top of page

# Terms of Service and Privacy Policy, Alpine Launcher

**Effective date:** 25 April 2026  
**Last updated:** 6 September 2026  
**Published at:** https://www.markusmaribu.com/alpinetos

---

## 1. About This Document

This document sets out the Terms of Service ("Terms") and Privacy Policy ("Policy") that govern your use of **Alpine Launcher** (the "App"), a third-party Android home-screen launcher available on Google Play.

The App is developed and published by **Markus Maribu** trading as **Krystall Media** ("we", "us", "our"), a business based in Norway.

By downloading, installing, or using the App you confirm that you have read, understood, and agree to be bound by these Terms and this Policy. If you do not agree, do not install or use the App.

Contact: **markus@krystall.media**

---

## 2. Terms of Service

### 2.1 Licence

Subject to your compliance with these Terms, we grant you a personal, non-exclusive, non-transferable, revocable licence to install and use the App on Android devices that you own or control, solely for your own private, non-commercial purposes. The App is distributed as a paid title on Google Play; this licence applies to copies installed from Google Play. We may verify that licence as described in section 2.2.

You may not:

- copy, modify, adapt, or create derivative works of the App;
- reverse-engineer, decompile, or disassemble the App, except to the extent permitted by applicable law;
- distribute, sublicense, rent, lease, or lend the App to any third party;
- circumvent licence verification or use a copy that was not obtained from Google Play in order to avoid payment;
- use the App for any unlawful purpose or in violation of any applicable laws or regulations;
- remove or obscure any copyright, trademark, or other proprietary notices in the App.

### 2.2 Purchase and Payment

The App is sold as a one-time purchase through Google Play. All payment processing is handled exclusively by Google LLC in accordance with Google Play's billing terms and your agreement with Google. We do not receive, store, or process any payment card or billing information.

**Licence verification.** In release builds we periodically confirm that the App was licensed through Google Play. The App asks Google Play services for a Play Integrity token and sends that token, together with a random request hash, to Alpine's backend (a Supabase Edge Function), which asks Google to decode it. A licensed result is cached on the device for about seven days so the App does not check on every launch. Copies that Google does not report as licensed may see a purchase reminder (dismissible for several hours) and may be unable to enable or open built-in Alpine apps until a valid Play licence is confirmed. Settings and the Alp Store catalogue remain available. This check does not send us your Google account email, payment details, or a persistent device identifier. Debug builds do not show the purchase reminder.

**Refunds** are subject to Google Play's refund policy. Google offers a 48-hour refund window for apps purchased on Google Play. Requests outside that window may be submitted to Google Play support; we have no ability to issue refunds directly. Where Norwegian consumer law or EU consumer law grants you a right of withdrawal beyond Google's standard window, those statutory rights are not affected by these Terms.

### 2.3 Updates and Changes to the App

We may release updates to the App from time to time to add features, fix bugs, or maintain compatibility with new Android versions. Updates distributed via Google Play are subject to these same Terms. We reserve the right to discontinue the App or specific features at any time, with reasonable notice where practicable.

### 2.4 Third-Party Services

The App communicates with the following external services for the purposes described below. Your use of the App constitutes your acknowledgment that these services operate under their own terms and privacy policies, over which we have no control.

| Service | Purpose | Terms / privacy |
|---|---|---|
| **Hugging Face** (huggingface.co) | One-time download of on-device AI model files (speech-to-text) | https://huggingface.co/privacy |
| **GitHub** (github.com) | One-time download of on-device AI model files (text-to-speech) | https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement |
| **WeatherAPI.com** (weatherapi.com) | Current weather, named-place lookup, and city search for the Weather app, called only from Alpine's Supabase Edge Function | [Terms](https://www.weatherapi.com/terms.aspx) |
| **Google Favicon Service** (t1.gstatic.com) | Fetching publication favicons for user-configured RSS feeds | https://policies.google.com/privacy |
| **User-configured RSS feed hosts** | Fetching magazine/news feed content and article images from URLs you add | Varies per host |
| **Supabase** (supabase.com) | Game Center account storage, profile sync, friend graph, game-stats sync, avatar storage, Tappy Duck, High Rise, and Sketch Hop leaderboard scores, Tappy Duck and High Rise multiplayer matchmaking/signaling, Sketch Guess turn-based matches, drawings, messages, guesses, and wallets, Call voice-call setup and WebRTC signaling, Chat messaging (opt-in), FCM device-token storage and push fan-out for Chat / Game Center alerts, the weather proxy/cache used by the notification panel, the Weather app, and Iris, and Play Integrity licence verification | https://supabase.com/privacy |
| **Firebase Cloud Messaging** (Google) | Delivering Chat, friend-request, game-invite, and turn alerts when Game Center or Chat is set up; the App registers an FCM device token with Google and stores it on Alpine's backend | https://firebase.google.com/support/privacy |
| **Google Cloud Vision API** (via Supabase Edge Function) | Automated SafeSearch moderation of Game Center profile photos and Chat image messages | https://cloud.google.com/terms/cloud-privacy-notice |
| **Google STUN** (stun.l.google.com) | NAT traversal for Tappy Duck, High Rise, and Call WebRTC peer-to-peer connections (opt-in, requires Game Center); the STUN server sees your public IP so the two devices can find each other | https://policies.google.com/privacy |
| **Google Play Store** (play.google.com) | Fetching game icon images for the Game Center UI; app distribution and payment processing | https://policies.google.com/privacy |
| **Google Play Integrity API** (via Supabase Edge Function) | Verifying that this installation is a licensed Google Play purchase | https://policies.google.com/privacy |
| **Android Geocoder** (device platform service, often Google on Play devices) | Turning approximate coordinates into a city/country label for Iris "where am I" replies and Weather "here" labels | https://policies.google.com/privacy |
| **Google Search / Wikipedia** | Search queries you start from Limelight Search, opened in your system browser | [Google](https://policies.google.com/privacy) / [Wikimedia](https://foundation.wikimedia.org/wiki/Policy:Privacy_policy) |
| **X (Twitter) or other share targets** | Tweet drafts you confirm in Iris, handed to the installed X app or Android's share sheet | [X](https://x.com/privacy) / varies per app you pick |

We do not receive any revenue share or other consideration from any of these third parties.

### 2.5 Custom Lock Screen

The App offers an **optional** cosmetic lock-screen feature. It is **off by default** and only runs if you turn on **Show on wake** under Settings → Lock Screen.

**This feature is not a security product.** The cosmetic lock screen does **not** replace, bypass, or weaken your device's PIN, pattern, password, or biometric lock. On a device with a secure lock, Alpine only dismisses its own overlay and then asks the **system keyguard** to authenticate you; we do not store or process your lock credentials.

The App provides two related behaviours:

| Mode | When it runs | What it does |
|---|---|---|
| **Show on wake** (Settings → Lock Screen) | Only while you keep the toggle on | A foreground service listens for the screen turning off and shows a cosmetic full-screen UI **over** the system keyguard when you next wake the device |
| **In-launcher boot overlay** | Once per device boot, only when **Show on wake** is **off** | The launcher may show the same cosmetic UI inside the main launcher activity the first time you open it after a reboot |

Enabling **Show on wake** means you acknowledge that:

- The App may run a **foreground service** (with a persistent notification on Android 13+ unless you deny notification permission; the lock screen still works if the notification is hidden, but the service keeps running).
- The App may **start that service after reboot** if the toggle remains on.
- Reliable operation may require you to grant **Display over other apps** in Android Settings; without it the overlay may appear only intermittently.
- The feature may use **additional battery** because the App stays active between screen-off events.
- The **camera shortcut** on the lock screen opens **Alpine Camera** over the lock screen when that built-in app is enabled (live preview uses the Camera permission you grant to Alpine); otherwise it opens your device's **system camera app**. Alpine does not capture photos from the system-camera fallback.

You must not rely on this feature to protect your device or data. We are not liable for loss arising from treating the cosmetic lock screen as a substitute for your device's real lock or security settings.

