Privacy Policy

Effective: 2026-07-09 · Last updated: 2026-07-22

1. Data Controller

Responsible for data processing under GDPR:

Johannes Eremin
Dunantstraße 6
79110 Freiburg im Breisgau
Email: jhnnsrmn@protonmail.com

2. What data we process

SorareTerminal processes only the data necessary for service operation:

We do not store crypto wallet private keys server-side: wallet signing happens exclusively locally in the optional companion app on your device (non-custodial).

3. Legal basis

4. Retention period

5. Sub-Processors

The following services process user data on our behalf:

ServicePurposeLocation
Hetzner Online GmbHServer hosting (application)Germany (EU) — Nuremberg
Neon, Inc.Managed database (PostgreSQL) incl. backupsEU region (Frankfurt) — to be confirmed by operator
Sorare SASAuthentication, market dataFrance (EU)
Functional Software, Inc. (Sentry)Error tracking (on errors only, PII-reduced)USA — SCC / EU-US Data Privacy Framework
Telegram (Group LLP)Notification channel (optional)UK
Google LLC (Gmail SMTP)Auth emails + notificationsUSA — SCC / DPF
Google LLC (Gemini API, optional)AI analysis using your own API key — only if usedUSA — SCC / DPF

6. Cookies

SorareTerminal uses only technically necessary cookies plus a language preference you choose:

We use no tracking cookies, no third-party cookies, no Google Analytics. As all cookies are strictly necessary or a deliberate user setting, no consent is required under § 25(2) TDDDG.

7. Your rights

No automated decision-making: No automated decision-making or profiling within the meaning of Art. 22 GDPR producing legal effects takes place.

8. Server location, third-party content, encryption

The application server runs at Hetzner Online GmbH in Germany (Nuremberg). The database is hosted as a managed service by Neon, Inc. (EU region Frankfurt — to be confirmed by operator).

Third-party content: In the logged-in area (dashboard), images (cards, players, club logos, and your Sorare profile picture) are loaded directly from Sorare's image/CDN servers. This technically transmits your IP address to Sorare. No tracking scripts or third-party cookies are involved.

API tokens (Sorare-OAuth) and other sensitive fields (2FA, optional Gemini key) are encrypted with Fernet (AES-128-CBC + HMAC-SHA256) at rest. Passwords are hashed with bcrypt (12 rounds).

Data transfer between your browser and our server is HTTPS-only (TLS 1.2+, Caddy + Let's Encrypt).

9. Contact

Privacy inquiries to jhnnsrmn@protonmail.com. We respond within the GDPR-mandated 1-month period.