Scope
This Privacy Policy applies to VikingPal, including the mobile application for iOS and Android, the website at vikingpal.oakdev.app, support requests, account deletion requests, email communications, and related services operated by OakDev & AI AB.
This policy covers personal data under the EU General Data Protection Regulation ("GDPR"), Swedish data protection law, UK GDPR where applicable, and other privacy laws that may apply based on your location. If a local law gives you stronger rights than this policy, we will honor those rights.
VikingPal is a Norse guidance and reflection app. It is not intended to be a medical, psychological, legal, financial, emergency, or crisis service.
Data Controller
The controller responsible for VikingPal is:
OakDev & AI AB Uddevalla, SwedenEmail: hello@oakdev.app
We decide why and how personal data is processed in VikingPal. Some third-party service providers process data on our behalf as processors. Others, such as Apple, Google Play, and certain advertising or payment services, may act as independent controllers for parts of their own services.
Data We Process
Account and authentication data
- Email address and login identifiers.
- Authentication tokens, account IDs, sign-in provider data, and security logs.
- Optional display name, profile preferences, language settings, theme choices, and app settings.
App content and activity
- Questions you ask in Hall of Gods, Ask VikingPal, reflection doors, Gods Council, rune casts, daily quests, and similar features.
- Generated guidance, saved answers, ritual journal entries, notes, reflection history, reading progress, and completed actions.
- Rune balance, starter runes, purchased runes, spending history, Hrafnlaus ad-free status, and Ragnarok purchase status.
- Feature interactions needed to provide the app, prevent abuse, debug errors, and keep entitlements synchronized across devices.
Purchase data
- Purchase tokens, receipt identifiers, product IDs, transaction timestamps, country or region, and store platform.
- We do not receive your full credit card number, banking credentials, or full payment account details from Apple or Google.
Device, diagnostics, and technical data
- Device model, operating system, app version, installation identifier, crash logs, performance diagnostics, IP address, approximate region, and timestamps.
- Advertising identifiers or similar identifiers where ads are enabled and permitted by your consent, device settings, and applicable law.
- Push notification tokens if push notifications are offered and you enable them.
Website and support data
- The website stores local preferences such as language and cookie banner choice in your browser's local storage.
- Hosting providers may process IP address, user agent, request URL, timestamps, and basic security logs when you visit the website.
- If you contact support, we process your name, email address, topic, message, screenshots, device information, and any other information you choose to send.
- The website loads Google Fonts, which may cause your browser to contact Google font servers.
Data we do not intentionally collect
- Precise GPS location, unless a future feature asks for it and you grant permission.
- Contacts, address book, microphone, camera, photos, or files, unless you choose to provide them for support or a future feature asks for permission.
- Full payment card data.
- Government ID numbers, health records, or financial account credentials.
Spiritual and Sensitive Content
Your prompts, journal entries, saved answers, and reflections may reveal religious or philosophical beliefs, emotional state, relationships, health concerns, or other sensitive information if you choose to include it. We do not require you to provide sensitive data, and you should avoid entering medical, legal, financial, emergency, or highly confidential information.
Where your content includes special category data under GDPR, such as religious or philosophical beliefs or health-related information, we process it only as needed to provide the feature you requested and, where required, based on your explicit consent. You may withdraw that consent by deleting the content, deleting your account, or contacting us.
We do not use your journal, prompts, or spiritual reflections to build advertising profiles for VikingPal. We do not sell this content to data brokers.
Purposes and Legal Bases
| Purpose | Examples | Legal basis |
|---|---|---|
| Create and secure your account | Authentication, login, account recovery, fraud prevention | Contract; legitimate interests; legal obligation where applicable |
| Provide VikingPal features | Questions, reflection doors, journal, saved guidance, runes, language, settings | Contract; explicit consent for special category data where required |
| Generate AI guidance | Sending prompts and relevant context to a contracted AI provider | Contract; consent or explicit consent where required for sensitive content |
| Manage purchases and entitlements | Hrafnlaus, Ragnarök, runes, receipts, purchase status, restores | Contract; legal obligation for tax/accounting records |
| Show and measure ads | Ad delivery, frequency, fraud prevention, ad measurement, consent choices | Consent where required; legitimate interests for non-personalized security and measurement |
| Improve reliability and safety | Crash reports, diagnostics, abuse prevention, debugging, security logs | Legitimate interests; legal obligation where applicable |
| Provide support | Email support, bug reports, deletion requests, privacy requests | Contract; legitimate interests; legal obligation for rights requests |
| Comply with law and defend rights | Accounting, tax, fraud, disputes, law enforcement requests | Legal obligation; legitimate interests; establishment or defense of legal claims |
AI Guidance Features
VikingPal includes AI-powered guidance features, including Ask VikingPal and related personal guidance experiences. When you use those features, the text you provide, relevant app context, and generated output may be processed by our contracted AI model provider to create a response.
- Do not submit emergency, medical, legal, financial, or other highly confidential information.
- AI output may be incomplete, inaccurate, offensive, repetitive, or unsuitable for your circumstances.
- AI guidance is for reflection only and does not create a professional, fiduciary, therapeutic, religious clergy, or advisory relationship.
- We may process prompts and outputs to provide the feature, maintain safety, investigate abuse, debug errors, and comply with law.
- We seek to limit AI data to what is necessary for the requested feature and contractual operation of the service.
