Privacy Policy
This Policy describes how user data is processed in the Colovia service (the “App”). The App is available as:
| Platform | Address |
|---|---|
| Web app | app.colovia.app |
| iOS | App Store, backed by api.colovia.app |
| Android | Google Play, backed by api.colovia.app |
1. Data Controller
E-com solutions OÜ
Reg. code 16662128 · Ida-Viru maakond, Lüganuse vald, Oandu küla, Allika, 42314, Estonia
Data protection contact: privacy@artia.club
2. What data we process
Sign-in data — depending on the method you choose:
- Guest sign-in — an anonymous account with a random identifier; no name or email requested
- Sign in with Google — your Google account ID, name, email and profile photo URL, as shared by Google with your consent
- Sign in with Apple — your Apple ID (sub), name and email (or a private relay address) if you chose to share them
- Email sign-in — your email address and a confirmation code
Data created while you use the App:
- Nickname and avatar color, if you set them
- Painting progress (filled regions, time spent)
- Points history, achievements, records
- Messages and emoji reactions in shared painting sessions
- Pictures created from your photos (the source photo is used to build your coloring page)
- Referral connections (who invited whom)
- Settings (theme, language, coloring options)
- Share cards with your progress (stored up to 7 days)
- Device push tokens (Apple APNS on iOS, Google FCM on Android) — to deliver notifications
- Purchase data: App Store / Google Play transaction identifiers, used to grant purchases and prevent double crediting. We never see your payment card — payments are processed by Apple and Google
- Anonymized usage events (catalog opened, painting started/completed) — our own analytics with no third-party analytics SDKs; events contain no name or email and are not used for advertising
- Android crash reports (Firebase Crashlytics) — technical data about the error and device
- Technical logs (kept 30 days when errors occur)
What we do NOT collect:
- Passwords or payment card data
- Geolocation
- Your phone contacts
- History of other apps or websites
- Biometrics
- Cross-app / cross-website tracking of any kind
- We do not sell your data and never share it with data brokers
3. Advertising
The mobile apps may show Google AdMob ads. When ads are enabled:
- AdMob processes technical device data under the Google Privacy Policy
- Users in the EEA/UK see a consent form (Google UMP); without consent, ads are served non-personalized
- Ads can be removed permanently with a one-time in-app purchase
4. Purposes
- Running the App: saving progress, leaderboards, collaborative painting
- Notifications (invites, reminders, session results) — only with your push permission
- Granting purchases and preventing abuse
- Aggregated analytics and product improvement
- Security and multi-accounting prevention
5. Sharing with third parties
- Apple Inc. — Sign in with Apple, push notifications (APNS), App Store purchases — Apple Privacy Policy
- Google LLC — Sign in with Google, push notifications (FCM), Google Play purchases, crash reports (Crashlytics), ads (AdMob, when enabled) — Google Privacy Policy, Firebase Privacy
- Hosting provider — server hosting in the Netherlands (Amsterdam, EU)
- Public authorities — only where required by applicable law
6. Retention
| Data | Period |
|---|---|
| Account and progress | While the account exists |
| Session chat messages | Until account deletion, or 30 days after the session ends |
| Share cards | 7 days |
| Push tokens | Until the app is uninstalled or permission revoked |
| Error logs | 30 days |
| Login history | 90 days |
| After account deletion | Progress and shared-room results remain only anonymized under the neutral name “Participant”; technical purchase identifiers are kept to prevent double crediting and refund abuse |
7. Your rights
- Know what data we hold about you and get a copy
- Correct inaccurate data
- Delete your account and related data (“right to be forgotten”)
- Withdraw consent
- Complain to your local data protection authority
Deleting your account in the App: More → Settings → Delete account (all platforms). After the two-step confirmation:
- Sign-in data, email, name, nickname, avatar and push tokens are erased
- Uploaded photos, chat messages and support records are deleted
- Access to points, rewards and purchases ends; signing in again creates a fresh empty account
- Progress and shared-room results remain only anonymized (“Participant”) so other players’ shared history stays intact
- Technical identifiers of purchases and one-time rewards are kept solely to prevent granting them twice
Without access to the App, email privacy@artia.club. We reply within 10 business days.
8. Security
- All traffic uses HTTPS / WSS
- Sign-in is verified with Google/Apple tokens or an email code; there are no passwords
- Database access is restricted and logged
- Daily backups
9. Cookies and local storage
The web app uses browser local storage only for your preferences and session token. There are no advertising or tracking cookies.
10. Children
On first launch the App asks your age and adjusts features accordingly; third-party services not intended for children are disabled for them. Accounts and data processing for children under 13 without parental consent are not intended. If you believe a child has provided us data, email privacy@artia.club and we will delete it.
11. Changes
The current version is always available at artia.club/colovia/privacy/. We announce material changes in the App.