Privacy Policy

Last updated: 29 July 2026

1. Who We Are

Valkara ("we", "us", "our") is operated by TechniSK s. r. o., a company registered in the Slovak Republic (Company ID: 55109357, Tax ID: 2121871059, VAT ID: SK2121871059), with registered office at Severná 1502/2, 974 01 Banská Bystrica. Contact: privacy@valkara.app

TechniSK s. r. o. is the controller of the personal data described in this policy within the meaning of Art. 4(7) GDPR. This policy covers the website at valkara.app and the Valkara mobile app for Android and iOS, and it is the whole of it — there is no second, internal policy that says something different. Where we say "we do not", we mean we do not do it at all, not that we do it in a way we have chosen not to describe.

Two things are worth knowing before you read the rest, because they shape everything else. First, Valkara works without an account: the core of the app is local to your device, and you can use it having given us nothing. Second, the sensitive data stays on your device — health, fitness, location, your quests and anything you write are stored in the app's own storage and are not uploaded to our servers. What follows explains, honestly and in detail, the narrow set of things that do reach us.

If you only want to know about cookies, jump to section 3. The short answer is that we set none.

2. What Data We Collect

Account Data

Health & Fitness Data

Collected only with your explicit permission, only on the mobile app:

Sourced from Apple HealthKit (iOS), Google Health Connect (Android), or manual entry within the app. All health and fitness data is processed and stored locally on your device, and is used only to calculate your biological age and in-app attributes. None of it is uploaded to our servers. If you use the optional social features, only your game stats (such as level and XP) can appear to other warriors; no heart rate, weight, sleep figure or other health metric is transmitted to us, so there is nothing for us to publish even by mistake.

You may see settings in the app for who can view "Health & vitals" or "Body metrics" on your profile. Those controls currently govern nothing, because no such data reaches our servers to be governed. They exist because an opt-in cloud-sharing feature is planned, and we would rather show you the control early than add it quietly later.

Our commitment, stated so you can hold us to it: health and fitness data will not be uploaded unless you switch it on yourself, for that specific category, having been told plainly what it means — and we will update this policy and notify you before such a switch exists, not after. It will never be on by default, never bundled into another setting, and never a condition of using anything. If you would like to be certain it can never happen, do not grant the health permission at all: the rest of the app works without it.

Location Data

Collected only with your explicit permission, only on the mobile app, and only while you are actively recording an outdoor activity session. We use your device location to measure distance, route and pace during a training session. Location is not tracked in the background, is never used for advertising, and is not shared with third parties. You can revoke location access at any time in your device settings.

Microphone and Motion Sensor (sleep monitoring)

Valkara's sleep mode is started by you, for one night at a time, and it ends when you end it or when the wake time you set arrives. While it runs, and only while it runs, the app may use two sensors on your device:

Both are processed entirely on your device, and the per-minute figures they produce are stored there in the app's own storage. None of it is uploaded to our servers, and none of it is used for advertising or shared with third parties. You can erase any night from the sleep report, decline the microphone and still use sleep mode, or not use sleep mode at all — the rest of the app is unaffected. On Android, a notification from your system shows whenever the microphone is in use, and your phone's own recording indicator is visible on both platforms.

Profile Photo (optional)

If you choose to set a profile photo, the app accesses your camera or photo library with your permission. The photo is stored locally on your device and is not uploaded to our servers.

What You Write to Other Warriors

If you use the optional social features, the direct messages, guild wall posts and kudos you send are stored on our servers so that the person on the other end can read them. That is the whole purpose, and there is no way around it — a message nobody can retrieve is not a message.

They are not end-to-end encrypted. We say so plainly rather than letting you assume otherwise: they are encrypted in transit and protected at rest by database access controls, but we hold the keys, which means we are technically capable of reading them. We do not. There is no scanning, no profiling, no automated classification, no advertising use, and no human at Valkara browsing conversations. The only circumstances in which anyone here would read a message are a specific report about that specific content, or a lawful order we are obliged to comply with — both described in section 13 of our Terms of Service.

