Skip to Content
Legal · Transparency

Your data, your game.

Tier is built for players who want to track their backlog, write reviews, and talk to friends. To keep the core app free, we now show a limited number of ads (banners and medium rectangles) through a consent-first advertising setup. This page explains exactly what we collect, why, who we share it with, and the control you have over it. Plain language, no dark patterns.

Effective July 21, 2026 GDPR · Belgian Act of 30/07/2018 Apple & Google compliant Ads shown with your consent

01 Identity of the data controller

Tier is a mobile application for video game tracking and social journaling. The data controller within the meaning of article 4(7) GDPR is a natural person established in Belgium:

  • Publisher: Riccardo Accardi (independent / sole trader)
  • Postal address: Chaussée de Mons 356, 1070 Brussels, Belgium
  • Company number (CBE / VAT): BE1006414491
  • Contact: contact@yourtier.com
  • Mobile app: distributed on the Apple App Store and Google Play under the bundle identifier com.yourtier.tier
  • Official website: yourtier.com

Because the publisher is a natural person and the processing is not carried out on a large scale within the meaning of article 37 GDPR, the designation of a Data Protection Officer (DPO) is not mandatory. The single point of contact for any privacy-related request is contact@yourtier.com. We respond within one month (art. 12.3 GDPR), extendable by two further months for complex requests.

02 Data we collect

Only what is necessary to operate the app, grouped by purpose:

Account and identity (Odoo res.users / res.partner)

Required
Username and email
For sign-in, account recovery and security alerts. Stored on res.users.
Required
Password
Stored as a salted KDF hash (never in clear text), following OWASP recommendations.
OAuth
Apple / Google identifier
Opaque token + verified email + display name if you use Sign in with Apple or Google. Apple relay emails are respected as provided.
Public
Gamer tag
Your in-app handle, stored on res.partner, distinct from your legal name.

Profile (all fields optional, on res.partner)

  • Display name, bio, pronouns, "gamer since" year
  • Date of birth — used to verify the minimum age (13 years) and filter PEGI / ESRB-rated content. The raw date is never displayed publicly; only the computed age bracket may be shown if you enable it.
  • Favourite genres and platforms
  • Avatar and profile banner
  • Social handles you enter: Twitter/X, Discord, Twitch, YouTube, Steam, Xbox Live, PSN, Nintendo. We only store the handles you enter — we do not call those platforms' APIs on your behalf.
  • Profile visibility: public, followers only or private.

Activity and content

  • Journal entries (tier.journal.entry) with one of four states: to play, playing, completed, abandoned.
  • Reviews (tier.review) — text and a 1-10 rating. Reviews you publish are public by design.
  • Custom lists (8 types: favourites, wishlist, backlog, etc.).
  • Social graph: follows (tier.user.follow) and blocks (tier.user.block).
  • Notification history (tier.notification) and gamification stats (XP, level, streaks).
To play Playing Completed Abandoned

Device and technical

  • Expo push tokens (tier.push_device) — only if you allow notifications.
  • Notification preferences and weekly digest opt-in (toggles in Settings).
  • App preferences (theme, reduced motion).
  • Authentication attempts (tier.auth_attempt: IP, user-agent, outcome) — brute-force protection.
  • Rate-limit counters — per user / per IP, over short windows.
  • Anonymised crash reports (Expo native reports) — unless you have disabled submission at the OS level.
  • Crash and performance telemetry (Sentry) — when enabled, technical diagnostics of errors and app performance: stack trace, device model, OS and app version, and a breadcrumb trail of the screens and API paths visited. Stripped of content — no IP address, no cookies, no request bodies; only a stable account id is attached. Disabled by default.
  • Usage events (tier.usage.event) — pseudonymous records of which API endpoint was called, the HTTP method and status, the response time, the platform and app version, tied either to your account id or to a one-way SHA-256 hash of an anonymous identifier for signed-out visitors. No IP address and no request content are stored. Enabled by default to monitor service health and security (legitimate interest), retained 90 days.

Advertising data

When ads are enabled and — where required — after you have given consent, our advertising partners (see section 05) may process:

  • A device advertising identifier — Apple's IDFA (iOS, only if you allow tracking via the App Tracking Transparency prompt) or Google's Advertising ID (Android), or a resettable equivalent.
  • Ad-interaction and delivery data — which ads were requested, shown, viewed or clicked; frequency-capping signals; coarse, non-precise location inferred from IP; and general device / technical attributes (device model, OS version, language, network type) used to select and measure ads.
  • On iOS, Apple's privacy-preserving SKAdNetwork postbacks are used to measure ad installs without identifying you individually.
x

We do NOT collect: your precise GPS location, your contacts, your calendar, your SMS or call logs, your microphone or camera feeds (the camera is only opened when you tap "take a new profile picture"), no health or biometric data, and no financial data.

