1. Who is responsible
Magura Digital OÜ is the controller of personal data processed for GazeStudy. Estonian registry code: 16981402. Registered address: Harju maakond, Tallinn, Kesklinna linnaosa, Jõe tn 3-303, 10151. For privacy questions and rights requests, contact artur.zhdan@gptinf.com. GazeStudy is a project of this company, not a university or medical provider.
2. What we collect
- Camera images: front-camera JPEG frames containing your face, eyes, and potentially your surroundings. These are identifiable images, not anonymous data. The app does not need access to your photo library.
- Study records: target and text positions, task responses such as readiness, frame associations, phase completion, interruption and recovery events, and consent version and time.
- Device and capture data: iPhone model identifier, OS version, camera format, image dimensions, display layout, camera intrinsics when available, face/eye landmarks and quality flags, timestamps and upload/performance diagnostics.
- Identifiers: your participant code, random session and process identifiers, and access capabilities used to recover and protect uploads. These records can be linked to your images. Do not put your name or email address in the participant-code field.
- Support: your email address, message, and information you choose to provide when you contact us.
- Service operation: Cloudflare processes connection information such as IP addresses, requested URLs, and request/security events to deliver and protect the website and API.
3. Why we use it
We use study recordings to develop, test, and evaluate gaze-estimation methods, including research models, and to investigate capture quality and failures. Face and eye analysis supports this research; it is not used to identify or authenticate people or create an identity database. We use support information to answer questions and handle rights requests, and service information to provide secure, reliable operation. We do not sell personal data, use it for advertising, or track you across other companies’ apps or websites. There are no advertising or analytics SDKs in the active native capture flow.
4. Consent and other legal bases
We rely on your consent for voluntary study collection and research use. The app asks you to confirm that you are 18 or older and agree to the disclosed study before camera access and collection. You can withdraw consent through the app or by contacting us. Withdrawal does not change the lawfulness of processing carried out before withdrawal. We rely on legitimate interests in secure service operation and responding to enquiries for necessary security and support processing, and on legal obligations where we must retain or disclose information by law. We do not use this study to make decisions that have legal or similarly significant effects on you.
5. Who can access it
Access is restricted to people authorised by Magura Digital OÜ who need it for the study or support. Cloudflare provides website/API hosting and private object storage and processes data to operate those services. Our email service processes correspondence you send to the published company email address. Apple may process App Store, device-permission, or distribution information under its own policies. We do not publish participant images or give recordings to external research teams, advertisers, or AI services for their independent use. We may disclose information if legally required. A new use or external release requiring consent will not be introduced silently under this policy.
6. Where processing occurs
The company is established in Estonia. Cloudflare operates globally, so processing can occur outside Estonia and the European Economic Area; the service is not configured as an EU-only storage service. Cloudflare describes its processor obligations and international-transfer safeguards, including applicable standard contractual clauses, in its Data Processing Addendum. Contact us for information about safeguards applicable to your data. We do not claim that a European company address means every copy is stored in Europe.
7. Retention
- Server recordings: camera images, manifests, session metadata, outcomes, and upload receipts expire 30 days after session creation. An hourly cleanup job removes expired recordings; our target is removal within the following hour.
- Withdrawal: an accepted in-app request blocks further normal upload and export immediately. The hourly job removes the server recording. Acknowledgement means the request was accepted, not that physical cleanup has already finished.
- Local files: recordings remain in the app’s private storage until you remove them using the app or uninstall it. Local study folders are excluded from the app’s normal device-backup flow. Deleting the app alone does not send a server deletion request.
- Withdrawal markers: small opaque session identifiers, withdrawal status and times, and one-way access-key hashes can remain after deletion to prevent an interrupted upload from recreating a withdrawn session. They do not contain your camera images or study measurements.
- Support: we keep correspondence only for as long as needed to resolve it and meet applicable obligations; you may ask us to delete it.
- Operational logs: limited request and security logs are separate from study recordings and follow the hosting provider’s applicable retention settings. They are not a research dataset.
8. Your rights and how to withdraw
You may request access, correction, erasure, restriction or portability where applicable, object to processing based on legitimate interests, and withdraw study consent. Use Request deletion in the app or email artur.zhdan@gptinf.com. Include the participant code or session ID if available, but never email the app’s access token, identity documents, or face images unless we explain a necessary secure verification process. We may ask for proportionate information to locate and verify the request. A code alone may not prove ownership. If we cannot identify your record, we will explain the limitation. We normally respond within one month, subject to extensions permitted by law. You may complain to Estonia’s Data Protection Inspectorate (Andmekaitse Inspektsioon) or the supervisory authority where you live or work.
9. Security
The app connects over HTTPS. Recordings use private object storage, session-specific access capabilities, and restricted administrator access. Integrity hashes and receipts help detect incomplete or changed uploads; they do not make images anonymous. Local files use iOS data-protection facilities. No transmission or storage system can be guaranteed completely secure.
10. Website cookies and external links
This website does not set analytics or advertising cookies, load third-party fonts, or embed tracking pixels. The website never requests camera or microphone access. Cloudflare still processes technical connection information necessary to serve and protect it and may apply essential security mechanisms. Following an external link or sending email involves that provider’s own data practices.
11. Children and policy changes
The study is for adults aged 18 or older. Do not participate or send a child’s recording. Contact us if you believe a child’s information was submitted so we can investigate and remove it. We publish a date and policy version when this policy changes. The app records the consent version associated with each session; material changes to study collection or use require an updated disclosure and consent.
This version is also available at /privacy/2026-09-08.