1. Introduction
Triu Cup ("the app", "we", "our") is a mobile app for collecting virtual stickers from the 2026 Football World Cup, operated by the developer under the name Francisco Mejía ("the data controller"). This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and what rights you have over it.
By registering and using Triu Cup, you accept the practices described in this policy. If you disagree, you must not use the app.
Data controller contact:
Email: soporte@triucup.app · Developer: Francisco Mejía
2. Data we collect
2.1 Data provided directly by the user
| Data | Purpose | Required? |
|---|---|---|
| Email address | Account identification, verification, password recovery | Yes |
| Name and surname | Public profile within the app | Yes |
| Username (@handle) | Unique identifier for friend search | Yes |
| Password | Authentication (stored securely, never in plain text) | Yes |
| Preferred language | Interface localisation | No |
| Favourite team | Profile personalisation | No |
| Reason for leaving | Optional feedback when deleting account | No |
2.2 Data generated by app use
- Album status: cards you own, duplicates, missing cards, collection progress per national team.
- Friends list: connections with other users, sent/received/accepted/rejected friend requests.
- Trades: trade offers created, received, accepted or rejected; cards offered and requested.
- Collection stats: completion percentage, unique/duplicate/rare card counts, ranking position.
2.3 Automatically collected data
- Session tokens: JWT access and refresh tokens required to maintain your session.
- Last activity timestamp: to control session expiry due to inactivity (30 minutes).
- Sync logs: pending operations to sync with the server (album data only).
3. How we use your data
We use your data exclusively for: authentication and account management; album operation; the friends system; trades; displaying the match calendar; displaying news; personalisation; security; and requesting reviews. We do not use your data for targeted advertising, training AI models, sale to third parties, or behavioural profiling for advertising purposes.
4. Third-party services
| SDK / Service | Purpose | Data shared |
|---|---|---|
| Google Play Integrity API (Android) | Verify the app runs on a genuine Android device | Nonce, integrity token (no personal data) |
| DeviceCheck / AppAttest (iOS) | Verify Apple device integrity | KeyId, attestation (no personal data) |
| flutter_secure_storage | Encrypted session token storage | Access token, refresh token, remembered email |
| sqflite (SQLite) | Local album database and sync queue | Album data, pending operations |
| shared_preferences | Simple preference storage | Tutorial state, review state |
| local_auth | Biometric authentication | Authentication result (yes/no) — no biometric data accessed |
| in_app_review | Request reviews on App Store / Google Play | No personal data |
We do not use Firebase, Google Analytics, Facebook SDK or any analytics, advertising or tracking service.
5. Authentication
We use JWT-based authentication. Passwords are transmitted encrypted via TLS and stored using secure hashing algorithms. We never store passwords in plain text. Biometric authentication (Face ID / Touch ID / fingerprint) does not give the app access to your biometric data — the app only receives a yes/no confirmation from the OS. Deep links using the triu:// scheme handle email verification and password reset.
6. Cookies and tracking
We do not use cookies, web beacons, tracking pixels or any tracking technology. The app does not incorporate third-party analytics or attribution systems.
7. Device permissions
| Permission | Platform | Purpose | Required? |
|---|---|---|---|
INTERNET | Android | API server communication and link opening | Yes |
NSFaceIDUsageDescription | iOS | Biometric authentication (Face ID) | Only if enabled |
| AppAttest environment | iOS | Device integrity verification | No (in development) |
| Browser query | Android | Open terms and privacy links in external browser | Yes |
The app does not request or use: camera, microphone, photo gallery, GPS location, contacts, calendar, external storage, Bluetooth or push notifications.
8. Security
- Encryption in transit: all server communication uses HTTPS/TLS.
- Certificate pinning (SPKI): in production, the app verifies the server's SHA-256 public key fingerprint to prevent Man-in-the-Middle attacks.
- Secure token storage: JWT tokens are stored in iOS Keychain or Android EncryptedSharedPreferences.
- Root/jailbreak protection: in production, the app detects compromised devices.
- Platform integrity: via Google Play Integrity API (Android) and DeviceCheck/AppAttest (iOS).
- Session expiry: sessions expire automatically after 30 minutes of inactivity.
- Login attempt limit: maximum 5 failed attempts before temporary lockout.
9. Data retention
| Data type | Retention period |
|---|---|
| Account data (email, name, username) | Until account deletion |
| Album status and cards | Until account deletion |
| Friends list | Until account deletion or friend removal |
| Trade history | Until account deletion |
| Session tokens (stored locally) | Until logout or expiry |
| Locally cached data (SQLite) | Until app data is cleared |
| Reason for leaving | Anonymised after 30 days |
10. Your rights (GDPR / CCPA)
If you reside in the European Economic Area (GDPR) or California (CCPA), you have the right to: access your personal data; rectify inaccurate data; erasure ("right to be forgotten"); restriction of processing; data portability; objection to processing; and withdrawal of consent. Contact us at soporte@triucup.app. We will respond within 30 days.
11. Account deletion
Profile → Settings → Delete account. Upon deletion, your server data (name, email, username, album progress, friends, trades) will be permanently deleted, session tokens will be removed, and any reason for leaving will be anonymised within 30 days. Note: uninstalling the app does not delete your server account. You must use the "Delete account" option within the app.
12. Minors policy
Triu Cup is intended for users aged 16 and over. We do not intentionally collect personal data from under-16s. If we discover we have collected data from a minor without parental consent verification, we will delete it immediately. Users aged 16–17 must have parental or guardian consent.
13. International data transfers
Our servers are hosted in the United States via Railway (cloud infrastructure provider). By using the app, your data may be transferred to and processed in the United States. We take the necessary measures to ensure an adequate level of protection, including standard contractual clauses where applicable.
14. Changes to this policy
We will update this Privacy Policy when necessary to reflect changes to the app or legal requirements. We will notify you of significant changes via the app or by email. The date of the last update appears at the top of this document.
15. Contact
- Email: soporte@triucup.app
- Developer: Francisco Mejía
