Privacy policy

Last updated July 30, 2026 · v1.0

This translation is provided for your convenience. In the event of any discrepancy, the French version prevails.

1. Controller

The controller of the data collected through the TITU app and the titu.app site is:

KAWLET, entreprise unipersonnelle à responsabilité limitée, whose registered office is at 15 Square Rameau, 59000 Lille (France), registered with the Trade and Companies Register of Lille Métropole under number 993 159 250 (hereinafter "TITU" or "we").

Contact for any question about data protection or to exercise your rights: yo@titu.app

You can also write to us by post at the registered office address.

KAWLET is not required to appoint a data protection officer within the meaning of Article 37 GDPR. Requests are handled directly by the company's management.

Competent supervisory authority: Commission Nationale de l'Informatique et des Libertés (CNIL — the French data protection authority), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr. If you live in another European Union country, you may contact the supervisory authority of your country of residence.

2. Scope and minimum age

This policy applies:

  • to the TITU mobile app (iOS and Android), which is the members-only product;
  • to the titu.app site, which includes the public pages, the /j/{code} invitation journey and the pitch and club directory.

It is written in accordance with Regulation (EU) 2016/679 (GDPR) and Act No. 78-17 of 6 January 1978 as amended, known as the loi Informatique et Libertés.

Minimum age: 16. TITU is not intended for people under 16 and we do not knowingly collect their data. Creating an account means you are at least 16. If you hold parental responsibility and find that a child under 16 has created an account, write to us at the contact address: the account will be deleted.

Two categories of data subject are covered by this policy:

  1. members, who have created a TITU account;
  2. third parties whose data is entered by a member — a "+1" invited to a session, or a held spot assigned by phone number. Section 6 is devoted to them.

3. Our design principles

The commitments below are not intentions: they can be verified in the way the service is built.

  • We sell no data, to anyone, in any form.
  • No behavioural advertising, no advertising profiling, no data broker, no ad network.
  • No automated decision-making within the meaning of Article 22 GDPR.
  • No third-party analytics tracker placed on your device: no Google Analytics, no pixel, no advertising SDK, no session recording.
  • The app asks for access neither to your address book, nor to your photo library, nor to your camera, nor to your microphone. No library allowing such access is built into the app. The only optional permission requested, apart from notifications, is location, and only to centre the pitch map on your position — that position is neither transmitted nor stored.
  • The bare minimum of identifiers. We collect no email address: authentication is by phone number, and there is no password and no social login. No TITU application table holds an IP address or a user agent.
  • Sensitive logic lives on the server. The rules that protect the data (who sees what, who can write what) are enforced by the database itself, not by the app: they cannot be bypassed from a phone.

4. The processing operations, one by one: purpose, data, legal basis, retention, recipients

This section is the backbone of this policy. Each processing operation is described on its own, with the legal basis that permits it within the meaning of Article 6 GDPR.

The technical recipients common to every operation (hosting providers, processors) are detailed in section 12. References to "Supabase" below mean our database host, located in the European Union.


4.1 — Account creation and authentication

  • Data: phone number; display first name or nickname; profile photo (optional); account language; creation date.
  • Technical point: your phone number is stored in the authentication service (auth.users), not in your profile's application table. No TITU business table holds your number.
  • Purpose: to let you create an account, sign in with a one-time code (OTP) received by SMS, and be identified by your teammates.
  • Legal basis: performance of the contract (Art. 6(1)(b)) — without an account there is no service.
  • Retention: for the life of the account. Erased or anonymised on deletion (section 16).
  • Recipients: Supabase (hosting and authentication service); the SMS provider configured at the authentication-service level (Twilio) to deliver the one-time code. Your first name and photo are visible to the members of your groups, according to the visibility setting on your profile.

4.2 — Sessions, queue and attendance

  • Data: taking a spot, confirming, dropping out, position in the queue, call-ups, team assigned at the lock, unannounced absences ("no-shows"), the history of a session's events.
  • Purpose: to run the group's mechanics — the reserved slot, active confirmation, the first-come-first-served queue, the lock before kick-off.
  • Legal basis: performance of the contract (Art. 6(1)(b)).
  • Retention: for the life of the account. On deletion, the rows for upcoming matches are erased and the spot is handed back to the group; the rows for matches already played are kept in anonymised form (section 16).
  • Recipients: the active members of your group; Supabase.

