Your data, your game.
Tier is built for players who want to track their backlog, write reviews, and talk to friends. To keep the core app free, we now show a limited number of ads (banners and medium rectangles) through a consent-first advertising setup. This page explains exactly what we collect, why, who we share it with, and the control you have over it. Plain language, no dark patterns.
01 Identity of the data controller
Tier is a mobile application for video game tracking and social journaling. The data controller within the meaning of article 4(7) GDPR is a natural person established in Belgium:
- Publisher: Riccardo Accardi (independent / sole trader)
- Postal address: Chaussée de Mons 356, 1070 Brussels, Belgium
- Company number (CBE / VAT): BE1006414491
- Contact: contact@yourtier.com
- Mobile app: distributed on the Apple App Store and Google Play under the bundle identifier
com.yourtier.tier - Official website:
yourtier.com
Because the publisher is a natural person and the processing is not carried out on a large scale within the meaning of article 37 GDPR, the designation of a Data Protection Officer (DPO) is not mandatory. The single point of contact for any privacy-related request is contact@yourtier.com. We respond within one month (art. 12.3 GDPR), extendable by two further months for complex requests.
02 Data we collect
Only what is necessary to operate the app, grouped by purpose:
Account and identity (Odoo res.users / res.partner)
Profile (all fields optional, on res.partner)
- Display name, bio, pronouns, "gamer since" year
- Date of birth — used to verify the minimum age (13 years) and filter PEGI / ESRB-rated content. The raw date is never displayed publicly; only the computed age bracket may be shown if you enable it.
- Favourite genres and platforms
- Avatar and profile banner
- Social handles you enter: Twitter/X, Discord, Twitch, YouTube, Steam, Xbox Live, PSN, Nintendo. We only store the handles you enter — we do not call those platforms' APIs on your behalf.
- Profile visibility:
public,followers onlyorprivate.
Activity and content
- Journal entries (
tier.journal.entry) with one of four states: to play, playing, completed, abandoned. - Reviews (
tier.review) — text and a 1-10 rating. Reviews you publish are public by design. - Custom lists (8 types: favourites, wishlist, backlog, etc.).
- Social graph: follows (
tier.user.follow) and blocks (tier.user.block). - Notification history (
tier.notification) and gamification stats (XP, level, streaks).
Device and technical
- Expo push tokens (
tier.push_device) — only if you allow notifications. - Notification preferences and weekly digest opt-in (toggles in Settings).
- App preferences (theme, reduced motion).
- Authentication attempts (
tier.auth_attempt: IP, user-agent, outcome) — brute-force protection. - Rate-limit counters — per user / per IP, over short windows.
- Anonymised crash reports (Expo native reports) — unless you have disabled submission at the OS level.
- Crash and performance telemetry (Sentry) — when enabled, technical diagnostics of errors and app performance: stack trace, device model, OS and app version, and a breadcrumb trail of the screens and API paths visited. Stripped of content — no IP address, no cookies, no request bodies; only a stable account id is attached. Disabled by default.
- Usage events (
tier.usage.event) — pseudonymous records of which API endpoint was called, the HTTP method and status, the response time, the platform and app version, tied either to your account id or to a one-way SHA-256 hash of an anonymous identifier for signed-out visitors. No IP address and no request content are stored. Enabled by default to monitor service health and security (legitimate interest), retained 90 days.
Advertising data
When ads are enabled and — where required — after you have given consent, our advertising partners (see section 05) may process:
- A device advertising identifier — Apple's IDFA (iOS, only if you allow tracking via the App Tracking Transparency prompt) or Google's Advertising ID (Android), or a resettable equivalent.
- Ad-interaction and delivery data — which ads were requested, shown, viewed or clicked; frequency-capping signals; coarse, non-precise location inferred from IP; and general device / technical attributes (device model, OS version, language, network type) used to select and measure ads.
- On iOS, Apple's privacy-preserving SKAdNetwork postbacks are used to measure ad installs without identifying you individually.
We do NOT collect: your precise GPS location, your contacts, your calendar, your SMS or call logs, your microphone or camera feeds (the camera is only opened when you tap "take a new profile picture"), no health or biometric data, and no financial data.
