Official legal notice

Privacy Policy

This Policy explains how Honor Pledge handles personal data, including data kept only on your device, cloud-synchronized pledge data, public Heroes Hall content, analytics, and purchases.

Effective and last updated: 4 August 2026 · Application: Honor Pledge · Android package: com.honorpledge.honor_pledge

Plain-language promise. Honor Pledge is for people aged 13 and older. We do not sell your personal data. Pledge photos and voice notes stay on your device and are not uploaded to our servers. Your pledge text is shown publicly only when the pledge is set to Public; private and Witnesses-only pledge text is hidden from public leaderboards.
Local media stays local

Photos and voice notes attached to pledges remain on the device where you created them.

You choose visibility

Public, Witnesses-only and Private visibility determine who can see the text of a pledge.

Account deletion

You can delete your account in the app or request deletion through our dedicated web page.

Age without a birth date

First-run age eligibility uses a broad age range stored only on your device. We do not ask for or upload your date of birth.

Краткое резюме на русском

Honor Pledge хранит фото и голосовые заметки к клятвам только на вашем устройстве и не загружает их на сервер. Для синхронизации через Supabase сохраняются аккаунт, имя героя, текст и параметры клятвы, видимость, сроки, свидетельские голоса, реакции, прогресс и сведения о подтверждённых покупках. Публичный текст клятвы показывается в рейтингах только при выбранной видимости Public. Firebase используется для ограниченной аналитики и диагностики сбоев, AppsFlyer — для измерения установок и рекламных кампаний; текст целей, email, коды свидетелей и локальные медиа туда не отправляются. Мы не продаём персональные данные. Удалить аккаунт можно в приложении или через отдельную страницу. Полный юридически значимый текст приведён ниже на английском языке.

Возраст: Honor Pledge предназначено для пользователей от 13 лет. При первом запуске выбирается только возрастной диапазон; дата рождения не запрашивается, а выбранный диапазон остаётся на устройстве. Если по закону страны пользователь ещё не может самостоятельно дать согласие на обработку данных, родитель или законный опекун должен ознакомиться с Политикой и разрешить обработку, основанную на согласии. Родитель или опекун может обратиться по адресу alsvarel.developer@gmail.com.

1. Controller and scope

Karalko Aliaksei, trading as the developer of Honor Pledge, is the controller responsible for the personal data described in this Policy.

Address: Ijslandstraat 11, 1363 DR Almere, Netherlands
Privacy contact: alsvarel.developer@gmail.com

This Policy applies to the Honor Pledge mobile application, its connected backend services, and the legal pages hosted at legal.alsvarel.com. It does not govern third-party applications or services that you independently choose to open, such as your calendar application, a sharing destination, Google Play, or the Apple App Store.