4.3 — Score, standings and man of the match

  • Data: match score, goals, assists, own goals, votes (man of the match, best piece of skill, worst performance), the group's calculated standings.
  • Purpose: to keep the group's score, standings and awards.
  • Legal basis: performance of the contract (Art. 6(1)(b)).
  • Retention: for the life of the account, then kept in anonymised form — a match result also belongs to the other players who were on the pitch.
  • Recipients: the active members of your group; Supabase.
  • Specific guarantee — the reciprocity lock: you see other people's votes only if you have voted yourself. That rule is not enforced by the app: it is written into the row-level security policy of the database (policy votes_select_reciprocal, function has_voted). A request sent from a modified client therefore cannot get around it.

4.4 — Football profile, gear and followed clubs

  • Data: position, strong foot, declared level, current club, team name, boot size, favourite brand, freely entered history and honours; declared gear (category, size, condition, rating, optional photo); followed clubs; comments and reactions posted in the group.
  • Purpose: to fill out your player profile and bring the group to life. All of this information is optional.
  • Legal basis: performance of the contract (Art. 6(1)(b)) — these features are part of the service you ask us to provide.
  • Retention: until you change or delete them; erased when the account is deleted.
  • Recipients: the people allowed by your visibility setting; Supabase.

4.5 — Visibility of your player profile

  • Data: two settings — the reach of your profile (vestiaire: you and the active members of your groups; members: any signed-in TITU account) and whether or not your competition statistics are shown.
  • Purpose: to let you decide who sees what.
  • Legal basis: performance of the contract (Art. 6(1)(b)), and consent (Art. 6(1)(a)) for showing competition statistics, which is off by default.
  • Default settings: reach vestiaire, competition statistics hidden. A "visible to everyone, including outside TITU" level does not exist: the service refuses that value on write.
  • Retention: life of the account.

4.6 — "+1" guests: a third party's data

This operation is covered by section 6, to which we refer you.

  • Data: the +1's first name; optional phone number; the identity of the host member.
  • Legal basis: legitimate interests (Art. 6(1)(f)).

4.7 — Held spots (automatic starters)

  • Data: phone number entered by a group admin, optional indicative first name, the identity of the person who issued the invitation.
  • Purpose: to let a group's founder hold spots for the core players before they even have an account, and to hand those spots back to them when they sign up.
  • Legal basis: legitimate interests (Art. 6(1)(f)) — putting together the group of players who already know each other and play together.
  • Retention: automatic minimisation. A held spot that has not been claimed is deleted by the server when the line-up locks (by default two hours before kick-off). A third party's number, where that person never signed up, therefore does not outlive the match. A claimed spot disappears when the person who created it deletes their account.
  • Recipients: the members of the group (who can see the held spot); Supabase.

4.8 — Geographic availability ("Up for a game near me")

  • Data: a geographic point that you place yourself on a map (not your GPS position), a radius of 1 to 30 km, an on/off flag and the date of the last call-out received.
  • Purpose: to be told when a group nearby is looking for a player to complete its line-up.
  • Legal basis: consent (Art. 6(1)(a)). The feature is off by default and is turned on by an explicit switch in your profile. You can turn it off at any time, without giving a reason; withdrawal takes effect for the future.
  • Limits: the search always excludes people already linked to the group; the same player cannot be called out more than once in any 20-hour period; a call-out reaches at most 30 people, nearest first. These limits are enforced by the server.
  • Retention: until you turn it off or delete your account. The row is erased when the account is deleted, and the flag is switched off when the account is paused.
  • Recipients: no third party receives your point. The group calling out sees only a rounded distance.

4.9 — Claiming an identity in the public results of competitions

This operation is covered by section 7, to which we refer you.

  • Legal basis: consent (Art. 6(1)(a)), time-stamped and versioned.

4.10 — Push notifications

Detailed in section 8.

  • Data: the device's notification token, platform (iOS/Android), token language; the queue of notifications to be sent.
  • Legal basis: performance of the contract (Art. 6(1)(b)) for the content of the notifications, which is strictly functional; the system-level permission can be revoked at any time in your phone's settings.

4.11 — Usage measurement

Detailed in section 9.

  • Legal basis: legitimate interests (Art. 6(1)(f)) — understanding whether the product works, with no tracker and no profiling.

4.12 — Match weather

  • Data: the pitch coordinates and the kick-off time. No data about you is transmitted.
  • Purpose: to show the weather at the time of the match in the group's history.
  • Legal basis: performance of the contract (Art. 6(1)(b)).
  • Recipient: Open-Meteo, a European service queried with no key and no account. The service receives a geographic point and a date, never a player identifier.
  • Retention: the weather is recorded once with the match and kept with the group's history.

