Document 01 · public-us-1.1

Privacy Policy

This Policy explains what Orillon collects, why it is used, which providers receive it, and how to exercise your choices and deletion rights.

Effective 17 August 2026
Version public-us-1.1
Scope Orillon iOS · US

Privacy Policy

English · United States release
01

Who controls your data

The controller of personal data processed through Orillon is Czumin Wojciech Szumiński, a sole proprietorship operated by Wojciech Szumiński and registered in Poland's Central Register and Information on Economic Activity, CEIDG.

The same email is the privacy request address. Orillon is offered through the United States App Store, but the controller is established in Poland.

02

Scope and age

This Policy covers the Orillon iOS app, its account and subscription services, this legal and support website, and support messages sent to us. Orillon is intended only for people aged 18 or older. We do not knowingly offer the service to children.

Before Orillon creates or restores a Supabase account or starts PostHog release checks, optional product analytics, or Sentry diagnostics, the first-run screen asks you to declare that you are 18 or older, agree to the Terms of Use and field-safety rules, and acknowledge this Privacy Policy. An under-18 declaration does not create an Orillon account and does not allow the service to start.

03

Data we collect

Depending on how you use Orillon, we process the following categories:

  • Account and identity data. A pseudonymous Supabase user ID, authentication and security metadata, and, if you use Sign in with Apple, the Apple account identifier and any name, email address, or private relay address Apple provides with your authorization.
  • Profile and preferences. Your chosen codename, training skills, self-selected coarse terrain, training cadence, onboarding state, notification choice, and narration preference.
  • Training and progress data. Mission and drill identifiers, steps, choices, outcomes, deterministic scores, completion status, timings, latency, timezone, event IDs, and related synchronization evidence.
  • Purchase and entitlement data. Product, subscription, receipt, transaction, entitlement, trial and renewal status, store environment, founding cohort status, and pseudonymous purchase lineage received from Apple and RevenueCat. We do not receive your full payment card number.
  • Technical and usage data. App and build version, operating system and device class, manually approved product interaction events, feature flag results, crash and performance diagnostics, IP address and ordinary HTTP or security metadata handled by our providers.
  • Support data. Your email address, message, attachments, and any troubleshooting details you choose to send.

We collect data from you, your use of the app, Apple, RevenueCat, and the providers listed below.

The app separately keeps a versioned first-run record in its local SQLite database. It records the adult declaration, accepted Terms and safety version, acknowledged Privacy Policy version, optional analytics and diagnostics choices, decision time, and receipt schema version. The installation-local record contains no account identifier, and Orillon does not upload it as a consent receipt. It remains until you uninstall the app or a required document-version change asks you to review the choices again.

04

Field notes and data we do not request

Free-text field-report prose is designed to remain temporary in app memory and is not intentionally uploaded to Orillon. Your device keyboard, dictation service, or a share destination you select may process what you type under its own policy. Avoid entering names or sensitive details about other people.

The current release does not ask Orillon for precise GPS location, contacts, camera or photo-library access, microphone recordings, advertising identifiers, public posts, or remote-push tokens. It does not sell personal data, act as a data broker, use cross-context behavioral advertising, or serve targeted ads.

05

How and why we use data

  • create and secure your account and link an Apple identity you choose;
  • deliver missions, drills, progress, export, synchronization, and personalization;
  • process purchases, verify entitlement, restore access, and prevent fraud;
  • operate release controls, diagnose faults, protect the service, and enforce Terms;
  • measure a limited onboarding and training funnel and improve the product;
  • answer support, privacy, safety, and legal requests; and
  • meet tax, accounting, consumer, security, and other legal obligations.

Where European data-protection law applies, our legal bases are performance of our contract with you, our legitimate interests in operating, securing and improving a proportionate service, compliance with legal obligations, and consent where we ask for it. You may object to processing based on legitimate interests by contacting us; we will assess the request under applicable law.

06

Analytics, diagnostics, and automated output

After the required first-run choices, Orillon uses PostHog to retrieve essential release, incident-stop, minimum-build, and content-suppression flags. These checks use a pseudonymous device identifier and ordinary network metadata, but do not send product analytics or feature-flag exposure events when optional analytics is off. Disabling product analytics does not disable these release-safety checks.

Product analytics and crash diagnostics are independent and off by default. If you enable product analytics, PostHog receives only a closed set of manually approved product events and limited properties. Autocapture, session replay, surveys, person profiles, advertising use, and location enrichment remain disabled. If you enable crash diagnostics, Sentry receives crash reports and sampled performance diagnostics. Default personal-information collection, screenshots, view hierarchy, session replay, request bodies, app breadcrumbs, and automatic network tracing remain disabled in our Sentry configuration. Orillon does not initialize Sentry reporting before that choice is enabled.

