Privacy Policy — FEATUP
⚠️ WORKING DRAFT — to be reviewed by a lawyer before publication. The French version prevails in case of discrepancy.
Version: 2.1 — 16 July 2026 Data controller: Eduard Ahmeti, sole proprietorship, Rue de la Maladière, 1205 Geneva, Switzerland — privacy@featup.app
FEATUP is a mobile application that connects people who want to practise sport together (partners, events, recurring groups, verified professionals). This policy describes which personal data we process, why, and what your rights are. It complies with the Swiss Federal Act on Data Protection (nFADP) and the EU General Data Protection Regulation (GDPR).
1. Data we collect
Account data (required): email address, password (hashed, never readable), first name, last name, gender, date of birth, city, username.
Profile data (optional): profile photo, album photos (max 6), biography, sports practised and levels, weekly training schedule (day, times, free-text venue).
Approximate location: if you allow it, your position is read only when opening the partner or event search, then rounded to about 1 km before any storage. Your exact position is never stored or displayed. No background tracking. Events and groups you create are stored with the venue you explicitly choose.
Usage data: friend requests, friendships, chat messages, blocked accounts, reports (of profiles or events), participation in events and group sessions (attendance "RSVP" responses), last activity date.
Community reliability and confirmed levels: after a session or event, participants can mutually confirm each other's attendance and, optionally, assess each other's sporting level. We store these individual confirmations and assessments, as well as the computed aggregates (reliability rate, confirmed level per sport, number of assessments). See section 2 (legal basis) and section 6 (what is visible).
Aggregated sports activity (gamification): streaks of active weeks, earned badges, counters of confirmed sessions — all derived from your real participation in sessions, never from your app usage.
Professional application (only if you apply for PRO status):
- identity document (photo);
- verification selfie — biometric data (see section 3);
- diplomas / certifications (1 to 3 photos);
- disciplines, professional headline, description, hourly rate.
Payment data (only for paid events, when this feature is active): amount, currency, payment status (pending, held, released, refunded, failed), Stripe technical identifiers (PaymentIntent, transfer), timestamps. We never see or store your card number: card data is entered directly in Stripe's interface and processed by Stripe. Organizers who receive payments create a Stripe Connect account; identification data required by Stripe (KYC, anti-money-laundering) is collected and processed by Stripe as a separate data controller.
Moderation data: for each public post (photo and caption), the result of the prior automated analysis (categories and scores) and, where applicable, the human moderator's decision (see section 4).
Technical data: device notification tokens (Firebase Cloud Messaging, if you enable notifications), chosen language and theme.
We do not collect: phone number, exact position, phone contacts, biometric data outside the explicit PRO application.
2. Purposes and legal bases
| Processing | Purpose | Legal basis |
|---|---|---|
| Account and profile | Provide the service (sports matching) | Performance of contract |
| Approximate location | Suggest nearby partners, events and groups | Consent (revocable) |
| Messages | Enable connections | Performance of contract |
| Community reliability (attendance confirmations, level assessments, aggregates) | Strengthen trust between members, reduce no-shows, make displayed levels dependable | Legitimate interest (community trust) |
| Gamification (streaks, badges, local leaderboards) | Encourage regular, real sporting activity | Performance of contract / legitimate interest |
| Match of the day (daily partner suggestions) | Suggest up to 3 compatible partners each day | Performance of contract; notification can be disabled (settings) |
| AI-generated "icebreaker" messages | Ease the first contact with a suggested partner | Performance of contract (see section 5) |
| Automated pre-publication moderation | Prevent the distribution of unlawful or harmful content | Legitimate interest (community safety); final decision is human (section 4) |
| PRO verification (identity document, diplomas) | Verify declared identity and qualifications | Performance of contract (PRO status requested) |
| Verification selfie (biometrics) | Verify that the PRO applicant is the holder of the identity document | Explicit consent (art. 6 para. 7 nFADP / art. 9(2)(a) GDPR, revocable) |
| Event payments (when the feature is active) | Collect, escrow, pay out, refund | Performance of contract + legal obligations (accounting, AMLA) |
| Reports and moderation (profiles, events) | Community safety, fraud prevention | Legitimate interest |
| Freezing funds upon report | Protect participants of an event that did not take place | Legitimate interest + performance of contract |
| Push notifications (requests, messages, match of the day, session reminders) | Keep you informed | Consent (revocable); the daily match push can be disabled individually in settings |
3. Biometric data: the PRO verification selfie
The verification selfie is sensitive data (biometric data within the meaning of art. 5 let. c nFADP and art. 9 GDPR). Its processing is subject to reinforced safeguards:
- Explicit consent: the selfie is only collected if you apply for PRO status and tick the dedicated consent box. Without consent, the application cannot be submitted — PRO status is simply unavailable, the rest of the application is unaffected.
- Guided capture on the device: face detection (single face, eyes open, smile) is performed locally on your phone (ML Kit library running on-device). No image or face data is transmitted to Google or any third party during this analysis.
- Single, limited use: the selfie is used exclusively for manual visual comparison with the identity document by the publisher. No automated facial recognition is performed server-side, no biometric template is created, no automated decision is made.
- Private storage: the selfie, identity document and diplomas are stored in a private space, encrypted in transit, inaccessible to other users, and are never published.
- Limited retention: see section 7.
