Supporting information
Privacy Policy
Prepared for review, not yet adopted or publication-ready. Operator details, service checks and contact mailbox activation remain outstanding.
This draft explains personal information used by the Axocana companion app and this website. It covers guest and email-linked accounts, virtual Sirius, your freshwater world and purchases where available. The real axolotl Sirius and the AI character are different: messages to virtual Sirius are processed by software.
1. Who is responsible and how to contact us
Axocana is the product name. The identity and address of its legal operator and data controller have not yet been confirmed for this draft; Axocana is not described here as a registered company. Those details must be supplied before this notice takes effect.
The designated privacy address is privacy@axocana.com. General app support belongs at support@axocana.com. Both mailboxes await activation. Please do not rely on them for a live request during this private review.
2. Information used in Axocana
- Account access: an account identifier, guest or linked-account status, authentication records and sessions. If you link an email address, it is used to verify and recover that account. A guest account still has an identifier; it is not the same as anonymous use.
- Your profile and journal: details you enter, such as a passport name, city, country and a playful passport answer, alongside journal bookmarks, visits and discoveries. The passport answer is not an account-recovery security answer. Location text is supplied by you; it is not a GPS reading.
- Your world: progress, wallet activity, virtual purchases, inventory, outfits, badges, tank decorations and placements, encounters and saved preferences needed to continue your journey.
- Sirius conversations: messages, replies, conversation identifiers, saved memories and any feelings or other personal details you choose to discuss. A message can remain saved even if a reply fails. A daily check-in is part of the chat, not a private medical record.
- Purchases and support features: store and product identifiers, transactions, purchase dates, delivery or refund status, a separate billing customer identifier, membership access and renewal information. Optional recognition preferences may include a display name and broad region.
- Help and feedback: the contact details, description and attachments you choose to send when support is available. Suggestions you confirm through Sirius can be stored for human review.
- Technical information: request and error information used to operate and troubleshoot services. Hosting and service infrastructure may process IP addresses, device or browser information and request times. The final production logging and diagnostic configuration still requires review.
Avoid putting passwords, payment credentials, precise addresses, medical details or another person’s private information into chat, profile fields or support attachments.
3. Why information is used
Account and game information lets Axocana authenticate you, save and restore progress, show your journal and maintain your habitat. Email verification helps protect recovery. Chat context enables relevant replies and safety checks. Purchase records allow delivery, restoration where supported, refund checks and prevention of duplicate credits. Technical records help diagnose failures, protect accounts and prevent abuse.
Optional public recognition is used only for the recognition setting you choose. Support information is used to investigate your request; confirmed product suggestions can help improve Axocana.
Proposed UK legal bases, subject to controller review: necessary account, progress and purchase processing would support performance of the service contract or steps you request before it. Proportionate security, fraud prevention and fault investigation would rely on legitimate interests after considering your rights, especially children’s interests. Optional AI sharing and public recognition require a clear choice; the applicable consent basis and withdrawal records must be confirmed before launch. Specific legal obligations may require particular transaction records. An obligation will not be assumed merely because retaining information is convenient.
Not every optional feature is necessary to use the app. Declining AI chat prevents new AI conversations, rather than requiring you to give unrelated personal information. Where consent is the legal basis, withdrawal does not make earlier lawful processing unlawful.
4. Virtual Sirius and AI processing
Talk to Sirius asks permission before sharing chat information with OpenAI. A request includes your message, recent conversation context, saved Sirius memories and current outfit details. OpenAI supplies replies and content safety processing. Axocana separately saves conversations and memories against your account.
Some information mentioned in conversation may become a saved memory. Review and remove memories using the app’s memory controls. You can reopen AI privacy below the message box and turn AI chat off. This stops new messages from that device; it does not erase previous chats or memories. Starting a new chat clears the conversation on that device, while earlier account records remain.
The reviewed integration requests that responses are not stored as retrievable response objects by OpenAI. That setting is not a promise of zero provider retention: safety logs and other permitted processing may still apply. Axocana’s final provider agreement, retention controls and any data-sharing or training settings require confirmation before publication. No blanket “no AI training” assurance is made in this draft.
AI replies and memory extraction can be inaccurate. Axocana is not intended to make decisions with legal or similarly significant effects about you through Sirius.
6. Device storage and this website
The app stores authentication and account-specific state on your device so sessions, preferences and recent activity can continue. Native authentication uses secure device storage; other app caches are separate and should not be treated as a secure place for secrets.
