Privacy Policy
1. Guest use (no account)
You can use Antigone without an account. In that case the following stays in your device's local storage and is not sent to us or to third parties:
- The record of places you have visited, that is, your Journal and passport (place, date, an optional note, who you went with, a weather tag and any photos you add to a visit)
- Your wishlist and your Expedition route
- Your learning progress: XP, streak and streak freezes, medallions, stones on the Road (Yol), daily quests and monthly emblems, the review deck (questions you got wrong), lesson results, topics learned
- Your notification preferences; which cities you have already received a “nearby site” or “You’re here” notification for; and the log of stamps added automatically in “You’re here” mode (city and day only, no location; section 3)
- Offline city packs you have downloaded (Plus; section 8)
- Your theme, language and personalisation settings, whether you have completed the introduction, and your answer about usage data
XP earned without an account does not count towards the rankings; it stays on the device. Uninstalling the app deletes all of this local data; “Erase data on this device” on the Explorer tab does the same without uninstalling. In guest use, too, crash reports and anonymous usage data are sent only if you have allowed it (section 6), and the contents of the data listed above are never part of them. To show Plus prices, the app connects to the subscription service RevenueCat at launch using a random, anonymous ID (section 8); none of the data listed above is included in that connection.
2. If you sign in: data sent to the server
You may choose to sign in with Apple (iOS and iPadOS) or with Google (Android, via the browser). If you do, the following is stored on Supabase:
| Data | Purpose |
|---|---|
| Account ID and email address (with Apple, this may be Apple's private relay address). No name is requested from Apple. | To identify your account and sign you in |
| Nickname (assigned automatically in the form “Gezgin 12345”; you can change it) | To appear in rankings instead of your real name |
| XP events (which city and stone earned how much XP, when, and in which week), total XP and league | Weekly league and world ranking |
| League membership (week, league, group, weekly result) | To run the weekly league groups |
| Cloud backup: visit records (place, date, your note, companion and weather tags, and only the file names of photos you added to a visit; the photos themselves are not backed up), wishlist, route and all of the learning progress listed in section 1 (the Road, streak and freezes, quests and emblems, review deck, lesson results, topics learned, and the cities whose field-file quiz you passed, with the dates) | Syncing across devices and backup |
| Reports (who reported which player and why) | Moderating nicknames and cheating |
| Friends (only if you use this feature): your invite code, who your friends are and since when, code attempt records (kept for 2 days) and the card shown to your friends (your streak count, the last day your streak stays visible, and the number of places you have visited; deleted once your last friend is gone) | Friends list and shared streak; protection against code guessing |
| Blocks (only if you block someone): whom you blocked and when | Hiding the blocked player's name in your rankings and preventing a friendship between you; only you can see the list |
| City suggestions (only possible while signed in): the name of the city you suggest, its location, your optional note and the app language; linked to your account and stored with the time you sent it | To evaluate whether to add the suggested city to the catalog |
| Antigone Plus entitlement record (only if you have bought Plus; section 8) | To unlock Plus content |
Your notification preferences and your location are not part of the cloud backup. Your nickname and XP may be visible to other players in rankings; your email address, notes and city suggestions are not. City suggestions are read only by the developer and are not shown to anyone in the app, including you. Other players cannot access your records directly, and only you can access your backup. The sign-in token needed to keep you signed in is stored on your device.
Data is hosted by Supabase (Supabase, Inc.) in its Frankfurt (EU) region; Supabase acts as a service provider processing data on our behalf. Apple and Google only verify your sign-in identity, and their own privacy policies apply.
Friends
If you are signed in, you can add friends. Friends are added only with an invite code (or a link that carries the code): your contacts, email and phone number are never accessed, and there is no search by name. Anyone who has your code can add you as a friend, so only give it to people you choose. You can renew your code at any time (the old one stops working at once). You can remove a friend by pressing and holding their name in the list; removal applies to both of you.
You can block a player from the league list or your friends list. A player you block appears without a name in your rankings, any friendship between you is removed for both of you, and neither of you can add the other again. The blocked person is not notified. Whom you blocked and when is stored on the server; only you can see this list, and you can undo a block at any time from the Blocked players list on the Friends screen. Blocking does not file a report.