Treat them as you would any ordinary messaging app that is not end-to-end encrypted: fine for arranging a training session, wrong for anything you would not want a court order to reach. Deleting your account deletes these messages for both sides — see our account deletion page for what that means for the other person.

App Usage Data

Device Data

Website Data

Website Analytics (cookieless)

We measure how the website is used so we can see where visitors get stuck. Neither method uses cookies, and neither identifies you or follows you across other websites. There are two:

Our own measurement. For each interaction we record only: the event (for example a page view, opening the registration form, or starting a download), the page path, the referring website's domain (not the full address), any campaign or affiliate code in the link you arrived through, and whether your screen is phone-, tablet- or desktop-sized. Interactions are grouped by a random identifier created in your browser tab, stored in sessionStorage, and deleted when you close that tab. It is not linked to your account, your email or your IP address.

Vercel Web Analytics. Our hosting provider also provides aggregated visitor statistics — page views, referrers, countries, browsers and devices. It is cookieless and stores nothing on your device; visitors are counted using a temporary identifier derived from request data that rotates daily and cannot be traced back to a person or linked across sites. We see only aggregate counts, never individual visitors. The same provider's Speed Insights feature measures anonymous page-performance timings (how fast pages load) to help us keep the site fast; it likewise sets no cookies and identifies no one.

If your browser sends a Do Not Track or Global Privacy Control signal, our own measurement records nothing at all.

Legal basis: legitimate interest in understanding and improving our own website (Art. 6(1)(f) GDPR). For the separate question of whether storing anything on your device requires consent, see section 3 below.

In-App Crash and Failure Reports

When something in the app breaks — it crashes, or it tells you that an action could not be completed — the app records what went wrong so it can be fixed. This is on by default and you can switch it off in Settings → Version Info → "Report crashes and failures".

Each report contains: the error message and its technical stack trace, a short trail of the steps the app took immediately beforehand (for example award XP → level up → open celebration), the screen it happened on, the app version, your device type and OS version. It does not contain your name, your email, your account, your quests or anything you have written.

Reports are grouped by a reporting identifier — a random value created on your device, not derived from anything about you, and shown to you in Settings → Version Info. It exists so that one fault can be counted across the devices it affects, and so that you can erase your own reports whenever you like: in the app under Settings → Version Info → "Delete my reports", or on our report deletion page without signing in to anything. Switching the reporting off does the same. Reports are written on your device first and sent later, so the app works offline and nothing waits on a network request.

Legal basis: legitimate interest in keeping Valkara working and secure (Art. 6(1)(f) GDPR). You may object at any time using the switch above, which also deletes any reports still waiting to be sent.

3. Cookies, Local Storage and Similar Technologies

Valkara sets no cookies whatsoever — not on the website, not in the app. We run no advertising, no ad network, no social plug-ins, no cross-site tracking, no fingerprinting, and no third-party tag manager. Nothing we store is ever read by another website, sold, or shared for marketing.

We do use two ordinary browser storage areas, and the law requires us to tell you about them in full even where they need no consent. This is the complete list — there is nothing else:

NameWhereWhat it holdsPurposeLifetime
sb-…-auth-token localStorage Your Supabase sign-in token Keeps you signed in on the dashboard so you are not asked for your password on every page. Set only after you sign in. Until you sign out or clear your browser storage
va_sid sessionStorage A random identifier, generated in your browser Groups the page views of one visit together so we can count visits rather than clicks. Not derived from anything about you or your device. Deleted when you close the tab
va_engaged sessionStorage The value 1 Records that this visit has already been counted as a real human visit, so automated crawlers do not inflate our figures and you are not counted twice. Deleted when you close the tab
referred_by sessionStorage The referral or affiliate code from the link you clicked Remembers, for the duration of your visit, who referred you, so that the reward you were promised is actually credited when you register. Deleted when you close the tab

Why we do not show you a cookie banner

Storing anything on your device is governed by Art. 5(3) of the ePrivacy Directive (2002/58/EC), in Slovakia § 109(8) of Act No. 452/2021 Coll. on electronic communications. It requires that you always be informed — which is the purpose of the table above — and that you consent, unless the storage is strictly necessary to provide a service you yourself asked for. Every item above falls inside that exemption, and we have deliberately built them so that they do:

We are aware that some regulators take a stricter view of analytics storage than others. We would rather be safe than clever, so you also have an unconditional way out that works before you have to trust any of the above: if your browser sends a Do Not Track or Global Privacy Control signal, our measurement never runs at all — no identifier is created, no storage is written, no data is sent. You can also block or clear all site storage in your browser settings; the website continues to work, and only your ability to stay signed in is affected.

