BETA SERVICE POLICY
Privacy Notice
Beta draft · last updated August 31, 2026
1. Who controls the data
Data controller/operator: [OWNER TO PROVIDE LEGAL NAME, ADDRESS AND JURISDICTION]. Privacy contact: [OWNER TO PROVIDE PRIVACY EMAIL]. This notice describes the planned beta processing and must be reviewed against the final deployment region and vendors.
2. Data we collect
We process account identifiers, verified email and display name; profile, avatar, bio, home region, visibility settings and selected social links; lists, quests, comments, ratings, follows and moderation history; subscription status and provider references; and technical security logs.
3. Location and proof visibility
Nearby search can use your device location when you grant browser permission. A check-in sends precise coordinates and accuracy with a short-lived challenge for one-time, low-assurance quest verification. Original photo proofs and their object keys are private, safety-scanned and available only to their owner through authenticated, short-lived access. Publication does not expose raw coordinates or proof bytes.
4. Public and searchable content
Your profile, home location, social accounts and quests follow your visibility choices. An approved collectible instead shows the contributor @handle and links to a contributor page because that public attribution is accepted at submission. A private-profile contributor page shows only the handle and public contribution history; after ordinary cancellation it also shows an account-canceled notice. People discovery exposes only coarse proximity bands, never an exact distance derived from a private home coordinate.
5. Translation and AI
When you request another language, eligible text is sent to the configured translation model. Results are stored by source revision, target language and model version so unchanged content is not translated again. List-generation prompts can be processed by the configured AI model and grounded against place results.
6. Service providers
The beta is designed to use AWS for hosting, identity, storage, scanning, databases, email and AI; Google Maps Platform for maps and place search; and Stripe or another configured provider for payment. Google processing is described in the Google Privacy Policy and map use is subject to the Google Maps Platform Terms . Final vendor/subprocessor list: [OWNER TO CONFIRM].
7. Retention and security
Private media uses restricted storage and time-limited access. Sessions use encrypted Secure, HttpOnly cookies; browser storage does not hold Cognito access, ID or refresh tokens. Retention periods for inactive accounts, proof files, logs, translations and moderation records: [OWNER TO SET BEFORE LAUNCH].
8. Your choices and rights
You can change public/searchable fields, unfollow people, withdraw publications and correct profile data. You may separately cancel the account, which preserves approved licensed contributions, or invoke an applicable personal-data deletion right. Authenticated active or canceled accounts can create a portable JSON export, available only to that account through a non-cacheable response for seven days. Contact [OWNER TO PROVIDE PRIVACY EMAIL] for correction, objection, withdrawal questions or other applicable rights.
9. Account deletion
Authenticated active or canceled users can request statutory deletion by entering an account-specific confirmation. This is separate from ordinary cancellation. Public/search visibility, including retained collectible contributions, is frozen immediately. A seven-day cooling-off period allows withdrawal before erasure begins; afterward private media and identity access are removed, contributed collectible media is deleted, credited handles and consent timestamps are anonymized, and profile data is erased. Restricted audit records may be retained where required, but are not public.
No proof evidence is made public by publishing a visit.Public projections contain minimized completion metadata only.