4.13 — Pitch and club directory, and clicks through to a partner offer

Detailed in section 10.

  • Legal basis: legitimate interests (Art. 6(1)(f)). On the visitor's side, this operation involves no personal data at all.

4.14 — Security, abuse prevention and technical logs

  • Data: counters of searches and identity claims per account, over a rolling 24-hour window (30 searches, 5 claims); a log of claim requests; the authentication log kept by the authentication service, which contains the IP address and user agent of sessions.
  • Purpose: to prevent abuse, in particular the misuse of identity search as a way of exposing third parties' identities; to keep accounts secure.
  • Legal basis: legitimate interests (Art. 6(1)(f)) — keeping the service secure and protecting the people whose data could be exposed.
  • Retention: the counters are reset at each new 24-hour window. These records are erased when the account is deleted, including the authentication log, which is purged both by account identifier and by phone number.
  • Recipients: Supabase; ourselves, for security purposes.

4.15 — Traceability of account lifecycle decisions

  • Data: an append-only log recording pauses, reactivations and deletions, with the date, the type of event and counters (number of spots handed back, +1s removed, devices detached). It keeps the account's technical identifier, but no identifying attribute at all once an account has been deleted.
  • Purpose: to be able to prove that a deletion request was actually carried out, and to diagnose an incident.
  • Legal basis: legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c), Article 5(2) GDPR: accountability).
  • Retention: kept without time limit, in non-identifying form. This log is accessible neither to anon nor to signed-in accounts: only the service role can read it.

4.16 — Responding to your requests

  • Data: the content of your message and what is needed to identify you.
  • Purpose: to handle your requests to exercise your rights and your support requests.
  • Legal basis: legal obligation (Art. 6(1)(c)) for requests to exercise rights; legitimate interests (Art. 6(1)(f)) for support.
  • Retention: 3 years from the last exchange, as evidence that the request was handled.

5. Structural guarantees

The commitments below are held by the structure of the database, not by an internal instruction. They depend neither on a good development habit nor on a setting someone could forget to restore: the data they rule out has nowhere to be written.

5.1 — No people in competition data. The tables that hold the public data of federations (clubs, pitches, competitions, teams, season entries, fixtures, results, standings) contain no column able to hold a person's name, a phone number, an email address, a date of birth, a referee or a named team sheet. Columns called "name" there refer exclusively to clubs, teams, pitches, competitions or match days. Those 56 tables are also entirely closed: row-level security enabled with no access rule at all, and no privilege granted to the anonymous and authenticated roles. No public query can read them.

5.2 — Profile photos are not public. The storage bucket for profile photos is private. The service never returns a public image address, only a path; display goes through a short-lived signed link (5 minutes), issued only where the access rules allow it — that is, to you or to an active member of a group you share. A modified client cannot grant itself the right to see a face.

5.3 — "+1" guests are out of the standings by construction. Guests are recorded in a dedicated table, separate from the line-up table. Standings, results and individual statistics are calculated exclusively from the line-up table. A +1 therefore cannot appear in the standings — not because a filter excludes them, but because they are not there.

5.4 — An unclaimed identity has nowhere to be written. In the table that holds a competition identity, the account identifier is the primary key. It is structurally impossible to record there the profile of someone who has no TITU account and has not confirmed being themselves.

5.5 — No Google Places content enters our data. From that service we keep only an opaque identifier, in a separate table whose constraints accept no other provider and no purpose other than linking a place. No Places content (name, reviews, photo, description) feeds our pitch listings or any automated writing process.

5.6 — No IP address in the application data. No TITU business table has an IP address or user agent column. That information exists only in the authentication service's log, for account security, and is purged when the account is deleted.

6. "+1" guests: when a member enters a third party's data

This is the most sensitive point of the service, and we document it in full.

What happens. When a session is short of players, a member can sign up a "+1": a friend who has no TITU account. They enter that person's first name and, optionally, their phone number. This is the data of someone who has no contract with us and who, at the time it is entered, may not know that their first name is on a team sheet.

Legal basis: legitimate interests (Art. 6(1)(f) GDPR). The interest pursued is organising a match between people who already know each other: the host member invites a friend they have already arranged to play with. The data involved is minimal (a first name, possibly a number), the processing is short-lived, and it involves no profiling, no marketing and no transfer to a third party. We have carried out a balancing test and consider that the interference with the +1's privacy is kept to the strict minimum.

