Privacy Policy
Lenswalker is a small hobby project. We only process the data the game needs to work, we run the photo AI on our own hardware, and we do not use ads, cookies or third-party trackers. This page explains the details.
1. Data Controller
The data controller for this website and the Lenswalker app is:
Daniel Maksymilian Syrnicki
Hauptstraße 35
55569 Monzingen
Germany
Email: daniel@lenswalker.online
2. Data We Collect
2.1 Account Data
When you register, we collect:
- Username (your choice). It is also your public player name.
- Password (stored only as a bcrypt hash, never in plain text)
- The activation code you registered with
- Email address (optional): you can add one later in your profile settings if you want password recovery. We confirm it with a verification link.
2.2 Game Data
During gameplay, we store:
- Game progress (level, experience points, mana and mana storage)
- Collected elements and essence, element mastery
- Daily activity (streak system), daily challenges
- Items, achievements and titles
- Your app language (English or German), so the Oracle answers in your language
2.3 Location Data
Lenswalker charges mana when you walk. For this, the app uses your device's location, but only after you allow it in your browser, and only while the app is open.
- Walking distance: while you walk, the app sends your position (latitude, longitude, accuracy) to our server every few seconds. The server only keeps your most recent position and its time to calculate the distance to the next one. Each update overwrites the previous one; we do not store a route history.
- Where a photo was taken: when you take a photo, the app saves your current position with it. When you reveal the photo, the location is stored with the discovery and shown on your personal Grimoire map.
- If you share a discovery as a post (in the public feed or in your guild hall), the location is not sent with it. Other players don't see it.
2.4 Photos and Discoveries
- Photos you take first go to the Film Roll, which is stored only on your device (in your browser's IndexedDB, up to 20 photos). Nothing is uploaded at this point.
- When you reveal a photo, it is uploaded to our server and stored there. Before the upload, the app scales the photo down and re-encodes it in your browser, so no embedded camera metadata (EXIF) is uploaded. After the server confirms the discovery, the photo is deleted from the Film Roll on your device.
- The AI analysis result is stored with the photo: subject, rarity, element, capture quality and a short flavor text (see section 5).
- Photos are loaded from addresses that contain a long random part and can be opened without logging in, because the app's image display cannot send login data. Anyone who has the exact address of a photo can view it.
2.5 Public Profile, Leaderboards and Community
Lenswalker has social features. The following is visible to other players, and parts of it also to visitors who are not logged in:
- Public profile: player name, level, streak, main element and mastery, equipped title, guild name and tag, bio (if you add one), number of posts, likes, followers and followed players
- Leaderboards: player name, level, experience points, number of discoveries, streak, essence per element, title and guild tag
- Posts you share to the community feed, with caption and hashtags (public, also visible without login)
- Comments on posts, including @mentions of other players
- Likes on posts
- Follow relationships (who you follow, who follows you)
We also store in-app notifications for you (for example new followers, likes, comments, replies, mentions, new posts from players you follow, milestones and item drops).
2.6 Guilds
If you found or join a guild, we store your membership, your role, the essence you invested in the guild fortress and any join requests. Guild name, tag, description and ranking are visible to all players. Only guild members can see:
- Messages in the guild chat
- Discoveries shared in the members-only guild hall, and likes on them
2.7 Push Notifications (optional)
If you turn on push notifications (the app asks, and you can also switch them on in your profile settings), your browser creates a push subscription and we store:
- The push endpoint: an address at your browser vendor's push service (for example Google, Apple or Mozilla) that identifies your browser on this device
- The encryption keys belonging to this subscription
- Your app language (for the text of the notifications) and your device's time zone (so we do not send notifications at night, 22:00 to 08:00 your local time, and can send streak reminders in the evening)
- When the subscription was created and when a notification was last delivered successfully
We send push notifications for comments, replies, mentions and new followers, for guild activity (chat, guild posts, join requests, fortress upgrades) and as reminders (mana full, streak about to end). The content of a notification is end-to-end encrypted on its way through the push service. How the push service works is explained in section 6.
You can turn push notifications off at any time in your profile settings or in your browser settings. Logging out also turns them off for that device. Subscriptions that the push service reports as expired are deleted automatically, and we keep at most 5 devices per player.
