Pintasy

Pintasy — Privacy Policy

Last updated: 24 September 2026

Pintasy is a fantasy league you play with people you know. It works by recording nights out, which means it holds photographs of identifiable people. This document says exactly what is stored, who can see it, and how to make it stop.

It is written from the database schema rather than from intent. Where it says "nobody can see X", that is enforced by a row-level security policy, not by a promise.


Who we are

Pintasy is operated by SVANE KREATIV, a Norwegian sole proprietorship (enkeltpersonforetak), organisation number 936 963 412, registered at Øvreveien 19, 4316 Sandnes, Norway.

SVANE KREATIV is the data controller for everything described below.

Questions, complaints, or a request to delete something: hello@pintasy.app. We aim to reply within 5 working days and to act on deletion requests within 30 days, which is the GDPR limit.


What we store

Your account. An email address, so you can sign in. There is no password — signing in is a six-digit code sent to that address.

Your profile. A display name, and optionally a photograph of you and a cut-out of it with the background removed. You can take that photograph in the app or choose it from your library; the app only ever receives the one image you pick.

Your date of birth. Pintasy is 18+. Your date of birth is used once, to check that, and is never shown to anyone — not on your card, not in your league. It is held in a separate table that no other person can read.

Photographs you take in the app. A night out is posted with the in-app camera only; you cannot post one from your camera roll. Location metadata is removed before upload — not filtered out, but destroyed, because the image is re-encoded from decoded pixels and there is no metadata container left to carry it.

Every post is two photographs, and one of them is of you. Pressing the shutter fires the rear camera at the drink, flips to the front camera, and fires again about half a second later. Both are uploaded. The second one is the small inset on the feed card — it is how the app knows a photograph of a pint is your pint. If the second capture fails the post still goes through with only the first. Both are deleted together, always: removing a photo removes both objects, and so does deleting your account.

League artwork. Any member of a league can choose its banner and badge from their library. The cropped images are stored privately and shared with members of that league. They do not count as posts or affect points. Removed and abandoned uploads are cleared by scheduled storage cleanup after the upload grace period.

The drink on a post. When you post, you can name the drink from the app's list or by scanning its barcode. The drink's name, and the barcode if you scanned one, are stored with the post and shown to the people who can see it.

Drinks you suggest. If a drink is missing from the list you can suggest it. The suggestion is stored with your account, read only by us, and never shown to anybody else.

Who is in a photograph. If somebody tags you, that link is stored. See *Being in someone else's photo*, below.

A notification token, if you turn notifications on. When you allow notifications, your phone issues an anonymous address that lets a message reach that device. It is stored against your account, one row per device, so a phone and a tablet can both be reached. It identifies the device and not you, it is never shown to another person, and it is deleted when you sign out on that device or delete your account. If you never allow notifications, none is created. Where it goes when a notification is sent is set out in *Who else sees it*, below.

What the game derives. How many nights you were out in a week, how many drinks were documented, and what your friends' teams scored. These come from photographs; you are never asked to report on yourself.

Error reports, which are not linked to you. When the app crashes or hits an error it cannot recover from, it sends us a report so we can fix it: the error message and where in the code it happened, which screen type was open (for example "a league table", never which league), the app's version and build, and your iPhone's iOS version. It is sent without your sign-in, and the table that holds it has no place for your name, email, account, device or network address, so nothing connects a report to you. Before it is stored, anything that looks like an email address, an id or a sign-in token is removed from the text. Only we can read the reports, and each is deleted 30 days after the day it arrived. The reason is keeping the app working, which is a legitimate interest.

What we do not store


Who can see it

Photographs are visible to your friends and to people in your mini-leagues. They are never visible through the global league, which contains everybody. If the only thing you share with someone is that global league, they cannot see your photographs, your face, or who else you go out with.

What they can see is your display name and your league points — your season total, this week's total, and how many weeks you have been scored. The global league is a table of managers and that is what a table shows. It carries no photograph: your picture and your cut-out are withheld there specifically, and that is a rule in the database rather than a choice the app makes.

No count of anybody's drinking is readable by any app at all. The table that holds what a person's week actually was — nights out, quiet streak — is readable only by the scoring engine. Until 13 August 2026 it was readable by every signed-in account, which meant a list of the people you go out with, ordered by how many nights they had been out, was one request away. It is not any more, and a test now fails the build if that permission comes back.

There is no table of who drank the most, and the configuration that would allow one fails at build time.

Your date of birth is visible to nobody.

Your points are visible to the managers who picked you, because that is what their pick was about. There is no table anywhere that ranks people by what they did — only tables that rank managers. A manager's total is mostly how well they read their friends, plus a capped point for each drink they documented in their own posts that week.


Being in someone else's photo

Somebody can photograph you and tag you without asking first. That is deliberate: asking permission at 1am from a person whose phone is in their pocket means the night never gets recorded.

What you get instead is an unconditional right to remove yourself, at any time, with no time limit, without giving a reason, and with no penalty to your score. Removal is final — it cannot be undone by us or by the person who tagged you, and they cannot re-tag you in that photo.

