DEN
Privacy notice
This notice explains data processing on dunbarexplorernetwork.com and in the DEN Android and Windows apps.
Effective: 11 September 2026.
1. Data controller
Data controller: Szabolcs Pápai, founder of DEN
Email: info@dunbarexplorernetwork.com
Phone: +36 30 346 9269
Website: dunbarexplorernetwork.com
2. How the app works
The DEN app displays content from the DEN website over a secure HTTPS connection. No user account is required, and the app does not request access to location, camera, microphone, contacts or files on your device.
3. Technical data processed automatically
When the website or app is opened, hosting and security providers may process technical data needed for operation and abuse prevention. This may include the IP address, access time, address of the page opened, and basic technical characteristics of the browser and device.
The purposes are to serve the website, maintain security, identify errors and filter malicious traffic. The legal basis is the controller's legitimate interest in secure and reliable operation. Technical data may be retained only as long as necessary or for periods required by providers' security and legal obligations.
4. Data stored on the device
The app and website may cache some public pages and images for faster operation. DEN Library reading bookmarks, saved listening positions for each book and reading speed remain solely in local storage on the user's device and are not sent to the controller. They can be removed by clearing the app's or website's data.
Read-aloud uses the device's built-in speech synthesiser. It does not record audio or use the microphone, and sends no personal data to the synthesiser beyond the public book text to be read. The app installed from the Play Store downloads the current book text over encrypted HTTPS and may temporarily cache the last successfully loaded copy on the device.
Your chosen language is stored on your device for future visits. You can change it using the language selector, or remove the preference by clearing this website’s data.
When signed out, DEN Compass stores the family profile, favourites, current and separately saved itineraries, private journal, Pucky permissions, personal alert settings, personal cost estimates and private stops only in local storage on the device. The user can also save an offline snapshot of the current itinerary with a separate button; this snapshot may include private stops and the budget. These can be removed by clearing the website's data.
If an adult user voluntarily signs in with a Google or Facebook account, the selected provider performs authentication through Supabase Auth. DEN uses the technical account identifier to sync the Compass profile, favourites, itineraries, private journal, private stops, personal cost estimates, permissions and notification settings—including quiet hours and frequency—across devices. The email address and display name received at sign-in may be used to identify the account and show its signed-in state. The family profile may contain each child's age, interests, energy level and environmental sensitivity setting, but it does not ask for a child's name or contact details. My DEN lets users download saved data in a machine-readable format and directly delete Compass cloud data; signing out alone does not delete an earlier save. Additional access, correction or deletion requests may also be submitted by email to the controller.
When a family circle is created, its name, each participant's display name and the jointly edited current itinerary are stored. To prevent edit conflicts, versions of the shared itinerary, the editor's display name and the edit time are retained; the interface shows the twelve latest versions. An adult participant can vote yes, maybe or no on shared itinerary stops for themselves or on behalf of children listed in the profile; no child account or child name is needed. An invitation is a random, one-use link valid for no more than seven days; the system stores a one-way fingerprint instead of the invitation code. Family profiles, favourites, separately saved plans, private stops, personal cost estimates and journals are not shared with other family members and are not included in public itinerary links. When a family circle is dissolved, its shared plan history and votes are deleted; when a participant leaves, that participant's votes are removed.
The private journal may store the selected place or programme, visit date, optional rating and a note of up to 500 characters. These are not shown publicly. Every data category for future Pucky assistance is protected by a separate permission that is off by default. This system does not provide Pucky with the journal, precise location or sign-in data.
Sign-in is required for an ‘I visited today’ report. DEN processes the visit date, structured observations, optional short clarification and the submitter's internal account identifier to prevent misuse and carry out editorial review. Only approved, aggregated reports from the past 30 days are shown publicly; the submitter's identifier and free-text clarification are not public. Deletion of a report can be requested from the controller by e-mail.
The notification centre stores the identifier of the last notification read and the notification preference on that device. If a user chooses to enable system notifications, DEN processes the anonymous technical subscription endpoint, device-generated technical keys and chosen language needed for delivery. We do not ask for a name, email address or phone number for this.
Notifications can be turned off at any time in the notification centre. When they are turned off, the device subscription is deleted; persistently invalid delivery endpoints are also removed. Notification history contains public DEN messages and is not used to create a personal reading profile.
Compass's separate personal device notifications are optional and are created from the user's own itinerary, favourites, family profile and configured quiet hours. The identifier of a personal alert already shown is stored locally on that device to avoid repetition. The feature can be turned off; background delivery depends on support from the device and application.
5. Traffic and usage analytics
DEN uses its own first-party analytics system. Basic anonymous measurement records the opened DEN page path, event type, interface used—web, Android/PWA or Windows—selected language, referring website name and country code for aggregate statistics. We do not store full IP addresses, precise location, names, email addresses or advertising profiles in the DEN analytics database. Basic measurement is based on our legitimate interest in measuring and improving the service; you may object by contacting the controller.
