Privacy Policy

Last updated: September 15, 2026

1. Introduction

Welcome to Levelium ("we", "us", or "our"). Levelium is a gamified productivity application available on mobile (Android/iOS) and web (levelium.app).

This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our application and website (collectively, the "Service"). This policy describes those practices; where we rely on your consent, we ask for it separately.

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR), the Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD), and all applicable data protection laws.

2. Data Controller

The data controller responsible for your personal data is:

3. Information We Collect

We collect the following categories of personal data:

3.1 Information You Provide

  • Account Information: Email address and display name when you create an account.
  • Profile Data: Character customization preferences within the RPG system, including avatar, body type, attributes, and cosmetics.
  • Architect Messages: Messages and requests you choose to submit to The Architect.
  • Support Reports: The report type and message you submit, together with your user identifier and, for reports sent by legacy clients, your email address when available.

3.2 Information Generated by Usage

  • Gamification Data: Missions created, completed, and tracked; habits; streaks; experience points (XP); character level and rank; attributes progression; and overall in-app progress.
  • Purchase Data: Records of in-app purchases and subscriptions (Battle Pass, Gem purchases). Payment processing is handled entirely by Google Play / Apple App Store; we do not collect or store payment card information.

3.3 Automatically Collected Information

  • Device Information: Device type, operating system, app version, interface dimensions, orientation, text scale, locale, timezone, and build information. Crash and diagnostic data may be associated with your account or device.
  • Usage Analytics: Pages visited and interactions on the deployed website, and app events such as screens and features used, mission identifiers, authentication method, and player level. This data is collected in aggregated or anonymized form where possible.
  • Google Sign-In Security: Google Sign-In may process a user identifier to record OAuth grants and your IP address to estimate your device's general location for sign-in security and fraud prevention. See Google's Sign-In data disclosure guidance.

4. How We Use Your Information

We use the information we collect to:

  • Provide the RPG Experience: Power your character progression, missions, habits, streaks, ranking system, and AI coaching features ("The Architect").
  • Manage Your Account: Authenticate your identity, manage your profile, and sync data across devices.
  • Process Purchases: Fulfill in-app purchases, manage subscriptions, and deliver premium content (gems, cosmetics, Battle Pass).
  • Send Communications: Notify you about account updates and important service changes. We will never send unsolicited marketing emails without your explicit consent.
  • Improve the Service: Analyze usage patterns to fix bugs, optimize performance, and develop new features.
  • Comply with Legal Obligations: Fulfill legal requirements provided by applicable law.

5. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds:

  • Contractual Necessity: Processing is necessary to provide the Service you have requested (account management, gamification features, purchases).
  • Consent: For non-essential purposes such as marketing communications. In app versions that include the AI data-sharing control, we also ask for explicit permission before sharing Architect data with external AI services. You can withdraw consent at any time.
  • Legitimate Interest: For analytics and security purposes, to improve our Service and protect against fraud.

6. Third-Party Services

We use the following third-party services to operate Levelium. Each processes data according to their own policies and terms:

Firebase (Google)

Authentication, database (Firestore), cloud functions, app analytics, and crash reporting.

Privacy →

Vercel Analytics

Website traffic and usage analytics when the website is deployed on Vercel.

Privacy →

Resend

Delivery of user-submitted support reports to Levelium. Reports may include your user identifier, report type, message, and an email address when supplied by a legacy client.

Privacy →

Mailgun

Delivery of branded authentication and account emails.

Privacy →

Google Play / Apple App Store

In-app purchases and subscription payment processing. We do not receive or store your payment card details.

Privacy →

RevenueCat

In-app purchases, subscriptions, entitlement validation, purchase fulfillment, and fraud/abuse prevention related to purchases. May process: app user identifier, product identifiers, transaction identifiers, purchase/subscription status, entitlement status, and related transaction metadata. RevenueCat does not receive or store your payment card details.

Privacy →

OpenRouter and routed AI inference providers

Primary AI processing for "The Architect". OpenRouter routes DeepSeek requests through a selected inference provider, whose identity and data practices may vary by request. See section 7.

Privacy →

7. AI Features ("The Architect")

Levelium offers AI-assisted features, including "The Architect", which provides coaching and guidance within the RPG system.

