Privacy Policy
This policy explains which data NerdScore uses, why it is needed, where it can be visible, and how to exercise your rights.
PrivacyTermsDelete dataSupportInternational privacy rightsLegal noticeOpen app
Version and effective date
Version 2.2, effective July 25, 2026. This policy applies to the Free mobile version of NerdScore distributed through supported app stores and to the connected web services. At this version date, Android is distributed through Google Play; iOS references apply from release on the Apple App Store.
The date and version are updated when this policy changes. Material changes are announced in the app or before a new acceptance; minor changes remain available on this page. Where a change requires new consent, it will not apply to optional processing until you provide that consent.
Data controller
The data controller is Alexander Goytom. For privacy, access, export, correction, deletion or removal requests, write to ertalex@hotmail.it.
NerdScore is a scorekeeping service for private board game groups. It does not require an email account and does not sell personal data.
Data we process and sources
You or members of your groups may provide profile names and photos, colors, preferences, group and game details, match scores, notes, taunts, invitations and reports. PINs are stored only as one-way hashes.
The service also creates guest-session tokens, profile and invite codes, timestamps, XP and unlock records, technical security logs, IP-based rate-limit data and a hashed device signal used for Free-plan limits. On iOS, Apple's identifier for vendor (IDFV) is used as the device signal: it is sent to the server over HTTPS, immediately transformed into an HMAC hash, and is not retained in clear text. In the Android version distributed through Google Play, Firebase App Check with Play Integrity receives technical app and device information and an attestation token to verify that requests come from the authentic app. Only with your consent, on Android and iOS, does Firebase Analytics receive limited usage events and an app-install identifier and may derive an approximate geographic region from a masked IP address; Google states that Analytics does not log or store the IP address. On iOS the Analytics SDK is not initialized before consent.
Group content is visible to authorized group members. Anyone who receives a profile code can open its limited preview. Media use opaque, non-listable URLs, but anyone who obtains a working media URL may retrieve that file: share profile, group and invite links only with the intended people.
For availability and security, NerdScore retains aggregate operational metrics such as service health, CPU, memory and disk use, request volume and latency, and response-class counts. These metrics do not contain full URLs, codes, tokens, readable IP addresses, names, photos or content. Events blocked by rate limits or App Check use only counters and a short, non-reversible hash of the technical identity. UptimeRobot checks only the public /health endpoint; ntfy notifications contain aggregate infrastructure status and never profile data.
Required and optional data
The guest session, profile, access codes, and the group, game, and match information you choose to enter are required only for the features you use. Without a feature's minimum data, NerdScore cannot create that profile, group, or history, but unrelated features remain available where technically possible.
Photos, notes, taunts, customizations, and Firebase Analytics are optional. You can use core features without a photo and without Analytics; refusing or withdrawing Analytics consent does not reduce Free features.
Evidence of accepting the terms
The server records the accepted policy and Terms versions, the server acceptance time, distribution, app version, legal country selected explicitly, applicable coarse age policy, and an HMAC-derived security fingerprint from IP and device signals. It does not record an exact age or date of birth. The record is used only to prove acceptance, enforce the selected country's rules and protect the service. The legal country is never inferred from the IP address, app language or Analytics.
The record is used to evidence the accepted terms and handle legal claims, based on performing the terms and the legitimate interest in documenting the agreement and defending rights. It is included in your data export and kept for up to 1,825 days from the server-recorded acceptance time, then deleted unless the law requires longer preservation.
Purposes and legal bases
When you create a profile or enter data for a feature you request, core data is processed to perform the service: create and link profiles, synchronize groups and score history, manage invitations, calculate XP and unlocks, and answer support or deletion requests. When another group member records a participant's minimum name or nickname, attendance or score for a private game, NerdScore relies instead on the legitimate interest in providing shared private scorekeeping, limited by group visibility, data minimisation and the right to object or request removal. Optional photos or other personal data about another person may be uploaded only with that person's permission.
Security, the hashed device signal, abuse prevention, rate limiting and moderation rely on the controller's legitimate interests in protecting users and the service. On Android, this purpose also includes app attestation through Firebase App Check and Play Integrity. Optional Firebase Analytics is used on either platform only after consent, which can be refused or withdrawn without losing core features.
Recipients, user sharing and advertising
Core data and media are hosted on an OVHcloud VPS in the Frankfurt, Germany data center. OVHcloud acts as the hosting provider and data processor under the applicable terms and data processing agreement. Google/Firebase processes technical data as a provider for App Check and Play Integrity in the Android Store version and, only after consent, for Analytics in the Android and iOS versions. NerdScore does not sell data, use it for advertising or grant advertising consent.
Users intentionally share content inside their groups and through codes or links. Upload a photo or personal information about another person only if you have permission; contact us to request removal.