Your friends see only this about you: your nickname, your streak (number of days), your XP this week, the number of places you have visited, whether you have played today, and your shared “streak together” (the number of consecutive days on which you both played at least one stone). They cannot see which places you visited, your notes, your visit dates, your league, your total XP, your email address or your backup. Your streak and visited-place count are calculated in the app and sent to the server only if you have at least one friend; the shared streak and weekly XP are calculated from the XP events already kept for the rankings. If you enter a wrong code too many times, you cannot try again for a while; attempt records are kept for 2 days for this purpose.
Visitor photos (not yet available)
This paragraph applies from the day photo submission is switched on in the app. If you are signed in, you can send Antigone one of the photos you added to a visit. Before sending, you explicitly confirm that the photo is yours and that you grant Antigone a licence to show it in the app and on its website under your nickname. The photo is re-encoded on your device, and its EXIF data, including location (GPS), is removed before upload. The server stores the photo file, the city it belongs to, your account, the version of the text you agreed to, and the times it was sent and reviewed. We review every photo by hand before publishing it; a photo that is not approved is shown to no one. An approved photo is visible to everyone on the city page under your nickname; your account ID and email address are not shown, and the photo's address contains nothing that links it to your account. Retention: files of rejected photos and of uploads that were never completed are deleted within 30 days; a published photo is kept until you withdraw the licence or delete your account. Other users can report an approved photo; a report stores who reported which photo and why. You can withdraw the licence at any time by writing to us, and we will remove the photo. Deleting your account also deletes the photos you sent and your reports.
3. Notifications and location
Antigone uses only local notifications: they are not sent from a server, the app does not obtain a push token, and our server cannot send notifications to your device. Notification permission is requested in the notification step of the introduction, with the switches on the Explorer tab, or when a Plus free trial starts; if you do not accept the iOS/iPadOS/Android permission prompt, no notifications are shown.
- Streak reminder (off by default): if your streak is alive and you have not played yet that day, a single reminder is scheduled on your device for the time you choose (8 pm by default; you can change it in Explorer → Settings). Only the streak information stored on the device is used.
- Nearby site and “You’re here” (off by default, one switch): when you arrive within about 25 km of an ancient city you have not yet visited, you get a notification, and when you enter a site itself (within about 750 m of its centre) you get a notification suggesting that you open “You’re here” mode. Both work even while the app is closed. They need notification permission and location permission (first “While Using the App”, then “Always”). “Always” permission is requested only when you turn this switch on.
- Trial reminder (Plus; section 8): if you have allowed notifications, a single reminder is scheduled two days before your free trial ends. You can turn it off in Explorer → Settings.
How location is used:
- Region monitoring (only if the switch above is on and “Always” permission is granted): when the app opens or returns to the foreground, your device's last known position (or, if there is none, a single current position) is read once and used to choose up to 20 regions near you: the sites themselves for the few nearest sites (including ones you have visited) and the surroundings of the nearest cities you have not visited and have not been notified about. The catalog coordinates of these places are handed to the operating system's region monitoring; when you enter a region, the system tells the app only which region you entered. There is no continuous location tracking and no location history. Each city sends you at most one “nearby site” notification, with at least 3 hours between such notifications; the “You’re here” notification comes at most once a day for the same site.
- While the app is open (only if you have granted “While Using the App” permission): your approximate position is read to show distances to cities on cards, to find nearby cities in the “Near me” section of the map, and to notice that you are at a site so the app can show the “You’re here” banner. This permission is first requested when you tap “Use my location” in the “Near me” section or in “You’re here” mode.
- “You’re here” mode: this screen, which you open while at a site, reads your position every few seconds for as long as it stays open, to show you on the site map and to open a structure's card when you come close to it. When two consecutive readings place you inside the site, your visit is recorded automatically, in the same form as a visit added with the “I’ve been here” button (place and date); this “stamp” is added at most once a day per city. Location reading stops when the screen closes.
Your coordinates are not stored, are not included in the cloud backup, are not sent to us or to any third party, and are not used in any analysis. The device keeps only which cities you have been notified about, the time of the last notification, and on which day a stamp was added for which city. A visit recorded automatically contains, like any visit you add yourself, only the place and date; if you are signed in, it is backed up in that form. Turning the switch off, or withdrawing location permission, stops region monitoring.