With the visitor's separate permission, detailed anonymous analytics may also be collected. A random device and session identifier is used to measure return visits, active usage time, scroll depth, and usage events for book chapters, bookmarks, read-aloud, music, video, notifications and DEN Compass. Text entered in the Compass search field and the contents of form fields are not sent. Before storage, the server converts the random identifier into a one-way, non-reversible code. Detailed measurement is based on the visitor's consent, which can be withdrawn at any time without disadvantage.
Detailed measurement can be enabled or disabled at any time using the Privacy button at the bottom of the page. When disabled, local anonymous identifiers are deleted and no new detailed events are created. Raw basic events without personal identifiers and pseudonymous detailed events are retained for no more than 90 days; daily aggregates that cannot be linked to a person may be kept longer to compare DEN's development over time.
We retain your privacy choice on your device and in a necessary preference cookie valid for up to one year. This cookie contains only your chosen analytics mode, not a visitor identifier.
6. Ko-fi support records
Ko-fi may send DEN an automatic payment notification after successful support. DEN stores the message and transaction identifiers needed to remove duplicates, as well as the payment time, type, amount, currency and technical recurring-support flag. A supporter's name appears in the private owner area only when the support was marked public in Ko-fi. DEN Analytics does not store the email address or private message forwarded by Ko-fi.
Support data is processed to verify and summarise voluntary support received and to meet related financial or legal obligations. Ko-fi and the selected payment provider process data under their own privacy notices.
For direct DEN payments, Stripe handles card details; DEN does not receive or store them. From verified Stripe payment notifications we record the amount, currency, timestamp, transaction identifier and recurring-payment indicator. We use a short-lived signed token to verify payment confirmation. The Analytics Centre does not save names or email addresses from this payment flow.
7. Contact
If someone voluntarily contacts us by phone or email, we use the name, contact details and message they provide to answer the enquiry, discuss arrangements and prepare any collaboration. We do not sell this information or use it to create advertising profiles.
Contact information is retained until the matter is resolved or for as long as applicable legal obligations justify. Deletion can be requested at the controller's email address unless retention is legally required.
8. Creator, author and partner applications
For creator or author applications, we use contact details, introductions and information about the submitted work, magazine article, idea, review or video, its sources, publication rights and any sponsorship or other interests to assess the application and discuss possible collaboration. For partner applications, we also process introductions, proposed collaboration and related DEN areas, plus the supplied representative and contact details for organisations, institutions, communities or businesses, for the same purposes. Decisions always involve human review. Submission is voluntary and does not itself constitute acceptance or permission to publish.
A creator or author name, introduction, profile image and related links may be made public only with separate consent. A partner name, introduction, image, logo and public links may appear only after separate discussion and written approval of the final profile page. Internal email addresses or phone numbers provided for applications are not automatically published; public contact details require separate approval. Corrections to public information or removal of a profile or published content can be requested at the controller's email address.
Application information is retained until assessment and collaboration discussions conclude; for accepted collaborations, it is retained as needed to maintain the relationship or meet applicable legal obligations. Please do not submit identity documents, home addresses, tax identifiers, special-category data or children's personal information.
9. Children's data
The app is primarily intended for parents, guardians and adult readers. We do not ask children to create accounts or provide personal information directly. Arrangements involving a child's participation are always discussed with a parent or legal representative. Please share only strictly necessary information about children.
The adult user completes the Compass family profile. Ages, interests, energy levels and sensitivity settings entered for planning are not public and are not included in a shared itinerary. In family voting, a parent or guardian may vote under the child's profile number and age; the system does not request a child name or child account. Please do not enter a child's name, contact details, health data or other unnecessary personal information in the report's free-text field.
10. External websites and providers
Users can voluntarily open Facebook and Ko-fi from the app, or initiate a phone call or email. These actions are initiated by the user, and the external services' own privacy terms apply.
Compass uses Open-Meteo's Budapest forecast for weather information. When directions are opened, the selected starting point and destination are passed to Google Maps; the device's precise location is read only with separate browser permission and is not saved by DEN. When searching for a nearby toilet, drinking fountain, baby-changing facility, shaded rest area, food or parking, the selected venue address and requested service are passed to Google Maps. Opening the BudapestGO link leads to BKK's external service. Google's and Supabase's own privacy terms also apply to the optional Google sign-in process. If Facebook sign-in or account linking is selected, Meta's and Supabase's own privacy terms also apply.
Hosting, security, email and telecommunications providers may be used to operate the website. These providers may process data only to provide their services, on the controller's behalf or to meet their own legal obligations.
11. Data security
Traffic between the website and app is encrypted using HTTPS. The app contains no external advertising or advertising-oriented user tracking and does not sell personal information. Analytics and support data can be viewed only in a management interface protected by sign-in and separate owner authorisation.
12. Your rights
You may request information about the processing of your personal data, access, correction, deletion or restriction, and object to processing based on legitimate interests. Data portability may also be requested where applicable.
Requests can be sent to info@dunbarexplorernetwork.com . Complaints may also be submitted to the Hungarian National Authority for Data Protection and Freedom of Information: naih.hu.
13. Changes to this notice
This notice may be updated when operations or legal requirements change. The current version is available on this page, showing its effective date.
Transparent and secure operation
For privacy questions or deletion requests, write to info@dunbarexplorernetwork.com.
Back to home