Agorion
Privacy Policy
Your privacy matters to us. This policy explains what information Agorion collects, why we collect it, and how we protect it.
Information We Collect
- Account details such as your name, email address, profile photo, and subscription tier.
- Authentication provider details (Apple Sign In or Google Sign-In account identifiers/profile information) when you choose social sign-in.
- Content you create or upload, including skills, media files, trade listings, chat messages, and ratings.
- Skill terms you publish or request, such as exchange-only, exchange-or-payment, payment-only, listed lesson rates, and whether a skill is self-paced in app, a live lesson, or both.
- Location coordinates when you create marketplace listings (used for distance-based search). Only city-level location is shown publicly.
- Location data shared in chat messages (if you choose to share your location).
- Biometric login preferences (Face ID/Touch ID). Biometric data stays on your device; we do not store your biometric data.
- Usage analytics, device metadata (model / OS version), push notification tokens, diagnostics, and crash logs.
How We Use Information
- To deliver and personalize core product features, including skill sharing, marketplace listings, and exchange matchmaking.
- To power skill listings that may be exchange-only, exchange-or-payment, or payment-only, and to support lesson request communication between users.
- To process your content through AI services (OpenAI) for features like skill generation, profile optimization, and content suggestions.
- To track referrals and grant trial rewards when referred users accept their first exchange.
- To enforce community guidelines, secure the platform, and prevent abuse through automated and manual review.
- To monitor service health, analyze feature adoption, and improve product quality.
- To send push notifications about messages, exchange requests, and important updates.
- To communicate transactional notices and support responses.
AI Processing
- Certain features send your content to OpenAI for processing, including skill descriptions, profile text, and chat suggestions.
- AI requests are routed through our secure server proxy to protect API keys and enforce usage limits.
- AI-generated content is provided as suggestions; you control what gets published.
- Content may be automatically reviewed by AI for community guideline compliance.
Content Visibility & Sharing
- Your skills, trade listings, profile name, photo, ratings, and Skill Trading Card are visible to other users.
- In-app messaging is primarily tied to skills, listings, exchange/trade interactions, and related profile interactions rather than a general-purpose username directory messaging feature.
- Plus subscribers can view your full skill content (up to 3 skills per month) without completing an exchange with you.
- Skill listings may include exchange-only, exchange-or-payment, or payment-only lesson terms, along with listed rates and whether the skill is self-paced in app, a live lesson, or both.
- Paid lesson requests are communication flows between users. Agorion does not process, guarantee, insure, or mediate off-app payments.
- Skill Trading Cards can be shared publicly via links (agorion.app/card/... ).
- Trade item locations are displayed at city level publicly; precise coordinates are used only for distance calculations.
- Referral links (agorion.app/join/...) contain your referral code but no personal information.
- Completion certificates display your name and the skill completed.
Data Storage & Security
- Data is hosted on Supabase with industry-standard encryption at rest and in transit.
- Biometric data never leaves your device; it uses Apple's secure enclave.
- Access to production data is limited to authorized personnel with role-based permissions and audit logging.
- We retain personal data only as long as needed to provide the service or comply with legal obligations.
Third-Party Services
- Google Sign-In / Google Identity Services for optional Google account authentication.
- Firebase Analytics, Crashlytics, and Cloud Messaging (FCM) for analytics, crash reporting, and push notifications.
- OpenAI for AI-powered features (skill generation, suggestions, content moderation).
- Apple for payments (StoreKit) and local push notifications.
- Supabase for authentication, database, file storage, and real-time messaging infrastructure.
- Cloudflare Workers for serving public landing pages (referral links, app association files).
- These providers process data under their own privacy policies; we share only the minimum information required.
Your Choices
- You can update account information or delete content directly in the app.
- Location sharing for listings is optional; you can skip adding location.
- Biometric login can be enabled or disabled in settings.
- Push notifications can be managed in iOS Settings.
- Contact support@agorion.app to request data export or full account deletion.
Children's Privacy
Agorion is not directed to children under 13. If we learn that a child has provided personal data, we will delete it promptly.
Updates & Contact
- We may revise this policy periodically. Updated versions will be posted in-app with a new effective date.
- Continued use after changes indicates acceptance of the updated policy.
- For questions or concerns email privacy@agorion.app.