ZQNZ Privacy Policy
Effective date: June 3rd 2026
ZQNZ is provided by Edvard Zeke Julius Witasp Gruvelgård. Contact: ezjwg@icloud.com
This Privacy Policy explains how ZQNZ handles information when you use the app, including local gameplay, local sequence creation, and community features.
Summary
- You can play locally and create locally saved sequences without an account.
- Community features use a username and password account. We do not collect email addresses for username-only accounts, and there is no email-based password recovery.
- The app uses YouTube playback through a visible embedded YouTube player. The app stores sequence data and limited YouTube metadata, not YouTube audiovisual content.
- The app uses Supabase to provide community accounts, published sequences, ratings, reports, moderation, sessions, and completion results.
- This release has no advertising, no in-app purchases, no third-party analytics, no cross-app tracking, and no sale of personal data.
Data Controller
For privacy laws such as the EU General Data Protection Regulation (GDPR), the data controller for ZQNZ community-account and community-feature data is:
- Controller: Edvard Zeke Julius Witasp Gruvelgård
- Contact: ezjwg@icloud.com
- Address: Visättravägen 30, 14150, Huddinge, Sweden
Data We Collect
When you use the app locally without an account, sequence data and local best results can remain on your device. That local-only data is not sent to our backend unless you choose to publish or otherwise use community features.
When you use community features, we store or process:
- Account data: username, internal account ID, password hash, session token records, account role, account status, and timestamps.
- Community sequence data: YouTube video ID, canonical YouTube URL, YouTube title, duration, metadata refresh timestamp, note JSON, sequence duration, visibility, moderation status, timestamps, play count, rating summary, and report count.
- Community activity: ratings, reports, optional report comments, author blocks, published-sequence deletion actions, and moderation actions.
- Gameplay results for community sequences: completion status, hit percentage, hit count, miss count, maximum streak, total note count, and best result.
- Abuse-prevention data: rate-limit counters, report identifiers, session tokens, and request metadata needed to operate, secure, and protect the community features.
- Support data: information you send to ezjwg@icloud.com, such as your username, device/app details, issue description, and contact information.
The app does not intentionally collect email address, phone number, physical address, precise location, contacts, camera data, microphone data, photos, health data, financial data, advertising identifiers, or payment information.
How We Use Data
We use data to:
- Create, authenticate, maintain, and delete username/password accounts.
- Publish, display, sort, rate, report, block, moderate, and delete community sequences.
- Show community discovery information such as ratings, play counts, and best completion results.
- Keep local gameplay available without an account.
- Enforce rate limits, detect abuse, prevent duplicate reports, protect the service, and support moderation.
- Refresh, sanitize, or remove stale YouTube metadata in line with YouTube API policy.
- Respond to support, privacy, legal, platform-review, security, and takedown requests.
Legal Bases For EU/EEA Users
Where GDPR or similar law applies, we rely on these legal bases:
- Contract: to provide requested app functionality, including accounts, sessions, community publishing, ratings, reports, sequence discovery, completion results, and account deletion.
- Legitimate interests: to secure the service, prevent abuse, apply rate limits, moderate community content, preserve de-identified moderation records, respond to support requests, and maintain service integrity.
- Legal obligation: to comply with applicable law, lawful requests, disputes, and takedown obligations.
- Consent: only where the app or platform asks for consent for a specific optional action. This release does not use consent for advertising, analytics, or tracking because those features are not included.
YouTube And Google
ZQNZ uses YouTube API Services and a visible embedded YouTube player. By using YouTube playback features in the app, you are also using YouTube/Google services.
The app stores sequence data and limited YouTube metadata: video ID, canonical URL, title, duration, and metadata refresh timestamp. The app does not download, cache, extract, isolate, or background-play YouTube audiovisual content.
YouTube and Google may process information when the embedded player loads or plays a video. Review:
- YouTube Terms of Service: https://www.youtube.com/t/terms
- Google Privacy Policy: https://policies.google.com/privacy
- Google Security Settings: https://security.google.com/settings/security/permissions
Service Providers And Recipients
We use:
- Supabase: backend database, API, account/session storage, community content storage, moderation records, and security/rate-limit support.
- YouTube/Google: embedded YouTube playback and YouTube metadata/player services.
- Apple: App Store distribution, platform review, TestFlight if used, device platform services, and App Store privacy/compliance processes.
These providers may process data according to their own terms and privacy practices. We do not sell personal data.
Retention
We keep data only as long as needed for the purposes described in this policy, unless a longer period is required or reasonably needed for safety, abuse prevention, dispute resolution, or legal compliance.
- Local sequences and local best results remain on your device until you delete them, delete the app, or your device removes the data.
- Account, session, published sequence, rating, block, and completion data are kept while your account and community content remain active.
- Published sequences can be deleted by the publishing account or removed through moderation.
- Account deletion removes the account, sessions, public username identity, and user-published sequences. Ratings are removed through account deletion. Reports may be removed or de-identified where needed for safety, abuse prevention, or legal compliance.
- YouTube metadata is refreshed or sanitized within the YouTube policy window used by the backend cleanup process, currently 30 days.
- Support emails and legal/takedown correspondence may be kept as needed to respond to the request and maintain records.
Account Deletion
You can delete your account in the app. You must enter your password to confirm deletion.
Account deletion removes your account, sessions, public username identity, and published sequences. Some moderation records may be retained without your account identity where needed for safety, abuse prevention, or legal compliance. Because accounts use only username and password, we cannot recover a lost password by email.
Your Privacy Rights
Depending on where you live, including under GDPR or applicable US state privacy laws, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data associated with you.
This release does not sell personal data or use personal data for cross-context behavioral advertising.
To make a privacy request, contact ezjwg@icloud.com. Include enough information to identify your account, such as your username. Do not send your password.
If you are in the EU/EEA, you may also have the right to lodge a complaint with your local data protection authority.
International Transfers
Supabase, YouTube/Google, Apple, and support systems may process data in countries other than your country of residence. Where required, transfers are handled using appropriate safeguards required by applicable law.
Security
We use reasonable technical and organizational measures to protect community data, including HTTPS requests, Supabase access controls, Row Level Security policies, rate limits, password hashing, and session-token storage. No method of transmission or storage is completely secure.
Do not share your password. Because the app does not collect email addresses, we cannot reset a lost password by email.
Community Reports And Moderation
Users can report community sequences for inappropriate username, abuse, spam, or other concerns. Signed-in users can also block authors where the app exposes that option. We may hide, remove, restore, or moderate content; delete accounts; preserve or de-identify reports; and take other reasonable actions to protect users, enforce the Terms, comply with platform rules, and comply with applicable law.
Copyright And Takedown Requests
The app does not host YouTube audiovisual content. For copyright concerns about a YouTube video, use YouTube's reporting tools.
For concerns about usernames, sequence note data, community metadata, or other content inside ZQNZ, contact ezjwg@icloud.com with enough detail to identify the content, the reason for the request, your contact information, and any rights you believe are affected.
Children
ZQNZ is not directed to children under 13 and is not intended to knowingly collect personal information from children under 13. The app includes visible YouTube playback and public community features, so App Store age-rating answers should account for YouTube content and user-generated community content.
If you believe a child has provided personal data, contact ezjwg@icloud.com.
Changes
We may update this policy when the app, backend, legal requirements, or platform requirements change. The latest version will be available at https://zqnz.app/privacy.