Triu Cup
MUNDIAL 2026
Album Matches Trades News Community FAQ
ES · Español EN · English PT · Português
Download
Back to home
Legal

Privacy Policy

Last updated: June 3, 2026

Contents
  1. Introduction
  2. Data we collect
  3. How we use your data
  4. Third-party services
  5. Authentication
  6. Cookies and tracking
  7. Device permissions
  8. Security
  9. Data retention
  10. Your rights (GDPR / CCPA)
  11. Account deletion
  12. Minors policy
  13. International transfers
  14. Changes to this policy
  15. Contact

1. Introduction

Triu Cup ("the app", "we", "our") is a mobile app for collecting virtual stickers from the 2026 Football World Cup, operated by the developer under the name Francisco Mejía ("the data controller"). This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and what rights you have over it.

By registering and using Triu Cup, you accept the practices described in this policy. If you disagree, you must not use the app.

Data controller contact:
Email: soporte@triucup.app · Developer: Francisco Mejía

2. Data we collect

2.1 Data provided directly by the user

DataPurposeRequired?
Email addressAccount identification, verification, password recoveryYes
Name and surnamePublic profile within the appYes
Username (@handle)Unique identifier for friend searchYes
PasswordAuthentication (stored securely, never in plain text)Yes
Preferred languageInterface localisationNo
Favourite teamProfile personalisationNo
Reason for leavingOptional feedback when deleting accountNo

2.2 Data generated by app use

  • Album status: cards you own, duplicates, missing cards, collection progress per national team.
  • Friends list: connections with other users, sent/received/accepted/rejected friend requests.
  • Trades: trade offers created, received, accepted or rejected; cards offered and requested.
  • Collection stats: completion percentage, unique/duplicate/rare card counts, ranking position.

2.3 Automatically collected data

  • Session tokens: JWT access and refresh tokens required to maintain your session.
  • Last activity timestamp: to control session expiry due to inactivity (30 minutes).
  • Sync logs: pending operations to sync with the server (album data only).

3. How we use your data

We use your data exclusively for: authentication and account management; album operation; the friends system; trades; displaying the match calendar; displaying news; personalisation; security; and requesting reviews. We do not use your data for targeted advertising, training AI models, sale to third parties, or behavioural profiling for advertising purposes.

4. Third-party services

SDK / ServicePurposeData shared
Google Play Integrity API (Android)Verify the app runs on a genuine Android deviceNonce, integrity token (no personal data)
DeviceCheck / AppAttest (iOS)Verify Apple device integrityKeyId, attestation (no personal data)
flutter_secure_storageEncrypted session token storageAccess token, refresh token, remembered email
sqflite (SQLite)Local album database and sync queueAlbum data, pending operations
shared_preferencesSimple preference storageTutorial state, review state
local_authBiometric authenticationAuthentication result (yes/no) — no biometric data accessed
in_app_reviewRequest reviews on App Store / Google PlayNo personal data

We do not use Firebase, Google Analytics, Facebook SDK or any analytics, advertising or tracking service.

5. Authentication

We use JWT-based authentication. Passwords are transmitted encrypted via TLS and stored using secure hashing algorithms. We never store passwords in plain text. Biometric authentication (Face ID / Touch ID / fingerprint) does not give the app access to your biometric data — the app only receives a yes/no confirmation from the OS. Deep links using the triu:// scheme handle email verification and password reset.

6. Cookies and tracking

We do not use cookies, web beacons, tracking pixels or any tracking technology. The app does not incorporate third-party analytics or attribution systems.

7. Device permissions

PermissionPlatformPurposeRequired?
INTERNETAndroidAPI server communication and link openingYes
NSFaceIDUsageDescriptioniOSBiometric authentication (Face ID)Only if enabled
AppAttest environmentiOSDevice integrity verificationNo (in development)
Browser queryAndroidOpen terms and privacy links in external browserYes

The app does not request or use: camera, microphone, photo gallery, GPS location, contacts, calendar, external storage, Bluetooth or push notifications.

8. Security

  1. Encryption in transit: all server communication uses HTTPS/TLS.
  2. Certificate pinning (SPKI): in production, the app verifies the server's SHA-256 public key fingerprint to prevent Man-in-the-Middle attacks.
  3. Secure token storage: JWT tokens are stored in iOS Keychain or Android EncryptedSharedPreferences.
  4. Root/jailbreak protection: in production, the app detects compromised devices.
  5. Platform integrity: via Google Play Integrity API (Android) and DeviceCheck/AppAttest (iOS).
  6. Session expiry: sessions expire automatically after 30 minutes of inactivity.
  7. Login attempt limit: maximum 5 failed attempts before temporary lockout.

9. Data retention

Data typeRetention period
Account data (email, name, username)Until account deletion
Album status and cardsUntil account deletion
Friends listUntil account deletion or friend removal
Trade historyUntil account deletion
Session tokens (stored locally)Until logout or expiry
Locally cached data (SQLite)Until app data is cleared
Reason for leavingAnonymised after 30 days

10. Your rights (GDPR / CCPA)

If you reside in the European Economic Area (GDPR) or California (CCPA), you have the right to: access your personal data; rectify inaccurate data; erasure ("right to be forgotten"); restriction of processing; data portability; objection to processing; and withdrawal of consent. Contact us at soporte@triucup.app. We will respond within 30 days.

11. Account deletion

Profile → Settings → Delete account. Upon deletion, your server data (name, email, username, album progress, friends, trades) will be permanently deleted, session tokens will be removed, and any reason for leaving will be anonymised within 30 days. Note: uninstalling the app does not delete your server account. You must use the "Delete account" option within the app.

12. Minors policy

Triu Cup is intended for users aged 16 and over. We do not intentionally collect personal data from under-16s. If we discover we have collected data from a minor without parental consent verification, we will delete it immediately. Users aged 16–17 must have parental or guardian consent.

13. International data transfers

Our servers are hosted in the United States via Railway (cloud infrastructure provider). By using the app, your data may be transferred to and processed in the United States. We take the necessary measures to ensure an adequate level of protection, including standard contractual clauses where applicable.

14. Changes to this policy

We will update this Privacy Policy when necessary to reflect changes to the app or legal requirements. We will notify you of significant changes via the app or by email. The date of the last update appears at the top of this document.

15. Contact

  • Email: soporte@triucup.app
  • Developer: Francisco Mejía
Triu Cup
MUNDIAL 2026

Made in Brazil with love by fans who missed collecting stickers. Inspired by the spirit of the 1986 World Cup.

Product
Digital album Live matches Trades News Statistics
Resources
Help center Community Blog Press Contact
Legal
Terms Privacy Cookies Report a bug System status
© 2026 Triu Cup. Independent project. Not affiliated with FIFA.
IGXTTYT