Privacy Policy

This Privacy Policy explains what personal data OmnidiaMarket collects, why we collect it, who we share it with, and the choices and rights you have. OmnidiaMarket is a free, play-money social prediction game — you predict real-world outcomes using virtual tokens that have no monetary value and cannot be cashed out.

Effective date: 25 June 2026 · Last updated: 25 June 2026

Virtual tokens only. No real money. No cash-out. Just bragging rights.

OmnidiaMarket is intended for users aged 18 and over.

Who we are

OmnidiaMarket is operated by Luka Zupanović, an individual based in Croatia. For the purposes of the EU General Data Protection Regulation (“GDPR”), we are the “data controller” for your personal data. You can reach us about privacy at abboscoinfinity@gmail.com. This policy applies to the OmnidiaMarket mobile apps and the services we provide through them (including our backend at api.omnidiamarkets.app).

Information we collect

We only collect what we need to run the game and keep it secure. There are three kinds: what you give us, what we collect automatically, and what we deliberately do not collect.

Information you give us

  • Account details: your email address, a password (which we store only as a secure Argon2id hash — we never see or keep your actual password), a username, and an optional display name.
  • Age confirmation: a record that you confirmed you are 18 or older. This is a simple timestamp — we do not ask for your date of birth.
  • Social sign-in (optional): if you choose “Continue with Google” or “Continue with Apple,” we receive a unique identifier for you from that provider, your email address (or Apple’s private-relay address if you choose to hide it), and whether the provider has verified your email. We never receive your Google or Apple password.
  • Content you create: prediction markets (their title, description, image, outcomes and dates), comments, community names and descriptions, your avatar choices, and the topics you tell us you’re interested in.
  • Images you upload, such as market or community pictures.
  • Messages you send us, for example when you contact support or make a privacy request.

Information we collect automatically

  • Security and session data: to keep you signed in and protect your account, we store a short device label hint (e.g. “iPhone”) and security references that we keep only as irreversible cryptographic hashes — including a hashed form of your IP address and app/browser user-agent, and hashed references to your sign-in sessions. We do not store your raw IP address, and we keep it out of our logs.
  • Device-integrity signals: a per-installation device hash and a platform integrity check (Apple App Attest or Google Play Integrity) used to prevent fraud and the creation of fake or duplicate accounts. These contain no contact information.
  • Push notification token: if you turn on notifications, we store the push token your device provides (Firebase Cloud Messaging on Android; Apple Push Notification service, via Firebase, on iOS) so we can alert you about your markets.
  • Your in-game wallet: your virtual-token balance and an append-only history of in-game token activity (such as trades, daily grants and market settlements). These tokens have no monetary value.
  • Crash diagnostics: if the app crashes, we receive a technical report (via Firebase Crashlytics) such as the error type and a stack trace, with sensitive fields removed.

What we do not collect

  • No advertising identifiers (we do not use Apple’s IDFA or Google’s Advertising ID).
  • No third-party analytics or tracking SDKs (no Google Analytics, Firebase Analytics, Amplitude, Mixpanel or similar).
  • No cookies or web tracking pixels — the apps sign you in with secure tokens, not cookies.
  • No precise location, contacts, health, biometric or other “special category” data.
  • We never sell your personal data, and we never share it for cross-context behavioural advertising.

How we use information

We use your data only for the purposes below. Under the GDPR we must have a “legal basis” for each use, shown in brackets.

  • To provide the game — create and secure your account, run markets and trading, show leaderboards, and display comments and content. (Legal basis: performance of our contract with you.)
  • To keep accounts and the platform safe — sign-in, rate limiting, fraud and abuse prevention, and device-integrity checks. (Legal basis: our legitimate interest in protecting users and the service; and legal obligation where it applies.)
  • To communicate with you about the service — for example password-reset and email-verification messages (sent through Resend), and push notifications you have switched on. (Legal basis: performance of our contract; and your consent for push notifications, which you can withdraw at any time in your device settings.)
  • To diagnose and fix problems — using crash and error reports. (Legal basis: our legitimate interest in providing a reliable app.)
  • To comply with the law and enforce our Terms. (Legal basis: legal obligation; and our legitimate interests.)

We do not use your data for behavioural advertising, and we do not make decisions about you by automated means that produce legal or similarly significant effects.

Cookies and analytics

The OmnidiaMarket apps do not use cookies and do not run any third-party analytics or advertising tools.

To keep you signed in, the apps store your sign-in tokens in your device’s secure storage (the iOS Keychain or Android’s encrypted preferences). This stays on your device.

