Legal

Privacy Policy

What personal data AllPlay collects, why we collect it, how long we keep it, who else processes it, and the rights you have over it. This is an information document under Articles 12 to 14 GDPR, not a contract.

Questions about this document:

v2.0 · In force from 24 July 2026

DocumentPrivacy Policy
Version2.0
In force from24 July 2026
ScopeThe AllPlay mobile application and the website at getallplay.com
Companion documentTerms of Service, published separately

This Privacy Policy explains what personal data we collect, why, and what rights you have. It is an information document under Articles 12, 13 and 14 GDPR. It is not a contract and you are not asked to accept it as one. Your agreement with us is the Terms of Service.

1. Who is responsible for your data

1.1 The controller is Matija Cvitic, trading under the name AllPlay, Skillingagatan 68, 646 32 Gnesta, Sweden. Contact: support@getallplay.com. AllPlay AB is currently being formed and is not yet the controller.

1.2 Once AllPlay AB has been registered with Bolagsverket, we intend to transfer the operation of the Service to the company, at which point AllPlay AB will become the controller. Before that happens we will document the transfer of controllership, update our agreements with the providers listed in clause 4.3, notify you, and publish the company's registration number and registered address in an updated version of this Policy.

1.3 We have not appointed a data protection officer. We assessed the conditions in Article 37(1) GDPR and concluded they are not met, on the basis that large-scale regular and systematic monitoring of people is not our core activity and we do not process special category data, or data relating to criminal convictions and offences, on a large scale. We review that assessment annually. Data protection questions go to support@getallplay.com.

1.4 We process personal data under the GDPR, the Swedish Data Protection Act (lag (2018:218)) and, for storage of and access to information on your device, the Swedish Electronic Communications Act (lag (2022:482)).

2. What we collect, why, and for how long

DataWhyLegal basis (Art. 6(1) GDPR)Kept for
User ID, email address, display name, username, full nameCreating and running your account, signing you in, contacting you about the Service(b) contractLife of the account
PasswordSigning you in. Passwords are handled by our authentication provider, Supabase, and are stored in hashed form. We never see or store your password in readable form and will never ask you for it.(b) contractLife of the account
Year of birthChecking you meet the minimum age of 13(f) legitimate interests in enforcing our minimum age and protecting younger usersLife of the account
Profile picture, bio, city, skill level, profile visibility settingShowing you to other users, according to your visibility setting(b) contractUntil you delete or change it, or the account is deleted
Device location (latitude and longitude)Finding pitches and matches near you, and confirming you are within 500 metres of the venue when you check in to a match(b) contract, because the coordinates are processed only to deliver the location-based feature you have actively asked forNot stored in our database. See clause 2.6.
Matches you create, join and attend; the fact that you checked in and the time you didRunning matches, showing participants, keeping the Service reliable(b) contractLife of the account; anonymised on deletion
Rank tier and division, matches played, MVP count, ELO fieldShowing your progression and activity level in the app(b) contractLife of the account; anonymised on deletion
Match results, MVP votes, player ratings you give and receiveRecording results and rating the experience(b) contractLife of the account; anonymised on deletion
Friend requests and friendshipsThe friends feature(b) contractUntil removed by either user, or the account is deleted
Teams you create or belong to, team role, team invitationsThe teams feature(b) contractUntil you leave the team, or the account is deleted. See clause 6.4b.
Tournaments you organise or take part in: tournament team, captaincy, group and fixture standing, scores, results, and champion statusRunning the tournament, showing brackets, standings and results to participants(b) contractUntil the tournament is deleted by the organiser, or the account is deleted. Historical results are anonymised in the same way as ordinary match results, see clause 6.3.
Match highlight media you upload (video and images), with file type and sizeSharing highlights from completed matches(b) contractUntil you delete it, or the account is deleted. See clause 6.
Your appearance in match media uploaded by another userLetting participants share highlights from matches they played in(f) legitimate interests in allowing participants to share match content, balanced against your interest in controlling your image. See clause 2.7.Until the uploader or we delete it
Users you blockMaking blocking work(b) contractUntil you unblock them, or the account is deleted
Reports you make or that concern you; moderation notes, decisions and who handled themKeeping the Service safe, investigating abuse, meeting DSA obligations, establishing and defending legal claims(f) legitimate interests; (c) legal obligation for DSA. Where a report contains an allegation of criminal conduct, clause 2.4 applies.Up to 24 months from resolution, depending on seriousness. See clause 2.4a.
Venue and pitch suggestions and reports you submitImproving pitch data(f) legitimate interests24 months
Push notification token, device platform, device language, last seen timeSending you notifications about your matches(b) contract for service notifications; (a) consent for marketingUntil notifications are turned off or the account is deleted
Notification history queued for youDelivering and troubleshooting notifications(b) contract12 months
Admin and leader role assignmentsAccess control for administrators and verified organisers(f) legitimate interestsLife of the role
Acceptance of the Terms and the version accepted, with timestampRecording which version you agreed to(b) contract; (f) legitimate interests in documenting the agreement and defending legal claimsLife of the account plus 24 months
IP address, device model, operating system, app version, language, crash logs, timestampsDelivering the Service securely, diagnosing faults, detecting and preventing abuse(f) legitimate interests6 months, longer only for an active investigation
Product analytics events, with an analytics identifierUnderstanding how the Service is used so we can improve it. Off unless you turn it on.(a) consent, and consent under Chapter 9 Section 28 of lag (2022:482)12 months; deleted if you withdraw consent
Website cookies and browser local storageKeeping you signed in and remembering your preferences on getallplay.com(b) contract for strictly necessary; (a) consent for everything elseSession, or up to 12 months
Correspondence with supportAnswering your questions(b) contract; (f) legitimate interests24 months
Accounting recordsSwedish accounting law(c) legal obligation7 years (bokföringslagen (1999:1078))

