Sfyra

Informativa privacy

Quali dati raccoglie Sfyra, perché, chi li vede e come farli sparire. Nessuna profilazione pubblicitaria, nessuna vendita di dati a terzi.

Versione 2026-08-18

1. Chi tratta i tuoi dati

Il titolare del trattamento è Alessandro Termine, persona fisica, che gestisce l'applicazione Sfyra.

Per qualsiasi cosa riguardi i tuoi dati, compreso l'esercizio dei diritti elencati al punto 7, scrivi a sfyra.app@gmail.com.

Sfyra non ha un responsabile della protezione dei dati: non ricorre nessuno dei casi in cui la legge lo impone.

2. Cosa raccogliamo quando crei l’account

Il tuo indirizzo email, che identifica l’account e serve a recuperare la password. Se entri con Google, riceviamo da Google l’email, il nome e l’immagine del profilo — non la password.

La password, solo se non usi Google. Non la vediamo: la custodisce Firebase Authentication in forma cifrata.

Il nome che scegli e, se vuoi, una foto profilo: sono quelli che vedono i tuoi compagni di sfida. La foto è facoltativa e puoi toglierla quando vuoi.

La data di nascita, che serve a verificare l’età minima del punto 8. Resta privata: non la vede nessun altro utente e non compare in nessuna schermata dell’app.

La lingua dell’app, per mandarti le notifiche nella lingua giusta, e la versione del regolamento che hai accettato con la data in cui l’hai fatto.

Le tue preferenze sul promemoria giornaliero — se lo vuoi e a che ora — e il fuso orario del telefono, che serve solo a far arrivare quel promemoria all’ora che hai scelto. Restano privati.

3. Cosa raccogliamo mentre usi l’app

L’obiettivo che scrivi, il titolo della sfida, la durata, la frequenza e la posta in gioco. L’obiettivo e il titolo li vede il tuo gruppo; se chi ha creato la sfida la mette in vetrina, li vedono tutti gli utenti di Sfyra.

Il «perché lo voglio» resta privato. Non lo vede nessun altro partecipante, non compare in vetrina, non esce mai dal tuo profilo.

I check-in giornalieri, con la nota e la foto se decidi di aggiungerle, le spinte che dai e che ricevi, e i conteggi che ne derivano — giorni fatti, giorni di fila, classifica. Li vedono i partecipanti alla stessa sfida.

Le richieste di partecipazione a una sfida pubblica: il tuo nome e la tua foto arrivano a chi l’ha creata, che decide se accettarti.

Le notifiche che ricevi, che restano consultabili nel centro notifiche, e — solo se dai il permesso alle notifiche — un identificativo tecnico del dispositivo, che serve a recapitarle e non identifica la persona.

Se segnali una sfida, registriamo il motivo che scegli, la nota che scrivi e il tuo nome: chi deve decidere ha bisogno di sapere cosa è stato segnalato e da chi. Il tuo nome non viene mostrato a chi subisce il provvedimento.

Non raccogliamo la tua posizione, la rubrica, la cronologia di navigazione, identificativi pubblicitari, né dati sulla salute richiesti come tali.

Attenzione a una cosa: un obiettivo che scrivi tu — «smettere di fumare», «tornare a dormire» — può dire qualcosa delle tue abitudini. Non ti chiediamo dati sanitari e non li trattiamo come tali, ma quello che scrivi lo decidi tu: se la sfida finisce in vetrina, l’obiettivo lo leggono tutti.

4. Perché possiamo trattarli

Per eseguire il contratto che nasce quando apri l’account (art. 6.1.b GDPR): account, sfide, check-in, foto, classifica e notifiche di servizio. Senza questi dati l’app non può funzionare.

Per adempiere a un obbligo di legge (art. 6.1.c): la verifica dell’età minima, richiesta dall’art. 8 GDPR.

Per un legittimo interesse (art. 6.1.f): tenere il servizio sicuro, prevenire gli abusi, gestire le segnalazioni. I dati usati sono gli stessi già necessari al servizio.

Sulla base del tuo consenso (art. 6.1.a): le notifiche push, che autorizzi dal sistema operativo e puoi revocare quando vuoi dalle impostazioni del telefono.

Fornire i dati non è obbligatorio, ma senza non è possibile aprire un account né partecipare a una sfida. La foto profilo e le foto dei check-in restano sempre facoltative.

5. Chi altro li vede

Gli altri partecipanti alla tua sfida vedono il tuo nome, la tua foto profilo, i tuoi check-in con note e foto, i tuoi conteggi.

Se chi ha creato la sfida la mette in vetrina, tutti gli utenti di Sfyra vedono l’obiettivo, il titolo, il nome di chi l’ha creata e quante persone partecipano. Non i check-in, non le foto, non i nomi degli altri partecipanti.

Google Ireland Limited, come responsabile del trattamento, per i servizi Firebase su cui l’app gira: accesso, database, archiviazione delle foto, funzioni server e notifiche push.

