Read The Game
Privacy Policy
Version: 2026-07-20.2
Controller/operator: Read The Game, operated by an individual in Brazil.
Privacy contact: contato.notadev@gmail.com
This policy describes current product behavior. Legal counsel review is required before claiming formal LGPD, GDPR, or other legal compliance.
Data We Process
- Account data: email address, Supabase Auth user id, login/session metadata handled by Supabase.
- Profile data: display name and locale.
- Account preferences: theme, navigation context, selected league, and Home widgets.
- Game data: leagues, memberships, roles, participants, predictions, season picks, storyline picks, score events, and league settings.
- Owner content: custom storyline prompts, options, results, and league visibility settings.
- Operational data: API rate-limit keys, security logs from hosting/providers, and cron/sync execution status.
- Legal records: accepted Terms and Privacy Policy versions, timestamp, and locale.
Why We Process Data
We process data to authenticate users, run private leagues, save predictions, calculate scores, show leaderboards, support account export/deletion, prevent abuse, secure the service, and satisfy legal or operational obligations.
Legal Bases
Depending on the context, processing may rely on contract performance, legitimate interests in operating and securing the service, consent for acceptance/version records where applicable, and legal obligations.
Sharing and Providers
Read The Game uses Supabase for authentication/database, Vercel for hosting/serverless functions, Upstash for production rate limiting when configured, and football-data.org for football data. We do not sell personal data.
International Transfers
Providers may process data outside your country. Provider safeguards and contractual protections should be reviewed before commercial launch.
Retention
Data is kept while your account is active or while needed to operate leagues, preserve game integrity, meet security needs, or comply with legal obligations. Account deletion removes the Auth user and data configured to cascade from that user. When an owner deletes a league, that league’s memberships, predictions, picks, storylines, score events, and audit events are deleted; user accounts and other leagues are unaffected.
Your Rights
Depending on applicable law, you may request access, correction, portability, deletion, confirmation of processing, information about sharing, restriction, objection, or withdrawal of consent. Contact contato.notadev@gmail.com. We may need to verify your identity before acting.
Export and Deletion
Use Account -> Data and security to export a JSON copy of your account data or delete your account. Owners can also delete an owned league from league settings after confirming its exact name. A later export does not include deleted-league data. You may also contact the privacy email for data-subject requests.
Security
Read The Game uses Supabase RLS, authenticated API routes, rate limits, HTTPS hosting, security headers, password-based Supabase Auth, and least-necessary browser configuration. Interface preferences are private to each account and are not available to another account in the same browser. No security system is perfect.
Children
Read The Game is not intentionally designed for children. Age requirements and parental-consent rules require legal and product review before launch to minors.