Survive the Snail
Privacy Policy
How LKG Labs LLC collects, uses, discloses, retains, and protects information when you use Survive The Snail.
Effective date: July 27, 2026
1. Who We Are
Survive The Snail is operated by LKG Labs LLC ("LKG Labs," "we," "us," or "our"). This Privacy Policy explains how we handle information when you use the Survive The Snail mobile app, website, and related services.
Support and privacy requests can be sent to support@survivethesnail.com.
2. Short Version
Survive The Snail turns your steps and walking/running distance into a fictional chase game. To do that, the app needs an account, age eligibility information, profile information, Motion and Fitness/pedometer permission on supported devices, body metrics you provide, gameplay data, and related settings such as notifications, purchases, challenges, coins, achievements, and leaderboards.
Your date of birth, height, weight, device identifier, email address, push token, direct activity records, and 15-minute chase distance verification buckets are not shown publicly. Your username, display name, profile photo, private-profile status, and limited chase/profile information may be visible to other signed-in users depending on your settings and social relationships.
We do not sell your fitness or body data, and we do not use it for advertising. Product analytics is currently disabled in the app. Users may see Google AdMob banner ads; the app currently requests non-personalized ads and does not request Apple's App Tracking Transparency permission or IDFA access.
3. Information We Collect
Account and Authentication Information
We collect account identifiers, email address, email verification status, authentication provider metadata, session information, password reset/update metadata, and sign-in timestamps. If you use Sign in with Apple or Google, those providers may send us identity information such as email address, provider user ID, and name fields that you authorize. Passwords are handled by Supabase Auth; we do not store your plaintext password.
Age, Profile, and Preferences
We collect your date of birth to enforce minimum age rules and apply age-sensitive advertising settings. The app currently applies a minimum age of 16 in EEA regions and 13 elsewhere, with a server-enforced 13-year floor. We also collect profile and preference details such as username, display name, optional profile photo, daily step goal, difficulty preference, timezone, private-profile and discoverability settings, notification preferences, account status, and onboarding status. Some settings, such as theme, units, haptics, local notification state, and cached app settings, may be stored locally on your device.
Motion, Activity, and Body Information
After you grant permission on supported devices, the app collects or derives step counts, walking/running distance, activity timestamps and coverage windows, activity source, a device pseudonym, live and daily activity totals, chase-specific activity totals, estimated active minutes, estimated calories, 15-minute chase distance verification buckets, daily goal status, streak status, and the height and weight you enter.
Height helps estimate stride and distance when native distance data is unavailable. Weight helps estimate active calories and effort. Height, weight, exact date of birth, and direct activity records are private account data.
Gameplay, Social, and Moderation Information
We collect gameplay state such as chase start time, lead distance, days survived, caught status, difficulty history, daily goal bonuses, achievements, challenge membership, challenge scores, challenge events, reactions, inbox messages, coin balance, shop item use, and virtual item effects. We also collect friend/follow relationships, friend requests, blocks, profile searches, reports you submit, report reasons, optional report details, and moderation-related records.
Photos and Uploaded Content
If you choose a profile photo, the app asks for camera or photo-library permission and uploads the selected image to our storage provider. Challenge banners currently use preset artwork or stored banner URLs. We delete user-owned profile and challenge storage objects when you delete your account, subject to backup and processor retention limits.
Purchases, Ads, Notifications, and Technical Information
If you buy coins, restore purchases, or use paid features, we and our payment processors may process product identifiers, transaction identifiers, store and environment details, purchase, refund, and restoration status, RevenueCat customer and event data, and purchase payloads needed for validation, fraud prevention, fulfillment, support, and accounting.
If ads are enabled for your account and region, Google AdMob may process device, app, network, ad delivery, ad interaction, diagnostic, and approximate location information as described by Google. The current app requests non-personalized ads only and initializes ad requests only after Google's consent system indicates ads may be requested.
