Privacy Policy
Effective date: March 17, 2026 · Last updated: September 21, 2026
1. Introduction
Darkel LLC, doing business as Darkel Capital ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our mobile applications (the "Apps") available on the Apple App Store and Google Play Store. Please read this policy carefully. If you disagree with its terms, please discontinue use of our Apps.
2. Information We Collect
Information You Provide
- Account registration information (e.g., name, email address)
- Profile information you choose to provide
- Communications you send us (e.g., support requests)
Information Collected Automatically
- Device identifiers (e.g., device model, operating system version)
- App usage data and crash reports
- IP address and general location (country/region level only)
Information We Do Not Collect
We do not collect precise geolocation, payment card details, government IDs, biometric data, or contact lists unless explicitly stated within an individual app's in-app disclosure at the time of collection.
3. How We Use Your Information
We use collected information to:
- Provide, operate, and improve our Apps
- Respond to support requests and communicate with you
- Monitor and analyze usage trends to improve user experience
- Detect, prevent, and address technical issues or fraud
- Comply with applicable legal obligations
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data under the following legal bases:
- Contractual necessity — To provide you with the Apps and services you request (e.g., account registration, app functionality).
- Legitimate interest — To improve our Apps, detect fraud, ensure security, and analyze usage trends. We balance these interests against your rights and freedoms.
- Legal obligation — To comply with applicable laws and regulations.
- Consent — Where required, we obtain your consent before collecting or processing specific data (e.g., optional analytics). You may withdraw consent at any time.
5. Third-Party Services
Our Apps may use third-party services that collect information. These may include:
- Firebase (Google) — crash reporting and analytics
- Apple App Store / Google Play — app distribution and in-app purchases
Each third-party service has its own Privacy Policy governing its use of your information. We encourage you to review those policies.
6. Google User Data
Some of our Apps offer optional features that use your Google account — signing in with Google, and, where the App provides them, features that act on your own YouTube channel, Google Calendar, or Google Drive files. Each feature asks for your permission on Google's consent screen the moment you first use it, requests only the permissions that feature needs, and can be disconnected at any time.
Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms: Google user data is used only to provide the feature you turned on and that is visible to you in the App. It is not used for advertising, is not sold, is not transferred to anyone except as needed to run that feature or as required by law, and is not read by our staff except with your permission, for security, or to comply with law. We do not sell, rent, or share Google user data with data brokers or information resellers, and we do not use it to train generalized AI or machine-learning models.
Google user data is protected by the measures described under Security and Data Protection below — encryption in transit and at rest, row-level access control, and server-side custody of your refresh token, which never reaches your device.
Revoking access. You can disconnect a connected Google account inside the App (Settings → Connected Accounts → Disconnect), which revokes our authorization at Google and deletes the stored token immediately. You can also remove our access at myaccount.google.com/permissions; the corresponding stored token is deleted within 30 days.
Where an App uses YouTube API Services, your use of that feature is also governed by the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
7. Data Retention
We retain your information only as long as necessary to provide you with the App and fulfill the purposes outlined in this policy, or as required by law. You may delete your account and associated data at any time through the in-app account deletion feature (Settings → Account → Delete Account), or by emailing us at info@darkelcapital.com.
8. Children's Privacy
Our Apps are not directed to children under 13 years of age (or under 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately at info@darkelcapital.com and we will take steps to delete that information.
9. Your Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information
- Object to or restrict our processing of your data
- Data portability (receiving your data in a structured format)
To exercise any of these rights, contact us at info@darkelcapital.com.
10. Security and Data Protection
We use technical and organizational security measures to protect the confidentiality, integrity, and availability of your information. These measures apply to sensitive data and to all Google user data obtained through Google APIs, on the same terms as the rest of your data.
- Encryption in transit — Traffic between our Apps or websites and our servers, and between our servers and third-party APIs including Google's, is encrypted with HTTPS/TLS 1.2 or higher. Plain, unencrypted connections are redirected to HTTPS or refused.
- Encryption at rest — Data held in our managed database and in our file and media storage is encrypted at rest with AES-256 by the hosting platform, backups included.
- Protection on your device — Session and credential material cached on a device is kept in the operating system's protected keystore (Apple Keychain, Android Keystore) rather than in ordinary app files. You can turn on an app lock requiring biometrics or a PIN; PINs are salted and hashed with PBKDF2 and never stored in readable form, and the app covers its contents in the app switcher while locked.
