Privacy
Effective 26 May 2026
About Bolão
Bolão is operated by Ricardo Dias, an individual based in Portugal, and is the controller of personal data processed through the service. For privacy questions or any request about your data, contact ricardofnd.dev@gmail.com.
What we collect
When you create an account, we store:
- Your email address.
- A display name (you choose it, or we use the one from your Google account if you sign in with Google).
- Your profile picture from Google, if you used Google Sign-In.
- Your password, in encrypted form. We never see the original.
While you use the service, we also store:
- Your match predictions, tournaments, and invite activity, with timestamps.
- If you enable push notifications, a token from your browser that lets us send match reminders. You can disable it at any time.
- A login cookie, your language and theme preferences, and your IP address (kept in server logs for approximately 30 days, then deleted).
We do not collect:
- Your real name, government ID, or postal address.
- Payment information — the service is free.
- Your location.
- Advertising or third-party tracking identifiers.
Why we collect it
We use the information above to operate the service:
- Your account, so you can sign back in.
- Your predictions, so we can score them and update the leaderboard.
- Your push token, only if you opted in for match reminders. You can turn it off in settings at any time.
- Basic security and abuse prevention.
We do not sell, advertise, or build commercial profiles based on your data.
Who else processes it
We rely on a small number of service providers. Each only receives the data needed to perform its role and may not use it for any other purpose.
- Supabase — authentication and database. Headquartered in the United States, with EU servers when the EU region is selected.
- Google — only when you choose Sign in with Google. Google handles the authentication and shares your email, name, and profile picture with us.
- Vercel — hosts the application. It briefly processes your IP address and request metadata to deliver pages.
- Web Push services (Google, Mozilla, or Apple, depending on your browser) — only if you opted in for notifications. Used to deliver the reminder to your device.
We do not sell your data and do not share it with advertisers.
Where your data is stored
Most data is stored on servers in Europe. Some providers above are based in the United States and may keep copies there; in those cases we rely on the European Commission's Standard Contractual Clauses to maintain equivalent protection.
Retention
- Account data: kept while your account is active.
- After account deletion: removed within 30 days, including backups.
- Server logs: approximately 30 days, then deleted.
Your rights
Under European data-protection law, you have the right to:
- Request a copy of the data we hold about you.
- Have inaccurate data corrected.
- Have your account deleted (also available from in-app settings).
- Restrict or object to specific processing.
- Receive a portable copy of your data.
Email ricardofnd.dev@gmail.com to exercise any of these rights. We aim to respond within 30 days.
You may also lodge a complaint with the Portuguese supervisory authority, Comissão Nacional de Proteção de Dados (cnpd.pt).
Children
You must be at least 13 years old to use the service. If a parent or guardian becomes aware that an under-13 has created an account or joined a pool, please contact us and we will close it.
Security
Passwords are stored in encrypted form and are not visible to us. All traffic uses HTTPS. We apply security updates promptly. No system is perfectly secure, so please use a unique password — or use Sign in with Google for an additional factor.
Cookies
We use only essential cookies:
- A session cookie to keep you signed in.
- A language cookie for translations.
- A theme cookie for light or dark mode.
- A participant cookie that binds the predictions you make before creating an account, so they aren't lost when you sign up. Cleared if you sign out or delete the cookie manually.
No advertising cookies. No third-party analytics.
Changes to this policy
When this policy is updated, the effective date above changes. Material changes will be surfaced in the app before they take effect.
Contact
Privacy questions or requests: ricardofnd.dev@gmail.com.
