Privacy Policy
What we collect, how we use it and how to manage your data.
Last updated 21 September 2026
We do not sell your data or run advertising. Habit names, notes and oaths are excluded from analytics. You can export your data, reset your progress or delete your account in the app or by contacting us. A pseudonymised trial record is retained for up to 12 months after deletion; §8 explains why.
1. Who we are
Torchkeep is made by Synthesist Ventures (Pty) Ltd, of 222 Smit St, Johannesburg 2001, South Africa. We are the data controller — the “responsible party”, in South African law — for the information described here.
This policy covers the Torchkeep app on Android and iOS and this website. If you want to talk to a person about any of it, write to admin@synthesistventures.com or call +27 72 449 7688.
Using Torchkeep is also governed by our terms of service, which cover the trial and subscription, what happens to your account if you stop paying, and the law that applies between us. This policy is part of that agreement.
We are established in South Africa and subject to the Protection of Personal Information Act (POPIA). We also offer Torchkeep in the UK and European Economic Area, where the UK GDPR and EU GDPR apply. Where protections differ, we apply the stronger protection. The rights in §9 are available to everyone.
2. What we collect
We collect the information needed to run your account and record your activity. For example, completion records let us calculate your streaks.
| Kind | What it is | Why we have it |
|---|---|---|
| Account | Email address; a hashed password or a passkey public key; an internal account ID | To create your account and sign you in. |
| Your hero | Hero name, appearance and class choices, oaths | To run the game and show your character to you — and to other heroes only as far as your visibility settings allow. |
| Habits and progress | Runes, Rituals, Quests, completions, streaks, XP, Coins, Stats, Journey progress, engraved runes, notes you write on a rune | To record your activity and calculate XP, levels and streaks. |
| Social | Companions, shared vigils, Sparks and camp-post notifications, blocks and mutes, your visibility settings | To run the optional social features, and to enforce the limits you set. There is no freeform chat in Torchkeep — camp post carries system-written notices, not messages you type. |
| Approximate location | A four-character geohash — an area roughly 20 km across | Only if you turn it on, and only to tag quests as weather-appropriate. See §5. |
| Device | Platform and app version, time zone, and a push notification token if you allow notifications | To deliver notifications, and to keep "today" and your streak correct when you change time zone. |
| Usage | Screens opened, features used, which experiment variant you saw, bucketed counts — never the text of a habit | To understand how people use the app. Enabled by default; you can disable it in Settings. See §6. |
| Crash reports | Error messages, stack traces, a tag for what the app was doing, your account ID | To find and fix bugs. Configured to send no personal data beyond that ID. |
| Subscription | Whether you have an active subscription or trial, and when it renews or lapses | To unlock the app. We never receive your card details — see §4. |
| What you send us | Support reports, emails, answers to questions we ask in-app | To reply, and to fix what you tell us about. |
We do not collect card details, contacts, photos, calendar entries or health records from your device. Torchkeep does not offer freeform messaging between users.
Information processed on your device
These features process information on your device without sending it to our servers:
- The Doorway helping hand (Android) reads the list of apps installed on your phone so you can pick one to open from a Rune. That list stays on the device.
- The light sensor helping hand reads ambient brightness to tell whether you actually went outside. The reading is used and discarded.
Your device calculates sunrise and sunset to choose the app’s day or night theme. This calculation stays on the device.
3. How we use it
We use your records to calculate XP, levels, Coins and streaks; personalise quests; deliver requested notifications; investigate crashes; and understand how people use the app.
We do not sell your data, share it with data brokers or use it for advertising. The app contains no advertising SDK.
4. Who else sees it
The following providers process information to help us operate Torchkeep. Their contracts limit how they may use it.
| Provider | What they get | What for |
|---|---|---|
| Supabase | Everything in §2 except crash reports, purchases and analytics | Our database, sign-in and server functions. Hosted in the EU (Stockholm). |
| Corbado | Passkey credential material | Passwordless sign-in on the web. |
| Google (Firebase Cloud Messaging) | Your push token and the text of the notification | Delivering camp-post notifications to your device. |
| PostHog | Usage events and your account ID | Product analytics, on their EU cloud. Off entirely if you opt out. |
| Sentry | Crash reports and your account ID | Error monitoring. Configured with personal data and performance tracing off. |
| Anthropic | Your level, local weather, the names of your rituals, and any likes or dislikes you entered | Generating a personalised daily quest. Sent from our server, never from your phone. |
| Open-Meteo | An approximate location as a geohash, without your account ID or name | Looking up the weather for an area. |
| RevenueCat | Your account ID and the purchase receipt from the store | Keeping one subscription working across Android and iOS. |
| Tally | What you type into the early-access form on torchkeep.com, and the page you opened it from | Running the early-access sign-up form on our website. Nothing in the app sends it anything. |
| Google Play / Apple | The information needed to process your store purchase | Taking the payment. See §4 on why we never hold your card details. |
Subscriptions are sold through Google Play and the App Store. The stores process payment. We receive subscription information, including its status and renewal date, but no card details.
We may also disclose information where the law requires it, to protect someone's safety, or as part of a merger or sale of the business — in which case whoever receives it is held to this policy or gives you notice before anything changes.
5. Location
Location is optional and off until you enable it. Your device sends a four-character geohash, identifying an area roughly 20 km across. We use it to look up local weather. Your precise coordinates stay on your device.
We send the geohash to Open-Meteo without an account ID. Turning location off deletes the stored geohash from our servers. Deleting your account clears the cached position from your device.