03 Legal bases (GDPR art. 6)

PurposeLegal basis
Account creation and managementPerformance of a contract — art. 6.1.b
Authentication, anti-fraud, rate-limitingLegitimate interest — art. 6.1.f
Push notifications (friends, social, releases)Consent — art. 6.1.a · per-channel toggle
Weekly email digestConsent — unsubscribe at any time
Public profile, reviews, listsContract + your visibility choice
Moderation, judicial requestsLegal obligation — art. 6.1.c
Aggregated, anonymous product statisticsLegitimate interest — art. 6.1.f
Crash diagnostics and usage analytics (data-minimised)Legitimate interest — art. 6.1.f
Personalised (interest-based) advertisingConsent — art. 6.1.a, collected via the in-app consent prompt; withdrawable at any time
Non-personalised ads, ad measurement and frequency cappingConsent and/or legitimate interest — art. 6.1.a / 6.1.f, depending on your choices and jurisdiction
Web audience measurement & advertising (yourtier.com — GA4, Meta Pixel / CAPI, AdSense)Consent — art. 6.1.a, granted only when you accept optional cookies; withdrawable via the cookie banner / Cookie Policy toggle

You can withdraw consent at any time without affecting the lawfulness of prior processing.

04 Purposes of processing

  1. Provide the core service — display your profile, journal, reviews and lists, and let you follow other players.
  2. Authenticate you — via email/password, Sign in with Apple or Sign in with Google. OAuth audience verification is enforced server-side.
  3. Personalise content — recommend games based on your favourites, history and trending scores.
  4. Send only the notifications you accepted — never others.
  5. Moderate the community — handle blocks, reports and violations.
  6. Protect the service — throttle abuse, detect credential stuffing.
  7. Comply with the law — respond to legal requests, keep evidence of deletions.
  8. Display and measure advertising — with your consent, show a limited number of banner / MREC ads and measure their delivery so the core app stays free (see section 05a).
!

We do not feed your personal data into any third-party AI training pipeline. No exceptions.

We do not sell your personal data for money in the ordinary sense. However, showing personalised ads involves sharing a device advertising identifier and ad-interaction data with our advertising partners, and some laws — notably California's CCPA/CPRA — define such cross-context behavioural advertising as a "sale" or "share". You can opt out at any time by refusing or withdrawing consent for personalised ads (see section 05a); you will still see non-personalised ads.

05 Recipients and sub-processors

Authentication providers

  • Apple — Sign in with Apple. We receive an opaque identifier, optionally your name and an email (real or relay).
  • Google — OAuth. We receive your sub, your verified email and basic profile info.

Game databases

We call these APIs from our backend using our own keys. Your identity is never transmitted.

Catalog
Game databases
Metadata, cover art.
Catalog
Steam
Releases & platform info.

Infrastructure and sub-processors

  • Backend host — Odoo 19 + PostgreSQL, hosted at Contabo GmbH, Welfenstrasse 22, 81541 Munich, Germany (EU). Primary storage.
  • Expo Inc. (United States) — Expo push relay (exp.host) and EAS build / OTA pipeline. Processes Expo push tokens and anonymised channel pings.
  • Sentry / Functional Software, Inc. (United States) — crash and performance telemetry, when enabled. Receives the minimised diagnostic data described in section 02 (no IP, no cookies, no request bodies; account id only). Disabled by default.
  • Apple App Store and Google Play — binary distribution and delivery.

LLM providers (tier_ai module, content enrichment only)

Used solely to enrich the public game catalog (mood, difficulty, facts about proper nouns). No personal data is sent to these providers — only public game titles and metadata.

  • Mistral AI (France) — no transfer outside the EU.
  • Groq Inc. (United States) — EU-US Data Privacy Framework when applicable, otherwise Standard Contractual Clauses.
  • OpenRouter (United States) — EU-US DPF when applicable, otherwise SCCs.

Advertising & mediation partners

To show ads, Tier integrates the Unity LevelPlay mediation SDK (formerly ironSource, a Unity company). LevelPlay routes each ad request to advertising networks that compete to fill it. The networks currently enabled are:

  • Unity LevelPlay / ironSource (mediation and demand) — Unity Technologies.
  • Google AdMob (demand, via bidding) — Google LLC. AdMob and its ad technology providers may process data as described in Google's policies. The current list of ad partners that may receive data is published at https://support.google.com/admob/answer/9012903.
  • Unity Ads (demand) — Unity Technologies.

