Privacy Policy

In short

ThroneSeeker operates no servers that process personal data. Location, searches, and visited thrones stay on your device. If you have your operating system’s backup switched on, they also sit in your personal backup at Google or Apple (see section 2). To make the product work (map, geocoding, toilet data) the app forwards individual requests to third-party APIs strictly as needed to fulfil each request.

Controller

ByteSide.io
Stefan Roßkopf
Anemonenweg 7
89547 Gerstetten
Germany
throneseeker (at) byteside.io

1. Location data

The app requests your location only while it is open ("when in use"). Background location is explicitly not requested (Android: isAndroidBackgroundLocationEnabled = false). On Android, the technical permissions requested are ACCESS_FINE_LOCATION (for the precise compass needle) and ACCESS_COARSE_LOCATION (fallback for an approximate position); on iOS, NSLocationWhenInUseUsageDescription is used.

Queried live, your location leaves the device solely to reach third-party APIs (see section 3) for maps and toilets in your vicinity. Coordinates already stored, such as those of the thrones you have conquered, can also travel into your personal device backup (see section 2). We neither store the location on our own servers (we have none) nor link it to your identity.

Legal basis: Art. 6(1)(b) GDPR (performance of the user contract; the compass and map cannot function without your location). You can revoke the underlying OS-level permission ("Location: while using the app") at any time in your device settings; the app handles the revocation and displays a corresponding notice.

2. Data stored on the device

Stored locally in a SQLite database on your device:

We never upload this data to servers of our own. Uninstalling the app removes it from the device, though a backup taken earlier can outlive it, see "Device backup" below. Within the app you can erase it at any time via Settings → Annals → Clear the throne registry or Erase the kingdom.

Legal basis: Art. 6(1)(b) GDPR (contract performance). For storage on your end device additionally § 25(2) no. 2 TDDDG (strictly necessary to provide the service you explicitly requested).

Device backup (Google, iCloud later on)

The app is not excluded from your operating system's backup (Android: allowBackup = true). With backups switched on, the local database described above goes into your personal backup, conquered thrones and their coordinates included, so that favourites and rank survive a move to a new phone. The same will apply to the iCloud backup in a later iOS version.

That backup sits in your own account. On Android it is handled by Google Android Auto Backup in your Google Drive storage, encrypted with your device's screen lock on current Android versions; on iOS it would be the iCloud backup. We have no access to it and learn neither its contents nor whether a backup exists at all. The provider is the controller for the backup itself, under its own privacy policy (Google, Apple).

You can switch it off yourself at any time without losing the app: on Android under Settings → Google → Backup, or System → Backup depending on the manufacturer, where backups can be disabled altogether or for individual apps. On iOS later under Settings → [your name] → iCloud → iCloud Backup.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in conquered thrones and favourites surviving a change of device). The backup happens solely within your own account and can be switched off in the operating system.

3. Third-party APIs

OpenStreetMap / Overpass API

We query toilet data directly from overpass-api.de (project maintainer: Roland Olbricht). If the primary endpoint is unavailable, an alternative Overpass mirror may be queried (currently the French instance overpass.openstreetmap.fr, operated by OpenStreetMap France). In the process, your approximate coordinates (search radius) and a user agent are transmitted. Privacy information: OSMF Privacy Policy.

Legal basis: Art. 6(1)(b) GDPR (contract performance; without toilet data the app has no function).

Geoapify (map tiles + reverse geocoding)

The map background and the reverse geocoding (turning coordinates into an address) run via the Geoapify service, operated by KEPTAGO LTD (N. Nikolaidi & T. Kolokotroni, ONISIFOROU CENTER, 2nd Floor, 8011 Paphos, Cyprus, EU; VAT no. CY60033286B). Coordinates and an API key are transmitted. Privacy information: Geoapify Privacy Policy.

Data processing agreement: the basis is the Geoapify Data Processing Agreement under Art. 28 GDPR. It commits Geoapify to carrying out the contractual processing exclusively within the EU or the EEA.

Legal basis: Art. 6(1)(b) GDPR. No third-country transfer (provider established in the EU/Cyprus).

Map navigation

The Navigate button opens your installed maps app (Google Maps, Apple Maps, OsmAnd or similar) with the destination coordinates in the URL. What happens there is governed by the respective provider. We do not transmit data ourselves but hand the call to your operating system.

App updates via Expo (EAS Update)

The app can receive improvements to its JavaScript part without a new store download ("over-the-air update"). For this we use the EAS Update service of 650 Industries, Inc. ("Expo"), 624 University Ave FL1, Palo Alto, CA 94301, USA. The app only checks there when it is recovering from an error (checkAutomatically: ON_ERROR_RECOVERY), not on every launch. According to Expo's own privacy policy, the device operating system and randomized tokens are processed so that Expo can tell whether an update has already been downloaded; the app also sends its runtime version and update channel so that it receives the matching update, and, as a technical necessity of the connection, the IP address. No location data, no identifier of your person.

Third-country transfer (USA): 650 Industries, Inc. is certified under the EU-U.S. Data Privacy Framework (listed as "Expo" in the DPF list of the U.S. Department of Commerce, status active, covering non-HR data). The transfer therefore rests on the European Commission's adequacy decision of 10 July 2023 under Art. 45 GDPR. Privacy information: Expo Privacy Policy.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in fixing bugs and delivering current software without waiting for store review).

Store rating prompt

The app may ask you for a rating through the operating system's interface. The dialog is shown by Google Play or Apple; whatever you enter there is processed solely by the respective store under its own terms. We receive no personal data from it.

