Gizlilik Politikası

Az veri toplarız. Topladıklarımız — ve özellikle senin hakkında herkese açık olanlar — burada dolandırmadan yazılı.

Son güncelleme: 2026-09-05

Bu belge İtalyanca ve İngilizce yazılmıştır ve geçerli olan bu sürümlerdir. Burada İngilizcesini okuyorsun. Italiano · English

1Controller

The data controller is GPR di Giovanni Pio Rizzi, a sole trader based in Italy, VAT IT04595240716.

For anything about your data write to [email protected] or [email protected]. We answer within a month, as the GDPR requires.

2What we collect

Little, and for a reason that is about the product rather than about privacy: the game is the leaderboard, and a leaderboard needs a name and a total.

We do not collect your card details and we store no GPS coordinates, and we use no third-party advertising or analytics SDKs.

3What is public

This is the part to read carefully, because it is the product and not a side effect.

Leaderboard information is public and readable without an account: anyone, registered or not, can see — and copy — the display name, picture, bio, country, city, amount spent, rank and join date of the top thousand.

You have two switches, and both work:

The rest — name, picture, bio — is public by definition. If you do not want something public, do not put it there.

4Who visited your profile

We say this because the data exists and nobody expects it to.

To count the unique visitors to a profile we have to keep one row per (profile, visitor) pair. That means the database holds the information about who looked at whose profile.

It is never shown to anyone: no screen and no app request returns visitor identities. Only the number comes out. But the data exists, and whoever has database access — that is, us — could reconstruct it. We would rather tell you.

5Direct messages are not end-to-end encrypted by default

Messages travel over an encrypted connection and the database is protected, but by default they are not end-to-end encrypted: on our server the text is readable.

End-to-end encryption is available per conversation and is not the default. When it is on, the text is encrypted on your device and the server cannot read it — and the app refuses to send in the clear if the other person's key is unavailable, rather than silently falling back. We do not turn it on for everyone and call it done, because encryption alone would not be enough here: the other person's public key comes from our server with no fingerprint verification, so a compromised server could substitute it. Saying "your messages are encrypted" without that sentence would be the worst kind of reassurance.

Act accordingly: direct messages are private, not secret.

6Why we process it (legal basis)

DataWhyLegal basis
E-mail, passwordThe account exists, sign-in, securityPerformance of a contract (art. 6.1.b)
Name, bio, picture, locationThe leaderboard and the public profilePerformance of a contract
PaymentsDelivering the service and keeping accountsContract + legal obligation (art. 6.1.c)
MessagesDelivering themPerformance of a contract
Security logsPreventing abuse and fraud, proving what happenedLegitimate interest (art. 6.1.f)
Consumption data to AppleAnswering a refund requestConsent (art. 6.1.a)

7Who we share it with

We never sell data to anyone. We share it only with the providers we need to run the service, each for their own part and under a processor agreement:

WhoWhatWhere
StripePayments on the web (card details live with them, not with us)US / EU
AppleIn-app purchases and, with your consent, the consumption data in section 8US / EU
HetznerThe servers and the databaseGermany
CloudflareProtection and delivery, edge logsEU / global
BackblazeBackups, encrypted before they leaveEU
ResendService e-mail (codes, notices)US / EU

Transfers outside the European Union rely on the Commission's Standard Contractual Clauses or on an adequacy decision.

8Consumption data sent to Apple

This section concerns only people who buy in the iPhone app and ask Apple for a refund of a purchase.

When you request a refund, Apple notifies us and gives us twelve hours to say what we had delivered to you. Apple uses the answer to inform its refund decision.

We ask you first. At the moment you request the refund, the app asks whether you consent to this being sent. It is explicit consent, freely given and revocable: refusing does not cost you the refund, the decision stays entirely Apple's. If you do not consent we send nothing at all — not even a negative answer — and stay silent, exactly as Apple instructs.

If you consent, five values and nothing else leave, about that single purchase:

FieldWhat it saysWhere it comes from
customerConsentedthat you consentedyour answer, recorded with a timestamp
deliveryStatuswhether the position had been granted to youthe delivery record
consumptionPercentage100% if delivered, 0% if nota position is granted all at once
sampleContentProvidedthat before paying we showed you what you were buyingthe purchase screen shows the projection
refundPreferenceomitted — we express no preference—

No personal details leave. No name, no e-mail, no account age, no lifetime spend, no count of previous refunds. The version of Apple's interface that asked for those has been superseded: the one we use has no field to put them in.

To exercise your rights over this data once it has reached Apple you must go to Apple: privacy.apple.com. We cannot delete it from their systems. Your consent and our answer are recorded on our side, and over those you exercise your rights by writing to us.

9How long we keep it

DataHow longWhy
Account and profileWhile the account is active—
Deleted account6 months, then irreversible anonymisationA window to change your mind: just sign in again
Payments10 yearsLegal obligation (art. 2220 Italian Civil Code)
MessagesDeleted at anonymisation—
Support requestsKept, with the e-mail replacedThey are very often about the deletion itself
Security and administrative logsAs long as they are needed to prove what happened on an accountLegitimate interest. We have no scheduled automatic deletion today, and we would rather say so than publish a deadline we do not keep
About payments, plainly. Erasure happens on the user row, not on the accounting ledger. When an account is anonymised the payment row remains — amount, date, channel, transaction id — but it no longer identifies anyone. That is how the right to erasure and the ten-year obligation to keep accounting records are held together.

10Your rights

You can ask us at any time to access your data, correct it, delete it, restrict its processing, take it elsewhere, or object to processing based on legitimate interest. Where we rely on consent, you can withdraw it whenever you want.

Write to [email protected] from the account's address, or use the support form. We answer within a month.

There is no "download my data" button yet: we handle the request by hand, and the answer still comes within a month.

If you think we are handling your data wrongly you can complain to the Italian data protection authority, the Garante per la protezione dei dati personali (gpdp.it), or to the authority where you live.

11Cookies

On this site and in the web app we use no profiling, analytics or advertising cookies, and there is no third-party tracker. That is why there is no banner: there would be nothing to ask you to accept.

We use only what keeps you signed in: your session token, stored in your browser on your device. It is technically necessary and needs no consent. The one actual cookie is the administrative session one, and it concerns only us.

12Security

How we protect all of this is written out, measure by measure, on the security page — with the list of what we do not promise beside the list of what we do.

13Minors

The service is for adults. We do not knowingly collect data from anyone under 18; if we learn we have, we delete the account and the data.

14Changes

If we change this policy we update the date at the top and, for substantial changes, tell you in the service. Previous versions can be requested at [email protected].

Web uygulamasını aç Bize yaz