Legal
Privacy Policy — Aquary
Learn what data the Aquary mobile application collects, how it is used, and how it is protected.
Effective date: August 4, 2026
This Privacy Policy describes how the Aquary mobile application (the "App"), published by Deruvish Labs, LLC ("we", "our", "us"), collects, uses, and protects personal information.
In short: Aquary requires no account, email, password, or phone number. It contains no ads, behavioral analytics, or cross-app tracking. RevenueCat is used only for purchase validation, subscription functionality, and aggregate purchase analytics. We do not sell your data or share it for marketing.
Data Controller
- Deruvish Labs, LLC, Sheridan, Wyoming, USA
- Contact: contact@deruvishlabs.com
Data Stored Only on Your Device
Your game progress (fish, decorations, in-game currencies, care values), settings, and sound preferences are stored only on your device. If you never use the social features, this game and social data is not sent to our Supabase social service. Data processed by RevenueCat for purchase validation is described separately under “Purchase Data” below.
In addition, the device's secure keystore (Keychain) holds anonymous transaction identifiers for delivered purchases (to prevent duplicate delivery) and, if you use the social features, the random device key. By operating-system design these records may remain on the device even after the App is deleted; they contain no personal details such as your name or email address.
Data Stored on Our Servers If You Use Social Features
Friends is optional; no social data leaves your device until you open the Friends section. When you first open the "Friends" feature, an anonymous record is created on our server to run the social features:
- Random device key: An anonymous identifier generated on your device. It is not linked to your name, email address, or any other account.
- Aquarium name and #TAG: The display name you choose and a randomly generated short tag.
- Aquarium status summary: Fish species and the nicknames you give them, placed decorations, and care values (such as water and fullness) — so that your friends can visit your aquarium.
- Friend connections: Connections you establish with one-time invite codes, caretaking permissions, and care journal entries.
- Block records: A record kept when you block an aquarium.
- Short-lived security counters: A one-way digest of the random device key and an HMAC digest derived from the IP address observed during the connection, using a server-only secret; the action category (for example registration, invitation, aquarium snapshot, or care), request count, and timestamp are used to limit automated abuse. Our application code does not store the raw IP address in the social database.
- Supabase connection logs: Supabase Edge infrastructure automatically records request/response metadata for service security, abuse prevention, and technical operation. This metadata may include the raw IP address and IP-derived approximate network location (country/region/city), request time and status, and execution duration. Aquary does not request iOS Location Services and does not collect GPS or precise location.
This data is hosted on Supabase infrastructure on servers in the European region. The App has no search, no discovery, and no matching with strangers; connections are made only through invite codes you share yourself. There is no free-text chat.
Purchase Data
In-app purchases and the Aquary+ subscription are processed by the Apple App Store or Google Play Store. We never have access to your payment details (such as card numbers). We use RevenueCat to validate purchases; RevenueCat processes an anonymous app user ID, product identifiers, transaction records, subscription status, and aggregate purchase analytics derived from those records. We do not use this data for advertising or cross-app tracking.
Notifications
Notifications are scheduled only on your device. In addition to one optional gentle daily invitation, one-time care alerts may be scheduled when fullness, water clarity, or temperature crosses a care threshold. Alerts are deferred during quiet hours and capped at 40 care alerts in each 14-day schedule. We do not collect push notification tokens; notification permission is entirely optional and can be turned off in system settings.
What We Do Not Use
- No ad networks; no advertising identifiers (IDFA/GAID) are collected.
- No behavioral, advertising, or cross-app tracking SDKs.
- No iOS location permission, GPS, or precise-location access. Supabase's IP-derived approximate network location is disclosed separately above.
- No access to contacts, camera, microphone, or photos.
- Your data is never sold, rented, or shared for marketing.
If this ever changes (for example, optional rewarded ads are added), this policy will be updated and the effective date renewed.
Third-Party Services
- Apple App Store / Google Play Store — Distribution and payment processing
- RevenueCat — Purchase validation, subscription management, and aggregate purchase analytics
- Supabase — Social feature database hosting (EU region), Edge request delivery, abuse prevention, and limited-retention connection logs
Legal Bases (GDPR)
- Performance of a contract: Providing the social features at your request.
- Legitimate interests: Preventing abuse (e.g., block records) and keeping the service secure.
- Consent: Where required for hosting data on servers abroad.
Data Retention
- Social data: Retained until you delete it. You can remove it immediately from the active database in Settings → Delete my data; provider backups expire through their ordinary retention cycle.
- Abuse-prevention counters: One-way device/IP digests have an operational lifetime of no more than one hour. Expired rows are normally deleted by a scheduled cleanup every 15 minutes; temporary service interruptions may delay physical deletion. Expired counters are not used for new rate-limit decisions.
- Supabase Edge connection logs: Retained for Supabase's limited, plan-dependent log retention window; on the plan currently in use, that window is no more than one day.
- Purchase records: Retained by the stores and RevenueCat for legally required periods.
- On-device game data: Deleted when you uninstall the App. The operating system may keep the random device key in secure storage across reinstallations for security and fraud prevention; this key contains no name, email address, or advertising identifier.
Children's Privacy
The App does not knowingly collect personal information from children under 13. By design, the social layer has no matching with strangers, no search, and no chat. If you are a parent or guardian and believe your child has provided us with data, contact us at the address below and we will delete it promptly.
Your Rights
Under applicable data protection laws (including the GDPR), you have the right to access, correct, delete, object to the processing of, and port your data. Use the in-app deletion path, or email contact@deruvishlabs.com with the subject "Aquary Privacy Request." You also have the right to lodge a complaint with your local data protection authority.
Security
Data is encrypted in transit (HTTPS/TLS) and stored on access-restricted infrastructure. No method is 100% secure; we apply reasonable technical and organizational measures.
Changes
We may update this policy from time to time. For material changes, we will update the effective date and provide notice through appropriate means.
Contact
Deruvish Labs, LLC, Sheridan, Wyoming, USA.
Email: contact@deruvishlabs.com