Skip to content
Legal
FifthSet

Privacy

Privacy policy

FifthSet is a free Grand Slam prediction game for private groups. This policy explains which personal data the web app and the iOS/Android app process, for what purpose, on which legal basis, and what your rights are under the GDPR.

Last updated September 17, 2026

01

Controller

The controller within the meaning of Art. 4(7) GDPR is:

Nicolai SchmidEmail: nicolai@fifthset.app

FifthSet is run by a private individual, not a company. No data protection officer is appointed because none is required by law. Please send privacy requests to the email address above.

02

What this policy covers

This policy applies to the web app at fifthset.app and to the FifthSet app for iOS and Android. Both are clients of the same backend, so the same data, purposes and processors apply; where the app behaves differently (push notifications, on-device storage) this policy says so.

Signing in happens on a page hosted by our authentication provider, WorkOS. What you enter there (email, passcode, or a social login) is processed by WorkOS on our behalf; FifthSet only receives the resulting account profile described below.

03

Data we process

We only process what the game needs. Concretely:

Support correspondence
When you contact support or request account deletion by email, we process your sender and account email addresses, message contents, and any screenshots or other attachments you choose to send. The in-app problem report also includes the app version, app variant, platform and originating screen in the email draft.
Account
Your email address, display name, profile-picture URL (if your login provides one) and the user id assigned by WorkOS. Received from WorkOS AuthKit when you sign in.
Game data
The groups you create or join, group names and styles, your match picks, podium calls, points and leaderboard position, and when each of those was made or changed.
Profile picture
Uploaded photos, private review candidates and moderation status; rule acceptances, blocks, report evidence, explanations and decisions. Your group admin reviews reports and photo submissions for that group; authorized platform moderators handle escalations. Other members see a photo only after approval for their group.
Notification settings
Your email/push preference per event. Push registration stores an Expo push token, a separately generated persistent installation ID, the platform (iOS/Android), and the app variant (development/preview/production). Push messages can contain private group names, tournament and round details, and your points, rank and rank changes. Their payload also contains the notification type, group ID and, when relevant, round number. Convex stores a delivery record linked to your account and device: the message and payload, delivery status, attempt count, Expo ticket ID, delivery errors and receipt results, and timestamps.
Usage and crash data
Which screens you open and which actions you take (e.g. "pick saved"), device type, operating system, browser or app version, language, and error or crash reports. Collected via PostHog. On the web, without analytics-cookie consent, events are pseudonymous: the browser keeps temporary analytics identifiers only in memory, but PostHog still receives events and network metadata such as your IP address and can correlate activity within a visit; consent enables cross-visit storage, account linkage using your WorkOS user id, and error reports. We no longer send your email as a person property. In the mobile app, analytics and crash reports are on by default and run only while you are signed in, as part of using the app; analytics events use your WorkOS user id. Screen recordings of your sessions in the app (what is shown on screen and where you tap; text you type and photos are masked before anything leaves the device) are made only if you turn the switch in Analytics & crash reports on yourself. You can turn all of this off at any time in Analytics & crash reports in Profile. Turning it off stops new reports and clears queued events and logs that have not yet been sent; it does not erase data already sent to PostHog. No advertising identifiers, no tracking across other apps or websites.
Emails
Transactional emails only: a round opening for picks, a podium reminder and the podium reveal. Resend processes your email address, delivery status and the rendered message content, including your display name, private group names and relevant tournament/match details. Podium-reveal messages also include other group members’ display names and their complete podium predictions. Convex separately records attempted recipient email addresses, including rejected addresses, with notification progress and counts to avoid duplicate sends when a batch resumes.
Technical logs
Hosting providers keep short-lived server logs (IP address, timestamp, requested URL, user agent) to operate and secure the service. Mobile update checks and downloads send Expo network/request metadata (including IP address) and platform, build/runtime and update-channel information. These requests occur independently of push permission and analytics consent.
04

Purposes and legal bases

Each processing activity rests on one of the legal bases in Art. 6(1) GDPR:

Support and privacy requests
Responding to ordinary support questions and investigating reported problems relies on Art. 6(1)(f) GDPR: our legitimate interest in helping users and maintaining a reliable service, including handling follow-up questions during the stated retention period. Processing necessary to fulfil statutory privacy and erasure requests relies on Art. 6(1)(c) GDPR in conjunction with Articles 12–22 GDPR. Please include only the information needed to handle your case.
Running the game
Account, groups, picks, scores and leaderboards — necessary to provide the service you signed up for. Art. 6(1)(b) GDPR (performance of a contract, i.e. the terms of use).
Game emails
Round-open, podium reminder and reveal emails are part of the game and can be switched off per event in the app's Profile, or by asking us. Art. 6(1)(b) GDPR.
Profile picture
Uploaded at your request, removable at any time. Art. 6(1)(b) GDPR.
Push notifications
Only after you opt in on your phone (system prompt and in-app setting). You can withdraw at any time in Profile or in the operating system's notification settings. Art. 6(1)(a) GDPR (consent).
Security and operation
Server logs, abuse prevention, error diagnosis. Art. 6(1)(f) GDPR — our legitimate interest in a service that stays up and is not misused.
Product analytics
Understanding which features are used and where the app fails, so we can improve it. Pseudonymous, cookieless web usage measurement uses Art. 6(1)(f) GDPR — our legitimate interest in improving a small, free product. Web analytics cookies, account linkage and crash reporting require your consent (Art. 6(1)(a) GDPR). In the mobile app, usage measurement, account linkage and crash reporting are part of the service described in the terms of use and run by default (Art. 6(1)(b) and (f) GDPR); you can object at any time with the switch in Profile. Screen recordings in the mobile app remain consent-based (Art. 6(1)(a) GDPR): they are made only after you turn that switch on yourself.
05

Processors and other recipients

We do not sell personal data and we show no advertising. We use the following service providers and disclose data to the other recipients described below. Providers acting on our behalf process data under data-processing agreements (Art. 28 GDPR).

Cloudflare — email forwarding
Cloudflare forwards incoming support and privacy-request emails, including sender/recipient information, message contents and attachments, to the operator’s support mailbox. The operator processes the correspondence there to handle your case.
WorkOS, Inc. (USA)
Sign-in and account management (AuthKit): email, name, profile picture, session.
Google, GitHub and Gravatar — profile-picture delivery
Social-login profile pictures can be loaded directly from googleusercontent.com (Google), avatars.githubusercontent.com (GitHub), or gravatar.com (Automattic). When you view these pictures in the app, a group, or an invite preview, your browser or device sends the provider request metadata such as your IP address and user agent. These providers process the requests under their own privacy terms.
Convex, Inc. (USA)
Database, backend functions and file storage for everything the game stores, including uploaded profile pictures. Hosted by Convex, Inc.
Vercel Inc. (USA)
Hosting and delivery of the web app, including its server logs.
PostHog Inc. — EU cloud
Product analytics and crash reporting. We use PostHog's EU cloud, so this data is stored in the European Union.
Resend, Inc. (USA)
Sending transactional emails and processing recipient addresses, delivery status and message content: recipient and group names, tournament/match details and, in podium-reveal emails, group members’ names and podium predictions.
Expo (650 Industries, Inc., USA)
Receives your device’s push token and the notification title, body and payload, including private group names, group ID, notification type, round details and, for results updates, points and rank changes. It relays the message and payload to Apple’s or Google’s push service. Expo also provides EAS Update: the mobile app contacts Expo to check for and download compatible updates on launch and during later checks, sending network/request metadata and platform, build/runtime and update-channel information. Update requests also occur when push and analytics are disabled.
Apple Inc. and Google LLC
Receive delivery tokens and the forwarded notification content and payload described above to deliver push notifications to your phone (APNs / Firebase Cloud Messaging) and distribute the app through their stores under their own privacy terms.
ESPN and Wikimedia — sports data and images
Draws, schedules and results are fetched by our backend from ESPN’s sports-data API without sending user account data. Your browser or device separately loads country flags directly from ESPN’s image servers while player photos are verified copies sourced from Wikimedia Commons and served from our Convex storage. Our backend retrieves Commons files without sending user account data; opening a photo credit link takes you to Wikimedia. Viewing these images, including where embedded in emails, exposes request metadata such as IP address and user agent to the image host (or to an image proxy used by your email provider).
Your groupmates and invite-link holders
Members of a group see each other's name, profile picture, points and — once a match has locked — each other's picks. Groups are private: only people with the invite link can join. Anyone who holds the invite link, however, sees a preview of the group before joining — its name and the display names and profile pictures of up to five members — so treat the link as the key to the group.