If we ever introduce storage that is not strictly necessary — an advertising pixel, a cross-site tag, a third-party analytics script — we will ask for your consent first, through a banner that makes refusing exactly as easy as accepting, and we will not set it unless and until you agree. We have no plans to do so.

The mobile app stores its data in its own private application storage on your device, not in cookies. See section 2 for what that data is.

4. How We Use Your Data

PurposeLegal Basis
Provide app and website functionalityContract (Terms of Service)
Calculate biological ageContract + Consent
Send push notificationsConsent
Apply early adopter pricingContract
Process referrals and affiliate commissionsContract
Improve the productLegitimate interest
Find and fix crashes and failures in the appLegitimate interest (switchable off)
Manage subscriptionsContract
Comply with legal obligationsLegal obligation

We do not sell your data. We do not share it with advertisers. We have never done so and will not begin without telling you first.

No automated decision-making

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Art. 22 GDPR, and we do not profile you for advertising. Your level, XP and biological age are calculated arithmetically from what you yourself log; they are features of the product you are using, they decide nothing about you outside the app, and no human or automated judgement about you is made or shared on their basis.

Do you have to give us this data?

Only an email address and a password are required, and only if you want a cloud account — the app's core features work with no account at all. Everything else is optional: if you do not grant health, location, camera or notification permissions, those specific features simply do not operate, and nothing else about the product changes. There is no statutory obligation on you to provide any of it.

5. Where Your Data Is Stored

6. International Data Transfers

Our own database and authentication run on Supabase in Frankfurt, Germany (AWS eu-central-1), so your account data, your public profile and your crash reports are stored inside the European Union. We name the region rather than saying "an EU region" because a claim you cannot check is not worth much.

Some of the providers we depend on are established in the United States, or may process limited data there in the course of operating a global service. Where that happens, the transfer is covered by one or both of the following safeguards under Chapter V GDPR:

ProviderWhat may leave the EEASafeguard
Vercel (hosting, aggregate analytics)Request metadata needed to serve the page; aggregate statisticsSCCs / Data Privacy Framework
Expo (push delivery, app updates)Device push token, app-update requestsSCCs / Data Privacy Framework
Apple (APNs, App Store)Device push token; purchase data handled by Apple as merchant of recordSCCs / Data Privacy Framework
Google (FCM, Google Play, Health Connect)Device push token; purchase data handled by Google as merchant of record. Health Connect data stays on your device and is not sent to Google by us.SCCs / Data Privacy Framework
Resend (email delivery)Your email address and the text of a service email we send youSCCs / Data Privacy Framework

Your health, fitness and location data is not part of any of this: it never leaves your device in the first place. You may request a copy of the relevant safeguards at privacy@valkara.app.

7. Data Retention

Data typeRetention
Cloud account & public profile dataKept while your account is active
On-device data (character, quests, health, training)Stays on your device until you delete it in the app or uninstall — we cannot access or remove it remotely
Inactive accountsAutomatically deleted after 2 years with no sign-in
When you delete your accountCloud data is erased immediately; any residual backups are purged within 30 days
Crash and failure reportsDeleted after 1 year. A rare fault can take months to explain, which is why these outlive usage data. Erased sooner on request — quote the reporting identifier from Settings → Version Info
A registration you started but never confirmedDeleted after 30 days. You never became a user, so there is nothing to justify keeping the address longer
Affiliate applications we do not take forwardDeleted within 12 months of the decision
Website measurement eventsDeleted after 14 months. They contain no personal data and no identifier that survives your browser tab

8. Your Rights (GDPR)

If you are in the EU/EEA or the UK, you have the right to:

To exercise any right: privacy@valkara.app. Exercising them is free and we will not ask you why. We will respond within one month of your request, as Art. 12(3) GDPR requires; if a request is exceptionally complex we may extend this by up to two further months, and we will tell you within that first month if we do. We will not charge a fee or refuse a request unless it is manifestly unfounded or excessive, and if we ever take that position we will explain it in writing and tell you how to challenge it.

