Subjective Club
Privacy Policy
1. Controller and scope
1.1 Subjective Club is operated by the individual identified in Controller identity and contact details (Section 14), who is the controller responsible for the personal-data processing described in this Privacy Policy (the Policy). References to we, us and our mean that individual.
1.2 This Policy covers the Subjective Club Android application (the App), the website at subjectiveclub.com and associated account, content, support and community features (the Service). It applies to users, website visitors, reporters and other people whose personal data we receive in connection with the Service.
1.3 This is a privacy notice, not a request to consent to all processing. Agreement to the Terms of Service, the content licence or this Policy does not replace a lawful basis under the General Data Protection Regulation (GDPR). In particular, optional analytics requires the separate choice described in Section 5.
1.4 This version applies from its publication to the processing it describes. It does not retroactively authorise processing. Material changes are addressed in Section 13.
2. Personal data, sources and necessity
2.1 Account and authentication data. When you register or sign in, we and our authentication provider process your email address, account identifier, authentication credentials and verification information, session tokens, account status and relevant security records. Password-based authentication and email verification are handled through Supabase. We also keep records of acceptance of applicable contractual documents and, where applicable, separate consent choices.
2.2 Profile and preferences. These include your username, display name, biography, avatar, current and historical username identifiers, profile visibility, interface and content-language preferences, and your declaration that you meet the adult age requirement. Registration does not request or store your date of birth. Choosing a pseudonym does not necessarily make your activity anonymous.
2.3 Content and participation. We process the Bingo cards, This or That options and selections, comments and other material you submit, including titles, descriptions, cells, images where the feature supports them, and associated identifiers, authorship, timestamps, visibility and version history. We also process participation, progress, completion and saved-content records, blocking relationships, and related interactions. Some version snapshots are retained to keep existing completions and shared records consistent.
2.4 Reports, moderation and correspondence. We process the reporting and reported account or content identifiers, material relevant to a report, decisions and related correspondence. If you contact us, the information includes your contact details, request, attachments and any information reasonably needed to respond, verify authority, investigate abuse or deal with a claim. Ordinary in-app reports may contain only identifiers; fuller information may be supplied by email.
2.5 Technical and request data. Operating the Service involves processing IP addresses, request times, requested resources and submitted search queries, device and browser information, App and operating-system versions, language, authentication and access events, error information, and relevant server or security logs. Not every field is retained for every request. Providers may process connection and operational data when delivering their services.
2.6 Notifications. We process Firebase installation identifiers linked to an account and platform, registration timestamps, notification preferences and notification delivery records. Notification payloads can contain Bingo and completion identifiers, a Bingo title and, where applicable, the public display name of the person whose activity triggered the notification. A notification may be visible on a device's lock screen depending on your settings.
2.7 Optional analytics. If you choose to enable analytics, Google Analytics for Firebase processes App-instance or similar pseudonymous identifiers, device and App information, interaction and event data, timestamps and approximate geographic information derived from technical data. Custom events describe feature use, such as an authentication method, content type, visibility or completion state. We do not intentionally put email addresses, usernames, user-written content or content identifiers in custom analytics parameters. Pseudonymous analytics data is not necessarily anonymous.
2.8 Camera, selected images and local storage. If you use an image feature, the App accesses images you select or capture through the relevant device controls and uploads the chosen material as needed for that feature. It does not require access to your contacts, microphone or precise device location for its current features. Local storage is used for sessions, settings, caches and App operation. The website account-deletion session is held in page memory rather than deliberately persisted by that flow in browser storage.
2.9 Sources other than you. Information may come from another user's submission, report or interaction; an authentication or infrastructure provider; a representative acting for you; or a competent authority. We do not acquire account profiles from data brokers. Where data about you is obtained indirectly, we will provide any additional notice required by Article 14 GDPR, subject to its applicable exceptions.
2.10 Required and optional information. An email address, credentials or verification, required profile information and confirmation of adult eligibility are needed to create and operate an account. Without the required data we cannot provide the relevant account feature. A biography, avatar, content submission and analytics consent are optional. Refusing optional analytics does not prevent use of the core Service. Failure to provide sufficient identifying information for a particular request may prevent us from safely fulfilling that request.
