PRIVACY & TRUST

Privacy Policy

Your location never leaves your phone. We believe privacy is an architectural invariant, not a legal afterthought.

Effective Date: August 17, 2026 Applicable to Togra for iOS & Android

App Store & Google Play Privacy Declarations

To provide complete transparency, here is the exact summary of data practices as declared on Apple's App Store Privacy Nutrition Labels and Google Play's Data Safety form:

Data Category Collected / Transmitted? Linked to You? Purpose & Handling
Precise Location (GPS) ❌ Not Collected No Processed strictly on-device. Proximity checks, bearing math, and geocell unlocking never leave your phone.
Coarse Location (City) ⚠️ Ephemeral (IP) No Used ephemerally via Geoapify on Explore load to center your city before GPS permissions. Never logged or stored.
Identifiers (Email / Handle) Optional (Account Holders) Linked to Account Required only for creating hunts, joining parties, or leaderboards. Anonymous play requires no account.
Usage Data (Product Telemetry) None Active in Release No No third-party analytics SDK is active in release builds. Internal event taxonomy contains zero coordinates, zero user IDs, and zero free text.
Diagnostics (Crash Reports) Scrubbed No Crash logs (Sentry) with strict automatic stripping of coordinates, paths, and sensitive user data.
User Content (Created Hunts) Creators Only Linked to Creator Hunts and clues authored by creators. Can be edited, unpublished, or permanently deleted at any time.

1. The Architectural Invariant: On-Device GPS

Togra is designed from the ground up so that no user GPS coordinate ever leaves your mobile device.

When you participate in a scavenger hunt:

  • All proximity threshold calculations, distance mathematics (Haversine calculations), and compass bearing orientations are executed entirely on your device's local CPU.
  • In competitive hunts, clue locations are protected using salted geohash cryptographic slow-hashes (scrypt / PBKDF2). Your device derives candidate cell hashes locally and compares them against the bundle without disclosing coordinates.
  • When you finish a hunt, our servers receive only your achievement statistics (the hunt ID, your chosen alias, total monotonic elapsed time, and per-clue split intervals). We never receive your breadcrumb trails, GPS fixes, or geographic coordinates.

2. Data Classification: What Lives Where

We classify all application data into clear categories to ensure minimal data processing:

📱 Device-Only Data (Never Uploaded)

  • Real-time GPS fixes, location history, and path traces.
  • Per-clue unlock locations and compass orientation data.
  • Solo gameplay progress, earned XP, streaks, levels, and badges.
  • Passport stamps and completion certificates.
  • Locally cached hunt bundles, media, and offline vector map tiles.

☁️ Server-Pseudonymous Telemetry

  • Leaderboard submissions (random adjective-animal alias e.g. amber-lynx, clue counts, elapsed time, split times).
  • Completion timestamps rounded to the nearest hour to prevent temporal correlation.
  • Aggregated finisher counts and median clue solve times.

👤 Server-Identity (Opt-in Accounts Only)

  • Account credentials (email address or Apple/Google ID) managed via first-party authentication.
  • Custom display handles (for party multiplayer and creators).
  • Created hunt drafts and published hunt content.
  • Active party memberships and join invitations.

3. Approximate Location via IP-Derived City Detection

When you open the Explore catalogue, our backend function (explore.discoverCity) reads your request IP address and queries Geoapify to derive an approximate city name and center coordinates.

Why we do this: This enables Togra to center the Explore map on your city immediately so you can browse nearby hunts without being forced to grant GPS permissions first.

Handling & Retention: This IP lookup is purely ephemeral. Neither your IP address nor the derived city coordinate is logged, stored in any persistent database, or linked to your account profile.

4. Multiplayer Parties & Social Play

Togra Parties allow groups of friends to walk a hunt together. When you join a party:

  • Party members can see your chosen display handle, your current clue number (e.g. "Clue 3 of 5"), and your completion time.
  • Teammates never see your physical location or GPS pin. Progress is shared strictly as an integer index along the clue trail.
  • You can leave a party at any time from the Party Board, which immediately removes your handle and progress from the group. Party organizers can also remove members from their party board.

5. AI-Assisted Generation & Clue Grading

Togra provides optional AI assistance for creators drafting hunts, and semantic answer grading for casual quiz clues:

  • Hunt Generation: AI prompts contain only a city name and thematic keywords (e.g. "Historic bakeries in Paris"). We never include user coordinates, personal addresses, or creator personal information in AI prompts.
  • Semantic Answer Grading: On published casual hunts, grading requests send only {question, user_answer, canonical_answer} to a secure evaluation model. No user identifier, auth token, or location is attached, and quiz submissions are not logged or stored.

6. Third-Party Services, Analytics & Diagnostics

We do not sell your personal data to data brokers, do not use ad-tech networks, and do not ship third-party tracking SDKs:

  • Product Analytics & Telemetry: No third-party analytics SDK or advertising tracker is active in our release builds. The app codebase includes an internal, privacy-preserving event taxonomy seam that strictly enforces zero coordinate collection, zero search query logging, and zero free-text transmission. If privacy-first analytics is activated in future updates, it will operate exclusively under these zero-PII constraints with randomized per-session identifiers that reset on every launch.
  • Mapbox / Map Tiles: We provide offline vector map tiles. Mapbox background telemetry is explicitly disabled at SDK initialization.
  • Sentry (Error & Crash Diagnostics): Crash logs automatically scrub any data shaped like geographic coordinates, personal identifiers, or auth headers before transmission.
  • Convex & Cloudflare: Secure first-party backend database, file storage (R2 for hunt covers), and edge deployment.

7. Account Deletion & Your Data Rights

We uphold your full rights under GDPR, CCPA, and global privacy frameworks to access, export, and delete your data at any time.

🗑️ How to Delete Your Account & Data

In-App Self-Service Deletion: Go to Passport → tap the ⚙︎ Settings icon → scroll to Your data → tap Delete account & on-device data.

This immediately wipes all local SQLite database records, MMKV caches, and passport stamps from your device. Your server session is revoked, your created drafts are deleted, published hunts are unpublished, and foreign-key references are swept permanently.

Manual Web / Email Request: If you no longer have the app installed, email rb@suprappstudio.com with the subject "Account Deletion Request" from your registered account email. We will process your deletion within 30 days.

8. Children's Privacy

Togra is designed for general audiences and does not knowingly collect personal identifiable information from children under the age of 13 (or the minimum legal age in your jurisdiction). Public scavenger hunts are accessible anonymously without creating an account or providing personal details.

9. Updates to This Policy

We may periodically update this Privacy Policy to reflect enhancements in our architecture, new features, or regulatory standards. The updated date at the top of this document will always reflect the latest revision.

10. Contact Us & Data Controller

If you have questions, comments, data access requests, or concerns regarding this Privacy Policy, please contact our Data Protection desk:

Suprapp Studio / Togra Privacy Desk

We respond to all privacy inquiries, data export requests, and deletion notices within 30 calendar days.