### 2.5.1 Passcode Lock

The App also offers an **optional** cosmetic **Passcode Lock**. It is **off by default** and only runs if you turn it on under Settings → Passcode Lock.

**This feature is not a security product.** The Alpine passcode does **not** replace, bypass, or weaken your device's PIN, pattern, password, or biometric lock, does **not** encrypt App data, and is **not** a device-encryption credential. It only gates Alpine's own cosmetic lock overlay. The passcode, lockout timestamps, and related toggles are stored **on your device only** and are never transmitted to us.

Enabling Passcode Lock means you acknowledge that:

- You may choose a 4-digit simple passcode or a custom passcode; failed-attempt lockout (if left on) is enforced on-device only.
- You may optionally allow Iris while the Alpine overlay is passcode-locked; that still does not unlock the system keyguard.
- You must not disable your device's real lock in reliance on Alpine's passcode.

We are not liable for loss arising from treating Passcode Lock as a substitute for your device's real lock or security settings.

### 2.6 Voice Calls (Call App)

The App includes an **optional** built-in **Call** feature that lets Game Center friends place voice calls to each other over the internet. Call is **off by default** until you enable it from Settings → Alpine Apps (or the Alp Store) and have completed Game Center setup.

**Call is not a telephony service.** It does not connect to the public telephone network, cannot dial phone numbers, and must not be used to reach emergency services. You must not rely on Call as a substitute for your device's phone app or any carrier-provided calling service.

Enabling Call means you acknowledge that:

- Call requires an **active internet connection** and a completed **Game Center** profile with at least one friend.
- During an active call the App uses the **microphone** to capture and transmit your voice **directly to the other participant** via a peer-to-peer WebRTC audio path; we do not record or store call audio on our servers.
- **Supabase** is used only to set up the call and relay WebRTC signaling until the direct link is established.
- A **local recents log** (friend nicknames and timestamps) is stored on your device only.

We are not liable for loss arising from treating Call as a substitute for real telephony or emergency calling.

### 2.7 Clock App

The App includes an **optional** built-in **Clock** feature (alarms, timers, stopwatch, and world clocks). Clock is **off by default** until you enable it from Settings → Alpine Apps (or the Alp Store).

Enabling Clock means you acknowledge that:

- The App may schedule **exact alarms** so timers and wall-clock alarms can fire while the device is dozing or the screen is off.
- When an alarm or timer fires, the App may show a **full-screen dismiss UI** (including over other apps, if Android grants full-screen intent permission) and may post a **high-priority notification**; vibration and wake locks may be used so the alert is noticeable.
- Alarm and timer settings, world-clock cities, and any **custom tones** you import are stored **on your device only** and are not transmitted to us.
- After a device reboot, the App may **re-arm** enabled alarms and pending snoozes.

Clock is a convenience feature and must not be relied on as the sole means of waking you for safety-critical, medical, or emergency purposes.

### 2.8 Voice Memo

The App includes an **optional** built-in **Voice Memo** feature. Voice Memo is **off by default** until you enable it from Settings → Alpine Apps (or the Alp Store).

Enabling Voice Memo means you acknowledge that:

- The App uses the **microphone** to capture audio you choose to record. Audio is written to files in the App's private storage and is **not** transmitted to us.
- While a recording is in progress the App may run a **microphone foreground service** with an ongoing "Recording" notification so the take can continue if you leave the Voice Memo screen.
- You may **share** a memo through Android's system share sheet; the recipient app then processes that file under its own terms. Sharing is user-initiated only.

Voice Memo is a convenience recorder and is not a secure vault. Recordings stay on the device until you delete them, clear App data, or uninstall.

### 2.9 Weather App

The App includes an **optional** built-in **Weather** feature. Weather is **off by default** until you enable it from Settings → Alpine Apps (or the Alp Store). The notification-panel weather header and Iris weather answers use the same backend path whether or not you enable the Weather app tile.

Enabling Weather (or using weather from the notification panel or Iris) means you acknowledge that:

- Approximate coordinates or a place name / city-search query are sent to Alpine's Supabase weather function, which queries WeatherAPI.com, as described in sections 3.3(b)–3.3(c).
- Saved locations you add in the Weather app (name and coordinates) are stored **on your device only**. Fetching conditions for a saved place still sends those coordinates to Alpine's weather function.
- Weather snapshots may be cached on the device and on Alpine's backend for about one hour.

Weather is a convenience feature. Conditions and forecasts come from a third-party service and may be incomplete or inaccurate.

### 2.10 Work Profile Apps

If your device has an Android **work profile** (a managed profile created by you or your organisation), the App can list launchable work apps alongside personal apps on the home screen, dock, and folders, and in Limelight Search and the A–Z app drawer. Work apps are marked with a work badge on the grid and a "Work Profile" label in the drawer.

**Alpine does not administer, enrol, or unlock a work profile.** The work profile remains under Android and, where applicable, your organisation's device-management policies. The App does not bypass quiet mode, work-profile locks, or IT restrictions. Launching a work app uses Android's standard launcher APIs and may prompt the system to turn work apps on.

Using a work profile with Alpine means you acknowledge that:

- The App runs in your **personal** user. It discovers work apps through Android's public launcher APIs (`LauncherApps`) and does not read work-profile files, email, or accounts.
- Work and personal copies of the same app are treated as separate icons. Placing a work app on the home screen stores a local user identifier on the device so the correct copy is launched.
- Uninstall or app-info actions for a work app are handed to the **system** for that profile.
- Work-profile app names, icons, and home-screen placements stay **on your device only** and are not transmitted to us. Optional Game Center game-library sync uses the personal profile's installed games, not the work profile.
- Your organisation may restrict which work apps are visible or launchable; Alpine cannot override those policies.

We are not your organisation's device administrator and are not responsible for work-profile policies, remote wipe, or IT access to the work profile.

### 2.11 Disclaimers

**The App is provided "as is" and "as available."** To the fullest extent permitted by applicable law, we disclaim all warranties, express or implied, including but not limited to implied warranties of merchantability, fitness for a particular purpose, and non-infringement.

We do not warrant that the App will be error-free, uninterrupted, or free of security vulnerabilities. Features that depend on third-party services (weather, geocoding, push delivery) are inherently dependent on those services remaining available and accurate.

The App is not directed at children under 13 (or under 16 where GDPR sets a higher age of digital consent). Optional social features (Game Center, Chat, and Call) are intended only for users who meet that threshold. Nicknames, profile photos, chat messages, Sketch Guess drawings and messages, and similar user content you submit are licensed to us solely as needed to operate those features, including storage, delivery, moderation, and push alerts, as described in the in-app Game Center and Chat Terms & Conditions.

Nothing in these Terms limits or excludes any warranty that cannot be disclaimed under Norwegian law or applicable EU consumer law.

### 2.12 Limitation of Liability

To the fullest extent permitted by applicable law, we shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of profits, data, goodwill, or other intangible losses, arising out of or in connection with your use of or inability to use the App.

Our total aggregate liability to you for any claims arising under or in connection with these Terms shall not exceed the amount you paid for the App.

These limitations do not exclude liability for death or personal injury caused by negligence, fraud, or any other liability that cannot be limited under Norwegian law.

### 2.13 Governing Law and Disputes

These Terms and any dispute or claim arising out of or in connection with them shall be governed by and construed in accordance with the laws of **Norway**, without regard to conflict-of-law principles.

Any dispute that cannot be resolved amicably shall be subject to the exclusive jurisdiction of the courts of Norway. If you are a consumer resident in the EU/EEA, you also retain the right to bring proceedings in the courts of your country of residence.

The European Commission's Online Dispute Resolution platform is available at: https://ec.europa.eu/consumers/odr/

### 2.14 Changes to These Terms

We may update these Terms from time to time. When we do, we will revise the "Last updated" date at the top of this document and, for material changes, provide notice through the App or Google Play listing. Continued use of the App after changes take effect constitutes your acceptance of the revised Terms. If you do not agree to the revised Terms, you should uninstall the App.