2. Data we process

CategoryExamplesHow and why
Account and profileAnonymous or permanent account ID, hero/display name, witness persona, account creation dates, email address if you choose to protect the account, and authentication status.Created through Supabase Auth to operate, secure and restore your account. Passwords are handled by the authentication provider; we do not receive a readable copy.
Local age eligibilityA broad range: under 13, 13-15, 16-17, or 18 and older. We do not request your birth date.Used on first launch to enforce the minimum age. The selection stays in local app storage and is not uploaded to our backend, Firebase or AppsFlyer.
Pledges and outcomesPledge text, deadline, selected Honor Pledge product and localized/reference amount, currency, visibility, witness requirement, five-digit witness code, attempt/revenge number, status, outcome, payment-due state and timestamps.Provided by you and synchronized to provide the core service, offline recovery, Witness flows, progression and Heroes Halls.
Witness and community activityYes/No witness vote, reaction type, Townhall salute, ranking, report reason and limited report context.Generated when you witness, react, salute or report. Used to operate community features, prevent duplicate voting and moderate content.
Progression and TownhallValor/Honor/Tarnish values, levels, unlocked choices, selected setting, hero presentation/appearance, Townhall visibility, public Townhall code and salute count.Calculated from pledge outcomes and purchases to provide progression, customization and visits.
Local pledge mediaOptional photo from your gallery and optional voice note of up to two minutes.Stored only on your device for your private use. These files and their local paths are not uploaded to Honor Pledge, Supabase, Firebase or AppsFlyer.
Device and security dataRandom installation identifier or non-reversible hash, platform, app version, last-seen time, failed witness-code attempts, rate-limit state, network request metadata and IP address received by network providers.Used for synchronization, one-vote-per-installation protection, session security, abuse prevention, troubleshooting and service delivery. Honor Pledge does not request Android Advertising ID in the current release configuration.
Analytics and attributionApp installation/session identifiers, app version, device model and operating system, language/region, approximate country inferred from IP, acquisition source, feature events, attempt/tier categories, and purchase success categories.Firebase Analytics and AppsFlyer help us understand product use, measure our own campaigns and improve the app. We do not send pledge text, email addresses, display names, witness codes, local-media paths, raw purchase tokens or free-form input as analytics fields.
Crash and diagnostic dataCrash stack traces, app state, device metadata, installation identifiers and a sanitized error category.Firebase Crashlytics helps diagnose stability and security problems. Our custom reporting removes original exception messages and other free-form content before submission, although provider-generated technical crash context may still be collected.
PurchasesStore product ID, transaction/order ID, purchase token or its hash, amount, currency, purchase status, test-purchase status, verification and refund/revocation information.Used to open and verify Honor Payments, prevent replay, settle progression once, provide support and meet accounting, fraud and store obligations. Payment-card or bank details are processed by the app store and are not provided to us.
Support and privacy requestsYour email address, message, verification information and any material you choose to send.Used to answer requests, verify account control, resolve disputes and comply with legal obligations. Please do not send passwords, witness codes, full purchase tokens or unnecessary sensitive information.
Legal-site trafficIP address, request URL, timestamp, browser/device and security metadata.Cloudflare processes limited traffic logs to deliver and protect these static legal pages. We do not place our own advertising or analytics cookies on these pages.

Device permissions and user-directed transfers

  • Microphone: requested only when you choose to record a pledge voice note. The recording remains local.
  • Photos/media picker: used only when you choose an attachment; the selected image remains local.
  • Notifications: used for local deadline reminders on your device. If cloud notifications are introduced, this Policy and store disclosures will be updated before release.
  • Calendar and sharing: when you choose these actions, Android sends the details you selected to the calendar or sharing application you choose. That recipient processes the data under its own policy.

3. Public and shared content

Honor Pledge includes user-generated and social features. Your visibility choice controls how pledge text is displayed:

  • Public: the pledge text and relevant public result information may appear in Heroes Halls and may be seen, reacted to, reported or shared by other users.
  • Witnesses-only: the pledge text is available to people who obtain the witness code for that pledge. The public Hall entry can show non-text result information, but the pledge text is hidden.
  • Private: the pledge text is not shown to other users. If an entry qualifies for a Hall, its text is hidden while permitted non-text result statistics may remain visible.

Public or shared data can include display name, rank, pledge/payment amount, status, attempt count, witness count, reactions, public Townhall appearance, Townhall code and salutes. You can change pledge and Townhall visibility in the app. A change affects future display after synchronization, but it cannot erase copies, screenshots or shares already made by other people.

We may mask words in public pledge text, investigate reports, restrict visibility, remove content or suspend accounts to enforce safety rules, store policies, legal obligations and our Terms or Community Rules. We do not use solely automated decisions that produce legal or similarly significant effects. Automated calculations may determine ranking, duplicate-vote prevention and in-app progression.

