Magyar
Terms of Use · NAIH complaint

Privacy Policy — Loremax Mobile Application

Last updated: 16 July 2026 Version: 1.5

Table of contents

  1. Introduction
  2. Scope and minimum age
  3. Personal data we collect
  4. Early Bird waitlist
  5. Legal bases
  6. Where data is stored
  7. How we use your data
  8. Who can see your data
  9. Device permissions
  10. Retention
  11. Your rights
  12. Account deletion
  13. Security
  14. Data breaches
  15. California residents
  16. Changes
  17. Contact

1. Introduction

This Privacy Policy describes how Loremax (“we”, “us”) collects, uses, stores, shares, and protects your personal data when you use the Loremax iOS and Android mobile application (the “App”) and related services at loremax.hu.

The legal bases and framework for processing:

  • Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR)
  • Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (Infotv.)
  • Mandatory requirements of app stores (Apple App Store, Google Play)

Data controller: Selmeczi Vilmos Vazul 2051 Biatorbágy, Szabadság út 48., Hungary Email: loremaxOfficial@gmail.com Website: https://loremax.hu

Privacy contact: loremaxOfficial@gmail.com (Loremax has not appointed a separate Data Protection Officer; contact us at the email above.)

Supervisory authority: NAIH — National Authority for Data Protection and Freedom of Information Website: https://www.naih.hu Complaints: https://www.naih.hu/online-ugyinditas

2. Scope and minimum age

This policy applies to users of the Loremax App who create an account or otherwise use the Service.

Loremax is a social “daily quest” app: users complete quests, upload photo proof, add friends, and receive notifications.

Minimum age: The App is not intended for children under 13. You must be at least 13 years old to use it (or 16 in EU member states where that is the age of digital consent for information society services). You must confirm this before sign-in. We do not knowingly collect data from children under 13. If you believe we have, write to loremaxOfficial@gmail.com — we will delete it promptly.

3. Personal data we collect

3.1 Account and identity

  • Email address — Sign in with Apple/Google, email/password registration, or manual entry; account, authentication, support
  • Password — email/password sign-in only; stored hashed by Supabase Auth; we never see the plain text
  • Email verification code (OTP) — at registration; handled by Supabase Auth
  • User ID (UUID) — generated at registration; internal identification
  • Username — you choose; public handle, friend requests, username login, invite links
  • Display name — from username or OAuth; shown to other users
  • OAuth data (Apple / Google) — identity token, email (Apple may provide a private relay address), name (first name, last name) when the provider shares them

We do not collect phone numbers.

3.2 Profile and social data

  • Profile photo (avatar) — public profile; public storage URL
  • XP / level — gamification
  • Creator points (`creative_points`) — points related to creating a self-made quest; stored on your profile
  • Own-quest state — if you write a self-made quest (see 3.3)
  • Badges (e.g. Early Bird) — in-app status stored on your profile
  • Friend connections and friend requests — social features
  • Quest history and daily quest state — quest completion
  • Quest approvals (validations) — approvals from friends
  • Quest ideas (submissions) — if you submit a quest suggestion
  • Last activity timestamp (`last_seen_at`) — service operation and abuse prevention; not sent to PostHog
  • Privacy settings in your profile:
  • past quests visible to friends (default: on)
  • friends list visible to friends (default: on)
  • push notifications (default: off until you enable)
  • analytics consent (default: off until you accept)
  • Legal consent record — Terms/Privacy version, acceptance time, app version, platform (`user_consents`)
  • In-app notifications — type, text, read state, related post ID

3.3 User-generated content

  • Quest proof photos — evidence of completion; each file has a direct URL (see section 6.1)
  • Captions / experience text (max ~280 characters) — optional description
  • Comments (max 500 characters) — social interaction
  • Optional location on posts — see section 3.5
  • Self-made quest text (title, description) — a quest you write yourself; available for up to 1 day; invited friends may see / complete it

3.4 Moderation and safety

  • Content reports — reporter ID, target type (post, quest, comment, user), reason code, optional details, status
  • User blocks — who blocked whom; visible only to the blocking user
  • Own post deletion feedback — optional reason when you delete your post (e.g. “inappropriate content”)

3.5 Location (optional — opt-in only)

The App may request location permission in two situations:

1. Quest upload — if you enable location sharing:

  • GPS coordinates (latitude, longitude, accuracy)
  • Reverse geocoding: city, country, ISO country code (on device, Expo Location API)
  • Timestamp

→ These are saved on the server with the post.

2. Profile → map → “my location” — for map display only:

  • We use your device GPS on-device only to show your position
  • We do not store it on the server or share it with others

Default: we do not collect location on the server. You can upload without location; you can use the map without permission (without your position shown).

