Privacy Policy
Last updated: July 14, 2026
This policy explains what personal information FinalPoint (“we”, “us”) collects when you use the service, how we use it, who we share it with, and what rights you have over it.
FinalPoint is operated by FinalPoint LTD, a company registered in England & Wales (company no. 17195243), based in London, United Kingdom. FinalPoint LTD is the Data Controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Questions, rights requests, and complaints can be sent to info@thefinalpoint.app.
1. Information we collect
We collect the following categories of information:
- Account information: email address, password (stored as a hash, never in plain text), display name, username, and date of birth. Date of birth is used solely to confirm you meet the minimum age requirement.
- Profile content: the profile picture you choose (preset illustration or photo you upload), the bio you write, and any display preferences.
- Match and group data: groups you create or join, sessions you attend, players you add, matches you record (including matches recorded against another player without a shared group), match scores, and derived EVO ratings.
- Activity and gameplay data: achievements you unlock, notifications we generate for you and your read / unread state for them.
- Messages: direct messages you exchange with other players and messages you post in a group’s chat, along with reactions, replies, pinned messages, and read state.
- Friends, blocks, and reports: friend requests you send and accept, players you block, reports you file, and, where you joined through a friend’s invite link, which player invited you.
- Subscription information: if you buy a paid tier, the tier, billing period, and current status of your subscription; payment itself is handled by Apple, Google, or our web checkout provider, and we never receive your card details.
- Usage analytics: events that describe how the app is used, such as signing up, logging a match, or opening a notification. These are tied to a random identifier and your account ID, never to your name or email, and they never include message content or match scores.
- Bug reports: when you use the “Report a bug” link we prefill an email with the page URL, your viewport size, user-agent string, and a timestamp to help us diagnose the issue. You can edit or remove any of that before sending.
- Technical information: session cookies needed to keep you signed in, IP address, user agent, and diagnostic logs collected when the app encounters an error.
- Device location: when you use “clubs near me” — or when a Club owner sets their Club’s location — and only if you grant permission, we read your device’s approximate GPS coordinates. Those coordinates are sent to our server for that one request, to find nearby Clubs or set a Club’s area; they are never stored against your profile. We keep only the resulting area labels and an approximate distance to show you.
- Apple Health data: on iPhone, and only if you grant permission, recent racket-sport workouts (type, time, and duration) plus the heart rate and active calories recorded during them. See section 3 for full detail.
2. How we use information
- To create your account and keep you signed in.
- To provide the service: store your matches, compute EVO ratings, show leaderboards and achievements, and share activity with the groups and players you interact with.
- To protect the service from abuse, fraud, and outages.
- To contact you about the service (for example, password resets or material changes to this policy).
- To fix bugs and improve the product.
- To understand, in aggregate, how features are used so we can decide what to improve next.
- To run optional programmes you take part in, such as referral rewards.
We do not sell your personal information. We do not use it for advertising.
Under the UK GDPR we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) to create your account, deliver the core features of the Service, and keep your session active.
- Legitimate interests (Art. 6(1)(f)) to protect the Service from abuse and fraud, to diagnose and fix errors, and to maintain the integrity of our ranking system.
- Legal obligation (Art. 6(1)(c)) where we are required to retain or disclose information to comply with applicable law.
- Consent (Art. 6(1)(a)) where you choose to submit optional information (for example, a profile picture).
3. Apple Health (HealthKit)
If you use FinalPoint on iPhone and grant permission, we read a limited set of workout data from Apple Health to power the optional “log your workout as a match” feature:
- Recent racket-sport workouts (tennis, badminton, table tennis, pickleball) — their type, start and end time, and duration.
- The average and maximum heart rate recorded during a workout.
- The active energy (calories) burned during a workout.
We use this data only to detect a recent workout and offer to log it as a match, and to store the heart rate, calories, and duration alongside the match you create so you can see your effort over time. We do not write any data back to Apple Health.
Apple Health data is read only with your explicit permission, which you grant through the standard iOS Health prompt and can withdraw at any time in the iOS Settings or Health app. The heart rate and calorie figures stored with a match are visible only to you — not to your opponents or other group members. We never use Apple Health data for advertising or marketing, never sell it, and never share it with third parties for those purposes; it is processed solely to provide the feature described above and stored in our Supabase database. This use complies with Apple’s HealthKit terms.