- Withdrawal of consent: at any time via privacy@featup.app; the documents are then deleted (the application or PRO status lapses).
4. AI-assisted content moderation
Every public post (photo and its caption) is analysed before publication by automated systems: a harmful-content detection model (OpenAI omni-moderation) and a complementary text analysis by a language model. This analysis produces risk categories and scores.
- Content judged safe: published immediately.
- Flagged or uncertain content: the post is held and forwarded to a human moderator, who alone decides to publish or reject. No adverse decision is fully automated (art. 21 nFADP / art. 22 GDPR): rejecting a post is always a human decision.
- The author sees their own pending posts (marked "pending review"); other users never see unvalidated content.
- Images are transmitted to the analysis provider via a short-lived temporary address; the provider does not use this data to train its models (section 6).
- Rejected content: kept for 90 days for evidence purposes (disputes, repeat offences, legal obligations), then deleted.
5. AI-generated suggestions ("icebreakers")
For the Match of the day, a short opening message may be generated by an AI from limited information already visible in the app: first names, shared sport, approximate distance and, where applicable, a compatible training slot. This message is a mere suggestion: it is never sent automatically, and you can edit or entirely replace it before sending. No content from your private conversations is transmitted to the AI.
6. Recipients, subprocessors and transfers
Hosting: your data is hosted by Supabase (Amazon Web Services infrastructure, Zurich, Switzerland region). Profile data, messages and documents do not leave Switzerland for storage.
| Subprocessor | Role | Location / transfers |
|---|---|---|
| Supabase (AWS) | Database hosting, storage, server functions | Switzerland (AWS Zurich) |
| Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc.) | Paid event payments (when the feature is active), organizer KYC | Ireland / USA — Swiss-U.S. & EU-U.S. Data Privacy Framework, standard contractual clauses |
| OpenAI (OpenAI, LLC) | Automated pre-publication moderation (images + text), icebreaker generation | USA — Swiss-U.S. Data Privacy Framework; our data is not used to train models (API) |
| Google Firebase (Cloud Messaging) | Push notification delivery (device tokens) | EU/USA — Data Privacy Framework |
| Sentry (Functional Software, Inc.) | Error and crash reports (technical data, no user content) | EU hosting (Germany) |
| OpenStreetMap / Photon / Nominatim | Map display, address search | EU — receive your IP address and the searched address text |
Face analysis: ML Kit runs entirely on the device; no image data is transmitted to Google.
No data is sold or shared with third parties for advertising purposes.
What other users see: your first name and last-name initial, your age (never your date of birth), your gender, your city, your approximate distance, your bio, your sports, your published photos (after validation); your aggregated reliability rate (from 5 assessments) and your community-confirmed levels (number of assessments and median — never who assessed you or how); for PROs: headline, disciplines, rate and average rating. Local leaderboards show only your first name, profile photo and number of sessions over the last 30 days, to users within roughly 25 km — no location or identity beyond that. Your schedule is only visible to your friends unless you choose to make it public. The organizer of a paid event sees paying participants' first names, amount paid and payment status. Your PRO application documents are never visible.
7. Retention periods
- Account and profile: as long as your account exists.
- Account deletion: immediate erasure of profile, photos, friendships, messages and position — "Delete my account" function in settings.
- Reliability and assessments: deleted with the assessed person's account; aggregates disappear with the profile.
- PRO application — documents (identity document, selfie, diplomas): application rejected → documents deleted within 90 days; application approved → kept while PRO status is active (proof of verification), deleted upon loss of status or account deletion.
- Payment data: transaction records (amounts, statuses, identifiers — no card data) are kept for 10 years after the transaction, in line with Swiss accounting obligations (art. 958f CO), including after account deletion; they are then dissociated from the deleted profile where possible.
- Content rejected by moderation: kept for 90 days for evidence purposes, then deleted (section 4).
- Reports (profiles and events): kept for 12 months for safety purposes, then anonymised; in case of dispute or fraud, until resolution.
8. Your rights (art. 25 ff. nFADP / art. 15-22 GDPR)
Two essential rights can be exercised directly in the app, without contacting us:
- Access and portability: Settings → Export my data (complete copy in JSON);
- Erasure: Settings → Delete my account (immediate, irreversible — subject to legal retention, section 7).
In addition:
- Rectification: edit your profile at any time in the app.
- Withdrawal of consent: disable location or notifications in the settings (the "Match of the day" push has its own switch); for the biometric selfie, write to privacy@featup.app.
- Objection and restriction: for processing based on legitimate interest (including community reliability and moderation), write to privacy@featup.app.
- Human review of a moderation decision: any removal or rejection can be contested via contact@featup.app — it will be reviewed by a person.
- Complaint: you may contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) or the authority of your country of residence.
For any request: privacy@featup.app.
9. Minimum age
FEATUP is restricted to people aged 16 and over. The account of anyone identified as under 16 will be deleted.
10. Security
Encryption in transit (TLS), row-level access control in the database (Row Level Security), hashed passwords, least-privilege access keys, sensitive documents in private storage spaces. Only the participants of a conversation can read its messages. Payment- and moderation-related writes can only be performed by our internal services, never by clients.
11. Changes
Any substantial change to this policy will be notified in the app before it takes effect. If a sensitive data category is processed for a new purpose, new explicit consent will be requested.