Privacy Policy
Last updated: 2026-07-10
Last updated: 23 July 2026.
1. The Controller
- Controller: Remény Farm Kft. ("Remény Farm", "we", "us", "our")
- Form: Hungarian limited-liability company
- Tax number: 26667089-2-10
- Company registry number: 10-09-037306
- Managing director: Goldmann Dávid
- General contact email:
info@remenyfarm.hu - Data-protection contact:
info@remenyfarm.hu - Data Protection Officer (DPO): <!-- TODO: not currently appointed; we are not statutorily required to appoint a DPO under GDPR Article 37, but if we do, the contact will be listed here -->
Remény Farm Kft. is a Hungarian limited-liability company with its registered seat in Hungary. Our full corporate identification — including the registered seat, the name of the company-registry court, and the statutory accounting identifier — is available in our Hungarian-language Impressum, which is the authoritative public record.
2. Scope of this Policy
This Privacy Policy describes how Remény Farm Kft. processes personal data in connection with the unified Chirp Coop and Remény Farm services, including:
- the public web surface at
chirpcoop.com; - the capability-equivalent web surface at
tyuk.remeny.farm, including RealChirp checkout and authenticated Patron features; - the Chirp Coop mobile applications for iOS and Android (current and future);
- supporting infrastructure used by the game (push notifications, analytics, AI generation, in-app purchases).
The two web hosts run one capability-symmetric application: the host selects language and brand, while authentication selects access to Patron features. The Hungarian-language privacy notice describes the same processing for Hungarian readers and includes local service detail. Neither host selection nor this language split changes the privacy boundary.
This Policy is based on Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and Act CXII of 2011 of Hungary on the right of informational self-determination and freedom of information ("Infotv.").
3. Principles of Processing
We process personal data in accordance with Article 5 of the GDPR. Specifically, we commit to:
- lawfulness, fairness, and transparency — processing only with a clear legal basis and in a manner explained to you in plain language;
- purpose limitation — using personal data only for the purposes described in this Policy;
- data minimisation — limiting collection to what is necessary;
- accuracy — correcting inaccurate data on request without undue delay;
- storage limitation — retaining personal data only as long as needed for the stated purpose or required by law;
- integrity and confidentiality — applying appropriate technical and organisational security measures;
- accountability — being able to demonstrate compliance with the above.
We do not sell personal data. We do not use personal data for behavioural advertising. We do not engage in automated decision-making that produces legal or similarly significant effects on you within the meaning of Article 22 of the GDPR.
4. Categories of Personal Data We Process
The following sub-sections list, for each category, the data processed, the purpose, the legal basis under Article 6 GDPR, and the retention period.
4.1 Account registration data
- Data: a Supabase-generated opaque user identifier and the literal account classification (
anonymousorpermanent). Chirp Coop may create an anonymous account after a successful security challenge without asking for an email address. If you later link the same account to email, we process that email address and preserve the same user identifier. An optional display name is processed only if you provide one. - Purpose: to identify the account, secure it, preserve game progress during an optional email upgrade, and deliver the game.
- Legal basis: GDPR Article 6(1)(b) — performance of the contract you enter into when you create a Chirp Coop account.
- Retention: for the lifetime of your active account. Account deletion removes the authentication account and private game identity as described in § 7, subject only to legally required detached records.
4.2 Game-state data
- Data: the name you give to your virtual queen; her current mood and progression state; gameplay events (logins, taps, ritual completions); egg draws and their outcomes; clan membership and inter-player relationships within the game.
- Purpose: to run the game, persist your progress between sessions, and enable the game features you use. A virtual queen and her game state are private account data by default.
- Legal basis: GDPR Article 6(1)(b) — performance of the contract.
- Retention: for the lifetime of the account, then deleted with the account unless a specific legal retention duty applies.
4.3 AI prompt and output data
This category is summarised here and described in full in § 6.
- Data sent to the model: the queen's name; her mood (derived from aggregate gameplay signals); current weather at the simulated farm region; a short summary of the last 24–48 hours of gameplay events relevant to her story.
- Data received from the model: a 2–3 sentence English-language Morning Chronicle entry.
- Purpose: to generate the daily Morning Chronicle that is part of the core gameplay loop.
