Last updated: May 20, 2026

Privacy Policy

DataFight respects your privacy. This policy explains what data we collect, why, with whom we share it, and the rights you have under the European General Data Protection Regulation (GDPR).

It applies to the DataFight mobile application (Android, with iOS to follow), the datafight.app website, and all associated services.

1. Data controller

DataFight is published by Younes Ouasmi, registered as a micro-entrepreneur in France.

Email contact for any data-related question: contact@datafight.app

Postal address: [TO BE COMPLETED BEFORE PLAY STORE PUBLICATION]

SIRET number: [TO BE COMPLETED]

2. Data we collect

a) Account data

  • Email address (account creation, login, service communications)
  • Google identifier (only if you use Google Sign-In)
  • Password (hashed via bcrypt, never stored in plain text)
  • Display name (optional)

b) Fight data

  • Athletes you create: name, weight category, country, sex, optional date of birth
  • Recorded actions: technique, tatami zone, situation, stance, striking limb, timestamps
  • Uploaded fight videos (encrypted at rest on Cloudflare R2)
  • Generated AI reports (coaching, scouting, game plan, tactic, head-to-head)
  • Notes, tactical drawings, and clip lists

c) Technical data

  • Anonymized device identifier
  • App version and operating system version
  • Error logs (without personal content)
  • IP address (access logs, retained 90 days)

d) Payment data

DataFight does not collect or store any banking data. All payments (subscriptions, one-time purchases, AI credits) are processed by Google Play. We only receive a transaction identifier and its status (succeeded / refunded).

3. Purposes and legal basis (GDPR Art. 6)

PurposeLegal basis
Providing the service (capture, scoring, analytics)Performance of contract
Storing your videos and structured dataPerformance of contract
Generating AI reports on demandConsent
Multi-device sync (paid plans)Performance of contract
Technical support and answering requestsLegitimate interest
Anonymized usage statistics (product improvement)Legitimate interest
Marketing communications (newsletter)Consent (opt-in)
Billing and storage of accounting recordsLegal obligation
Fraud prevention and securityLegitimate interest

4. Subprocessors and partners

To provide the service, DataFight relies on the following subprocessors. Each is bound by an agreement compliant with GDPR Art. 28.

PartnerRoleLocation
SupabaseAuthentication + databaseEuropean Union (Frankfurt)
Cloudflare R2Encrypted video storageEuropean Union
Google Cloud (Gemini API)AI report generationUnited States — SCCs in place
Google PlayDistribution and paymentsUnited States — DPF + SCCs
VercelMarketing website hostingGlobal edge network

Transfers outside the EU

For subprocessors located outside the EU, Standard Contractual Clauses (SCCs) approved by the European Commission are in place, supplemented where applicable by adherence to the EU-US Data Privacy Framework (DPF).

5. No resale, no ad tracking

DataFight never sells your data. We do not share any information with data brokers, advertisers, social networks, or third parties for commercial purposes.

The application contains no advertising tracking SDK (no Facebook SDK, no in-app Google Analytics, no AdMob). The datafight.app marketing site uses no third-party cookies.

6. Security

  • Authentication handled by Supabase (signed JWTs, refresh tokens, MFA available)
  • Row-Level Security at the database level: only your account can access your data
  • Videos accessible only via short-lived signed URLs (Cloudflare R2)
  • Encryption at rest for videos and the database
  • Encryption in transit (TLS 1.3) for all communications
  • AI models receive only anonymized aggregates — never the raw videos
  • Encrypted daily backups

7. Retention period

DataDuration
Active accountAs long as you use the app
Inactive accountAutomatic deletion after 24 months of inactivity (30-day email notice)
Deletion requestProcessed within 30 days maximum
Access and IP logs90 days
Anonymized error logs12 months
Accounting records (Play Store)10 years (legal obligation)
Generated AI reportsAs long as the account is active

8. Your rights (GDPR)

Under the GDPR you have the following rights over your personal data:

  • Right of access: obtain a copy of the data we hold about you
  • Right of rectification: correct inaccurate data
  • Right to erasure (“right to be forgotten”): delete your account and all your data
  • Right to portability: export your data in an open format (CSV) from Profile → Export my data
  • Right to object: refuse certain processing, in particular marketing
  • Right to restriction: temporarily freeze a contested processing
  • Right to withdraw consent at any time

How to exercise your rights

Send your request to contact@datafight.app from the email address associated with your account. We respond within 30 days maximum (and often within 48 hours).

You also have the right to lodge a complaint with the French Data Protection Authority (CNIL) — www.cnil.fr — 3 Place de Fontenoy, 75007 Paris — or your local supervisory authority.

9. Minors

DataFight is not intended for children under 13. If you are between 13 and 15, your account must be created under the responsibility of a parent or legal guardian (GDPR Art. 8).

If we discover that an account has been created by a minor under 13 without parental authorization, we will delete it immediately.

10. Cookies and trackers (website)

The datafight.app website uses only strictly technical cookies (language preference). No advertising or third-party analytics cookies are set.

The mobile application does not use cookies (web technology).

11. Changes to this policy

This policy may be updated to reflect changes in the service or legal framework. The date of last update is shown at the top of this page.

In case of a substantial change, we will inform you by email and/or in-app notification at least 30 days before it takes effect. Continued use after the effective date constitutes acceptance.

12. Contact

For any question about this policy or your data: contact@datafight.app

To delete your account, see our dedicated page: Account deletion.