---

## 3. Privacy Policy

This Privacy Policy explains what information Alpine Launcher collects, how it is used, and your rights under the **General Data Protection Regulation (GDPR)** as implemented in Norway via the EEA Agreement and the Norwegian Personal Data Act (*personopplysningsloven*).

**Data controller:**  
Markus Maribu / Krystall Media  
Norway  
markus@krystall.media

### 3.1 Core Privacy Principle

Alpine Launcher is designed to process user data on the device wherever possible. The App contains no analytics SDK, no telemetry, no crash-reporting service, and no advertising code. It does not sell your personal data, broker it, or use it for advertising. We do not receive location, voice audio, notification content, lock-screen or passcode preferences, camera captures, Voice Memo recordings, your list of installed apps (personal or work-profile), or other usage data on our own servers; limited information may be sent **directly from your device** to the third-party services listed in sections 2.4 and 3.3 solely to enable on-demand weather (including Weather-app city search), place-name lookup, platform reverse-geocoding (Geocoder), one-time AI model downloads, RSS feed retrieval, periodic Play licence verification, Limelight web searches you start in your browser, tweet drafts you confirm in Iris, support emails you choose to send, and, if you opt in, the Game Center, Tappy Duck, High Rise, Sketch Hop, and Sketch Guess online features, Call voice calls, Chat social features, and Firebase Cloud Messaging push alerts described in sections 3.3(f)–3.3(o). If your device has a work profile, launchable work apps are listed and launched on-device only as described in section 2.10.

If you enable the optional cosmetic lock screen (**Show on wake**), the App may **run in the background** (as a foreground service) and **start after reboot** while that toggle is on. No lock-screen data is transmitted to us or to third parties. If you enable **Passcode Lock**, the passcode stays on the device only.

Optional built-in apps such as **Clock**, **Compass**, **Calculator**, **I Am Rich**, **Voice Memo**, **Annelida**, and **Contacts** process their data on your device only, except that Contacts shows Game Center friends and sending a friend request still uses the Game Center path in section 3.3(f). Clock may schedule exact alarms, post ringing notifications, and re-arm alarms after reboot; Compass may read orientation sensors and - if you grant location - your approximate coordinates for on-screen display and magnetic declination; Voice Memo stores recordings you make in the App's private storage and may keep a microphone foreground service running while you record; Annelida stores animation and texture preferences and any custom texture images you pick. **Contacts does not read your device address book** and does not request Android Contacts permission; it lists Game Center friends you already added. None of that Clock, Compass, Voice Memo, Annelida, or Contacts-local data is transmitted to us. The optional **Weather** app uses the same off-device weather path described in sections 3.3(b)–3.3(c); saved places stay on the device.

### 3.2 Data That Stays Entirely on Your Device

The following information is accessed or generated by the App and **never leaves your device**:

| Data | Purpose | Permission Required |
|---|---|---|
| List of installed applications (personal user and, if present, launchable work-profile apps) | Populating the home screen, dock, folders, Limelight Search, and app drawer; distinguishing work copies with a badge and label | `QUERY_ALL_PACKAGES` for the personal user (restricted, launcher exemption); work-profile apps via Android `LauncherApps` (no extra permission). Never transmitted. |
| Home-screen layout and app groups | Persisting your personalised configuration, including whether a tile is a work-profile app | None (stored in app's private storage) |
| Recently used apps | Powering the Recent Apps shortcut (home-button double-tap) | Usage access, granted manually in Android Settings |
| Notification content | Displaying notifications in the swipe-down panel | Notification access, granted manually in Android Settings |
| Wi-Fi signal strength (RSSI) | Rendering the signal icon in the custom status bar | `ACCESS_WIFI_STATE` (auto-granted, no prompt) |
| Carrier name and signal level | Rendering the carrier name and mobile signal icon in the custom status bar | None (uses `TelephonyManager` without `READ_PHONE_STATE`) |
| Microphone audio | Capturing speech for the on-device voice assistant (Iris); recording Voice Memos you start | `RECORD_AUDIO`, runtime prompt |
| Voice assistant transcripts and AI responses | Displaying the conversation in the assistant panel | None (held in memory only, cleared on exit) |
| Wallpaper image data | Caching your selected wallpaper | None (stored in app's private storage) |
| App preferences (units, icon packs, language, etc.) | Persisting your settings | None (stored in app's private DataStore) |
| Custom icon overrides | Storing user-assigned custom app icons | None (stored in app's private storage) |
| Music library metadata (titles, artists, album art) | Displaying and playing music you select via the built-in music player | Storage Access Framework, you choose which folders to grant |
| Book / PDF library metadata | Displaying and reading documents you select via the built-in book reader | Storage Access Framework, you choose which folders to grant |
| Magazine / RSS feed configuration and cached content | Storing the feed URLs you add and caching fetched articles locally | None (stored in app's private storage) |
| **Show on wake** preference (over-keyguard lock screen) | Remembering whether the cosmetic lock screen feature is enabled | None (stored in the App's private SharedPreferences) |
| Passcode Lock value, enable/lockout toggles, failed-attempt counters, and related flags | Gating Alpine's cosmetic lock overlay if you turn Passcode Lock on | None (stored in the App's private DataStore); never transmitted |
| Per-boot lock-screen flag (in-launcher overlay) | Showing the cosmetic lock screen once inside the launcher after each reboot when **Show on wake** is off | None (stored in the App's private DataStore) |
| Device date and time | Clock shown on the cosmetic lock screen | None (read from the device; not sent off-device) |
| Device orientation | Laying out bezels correctly on the lock screen in landscape | None (read on-device via orientation sensors; not stored or transmitted) |
| Home-screen widget IDs, spans, and layout | Hosting Android app widgets you add to the home screen | Bind-widget permission, granted via the system dialog when you add a widget. Third-party widgets are provided by other apps and may collect or transmit data under those apps' own policies; Alpine only hosts the widget view and stores the widget ID and size locally. |
| Custom splash image and scale | Showing a boot splash you choose | None (image copied into the App's private storage; chosen via the system picker) |
| Limelight Search source list and app-drawer toggle | Remembering which search sources you enabled | None (stored in the App's private DataStore) |
| On-screen keyboard layout, language, and click prefs | Powering Alpine's in-app keyboard | None (stored in the App's private DataStore); keystrokes stay on the device |
| Custom vibration patterns and alert-tone prefs | Playing haptics and sounds you configure | None (stored in the App's private DataStore) |
| Play licence cache (verdict, licensed-until, snooze) | Avoiding a Play Integrity check on every launch | None (stored in the App's private DataStore); the check itself is described in section 3.3(j) |
| FCM device token (local copy) | Remembering the push token last registered so it can be unregistered | None (stored in the App's private SharedPreferences); the token is also sent off-device as described in section 3.3(l) |
| Battery-optimization prompt flag | Remembering that the one-time exemption dialog was shown | None (stored in the App's private SharedPreferences) |
| Game Center nickname and profile photo (local copy) | Creating and editing your Game Center profile before upload | None (stored in the App's private storage) |
| Game Center session token | Maintaining your anonymous Game Center sign-in | None (stored in app's private SharedPreferences) |
| Installed game list (package names and labels) | Populating the Game Center game library and play-time tracking | `QUERY_ALL_PACKAGES` (normal); `PACKAGE_USAGE_STATS` (special, manual). Personal-profile games only; work-profile apps are not synced to Game Center. |
| Chat conversation and message cache | Displaying conversations while offline or before sync completes | None (stored in app's private storage) |
| Chat locally hidden or deleted state | Hiding conversations and messages you delete on this device | None (stored in app's private storage) |
| Locally blocked Chat profile IDs | Hiding direct threads with users you have blocked | None (stored in app's private storage) |
| Chat setup agreement flag | Remembering that you accepted the in-app Chat Terms & Conditions | None (stored in app's private DataStore) |
| Chat image attachments (pending send / local preview) | Staging photos before upload and showing images while moderation is in progress | None (stored in app's private storage; images chosen via the system gallery picker or system camera intent) |
| Camera photos and videos | Capturing and saving stills and clips from the built-in Camera app | `CAMERA`, runtime prompt; `RECORD_AUDIO`, runtime prompt when recording video with sound |
| Alpine Gallery media | Displaying, editing, cropping, and managing photos and videos the App created under its own MediaStore folders, and folders you add from device storage | App-owned MediaStore entries need no broad storage permission on modern Android; added folders use Storage Access Framework, you choose which folders to grant |
| Tappy Duck local best score and play-time stats | Showing your personal best and play time offline; contributing to Game Center "Recently Played" when online | None (stored in app's private DataStore) |
| High Rise local best score and play-time stats | Showing your personal best and play time offline; contributing to Game Center "Recently Played" when online | None (stored in app's private DataStore) |
| Sketch Hop local best score and play-time stats | Showing your personal best and play time offline; contributing to Game Center "Recently Played" when online | None (stored in app's private DataStore) |
| Sketch Guess local play-time stats and color-visibility prefs | Showing play time offline; contributing to Game Center "Recently Played" when online; remembering which owned colors you hid | None (stored in app's private DataStore) |
| Call favorites (Game Center friend profile IDs) | Populating the Call app's Favorites tab | None (stored in app's private DataStore) |
| Call recents log (friend nicknames, timestamps, call direction) | Displaying your placed, received, and missed calls in the Call app | None (stored in app's private DataStore) |
| MyBeer drink selection preference | Remembering which virtual drink you selected in the MyBeer app | None (stored in app's private DataStore) |
| Device accelerometer / gravity (MyBeer, Sketch Hop) | Animating the virtual drink's liquid surface to match device tilt; steering the Sketch Hop player left and right | None (read on-device via motion sensors; not stored or transmitted) |
| Clock alarms, snoozes, world-clock cities, and enable toggle | Scheduling and displaying alarms, timers, and world clocks in the Clock app | None (stored in app's private DataStore); exact alarms use `USE_EXACT_ALARM` |
| Custom Clock alarm/timer tones | Playing tones you import for alarms and timers | None (audio files copied into the App's private `clock_tones` storage; chosen via the system file picker) |
| Clock full-screen-intent and lock-screen prompt flags | Remembering whether you dismissed prompts about full-screen alerts or the cosmetic lock screen | None (stored in app's private DataStore) |
| Compass enable toggle and location-prompt flag | Remembering whether Compass is enabled and whether the location permission prompt was shown | None (stored in app's private DataStore) |
| Weather enable toggle, location-prompt flag, saved places, and selected place | Remembering whether the Weather app is enabled and which locations you saved | None (stored in the App's private DataStore); fetching conditions for a saved place is described in section 3.3(b) |
| Weather snapshot cache | Reusing a recent weather reading after process death | None (stored as `weather_cache.json` in the App's private cache); the fetch itself is described in section 3.3(b) |
| Voice Memo recordings | Playing back memos you recorded | None (WAV files in the App's private `voice_memos` storage); sharing a memo uses the system share sheet and is user-initiated |
| Voice Memo enable toggle | Remembering whether Voice Memo is enabled on the home screen | None (stored in the App's private DataStore) |
| Annelida animation and texture preferences | Remembering which Annelida tweaks you listed and how they play | None (stored in the App's private DataStore) |
| Annelida custom texture images | Replacing stock linen / dock / keyboard textures with images you pick | None (copied into the App's private `annelida_textures` storage; chosen via the system picker) |
| Device magnetometer / orientation (Compass) | Computing compass heading for the Compass dial | None (read on-device via motion sensors; not stored or transmitted) |
| Approximate coordinates (Compass) | Showing latitude/longitude on the Compass screen and computing magnetic declination | `ACCESS_COARSE_LOCATION` - runtime prompt; read on-device only, never sent off-device for Compass |
| Alp Store enabled toggle | Remembering whether the Alp Store discovery tile is shown on the home screen | None (stored in app's private DataStore) |
| Contacts enable toggle | Remembering whether the Contacts app is shown on the home screen | None (stored in the App's private DataStore) |
| Alpine Apps toggles (Camera, Gallery, Chat, Call, Clock, Compass, Weather, Calculator, Voice Memo, Annelida, Contacts, Tappy Duck, High Rise, Sketch Hop, Sketch Guess, MyBeer, Settings, etc.) | Remembering which built-in Alpine apps you have enabled on the home screen | None (stored in app's private DataStore) |

