Privacy Policy – Jolt

Last updated: 2026-07-11

Effective Date: July 11, 2026 This document describes how we process personal data when using the Jolt application and the related website joltapp.net.

1. Data Controller

The data controller is: Pavel Kupčík Vysoká nad Labem 210 503 31 E-mail: kupcik46@gmail.com

In this policy, we use the terms "Jolt", "we", "us", or "our". We are established in the Czech Republic. The supervisory authority is the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, e-mail: posta@uoou.cz, tel.: +420 234 514 111. The processing of personal data is governed primarily by Regulation (EU) 2016/679 (GDPR), Act No. 110/2019 Coll., on personal data processing, Act No. 127/2005 Coll., on electronic communications, and Act No. 480/2004 Coll., on certain information society services. A Data Protection Officer has not been appointed because this obligation did not arise for us under the current processing setup. If this changes, we will update this policy.

2. What data we process, for what purpose, and on what legal basis

2.1 Account and authentication

DataPurposeLegal BasisObligation / Consequence of not providing
E-mail addressAccount creation and management, service communicationPerformance of a contract under Art. 6(1)(b) GDPRMandatory data; without it, the account cannot be created and used
Name / nicknameUser profile displayPerformance of a contract under Art. 6(1)(b) GDPRMandatory data to the extent needed for the account; without it, the profile cannot be used properly
Profile avatarProfile personalizationPerformance of a contract under Art. 6(1)(b) GDPRVoluntary data; if you do not provide it, you can still use the account without it
Data from OAuth login (e.g., Apple / Facebook), especially a technical identifier, e-mail, and possibly display name according to the service's settingsThird-party login and identity linking with the accountPerformance of a contract under Art. 6(1)(b) GDPRMandatory only if you choose this login method

If you log in via Apple, Facebook, or another provider, we obtain the data that this provider passes to us in accordance with your settings. The source of this data is the respective login provider.

2.2 Educational and game data

DataPurposeLegal BasisObligation / Consequence of not providing
XP points, level, streaksBasic app functionsPerformance of a contract under Art. 6(1)(b) GDPRData is generated by using the app; without processing it, the function cannot be provided
Card interactions (swipes, answers)Content delivery, personalization, and progress evaluation within the servicePerformance of a contract under Art. 6(1)(b) GDPRData is generated by using the app
Viewed cards, category scoresProgress tracking and recommendations within the servicePerformance of a contract under Art. 6(1)(b) GDPRData is generated by using the app

2.3 Social features

DataPurposeLegal BasisObligation / Consequence of not providing
Friend codes, squadsSocial and competitive functionsPerformance of a contract under Art. 6(1)(b) GDPROptional; without them, social features will not be available
Duel historyRecord of competitive games and resultsPerformance of a contract under Art. 6(1)(b) GDPRData is generated when using duels

2.4 Push notifications

DataPurposeLegal BasisObligation / Consequence of not providing
Device push tokenSending push notifications that are not essential for providing the service itselfConsent under Art. 6(1)(a) GDPRVoluntary; without consent, we will not send you push notifications

You can revoke your consent at any time in your device settings or app settings.

2.5 Crash diagnostics and technical stability

DataPurposeLegal BasisObligation / Consequence of not providing
Pseudonymous user or session identifierAssigning a technical error to a session and resolving itLegitimate interest under Art. 6(1)(f) GDPRData is generated by using the app
Device model, operating system version, and app versionReproduction, analysis, and fixing of crashes and errorsLegitimate interest under Art. 6(1)(f) GDPRData is generated by using the app
Technical crash logs and stack tracesDiagnostics of error causesLegitimate interest under Art. 6(1)(f) GDPRData is generated by using the app

Our legitimate interest is ensuring the app's security, technical stability, and functionality. You may object to processing based on legitimate interest. If the nature of the specific processing allows it, we will also offer you a technical disablement of the relevant function in the app settings.