Your right to complain

If you believe we have handled your data unlawfully, you can complain to a supervisory authority at any time — you do not have to contact us first, although we would like the chance to put it right. Our lead supervisory authority is:

Úrad na ochranu osobných údajov Slovenskej republiky
Hraničná 12, 820 07 Bratislava 27, Slovak Republic
dataprotection.gov.sk · statny.dozor@pdp.gov.sk · +421 2 3231 3214

You may equally complain to the supervisory authority of the EU/EEA country where you live or work, or where you think the problem occurred. If you are in the UK, that is the Information Commissioner's Office (ico.org.uk). You also have the right to an effective judicial remedy under Art. 79 GDPR.

Data protection officer

We are a small company and our processing does not meet the conditions in Art. 37(1) GDPR that would require us to appoint a data protection officer — we do not monitor people on a large scale, and the health data the app handles stays on your device rather than being processed by us. Privacy questions are handled directly by the company at privacy@valkara.app, and that address reaches a person who can act on them. If that ever changes, we will name a data protection officer here.

One of these is worth spelling out, because crash reports are not tied to your account:

9. Health Data (Special Category)

Health and fitness data is a special category of personal data under Art. 9 GDPR, and we treat it as the most sensitive thing the app touches.

The design decision that matters most is this: we never receive it. It is read on your device, calculated on your device and stored on your device, in the app's own private storage. It is not transmitted to our servers, not backed up to them, not visible to us in any support tool, and not included in any analytics or crash report. If our servers were breached tomorrow, no health data of yours would be in them, because none is there.

Within the app it is processed on the basis of your explicit consent under Art. 9(2)(a) GDPR, given through your device's own health permission prompt, and used only to show you your own figures and to calculate your biological age and in-app attributes. It is never used for advertising, never sold, never shared with third parties, and never used to make any decision about you.

You can withdraw that consent at any moment by revoking Apple HealthKit or Google Health Connect access in your device settings; the features that depend on it stop, the rest of the app carries on, and you can delete the data already held by deleting it in the app or uninstalling. If you use the optional social features, only game statistics such as level and XP can appear to other users — no heart rate, weight, sleep figure or other health metric is sent to us at all, so none can be shown. See section 2 for what would have to change before that were ever untrue, and the commitment we have made about it.

10. Affiliate and Referral Data

If you refer other users, or take part in the affiliate program for creators and publishers:

If you apply to the affiliate program

The application form on our affiliate page collects your name, email address, platform, audience size range and content type. We use it for one thing: deciding on your application and contacting you about it. Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR).

It is not used for marketing, not shared with anyone, and not linked to any Valkara user account you may also hold. Applications we do not take forward are deleted within 12 months; applications that are approved are kept for as long as you remain an affiliate, and then for the period our tax and accounting law requires for the payments made to you. You can ask us what we hold, or ask for erasure, at privacy@valkara.app.

No commission data is shared with anyone. Valkara is free during the testing period, no subscription revenue exists yet, and consequently no affiliate payouts have been made and no payment provider has been engaged. When payouts begin, we will name the provider in this policy and in the table in section 12 before any of your data reaches it, and we will notify affiliates of the change. We would rather leave this paragraph awkwardly specific than list a placeholder recipient you cannot check.

11. Children

Valkara is not directed at children and is not intended for anyone under 16. Slovakia has set the age of consent for information society services at 16 under Art. 8 GDPR, and we apply that limit to every user regardless of country rather than operating a lower threshold anywhere.

We ask you to confirm your age at registration and we do not knowingly collect data from anyone below it. We do not profile users by age, and we do not advertise to anyone.

If you are a parent or guardian and believe a child has created an account, write to privacy@valkara.app. You do not need to prove anything or fill in a form: tell us the account and we will suspend it immediately, delete it and its data, and confirm to you in writing when it is done. If we discover such an account ourselves, we do the same without waiting to be asked.

