Moonveil Privacy Policy
1. Controller and contact
The controller of personal data processed through Moonveil – Tarot & Guidance (the “App”) is TealDev Mateusz Pilarski, ul. Orzechowa 37/17, 21-500 Biała Podlaska, Polska, tax or registration number NIP 5651479302 (“Moonveil”, “we”, “us”).
Privacy contact: tealdevmp@gmail.com. Support contact: tealdevmp@gmail.com.
2. Privacy-by-default design
The App can be used in guest mode without an account. By default, tarot readings, notes, custom spreads, profile information, a name and date of birth used for numerology, zodiac results and similar personal content are stored locally on the user’s device. We cannot access local-only data.
Local-only data leaves the device only when the user deliberately uses a feature that requires transmission, such as account sign-in, purchase restoration, support contact or optional cloud backup.
3. Data processed
| Category | Examples | When processed |
|---|---|---|
| Account and authentication | Internal user ID, optional verified email, Google/Apple provider ID, account status, login timestamps and account creation/update timestamps. | When an account is created or used. |
| Purchases and access rights | RevenueCat app user ID, store, product ID, subscription state, renewal/expiry/grace-period dates, entitlements, purchase/refund events, price and currency metadata and billing audit records. | When a purchase, subscription, restore or billing-status check occurs. |
| Optional cloud backup | A user-selected backup payload, schema version, revision and update timestamp, currently limited by the backend to 5 MB. | Only when the user enables or invokes cloud backup/sync. |
| Support communications | Email address, message content, attachments and information voluntarily supplied by the user. | When the user contacts support or privacy staff. |
| Technical and security data | IP address, timestamps, request path, app/version information, error details, authentication/security events and server or reverse-proxy logs. | When the App communicates with backend or content-delivery services. |
| Device permissions and selected media | System language and media selected through the operating-system photo/image picker. Camera or photo access is requested only where a feature needs it. | When the user chooses such a feature and grants permission. |
We do not receive the user’s payment-card number. Payments are processed by Google Play or Apple’s App Store.
4. Sensitive content in optional backup
Journal entries, tarot readings or spiritual-profile content may reveal religious or philosophical beliefs or other sensitive information. Such content remains local by default. Before optional cloud backup of this content is enabled, the App must provide a separate, clear opt-in and, where required by law, collect explicit consent. Consent can be withdrawn by deleting or disabling the backup without affecting the lawfulness of earlier processing.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provide guest features, accounts, sign-in, purchase restoration, paid access and requested backup/sync. | Performance of a contract or steps requested before entering a contract (GDPR Article 6(1)(b)). |
| Process optional sensitive content placed in cloud backup. | Explicit consent where Article 9 GDPR applies, together with the applicable Article 6 basis. |
| Maintain billing, accounting and legally required transaction records. | Compliance with legal obligations (Article 6(1)(c)). |
| Secure the service, prevent abuse/fraud, diagnose faults and establish or defend legal claims. | Legitimate interests (Article 6(1)(f)), balanced against user rights. |
| Answer support and privacy requests. | Contract, legal obligation or legitimate interests depending on the request. |
6. Recipients and service providers
Depending on the feature used, data may be processed by:
- Google (Google Sign-In and Google Play billing);
- Apple (Sign in with Apple and App Store billing);
- RevenueCat, which processes purchase and entitlement data on our behalf;
- OVHcloud, which hosts the Moonveil backend, PostgreSQL database, operational logs and backups;
- Cloudflare R2, used to deliver application/content assets;
- Expo/650 Industries, where Expo Application Services or over-the-air updates are used in the released build;
- GitHub Pages, if it hosts these public legal pages;
- professional advisers or public authorities where required by law.
Google and Apple may also act as independent controllers for their store and account services. The current processor register is published in the project’s legal documentation and must be updated before adding new SDKs or vendors.
7. International transfers
Some providers operate outside the European Economic Area, including in the United States. Where required, transfers are based on an adequacy decision, the European Commission’s Standard Contractual Clauses or another lawful safeguard. RevenueCat’s current DPA identifies Moonveil as controller and RevenueCat as processor and provides transfer safeguards for restricted transfers.
8. Advertising, analytics and tracking
The current design does not include advertising SDKs, behavioural advertising or third-party marketing analytics. We do not sell personal data. If analytics, advertising or non-essential tracking is added later, this policy and the store disclosures will be updated before deployment and any consent required by law will be collected first.
9. Retention
- Local data remains on the device until deleted in the App, removed by uninstalling, or retained by the user’s device backup settings.
- Account-linked data and cloud backup remain until the account or backup is deleted, unless a longer period is legally required.
- Deleted production data may remain in restricted disaster-recovery backups for up to 14 days and is not used for ordinary processing.
- Security and request logs are retained for 30 days unless needed longer to investigate an incident or legal claim.