4. Who we share information with
We share information with a small number of data processors who process it on our behalf under written contracts that comply with Article 28 of the UK GDPR:
- Supabase (database, authentication, file storage). Hosting may be located in the European Union or United States.
- Vercel (application hosting and delivery). Hosting may be located in the United States or European Union.
- Cloudflare (DNS and edge proxy in front of our hosting; handles connection metadata such as IP address and request headers). Cloudflare also provides the invisible bot-check (Turnstile) on our sign-in and sign-up forms.
- Sentry (error monitoring, receives diagnostic logs when the app crashes). Hosting located in the European Union (Germany).
- PostHog (product analytics). Hosting located in the European Union. Receives the usage events described in section 1, tied to a random identifier stored on your device and to your account ID once you sign in; configured to never receive names, email addresses, message content, or match scores.
- RevenueCat (subscription management for the paid tiers — Rally and Pro). Hosting located in the United States. Only receives an identifier we generate for your account and the subscription status; never your email or password. Purchases made on the web run through RevenueCat’s checkout with payment processed by Stripe; your card details go directly to the payment processor and never touch our servers.
- Apple and Google (in-app purchase, push notifications, and platform analytics when you use the mobile app). Push notifications are delivered through their notification services (the Apple Push Notification service and Google’s Firebase Cloud Messaging), which hold a delivery token for each of your devices. Each platform’s own privacy policy applies to data they hold about you as a platform user.
We share information with other players in the context of play: the other members of any group you join see your display name, username, profile picture, and match results for that group; if you record a match against another FinalPoint user without a shared group (a “Quick Match”), that match and your public profile fields are visible to them. Messages you send are visible to the people in the conversation: the other person in a direct message, or every member of the group for a group chat. Beyond that we only disclose information when required by law or to protect the rights, property, or safety of our users. Section 5 describes what is visible more widely, including to people who are not signed in.
5. Your profile and what others can see
You have a public profile page at thefinalpoint.app/profile/<your username>. By default it is visible to anyone who has the link, including people without a FinalPoint account, and it powers the preview card messaging apps generate when the link is shared. It shows your display name, username, avatar, bio, the date you joined, your per-sport EVO ratings and records, your most recent confirmed matches, and a selection of your achievements.
You can make your profile private at any time from Settings. A private profile shows visitors only your name, avatar, and join date. People in your groups still see your activity inside the groups you share, and your matches remain visible to the people you played them with.
- Group invite links: anyone who opens an invite link sees the group’s name, sport, member names and avatars, and recent match activity before signing in. Only share an invite link with people you want in the group.
- Clubs: a verified, listed Club is semi-public. Its name, description, location, sports, and member count are visible to anyone browsing discovery or holding its link, including people who are not signed in. Announcements a Club posts are visible to its members. Joining a Club requires you to be 18 or older and to have a display name, photo, and date of birth on your profile.
- Global leaderboards: once you have 20 or more confirmed games in a sport, you can appear on that sport’s global leaderboard, visible to signed-in players. Players with private profiles are not shown.
- Username search: signed-in players can find you by your @username, for example to record a match against you. Blocking a player removes you from their search results and stops their messages.
- Community pages: publicly listed communities have a public page showing only aggregate figures such as member count and recent activity. Your name does not appear there to signed-out visitors.
6. Data retention
We keep account and match data for as long as your account is active. You can delete your account yourself at any time from Settings → Delete my account, or by emailing us. Deletion is immediate and permanent: your profile, sign-in credentials, push subscriptions, in-app inbox, RSVPs, group memberships, friendships, blocks, and reports are removed, and the messages you sent in direct messages and group chats are permanently deleted (a direct-message conversation disappears for the other person too). If you sign up again with the same email later, you get a brand new account — none of the old data is brought back. Matches you played in are preserved for the other players’ records, but where your name used to appear opponents will see “Unknown player.” Anonymous account-deletion feedback you provide is kept for product research and is not linked to you. Error logs in Sentry are retained for up to 90 days.
Deleting your account does not cancel a paid subscription. If you subscribed through the App Store or Google Play, cancel the subscription there (or from Settings → Subscription) before deleting your account, otherwise the store may continue to bill you.
If you delete an individual chat message while your account is open, it disappears from the app for everyone immediately; we may keep the underlying record for a limited time so we can act on abuse reports about it.
When you delete a match, it disappears from the app straight away and is permanently purged from our database within 7 days. That short window exists only so you can restore a match you deleted by mistake; once it passes, the record is gone for good.