We may add further networks in the future; when we do, they will be covered by the same in-app consent flow and this policy will be updated. These partners may act as independent controllers for the advertising data they receive.

05a — Advertising & monetization

  • What ads look like. Only banner and medium-rectangle (MREC) ad formats. No full-screen interstitials and no rewarded video at this time.
  • Consent first (EEA / UK / Switzerland). On first launch (and on request) we show a Google-certified consent message (Google User Messaging Platform, based on the IAB Transparency & Consent Framework). You can Consent, Manage options, or refuse. Your choice controls whether ads are personalised or non-personalised.
  • iOS App Tracking Transparency. On iOS, if personalised advertising is offered, the system App Tracking Transparency prompt may appear asking whether Tier can access the IDFA. If you decline, we do not use the IDFA and ads are non-personalised / measured only via SKAdNetwork.
  • SKAdNetwork. On iOS, install and conversion measurement uses Apple's privacy-preserving SKAdNetwork, which does not identify you individually.
  • How to change your mind. You can re-open the consent choices at any time in Settings → Privacy → "Ad choices", reset your advertising identifier in your device settings, or, on iOS, change tracking permission in iOS Settings → Privacy & Security → Tracking.
  • Children. Ad requests are configured as "not directed to children" and confirmed minors always receive non-personalised ads. The app is not intended for users under 13 (or under the applicable EU digital-consent age).
i

No cross-app tracking beyond advertising. Outside the advertising setup described above, we do not track your activity across other companies' apps or websites. In line with article 28 of the DSA, we never display advertising based on profiling of minors — confirmed minors only ever receive non-personalised ads.

05b — Web analytics & advertising (yourtier.com)

Our website yourtier.com (public pages, legal pages and the web companion) uses third-party analytics and advertising in addition to the mobile setup above. They are all off by default and only activate after you accept optional cookies in the cookie banner. The full cookie list is in the Cookie Policy.

  • Google Analytics 4 (measurement id G-81Z6KRF8XY) — audience measurement and product statistics. Sets the _ga and _ga_* cookies. A server-side Measurement Protocol sender also forwards key events (sign-up, affiliate click) to GA4; for signed-in users these server-side events include your internal user id. It is fail-closed — it only sends when optional-cookie consent is granted and the _ga cookie exists. Recipient: Google Ireland Ltd / Google LLC.
  • Meta (Facebook) Pixel (id 1005971575645752) — measures and attributes ad conversions for our marketing. Loaded with consent revoked by default; it only runs after you accept optional cookies. Sets the _fbp cookie (and _fbc if you arrive via a Meta ad click). A server-side Conversions API additionally sends a small set of key events (registration, affiliate click) directly from our server; the same fail-closed consent gate applies. In those server events your email and user id are hashed with SHA-256 before being sent; your IP address and browser user agent are transmitted as Meta's standard matching keys. Recipient: Meta Platforms Ireland Ltd.
  • Google AdSense (Auto Ads) (publisher ca-pub-8020007711100279) — shows ads on quality-gated public pages so the service stays free. It honours Google Consent Mode signals: while consent is denied, ads are limited / non-personalised. Recipient: Google Ireland Ltd / Google LLC.

Legal basis: consent (art. 6.1.a GDPR) for all of the above. Consent is denied by default (Google Consent Mode v2 signals set to "denied", Meta Pixel set to "revoke") and is granted only when you accept optional cookies. You can withdraw your consent at any time using the cookie banner ("Only essentials" / "I agree") or the re-consent toggle on the Cookie Policy page, which works both ways (grant and revoke).

06 International transfers (GDPR chapter V)

The primary database is located in the European Union (host: Contabo GmbH, Munich, Germany). Where third parties process your data outside the EU, the transfers rely on one of the following safeguards from articles 44 to 49 GDPR:

