Skip to content

What we store, and what we cannot see.

This policy sets out what personal data Hollowine collects, what of it we can actually read, where it is held and for how long. It covers the Hollowine app and this website.

Most of it comes down to one thing: what you write in the village is encrypted on your phone before it goes anywhere, so there is very little here for us to see. The rest is written out anyway, including the parts that are less flattering to us, and it is written to be read rather than survived.

Controller and contact

Hollowine is built and operated by Kamil Klofczynski, trading as hollowww.dev, based in Helsinki, Finland, acting as the data controller under the GDPR.

For any question or request arising from this policy, including any request concerning your data: me@hollowww.dev.

Summary

  • Everything you write inside the village is encrypted on your device before transmission. The server holds ciphertext, and the encryption key never leaves your device.
  • The readable account data is your email address, whether the account is confirmed, the date it was created, the date onboarding was completed, and the time of the most recent sync.
  • This website sets no cookies and loads no analytics or third-party tracking scripts. Server logs retain IP addresses for 90 days.
  • No personal data is sold, and none is shared with advertisers or data brokers.
  • Your account and village data are hosted inside the EU. App performance and error reports are processed in the United States by Expo, the company behind the framework Hollowine is built on.

Village data

All village data is encrypted on your device before it is sent anywhere. The server stores ciphertext.

Two payload fields are stored in readable form because the server requires them in order to operate: the timestamp your profile was created and the timestamp you finished onboarding. Every other field inside a row, on every table, is encrypted. Each row also carries four operational columns outside the encrypted payload, because the server needs them to reconcile your devices: which table the row belongs to, its identifier, whether it has been deleted, and the time it was last written to the server. These are readable. The date of your most recent sync is derived from them, as is the record of whether an account was active in a given month.

Account data

Signing in uses an email address and a one-time code. The email address is held in AWS Cognito in readable form, as it is required to deliver the code.

The operator dashboard used to run the service can display, for a given account:

  • the email address, and whether the account is confirmed
  • the date the account was created, and the date onboarding was completed
  • the time of the most recent sync to the server
  • whether an active session exists

Waitlist and newsletter

If you join the waitlist or subscribe to the newsletter, your email address is stored encrypted at rest with a key held on the server, together with the date you subscribed and the platform you selected. This data is not end-to-end encrypted and is readable by us. It is used solely to send Hollowine updates. Every message carries a one-click unsubscribe link, and unsubscribing deletes the record.

Website visits

No cookies are set, no analytics script runs in your browser, and no third-party tracker is embedded on this site.

The content delivery network writes one server log line per request, recording your IP address, the page requested, the browser user-agent string, and the referring page where one is present. Your country is inferred from your IP address at the CDN edge and included in the log line; no more precise location is ever available. These logs are deleted automatically after 90 days. They are used to produce visit and page counts, and a country-level breakdown of where visitors arrived from; IP addresses are hashed in that process and the addresses themselves are discarded.

Contact form

Messages submitted through the contact form, and the email address supplied with them, are emailed to us so that we can reply. They are not used for any other purpose.

Error and performance reports

The app sends two kinds of diagnostic data to Expo Observe, a service run by Expo (the company behind the framework Hollowine is built on), so we can find and fix problems and see whether the app is running well on real devices:

  • Performance data - how long the app takes to start, and how long each screen takes to load, together with which screens were visited and in what order.
  • Error reports - when the app hits an error, its message and stack trace, the app version, your device model and operating system version, and the same trail of screens visited beforehand. Email addresses and access tokens are stripped from the report before it is sent, and no village content is included.

This data is tied to your device installation, not to your account, email address or identity - Expo has no way to connect it back to you. As with any network request, your IP address is visible to Expo's infrastructure at the point of transmission. Reporting runs in released builds only. Native crashes in the app's underlying platform code (as opposed to errors inside the app's own code) are not currently captured by any service we use.

Expo processes this data in the United States, not the EU. Expo certifies compliance with the EU-U.S. Data Privacy Framework (see Expo's own privacy policy), which is the mechanism that permits this transfer under the GDPR. Retention is set by Expo's own policy, not ours.

Where data is held

Your account and village data are hosted on Amazon Web Services in the eu-north-1 region (Stockholm, Sweden), inside the EU. Error and performance reports (see above) are processed by Expo in the United States. AWS and Expo act as processors; no other company processes your data.

Retention

What Kept for
Village data Until you delete it or delete your account
Server backups A rolling 35-day recovery window
Deletion markers Retained, see below
Waitlist and newsletter addresses Until you unsubscribe
Website server logs 90 days
Emails you send us Until cleared manually

When an item is deleted, a marker recording its id and the time of deletion is retained so that the deletion can reach your other devices. The marker carries no content. Markers do not expire: they are the mechanism by which a deletion reaches a device that was offline at the time, and expiring them would allow deleted data to reappear on a device that had been offline for a long period.

Deleting your account removes your village data from the server. Backups run on a rolling 35-day window, so a copy may persist in backups for up to 35 days before ageing out.

Legal bases

  • Operating your account and syncing your village - performance of the agreement between us (GDPR Article 6(1)(b)).
  • Waitlist and newsletter emails - your consent (Article 6(1)(a)), withdrawable at any time through the unsubscribe link in every message.
  • Server logs, and the visit counts derived from them - legitimate interest (Article 6(1)(f)) in keeping the service secure and measuring readership. Nothing is stored on or read from your device, so consent is not the applicable basis and no cookie banner is required.
  • Error and performance reports - legitimate interest (Article 6(1)(f)) in finding and fixing defects and keeping the app working well. Transferred to Expo in the United States under Expo's certified EU-U.S. Data Privacy Framework compliance.

Your rights

Under the GDPR you may request access to your personal data, rectification, erasure, portability or restriction of processing, and you may object to processing carried out on the basis of legitimate interest.

Village data can be deleted directly in the app. For anything else, email me@hollowww.dev; we will respond within 30 days.

One limitation applies: encrypted village data cannot be supplied in readable form, because we cannot decrypt it. The ciphertext can be supplied. A readable copy has to be exported from your own device.

Complaints may be directed to the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi), or to the supervisory authority in your country of residence.

Children

Hollowine is not intended for children under 13, and accounts are not knowingly created for them.

Changes

Where this policy changes in a way that affects what is collected or what is readable, the change will be announced rather than published quietly. The date below identifies the version you are reading.

If any part of this is unclear, or you want something done with your data, write to me@hollowww.dev. A person reads it.

Last updated: 28 August 2026.