4. Purposes and legal bases

Where the GDPR or similar law applies, we rely on the following bases:

  • Performance of a contract: to create and authenticate accounts, save and synchronize pledges, provide Witness/Heroes/Townhall features, process user-requested visibility changes, verify purchases and provide support.
  • Legitimate interests: to secure the service, prevent duplicate voting and fraud, diagnose crashes, maintain basic product analytics, moderate content, enforce our rules, defend legal claims and improve reliability. We balance these interests against your rights and apply data minimization.
  • Consent: where applicable law requires consent for non-essential analytics, attribution, device access or similar technologies. You may withdraw consent without affecting earlier lawful processing. A store release must present any consent control required in your location before activating the affected technology.
  • Legal obligation: to comply with tax, accounting, consumer-protection, privacy, lawful-request and app-store obligations.
  • Protection of rights and safety: where necessary to establish, exercise or defend claims, respond to abuse or protect users and the public.

5. Who receives data

We disclose data only as described below and only to the extent needed. Service providers are contractually or legally required to use data for the instructed service and to apply protections consistent with this Policy and applicable law.

RecipientRole and dataMore information
Supabase, Inc.Cloud database, authentication and server functions; account, pledge, community, progression and transaction-verification data. The primary project region is EU West (Ireland).Privacy · DPA
Google LLC / FirebaseAnalytics and Crashlytics; technical identifiers, app events, crash and diagnostic data. Google Play separately processes store purchases and may provide transaction status to us.Firebase privacy · Google Privacy Policy
AppsFlyer Ltd.Installation attribution, campaign measurement and fraud protection; installation/App Set identifiers, IP/network metadata, device/app information and allow-listed events.Services Privacy Policy · Opt-out
Apple Inc. / App StoreIf an iOS version is offered, Apple processes downloads and purchases and provides transaction status needed for entitlement and support.Apple Privacy Policy
Cloudflare, Inc.DNS, delivery, security and hosting of these legal pages; IP address and limited HTTP/security logs.Privacy Policy
Other users and user-selected recipientsPublic or Witnesses-only information according to your settings; calendar/share applications receive only content you choose to send.Your visibility and sharing choices control the transfer.

We may also disclose information when reasonably necessary to comply with law or valid legal process, investigate fraud or abuse, protect rights or safety, or complete a merger, financing, acquisition, reorganization or sale. In a business transfer, the recipient must continue to respect this Policy or provide legally required notice and choices.

6. International transfers

Our primary Supabase database is hosted in the European Union. Some providers operate globally and may process data outside your country, including in the United States or Israel. Where required, we use provider data-processing terms, the European Commission's Standard Contractual Clauses, adequacy decisions or another lawful transfer mechanism. You may contact us for information about the relevant safeguards.

7. Retention

We keep personal data only for as long as needed for the purposes above, then delete or de-identify it, subject to technical and legal limits:

  • Account, pledges, votes, reactions and progression: while the account is active. They are removed from our active application database when the account is deleted, unless a limited record must be retained for law, refunds, security or dispute resolution.
  • Local photos and voice notes: until you remove them, delete the account from that device, clear application data or uninstall the app. A web deletion request cannot remotely erase files that never left your device.
  • Public content: while the account/content remains active and public. Visibility changes stop future public display after synchronization; cached or independently copied material may persist outside our control.
  • Reports and moderation records: for as long as reasonably necessary to investigate, prevent repeat abuse, document enforcement and resolve disputes, ordinarily no longer than 24 months after closure unless a longer period is required for an active issue or by law.
  • Crashlytics: Google states that crash stack traces and associated identifiers are retained for 90 days before removal begins.
  • Firebase Analytics: retained according to the configured Google Analytics property retention setting and any aggregate-reporting rules; user-level event data will not be configured for longer than 14 months without updating this Policy and the applicable controls.
  • AppsFlyer: AppsFlyer states that end-user data is retained for no more than 24 months unless we direct otherwise or law permits/requires longer. We may request a shorter period or deletion where appropriate.
  • Security and deletion records: a minimal deletion tombstone or anti-abuse record may be kept for the lifetime of previously issued sessions plus a limited retry/security period, ordinarily no longer than 90 days, unless a longer period is required to investigate abuse or comply with law.
  • Purchases and legal records: store transaction and accounting records may be retained for the period required by tax, consumer, refund, fraud-prevention or accounting laws. Where possible, they are separated from the deleted account or minimized.
  • Support correspondence: normally up to 24 months after the matter closes, longer if necessary for an unresolved dispute or legal obligation.