3.6 Data stored on your device (AsyncStorage)

The App does not use SecureStore. Device-stored data includes:

  • Authentication session — Supabase session tokens (maintain sign-in)
  • App language (HU/EN)
  • Age confirmation flag
  • Analytics consent local copy
  • Pending analytics choice — before OAuth registration
  • Pending invite username — to process friend invites
  • Pending Early Bird code — badge redemption after registration
  • Remembered email — if “Remember email” is enabled on login
  • Login/signup form drafts — temporary email only (not password)
  • Custom quest type labels and colors — device only; not synced to our servers
  • Analytics anonymous ID — used for events only when analytics is enabled
  • Internal app state — onboarding, app-review prompt timestamp, auth rate-limit timestamps

3.7 Server-side technical data

  • Platform (iOS/Android) — profile, push token, consent log
  • Expo push token — push notifications when enabled
  • Rate-limit counters — abuse prevention (rolling 24-hour window)

3.8 Product analytics (PostHog EU — consent only)

Host: `https://eu.i.posthog.com`

  • The processor may use additional subprocessors, which may be located outside the EEA.

Distinct ID: your Supabase user UUID after sign-in.

Allowed events: `app_open`, `quest_upload_submitted`, `quest_upload_completed`, `quest_upload_location_saved`, `invite_link_shared`, `friend_request_sent`, `quest_approved`, `quest_proof_shared`, `quest_idea_submitted`, `quest_skipped`, `own_quest_created`, `own_quest_uploaded`.

Event properties: app version, platform; some events include a quest UUID (`quest_id`) or share source — not personal content.

We do not send to PostHog: email, username, invite URLs, GPS, captions, quest text, or image URLs.

4. Early Bird waitlist (website)

Users can join the Loremax Early Bird waitlist through the official website.

Data processing

When subscribing to the waitlist, we process the following data:

  • email address
  • subscription timestamp
  • technical identifiers to authenticate the application

Purpose of processing

Data is processed exclusively for the following purposes:

  • providing early access (Early Bird)
  • sending notifications about the app launch
  • assigning Early Bird eligibility and badge

Redemption in the app

Early Bird eligibility is activated in the app using a unique redeem code.

In the app, only the redeem code is entered; providing an email address is not required.

Data retention

Waitlist-related data is retained only as long as necessary and deleted when eligibility ends or upon user request.

5. Legal bases for processing (GDPR Article 6)

  • Account, quests, friends, feed, notifications (app) — Art. 6(1)(b) — performance of contract
  • Push notifications — Art. 6(1)(a) — consent (OS permission + in-app setting)
  • Optional upload location — Art. 6(1)(a) — consent (per-upload checkbox)
  • Product analytics (PostHog) — Art. 6(1)(a) — consent (first-use modal + Settings; default off)
  • Last activity, rate limits, moderation, reports — Art. 6(1)(f) — legitimate interests (security, abuse prevention, service operation)
  • Legal consent log — Art. 6(1)(c) and Art. 6(1)(b) — legal obligation and contract
  • Other legal compliance — Art. 6(1)(c)
  • Account deletion / erasure request — Art. 6(1)(b) and Art. 17

6. Where data is stored

6.1 Cloud — Supabase (processor)

Region: EU (Zurich)

PostgreSQL: accounts, profiles, friendships, quests, comments, notifications, push tokens, reports, blocks, consents, waitlist, rate-limit logs.

Storage bucket `quest-proof` (avatars, quest photos): Supabase Storage is configured so each upload has a predictable, direct URL. The App does not publish these URLs in search engines or public lists; images are primarily shown to friends and quest participants in the App. If someone obtains the exact URL (e.g. via sharing, forwarding, or technical tools), they can download the image. Do not upload content you would not want shared in this way.

Supabase Edge Functions (server-side, JWT or secret):

  • `delete-account` — account and storage deletion, PostHog erasure (if configured)
  • `export-my-data` — GDPR data portability
  • `push-dispatch` — delivers push messages via Expo
  • `waitlist-sync` — syncs website waitlist emails (secret key)

6.2 Your device

See section 3.6 — AsyncStorage.

6.3 Third-party processors

  • Supabase Inc. — database, auth, storage, edge functions — EU (Zurich)
  • Apple Inc. — Sign in with Apple — global
  • Google LLC — Sign in with Google — global
  • Expo / EAS — push delivery (Expo Push Service) — USA
  • PostHog Inc. — product analytics (consent only) — EU (`eu.i.posthog.com`)

For transfers outside the EEA, appropriate safeguards (e.g. SCCs) apply. We enter into data processing agreements where required by GDPR Article 28.

