Privacy policy
1. Overview and controller
This Privacy policy explains how personal data is processed on playtippr.de and in the Tippr apps for iPhone, iPad and Android. The controller is Yannik Muth, Leo-Leistikow-Allee 4, 22081 Hamburg, Germany, email hallo@playtippr.de.
We process data required for operation, security, communication and the functions described below. The main legal bases are performance of a contract, consent, legal obligations and legitimate interests under Article 6 GDPR.
2. Website hosting by Cloudflare
The website is delivered as a Cloudflare Worker through the network of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare receives technical connection data for Website hosting, content delivery, TLS encryption and protection against abusive requests.
This may include the IP address, requested URL, time, browser and device details, HTTP headers, security data and error data. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in a secure, fast and stable website. We have a data processing agreement with Cloudflare. Transfers to the United States rely, as applicable, on the EU-US Data Privacy Framework or EU Standard Contractual Clauses. Details: cloudflare.com/privacypolicy.
3. Contact
If you contact us by email, we process the sender address, content, time and metadata needed to respond. The legal basis is Article 6(1)(b) GDPR for contractual matters and otherwise Article 6(1)(f) GDPR. We delete correspondence when it is no longer needed and no legal duty or claim requires retention.
4. Account and app use
Depending on how you use Tippr, we process your email address, authentication data, internal account ID, display name, optional profile image and favourite team, predictions, points, statistics, awards, group memberships, group content, chat messages, comments, push token, platform, app version and technical error data.
The legal basis is Article 6(1)(b) GDPR. Core data is stored with Supabase, Inc. as our processor in an EU data centre in Ireland. Details: supabase.com/privacy.
5. Other services
Apple Sign In or Google OAuth processes data required for authentication. Apple Push Notification Service or Firebase Cloud Messaging processes device push tokens when notifications are enabled. API-FOOTBALL supplies fixtures and results; we do not send it account data, predictions or group data.
App versions still in circulation may send product events and a random installation identifier to TelemetryDeck in parallel with our own analytics. According to the provider, processing takes place in Germany and IP addresses are not stored. This service is being discontinued. Details: telemetrydeck.com/privacy.
6. Product analytics in the app and website
We record technical events to detect errors, understand core flows and plan capacity. An event may contain the event name and time, platform, app version, coarse size categories and, for signed-in users, a pseudonymous identifier derived from the account ID. A daily changing identifier is used for signed-out website visits.
Our own analytics does not contain predictions, chat messages, keystrokes, screen recordings, contacts, precise locations, IP addresses or advertising identifiers. This statement applies only to our own analytics, not to the separate Google AdMob processing in section 7.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are error detection, stability, capacity planning and improving interrupted core flows. Technical raw events are normally deleted after 14 days and other raw events after 120 days. Anonymous daily totals may remain longer; account-related pseudonymous daily values are removed with a processed account deletion unless an overriding duty applies.
Right to object under Article 21 GDPR
You may object at any time to product analytics based on Article 6(1)(f) GDPR. Email hallo@playtippr.de from your account address with the subject “Object to product analytics”. We process the objection within one month.
7. Advertising with Google AdMob
The free app may display ads supplied by Google AdMob, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. There are no ads on playtippr.de. An active Tippr Pro subscription removes ads from the app.
According to Google, the Google Mobile Ads SDK may collect or share IP address and coarse location, product interactions and ad events, diagnostics, device identifiers and account identifiers for advertising, analytics and fraud prevention. On Android this can include the advertising ID and app set ID where available. Tippr does not request App Tracking Transparency on iOS, so AdMob does not receive an IDFA there. This does not describe Android.
Google may process data for its own purposes. Sources: Google Mobile Ads SDK data disclosure and Google Privacy Policy.
We use Google's User Messaging Platform for consent. The legal basis for processing that requires consent is Article 6(1)(a) GDPR. You can change the decision in the app under Profile, Settings, Privacy and “Manage advertising consent”. Withdrawal applies for the future. Google states that applicable adequacy decisions and Standard Contractual Clauses protect transfers to the United States.
8. Tippr Pro, store purchases and RevenueCat
Purchases and payments are handled exclusively by the Apple App Store or Google Play. We do not receive card or bank details or a billing address. Apple or Google remains responsible for payment, receipts, refunds and its statutory retention obligations.
We use RevenueCat, Inc. as a processor to verify and manage subscription status. RevenueCat receives the pseudonymous Tippr account ID, product and subscription status, purchase and expiry times, store country and limited technical offer attributes. It does not receive your name, email address, predictions, groups or payment details.
The legal basis is Article 6(1)(b) GDPR. RevenueCat also processes data in the United States; its data processing agreement includes EU Standard Contractual Clauses. Details: revenuecat.com/privacy and revenuecat.com/dpa.
Deleting the Tippr account does not cancel the store subscription. During account deletion, the RevenueCat customer is automatically deleted before the Tippr account is deleted; if this step fails, the Tippr account is not deleted. RevenueCat-related access requests can be sent from your account address to hallo@playtippr.de.
9. Imports from other prediction games
A group administrator may import display names and point totals from an existing group. Contact details and historical individual predictions are not imported. The legal basis is Article 6(1)(f) GDPR: the group's interest in continuing its table. Unclaimed places are pseudonymised after no more than 180 days. Earlier deletion can be requested from the group manager or hallo@playtippr.de.
10. Retention and account deletion
Active Tippr account data is normally kept while the account exists. After deletion in the app or a verified email request, we process deletion or irreversible anonymisation of active data assigned to the account within 30 days. See Delete account and data.
Deletion cannot cover data that Apple or Google retains under its own responsibility for purchases, billing, refunds or legal obligations. The RevenueCat customer is automatically deleted before the Tippr account is deleted, as described in section 8. Receipts, suppression records or security data may be retained only while a legal retention duty or defence against specific abuse requires it and are blocked for other purposes.
Deleted data may remain in encrypted backups for up to 30 days. It is not restored to the active service unless required for recovery after a security incident and expires with the backup cycle.
11. Your rights
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, portability and objection. Consent can be withdrawn for the future. You may also complain to a data protection authority. Email requests to hallo@playtippr.de; we may require confirmation through the account email address.
12. Security
We apply technical and organisational safeguards. Data is transmitted using TLS, passwords are not stored in plain text and access is restricted.
13. Changes
We update this policy if services, functions or legal requirements change. The current version is available on this page.
Last updated: 27 August 2026