Providers may keep limited backups or security logs for their documented deletion cycles. Data removed from active systems may remain in protected backups until those backups rotate and is not restored except for disaster recovery, security or legal necessity.

8. Your choices and privacy rights

Depending on your location, you may have rights to receive information, access, correct, delete, restrict or object to processing, withdraw consent, and obtain portable data. You may also have the right to complain to a supervisory authority and not be discriminated against for exercising privacy rights.

  • Change pledge or Townhall visibility inside the app.
  • Decline optional microphone, photo or notification permissions in device settings; the related optional feature will not work.
  • Request access, correction, export, restriction, objection or deletion by emailing alsvarel.developer@gmail.com.
  • Use AppsFlyer's device opt-out for AppsFlyer measurement.

We may ask for information reasonably necessary to verify that you control the relevant account. We aim to respond within one month where the GDPR applies and within other time limits required by applicable law. If you are in the EEA, you may complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local authority.

United States disclosures. We do not sell personal information for money and do not use sensitive pledge content for targeted advertising. We use limited device/app activity data to measure our own advertising and product performance. If a jurisdiction treats a future advertising integration as a “sale,” “sharing,” or targeted advertising, we will provide the required notice and opt-out before enabling it. California residents may request access, correction or deletion and may exercise applicable opt-out/limitation rights without discrimination.

9. Account and data deletion

The fastest method is inside Honor Pledge: open Profile, open the settings/ledger panel, choose Delete account and data, and confirm. The app requests deletion of the server account and associated application records and erases private pledge photos and voice notes from that device.

You can also submit a request outside the app through our dedicated page. Web requests may require verification and cannot remotely erase local-only media from a device.

10. Security

We use measures designed to protect data, including HTTPS/TLS in transit, authenticated server requests, database row-level access controls, least-privilege server secrets, one-way installation hashes, rate limits, replay protection for purchases and duplicate-vote controls. We keep local media out of cloud and analytics payloads, do not include payment-card credentials in the app, and sanitize developer-supplied crash messages.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we investigate suspected incidents and provide legally required notices. Contact us promptly if you believe your account or data may have been compromised.

11. Age requirement, minors and parents

Honor Pledge is intended for people aged 13 and older. The first-run screen asks for a broad age range, not a birth date. A person who selects under 13 cannot complete setup. We do not knowingly offer the service to, or collect personal data from, children under 13.

If you are under the age at which you may independently consent to data processing in your country, a parent or legal guardian must review this Policy and authorize any processing that relies on consent. In the Netherlands that age is generally 16. Core account, security and service operations may instead rely on contract, legitimate interests or legal obligations as described above.

For users aged 13-17, a parent or guardian should review the public visibility, Witness, community and Honor Payment features with the user. Public pledges can be read, reacted to, reported, shared or captured by other people. Honor Payments are never automatic and each store purchase requires an affirmative Google Play or App Store confirmation; available family approval controls are administered by the relevant store account holder.

We do not request a minor's school, precise location or parental contact details. Optional pledge photos and voice notes remain on the device. Analytics and attribution use the limited technical data described in this Policy and are not supplied with pledge text, display name, email address, witness code or local media.

A parent or guardian who believes that a child under 13 created an account, or who wants to exercise privacy rights for a minor, may contact alsvarel.developer@gmail.com. We may request proportionate information to verify the request and relationship, and will delete or restrict the data as required by law. A self-declared age range does not replace verifiable parental authorization where applicable law specifically requires it.

12. Changes and contact

We may update this Policy when the product, providers or law changes. We will revise the date above and, for material changes, provide an appropriate notice in the app or by another available channel. Material changes will not be applied retroactively where consent is legally required.

Questions, complaints and privacy requests:

Karalko Aliaksei
Ijslandstraat 11
1363 DR Almere
Netherlands
alsvarel.developer@gmail.com