Privacy policy
Last updated: 3 October 2026
Who is responsible
The Harmoniser project (“we”, “us”) runs this website and the capsule marketplace, and publishes the Harmoniser app for HarmonyOS. For the purposes of the EU General Data Protection Regulation (GDPR), we act as the controller for the data described below. This hackathon draft does not yet name the controller's legal identity or a private channel for privacy requests; both will be published before any commercial release. Do not put personal data in a public issue: a public tracker is not a private channel.
What the app does on your device
- Capsules you create, their state (counters, checklists, timers) and your permission choices are stored on your device. We never receive them from the app.
- Rule-based generation and the optional on-device model run locally. The on-device engine is built so it makes no network calls.
- Cloud AI is off by default. If you turn it on and add your own API key, the text you type is sent to the provider you chose so it can build the capsule. Your key stays on your device and is never packed into the app or sent to us.
- When a capsule asks for a device feature (reminders, notifications, motion, and so on), the app shows a permission sheet first. Denials are final and are logged on the device.
What the marketplace stores
If you publish a capsule on this site, or install one, we process:
- the capsule JSON you choose to publish, with the name, description and tags you enter — this is public by design and shown to anyone who visits the marketplace;
- a keyed hash of an anonymous owner token. Your browser sends it to the API over HTTPS when you publish or delete, and the server stores only the hash — never the token, and never in a public listing. It is what proves you can delete a capsule you published;
- a keyed hash of a separate anonymous install ID, sent when you install, report or pair a device. It is not a publishing credential and never owns a capsule; it exists so installs and reports can be de-duplicated without identifying you;
- a one-way hash of your IP address, used only to enforce the publish rate limit and to de-duplicate install and report actions. The raw IP is not stored;
- ordinary server logs from our hosting provider, which may include IP addresses and request metadata for security and debugging.
Browsing the marketplace needs no account. We do not sell data, and we do not run advertising or third-party analytics trackers.
Why we may process it (legal bases)
- Performance of a service you asked for (Art. 6(1)(b) GDPR): publishing, listing, installing and deleting capsules.
- Legitimate interests (Art. 6(1)(f) GDPR): keeping the marketplace available and abuse-resistant, rate limiting and moderation.
- Consent (Art. 6(1)(a) GDPR): where we ask for it before doing anything optional; you can withdraw it at any time.
How long we keep it
- Published capsules: until the publisher deletes them or we remove them (deletion removes the public payload immediately; a minimal audit record may remain).
- Install and report receipts: about 24 hours.
- Rate-limit buckets: about 25 hours in total.
- Hosting logs: according to our hosting provider's short retention.
Who processes it with us
The site and its API run on Vercel, and the data is stored in MongoDB Atlas. Both are established providers that process data on our behalf, and both may process data outside the European Economic Area using standard contractual safeguards. We do not share marketplace data with anyone else except where the law requires it.
Your rights
Under the GDPR you can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interests. Because marketplace publishing is anonymous, we usually cannot identify you from a capsule alone; if you hold the owner token used to publish it, you can delete it yourself, and we can act on a request that identifies the exact capsule. You also have the right to complain to a supervisory authority — for example the Polish Data Protection Authority (UODO) where this project was built, or the authority in your own country.
The 108 seeded template capsules are permanent built-ins: they were published without an owner who holds a delete credential, so they cannot be deleted with an owner token. An operator can remove them from the database if needed. Capsules you publish yourself keep the normal owner-token delete contract.
Security and children
Traffic is encrypted in transit; authentication credentials are sent to the API over HTTPS and stored only as keyed hashes. The database user is least-privilege. The marketplace is not intended for children, and we do not knowingly collect data from children.
Changes
We will update this page when the marketplace changes, and the date at the top will change with it. This notice covers the HackYeah 2026 prototype and will be reviewed before any commercial release.