Your position itself is determined by your device's operating system (Apple's Location Services on iOS and iPadOS, the device's location service on Android); those services are covered by their own privacy policies.
4. Other permissions
Photos: when you add a photo to a visit, the system photo picker opens; Antigone receives only the photos you choose and does not see the rest of your library. A chosen photo is scaled down and re-encoded (EXIF data, including location, is removed) and stored only on your device; the cloud backup holds only its file name, not the photo. A photo leaves your device only if you choose to send it, as described under “Visitor photos” in section 2. Deleting a visit also deletes its photos from the device.
Antigone does not request camera, contacts, microphone, calendar, health or motion permission. Apart from the photo picker, the only permissions it asks for are the notification and location permissions described in section 3; both are optional, and if you decline them the rest of the app works the same.
5. Deleting your account and data
You can delete your account inside the app with “Delete account” on the Explorer tab. This deletes the account, nickname, XP, league history, friendships, your invite code and the card shown to friends, blocks (yours and those of others who blocked you), reports, city suggestions, the visitor photos you sent and your reports about photos, the cloud backup and the Plus entitlement record, and asks RevenueCat to delete your subscription customer record. If you signed in with Apple, your Apple sign-in token is also revoked. Deletion runs through a server-side deletion function and is immediate and cascading. The records on your device remain as guest data; you can delete them too with “Erase data on this device” or by uninstalling the app. Deleting your account does not cancel your Apple subscription (section 8).
Because crash reports and anonymous usage data are not linked to your account, they cannot be found and deleted together with it; they are deleted automatically when the period in section 10 ends. A reported nickname may be reset automatically after three separate reports, or hidden by moderation.
The outcome of a deletion (the account ID and whether it succeeded) may be written as one line to the hosting provider's technical log; that line expires automatically at the end of the provider's limited log retention period and is not used for anything else.
6. Tracking, ads, analytics and crash reports
The free version of the app shows non-personalised full-screen ads through Google AdMob (Google Ireland Limited and Google LLC). Ads appear only at natural breaks (after you finish a lesson or as you leave a city page), no more than once every 4 minutes, and never during the first 24 hours after you install the app. Antigone Plus subscribers see no ads. The app does not ask for permission to track you and does not access the advertising identifier (IDFA); there is no cross-app tracking (“tracking” as Apple defines it). Your data is not sold, and your Antigone account, email address, notes, visits and location are never given to Google.
What Google receives. When an ad is requested and shown, the Google Mobile Ads SDK processes, as Google describes it: your IP address (to estimate an approximate location), device and app information (such as device model, operating system and app version, language and screen size), a device identifier specific to this app (IDFV), advertising data and your interactions with ads (an ad being shown, tapped or closed), and performance and crash data. Google uses this to serve and measure ads, prevent fraud and improve its services. Non-personalised ads are chosen by context and approximate location, not by an interest profile. Details: Google Privacy Policy and How Google uses information from sites or apps that use its services.
EU/EEA, United Kingdom and Switzerland. In these regions Google's consent form (Google's certified consent management platform) is shown once before any ad is requested; it opens at the first natural break in the app, not during onboarding. You can change your choice at any time in Explorer → Settings → “Ad privacy options”; this option appears in settings once Google's consent check has run on your device (that is, once ads are active for you). If you do not consent, Google may show only limited ads that use no cookies or device identifiers, or no ads at all.
We ask first. During the introduction, on the notifications step, we ask once with a separate “Send anonymous usage data” switch. The switch starts off, is independent of notification permissions, and is only on if you turn it on. Until you answer, neither crash reports nor usage data are sent. Usage events that occur during the introduction meanwhile wait only in the device's memory: if you turn the switch on and continue, they are sent; if you leave the step with the switch off (including “Skip”), or close the app without answering, they are deleted without being sent. You can change your choice at any time with the “Send anonymous usage data” switch in Explorer → Settings; the switch turns both services on and off together. Once you turn it off, nothing more is sent; data already sent is deleted when the period in section 10 ends. Your choice is stored only on your device.
