GazeStudy
← Back to GazeStudy

Privacy policy

Your data, explained

Effective 8 September 2026. Policy 20260908-magura-30d-3. This policy covers the GazeStudy iPhone app, its capture service, and gazestudy.com.

1. Who is responsible

Magura Digital OÜ is the controller of personal data processed for GazeStudy. Estonian registry code: 16981402. Registered address: Harju maakond, Tallinn, Kesklinna linnaosa, Jõe tn 3-303, 10151. For privacy questions and rights requests, contact artur.zhdan@gptinf.com. GazeStudy is a project of this company, not a university or medical provider.

2. What we collect

  • Camera images: front-camera JPEG frames containing your face, eyes, and potentially your surroundings. These are identifiable images, not anonymous data. The app does not need access to your photo library.
  • Study records: target and text positions, task responses such as readiness, frame associations, phase completion, interruption and recovery events, and consent version and time.
  • Device and capture data: iPhone model identifier, OS and app version, camera format, image dimensions, display layout and device geometry estimates, camera intrinsics when available, face/eye landmarks and quality flags, relative capture/display timestamps, camera exposure and ISO settings, display brightness setting, battery and thermal state, and upload/performance diagnostics. Brightness is a device setting, not a measurement of room illumination.
  • Optional depth: when you separately opt in and supported hardware is available, front-camera depth maps aligned in time with selected camera images, plus camera calibration and depth-quality information. These distance measurements can describe the shape and position of your face and surroundings. They are linked to your identifiable camera images.
  • Optional motion: when you separately opt in, device attitude, gravity, rotation rate, and acceleration with relative timestamps during study capture. These describe phone movement; we do not use them to determine your location.
  • Identifiers: your participant code, random session and process identifiers, and access capabilities used to recover and protect uploads. These records can be linked to your images. Do not put your name or email address in the participant-code field.
  • Support: your email address, message, and information you choose to provide when you contact us.
  • Service operation: Cloudflare processes connection information such as IP addresses, requested URLs, and request/security events to deliver and protect the website and API.
The native study does not request microphone recordings, GPS location, contacts, advertising identifiers, HealthKit data, Face ID templates, ARKit face meshes, or ARKit gaze estimates. Depth and motion are separate optional choices, each off by default; the main study remains available when you decline either. Older app versions may not offer these optional measurements. Camera permission does not by itself mean that every preview frame is saved or uploaded.

3. Why we use it

We use study recordings to develop, test, and evaluate gaze-estimation methods, including research models, and to investigate capture quality and failures. Optional depth helps study viewing distance and camera geometry; optional motion helps study phone movement and its relationship to image quality and gaze-estimation errors. Face and eye analysis supports this research; it is not used to identify or authenticate people or create an identity database. We use support information to answer questions and handle rights requests, and service information to provide secure, reliable operation. We do not sell personal data, use it for advertising, or track you across other companies’ apps or websites. There are no advertising or analytics SDKs in the active native capture flow.

4. Consent and other legal bases

We rely on your consent for voluntary study collection and research use. The app asks you to confirm that you are 18 or older and agree to the disclosed study before camera access and collection. Depth and motion each have a separate choice, off by default; camera permission alone does not authorise those optional collections. You can change these choices before a new recording and participate with both disabled. You can withdraw consent through the app or by contacting us. Withdrawal does not change the lawfulness of processing carried out before withdrawal. We rely on legitimate interests in secure service operation and responding to enquiries for necessary security and support processing, and on legal obligations where we must retain or disclose information by law. We do not use this study to make decisions that have legal or similarly significant effects on you.

5. Who can access it

Access is restricted to people authorised by Magura Digital OÜ who need it for the study or support. Cloudflare provides website/API hosting and private object storage and processes data to operate those services. Our email service processes correspondence you send to the published company email address. Apple may process App Store, device-permission, or distribution information under its own policies. We do not publish participant images or give recordings to external research teams, advertisers, or AI services for their independent use. We may disclose information if legally required. A new use or external release requiring consent will not be introduced silently under this policy.

6. Where processing occurs

The company is established in Estonia. Cloudflare operates globally, so processing can occur outside Estonia and the European Economic Area; the service is not configured as an EU-only storage service. Cloudflare describes its processor obligations and international-transfer safeguards, including applicable standard contractual clauses, in its Data Processing Addendum. Contact us for information about safeguards applicable to your data. We do not claim that a European company address means every copy is stored in Europe.

7. Retention

  • Server recordings: camera images, optional depth and motion, manifests, session metadata, outcomes, and upload receipts expire 30 days after session creation. An hourly cleanup job removes expired recordings; our target is removal within the following hour.
  • Withdrawal: an accepted in-app request blocks further normal upload and export immediately. The hourly job removes the server recording. Acknowledgement means the request was accepted, not that physical cleanup has already finished.
  • Local files: recordings remain in the app’s private storage until you remove them using the app or uninstall it. Local study folders are excluded from the app’s normal device-backup flow. Deleting the app alone does not send a server deletion request.
  • Withdrawal markers: small opaque session identifiers, withdrawal status and times, and one-way access-key hashes can remain after deletion to prevent an interrupted upload from recreating a withdrawn session. They do not contain your camera images or study measurements.
  • Support: we keep correspondence only for as long as needed to resolve it and meet applicable obligations; you may ask us to delete it.
  • Operational logs: limited request and security logs are separate from study recordings and follow the hosting provider’s applicable retention settings. They are not a research dataset.
Any identifiable research working copies remain subject to the same study retention and withdrawal requirements. We may retain aggregate results that no longer identify you. We do not promise that published non-identifying aggregate findings can be removed retroactively.

8. Your rights and how to withdraw

You may request access, correction, erasure, restriction or portability where applicable, object to processing based on legitimate interests, and withdraw study consent. Use Request deletion in the app or email artur.zhdan@gptinf.com. Include the participant code or session ID if available, but never email the app’s access token, identity documents, or face images unless we explain a necessary secure verification process. We may ask for proportionate information to locate and verify the request. A code alone may not prove ownership. If we cannot identify your record, we will explain the limitation. We normally respond within one month, subject to extensions permitted by law. You may complain to Estonia’s Data Protection Inspectorate (Andmekaitse Inspektsioon) or the supervisory authority where you live or work.

9. Security

The app connects over HTTPS. Recordings use private object storage, session-specific access capabilities, and restricted administrator access. Integrity hashes and receipts help detect incomplete or changed uploads; they do not make images anonymous. Local files use iOS data-protection facilities. No transmission or storage system can be guaranteed completely secure.

10. Website cookies and external links

This website does not set analytics or advertising cookies, load third-party fonts, or embed tracking pixels. The website never requests camera or microphone access. Cloudflare still processes technical connection information necessary to serve and protect it and may apply essential security mechanisms. Following an external link or sending email involves that provider’s own data practices.

11. Children and policy changes

The study is for adults aged 18 or older. Do not participate or send a child’s recording. Contact us if you believe a child’s information was submitted so we can investigate and remove it. We publish a date and policy version when this policy changes. The app records the consent version associated with each session; material changes to study collection or use require an updated disclosure and consent.

This version is also available at /privacy/2026-09-08-v3. Previous policy: 8 September 2026, version 2.