2.1 Legitimate interests. Where we rely on Article 6(1)(f), our interests are keeping the Service safe, preventing abuse and fraud, securing our systems, and establishing, exercising and defending legal claims. We have weighed those against your rights and concluded the processing is necessary, falls within what users of a service that arranges physical meetings would reasonably expect, and has limited impact because we do not use the data for advertising or for sale to third parties. You can object under Article 21 GDPR, and we will stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms.

2.2 Automated evaluation and profiling. Some parts of the app calculate values from your activity automatically. We want to be precise about what actually happens, because this is the kind of statement that must be exactly true.

Your rank tier and division are calculated solely from the number of matches you have played. More matches played moves you up. It is a measure of participation, not of skill, and nothing else feeds into it.

Your ELO field currently holds the same starting value for every user and is not yet calculated from anything. If we activate a rating calculation, we will update this Policy first and tell you what it is based on.

Player ratings are given to you by other participants after a match, and are shown on your profile.

MVP votes are cast by other participants and counted on your profile.

Taken together these are profiling in the broad sense of Article 4(4) GDPR, because they involve automated evaluation of aspects of your activity. The practical consequences are limited: a higher or lower rank changes what is displayed on your profile. It does not determine whether you can use the Service, which matches you can join, or how we treat you if you are reported. It is not used to make decisions producing legal effects concerning you, or similarly significantly affecting you, within the meaning of Article 22 GDPR. Significant measures against an account, such as suspension or termination, are subject to human review where reasonably practicable and wherever the law requires it.

2.3 Special category data. We do not ask for special category data under Article 9(1) GDPR and we do not deliberately collect or infer data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data about sex life or sexual orientation. Please do not put that kind of information in your profile, your bio, or in content you upload.

It may nonetheless reach us incidentally, most obviously where someone includes it in a safety report or in a message to support. Where that happens, we process it only where an exception under Article 9(2) GDPR applies. Depending on the situation that may be: because it is necessary for the establishment, exercise or defence of legal claims (Article 9(2)(f)); because it is necessary to protect someone's vital interests in an emergency where they cannot give consent (Article 9(2)(c)); because you have given explicit consent (Article 9(2)(a)); or because the person concerned has manifestly made the data public (Article 9(2)(e)). We do not rely on a single ground for all cases, and we keep such data only as long as necessary for the purpose it arose in.

2.4 Reports containing allegations of criminal conduct. We do not ask for, and do not systematically collect, data about criminal convictions and offences. Most safety reports concern conduct that breaches our rules, such as abusive language, repeated no-shows or manipulating results, and are not about crime at all.