Safety-related records are kept separately, even after you delete your account, because we have a legitimate interest in detecting repeat-offender behaviour and complying with our obligations under the UK Online Safety Act 2023. Specifically:
- Reports filed about you and the moderation action taken on them: kept for up to 3 years from the report date.
- Match disputes you opened or were the subject of: kept for up to 2 years from resolution.
- Moderation audit log entries (warnings, suspensions, bans against any account): kept for up to 5 years from the action date.
These records contain only the minimum needed to recognise a repeat incident: the action taken, the reason, the timestamp, and the internal account identifier. They do not retain your name, email, or any other identifying contact details after deletion.
7. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Delete your account and the data associated with it.
- Export a copy of your data in a portable format. You can do this yourself at any time from the app’s Career page, which downloads your full profile and match history as JSON or CSV.
- Object to or restrict certain kinds of processing.
- Lodge a complaint with your local data protection authority. In the United Kingdom this is the Information Commissioner’s Office (ICO), reachable at ico.org.uk/make-a-complaint.
To exercise any of these rights, email info@thefinalpoint.app. We will respond within 30 days (or sooner where required by law). We may need to verify your identity before acting on a request.
8. Children
FinalPoint is not intended for children under 13. We do not knowingly collect information from anyone under 13. If you believe a child has given us personal information, contact us and we will delete it.
Some features, including community groups, require you to be 18 or older. We verify age by asking for your date of birth at sign-up and relying on that information; we do not currently use third- party age-verification services or government ID checks. If we become aware that someone under the required age has accessed a restricted feature, we will remove that access.
9. Security
We protect data in transit with HTTPS, at rest with encryption provided by our hosting and database providers, and through row-level access controls so users can only read rows they have permission to see. No system is perfectly secure; we work in good faith to minimise risk.
10. International transfers
Our service providers may process data outside your country of residence, including in the United States and the European Union. Where required, we rely on standard contractual clauses or other lawful transfer mechanisms.
11. Cookies and local storage
We use a small number of cookies that are strictly necessary to sign you in and keep your session active. We do not use advertising or tracking cookies.
The app also stores a few small values in your browser’s local and session storage to remember preferences between visits. These never leave your device and contain no personal information:
- Whether you’ve dismissed the “Add to home screen” prompt.
- Which version of the in-app changelog you’ve already seen.
- A flag marking that the loading-screen tip of the day has already been shown once in the current tab.
Our analytics tool (PostHog, see section 4) stores a random identifier so repeat visits from the same device are counted as one person. On the web, because this is not strictly necessary, we only set it after you accept analytics on the consent banner shown when you first open FinalPoint; if you decline, PostHog is never loaded and no identifier is stored. In the mobile app, product analytics are on by default and can be turned off at any time in the app’s Settings. When enabled, it is used only to understand how the product is used, never for advertising, and is not shared with anyone else.
12. Community groups
When you join a community group, certain information about you becomes visible to other members of that same group:
- Your display name, username, and avatar.
- Matches you log inside that community group, including the score and the people you played against.
- Your rank on that community’s leaderboard for the last 30 days.
Information that stays private to you alone (not shared with other community members) includes your date of birth, email address, matches from outside that community group, the other communities you belong to, your friend list, and your location. Matches you log in a community group can appear among the recent matches on your profile page while it is public (see section 5); make your profile private if you do not want that.
The lawful basis for this sharing is performance of the contract you enter into with us when you join a community group (UK GDPR Art. 6(1)(b)) and our legitimate interest in keeping community groups safe, fair, and accurate (Art. 6(1)(f)).
Community groups require you to be at least 18. Full rules and expectations are in our Community Standards.
13. Illegal content and platform safety
FinalPoint is a user-to-user service under the UK Online Safety Act 2023. We take steps to detect and remove illegal content as soon as we are made aware of it, including content that promotes terrorism, child sexual exploitation, fraud, the sale of illegal goods, the encouragement of suicide or self-harm, or harassment that meets the threshold of a criminal offence. If you encounter content of this kind on FinalPoint, please report it through the in-app Report menu or email info@thefinalpoint.app. We aim to act on safety-related reports within 24 hours. If you are in immediate danger, contact your local emergency services first.
14. Changes to this policy
We may update this policy from time to time. When we make material changes we’ll update the date at the top and, where appropriate, notify you by email or through the app.
15. Contact
Questions, concerns, or requests about this policy can be sent to info@thefinalpoint.app.