- Routine support records are retained for 12 months after closure. Records necessary for a complaint, legal claim or defence may be isolated and retained for the applicable limitation period.
- Accounting and transaction records are retained for the period required by applicable tax/accounting law, commonly up to five years after the end of the relevant tax year in Poland.
10. Security
We use access controls, TLS encryption in transit, secret management, restricted production access, database backups, audit records and other technical and organisational safeguards appropriate to the risk. No system is completely secure. Users should protect their device, store credentials and exported backups.
11. User rights
Subject to applicable law, users may request access, rectification, erasure, restriction, portability and objection, and may withdraw consent at any time. A complaint may be lodged with the competent supervisory authority; in Poland this is the President of the Personal Data Protection Office (UODO). Requests should be sent to tealdevmp@gmail.com. We may verify identity and generally respond without undue delay and within one month.
12. Account deletion and subscriptions
Users can initiate account deletion in the App or through the external account deletion page. Deleting a Moonveil account removes the backend account, associated cloud backup, Moonveil billing metadata and the linked RevenueCat customer, subject to lawful retention. It does not automatically cancel an active Google Play or App Store subscription. Store subscriptions must be cancelled separately in the relevant store account.
13. Children
The App is not directed to children under 16. Users below the age required by their country to consent to online services must use the App only with valid parental or guardian authorisation. We do not knowingly create accounts for children contrary to applicable law.
14. Changes
Material changes will be announced in the App or by another appropriate method before they take effect where required. The version and effective date will be shown on this page.
Polityka prywatności Moonveil
1. Administrator i kontakt
Administratorem danych osobowych przetwarzanych w związku z aplikacją Moonveil – Tarot & Guidance jest TealDev Mateusz Pilarski, ul. Orzechowa 37/17, 21-500 Biała Podlaska, Polska, NIP lub numer rejestrowy NIP 5651479302 („Moonveil”, „my”).
Kontakt w sprawach prywatności: tealdevmp@gmail.com. Pomoc techniczna: tealdevmp@gmail.com.
2. Prywatność domyślna
Z aplikacji można korzystać jako gość, bez konta. Odczyty tarota, notatki, własne rozkłady, dane profilu, imię i data urodzenia używane do numerologii, wyniki zodiakalne i podobne treści są domyślnie przechowywane lokalnie na urządzeniu. Nie mamy dostępu do danych pozostających wyłącznie na urządzeniu.
Dane lokalne opuszczają urządzenie tylko wtedy, gdy użytkownik świadomie korzysta z funkcji wymagającej transmisji, np. logowania, przywracania zakupów, kontaktu z pomocą albo opcjonalnego backupu w chmurze.
3. Jakie dane przetwarzamy
| Kategoria | Przykłady | Kiedy |
|---|---|---|
| Konto i logowanie | Wewnętrzny identyfikator użytkownika, opcjonalny zweryfikowany e-mail, identyfikator Google/Apple, status konta, daty logowania i utworzenia konta. | Po utworzeniu lub użyciu konta. |
| Zakupy i uprawnienia | RevenueCat app user ID, sklep, identyfikator produktu, status subskrypcji, daty odnowienia/wygaśnięcia/grace period, entitlementy, zdarzenia zakupu/zwrotu, waluta, cena i historia audytowa. | Przy zakupie, subskrypcji, restore lub synchronizacji statusu. |
| Opcjonalny backup | Wybrany przez użytkownika payload backupu, wersja schematu, rewizja i data aktualizacji; backend ogranicza obecnie backup do 5 MB. | Tylko po włączeniu lub ręcznym użyciu backupu/synchronizacji. |
| Kontakt z pomocą | E-mail, treść wiadomości, załączniki i dobrowolnie przekazane informacje. | Gdy użytkownik kontaktuje się z nami. |
| Dane techniczne i bezpieczeństwa | Adres IP, czas żądania, ścieżka API, wersja aplikacji, błędy, zdarzenia uwierzytelnienia i logi serwera lub reverse proxy. | Gdy aplikacja komunikuje się z backendem lub CDN. |
| Uprawnienia urządzenia i wybrane media | Język systemu i pliki wybrane systemowym pickerem. Dostęp do aparatu lub zdjęć jest proszony tylko dla funkcji, która go wymaga. | Po wybraniu funkcji i udzieleniu uprawnienia. |
Nie otrzymujemy numeru karty płatniczej. Płatność obsługuje Google Play lub App Store.
4. Wrażliwe treści w opcjonalnym backupie
Notatki, odczyty tarota i profil duchowy mogą ujawniać przekonania religijne lub światopoglądowe albo inne wrażliwe informacje. Domyślnie pozostają lokalne. Przed uruchomieniem backupu takich treści aplikacja musi pokazać odrębny, jasny opt-in i — gdy prawo tego wymaga — zebrać wyraźną zgodę. Zgodę można wycofać przez usunięcie lub wyłączenie backupu.
