00
PPrivacy Preamble
Welcome to the Pact Data Sanctuary. This Privacy Policy explains how we collect, use, store, protect, and share your personal information when you use our chromatic exploration application. We treat your data with the same reverence you bring to capturing fleeting moments of color.
By using Pact, you entrust us with your visual memories, emotional states, and location journeys. We honor this trust through transparent data practices, robust security measures, and an unwavering commitment to your privacy rights.
🔒 Our Privacy Promise
We will never sell your personal data. We minimize data collection to what is essential. We empower you with control over your information. We maintain strict confidentiality in all chromatic matters.
01
1Information We Collect
1.1 Visual Chromatic Data
Images captured through the Application, including metadata and color analysis results.
- Captured Images: Full-resolution photographs taken via Pact's camera interface or imported from device galleries
- Color Analysis Data: Dominant color values, hex codes, RGB values, and color distribution maps generated by our algorithms
- Image Metadata: Timestamps, device camera settings, orientation data, and file format information
- Visual Fingerprints: Unique identifiers for duplicate detection and cloud synchronization
1.2 Emotional & Cognitive Data
Your subjective responses to chromatic experiences and creative expressions.
- Mood Tags: Emotional states you associate with specific colors or photographs (e.g., "serene," "energized," "melancholic")
- Descriptive Text: Captions, stories, and narrative content accompanying visual entries
- Reaction Data: Heart ratings, favorites, and engagement patterns with your own content
- Color Preferences: Historical patterns of color selections and spin outcomes
1.3 Geolocation Data
Location information that maps your chromatic explorations across physical space.
- GPS Coordinates: Precise latitude and longitude captured when photographs are taken (with permission)
- Place Names: Reverse-geocoded addresses, landmarks, and neighborhood identifiers
- Route Data: Sequential location points forming your color hunting journeys
- Environmental Context: Weather conditions, time of day, and lighting quality at capture moments
1.4 Account & Identity Data
- Email address (dahipactakde019j@zohomail.cn or your provided address)
- Username and profile identifiers
- Encrypted authentication credentials and password hashes
- Account creation date and activity timestamps
- Device identifiers and IP addresses for security
1.5 Technical & Usage Data
- Device model, operating system version, and screen specifications
- Application crash logs and performance metrics
- Feature usage patterns and interaction frequencies
- Color wheel spin counts and session durations
- Network connection types and bandwidth statistics
02
2How We Use Your Data
2.1 Core Service Provision
Your data powers the essential chromatic functions of Pact:
- Color Categorization: Analyzing uploaded images to extract and organize by dominant hues
- Memory Organization: Creating your personal visual archive sorted by color, time, and location
- Journey Mapping: Displaying your chromatic explorations across geographic space
- Mood Correlation: Connecting emotional tags with color patterns for personal insights
2.2 Service Improvement
We analyze aggregated, anonymized data to:
- Enhance color recognition algorithm accuracy
- Optimize cloud storage and synchronization speeds
- Develop new features based on usage patterns
- Identify and resolve technical malfunctions
- Improve user interface and experience design
2.3 Communication
We use your contact information to:
- Send essential service notifications (security alerts, policy updates)
- Respond to inquiries sent to dahipactakde019j@zohomail.cn
- Deliver personalized color insights (if opted in)
- Notify you of significant changes to your visual archive
Advertising Prohibition
We do not use your data for third-party advertising. We do not build advertising profiles. We do not share data with ad networks. Your chromatic journey is not a marketing opportunity.
03
3Legal Basis for Processing
3.1 Performance of Contract
Most data processing is necessary to fulfill our contractual obligation to provide chromatic organization services. Without processing your images, we cannot categorize them by color. Without location data, we cannot map your journeys.
3.2 Legitimate Interests
We process certain data based on legitimate interests in:
- Maintaining platform security and preventing fraud
- Analyzing aggregated usage for service improvement
- Enforcing our terms and protecting user rights
3.3 Consent
Specific processing activities require your explicit consent:
- Location tracking for journey mapping (can be revoked in device settings)
- Marketing communications about new features (opt-in only)
- Anonymized data contribution to color research studies
- Public sharing of content in community features
3.4 Legal Obligations
We may process data to comply with valid legal requests, court orders, or regulatory requirements. We will notify you of such requests unless prohibited by law.
04
4Data Sharing & Disclosure
4.1 Third-Party Service Providers
We engage trusted processors who handle data on our behalf:
- Cloud Infrastructure: Encrypted storage and computing services (AWS, Google Cloud)
- Security Services: Fraud detection and authentication providers
- Analytics: Anonymized usage analysis (Mixpanel, Amplitude)
- Communication: Email delivery services for notifications
All processors are contractually bound to use data solely for Pact service provision and maintain security standards equivalent to our own.