- Legal basis: GDPR Article 6(1)(b) — performance of the contract.
- Retention: generated Chronicle entries remain private Account data and are deleted with the Account as described in § 7. Prompt content sent to Anthropic is handled according to the Anthropic service terms and Trust Center configuration we have selected; we configure the integration so that prompt content is not used to train Anthropic's models, and Anthropic retains the content only within its operational service window. <!-- TODO: confirm the Anthropic DPA URL and the precise retention window once the Trust Center settings are signed off -->
4.4 Mobile in-app purchase metadata
- First-cohort status: the first international soft-launch cohort has no ads and no in-app purchases. RevenueCat is not initialised for that cohort, and no purchase or entitlement metadata is collected from those players. Patron or real-farm status has no gameplay effect in that cohort.
- Data if a later accepted release activates IAP: mobile Game purchase and entitlement state as reported by RevenueCat (active, in grace period, expired, refunded); the product identifier; transaction timestamps; and platform. Card numbers and platform-account credentials are processed exclusively by Apple Inc. or Google LLC; Remény Farm Kft. does not have access to them.
- Purpose: to deliver mobile in-app purchases, manage entitlements (virtual gifts, cosmetics, paid egg draws, noncompetitive convenience boosts, optional mobile-game subscriptions), and comply with Hungarian accounting and tax law.
- Legal basis: GDPR Article 6(1)(b) — performance of the contract; and GDPR Article 6(1)(c) — compliance with a legal obligation, specifically the accounting-record retention duty under Hungarian law.
- Retention: accounting records relating to purchases are retained for 8 years as required by section 169(2) of Act C of 2000 on Accounting. <!-- TODO: confirm the final retention configuration with our accountant; the 8-year period is the statutory floor for accounting records and may be applied more narrowly to in-app-purchase metadata that does not constitute an accounting document on its own -->
4.5 Diagnostic and security data
- Data: scrubbed crash and error reports collected by Sentry. Allowed diagnostic context is limited to release/build, environment, platform, operating-system and device model, app state, error type/stack, opaque route or state-machine identifiers, and the opaque Supabase user identifier where a valid session exists. The application disables default PII collection and sends no IP field; the first international cohort is blocked until provider-side IP scrubbing is enabled and evidenced in the hosted Sentry project.
- Excluded data: session replay, screenshots, attachments, user feedback, profiling, performance traces, request or response bodies, headers, cookies, query strings, form values, local or session storage, full user-entered URLs, email, display name, queen name, Patron data, advertising identifiers, device identifiers, and auth or challenge tokens.
- Purpose: to keep the game stable, diagnose bugs, detect abuse, and protect against fraud.
- Legal basis: GDPR Article 6(1)(f) — legitimate interest in operating a safe and reliable service. We have considered and documented the balancing test: the data is limited, retention is short, the data subjects have an existing relationship with us, and you would reasonably expect this kind of operational logging.
- Retention: in accordance with Sentry's default retention rules (typically 30–90 days). IP addresses are not retained beyond the operational window required to investigate the event in which they were captured. <!-- TODO: confirm the precise Sentry project-level retention setting and document it here -->
4.6 Indirect contextual data
- Data from OpenWeatherMap: non-personal weather data for the geographic region of the simulated farm. This is not personal data about you and is not linkable to your account, but it is included here because it forms part of the prompt context described in § 4.3 and § 6.
4.7 Cloudflare Turnstile security challenge
- Data: Cloudflare may receive the IP address, browser and device signals, and challenge-interaction data needed to determine whether a request is automated. Chirp Coop receives a short-lived challenge token.
- Purpose: to prevent automated anonymous-account creation and abusive email-code requests.
- Handling: the token stays in process memory, is never placed in a URL, browser storage, logs, analytics, or rendered HTML, and is passed unchanged to Supabase Auth. Supabase Auth is the only service that verifies it. Each attempt uses fresh cryptographic state and a fresh challenge.
- Legal basis: GDPR Article 6(1)(f), our legitimate interest in preventing abuse and protecting account infrastructure.
- Retention: Chirp Coop does not retain the challenge token. Cloudflare applies its own security-service retention under its DPA and privacy terms.
