Privacy Policy – Jolt
Last updated: 2026-07-11
Effective Date: July 11, 2026 This document describes how we process personal data when using the Jolt application and the related website joltapp.net.
1. Data Controller
The data controller is: Pavel Kupčík Vysoká nad Labem 210 503 31 E-mail: kupcik46@gmail.com
In this policy, we use the terms "Jolt", "we", "us", or "our". We are established in the Czech Republic. The supervisory authority is the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, e-mail: posta@uoou.cz, tel.: +420 234 514 111. The processing of personal data is governed primarily by Regulation (EU) 2016/679 (GDPR), Act No. 110/2019 Coll., on personal data processing, Act No. 127/2005 Coll., on electronic communications, and Act No. 480/2004 Coll., on certain information society services. A Data Protection Officer has not been appointed because this obligation did not arise for us under the current processing setup. If this changes, we will update this policy.
2. What data we process, for what purpose, and on what legal basis
2.1 Account and authentication
| Data | Purpose | Legal Basis | Obligation / Consequence of not providing |
|---|---|---|---|
| E-mail address | Account creation and management, service communication | Performance of a contract under Art. 6(1)(b) GDPR | Mandatory data; without it, the account cannot be created and used |
| Name / nickname | User profile display | Performance of a contract under Art. 6(1)(b) GDPR | Mandatory data to the extent needed for the account; without it, the profile cannot be used properly |
| Profile avatar | Profile personalization | Performance of a contract under Art. 6(1)(b) GDPR | Voluntary data; if you do not provide it, you can still use the account without it |
| Data from OAuth login (e.g., Apple / Facebook), especially a technical identifier, e-mail, and possibly display name according to the service's settings | Third-party login and identity linking with the account | Performance of a contract under Art. 6(1)(b) GDPR | Mandatory only if you choose this login method |
If you log in via Apple, Facebook, or another provider, we obtain the data that this provider passes to us in accordance with your settings. The source of this data is the respective login provider.
2.2 Educational and game data
| Data | Purpose | Legal Basis | Obligation / Consequence of not providing |
|---|---|---|---|
| XP points, level, streaks | Basic app functions | Performance of a contract under Art. 6(1)(b) GDPR | Data is generated by using the app; without processing it, the function cannot be provided |
| Card interactions (swipes, answers) | Content delivery, personalization, and progress evaluation within the service | Performance of a contract under Art. 6(1)(b) GDPR | Data is generated by using the app |
| Viewed cards, category scores | Progress tracking and recommendations within the service | Performance of a contract under Art. 6(1)(b) GDPR | Data is generated by using the app |
2.3 Social features
| Data | Purpose | Legal Basis | Obligation / Consequence of not providing |
|---|---|---|---|
| Friend codes, squads | Social and competitive functions | Performance of a contract under Art. 6(1)(b) GDPR | Optional; without them, social features will not be available |
| Duel history | Record of competitive games and results | Performance of a contract under Art. 6(1)(b) GDPR | Data is generated when using duels |
2.4 Push notifications
| Data | Purpose | Legal Basis | Obligation / Consequence of not providing |
|---|---|---|---|
| Device push token | Sending push notifications that are not essential for providing the service itself | Consent under Art. 6(1)(a) GDPR | Voluntary; without consent, we will not send you push notifications |
You can revoke your consent at any time in your device settings or app settings.
2.5 Crash diagnostics and technical stability
| Data | Purpose | Legal Basis | Obligation / Consequence of not providing |
|---|---|---|---|
| Pseudonymous user or session identifier | Assigning a technical error to a session and resolving it | Legitimate interest under Art. 6(1)(f) GDPR | Data is generated by using the app |
| Device model, operating system version, and app version | Reproduction, analysis, and fixing of crashes and errors | Legitimate interest under Art. 6(1)(f) GDPR | Data is generated by using the app |
| Technical crash logs and stack traces | Diagnostics of error causes | Legitimate interest under Art. 6(1)(f) GDPR | Data is generated by using the app |
Our legitimate interest is ensuring the app's security, technical stability, and functionality. You may object to processing based on legitimate interest. If the nature of the specific processing allows it, we will also offer you a technical disablement of the relevant function in the app settings.