This website saves your sound choice in browser local storage under axocana.sound. You can change it with the sound control or remove it by clearing this website’s storage.
The footer’s Unique visits counter displays an approximate shared total of browsers that have visited the website. A local axocana.visitCount marker prevents refreshes and page navigation from counting the same browser again for up to one year. Another device or browser, private browsing, clearing website data or expiry of that marker can add a new visit. Visitors who exclude counting, signal a privacy preference or cannot save the marker are not added.
The counter stores an aggregate total, not a page history. The application does not save names, emails, IP addresses, user-agent strings or referring pages with it. A random one-time request receipt is briefly stored on your browser until counting is confirmed; a hash is retained on the server to prevent duplicate increments when a request is retried. Receipts expire after 24 hours and expired server receipts are removed on the next count request. A very late unconfirmed request is not counted again. Hosting providers may separately process ordinary connection or security logs.
Open Unique visits in the footer and choose Exclude this browser to stop future counting. The axocana.visitCounting preference remembers that choice; it can be changed there later. Global Privacy Control and Do Not Track signals are also respected. An earlier visit remains part of the anonymous aggregate and is not linked back to you. The private preview and eventual published site use separate totals.
No advertising tracker, third-party analytics script or contact form has been added. The operator must confirm the statistical purpose, applicable storage exception or consent basis, and final hosting configuration before enabling the published counter. This private draft does not establish legal approval for production analytics.
7. Where processing takes place
Service providers may process information in countries outside your own. The deployment region and international transfer arrangements for the production app are not yet verified. Before launch, the operator must identify destinations and assess the relevant safeguards, including adequacy decisions or approved contractual protections where UK law requires them. This draft does not claim that every record remains in the UK.
8. Retention and deletion
Account records support your continuing journey until they are removed through applicable deletion controls. Signing out, uninstalling, turning AI off or starting a new conversation is not a request to delete all server records. See Account & Data Deletion for the separate controls and request process.
The deletion implementation removes the authentication account and relies on database relationships to remove linked profile, conversation, memory and progress records. Its deployment and complete coverage still require testing before this can be promised as an operational service.
Billing identifiers, purchase transaction records and received billing-event payloads are retained separately by the current implementation after the direct account link is removed. This helps handle delayed store events and duplicate claims, but the records must not be described as necessarily anonymous. Their permitted scope, access and retention period need approval. Apple, Google and RevenueCat may retain their own transaction records.
Final limits for account inactivity, conversations, support correspondence, logs, backups and billing events have not yet been established in this draft. The operator must set and implement a purpose-based schedule, document any specific legal requirement and explain when backups cease retaining deleted data. No immediate erasure of every provider copy is promised.
9. Security
The implementation includes authenticated requests, account-scoped access rules, email verification and secure native session storage. Access should be limited to the people and services that need it. These measures reduce risk; no app or transmission is completely secure. Production access controls, backups, incident handling and provider configuration still need operational verification.
Keep access to your linked email secure. Axocana support should never need your password, email verification code or full payment-card details.
10. Your choices, rights and complaints
Depending on the law that applies, you may request access to or a copy of personal information, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw a choice that relies on consent. Rights can have lawful exceptions; a request should be assessed individually, with an explanation of any refusal or retained information.
The designated route is privacy@axocana.com once activated. Say which right you wish to exercise and identify the relevant account without sending credentials. Proportionate verification may be needed to avoid disclosing or deleting another person’s information. Applicable legal response periods still apply; the absence of a promised support turnaround does not remove them.
If UK data protection law applies, you can complain to the Information Commissioner’s Office. Elsewhere, you may have a right to contact your local privacy regulator. Additional regional rights and any required appeal route must be confirmed for the final launch territories.
11. Younger users
The current product documentation envisages users aged 13 and above. The launch eligibility rules, age checks and protections for teenagers are not yet final. This draft must not be treated as evidence of effective age verification or parental consent.
Axocana is not intended to invite children under 13 to create accounts or submit chat information. If you believe a child has supplied information outside the permitted age rules, use the privacy route once active so it can be investigated and appropriately removed. A parent’s concern can be raised without sending the child’s conversation history or identity documents in the first message. Protections for users under 18 and any applicable parental rights must be assessed before release.
12. Changes to this notice
The adopted notice will carry an effective date. Material changes to purposes, providers or choices should be explained before they apply, with a fresh choice where required. This review date is not an effective date, and these drafts do not authorise additional collection.