Informing the data subject. By signing up a +1, the host member undertakes to have informed that person that they are being signed up to a TITU session and to have their agreement to share their number. If you have been signed up as a +1 and do not want to be, two routes are open to you: ask the member who signed you up to remove you, or write to us directly at the contact address — we will erase the data.

What is done, and what is not:

  • A +1 is never in the standings. They are recorded in a dedicated table (see section 5.3): they cannot appear in individual results, statistics or the group's standings. This is not a display choice, it is the structure of the data.
  • The number is used for one thing only: recognition at sign-up. If that person later creates a TITU account with that number, the service spots the match and links the +1's record to their account: they get back the record of the matches they actually played. The number is never used to send a message, an invitation or a reminder.
  • The number is normalised (only the digits are kept) and the same number cannot be signed up twice for the same session.
  • Server-side limits. A +1 can be added only if spots are genuinely free, if the queue is empty (nobody waiting must be jumped) and within the cap set by the group. These rules are enforced by the database, not by the app.
  • A +1's unannounced absence is charged to their host, not to them.

Retention. A +1's first name appears on the group's team sheet and stays there, because it is part of the other players' shared history. The phone number, on the other hand, is erased in the following cases: when the host member deletes their account; when the +1 creates an account and becomes a full member; or on request sent to our contact address. In full transparency, you should know that a host removing a +1 from a session marks the row as withdrawn but does not on its own delete the number: an erasure request must be sent to us, and we act on it.

Community call-outs. When a player joins a session through the community call-out (section 4.8), they are recorded in the same dedicated table, with a note of where they came from. They are not a member of the group and do not enter the group's standings.

7. Identity claim — "is this you?"

TITU lets you, if you wish, link to your account the statistics of a player found in the public results of competitions.

⚠️ An essential point, stated without ambiguity: no federation transmits data to us, and we have no data-sharing partnership with any federation. We read only competition results that are publicly published, at the moment you ask us to. Any wording suggesting otherwise would be inaccurate.

Legal basis: your consent (Art. 6(1)(a) GDPR), obtained before the processing, time-stamped and versioned. The consent text carries a version number (currently 2026-07-30.1) which is recorded with your confirmation. The server is the authority: if the text has changed since it was displayed, the claim is refused and consent must be given again on the up-to-date version. The feature is entirely optional; doing nothing is a perfectly valid answer.

How it works, in order:

  1. On demand, never pre-emptively. Nothing is read until you have declared your club yourself. There is no pre-built stock of player records, no database of identities waiting to be claimed.
  2. The search keeps nothing. Public team sheets are read at that moment by a dedicated function that writes to no database. Its only state is a bounded 5-minute in-memory cache, which disappears with the process. No file, no row, no trace of the people who are not you.
  3. The candidates offered to you are anonymised. You never see a third party's full name: only the first name followed by the initial of the surname ("Luca A."), the year of birth where the source publishes it, and sporting details (team, competition, season, appearances, goals, shirt number). The real federation identifier is never exposed in clear.
  4. The link to a candidate is encrypted, short-lived and personal. Each candidate offered comes with an encrypted token containing the real identifier, your account identifier and a 10-minute expiry. A token offered to someone else is refused; an expired token is refused. You can only claim what was offered to you, and within those ten minutes.
  5. We keep only you. After your confirmation, only your record is saved. The other candidates have, structurally, nowhere to be written: in the table that holds an identity, the account identifier is the primary key (section 5.4).
  6. One identity, one account. The same competition identity can be linked to only one TITU account.

Data kept after your confirmation: first name and surname as published by the source, competition identifier, club and team, the source address, the consent version, the date of the claim; together with your statistics by season (competition, level, team, number, appearances, goals, cards, dates of first and last match).

Date of birth: it is kept only for the person who confirmed being themselves. For the other candidates, the year exists only for as long as it is displayed, and is never recorded. If the source publishes only the year, we record only the year — we do not invent a 1 January. On your profile, only the year is shown, never a full date. As at the date of this policy, none of the sources currently connected publishes a date or year of birth: no birth data is therefore actually collected.

Display: your competition statistics are hidden by default. Showing them on your profile requires a second setting, which you turn on explicitly (section 4.5).

Coverage: the feature is available only for countries where a public source is supported. If your country has none, the service tells you so and nothing is read.