- Access control and least privilege — Every table in our database enforces row-level security, so an authenticated request can only reach the records that account's role permits. Administrative access to production systems is limited to a small number of named, authorized people and is used to operate, secure, and support the service, not to browse customer content.
- Narrowest permissions — Each feature that uses a third-party API asks only for the permissions that feature needs, in its own separate consent. We do not bundle permissions, do not carry a permission granted for one feature into another, and do not request a broader permission where a narrower one exists.
- Server-side custody of third-party credentials — Your Google refresh token is never sent to your device and never stored in the app. It is held only on our server, in a store the public API cannot reach: direct access is revoked for every client role, row-level security admits the server alone, and the token can be read only by a single hardened server function through routines that re-check that the caller owns the connection. The app receives only a short-lived access token, valid about one hour, limited to the scopes of the one feature invoked. The Google OAuth client secret exists only in that function's server environment and is not present in any published app binary or web bundle.
- Separation from advertising and analytics — Google user data is kept apart from our advertising and analytics systems. It is never shared with advertising partners, data brokers, or information resellers, and it is not used to develop, improve, or train generalized artificial-intelligence or machine-learning models.
- Deletion and revocation — Disconnecting a Google account revokes our authorization at Google and deletes the stored token immediately; a token you revoke from your Google account instead is deleted within 30 days.
- Monitoring and incident response — Access to production systems is logged and monitored, and platform and dependency security updates are kept current. See Data Breach Notification below.
No method of transmission over the internet or of electronic storage is 100% secure, and we cannot guarantee absolute security. If you believe you have found a security problem in one of our Apps, write to info@darkelcapital.com and we will respond.
11. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR. If the breach is likely to result in a high risk to you, we will also notify affected users without undue delay via email or in-app notification.
12. Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:
- Right to Know — You may request details about the categories and specific pieces of personal information we have collected about you in the prior 12 months.
- Right to Delete — You may request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out — You have the right to opt out of the sale or sharing of your personal information.
- Right to Non-Discrimination — We will not discriminate against you for exercising your privacy rights.
We do not sell or share your personal information as defined under the CCPA/CPRA. We do not use sensitive personal information for purposes other than those permitted by the CCPA/CPRA.
To exercise any of these rights, contact us at info@darkelcapital.com. We will respond within 45 days.
13. International Data Transfers
Our Apps use third-party services (such as Firebase) that may process data in the United States and other countries. If you are located outside the United States, your information may be transferred to and processed in the US, where data protection laws may differ from those in your country. By using our Apps, you consent to this transfer. We rely on standard contractual clauses and other lawful transfer mechanisms to protect your data during international transfers.
14. Cookies and Tracking Technologies
Our website (darkelcapital.com) does not use cookies, tracking pixels, analytics tools, or third-party resources. All fonts and stylesheets are self-hosted — no data is transmitted to external servers when you visit our website. Our mobile Apps may use Firebase Analytics, which collects device identifiers including Advertising ID (IDFA on iOS, GAID on Android), Firebase Installation ID, and Analytics App Instance ID for crash reporting and usage analytics.
Do Not Track Signals
Our website does not track visitors and therefore does not respond to "Do Not Track" (DNT) browser signals, as there is no tracking to disable. Our mobile Apps respect device-level privacy settings, including Apple's App Tracking Transparency (ATT) framework and Google's advertising ID controls.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will update both the "Effective date" and "Last updated" date at the top of this page. Material changes will take effect 30 days after posting. Continued use of our Apps after the effective date constitutes acceptance of the updated policy.
16. Data Protection Officer and EU Representative
Darkel LLC, doing business as Darkel Capital, is based in the United States and does not have an establishment in the European Union. As a US-based company, we are not required to appoint a Data Protection Officer (DPO) or EU representative under GDPR. However, we take your privacy seriously and will respond to all data protection inquiries. If you have GDPR-related concerns, contact us at the address below.
17. Contact Us
If you have questions or concerns about this Privacy Policy, please contact us:
Darkel LLC d/b/a Darkel Capital
5900 Balcones Dr Suite 100
Austin, TX 78731, USA
Email: info@darkelcapital.com
Website: darkelcapital.com