Ads, Analytics, Cookies, and Local Storage
Ads in the app
The free Wanderer path may be ad-supported. Advertising partners, including Google advertising services where enabled, may process device information, app information, IP address, advertising identifiers, consent status, ad interactions, approximate location, and fraud-prevention signals. Depending on your region and settings, ads may be personalized or non-personalized.
You can control ad personalization through in-app consent controls where available, your device settings, Apple App Tracking Transparency choices, Google ad settings, and other platform controls. If you purchase an ad-free entitlement such as Ragnarok, we use purchase status to suppress ads where the entitlement is active.
Analytics and diagnostics
We may use analytics, crash reporting, and performance tools to understand app stability, feature usage, errors, and abuse. We try to use aggregated or minimized data where practical. We do not use your private journal text or prompts for advertising profiles.
Website local storage
The website currently uses browser local storage for language preference and the cookie banner choice. This is not used to track you across other websites. You can clear local storage through your browser settings.
Third-party resources
The website uses Google Fonts and may use hosting/CDN services. These providers may receive technical request data such as IP address, user agent, requested resource, and timestamp.
Service Providers and Other Recipients
We use third parties to operate VikingPal. The exact provider list may change as the app evolves, but the categories include:
- Firebase and Google Cloud services for authentication, database, cloud functions, hosting, security, analytics, crash reporting, remote configuration, push notifications, and related infrastructure where enabled.
- Apple App Store and Google Play for app distribution, in-app purchases, purchase restoration, refunds, and platform compliance.
- Advertising partners for ad delivery, ad measurement, fraud prevention, and consent handling where the ad-supported tier is used.
- AI model providers for generating responses to prompts in AI-powered features.
- Email and support tools for support messages, deletion requests, bug reports, and privacy requests.
- Hosting, DNS, CDN, and security providers for operating the website and protecting it from abuse.
- Professional advisers and authorities where required for legal, tax, accounting, security, or dispute purposes.
We require processors to process personal data only under appropriate contractual terms. Some providers may also process data as independent controllers for their own platform, fraud prevention, billing, legal compliance, or advertising purposes.
International Transfers
OakDev & AI AB is based in Sweden. Some service providers are located outside Sweden, the EU, the EEA, or the UK. When personal data is transferred internationally, we rely on appropriate safeguards where required, such as adequacy decisions, the EU Standard Contractual Clauses, UK transfer mechanisms, the EU-U.S. Data Privacy Framework where applicable, and supplementary safeguards where appropriate.
International providers may be subject to laws in their own jurisdictions. We assess providers and use contractual and technical safeguards to reduce risk, but no international transfer can be made entirely risk-free.
Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law. Retention periods may differ between active systems, backups, security logs, app store records, and third-party processors.
When you delete your account in the app, deletion begins immediately for active account functionality. If you request deletion by email, we will verify and process the request without undue delay and normally within 30 days. Some records may remain for a limited period in backups, logs, platform records, processor systems, or legal/accounting records, and will be isolated from ordinary use where practical.
Security
We use technical and organizational safeguards appropriate to the nature of the data and the size of our service, including:
- Encrypted transport using HTTPS/TLS.
- Managed authentication and access controls.
- Provider-side encryption and security controls for cloud infrastructure where supported.
- Restricted access to production data based on operational need.
- Logging, monitoring, and review of suspicious activity where appropriate.
- Account deletion and privacy request workflows.
No service is perfectly secure. You are responsible for keeping your device, email account, app store account, and login credentials secure. If we become aware of a personal data breach that is likely to affect your rights and freedoms, we will notify affected users and supervisory authorities as required by law.
Your Rights
Depending on your location, you may have the right to:
Request confirmation and a copy of personal data we process about you.
Ask us to correct inaccurate or incomplete personal data.
Delete your account in the app or request erasure by email, subject to legal exceptions.
Ask us to restrict processing in certain circumstances.
Request portable data where the law gives you that right.
Object to legitimate-interest processing and opt out of direct marketing or certain ads where applicable.
You may also withdraw consent where processing is based on consent. Withdrawal does not affect processing that occurred before withdrawal.
To exercise rights, email hello@oakdev.app. We may need to verify your identity before responding. We normally respond within one month, unless the request is complex or numerous, in which case the law may allow more time.
If you are in Sweden or the EEA, you may lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority. IMY is available at imy.se.
California and similar privacy laws
We do not sell personal information for money. Some advertising or analytics activity may be considered "sharing" or targeted advertising under certain U.S. state laws when personalized ads are enabled. You can use app, device, platform, and consent controls to limit personalized ads, and you may contact us to request access, deletion, correction, or opt-out rights available under applicable law.
Children
VikingPal is not directed to children under 13. Users under the age required for digital consent in their country must use VikingPal only with permission from a parent or legal guardian. We do not knowingly collect personal data from children in violation of applicable law.
If you believe a child has provided personal data to VikingPal without required consent, contact us at hello@oakdev.app and we will take appropriate steps to delete or restrict the data.
Changes to This Policy
We may update this Privacy Policy as VikingPal changes or as legal requirements evolve. The current version is always available at vikingpal.oakdev.app/privacy. If we make material changes, we will provide reasonable notice through the app, website, email, or another appropriate method.
Contact
For privacy questions, account deletion, or data rights requests, contact:
OakDev & AI AB - Privacy Uddevalla, Swedenhello@oakdev.app