03 Legal bases (GDPR art. 6)
| Purpose | Legal basis |
|---|---|
| Account creation and management | Performance of a contract — art. 6.1.b |
| Authentication, anti-fraud, rate-limiting | Legitimate interest — art. 6.1.f |
| Push notifications (friends, social, releases) | Consent — art. 6.1.a · per-channel toggle |
| Weekly email digest | Consent — unsubscribe at any time |
| Public profile, reviews, lists | Contract + your visibility choice |
| Moderation, judicial requests | Legal obligation — art. 6.1.c |
| Aggregated, anonymous product statistics | Legitimate interest — art. 6.1.f |
| Crash diagnostics and usage analytics (data-minimised) | Legitimate interest — art. 6.1.f |
| Personalised (interest-based) advertising | Consent — art. 6.1.a, collected via the in-app consent prompt; withdrawable at any time |
| Non-personalised ads, ad measurement and frequency capping | Consent and/or legitimate interest — art. 6.1.a / 6.1.f, depending on your choices and jurisdiction |
| Web audience measurement & advertising (yourtier.com — GA4, Meta Pixel / CAPI, AdSense) | Consent — art. 6.1.a, granted only when you accept optional cookies; withdrawable via the cookie banner / Cookie Policy toggle |
You can withdraw consent at any time without affecting the lawfulness of prior processing.
04 Purposes of processing
- Provide the core service — display your profile, journal, reviews and lists, and let you follow other players.
- Authenticate you — via email/password, Sign in with Apple or Sign in with Google. OAuth audience verification is enforced server-side.
- Personalise content — recommend games based on your favourites, history and trending scores.
- Send only the notifications you accepted — never others.
- Moderate the community — handle blocks, reports and violations.
- Protect the service — throttle abuse, detect credential stuffing.
- Comply with the law — respond to legal requests, keep evidence of deletions.
- Display and measure advertising — with your consent, show a limited number of banner / MREC ads and measure their delivery so the core app stays free (see section 05a).
We do not feed your personal data into any third-party AI training pipeline. No exceptions.
We do not sell your personal data for money in the ordinary sense. However, showing personalised ads involves sharing a device advertising identifier and ad-interaction data with our advertising partners, and some laws — notably California's CCPA/CPRA — define such cross-context behavioural advertising as a "sale" or "share". You can opt out at any time by refusing or withdrawing consent for personalised ads (see section 05a); you will still see non-personalised ads.
06 International transfers (GDPR chapter V)
The primary database is located in the European Union (host: Contabo GmbH, Munich, Germany). Where third parties process your data outside the EU, the transfers rely on one of the following safeguards from articles 44 to 49 GDPR:
| Recipient | Country | Safeguard |
|---|---|---|
| Apple Inc. (Sign in with Apple) | United States | EU-US Data Privacy Framework adequacy decision |
| Google LLC (Sign in with Google) | United States | EU-US Data Privacy Framework adequacy decision |
| Expo Inc. (push, EAS) | United States | EU-US DPF when certified, otherwise Standard Contractual Clauses (decision 2021/914) |
| Sentry / Functional Software, Inc. | United States | EU-US DPF when certified, otherwise SCCs — data-minimised diagnostics only (no IP / cookies / bodies) |
| Groq Inc. / OpenRouter (tier_ai) | United States | EU-US DPF when applicable / SCCs — and no personal data transmitted |
| Mistral AI (tier_ai) | France (EU) | Intra-EU processing, no transfer to a third country |
| Catalog APIs (third party game databases) | United States | Read-only from our backend with our own keys — no personal user data transmitted |
| Unity Technologies (LevelPlay / ironSource / Unity Ads) | United States & others | Standard Contractual Clauses; advertising data processed only per your consent choices |
| Google LLC (AdMob & ad technology providers) | United States | EU-US Data Privacy Framework when applicable, otherwise SCCs; advertising data per your consent choices |
| Google LLC (Google Analytics 4 & AdSense — web) | United States | EU-US Data Privacy Framework adequacy decision; only after cookie consent |
| Meta Platforms Ireland Ltd (Pixel & Conversions API — web) | Ireland (EU), onward to Meta Platforms, Inc. (US) | Intra-EU controller; onward US transfer under the EU-US Data Privacy Framework — only after cookie consent (email & user id SHA-256 hashed) |
A copy of the Standard Contractual Clauses signed with each US-based sub-processor can be obtained on request at contact@yourtier.com.