While **Show on wake** is enabled, the App registers for **screen-off** events on the device solely to pre-stage the cosmetic lock-screen UI before the next wake. These events are processed on-device only and are not transmitted to us.

All speech recognition and language-model inference run locally on your device against model files stored in the App's private storage. No audio, transcript, or AI response is ever transmitted off the device.

### 3.3 Data Transmitted Off the Device

The App makes outbound network requests in the following narrowly scoped situations. Every HTTPS or WebRTC connection necessarily reveals your device's current IP address to the destination. For Call, Tappy Duck, and High Rise, WebRTC ICE candidates can also include local and public IP addresses, which are relayed through Supabase to the other participant, and Google's STUN server sees your public IP so the two devices can find each other. We do not store IP addresses as a user profile.

#### (a) AI Model Download, Hugging Face and GitHub

**What is sent:** A standard HTTPS GET request to Hugging Face's CDN (for speech-to-text models) or GitHub's release CDN (for text-to-speech models) for model files, with no personal identifiers. If you provide a Hugging Face API token to access gated models, that token is transmitted to Hugging Face's servers as an `Authorization` header. The token is stored in the App's private DataStore (protected by Android's app sandboxing and any device-level encryption the OS provides) and is never sent to us or to any other party.

**When:** Once, the first time you open the voice assistant, if the model files are not already on disk. Subsequent uses are fully offline.

**Legal basis (GDPR Art. 6):** Legitimate interest, necessary to deliver the on-device AI feature you have chosen to use.

#### (b) Weather Data, WeatherAPI.com via Supabase

**What is sent:** Your approximate latitude and longitude (rounded to three decimal places, roughly a 100-metre to 1-kilometre cell) when you ask for weather at your location or open the Weather app on the "here" page, or the stored coordinates of a saved Weather-app place. Requests go to Alpine's Supabase Edge Function, which forwards a rounded query to WeatherAPI.com. No account identifier, device ID, or WeatherAPI.com key is included on the device request. The WeatherAPI.com key is stored only as a server-side secret.

**When:** When you open the notification panel, open the Weather app, or ask the voice assistant a weather question, and only if you have granted the location permission for "here" weather (named-place questions and saved-place fetches send the place name or stored coordinates even without location). Results are cached on the device (including in a private cache file that survives process death) and on the server for one hour, and are reused only while you remain within about one kilometre of the location that reading was fetched for. Moving outside that radius makes the old snapshot irrelevant and Alpine's backend requests a new WeatherAPI.com reading for the new area (still at most one upstream call per location cell per hour, fetching current conditions and the short forecast together).

**Legal basis (GDPR Art. 6):** Legitimate interest, providing current weather information is a core feature you have actively enabled by granting location access, opening the Weather app, or asking Iris about a named place.

#### (c) Place-Name Weather Queries and City Search

Named-place weather uses the same backend path described in (b). The place name extracted from your voice query is sent to Alpine's Supabase Edge Function, which resolves it through WeatherAPI.com. Geocoding results are cached with the weather payload.

The Weather app's city search sends the text you type (for example "Stavanger") to the same Edge Function as a search query. The function returns matching place names and coordinates from WeatherAPI.com so you can save a location. Saved places themselves stay on your device.

**Legal basis (GDPR Art. 6):** Legitimate interest, resolving the location you explicitly named or searched for is necessary to show weather for that place.

#### (d) RSS / Magazine Feeds, User-Configured Hosts

**What is sent:** Standard HTTPS GET requests to RSS feed URLs that you have added in the App's magazine/newsstand settings, including a User-Agent string identifying the App (`AlpineLauncher/1.0`). Article images referenced within the feed XML are loaded from whatever hosts the feed content specifies (via the App's image-loading library). No account identifier, device ID, or any personal identifier beyond your IP address is included in these requests.