3. Purposes and legal bases
3.1 Performance of the contract - Article 6(1)(b) GDPR. We process data objectively necessary to register and authenticate you; maintain your account and chosen settings; store and deliver content at your request; provide participation, progress and completion functions; deliver requested service notifications in accordance with your notification choices; and respond to requests necessary to provide the contracted Service. Merely referring to an activity in the Terms does not make all related processing necessary for the contract.
3.2 Legitimate interests - Article 6(1)(f) GDPR. Where your interests and fundamental rights do not override them, we process proportionate data to protect accounts and infrastructure; prevent fraud, impersonation, spam and circumvention; administer community rules and non-statutory moderation; diagnose faults; manage non-contractual correspondence; preserve the integrity of existing shared records; and establish, exercise or defend legal claims. The relevant interests are safe and reliable operation, protection of users and rightsholders, prevention of misuse and protection of lawful rights. Historical usernames and limited deletion markers may be used for these purposes only while necessary. You may object as described in Section 11.
3.3 Legal obligations - Article 6(1)(c) GDPR. We process data where necessary to comply with applicable obligations, including data-subject requests, legally required consumer-complaint records, valid authority orders, and applicable duties concerning illegal-content notices, reasons for restrictions and reporting serious offences under the Digital Services Act. We do not treat a private commercial preference as a legal obligation.
3.4 Consent - Article 6(1)(a) GDPR and applicable device-access rules. Optional analytics is based on your separate consent. Where we request another optional use that requires consent, we will identify its purpose at the time and allow the required choice. A device permission for notifications or a camera is not consent to unrelated analytics, advertising or disclosure.
3.5 Vital interests - Article 6(1)(d) GDPR. In an exceptional situation involving a credible threat to someone's life or physical safety, necessary information may be used or disclosed to protect vital interests, where the legal conditions are met.
3.6 Special-category and criminal-offence information. The Service does not require sensitive information such as health data, sexual orientation, religious beliefs or political opinions. Do not submit it about another person without a lawful basis and necessary permissions. If such data is incidentally received, an Article 6 basis alone is insufficient: processing also requires an applicable Article 9 condition, for example information you have manifestly made public yourself or processing necessary for legal claims. These exceptions are applied narrowly. A private or unlisted submission is not treated as manifestly public merely because it was uploaded. Criminal-offence data is processed only where Article 10 and applicable law permit it. Material that cannot lawfully be processed must be restricted, removed or otherwise handled as the law requires.
3.7 Content licensing, promotion and future features. The content licence in the Terms concerns intellectual-property rights. It does not authorise arbitrary personal-data use. Private content will not be made public for promotion merely because a broad copyright licence exists. We do not currently use User Content to train a general-purpose artificial-intelligence model or sell personal data. Before introducing a new promotional, model-training or other purpose involving personal data, we must establish the applicable legal basis, give the required information and obtain consent where necessary.
3.8 Automated decisions. We do not make decisions based solely on automated processing that produce legal or similarly significant effects within Article 22 GDPR. Technical access and filtering rules affect content availability, and discovery takes account of content language, publication recency, visibility, status, blocks and reports. These are not a representation that the Service performs automated psychological or behavioural profiling.
4. Visibility and disclosure to other users
4.1 Public by default. New profiles default to public visibility. Public content and profile information may be visible to other users and, through supported public pages or links, to people without an account. Public information can be copied, quoted, indexed or redistributed by recipients.
4.2 Private profiles are not anonymous accounts. A private profile restricts access to some profile activity and counts, but basic profile information, including its identifier, username or display name, biography and avatar, may remain accessible to signed-in users who are not blocked. Separately public content may still appear with author information even when the author's profile is private.
4.3 Avatar addresses. Avatars are served using public storage addresses. A person with an avatar URL may be able to view the image independently of the profile's visibility setting. Do not use an avatar that you need to keep confidential.
4.4 Unlisted content. An unlisted link is an access mechanism, not a confidentiality guarantee. Anyone obtaining a valid link may be able to open and forward it. Revocation restricts subsequent access through that link but cannot recall screenshots, downloaded material or information already received.