Chi gestisce Sfyra, ma solo quando arriva una segnalazione. Se qualcuno segnala una sfida, il titolare ne vede il contenuto — obiettivo, titolo, posta in gioco — e, se serve a decidere, può aprire le foto dei check-in di quella sfida. Ogni apertura resta registrata: chi ha guardato, cosa, quando e per quale segnalazione, e quel registro non è cancellabile da nessuno. Senza una segnalazione nessuno guarda niente: non esiste alcun controllo sistematico dei contenuti.

Nessun altro. Non vendiamo, non cediamo e non condividiamo i tuoi dati con inserzionisti o intermediari pubblicitari.

6. Dove stanno, e per quanto

Il database, le foto e le funzioni server stanno su infrastruttura Google nell’Unione Europea. Le notifiche push possono transitare per l’infrastruttura globale di Google: per quei trasferimenti Google applica le clausole contrattuali standard della Commissione europea.

I dati restano finché tieni l’account: non c’è una scadenza automatica.

Puoi cancellare l’account quando vuoi, dalle impostazioni dell’app. La cancellazione è immediata e non è reversibile: spariscono profilo, iscrizioni, obiettivi, check-in, foto, notifiche e l’account di accesso.

Un’eccezione, dichiarata: nei riepiloghi delle sfide già chiuse restano i tuoi numeri, senza il tuo nome e senza la tua immagine. La classifica finale è la storia anche degli altri partecipanti, e riscriverla cancellerebbe la loro; quei numeri, staccati dal nome, non permettono più di risalire a te.

Se sei proprietario di una sfida ancora in corso, la sfida passa a chi è entrato per primo. Se non resta nessun altro, viene cancellata insieme all’account.

Le segnalazioni e il registro degli accessi restano finché serve a dimostrare come è stata presa una decisione. Il registro non lo cancella nessuno, nemmeno chi modera: è ciò che rende verificabile che una foto sia stata aperta per una ragione e non per curiosità.

Nel centro notifiche vedi gli ultimi sette giorni.

7. I tuoi diritti

Puoi accedere ai tuoi dati e chiederne copia, correggerli, cancellarli, limitarne il trattamento, opporti a quello fondato sul legittimo interesse, riceverli in un formato leggibile da una macchina e revocare il consenso alle notifiche.

Nome e foto li cambi da solo nelle impostazioni, e l’account lo cancelli da lì. Per tutto il resto scrivi a sfyra.app@gmail.com: rispondiamo entro un mese.

Non prendiamo decisioni automatizzate che producano effetti giuridici su di te, e non facciamo profilazione.

Se pensi che i tuoi dati siano trattati male puoi rivolgerti al Garante per la protezione dei dati personali (www.garanteprivacy.it) o all’autorità del paese in cui vivi.

8. Minori

Per usare Sfyra servono almeno 14 anni, o l’età superiore prevista dal tuo paese: 15 in Francia, 16 in Germania. La data di nascita serve a verificarlo.

Se hai meno di 18 anni, puoi usare Sfyra solo con il consenso di chi esercita la responsabilità genitoriale.

Se ci accorgiamo che un account appartiene a chi non ha l’età minima, lo cancelliamo.

9. Sicurezza

I dati viaggiano cifrati. L’accesso è regolato da regole che il server applica a ogni singola richiesta: nessuno può leggere le sfide di cui non fa parte, e i dati privati — data di nascita, il tuo «perché» — sono leggibili solo da te.

Nessun sistema è sicuro al cento per cento. Se dovesse verificarsi una violazione che comporta un rischio per i tuoi diritti, lo comunicheremo al Garante entro 72 ore e, quando la legge lo impone, anche a te.

10. Modifiche

Se cambiamo questa informativa in modo sostanziale te lo diciamo nell'app. La versione aggiornata è sempre a https://sfyra.app/privacy.


English

Privacy notice

What Sfyra collects, why, who sees it and how to make it disappear. No advertising profiling, no selling data to third parties.

Version 2026-08-18

1. Who processes your data

The data controller is Alessandro Termine, a natural person, who runs the Sfyra application.

For anything concerning your data, including the rights listed in section 7, write to sfyra.app@gmail.com.

Sfyra has no data protection officer: none of the cases in which the law requires one apply here.

2. What we collect when you create the account

Your email address, which identifies the account and lets you recover the password. If you sign in with Google, we receive your email, name and profile picture from Google — not your password.

Your password, only if you are not using Google. We never see it: Firebase Authentication keeps it encrypted.

The name you pick and, if you want, a profile photo: these are what your challenge mates see. The photo is optional and you can remove it whenever you like.

Your date of birth, used to check the minimum age in section 8. It stays private: no other user sees it and it appears nowhere in the app.

The app language, so notifications reach you in the right one, and the version of the rules you accepted together with the date you did.

Your daily reminder preferences — whether you want it and at what time — and your phone’s time zone, used only to make that reminder arrive at the hour you picked. They stay private.