4.8 First-cohort product analytics
- Data: after a valid Supabase session exists, the mobile app may send an allowlisted product event under the opaque Supabase user identifier. Common fields are limited to platform, launch market when available without IP or GPS inference, app version, build number, the literal cohort key, and anonymous/permanent account type. The one permitted event-specific field is an opaque upgrade-catalog identifier on the first soft-currency upgrade event.
- Excluded data: email, display name, queen name, Patron identity, advertising identifier, device fingerprint, payment value, free text, precise location, URL, referrer, user agent, screen dimensions, timezone, feature flags, and automatic client metadata.
- Operation: PostHog receives raw, single-event HTTPS requests only. No PostHog client SDK, autocapture, cookie, local storage, durable queue, or automatic retry is used. Each event disables GeoIP. PostHog may create a minimal person record keyed only by the opaque Supabase identifier so that person, event, and recording erasure can be requested and verified; we send no person properties.
- Purpose and legal basis: to measure first-cohort retention and product milestones under GDPR Article 6(1)(f). Analytics failures never affect sign-in or gameplay.
4.9 Public-web measurement, attribution, and functional referral fulfillment
- Scope: browser measurement is disabled on authenticated, admin, account, redemption, game-bootstrap, auth-secret URL fragments, and other sensitive destinations. On eligible public pages it remains disabled until granular prior consent. Missing, invalid, blocked, or unwritable consent storage fails closed.
- Analytics data: Vercel Analytics and Speed Insights receive the public-page use and performance context required by those services. Profileless PostHog sales events use an ephemeral in-memory random ID and a closed field list: event name; host, path, locale, surface, placement, target, section/FAQ/ calculator values; checkout attempt, quantity, duration, provider, status or error; order ID, currency and value; picker counts; referral handle and UTM values; and share moment/channel. GeoIP and person profiles are disabled.
- Marketing measurement and conversion data: with marketing consent, a
referral handle and
utm_source,utm_medium, andutm_campaignmay be kept for 30 days and attached to checkout for attribution. Referral/UTM values and checkout-event referral properties are sent to PostHog only when marketing consent also exists. A first-party sales-visit counter is incremented at most once per tab, and checkout/session markers prevent duplicate reporting. Google Tag Manager requires both analytics and marketing consent. The RealChirpbegin_checkoutevent contains total value, currency, quantity, and stable item ID, name, category, and unit price. It contains no email, order ID, payment-session token, or referral value. The post-payment redemption route remains browser-telemetry-free. - Functional referral discount and reward data: independently of marketing
consent, the referral handle from a
?ref=link may be stored by itself for up to 30 days inchirp-referral-discountand sent with a gift or RealChirp checkout. It is used to apply the promised buyer discount. After successful payment, the server validates the public handle, records the referral conversion, and fulfills the referrer's bonus-month reward subject to the monthly anti-abuse cap. This functional path carries no UTM or browser measurement data and sends no referral property to PostHog without marketing consent. - Measurement purpose and legal basis: consented public-funnel, performance, referral, and conversion measurement under GDPR Article 6(1)(a). We do not use these tools for behavioural advertising.
- Functional referral purpose and legal basis: applying the buyer discount and fulfilling the capped referrer reward under GDPR Article 6(1)(b), performance of the referral offer.
4.10 Account-email synchronisation marker
- Data and purpose: after an account-email change, the browser may retain a versioned MailerLite synchronisation marker containing the opaque account ID, SHA-256 digests of the old and target normalized addresses, and expiry. It contains no plaintext email and is used only to detect confirmation and queue the current Patron contact for server-side MailerLite synchronisation.
- Legal basis and retention: GDPR Article 6(1)(b), performance of the requested account operation. The marker lasts no more than 24 hours and is cleared on invalid data, account/address mismatch, sign-out, or successful queueing. MailerLite receives the confirmed contact data through the existing server-side patron-contact workflow, not from the marker itself.
4.11 Uploaded profile images
- Data and purpose: a profile image deliberately selected on web or through the native camera/library prompt is processed to display the account avatar. The client prepares image pixels, but the server is authoritative: it checks the declared JPEG/PNG type against the bytes, rejects unsafe dimensions, decodes the image, limits its longest edge to 512 pixels, and stores a newly encoded canonical PNG. The stored avatar therefore carries pixels, not the source file's EXIF, GPS, or other embedded metadata.
