Privacy Policy — Il Sassarese Medio
Last updated: August 10, 2026
This policy explains how Il Sassarese Medio (the "Controller") processes personal data in the Il Sassarese Medio app for iOS and Android and on the website.
1. Data controller and contact details
The data controller is Pulse Stack Labs Limited, registered at 9 EDENVALE RD, D06 TD85, DUBLIN — IRELAND. For questions about data processing or to exercise the rights described below, email [email protected].
2. Data processed and purposes
| Data | Purpose | Legal basis |
|---|---|---|
| Display name, email, account ID and credentials managed by the authentication service | Create and manage the account, provide access and password recovery | Performance of a contract or pre-contractual measures (Article 6(1)(b) GDPR) |
| Optional answers about interests, use of local apps and relationship with Sassari | Personalise content and understand aggregate interest; answers may be changed or left blank | Consent, where required (Article 6(1)(a) GDPR) |
| Technical Supabase identifier created anonymously on the first vote or reaction | Apply per-identity limits without requiring immediate registration | Performance of the service and legitimate interest in preventing abuse (Article 6(1)(b)/(f) GDPR) |
| Article reactions and poll votes | Record one interaction per technical identity or account and display aggregate results | Performance of the service (Article 6(1)(b) GDPR) |
| Turnstile token, verification result, hostname/action and one-time technical proof stored only as a hash | Verify that the first participation is not automated and prevent abuse | Legitimate interest in service security (Article 6(1)(f) GDPR) |
| Digital card: display name, card status and opaque QR code | Provide the card and, when requested, add it to Apple Wallet or Google Wallet | Performance of the service (Article 6(1)(b) GDPR) |
| Random installation identifier, FCM token, platform, authorisation status and notification preferences | Send selected push notifications and manage delivery on the device | Consent for notifications and access to device functions (Article 6(1)(a) GDPR) |
| Hashed installation identifier, opened article and opening date | Measure approximate, deduplicated article opens | Legitimate interest in evaluating content use with pseudonymised data (Article 6(1)(f) GDPR) |
| App usage events, viewed screens and feature interactions | Understand aggregate app use and improve content and features | Consent through App Tracking Transparency on iOS where applicable; legitimate interest for essential measurement on Android (Article 6(1)(a)/(f) GDPR) |
| Content of a support request | Respond to the request | Performance of the service or legitimate interest in providing support (Article 6(1)(b)/(f) GDPR) |
The app does not collect IP addresses or advertising identifiers to count article opens. The card QR contains an opaque UUID, not the user's name, email or ID.
3. Accounts and public content
Browsing Home, Explore, public articles and polls does not require registration. On the first vote or reaction, the app may create an anonymous Supabase technical identity, separate from the installation identifier. This identity has no Profile, Card, interests, avatar or Wallet.
If you later register by email, Google or Apple, the technical identity is converted or linked while retaining interactions. If you sign in to an existing account, compatible interactions are transferred; where the guest and account have already interacted with the same content, the account choice takes precedence.
Individual reactions and votes are not public. Other users see only aggregate reaction counts and poll results according to the rules shown in the app.
4. Push notifications
Notifications are optional and can be authorised, disabled or changed in the app and device settings. The app uses Firebase Cloud Messaging (FCM); on iOS, delivery also uses Apple Push Notification service (APNs). Notifications contain only a content type and technical identifier, not sensitive data.
Turning off the main notification switch removes FCM topic subscriptions. Local preferences may remain on the device so they can be restored if notifications are enabled again.
5. Providers and recipients
Data is processed by authorised personnel of the Controller and, where necessary, by providers acting as processors or independent controllers under their terms. In particular:
- Supabase provides authentication, database, server functions and storage;
- Cloudflare provides Turnstile for anti-abuse verification of first participation and may process technical data, including the IP address, under its own policy;
- Google Firebase and Google Analytics provide push notifications and aggregate app usage measurement;
- Apple supports notification delivery on iOS and, when requested, adding the card to Apple Wallet;
- Google supports Google sign-in, FCM and, when requested, adding the card to Google Wallet.
Opening YouTube videos, the merchandise store, shared links or other external links takes place on the relevant services. Those providers' privacy policies govern their processing.
Where a provider processes data outside the European Economic Area, the Controller adopts the safeguards required by the GDPR, such as adequacy decisions or standard contractual clauses, where applicable.
6. Security
Access to personal data is limited to the account owner and authorised personnel where necessary. The backend applies row-level access controls; sensitive operations such as voting, reactions and account deletion are handled server-side. Administrative keys, Wallet certificates and provider credentials are not included in the app.
7. Account deletion
You can delete a registered account from the Profile section of the app. The request deletes the authentication user and linked owned data, including the profile and card, according to the database's technical relationships. The device installation may remain registered without an account link solely for technical notification management. To exercise rights concerning an anonymous technical identity, contact the Controller using the details above.
Account deletion does not remove data that the Controller must retain by law, to establish or defend a legal claim, or data already anonymised or aggregated.
8. Retention
- account and card data: until account deletion, subject to legal obligations;
- anonymous technical identity, votes and reactions: retained to keep uniqueness and results stable; the first version has no automatic deletion, subject to a data-subject request or future archiving policy;
- Turnstile proofs: five minutes and one use; guest merge tokens: up to 24 hours and one use;
- push preferences and installation data: until deactivation or token replacement;
- support requests: for the time needed to respond and for 30 days.
9. Data-subject rights
Where Articles 15–22 GDPR apply, you may request access, rectification, deletion, restriction, portability and objection, or withdraw consent without affecting the lawfulness of earlier processing. Email [email protected]. You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
10. Changes to this policy
The Controller may update this policy to reflect legal or service changes. The updated version will show its latest revision date and will be made available before material changes take effect.