3. What we collect while you use the app

The goal you write, the challenge title, its length, its frequency and what is at stake. Your group sees the goal and the title; if the person who created the challenge puts it on the public shelf, every Sfyra user sees them.

Your “why I want it” stays private. No other participant sees it, it never appears on the shelf, it never leaves your profile.

Your daily check-ins, with the note and photo if you choose to add them, the cheers you give and receive, and the counts that follow — days done, streak, standings. Participants in the same challenge see them.

Requests to join a public challenge: your name and photo reach whoever created it, who decides whether to let you in.

The notifications you receive, which stay readable in the notification centre, and — only if you allow notifications — a technical device identifier, used to deliver them, which does not identify the person.

If you report a challenge, we record the reason you pick, the note you write and your name: whoever has to decide needs to know what was reported and by whom. Your name is not shown to whoever the decision affects.

We do not collect your location, your contacts, your browsing history, advertising identifiers, or health data as such.

One thing to keep in mind: a goal you write yourself — “quit smoking”, “sleep properly again” — can say something about your habits. We do not ask for health data and do not treat it as such, but what you write is your choice: if the challenge goes on the public shelf, everyone reads the goal.

4. Why we are allowed to

To perform the contract that starts when you open the account (art. 6.1.b GDPR): account, challenges, check-ins, photos, standings and service notifications. Without this data the app cannot work.

To comply with a legal obligation (art. 6.1.c): the minimum-age check required by art. 8 GDPR.

For a legitimate interest (art. 6.1.f): keeping the service safe, preventing abuse, handling reports. The data used is the same the service already needs.

On your consent (art. 6.1.a): push notifications, which you allow through the operating system and can withdraw at any time in your phone settings.

Providing this data is not compulsory, but without it you cannot open an account or take part in a challenge. The profile photo and the check-in photos are always optional.

5. Who else sees it

The other participants in your challenge see your name, your profile photo, your check-ins with notes and photos, your counts.

If the person who created the challenge puts it on the public shelf, every Sfyra user sees the goal, the title, the creator’s name and how many people are taking part. Not the check-ins, not the photos, not the other participants’ names.

Google Ireland Limited, as processor, for the Firebase services the app runs on: sign-in, database, photo storage, server functions and push notifications.

Whoever runs Sfyra, but only when a report comes in. If someone reports a challenge, the controller sees its content — goal, title, stake — and, if it helps to decide, may open that challenge’s check-in photos. Every opening is logged: who looked, at what, when and for which report, and that log cannot be deleted by anyone. Without a report nobody looks at anything: there is no systematic monitoring of content.

Nobody else. We do not sell, transfer or share your data with advertisers or ad intermediaries.

6. Where it lives, and for how long

The database, the photos and the server functions sit on Google infrastructure in the European Union. Push notifications may travel through Google’s global infrastructure: for those transfers Google applies the European Commission’s standard contractual clauses.

Data stays as long as you keep the account: there is no automatic expiry.

You can delete the account whenever you want, from the app settings. Deletion is immediate and cannot be undone: profile, memberships, goals, check-ins, photos, notifications and the sign-in account all go.

One stated exception: in the recaps of challenges already closed, your numbers remain, without your name and without your picture. The final standings are the other participants’ story too, and rewriting them would erase theirs; those numbers, detached from the name, no longer lead back to you.

If you own a challenge still running, it passes to whoever joined first. If nobody is left, it is deleted along with the account.

Reports and the access log stay for as long as they are needed to show how a decision was made. Nobody deletes the log, not even whoever moderates: it is what makes it verifiable that a photo was opened for a reason and not out of curiosity.

The notification centre shows the last seven days.

7. Your rights

You can access your data and ask for a copy, correct it, erase it, restrict its processing, object to processing based on legitimate interest, receive it in a machine-readable format and withdraw your consent to notifications.

You can change your name and photo yourself in the settings, and delete the account from there. For anything else write to sfyra.app@gmail.com: we answer within one month.

We take no automated decisions producing legal effects on you, and we do not profile you.

If you believe your data is being mishandled you can turn to the Italian data protection authority (www.garanteprivacy.it) or to the authority of the country you live in.

8. Minors

You must be at least 14 to use Sfyra, or the higher age your country sets: 15 in France, 16 in Germany. The date of birth is what checks it.

If you are under 18, you may use Sfyra only with the consent of whoever holds parental responsibility for you.

If we find that an account belongs to someone under the minimum age, we delete it.

9. Security

Data travels encrypted. Access is governed by rules the server applies to every single request: nobody can read challenges they are not part of, and private data — date of birth, your “why” — is readable only by you.

No system is completely secure. Should a breach occur that puts your rights at risk, we will report it to the supervisory authority within 72 hours and, where the law requires, to you as well.

10. Changes

If we change this notice substantially we will say so in the app. The current version is always at https://sfyra.app/privacy.