Effective August 18, 2026
Privacy without a profile.
The core room does not require a public profile, email address, or password.
Shared room data
Supabase stores a random anonymous user ID, GP-scoped choices and mood reasons, public Forza / Basta banners, reactions, report reasons, timestamps, a random browser session key with campaign context, and security information needed to prevent abuse. An unlinkable referral token can connect one completed share to a later arrival and confirmed feeling without identifying either fan. A daily rotating one-way network fingerprint supports short-term limits; Pulse does not store the raw IP address in its application tables. If you explicitly request a one-time Court or next-flag callback, Pulse also stores the browser push endpoint and encrypted delivery keys needed for that alert.
What stays on this device
An unsent public-banner draft, callback intent, immediate local copy of room choices, and pending browser subscription replacement may remain in browser storage. The anonymous Supabase session also stays on the device so vote limits, author controls, and deletion keep working. A callback also leaves a Web Push subscription and notification permission that you can revoke in browser settings. Clearing site data removes this device state.
Why data is used
Data is used to show live room totals, prevent vote inflation, deliver public discussion, moderate reports, operate the service, send one requested Court alert if evidence arrives early enough, or return you once when the selected GP opens from a verified flag.
How long it stays
Only the current GP room is public. Each shared vote, mood reason, banner, reaction, and report is kept for up to 180 days from that row's own creation or latest applicable update. An aged anonymous account is removed only after no retained room, event, callback, moderation, or publication row still points to it. Basic product and referral events are kept for 90 days, write-limit events for 30 days, and daily network fingerprints for two days. Those fingerprints use SHA-256 HMAC with a random database-private daily key; Pulse stores neither the raw address nor that key in public application data. A Court subscription expires no later than its evidence window or the final hour of the room. A next-flag subscription lasts only for the selected GP and expires no later than 45 days after opt-in or eight hours after that race starts. Endpoints and encrypted keys are deleted before the one delivery attempt, at expiry, or during the daily purge. A one-time click receipt expires within 30 days; aggregate delivery totals contain no endpoint or encryption key. Every GP requires an explicit opt-in, although the browser's push provider may reuse the same transport endpoint.
Delete your room data
Delete only the current anonymous account to remove its linked votes, mood reasons, banners, reactions, reports, and pending push subscriptions immediately. Email and moderator identities are rejected by this public deletion control. Confirmed participation events are linked to that random anonymous account ID while the account exists; deleting the account removes that link, and the remaining event expires on the schedule above. Credential-free delivery aggregates and click receipts are not linked to that account.
The action opens the shared deletion control on Tifosi Pulse and asks for confirmation before the server deletes anything.
Delete my room dataProviders
Supabase provides authentication, database, and live delivery. Vercel provides hosting. Cloudflare Turnstile provides bot protection. The push service selected by your browser transports an encrypted callback only after you opt in.
Contact
Privacy and deletion questions can be sent to privacy@tifosipulse.com.