5. Cele i podstawy prawne
| Cel | Podstawa |
|---|---|
| Funkcje gościa, konto, logowanie, restore, płatny dostęp i żądany backup/sync. | Wykonanie umowy lub działania na żądanie przed jej zawarciem — art. 6 ust. 1 lit. b RODO. |
| Opcjonalne wrażliwe treści w backupie. | Wyraźna zgoda, gdy zastosowanie ma art. 9 RODO, wraz z odpowiednią podstawą z art. 6. |
| Rozliczenia i wymagane prawem rejestry. | Obowiązek prawny — art. 6 ust. 1 lit. c RODO. |
| Bezpieczeństwo, zapobieganie nadużyciom, diagnostyka i roszczenia. | Prawnie uzasadniony interes — art. 6 ust. 1 lit. f RODO. |
| Obsługa zgłoszeń. | Umowa, obowiązek prawny albo uzasadniony interes — zależnie od sprawy. |
6. Odbiorcy i dostawcy
Zależnie od użytej funkcji dane mogą być przetwarzane przez Google, Apple, RevenueCat, OVHcloud, Cloudflare R2, Expo/650 Industries, GitHub Pages oraz doradców lub organy publiczne, gdy wymaga tego prawo. Google i Apple mogą być niezależnymi administratorami w zakresie własnych kont i sklepów.
7. Transfery poza EOG
Niektórzy dostawcy działają poza EOG, w tym w USA. Gdy jest to wymagane, korzystamy z decyzji stwierdzającej odpowiedni stopień ochrony, standardowych klauzul umownych Komisji Europejskiej lub innego legalnego zabezpieczenia.
8. Reklamy, analityka i śledzenie
Obecny projekt nie zawiera SDK reklamowych, reklamy behawioralnej ani zewnętrznej analityki marketingowej. Nie sprzedajemy danych osobowych. Dodanie takich narzędzi wymaga wcześniejszej aktualizacji dokumentów, deklaracji sklepowych i zebrania wymaganych zgód.
9. Retencja
- Dane lokalne pozostają na urządzeniu do usunięcia w aplikacji, odinstalowania lub zgodnie z ustawieniami kopii urządzenia.
- Dane konta i backup istnieją do usunięcia konta lub backupu, chyba że prawo wymaga dłuższej retencji.
- Usunięte dane mogą pozostać w odizolowanych kopiach awaryjnych maksymalnie 14 dni.
- Logi bezpieczeństwa są przechowywane 30 dni, chyba że incydent lub roszczenie wymaga dłużej.
- Zwykłe zgłoszenia wsparcia są przechowywane 12 miesięcy od zamknięcia. Dane potrzebne do reklamacji, dochodzenia lub obrony roszczeń mogą zostać wydzielone i przechowane przez właściwy okres przedawnienia.
- Dokumentacja rozliczeniowa jest przechowywana przez okres wymagany prawem podatkowym i rachunkowym, zwykle do pięciu lat od końca właściwego roku podatkowego w Polsce.
10. Bezpieczeństwo
Stosujemy kontrolę dostępu, TLS podczas transmisji, zarządzanie sekretami, ograniczony dostęp produkcyjny, kopie zapasowe i rejestry audytowe. Żaden system nie daje pełnej gwarancji bezpieczeństwa. Użytkownik powinien chronić urządzenie, konto sklepu i eksportowane kopie.
11. Prawa użytkownika
Użytkownik może — zależnie od przepisów — żądać dostępu, sprostowania, usunięcia, ograniczenia, przeniesienia danych, wnieść sprzeciw i wycofać zgodę. Może też złożyć skargę do Prezesa Urzędu Ochrony Danych Osobowych. Wnioski należy wysyłać na tealdevmp@gmail.com. Możemy zweryfikować tożsamość; odpowiadamy bez zbędnej zwłoki, zasadniczo w ciągu miesiąca.
12. Usunięcie konta i subskrypcja
Usunięcie konta można rozpocząć w aplikacji albo na stronie usunięcia konta. Usunięcie obejmuje konto backendowe, backup, metadane billingowe Moonveil i powiązanego klienta RevenueCat, z zastrzeżeniem legalnej retencji. Nie anuluje automatycznie subskrypcji w Google Play lub App Store — trzeba ją anulować osobno w sklepie.
13. Dzieci
Aplikacja nie jest kierowana do osób poniżej 16 lat. Osoba, która według prawa swojego kraju nie może samodzielnie wyrazić zgody na usługę online, może korzystać tylko z ważną zgodą rodzica lub opiekuna.
14. Zmiany
O istotnych zmianach poinformujemy w aplikacji lub inną odpowiednią metodą przed ich wejściem w życie, jeżeli wymaga tego prawo. Aktualna wersja i data będą widoczne na tej stronie.