**When:** When you open the magazine reader, and periodically (approximately hourly) to refresh feed content. Feed content is cached on disk to reduce network requests.

**Legal basis (GDPR Art. 6):** Legitimate interest, fetching feeds is necessary to deliver the magazine reader feature you have configured.

#### (e) Publication Favicons, Google Favicon Service

**What is sent:** An HTTPS request to Google's favicon service (`t1.gstatic.com`) containing the domain name derived from each RSS feed URL you have configured. No other information is included.

**When:** When the magazine reader loads, to display a recognisable icon for each configured publication.

**Legal basis (GDPR Art. 6):** Legitimate interest, displaying publication branding for feeds you have chosen to add.

#### (f) Game Center, Supabase and Google Cloud Vision

Game Center is an **optional** social feature. It is entirely opt-in: no Game Center data is collected or transmitted unless you complete the Game Center setup flow and agree to its in-app Terms & Conditions.

**What is sent:**

| Data | Recipient | Purpose |
|---|---|---|
| User-chosen nickname (max 15 characters) | Supabase | Profile identity; visible to friends |
| Profile photo (JPEG) | Supabase Storage; then forwarded to Google Cloud Vision (via a Supabase Edge Function) for automated SafeSearch moderation | Avatar display and content-safety screening |
| Friend code (a 9-character hash derived from `Settings.Secure.ANDROID_ID`) | Supabase | Unique profile identifier for sending and receiving friend requests |
| Anonymous user ID (UUID assigned by Supabase Auth) | Supabase | Session management |
| Friend-request and friend-list actions (send, accept, decline, remove) | Supabase | Managing your friend graph |
| Installed game package names and display names | Supabase | Syncing your game library and presence with friends |
| Per-game play time (total and today, in milliseconds) | Supabase | Play-time statistics visible on your profile and to friends |
| Profile reports (target profile ID and optional reason) | Supabase | User-initiated content reports |
| Block actions (blocked profile ID) | Supabase | User-initiated blocking |
| Recently Met pair (your profile ID, the other player's profile ID, game key, timestamp) | Supabase | Showing people you just played with in Tappy Duck, High Rise, or Sketch Guess so you can add them as friends |
| Tappy Duck best score | Supabase | Global and friends leaderboards (only your highest score is stored; lower submissions are ignored) |
| Tappy Duck multiplayer match state (match ID, opponent profile ID, ready status, pipe seed) | Supabase | Quick-match queue, friend invites, and rematch coordination |
| WebRTC signaling payloads (session description and ICE candidates, which can include IP addresses) | Supabase | Relaying Tappy Duck multiplayer connection setup between two players; deleted when the match ends |
| Tappy Duck gameplay sync (bird position, score, alive/dead state) | Direct peer-to-peer via WebRTC data channel between the two players | Real-time multiplayer gameplay; not stored on our servers |
| High Rise best score and best population | Supabase | Global and friends leaderboards (only your highest score is stored; lower submissions are ignored) |
| High Rise multiplayer match state (match ID, opponent profile ID, ready status, game seed) | Supabase | Quick-match queue, friend invites, rematch coordination, and synchronized countdown |
| WebRTC signaling payloads (session description and ICE candidates, which can include IP addresses) | Supabase | Relaying High Rise multiplayer connection setup between two players; deleted when the match ends |
| High Rise gameplay sync (building state, scores, alive/dead state) | Direct peer-to-peer via WebRTC data channel between the two players | Real-time multiplayer gameplay; not stored on our servers |
| Sketch Hop best score | Supabase | Global and friends leaderboards (only your highest score is stored; lower submissions are ignored) |
| Sketch Guess match state (match ID, opponent profile ID, status, turn, streak) | Supabase | Friend invites, random worldwide matchmaking, and turn-based play |
| Sketch Guess drawings (stroke data) and optional drawing messages | Supabase | Showing your drawing and optional caption to your opponent (a friend or a worldwide match) |
| Sketch Guess guesses, guess replay, and awarded coins | Supabase | Resolving turns and replaying a guess for the drawer |
| Sketch Guess wallet (coins, owned colors, concurrent-game slots, queue status) | Supabase | In-game progress and the random-match queue |
| FCM device token | Google Firebase and Supabase | Delivering friend-request, game-invite, and turn alerts while the App is in the background, as described in section 3.3(l) |

**No email address, phone number, real name, or Google account information** is collected by Game Center. Sign-in is anonymous.

**When:** After you complete Game Center setup, the App syncs profile data, friends, and friend requests approximately every 15 seconds while the App is in the foreground, and registers an FCM device token for background alerts. Game stats are synced when the Game Center screen loads. Tappy Duck, High Rise, and Sketch Hop scores are submitted when you finish a run with Game Center enabled. Tappy Duck and High Rise multiplayer matchmaking and signaling occur while you are in an online multiplayer session. Sketch Guess match, drawing, guess, and wallet data is sent while you play with Game Center enabled.

**Legal basis (GDPR Art. 6):** Consent, you explicitly opt in via the Game Center setup flow and agree to the in-app Game Center Terms & Conditions before any data is transmitted.

#### (g) Game Icons, Google Play Store

**What is sent:** HTTPS requests to the Google Play Store listing page for each installed game, containing the game's package name in the URL and a standard browser-like User-Agent header. No personal or device identifiers are included.

**When:** When the Game Center UI loads, to display recognisable game icons.

**Legal basis (GDPR Art. 6):** Legitimate interest, displaying game artwork for the Game Center feature you have enabled.

#### (h) Chat, Supabase and Google Cloud Vision

Chat is an **optional** messaging feature built on the same anonymous Game Center account. It is entirely opt-in: no Chat data is collected or transmitted unless you enable Chat from Settings → Alpine Apps, complete the Chat setup flow (which shares your Game Center nickname and profile photo), and agree to the in-app Chat Terms & Conditions.

**What is sent:**

| Data | Recipient | Purpose |
|---|---|---|
| Text message content | Supabase | Delivering messages in direct conversations with Game Center friends, private group chats, and public Global channels |
| Message images (JPEG) | Supabase Storage; then forwarded to Google Cloud Vision (via a Supabase Edge Function) for automated SafeSearch screening; images may also be held for manual moderator review before becoming visible to other participants | Image messaging and content-safety screening |
| Conversation metadata (participants, read timestamps, group titles) | Supabase | Conversation list, unread counts, and read receipts |
| Profile reports from Chat (target profile ID and optional reason) | Supabase | User-initiated content reports (same reporting system as Game Center) |
| Block actions (blocked profile ID) | Supabase | User-initiated blocking; prevents message delivery in direct conversations and hides blocked users' messages from your view in all conversation types |
| FCM device token | Google Firebase and Supabase | Delivering Chat alerts while the App is in the background, as described in section 3.3(l) |

Chat reuses the Game Center identity described in section 3.3(f). **No email address, phone number, real name, or Google account information** is collected for Chat. **Messages are not end-to-end encrypted.** Messages posted in Global channels are visible to every Chat user and may remain visible after you stop using Chat or reset Game Center.

**When:** After you complete Chat setup, the App syncs conversations and messages approximately every 15 seconds while the App is in the foreground and Chat is enabled, and registers an FCM device token for background alerts.

**Legal basis (GDPR Art. 6):** Consent, you explicitly opt in via the Chat setup flow and agree to the in-app Chat Terms & Conditions before any message data is transmitted.

#### (i) Call, Supabase and Google STUN

Call is an **optional** voice-calling feature for Game Center friends. It is entirely opt-in: no Call data is collected or transmitted unless you enable Call from Settings → Alpine Apps (or the Alp Store) and have completed Game Center setup. Call reuses the anonymous Game Center identity described in section 3.3(f).