12. Third-Party Services

ServicePurposePrivacy Policy
SupabaseAuthentication, databasesupabase.com/privacy
Apple App StoreIn-app purchases / subscriptions (iOS)apple.com/legal/privacy
Google PlayIn-app purchases / subscriptions (Android)policies.google.com
Apple HealthKitHealth data (iOS)apple.com/privacy
Google Health ConnectHealth data (Android)policies.google.com
VercelWebsite hosting & cookieless aggregate web analyticsvercel.com/legal/privacy-policy
Expo (EAS)Push notification delivery, over-the-air app updates, and hosting the Android APK — the "Download APK" link on our home page redirects to expo.dev, so your IP address and browser reach them when you download the beta buildexpo.dev/privacy-explained
Apple APNs / Google FCMPush notification delivery to your deviceapple.com/legal/privacy · policies.google.com
ResendDelivery of service emails we send you directly — currently only replies about a bug report you submitted. Your email address and the message reach them for that purpose. Account confirmation and password-reset emails do not go through Resend; those are sent by Supabase.resend.com/legal/privacy-policy

Each of these acts as our processor under Art. 28 GDPR, or as an independent controller for its own platform (Apple and Google in respect of App Store and Google Play purchases), under a written agreement. This table is exhaustive: we use no advertising network, no data broker, no customer-data platform and no third-party analytics or session-recording service. There is no affiliate payment provider in this table because we have not engaged one — see section 10.

13. Push Notifications and Email

Push notifications

We send push notifications only with your explicit permission. You can disable them at any time in your device settings. Notification tokens are not used for any other purpose.

Notifications are delivered through Expo's push service and, at the device level, Apple Push Notification service (APNs) on iOS or Google Firebase Cloud Messaging (FCM) on Android. A device push token is shared with these providers solely to deliver your notifications.

Email

We do not send marketing email. There is no newsletter, no promotional campaign, no "we miss you" sequence, and your address is never given, sold or rented to anyone for their own use. If that ever changes we will ask you to opt in first, separately, and you will be able to leave with one click.

The only messages we send are the ones the service itself requires:

EmailWhenLegal basis
Confirm your addressOnce, when you registerPerformance of the contract (Art. 6(1)(b))
Password resetOnly when you ask for onePerformance of the contract
Reply about a bug report or feedback you sent usWhen we have an answer for youPerformance of the contract
Material changes to these terms or this policy, and security incidents affecting youRarely, and only when there is something you need to knowLegal obligation (Art. 33/34 GDPR) or legitimate interest

None of these are marketing, so none carry an unsubscribe link — you cannot opt out of being told that your password was reset or that your data was breached, and it would not be in your interest to. If you want no email from us at all, delete your account and there will be none.

Registration and password emails are sent by Supabase; replies about bug reports are sent through Resend. Both appear in the table in section 12.

14. Security

If something goes wrong

No security measure is absolute, and we will not claim otherwise. If a personal data breach occurs, we will notify the Slovak supervisory authority within 72 hours of becoming aware of it as Art. 33 GDPR requires, and we will tell you directly and without undue delay where the breach is likely to result in a high risk to your rights, as Art. 34 requires. We will tell you what happened, what data was involved and what you should do, in plain language and without waiting until we have a comfortable explanation.

15. Changes to This Policy

We will notify you of material changes by email and by in-app notification, before they take effect wherever that is possible, and the "Last updated" date at the top always reflects the most recent revision. If a change would newly require your consent — a new purpose, a new category of data, a new recipient — we will ask for that consent separately and will not rely on your silence. For changes that do not require consent, continuing to use the Service after we have notified you indicates acceptance; if you would rather not accept, you can delete your account at any time on our account deletion page.

16. Contact

Privacy questions: privacy@valkara.app
Account & data deletion: use our account deletion page — sign in and delete your account and data instantly, no request or waiting needed.

TechniSK s. r. o.
Company ID: 55109357 · Tax ID: 2121871059 · VAT ID: SK2121871059
Severná 1502/2, 974 01 Banská Bystrica
Slovak Republic

← Back to Valkara