4.2 Legal Disclosure
We may disclose data when:
- Required by subpoena, court order, or other valid legal process
- Necessary to protect our rights, property, or safety
- Investigating potential violations of our terms of service
- Preventing imminent harm to users or the public
4.3 Business Transfers
In the event of a merger, acquisition, or asset sale, user data would be transferred subject to the same privacy commitments. You would be notified of any change in data controller identity.
What We Never Do
We never sell your personal data to data brokers. We never share your photographs with AI training datasets without explicit consent. We never provide location histories to third parties for commercial purposes.
05
5Data Security Measures
5.1 Encryption Protocols
- Transit: TLS 1.3 encryption for all data in transit between your device and our servers
- At Rest: AES-256 encryption for all stored photographs and personal data
- End-to-End: Optional encryption for sensitive emotional entries with user-controlled keys
5.2 Access Controls
- Multi-factor authentication for all administrative access
- Role-based permissions limiting data exposure to essential personnel
- Comprehensive access logging and anomaly detection
- Regular security training for all team members
5.3 Infrastructure Security
Our servers reside in SOC 2 Type II certified data centers with:
- 24/7 physical security and biometric access controls
- Redundant power and network connectivity
- Fire suppression and climate control systems
- Regular penetration testing and vulnerability assessments
5.4 Incident Response
In the unlikely event of a data breach, we will:
- Notify affected users within 72 hours of discovery
- Report to relevant supervisory authorities as required by law
- Provide detailed remediation steps and protective recommendations
- Maintain transparency through updates to dahipactakde019j@zohomail.cn
06
6Data Retention & Deletion
6.1 Retention Periods
Retained indefinitely while your account remains active to provide continuous service.
- Photographs: Retained until manual deletion or account termination
- Location History: Retained for 24 months, then anonymized for research
- Mood Data: Retained until account deletion (core to service experience)
- Account Credentials: Retained until account termination plus 90 days
- Usage Logs: Retained for 12 months for security and improvement
6.2 Account Deletion
Upon receiving a deletion request via dahipactakde019j@zohomail.cn or in-app settings:
- All personal identifiers are purged within 30 days
- Photographs are permanently deleted from active servers
- Backup systems are cleared within 90 days
- Anonymized color distribution statistics may be retained for research
- Legal holds may delay deletion if required by valid process
6.3 Right to Be Forgotten
You may request erasure of specific data elements without full account deletion. We will comply within 30 days unless legal obligations require retention.
07
7Your Privacy Rights
👁
Right to Access
Request a complete copy of all personal data we hold about you
✏
Right to Rectification
Correct inaccurate or incomplete personal information
🗑
Right to Erasure
Request deletion of your data ("Right to be Forgotten")
⏸
Right to Restriction
Limit how we process your data in certain circumstances
📦
Right to Portability
Receive your data in a structured, machine-readable format
✋
Right to Object
Opt out of processing based on legitimate interests
7.1 Exercising Your Rights
Submit requests to dahipactakde019j@zohomail.cn with subject line "Privacy Rights Request." Include:
- Your registered email address
- Specific right being exercised
- Verification of identity (last login date, device type)
- Any relevant details to locate the data
We respond to all requests within 30 days. Complex requests may require up to 90 days with interim updates.
7.2 Right to Complain
If you believe we have violated your privacy rights, you have the right to lodge a complaint with your local data protection supervisory authority.
08
8International Data Transfers
8.1 Transfer Mechanisms
Pact operates globally. Your data may be transferred to and processed in countries outside your residence. We ensure protection through:
- Standard Contractual Clauses: EU Commission-approved data transfer agreements
- Adequacy Decisions: Transferring only to jurisdictions with recognized adequate protection
- Binding Corporate Rules: Internal data protection policies for group transfers
8.2 Data Localization
Where legally required, we maintain local data centers to ensure your visual archives remain within jurisdictional boundaries. You may request information about where your specific data is stored.
09
9Children's Privacy
Pact is not intended for children under 13 years of age. We do not knowingly collect personal data from children. If we discover that a child under 13 has provided us with personal information, we will immediately delete such data from our servers.
If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us immediately at dahipactakde019j@zohomail.cn with subject line "Child Data Removal Request."
Teen Users (13-17)
Users aged 13-17 may use Pact with parental consent. We limit data collection for teen accounts, disable certain social features by default, and provide enhanced privacy controls.
10
XPolicy Evolution
10.1 Change Notification
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be communicated via:
- In-app notification at least 30 days before effectiveness
- Email to your registered address (dahipactakde019j@zohomail.cn or your provided email)
- Prominent banner on our website
10.2 Version Control
Each version of this policy is dated at the top. Previous versions are available upon request for comparison. Continued use after changes constitutes acceptance of the revised policy.