**What is sent:**

| Data | Recipient | Purpose |
|---|---|---|
| Call session metadata (call ID, caller and callee profile IDs, status, timestamps) | Supabase | Placing, ringing, answering, declining, and ending calls between Game Center friends |
| WebRTC signaling payloads (session description and ICE candidates, which can include IP addresses) | Supabase | Relaying Call connection setup between two participants until the direct link is established |
| Live voice audio | Direct peer-to-peer via WebRTC audio track between the two participants | Real-time voice conversation during an active call; not stored on our servers |

**No email address, phone number, real name, or Google account information** is collected for Call. **Calls are not recorded** by us and **voice audio is not stored** on our servers. A local recents log (friend nicknames and timestamps) stays on your device only.

Google STUN (`stun.l.google.com`) is used only to help the two devices discover a path; it sees your public IP address for that purpose.

**When:** When you place or receive a call from the Call app, the App polls Supabase for incoming calls and active session state while the Call screen is open. Signaling is exchanged until the WebRTC audio path connects.

**Legal basis (GDPR Art. 6):** Consent, you explicitly opt in by enabling Call and completing Game Center setup before any call data is transmitted.

#### (j) Play licence verification, Google Play Integrity via Supabase

Licence checks are **not** an opt-in social feature. They run in **release** builds so we can confirm that this installation was purchased on Google Play.

**What is sent:**

| Data | Recipient | Purpose |
|---|---|---|
| Opaque Play Integrity token (created on-device by Google Play services) | Alpine's Supabase Edge Function, which forwards it to the Google Play Integrity API | Confirming app integrity and whether Google considers the App licensed for this Google account |
| Random request hash generated on the device | Alpine's Supabase Edge Function and Google Play Integrity | Binding the token to this check so it cannot be replayed |

The Edge Function returns only `licensed`, `unlicensed`, or `unevaluated` to the App. **We do not receive your Google account email, payment card details, or a persistent device identifier** from this check. We do not store the Integrity token after the check completes; Edge Function logs may briefly record the licensing and app-recognition verdicts for debugging.

**When:** When the locally cached licensed-until timestamp has expired (about every seven days while you use the App). If a copy is treated as unlicensed, a purchase reminder may appear and built-in Alpine apps may be withheld as described in section 2.2.

**Legal basis (GDPR Art. 6):** Performance of contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)), verifying that you have a valid Google Play purchase of the paid App.

#### (k) Limelight Search, Google and Wikipedia (system browser)

**What is sent:** If you tap a Google or Wikipedia action in Limelight Search (the app drawer), Alpine opens your **system browser** with the search query in the URL. Alpine does not itself upload the query to Google or Wikipedia, and does not receive search results. Those services then process the query under their own policies.

**When:** Only when you choose a web-search action in Limelight.

**Legal basis (GDPR Art. 6):** Legitimate interest, opening the search you explicitly requested.

#### (l) Push alerts, Firebase Cloud Messaging via Supabase

Push delivery is **not** a separate product you turn on by itself. After you complete **Game Center** or **Chat** setup, the App registers an FCM device token so friend-request, game-invite, turn, and Chat alerts can arrive while Alpine is in the background or the screen is off.

**What is sent:**

| Data | Recipient | Purpose |
|---|---|---|
| FCM device token issued by Google Play services | Google Firebase; Alpine's Supabase backend (`device_push_tokens`, linked to your anonymous Game Center account) | Addressing push messages to this installation |
| Generic notification title and body (for example "Chat" / "New message") plus a `kind` flag | Google FCM, which delivers the alert to this device | Waking the App and showing a heads-up notification. Message text, images, and friend names are **not** included in the payload |

The token is a persistent device identifier. It is **not** your Google account email. A local copy is kept so the App can unregister the token if you reset Game Center or turn both Chat and Game Center off. If FCM is unavailable (no Play services), Alpine falls back to a websocket and may prompt once for a battery-optimization exemption.

**When:** After Game Center or Chat setup completes, and whenever Google rotates the token. Tokens are removed from Alpine's backend when you unregister or reset Game Center.

**Legal basis (GDPR Art. 6):** Consent, you opt in by completing Game Center and/or Chat setup. Delivery is necessary to provide the social alerts those features advertise.

#### (m) Platform reverse-geocoding (Android Geocoder)

**What is sent:** Approximate latitude and longitude to the device's **Geocoder** service so Iris can answer "where am I" and so Weather can label the "here" page with a city/country name. On many Google Play devices that service is operated by Google and the coordinates leave the device. Alpine does not send those coordinates to Krystall Media for this step.

**When:** When Iris handles a location-intent question, or when Weather / the notification panel needs a city label for the current fix.

**Legal basis (GDPR Art. 6):** Legitimate interest, turning a coarse fix into a place name you asked for or that the Weather UI needs to display.

#### (n) Feedback email (user-initiated)

**What is sent:** If you use Settings → Feedback, Alpine opens your email app with a draft addressed to markus@krystall.media. The draft pre-fills the App version plus device manufacturer, model, and Android version. Nothing is uploaded until you send the email. Your email provider then processes the message under its own terms.

**When:** Only when you tap Send Feedback and send the message.

**Legal basis (GDPR Art. 6):** Legitimate interest / your request, handling the support message you chose to send.

#### (o) Iris tweet drafts, X and the share sheet (user-initiated)

**What is sent:** If you ask Iris to compose a tweet and confirm posting, Alpine opens the installed **X (Twitter)** app when present, or otherwise Android's system share sheet, with the draft text. Alpine does not itself upload the draft to X or any other network. The app you confirm then processes the text under its own terms.

**When:** Only when you confirm posting a tweet draft.

**Legal basis (GDPR Art. 6):** Legitimate interest / your request, handing the draft you chose to share to the app you chose.

### 3.4 Location Data

The App requests **coarse-location** access only (`ACCESS_COARSE_LOCATION`). This permission instructs Android to provide location fixes at approximately neighbourhood-level precision (roughly one kilometre), and no fine-grained GPS coordinates are made available to the App.

Location is accessed in these situations only:

| Feature | How location is used | Leaves the device? |
|---|---|---|
| Weather (notification panel / Weather app / Iris) | Approximate coordinates, a named place, or a city-search query are sent to Alpine's Supabase weather function, which queries WeatherAPI.com as described in sections 3.3(b)–3.3(c) | Yes - rounded coordinates / place name / search text to Alpine's backend, then WeatherAPI.com |
| Weather "here" city label and Iris "where am I" | Approximate coordinates are reverse-geocoded by the platform **Geocoder** so the App can show or speak a city/country name | Often yes - on Google Play devices the platform Geocoder typically sends coordinates to Google's geocoding service; Alpine does not send those coordinates to Krystall Media |
| Compass | Last-known approximate coordinates are read on-device to show latitude/longitude and to compute magnetic declination for the heading | No - Compass never transmits location |

The App does not track your location in the background, does not log a location history, and declares only **`ACCESS_COARSE_LOCATION`** in its manifest (not `ACCESS_FINE_LOCATION`). Weather requests send latitude and longitude rounded to three decimal places to Alpine's Supabase weather function as described in section 3.3(b); those values come from Android's coarse-location pipeline (neighbourhood-level accuracy typical of that permission).

If you deny the location permission, weather-for-here features and Compass coordinate/declination display will be unavailable or limited; named-place weather, Weather-app saved places, and the Compass dial (relative heading from on-device sensors) can still work, and all other App features continue to work normally.

