Legal · Privacy
Privacy Policy
Last updated 13 September 2026
This Privacy Policy explains how Grada (the "App") collects, uses, stores, and protects your information. Grada is an independent app that lets football fans capture and collect memories of the matches they attend, build a personal "passport" of the stadiums and cities they have visited, and share those memories with friends.
Because the developer of Grada is based in Germany, this Policy is written to comply with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). It also reflects Apple's App Store requirements.
1. Who is responsible for your data (Data Controller)
The "data controller" responsible for your personal data is:
Mauricio Figueroa (individual developer)
Berlin, Germany
Contact: hello@gradaapp.com
If you have any questions about this Policy or how your data is handled, you can reach the developer at the email address above.
2. A note on the kind of app this is
Grada is built by a single independent developer. We have deliberately tried to collect as little personal data as possible and to keep your private memories private:
- We use anonymous, privacy-first analytics that do not identify you personally.
- Your memories are private by default. Other users can only see the full details of a memory once you and they are connected as friends — either by accepting a friend request, or by you sharing an invite link to that memory.
- We do not sell your personal data to anyone, ever.
We will always be honest about what we collect. The rest of this document explains exactly that.
3. What data we collect
3.1 Account and profile data
When you sign in, we use Sign in with Apple or Google Sign-In. From those services we receive and store:
| Data | Source | Notes |
|---|---|---|
| Email address | Apple / Google | Used as your account identifier. If you use Apple's "Hide My Email," we only receive the relay address. |
| First and last name (or given name) | Apple / Google | Pre-fills your profile; you can edit it. |
| Username | You | Chosen by you, or auto-generated if you don't pick one. |
| Profile photo (avatar) | You | Optional; stored on Cloudinary (see §5). |
| Login provider | Derived | Whether you signed in with Apple or Google. |
| Favorite team (name, logo, city, country) | You | Optional. |
| Account creation date | Automatic | When your account was created. |
3.2 Content you create ("Memories" and related data)
When you use the App you may create:
- Football memories — each memory includes one photo you upload, and may include an optional photo of your match ticket, plus details of the event: the stadium, city, country, competition, season, team, and match date, and optional notes and tagged friends who attended with you.
- Manual fixtures — if you cannot find a specific match, you may enter the match details (teams, score, date) yourself. This content is created and controlled entirely by you (see also our Terms & Conditions).
- City stamps / Passport data — collectible stamps that are generated automatically from the memories you create.
3.3 Social data
- Friend relationships and friend requests (who you are connected to, and pending invites).
- Invite links. If you share a memory with someone who is not yet your friend, we create a single-use invite code (valid for 7 days) and record who redeems it. Before they join, the invited person can see a preview of the memory: the cover photo, stadium, date and teams, your username and profile photo, and the usernames and profile photos of the friends already tagged in it. Redeeming the invite makes you friends and adds them to the memory in one step. Invite codes and redemption records are deleted with the memory or your account.
3.4 Support and feedback data
If you send feedback through the App, we collect the message you write, and optionally an email address and a photo you choose to attach, along with the feedback type, app version, platform, and language/locale to help us reproduce issues.
3.5 Device data for push notifications
If you allow notifications, we store a push notification token and your device name so we can deliver notifications to you. We use Firebase Cloud Messaging purely as the delivery channel for notifications — not for advertising or profiling.
3.6 Purchase data
Grada offers optional "support the developer" tips (e.g. Coffee, Lunch, Sponsor) as in-app purchases. These are voluntary, give you no special features or benefits, and are processed by Apple and managed through RevenueCat. We never see or store your card or payment details — Apple handles the payment. We receive only the purchase status and an anonymous purchase identifier linked to your account.
3.7 Analytics data (anonymous)
We use TelemetryDeck, a privacy-focused analytics service, to understand how the App is used (for example, which screens are opened or how often memories are created) so we can improve it. By design:
- Analytics signals are tied to an anonymous, hashed identifier, not to your name or email.
- We do not send your friends' identities, your photos, exact event dates, GPS coordinates, full addresses, or the contents of your feedback to analytics.
We do not use Google Analytics, advertising SDKs, or Apple's App Tracking Transparency tracking. We do not track you across other apps or websites.
3.8 Our website and the launch waitlist
Our website, www.gradaapp.com, does not use cookies or analytics. Three things do happen there:
- If you join the launch waitlist, your email address is stored and sent by Kit (Kit.com), our email service provider. We use it only to email you about the launch. You confirm your address by email first (double opt-in), and every email includes an unsubscribe link. Unsubscribing deletes you from the list.
- The site is hosted on Vercel, which keeps short-lived server logs (IP address, browser, pages requested) to serve and secure the site.
- Fonts are loaded from Google Fonts, so your browser sends your IP address to Google when it downloads them.
