Last updated: August 9, 2026
Benjamin Tourneur (individual) — benjamin@quokalm.fr
User Account Email address, username, password (encrypted by Supabase Auth — never accessible in plain text), avatar (optional), language preference, reputation score, total upvotes received, premium status.
Google Sign-In (OAuth) If you sign in with Google, we receive your email address and Google profile name to create or identify your account. No Google password is stored by Quokalm.
Sign in with Apple (iOS) If you sign in with Apple, we receive a unique Apple identifier and an email address to create or identify your account. If you enable "Hide My Email", Apple only passes on an anonymous relay address — your real address is never disclosed to us. Any name provided by Apple is used only at account creation and is never published; your public username remains the one you choose. No Apple password is stored by Quokalm.
Community Contributions Spots added (name, address, GPS coordinates, description, tags, photos), written comments, spot and comment upvotes, tag votes (+1/-1), off-peak times, peak times, vibe reports, temporary alerts and associated votes, sound level measurements in decibels, attitude ratings on health and leisure places (a 1-4 level per subject; only the community median, the breakdown of votes per level, and their count are displayed publicly), toilet accessibility levels, dietary option levels for gluten-free, dairy-free and vegan, seating comfort levels and lighting intensity levels (a 0-2 level per topic; these votes describe what the venue offers, never your health or your diet, and only the community median together with the breakdown of votes is displayed publicly).
Polls Your poll responses are recorded and linked to your user identifier to guarantee vote uniqueness.
Badges Badges unlocked and rarity tiers based on your in-app activity.
Location Your GPS position is used solely to center the map and perform nearby searches. It is processed locally on your device and is not stored on our servers.
Microphone Microphone access is required solely during ambient sound level measurement. No audio recording is made, transmitted, or retained. Only the numerical decibel (dB) value is stored in the database.
Advertising Data For non-premium users, Google AdMob may collect a mobile advertising identifier and ad interaction data (impressions, clicks, rewarded video views), in accordance with Google's privacy policy. In addition to banner and interstitial ads, an optional rewarded video may be offered to unlock an additional extended search beyond the free daily allowance. Watching it is always your choice, is never required, and is never offered in Health mode. On Android, this identifier is the GAID; you can reset or delete it in Settings → Privacy → Ads. On iOS, the app does not request tracking permission (App Tracking Transparency): Apple's advertising identifier (IDFA) is not collected and your data is not used to track you across other companies' apps and websites. Ads are contextual. You can further limit personalization in Settings → Privacy & Security → Apple Advertising.
In-App Purchases The "Remove Ads" purchase is processed exclusively by Google Play (Android) or the Apple App Store (iOS). RevenueCat receives an anonymized purchase identifier and an anonymous app-level identifier in order to validate your premium entitlement and allow the purchase to be restored. No payment card data is transmitted to Quokalm.
Push Notifications When you grant notification permission, an Expo Push Token (a unique device identifier for notifications) is stored. We record: the token, the platform (Android or iOS), the device identifier, and your notification preferences (enabled/disabled, per type). Delivery is handled by Firebase Cloud Messaging on Android and by the Apple Push Notification service (APNs) on iOS. This data is deleted along with your account.
Zone Alerts If you define an alert zone to be notified of new spots, the center and radius of that zone are stored. This data is deleted along with your account.
Offline Data When you use the app without a connection, certain actions are temporarily stored in your device's local memory (AsyncStorage) and deleted after synchronization.
Your data is used to: