Karol DecykKOS-MOS
KOS-MOSPhotographyVideoWebsitesGamesArtContact

PRIVACY

Privacy Policy

This privacy policy explains what data is processed when using the KOS-MOS website, why it is processed and what rights users have.

Last updated: 26 August 2026

1. Controller

The controller responsible for personal data processed in connection with KOS-MOS is:

Karol Decykul. E.Sz. Zarembiny 19/2285-792 BydgoszczPoland

Email: contact@karoldecyk.com

2. General information and legal bases

Data is processed only to the extent needed to provide the website, handle enquiries, operate the voluntary public leaderboard, provide voluntary usage analytics and provide features selected by users. The principles of lawfulness, data minimisation, purpose limitation and storage limitation apply.

Depending on the feature, processing relies on Article 6(1)(b) GDPR (steps before entering into a contract at the user's request), Article 6(1)(f) GDPR (legitimate interests), or Article 6(1)(a) GDPR (consent). The details are set out below.

Providing form data and participating in the global leaderboard are voluntary. Without the contact and message data needed for a specific enquiry, it may not be possible to handle it meaningfully. Other website features do not depend on leaderboard participation.

3. Hosting and technical delivery

The website is delivered through Firebase App Hosting, a Google service running on Google Cloud infrastructure. Requests may involve processing connection data needed for delivery, security and diagnostics, in particular the IP address, request time, requested resource and browser information.

The application is built with Cloud Build, runs on Cloud Run and is delivered through Google Cloud Load Balancer with Cloud CDN enabled. The App Hosting backend's primary region is europe-west4 (Netherlands); uncached requests are served from that region, while Cloud CDN operates globally.

App Hosting makes Cloud Build build logs and Cloud Run and Cloud CDN runtime logs available in Cloud Logging. Their scope and retention depend on the Google Cloud services and the project's logging configuration. The europe-west4 region does not mean that all logs, build artefacts, CDN copies or other Firebase data are processed exclusively in the Netherlands.

The legal basis is Article 6(1)(f) GDPR: the legitimate interest in delivering a secure, stable and performant website.

Functional language preference

After a conscious language choice in the language switcher, the website may store the functional cookie kosmos-locale with one of the values pl, de or en for 12 months. Its only purpose is to restore that language when the site root is opened later. The cookie is not an analytics or tracking ID, contains no visitor or session identifier, and is independent of analytics consent. On a first visit without a stored choice, the Accept-Language header is used only for that request and the cookie is not written.

  • Firebase App Hosting architecture
  • Firebase App Hosting logs and metrics

4. Contact requests

The contact form and website request form send data to KOS-MOS's own server endpoint. After validation, the request is stored in the contactRequests collection in Cloud Firestore and is available only in the protected Admin Inbox.

Depending on the form, the data may include name, email address, message or project idea, topic or website type, locale, and optionally budget, currency and timeframe. The application deliberately does not store an IP address, User-Agent or attachments with the request.

For enquiries about possible services or collaboration, the legal basis is Article 6(1)(b) GDPR — pre-contractual steps taken at the data subject's request. Other general communication is processed under Article 6(1)(f) GDPR — the legitimate interest in receiving, organising and responding to incoming communication.

New requests receive a technical expiry time of 365 days. This is the project's retention period, not a statutory period. The automatic Firestore deletion policy has been configured; physical deletion after expiry may be technically delayed.

If the form backend is unavailable, the website may open a prepared email to the public KOS-MOS address. The website does not store an additional local copy of that draft; the user then sends it through their own email client and provider.

Emails sent to this public KOS-MOS address are technically processed through Cloudflare Email Routing and forwarded to a verified internal mailbox of the controller. The private destination address is not published. This service concerns only incoming email to the public address and is not the hosting of the KOS-MOS website, which is provided separately through Firebase App Hosting.

The public address available through this routing is: contact@karoldecyk.com

  • Cloudflare Email Routing documentation

5. Morfi Runner — global leaderboard

Voluntarily submitting a result stores playerName, score, gameVersion, locale, createdAt, status and optional runMeta in Cloud Firestore (technical run data such as distance, coins, coin bonus and build identifier). New scores do not receive an automatic expiry date. The application does not add an IP address, User-Agent, user ID, email address or device ID.

The public endpoint returns only the nickname (playerName), score, locale, game version and optionally the creation time. It does not publish the document ID, runMeta, status, legacy technical expiry fields or moderation information. A nickname may be personal data; the selected nickname and score can appear publicly in the ranking.

The legal basis is Article 6(1)(f) GDPR. The legitimate interest is operating and providing a public game ranking with a limited data set. Participation is voluntary and is not required for other parts of the website.

Global ranking entries are generally retained for as long as the Morfi Runner leaderboard is operated and the entry is needed for that purpose. The age of an entry does not by itself cause it to be hidden. An entry may be deleted individually, in particular following a valid request from the data subject.

Deletion of an entry can be requested. The nickname, score and approximate submission time may be needed to locate it. Identical nicknames can require additional details for an unambiguous match; there is no public self-service deletion API.

Requests about leaderboard entries can be sent to: contact@karoldecyk.com

6. Morfi Runner — local browser storage

Morfi Runner uses localStorage for game features. This is not an analytics or marketing system. The following keys are used:

  • kosmos-games-morfi-runner-highscores-v3 — local top-five leaderboard
  • kosmos-games-morfi-runner-player-name — remembered nickname
  • kosmos-games-morfi-runner-sound-v1 — remembered sound setting
  • kosmos-games-morfi-runner-preferences-consent-v1 — preference-memory decision

Local scores

The local top five is stored only in the browser for the expressly offered local leaderboard. It is not sent to KOS-MOS unless the user separately uses the global score submission flow. To the extent this storage is necessary for the requested local feature, the exception in Article 399(3)(2) of the Polish Electronic Communications Law (PKE) applies.

Nickname and sound

These convenience values are stored persistently only after “Remember my settings on this device” is enabled. Without opt-in they remain only in the current session. The choice can be disabled, which removes the persistent nickname, sound value and preference decision. The legal basis is consent under Article 399 PKE and — where the nickname is personal data — Article 6(1)(a) GDPR. The preference key is not a marketing or tracking cookie.

Deleting local data

“Delete local game data” removes local Runner data from that browser. It does not delete entries previously submitted to the global leaderboard.

7. Privacy-friendly usage analytics

KOS-MOS operates its own limited analytics solely to understand the use of pages and sections, their approximate visible time, broad traffic sources, device classes and selected features, and to improve the website on that basis. Analytics is not used for advertising, marketing, data sales, cross-site tracking or user profiling.

Processing begins only after explicit consent. The legal basis is Article 6(1)(a) GDPR and Article 399 PKE for access to device storage. Before a decision, and after choosing “Necessary only”, no tracker, session ID or request to /api/analytics is started.

Scope of measurement

After consent, sessions and views of allowed public routes, including legal pages, approximate visible seconds and entrances are counted. “Visible time” only means that the tab was visible; it does not establish attention or that content was read.

The traffic source is reduced to one of direct, internal, google, bing, instagram, facebook, github or other. Full referrer URLs, paths, query parameters, search terms and campaign/UTM parameters are not stored.

After analytics consent, the browser determines only a coarse device class (mobile, tablet, desktop or unknown) and transmits that class. The full User-Agent is not stored in the analytics system; browser, operating system, screen size, Client Hints and fingerprinting data are not collected.

Selected interactions are stored only as counters from a fixed list: a click on the MetaMORFS APK download, Morfi Runner game start, Morfi Runner game over, a successful Runner score submission, opening an Instagram reel in the local modal, actually loading an Instagram embed after a separate Instagram consent, opening a photography lightbox, a click on the Art contact, and a successful submission of the general contact form or a website enquiry. Closing a lightbox or gallery, changing images, playing local videos, merely opening a form, failed submissions and arbitrary external links are not counted. Form contents, nickname, score value, photo ID, reel ID, full destination URL and other event parameters are not stored.

Browser decision and session

The accepted or rejected decision and its time are stored for no more than approximately 6 months in localStorage under kosmos-analytics-consent-v1. The key contains no user or session identifier. If storage is unavailable, the decision applies only for the lifetime of the current document and is not persisted.

After consent, a random session UUID exists only in the RAM of the current tab. It is not put into cookies, localStorage, sessionStorage, daily aggregates or technical receipts; a reload or new tab creates a new approximate session.

Consent can be withdrawn through “Privacy settings”. Withdrawal immediately stops the RAM session, discards the unsent visible-time accumulator and performs no final flush. Instagram consent and the separate choice to remember Runner preferences are independent from analytics consent.

Aggregates, retention and infrastructure

Firestore stores only UTC daily aggregates: totals for sessions, page views and visible seconds, and maps for pages and entrances, locales, broad sources, device classes and selected interaction counts. No raw event history is created. Each day receives a deterministic expiresAt 24 months after its date; later updates do not extend that deadline.

For idempotency, a short-lived receipt contains only the schema version, consent version, receipt time, expiresAt and list of event types. It contains no session ID, route or interaction name and expires after 7 days. Physical Firestore deletion after expiresAt may be technically delayed.

Hosting infrastructure may technically process an IP address to deliver and secure a request, as explained in the hosting section. The application's analytics logic does not store an IP address, IP hash, geolocation or country.

8. Instagram content

The video gallery displays local posters. Neither loading the page nor merely opening the modal sends a request to Instagram. Only an explicit activation click loads instagram.com/embed.js and the official Instagram embed; consent is not stored persistently.

After activation, a direct connection to Instagram/Meta is established. Meta may then process, in particular, the IP address, browser and device information, connection information and other usage data described in its privacy policy.

The legal basis for loading the previously blocked content is consent under Article 6(1)(a) GDPR and Article 399 PKE where applicable. Without consent, the local poster remains visible and the embed is not loaded. Analytics consent does not load Instagram, and activating Instagram does not grant analytics consent.