The website that hosts this policy is a plain, static page: it sets no cookies, loads no third-party scripts, and runs no trackers.

How information is shared

We do not sell your personal data. We share limited data with trusted service providers (“processors”) who act only on our instructions and only to help us run OmnidiaMarket:

  • Railway — hosting and database; stores your account and game data.
  • Cloudflare — image storage (Cloudflare R2) for pictures you upload, plus network and security infrastructure.
  • Google Firebase — Cloud Messaging to deliver Android push notifications, and Crashlytics for crash reports. Push payloads carry only a device token and a notification type and IDs — not message bodies or personal content.
  • Apple Push Notification service (via Firebase) — to deliver iOS push notifications.
  • Resend — to send transactional emails (such as password reset and email verification) to your address. Email sending may be switched off during the beta.
  • Google and Apple — only if you use social sign-in, to authenticate you.
  • Apple App Store and Google Play — if you ever buy virtual tokens or cosmetic items, Apple or Google process the payment, not us. We receive a confirmation or receipt reference and never see your card details.

We may also disclose information:

  • to comply with the law, a court order, or a valid request from a public authority;
  • to protect the rights, property, safety and security of our users, the public, or OmnidiaMarket, and to investigate fraud or abuse; and
  • as part of a merger, acquisition, or sale of assets — in which case we will let you know, and any new owner will remain bound by this policy.

Data retention and security

How long we keep data

  • We keep your account data for as long as your account is active.
  • When you delete your account (see “Your rights and choices” below), we anonymise your account and remove personal identifiers such as your username and email, and we revoke your sign-in sessions.
  • To keep the game economy honest, some records — such as the append-only token ledger and trades — are kept in an anonymised form linked to a non-identifying reference rather than to your personal details.
  • Security tokens (sign-in sessions, password-reset and email-verification links) expire automatically and are then removed.
  • Backups are kept for a limited time and overwritten on a rolling basis.

How we protect data

  • Passwords are hashed with Argon2id; we never store them in plain text.
  • Sensitive identifiers (IP address, user-agent, tokens) are stored only as cryptographic hashes, and raw values are kept out of our logs.
  • Data is encrypted in transit using HTTPS/TLS, and sign-in tokens on your device are held in the platform’s secure store.
  • We use rate limiting, detection of re-used sign-in tokens, and device-integrity checks to defend accounts.
  • No online service can be 100% secure, but we work hard to protect your data and will notify you and the competent authority of a data breach where the law requires.

Your rights and choices

If you are in the EEA or UK (GDPR)

You have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased (the “right to be forgotten”);
  • restrict or object to certain processing, including processing based on our legitimate interests;
  • receive your data in a portable format; and
  • withdraw any consent you gave (for example, by turning off push notifications).

You also have the right to complain to your data protection authority. In Croatia this is the Personal Data Protection Agency (AZOP, azop.hr).

If you are in California (CCPA/CPRA)

You have the right to know what personal information we collect, to access and delete it, to correct it, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share your personal information as those terms are defined, and we do not use it for cross-context behavioural advertising. We will never discriminate against you for exercising your rights.

How to exercise your rights

You can delete your account at any time from inside the app (Settings → delete account), which anonymises your data and ends your sessions. For any other request, email abboscoinfinity@gmail.com. We will respond within the time the law requires (generally one month under the GDPR). We do not send marketing emails; the only emails we send are essential service messages, and push notifications are always optional.

Children and the 18+ requirement

OmnidiaMarket is intended for people aged 18 and over and is not directed at children. We ask you to confirm your age when you sign up, and we do not knowingly collect personal data from anyone under 18 (or under the digital-consent age in your country, which is 16 in Croatia).

If you believe a child has given us personal data, please contact abboscoinfinity@gmail.com and we will delete it. Parents and guardians may contact us at the same address.

International users

OmnidiaMarket is operated from Croatia in the European Union. Some of our service providers (such as Cloudflare, Google, Apple, Railway and Resend) may process data outside the European Economic Area, including in the United States.

When personal data leaves the EEA, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses or an adequacy decision — so that it stays protected. By using OmnidiaMarket you understand that your data is handled as described in this policy.

Changes to this policy

We may update this policy from time to time. When we do, we will change the “Last updated” date above. If a change is significant, we will give you notice in the app or by email before it takes effect. If you keep using OmnidiaMarket after a change, that means you accept the updated policy.

Contact

Data controller: Luka Zupanović (individual), Croatia, operating OmnidiaMarket.

Privacy contact: abboscoinfinity@gmail.com

If you are in the EU, you may also contact the Croatian Personal Data Protection Agency (AZOP) at azop.hr.