2.6 Usage analytics

DataPurposeLegal BasisObligation / Consequence of not providing
Screen views, in-app eventsUsage analysis and feature improvementConsent under Art. 6(1)(a) GDPRVoluntary; if refused, we will not run analytics
Pseudonymous app instance identifierAggregate analytics and usage measurementConsent under Art. 6(1)(a) GDPRVoluntary

We will request consent before launching analytics tools, and you can change it at any time in the app settings.

2.7 Session replay

If we activate a session replay tool or similar interface usage analysis technology, we will do so only based on prior consent, if required by law. Before sending, we will mask input fields and other sensitive elements to a reasonable extent. If we do not use this technology, this processing does not occur.

2.8 Advertising

DataPurposeLegal BasisObligation / Consequence of not providing
Advertising ID (e.g., GAID / IDFA) and other advertising identifiersPersonalized ads and ad measurementConsent under Art. 6(1)(a) GDPRVoluntary; without consent, we will not run personalized ads
Data necessary to display non-personalized ads to a technically necessary extentEnsuring the display of non-personalized adsLegitimate interest under Art. 6(1)(f) GDPR only if the specific technology does not require prior consent; if the technology requires consent, we will use consent for this purpose as wellWithout providing this data, the relevant advertising function may not be available

If advertising technologies store or access information on your device, we use them only in accordance with the prior consent rules, unless the specific technology is strictly necessary for a service you have explicitly requested.

2.9 Website joltapp.net

DataPurposeLegal BasisObligation / Consequence of not providing
E-mail for beta registrationInforming about the beta launch and related communication you requestedConsent under Art. 6(1)(a) GDPRVoluntary; without it, we cannot include you in the beta registration
Analytics and marketing pixelsMeasurement of traffic, campaigns, and marketingConsent under Art. 6(1)(a) GDPRVoluntary; without consent, they will not be launched

We launch pixels and similar technologies on the website only after prior consent, unless they are strictly necessary for the website's functioning. If we send you commercial communications or other marketing e-mails based on your beta registration, we will do so only in accordance with applicable laws. Every such communication will contain an easy opt-out option.

2.10 Pre-login identifiers

DataPurposeLegal BasisObligation / Consequence of not providing
Technical session or instance identifier before loginBasic app functions, technical content delivery, protection against abuseLegitimate interest under Art. 6(1)(f) GDPR, or performance of a contract depending on the nature of the specific functionWithout it, the basic technical functioning of the app may not be available

2.11 Where we obtain data from

We obtain personal data:

directly from you during registration, app usage, or communication with us,

from third-party login providers if you choose to use OAuth login,

automatically from your device and app to the extent necessary for technical functioning, security, analytics, or advertising according to your consent settings.

3. Recipients, processors, and other involved entities

Our technology and service providers may be involved in the processing. These partners may act as our processors, or in some cases as independent controllers or other recipients depending on the nature of the service. Therefore, we do not automatically designate all the entities listed below as processors; their status may vary depending on the specific service and contractual setup. If a partner acts as a processor, we ensure a contractual arrangement in accordance with Art. 28 GDPR.

EntityRole TypeServiceData CategoryLocation
Supabase, Inc.typically processorDatabase and authenticationAccount, educational and game data, social dataMay include the EU and third countries depending on service settings
Vercel, Inc.typically processorWebsite hostingTechnical traffic data, beta registration dataMay include the EU and third countries
Resend, Inc.typically processorTransactional e-mailsE-mail address and related technical dataMay include third countries
Google LLC and related Google group companiesprocessor or independent controller depending on the specific serviceCrash diagnostics, analytics, advertisingDiagnostic data, analytics data, advertising identifiers and related dataMay include third countries
Microsoft Corporationprocessor or independent controller depending on the specific serviceSession replay / interface analytics, if activeMasked interface recordings and related technical dataMay include third countries
Meta Platforms Ireland Ltd. and related companiesindependent controller or joint controller depending on the specific serviceWeb pixel and marketing tools, if activePseudonymous event data and marketing identifiersMay include the EU and third countries
TikTok Technology Ltd. and related companiesindependent controller or other recipient depending on the specific serviceWeb pixel and marketing tools, if activePseudonymous event data and marketing identifiersMay include the EU and third countries

If we do not actually use any of the listed services, the respective processing does not take place, and you can remove the entity from the published version. We do not sell your personal data.