RecipientCountrySafeguard
Apple Inc. (Sign in with Apple)United StatesEU-US Data Privacy Framework adequacy decision
Google LLC (Sign in with Google)United StatesEU-US Data Privacy Framework adequacy decision
Expo Inc. (push, EAS)United StatesEU-US DPF when certified, otherwise Standard Contractual Clauses (decision 2021/914)
Sentry / Functional Software, Inc.United StatesEU-US DPF when certified, otherwise SCCs — data-minimised diagnostics only (no IP / cookies / bodies)
Groq Inc. / OpenRouter (tier_ai)United StatesEU-US DPF when applicable / SCCs — and no personal data transmitted
Mistral AI (tier_ai)France (EU)Intra-EU processing, no transfer to a third country
Catalog APIs (third party game databases)United StatesRead-only from our backend with our own keys — no personal user data transmitted
Unity Technologies (LevelPlay / ironSource / Unity Ads)United States & othersStandard Contractual Clauses; advertising data processed only per your consent choices
Google LLC (AdMob & ad technology providers)United StatesEU-US Data Privacy Framework when applicable, otherwise SCCs; advertising data per your consent choices
Google LLC (Google Analytics 4 & AdSense — web)United StatesEU-US Data Privacy Framework adequacy decision; only after cookie consent
Meta Platforms Ireland Ltd (Pixel & Conversions API — web)Ireland (EU), onward to Meta Platforms, Inc. (US)Intra-EU controller; onward US transfer under the EU-US Data Privacy Framework — only after cookie consent (email & user id SHA-256 hashed)

A copy of the Standard Contractual Clauses signed with each US-based sub-processor can be obtained on request at contact@yourtier.com.

07 Retention periods

DataRetention
Account profileUntil account deletion.
Reviews, lists, journal, social graphUntil the item or the account is deleted.
Authentication attempts90 days, then deletion.
Rate-limit countersSliding window — minutes to hours.
Account-deletion audit logKept indefinitely and anonymised (only a short SHA-256 prefix of the former identifier is stored, as evidence that the deletion took place).
Moderation recordsDuration of the applicable statute of limitations for the offence concerned.
Crash logs (Expo native)30 days.
Crash & performance telemetry (Sentry)Sentry's default retention (typically 90 days), when enabled.
Usage events (tier.usage.event)90 days, then deletion.
Advertising identifiers & ad-interaction logsRetained by the advertising partners under their own policies (see section 05). On our side we keep only aggregated, non-identifying delivery metrics.
Web analytics & advertising cookies (GA4, Meta Pixel, AdSense)Per the Cookie Policy and each provider's own policy; set only after consent. After you withdraw consent they are no longer used and expire on their own — you can also delete them at any time in your browser.

08 Visibility of your content

You control who can see your profile and your content via the visibility setting:

  • Public — anyone, including signed-out visitors, can see your profile, reviews and public lists.
  • Followers only — visible only to users you follow back.
  • Private — visible only to you.
!

Warning: anything you post in Public mode may be cached, screenshotted or quoted by other users. We cannot retroactively erase content that has been copied off-platform.

09 Your rights

Under the GDPR (and equivalent texts — UK GDPR, LGPD, CCPA / CPRA…), you can:

Access (art. 15)

Obtain a copy of the personal data we hold about you.

Rectification (art. 16)

Correct any inaccurate data — most fields are editable in Profile & Settings.

Erasure (art. 17)

Delete your account from the app (Settings → Account → Delete account).

Portability (art. 20)

You can request a full export of your personal data (profile, journal, reviews, lists, comments, follows) in a structured, commonly used and machine-readable format — JSON or CSV at your choice. Just email contact@yourtier.com from the address tied to your account. Reply within one month (art. 12.3 GDPR).

Restriction (art. 18)

Request the suspension of processing while a dispute is pending.

Objection (art. 21)

Object to processing based on legitimate interest.

Withdraw consent

Turn off notifications, the email digest and any optional feature at any time.

Opt out of personalised ads

Refuse or withdraw consent for personalised advertising at any time via Settings → Privacy → "Ad choices", without losing access to the app — you will still see non-personalised ads.

To exercise these rights, write to contact@yourtier.com from the address tied to your account. We may ask you to prove your identity before acting. Reply within one month (art. 12.3 GDPR).

Record of processing activities (art. 30 GDPR). In accordance with article 30 GDPR, we maintain a record of processing activities, available on request at contact@yourtier.com.

!

Right to lodge a complaint with the APD/GBA. If you believe that the processing of your personal data infringes the GDPR, you can lodge a complaint with the Belgian Data Protection Authority (APD/GBA — Autorité de Protection des Données / Gegevensbeschermingsautoriteit) — https://www.autoriteprotectiondonnees.be — or with the supervisory authority in your country of residence (art. 77 GDPR).

10 Minors

The minimum age to create a Tier account is 13 years old. We do not knowingly process personal data about children under 13 (or the higher equivalent local age of digital consent where applicable).

Belgium and the EU — digital age of consent (GDPR art. 8). In Belgium, the Act of 30 July 2018 (art. 7) sets the digital age of consent at 13. No additional parental authorisation is required for users aged 13 or above. In other EU Member States, the local threshold can be higher (up to 16 years); we apply the local threshold where applicable. Parents may at any time write to contact@yourtier.com to exercise the rights of access, rectification or erasure on behalf of their child.