### 3.5 Permissions Summary

| Permission | Classification | How Granted | Used For |
|---|---|---|---|
| `QUERY_ALL_PACKAGES` | Restricted (launcher exemption) | Auto at install | Discovering launchable apps in the personal user for the home screen and drawer. Work-profile apps are listed through Android's `LauncherApps` API, not this permission. |
| `REQUEST_DELETE_PACKAGES` | Normal | Auto at install | Initiating system uninstall flow |
| `SET_WALLPAPER` | Normal | Auto at install | Setting home-screen wallpaper |
| `WRITE_SETTINGS` | Special | Manual via Settings | Display brightness on Brightness & Wallpaper; lock-screen auto-sleep timeout |
| `EXPAND_STATUS_BAR` | Normal | Auto at install | Expanding the system status bar |
| `RECORD_AUDIO` | Dangerous | Runtime prompt | Voice assistant microphone capture; Call voice calls; Voice Memo recordings; optional audio track when recording video in the Camera app |
| `CAMERA` | Dangerous | Runtime prompt | Live preview, still capture, and video recording in the built-in Camera app (including the lock-screen Alpine Camera shortcut) |
| `INTERNET` | Normal | Auto at install | Weather (including Weather-app city search), geocoding, model downloads, RSS feeds; Play Integrity licence checks; FCM token registration and push delivery; Game Center / Chat / Call / online games when opted in; game icons and favicons |
| `ACCESS_NETWORK_STATE` | Normal | Auto at install | Network availability checks |
| `ACCESS_WIFI_STATE` | Normal | Auto at install | Wi-Fi signal icon in status bar |
| `FOREGROUND_SERVICE` | Normal | Auto at install | Background music playback; optional lock-screen service when **Show on wake** is on; Clock alarm-pending helper when needed; Voice Memo recording service |
| `FOREGROUND_SERVICE_MEDIA_PLAYBACK` | Normal | Auto at install | Typed foreground service for music player |
| `FOREGROUND_SERVICE_SPECIAL_USE` | Normal (declared FGS type) | Auto at install; feature enabled by user | Typed foreground service for the optional over-keyguard lock screen; Clock alarm-pending service |
| `FOREGROUND_SERVICE_MICROPHONE` | Normal (declared FGS type) | Auto at install; feature enabled by user | Typed foreground service so a Voice Memo can keep recording after you leave the Voice Memo screen |
| `RECEIVE_BOOT_COMPLETED` | Normal | Auto at install | Restarting the lock-screen service after reboot if **Show on wake** is on; re-arming Clock alarms and snoozes after reboot |
| `POST_NOTIFICATIONS` | Dangerous (API 33+) | Runtime prompt (API 33+) | Music playback notification; optional persistent notification for the lock-screen foreground service; Clock alarm and timer ringing notifications; Voice Memo recording notification; Chat / Game Center FCM alerts |
| `VIBRATE` | Normal | Auto at install | Haptic feedback during High Rise and Sketch Hop gameplay; Clock alarm and timer ringing vibration |
| `USE_EXACT_ALARM` | Normal (clock / alarm use) | Auto at install | Exact AlarmManager wakeups for Clock timers and wall-clock alarms |
| `USE_FULL_SCREEN_INTENT` | Special / restricted | Auto at install; may require user grant on some Android versions | Full-screen Clock alarm/timer dismiss UI when an alert fires |
| `WAKE_LOCK` | Normal | Auto at install | Keeping the screen/CPU awake briefly while a Clock alarm or timer is ringing (especially when the cosmetic lock screen is off); finishing Chat / Game Center refresh while the screen is off if you grant a battery-optimization exemption |
| `INSTALL_SHORTCUT` | Normal | Auto at install | Pinning app shortcuts to the home screen |
| `PACKAGE_USAGE_STATS` | Special | Manual via Settings | Recent Apps panel; Game Center play-time tracking |
| `ACCESS_COARSE_LOCATION` | Dangerous | Runtime prompt | Weather features; optional Compass coordinates and magnetic declination |
| `ACCESS_NOTIFICATION_POLICY` | Special | Manual via Settings | Do Not Disturb toggle on the main Settings screen |
| `REQUEST_IGNORE_BATTERY_OPTIMIZATIONS` | Special | System prompt (once, only if Firebase Cloud Messaging is unavailable) | Keep the Chat / Game Center websocket fallback working while the screen is off on aggressive OEMs; skipped when FCM can deliver high-priority messages through Doze. Declining still allows those features, but asleep alerts may wait until the next manual wake |
| **Display over other apps** | Special | Manual via Settings | Reliable display of the over-keyguard lock screen from the background; may also help present Clock ringing dismiss UI |
| Bind app widget | Special | System dialog when you add a widget | Hosting third-party home-screen widgets |
| Notification Listener | Special | Manual via Settings | Notification panel; optional lock-screen notification display |

### 3.6 Data Retention

For all features except Game Center, Call, Chat, Firebase Cloud Messaging tokens, weather proxy/cache, and the ephemeral Play Integrity licence check described in section 3.3(j), the App does not operate a server-side database and we hold no personal data on our own infrastructure. If you enable Game Center, Call, or Chat, profile, social, and push-token data is stored on a third-party hosted database (Supabase) as described below.

#### On-device data

- **On-device preferences and layout:** retained until you clear the App's data or uninstall it.
- **Downloaded AI models:** retained in the App's private storage until you clear data, delete them from within the App, or uninstall.
- **Cached location and weather:** the latest weather snapshot is written to a private cache file (`weather_cache.json`) and reused for about one hour while you stay near that fetch point; cleared when you clear App data, factory-reset, or uninstall. In-memory location snapshots used by Iris are cleared when the App process ends.
- **AI conversation transcripts:** held in memory only; not persisted to disk and cleared when the App process ends.
- **RSS / magazine feed cache:** retained on disk until you clear the App's data, remove the feed, or uninstall.
- **Music and book library metadata:** the App accesses files you grant via Android's Storage Access Framework; it does not copy or retain the underlying media files beyond in-memory playback and cached artwork in the App's private storage.
- **Alpine Gallery user-added folders:** the App accesses photos and videos in folders you grant via Android's Storage Access Framework; it does not copy those files. The folder URI list is retained until you remove the folder, clear the App's data, or uninstall.
- **Custom icon overrides:** retained in the App's private storage until you reset the icon or uninstall.
- **Lock-screen preference (**Show on wake**):** retained until you turn the feature off, clear the App's data, or uninstall.
- **Passcode Lock value and related flags:** retained until you turn Passcode Lock off, clear the App's data, or uninstall.
- **Per-boot lock-screen flag:** retained until you clear the App's data or uninstall.
- **Custom splash image and scale:** retained until you reset the splash, clear the App's data, or uninstall.
- **Home-screen widget IDs and spans:** retained until you remove the widget, clear the App's data, or uninstall.
- **Limelight Search sources, keyboard prefs, and custom vibration patterns:** retained until you clear the App's data or uninstall.
- **Play licence cache:** retained until the licensed-until timestamp expires, you clear the App's data, or uninstall. Clearing it only causes the next check to run again; it does not delete a Google Play purchase.
- **Battery-optimization prompt flag:** retained until you clear the App's data or uninstall.
- **Game Center session and local profile:** retained until you reset Game Center, clear the App's data, or uninstall.
- **Chat conversation and message cache, locally hidden/deleted state, and blocked-profile list:** retained until you reset Game Center (which clears local Chat state), clear the App's data, or uninstall.
- **Chat setup agreement flag:** retained until you clear the App's data or uninstall.
- **Camera photos and videos:** retained in the device's shared MediaStore under the App's Alpine Gallery folders until you delete them from Alpine Gallery or via another app with access to those files.
- **Tappy Duck local best score and play-time stats:** retained until you clear the App's data or uninstall.
- **High Rise local best score and play-time stats:** retained until you clear the App's data or uninstall.
- **Sketch Hop local best score and play-time stats:** retained until you clear the App's data or uninstall.
- **Sketch Guess local play-time stats and color-visibility prefs:** retained until you clear the App's data or uninstall.
- **Call favorites and recents log:** retained until you clear the App's data or uninstall.
- **Clock alarms, snoozes, world clocks, custom tones, and related prompt flags:** retained until you clear the App's data or uninstall. Custom tone audio files are removed with App data or uninstall.
- **Weather saved places and Weather-app toggles:** retained until you remove the place, clear the App's data, or uninstall.
- **Voice Memo recordings:** retained in the App's private `voice_memos` storage until you delete the memo, clear the App's data, or uninstall. Sharing a memo copies it to the app you choose.
- **Annelida preferences and custom texture images:** retained until you reset the texture, clear the App's data, or uninstall.
- **FCM device token (local copy):** retained until you reset Game Center, disable Chat and Game Center, clear the App's data, or uninstall.
- **Compass enable toggle and location-prompt flag:** retained until you clear the App's data or uninstall.
- **MyBeer drink selection, Alp Store enabled toggle, and Contacts enable toggle:** retained until you clear the App's data or uninstall.
- **Alpine Apps toggles:** retained until you clear the App's data or uninstall.
- **Android Auto Backup:** the App does not participate in Android Auto Backup or device-to-device app-data transfer (`allowBackup` is disabled). Clearing App data or uninstalling removes the local copy on that device. Alpine Gallery media saved to shared Pictures/Movies storage, and a system wallpaper previously set by the App, may remain after uninstall until you delete them separately. Server-side Game Center, Chat, Call, and FCM push-token data is unaffected by uninstall.