- Legal basis and retention: GDPR Article 6(1)(b), performance of the requested profile feature. The avatar is retained until replacement or account deletion, subject to the deletion rules in § 7.
4.12 Walk-up egg-sale receipts
- Data: when you buy eggs in person at the farm (a "walk-up" sale), the seller may enter an email address at the handoff kiosk so the electronic receipt can be delivered to you. The buyer has no account; the kiosk stores the email address only against the issued receipt in a server-only ledger, together with the sale's quantity, price, and receipt number.
- Purpose: to issue and deliver the statutory electronic receipt for the sale and to keep the farm's own record of who a receipt was sent to.
- Legal basis: GDPR Article 6(1)(c) — compliance with Hungarian accounting and invoicing law; the email delivery itself is the requested fulfilment of the sale under Article 6(1)(b).
- Retention: the receipt is an accounting record retained for 8 years under section 169(2) of Act C of 2000 on Accounting. The delivery email address is kept with the receipt ledger beyond that window by decision of the controller, as the farm's own record of receipt delivery. Because the buyer has no account, this address sits outside the account-keyed erasure workflow: an erasure or access request for a walk-up purchase is handled manually via the contacts in § 1.
5. Recipients and Processors
We use the following processors to deliver the game. Each is bound by a written data-processing agreement (DPA) under Article 28 of the GDPR.
| Processor | Activity | Seat | DPA / Compliance reference | |---|---|---|---| | Vercel Inc. | Hosting, CDN, build infrastructure, and consented web analytics/performance measurement | United States | DPA available | | Supabase Inc. | Database, authentication, Edge Function runtime, storage | United States | DPA available | | Cloudflare Inc. | Turnstile abuse-prevention challenge; R2 object storage and CDN delivery for avatars and real-chicken photos, retained until avatar replacement/account deletion or under the real-chicken farm-record permanence rule | United States | applicable Cloudflare DPA | | Anthropic PBC | AI generation — configurable Claude model, currently Claude Sonnet 5 (Morning Chronicle) | United States | Trust Center + DPA <!-- TODO: link the Trust Center settings page once finalised --> | | Stripe Payments Europe, Ltd. / Stripe group | Web checkout, subscriptions, and payment-event metadata; card data stays with Stripe | Ireland / United States | applicable Stripe DPA | | OneSignal, Inc. | Mobile push delivery and notification interaction data | United States | DPA available | | RevenueCat Inc. | Future mobile Game IAP purchase and entitlement orchestration; not initialised for the first international soft-launch cohort | United States | DPA available | | Apple Inc. / Google LLC | Mobile platform billing (App Store, Play Store) | United States | platform terms | | OpenWeatherMap Ltd. | Weather data feed (non-personal) | United Kingdom | service terms | | Functional Software Inc. (Sentry) | Error tracking | United States | DPA available | | PostHog Inc. | Raw first-cohort mobile analytics under § 4.8 and consented, profileless public-web sales analytics under § 4.9 | United States | DPA available | | Google LLC | Google Tag Manager, Google Analytics 4, and Google Ads consented public-web/conversion measurement under § 4.9 | United States | applicable Google data-processing terms | | MailerLite Limited | Patron contact and email-list synchronisation after a confirmed account-email change | Ireland | applicable data-processing agreement |
We only share personal data with these processors to the extent necessary for the activity listed. Where a transfer outside the EEA occurs, the applicable provider agreement supplies the transfer mechanism, such as participation in the EU–US Data Privacy Framework or Standard Contractual Clauses where required. We do not claim that one mechanism applies to every provider or transfer.
Beyond processors, we may also disclose personal data to:
- competent public authorities (courts, regulators, tax authorities, law-enforcement bodies) where we are legally required to do so;
- professional advisors (accountants, auditors, lawyers) bound by professional confidentiality obligations;
- a successor entity in the event of a corporate restructuring, merger, or acquisition, subject to the same protections set out in this Policy.
6. AI Processing — Specific Notice
A core feature of Chirp Coop is the Morning Chronicle: once per day, for each named queen, our system asks a configurable Claude model — currently Claude Sonnet 5 and operated by Anthropic PBC — to write a short 2–3 sentence narrative passage about how the queen spent her last day. This section explains exactly what flows through that pipeline, so that you can make an informed decision about whether to use the feature.