7. How we use your data

  • Operate the App
  • Authenticate you and maintain your session
  • Send push notifications when enabled in the app and OS: friend requests, quest approvals, and occasional quest reminder pushes for inactive users (about every 2–3 days if they have not opened the app for a while) — no streak or in-app daily quest notifications. Friend requests and approvals are sent immediately.
  • Show content to friends and participants
  • Moderation, report handling, blocks
  • Improve the App through analytics only with your consent
  • Abuse prevention (rate limits)
  • Legal compliance, enforce Terms of Use

We do not sell personal data to third parties. We do not use your data for third-party advertising.

8. Who can see your data

  • Email — only you (and authorized administrators for internal tasks)
  • Username, display name, avatar, XP, creator points, badges — signed-in Loremax users
  • Quest posts (photo, caption, optional location) — you, your friends, and quest participants
  • Past quests on profile — friends (if enabled)
  • Friends list — friends (if enabled)
  • Comments — post owner and participants
  • Invite links — username only — `https://loremax.hu/i?u={username}`
  • Blocks — visible only to the user who blocked
  • Reports — reporter and admins; not visible to other users

9. Device permissions

  • Camera — quest upload, avatar, QR scan
  • Photo library — select/save images
  • Location (when in use) — on quest upload (if you enable it), or on the profile map to show your position (“my location”; GPS is not sent to the server in this case)
  • Notifications — push when enabled
  • Apple Sign In — iOS authentication

Denying permissions limits related features.

10. Retention

  • Account and profile — until account deletion, or as required by law
  • Quest posts, photos, comments — until account deletion
  • Push tokens — until deletion or you disable push
  • Analytics (PostHog) — up to 12 months; erasure requested on account deletion
  • Rate-limit logs — rolling 24 hours
  • Server-side security backups, encrypted, for disaster recovery — up to 30 days
  • Legal consent log — while account exists plus statutory limitation
  • Early Bird waitlist — until redemption / end of launch campaign, then may be deleted

Fulfilling an erasure request: without undue delay, at latest within one month (GDPR Art. 17).

11. Your rights

Under GDPR and Infotv., you have:

  1. Access (Art. 15)
  2. Rectification (Art. 16)
  3. Erasure — “right to be forgotten” (Art. 17)
  4. Restriction of processing (Art. 18)
  5. Data portability (Art. 20)
  6. Objection (Art. 21)
  7. Withdraw consent (Art. 7)
  8. Complaint to NAIH

How to exercise your rights

  • Delete account — App → Settings → Delete account
  • Delete account (web) — https://loremax.hu/app/account-deletion
  • Download your data — Settings → Download my data (JSON)
  • Analytics opt-out — Settings → turn off analytics
  • Push opt-out — Settings → turn off push, or revoke OS permission
  • Past quests / friends list visibility — Settings
  • Location — do not enable on quest upload; on the map, do not use “my location”, or revoke OS location permission
  • Other requests — loremaxOfficial@gmail.com — response within one month

We may verify your identity where necessary.

12. Account deletion

When you delete your account:

  1. Cloud files (avatar, quest photos) are removed
  2. Database records are deleted (profile, friendships, quests, comments, tokens, notifications, reports, blocks, etc.)
  3. Supabase Auth account is deleted
  4. We make commercially reasonable efforts to erase PostHog analytics data when server-side integration is configured (fallback deletion may not always reach PostHog)
  5. You are removed from other users’ quest participant lists
  6. Community quest templates you created are anonymized (`created_by` cleared)

May persist: encrypted backups (up to 30 days); content saved on another user’s device; processor logs; anonymized feedback for statistics.

13. Security

HTTPS/TLS, row-level security (RLS), rate limits, validation, server-side secrets. No method is 100% secure. Concerns: loremaxOfficial@gmail.com.

14. Data breaches

If a breach is likely to affect your rights, we notify NAIH within 72 hours (GDPR Art. 33) and you where the risk requires it (GDPR Art. 34).

15. California residents (CCPA/CPRA)

If you are a California resident and the California Consumer Privacy Act / CPRA applies to us (when applicable revenue and data-processing thresholds are met): you may have rights to know, delete, correct, and opt out of sale of data. We do not sell personal data and do not share it for cross-context behavioral advertising. Requests: loremaxOfficial@gmail.com. The GDPR rights and account deletion above are available to all users.

16. Changes

For material changes, we notify you in the App or by email. The “Last updated” date will change.

17. Contact

Selmeczi Vilmos Vazul 2051 Biatorbágy, Szabadság út 48. Email: loremaxOfficial@gmail.com Support: loremaxOfficial@gmail.com

This site does not use analytics cookies.

SupportPrivacyTermsAccount deletion