If you enable notifications, we collect an Expo push token, iOS identifier for vendor or other device pseudonym, platform, token status, notification preferences, notification queue records, delivery status, and errors. We may also receive technical information from your device, app stores, hosting providers, Supabase, Expo, RevenueCat, Google, Apple, and support interactions, such as IP address, request metadata, crash or diagnostic logs, device model, OS version, app version, support messages, and timestamps.
4. How We Use Information
We use information to:
- create, authenticate, verify, secure, and maintain accounts;
- enforce age eligibility and account rules;
- calculate steps, distance, active minutes, calories, lead distance, caught status, daily goals, streaks, achievements, leaderboards, challenge results, and other gameplay features;
- sync activity across app launches, foreground activity, and background refresh when supported by the device;
- provide social features such as search, friend requests, private profiles, blocking, reports, challenges, reactions, and leaderboards;
- fulfill coin purchases, virtual item use, purchase restoration, refunds, and fraud prevention;
- show non-personalized ads where enabled and allowed;
- send notifications you enable;
- provide data export and account deletion tools;
- respond to support, safety, legal, and privacy requests;
- detect, prevent, and investigate abuse, cheating, fraud, security incidents, and technical failures;
- comply with legal obligations and enforce our Terms of Service.
5. Social Visibility
Other signed-in users may see:
- your username, display name, profile photo, and private-profile status;
- whether you are searchable;
- friend/follow relationship status;
- limited profile and chase summary data when allowed by your privacy settings;
- challenge participation, scores, rankings, events, reactions, and milestones in shared challenges;
- global leaderboard information if your profile is public, discoverable, and leaderboard visibility is enabled.
Private Profile limits activity and chase details to friends and hides your account from the global leaderboard. Private profiles may still appear in profile search with limited identity fields so other users can send friend requests. Blocks restrict blocked accounts from seeing your profile, inviting you to challenges, and appearing in certain social surfaces.
6. Legal Bases for EEA, UK, and Similar Regions
Where data-protection law requires a legal basis, we rely on:
- Contract: account creation, authentication, core chase processing, activity sync, body metrics needed for estimates, social features, purchases, virtual items, challenges, leaderboards, support, and account deletion.
- Consent: optional notifications, camera/photo-library access, ad consent choices where required, and any processing that local law treats as requiring consent.
- Legitimate interests: security, abuse prevention, fraud prevention, cheating detection, service reliability, limited moderation, and legal-defense records, after considering user rights and expectations.
- Legal obligations: tax, accounting, consumer, platform, safety, data-protection, and law-enforcement obligations where applicable.
Motion, activity, height, weight, and derived fitness information may be considered sensitive or health-related information in some jurisdictions. Where local law requires an additional condition or consent for that type of information, we rely on the applicable condition, permission, or consent presented in the app or required by law.
7. How We Share Information
We share information only as needed to operate, protect, and improve the Service, or as required by law. Recipients may include:
- Supabase: authentication, database, storage, Edge Functions, access controls, and backend processing.
- Expo: app services, updates, push notification token delivery, and related infrastructure.
- Apple: Sign in with Apple, App Store distribution, in-app purchases, refunds, device permissions, and platform services.
- Google: Google sign-in where used, Google Mobile Ads/AdMob, advertising consent forms, ad delivery, and ad verification.
- RevenueCat: in-app purchase, coin pack, webhook, restoration, refund, and customer deletion workflows.
- PostHog: product analytics is currently disabled, but deletion tooling exists for prior or future analytics records if any are present.
- Other users: profile identity, leaderboards, friend/challenge information, challenge events, reactions, and other social visibility described above.
- Service providers and professional advisers: hosting, security, support, legal, accounting, audit, and compliance providers.
- Authorities or other parties: when we believe disclosure is required by law, needed to protect rights or safety, or necessary to investigate fraud, abuse, or security incidents.
- Business transaction parties: if we are involved in a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate protections.
We do not sell fitness or body data, use fitness or body data for advertising, or knowingly sell personal information or share it for cross-context behavioral advertising as those terms are commonly used in U.S. state privacy laws. If our ad configuration changes to personalized or cross-context behavioral advertising, we will update this Policy and provide any required opt-out controls.