6.1 What we send
The prompt sent to Anthropic on your behalf contains:
- the name you chose for your queen — this is free-text you supplied and may, in principle, contain personal information if you elected to put your own name in it (we recommend you do not);
- the mood and gameplay state of the queen, derived from aggregate signals;
- the current weather at the simulated farm region, taken from OpenWeatherMap;
- a short summary of recent gameplay events for that queen.
We do not send your email address, your Supabase user identifier, your IP address, your billing information, or any payment data to Anthropic.
6.2 What we receive
A 2–3 sentence English-language narrative passage that is then stored against the queen's profile and rendered as her Morning Chronicle.
6.3 Training opt-out
We configure our Anthropic integration so that prompt content is not used to train Anthropic's models. Anthropic retains the content only within its operational service window for the limited purposes of operating the API, abuse prevention, and meeting its own legal obligations. The current applicable terms and Trust Center configuration are referenced in the processor table above. <!-- TODO: link the specific Anthropic Trust Center configuration page once finalised -->
6.4 Nature of the output
The Chronicle output is creative writing, not factual reporting. It is generated by a language model and may contain hallucinations, mistakes, or stylistic embellishments. It is not a record of anything that physically happened, and it is not medical, veterinary, or any other form of professional advice. The corresponding limitation of liability appears in our Terms of Service.
6.5 Your right to know
You have the right, at any time, to ask us what the model has generated about your queen, to receive a copy of the prompt and output for any specific Chronicle entry, and to ask us to delete a specific Chronicle entry if you find it inappropriate. Contact us using the addresses in § 1.
7. Account Deletion and Real-Chicken Record Permanence
Anonymous and permanent users can initiate account deletion in the mobile app and at the directly reachable web resource /account/delete. The web resource requires authentication so the request is applied only to the current account.
- Anonymous accounts: deletion immediately removes the Supabase Auth account and associated private queen, brood, and wallet/ledger data that is not legally retained unless the account identity changed before the request. Erasure of the opaque telemetry and push identity and matching records at PostHog, Sentry, and OneSignal is durably queued; our current target is completion within 30 days.
- Permanent accounts: deletion may require confirmation or reauthentication and may complete asynchronously. The deletion resource reports the expected timing and completion status; our current target is completion within 30 days.
- Email-linked game data: the private virtual queen, private chronicles, game state, and account profile are deleted with the playable account. A virtual queen is not published by default and is not retained as a public profile after deletion.
- Required retention: fraud, payment, tax, and audit records are retained only where law requires, minimised, and detached from the playable account.
- Real chickens: a real farm animal's public profile and life history remain subject to the farm-record permanence rule. Account deletion closes patronage as required and removes or pseudonymises Patron personal data, but it does not erase the animal's permanent public record.
8. Your Rights
You have the following rights under the GDPR and the Infotv., subject to the redaction carve-out in § 7:
- Right of access (GDPR Article 15) — to obtain confirmation of whether we process personal data about you, and a copy of that data.
- Right to rectification (GDPR Article 16) — to have inaccurate personal data corrected.
- Right to erasure (GDPR Article 17) — to have your personal data deleted through the workflow described in § 7, subject to statutory retention and the separately redacted public history of a real farm animal.
- Right to restriction of processing (GDPR Article 18).
- Right to data portability (GDPR Article 20) — to receive a machine-readable copy of the personal data you provided to us.
- Right to object (GDPR Article 21) — to processing based on legitimate interest, on grounds relating to your particular situation.
- Right to withdraw consent (where processing is based on consent) — withdrawal does not affect the lawfulness of processing already carried out before the withdrawal.
To exercise any of these rights, contact us at the addresses in § 1. We will respond substantively within 30 days of receiving your request. If your request is complex or one of several requests, we may extend the response window by up to two further months under Article 12(3) GDPR; we will tell you if we do.
We will not charge you a fee for exercising your rights unless your request is manifestly unfounded or excessive (Article 12(5) GDPR).