A report can nonetheless contain an allegation of criminal conduct, for example where someone reports suspected grooming, an assault at a match, or a threat. Where an allegation is specific enough to concern a particular offence, Article 10 GDPR applies and restricts how it may be processed.

Where that happens:

  • We process the report only where EU or Swedish law permits it, including where we are required under Article 18 of the Digital Services Act to inform a competent authority of information giving rise to a suspicion of an offence involving a threat to a person's life or safety, and where processing is necessary for the establishment, exercise or defence of legal claims.
  • Access is restricted to administrators handling that report.
  • We do not use the allegation for any purpose other than handling the report, protecting users and, where applicable, passing the matter to the competent authority.
  • We keep it only as long as necessary, as set out in clause 2.4a.

Where neither a legal obligation nor the legal claims ground permits continued processing, we do not retain the allegation beyond the limited initial assessment and any necessary transmission to a competent authority. We record internally which ground applies in each serious case.

2.4a How long we keep reports. We keep reports and the record of what we decided for up to 24 months from resolution. How long we actually keep a given report depends on how serious it was and whether the record is still needed for safety, legal claims or compliance. A minor report that was resolved without action is deleted sooner. A record relating to a serious safety incident is more likely to be kept for the full period.

2.5 What you have to give us. An email address and a display name are needed to create an account, and a year of birth is needed for the age check. Without them we cannot provide the Service. Location, notifications and analytics are optional. Refusing them costs you nothing except that particular feature. You can turn location and notification permissions off at any time in your device settings.

2.6 Location in more detail. Because location is the most sensitive thing we touch, here is exactly what happens.

When you look at the map or search for matches, your coordinates are sent with the query to find pitches near you. They are used to answer that query and are not written to your profile or to any other record.

When you check in to a match, your coordinates are sent so we can measure the distance between you and the venue. If you are within 500 metres, the check-in succeeds. We store the fact that you checked in and the time. We do not store the coordinates you sent, and we do not store the measured distance.

We do not keep a location history. No other user can see your position at any time.

Technical logs. We do not store coordinates in our application database, and they are not written to any table.

Coordinates are sent inside the body of ordinary network requests, never in the web address, so they do not end up in browser history, referrer headers or standard access logs. We have configured our systems not to log the contents of location requests. Where coordinates could still appear in a diagnostic log, for example in an error report, we treat those logs as restricted: access is limited to administrators, they are used only for security, fault diagnosis and abuse prevention, and we delete them within 30 days rather than keeping them for the full technical data period.

We do not send coordinates to our analytics provider, and no analytics event contains latitude, longitude or distance.

Legal basis. We rely on performance of the contract, because we process your coordinates only when you actively use a feature that needs them: looking for nearby matches, or checking in. Your device will also ask for operating system location permission. That permission is a technical gate, not the legal basis, and turning it off simply means those features are unavailable.

2.7 Media uploaded by other users. Other participants can upload photos and video from matches you played in, and you may appear in that content.

We do not use facial recognition or any other biometric identification, and we do not tag or index people appearing in media.

Whoever uploads content must have the right to share it under clause 10.4 of the Terms of Service, which requires permission from the people shown and particular care where a child appears.

If you appear in content you are unhappy with, you can report it in the app or email support@getallplay.com, and we will review it and remove it where appropriate. You can also object under Article 21 GDPR.

3. Data we get from sources other than you

3.1 This is the information required by Article 14 GDPR.

3.2 We receive personal data about you from:

  • (a) Apple, where you sign in with Apple: a user identifier and, depending on your choice, either your email address or a private relay address;
  • (b) Google, where you sign in with Google: a user identifier, your email address, your name and your profile picture;
  • (c) other users, where someone reports you, rates you, votes for you as MVP, sends you a friend or team request, or names or shows you in content they upload.

3.3 We process that data for the purposes and on the legal bases in clause 2. Where Article 14 requires it, we inform you at the time of first contact and in any event within one month of getting the data.

We may delay or withhold that information only where an applicable exception under Article 14(5) GDPR or another legal restriction permits us to do so. Situations where that may apply include where telling you would seriously impair a safety investigation, where it would identify the person who reported something and put them at risk, or where disclosure is prohibited by law. We assess this case by case rather than treating it as automatic.