8. International Transfers
We and our service providers may process information in the United States and other countries. If you are in the EEA, UK, Switzerland, or another region with transfer restrictions, we use available transfer mechanisms such as adequacy decisions, Data Privacy Framework participation where valid, Standard Contractual Clauses, contractual commitments, and supplementary safeguards as applicable.
9. Retention
We keep information only as long as needed for the purposes described in this Policy unless a longer period is required or allowed by law. Current app-specific retention practices include:
- account, profile, gameplay, social, challenge, purchase, and support records are generally kept while your account is active;
- accounts that never finish onboarding are deleted after 30 days;
- 15-minute chase distance verification buckets are deleted after 30 days;
- final notification outbox payloads are deleted after 30 days;
- inactive push tokens are deleted after 30 days;
- expired targeted inbox messages are deleted after 30 days;
- completed processor-erasure retry jobs are deleted after 30 days;
- profile photos and challenge storage objects owned by your account are removed during account deletion;
- RevenueCat and PostHog deletion is attempted during account deletion and retried through a minimal processor erasure queue if a processor request fails.
Backups, platform purchase histories, app-store records, processor logs, fraud-prevention records, legal records, tax/accounting records, and support records may follow different retention periods.
10. Your Choices and Controls
You can:
- edit your profile, name, username, email, password, date of birth, height, weight, daily goal, units, theme, haptics, and notification preferences in the app;
- enable or disable Private Profile in Settings > Visibility;
- block accounts from their profile or manage blocked accounts in Settings;
- report accounts from a user's profile;
- enable or disable notification categories in Settings > Notifications;
- open Advertising Preferences in Settings when Google's consent system requires that regional option;
- download a machine-readable copy of your data in Settings > Download My Data;
- delete your account in Edit Profile > Delete Account.
You can also contact support@survivethesnail.com to request help with access, correction, deletion, restriction, objection, portability, consent withdrawal, or other privacy rights that apply in your region.
We may need to verify your identity before completing a request. Some requests may be limited by legal obligations, fraud prevention, security, technical constraints, platform records, or other users' rights.
11. Account Deletion
You can delete your account in the app from Edit Profile > Delete Account. Deletion removes your Supabase Auth user, profile, dependent database rows, and user-owned storage objects from active systems. We also attempt to erase related RevenueCat and PostHog records using the user identifier associated with your account.
Deleting your account does not automatically refund purchases managed by Apple, Google, or another app-store provider. Refund requests are handled by the relevant app-store provider unless applicable law requires otherwise.
12. Children and Teens
Survive The Snail is not intended for children below the minimum age shown during signup. The app currently applies age 16 in EEA regions and age 13 elsewhere, with a server-side 13-year minimum. If you believe a child below the applicable minimum age has provided information to us, contact support@survivethesnail.com and we will review and delete the account where required.
Parents or guardians should contact us if local law requires parental authorization for a teen's use of the app and that authorization was not obtained.
13. Automated Gameplay and Estimates
The app automatically calculates game progress, distance estimates, calorie estimates, activity freshness, rankings, rewards, challenge outcomes, and whether the fictional chase catches a player. These calculations affect in-app gameplay, leaderboards, and notifications. They do not create legal, employment, credit, insurance, medical, or similarly significant real-world effects.
Activity and body estimates can be inaccurate because they depend on device sensors, operating-system data, permission state, sync timing, height/weight estimates, and network availability.
14. Security
We use technical and organizational measures designed to protect information, including encrypted transport, Supabase authentication, row-level access controls, restricted profile columns, secure session storage, storage cleanup on deletion, retention jobs, and service-role restrictions for privileged backend functions. No system is completely secure. If a data incident occurs, we will assess it and provide notices required by law.
15. Third-Party Links and Services
The app may open websites, app-store pages, provider login pages, purchase flows, or privacy options controlled by third parties. Those third parties process information under their own terms and privacy policies.
16. Changes to This Policy
We may update this Privacy Policy when our practices, services, vendors, or legal requirements change. We will update the effective date and provide additional notice or request consent when required by law.