Halbreven

Privacy Policy

Halbreven holds less about you than the group chat it replaces. What it does hold is fenced in the database, not in the interface — which is the difference between a promise and a guarantee. This page says exactly what that is.

Applies from the first release.


Who is responsible

The data controller is Arrit Gashi, trading as Halbreven. For anything on this page, write to info@halbreven.com. That address is read by a person, and it is the same one for a question, a request for your data, or a complaint.


What we collect, and why

Everything below is held because the app cannot do what you asked it to do without it. That is the legal basis for all of it — performance of the agreement you make when you sign in (GDPR Article 6(1)(b)), except where a row says otherwise.

WhatWhyKept until
Your email addressIt is how you sign in — a six-digit code is sent to it. There is no password to store.You delete your account
A display nameSo your teammates know who is on the sheet. It is free text; it does not have to be your real name.You delete your account
A profile photo, if you add oneOptional. Initials are drawn if you do not.You delete your account
Your month and year of birthTo confirm you are an adult. Halbreven's groups are for players 18 and over; a group run as a club team may admit younger players with a parent's confirmed consent. We ask for the month and year, never the day.You delete your account
When you agreed to the TermsSo we can show, if asked, that you were shown them. Recorded on first sign-in. Legal basis: our legitimate interest in being able to evidence the agreement (Article 6(1)(f)).You delete your account
A push-notification tokenSo your phone can be told when teams go up. It identifies the device, not you, and it is issued by Apple or Google.You sign out, or delete your account
A parent or guardian's email, only for a player under 18To send the one email that asks them to confirm. A pending request expires after 14 days.The request is answered or expires; a confirmed one is kept as the record that the membership was lawful

Plus what you create by using the app: your answers to fixtures, the matches you played, your ratings of teammates and theirs of you, your trust score, any cards, your chat messages and reactions, and anything you post to your group's timeline. All of it is filed against a group and you together, never against you alone — see below.

What we do not collect

  • No location, ever — not even for the venue, which is free text somebody types.
  • No contacts, no address book, no phone number.
  • No advertising identifier, no analytics, no tracking across other apps or websites. The app does not ask for tracking permission because it does not track.
  • No passwords.
  • No photo metadata. Location and camera details are stripped from every photo before it leaves your phone.

Ratings are anonymous by construction

After a match you may be asked to rate a few teammates, and they may rate you. This is the part worth explaining properly, because "we promise not to show it" is not the same as "it cannot be shown".

Individual ratings live in a table with row-level security switched on and no access policies written for it at all. In practical terms: there is no query any player, any admin, or any export can run that returns who rated whom. The only things that read it are locked server-side routines that hand back averages.

What this means

You see your own scores and how they are moving. You never see who gave you which one. Neither does your group admin, neither does anybody else, and neither do we — it is not a setting that can be turned off, because there is nothing to turn off.

A score is also held back until enough ratings exist for it to mean anything, so nobody can work backwards from a handful of them.


Groups do not leak into each other

Every score, card, attendance record and trust event is filed against a group and a person together, never against a person alone. Your record in one group is not visible from another. Neither is your card history, your attendance, or anything that happened there.

The one exception, stated plainly

Your profile carries an overall rating and trust score — the average across your groups — and anyone who shares a group with you can see it. That is a deliberate decision, made so a player's reputation travels with them rather than resetting every time they join somewhere new.

And the honest caveat

An overall average shown beside a per-group score is arithmetically reversible. Somebody in one of your groups can see your score there, see your overall, and work out the rest — exactly, if you are in two groups. We narrow it (only groups with enough ratings are averaged) but we do not close it, and we would rather write that here than claim a privacy property the maths does not support.

It does not touch the paragraph above. Individual ratings stay unreadable to everyone regardless.


Who else sees it

Nobody, for any purpose of their own. Two companies process data on our behalf, under contracts that bind them to our instructions:

  • Supabase hosts the database, sign-in, and photo storage. This is where everything above lives.
  • Sentry receives a crash report when the app fails. A report carries what went wrong, the phone model and the app version — and nothing that identifies you. Personal data is switched off at the source; it never carries your email, your messages, photos or ratings.

We do not sell data, share it with advertisers, or hand it to anyone else — with the one exception the law makes: if a court or authority with the power to require it does so.

Where it lives

The database is hosted by Supabase in the United States (AWS, Virginia). For anyone in the EU, the UK, or Switzerland, that is a transfer outside your region. It is covered by the European Commission's Standard Contractual Clauses in our agreement with Supabase, which is the safeguard the GDPR requires for it. Crash reports, which identify nobody, are held by Sentry in the EU.


How the fences are built

Access rules live in the database, not in the app. Every table carries the group it belongs to, has row-level security enabled, and has its policies written in the same change that created it — so a screen cannot ask for something it should not have, even by mistake, and a bug in the interface cannot become a data leak.

  • Photos are private. Every image lives in a private bucket and is served through a short-lived signed link. There is no public URL to guess or share.
  • Nothing is publicly indexable. No public profiles, no discoverable groups, nothing for a search engine to reach.
  • Writes that must hold together are atomic — a card and the trust it costs are recorded as one operation, so a half-finished action cannot leave a wrong record behind.

Deleting your account

There is a Delete account button on your profile in the app. It does what it says, immediately, and it cannot be undone.

What goes:

  • Your login. You are signed out of every device.
  • Your email, name, photo, month and year of birth, and push token.
  • Every photo you uploaded, every post, comment, like and reaction.
  • Your chat messages are blanked — the space stays so the conversation still reads, but the words and photos are gone.
  • Any pending request to a parent or guardian.

What stays, and why:

  • The matches your groups played, with "Former player" where your name was. A match that happened, happened; the other ten people on the sheet have a legitimate interest in their own record of it (Article 17(3)).
  • Your ratings of others, and theirs of you, as anonymous numbers inside averages that can no longer be attributed to you.
  • Attendance, trust events and cards in the groups you were in, likewise anonymised. A no-show that happened still happened.

If you run a group that still has other people in it, the app asks you to hand it over or delete it first, so nobody is left with a group that has no owner.


Your rights

Under the GDPR — and we apply the same to everyone, wherever they are — you can ask us for:

  • A copy of what we hold about you, in a form you can take elsewhere.
  • A correction of anything wrong. Your name and photo you can change yourself, in the app.
  • Deletion, as above — the button in the app does it, or write to us.
  • A restriction on processing, or an objection to it, where the basis is our legitimate interest.

Write to info@halbreven.com from the address you signed in with. We answer within a month. You can also complain to a supervisory authority — in Kosovo the Information and Privacy Agency, in the EU the authority in your country — though we would rather hear it first.


Age

Halbreven's groups are for adults. We ask for your month and year of birth once, when you sign up, and the app refuses to let anyone under 18 create or join a group — the rule is enforced on the server, not in the interface, so it cannot be skipped. The one exception is a group run as a club team, which may admit a younger player only after a parent or guardian confirms by email. We do not knowingly hold an account for a child outside that arrangement; if you believe one exists, write to us and it will be removed.

Advertising

The app is free for players and always will be for anything that matters. A group may carry a sponsor — a local bar, a sports shop, the pitch it rents — shown to the group as a whole in a card, a post, and one message after a match. Sponsorship is never targeted using your ratings, your trust score or your attendance; those exist to pick fair teams, not to sell things. We count how many times a sponsor's card was shown to a group. We do not tell a sponsor who saw it.

Changes

If this page changes in a way that matters, the app will show you the new version and ask you to continue past it before you next use it. The version date at the top is the one you agreed to.