LEGAL

Privacy &
Rules.

UPDATED AUGUST 4, 2026 · V3
Privacy Rules 21+
TL;DR
01 Data controller: ENSITICS.IO (SAS), 1 rue de Stockholm, 75008 Paris, France — Section 12 below.
02 We collect: email, login data, your picks history. In the mobile app — also your device ID, purchase history and what you do in the app.
03 In the app, subscriptions are bought through Apple. We never see your card.
04 We don't sell your data. Ever.
05 You can delete your account at any time.
06 Predictions are signals — not guarantees.
07 You must be 21+ to use Ensitics.
SECTION 01

Information We Collect

1.1 Personal Information

We collect information you provide directly to us, including:

  • Email address for account registration.

  • Profile information from social sign-in providers — Google on the website; Google and Apple in the iOS app; Google only in the Android app. Section 10.4 lists what each provider passes to us.

  • Payment information. On the website, payments are processed by Stripe. In the mobile app, subscriptions are sold and processed by the app store you bought them from: Apple through In-App Purchase on iOS, Google through Google Play Billing on Android. In every case your card details go straight to the payment provider and are never stored on our servers. See Section 10.1.

  • Payout details, if you take part in our referral programme and request a payout: the PayPal address, bank account or crypto-wallet address you choose. Unlike card details, these are stored on our servers — see Sections 03, 04 and 07.

  • Communication preferences and settings.

1.2 Usage Information

We automatically collect information about your use of our platform:

  • Pages visited and features used.

  • Time spent on the platform.

  • Device and browser information.

  • IP address and general location data.

SECTION 02

How We Use Your Information

We use the information we collect to:

  • Provide and maintain our esports analytics services.

  • Process subscription payments and manage your account.

  • Send important updates about our services.

  • Improve our platform and develop new features.

  • Ensure platform security and prevent fraud.

  • Comply with legal obligations.

2.1 Legal Bases for Processing

Under the GDPR we rely on the following legal bases:

  • Performance of a contract — creating and running your account, delivering predictions, selling and managing your subscription.

  • Legitimate interests — platform security, fraud and abuse prevention, and the measurement we need to keep the service working. Outside the countries where we ask for prior consent, this basis also covers the server-side campaign measurement described in Section 03. We weigh these against your rights, and you can object at any time (Section 08).

  • Consent — product analytics, marketing messages and any non-essential cookies. You give it explicitly and can withdraw it at any time; withdrawal does not affect processing already carried out.

  • Legal obligation — keeping accounting and payment records for the periods tax law requires.

2.2 Automated Decision-Making

Our predictions are generated by automated models, but they are informational content. They do not produce legal effects concerning you and do not similarly significantly affect you, so we do not carry out automated decision-making within the meaning of Article 22 GDPR.

SECTION 03

Information Sharing

We never sell your personal information and we never trade it. We share it with third parties in the following cases:

  • To trusted service providers who help us operate the platform: Stripe (payments on the website), Apple (in-app purchases and subscription billing in the iOS app), Google (in-app purchases, push notifications, sign-in and app integrity checks in the Android app), Abios (esports data).

  • To analytics and marketing platforms — Google Analytics, Meta, TikTok, X, Reddit and Brevo — to measure how the website and our campaigns perform. This applies to the website only; it does not happen in the mobile app. Everything these platforms set or read in your browser happens only with your consent. Server-side conversion events (such as "signed up" or "purchased") are sent only with your consent if you are in the EU/EEA, the United Kingdom, Switzerland or Brazil; elsewhere we send them under our legitimate interest in measuring our advertising (Section 02.1) — unless you have declined, because declining stops these events wherever you are.

  • If you joined Ensitics through an invite link or an invite code, the person who invited you earns a commission on our revenue from your payments. In their referral dashboard they see your email address only in masked form (like m•••@example.com), plus the commission amount, status and date — never your card details, your invoices or what exactly you bought. If you delete your account, even the masked reference is removed and their dashboard shows a dash.

  • If you are a referral partner and request a payout, we pass the payout details you gave us — a PayPal address, bank account or crypto-wallet address — to the provider that executes the transfer, and to no one else.

  • When required by law or to protect our rights.

  • With your explicit consent.

Some of our service providers are located outside the European Economic Area. Where that is the case, the transfer relies either on an adequacy decision of the European Commission or on the European Commission's Standard Contractual Clauses, with additional safeguards where they are required. Write to privacy@ensitics.io for a copy of the safeguards that apply.

SECTION 04

Data Security

We implement appropriate security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Payment information is never stored on our servers: on the website it is processed by Stripe, and in the mobile app by Apple or Google, depending on the store you bought through. The one exception is referral payouts: the payout details partners give us (Section 01) are stored on our servers so we can execute the transfer and account for it.