07 Retention periods
| Data | Retention |
|---|---|
| Account profile | Until account deletion. |
| Reviews, lists, journal, social graph | Until the item or the account is deleted. |
| Authentication attempts | 90 days, then deletion. |
| Rate-limit counters | Sliding window — minutes to hours. |
| Account-deletion audit log | Kept indefinitely and anonymised (only a short SHA-256 prefix of the former identifier is stored, as evidence that the deletion took place). |
| Moderation records | Duration of the applicable statute of limitations for the offence concerned. |
| Crash logs (Expo native) | 30 days. |
| Crash & performance telemetry (Sentry) | Sentry's default retention (typically 90 days), when enabled. |
Usage events (tier.usage.event) | 90 days, then deletion. |
| Advertising identifiers & ad-interaction logs | Retained by the advertising partners under their own policies (see section 05). On our side we keep only aggregated, non-identifying delivery metrics. |
| Web analytics & advertising cookies (GA4, Meta Pixel, AdSense) | Per the Cookie Policy and each provider's own policy; set only after consent. After you withdraw consent they are no longer used and expire on their own — you can also delete them at any time in your browser. |
08 Visibility of your content
You control who can see your profile and your content via the visibility setting:
- Public — anyone, including signed-out visitors, can see your profile, reviews and public lists.
- Followers only — visible only to users you follow back.
- Private — visible only to you.
Warning: anything you post in Public mode may be cached, screenshotted or quoted by other users. We cannot retroactively erase content that has been copied off-platform.
09 Your rights
Under the GDPR (and equivalent texts — UK GDPR, LGPD, CCPA / CPRA…), you can:
Access (art. 15)
Obtain a copy of the personal data we hold about you.
Rectification (art. 16)
Correct any inaccurate data — most fields are editable in Profile & Settings.
Erasure (art. 17)
Delete your account from the app (Settings → Account → Delete account).
Portability (art. 20)
You can request a full export of your personal data (profile, journal, reviews, lists, comments, follows) in a structured, commonly used and machine-readable format — JSON or CSV at your choice. Just email contact@yourtier.com from the address tied to your account. Reply within one month (art. 12.3 GDPR).
Restriction (art. 18)
Request the suspension of processing while a dispute is pending.
Objection (art. 21)
Object to processing based on legitimate interest.
Withdraw consent
Turn off notifications, the email digest and any optional feature at any time.
Opt out of personalised ads
Refuse or withdraw consent for personalised advertising at any time via Settings → Privacy → "Ad choices", without losing access to the app — you will still see non-personalised ads.
To exercise these rights, write to contact@yourtier.com from the address tied to your account. We may ask you to prove your identity before acting. Reply within one month (art. 12.3 GDPR).
Record of processing activities (art. 30 GDPR). In accordance with article 30 GDPR, we maintain a record of processing activities, available on request at contact@yourtier.com.
Right to lodge a complaint with the APD/GBA. If you believe that the processing of your personal data infringes the GDPR, you can lodge a complaint with the Belgian Data Protection Authority (APD/GBA — Autorité de Protection des Données / Gegevensbeschermingsautoriteit) — https://www.autoriteprotectiondonnees.be — or with the supervisory authority in your country of residence (art. 77 GDPR).
10 Minors
The minimum age to create a Tier account is 13 years old. We do not knowingly process personal data about children under 13 (or the higher equivalent local age of digital consent where applicable).
Belgium and the EU — digital age of consent (GDPR art. 8). In Belgium, the Act of 30 July 2018 (art. 7) sets the digital age of consent at 13. No additional parental authorisation is required for users aged 13 or above. In other EU Member States, the local threshold can be higher (up to 16 years); we apply the local threshold where applicable. Parents may at any time write to contact@yourtier.com to exercise the rights of access, rectification or erasure on behalf of their child.
Some games in the catalog carry a PEGI / ESRB rating. The "date of birth" field is used to verify the minimum age and to filter the display of rated content; the raw date is never displayed publicly.