  • Meta Privacy Policy

9. MetaMORFS, GitHub and external links

The MetaMORFS download buttons are ordinary links to the BlackzonePL/MetaMORFS-Releases repository on GitHub. No GitHub script, API or iframe is included when the KOS-MOS page loads. Only a click takes the user away from KOS-MOS and establishes a connection to GitHub.

Likewise, an ordinary link to an external website establishes a connection to that provider only after the link is activated, unless the content is expressly identified as embedded.

10. Administrative email notifications — Resend

After a request has been stored successfully, the server sends a minimal notification through Resend (Plus Five Five, Inc.) to the operator's internal address. It contains neutral text, the contact channel or source, an internal Firestore request ID, server timestamp, relative admin path and technical recipient address.

The notification sent to Resend does not contain the visitor's name, email address, message, project idea, budget or timeframe. Ireland (eu-west-1) is selected as the sending region, but this does not mean that all Resend data is stored exclusively in Ireland.

Resend states in its DPA that its primary processing operations take place in the United States. The DPA includes the Standard Contractual Clauses (SCCs) and the EU–US Data Privacy Framework as mechanisms relevant to international transfers.

Resend is used only for this outgoing minimal administrative notification. It does not process incoming messages to the public KOS-MOS address; that separate flow uses Cloudflare Email Routing.

  • Resend Data Processing Addendum

11. Firebase / Google

KOS-MOS uses Cloud Firestore, Cloud Storage and server-side Firebase Admin. Contact requests and Morfi Runner features pass through KOS-MOS's own Next.js API/server logic; visitors do not access Firestore directly through the Firebase Web SDK for these features. Photography files from Cloud Storage are also delivered through server-side logic.

Google/Firebase acts as a technical service provider and processor. The Cloud Firestore and Cloud Storage data locations have not been confirmed from the project settings and are not inferred from the App Hosting region. The same limitation applies to Firebase Authentication data and the global build, logging and CDN infrastructure.

Google's official terms provide for processing by Google and subprocessors at their infrastructure locations, subject to applicable data-location commitments, and safeguards for international transfers.

  • Firebase Privacy and Security
  • Firebase Data Processing and Security Terms

12. Retention periods

Contact requests have a project retention period of 365 days, and new records receive a server-generated expiresAt field. Analytics daily aggregates are retained for a fixed 24 months from their UTC day and minimal receipts for 7 days. Global scores have no automatic expiry date. They are retained while the Morfi Runner leaderboard is operated and for as long as they are needed to provide it, unless a particular entry is deleted sooner.

Local game data remains in the browser until the user deletes it, withdraws preference storage or clears the site's browser data. Other data is retained only for as long as required for its purpose or to establish, exercise or defend legal claims.

13. Recipients and international transfers

Data is accessible to the operator and — only to the necessary extent — Google/Firebase for Firebase App Hosting and the other Firebase services used, Resend, and Cloudflare Email Routing for messages sent to the public address as the technical forwarding service to the verified internal mailbox. Data is disclosed to public authorities only where required by applicable law.

Providers with infrastructure outside the European Economic Area may involve international transfers. The mechanisms in Chapter V GDPR and the relevant provider's official terms are used, particularly adequacy decisions or Standard Contractual Clauses where applicable.

14. Data subject rights

Within the limits of the GDPR, data subjects have rights of access and to a copy, rectification, erasure, restriction of processing and data portability where applicable. They may also object to processing based on Article 6(1)(f) GDPR.

Handling a request may require information needed to verify identity or locate the correct record. Please do not provide more data than is required for that purpose.

Privacy requests can be sent to: contact@karoldecyk.com

15. Withdrawal of consent

Where processing is based on consent, it can be withdrawn at any time with effect for the future. Withdrawal does not affect the lawfulness of processing before it. Analytics can be disabled through “Privacy settings”; remembering the nickname and sound in the game settings; Instagram content must be activated again after closing.

16. Right to object

For reasons relating to a particular situation, a person may object to processing based on Article 6(1)(f) GDPR. Processing will then stop unless compelling legitimate grounds override the person's rights and freedoms, or the data is needed to establish, exercise or defend legal claims.

17. Right to lodge a complaint

Anyone who believes that their data is being processed unlawfully may lodge a complaint with a data protection authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO). Another competent supervisory authority may also be contacted under Article 77 GDPR.

  • Official UODO website

18. No advertising trackers, profiling or automated decisions

KOS-MOS does not use external analytics or advertising trackers, Meta Pixel, Google Analytics or a general marketing tracking system. The only usage analytics is the limited, first-party aggregation described above, enabled after consent.

During normal use, visitor data is not sent to an AI service at runtime. There is no profiling and no automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR.

19. Changes to this privacy policy

This policy may be updated when website features, technical providers or legal requirements change. The current version and update date will be published on this page. Material new processing will be explained before it is introduced where required.

KOS-MOS · KAROL DECYK

ImprintPrivacyTerms