If you agree, we use two services to fix and improve the app. Neither is linked to your Antigone account, your name, your nickname or your email address:
- Crash reports (Sentry, Functional Software, Inc.). When the app crashes or an error occurs, a technical report is sent: the error message and where in the code it happened, the app and operating system versions, the device model, technical details such as memory and storage state and the device's language and time zone settings, and the few technical steps just before the error (for example, which screen was opened). In addition, whether app sessions ended in a crash and performance measurements such as launch time (for a sample of sessions) are sent. Your notes, nickname and search text are removed from these steps; no screenshot is taken, no user ID is attached to the report, and your IP address is not stored. The data is kept in Sentry's EU (Germany) region.
- Anonymous usage data (PostHog, Inc.). Counts which screens and features are used: opening the app, which screen was opened (only the type of screen, for example “city page”, not which city), the steps of the introduction, starting and finishing a lesson (whether it was passed, and a rough accuracy range), where a city was opened from, recording a visit, whether a search was made and whether it had results (not what you searched for), share cards, map filters, opening a field file or “You’re here” mode, whether a permission was granted when it was requested, and the steps on the Plus sales page (why the page was opened, the plan chosen, and whether the purchase was completed or abandoned; not any error text). Only city, lesson and structure IDs, counts and fixed options are sent with these events, together with the app version and language, the platform, the device manufacturer and model, the operating system version, the screen size and the device's language and time zone settings. The identifier is a random installation number created on your device when you give permission; it is never matched with your Antigone account, your email address or the advertising identifier, and it changes if you delete and reinstall the app. No person profiles are created; your IP address and any location derived from it are not stored, no screen recording is made, and nothing you type is collected. The data is kept in PostHog's EU (Germany) region.
7. Photos, maps and technical connection data
City photographs in the app mostly come from Wikimedia Commons under their licences (CC BY, CC BY-SA, public domain) with photographer credits; see About → Photo credits in the app. Catalog information is based on UNESCO and Turkish Ministry of Culture and Tourism sources; these institutions receive no data from you through the app.
City photos may be bundled in the app or downloaded from our hosting server (Supabase Storage). The map is drawn with Apple Maps on iOS and iPadOS, Google Maps on Android, and CARTO/OpenStreetMap tiles in the web version. When a file or map tile is downloaded, or when the app connects to a server (sign-in, backup, league, subscription status), your IP address and technical request details (time, requested address, browser or app information) may technically end up in that server's logs, even if you have no account. These logs are deleted after the provider's limited retention period. We do not use this information for analytics or advertising; the map providers' own privacy policies apply.
8. Antigone Plus
Antigone Plus is the app's paid subscription; what it includes, and the limits of the free version, are shown on the Plus page in the app before you buy. The purchase terms are in section 6 of the Terms of Use. Plus subscribers see no ads.
- Payment is handled by Apple. Plus is an auto-renewing subscription bought on the App Store with your Apple ID. Apple processes the payment; your card, billing or payment details never reach us or RevenueCat. Apple's privacy policy applies.
- An account is required. You are asked to sign in before buying or restoring Plus, so that the subscription is tied to your Antigone account and works on all your devices.
- RevenueCat (RevenueCat, Inc., USA). A subscription service that works on our behalf to verify App Store purchases and keep track of subscription status. The app connects to RevenueCat when it opens: with a random, anonymous ID if you have no account, or with your Antigone account ID (a random number; your name and email address are not sent) if you are signed in. RevenueCat processes this ID; the App Store's purchase records (product, plan, purchase, renewal and expiry dates, trial, cancellation and refund information, store country and currency); technical details such as the app and operating system versions; and your IP address during the connection. If you have not bought anything, RevenueCat holds only the anonymous ID and technical details. RevenueCat may process data in the USA; this transfer is subject to safeguards such as standard contractual clauses. RevenueCat's privacy policy also applies.
- Plus entitlement record. When something changes in your subscription, RevenueCat notifies our server. Our server then fetches the current status from RevenueCat and writes the following to a single record linked to your Antigone account: until when Plus is valid, its source (for example, the App Store), the product, the environment (real or test purchase), the status (active, cancelled, billing issue, expired, transferred to another account), and the ID and time of the latest update. Only the server writes this record; the app only asks “do I have Plus?”. Purpose: unlocking Plus content.
