zoonelo

Privacy policy

Clear information about your account, your data, and using Zoonelo.

Effective October 3, 2026.

Operated by Envisionary Design. Contact support.

Who operates Zoonelo

Zoonelo is operated by Envisionary Design (envisionarydesign.com). This policy explains how we handle information when you use Zoonelo. Use the Feedback tab or the contact form on our Help page with privacy questions or requests.

Information you provide

We collect your sign-in email, account identifier and profile details such as display name and timezone. If you choose a social sign-in option such as Google, Facebook or GitHub, that provider and our authentication provider process the information needed to authenticate you. We also receive information you include in support messages and any group names or logos you upload.

Instagram and Facebook information

With your authorization, Zoonelo uses official platform APIs to read account identifiers, usernames, profile details, published content identifiers, post URLs, content types, publication times, follower counts and available performance metrics such as likes, reactions, comments counts, shares, saves, views and reach. Availability depends on your account type and granted permissions. Access credentials are used to maintain the authorized connection. Google sign-in does not authorize Instagram or Facebook access. We do not ask for your social account password. The public city demo uses sample data rather than your platform data.

How we use information

We use account information to provide sign-in and account settings; authorized activity to display progress, buildings, challenges and metrics; and technical records to operate, troubleshoot and protect the service. We use contact messages to respond to requests. We do not use connected platform data for unrelated advertising or sell it.

Sharing and service providers

Supabase provides authentication, database and storage services. Netlify hosts the website. Google and connected social platforms process authentication or authorization when you use their services. These providers may process information in countries other than where you live. Authorized group participants can see activity, display names and rankings shared within their group. Your private account settings and connection credentials are not shared with group members. We may disclose information when legally required or necessary to address fraud, abuse or threats to safety.

Browser storage and technical information

We use browser storage to maintain your signed-in session and a short-lived security cookie to verify Facebook authorization. Our service providers may process IP addresses, request details, device/browser information and security or diagnostic logs when serving the app. The city demo keeps its simulation in memory and resets when reloaded. The current app does not include advertising cookies or an advertising tracker.

Retention

We retain your account, profile and activity history while your account remains open so you can keep your progress. On a verified deletion request, we remove the applicable records from our active systems. Copies already held in provider backups may remain until those backups expire or are overwritten under the provider’s retention settings; they are not used to restore your account for ordinary use. If a backup is restored for recovery, completed deletions must be reapplied. We retain only information necessary to meet legal obligations, resolve disputes, address security incidents or document a request, where applicable. Contact us for questions about retained information.

Your choices and requests

You can edit your profile, sign out, and download currently accessible account records from Settings. That download excludes credentials, uploaded files, authentication logs and inaccessible historical group records; use our contact form for a broader access request. Use the contact form on our Help page to request access, correction or deletion, or raise an objection or restriction request where applicable. We verify account ownership before disclosing or deleting private records. If you have rights under applicable privacy law, these instructions do not limit them; you may also contact the relevant privacy regulator.

Disconnecting and deleting

You can revoke Zoonelo authorization through the connected provider’s settings. Revocation and account deletion are separate: revoking access does not itself remove data already stored by Zoonelo. For deletion, follow the Data deletion page or use the contact form on our Help page. Deleting Zoonelo data does not delete your original posts or your Instagram, Facebook or Google account.

Children

Zoonelo is not intended for children under 13. Do not create an account if you are under 13. If you believe a child has provided personal information, use the Feedback tab or the contact form on our Help page so we can investigate and remove it where appropriate.

Policy updates

We will update this page when our practices change and identify the effective date. Material changes to how connected data is used will be communicated before the new use begins. Any additional authorization required by a platform will be requested separately.

Payments

Stripe processes checkout payments. Zoonelo stores the order reference, payment status, amount, currency and sprint registration needed to fulfill your purchase. Zoonelo does not receive or store your full card number. Use the Feedback tab or the contact form on our Help page for billing or payment-data questions.

GitHub public activity

When you explicitly connect GitHub imports, we verify your linked GitHub identity and retrieve public profile identifiers, follower counts, public development events and star counts on your owned non-fork public repositories. We do not import private repository content. The initial event feed is limited to up to 300 events within 30 days; recorded activity then accumulates through periodic imports. GitHub sign-in alone does not enable these imports. Disconnecting stops future polling; previously imported history remains until account deletion. GitHub activity stays private unless you choose to share the account with a community that tracks GitHub. Shared buildings include imported activity, available followers and repository star totals. GitHub rankings are separate from social-post rankings.

Feedback and support

When you submit feedback, we collect your category, message, the page path, optional reply email, and any images or voice recording you choose to attach. We do not automatically capture screenshots. Images are resized in your browser. You can remove attachments or recordings before sending. A keyed hash derived from your IP address and temporary security checks help limit abuse; raw IP addresses are not stored in our feedback tables. Supabase stores reports and attachments privately, and Resend delivers them to our support inbox. These records are used to respond to requests, investigate problems and prevent abuse, and retained only as needed for those purposes and applicable obligations. You may request access or deletion through the same form.

Billboard advertising

We store the artwork, destination URL, placement, review history and payment reference you submit for a billboard. Drafts are private. Approved artwork and links are displayed to people viewing the city. Stripe processes payment details; Zoonelo does not store card numbers. The owner reviews advertising submissions and feedback, including ad reports.