Treasure Seeker Privacy Policy
This policy explains what data Treasure Seeker processes on your device, what data is sent to the Treasure Seeker server when you use online features, which third-party services are involved, and why that processing happens.
1. Data stored on your device
- App settings and gameplay preferences (for example audio, haptics, locale, game setup choices, and crash-log sharing preference).
- Gameplay history, local stats, hunt drafts, and temporary hunt data.
- Marked locations, clue photos, and other setup data that stay local unless you start an online party that uploads them.
- Auth/session data used to keep your app installation signed in to server features.
- Pending crash reports captured locally after a crash until you upload them or clear app data.
- Bluetooth signal samples, live GPS fixes, and motion/compass readings used for gameplay feedback and local hunt logic.
Local app data is stored in the app's private storage area on your device.
2. Data sent to the server when you use online features
- Installation identifiers, platform, app version, auth tokens, and a hashed device-binding identifier used to authorize requests and recover account state on the same device.
- Question feature inputs such as selected themes, difficulty tier, locale/language, topic search queries, and question-exposure history used to avoid repeats.
- Party and multiplayer data such as host/player display names, party code and ID, party settings, readiness and state updates, gameplay telemetry (distance/questions/correct count), and any optional clue photo you attach.
- For outdoor party play, the marked treasure location coordinates and horizontal accuracy you choose when setting the target.
- Purchase and unlock records such as feature unlocks, token balances, transaction history, restore/reversal requests, and client request IDs. Our server does not process payment card details.
- Minimal anti-abuse receipts used to prevent repeated free-token claims after account deletion. These receipts use a server-protected hash of an app/device eligibility signal and do not include gameplay history, location, photos, support messages, purchase history, or token balance.
- Support request messages you submit from inside the app.
- Optional crash reports if you explicitly enable crash log sharing in Settings or confirm a post-crash prompt. These can include exception stack traces, error source, app version, platform, timestamps, and related diagnostic text.
- Push-notification registration data, including your Firebase Cloud Messaging (FCM) device token, plus limited client diagnostics when the app reports push-delivery problems.
- Hidden-phone sound listener registrations and short-lived beep command records tied to session codes and host tokens so the hidden-phone clue feature can wake the target device.
- System message delivery and dismissal receipts for announcements shown in the app.
We use this data only to operate app functionality, secure access, troubleshoot issues, and maintain service reliability.
3. Permissions and on-device processing
- Location permission is used for outdoor GPS treasure setup and seeking. Live GPS fixes are processed on your device; only marked outdoor target coordinates and derived multiplayer telemetry are sent to our server.
- Bluetooth and nearby-device permissions are used for indoor BLE seeking, hidden-phone broadcasting, and nearby pairing. BLE signal strength data is processed on your device and is not sent to our server.
- Camera permission is used only if you choose to capture an optional clue photo.
- Notification permission is used for push notifications and hidden-phone alerts.
- Motion sensors, vibration, wake locks, and foreground services are used to power gameplay feedback and keep active hunts running reliably.
4. Third-party services
- Map tiles are loaded directly from OpenStreetMap tile servers when you use the map preview or map clue features.
- Firebase Cloud Messaging (FCM) is used to deliver push notifications and hidden-phone wake-up signals.
- OpenAI is used server-side to generate and verify quiz question content. Selected question themes, difficulty, locale, and language may be included in those server-side requests.
We do not sell personal information.
5. About age-based feature restrictions
To help protect younger users, some features of Treasure Seeker are restricted until a date of birth is entered in the app. This is because certain features may involve data types that are considered more sensitive for children in some jurisdictions, such as precise location, image sharing for outdoor hunts, support messages, and diagnostic error reporting. By default, these features remain disabled unless the app determines that they are age-appropriate. We do not send your date of birth to our servers for this purpose; it is used locally on your device only to decide whether these features should be available.
6. Retention
Device-stored data remains on your device until you clear app data or uninstall the app. Server-side records are retained only as long as needed for app operation, security, support, anti-abuse, and legal obligations. Server operational logs and uploaded crash reports are retained for 21 days by default unless a longer period is required to resolve an active issue. Minimal anti-abuse receipts for free-token eligibility are retained for up to 24 months unless a longer period is required for security, fraud, abuse, dispute, or legal reasons.
7. Security
We use authentication and transport security controls to protect data in transit and to limit unauthorized access.
8. Deleting your account data
Treasure Seeker is designed to collect as little directly identifying account information as possible. We do not use email-and-password accounts. Instead, the app creates a unique account linked to app-specific identifiers generated and stored on your device so that online features can work without requiring your email address or a web sign-in.
Because of that design, we cannot identify your Treasure Seeker account from an email address or username on this website. To delete your account and the server data associated with it, you must start the deletion from inside the app on the device that created the account.
In the app, open Settings, go to Danger Zone, and choose Delete Account.
This permanently deletes account-linked server data, removes purchase and unlock history for that account,
clears local app data on the device, and closes the app. We may retain a minimal anti-abuse receipt to prevent repeated free-token claims after deletion. More details are available on the
Delete Account page.
If any residual operational log data cannot be removed immediately as part of that process, it is purged by our scheduled retention cleanup. Our current server log retention window is 21 days.
9. Your choices
- You can avoid online data transfer by not using online-only features.
- You can deny permissions such as location, Bluetooth, camera, or notifications, although related features may not work without them.
- You can turn crash-log sharing on or off in Settings.
- You can clear local app data from your device settings or uninstall the app.
10. Contact
For privacy questions, use the in-app Support feature.