For Architect chat, Levelium may send your message, up to 10 recent chat entries, your player name, progression, attributes, streak, and relevant recent activity to external AI services to generate a response. Only use this feature if you are comfortable sharing that information with those services.

If you request a rolling seven-day report, our server retrieves the missions, completion history, and timezone-based dates needed for that report and sends a summarized selection of the relevant context for AI processing.

The Architect uses DeepSeek V4 Flash through OpenRouter. OpenRouter routes each request to an inference provider selected for this route, and that provider may vary by request. The company that developed a model is not necessarily the provider that receives and processes a particular request. Some earlier requests may have been processed by the Google Gemini API; data already sent remains subject to the terms that applied when it was received.

For Architect requests, Levelium asks OpenRouter to restrict provider data collection and require a zero data retention (ZDR) route. These controls do not guarantee that no logs or request metadata are retained. OpenRouter and routed providers have their own processing and retention practices, which may vary with the route, selected provider, and applicable terms. Review OpenRouter's data collection information, its provider logging information, and the selected provider's terms and privacy notice. For earlier requests processed by Google, see the Gemini API terms.

In versions with the AI data-sharing control, we ask for explicit permission for the current session before the first chat message or report request is sent. You may decline, or withdraw permission through the Architect privacy action. Declining or withdrawing does not affect other app features. Permission is not stored permanently, so an app restart or session change will require permission again before another send. Withdrawal stops future sends; it does not undo processing or retention of data already sent.

Levelium stores generated responses, generated missions and reports, and related request state in Firebase under your account. Recent chat and pending recovery data are also kept on your device. Starting a new chat clears the local conversation view only; it does not by itself delete account data already stored in Firebase or data already sent to an external AI service.

Please do not submit sensitive personal information (such as health, financial, government identifiers, or other sensitive data) to AI features.

AI-generated responses can be inaccurate or incomplete. You should not rely on them as professional advice (medical, legal, financial, or otherwise).

8. Data Protection & Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS/HTTPS) and at rest.
  • Secure authentication via Firebase Auth with industry-standard protocols.
  • Access controls limiting data access to authorized personnel only.
  • Regular security reviews and monitoring.

While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We encourage you to use a strong, unique password for your account.

9. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you the Service. When account deletion is completed, Levelium removes the primary account and profile data it controls. We may retain limited records where needed for security, fraud and replay prevention, administrative audit, support follow-up, or legal obligations. These records may include pseudonymous fraud or replay markers, administrative audit records, support report content, and purchase records required for tax compliance.

Account deletion does not itself erase copies, logs, or request metadata already held by OpenRouter, a routed inference provider, Google (which may have received earlier Architect requests), or another external service. Their separate retention practices may apply to data they have already received. You can contact Levelium to exercise your rights; where applicable, we will address data we control and coordinate the request with the relevant provider.

Anonymized and aggregated data that cannot identify you may be retained indefinitely for analytical purposes.

10. Your Rights

Under the GDPR and applicable data protection laws, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your account and the associated personal data controlled by Levelium, subject to applicable legal exceptions. External providers' separate retention practices are described in section 9. You can initiate deletion from within the app settings or by contacting us at support@levelium.app. See our account deletion page for step-by-step instructions.
  • Right to Restriction: Request that we limit the processing of your data in certain circumstances.
  • Right to Data Portability: Receive your data in a structured, commonly used, and machine-readable format.
  • Right to Object: Object to the processing of your data based on legitimate interest grounds.
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at support@levelium.app. We will respond within 30 days. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) or your local supervisory authority.

11. Children's Privacy

Levelium is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly. If you believe your child has provided us with personal data, please contact us at support@levelium.app.

12. International Data Transfers

Your data may be processed outside the European Economic Area (EEA) by service providers used to operate Levelium. For Architect requests, the processing location can depend on the inference provider selected by OpenRouter. Earlier requests may also have been processed by Google. Provider terms and privacy notices describe their processing and transfer mechanisms, and Levelium remains responsible for its obligations under applicable data protection law. Contact us if you would like more information about a particular transfer or want to exercise an applicable right.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy on this page and updating the "Last updated" date. For material changes, we may also send a notification through the app or via email. We encourage you to review this page periodically.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Levelium

📧 Email: support@levelium.app

🌐 Web: levelium.app