3a. Google user data (Sign in with Google)

This clause gathers, in one place, what happens to data we receive from Google when you choose Sign in with Google. It adds nothing to what clauses 2, 3, 4 and 6 already say; it restates it so that it can be read on its own.

3a.1 What we access. Only the basic sign-in scopes: openid, email and profile. From those we receive a Google user identifier, your email address, your name and your profile picture. We do not request, and cannot see, your Gmail, Drive, Contacts, Calendar or any other Google service.

3a.2 How we use it. The identifier and email address create your AllPlay account and sign you in on later visits. Your name and profile picture pre-fill your display name and profile picture so you are recognisable to other players; you can change or remove both at any time in the app, and a change in AllPlay does not change anything in your Google account. We also use the email address to contact you about the Service. We do not use any of it for advertising, and we do not use it to build a profile of you for any purpose other than running AllPlay.

3a.3 How we store it. It is stored in our database with the rest of your account, hosted by Supabase in the EU (Frankfurt), encrypted in transit and at rest. Access is limited to administrators and is used only for support, security and abuse prevention. Retention is the same as the rest of your account data in the table in clause 2: we keep it for the life of the account.

3a.4 Who we share it with. Nobody, other than the processors listed in clause 4.3 who host and operate the Service on our behalf under written instructions. We do not sell it, we do not share it for advertising, and we do not transfer it to any third party for their own purposes. Other users see only what your profile visibility setting allows — your display name and picture — never your email address.

3a.5 How to delete it. Delete your account in the app under Settings, then Delete account. That removes the Google identifier, the email address, the name and the picture, together with the rest of your account, as described in clause 6. Deletion is immediate and cannot be undone. If you no longer have the app installed you can ask us to delete the account by writing to support@getallplay.com, or read the full description at https://getallplay.com/delete-account. You can also revoke AllPlay's access from your Google account at https://myaccount.google.com/permissions; that stops future sign-ins but does not by itself delete the AllPlay account, so do both if you want the data gone.

3a.6 Contact. Questions about any of this, and requests under clause 7, go to support@getallplay.com. The controller's postal address is in clause 1.1.

4. Who we share data with

4.1 We do not sell your personal data and we do not share it for advertising.

Where a match is sponsored, the sponsor does not receive participant identities or individual activity data. They receive aggregate information only. If that ever changes, we will tell you separately and will not do it without a valid legal basis.

4.2 Other users. What other users can see depends on your profile visibility setting, and is described in clauses 4.2 and 5.4 of the Terms of Service. Your location is never shown to another user in any circumstance.

4.3 Providers acting on our instructions (processors). These providers process personal data on our documented instructions under agreements meeting Article 28 GDPR:

ProviderWhat forWhere
SupabaseDatabase, authentication, file storage, realtime, edge functionsPrimary project configured in an EU region
VercelHosting and delivery of the app and websiteGlobal infrastructure. Selected application functions execute in an EU region. Networking, CDN, logs and backups may involve processing outside the EU/EEA under Vercel's DPA.
PostHogProduct analytics, only if you consentEU region
Google WorkspaceHandling email sent to and from support@getallplay.comGlobal infrastructure. International transfers are governed by Google's data processing terms and applicable transfer safeguards.

4.3a Providers acting as independent controllers or under their own terms. These companies decide for themselves how they process certain data, so they are not simply acting on our instructions. Their own privacy policies apply to that processing, alongside this one:

ProviderWhat for
AppleApp Store distribution, Sign in with Apple, push notification delivery via APNs
GoogleSign in with Google, Places API for venue information
Map tile providerServing the map tiles your device loads

Their own privacy policies also apply to processing where they determine the purposes and means, and we recommend you read them. That does not affect our own responsibility for choosing and configuring those services, for what we disclose to them, for informing you, and for assessing international transfers.

4.3b Email and support. When you email support@getallplay.com, your message is handled by Google Workspace, which processes your email address, the content of your message and any attachments on our behalf. If we add other tools that process personal data, such as error monitoring or customer support software, we will list them here before they go live.