Withdrawal at any time. A button in your profile unlinks the identity. Withdrawal immediately erases your identity record and all of your competition statistics, with no archive, no copy, no bin. In the internal claims log, the identifier pointing to a person is zeroed out; all that remains is the trace of an event (a claim took place on such a date, on such a federation, for such a club), with no name.

Disputes. If you believe an account has linked itself to your identity, write to us at the contact address: we can flag the identity as disputed — which immediately removes it from display — and then unlink it.

Protection against misuse. An account is limited to 30 searches and 5 claims per 24-hour period. That limit deliberately closes off one avenue of abuse: claiming and cancelling in a loop to reveal a full name each time round.

8. Push notifications

What we keep: for each device, a notification token, the platform (iOS or Android) and the token's language. No advertising identifier, no hardware identifier.

When permission is requested. It is never requested on first launch of the app. It is requested after you have created or joined a group — that is, at the point where a notification finally means something to you. Refusing has no effect on the rest of the service.

Notification content is composed on our server, in the language of the receiving device, from an internal queue. A notification can contain the group's name, the pitch name, the match date and, depending on the case, a player's first name (for example when a spot has been reserved for you or when a player has joined the session).

Recipients: the composed message and the device token are passed to Google (Firebase Cloud Messaging) for delivery and, on iOS, to Apple (APNs). This is the standard delivery mechanism for mobile notifications; there is no way to deliver a push notification without going through these services.

Retention: a token is kept for as long as the app is installed and the account active. It is erased immediately if you pause or delete your account, and it is removed automatically when the delivery service tells us it is no longer valid.

Withdrawal: you can revoke the permission at any time in your operating system's settings. TITU's Settings screen shows the current permission state and offers the way back.

9. Usage measurement

We use PostHog, in the European Union region, to understand whether the product works.

What we do:

  • Named events only, fired explicitly by our code. There is no automatic capture of what you do, no session recording ("session replay"), no heatmap, no tracking of what you type.
  • The list of events is short and closed. In the app: group_created, group_joined, place_taken, slot_confirmed, absence_declared, score_submitted, motm_voted, guest_added, community_opened, community_joined, card_shared, push_permission. On the site: web_join_viewed, web_otp_sent, web_otp_verified, web_group_joined, web_lang_switch, web_confirm, web_declare_absence, web_undo_absence, web_pass_offer, web_take_place, web_submit_score.
  • Each event carries minimal technical properties: the identifier of the object concerned (a session, a group), the platform and the environment. Nothing you type is transmitted.
  • Once you are signed in, events are attached to the technical identifier of your account (a UUID). Before sign-in, they are sent under the identifier anon.
  • No analytics cookie, no storage on your device, no advertising identifier. Sending is a plain direct HTTP request; we do not embed PostHog's SDK. As a result, this processing involves no access to, and no storage of information in, your device within the meaning of Article 82 of the French Data Protection Act, and is therefore not subject to prior consent on that basis.
  • As with any network request, PostHog's server sees the IP address the call comes from. We do not record it on our side and do not cross-reference it with any other processing.

Legal basis: legitimate interests (Art. 6(1)(f)). You can object to this processing at any time by writing to us at the contact address.

Retention: we undertake not to keep these events for more than 25 months.

Without a configuration key, measurement is entirely inactive: the code sends nothing.

10. Pitch and club directory, and partner offers

The titu.app site publishes a directory of football pitches and clubs, built from public data (public open data, public registers, information published by federations). These pages carry no personal data: they describe places, facilities, clubs and competitions. Club officials, named contacts and named team sheets are excluded from them by construction (section 5.1).

Browsing. Browsing the directory requires neither an account nor a tracking cookie. None of our tables keeps a visitor's IP address.

Clicks through to a partner booking offer. When you click on a booking offer, you go through a technical redirect that increments a counter. That counter contains exactly: the offer's identifier, today's date, the surface the click came from (listing, city page or map), the number of clicks and the timestamps of the first and last click of the day. No IP address, no cookie, no account, no player identifier, no browser fingerprint. It is therefore impossible, from this counter, to know who clicked.

The redirect is also configured to send no referrer to the partner site, and the outbound link carries the attributes nofollow sponsored noopener noreferrer. The partner therefore does not know which TITU page you came from.

Position on the map. The "near me" button on the pitch map uses your device's location solely to centre the view. That position is neither sent to a server nor stored. It is distinct from the geographic availability point described in section 4.8, which you place yourself and which is stored with your consent.

