The full version follows. It explains exactly what happens to your data, and it is the version that governs.
The data controller is:
| Service owner | Emil Rustamzade Valeh oglu, individual entrepreneur |
|---|---|
| VÖEN (tax number) | 1007379292 |
| Country of registration | Republic of Azerbaijan |
| Contact for anything about data | help@founday.me |
Below, "we" means the entrepreneur named above, "Founday" or "the app" means the Founday mobile game, and "you" means the player.
We collect only what the game cannot work without. Nothing "just in case", and nothing for advertising.
| Data | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Email address | Creating your account and signing you in; sending the six-digit codes that confirm your address or restore your password; telling you when your password has been changed; replying to your support email | Performance of our contract with you |
| Name | What the app calls you: it appears on your "You" screen. It does not have to be your real name and does not have to be unique | Performance of contract |
| Date of birth | Only to check that you are at least 13. It is shown nowhere, our server does not even send it back to the app, and it is used for nothing else | Legal obligation and protection of children |
| Password | Signing in. We never store the password itself — only an irreversible hash of it (Argon2id), from which the password cannot be recovered | Performance of contract |
| If you sign in with Google or Apple: the account identifier the provider gives us, the email address it has confirmed (with Apple this may be a private relay address that hides your real one) and your name, if the provider passes it on | Signing in without a password. We check the provider's sign-in token ourselves; your Google or Apple password never reaches us | Performance of contract |
| Photos | This is the game itself: each step of a journey is answered with a photo, taken with the app's camera or picked from your gallery. Our server keeps the photo reduced to the size the app needs (at most 2,560 pixels on the long side; a smaller picture is kept as it arrived) and a small thumbnail of it. The full-size original is not kept | Performance of contract |
| Captions | Words you add to a shot, and the name you give a finished journey for its postcard. Always optional | Performance of contract |
| Your journeys | Which journeys you have started and when, which steps you have shot, which journeys you have finished; your postcards — the image assembled from your shots, its layout and the part of each shot you framed for it; whether the postcard has already been assembled in front of you. This is why the app looks the same after reinstalling or on a new phone | Performance of contract |
| Sessions: a random device code that the app creates for itself when installed (not the phone's hardware identifier and not an advertising identifier), the device name the phone reports (for example, "Pixel 7"), when you signed in and when the session expires | The "Where I'm signed in" list in Settings, so you can sign out of a device that is not yours; account security. The session key itself is stored only as a hash | Performance of contract and legitimate interest (account security) |
| Security records: sign-in attempts, requests for email codes and code entries — which email address, device code or IP address they came from, and when | Stopping password guessing and stopping anyone from flooding a mailbox with codes. The codes themselves are stored only as a hash | Legitimate interest (service security) |
| IP address | Processed on every request — communication is impossible otherwise. It passes through Cloudflare's network, appears in our server's technical log, and is used to limit abuse when a request carries no device code. It is not saved to your account, and we do not use it to work out where you are | Legitimate interest (service security) |
| Language of our emails | Taken from the language the app was using when you signed up, so that codes arrive in a language you read. The interface language you choose in Settings lives on your phone; our server learns it only for notifications (next row) | Performance of contract |
| For notifications: the address of this copy of the app that Google (Android) or Apple (iPhone) issues — the device token; whether the phone is an Android or an iPhone, and for an iPhone which Apple delivery server to use; its time zone; the language chosen in the app; the app version; the device code from the sessions row; when the phone first and last reported all this | Delivering a notification to every phone where you are signed in, in the language of the app and in the daytime by your clock (if the phone does not report a time zone, we count by UTC+3). The phone reports this while you are signed in, whether or not notifications are allowed: whether to show them is up to the phone. The token is not the phone's hardware identifier and not an advertising identifier, and it is good only for Founday | Legitimate interest (reminding you of your journeys); notifications are shown only if they are allowed on your phone |
| Notification log: for each notification, its reason (for example, one shot left before a postcard, or a new journey), the journey and step it was about, which wording was used, when it went out, and whether any of your phones accepted it | Keeping notifications rare, not repeating the same words twice in a row, and announcing a new journey only once. To decide whether there is anything to tell you, and what, the server looks at your journeys: which are started, which steps are shot, and when | Legitimate interest (rare, non-repetitive notifications) |
| Support correspondence | Answering you and fixing the problem. The correspondence is kept at our email provider | Performance of contract and legitimate interest |
| Email left on the founday.me waitlist | One message — that the app has launched. Nothing else: no newsletters, no advertising. The list is kept separately from game accounts, and every email we send carries a one-click unsubscribe | Your consent, which you may withdraw at any time |
| Anonymous visit statistics for founday.me and legal.founday.me: page address, referrer, country, device type | Knowing whether anyone reaches the site, and from where. No cookies and no identifiers: we do not recognise the same visitor tomorrow or on another site, and these statistics are never joined with a game account | Legitimate interest (knowing whether the site works) |
About what is written inside a photo file. A camera can store extra information inside a photo: the time, the phone model, sometimes the place. The app never asks for your location, and we use none of this information except the orientation, so that the photo stands the right way up. The iPhone app removes the place from a photo before sending it. In other cases the information inside the file may stay with the photo.
On your phone. The app keeps a copy of your journeys and shots on the phone, so that it opens quickly and works without a connection, plus a queue of shots that have not reached our server yet. Your session keys are kept in the phone's protected storage. Signing out or deleting the account wipes all of this from the phone. The app also remembers on the phone that it has already asked about notifications, so as not to ask twice; that mark stays after you sign out.
Nobody but you. Founday has no shared feed, no friends list and no public profile: your journeys, shots, captions and postcards are shown only to you, on any phone where you sign in.