4. Why we use your data, and our legal basis (GDPR Article 6)
| Purpose | Legal basis |
|---|---|
| Create and maintain your account; let you sign in | Performance of a contract (Art. 6(1)(b)) |
| Store and display your memories, stamps, and profile | Performance of a contract (Art. 6(1)(b)) |
| Let you connect with friends and share memories | Performance of a contract (Art. 6(1)(b)) |
| Send push notifications you opted into | Your consent (Art. 6(1)(a)) — you can withdraw at any time in device settings |
| Process optional support purchases | Performance of a contract (Art. 6(1)(b)) |
| Anonymous analytics to improve the App | Our legitimate interest in improving the service (Art. 6(1)(f)); data is anonymized |
| Respond to your feedback and support requests | Legitimate interest / your consent |
| Comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
5. Third-party services we share data with (Processors)
We rely on a small number of trusted service providers ("processors") to run the App. We share only what each service needs to do its job.
| Service | What it does | Data involved |
|---|---|---|
| Supabase | Backend database, authentication, and server functions | Account, memories, friends, and the metadata above |
| Cloudinary | Image storage and delivery (CDN) for all images: avatars, memory photos, ticket photos, and feedback photos | Your uploaded images, stored in per-user folders |
| Apple (Sign in with Apple & App Store) | Authentication and payment processing | Email, name; payment is handled entirely by Apple |
| Google (Google Sign-In) | Authentication | Email, name, profile basics |
| Firebase Cloud Messaging (Google) | Delivery of push notifications | Push token, device name |
| RevenueCat | Management of in-app purchases | Anonymous purchase identifier and status |
| TelemetryDeck | Privacy-first, anonymous product analytics | Anonymized usage signals only |
| API-Football | Source of match fixtures, team logos, and stadium info shown in the App | We fetch football data from them; we do not send your personal data to them |
| Kit (website only) | Launch-waitlist emails | Your email address and confirmation status |
| Vercel (website only) | Hosting for www.gradaapp.com | Short-lived server logs |
| Google Fonts (website only) | Web fonts | IP address when fonts are downloaded |
We do not sell or rent your personal data, and we do not share it for third-party advertising.
6. International data transfers
Some of our processors (for example Cloudinary, Google, Apple, and RevenueCat) are based in or process data in the United States or other countries outside the European Economic Area (EEA). Where data is transferred outside the EEA, we rely on legally recognized safeguards such as the EU Standard Contractual Clauses and/or the EU–U.S. Data Privacy Framework, so your data continues to receive an adequate level of protection.
7. How long we keep your data (Retention)
- We keep your account data and memories for as long as your account is active.
- When you delete your account (see §9), we delete your profile, memories, photos, friend connections, stamps, device tokens, and related data from our systems.
- Anonymous analytics signals are not linked to your identity and are retained in aggregate.
- We may retain limited information for a short period where required for legal, security, or fraud-prevention reasons, or where it sits in routine backups that are rotated and overwritten on a normal cycle.
8. User-generated content and moderation
Grada lets users upload photos (memories and tickets) and post in a community feed. We want to be transparent with you about the current state of moderation:
- At this time the App does not have an automated or manual system to pre-screen or review uploaded content. We cannot guarantee that all content shown is appropriate.
- We are actively building safety features, including a report button on community posts, to allow users to flag content that is inappropriate, illegal, sexual, hateful, or otherwise violates our Terms & Conditions.
- If you encounter content that concerns you, please contact us at hello@gradaapp.com and we will review and act on it, including removing content and, where appropriate, suspending accounts.
Remember that memory details are only visible to your accepted friends. The community feed shows a more limited preview to other users.
9. Your rights and choices
9.1 Your GDPR rights
As a user (and especially if you are in the EU/EEA), you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data (you can edit much of this directly in the App);
- Erase your data ("right to be forgotten");
- Restrict or object to certain processing;
- Data portability — receive your data in a portable format;
- Withdraw consent at any time (e.g. by turning off notifications);
- Lodge a complaint with a supervisory authority.
To exercise any of these rights, email hello@gradaapp.com. We will respond within the timeframes required by law (generally within one month).
We do not make decisions about you based solely on automated processing, and we do not build profiles of you.
9.2 Deleting your account
You can delete your account at any time directly in the App (Settings → Delete Account). This permanently removes your profile, memories, photos, stamps, friend connections, and device tokens, as described in §7.
9.3 Push notifications
You can turn notifications on or off at any time in your device's system settings.
9.4 Supervisory authority
If you are in Germany, the competent authority for the developer's location is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
https://www.datenschutz-berlin.de
You also have the right to contact the supervisory authority in your own country of residence.
10. Children's privacy
Grada is not intended for anyone under the age of 16. We do not knowingly collect personal data from children under 16. This minimum age aligns with the digital-consent age under the GDPR in Germany. If you believe a child under 16 has provided us with personal data, please contact hello@gradaapp.com and we will delete it promptly.
11. How we protect your data
We use industry-standard measures to protect your data, including encryption in transit (HTTPS/TLS), authenticated access controls, and reputable infrastructure providers. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
12. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you within the App. Your continued use of Grada after changes take effect means you accept the updated Policy.
13. Contact us
For any privacy questions, requests, or concerns:
Mauricio Figueroa
Email: hello@gradaapp.com
Berlin, Germany