11. Cookies and local storage

TITU sets no advertising cookie and no analytics cookie. There is therefore no consent banner, because there is nothing to consent to.

The only items placed in your browser are strictly necessary for the site to work and exempt from consent under Article 82 of the French Data Protection Act:

NameTypePurposeDuration
sb-…-auth-tokenCookie and local storageKeep your session signed in and refresh the access tokenSession duration, renewed for as long as you stay signed in
titu.localeCookie and local storageRemember the display language you have chosen, including for routing when you arrive on the site1 year
titu.locale.pendingLocal storageFlag that a language choice has not yet been saved to the accountUntil confirmed

In the mobile app, the equivalent preferences are kept locally on the device and disappear when it is uninstalled.

12. Recipients, processors and transfers outside the EU

Your data is never sold, rented or transferred. It is accessible to authorised staff at KAWLET, strictly on a need-to-know basis, and to the technical processors listed below. Each acts on our instructions and is bound by a processing agreement compliant with Article 28 GDPR.

ProcessorRoleLocation of processingSafeguards
SupabaseDatabase, authentication, file storage, server functionsEuropean Union — West EU (Paris) region. File storage runs on AWS infrastructure.Processing agreement; standard contractual clauses for any support access from a third country
Vercel Inc.Hosting of the titu.app site (front end) and its delivery networkUnited States, with worldwide deliveryEuropean Commission standard contractual clauses. Some of these providers are also certified under the EU-US Data Privacy Framework; a copy of the safeguards applying to a given provider can be requested at yo@titu.app
TwilioDelivery of the SMS containing the one-time codeUnited States, with points of presence in EuropeStandard contractual clauses and binding corporate rules
Google LLC (Firebase Cloud Messaging)Delivery of push notifications on Android and iOSUnited StatesEuropean Commission standard contractual clauses. Some of these providers are also certified under the EU-US Data Privacy Framework; a copy of the safeguards applying to a given provider can be requested at yo@titu.app
Apple Inc. (APNs)Delivery of push notifications on iOSUnited StatesStandard contractual clauses; the service is inseparable from the iOS operating system
PostHogUsage measurement through named eventsEuropean UnionProcessing agreement; EU hosting
Open-MeteoHistorical weather for a matchEuropean UnionQueried with no key and no account; receives no personal data
Google LLC (Google Fonts)Download of typefaces by the mobile app on first launch. As a result receives the device's IP address. On the site, fonts are served from our own servers: no call.United StatesStandard contractual clauses
OpenFreeMapBase map for the pitch directory. Receives the IP address and the geographic area viewed.European Union (Netherlands)Public tile service; no account and no identifier transmitted
OpenStreetMap FoundationBase map for the "up for a game near me" screen in the app. Receives the IP address and the area viewed.United Kingdom / European UnionPublic tile service; no account and no identifier transmitted

Transfers outside the European Union. The core of your data — account, groups, sessions, scores, profiles — is hosted in the European Union. Transfers to the United States are limited to what is technically unavoidable: delivering the site's pages, delivering an SMS and delivering a push notification. They are covered by the mechanisms provided for in Chapter V GDPR (adequacy decision, standard contractual clauses).

Other possible recipients: the other members of your groups, within the limits described in section 4; and, where applicable, judicial or administrative authorities acting on a lawful order.

13. Retention periods — summary

DataRetention
Phone number, first name, photo, languageLife of the account, then erased on deletion
Football profile, gear, followed clubs, comments, reactionsLife of the account, then erased
Geographic availability pointUntil turned off, then erased on deletion
Notification tokensUntil the account is paused or deleted, or until invalidated by the delivery service
Competition identity and statisticsUntil the claim is withdrawn or the account deleted, then erased with no archive
Line-ups, scores, goals and votes for matches already playedKept, in anonymised form once the account is deleted (section 16)
Line-ups for upcoming matchesErased when the account is deleted, the spot being handed back to the group
A "+1"'s first name on a past team sheetKept with the group's history
A "+1"'s phone numberUntil conversion into an account, deletion of the host's account, or an erasure request
Unclaimed held spotDeleted automatically when the line-up locks (by default, 2 h before kick-off)
Authentication log (IP address, user agent)Purged when the account is deleted
Account lifecycle logKept without time limit, in non-identifying form
Usage measurement events25 months at most
Requests sent to our contact address3 years from the last exchange

Transparency on this point: apart from the cases where a period is expressly stated above, the data attached to your account is kept for as long as your account exists. We do not apply an automatic purge by age; it is pausing and deletion, described in sections 15 and 16, that decide its fate.