2.6 Usage analytics
| Data | Purpose | Legal Basis | Obligation / Consequence of not providing |
|---|---|---|---|
| Screen views, in-app events | Usage analysis and feature improvement | Consent under Art. 6(1)(a) GDPR | Voluntary; if refused, we will not run analytics |
| Pseudonymous app instance identifier | Aggregate analytics and usage measurement | Consent under Art. 6(1)(a) GDPR | Voluntary |
We will request consent before launching analytics tools, and you can change it at any time in the app settings.
2.7 Session replay
If we activate a session replay tool or similar interface usage analysis technology, we will do so only based on prior consent, if required by law. Before sending, we will mask input fields and other sensitive elements to a reasonable extent. If we do not use this technology, this processing does not occur.
2.8 Advertising
| Data | Purpose | Legal Basis | Obligation / Consequence of not providing |
|---|---|---|---|
| Advertising ID (e.g., GAID / IDFA) and other advertising identifiers | Personalized ads and ad measurement | Consent under Art. 6(1)(a) GDPR | Voluntary; without consent, we will not run personalized ads |
| Data necessary to display non-personalized ads to a technically necessary extent | Ensuring the display of non-personalized ads | Legitimate interest under Art. 6(1)(f) GDPR only if the specific technology does not require prior consent; if the technology requires consent, we will use consent for this purpose as well | Without providing this data, the relevant advertising function may not be available |
If advertising technologies store or access information on your device, we use them only in accordance with the prior consent rules, unless the specific technology is strictly necessary for a service you have explicitly requested.
2.9 Website joltapp.net
| Data | Purpose | Legal Basis | Obligation / Consequence of not providing |
|---|---|---|---|
| E-mail for beta registration | Informing about the beta launch and related communication you requested | Consent under Art. 6(1)(a) GDPR | Voluntary; without it, we cannot include you in the beta registration |
| Analytics and marketing pixels | Measurement of traffic, campaigns, and marketing | Consent under Art. 6(1)(a) GDPR | Voluntary; without consent, they will not be launched |
We launch pixels and similar technologies on the website only after prior consent, unless they are strictly necessary for the website's functioning. If we send you commercial communications or other marketing e-mails based on your beta registration, we will do so only in accordance with applicable laws. Every such communication will contain an easy opt-out option.
2.10 Pre-login identifiers
| Data | Purpose | Legal Basis | Obligation / Consequence of not providing |
|---|---|---|---|
| Technical session or instance identifier before login | Basic app functions, technical content delivery, protection against abuse | Legitimate interest under Art. 6(1)(f) GDPR, or performance of a contract depending on the nature of the specific function | Without it, the basic technical functioning of the app may not be available |
2.11 Where we obtain data from
We obtain personal data:
directly from you during registration, app usage, or communication with us,
from third-party login providers if you choose to use OAuth login,
automatically from your device and app to the extent necessary for technical functioning, security, analytics, or advertising according to your consent settings.
3. Recipients, processors, and other involved entities
Our technology and service providers may be involved in the processing. These partners may act as our processors, or in some cases as independent controllers or other recipients depending on the nature of the service. Therefore, we do not automatically designate all the entities listed below as processors; their status may vary depending on the specific service and contractual setup. If a partner acts as a processor, we ensure a contractual arrangement in accordance with Art. 28 GDPR.
| Entity | Role Type | Service | Data Category | Location |
|---|---|---|---|---|
| Supabase, Inc. | typically processor | Database and authentication | Account, educational and game data, social data | May include the EU and third countries depending on service settings |
| Vercel, Inc. | typically processor | Website hosting | Technical traffic data, beta registration data | May include the EU and third countries |
| Resend, Inc. | typically processor | Transactional e-mails | E-mail address and related technical data | May include third countries |
| Google LLC and related Google group companies | processor or independent controller depending on the specific service | Crash diagnostics, analytics, advertising | Diagnostic data, analytics data, advertising identifiers and related data | May include third countries |
| Microsoft Corporation | processor or independent controller depending on the specific service | Session replay / interface analytics, if active | Masked interface recordings and related technical data | May include third countries |
| Meta Platforms Ireland Ltd. and related companies | independent controller or joint controller depending on the specific service | Web pixel and marketing tools, if active | Pseudonymous event data and marketing identifiers | May include the EU and third countries |
| TikTok Technology Ltd. and related companies | independent controller or other recipient depending on the specific service | Web pixel and marketing tools, if active | Pseudonymous event data and marketing identifiers | May include the EU and third countries |
If we do not actually use any of the listed services, the respective processing does not take place, and you can remove the entity from the published version. We do not sell your personal data.