Some games in the catalog carry a PEGI / ESRB rating. The "date of birth" field is used to verify the minimum age and to filter the display of rated content; the raw date is never displayed publicly.

In line with article 28 of the EU Digital Services Act (DSA), we never display targeted advertising based on profiling of minors.

If you believe a child signed up without appropriate consent, write to contact@yourtier.com and we will delete the account.

11 Security

  • Passwords — slow, salted KDF hashing. Never stored or transmitted in clear text.
  • HTTPS / TLS — enforced everywhere. End-to-end in-transit encryption.
  • Encryption at rest — at the file-system / disk level on the hosting infrastructure.
  • Multi-tier API access — public / user (portal) / internal / admin, with per-endpoint allow-lists.
  • Anti brute-forcetier.auth_attempt log and rate-limit counters.
  • Row-level security via Odoo ir.rule constraints — portal users can only read the allowed fields on other users.
  • OAuth audience verification server-side — client identifiers are public by design, the security boundary is audience verification.
  • Account-deletion cool-down to prevent accidental or coerced deletions.
i

In the event of a personal data breach affecting you, we will notify both you and the APD/GBA within 72 hours, as required by article 33 GDPR.

12 Cookies and local storage

The mobile app does not use HTTP cookies. We use strictly necessary technical storage to keep you signed in and remember your preferences, and — only in line with your consent choices — advertising SDK storage to deliver, cap and measure ads:

  • Secure storage (Keychain on iOS / Keystore on Android via expo-secure-store) for authentication tokens.
  • AsyncStorage for non-sensitive preferences (theme, last visited tab, daily-prompt dismissal date).
  • Advertising SDK storage and identifiers. The advertising SDK and its partners may store and access identifiers and similar technologies on your device to deliver, cap and measure ads — only in line with your consent choices (see section 05a).
  • On yourtier.com (web companion / legal pages), essential first-party cookies are always set for the session. Analytics cookies (Google Analytics 4) and advertising cookies (Meta Pixel, Google AdSense) are set only after you accept optional cookies in the cookie banner; you can withdraw consent at any time via the Cookie Policy toggle. See the Cookie Policy for the full cookie list (see also section 05b).

13 Push notifications and email

Push notifications are sent only when you have enabled the corresponding toggle (friends activity, social, releases). You can revoke notification permission at the OS level at any time (iOS Settings → Notifications → Tier; Android App info → Notifications).

The weekly email digest is opt-in. Turn it off in Settings or use the unsubscribe link present in every email.

14 Account deletion — what happens

  1. Your res.users record is archived; identifying fields on res.partner (email, gamer tag, bio, avatars, banner, social handles, date of birth, pronouns) are wiped or replaced with placeholder values.
  2. A short SHA-256 prefix of your former identifier is written to the deletion audit log as evidence that the request was honoured. The original email is not retained.
  3. All your active sessions are revoked.
  4. Your reviews and lists are either deleted or anonymised so as not to orphan other users' interactions.
!

Account deletion is irreversible. We will not be able to recover your data afterwards.

15 Automated decision-making (GDPR art. 22)

Tier does not make decisions producing legal effects, or significantly affecting you, based solely on automated processing within the meaning of article 22 GDPR.

Content moderation combines 49 automated detection rules (spam, hate speech, prohibited content, coordinated inauthentic behaviour) with a human review queue. Sanctions (content removal, suspension, ban) are always reviewed and confirmed by a human moderator. You can appeal any decision by writing to contact@yourtier.com — reply within one month.

Recommendations (suggested games, users to follow) are based on your declared favourites and in-app activity. They are purely indicative and have no legal effect.

16 Changes to this policy

Material changes are announced in-app and by email at least 30 days before they take effect. The "Effective" date at the top of this page always reflects the current version. Continued use of the service after that date constitutes acceptance of the updated policy.

17 Contact

Publisher (data controller): Riccardo Accardi
Postal address: Chaussée de Mons 356, 1070 Brussels, Belgium
Company number (CBE / VAT): BE1006414491
Single point of contact: contact@yourtier.com
Official website: yourtier.com

If you believe your rights have not been respected, you can lodge a complaint with your supervisory authority. Belgian and EU residents can contact the APD/GBAhttps://www.autoriteprotectiondonnees.be.

Got an unanswered question?

We read every email. Drop us a line — reply within one month, usually much sooner.

Contact us →