4. Crash diagnostics (Sentry)

If the app crashes, an anonymized crash report may be transmitted to Sentry’s EU region (telemetry data hosted in Frankfurt, Germany). The provider and processor is Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA; represented in the EU by Sentry Software Netherlands B.V., Schiphol Boulevard 359, 1118 BJ Amsterdam Schiphol, Netherlands, as EU representative under Art. 27 GDPR (contact: compliance (at) sentry.io). A data-processing agreement (Sentry Data Processing Addendum) including the EU Standard Contractual Clauses (SCC, 2021/914) as a transfer safeguard under Art. 46 GDPR is in place.

We configure Sentry with active PII scrubbing (sendDefaultPii: false) and an additional beforeSend filter that strips geo contexts. Transmitted are only: stack traces, app version, device model, OS version, language setting. Not transmitted are: location data, IP address as a personal identifier, advertising IDs, your favourites or visited thrones.

Third-country transfer (USA): Although telemetry data is stored in the EU region (Frankfurt), administrative access from the USA or processing of cross-organizational account metadata in the USA cannot be excluded. The transfer basis is the SCCs mentioned above.

Opt-out: You can disable this transmission at any time in the app under Settings → Discretion → "Share anonymous diagnostics". The change takes effect on the next app start.

Retention: 90 days (Sentry default), after which events are deleted automatically.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in app stability and bug fixing).

5. In-app purchases

Purchases within the app (ThroneSeeker Pro, Knight Without Realm) are processed exclusively by the respective store (Google Play or the Apple App Store). From Google/Apple we receive no payment data, only the information that a purchase has been made or refunded for a store-internal, pseudonymous user ID.

To technically manage the entitlement (status cache, restore purchase, cross-platform entitlements) we use RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA. RevenueCat receives an anonymous installation ID, your store country, and the purchase/refund status. No identity, no location data, no payment information. Data is hosted on Amazon Web Services (AWS) in the USA.

Third-country transfer (USA): The transfer is based on the RevenueCat Data Processing Addendum (DPA) including the EU Standard Contractual Clauses, Module 2 (Controller to Processor) under Commission Implementing Decision (EU) 2021/914 as a transfer safeguard under Art. 46(2)(c) GDPR. Privacy information: RevenueCat Privacy Policy.

Legal basis: Art. 6(1)(b) GDPR (performance of the purchase contract for the Pro unlock).

6. This website

This website is delivered statically via a Caddy web server at the Falkenstein (Vogtland, Saxony) data centre of Hetzner Online GmbH, Germany. A data processing agreement under Art. 28 GDPR is in place with Hetzner. We use no cookies, no tracking, no analytics, no external fonts (Inter is self-hosted) and no CDN.

Local browser storage (localStorage): We remember only your deliberately chosen language preference (ts-lang). This storage is exempt from consent under § 25(2) no. 2 TDDDG, because it is strictly necessary for the function you explicitly requested: "land in the right language on your next visit". You can clear these values via your browser settings at any time.

Server logs (anonymized): The web server writes access logs in a privacy-friendly format:

Browser APIs blocked at the server level: Via the Permissions-Policy response header we proactively disable, on this website, geolocation, camera, microphone, payment API, USB, Bluetooth, motion/gyro/magnetometer sensors, and Google’s "FLoC"/Topics API (interest-cohort=()). Accidental tracking through these APIs is therefore technically excluded.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational security, abuse prevention, and basic reach statistics with minimal personal reference).

7. What we deliberately do not do

8. Contacting us

If you contact us by email (throneseeker (at) byteside.io), we process your message and email address solely to respond to your request. Legal basis: Art. 6(1)(b) GDPR (pre-contractual / contractual) or (f) (legitimate interest in answering inquiries). We delete inquiries once they are no longer needed, subject to any statutory retention obligations.

Email provider: Our business email runs on Microsoft 365 / Exchange Online provided by Microsoft Ireland Operations Limited (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland) with EU Data Boundary enabled; i.e. customer data at rest (mailbox contents) is stored and processed exclusively within the EU/EEA. The legal basis is the Microsoft Products and Services Data Protection Addendum (DPA) including the EU Standard Contractual Clauses (SCC, 2021/914). Occasional administrative access by Microsoft Corporation (USA) for support, engineering or security purposes cannot be entirely excluded despite the EU Data Boundary; to that extent there is a third-country transfer based on the SCCs mentioned above under Art. 46(2)(c) GDPR.

If you use the WhatsApp contact listed in the legal notice, you transmit your phone number and message content to WhatsApp Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) as the controller for the WhatsApp services in the EEA. For cross-product account processing with other Meta services, Meta Platforms Ireland Limited is additionally a joint controller. Processing on servers outside the EU (in particular the USA) cannot be excluded; we have no influence on this. If you would like to avoid this, please use the email route.

9. Your rights

You have the right at any time to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21) under GDPR. Where processing is based on consent, you may withdraw it with effect for the future (Art. 7(3)).

To exercise these, contact throneseeker (at) byteside.io. Since we store no personal data on our own servers, a request for access will typically amount to a confirmation that we hold no data about you, plus any existing email correspondence and (if you have made a Pro purchase) the pseudonymous entitlement data held at RevenueCat.

10. Right to lodge a complaint

You have the right to lodge a complaint with a data-protection supervisory authority. The authority competent for us is:

State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI BW)
Heilbronner Straße 35, 70191 Stuttgart, Germany
(Postal address: Postfach 10 29 32, 70025 Stuttgart)
Phone: +49 711 615541-0
Email: poststelle (at) lfdi.bwl.de
www.baden-wuerttemberg.datenschutz.de