4.4 Map and pitch data. The underlying pitch and map data originates from OpenStreetMap contributors. The map images themselves are served by a tile provider, and when your device loads a tile it makes a request directly to that provider, which includes your IP address and the area of the map you are viewing. That is how web maps work everywhere; it is not something we can see or control. The tile provider's own privacy policy applies to that request. Map tiles are currently served by CARTO, using their dark-themed basemap. CARTO's servers receive your IP address and the map area you are viewing when a tile loads. We will update this Policy if we change provider.

4.5 Partner organisations. Where you take part in a session run by a partner organisation, we may tell that organisation that you are taking part, so they can run the session. We do not share any other activity and never share location.

The session page identifies the partner organisation and gives information about its role in handling participant data. Depending on the arrangement, a partner may act as an independent controller, as a joint controller with us, or as a processor acting on our instructions. We determine and document that role in a written agreement before the session begins, and provide any additional privacy information required.

4.6 Authorities. We disclose personal data where the law requires it, on a court order, and on a lawful request from a competent authority. Where clause 7.6 of the Terms of Service applies, we disclose the relevant information to the competent law enforcement or judicial authority, including the Swedish Police Authority where appropriate. Where we are allowed to, we will tell you.

4.7 Business transfer. If the business is merged, acquired or transferred, personal data may go to the acquiring entity, which will remain bound by this Policy or one that protects you no less. We will tell you before that happens.

4.8 Aggregate data. We may publish statistics that do not identify anyone. Those are not personal data.

5. Transfers outside the EU

5.1 Our primary database, file storage and analytics projects are configured in EU regions. Some providers operate global networks, support systems, logs or backups, which may involve processing outside the EU/EEA. Several of these providers also have parent companies in the United States, which may in principle be subject to laws allowing access requests.

5.2 Apple and Google process data globally as part of app distribution, sign-in and push notification delivery.

5.3 Where personal data is transferred to a third country, we rely on a European Commission adequacy decision under Article 45 GDPR, including the EU-US Data Privacy Framework where the recipient is certified, or on the Standard Contractual Clauses adopted under Article 46(2)(c) GDPR by Implementing Decision (EU) 2021/914.

5.4 You can ask us for a copy of the safeguards we rely on at support@getallplay.com.

6. Deleting your account

6.1 You can delete your account at any time in the app, under Settings.

6.2 When you delete your account, the following is deleted: your profile, including your name, username, email address, profile picture, bio, city, year of birth and skill level; your friendships and friend requests; your team memberships; your push notification tokens and queued notifications; your device records; and the match highlight media you uploaded.

6.3 The following is anonymised rather than deleted, so that matches other people played in remain accurate: your participation in past matches, including check-in records, match results, MVP votes, and the ratings you gave and received. After anonymisation these records no longer identify you.

6.4 The following is kept: safety reports made about you and the moderation record of what we decided, for up to 24 months from resolution, so that we can defend legal claims; and accounting records where Swedish law requires it.

6.4a Preventing a removed user from returning. Where we have terminated an account for a serious safety breach, we keep a one-way hash of the email address of that account, so that the same address cannot immediately be used to register again. We keep a pseudonymised one-way value derived from the email address using a keyed hash with a secret held only on our server, rather than the address in readable form. That value remains personal data, because it can be used to recognise a repeated registration attempt, and we protect it accordingly. Only administrators can access it, and we keep it for 24 months. The legal basis is our legitimate interest in protecting other users, in particular minors, from someone we have already removed. Where the termination relates to alleged criminal conduct, clause 2.4 also applies.

6.4b Teams and matches you created. If you are the captain of a team with other members, deleting your account transfers captaincy to another member rather than deleting the team, so that the other members do not lose it. If no other member remains, the team is deleted. Matches you created that have already taken place are anonymised as described in clause 6.3. Matches you created that have not yet taken place are cancelled, and the participants are notified.

6.4c Your sign-in identity. Deleting your account also deletes your authentication record, including any linked Sign in with Apple or Sign in with Google identity. Your username is released and may be taken by another user afterwards.

6.5 Content other users have already downloaded or saved cannot be recalled.

6.6 Deleted data remains in encrypted backups until those backups expire. Backup schedules differ between our database, file storage and hosting providers, so we state a single upper bound that covers all of them: backup copies may remain for up to 90 days. In practice our database backups expire sooner than that. During that window the data is not accessible in the app and is used only to restore a system after a failure.