4.5 Shared and completed content. Visibility changes, edits or account deletion do not necessarily erase another user's eligible completion record or an existing content-version snapshot. Account deletion detaches authorship and archives authored content as explained in Section 9. A remaining text or image can still identify a person even when displayed under “Deleted user.”
4.6 Operator access. Restricted visibility does not prevent authorised access where necessary to operate the Service, investigate a report, maintain security or comply with law. Recipients' independent misuse is not authorised by this Policy. It does not remove our own security, erasure or other legal duties.
5. Optional analytics, notifications and device choices
5.1 Analytics choice. Firebase Analytics is optional and is enabled only after you give affirmative consent through the analytics choice presented in the App. Refusal is available without losing core Service access. No non-essential analytics collection is authorised before that choice, and declining or withdrawing consent must not cause equivalent analytics to be sent under another label.
5.2 Withdrawal. You can change the analytics choice through the App's privacy or analytics controls at any time, as easily as you gave it. You may also contact us. Withdrawal stops future consent-based collection and does not affect the lawfulness of earlier processing. We erase or anonymise existing personal data when no other lawful basis justifies its retention. You may also exercise the erasure right separately.
5.3 Analytics scope. Analytics is used to understand feature adoption and improve the App. Advertising-ID collection and advertising-personalisation signals are disabled in the App's configuration. We do not use this consent for personalised advertising, cross-service advertising audiences or uploading the text of your content to analytics. Google Analytics for Firebase has processing terms separate from Firebase Cloud Messaging.
5.4 Notifications. You may control notification display through Android settings and relevant App preferences. Installation registration and service-side delivery records are distinct from permission to display a notification: disabling display does not itself delete the Firebase installation identifier or all related records. Contact us to exercise applicable deletion or objection rights.
5.5 Website and necessary storage. Authentication, security, delivering requested pages and remembering necessary choices may involve cookies, tokens, local storage or comparable technologies. This Policy does not describe all infrastructure as cookie-free. Any non-essential website analytics or tracking would require its own appropriate notice and consent before activation; App analytics consent does not automatically cover website tracking.
5.6 Consent records. We retain proportionate records of the choice, notice version and relevant time to respect your preferences and demonstrate compliance. Consent records are not permission to continue the activity after withdrawal.
6. Recipients and service providers
6.1 Personal data is disclosed only for the purposes described in this Policy and with an applicable legal basis. Relevant recipients include:
(a) Supabase, for authentication, the application database, storage and related infrastructure;
(b) Render, for backend hosting and operational infrastructure;
(c) Google Firebase Cloud Messaging, for installation-based notification delivery, and Google Analytics for Firebase, separately, when analytics is enabled with consent;
(d) OpenAI Sites, for website hosting, with Cloudflare and other authorised infrastructure subprocessors used in that hosting arrangement;
(e) authorised support or moderation personnel and providers handling email, communications, security or professional advice, where needed for those functions;
(f) other users or members of the public according to Section 4; and
(g) competent authorities, courts, rightsholders or other parties where a particular disclosure is necessary and lawful for a notice, investigation, legal duty, claim or protection of rights.
6.2 Providers acting as processors must process data under applicable processing arrangements and instructions. Some providers may act separately as controllers for their own account, security, billing or legally required processing; their applicable notices address that separate role. A provider's notice does not replace our responsibilities for our own processing.
6.3 If the Service or relevant assets are transferred, necessary data may be disclosed to advisers and a prospective or actual successor under appropriate confidentiality and data-protection safeguards. A transfer does not authorise unrestricted new purposes. We will provide required information about a change of controller or processing.
6.4 We do not sell personal data or share it for cross-context behavioural advertising. Disclosure to a hosting, authentication, messaging or consent-based analytics provider is for the stated service purposes, not an unlimited right to use the data.
7. International processing and safeguards
7.1 We are based in Hungary. Providers and their authorised subprocessors operate internationally. Personal data may be stored or accessed outside the European Economic Area (EEA), including in the United States and Singapore, for the hosting, authentication, messaging, analytics, security and support purposes described here. Selecting a European primary hosting region does not necessarily prevent support access, operational processing or onward transfers outside that region.