4. Transfer of personal data outside the EU/EEA

Some of our providers or their subcontractors may be established outside the European Union or the European Economic Area, particularly in the USA. In such cases, we transfer personal data only if an adequate legal mechanism is ensured for such transfer, in particular:

standard contractual clauses issued by the European Commission,

an adequacy decision, if applicable to a specific country or recipient,

or another legally permissible transfer mechanism.

We do not use the general label "SCC / DPF" without verification. The specific transfer mechanism may vary depending on the recipient and current service settings. Upon request, we will provide you with more detailed information about the mechanism used for a specific category of recipients.

5. Retention period of personal data

We retain personal data only for the time necessary for the stated purposes.

Data CategoryRetention Period
Account data (e-mail, name, avatar)Until account deletion; residual copies in backups are deleted according to providers' retention cycles, usually within 30 days
Educational and game dataUntil account deletion; residual copies in backups are deleted according to providers' retention cycles, usually within 30 days
Social dataFor the duration of account use; completed or expired duels may be deleted continuously according to service settings
Push tokenUntil consent revocation, notification deactivation, or account deletion
Crash diagnostic dataFor the period set by the relevant tool, typically up to 90 days
Analytics dataFor the period set by the relevant tool; where possible, we set reasonably short retention periods
Session replay dataOnly if the service is active and only for the time necessary for analysis; the specific period is governed by the tool's settings
Advertising dataFor the period set by the relevant advertising tools and according to your consent settings
Beta registration e-mailsUntil the end of the beta program and a reasonable time thereafter, but no longer than 6 months, or until consent revocation / opt-out
Pre-login technical identifiersFor the time necessary for the technical functioning of the app; local identifiers may remain on your device until app data is cleared

We may keep aggregated statistical outputs longer, but only if they no longer allow the identification of a specific person or have been properly anonymized. After the respective period expires, we will delete, anonymize, or stop actively using the personal data in accordance with our retention rules.

6. Your rights

You have the following rights in particular:

the right of access to personal data,

the right to rectify inaccurate or incomplete data,

the right to erasure,

the right to restriction of processing,

the right to data portability if legal conditions are met,

the right to object to processing based on legitimate interest,

the right to withdraw consent at any time without affecting the lawfulness of prior processing,

the right to lodge a complaint with a supervisory authority.

You can exercise your rights via e-mail at kupcik46@gmail.com or through in-app functions, if available. We respond to requests without undue delay, at the latest within 1 month of receipt; in complex cases, this period may be extended by a further 2 months, about which we will inform you.

7. Automated decision-making

We do not conduct decision-making based solely on automated processing that would have legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR.

8. Children

The Jolt app is intended for users aged 16 and older as our product rule. This is without prejudice to the fact that under Czech law, the relevant age limit for some consents to personal data processing for information society services is 15 years. We do not knowingly collect personal data from persons who do not meet the conditions for using the app. If you find that such a person has provided us with personal data in violation of this policy, please contact us and we will delete the data without undue delay or take other appropriate measures.

9. Cookies and similar technologies

On the joltapp.net website and possibly in the app, we may use cookies, SDKs, and other technologies that store or access information on a device. We use these technologies only if we have an appropriate legal basis for them. If prior consent is required by law, we will request it beforehand. Without consent, we use only those technologies that are strictly necessary for the transmission of a communication or for a service you have explicitly requested. You can change your preferences at any time in the cookie banner, website settings, or app settings, depending on the nature of the specific technology.

10. Changes to this policy

We may update this policy from time to time. We will inform you of material changes in an appropriate manner before they become effective, for example in the app or by e-mail. If consent is required for a new or expanded processing method, we will request it separately. Continued use of the app itself does not substitute consent where consent is legally required.