4. Transfer of personal data outside the EU/EEA
Some of our providers or their subcontractors may be established outside the European Union or the European Economic Area, particularly in the USA. In such cases, we transfer personal data only if an adequate legal mechanism is ensured for such transfer, in particular:
standard contractual clauses issued by the European Commission,
an adequacy decision, if applicable to a specific country or recipient,
or another legally permissible transfer mechanism.
We do not use the general label "SCC / DPF" without verification. The specific transfer mechanism may vary depending on the recipient and current service settings. Upon request, we will provide you with more detailed information about the mechanism used for a specific category of recipients.
5. Retention period of personal data
We retain personal data only for the time necessary for the stated purposes.
| Data Category | Retention Period |
|---|---|
| Account data (e-mail, name, avatar) | Until account deletion; residual copies in backups are deleted according to providers' retention cycles, usually within 30 days |
| Educational and game data | Until account deletion; residual copies in backups are deleted according to providers' retention cycles, usually within 30 days |
| Social data | For the duration of account use; completed or expired duels may be deleted continuously according to service settings |
| Push token | Until consent revocation, notification deactivation, or account deletion |
| Crash diagnostic data | For the period set by the relevant tool, typically up to 90 days |
| Analytics data | For the period set by the relevant tool; where possible, we set reasonably short retention periods |
| Session replay data | Only if the service is active and only for the time necessary for analysis; the specific period is governed by the tool's settings |
| Advertising data | For the period set by the relevant advertising tools and according to your consent settings |
| Beta registration e-mails | Until the end of the beta program and a reasonable time thereafter, but no longer than 6 months, or until consent revocation / opt-out |
| Pre-login technical identifiers | For the time necessary for the technical functioning of the app; local identifiers may remain on your device until app data is cleared |
We may keep aggregated statistical outputs longer, but only if they no longer allow the identification of a specific person or have been properly anonymized. After the respective period expires, we will delete, anonymize, or stop actively using the personal data in accordance with our retention rules.
6. Your rights
You have the following rights in particular:
the right of access to personal data,
the right to rectify inaccurate or incomplete data,
the right to erasure,
the right to restriction of processing,
the right to data portability if legal conditions are met,
the right to object to processing based on legitimate interest,
the right to withdraw consent at any time without affecting the lawfulness of prior processing,
the right to lodge a complaint with a supervisory authority.
You can exercise your rights via e-mail at kupcik46@gmail.com or through in-app functions, if available. We respond to requests without undue delay, at the latest within 1 month of receipt; in complex cases, this period may be extended by a further 2 months, about which we will inform you.
7. Automated decision-making
We do not conduct decision-making based solely on automated processing that would have legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR.
8. Children
The Jolt app is intended for users aged 16 and older as our product rule. This is without prejudice to the fact that under Czech law, the relevant age limit for some consents to personal data processing for information society services is 15 years. We do not knowingly collect personal data from persons who do not meet the conditions for using the app. If you find that such a person has provided us with personal data in violation of this policy, please contact us and we will delete the data without undue delay or take other appropriate measures.
9. Cookies and similar technologies
On the joltapp.net website and possibly in the app, we may use cookies, SDKs, and other technologies that store or access information on a device. We use these technologies only if we have an appropriate legal basis for them. If prior consent is required by law, we will request it beforehand. Without consent, we use only those technologies that are strictly necessary for the transmission of a communication or for a service you have explicitly requested. You can change your preferences at any time in the cookie banner, website settings, or app settings, depending on the nature of the specific technology.
10. Changes to this policy
We may update this policy from time to time. We will inform you of material changes in an appropriate manner before they become effective, for example in the app or by e-mail. If consent is required for a new or expanded processing method, we will request it separately. Continued use of the app itself does not substitute consent where consent is legally required.