14. Data security

In accordance with Article 32 GDPR, we implement the following measures:

  • Encryption of communications with TLS on every exchange, app and site.
  • Encryption of data at rest by our hosting provider.
  • Row-level security in the database. Every sensitive table carries access rules evaluated by the database engine: a client can read only what the rule allows, whatever query it sends. This is the mechanism that holds the vote reciprocity lock (section 4.3) and the confidentiality of profile photos (section 5.2).
  • All sensitive operations are transactional and executed server-side. Taking a spot, declaring an absence, confirming, claiming an identity, deleting an account: the client calls, it does not decide.
  • Time-based transitions (opening the queue, the lock, an offer expiring) are triggered by a scheduled task on the server, never by the device: changing the time on your phone has no effect.
  • Ring-fencing of competition data: row-level security enabled with no access rule and no privilege granted to the public roles.
  • Rate limiting on sensitive functions, and an audit log on identity claims.
  • Private photo storage bucket, access through a 5-minute signed link.

In the event of a data breach likely to result in a risk to your rights and freedoms, we will notify the CNIL within 72 hours (Article 33 GDPR) and inform you directly where the risk is high (Article 34).

15. Pausing your account

Pausing is a reversible step that takes you out of circulation without destroying your history. It is triggered from Settings › Danger zone › Pause.

What happens immediately:

  1. Your upcoming spots are handed back to the group — your sign-ups for future sessions are released, and the next substitute is called up. The same applies to the "+1" guests you hosted and to sessions you had joined through a community call-out.
  2. Your geographic availability is switched off (the row is kept so it can be restored to you).
  3. Your notification tokens are deleted: you receive nothing more.
  4. Notifications not yet sent that were addressed to you are deleted.
  5. Your player profile stops being viewable by others.

What is preserved: your first name, your photo, your language, your group memberships, your match history, your standings, your football profile, your gear, your comments, and your competition identity if you claimed one.

What is blocked while paused: you can no longer take or confirm a spot, join a group, add a "+1", vote, comment, react, or change your geographic availability. Any attempt is refused by the database itself, with an explicit message.

Coming back takes one step, from the same screen. Your geographic availability is switched back on only if it was on before the pause. However, the spots handed back do not come back: someone may have played in your place, and we dispossess nobody.

One reservation: a player who is the last admin of a group that has other members cannot pause until they have handed over the keys. This is no obstacle to your rights: handing over takes two steps from the dressing room screen.

16. Deleting your account — what is erased, what is anonymised

Deletion is triggered from Settings › Danger zone › Delete my account, with an explicit confirmation. It is immediate, permanent and with no bin: there is no grace period, no backup and no way to restore. A deleted account cannot be reactivated.

Before anything is frozen, your spots are handed back. That is the first operation, and it covers every form of spot an account can hold: your sign-ups for future sessions, the "+1" guests you hosted, sessions joined through a community call-out, and the held spots you had created or that were meant for you. Missing a single one of these forms would leave a ghost spot: a group that thinks it is ten and plays nine. That is not a display detail — it is other people's data that we would be damaging.

What is ERASED, with no copy and no archive:

  • your phone number, including in the authentication log — a log tied to your account by no technical link, and which deleting the account therefore does not reach on its own: it is purged explicitly, both by identifier and by number;
  • your profile photo: the reference is erased immediately, and the file is removed from storage by an automated task that runs every five minutes;
  • your language, your football profile, your gear, your followed clubs;
  • your comments and your reactions;
  • your geographic availability point and its radius;
  • your device tokens and your notification queue — including notifications addressed to others that named you;
  • the session event log that carried your first name in clear ("so-and-so took a spot"), and, in those same entries, the first name of a "+1" you had brought;
  • your competition identity and all of your statistics, together with the claims log concerning you;
  • the held spots you had created and those that carried your number;
  • the phone number of any "+1" you had brought;
  • your authentication identity and all of your sessions and tokens.

What is ANONYMISED and kept:

Your profile becomes a shell with no identifying attribute at all: your display name is replaced by a meaningless technical pseudonym (in the form #a3f91c), and the photo and language are cleared.

