ShroomShroom Privacy Policy
Effective: 04.09.2026 · Version 1.1
1. Controller
ARC Baltic OÜ, registry code 10741973, Tammeallika, Rätsepa küla, 86816 Tori vald, Pärnu maakond, Estonia ("we"). Data protection contact: shroom@shroomshroom.app. You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or your local supervisory authority.
2. What we collect
Account: email, display name, handle, guardian link for junior accounts, settings, consent records. Finds: your photographs; EXIF metadata from them, including precise GPS coordinates, timestamps and camera data; the reverse-geocoded place names we derive; species suggestions returned by our identification provider and your confirmations/corrections; evidence and condition inputs; scores. Verification (only when a feature requires it): the pass/fail or age-band result and a reference code from VerifEye. The verification image itself is processed by VerifEye and deleted once the result is produced; we do not receive or store it. Fraud-prevention retention: see section 6. Social: leagues, memberships, friend connections, share images you generate. Technical: device/browser type, app version, IP address, server logs, crash reports. We use privacy-preserving analytics only, with no cross-site tracking and no advertising networks. Payments (future): handled by a payment provider; we store order and invoice data, never full card numbers.
We do not collect contacts, background location, or advertising identifiers. Location comes from photo EXIF you upload, from the location you tag, or coarsely from your IP address.
3. Why, and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Running the game: accounts, cards, hunts, leaderboards, sharing | account, finds, social | Art. 6(1)(b) contract |
| Species identification via Kindwise (photos + coordinates + date sent to the API) | find photos, GPS, time | Art. 6(1)(b) contract |
| Reverse geocoding of place names (In-ADS/Maa-amet) | GPS | Art. 6(1)(b) contract |
| Protected-area handling (showing park name instead of location) | GPS | Art. 6(1)(b) + 6(1)(c) where law requires |
| Improving identification: training and evaluating recognition models on photos + observation records | finds (pseudonymised for training) | Art. 6(1)(f) legitimate interest, with opt-out (Settings → "Model improvement") |
| Licensing pseudonymised research datasets to third parties | finds, pseudonymised, coordinates truncated to 3 km, protected areas to area name | Art. 6(1)(f) legitimate interest, with opt-out (Settings → Privacy → "Research datasets") |
| Age/identity verification result | result + reference code | Art. 6(1)(c) where law requires age checks; otherwise 6(1)(b) |
| Optional research programme on verification images | verification images of consenting adults | Art. 6(1)(a) + Art. 9(2)(a) explicit consent, collected in-app, withdrawable, never a condition of use |
| Fraud and abuse prevention | technical data, verification metadata | Art. 6(1)(f) legitimate interest |
| Service emails (league digests, flush alerts you enabled, account notices) | account | Art. 6(1)(b); marketing only with consent, Art. 6(1)(a) |
| Legal obligations (accounting, requests from authorities) | order data, records | Art. 6(1)(c) |
Legitimate-interest assessments for the two (f) items are kept on file and available to supervisory authorities on request.
4. Who receives data (processors and recipients)
| Recipient | Role | Data | Location |
|---|---|---|---|
| Supabase (hosting, auth, storage) | processor | all service data | EU |
| Kindwise s.r.o. (mushroom.id) | processor | find photos (resized), GPS, timestamp | EU |
| Realeyes OÜ (VerifEye) | processor | verification image (transient), result | EU |
| Maa-amet In-ADS | public service | coordinates for geocoding | EE |
| Email delivery provider | processor | email, name | EU |
| Payment provider (future) | independent controller | payment data | EU |
| Other players | recipients | what sections 4.3/9 of the Terms describe: username, scores, cards and hunt maps including find locations, public by default until you make them private | — |
| Dataset licensees | recipients | pseudonymised observation records per Terms 4.4 | worldwide, under licence terms forbidding re-identification |
Transfers outside the EEA, if any, use adequacy decisions or standard contractual clauses.
5. Retention
Headline: your account and Content are kept until you delete them, so returning players keep their collection, subject to a 10-year inactivity limit with reminders. The full schedule is in the Retention Schedule document (part of this policy). Key clocks: verification results 12 months; suspected-fraud verification data 30 days; server logs 12 months; accounting records 7 years (Estonian Accounting Act); deleted accounts purged from live systems within 30 days and from backups within 90 days. Pseudonymised records already included in released research datasets or trained models are not recalled by deletion, but are excluded from future releases.
6. Verification details
Verification is performed by VerifEye under its own notice shown at the moment of verification. The image is analysed to produce a result and deleted; neither we nor VerifEye retain it, except that where spoofing or fraud is suspected, the attempt (metadata and, where strictly necessary, the image) may be kept for up to 30 days solely for investigation, then deleted. Verification images are used for model training only under the separate opt-in research programme (Terms 7.4), which is limited to adults, off by default, and withdrawable with forward-effect deletion.
7. Children
Junior accounts (13–17) require a linked guardian who consents and can review and delete the child's data. We do not knowingly serve under-13s; where local law sets a higher digital-consent age, that age applies. Children's data is excluded from third-party dataset licensing and from the verification research programme.
8. Your rights
Access, rectification, erasure, restriction, portability (export of your records and photos in Settings), objection (including to legitimate-interest processing: separate Settings toggles for model improvement and for research datasets, or by email), and withdrawal of any consent without affecting past processing. We answer within one month. Complaints: shroom@shroomshroom.app, or AKI.
9. Security
TLS in transit, encryption at rest, row-level access control, API keys held server-side only, least-privilege access, logging of admin actions. Breach notification per Art. 33/34.
10. Changes
Material changes are announced in-app and by email 30 days ahead, and the current version and its effective date are always shown at the top of this page.