In line with article 28 of the EU Digital Services Act (DSA), we never display targeted advertising based on profiling of minors.
If you believe a child signed up without appropriate consent, write to contact@yourtier.com and we will delete the account.
11 Security
- Passwords — slow, salted KDF hashing. Never stored or transmitted in clear text.
- HTTPS / TLS — enforced everywhere. End-to-end in-transit encryption.
- Encryption at rest — at the file-system / disk level on the hosting infrastructure.
- Multi-tier API access — public / user (portal) / internal / admin, with per-endpoint allow-lists.
- Anti brute-force —
tier.auth_attemptlog and rate-limit counters. - Row-level security via Odoo
ir.ruleconstraints — portal users can only read the allowed fields on other users. - OAuth audience verification server-side — client identifiers are public by design, the security boundary is audience verification.
- Account-deletion cool-down to prevent accidental or coerced deletions.
In the event of a personal data breach affecting you, we will notify both you and the APD/GBA within 72 hours, as required by article 33 GDPR.
12 Cookies and local storage
The mobile app does not use HTTP cookies. We use strictly necessary technical storage to keep you signed in and remember your preferences, and — only in line with your consent choices — advertising SDK storage to deliver, cap and measure ads:
- Secure storage (Keychain on iOS / Keystore on Android via
expo-secure-store) for authentication tokens. - AsyncStorage for non-sensitive preferences (theme, last visited tab, daily-prompt dismissal date).
- Advertising SDK storage and identifiers. The advertising SDK and its partners may store and access identifiers and similar technologies on your device to deliver, cap and measure ads — only in line with your consent choices (see section 05a).
- On
yourtier.com(web companion / legal pages), essential first-party cookies are always set for the session. Analytics cookies (Google Analytics 4) and advertising cookies (Meta Pixel, Google AdSense) are set only after you accept optional cookies in the cookie banner; you can withdraw consent at any time via the Cookie Policy toggle. See the Cookie Policy for the full cookie list (see also section 05b).
13 Push notifications and email
Push notifications are sent only when you have enabled the corresponding toggle (friends activity, social, releases). You can revoke notification permission at the OS level at any time (iOS Settings → Notifications → Tier; Android App info → Notifications).
The weekly email digest is opt-in. Turn it off in Settings or use the unsubscribe link present in every email.
14 Account deletion — what happens
- Your
res.usersrecord is archived; identifying fields onres.partner(email, gamer tag, bio, avatars, banner, social handles, date of birth, pronouns) are wiped or replaced with placeholder values. - A short SHA-256 prefix of your former identifier is written to the deletion audit log as evidence that the request was honoured. The original email is not retained.
- All your active sessions are revoked.
- Your reviews and lists are either deleted or anonymised so as not to orphan other users' interactions.
Account deletion is irreversible. We will not be able to recover your data afterwards.
15 Automated decision-making (GDPR art. 22)
Tier does not make decisions producing legal effects, or significantly affecting you, based solely on automated processing within the meaning of article 22 GDPR.
Content moderation combines 49 automated detection rules (spam, hate speech, prohibited content, coordinated inauthentic behaviour) with a human review queue. Sanctions (content removal, suspension, ban) are always reviewed and confirmed by a human moderator. You can appeal any decision by writing to contact@yourtier.com — reply within one month.
Recommendations (suggested games, users to follow) are based on your declared favourites and in-app activity. They are purely indicative and have no legal effect.
16 Changes to this policy
Material changes are announced in-app and by email at least 30 days before they take effect. The "Effective" date at the top of this page always reflects the current version. Continued use of the service after that date constitutes acceptance of the updated policy.
17 Contact
Publisher (data controller): Riccardo Accardi
Postal address: Chaussée de Mons 356, 1070 Brussels, Belgium
Company number (CBE / VAT): BE1006414491
Single point of contact: contact@yourtier.com
Official website: yourtier.com
If you believe your rights have not been respected, you can lodge a complaint with your supervisory authority. Belgian and EU residents can contact the APD/GBA — https://www.autoriteprotectiondonnees.be.
Got an unanswered question?
We read every email. Drop us a line — reply within one month, usually much sooner.