Analysis is off by default at first launch. Completing the free-category demographic form does not enable it (Section 1.3.1). You can enable or withdraw this consent in Profile > Account Management > Privacy & Consent. Location and account security are not withdrawable optional consent.
- Contract Performance (Article 6(1)(b)):
- Location processing for trophy validation and visit detection while the App is in use, including on-device checks and transmission of visit coordinates to our servers for geofence verification (Section 1.1). Periodic background location updates only if you enable Background Location (Always) — never required for the core contract; denying Always only stops that optional feature
- Core game features and functionality
- User account management and authentication
- Demographic profile (age range, gender, family situation) required to activate free trophy categories (Section 1.3.1)
- Snapventure photo storage and sharing
- Leaderboard and statistics display
- Partner reward unlock and redemption verification (Section 1.7)
- Friends / social features (Section 1.8)
- Local device notifications for feature alerts you use (Section 1.9)
- Automated anti-cheat restrictions where necessary for fraud prevention (GDPR Article 22(2)(a)), with human appeal
This processing is necessary to provide the services you have requested when using the app.
- Legitimate Interest (Article 6(1)(f)):
- Anti-spoofing and fraud prevention to maintain fair gameplay
- Security measures and device integrity verification (including App Attest / App Check and related anti-cheat signals described in Section 2.2)
- Anti-spoofing analysis: Trust score logging (49-hour TTL), device integrity checks, and teleport detection using static trophy locations (not your raw GPS history)
- Preventing abuse, grey-market account or progress trade, and protecting user data
These activities are necessary to protect the integrity of the game and the interests of all users.
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights, given limited validation-log retention, on-device raw GPS where described, and your right to object (Section 5.4). Optional partner analytics are consent-based (Section 1.5), not legitimate interest. Summary on request: support@getstryked.com.
- Legal Obligation (Article 6(1)(c)):
- Compliance with data protection regulations and responding to lawful authority requests
- Responding to legal requests or court orders
- Note: we do not currently keep a separate multi-year tax archive of in-app purchase documents after account deletion; Apple retains App Store records under Apple’s policies (Section 1.4 / 3.2)
Sensitive location data (not GDPR Article 9 special category data): Precise location is not a special category under GDPR Article 9. It is nonetheless sensitive in practice. We process it for core gameplay under contract (Article 6(1)(b)) — on-device for discovery and anti-spoofing, and as a visit coordinate check on our servers when you confirm a trophy visit — and, where applicable, legitimate interest for fraud prevention (Article 6(1)(f)). Optional analytics that use only approximate (city-level) location require separate Behavioral Analysis consent (Article 6(1)(a)).
© 2026 Stryked. All rights reserved.
This privacy policy is effective as of August 2, 2026 (version 2.12).