We do not look at them either. Our tools for running the service show a person's name, email, when they joined and how many journeys, shots and postcards they have — not the photos themselves.
A photo leaves Founday in one way only: when you tap Share on a postcard. That opens your phone's usual share sheet, and you choose where the postcard goes. Once sent, it is in the hands of the people and services you sent it to, and we cannot call it back.
If a future version of Founday lets you show your journeys to people close to you, we will update this policy before that version comes out.
| Camera | Asked the first time you open the viewfinder. Without it you can still pick photos from your gallery |
|---|---|
| Gallery | No permission is asked. "From the roll" uses the phone's own picker, which hands the app only the picture you chose |
| Saving a postcard (iPhone) | If you choose "Save Image" in the share sheet, iPhone asks whether Founday may add photos. That permission lets the app add a picture; it does not let it read your gallery |
| Notifications | Asked once, the first time the main screen opens after you sign in. On Android 12 and earlier the phone does not ask, and notifications are on from the start. If you allow them, Founday now and then invites you back to your journeys: the next task by name, the last shot before a postcard, a new journey. No more than once a day and only in the daytime by your phone's clock. You turn them off in the phone's settings: the app has no switch of its own and does not ask a second time |
| Internet | Talking to our server |
The app asks for no other permissions: no location, no contacts, no microphone.
We work with providers who process data on our instructions and only to run the service (data processors under the GDPR). Each receives the minimum its job requires.
| Who | What they receive | Why |
|---|---|---|
| Hetzner Online GmbH (Germany) | Everything kept in our database: account, journeys, captions, sessions, notification tokens and log, security records | Hosting our server and database, in a data centre in the European Union |
| Cloudflare, Inc. (USA) | All network traffic to our server and websites, including IP addresses; the files of your photos, their thumbnails and your postcards; database backups; anonymous website visit statistics | Attack protection and traffic delivery; file storage; backups; hosting founday.me and legal.founday.me with Web Analytics — a cookieless counter that reports page views without identifying anyone |
| Sendinblue SAS (Brevo, France) | Your email address and the text of the message; the website waitlist is stored there too | Sending sign-up and password-reset codes and the note that your password has changed; sending the launch announcement to everyone who left an address on founday.me |
Google and Apple. If you sign in with Google or Apple, you sign in on their side, under their own privacy policies. They give us a token that confirms who you are — an account identifier, a confirmed email address and sometimes your name — and for signing in we send them nothing about you. Notifications reach your phone through them too: our server hands Google's Firebase Cloud Messaging (Android) or Apple Push Notification service (iPhone) the device token, the title and text of the notification — the names of a journey and a task, sometimes how many shots of the journey you have taken — and which journey and step it opens, and the service delivers it to your phone. On Android the app gets its token from Google's Firebase Cloud Messaging library, built in for this purpose alone. The app itself is distributed through Google Play and the App Store, which process data under their own terms.
We may also disclose data where the law or a lawful authority request requires it, or where it is necessary to protect someone's life and safety.
Our server and database are in the European Union. Cloudflare is a US company with a worldwide network, so part of the data — traffic, files and backups — is processed outside the EU. Notifications are delivered by Google's and Apple's services, which also work outside the EU. Such transfers rely on the European Commission's Standard Contractual Clauses and other safeguards provided by law. The service owner is based in Azerbaijan and runs the service from there.
| Your journeys, photos, captions and postcards | As long as the account exists. Replacing a shot deletes the previous file at once; cancelling a journey deletes all its shots at once. We keep no history of replaced shots |
|---|---|
| Account data | As long as the account exists |
| A sign-up that was never confirmed | Stays until you confirm the address or ask us to delete it |
| Email codes | A code works for 10 minutes and is gone as soon as it is used |
| Sessions | A session works until you sign out, or for 30 days after the app last used it |
| Notification token | While the phone is signed in to your account. It is removed when you sign out on that phone, when that phone's session is ended from another device or by a password change or reset, and when the account is deleted; a token that Google or Apple reports as no longer valid is erased too. A session that runs out by itself does not remove the token, so notifications can arrive even if the app has not been opened for a long time |
| Notification log | As long as the account exists |
| Security records, backups and technical logs | Kept for a limited time and then overwritten |
| After account deletion | Erased from the live service at once. Copies that may remain in backups and logs are overwritten over time |
| Support correspondence | Kept at our email provider |
| Anonymous website visit statistics | Up to 6 months on Cloudflare's side, and never tied to a person at any point |
| Waitlist email | Until you unsubscribe — or until the list is no longer needed: the launch message goes out once, and no later than 12 months after launch the list is deleted entirely |
You must be at least 13 to play. We ask for a date of birth at sign-up and do not create accounts for anyone younger.
If you live in an EU country with a higher digital-consent age for children (between 13 and 16, depending on the country) and you are below that age, you may use Founday only with the consent of a parent or legal guardian.
If we learn that an account belongs to a child below the permitted age, we delete the account and the data attached to it. If you are a parent and believe your child signed up without your consent, write to help@founday.me and we will delete the account.
Under data-protection law (including the GDPR for players in the EU and EEA) you have the right to:
Some of this you can do inside the app: sign out of other devices, change your password, replace a shot, cancel a journey, delete the account. Your name and email cannot be changed in the app yet. For that and everything else, write to help@founday.me from the address linked to your account. There is no charge.
No one's protection is absolute. If a breach does occur and creates a risk to your rights, we will notify you and the supervisory authority within the deadlines set by law.
When this policy changes, the date and version at the top of this page change with it. Previous versions are available on request.
For anything about data: help@founday.me. The same address handles access, correction and deletion requests.