2.8 Usage Events
To understand whether new players get started successfully and whether they come back, the game records a few simple events in our own database, linked to your player account:
- Sent by the app: app opened (at most once per day), photo taken, introduction finished, tutorial finished, push notifications declined, invite code shared, app added to the home screen
- Recorded by the server: registration (with the kind of code used: admin, waitlist or friend invite), push notifications turned on, guild founded, guild joined, reminder email sent
Each event only contains its name, the time and, for some events, a short detail like the code type. There are no third-party analytics tools, no advertising IDs and no device fingerprinting.
2.9 Invite Codes
Registration requires an activation code. After your first reveal, you get three codes to invite friends. We store which code was used by which account, so you can see the player name of friends who registered with your codes.
2.10 Safety Data
To maintain community safety:
- Block list (accounts you've blocked, private, only visible to you)
- Reports you submit about posts or comments (reason and optional explanation)
2.11 Waitlist Data
If you request an invite on our landing page:
- Email address
- Signup source (which page or form)
- Signup date and the date an invite was sent
We send your activation code to this address right away. The operator also receives a short email notification about each new signup. Waitlist entries are separate from game accounts and are used only to send invites. The form contains a hidden field to filter out automated spam signups.
2.12 Technical Data
For security and functionality:
- IP address (temporary, for rate limiting)
- Browser information (User-Agent)
2.13 Emails
If you have added an email address, we send you account emails (email verification, password reset). If you have not played for a while, we may occasionally send you an email about what has changed in the game. We never sell or share your email address.
2.14 Feedback
When you send feedback in the app (Profile → settings → Send feedback), we store your message, the type you chose (bug, idea, other) and your player account. Sent along automatically: app version, browser and device (user agent), screen size, app language, the current screen, whether the app is installed and online, and the app's most recent error messages. The form says so. You can optionally attach up to two screenshots; they are downscaled, stored and attached to the email to the operator. The feedback is also emailed to the operator (through the email service in section 6.1), with your email address if you have added one, so we can reply.
3. Purposes and Legal Bases
We use your data exclusively for:
- Providing and operating the game (account, game progress, location for walking and the map, photos and AI analysis, social features, guilds, notifications, invite codes, account emails): Art. 6(1)(b) GDPR (performance of the contract, i.e. the terms of use of the game).
- Push notifications: your consent, Art. 6(1)(a) GDPR. You can withdraw it at any time by turning push off.
- Location and camera access: only after you allow it in your browser. The browser permission can be revoked at any time; without location, walking does not charge mana.
- Feedback: handling your bug report or suggestion, Art. 6(1)(b) GDPR (the game's terms of use) and our legitimate interest in a bug-free game, Art. 6(1)(f) GDPR.
- Protection against abuse (rate limiting, blocks, reports, spam filter) and usage events to improve the game: our legitimate interest in a secure, working game, Art. 6(1)(f) GDPR.
- Occasional emails to inactive players: our legitimate interest in letting players know about changes, Art. 6(1)(f) GDPR. You can object at any time by replying to the email or writing to us.
- Waitlist: sending the invite you requested, Art. 6(1)(b) GDPR (steps prior to entering into a contract at your request).
3.1 Voluntary Data Provision
Providing your data is entirely voluntary. You can play the game with just a username and password. Email is optional and only needed if you want password recovery. Location access is needed to charge mana by walking; push notifications are optional. If you choose not to provide certain data, you can still use the core game features.
4. Retention Periods
There is currently no button to delete your account in the app. Email us and we will delete your account and the data linked to it.
- Account data and game progress: until your account is deleted
- Photos and discoveries (including their location): until you delete them or your account is deleted
- Last walking position: overwritten with every location update
- Film Roll: on your device until the photo is revealed or you delete it
- Social data (posts, comments, likes, follows, bio): until you delete them or your account is deleted
- Guild chat messages: until the guild is disbanded, or until you ask us to delete them
- In-app notifications: deleted automatically after 30 days
- Push subscriptions: until you turn push off, log out on that device, or the push service reports the subscription as expired
- Usage events: deleted automatically after 12 months, at the latest together with your account
- Feedback (including screenshots): deleted automatically after 12 months, at the latest together with your account; the email to the operator is deleted once the matter is resolved
- Technical data (IP): Maximum 7 days (for security)
- Waitlist entries: kept (marked as invited) until you request removal
5. AI Image Analysis (Automated Decision-Making)
Your photos are analyzed by an AI (Qwen3-VL) that runs on our own hardware. Images are not sent to external services or third-party AI providers and are not used for AI training. For players who use the app in German, the AI's text answer (subject and flavor text) is translated into German, also on our own hardware.