7. Your rights

7.1 You have the rights below. Exercising them is free. We will respond within one month of your request. Where a request is complex, or where we receive a number of requests, we may extend that by up to two further months, and we will tell you within the first month and explain why.

RightArticleWhat it meansHow to use it
Access15Confirmation of whether we process your data, a copy of it, and the information in Article 15(1)support@getallplay.com
Rectification16Correcting data that is wrong, and completing data that is incompleteEdit your profile in the app, or support@getallplay.com
Erasure17Deleting your data where a ground in Article 17(1) appliesDelete your account in the app, or support@getallplay.com
Restriction18Restricting processing in the situations in Article 18(1)support@getallplay.com
Notification to recipients19We tell each recipient about a correction, deletion or restrictionWe do this
Portability20Receiving the data you gave us in a structured, commonly used, machine-readable format, and having it sent to another controller where technically feasible. This generally covers data you provided and which we process automatically on the basis of consent or contract. It does not necessarily cover internal moderation assessments or values we derived ourselves.support@getallplay.com
Objection21Objecting to processing based on Article 6(1)(f), and objecting at any time to direct marketingsupport@getallplay.com
Withdrawing consent7(3)Withdrawing consent at any time, as easily as you gave it, without affecting what was lawful before. This applies to analytics, and to marketing notifications. Location is processed on the basis of contract, not consent, so turning off location permission is a choice not to use those features rather than a withdrawal of consent.Privacy Choices in the app, or your device settings for location and notifications
Complaint77Complaining to a supervisory authorityIMY, Box 8114, 104 20 Stockholm, imy@imy.se

7.2 Where we need to, we may ask you to verify your identity, so that we do not disclose someone's personal data to the wrong person.

8. Security

8.1 We use technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. These include encrypted transmission using TLS, authentication handled by a managed provider, row-level access rules in the database that limit each account to the data it is entitled to, administrative access granted on a least-privilege basis, logging of moderation decisions including who made them and when, and managed infrastructure that receives security updates and monitoring.

8.2 We will never ask you for your password.

8.2a Data protection impact assessment. The Service is used by people under 18, processes location data to deliver features, involves user-generated content and safety reports, and arranges meetings between users in the physical world. Because of that combination we are carrying out a data protection impact assessment under Article 35 GDPR. We review it when we add features that change the risk picture, in particular before activating any rating system, before adding messaging, before launching paid features, and before expanding to new markets.

8.3 If a personal data breach happens, we will notify IMY without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people's rights and freedoms, as required by Article 33 GDPR.

8.4 Where a breach is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay, as required by Article 34 GDPR.

9. Children

9.1 The minimum age for an account is 13. We check your year of birth at registration.

9.2 Because we cannot verify age beyond that check, the safety measures in clause 4 of the Terms of Service apply to every user, whatever age they have given.

9.3 If we learn that an account belongs to a child under 13, we suspend it and delete the data. We keep a pseudonymised value derived from the email address, on the same terms as clause 6.4a, so that the same address cannot immediately be used to register again. Because the reason for the block is age rather than conduct, we keep it only until the person would reach 13, up to a maximum of 24 months, so that a child who was too young is not prevented from joining once they are old enough. We keep anything else only where a legal obligation requires it.

9.4 A parent or guardian can contact us at support@getallplay.com about a child's account, including to ask us to delete it.

10. Changes to this Policy

10.1 We may update this Policy. The current version is always available in the app and at getallplay.com, with the date it took effect.

10.2 Where a change significantly affects how we use your data, we will tell you in the app or by email before it takes effect.

11. Contact

SubjectContact
Data protection questions and requests under Articles 15 to 22 GDPRsupport@getallplay.com
General supportsupport@getallplay.com
Complaint to the supervisory authorityIntegritetsskyddsmyndigheten, Box 8114, 104 20 Stockholm, imy@imy.se

Matija Cvitic, trading under the name AllPlay · Skillingagatan 68, 646 32 Gnesta · Version 2.0 · getallplay.com

Contact

AllPlay is operated by Matija Cvitic, trading under the name AllPlay, Skillingagatan 68, 646 32 Gnesta, Sweden.

Data protection, privacy and account questions, including requests to exercise your rights under the GDPR: . We answer within 30 days.

To delete your account and everything on it, see .