7.2 Some destination countries, including Singapore, are not covered by a European Commission adequacy decision. The United States adequacy decision applies only to transfers covered by the EU-US Data Privacy Framework to participating organisations. Before permitting a transfer not covered by an applicable adequacy decision, we require the recipient to be bound by the applicable European Commission Standard Contractual Clauses and apply supplementary measures where required. Optional analytics consent is not used as a blanket waiver of these safeguards or as permission for routine transfers without them.
7.3 The providers' published arrangements describe the available safeguards and subprocessors: Supabase's Data Processing Addendum, Render's Data Processing Addendum, Firebase's Data Processing and Security Terms, Google Analytics data-processing terms, and the ChatGPT Sites Data Processing Addendum. The mechanism for a particular transfer depends on the applicable provider agreement, recipient and destination, not merely the provider's brand or the location of its headquarters.
7.4 You may contact support@subjectiveclub.com for information about the recipients, countries and safeguards applicable to your data, or a copy of the relevant safeguards. Redactions will be limited to what is necessary and lawful to protect confidential information, security or the rights of others; they will not be used to withhold information you are entitled to receive.
8. Retention
8.1 Data is retained only for the relevant purpose and applicable legal requirements, not simply because storage is available. Unless a specific period is stated below, the period is determined by the account or record's continuing function, whether a security issue or dispute remains live, the applicable legal retention or limitation period, and whether the purpose can be achieved with less data.
8.2 Accounts and active content. Account and profile data is normally kept while the account remains active. Content, progress and participation records are retained to provide the features you use. Account closure triggers the process in Section 9; it is not a representation that every associated copy is immediately destroyed.
8.3 Content versions and shared records. Active and referenced content versions may remain while needed for a valid current content or completion record. Older, unreferenced versions are compacted through the content-version process; it is not an immediate erasure operation for every edit. A retention need for a version does not justify keeping unnecessary identifying information within it.
8.4 Deletion markers and aliases. Limited deletion records include the former account identifier, a one-way hash of the normalised email address and current or historical usernames. These records are pseudonymous personal data, not automatically anonymous. They do not have a fixed automatic expiry in the account-deletion process. Retention is limited to a continuing, demonstrable need to prevent impersonation or restriction evasion, preserve necessary reference integrity or address a specific legal claim; records must be removed or further minimised when that need ends. Keeping a username reference does not justify retaining an entire deleted profile.
8.5 Reports, security and legal records. Reports and investigation material are kept while an issue and any necessary review or associated claim remain unresolved, and for a further period only where justified by an applicable legal duty or limitation period. Routine technical logs are limited to what is necessary for security, troubleshooting and reliable operation. Evidence subject to a valid preservation requirement may be held longer with restricted use.
8.6 Consumer complaints. Where Hungarian consumer-complaint rules apply, the complaint and our substantive response are retained for three years. Other correspondence is kept for the period needed to resolve the matter and any properly justified related claim.
8.7 Analytics. The retention setting for identifiable or pseudonymous user-level and event-level Analytics data is two months, without extending user-level retention merely because of new activity. Google's deletion processing may take additional time under its documented schedule. This limit does not apply to genuinely anonymous aggregate statistics that no longer identify a person. A different provider security or legal record requires its own retention justification; it is not an extension of optional analytics by default.
8.8 Notification and infrastructure copies. Our account-linked push registration and delivery records are removed through account deletion, subject to a specific lawful preservation need. Deleting our database row is distinct from deleting a provider's installation record. Firebase states that installation identifiers remain until deletion is requested through its API and that removal from its live and backup systems can then take up to 180 days; see Firebase's retention information. Other provider logs and backups follow the applicable processing arrangements and deletion cycles. A backup may not be immediately editable, but is not a basis for renewed ordinary use of erased data.
8.9 You may ask us about the period or criteria applicable to a particular record and exercise the rights below. Retention exceptions are assessed for the data and purpose concerned; they are not a licence to keep every deleted account indefinitely.
9. Account deletion and removal of content
9.1 You may request account deletion in the App or through the account-deletion page. You may also contact support@subjectiveclub.com, including if you cannot use those controls. Proportionate identity verification may be required.
9.2 The account-deletion process removes the authentication account, profile and avatar objects, and account-linked progress, participation, completion and preference records. Authored content is archived, active share links are revoked and its direct author-account association is removed. Attribution may appear as “Deleted user.” Other people's retained completion records and related version snapshots may remain.