Processing outside the EEA
The core infrastructure stores profile, group, match and media data in Germany, within the European Economic Area. Some technical data processed by Google/Firebase for App Check and Play Integrity on Android and, only after consent, for Analytics on Android and iOS may be processed outside the EEA. Transfers to certified US Google entities are covered, where applicable, by the EU-U.S. Data Privacy Framework; where that framework does not apply, Google uses the safeguards in the applicable terms, including European Union Standard Contractual Clauses or another permitted transfer basis. Contact us for current details relevant to your request.
Do Not Track, Global Privacy Control, and cross-service tracking
NerdScore does not sell or share data for behavioral advertising and does not track your activity over time across unrelated third-party websites or services. It does not integrate advertising networks. When accepted, Firebase Analytics measures only NerdScore usage and is not used for ads or advertising profiles.
Do Not Track and Global Privacy Control signals do not change processing that is strictly necessary for operation and security. Optional processing is controlled by the Analytics setting in the app: when disabled, NerdScore does not send Firebase Analytics events; on iOS Firebase Analytics is not initialized until you consent.
Automated decisions
NerdScore automatically calculates scores, rankings, XP, levels, and unlocks using transparent game rules, but it does not make automated decisions that produce legal or similarly significant effects on a person.
Security
The public app uses HTTPS. Access is controlled with unguessable session and sharing tokens, group permissions, hashed PINs, rate limits, progressive PIN lockout and audit records. The Android Store version also uses Firebase App Check with Play Integrity to assess whether requests come from the authentic app. For the initial release, App Check is monitored without enforcement. Enforcement will be enabled shortly afterward, once the first Google Play downloads confirm that valid tokens are arriving correctly. The iOS wrapper loads app assets from its bundle, validates the origin of messages sent to the native bridge, and grants camera access only to the trusted local origin. No system can guarantee absolute security, so do not place unnecessary sensitive information in names, notes or photos.
Retention
Live profile and group data remains while needed for the service or until deletion. A deleted profile loses its direct fields, photo, code, PIN, unlocks and active links; shared match rows remain under a pseudonymous Deleted profile identifier so other members keep a coherent score history. Open moderation reports remain until review and, once closed, for no more than 730 days; they may retain the pseudonymous reference needed to document moderation. Formal legal notices remain while open and, once closed, for no more than 1,825 days so that the notice, assessment, decision and communications can be documented; queued email records are deleted with the notice. Free-plan quota events are deleted after 90 days. Inactive hashed device buckets are deleted after 365 days when they have no live session or active entitlement. For an app-store purchase linked to a deleted profile or retired device, only the non-reversible token hash may remain, without a profile link, for as long as needed to prevent reuse. Audit logs are deleted after 365 days. The server keeps the latest 7 successful database dumps, not necessarily seven calendar days; backups are used only for disaster recovery and deleted data may remain until the relevant dump is pruned.
Where required by law or necessary to establish, exercise or defend legal claims, content removed after a valid complaint and its associated evidence may be kept for up to 180 days in a separate encrypted archive accessible only to authorized administrators. It remains longer only under a lawful preservation order or legal hold. The archive is not used by app features, and each record is automatically deleted when its retention period and any hold have expired.
Technical monitoring retention
Local aggregate operational metrics rotate after 14 days. Security counters and technical hashes used to estimate how blocked events are distributed expire after 48 hours. UptimeRobot and ntfy apply their own retention periods only to the minimum technical data they receive; no user content is sent to those services. When India is selected as the legal market, NerdScore also keeps security and computer-traffic logs for 180 days to detect, investigate and report cyber incidents. These records may include time, request method and route template, result, IP address, app or device metadata and opaque session or profile identifiers. They exclude request bodies, query strings, access tokens and user content, are access-restricted and are disclosed to CERT-In only when legally required.
Your rights
You may request access, a machine-readable export, correction, deletion, restriction or portability, and may object where processing relies on legitimate interests. Write to ertalex@hotmail.it; identity checks may be required to protect other users.
You may withdraw analytics consent in the app at any time. You may also complain to your local supervisory authority; in Italy this is the Garante per la protezione dei dati personali.
International privacy rights
We provide every user, regardless of country, a way to request access, a copy, correction, and deletion of their data. We do not discriminate against anyone who exercises a privacy right, and we do not sell or share personal data for money or targeted behavioral advertising.
If the law where you live provides additional rights, identify them in your request.
Changing NerdScore's language changes only the translation you read. It does not change your country, the law that applies, the competent authority, or any mandatory rights you have where you live.
Minors
NerdScore is not directed to children under 16. Do not upload a minor's personal data without the authority required by applicable law; contact us if such data should be removed.
Deletion and historical records
You can delete the active profile in the app. You can also request deletion without the app from the Delete data page. Device-only preferences and cached data are cleared separately with Clear local data.
Pseudonymous historical match rows are excluded from current leaderboards, badges and awards. If a remaining record can still identify you in context, contact us so the specific record can be assessed and removed or further de-identified.