Beyond that, we disclose personal data only where the law requires it.

06

International transfers

WorkOS, Convex, Vercel, Resend and Expo are US companies, so personal data may be processed in the United States. Where a provider is certified under the EU–US Data Privacy Framework we rely on the European Commission's adequacy decision; otherwise the transfer is covered by the Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) that are part of the provider's data-processing agreement.

Analytics data stays in the EU (PostHog EU cloud).

Support forwarding, social profile pictures, sports images, push delivery and app-store distribution can also involve processing in the United States by Cloudflare, Google, GitHub, Automattic (Gravatar), ESPN (Disney) and Apple. Wikimedia also processes request metadata when you open an external photo credit link. Cloudflare’s forwarding terms include its Data Privacy Framework commitments and data-processing addendum. Google and GitHub describe Data Privacy Framework participation; Apple describes Standard Contractual Clauses for international transfers from the EEA. See the provider terms below for their scope and how to request details of safeguards.

For direct image requests, Google, GitHub, Automattic, ESPN/Disney process request metadata under their own privacy policies as independent providers. Automattic describes standard contractual safeguards for relevant onward transfers; Disney describes safeguards that may include Standard Contractual Clauses. Opening an external Wikimedia credit link is subject to Wikimedia’s privacy policy, which describes processing in the United States. We do not claim that our processor agreements cover these independent providers or that their independent status itself supplies a transfer safeguard.

The following provider policies describe their processing locations and applicable transfer arrangements. You can also contact us at the privacy email above for information about the safeguards used for FifthSet’s contracted services.

Cloudflare — privacy and transfer terms

Google — privacy and transfer terms

GitHub — privacy and transfer terms

Apple — privacy and transfer terms

Automattic / Gravatar — privacy and transfer terms

ESPN / Disney — privacy and transfer terms

Wikimedia — privacy and transfer terms

07

How long we keep data

We keep personal data only as long as the game needs it:

  • Support correspondence: we retain identifiable emails and attachments while a case is open and for up to 90 days after it closes. After that, we anonymize the correspondence, including identifying information in message contents and attachments.
  • Account data: until you delete your account.
  • Groups, picks and scores: for as long as the group exists, so the history stays readable for its members; your own entries go when you delete your account.
  • Raw images are deleted after preparation; abandoned uploads after 24 hours. Pending photos are retained during human review. Approved photos remain until replacement, removal or account deletion. Rejected and replaced images are removed when they are no longer your current private photo and no group approval, pending review or retained report still needs them. Report evidence and explanations are cleared 30 days after closure; minimal moderation audit records after 90 days, earlier on account deletion. Blocks and rule acceptances last while the account exists.
  • Push registrations and delivery history in Convex: turning push off on a phone, signing out there or an invalid-token verdict stops use of the affected registration, but does not itself erase its stored token, installation ID or past deliveries. Message/game data, delivery status, Expo ticket IDs, errors and timestamps have no general time-based expiry; completing delivery does not remove them. Account deletion removes that account’s registrations and deliveries through bounded cleanup, and removing a solo group also removes deliveries linked to that group, including former members’ deliveries.
  • Usage and crash events: deleting your account also requests erasure of the PostHog person profile and events linked to your account, including older email properties on that profile. Provider erasure runs asynchronously and failed requests are retried. Sign-out alone does not erase transmitted data. The same deletion request also opens a verification task for detached historical events, late arrivals and separate application logs. We retain your email while processing the request so we can send confirmation, then remove it from the deletion work record. Unlinked anonymous events remain subject to project retention.
  • Resend retains its delivery logs according to its own retention settings. In our Convex email component, daily cleanup removes finalized email records after seven days and abandoned records after 28 days. Separately, notification ledgers hold attempted recipient addresses and progress/counts. Daily cleanup removes recipient markers from completed claims. Abandoned claims are closed and their recipient markers removed once both the tournament’s recorded completion and the latest send or claim activity are over 28 days old. Active claims retain their progress. Account deletion also scrubs known current and former addresses, except markers still needed by another account sharing an address; older, unattributable addresses remain until claim cleanup. Non-recipient claim metadata and counts have no automatic expiry.
  • Server logs: a few days to weeks, as configured by the hosting providers.
08