9.3 Archiving and detached attribution do not necessarily erase personal data inside a title, description, image or other contribution. If retained content still identifies you or another person, it remains subject to data-protection law. Please identify the affected material when asking for erasure so that we can assess it specifically.
9.4 Limited records described in Section 8 may remain only with an applicable justification. Statutory restrictions on further use and rights to retrieve qualifying non-personal content following consumer withdrawal or termination also apply, as explained in the Terms of Service.
9.5 Deleting the App, closing a browser, making a profile private, deleting an account and withdrawing analytics consent are different actions. Independently copied public material may remain with third parties. We will take any steps required of us by law concerning recipients or public copies; this Policy does not promise that all independent copies can be recalled.
10. Security
10.1 We use technical and organisational measures appropriate to the processing and risk, including authenticated access, access restrictions and protected communications. Authorised access must be limited to the relevant function. You should protect your credentials and device, install necessary security updates and promptly report suspected compromise.
10.2 No online service can guarantee absolute security. This statement does not waive our duty to provide appropriate security, assess incidents, or notify a supervisory authority or affected people where the GDPR requires it. The Service is not intended as secure confidential storage.
11. Your rights and how to exercise them
11.1 Subject to the applicable conditions and exceptions, you may request access to your personal data and a copy; correction of inaccurate or incomplete data; erasure; restriction of processing; and portability of data you provided that is processed by automated means on consent or contract grounds.
11.2 Right to object. You may object at any time, on grounds relating to your particular situation, to processing based on legitimate interests. We will stop that processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or processing is needed for legal claims. If personal data is ever processed for direct marketing, objection to that marketing is unconditional.
11.3 You may withdraw consent at any time without affecting earlier lawful processing. Where applicable, you may exercise protections relating to solely automated decisions producing legal or similarly significant effects. We will explain a relevant statutory restriction or refusal rather than rely on a general contractual waiver.
11.4 Send requests to support@subjectiveclub.com. We may ask only for additional information reasonably necessary to verify identity, authority or the scope of the request. Do not send identity documents or sensitive information unless reasonably requested through an appropriate process.
11.5 We respond without undue delay and normally within one month of receiving a request. Where permitted because of complexity or the number of requests, this may be extended by up to two further months; we will explain the extension within the initial month. Requests are normally free. A fee or refusal for a manifestly unfounded or excessive request is permitted only under the applicable statutory conditions, which we must substantiate.
11.6 Complaints. You may complain to the supervisory authority in the EEA country of your habitual residence, workplace or alleged infringement, and seek a judicial remedy. You do not have to contact us first. In Hungary, the competent authority is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address: 1363 Budapest, Pf. 9., Hungary
Email: ugyfelszolgalat@naih.hu
Website: NAIH
12. Age restriction
12.1 The Service is intended for adults aged 18 or over. We ask for an adult-eligibility declaration, not a date of birth, and do not intentionally offer accounts to children. This declaration is not a guarantee that no minor will attempt to use the Service.
12.2 If you believe a child has provided personal data or created an account, contact us. We will assess the information and take appropriate action, including restricting the account and deleting data that cannot lawfully be retained. Evidence may be preserved where a specific safeguarding or legal duty requires it.
13. Changes and relationship to other documents
13.1 We may update this Policy to reflect changes in the Service, processing or law. The revision date identifies the text. Material changes will be communicated in an appropriate, accessible manner before new processing begins where required, and renewed consent will be requested where necessary. Continued use alone is not consent to a new optional purpose.
13.2 The Terms of Service, including their application licence and community rules, govern the contractual and community relationship. No content licence, disclaimer or liability limit in the Terms removes a data-subject right, a mandatory compensation right or the authority of a regulator.
13.3 This Policy is written in English. Any mandatory requirement to provide information in another language or in a form understandable to the intended audience remains applicable.
14. Controller identity and contact details
Denis Bolgarchuk
Individual operating under the name Subjective Club
Location: Budapest, Hungary
Privacy contact: support@subjectiveclub.com
You may use these contact details for privacy enquiries and requests concerning your personal data. Your rights and the request procedure are described in Section 11.
Version 1.0
Revision date: 8 September 2026