प्राइवेसी पॉलिसी
हम कम इकट्ठा करते हैं। जो इकट्ठा करते हैं — और ख़ासकर आपके बारे में जो सार्वजनिक है — वह यहाँ साफ़-साफ़ लिखा है।
आख़िरी अपडेट: 2026-09-05
यह दस्तावेज़ इतालवी और अंग्रेज़ी में लिखा गया है, और वही संस्करण मान्य हैं। यहाँ आप अंग्रेज़ी संस्करण पढ़ रहे हैं। Italiano · English
1Controller
The data controller is GPR di Giovanni Pio Rizzi, a sole trader based in Italy, VAT IT04595240716.
For anything about your data write to [email protected] or [email protected]. We answer within a month, as the GDPR requires.
2What we collect
Little, and for a reason that is about the product rather than about privacy: the game is the leaderboard, and a leaderboard needs a name and a total.
- E-mail — to create the account, sign in, and send service messages.
- Display name, bio and profile picture — whatever you choose, and it is public.
- Location — country, region, province and city, to place you on the geographic boards. Normally you pick them from a list. If instead you tap "Use my location" — and only then, after the system has asked your permission — the app reads the device's location and turns it into a place name to fill the fields for you. The coordinates never reach us and we store none of them: only the country, region, province and city names arrive at our server. You can skip that button and type everything by hand.
- Purchase amounts and history — how much and when, plus the payment provider's transaction id.
- Messages — what you write in group chats and direct messages.
- Profile visits — a count, plus the (profile, visitor) pair needed to count unique visitors. See section 4.
- Notification tokens — if you turn push notifications on.
We do not collect your card details and we store no GPS coordinates, and we use no third-party advertising or analytics SDKs.
3What is public
This is the part to read carefully, because it is the product and not a side effect.
Leaderboard information is public and readable without an account: anyone, registered or not, can see — and copy — the display name, picture, bio, country, city, amount spent, rank and join date of the top thousand.
You have two switches, and both work:
- Hide the amount — your row stops showing the figure, to everyone.
- Hide the country — your row stops showing the flag. Note: this is cosmetic, it does not remove you from your country's board.
The rest — name, picture, bio — is public by definition. If you do not want something public, do not put it there.
4Who visited your profile
We say this because the data exists and nobody expects it to.
To count the unique visitors to a profile we have to keep one row per (profile, visitor) pair. That means the database holds the information about who looked at whose profile.
It is never shown to anyone: no screen and no app request returns visitor identities. Only the number comes out. But the data exists, and whoever has database access — that is, us — could reconstruct it. We would rather tell you.
5Direct messages are not end-to-end encrypted by default
Messages travel over an encrypted connection and the database is protected, but by default they are not end-to-end encrypted: on our server the text is readable.
End-to-end encryption is available per conversation and is not the default. When it is on, the text is encrypted on your device and the server cannot read it — and the app refuses to send in the clear if the other person's key is unavailable, rather than silently falling back. We do not turn it on for everyone and call it done, because encryption alone would not be enough here: the other person's public key comes from our server with no fingerprint verification, so a compromised server could substitute it. Saying "your messages are encrypted" without that sentence would be the worst kind of reassurance.
Act accordingly: direct messages are private, not secret.
6Why we process it (legal basis)
| Data | Why | Legal basis |
|---|---|---|
| E-mail, password | The account exists, sign-in, security | Performance of a contract (art. 6.1.b) |
| Name, bio, picture, location | The leaderboard and the public profile | Performance of a contract |
| Payments | Delivering the service and keeping accounts | Contract + legal obligation (art. 6.1.c) |
| Messages | Delivering them | Performance of a contract |
| Security logs | Preventing abuse and fraud, proving what happened | Legitimate interest (art. 6.1.f) |
| Consumption data to Apple | Answering a refund request | Consent (art. 6.1.a) |
7Who we share it with
We never sell data to anyone. We share it only with the providers we need to run the service, each for their own part and under a processor agreement:
| Who | What | Where |
|---|---|---|
| Stripe | Payments on the web (card details live with them, not with us) | US / EU |
| Apple | In-app purchases and, with your consent, the consumption data in section 8 | US / EU |
| Hetzner | The servers and the database | Germany |
| Cloudflare | Protection and delivery, edge logs | EU / global |
| Backblaze | Backups, encrypted before they leave | EU |
| Resend | Service e-mail (codes, notices) | US / EU |
Transfers outside the European Union rely on the Commission's Standard Contractual Clauses or on an adequacy decision.
8Consumption data sent to Apple
This section concerns only people who buy in the iPhone app and ask Apple for a refund of a purchase.
When you request a refund, Apple notifies us and gives us twelve hours to say what we had delivered to you. Apple uses the answer to inform its refund decision.
We ask you first. At the moment you request the refund, the app asks whether you consent to this being sent. It is explicit consent, freely given and revocable: refusing does not cost you the refund, the decision stays entirely Apple's. If you do not consent we send nothing at all — not even a negative answer — and stay silent, exactly as Apple instructs.
If you consent, five values and nothing else leave, about that single purchase:
| Field | What it says | Where it comes from |
|---|---|---|
| customerConsented | that you consented | your answer, recorded with a timestamp |
| deliveryStatus | whether the position had been granted to you | the delivery record |
| consumptionPercentage | 100% if delivered, 0% if not | a position is granted all at once |
| sampleContentProvided | that before paying we showed you what you were buying | the purchase screen shows the projection |
| refundPreference | omitted — we express no preference | — |
No personal details leave. No name, no e-mail, no account age, no lifetime spend, no count of previous refunds. The version of Apple's interface that asked for those has been superseded: the one we use has no field to put them in.
9How long we keep it
| Data | How long | Why |
|---|---|---|
| Account and profile | While the account is active | — |
| Deleted account | 6 months, then irreversible anonymisation | A window to change your mind: just sign in again |
| Payments | 10 years | Legal obligation (art. 2220 Italian Civil Code) |
| Messages | Deleted at anonymisation | — |
| Support requests | Kept, with the e-mail replaced | They are very often about the deletion itself |
| Security and administrative logs | As long as they are needed to prove what happened on an account | Legitimate interest. We have no scheduled automatic deletion today, and we would rather say so than publish a deadline we do not keep |
10Your rights
You can ask us at any time to access your data, correct it, delete it, restrict its processing, take it elsewhere, or object to processing based on legitimate interest. Where we rely on consent, you can withdraw it whenever you want.
Write to [email protected] from the account's address, or use the support form. We answer within a month.
There is no "download my data" button yet: we handle the request by hand, and the answer still comes within a month.
If you think we are handling your data wrongly you can complain to the Italian data protection authority, the Garante per la protezione dei dati personali (gpdp.it), or to the authority where you live.
11Cookies
On this site and in the web app we use no profiling, analytics or advertising cookies, and there is no third-party tracker. That is why there is no banner: there would be nothing to ask you to accept.
We use only what keeps you signed in: your session token, stored in your browser on your device. It is technically necessary and needs no consent. The one actual cookie is the administrative session one, and it concerns only us.
12Security
How we protect all of this is written out, measure by measure, on the security page — with the list of what we do not promise beside the list of what we do.
13Minors
The service is for adults. We do not knowingly collect data from anyone under 18; if we learn we have, we delete the account and the data.
14Changes
If we change this policy we update the date at the top and, for substantial changes, tell you in the service. Previous versions can be requested at [email protected].