Gnostis Ελληνικά
Privacy Policy

Privacy Policy

This binding legal document sets forth the framework under which the digital software Gnostis (hereinafter "Application") processes personal data in strict compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR).

Current Version 2.5
Effective Date August 11, 2026
Scope gnostis.vspapg.gr
Language English

Contents

  1. Scope & Advertising
  2. Data Controller
  3. Data Categories
  4. Legal Bases
  5. Recipients & Ad Networks
  6. Retention Periods
  7. Data Subject Rights
  8. Minors & Age Rating
  9. Governing Law

Integrated Advertising Disclosure: The Application incorporates programmatic advertising frameworks (including but not limited to Google SDKs/AdMob). By utilizing the Application, you explicitly acknowledge and consent to the execution of identifiers and analytics frameworks deployed for telemetry and marketing tracking.

1. Scope, Material Jurisdiction, and Amendments

The provisions of this Policy govern the Gnostis application ecosystem across iOS and Android platforms, the tracking components, and related backend infrastructures. Account registration and use of the Application signify that you have been informed of this Policy.

This Policy may be amended — for example when features, providers or legislation change. Each new version is published on this page with a new version number and effective date; material changes are announced in advance through the Application or the website.

2. Identity of the Data Controller

Vasilis Savvas Papagrigoriou
Legal Status: Natural Person — Independent Developer
Jurisdiction: Hellenic Republic (Greece)
Address: Rhodes, 85101, Greece
Email: vasilispapg@outlook.com

3. Categorization and Nature of Collected Personal Data

3.1. Technical Logs, Identifiers & Advertising Metrics

  • Advertising Identifiers: ID for Advertisers (IDFA on iOS) and Google Advertising ID (GAID on Android) utilized for ad serving, delivery metrics, and analytics.
  • Account Credentials: Email addresses, OTP states, Google/Apple authentication tokens, pseudonyms, and localized secure storage tokens (SecureStore/JWT).
  • Technical Tracking: Device models, OS versions, IP addresses (processed transiently for anti-abuse and regional ad mapping), and standard server logs.
  • Push Notification Tokens: the Expo push token of your device, stored only while notifications are enabled and used to deliver game notifications (e.g. streak reminders, rewards).

3.2. Telemetry and Dynamic Progress Data

  • Gamification Variables: XP records, level, virtual currency ledger (Gem tracking), trophy parameters, unlocks, items purchased via virtual currency (including but not limited to powerups, cosmetic frames, and communication bubble packs).
  • AI-Generated Metrics: Question reports, metadata of games played, and win/loss records. The content of the questions is entirely AI-generated and evaluated, and does not fall under personal data.
  • Subscription & Purchase Data: VIP subscription status and expiry, store platform, product id, and the store transaction / original-transaction identifier used to validate and renew your subscription. We never see or store your payment card details — these are handled solely by Apple / Google.

3.3. In-App Analytics (Opt-Out Available)

By default we collect aggregated product analytics — never a personal heatmap tied to your account. You may disable this under Settings → Data & privacy. When enabled, this may include:

  • Screen names and time spent on each screen
  • Button and UI element taps (semantic labels, not screenshots)
  • Approximate tap zones and scroll-depth attention on a grid (heatmap cells; vertical content depth, not screenshots)
  • Named UI region attention (e.g. category grid, arena card)
  • Platform, app version, and device aspect bucket (tall/standard/wide)

Events are buffered briefly on-device, sent over your authenticated session, aggregated anonymously on our servers without storing your user ID in analytics tables, and deleted after ninety (90) days. You may opt out at any time via Settings.

4. Legal Bases for Processing (Art. 6 GDPR)

Processing Purpose Legal Basis
Account Management & Contractual Execution Article 6(1)(b) — Performance of a contract
Programmatic Ad Targeting Article 6(1)(a) — Consent collected in-app via the Google consent form (UMP) and, on iOS, App Tracking Transparency; you can change it at any time in your device or app settings. Without consent, only non-personalized ads are shown.
Push Notifications & Occasional Update Emails Article 6(1)(a) — your device's notification permission for push; Article 6(1)(f) — legitimate interest for occasional update emails, always with an unsubscribe link and a per-user opt-out.
Aggregated Product Analytics (opt-out via Settings → Data & privacy) Article 6(1)(f) — Legitimate interest in improving the app; you may disable at any time
Security, Integrity, Abuse Mitigation Article 6(1)(f) — Legitimate interest of the Provider

5. Data Recipients, Subprocessors, and Advertising Networks

We share necessary data assets with service providers (OVHcloud for server infrastructure hosted in the EU, Resend for authentication mailings, Sentry for server-side error monitoring, and Expo — expo.dev — for push-notification delivery and application updates).

Where a recipient processes data outside the EU/EEA (e.g. Google LLC in the United States), the transfer relies on an adequacy decision (EU–US Data Privacy Framework) and/or the European Commission's Standard Contractual Clauses.

Furthermore, advertising tracking strings, telemetry markers, and device metadata are shared directly with Google LLC (AdMob) and associated programmatic ad exchanges to ensure proper asset monetization, tracking validation, and performance measurement.

In-app purchases and the VIP auto-renewing subscription are processed by Apple (App Store) and Google (Google Play) as payment processors. They also send us server-to-server notifications (receipts and renewal / cancellation / refund events) so we can keep your VIP entitlement accurate. We never receive your payment card details.

6. Data Retention Limitations

Core account attributes and virtual item purchases remain stored for the lifetime of the profile until a direct erasure request is triggered via in-app configuration. Dynamic analytics records are systematically dropped after ninety (90) days.

7. Rights of Data Subjects

Users maintain the rights of Access (Art. 15), Rectification (Art. 16), Erasure (Art. 17), Restriction (Art. 18), Portability (Art. 20), and Objection (Art. 21) via written contact to vasilispapg@outlook.com. You can also erase your account and data directly in the app (Settings → Delete account) and export your data via the in-app data export.

If you believe your rights have been infringed, you have the right to lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias 1-3, 115 23 Athens — www.dpa.gr — or with the supervisory authority of your EU member state of residence.

Where processing is based on consent, you may withdraw it at any time via your device or in-app settings, without affecting the lawfulness of processing before the withdrawal. The Application does not make decisions based solely on automated processing that produce legal effects concerning you (Art. 22 GDPR).

8. Minor Users and Age Rating

The Application's content is family-friendly; the official age rating is the one displayed on the App Store / Google Play listing at any given time and may differ per platform. However, the creation of a persistent online data profile under the GDPR requires an age threshold of sixteen (16) years or older, or alternative explicit parental verification.

9. Governing Law and Jurisdiction

This Policy is governed strictly by the laws of Greece. The Courts of Athens retain absolute and exclusive jurisdiction over any contractual or actionable dispute arising under these terms.