Privacy Policy — Il Sassarese Medio

Last updated: August 10, 2026

This policy explains how Il Sassarese Medio (the "Controller") processes personal data in the Il Sassarese Medio app for iOS and Android and on the website.

1. Data controller and contact details

The data controller is Pulse Stack Labs Limited, registered at 9 EDENVALE RD, D06 TD85, DUBLIN — IRELAND. For questions about data processing or to exercise the rights described below, email [email protected].

2. Data processed and purposes

DataPurposeLegal basis
Display name, email, account ID and credentials managed by the authentication serviceCreate and manage the account, provide access and password recoveryPerformance of a contract or pre-contractual measures (Article 6(1)(b) GDPR)
Optional answers about interests, use of local apps and relationship with SassariPersonalise content and understand aggregate interest; answers may be changed or left blankConsent, where required (Article 6(1)(a) GDPR)
Technical Supabase identifier created anonymously on the first vote or reactionApply per-identity limits without requiring immediate registrationPerformance of the service and legitimate interest in preventing abuse (Article 6(1)(b)/(f) GDPR)
Article reactions and poll votesRecord one interaction per technical identity or account and display aggregate resultsPerformance of the service (Article 6(1)(b) GDPR)
Turnstile token, verification result, hostname/action and one-time technical proof stored only as a hashVerify that the first participation is not automated and prevent abuseLegitimate interest in service security (Article 6(1)(f) GDPR)
Digital card: display name, card status and opaque QR codeProvide the card and, when requested, add it to Apple Wallet or Google WalletPerformance of the service (Article 6(1)(b) GDPR)
Random installation identifier, FCM token, platform, authorisation status and notification preferencesSend selected push notifications and manage delivery on the deviceConsent for notifications and access to device functions (Article 6(1)(a) GDPR)
Hashed installation identifier, opened article and opening dateMeasure approximate, deduplicated article opensLegitimate interest in evaluating content use with pseudonymised data (Article 6(1)(f) GDPR)
App usage events, viewed screens and feature interactionsUnderstand aggregate app use and improve content and featuresConsent through App Tracking Transparency on iOS where applicable; legitimate interest for essential measurement on Android (Article 6(1)(a)/(f) GDPR)
Content of a support requestRespond to the requestPerformance of the service or legitimate interest in providing support (Article 6(1)(b)/(f) GDPR)

The app does not collect IP addresses or advertising identifiers to count article opens. The card QR contains an opaque UUID, not the user's name, email or ID.

3. Accounts and public content

Browsing Home, Explore, public articles and polls does not require registration. On the first vote or reaction, the app may create an anonymous Supabase technical identity, separate from the installation identifier. This identity has no Profile, Card, interests, avatar or Wallet.

If you later register by email, Google or Apple, the technical identity is converted or linked while retaining interactions. If you sign in to an existing account, compatible interactions are transferred; where the guest and account have already interacted with the same content, the account choice takes precedence.

Individual reactions and votes are not public. Other users see only aggregate reaction counts and poll results according to the rules shown in the app.

4. Push notifications

Notifications are optional and can be authorised, disabled or changed in the app and device settings. The app uses Firebase Cloud Messaging (FCM); on iOS, delivery also uses Apple Push Notification service (APNs). Notifications contain only a content type and technical identifier, not sensitive data.

Turning off the main notification switch removes FCM topic subscriptions. Local preferences may remain on the device so they can be restored if notifications are enabled again.

5. Providers and recipients

Data is processed by authorised personnel of the Controller and, where necessary, by providers acting as processors or independent controllers under their terms. In particular:

  • Supabase provides authentication, database, server functions and storage;
  • Cloudflare provides Turnstile for anti-abuse verification of first participation and may process technical data, including the IP address, under its own policy;
  • Google Firebase and Google Analytics provide push notifications and aggregate app usage measurement;
  • Apple supports notification delivery on iOS and, when requested, adding the card to Apple Wallet;
  • Google supports Google sign-in, FCM and, when requested, adding the card to Google Wallet.

Opening YouTube videos, the merchandise store, shared links or other external links takes place on the relevant services. Those providers' privacy policies govern their processing.

Where a provider processes data outside the European Economic Area, the Controller adopts the safeguards required by the GDPR, such as adequacy decisions or standard contractual clauses, where applicable.

6. Security

Access to personal data is limited to the account owner and authorised personnel where necessary. The backend applies row-level access controls; sensitive operations such as voting, reactions and account deletion are handled server-side. Administrative keys, Wallet certificates and provider credentials are not included in the app.

7. Account deletion

You can delete a registered account from the Profile section of the app. The request deletes the authentication user and linked owned data, including the profile and card, according to the database's technical relationships. The device installation may remain registered without an account link solely for technical notification management. To exercise rights concerning an anonymous technical identity, contact the Controller using the details above.

Account deletion does not remove data that the Controller must retain by law, to establish or defend a legal claim, or data already anonymised or aggregated.

8. Retention

  • account and card data: until account deletion, subject to legal obligations;
  • anonymous technical identity, votes and reactions: retained to keep uniqueness and results stable; the first version has no automatic deletion, subject to a data-subject request or future archiving policy;
  • Turnstile proofs: five minutes and one use; guest merge tokens: up to 24 hours and one use;
  • push preferences and installation data: until deactivation or token replacement;
  • support requests: for the time needed to respond and for 30 days.

9. Data-subject rights

Where Articles 15–22 GDPR apply, you may request access, rectification, deletion, restriction, portability and objection, or withdraw consent without affecting the lawfulness of earlier processing. Email [email protected]. You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

10. Changes to this policy

The Controller may update this policy to reflect legal or service changes. The updated version will show its latest revision date and will be made available before material changes take effect.