From then on, the rows that pointed to you point only to a bare identifier, and are therefore anonymised in a single step:

  • the line-ups of matches already played;
  • the goals, assists and statistics of those matches;
  • the votes you cast and those you received;
  • the team sheets carrying a "+1" you had brought — their first name stays, because it is not your data: it is a third party's, written on the team sheet of a group that is entitled to keep its own history.

Why not erase everything? Because a match score is not your data alone. It also belongs to the nine other people who were on the pitch. Erasing the row would mutilate their history, their standings and their results. So we destroy the link to you, which takes those rows outside the scope of the Regulation, rather than destroying a group's shared memory.

One reservation, the same as for pausing: a player who is the last admin of a group that has other members must first hand over the keys. Handing over takes two steps from the dressing room screen. If you cannot manage it, write to us: we will carry out the deletion.

Two points of transparency:

  1. In a technical fallback case where the authentication row could not be deleted in the same operation, the account is banned before any purge is attempted: signing in becomes impossible even if the purge fails. That order is the guarantee, and the remainder is then deleted by us.
  2. Account deletion is available only in the mobile app. If you no longer have access to the app, write to us at the contact address: we will carry out the deletion.

17. Your rights

You have the following rights over your personal data:

  • Right of access (Art. 15) — to obtain confirmation that we process your data and to obtain a copy of it.
  • Right to rectification (Art. 16) — to correct inaccurate or incomplete data. Most of your information can be edited directly in the app.
  • Right to erasure (Art. 17) — to have your data deleted. It is exercised directly by deleting the account (section 16), or on request.
  • Right to restriction of processing (Art. 18).
  • Right to object (Art. 21) — to object to processing based on our legitimate interests, in particular usage measurement.
  • Right to data portability (Art. 20) — to receive the data you have provided to us in a structured, machine-readable format.
  • Right to withdraw your consent at any time, as easily as you gave it, for the processing that depends on it: geographic availability (a switch in your profile), identity claims (a withdrawal button in your profile), display of competition statistics, and push notifications (your system settings). Withdrawal does not affect the lawfulness of processing carried out beforehand.
  • Right to give directions as to what happens to your data after your death (Article 85 of the French Data Protection Act).

What the app lets you do on your own, immediately: view and edit your profile, your player profile, your gear and your visibility settings; turn geographic availability on or off; unlink a competition identity, which erases the associated statistics; pause the account; delete the account, with a statement of what is erased and what is anonymised.

⚠️ What the app does NOT yet allow, in all honesty: there is no automated export of your data into a machine-readable file, and there is no single screen summarising all the data held and the consents given. The rights of access (Art. 15) and portability (Art. 20) are therefore exercised on request sent to yo@titu.app; we will send you an export in a structured format. We do not claim otherwise, and this feature is part of our planned development.

How to exercise your rights: write to yo@titu.app, from a means that allows you to be identified, setting out your request. We may ask you for proof of identity in the event of reasonable doubt. We reply within one month, extendable by two months for a complex request, in which case we will tell you.

If you are a "+1" whose first name and possibly phone number a member has entered without you being a member yourself: your rights are the same. Write to us at the contact address, or ask the member who signed you up to remove you.

Complaints: if you believe your rights are not being respected, you can lodge a complaint with the CNIL (cnil.fr/plaintes) or with the supervisory authority of your country of residence.

18. Changes to this policy

This policy may change, in particular to reflect a new feature, a change of processor or a regulatory development.

In the event of a material change, we will tell you through a message in the app or on the site before it takes effect. Where the change concerns processing based on your consent, fresh consent will be requested — this is notably the case for identity claims, whose text carries a version number recorded with your confirmation and checked by the server at every claim.

The version in force is always available from the titu.app site and from the app's settings. The date of the last update appears at the top of the document.

Version 1.0 — in force from 30 July 2026.

Contents
  1. 1. Controller
  2. 2. Scope and minimum age
  3. 3. Our design principles
  4. 4. The processing operations, one by one: purpose, data, legal basis, retention, recipients
  5. 5. Structural guarantees
  6. 6. "+1" guests: when a member enters a third party's data
  7. 7. Identity claim — "is this you?"
  8. 8. Push notifications
  9. 9. Usage measurement
  10. 10. Pitch and club directory, and partner offers
  11. 11. Cookies and local storage
  12. 12. Recipients, processors and transfers outside the EU
  13. 13. Retention periods — summary
  14. 14. Data security
  15. 15. Pausing your account
  16. 16. Deleting your account — what is erased, what is anonymised
  17. 17. Your rights
  18. 18. Changes to this policy