Your rights

Under the GDPR you may at any time:

  • request access to the personal data we hold about you (Art. 15),
  • have inaccurate data corrected (Art. 16),
  • have your data erased (Art. 17) — see the deletion section below,
  • have processing restricted (Art. 18),
  • receive your data in a portable format (Art. 20),
  • object to processing based on legitimate interests (Art. 21),
  • withdraw a consent you have given, with effect for the future (Art. 7(3)) — for push notifications simply in Profile or your phone's settings.

You also have the right to lodge a complaint with a data protection supervisory authority, for example the authority of the German federal state or EU member state where you live (Art. 77 GDPR). To exercise any right, write to the email address in the controller section.

09

Deleting your account

Open Profile and choose "Delete account". This removes your account, your picks and podium calls, your group memberships, your notification settings and push tokens, and any uploaded profile picture. Groups you were in continue for their remaining members without your entries.

The same request includes your WorkOS sign-in identity and associated provider cleanup. We aim to finish within 30 days. Confirmation goes to your account email; if your account has no email address, contact support for confirmation. If you cannot sign in to request deletion, email us from the address on your account.

10

Cookies and local storage

The web app uses no advertising cookies and no cross-site tracking. What it does store in your browser:

Session (WorkOS)
An encrypted, essential cookie that keeps you signed in. Deleted when you sign out; otherwise expires on its own.
fs-language
Your chosen language (English or German), one year. Set when you use the language switch, and when you open one of these pages from the app: the app passes along the language it is showing (?lang=) so the page opens in the same language.
fs-theme
Your light/dark preference, in local storage. Only set when you use the theme switch.
PostHog
Without your consent, analytics uses memory only, with no analytics cookies or local storage. If you allow it, PostHog stores an analytics id and event queue in cookies and local storage and links events to your WorkOS user id when signed in. Your choice is stored separately as fs-analytics-consent. Data is sent to PostHog’s EU cloud. Use Analytics settings below or the footer link to revoke consent at any time.

The mobile app stores your session in the device's secure storage (Keychain / Keystore) and your appearance, language and analytics preferences on the device. Analytics and crash reports are on by default and PostHog reports only while you are signed in. Before you sign in, and on later launches after you have turned them off, PostHog does not start and no analytics files, events or logs are created. Turning them off or signing out stops new reports and clears queued events and logs; the analytics identifiers already stored on the device are not deleted by that. While enabled, PostHog keeps its analytics id and the queue of not-yet-sent events in a file on the device; before reporting starts after an app restart, the stored analytics identity is reset and previously queued events and logs are discarded, including data left by older app versions. The id is linked to your account when you sign in and reset when you sign out. Your choice in Analytics & crash reports in Profile is saved across app restarts. When you first enable push notifications, the app also stores a random installation identifier in SecureStore under fifthset.push-installation-id. It links this installation to its push registration, is not an advertising or hardware identifier, and has no fixed expiry. Signing out or disabling push does not erase the local identifier; it remains until its secure-storage entry is removed. Disabling delivery and deleting the backend registration are separate from deleting this local value.

You can change your web analytics choice here at any time. Revoking consent removes PostHog browser identifiers and stops account-linked analytics and crash reports in this browser. Pseudonymous, cookieless usage measurement continues: temporary identifiers can link activity within a visit, and events and network metadata still reach PostHog. Your choice is saved for this browser; already transmitted data is not deleted by this control.

11

Children

FifthSet is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, tell us and we will delete it.

12

Changes to this policy

We update this policy when the service or its providers change. The date at the top shows the current version. Material changes are announced in the app or by email before they take effect.