6. Analytics, and how to turn it off
Product analytics is on by default. Turn it off in Settings → Privacy → Helping us improve. The change applies from the next event, without restarting the app.
Analytics records which screens you open and features you use, along with counts grouped into ranges. It excludes your email address and text you enter, including habit names, anchors, notes and oaths. Automated checks help enforce this restriction.
Analytics runs on PostHog’s EU cloud. Session replay, which records screen activity, is not enabled. If analytics is enabled, you may see an optional in-app survey.
7. Our legal grounds
The table cites the GDPR articles, because they are the more specific of the two regimes. POPIA s11 recognises the same grounds under different names — contract, consent, and legitimate interests — so each row holds either way.
| Purpose | Basis |
|---|---|
| Running your account and the app | Performance of a contract (Art. 6(1)(b)) |
| Taking payment and managing subscriptions | Performance of a contract (Art. 6(1)(b)) |
| Location-based quest personalisation | Consent (Art. 6(1)(a)) — the device permission, withdrawable at any time |
| Product analytics and crash reporting | Legitimate interests (Art. 6(1)(f)) — improving the app, balanced against a one-tap opt-out |
| Keeping a spent-trial record for 12 months | Legitimate interests (Art. 6(1)(f)) — preventing repeat free trials. See §8 |
| Security, abuse handling and legal obligations | Legitimate interests and legal obligation (Art. 6(1)(f), (c)) |
Where we rely on legitimate interests you have the right to object, and for analytics that objection is the toggle in §6 — you do not have to write to us to exercise it.
8. How long we keep it
We retain account data while your account exists. Account deletion removes it immediately and cannot be reversed. Copies may remain temporarily in encrypted backups until those backups rotate out. The trial record and provider retention are explained below.
Trial records after deletion
After account deletion, we retain a trial record for up to 12 months to prevent repeated free trials. It contains a one-way hash of your email address and the number of unused trial days. We cannot reverse the hash to read your address. This record expires automatically and does not delay account deletion.
The trial record is pseudonymised personal information. It holds the hashed address, unused trial days and an expiry date. It contains no name, habit records or account ID.
Support emails are kept while they are useful and then deleted. Analytics events are pseudonymous and expire on our provider's retention schedule; if you delete your account and want your analytics history purged too, say so when you write to us and we will do it by hand.
9. Your rights
The following options are available in Settings:
- Take a copy of everything — Settings → Export my data creates a file containing your account data, including habit names and other text you entered.
- Start fresh — Settings → Fresh start wipes your progress while keeping your account.
- Delete everything — Settings → Delete account, or ask us from the web if you have already uninstalled.
You also have the right to ask us to correct data that is wrong, to restrict or object to certain processing, and to receive your data in a portable form — that last one is the export above. Write to admin@synthesistventures.com for anything the app does not already do, and we will answer within 30 days. We will not charge you, and we will not make you justify the request.
If you think we have handled your data badly, you can complain to a regulator. Because we are established in South Africa and serve people abroad, more than one may be open to you:
- South Africa — the Information Regulator, which supervises us directly under POPIA.
- United Kingdom — the Information Commissioner's Office.
- EEA — the supervisory authority of the country you live in.
You may contact a regulator directly. You do not need to complain to us first.
10. Deleting your account
Account deletion removes your profile, hero, Runes, Rituals, Quests, completion history, streaks, engravings, Journey progress, Coins, inventory and companion links. We cannot restore a deleted account.
Use Settings → Delete account for immediate deletion. If you cannot access the app or would prefer help, send a request; we will complete it within 30 days. The trial record and backup and provider retention are described in §8.
Cancelling your subscription is a separate thing and happens in Google Play or the App Store — deleting your account does not cancel a subscription, and we cannot cancel it for you.
11. What other heroes can see
Torchkeep's Privacy screen controls, separately for anyone on the road and for your companions, whether they can see your hero name, your fire, your class and your strongest oath, whether you turn up in search, and who may send you invites, Sparks or companion requests.
Server-side access controls apply your visibility choices when information is requested. Torchkeep has no leaderboards or public profile pages.
12. Children
Torchkeep is not intended for children under 13, or under the minimum age where you live if that is higher, and we do not knowingly collect their information. If you believe a child has created an account, write to us and we will delete it.
13. Data storage and international transfers
Our database and server functions run in Stockholm, in the European Union, regardless of where you use the app.
Access to this data can involve the following international transfers:
- To us, in South Africa. We administer the service from South Africa, so our own access to your data is a transfer out of the EU. It is covered by appropriate safeguards — standard contractual clauses — and by the fact that you are asking us to run the service for you.
- To the providers in §4. Some process data in the United States or elsewhere. Where they do, we rely on standard contractual clauses and, for providers certified under it, the EU-US Data Privacy Framework.
POPIA s72 governs transfers out of South Africa in the same spirit: we send personal information onward only to recipients bound by comparable protection, which the same contractual terms provide.
14. Security
Data travels over encrypted HTTPS/TLS connections. Server-side access controls check identity and restrict access to game data. Production access is limited to people who need it to operate the service. If a security incident occurs, we will notify you and the relevant authority within the time required by law.
15. Changes to this policy
We update this policy when our data practices change. New providers are disclosed in §4 before they receive user data. Material changes will also be announced in the app, and the date at the top of this page will be updated.
16. Contact
Questions about this policy, or about your data: admin@synthesistventures.com, or +27 72 449 7688. By post: Synthesist Ventures (Pty) Ltd, 222 Smit St, Johannesburg 2001, South Africa.
For anything else about the app, the help page is a better start.