5.1 How the AI Works
The AI automatically determines:
- Rarity score (1-10) based on the subject photographed
- Element type based on colors and context
- Capture quality based on photo composition
5.2 Consequences of AI Decisions
These automated decisions affect your gameplay: higher rarity and quality scores result in more experience points (XP) and essence. There is no human review of individual AI decisions. The decisions only affect the game; they have no legal or similarly significant effect on you.
5.3 Your Rights Regarding AI Decisions
If an analysis fails, you can retry it. If you believe an AI decision was incorrect, you can contact us for review.
6. Data Storage and Recipients
All data is stored on servers in Germany. We do not sell your data and do not share it with advertisers. Your data only reaches the services listed below, and only as far as needed for the respective function.
6.1 Email Service
For emails (activation codes, email verification, password reset, occasional game news for inactive players), we use Mailjet, a French company with EU data centers in Belgium. Mailjet is GDPR compliant. If Mailjet is unavailable, emails are sent through our own mail server.
6.2 Push Services of Browser Vendors
Push notifications can only be delivered through the push service of the browser you use; your browser chooses it. We only accept push services of Google (Firebase Cloud Messaging: Chrome, Edge, Android), Mozilla (Firefox), Apple (Safari, iPhone and iPad) and Microsoft (Windows). The push service receives the encrypted notification, your push endpoint and technical data such as the time of delivery; it cannot read the content. These companies may process data outside the EU, for example in the USA. Their own privacy policies apply to the push service.
6.3 Map Tiles
The Grimoire map in the app loads map images from the tile servers of OpenStreetMap (OpenStreetMap Foundation, United Kingdom). When you open the map, your browser requests the map area it shows. This transmits your IP address and the map area to OpenStreetMap. The United Kingdom has an EU adequacy decision. See the OpenStreetMap Foundation privacy policy.
7. Cookies, Tracking and Your Device
This website and the app use no cookies and no third-party tracking services like Google Analytics. The only usage statistics are the first-party events described in section 2.8.
The app stores the following in your browser. It is strictly necessary for the functions you use:
- localStorage: your login token (so you stay logged in; it is only sent to our own server), settings such as language, whether you have completed the introduction and tutorial, a pending reveal if the app is closed during one, and results of reveals you haven't looked at yet (for up to 48 hours)
- IndexedDB: your Film Roll photos with their capture location (see section 2.4)
- Service worker cache: app files, so the app loads quickly and works offline
You can delete this data at any time in your browser settings; you will then be logged out and unrevealed Film Roll photos are lost.
8. Your Rights (GDPR)
You have the following rights regarding your data:
- Access: You can request what data we store about you
- Rectification: You can have incorrect data corrected
- Erasure: You can request deletion of your data
- Restriction: You can request that we restrict processing of your data
- Data Portability: You can request your data in a portable format
- Objection: You can object to processing based on our legitimate interest (section 3), for example usage events or reminder emails
- Withdraw consent: You can withdraw consent at any time, with effect for the future
For all requests, contact us at: daniel@lenswalker.online
8.1 Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. For Germany, you can contact the Federal Commissioner for Data Protection:
BfDI (Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit)
Graurheindorfer Str. 153, 53117 Bonn
Website: www.bfdi.bund.de
9. Data Security
We protect your data through:
- Encrypted transmission (HTTPS/TLS)
- Secure password storage (bcrypt hash)
- Signed login tokens (JWT) that expire after 7 days
- Rate limiting against attacks
- End-to-end encrypted push notification content
10. Minimum age
You must be at least 16 years old to use Lenswalker (Art. 8 GDPR); you confirm this when you register. We do not knowingly collect data from younger people. If you learn that someone under 16 has an account, please contact us and we will delete it.
11. Changes
We reserve the right to update this privacy policy. Significant changes will be published on this page.