You can refuse either optional choice without losing training, purchase, export, or deletion access. Change either choice later in Config → Privacy. Turning a choice off stops new optional capture; it does not erase information already received by a provider. Account deletion or a privacy request provides the broader deletion route described below.

Orillon calculates training scores and learning feedback using deterministic rules. The launch release does not send your prompts or field prose to a conversational AI provider, and it does not make decisions that produce legal or similarly significant effects about you.

07

Providers and recipients

We use the following providers to operate Orillon:

  • Supabase for authentication, database, storage, and server functions;
  • RevenueCat for subscription and entitlement infrastructure;
  • PostHog for essential release flags and, only if enabled, limited product analytics;
  • Sentry for optional crash diagnostics and sampled performance monitoring;
  • Expo for app builds, compatible updates, and this website's hosting;
  • Cloudflare as part of website delivery and security; and
  • Google for the Gmail support inbox.

Apple processes App Store, Sign in with Apple, purchase, billing, refund, and device information under Apple's Privacy Policy. We may also disclose information when required by law, to protect rights or safety, or in connection with a business reorganization subject to appropriate safeguards. Orillon sends data to these providers for the purposes listed above. Each provider also operates under its own terms and privacy information linked above, and some platforms may act independently for parts of their processing. You may ask us for the provider and account records we hold.

08

International processing

The controller is in Poland, the app is offered in the United States, and providers may process data in the United States, European Economic Area, or other regions in which they operate. Where transfer protections are required, applicable provider terms may rely on adequacy decisions, standard contractual clauses, or other lawful mechanisms. You may ask us which information we currently hold about a specific transfer. We do not claim that every provider path stays in one region.

09

Retention

We use purpose-based retention rather than one period for every record. Active account, profile, progress, and entitlement data is kept while your account exists and as needed to provide the service. Export sessions stop working after one hour and are removed on a later export or account cleanup. Support records are kept while the matter is open and afterward only as needed for security, legal claims, or compliance.

Technical telemetry, provider logs, and backups follow the retention and rotation settings available in each service. Periods differ, and copies may persist until expiry or overwrite. We use purpose-based deletion or expiry and aim to select the shortest practical periods, but provider backup timing may be outside our direct control. Purchase, accounting, fraud-prevention, security, and legal records may be retained for the period required or permitted by applicable law. When data is no longer needed, we delete it, detach it from the active account, or anonymize it as appropriate.

The local first-run record remains on the installation so Orillon can apply the current document versions and privacy choices. Because it contains no account identifier, it may remain after account deletion and is removed when you uninstall the app or when Orillon replaces it after a required document-version review. Information already sent after an optional choice follows the provider and deletion rules above rather than the lifetime of the local switch.

10

Export and account deletion

In Orillon, open Config → Account to export your data or delete your account. Deletion removes the active authentication account, profile, personalization, and mutable progress from our live account systems and clears local account state from the device when cleanup succeeds. The installation-level first-run choice record described above contains no account identifier and may remain so a new account on the same installation does not repeat unchanged notices.

Limited pseudonymous measurement receipts, ingest and erasure evidence, transaction hashes, purchase lineage, and records needed for integrity, security, restore, refunds, chargebacks, accounting, or legal obligations may remain. Apple and RevenueCat may retain purchase records under their own responsibilities. Email us if you want a broader deletion review. Deleting the app or Orillon account does not cancel an Apple subscription. Manage billing separately at Apple Subscriptions.

11

Your privacy choices and rights

Subject to applicable law, you may request access, a portable copy, correction, deletion, restriction, or information about disclosure; object to certain processing; withdraw consent where consent is the basis; and appeal or complain to a regulator. We do not discriminate against you for exercising a privacy right.

Email wojciechszuminski0@gmail.com with the subject “Privacy request.” We may verify your identity and an authorized agent's authority before acting. You may also complain to the President of the Polish Personal Data Protection Office or another competent authority.

You can change notification permission in iOS Settings. This website has no client-side analytics, optional cookies, forms, or browser storage. Because Orillon does not use cross-site advertising tracking, browser “Do Not Track” signals do not change its behavior.

In the app, open Config → Privacy to enable or disable Product analytics and Crash diagnostics independently. Both are off until you enable them, and refusing or withdrawing either choice does not reduce core service access. Essential PostHog release-safety checks continue without product-event capture. The Privacy Policy and Terms of Use remain available under Config → Legal & Support.

12

Security

We use access controls, transport encryption, row-level database controls, pseudonymous identifiers, restricted event fields, and server-side entitlement checks. No system is completely secure, so please use device security, keep your Apple account protected, and contact us if you suspect unauthorized access.

13

Policy changes

We may update this Policy when the product, providers, law, or release territory changes. We will post the new version and effective date here and provide additional notice when required. Material new collection or use may require a new choice before it begins.

14

Contact

Questions, privacy requests, and complaints can be sent to wojciechszuminski0@gmail.com. See the Support page for billing, account, and technical help.