Privacy Policy - Tipper
This Privacy Policy describes how Tipper (“we”, “us”) collects, uses, shares, and protects information when you use the Tipper mobile application (“App”). It is written to comply with applicable data protection laws - including Brazil's LGPD (Law No. 13.709/2018) - and with the privacy requirements of the Apple App Store and Google Play.
Tipper is a sports information app for e-soccer (FIFA): live scores, statistics, head-to-head data, and alert bots that send push notifications you configure. Tipper is not a bookmaker, does not accept or process bets, and does not provide odds or betting advice.
1. Controller and contact
The controller of personal data processed in the App is Griff Studio. For privacy questions, data-subject rights, or our Data Protection Officer, contact [email protected]. For general app support, use [email protected].
2. Data we collect
We collect only what is needed to operate the App, depending on the features you use:
- Account data: name, email address, and an internal user identifier when you sign up or sign in with Apple, Google, or Facebook. For email sign-up we store a hashed version of your password - never plaintext. For social sign-in we store a stable provider identifier (your email may be hidden with Sign in with Apple).
- Device data: push notification token and device identifier, used solely to deliver the alerts you configure.
- User content: bot rules, notification layouts, preferences, and settings you create and save in the App.
- Subscription data: subscription/purchase status and history (product, store, dates, entitlement), processed by the Apple App Store and RevenueCat. We do not collect or store full payment card numbers.
- Product usage: feature interactions (e.g. head-to-head and statistics queries) used to operate and improve the App.
- Diagnostics: crash and error reports, with identifiers and sensitive information removed or obfuscated (scrubbed) before transmission.
We do not collect precise location, contacts, photos, microphone, or camera data, and we do not process sensitive personal data.
3. How we use data and legal bases
- Provide the App - authentication, bot sync, and core functionality. Basis: performance of a contract.
- Send push notifications according to your rules. Basis: consent, given when you authorize notifications on your device.
- Process subscriptions and unlock premium features. Basis: performance of a contract.
- Security, fraud prevention, and improvement of stability and performance. Basis: legitimate interest.
- Respond to support and meet legal obligations. Bases: performance of a contract and legal obligation.
4. Sharing and processors
We do not sell your personal data and do not use it for behavioral advertising. We share data only with providers acting as processors, as needed to run the App:
- Apple - Sign in with Apple, App Store/subscriptions, and push delivery (APNs).
- Google - when you choose to sign in with Google (authentication).
- Meta (Facebook) - when you choose to sign in with Facebook (authentication).
- RevenueCat - subscription management and validation (receives a user identifier and transaction data, not full payment data).
- Sentry - crash and error monitoring (minimized data, with personal information removed before transmission).
- Groq - generation of “AI Insight” narratives. Receives only public match data (e-soccer player handles, score, minute, league). No personal data of yours is sent to this service.
- Infrastructure provider that hosts our API and stores App data.
- Authorities, when required by law, court order, or regulatory request.
5. International transfers
Some processors above (such as Apple, Google, Meta, RevenueCat, Sentry, and Groq) are located outside Brazil, mainly in the United States. Where this happens, international data transfers rely on Article 33 of the LGPD and on contractual clauses and adequate safeguards offered by those providers. By using the App, you acknowledge that some processing may occur abroad.
6. Retention and security
We keep your data while your account is active and for as long as needed to fulfill the purposes of this Policy or legal obligations. Security and transaction logs may be kept for additional periods where required by law. After those periods, data is deleted or anonymized.
We apply technical and organizational safeguards, including encryption in transit (HTTPS/TLS), secure credential storage, password and token hashing, server access controls, and data minimization in diagnostics.
7. Your rights
Depending on your jurisdiction (including under the LGPD), you may request: confirmation of processing; access; correction; anonymization, blocking, or deletion of unnecessary data; portability; information about sharing; and withdrawal of consent.
Account deletion: you can delete your account and associated data directly in the App's profile settings, or by emailing [email protected]. For other privacy rights, contact [email protected]. We respond within the legal timeframe.
8. Children
Tipper is intended for users aged 13 and over. We do not create accounts for, or knowingly collect data from, children under 13. If we learn we have collected such data without a lawful basis, we will delete it. Guardians can contact us at [email protected].
9. Tracking and advertising
Tipper does not track you across third-party apps and websites for advertising and does not use the advertising identifier (IDFA), as declared in Apple's privacy manifest (NSPrivacyTracking = false). We do not show third-party ads.
10. Changes
We may update this Policy from time to time. The “Last updated” date at the top indicates the current version. Material changes will be communicated in the App or on this page. Continued use after publication means you are aware of the updated version.