#### Server-side data (Game Center, Call, Chat, push tokens, weather cache, and licence checks)

- **Profile (nickname, friend code, avatar URL, game stats):** retained on Supabase until you use the in-app "Reset Game Center" option, which resets your server-side profile and clears associated Game Center and non-global Chat data. Uninstalling the App removes only the local session; if you wish to delete your server-side data, use the reset option before uninstalling or contact us at markus@krystall.media.
- **Friend graph (friendships, pending requests):** deleted when either party resets their Game Center profile or when you remove a friend.
- **Recently Met pairs:** retained on Supabase until you reset Game Center. New matches in Tappy Duck, High Rise, or Sketch Guess add or refresh a row for each player.
- **Avatar images:** stored in Supabase Storage. Replaced when you upload a new photo; deleted when you reset Game Center.
- **Profile reports, blocks, and moderation bans:** retained for moderation purposes until the reported or blocked profile is deleted or a ban is lifted.
- **Game presence and play-time records:** deleted when you reset Game Center.
- **Chat messages (text and approved images):** up to 50 messages per conversation are retained on Supabase; older messages are automatically purged. When you reset Game Center, your participation in direct and group conversations is removed and messages you sent in those conversations are deleted; **messages you posted in Global channels remain visible to all Chat users** and are not removed by reset.
- **Pending or rejected Chat images:** stored in Supabase Storage until approved, rejected, or the associated conversation is deleted.
- **Tappy Duck leaderboard scores:** retained on Supabase until you use the in-app "Reset Game Center" option, which clears your server-side profile including leaderboard entries.
- **Tappy Duck multiplayer match records and signaling payloads:** retained on Supabase only for the duration of an active or recently finished match; cleared when the match ends or you leave multiplayer.
- **High Rise leaderboard scores:** retained on Supabase until you use the in-app "Reset Game Center" option, which clears your server-side profile including leaderboard entries.
- **High Rise multiplayer match records and signaling payloads:** retained on Supabase only for the duration of an active or recently finished match; cleared when the match ends or you leave multiplayer.
- **Sketch Hop leaderboard scores:** retained on Supabase until you use the in-app "Reset Game Center" option, which clears your server-side profile including leaderboard entries.
- **Sketch Guess matches, drawings, messages, guesses, and wallet:** retained on Supabase while the match or wallet is active. Abandoning a match removes that match. Reset Game Center clears your server-side profile, including Sketch Guess wallet and associated matches.
- **Call session records (participants, status, timestamps):** retained on Supabase as historical records linked to your Game Center profile; WebRTC signaling payloads are retained only for the duration of an active call setup. Reset Game Center clears your profile identity but does not delete past call session records associated with your anonymous account ID.
- **FCM device tokens:** stored on Supabase and associated with your anonymous Game Center account for as long as Chat or Game Center remains set up. Unregistering (reset Game Center, disable both features, or a successful token refresh) deletes that token row. Google also holds the token while FCM is registered.
- **Weather proxy cache:** Alpine's weather Edge Function may cache a rounded-cell reading for about one hour. Place-search queries are not stored as a user profile.
- **Play Integrity tokens:** processed in memory by the licence Edge Function and not written to a user database. The Function returns only a status to the App. Logs may briefly record licensing and app-recognition verdicts for debugging.

### 3.7 Your Rights Under GDPR

As a resident of the EEA you have the following rights regarding any personal data we process:

- **Right of access (Art. 15):** You may request confirmation of whether we hold any personal data about you and, if so, a copy.
- **Right to rectification (Art. 16):** You may request correction of any inaccurate personal data.
- **Right to erasure (Art. 17):** You may request deletion of your personal data ("right to be forgotten"), subject to applicable legal obligations.
- **Right to restriction of processing (Art. 18):** You may request that we limit how we process your data in certain circumstances.
- **Right to data portability (Art. 20):** You may request your personal data in a structured, machine-readable format.
- **Right to object (Art. 21):** You may object to processing based on legitimate interest.
- **Right to withdraw consent:** Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.

To exercise any of these rights, contact us at **markus@krystall.media**. We will respond within 30 days. For data that remains exclusively on your device, the most direct way to exercise erasure rights is to clear the App's data or uninstall it via Android Settings. For Game Center, Call, Chat, and FCM push-token server-side data, you can use the in-app "Reset Game Center" option to reset your profile and clear associated social, push-token, and non-global Chat data, or contact us to request deletion. Note that Global channel messages you have posted are not removed by reset.

You also have the right to lodge a complaint with the Norwegian supervisory authority:

**Datatilsynet**  
Postboks 458 Sentrum, 0105 Oslo  
https://www.datatilsynet.no  
+47 22 39 69 00

### 3.8 Children

The App is not directed at children under the age of 13 (or under 16 in jurisdictions where GDPR sets a higher age of digital consent) and does not knowingly collect personal data from such children. Game Center, Chat, and Call include social features, public nicknames, profile photos, friend requests, text and image messaging, public Global channels, voice calls between friends, Sketch Guess drawings and messages, and user-generated reports, that are intended for users who meet the applicable age threshold. We do not implement an age-verification gate; parental supervision is recommended for minors using the App. If we become aware that a child below the applicable age has created a Game Center profile, used Chat or Call, or otherwise provided personal data, we will take steps to delete the relevant data. If you believe a child has used the App and you have concerns, please contact us at **markus@krystall.media**.

### 3.9 Security

We implement appropriate technical measures to protect data handled by the App:

- All outbound network requests use HTTPS/TLS.
- Any Hugging Face API token you optionally provide is stored in the App's private Preferences DataStore, sandboxed inside the App's data directory and protected by Android's app-level isolation and any device-level encryption the OS provides.
- The Alpine passcode, if you set one, is stored only in the App's private DataStore and is never transmitted.
- The App requests only the minimum permissions necessary for each feature.
- Downloaded model files are stored in the App's private `filesDir`, inaccessible to other apps without root access.

No method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

### 3.10 International Transfers

Some of the third-party services listed in sections 2.4 and 3.3 are operated by organisations that may process data outside the European Economic Area (EEA), including in the United States or other countries. This can apply, for example, to Hugging Face, GitHub, WeatherAPI.com, Google (favicon, Play Store pages, Cloud Vision moderation, Play Integrity licence checks, Firebase Cloud Messaging, STUN, platform Geocoder, and Limelight web searches opened in your browser), X (Twitter) or another share target if you confirm an Iris tweet draft, Supabase (when used for Game Center, Chat, Call, online games, FCM token storage, weather, or licence verification), and the hosts of any RSS feeds you configure.

Where such transfers occur, they are limited to the data and purposes described in this Policy. Those providers act as independent controllers or processors under their own terms. If you do not wish data to leave your device for an optional feature, do not enable that feature (for example, do not complete Game Center, Chat, or Call setup, and do not grant location for weather). Licence verification in release builds is required to confirm a valid Google Play purchase and is not an optional social feature.

### 3.11 Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be published at the URL above and reflected in the "Last updated" date. For material changes we will provide notice through the App or the Google Play listing. Continued use of the App after changes take effect constitutes acknowledgment of the revised Policy.

---

## 4. Contact

For all questions, requests, or complaints relating to these Terms or this Privacy Policy:

**Markus Maribu / Krystall Media**  
Email: markus@krystall.media  

---

*© 2026 Markus Maribu / Krystall Media. All rights reserved.*


 

bottom of page