Nobody is told that you removed a tag. Not the person who posted it, not your league. There is no count and no notification, because being seen to object would turn an unconditional right into a social cost.

Blocking somebody stops you seeing each other, stops them tagging you, removes every tag they have already placed on you, and takes their face off your league table — in one action.

Nobody can tag you unless they can already see you, which means a friend or somebody in one of your mini-leagues. A stranger cannot put you in their night.

Reporting sends it to us. It does not delete anything, hide anything, or notify the person reported — we review it and can remove the photograph or the account. If you want something to stop IMMEDIATELY, remove the tag or block them: both act at once and need nobody's decision.

See the Terms for what we do with a report.


Deleting things

A photo you posted. Delete it from your profile. The image is removed from view at once and from storage within about an hour, and it stops counting from the moment you ask — in every week that has not yet been finalised. A week already scored keeps the result it had, for the same reason as the second limit below: other people's finished tables were calculated from it.

Your account. Delete it in the app, from Settings (the gear on the You tab). It removes:

Four honest limits:


Who else sees it

Supabase hosts the database in the EU (Frankfurt), and the photographs posted before we moved them to Cloudflare. They process it on our instructions and for no purpose of their own.

Cloudflare stores the photographs (posts, selfies, profile pictures and league artwork) in a private R2 bucket held in the EU. It processes them on our instructions and for no purpose of its own.

Open Food Facts sees a barcode. If you scan a bottle or a can, the app sends that number to world.openfoodfacts.org to look up what the drink is called. Like any website, it sees the network address the request comes from; nothing else about you goes with it — no account, no photograph, no identifier — and the request is made whether or not you go on to post anything. It is a free public database, and drink names from it are © Open Food Facts contributors under the Open Database License.

Resend sends the sign-in emails. It receives your email address and the six-digit code, and nothing else.

ImprovMX forwards mail sent to hello@pintasy.app to our inbox, so it handles whatever you choose to write to us.

Expo delivers push notifications and app updates, and these are the only places where anything leaves the EU. When the app has a notification to send you, we hand Expo — in the United States — your device's notification token and the message itself, and Expo passes it to Apple. The message contains another person's display name, because that is what it is for: *"Anna liked your photo"*, *"Anna tagged you in a post"*. It also carries the id of the photograph concerned, so tapping the notification can open it.

Expo is a delivery service. It is not analytics, it does not profile anyone, and it receives nothing else — no email address, no photograph, no date of birth. If you never turn notifications on, no notification is ever sent through it. You can stop this at any time by turning notifications off for Pintasy in your phone's settings, which also removes the token.

Expo also delivers updates to the app itself. Each time the app starts, it asks Expo whether a newer version of its code is available, so a fix can reach you without a trip to the App Store. The request carries the app's version, the update it is running, and a random identifier the app creates when it is installed, which Expo uses to count how many phones receive an update. That identifier is not connected to your account, your name or your email, and like any server Expo sees the network address the request comes from. Nothing else about you goes with it.

Each of these processes what it receives only to provide that one service to us. Beyond them, nobody receives anything. There is no analytics service, no advertising network, and no third-party tracking of any kind in this app — no advertising identifier is read, and nothing you do here is measured for anybody else's purposes.


Where it is held

The database is with Supabase, in the EU (Frankfurt). Photographs are in private storage in the EU, with Cloudflare (or with Supabase for older ones): they are never public URLs, and every view is a short-lived signed link issued only to somebody the rules above already allow.

How long

Photographs and the facts derived from them are kept while your account exists. Delete your account and they go with it, subject to the four limits above.

There is no automatic expiry for photographs: nothing deletes an old one on a timer, so a photo you posted stays until you delete it, its poster deletes it, or one of you deletes their account.

Error reports are the exception. Each is deleted automatically 30 days after the day it arrived.

Your rights

Pintasy is operated from Norway, so the EU General Data Protection Regulation applies to you as it is incorporated into Norwegian law by the Personal Data Act (personopplysningsloven).

You can ask for a copy of your data (access), ask us to correct it (rectification), ask us to delete it (erasure), ask us to stop or limit what we do with it (restriction and objection), and ask for it in a portable form you can take elsewhere (portability). Most of that is in the app already. For anything else, email the address at the top.

Email us and we will send you everything we hold about you, including your photographs, as files you can keep or take elsewhere, within a month. It leaves out what belongs to other people: who reported or blocked you, which managers picked you, and who liked your photos (you get the count).

Our lawful basis is contract for running the game you signed up to, and legitimate interests for keeping it safe and working — which is what reports, blocks and error reports are for.

If we get it wrong you can complain to a regulator, and you do not need our permission to do it. In Norway that is Datatilsynet (datatilsynet.no). If you live elsewhere in the EEA you may complain to your own national authority instead.

Children

Pintasy is 18+. Age is checked at signup by a database constraint, not only by the form. If you believe somebody under 18 has an account, email us and we will remove it — that removal runs the same code your own deletion does, and records why it happened.

Changes

If this changes in a way that affects what is stored or who can see it, we will say so in the app before it takes effect.

The other document

Terms of Use covers what you may post, what happens to a report, and when we can end an account. This one is only about data.