9. Security Measures
We apply the following technical and organisational security measures, designed in line with Article 32 GDPR:
- HTTPS everywhere — all traffic between you and our services is encrypted in transit using TLS;
- Supabase Row Level Security (RLS) as the authoritative permission boundary on database tables; application code defers to RLS rather than reimplementing access rules;
- passwordless authentication — we sign you in with email "magic-link" tokens rather than storing passwords;
- secrets in Supabase Vault — service-role credentials, API keys, and webhook secrets are stored encrypted at rest and never embedded in client code;
- regular backups of the production database;
- PII-scrubbed error capture — Sentry stack traces are filtered to remove email addresses, display names, and other identifying values before they are stored;
- fresh Turnstile challenges for anonymous bootstrap and configured email-code requests, with tokens kept out of URLs, storage, logs, analytics, and HTML;
- least-privilege access controls internally — only the people who need access to a category of data have access to it;
- subprocessor management — we review the security posture of each processor before engaging them and re-review on changes that affect our risk profile.
No system is perfectly secure. If we discover a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the competent supervisory authority in accordance with Articles 33 and 34 GDPR.
10. Cookies and Similar Technologies
Our Cookie Policy lists the current necessary and consented browser storage, processors, retention, and the footer control for withdrawing optional measurement consent.
11. Children's Data
Chirp Coop is intended for users aged 13 and over. The real-chicken patron service at tyuk.remeny.farm is a separate product with its own age threshold of 18+ under its own Terms.
11.1 Age of digital consent
Where you are a resident of the European Union or the European Economic Area, we rely on Article 8 GDPR. The default age of digital consent under the GDPR is 16, with Member States able to set a lower threshold no lower than 13. Where you are aged 13–15 and resident in a Member State whose national age threshold is higher than your age, we require verifiable parental consent before we may rely on consent as the legal basis for any processing that depends on consent. Hungary's age threshold for digital consent is 16; users aged 13–15 resident in Hungary therefore need verified parental consent.
We do not knowingly create accounts for users under 13. If we become aware that a user is under 13, we will close the account and delete the associated personal and private game data, subject only to legally required retention and the separately redacted public record of any real farm animal.
11.2 No targeted advertising to minors
We do not show targeted advertising to any user, and in particular we never profile users for marketing purposes. We do not use minors' personal data for marketing purposes of any kind.
11.3 Parental enquiries
A parent or legal guardian who believes their child has created an account without consent can contact us using the addresses in § 1. We will act on a substantiated parental request without undue delay.
12. International Data Transfers
Several of our processors are established in the United States (see § 5). Personal data transferred to those processors is transferred under:
- the European Commission adequacy decision for the EU–US Data Privacy Framework (where the processor is certified under the Framework); and/or
- Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR, supplemented by appropriate additional safeguards where required by the transfer-impact assessment.
We review the legal basis of each international transfer on an ongoing basis. If the European Court of Justice or the supervisory authorities determine that a transfer mechanism is no longer valid, we will update this Policy and, where necessary, change processors.
13. Right to Complain
If you believe our processing of your personal data violates the GDPR or the Infotv., you have the right to lodge a complaint:
- with the Hungarian supervisory authority — the National Authority for Data Protection and Freedom of Information (NAIH):
- website: naih.hu
- email:
ugyfelszolgalat@naih.hu
- with the supervisory authority of the EU or EEA Member State of your habitual residence or place of work, if you are resident in another Member State; the European Data Protection Board maintains a list of national authorities at edpb.europa.eu;
- with a competent court, in addition to or instead of lodging an administrative complaint, where you believe your rights have been infringed (Article 79 GDPR).
You also have the right to seek a judicial remedy against a supervisory authority's decision under Article 78 GDPR.
14. Amendments to this Policy
We may amend this Privacy Policy from time to time — in particular when laws change, when we add or change processors, or when we introduce a new feature that affects how we process personal data.
When we make a material change, we will:
- publish the updated Policy at
chirpcoop.com/privacy; - send a notification to the email address on your account at least 30 days before the changes take effect;
- give you the opportunity to cancel your account before the new terms apply if you do not agree with them.
Non-material changes (typo fixes, structural edits, clarifications that do not change the underlying processing) take effect immediately when we publish them. We update the Last updated date at the top of the page every time the Policy is republished.
15. Effective Date
This Privacy Policy is effective from 16 July 2026.