SECTION 05

Cookies and Tracking

We use cookies and similar technologies in three categories:

  • Strictly necessary — sign-in, session and security. The site cannot work without them, and they are set without consent.

  • Analytics — how the site is used, so we can fix and improve it. Set only with your consent.

  • Marketing and measurement — measuring how our campaigns perform. Set only with your consent.

  • Referral attribution — if you open an invite link, one first-party cookie (ensitics_ref) remembers the invite code for 60 days so the invitation can be credited when you register. We set it only when you follow such a link — that click is the request it serves. It is not used for anything else and is never shared.

We ask before setting anything that is not strictly necessary, and declining is as easy as accepting. You can change or withdraw your choice at any time through the consent banner; withdrawal takes effect going forward. The mobile app does not use cookies: your session and settings are stored locally on your device.

SECTION 06

Third-Party Services

Our platform integrates with third-party services:

  • Social sign-in providers — Google on the website; Google and Apple in the iOS app; Google only in the Android app.

  • Stripe — payment processing on the website.

  • Apple In-App Purchase and Google Play Billing — subscription purchases and billing in the mobile app, Apple on iOS and Google on Android.

  • Abios API — esports data.

  • Analytics and marketing platforms — Google Analytics, Meta, TikTok, X, Reddit, Brevo. Website only; Section 03 describes exactly when they receive data and on which legal basis.

  • The mobile app contains no third-party advertising, attribution or analytics SDKs.

Each service has its own privacy policy governing the use of your information.

SECTION 07

Data Retention

We keep personal data only as long as we need it. In practice:

  • Account data — as long as your account exists. When you delete it, the account and the data linked to it go, except what we must keep by law.

  • Analytics events — 180 days, then deleted automatically.

  • Payment and subscription records — for the period accounting and tax law requires; the raw payloads from the payment provider are stripped after 30 days and only the ledger entry remains.

  • Referral commission and payout records — for the same period as other payment and accounting records; when a referred account is deleted, the commission line keeps only an unlinked dash in place of that person.

  • Push notification records — 30 days after they expire.

  • Web sessions — 7 days of inactivity.

  • Internal audit records of actions taken on an account — 5 years, because we need them to show what happened to an account and when.

  • On your device — the analytics queue holds events for at most 7 days; diagnostics are kept at most 30 days and never leave the device.

  • The optional reason you may give when deleting your account — kept for 24 months, then deleted. When we delete an account we overwrite your name, email address and identifiers, but the internal account record and its identifier stay, so this reason is pseudonymised rather than fully anonymous. We read it in aggregate to understand why people leave; we never use it to contact you.

You may request deletion of your account and associated data at any time.

SECTION 08

Your Rights

You have the right to:

  • Access your personal information.

  • Correct inaccurate information.

  • Request deletion of your data.

  • Withdraw consent for data processing.

  • Export your data in a portable format.

  • Object to processing based on our legitimate interests.

  • Ask us to restrict processing while we resolve a request you have made.

  • Lodge a complaint with the data protection authority of the country where you live or work, or where you believe the problem occurred.

How to ask, and when we answer. Send any request under this section to privacy@ensitics.io, from the email address on your account. If we cannot tell that the request is really yours, we will ask you for something that confirms it — we do that so we never hand your data to someone else. We answer within one month of receiving your request. If the request is complex, or if you have sent several, we may need up to two further months; in that case we will tell you inside the first month and say why. Answering is free. If we cannot do what you asked, we will tell you that and explain the reason.

SECTION 09

Age Restrictions

// 21+ Only

Our platform is intended for users 21 years of age and older. We do not knowingly collect personal information from individuals under 21.

SECTION 10

Mobile Application

This section covers the Ensitics mobile application. Sections 01–09 describe the platform as a whole; where the app works differently from the website, this section applies.

10.1 Purchases and Payments

Subscriptions bought inside the mobile app are sold and processed by the app store you bought them from: Apple through In-App Purchase on iOS, Google through Google Play Billing on Android.

  • Your payment details — card number, billing address and your Apple ID or Google account credentials — are handled entirely by that store. We never receive them, see them or store them.

  • The store sends us a purchase record: which product was bought, when, and whether the subscription is still active. We use it for nothing else.

  • Refunds, cancellations and billing disputes for in-app purchases are handled by that store under its own terms and privacy policy.

  • Stripe processes payments made on our website only. Stripe is not used in the mobile app and receives no data from it.

  • If you installed the app through an invite and later subscribe, the person who invited you earns a commission calculated on our proceeds from the store — Section 03 describes what they can and cannot see. Nothing extra is collected from you for this beyond the referral code mentioned in 10.5.