- Field files. The field files included in Plus are downloaded from the server while you are signed in and stored on your device so that you can read them offline. A copy is tied to the account that downloaded it; no other account or guest can see it. Copies are deleted from the device when you sign out, when you delete your account, or when the server reports that your Plus has ended. Offline, a copy opens if your entitlement was confirmed within the last 30 days. Which field files you read is not recorded in the database (if you have agreed, it is only counted in the anonymous usage data described in section 6).
- Offline city packs. With Plus you can download a city's photos and field file to your device. The photos are kept in the device's cache and are not deleted when Plus ends; the field file in the pack follows the rules above. You can delete a pack at any time.
- Trial reminder. If you start with a free trial and have not yet decided on notification permission, you are asked for it once when the trial starts. If you allow notifications, a single local reminder is scheduled on your device two days before the trial ends and the first payment is taken. You can turn it off in Explorer → Settings.
- Deleting your account does not cancel the subscription. Deleting your account also deletes the Plus entitlement record and your RevenueCat customer record, but your Apple subscription continues. To stop being charged, cancel the subscription in your device's Settings → [your name] → Subscriptions. Apple keeps its own purchase records under its own rules.
9. Children
Antigone is not directed to children under 13 and does not intend to knowingly collect personal data from them. Creating an account is optional; if you are under 13 (or below the age of digital consent in your country), please do not sign in or agree to send usage data without a parent's permission. If we become aware of an account belonging to a child, we will delete it.
10. Retention
Account data, the Plus entitlement record and your RevenueCat customer record are kept until you delete your account; deletion is immediate and cascades to all linked data. Server logs are deleted at the end of the provider's limited retention period. Crash reports are kept for at most 90 days and anonymous usage data for at most 12 months, then deleted. Data on your device stays there until you uninstall the app or use “Erase data on this device”; field-file copies are also removed when you sign out. Google keeps advertising-related data under its own policy; Antigone does not receive or store it.
11. Your rights (KVKK and GDPR)
You have the right to learn whether your data is processed, to request a copy, to have it corrected or deleted, to object to processing, to withdraw consent you have given, and (under the GDPR) to data portability, as well as the right to complain to your supervisory authority (in Türkiye, the Personal Data Protection Authority, KVKK). Deletion is self-service via “Delete account” in the app; for other requests, write to [email protected]. Controller: Sezer Kuşku.
Legal bases: entering into and performing the contract (account, backup, league, friends and Plus, including purchase verification through RevenueCat); legitimate interest (security, preventing abuse and cheating, technical connection logs); your consent (crash reports and anonymous usage data; you can withdraw it at any time in Explorer → Settings, and withdrawal does not affect the lawfulness of processing before it); and, for notifications and location, the permission you give in the operating system's prompt (which you can withdraw at any time in your device settings).
Service providers and where data is processed: account data through Supabase (EU, Frankfurt), crash reports through Sentry (EU), anonymous usage data through PostHog (EU), and subscription status through RevenueCat (USA). Transfers outside the EU or Türkiye, and service providers' sub-processors outside the EU, are subject to the safeguards required by applicable law, such as standard contractual clauses.
Advertising: showing non-personalised ads in the free version is based on our legitimate interest in keeping a free version available; in the EU/EEA, the United Kingdom and Switzerland, storing and reading information on your device relies on the consent you give in Google's consent form. Google acts as an independent controller for its advertising service and may process data in other countries, including the United States, subject to Google's standard contractual clauses.
12. Changes and contact
Changes will be published at this address with an updated effective date. New in version 1.4 (compared with the previously published version, 1.1): non-personalised ads through Google AdMob in the free version and the EU/EEA consent form (sections 6, 8, 10 and 11); crash reports (Sentry) and anonymous usage data (PostHog), sent only with your permission, and how permission is asked for and withdrawn (section 6); the Antigone Plus subscription, RevenueCat and the Plus entitlement record (section 8); local notifications, “You’re here” mode and on-device location use (section 3); friends, what friends see and blocking, and the current contents of the cloud backup (section 2); visit photos that stay on your device (section 4); visitor photo submission, which is not yet available (section 2); technical logs (sections 5 and 7); retention periods (section 10) and legal bases (section 11). Contact: [email protected]