GOLD STAR BY STRAWBERRY POP STUDIOS

Privacy Policy

Beta draft · Last updated September 18, 2026

Who this policy is for

This policy describes the Gold Star app and this beta website, operated by Strawberry Pop Studios. Questions can be sent to [email protected].

Information used to run Gold Star

  • Account and profile: sign-in identifiers such as your email, authentication records, profile information, and images you choose to provide.
  • Relationship and pairing: invitations, membership and pairing information used to connect your shared experience.
  • Shared activity: Gold Stars, rewards, configured demerits, history and calendar entries, milestones, and prizes.
  • Media: uploaded profile images and other user-provided media, plus references to stickers or GIFs selected in the app.
  • Notifications and device information: notification preferences, push delivery identifiers, permissions, and technical data needed to deliver notifications and troubleshoot the app.
  • Security and service records: logs, request metadata, errors, support correspondence, and operational records used to run, protect, and diagnose the service.

How information is used and shared

We use this information to authenticate accounts, connect partners, show shared activity, store media, deliver notifications, provide support, and maintain security. Information you add to shared features may be visible to your paired partner. Use those features with mutual agreement and avoid uploading information you do not have permission to share.

Service providers and third-party content

Gold Star uses Supabase for backend data, authentication, and storage. The app includes GIPHY integration for GIF content; searches or media requests may be processed by GIPHY and its delivery infrastructure. Cloudflare hosts this website, and the current APK is distributed through Expo. Notification delivery also relies on delivery providers and device operating systems. These services may process technical request and device information under their own terms and privacy policies.

This website does not include a sign-in form, advertising scripts, or an added analytics integration in this release. Hosting and download providers can still process network and security logs.

Media and account security

Access controls are used to restrict account data and private media. No service can guarantee absolute security. Protect your device and sign-in access, and do not send passwords or verification codes to support.

Account deletion

Normal-user deletion is currently disabled. The Delete Account page explains current availability. When enabled, the deletion process will require fresh verification and acceptance of the request. On completion, identifying account data and private user media are removed; the Auth identity is deleted last.

A surviving partner may retain minimal non-identifying history. Final-member deletion purges the survivor archive. Processing may take time, and accepted requests will retry automatically once the feature is enabled. Completed operational deletion identifiers are retained for 30 days.

Retention and privacy questions

Data is used for the purposes described above while providing the service. Detailed retention periods for other service logs, support correspondence, provider backups, and any legal retention exceptions are still under owner and legal review. Contact support to ask about your information or privacy options; availability of a particular legal right depends on applicable law.

Items pending owner and legal review

Before broader release, the owner must review operator identity and contact details; eligible ages and children’s privacy; the complete provider and data inventory; log and backup retention; international processing; applicable privacy rights and request handling; and any required legal disclosures. This beta draft does not assert GDPR, CCPA, or other regulatory compliance.

Changes and contact

This page may change as the beta develops. The updated date will appear above. Contact [email protected] with questions.