10.2 Device Identifiers and Purchase History

The app sends us a device identifier and an app installation identifier, together with your purchase and subscription history — which plan you bought, when it started, when it renews or expires, and whether it is currently active. The device identifier is a random value we generate and keep in your device's secure storage: the keychain on iOS and the Android Keystore on Android. It is not Apple's advertising identifier and not the vendor identifier, and on Android it is neither the Google Advertising ID nor the Android ID. This information is linked to your Ensitics account. We use it to:

  • confirm that your subscription is active and unlock paid features;

  • restore your subscription when you reinstall the app or sign in on another device;

  • detect duplicate or fraudulent purchases.

10.3 App Analytics

The app records a fixed, closed list of events — app opens, screen views, pricing views, taps on Pro calls to action, prediction views, prediction unlock attempts and referral link opens. We use them only to fix bugs, measure whether a feature does its job and decide what to build next.

  • This activity is linked to your Ensitics account and is sent only to Ensitics servers.

  • The app contains no third-party advertising, attribution or analytics SDKs. We do not use your app activity for advertising and we do not track you across other companies' apps or websites.

  • You can withdraw your consent to analytics at any time. When you do, the events still queued on your device are erased.

  • Crash, hang and performance diagnostics never leave your device. They are stored locally as bounded counters — no stack traces, no personal data — for at most 30 days, are excluded from device backups, and are erased when you log out or delete your account. We do not receive them.

  • On iOS, the only third-party library in the app that handles your data is Google Sign-In. On Android the app additionally uses Google Play Billing (purchases), Firebase Cloud Messaging (push notifications), Play Integrity (a check that the app and the device are genuine), Play Install Referrer (reading the invite code once, at install) and Google's Credential Manager (sign-in). All of them are Google components. None of them is an advertising, attribution or cross-app tracking SDK.

10.4 Signing In to the App

The app offers Google sign-in on both platforms, and Sign in with Apple on iOS. There is no Sign in with Apple on Android.

  • Sign in with Google — Google passes us your name, email address and profile picture. Depending on your Google account settings it may also pass a phone number and an approximate, city-level location.

  • Sign in with Apple (iOS only) — Apple passes us your name and email address. Apple lets you hide your real address and share a private relay address instead. If you choose that, we never learn your real email; messages we send still reach you through Apple's relay.

10.5 What the App Collects — Summary

The categories below match both the App Store privacy questionnaire ("App Privacy") and the Google Play Data safety form for this app. All of them are linked to your account; none of them are used for advertising or to track you across other companies' apps and websites.

  • Email address — sign-in, account, service messages (10.4; Section 01).

  • Name — account profile (10.4).

  • Phone number — only if your Google account passes one (10.4).

  • User ID — your Ensitics account identifier (Section 01).

  • Device ID — subscription checks, device sessions and restore (10.2).

  • Purchase history — subscription status and restore (10.1; 10.2).

  • Product interaction — the closed list of in-app events (10.3).

  • Other usage data — your referral code, if you installed the app from an invite link (10.3).

  • Other user content — the optional reason you give when deleting your account (10.6).

  • Coarse location — city level, only if passed by your sign-in provider (10.4; 1.2).

  • Other data types — additional data the Google Sign-In library declares when you sign in with Google (10.4).

10.6 Your Rights in the App

Everything in Section 08 applies to the app in full.

  • You can delete your account from inside the app or by writing to privacy@ensitics.io. Deleting your account removes your app activity, device identifiers and picks history from our systems.

  • If you give an optional reason when you delete your account, we keep it for 24 months to understand why people leave. It stays attached to a pseudonymised internal account record: your name, email address and identifiers are overwritten, but the internal record and its identifier remain. We never use the reason to contact you.

  • The store you bought through keeps its own record of your purchase and we cannot delete it — you manage it in your Apple ID settings or in your Google Play account. Deleting your Ensitics account does not cancel a store subscription: cancel it in Apple or Google Play as well, or it will keep renewing.

  • The app is for users aged 21 and over, the same as the website (Section 09).

SECTION 11

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

Languages. This policy is published in English, Russian, Portuguese, Spanish, Polish, German and French. English is the reference version: where a translation differs from it, the English wording is what we mean. This does not take away any right you have under the consumer or data protection law of your own country, and it does not stop you relying on the version in your own language where that law allows you to.

SECTION 12

Who We Are

ENSITICS.IO, société par actions simplifiée (SAS), registered in France under number 928 888 858 (RCS Paris), with its registered office at 1 rue de Stockholm, 75008 Paris, France, is the controller of the personal data described in this policy.

  • Write to us about anything in this policy — including any request under Section 08 — at privacy@ensitics.io, or by post to the address above.

  • We have not appointed a Data Protection Officer, because Article 37 GDPR does not require us to. Responsibility for data protection sits with the founder, reachable at the same address.

  • Our lead supervisory authority is the CNIL (Commission Nationale de l'Informatique et des Libertés), France. That does not limit the right described in Section 08 to complain to the authority in your own country.

CONTACT

Questions about your data? privacy@ensitics.io